Bitcoin Forum
May 14, 2024, 03:52:23 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Contract Addresses: The need to be more cautious  (Read 215 times)
evichi (OP)
Jr. Member
*
Offline Offline

Activity: 1190
Merit: 7


View Profile
April 21, 2023, 10:01:58 PM
 #1

I saw a token in my wallet which I suspected could be a fake one. On visiting Coinmarketcap to check if the contract address on Coinmarketcap is the same as the one in my wallet, I noticed there was a difference. But that was not the problem, what bothered me most was the striking resemblance of the two contract addresses. There is some noticeable frightening resemblance:

Token Name: CryptoGPT
Blockchain: Binance Smart Chain

Original Contract Address (from Coinmarketcap: https://coinmarketcap.com/currencies/cryptogpt/): 0x153c0c947177e631e3dfc594ba28750d3a921fb5  https://bscscan.com/address/0x153c0c947177e631e3dfc594ba28750d3a921fb5

Fake Contract Address (Fake token sent to my wallet): 0x513C285CD76884acC377a63DC63A4e83D7D21fb5  https://bscscan.com/address/0x513c285cd76884acc377a63dc63a4e83d7d21fb5

On comparing the two:  you notice the last five digits of the two addresses are the same. There is also some similarity on the four digits after the 0x at the beginning of the addresses.  Also there is a ‘77’ somewhere between the addresses. The striking resemblance marvelled me and I decided to share this experience to alert both newbies and experienced. Interacting with a malicious token may lead to loss of tokens in your wallet. Please share your comments. Perhaps some of you already have such experience?

▬▬▬▬[ CHAIN JOES || THE FUTURE OF WEB3 GAMING  ]▬▬▬▬▬
CHAINJOES.COM
1715658743
Hero Member
*
Offline Offline

Posts: 1715658743

View Profile Personal Message (Offline)

Ignore
1715658743
Reply with quote  #2

1715658743
Report to moderator
Make sure you back up your wallet regularly! Unlike a bank account, nobody can help you if you lose access to your BTC.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
coin-investor
Hero Member
*****
Offline Offline

Activity: 2828
Merit: 578


Leading Crypto Sports Betting & Casino Platform


View Profile
April 21, 2023, 10:20:10 PM
 #2

I am fully aware of that and I also received a lot of fake coins trying to resemble a real one, so to keep yourself safe from this check the official site to get the contract address or from the market aggregator if you're going to trade in a Decentralized Exchange.

These are spam tokens created as a trap if you're careless about how you transact.
Scammers are improving they can now use a contract address that is very much similar to the real one, so awareness is very important you should check and double the details.
One moment of carelessness and you lose your coins.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Oceat
Sr. Member
****
Offline Offline

Activity: 2506
Merit: 368


View Profile
April 21, 2023, 10:28:15 PM
 #3

This is new to me though I haven't been trading altcoins but seeing this was helpful to all of us. And also we should be very cautious and careful to check every numbers and letters of the address before doing anything or just triple check everything if you aren't satisfied but just don't be too quick to send.

Thanks for this newbies should be aware of this in the first place since scammers are doing everything they can to make advantage or steal our coins. It may not be just in the altcoins but it's mostly likely existing to BTC address too.

3996
WalkerIVIV
Hero Member
*****
Offline Offline

Activity: 2436
Merit: 503


Cryptocasino.com


View Profile
April 21, 2023, 10:48:57 PM
 #4

i've just heard about it just now, fake coins with their uncanny resemblance with the original contract address, i'd say nowadays, if i want to add token i'd just go to coinmarketcap and add it from there, since they provides button for it, more convenient and definitely hardly gonna be scammed by these fake coins.

noorman0
Hero Member
*****
Offline Offline

Activity: 1764
Merit: 694


[Nope]No hype delivers more than hope


View Profile WWW
April 21, 2023, 10:53:33 PM
 #5

Haven't looked into how this is done, it looks like scammers are slowly finding more sophisticated ways to generate nearly identical addresses.
However, one should be more careful dealing with altcoin projects because scammers are increasing their ability to trap users.

This space for rent.
Available in mid January 2024 - PM me
bitkanu
Hero Member
*****
Offline Offline

Activity: 2184
Merit: 513


Moonbet.io | Web3 Casino


View Profile
April 21, 2023, 11:02:09 PM
 #6

this is why rechecking the address is always essential, it's just ridiculous how these scammers have quite literally created so many fake token smart contract address that actually we've lost count, considering the fact that now the address almost identical, I think its time for the swap platform taking care of their platform by adding further massive verification of the verified token into their swap platform, maybe even pulling data from cmc and coingecko.

       ▒▒▒▒▓███▓▒▒▒▒     
    ▓██▓▓█████████▓▓██▒ 
   ███████▓▓░░░▓▓███████
  ▓▓▓██▓          ░███▓▓▓
 ▒▓▒██▒       ░▓█   ██▒▓▒
▒▓▓▓▒       ▓███    ▓▓▓
████     █████░     ████
████▓░  ██████▓      ████
▒▓▓▓██▒    ████▓     ░▓▓▓
 ▒▓▒███▓▒▒▓░ ▓█      ██▒▓░
  ▓▓▓██████▒       ▓██▓▓▓
   ▓████████░░░██▓█████
    ▒██▓▓▓████████▓▓██░ 
       ░▒▒▒▓█▓█▓▒▒▒       
.MOONBET.||       ▒▒▒▒▓███▓▒▒▒▒     
    ▓██▓▓█████████▓▓██▒ 
   ███████▓▓░░░▓▓███████
  ▓▓▓██▓          ░███▓▓▓
 ▒▓▒██▒       ░▓█   ██▒▓▒
▒▓▓▓▒       ▓███    ▓▓▓
████     █████░     ████
████▓░  ██████▓      ████
▒▓▓▓██▒    ████▓     ░▓▓▓
 ▒▓▒███▓▒▒▓░ ▓█      ██▒▓░
  ▓▓▓██████▒       ▓██▓▓▓
   ▓████████░░░██▓█████
    ▒██▓▓▓████████▓▓██░ 
       ░▒▒▒▓█▓█▓▒▒▒       
█▀▀▀











▀▀▀▀
> TWITTER
> MEDIUM
> INSTAGRAM
> TELEGRAM
▀▀▀█











▀▀▀▀
sunsilk
Hero Member
*****
Offline Offline

Activity: 2912
Merit: 620



View Profile
April 22, 2023, 04:58:28 AM
 #7

It may not be an address but it's a contract address so I think that it's still inside of this type of attack which is the address poisoning.

Thread: What are Address Poisoning Scams?

That thread is giving the description of it and everything related to it. Just as the example you've said that the first and last texts/letters are the same but in the middle, it's totally different.

vv181
Legendary
*
Offline Offline

Activity: 1932
Merit: 1273


View Profile
April 23, 2023, 01:46:26 AM
 #8

It may not be an address but it's a contract address so I think that it's still inside of this type of attack which is the address poisoning.

The contract does indeed use a vanity address as the smart contract address. But I don't understand what is their purpose to execute the scheme with the smart contract address, one plausible scenario is they expect the user to wrongly enter the intended smart contract token address, although I'm not sure how effective it is.

i've just heard about it just now, fake coins with their uncanny resemblance with the original contract address, i'd say nowadays, if i want to add token i'd just go to coinmarketcap and add it from there, since they provides button for it, more convenient and definitely hardly gonna be scammed by these fake coins.

I'd expect there might be also a clone/similar token name on CMC that might deceive the user. Verifying the smart contract address besides only from one source, CMC, should be also a priority.
hd49728
Legendary
*
Offline Offline

Activity: 2086
Merit: 1029



View Profile WWW
April 23, 2023, 03:21:47 AM
 #9

Original Contract Address (from Coinmarketcap: https://coinmarketcap.com/currencies/cryptogpt/): 0x153c0c947177e631e3dfc594ba28750d3a921fb5  https://bscscan.com/address/0x153c0c947177e631e3dfc594ba28750d3a921fb5

Fake Contract Address (Fake token sent to my wallet): 0x513C285CD76884acC377a63DC63A4e83D7D21fb5  https://bscscan.com/address/0x513c285cd76884acc377a63dc63a4e83d7d21fb5

On comparing the two:  you notice the last five digits of the two addresses are the same. There is also some similarity on the four digits after the 0x at the beginning of the addresses.  Also there is a ‘77’ somewhere between the addresses. The striking resemblance marvelled me and I decided to share this experience to alert both newbies and experienced. Interacting with a malicious token may lead to loss of tokens in your wallet. Please share your comments. Perhaps some of you already have such experience?
It is your money and if you are lazy and can not spend few seconds to fully check a smart contract address, you are deserved to lose your money.

In addition, you can check those contract address with coinmarketcap, coingecko, dex screener, dextools, dex guru.
to see their trading volume and liquidity pool.

Faked token will have very low trading volume and low liquidity pool. That is easy to realize if you know those checking steps.

https://www.dextools.io/app/en
https://dex.guru/token
https://dexscreener.com/

.freebitcoin.       ▄▄▄█▀▀██▄▄▄
   ▄▄██████▄▄█  █▀▀█▄▄
  ███  █▀▀███████▄▄██▀
   ▀▀▀██▄▄█  ████▀▀  ▄██
▄███▄▄  ▀▀▀▀▀▀▀  ▄▄██████
██▀▀█████▄     ▄██▀█ ▀▀██
██▄▄███▀▀██   ███▀ ▄▄  ▀█
███████▄▄███ ███▄▄ ▀▀▄  █
██▀▀████████ █████  █▀▄██
 █▄▄████████ █████   ███
  ▀████  ███ ████▄▄███▀
     ▀▀████   ████▀▀
BITCOIN
DICE
EVENT
BETTING
WIN A LAMBO !

.
            ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
▄▄▄▄▄██████████████████████████████████▄▄▄▄
▀██████████████████████████████████████████████▄▄▄
▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
  ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
       ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.PLAY NOW.
adaseb
Legendary
*
Offline Offline

Activity: 3752
Merit: 1710



View Profile
April 23, 2023, 04:58:51 AM
 #10

This seems similar to an address poisoning however why would you do a phish smart contract exactly ? What would you get out of it? From what I understand you can’t withdraw from a smart contract so what is the point exactly?

With regular addresses they are hoping you only look at the first few and last few characters and copy and paste the wrong address and send to them. However no idea why they would use a smart contract address.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Similificator
Sr. Member
****
Offline Offline

Activity: 882
Merit: 403


View Profile
April 23, 2023, 07:06:47 AM
 #11

It is quite alarming to see how hard working these scammers are in finding new ways just to scam others when they can just put these efforts in other things and be more productive earning in the right way. If you think about it, isn't it such a waste of knowledge and talent?

Anyway, I never knew that you can now generate addresses that are similar to other addresses. I used to think that addresses being generated per wallet are completely random.  And depending on how the contract was coded/created, this may be just a prank and also a study to record data on how effective it would be to use as phishing and stealing crypto online. Anyway, seems like the crypto people now has to be more careful and give extra effort when sending funds from one wallet to another.
@sriyan
Member
**
Offline Offline

Activity: 468
Merit: 13


View Profile
April 23, 2023, 07:19:37 AM
 #12

I saw a token in my wallet which I suspected could be a fake one. On visiting Coinmarketcap to check if the contract address on Coinmarketcap is the same as the one in my wallet, I noticed there was a difference. But that was not the problem, what bothered me most was the striking resemblance of the two contract addresses. There is some noticeable frightening resemblance:

Token Name: CryptoGPT
Blockchain: Binance Smart Chain

Original Contract Address (from Coinmarketcap: https://coinmarketcap.com/currencies/cryptogpt/): 0x153c0c947177e631e3dfc594ba28750d3a921fb5  https://bscscan.com/address/0x153c0c947177e631e3dfc594ba28750d3a921fb5

Fake Contract Address (Fake token sent to my wallet): 0x513C285CD76884acC377a63DC63A4e83D7D21fb5  https://bscscan.com/address/0x513c285cd76884acc377a63dc63a4e83d7d21fb5

On comparing the two:  you notice the last five digits of the two addresses are the same. There is also some similarity on the four digits after the 0x at the beginning of the addresses.  Also there is a ‘77’ somewhere between the addresses. The striking resemblance marvelled me and I decided to share this experience to alert both newbies and experienced. Interacting with a malicious token may lead to loss of tokens in your wallet. Please share your comments. Perhaps some of you already have such experience?


Also, you have to check the transaction history of the token. Because anyone can create a fake token and list it in Coinmartketcap or Coingecko.
crwth
Copper Member
Legendary
*
Offline Offline

Activity: 2758
Merit: 1251


Try Gunbot for a month go to -> https://gunbot.ph


View Profile WWW
April 23, 2023, 07:23:46 AM
 #13

I didn't know that that was the strategy now. The scammers are adapting and making sure that they catch some unknowledgeable people that can fall into the trap that they have set.

I'm curious as to how they did it to be that similar. Isn't it something hard to do?

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
someone703
Full Member
***
Offline Offline

Activity: 943
Merit: 101


View Profile
April 23, 2023, 08:03:17 AM
 #14

This sounds quite new to me as this is also my first time hearing about contracts being quite similar, I don't understand how they are about them. However, it is not too much of a concern for me, as I have a habit of always checking everything before proceeding to accept a transaction, but it should also be warned to many people because if it is just a glance, many people will also it's the same address.

rahulzx
Jr. Member
*
Offline Offline

Activity: 164
Merit: 2


View Profile
April 23, 2023, 11:20:59 AM
 #15


Also, you have to check the transaction history of the token. Because anyone can create a fake token and list it in Coinmartketcap or Coingecko.

there may be filtering and regulations when listing the coin in those sites. So how did they launch fake coins and scamming people on that trusted reputed sites?
 
sunsilk
Hero Member
*****
Offline Offline

Activity: 2912
Merit: 620



View Profile
April 23, 2023, 08:30:51 PM
 #16

It may not be an address but it's a contract address so I think that it's still inside of this type of attack which is the address poisoning.

The contract does indeed use a vanity address as the smart contract address. But I don't understand what is their purpose to execute the scheme with the smart contract address, one plausible scenario is they expect the user to wrongly enter the intended smart contract token address, although I'm not sure how effective it is.
That's more likely the reason why they do that.

I guess everything that's related to attack means to fool the users and think that they're on the right contract address and this gives the benefit to the developer of it that has only one intention.

And that's to trick people, that's why those people that are into so much stuff in the altcoins market are the ones prone to this attack.

Captain Corporate
Hero Member
*****
Offline Offline

Activity: 1974
Merit: 575



View Profile WWW
April 23, 2023, 08:37:06 PM
 #17

This is an old tactic, is not really a new one. People do this because there is actually money to be made from this, if you check some of the bigger ones of this attack, there are people who got away with millions of dollars from this. Which is why its such an important thing, it really does make it a lot more worse for many people. Hence, the best thing in this case would be making sure that we end up with a proper security of our own. Your mind is your own best security, obviously tools and software and better protected websites are all great, but when it comes down to security, your mind is the best one. How? Because if you end up protecting yourself from these silly attacks and fakes, then you would be able to do a lot better. Most people just rely on tools for that, and that is why they end up losing a lot of money as well. I don't, I know all the latest scams and hacks, so I try to stay away from them all.

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
bitbollo
Legendary
*
Offline Offline

Activity: 3248
Merit: 3500


Nec Recisa Recedit


View Profile
April 23, 2023, 09:01:28 PM
 #18

The contract address is really similar and could easily mislead ... literally anyone!
Well a free-token in a wallet it's always some "suspicious" at least to me Tongue

This is really an interesting report and thanks for sharing it. Yes is not a new one tactic for scam, but is not common.

I suggest OP to post a report in Scam Accusation board, other people could become aware of it https://bitcointalk.org/index.php?board=83.0

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
fvb
Member
**
Offline Offline

Activity: 1470
Merit: 13


View Profile
April 23, 2023, 09:05:42 PM
 #19

Yes, the resemblance is indeed very similar. But personally, I always check such moments on sites specially created for this. I also try not to be lazy and put contracts for comparison one under the other and thus you can immediately see the difference. Even if it differs by one number or letter

⬣⬣⬣⬣⬣⬣⬣⬣    ⬣⬣⬣⬣    ⬣⬣    ⬣     C O M B O     ⬣    ⬣⬣    ⬣⬣⬣⬣    ⬣⬣⬣⬣⬣⬣⬣⬣
A leading provider of scaling solutions for Web3 game developers
|      Twitter      |    Telegram    |     Discord     |     Medium     |      GitHub      |
goaldigger
Sr. Member
****
Offline Offline

Activity: 2352
Merit: 356



View Profile
April 23, 2023, 09:09:03 PM
 #20

Is both contract address listed on Coinmarketcap? I wonder if CMC did a cross checking on this one before making it available in the public, this is also why I always ask the developer for the real address details to avoid problems. Be careful, there’s also a lot of fake tokens on many wallet which scammers are sending it to fool the owner of that wallet because if you do transactions with those fake tokens, your wallet will surely be in trouble.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?█▀▀▀











█▄▄▄
.
PLAY NOW
▀▀▀█











▄▄▄█
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!