Malicious actors have stolen more than $1m in a ‘pig butchering’ cryptocurrency scam in just three months, researchers from Sophos have found. The highly sophisticated operation used a total of 14 domains and dozens of nearly identical fraud sites, according to the investigation. The attackers utilized fake trading pools of cryptocurrency from decentralized finance (DeFi) trading applications to defraud their victims, with one individual losing $22,000 in a single week. These “liquidity pools,” which encompass various types of cryptocurrencies, enable users to make profits by trading from one cryptocurrency to another. Those who participate receive a percentage of any fee paid when a trade is made – with another account (typically the operators of the pool) given permission to access participants’ wallets to facilitate the trades.