Upgraded Fake Wallet Scams: Beware of Multi-Signature ‘Fish Farming’
Author: Bitrace source: https://mp.weixin.qq.com/s/Y0nMzraWgWynF3jicNb0sA Recently, several victims have contacted us for help through Bitrace, reporting that they were unable to use their cryptocurrency wallet app properly. Specifically, they were experiencing errors when trying to transfer funds and were unable to call other on-chain contracts. However, deposits were working normally, and their assets were eventually transferred out of their accounts all at once. Investigation revealed that the victims had downloaded a fake wallet app, which led to their private keys being leaked and their account permissions being changed by thieves. The Bitrace team has been closely monitoring the trend of crypto theft crimes. Compared to earlier simple virus-style installation package attacks, this type of multi-signature scam has been optimized in the “fish farming” process. This article will provide an introduction to this technique. What is Multi-Signature “Multi-Signature” (also known as “Multi-Sig”) is a widely used security mechanism in blockchain technology. Transactions can only be completed when a certain number of users with private key permission agree to sign the transaction. Multi-Sig helps prevent malicious attacks and fraudulent behavior, improves the security and availability of encrypted assets, and solves the potential trust issues in cooperative asset management. Therefore, it has been widely adopted. Using Multi-Sig also means that if a user’s private key is hacked or stolen, the hacker cannot transfer the assets successfully, as they do not have access to the private keys of the other users with Multi-Sig permission. However, if the highest level of Multi-Sig permission is stolen, it becomes a dictatorship, and hackers can disguise themselves as a peer and wait in the dark for the funds to accumulate before striking. The implementation of Multi-Sig fraud In traditional fake wallet scams, hackers obtain the private key of an address through a fake wallet and share the address operation permission with the user. Both parties can transfer all funds out of the address. In this type of scam, hackers have two options: either steal the assets immediately, leaving the user with a zero balance, or wait for the user to accumulate more assets, which is called “fishing” by criminals. In a multi-signature scam, the user loses their account permission, and during this period, the address remains in a state of “in-only” operation. In theory, as long as the user does not operate a transfer out, they will never realize that they are on the edge of being stolen. For hackers, they do not have to worry about when the “duck” in their hand will fly away, and naturally, they will not alert the user. They only need to wait for the user to continue depositing funds into the address. Clearly, the multi-signature scam is an upgraded iteration of the fake wallet scam, and the method is more concealed, with a higher success rate for illegally obtaining assets. The Industrialization of Multi-Signature Scams Based on the information provided by a victim, the Bitrace team has found that as of the writing of this article, the scam gang has stolen the assets of 29 people through this method, totaling about 215,600 USDT. Bitrace’s intelligence team also found that many cryptocurrency users have fallen victim to this type of multi-signature scam on various social media platforms, indicating that this black industry is gradually becoming industrialized. This is not good news for the vast majority of cryptocurrency users. How to prevent multi-signature scams ● Refuse to install or use any crypto wallet other than those provided by the official website, including those downloaded from the application store, search engine results, or installation files sent by friends. ● Confirm the accuracy of the official website through multiple cross-checks, and do not blindly trust the website authentication of search engines. ● Refuse to use wallets to make crypto payments to websites or services with unknown sources, including gambling, pornography, and other online services. ● Separate wallets for large amounts of funds, and only use daily wallets to interact with other contracts. ● Do not trust internet friends who actively teach crypto investment. Conclusion Bitrace suggests that major wallet provider enable client detection of changes in multi-signature permissions and display the message “Your wallet operation permissions have been changed” as soon as possible. If users can be identified and informed in a timely manner, it will effectively prevent greater losses from occurring. For example, the Tron official browser displays a clear reminder when a user’s address permissions change. The iterative evolution of on-chain fraudulent activities is accelerating, and even for the same type of fraud, the latest implementation path and hiding method are more secretive than before. With the growth of cryptocurrency adopters, more widespread losses are inevitable. If you are unfortunate enough to suffer a loss, you can contact Bitrace for help at any time. Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
Global Crypto Mining News (Mar 27 to Apr 2)
Monday, April 3, 2023
1. Bitcoin miners earned more than $718 million in March, a new high since May 2022. In addition, Bitcoin hashrate has risen about 20% since the beginning of the month. 2. Securities and Exchange
Asia's weekly TOP10 crypto news (Mar 27 to Apr 2)
Sunday, April 2, 2023
Author:Lily Editor:Colin Wu 1. Hong Kong's weekly summary 1.1 Chinese banks court crypto firms in Hong Kong after mainland ban link The Hong Kong arms of Bank of Communications Co., Bank of China
VC monthly report, The number and amount of financing have dropped significantly in Mar
Sunday, April 2, 2023
Author: WuBlockchain According to RootData's statistics, there were a total of 84 publicly announced investment projects in March in the cryptocurrency venture capital (VC) field, representing a
Weekly project updates: BNBChain proposes lower fees, Sei Foundation, THORChain halted globally, etc
Saturday, April 1, 2023
1. ETH's weekly summary a. Ethereum Foundation announces Shapella network upgrade activation date link On March 28, the Ethereum Foundation officially released an announcement: The Shapella network
WuBlockchain Weekly:Binance sued by CFTC、Gucci teams up with Yuga Labs、SBF charged with bribery and Top10 News
Friday, March 31, 2023
Top10 News 1. Yuga Labs' weekly summary a. Gucci teams up with company behind Bored Ape Yacht Club link On March 27, Luxury brand Gucci has announced a partnership with Yuga Labs, and Gucci will
You Might Also Like
Trump could put billions into US Bitcoin reserve without Congress approval
Friday, November 15, 2024
David Bailey suggests over $10 billion could be put into a reserve before needing to get Congress to approve funding. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
NFT & Gaming Weekly - 📈 OpenSea is set to undergo a revamp; McDonald's announced a collaboration with NFT brand D…
Friday, November 15, 2024
OpenSea is set to undergo a significant revamp. McDonald's announced a collaboration with NFT brand Doodles. Lamborghini launches Fast ForWorld Revuelto NFT mint. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
WuBlockchain Weekly: Bitcoin Market Cap Surpasses Silver, U.S. Advances Initiative to Include Bitcoin in Strategic…
Friday, November 15, 2024
As Bitcoin approaches $90000, its market capitalization has reached $1.751 trillion, surpassing silver's $1.734 trillion, placing it eighth among global assets by market value. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
DeFi & L1L2 Weekly — 📈 Solana outshines Ethereum with 123 million active addresses in October; Ethereum launches …
Friday, November 15, 2024
Solana outshines Ethereum with 123 million active addresses in October. Ethereum launches Mekong testnet to preview Pectra upgrade. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
DeFi & L1L2 Weekly — 📈 Solana outshines Ethereum with 123 million active addresses in October; Ethereum launches …
Friday, November 15, 2024
Solana outshines Ethereum with 123 million active addresses in October. Ethereum launches Mekong testnet to preview Pectra upgrade. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Interview with Qiao Wang: How to invest in PUMPFUN to get at least 1,000 times? Alliance's ultra-early stage inves…
Friday, November 15, 2024
In this interview, Qiao Wang, Alliance's co-founder and well-known crypto industry investor, shared his investment strategy in the Crypto field. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Bitcoin breaks yet another all-time high, now testing $92,000
Friday, November 15, 2024
Global digital market cap reaches $3.02 trillion as Bitcoin dominates, up 117% YTD. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Welcome to the next era of Flipside
Friday, November 15, 2024
It's an upgrade we've all been waiting for. We've got a fresh look to reflect our business. Check it out now and explore the new look The instruments to measure blockchain growth have
Interview with Binance Chief Compliance Officer, Noah Perlman
Friday, November 15, 2024
Previously Noah Perlman worked for the cryptocurrency exchange Gemini as the Chief Compliance Officer and then as the Chief Operating Officer. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Reminder: Donald Trump Secures Victory As Ripple CEO Demands SEC Chair Be Replaced
Friday, November 15, 2024
We bring you the top stories in crypto every week! Stories like... Monday Nov 11, 2024 Sign Up Your Weekly Update On All Things Crypto TL;DR Donald Trump Secures Victory As Ripple CEO Demands SEC Chair