BTC $83,466.89 -1.31%
ETH $2,678.55 -0.35%
BNB $764.60 -1.65%
XRP $1.49 -2.45%
SOL $118.86 -3.25%
TRX $0.3357 +0.60%
DOGE $0.0940 -3.05%
ADA $0.2457 -3.73%
BCH $308.57 -7.54%
LINK $15.28 +8.73%
HYPE $88.06 -4.06%
AAVE $148.01 -4.25%
SUI $1.14 -8.72%
XLM $0.2287 +5.74%
ZEC $1,471.38 -8.46%
AAPL $338.48 -0.54%
AMZN $246.58 -1.44%
GOOGL $342.76 -0.39%
MSFT $509.94 -1.44%
META $715.18 -4.72%
NVDA $228.75 +1.49%
TSLA $357.44 -4.33%
SNDK $1,710.73 -4.13%
INTC $115.97 -7.81%
SPCX $145.65 -2.13%
MU $1,053.43 -3.84%
AMD $608.74 -4.07%
BTC $83,466.89 -1.31%
ETH $2,678.55 -0.35%
BNB $764.60 -1.65%
XRP $1.49 -2.45%
SOL $118.86 -3.25%
TRX $0.3357 +0.60%
DOGE $0.0940 -3.05%
ADA $0.2457 -3.73%
BCH $308.57 -7.54%
LINK $15.28 +8.73%
HYPE $88.06 -4.06%
AAVE $148.01 -4.25%
SUI $1.14 -8.72%
XLM $0.2287 +5.74%
ZEC $1,471.38 -8.46%
AAPL $338.48 -0.54%
AMZN $246.58 -1.44%
GOOGL $342.76 -0.39%
MSFT $509.94 -1.44%
META $715.18 -4.72%
NVDA $228.75 +1.49%
TSLA $357.44 -4.33%
SNDK $1,710.73 -4.13%
INTC $115.97 -7.81%
SPCX $145.65 -2.13%
MU $1,053.43 -3.84%
AMD $608.74 -4.07%

phishing

All
Article
Flash

Phishing websites use meme coin display pages to attract traffic, resulting in significant losses for multiple traders

Recently, the meme coin market has been booming, and on-chain trading has become increasingly active. However, with the warming market, meme coin display pages have frequently shown highly disguised phishing links, and the "novel" attack methods have caused several seasoned traders to fall victim. Crypto KOLs @insidecalls and @cladzsol recently revealed that while scanning chains, they clicked on the meme coin homepage, which resulted in a "cloudfare verification" prompt. After completing the verification as instructed, the victim's on-chain funds were stolen. Among them, @cladzsol lost approximately $600,000 in assets.According to market news, on several recently popular meme coin display pages, the homepage redirects to a "cloudfare verification" page, which is actually a phishing link. If users follow the prompts, their computer systems will download and execute malicious scripts, leading to asset loss. This phenomenon is so rampant that it may be related to the delayed review processes of mainstream trading aggregation platforms like DexScreener. Currently, the display logic of relevant platforms is to directly reference the "official website" or social media links filled in the token metadata. These fields can be updated by token creators or those who later claim "community takeover." Hackers are exploiting this review loophole to transform meme coin display pages into new "fishing grounds" for phishing attacks. Users may inevitably click on unfamiliar links during the chain scanning process; if a "cloudfare verification" or other highly suspicious page appears, they should close it immediately to avoid interaction and protect their asset security.

first_img Trezor marketing platform was breached, 347,000 users received phishing emails

Bitcoin hardware wallet manufacturer Trezor has warned that its third-party marketing platform Brevo, used for sending newsletters, experienced a data breach, with attackers using the platform to send phishing emails to 347,000 Trezor customers. The attackers sent emails using Trezor's domain, making the phishing attempt more deceptive, with malicious links encouraging users to download applications and enter wallet backups.Trezor stated that it shut down the domain at the DNS level within 20 minutes to prevent the links from remaining active, but approximately 2,500 people had already clicked on them. Trezor has suspended its Brevo account to stop further emails from being sent and emphasized that other Trezor systems were not affected aside from the marketing platform, while reminding users that Trezor never asks customers for wallet backups.Prior to this incident, Trezor disclosed last month that its third-party fulfillment partner ShipMonk was attacked, resulting in the data breach of 11,742 customers; last week it also reported that the names, emails, phone numbers, shipping addresses, and order numbers of another 67,000 U.S. customers were exposed in the breach. This year, cryptocurrency wallet Ledger's payment processor Global-e and wallet provider SafePal have also experienced data breaches, with approximately 39,800 customers' order information at SafePal being accessed without authorization.

SafePal updates on security incident progress: launching anti-phishing actions and will commission a third-party agency to review the order system

The cryptocurrency wallet project SafePal has released updates on the security incident, stating that it is continuously tracking phishing websites and impersonation accounts, and plans to introduce a professional anti-phishing security company to expedite the removal of malicious information to protect user asset security. SafePal mentioned that it is currently in the final selection process among four professional anti-phishing security companies, and once a partner is selected, it will further enhance the efficiency of handling threats such as counterfeit websites and scam accounts.The team is also continuously monitoring whether the affected data has been sold or made public, including channels such as dark web forums and trading markets. Once signs of data leakage are detected, affected users will receive risk alerts immediately. Regarding security audits, SafePal stated that it is in the final selection among three mature independent security institutions, which will conduct a comprehensive security review of the order system. Meanwhile, the team is reassessing the order and logistics processes to reduce the amount of data that needs to be stored in the initial phase of the system, thereby reducing potential risks from the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating the fraud protection page, providing updates on the incident, FAQs, and analysis of fraud cases. SafePal once again reminds users: the official will never ask users to provide their seed phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify the source of information through official channels.

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.
app_icon
ChainCatcher Building the Web3 world with innovations.