Bitcoin Forum
July 07, 2024, 05:28:39 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Beware of Metamask phishing emails  (Read 120 times)
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1610
Merit: 792



View Profile
June 30, 2024, 07:56:50 PM
Last edit: July 01, 2024, 12:52:29 PM by Ultegra134
Merited by Lucius (1), Lafu (1)
 #1

I received this email today, which is of course a phishing email, but it looked a little more believable compared to others I've received the past few months, it even has a "verified" tick next to their email. Never "manually" secure your account by connecting your wallet to an unknown service or platform, or even worse, input your private key because automatic validation "failed".

Unfortunately, there's still a reasonable amount of people who are unaware and fall victims to these scams.


R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Orpichukwu
Sr. Member
****
Offline Offline

Activity: 532
Merit: 350



View Profile
June 30, 2024, 08:02:23 PM
 #2

The first method to detect a scam email without even trying to locate the error that might come with the email is that creating a Metamask wallet doesn't require users to input their email address before the wallet creation can be done; you just generate your wallet phrase or private key, and that's it.
 
So how can Metamask get your email address without you giving it to them? I personally discard any email that claims to come from all these wallet providers, and I know I have not given them my email address before. Receiving email from them alone is a scam.

.
Duelbits
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
JeromeTash
Legendary
*
Offline Offline

Activity: 2198
Merit: 1217


Heisenberg


View Profile
June 30, 2024, 08:52:57 PM
 #3

That blue checkmark is rather psychological to some users. It makes them believe as though the email is authentic, and yet it is not. I believe your email address must have leaked in one of those crypto related websites you signed for. So the scammer have an idea that you are into crypto.
It could have been something similar to the CoinMarketCap hack sometime back or the recent Coingecko hack.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
_act_
Legendary
*
Offline Offline

Activity: 938
Merit: 1235



View Profile
July 01, 2024, 04:37:17 AM
 #4

It could have been something similar to the CoinMarketCap hack sometime back or the recent Coingecko hack.
You mean the email of users leaked on Coinmarketcap or Coingecko? It could also be the user itself submitted his email somewhere online. Even those that submit their email for Trezor newsletter got their email breached by hackers. But is there a way that someone will provide his email somewhere on Metamask? This phishing attacker is common to Metamask users. I guess the bad actor knows definitely that the user are using Metamask.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Lucius
Legendary
*
Offline Offline

Activity: 3290
Merit: 5747


Donate to a noble cause🚑 - Link in profile


View Profile WWW
July 01, 2024, 10:08:02 AM
Last edit: July 01, 2024, 01:46:15 PM by Lucius
 #5

I've never used this wallet because I simply didn't need it, and the fact that it only had a browser version in the past (if I'm not mistaken) was completely repulsive to me considering that it's just too big a risk. I understand that a lot of people need to use this kind of wallet considering what they do, but I see countless risks in all of this, not only because scammers target potential victims through phishing, but also how often we can read that someone has linked their wallet in this way he was left without everything.



@Ultegra134, maybe you didn't notice (or it doesn't matter too much to you), but the screenshot you posted reveals your e-mail address.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
coin-investor
Hero Member
*****
Offline Offline

Activity: 2884
Merit: 582


Leading Crypto Sports Betting & Casino Platform


View Profile
July 01, 2024, 12:48:35 PM
 #6

I received this email today, which is of course a phishing email,
In that case your email has been pawned or there is a data breach on one of the site where your email is part of the breach, you should check it using this tool Check if your email address is in a data breach

Quote
but it looked a little more believable compared to others I've received the past few months, it even has a "verified" tick next to their email.
Even scammers can use this feature to scam their recipients, if you do not know the sender or you have not opted to be part of their email database then its considered a spam, and besides Metamask never ask for emails so how come they will send you an update through email.
Quote
Never "manually" secure your account by connecting your wallet to an unknown service or platform, or even worse, input your private key because automatic validation "failed"
If they ask you for private keys then its a scam, no platform other than your wallet can ask your private key or seeds




..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
cryptomaniac_xxx
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 599


View Profile
July 01, 2024, 12:54:15 PM
 #7

I received this email today, which is of course a phishing email, but it looked a little more believable compared to others I've received the past few months, it even has a "verified" tick next to their email. Never "manually" secure your account by connecting your wallet to an unknown service or platform, or even worse, input your private key because automatic validation "failed".

Unfortunately, there's still a reasonable amount of people who are unaware and fall victims to these scams.

Yes, this is another classic example of the modus of scammers, they try to emulate those well known wallet and try to be spoof team with this kind of emails. It's good that you recognized this as a phishing email and hopefully we one will fall for it.

Not just in email though, even is SMS or text message, this scammers are very active, not just in crypto, but everything financial like banks. And as what others said, it's better to verify first and just don't try them.
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1610
Merit: 792



View Profile
July 01, 2024, 01:02:18 PM
 #8

I've never used this wallet because I simply didn't need it, and the fact that it only had a browser version in the past (if I'm not mistaken) was completely repulsive to me considering that it's just too big a risk. I understand that a lot of people need to use this kind of wallet considering what they do, but I see countless risks in all of this, not only because scammers target potential victims through phishing, but also how often we can read that someone has linked their wallet in this way he was left without everything.



@Ultegra134, maybe you didn't notice (or it doesn't matter too much to you), but the screenshot you posted reveals your e-mail address.
Thanks, totally forgot about it! I Reuploaded the screenshot without it.

I'm not too fond of this wallet either, I've used it in the past when I was staking on Beefy or similar platforms. I've now stopped using it and withdrew all my funds, I also didn't feel safe using it and read quite a few stories of people getting scammed. I almost got scammed as well, but it was my fault, it just shows the vulnerabilities of such wallet.
That blue checkmark is rather psychological to some users. It makes them believe as though the email is authentic, and yet it is not. I believe your email address must have leaked in one of those crypto related websites you signed for. So the scammer have an idea that you are into crypto.
It could have been something similar to the CoinMarketCap hack sometime back or the recent Coingecko hack.
That's true, at it's quite common on social media pages, where you can practically purchase it for a small amount of money. That's actually an old email of mine which has been found in quite a few database leaks.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
robelneo
Legendary
*
Offline Offline

Activity: 3290
Merit: 1209


View Profile WWW
July 01, 2024, 03:31:38 PM
 #9

I always hit spam on emails I'm unfamiliar with, and if they do not have an unsubscribe button, it's targeted spam and likely a scam attempt.
I checked the source of the email, and it's using the domain
Code:
qemailserver.com
My anti-virus is blocking it because of its invalid certificate; a legitimate site will always have a valid certificate.
Quote
URL: qemailserver.com
Reason: Invalid name of certificate. Either the name is not on the allowed list or was explicitly excluded. View certificate



█████████████████████████████████
████████▀▀█▀▀█▀▀█▀▀▀▀▀▀▀▀████████
████████▄▄█▄▄█▄▄██████████▀██████
█████░░█░░█░░█░░████████████▀████
██▀▀█▀▀█▀▀█▀▀█▀▀██████████████▀██
██▄▄█▄▄█▄▄█▄▄█▄▄█▄▄▄▄▄▄██████████
██░░█░░█░░███████████████████████
██▀▀█▀▀█▀▀███████████████████████
██▄▄█▄▄█▄▄███████████████████████
██░░█░░█░░███████████████████████
██▀▀█▀▀█▀▀██████████▄▄▄██████████
██▄▄█▄▄█▄▄███████████████████████
██░░█░░█░░███████████████████████
█████████████████████████
██
███████████████████████
█████▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████▄▄▄▄▄▄▄▄████▄▄▄█████
██████████████▄██████████
████████████████▄████████
█████████████████████████
█████████████████████████
████████████████████████
██
██████████████████████
██████████████████▀▀████
██████████████▀▀░░░░████
██████████▀▀░░░▄▀░░▐████
██████▀▀░░░░▄█▀░░░░█████
████▄▄░░░▄██▀░░░░░▐█████
████████░█▀░░░░░░░██████
████████▌▐░░▄░░░░▐██████
█████████░▄███▄░░███████
████████████████████████
████████████████████████
████████████████████████
albon
Legendary
*
Offline Offline

Activity: 1750
Merit: 1407



View Profile
July 01, 2024, 03:50:14 PM
 #10

at it's quite common on social media pages, where you can practically purchase it for a small amount of money. That's actually an old email of mine which has been found in quite a few database leaks.
This may not be the original blue tick in the message you received. It may be one of the symbols used as a trick to make the sender’s email/name appear as if it actually has the original verification mark, or perhaps the scammers have used the BIMI feature provided by Gmail and Yahoo through their primary domain and their brand logo to obtain this verification mark that is given to the owners of organizations, companies, public figures and the like. For this reason, verification marks have become easy, as you mentioned, and can be purchased through social media. Therefore, the sender’s email and the content of the message are one of the clear signs that prove this phishing attempt.

I do not advise anyone to open the email links or download any attached files. Instead, rely on bookmarked official links in your browser. MetaMask is a secure wallet, and these phishing messages target all wallets and crypto platforms. Therefore, everyone should be aware of what they are doing and know the necessary security measures.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
aioc
Hero Member
*****
Offline Offline

Activity: 2954
Merit: 567



View Profile
July 02, 2024, 12:27:26 PM
 #11

Even if they are using a blue tick that makes the email legit, we still have to follow the established advice of not connecting our wallet to platforms coming from emails.

Metamask clearly stated it in their article :

Quote
MetaMask will never send you unsolicited emails.
MetaMask will not and cannot initiate email correspondence with you.
We hold no personal identifying information such as names, email addresses, or otherwise — we don't collect these at any point whilst you're creating your wallet. This means we have no means of contacting you directly unless you specifically request it. And even then, there are only a few specific ways you can do this.

https://support.metamask.io/privacy-and-security/staying-safe-in-web3/i-received-an-email-claiming-to-be-from-metamask-is-it-legit

This kind of email is for newbies who are not aware of Metamask policy regarding emails.

NotATether
Legendary
*
Offline Offline

Activity: 1652
Merit: 6972


In memory of o_e_l_e_o


View Profile WWW
July 04, 2024, 05:32:16 PM
 #12

I receive this bullshit all the time. It is automatically thrown in the dumpster bin (aka. Spam).

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Lafu
Legendary
*
Offline Offline

Activity: 3024
Merit: 3134



View Profile
July 04, 2024, 06:57:59 PM
 #13

I receive this bullshit all the time. It is automatically thrown in the dumpster bin (aka. Spam).
Same here , and there are also a ton of other Fake / Phishing emails all the time.
I guess the first one i have seen was years ago and i also posted it somewhere (i think it was Meta) but at that time the Links was posted in the Forum.
There are so many fake mails for everything lately even you dont have an account on the website and service you get one.

Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1610
Merit: 792



View Profile
July 04, 2024, 08:28:03 PM
 #14

I receive this bullshit all the time. It is automatically thrown in the dumpster bin (aka. Spam).
I receive a bunch of them daily on this email address, however, a large number of them, especially cryptocurrency related ones slip through the spam folder and land in my inbox. Not sure if it's random or Yahoo is crap at identifying phishing and scam emails, or those emails are so sophisticated that manage to pass through their security. They're annoying either way.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!