Bitcoin Forum
May 13, 2024, 09:47:13 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: "G2A refund" BTC scam.Beware.  (Read 136 times)
davis196 (OP)
Hero Member
*****
Offline Offline

Activity: 2968
Merit: 914



View Profile
April 10, 2020, 06:43:44 AM
 #1

There's a new scam that I discovered recently.
Here are the details:
The victim gets tricked into installing a Tampermonkey script in his Chrome browser and using that script to purchase game keys or gift cards on G2A using Bitcoin.The victim is manipulated to believe that the script will change the timezone of the checkout page and make the payment session to expire,therefore Bitpay(the BTC payment processor of G2A) will refund automatically all transactions above 0.005 BTC,while G2A will complete the order and deliver the game keys/gift cards.

Hence,you get games and gift cards FOR FREE! Right? WRONG!

In reality,the Tampermonkey script changes the Bitpay wallet address on the G2A checkout page with the BTC address of the creator of that script(the scammer).The victim sends BTC to the scammers address and expect an automatic refund from G2A,but such refund never happens and the BTC are gone...

I don't want to post links here,but you can search Youtube for "G2A refund" and there are a bunch of videos about this "exploit". Usually the videos have more likes than dislikes and lots of fake sounding bot comments,about the script "working perfectly".

The Tampermonkey scam script has several names- "G2A refund glitch","timezone exploit","G2A exploit".

I don't use G2A and I don't care about this shady gaming marketplace.
If you ever want to buy something from G2A,just don't trust the "get everything on G2A for free" videos and methods that are shared across the internet.




The forum strives to allow free discussion of any ideas. All policies are built around this principle. This doesn't mean you can post garbage, though: posts should actually contain ideas, and these ideas should be argued reasonably.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715593633
Hero Member
*
Offline Offline

Posts: 1715593633

View Profile Personal Message (Offline)

Ignore
1715593633
Reply with quote  #2

1715593633
Report to moderator
1715593633
Hero Member
*
Offline Offline

Posts: 1715593633

View Profile Personal Message (Offline)

Ignore
1715593633
Reply with quote  #2

1715593633
Report to moderator
1715593633
Hero Member
*
Offline Offline

Posts: 1715593633

View Profile Personal Message (Offline)

Ignore
1715593633
Reply with quote  #2

1715593633
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6989



View Profile WWW
April 10, 2020, 09:30:07 PM
 #2

That's not really new. I have seen this scam multiple times with G2A, BitPay, LocalBitcoins and NitrogenSports.

Here is my last thread about the exact same scam: Fake "Localbitcoin doubling BTC exploit script" scam

The rule of thumb is "never run any unknown script" in your browser.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Jating
Hero Member
*****
Offline Offline

Activity: 2926
Merit: 808


View Profile
April 10, 2020, 11:45:19 PM
 #3

This has been on-going since September, same time that many Youtube accounts get hack and I'm sure besides from the fake giveways, this scam has also been exploited by the Youtube account hackers. As @TryNinja said, don't run untrusted extensions and perhaps why this kind of exploits didn't get as much traction to let's see a fake giveaway because you need tampermonkey and then you need to download this supposedly hack. As opposed to fake giveaways that noobs easily fall because all you have to do is to deposit to the scammers address.

But thanks to the heads-up.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!