Worked example · 2024-20
Rocket Pool fake-staking-frontend phishing campaigns — Ethereum — 2024–2025
Summary
Rocket Pool is a decentralised Ethereum liquid-staking protocol with a distinctive dual-flow architecture: users can either (a) deposit ETH to mint rETH (liquid-staking token — the "liquid staker" flow, analogous to Lido stETH), or (b) deposit 16 ETH + a minimum of 2.4 ETH-worth of RPL (Rocket Pool's governance token) to create a minipool and become a node operator (the "node operator" flow, which earns additional RPL rewards and commission on the staked ETH). Both flows require users to interact with the Rocket Pool staking interface, connect their wallets, and execute deposit transactions to the Rocket Pool smart contracts.
During 2024–2025, phishing operators deployed typosquat domains impersonating Rocket Pool's staking interface: rocket-pool.org, rocketpool-stake.com, rpl-staking.net, rocketpool-minipool.com. The fake frontends mirrored the legitimate Rocket Pool staking interface, displaying competitive APR projections and the node-operator commission rate. The campaigns targeted both the liquid-staker and node-operator flows, but the node-operator phishing sub-shape — where the attacker's fake interface prompted the user to deposit 16 ETH + 2.4 RPL-equivalent to "create a minipool" — was particularly high-value per victim because the minipool creation deposit is structurally larger (16 ETH minimum) than a typical liquid-staking deposit.
The phishing extraction worked through the same structural primitive as Lido stETH and EigenLayer campaigns: the fake interface routed the deposit transaction to an attacker-controlled address rather than to Rocket Pool's canonical staking contract. The user received no rETH and no minipool NFT (the receipt token for Rocket Pool node operators) — the deposit was an outright transfer to the attacker.
Some campaigns combined the staking-interface phishing with a secondary drain: after the user deposited ETH for a minipool, the fake interface requested an ERC-20 approve() for the user's existing RPL or rETH balance to an attacker-controlled spender, draining the user's existing Rocket Pool positions. The secondary drain could extract the user's full Rocket Pool balance — including rETH accumulated from prior liquid-staking deposits and RPL staked in existing minipools — beyond the new minipool deposit.
The search-engine-advertisement vector was active: users searching for "Rocket Pool node operator," "create Rocket Pool minipool," or "Rocket Pool stake ETH" encountered sponsored results leading to typosquat domains. The Rocket Pool community maintained informal domain allowlists in their Discord and Reddit channels, and the Rocket Pool team published canonical interface URLs in their documentation, but the domain-reputation infrastructure lagged behind the campaign deployment cadence.
The cohort generalises the T3.005 surface from single-flow liquid-staking protocols (Lido, Marinade) to a dual-flow protocol (Rocket Pool), demonstrating that the phishing surface width expands with the number of distinct staking flows the protocol offers — each flow is an independent T3.005 surface that the attacker can target with a flow-specific fake interface.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-Q1 to 2024-Q2 | Rocket Pool minipool creation activity increases as ETH staking yields attract node operators; typosquat domains (rocket-pool.org, rocketpool-stake.com) begin appearing | (standing T3.005 surface; Rocket Pool's dual-flow architecture creates two victim cohorts) |
| 2024-Q3 to 2024-Q4 | First major wave: node-operator-targeted campaigns (rocketpool-minipool.com, rpl-staking.net) serve cloned Rocket Pool interface; deposit routed to attacker-controlled address; minipool creation deposit (16 ETH minimum) yields higher per-victim extraction | T3.005 (node-operator-flow phishing sub-shape) |
| 2024-Q4 to 2025-Q1 | Campaigns expand to liquid-staker flow (rETH minting) and add secondary-approval drain for existing rETH/RPL balances; typosquat domains include rpl-minipool-staking.com, rocketpool-eth.com | T3.005 + T4.002 (secondary-approval drain) |
| 2025-Q1 to 2025-Q2 | Search-engine advertisement campaigns for "Rocket Pool stake ETH" and "Rocket Pool node operator" keywords; sponsored results lead to typosquat domains | T3.005 (search-engine-advertisement interception) |
| 2025-Q2 onward | Rocket Pool community domain allowlists updated; Google Safe Browsing flags and PhishTank entries reduce campaign effectiveness; residual campaigns continue at lower volume | (defender response; ongoing low-level surface) |
| Continuing | Rocket Pool's dual-flow architecture (liquid staker + node operator) means two distinct T3.005 surfaces exist per user; the node-operator flow's higher deposit minimum (16 ETH) makes it a structurally higher-value phishing target | T3.005 (ongoing surface; dual-flow architecture) |
Realised extraction
Aggregate mid-six-figures to low-seven-figures USD across the cohort. Per-victim extraction is bifurcated: liquid-staker-flow victims typically lost smaller amounts (mid-four-figures for rETH minting deposits of a few ETH), while node-operator-flow victims lost larger amounts (low-to-mid-five-figures for 16 ETH minipool deposits, or higher if the secondary-approval drain captured the user's existing rETH and RPL balances). The node-operator sub-shape's structurally higher deposit minimum (16 ETH) makes it the load-bearing extraction driver for the cohort's aggregate loss figure. Recovery has not been publicly confirmed.
Public references
- Rocket Pool official documentation — canonical interface URLs, staking contract addresses, and minipool creation flow
- Rocket Pool community channels (Discord, Reddit r/rocketpool) — informal domain allowlists and phishing-warning threads (2024–2025)
- Google Safe Browsing and PhishTank domain-reputation records for Rocket Pool typosquat domains
- Cross-reference: T3.005 at
techniques/T3.005-fake-validator-staking-frontend-phishing.md - Cross-reference:
examples/2022-2023-lido-steth-staking-phishing-cohort.md— Lido stETH staking-interface phishing campaigns (2022–2023) - Cross-reference:
examples/2024-2025-eigenlayer-airdrop-staking-frontend-phishing-cohort.md— EigenLayer restaking-frontend phishing cohort (2024–2025) [rocketpoolphishing2022]— Rocket Pool fake-staking-portal incidents (2022–2023); community reports and domain-reputation service records