BTC $62,728.97 -1.56%
ETH $1,871.56 -0.90%
BNB $607.03 -0.73%
XRP $1.00 -0.82%
SOL $75.43 -0.84%
TRX $0.3332 -0.13%
DOGE $0.0694 -1.43%
ADA $0.1818 -1.87%
BCH $204.92 -4.63%
LINK $8.82 +1.34%
HYPE $56.40 -2.24%
AAVE $86.71 -2.51%
SUI $0.6777 -1.84%
XLM $0.1584 -1.49%
ZEC $487.43 -1.78%
BTC $62,728.97 -1.56%
ETH $1,871.56 -0.90%
BNB $607.03 -0.73%
XRP $1.00 -0.82%
SOL $75.43 -0.84%
TRX $0.3332 -0.13%
DOGE $0.0694 -1.43%
ADA $0.1818 -1.87%
BCH $204.92 -4.63%
LINK $8.82 +1.34%
HYPE $56.40 -2.24%
AAVE $86.71 -2.51%
SUI $0.6777 -1.84%
XLM $0.1584 -1.49%
ZEC $487.43 -1.78%

phishing

All
Article
Flash

The Ethereum Foundation provides security funding to WEBCAT to assist in wallet verification front-end code to prevent phishing attacks

According to official news, the Ethereum Foundation's "Trillion Dollar Security" (1TS) has announced a special grant to the Freedom of the Press Foundation (FPF) to support the ongoing development of the open-source tool WEBCAT, aimed at addressing the long-standing front-end code verification security gap in Ethereum wallets and decentralized applications (DApps).WEBCAT (Web-based Code Assurance and Transparency) is an open-source tool designed to help browsers verify whether the code loaded by a website matches the version publicly released by the developer.This funding will promote the expansion of WEBCAT to Ethereum wallets and application scenarios, enabling users to verify whether the front-end pages they access have been tampered with.The Ethereum Foundation stated that while HTTPS can verify the website a user is connected to and encrypt communication, it cannot prove that the front-end code actually running on the website is the same version released by the developer. If an attacker controls the website's front-end code, they may modify the transaction receiving address without the user's knowledge or induce the user to sign transactions that do not match the content displayed on the page.The Ethereum Foundation noted that front-end attacks have become a significant security risk for blockchain infrastructure, with malicious modifications to web interfaces potentially leading to supply chain attacks, DNS hijacking subsequent attacks, and user interface deception.WEBCAT was initially developed by the Freedom of the Press Foundation to enhance the code credibility of secure communication systems like SecureDrop.With this expansion into the Ethereum ecosystem, it will complement security measures such as "Clear Signing" in the 1TS program: the former helps wallets confirm that the application front-end has not been tampered with, while the latter helps users understand the transaction content they are approving.

The IRS warns cryptocurrency holders that scammers are mailing fake letters to steal assets or data

According to Bloomberg, the Internal Revenue Service (IRS) has warned cryptocurrency holders that scammers are contacting some taxpayers by mailing fake letters in an attempt to steal their digital assets or personal data. The IRS stated that these letters may ask taxpayers to register for a so-called "Digital Asset Compliance Portal," which does not exist. The IRS also reminds users not to scan suspicious QR codes and not to answer or cooperate with calls requesting payment.While phishing and digital scams are not new in the cryptocurrency industry, sending fake IRS notices through physical mail seems to be a new scam tactic. Since the IRS has indeed sent letters related to digital assets to taxpayers in the past, and last year saw a surge in cryptocurrency tax filing notifications, many taxpayers are confused, which may lead scammers to exploit this familiarity for disguise. As the U.S. tax system requires taxpayers to disclose cryptocurrency activities on their tax returns, communication between the IRS and cryptocurrency holders has become more common. This also makes counterfeit tax notices more misleading. For cryptocurrency users, encountering "IRS letters" involving portal registration, QR code scanning, wallet connections, or payment requests should be treated with caution, and verification should be done through official channels.

Google's false encryption ads continue unabated, with a phishing site impersonating Uniswap stealing another $400,000

On-chain analyst "b-block" posted on social media on Monday that a counterfeit Uniswap website is stealing funds from multiple wallets, with assets held by the scammers valued at over $400,000. Stacy Muur, founder of the Web3 marketing agency Green Dots, shared screenshots of false sponsored results from search engines, criticizing Google for ignoring this issue for years, leading to fake links ranking above real ones, resulting in users continuously being scammed.According to Etherscan data, the two flagged addresses hold a total of about 146 ETH, valued at approximately $306,000. DeFiLlama pointed out that fake ads on Google are a common source of phishing attacks. The crypto nonprofit organization Security Alliance (SEAL) reported in April that phishing activities on Google searches significantly increased in March, with attackers deploying highly deceptive fake ads by paying for or hijacking legitimate ad accounts, using seemingly real URLs to bypass Google's automatic checks, and loading malicious payloads through hidden iframes.SEAL has blocked over 356 malicious ad links and stated that the volume of Google ads deployed by attackers has remained stable for over a year, with no slowdown in attack activities. Reports indicate that between March 13 and 30 alone, a total of $1.27 million was stolen. Additionally, earlier this month, there were malicious ad campaigns targeting Mac users that utilized Google ads and the AI chatbot Claude for shared chats. Malwarebytes also reported that Facebook is similarly a hotspot for fake ads and scams.

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.
app_icon
ChainCatcher Building the Web3 world with innovations.