The attacker wouldn't lose money because they're using that wallet to pay the fees, so you'd be the only one paying the transaction fee. Also, if this became a standard, it's possible that attackers would find ways around it (it kind of becomes an arms race to see who can bribe miners the most).
If your wallet contains no ETH, but contains for example, USDC, then they have to transfer their own ETH in to make a transaction to extract the USDC. This would work in theory, but it's such a common way to scam/hack people already that most attackers would be able to sniff out the honeypot.
The typical scam is "leaking" the private key for a wallet that has, say, $30 of some valuable token in it (e.g. on reddit, discord, anywhere that less technical users congregate). When users import the key and realize they can transfer the token out, they only need to deposit some ETH to the wallet first to pay for gas fees. But when they do that, a script automatically sends the ETH somewhere else.
Personally I see this being a potentially valuable way to manage servers, and also pay a non-critical bug bounty to black-hats. Each server can have its own crypto wallet, and the amount you fund it with varies based on how critical it is. If a compromise of one system occurs, you know immediately where the compromise occurred based on the address.
The attacker gets a payday, and you get a lead on something you need to patch.
The hackers could operate a miner which privately adds that transaction every time it tries to solve a block, but broadcasts it only when they successfully got the block. It could be running for days before it succeeds, because there's probably no urgency. They can take all the fees, and it's difficult to frontrun because nobody knows the theft is happening until the block is already solved and it's almost too late.
Old situation: blackhats sticks around for weeks or even months, exfiltrate data, blackmail, install crypto miners, etc.
With crypto honeypot: blackhats take the crypto and leaves.
With rigged crypto honeypots that are actually not redeemable:
>on the hacker forums:
>Guy A: "I tried to take the bitcoins from Corp A's honeypot wallet, but they broadcasted a high fee transaction and beat me to it."
>Guy B: "Funny, same thing happened to me last week with Corp B's wallet."
>Guy A: "Guess it's back to the old blackmail method then."
Bottom line: I think we can guess which option a CEO would usually choose
Remember that this method works best when it's not obvious that it is a tripwire, and may be best of all when it acts as a bribe to a greedy individual within a group of hackers.
What do you mean? The only outcome is that the company loses money due to giving it to miners.