Blockchain safety agency SlowMist has highlighted 5 widespread phishing methods crypto scammers used on victims in 2022, together with malicious browser bookmarks, phony gross sales orders and trojan malware unfold on messaging app Discord.

It comes after the safety agency recorded a complete of 303 blockchain safety incidents within the 12 months, with 31.6% of those incidents attributable to phishing, rug pull or different scams, in keeping with a Jan. 9 SlowMist blockchain safety report.

A pie chart of assault strategies in 2022 in percentages Supply: SlowMist

Malicious browser bookmarks

One of many phishing methods makes use of bookmark managers, a function in most fashionable browsers.

SlowMist mentioned scammers have been exploiting these to finally acquire entry to a undertaking proprietor’s Discord account.

“By inserting JavaScript code into bookmarks via these phishing pages, attackers can doubtlessly acquire entry to a Discord consumer’s info and take over the permissions of a undertaking proprietor’s account,” the agency wrote.

After guiding victims so as to add the malicious bookmark via a phishing web page, the scammer waits till the sufferer clicks on the bookmark whereas logged into Discord, which triggers the implanted JavaScript code and sends the sufferer’s private info to the scammer’s Discord channel.

Throughout this course of, the scammer can steal a sufferer’s Discord Token (encryption of a Discord username and password) and thus acquire entry to their account, which permits them to publish faux messages and hyperlinks to extra phishing scams posing because the sufferer.

‘Zero greenback buy’ NFT phishing

Out of 56 main NFT safety breaches, 22 of these have been the results of phishing assaults, added SlowMis

One of many extra well-liked strategies utilized by scammers would trick their victims into signing over NFTs for virtually nothing via a phony gross sales order.

As soon as the sufferer indicators the order, the scammer can then buy the consumer’s NFTs via a market at a worth decided by them.

Forged your vote now!

“Sadly, it is not attainable to deauthorize a stolen signature via websites like Revoke,” the report wrote.

“Nevertheless, you’ll be able to deauthorize any earlier pending orders that you just had arrange, which might help mitigate the chance of phishing assaults and forestall the attacker from utilizing your signature.”

Malicious program foreign money theft

In keeping with SlowMist, this sort of assault often happens via personal messages on Discord the place the attacker invitations victims to take part in testing a brand new undertaking, then sends a program within the type of a compressed file that incorporates an executable file of about 800 MB.

After downloading this system, it is going to scan for information containing key phrases like “pockets” and add them to the attacker’s server.

“The newest model of RedLine Stealer additionally has the flexibility to steal cryptocurrency, scanning for put in digital foreign money pockets info on the native pc and importing it to a distant management machine,” mentioned SlowMist.

“Along with stealing cryptocurrency, RedLine Stealer may also add and obtain information, execute instructions, and ship again periodic details about the contaminated pc.”

An instance of the RedLine Stealer in motion. Supply: SlowMist

‘Clean Examine’ eth_sign phishing

This phishing assault permits scammers to make use of your personal key to signal any transaction they select. After connecting your pockets to a rip-off web site, a signature utility field might pop up with a pink warning from MetaMask.

After signing, attackers acquire entry to your signature, permitting them to assemble any information and ask you to signal it via eth_sign.

“This sort of phishing may be very complicated, particularly relating to authorization,” mentioned the agency.

Similar ending quantity switch rip-off

For this rip-off, attackers airdrop small quantities of tokens, resembling .01 USDT or 0.001 USDT to victims typically with an analogous deal with, apart from the previous few digits within the hopes of tricking customers into unintentionally copying the mistaken deal with of their switch historical past.

An instance of a identical finish quantity phishing try. Supply: SlowMist

The remainder of the 2022 report coated different blockchain safety incidents within the 12 months, together with contract vulnerabilities and personal key leakage.

Associated: DeFi-type tasks acquired the very best variety of assaults in 2022: Report

There have been roughly 92 assaults utilizing contract vulnerabilities within the 12 months, totaling almost $1.1 billion in losses due to flaws in sensible contract design and hacked packages.

Non-public key theft then again accounted for roughly 6.6% of assaults and noticed not less than $762 million in losses, probably the most distinguished examples being the Ronin bridge and Concord’s Horizon Bridge hacks.


Please enter your comment!
Please enter your name here