Bitcoin Forum
May 06, 2024, 03:26:17 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: How is sending bitcoin through a QR-code safe ?  (Read 231 times)
Becassine (OP)
Hero Member
*****
Offline Offline

Activity: 1820
Merit: 776


I love BitBox02 (Shiftcrypto) and Zeus (Cryptotag)


View Profile WWW
July 14, 2023, 07:19:21 PM
Merited by lovesmayfamilis (1)
 #1

I was reading the very interesting post of LoyceV about this clipboard virus (https://bitcointalk.org/index.php?topic=5190776.0)

Quote
How it works
1. You select a Bitcoin address, and press CTRL-C.
2. The malware changes the address to an address owned by the hacker/scammer.
3. You press CTRL-V and lose any funds you send.
Even if you check part of the pasted Bitcoin address, chances are the first few characters are the same, and you still won't notice the address was changed.

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
1714965977
Hero Member
*
Offline Offline

Posts: 1714965977

View Profile Personal Message (Offline)

Ignore
1714965977
Reply with quote  #2

1714965977
Report to moderator
1714965977
Hero Member
*
Offline Offline

Posts: 1714965977

View Profile Personal Message (Offline)

Ignore
1714965977
Reply with quote  #2

1714965977
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714965977
Hero Member
*
Offline Offline

Posts: 1714965977

View Profile Personal Message (Offline)

Ignore
1714965977
Reply with quote  #2

1714965977
Report to moderator
1714965977
Hero Member
*
Offline Offline

Posts: 1714965977

View Profile Personal Message (Offline)

Ignore
1714965977
Reply with quote  #2

1714965977
Report to moderator
Nwada001
Hero Member
*****
Offline Offline

Activity: 574
Merit: 627



View Profile
July 14, 2023, 07:23:01 PM
 #2

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?
I don't think that will ever be possible. The reason is this: for the clipboard virus, the hacker needs the victim to copy the original address, which he could change to his own. That's how the malware is being programmed.

But for QR codes, what you need is to use your device, scan through the QR code, and it will automatically be imputed to wherever you are sending from. So for the hacker to be able to change the QR Code scanner, they will need more extra work, but for the main time, address scanning is still the best option. And one should always cross-check his address before authorizing a transaction.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Charles-Tim
Legendary
*
Offline Offline

Activity: 1540
Merit: 4845



View Profile
July 14, 2023, 07:51:33 PM
 #3

If you are the receiver and you click on receive and the receive address is brought up as QR code, you are safe if the sender scan the QR code directly like that. But if you copy the address and want to send, the address can be changed by clipboard malware to a hackers address. So QR code is safe if you are the receiver and the sender scan the QR code directly from your device.

If you are the sender and you scan the QR code directly, it is also safe. You do not copy anything to the clipboard, not to talk of any data modified.

The malware gain access to the clipboard of a device and modifies data that is copied and change to attackers data. But with QR code, no data/address copied to the clipboard.

QR code used in this way is very safe. QR code is the safest for making bitcoin transaction, not only because data is not modified, but also because no way for malware to be transmitted.

But always check and double check the address before sending.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
FatFork
Legendary
*
Offline Offline

Activity: 1596
Merit: 2588


Top Crypto Casino


View Profile WWW
July 14, 2023, 07:58:32 PM
 #4

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?

To my knowledge, there hasn't been a single documented case of this specific type of attack. When you scan a QR code with your software wallet, the payment information is directly fed into your wallet without going through a clipboard buffer. This eliminates the possibility of malware intercepting and modifying the information. Nevertheless, it's still a good idea to double-check that the payment details actually match what you see on the screen next to the QR code, just to be safe.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
July 14, 2023, 08:05:57 PM
 #5

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?
They started putting everything in QR codes, and I don't think this is always a good idea, but it can certainly be used for sending and receiving Bitcoin, or importing and exporting seed phrases.  
One of the problems I have with QR codes is bunch of different encoding that can be closed sourced, and it often happens one QR code is not compatible with some devices and smartphones.
It's trivial for scammers to change and modify QR codes, but using airgapped wallets (Passport, Keystone, Coldcard, Krux SeedSigner, etc) reduces that risk a lot.
Using QR codes with hot wallets can be problematic because it's much harder to verify if something is modified or not, so it's good to confirm address additioanlly.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Yawa2020
Member
**
Offline Offline

Activity: 700
Merit: 30


View Profile
July 14, 2023, 08:12:11 PM
 #6

But for QR codes, what you need is to use your device, scan through the QR code, and it will automatically be imputed to wherever you are sending from. So for the hacker to be able to change the QR Code scanner, they will need more extra work, but for the main time, address scanning is still the best option. And one should always cross-check his address before authorizing a transaction.
It might be possible by hacking the person's phone camera but this will be very difficult and will require a high professional tools which might not worth the stress and time. Scanning QR code seems secure for now but the problem with scanning is that distance transaction can not be carried out using scanning method.
un_rank
Hero Member
*****
Offline Offline

Activity: 714
Merit: 684


- Jay -


View Profile WWW
July 14, 2023, 08:22:19 PM
 #7

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?
To the best of my software knowledge (which is not much), it is not possible yet for a QR code to be changed through a malware on the device it is being scanned on. If that is possible, then the phone need to have been so corrupted that the hackers will be able to steal whatever is on it without going through all that.

You will be extra secure if you double check every letter in the (scanned or copied) address before sending.

- Jay -

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Nwada001
Hero Member
*****
Offline Offline

Activity: 574
Merit: 627



View Profile
July 14, 2023, 09:29:31 PM
 #8

It might be possible by hacking the person's phone camera but this will be very difficult and will require a high professional tools which might not worth the stress and time.

There is nothing impossible for these hackers, and nothing is expensive for them; they are already professionals in that field, looking for victims. If they see a tool that could help them hack through a camera (if there isn't any already), it will cost them little compared to what they will use that tool for, and as such, they will pay anything to get it. You spend money, combined with skill, to get things done.

Quote
Scanning QR code seems secure for now but the problem with scanning is that distance transaction can not be carried out using scanning method.
 
How do you mean that if I send a coin to the Bitcoin address of someone, do I need the person to be in the same place as me? No. The same thing is applicable with the QR code. If you are not sending it to your own wallet, where you will directly scan it from the wallet provider, all you have to do is ask the receiver to send you the QR code, and you can scan it from wherever you are.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Faisal2202
Sr. Member
****
Offline Offline

Activity: 1204
Merit: 466


#SWGT CERTIK Audited


View Profile WWW
July 14, 2023, 10:00:04 PM
 #9

You pointed out a very good question. To understand the answer we must know how QR code works. We do know that each person has it's own unique QR code which is generated each time somewhere like in some wallets or exchanges such codes are unique everytime. Coming back to the point.

In QR code scams, a scammer could replicate ke exchange his own QR code with your QR code so when an other person intends to send you money by scanning that QR code then the money will be sent to him not you. And k think detecting such activities are difficult in QR code because in wallet address we can compare the characters but in QR code it is a big difficult to compare the patterns which might look same but the numbers hidden in it might contain different wallet address and that can't be seen by naked eyes of at least without decryption of it.

Stalker22
Legendary
*
Offline Offline

Activity: 1498
Merit: 1358



View Profile
July 14, 2023, 10:04:25 PM
 #10

~
all you have to do is ask the receiver to send you the QR code, and you can scan it from wherever you are.

I think that is exactly what he was implying. If the recipient sends the QR code remotely, for example via email or chat messages, then there is a risk that a potential attacker can intercept that communication and modify the QR code. Paying with a QR code is only safe if you are sure of the authenticity and integrity of the QR code you are scanning.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Adbitco
Hero Member
*****
Offline Offline

Activity: 1428
Merit: 653


Always Act Smart and Play Safe With Your Funds


View Profile WWW
July 14, 2023, 10:19:28 PM
 #11

QR code to me is the safest way to scan and send payment since there is no copy and paste to send payment only scan and pay without copying address. QR code is already being designed with rightful address so there's no way to be attacked by any scammer or hacker. Although I can not say with all assurance that it can't be hacked, nowadays things are really happening because scammer are exploring different ways to phish people's funds.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
kamvreto
Legendary
*
Offline Offline

Activity: 1960
Merit: 1157


View Profile
July 14, 2023, 10:48:51 PM
 #12

~
all you have to do is ask the receiver to send you the QR code, and you can scan it from wherever you are.

I think that is exactly what he was implying. If the recipient sends the QR code remotely, for example via email or chat messages, then there is a risk that a potential attacker can intercept that communication and modify the QR code. Paying with a QR code is only safe if you are sure of the authenticity and integrity of the QR code you are scanning.

It may have happened to me, fraudulent schemes are currently growing and becoming more sophisticated. Before making a payment with a QR code, we can see the payment information that appears before selecting the send button. here will be shown the intended merchant information and input the nominal to be sent. Sometimes there are people who replace the physical QR code in a store with their QR code (fraudsters) with almost the same name. That 's why you have to be careful and confirm before sending.
Nwada001
Hero Member
*****
Offline Offline

Activity: 574
Merit: 627



View Profile
July 14, 2023, 10:49:50 PM
 #13

~
all you have to do is ask the receiver to send you the QR code, and you can scan it from wherever you are.

I think that is exactly what he was implying. If the recipient sends the QR code remotely, for example via email or chat messages, then there is a risk that a potential attacker can intercept that communication and modify the QR code. Paying with a QR code is only safe if you are sure of the authenticity and integrity of the QR code you are scanning.

That's why it will always be advisable to me to request that the QR code be attached with the wallet below it for authentication purposes, and when that is also being done to take some extra measures for security reasons, we should always ask the sender to confirm if the address received and gotten from the QR code is the same as what was sent.

It may have happened to me, fraudulent schemes are currently growing and becoming more sophisticated. Before making a payment with a QR code, we can see the payment information that appears before selecting the send button. here will be shown the intended merchant information and input the nominal to be sent. Sometimes there are people who replace the physical QR code in a store with their QR code (fraudsters) with almost the same name. That 's why you have to be careful and confirm before sending.

Exactly why I said this 👇👇
And one should always cross-check his address before authorizing a transaction.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Cryptomultiplier
Full Member
***
Offline Offline

Activity: 770
Merit: 180


Eloncoin.org - Mars, here we come!


View Profile WWW
July 14, 2023, 11:26:19 PM
 #14

If the exchange shows options to send or receive crypto via QR code, it means it is a possible choice for transactions incase the other fails or you fail to have the requirements for it to approve a transaction.

QR code has been existing for some time now and it is rare to see most devices these days without its feature. One interesting thing is the way exchanges and some apps has included it as authentication option for login into an account, sharing files, data, contacts too. The uniqueness of the Hash is what also sets it apart. Each individual to its own hash.
Although the fear of having malicious bugs or phishing URL embedded within once scanned is accurate, to ensure a second or maybe a third confirmation of the details displayed is necessary to avoid falling victim to hackers or scammers.

hatshepsut93
Legendary
*
Offline Offline

Activity: 2968
Merit: 2145



View Profile
July 14, 2023, 11:53:17 PM
Merited by LoyceV (4)
 #15

First of all, the QR code itself can be replaced without hacking. For example, if it's a sticker, someone can put their own sticker on top of the original one. If it's a photo posted on social media, someone can edit it in Photoshop to put their address. You get the idea.

But on software level, this task is not as trivial as replacing a clipboard, but still could be achieved, at least theoretically. The QR-code scanner app could be exploited to replace Bitcoin adresses with hacker's address, if it has such a sophisticated vulnerability.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
ImThour
Copper Member
Legendary
*
Offline Offline

Activity: 1400
Merit: 1512


Bitcoin Bottom was at $15.4k


View Profile
July 15, 2023, 07:55:15 AM
 #16

It's difficult to replace a QR Code from a website if it's in SVG shapes like <rect> and if it's just an image, it can be easily replaced just like the Bitcoin Wallet Address.
If you don't understand the difference, I will explain it a bit more.

1. QR Code as a combination of Rectangles:


In this, you can see each rectangle has to be replaced to form a new QR.

2. QR Code as an Image: That will be just a QR code in a .png or .jpeg format and one line of code can replace it.

Hope it's helpful.
LoyceV
Legendary
*
Offline Offline

Activity: 3304
Merit: 16600


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 15, 2023, 01:51:33 PM
 #17

With QR-codes, there's a much simpler attack vector than changing the QR-code: the malware will be in the software used to create or read the code.
Both malicious QR code generators and readers exist.

satscraper
Hero Member
*****
Offline Offline

Activity: 728
Merit: 1373


Cashback 15%


View Profile
July 15, 2023, 03:01:35 PM
 #18


i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?

The short answer is YES,it is technically possible for malware to manipulate QR codes.

That is why it is very important to check the transaction's details ( such as destination address, change address, amount being sent) shown on the screen of airgapped hardware wallet if what is meant  in your question was HW interaction with bitcoin light client.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
pawanjain
Hero Member
*****
Offline Offline

Activity: 2674
Merit: 713


Nothing lasts forever


View Profile
July 15, 2023, 03:19:45 PM
 #19

I was reading the very interesting post of LoyceV about this clipboard virus (https://bitcointalk.org/index.php?topic=5190776.0)

Quote
How it works
1. You select a Bitcoin address, and press CTRL-C.
2. The malware changes the address to an address owned by the hacker/scammer.
3. You press CTRL-V and lose any funds you send.
Even if you check part of the pasted Bitcoin address, chances are the first few characters are the same, and you still won't notice the address was changed.

i was wondering if it's possible to change a QR-code the same way that the victim sends the btc to the scammer address ?

Clipboard virus won't be able to do anything when we are using QR codes.
To apply the same technique for a QR the hacker will have to inject malicious code in the app that the user is using to scan the QR code.
That is something very hard to achieve because of security protocols on devices these days.
So we are good when using QR codes.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
tabas
Hero Member
*****
Offline Offline

Activity: 2996
Merit: 734


Top Crypto Casino


View Profile
July 15, 2023, 03:21:44 PM
 #20

Possible, like if you're in a store and a con gets in and tried to lose the attention of the staff replacing the QR code that's dedicated for direct store payments. I've seen a video dramatization of it. So, it's like a group of people, either a woman and man but also can be done by a single person. The woman attracts the staff and makes a conversation not knowingly, there's the intention of replacing the QR code with the one that they've made. So, this is the scenario in physical places. What I think for online transactions, it's the same scam that they're trying to imitate someone and just simply sends their own QR code to misled customers. And as said by satcraper, through malware so be cautious with links and files that you guys download.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!