{"success":true,"data":{"id":"point-farm-airdrop-drainer","label":"Fake DeFi points-to-token airdrop claim (Blur/Pendle/EigenLayer points) to drain wallets via malicious connect-wallet portal","description":"Fake DeFi points-to-token airdrop claim targeting users who have accumulated points on protocols like Blur, Pendle, EigenLayer, Renzo, EtherFi, and LayerZero. Points farming is a dominant 2024-2026 DeFi participation mechanism — protocols award off-chain points for liquidity provision and protocol interaction, which are later converted to token airdrops. Attackers send fake \"Your Blur/Pendle/EigenLayer points are now eligible for conversion — connect your wallet to claim before the deadline\" emails. When the victim connects their wallet to the malicious portal, it prompts them to sign a transaction that either approves unlimited token transfers (ERC-20 approval drain) or signs a malicious EIP-712 permit that drains the entire wallet. Points-farming users are high-value targets: they tend to hold significant DeFi positions and are conditioned to connect wallets and sign transactions frequently. The signal fires when: (1) body references a DeFi protocol with points (Blur, Pendle, EigenLayer, Renzo, EtherFi, etc.) AND (2) points-to-token conversion, airdrop claim, or connect-wallet-to-claim is present AND (3) sender is NOT an official protocol domain AND (4) no List-Unsubscribe or In-Reply-To. Source: GC1 R14 council #6; Chainalysis DeFi phishing report 2026.","tier":"danger","category":"phishing","isThin":false}}