[ad_1]
Blockchain security firm CertiK has reminded the crypto community to remain vigilant against ice phishing scams, a unique type of phishing scam targeting Web3 users first identified by Microsoft earlier this year.
In a December 20 analyst report, CertiK described ice phishing scams as an attack that tricks Web3 users into signing authorizations that ultimately allow a scammer to spend their tokens.
This differs from traditional phishing attacks that attempt to gain access to confidential information such as private keys or passwords, such as the fake websites set up that claimed to help FTX investors recover lost funds during exchange.
#CertiKSkynetAlert
1/ Ice phishing is a considerable threat to the Web3 community
Instead of accessing your private key, crooks trick you into signing authorizations to spend your assets.
Describe below what to look out for and how to protect yourself!
— CertiK Alert (@CertiKAlert) December 20, 2022
A December 17 scam where 14 Bored Apes were stolen is an example of an elaborate ice phishing scam. An investor was convinced to sign a transaction request disguised as a movie deal, which ultimately allowed the scammer to sell all of the user’s monkeys to himself for a negligible amount.
The company noted that this type of scam is a significant threat only found in the Web3 world, as investors are often required to sign authorizations for the decentralized finance (DeFi) protocols they interact with, which could be easily faked.
The hacker just needs to trick a user into believing that the malicious address they are giving their approval to is legitimate. Once a user approves the permissions allowing the scammer to spend tokens, the assets are likely to be depleted.
Once a scammer gets approval, they can transfer assets to any address they want.
An example of how an ice phishing attack on Etherscan works. Source: Certik
To protect against ice phishing, CertiK has recommended that investors revoke permissions for addresses they don’t recognize on blockchain mining sites such as Etherscan, using a token approval.
Related: Co-Founder of $4 Billion OneCoin Scam Pleads Guilty, Faces 60 Years in Prison
Additionally, addresses that users plan to interact with should be searched on these blockchain explorers for suspicious activity. In its analysis, CertiK points to an address that was funded by Tornado Cash withdrawals as an example of suspicious activity.
CertiK also suggested that users should only interact with official sites they are able to verify, and be especially wary of social media sites like Twitter, highlighting a fake Twitter Optimism account as an example.
Fake Twitter account Optimism. Source: Certik
The company also advised users to take a few minutes to verify a trusted site such as CoinMarketCap or Coingecko, users could have seen that the linked URL was not a legitimate site and should be avoided.
Tech giant Microsoft was first to highlight the practice in a February 16 blog post, saying at the time that while credential phishing is very prevalent in the Web2 world, the ice phishing gives individual scammers the opportunity to steal part of the crypto industry. while maintaining almost complete anonymity.
They recommended that Web3 projects and wallet providers increase the security of their services at the software level to prevent the burden of avoiding ice phishing attacks from being placed solely on the end user.
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMiYWh0dHBzOi8vY29pbnRlbGVncmFwaC5jb20vbmV3cy9ob3ctdG8tYXZvaWQtZ2V0dGluZy1ob29rZWQtYnktY3J5cHRvLWljZS1waGlzaGluZy1zY2FtbWVycy1jZXJ0aWvSAQA?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]