{"success":true,"data":{"id":"lrt-restaking-eip712-phish","label":"EIP-712 typed-data signature phishing for Liquid Restaking Token protocols (EigenLayer, EtherFi, Kelp DAO, Renzo) from non-protocol sender","description":"EIP-712 typed-data signature phishing targeting Liquid Restaking Token (LRT) protocol users — attackers send fake \"claim restaking rewards\" or \"re-delegate your stake\" emails requesting an off-chain EIP-712 permit signature. Liquid restaking protocols (EigenLayer, EtherFi/eETH, Kelp DAO/rsETH, Renzo/ezETH, Swell/swETH, Puffer Finance) allow Ethereum stakers to earn additional yield by restaking their LSTs into shared security networks. In 2025-2026, EigenLayer alone holds $15B+ in restaked assets. Attackers exploit the complex UX of DeFi — users are accustomed to signing off-chain EIP-712 messages for legitimate protocol interactions (permit2, delegation, reward claims). A maliciously crafted EIP-712 message signed by the victim may authorize token transfers or drain the wallet via the permit pattern. Phishing emails impersonate protocol notifications about \"accumulated restaking rewards ready to claim\" or \"re-delegation required to continue earning\" with urgency (expires in 24 hours). The signal fires when: (1) body references an LRT protocol brand (EigenLayer, EtherFi, eETH, Kelp DAO, rsETH, Renzo, ezETH, Swell, Puffer, etc.) AND (2) EIP-712 signature or restaking-claim action is present AND (3) sender is NOT an official protocol domain AND (4) no List-Unsubscribe or In-Reply-To. Source: GC1 R14 council #5; CertiK LRT phishing report Q1 2026; Chainalysis restaking fraud analysis.","tier":"danger","category":"phishing","isThin":false}}