Bitcoin Forum
May 11, 2024, 02:40:34 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Web3: A new attack vector for cyber criminals  (Read 191 times)
TravelMug (OP)
Hero Member
*****
Offline Offline

Activity: 2632
Merit: 833



View Profile
February 07, 2020, 12:53:28 AM
Last edit: October 19, 2023, 04:28:23 AM by TravelMug
Merited by Baofeng (1), Bttzed03 (1)
 #1

In the last two years, we have seen cyber criminals stepping up their game with fake giveaways, fake hardware wallets, and fake websites to get our personal info and data. However, they are going one level up again, this time taking advantage of web3 and the whole new hype - DeFi.

What is web3.js?

Quote
web3.js - Ethereum JavaScript API

web3.js is a collection of libraries which allow you to interact with a local or remote ethereum node, using a HTTP or IPC connection.

So it means that we just interact with our wallets and we don't need to enter our passwords or recovery phases. So here is one example,




On the left is the fake and scam website and I used the screenshot here. And on the left is the real one: https://migrate.makerdao.com/. So by design, you can't real tell the difference isn't it?

So basically if you have visited the phishing site and follow the instructions, you will be prompted to have access to your wallet thru MetaMask and then once you send the SAI, it's a done deal.

So I advise everyone to watch out for this new kind of attack vector.

References:


https://web3js.readthedocs.io/en/v1.2.6/
https://bitcointalk.org/index.php?topic=5219002.0/

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
1715438434
Hero Member
*
Offline Offline

Posts: 1715438434

View Profile Personal Message (Offline)

Ignore
1715438434
Reply with quote  #2

1715438434
Report to moderator
1715438434
Hero Member
*
Offline Offline

Posts: 1715438434

View Profile Personal Message (Offline)

Ignore
1715438434
Reply with quote  #2

1715438434
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715438434
Hero Member
*
Offline Offline

Posts: 1715438434

View Profile Personal Message (Offline)

Ignore
1715438434
Reply with quote  #2

1715438434
Report to moderator
1715438434
Hero Member
*
Offline Offline

Posts: 1715438434

View Profile Personal Message (Offline)

Ignore
1715438434
Reply with quote  #2

1715438434
Report to moderator
1715438434
Hero Member
*
Offline Offline

Posts: 1715438434

View Profile Personal Message (Offline)

Ignore
1715438434
Reply with quote  #2

1715438434
Report to moderator
Baofeng
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
February 12, 2020, 10:27:58 PM
Merited by TravelMug (1)
 #2

Thank you for referencing my post about this new attack that the cyber criminals are exploiting.

This kind of attacks surfaces around mid January this year, and the good thing is that other fake websites have been quickly shutdown. But I have no doubt that the cyber criminals are just waiting for the perfect time to release another attack similar to this.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!