Bitcoin Forum
May 04, 2024, 02:36:21 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: A very strange dust attack or an attempted robbery?  (Read 266 times)
MusaMohamed
Sr. Member
****
Offline Offline

Activity: 896
Merit: 290



View Profile
September 12, 2023, 12:38:52 AM
Merited by vapourminer (2), pooya87 (2)
 #21

They move from altcoins to Bitcoin but using a same method for Address Poisoning Attacks.

Metamask: Address Poisoning scams

I see many exchanges recent years upgrade their systems to remind users to check first and last characters of address they are sending cryptocurrency to. In addition, if possible, if have time (I am surely have time because it's my money), checking all characters or some characters in the middle of address is useful to avoid Address Poisoning scams.

How to lose your Bitcoins with CTRL-C CTRL-V. Copy some characters in the middle of address and find it in a receiving address is helpful too.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBITCRYPTO
FUTURES
[
1,000x
LEVERAGE
][
.
COMPETITIVE
FEES
][
INSTANT
EXECUTION
]██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████████████████████████████████████████████████
.
TRADE NOW
.
████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
1714833381
Hero Member
*
Offline Offline

Posts: 1714833381

View Profile Personal Message (Offline)

Ignore
1714833381
Reply with quote  #2

1714833381
Report to moderator
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714833381
Hero Member
*
Offline Offline

Posts: 1714833381

View Profile Personal Message (Offline)

Ignore
1714833381
Reply with quote  #2

1714833381
Report to moderator
pooya87 (OP)
Legendary
*
Offline Offline

Activity: 3444
Merit: 10546



View Profile
September 12, 2023, 04:58:21 AM
 #22

-Using a good wallet that lets you block incoming dust transactions is a smart move.
You cannot block incoming tx's into your wallet, in other words you can't stop someone from sending you BTC's.
I believe what @albert0bsd means by "block" is to either "freeze" or "hide" these outputs either manually or automatically so that you don't see them when spending from your wallet to avoid such mistakes. For example Electrum has manual output/coin freezing option.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
un_rank
Hero Member
*****
Offline Offline

Activity: 714
Merit: 684


- Jay -


View Profile WWW
September 12, 2023, 05:10:47 AM
Merited by Z-tight (2)
 #23

I'm confused about where they get those thousands of addresses for dust attacks.

Technically, I don't know how this works further with them but I think this wasting of time since we know most people will always double-check transactions before sending or transferring to another address.
There are ways they can do that.

Most people will most of the time double check just the first and last few words, there can still be loopholes which scammers can exploit. Scammers are after the few times where we forget to double check or after those users that do not check at all.

I believe what @albert0bsd means by "block" is to either "freeze" or "hide" these outputs either manually or automatically so that you don't see them when spending from your wallet to avoid such mistakes. For example Electrum has manual output/coin freezing option.
AFAIK some wallets allow one to do this manually after they have already received the dust transaction or any type of transaction that they will not want to be mixed with their other outputs, but I do not know of any automatic way to do this, where an incoming transaction gets automatically frozen based on some preset rules, like:
- less than a certain amount of sats or,
- from a certain address.

This will be a useful but I do not know if it is available now.

- Jay -

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
September 12, 2023, 05:28:21 AM
 #24

It surely is a lot of trouble for the small chance that people will actually "copy&paste" the wrong address? In any way, since the "Clipboard" attacks, I am double checking all addresses I use, before I click on the "enter" button, because I know they try things similar to this in that hack.

It is sad that people will go so far and put in so much effort to steal people's money, when they have the skills to work for that money. I guess it is easier to steal, than making an honest living these days.  Angry

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
MusaMohamed
Sr. Member
****
Offline Offline

Activity: 896
Merit: 290



View Profile
September 12, 2023, 05:51:11 AM
Merited by Symmetrick (3), vapourminer (2)
 #25

I believe what @albert0bsd means by "block" is to either "freeze" or "hide" these outputs either manually or automatically so that you don't see them when spending from your wallet to avoid such mistakes. For example Electrum has manual output/coin freezing option.
You are right.
To freeze an address, right click on that address, choose Freeze.
To freeze an UTXO, right click on that address, choose Add to Coin control. Then on Coins tab, right click on an UTXO, choose Freeze (two options, Freeze coins; Freeze address).

Dust Attack, what it is, why it is dangerous and how to prevent falling to it
Freeze an address in Electrum
Guide to freeze address in Electrum wallet

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBITCRYPTO
FUTURES
[
1,000x
LEVERAGE
][
.
COMPETITIVE
FEES
][
INSTANT
EXECUTION
]██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████████████████████████████████████████████████
.
TRADE NOW
.
████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
NotATether
Legendary
*
Offline Offline

Activity: 1596
Merit: 6728


bitcoincleanup.com / bitmixlist.org


View Profile WWW
September 12, 2023, 06:32:53 AM
 #26

It seems that the attacker is not making any vanity bech32 addresses according to the explanation in OP, just legacy addresses.

I mean what is this guy thinking. Does he really think some random guy is going to send money to address he just got sats from? Most likely what will happen is they will just keep the sats and not send it anywhere. It's a pretty lame scam attempt that won't work at all - besides he just copied first 2 and last 4 characters.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
pooya87 (OP)
Legendary
*
Offline Offline

Activity: 3444
Merit: 10546



View Profile
September 12, 2023, 09:32:13 AM
 #27

besides he just copied first 2 and last 4 characters.
Yeah, it's the poor mans scam for sure Cheesy
The scammer probably had a slow machine that couldn't brute force more than 2 from the start and 4 checksum characters. In fact the forth letter was the first thing I noticed that helped me recognize the difference.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!