Disclosure Today
  • Home
  • Business
  • Gaming
  • Crypto
Sunday, March 26, 2023
No Result
View All Result
  • Home
  • Business
  • Gaming
  • Crypto
No Result
View All Result
Disclosure Today
No Result
View All Result
Home Crypto

Security PSA: Mining Pool Scams Targeting Self-Custody Wallets

Coinbase by Coinbase
March 24, 2022
in Crypto
0
24
SHARES
800
VIEWS
Share on FacebookShare on Twitter

By Coinbase Security Team

As part of our mission to build a more fair, accessible, efficient, and transparent financial system enabled by crypto, we actively monitor for security threats not only to Coinbase but to the crypto ecosystem as a whole. As we have discussed in our previous blog posts on industry-wide crypto security threats and airdrop phishing campaigns, malicious activity against any crypto user or business is bad for the industry. That’s why it’s important to have a community mindset when we see security threats in the wild. As they say, rising tides lift all boats.

Recently, our security teams have uncovered ongoing mining pool scams targeting users of self-custody wallets. These scams have primarily leveraged malicious smart contracts on the Ethereum network. Based on blockchain research into known scammer wallets, Coinbase estimates these have resulted in the theft of over $50 million in crypto assets from a variety of non-custodial wallet applications. These scams target those using any decentralized wallet browser (e.g. Coinbase Wallet, Metamask, Trust, etc).

The scam typically follows this chain of events:

Victims are contacted via social media and/or other messaging services by scammers claiming to offer an attractive crypto investment opportunity to stake USDT (Tether) in their wallet for a guaranteed returnVictims are directed to visit a fraudulent website that can only be accessed via a crypto wallet browser or extension. These websites generally contain fake reviews, endorsements, live-feed payouts, and partner lists to add an appearance of authenticityScam sites will often fraudulently claim to be sponsored by or partnering with recognizable crypto brands such as Coinbase, Binance, and MetaMaskExample mining pool landing page

Source: Scam Site

Clicking the ‘Receive’ button displays a pop up similar to this

Source: Scam Site

Clicking this ‘Receive’ button will then display a fake pop-up designed to impersonate the Coinbase Wallet interface. The permissions that are displayed are not the true permissions that are actually being requested and are intentionally displayed in a way to attempt to trick users into clicking ‘Connect’

Source: Scam Site

Viewing the smart contract via a trusted token approval checker shows the true permissions being requested. The scammer gains delegated transaction approval status with an unlimited transaction allowance within the victim wallet, meaning the scammer can approve USDT sends of any amount on behalf of this wallet.

Source: etherscan.io

Attackers will remove USDT from the victim’s wallet and the scam site will show that their balance is increasing. Scammers will frequently reassure victims that if they add more funds, they will get more USDT in returns by mining.At the end of the period, the funds are not returned to the victim and no profits will be received.If the victim contacts customer support via the fraudulent website, the attacker may indicate they detected irregular activity on the account and that in order to fix that issue, the victim would need to pay additional USDT to ‘release’ the funds. However, no funds are ever returned regardless of whether or not the victim makes payment.The following security steps can be taken to defend your assets:

Be wary of investments that claim a guaranteed returnBe wary of investment advice and opportunities from unknown or untrusted sourcesDo not visit or connect self-custody wallets to any unknown siteDo not hold high value assets in the same wallet used to regularly interact with dapps. Use cold storage or custodial solutions such as the freely available Coinbase Vault.Use a token approval checker to validate actual permissioning on self-custody wallets and revoke approvals that you did not knowingly authorize.Coinbase is working with industry partners to take down these sites and developing ways to warn users when visiting known scam sites in order to help limit the damage caused by this type of scam.

Read More

Previous Post

Michael Grade appointed Ofcom chair after lengthy search

Next Post

P&O chief admits breaking law over mass sackings

Next Post

P&O chief admits breaking law over mass sackings

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Singapore launches quarantine-free travel to 10 countries

October 19, 2021

Chainlink Targets Double Digits After Staking Roadmap Update

June 8, 2022

Can Terra Classic’s USTC Stablecoin Ever Reclaim $1?

October 10, 2022
Three community-led ways to promote equity and make better games

Three community-led ways to promote equity and make better games

November 3, 2021

Trump Spac fails to pay proxy firm despite tough hunt for votes

September 17, 2022

European gas prices soar after Russia deepens supply cuts

July 26, 2022

Justice Department under pressure to explain raid on Trump’s estate

August 9, 2022

Johnson braced for Gray report into lockdown parties

January 26, 2022

Chainlink Looks Ready to Start a New Bull Rally

October 19, 2021

New Hong Kong school textbooks say city was not a British colony

June 15, 2022

Bank of France Eyes 2023 for CBDC Launch

July 12, 2022

Aurora Pays Out $6M Bug Bounty to White Hat Hacker

June 7, 2022

U.S. Publishes Fact Sheet on Global Crypto Regulation

July 7, 2022

The Problem With the Latest Bitcoin Price Rally

July 21, 2022

Fired P&O seafarers recall ‘shocking’ sackings as they face uncertain future

April 1, 2022

Golden Apple Comics kicks off its new comics preservation charity with help from Frank Miller

March 3, 2022
  • Home
  • Crypto

© 2021 Disclosure / Today.

No Result
View All Result
  • Home
  • Crypto

© 2021 Disclosure / Today.