A cryptocurrency holder lost approximately $5,000 after connecting to a hotel's public WiFi and discussing crypto assets in a public setting. The hacker used a man-in-the-middle (MITM) attack to inject malicious code into a web page, tricking the victim into signing a permission grant rather than a transaction. The wallet was drained days later, including SOL, various tokens, and NFTs.
How the MITM Attack Worked
Public WiFi networks typically lack strong isolation between devices, allowing attackers to intercept and modify traffic. The victim connected to the hotel's free WiFi, which required only a captive portal. While browsing, a seemingly legitimate website was infected with malicious code. The attacker listened in on a phone call where the victim discussed crypto with a friend, identifying the target as a crypto holder using Phantom wallet.
Deceptive Permission Request
The victim was using Jupiter Exchange, a decentralized exchange, to swap tokens. The malicious code replaced the legitimate swap request with a wallet authorization prompt. Mistaking it for part of the normal Jupiter workflow, the victim approved the request. In reality, it granted a third-party address permission to control the wallet. The attacker waited until after check-out to execute the theft.
Lessons Learned
The victim admitted multiple mistakes: using hotel public WiFi instead of a mobile hotspot; discussing crypto holdings in public; and approving a wallet request without verifying details. The wallet was a hot wallet used for daily operations, not the main storage. Still, the loss of $5,000 was painful. The incident underscores the risk of public WiFi for crypto users and the importance of scrutinizing every wallet authorization request, no matter the platform.

