[ad_1]
Bitcoin self-guarding (BTC) provider Casa warns of physical attacks on Bitcoin holders as they publish a blog post outlining details of a recent incident.
Their customers’ bad experience on Tinder combines elements of social engineering, sim trading, and a more old-fashioned drug and theft attack.
One of our clients was targeted on a dating app and ended up being drugged in an attempt to clear his crypto accounts. This is the story of the attack and our post mortem analysis of what went wrong and what went right. https://t.co/co3XacQGQp
– Jameson Lopp (@lopp) July 8, 2021
Devil’s breath
According to the story, an alleged Bitcoin holder and trader found his date through the Tinder mobile app, where he contacted a woman who claimed to be a cryptocurrency trader.
When the two met in person, he noticed that her photos were slightly different from her appearance in person, but he didn’t think much about it.
The victim recalls that she said her parents bought her 1 bitcoin for $ 30,000, but otherwise she didn’t talk about crypto for the rest of their time together.
During their date, two decided to return to the man’s apartment, and somewhere in between, the woman mixed her drink with scopolamine, also called Devil’s Breath, or a benzodiazepine, drugs known to cause memory loss and inhibitions. depreciation.
According to the message, he believes the woman took his phone and asked him to show him how to unlock it and find his passwords.
The man woke up the next day and his phone was gone, although all of his other personal belongings, including a wallet with cash, debit cards and ID, were still there.
Saved by the multisig
The victim immediately verified various accounts from his laptop and found that purchases on his bank account had been attempted at several exchanges and that Bitcoin withdrawals had been attempted from other custodians, while the attacker was trying to undress him, figuratively speaking.
Many of our customers will also have password managers and 2FA on their phones. In this customer’s case, even though he was not using SMS 2FA, he was using TOTP 2FA through a Google authenticator app on the phone. Since the attacker forced him to unlock his phone’s unlock code, they had access to 2FA for all of his accounts, the post said as the author drew a parallel with the so-called sim swap attacks. .
He ultimately only lost a small amount of Bitcoin because one of his exchange accounts was compromised, while the largest percentage of his total holdings was saved through the multisig setup he had.
The attacker only had one of the victim’s five keys, which allowed him to block other requested purchases and withdrawals by contacting custodians and filing a compromise.
Get an edge in the crypto-asset market
Access more crypto information and background in each article as a paid member of CryptoSlate Edge.
Chain analysis
Price snapshots
More context
Sign up now for $ 19 / month Check out all the benefitsPosted in: Bitcoin, Crime
Like what you see? Subscribe for updates.
|
Sources 2/ https://cryptoslate.com/bitcoin-catfishing-drugs-how-a-tinder-match-almost-led-to-crypto-robbery/ The mention sources can contact us to remove/changing this article |
[ad_2]