• Contact Us
  • Homepages
Newsletter
Today Bitcoin News
Advertisement
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
Today Bitcoin News
No Result
View All Result
Home NEWS BAYC

How to avoid getting hooked by crypto ‘ice phishing’ scammers — CertiK

news by news
December 21, 2022
in BAYC, Certik, Coingecko, CoinMarketCap, Etherscan, permissions, Tornado
0
How to avoid getting hooked by crypto ‘ice phishing’ scammers — CertiK
192
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Ice phishing is a type of scam that exists only in Web3 and is a “considerable threat” to the crypto community, said the firm.

Blockchain security company CertiK has reminded the crypto community to stay alert over “ice phishing” scams — a unique type of phishing scam targeting Web3 users — first identified by Microsoft earlier this year. 

In a Dec. 20 analysis report, CertiK described ice phishing scams as an attack that tricks Web3 users into signing permissions which end up allowing a scammer to spend their tokens.

Related articles

$4M ‘exit scam’ suspected as Kokomo Finance flies off radar, token plunges

$4M ‘exit scam’ suspected as Kokomo Finance flies off radar, token plunges

March 27, 2023
Wallet tied to Uranium Finance hacker reawakens after 647 days, shifting $3.3M

Wallet tied to Uranium Finance hacker reawakens after 647 days, shifting $3.3M

March 7, 2023

This differs from traditional phishing attacks which attempt to access confidential information such as private keys or passwords, such as the fake websites set up which claimed to help FTX investors recover funds lost on the exchange.

#CertiKSkynetAlert

1/ Ice phishing is a considerable threat to the Web3 community

Instead of gaining accessing to your private key, scammers trick you into signing permissions to spend your assets.

We’ll outline below what to look out for, and how to protect yourself!

— CertiK Alert (@CertiKAlert) December 20, 2022

A Dec. 17 scam where 14 Bored Apes were stolen is an example of an elaborate ice phishing scam. An investor was convinced to sign a transaction request disguised as a film contract, which ultimately enabled the scammer to sell all of the user’s apes to themselves for a negligible amount.

The firm noted that this type of scam was a “considerable threat” found only in the Web3 world, as investors are often required to sign permissions to decentralized finance (DeFi) protocols they interact with, which could be easily faked.

“The hacker just needs to make a user believe that the malicious address that they are granting approval to is legitimate. Once a user has approved permissions for the scammer to spend tokens, then the assets are at risk of being drained.”

Once a scammer has gained approval, they are able to transfer assets to an address of their choosing.

An example of how an ice phishing attack works on Etherscan. Source: Certik

To protect themselves from ice phishing, CertiK recommended that investors revoke permissions for addresses they don’t recognize on blockchain explorer sites such as Etherscan, using a token approval tool.

Related: $4B OneCoin scam co-founder pleads guilty, faces 60 years jail

Additionally, addresses that users are planning to interact with should be looked up on these blockchain explorers for suspicious activity. In its analysis, CertiK points to an address that was funded by Tornado Cash withdrawals as an example of suspicious activity.

CertiK also suggested that users should only interact with official sites they are able to verify, and to be particularly wary of social media sites like Twitter, highlighting a fake Optimism Twitter account as an example.

Fake Optimism Twitter account. Source: Certik

The firm also advised users to take a couple of minutes to check a trusted site such as CoinMarketCap or Coingecko, users would have been able to see that the linked URL was not a legitimate site and should be avoided.

Tech giant Microsoft was the first one to highlight this practice in a Feb. 16 blog post, saying at the time that while credential phishing is very predominant in the Web2 world, ice phishing gives individual scammers the ability to steal a chunk of the crypto industry while maintaining “almost complete anonymity.”

They recommended that Web3 projects and wallet providers increase the security of their services on the software level in order to prevent the burden of avoiding ice phishing attacks being placed solely on the end-user.

Share77Tweet48

Related Posts

$4M ‘exit scam’ suspected as Kokomo Finance flies off radar, token plunges

$4M ‘exit scam’ suspected as Kokomo Finance flies off radar, token plunges

by news
March 27, 2023
0

Kokomo Finance's social media presence and websites are offline, while the price of the KOKO token fell more than 95%...

Wallet tied to Uranium Finance hacker reawakens after 647 days, shifting $3.3M

Wallet tied to Uranium Finance hacker reawakens after 647 days, shifting $3.3M

by news
March 7, 2023
0

The hacker has other associated wallets that have also shifted funds to privacy networks such as Aztec. One of the...

Whale sells 1,010 NFTs in 48 hours in ‘largest NFT dump ever’

Whale sells 1,010 NFTs in 48 hours in ‘largest NFT dump ever’

by news
February 25, 2023
0

With the Blur marketplace set for a second airdrop soon, Nansen’s Andrew Thurman theorized that this major NFT dump could...

No ‘respite’ for exploits, flash loans or exit scams in 2023: Cybersecurity firm

No ‘respite’ for exploits, flash loans or exit scams in 2023: Cybersecurity firm

by news
January 3, 2023
0

The industry is likely to see “further attempts from hackers targeting bridges in 2023," while users are urged to be...

$62M crypto stolen in Dec was the ‘lowest monthly figure’ in 2022: CertiK

$62M crypto stolen in Dec was the ‘lowest monthly figure’ in 2022: CertiK

by news
January 2, 2023
0

The month of December had the smallest figure for cryptocurrencies stolen in 2022 with around 23 major incidents according to...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

February 18, 2023
Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

March 1, 2023
Silvergate stock plunges 31% after delayed filing raises doubts over future

Silvergate stock plunges 31% after delayed filing raises doubts over future

March 2, 2023
ShapeShift responds to Sen. Warren’s comments to ‘set the record straight’

ShapeShift responds to Sen. Warren’s comments to ‘set the record straight’

February 19, 2023

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Cboe Digital receives nod for margin trades on its crypto futures exchange

Cboe Digital receives nod for margin trades on its crypto futures exchange

June 6, 2023
SEC’s Binance suit contains heavy mix of predictable charges, novel revelations

SEC’s Binance suit contains heavy mix of predictable charges, novel revelations

June 6, 2023
Fines and regulation: The ever-growing landscape of crypto compliance

Fines and regulation: The ever-growing landscape of crypto compliance

June 5, 2023
JPMorgan uses blockchain for 24/7 dollar transfers with Indian banks

JPMorgan uses blockchain for 24/7 dollar transfers with Indian banks

June 5, 2023
Today Bitcoin News

© 2022

Navigate Site

  • 2022
  • 2023
  • 5G
  • 5G network
  • Altcoin
  • bank of china
  • bank of england
  • Bank of Japan
  • Bank of Russia
  • Binance Academy
  • BingChatGPT
  • Bitcoin
  • Changpeng Zhao
  • ChatGPT Web3
  • coinbase
  • CoinDesk
  • CoinMarketCap

Follow Us

No Result
View All Result
  • Contact Us
  • Homepages

© 2022