Phishing Attacks Impersonating Popular Metaverse Projects Targeting MetaMask Users

Phishing Attacks Impersonating Popular Metaverse Projects Targeting MetaMask Users
фото показано с : zycrypto.com

2022-3-2 15:56

The Guardio research team has discovered a broad and deep network of sophisticated phishing attacks chaining some of the sphere’s leading brands and targeted explicitly at MetaMask users exploring the developing metaverse space.

Hackers Target Metaverse Users using MetaMask

Guardio, a cyber-security startup dedicated to keeping users’ identity and information secure, revealed in their recent blog post how hackers have already cumulatively stolen hundreds of thousands of dollars from unsuspecting users, most of whom were in the sprawling NFTs and metaverse. 

Malicious actors could pull off this attack because of the high number of users reliant on MetaMask. The multi-browser plugin wallet is one of the most widely used hot wallets allowing users to connect to dApps and explore the base layer. 

As of early March 2022, there were more than 10 million downloads on the Chrome browser wallet alone. A ConsenSys finding revealed that there are, on average, 10 million monthly active users. However, considering how fast NFT solutions are adopted and the promise of the metaverse, it is expected that more users would download and install MetaMask as their choice browser wallet. Moreover, attackers reckon that metaverse users are tech-savvy, have been in the crypto space, and are most likely crypto holders.

Phishing Attacks on Crypto Wallets Are on The Rise

To pull off their heist, the research team discovered that hackers cloned famous websites of leading NFT and metaverse brands like Decentraland, OpenSea, and The Sandbox, before executing their phishing campaigns. 

Their attacks were successful because these sites often have a high level of functionality with complicated flows of connections requiring connecting MetaMask holders to manually approve transactions before posting them on-chain. By cloning the original website using age-old techniques like IDN attacks, some users were caught offside and gave their MetaMask private keys (Seed Phrase), thus allowing the hackers to access their wallets.

Hundreds of these cloned “low flying” websites were also ranked on the first page because hackers poured resources and used malvertising techniques, ranking them on the first page of Google search results. Some of them even managed to run some targeted Google Ads campaigns around specific Keywords:

Blockchain Cuts Both Ways

Even though crypto and blockchain solutions have real-world uses and have been massively disruptive, security remains a challenge as evidenced above. The situation is exacerbated by distributed ledger technology’s architecture which prioritizes power decentralization over everything else. As power is decentralized to ordinary end users—many of whom may not have the know-how and even basic techniques of safeguarding assets in an immutable public blockchain, billions of assets have been permanently lost or stolen. 

Notably, hackers have been historically wreaking havoc on crypto infrastructure, stealing assets. In recent years and as decentralized facilitators take charge, hackers have their guns trained on end-users in, among many fields, metaverse and NFTs. In response, users are urged to keep their private keys private and always practice due diligence to prevent losing assets. This means double-checking URLs before approving transactions through MetaMask and using up-to-date antivirus programs as a primary shield.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Metaverse ETP (ETP) на Currencies.ru

$ 0.0091367 (+0.27%)
Объем 24H $14.09k
Изменеия 24h: 1.98 %, 7d: -2.72 %
Cегодня L: $0.0091367 - H: $0.0091367
Капитализация $0 Rank 4031
Цена в час новости $ 0.1366 (-93.31%)

users phishing metamask metaverse attacks leading brands

users phishing → Результатов: 117


LocalBitcoins Users Scammed of Bitcoin in Phishing Attack, Forum Suspended

Users of the peer-to-peer OTC Bitcoin trading service LocalBitcoins have been targeted by cyber criminals as part of a phishing scam, resulting in the user’s Bitcoin being stolen. Forum users were being redirected to a phishing site, which was prompting the users to input two-factor authentication codes that were used to access user accounts and empty.

2019-1-26 16:37


Фото:

Almost $1 Million Stolen in Phishing Attack on Electrum Wallet

Popular cryptocurrency wallet Electrum is in the midst of an ongoing hack which saw almost $1 million in Bitcoin stolen so far, Reddit users discovered on December 27, 2018. 250 BTC Stolen in Electrum Wallet Hack It seems that hackers aren’t lying idle during Christmas time, as a popular cryptocurrency wallet has reportedly experienced one of the largest thefts of.

2018-12-30 00:00


Top 5 Crypto Crime Trends: Cryptojacking Malware, Botnets, Trojan Horses, Phishing and Sextortion

Cryptocurrency is no stranger to dubious tactics by those who are looking to cheat the system – and those who use it. Several digital security companies, such as Kaspersky Labs, have been trying to provide cryptocurrency users and services with the tools and resources they need to combat against the troublesome tactics. Here are just […]

2018-11-14 22:29


Фото:

Singapore Phishing Websites Using Fake News to Get Users’ Bank and Credit Card Details

Phishing websites have been using fake news involving the Deputy Prime Minister of Singapore as means of aquiring users’ credit card and bank account information. Get Rich Quick Scheme The Singaporean government has condemned two separate websites for trying to acquire bank account and credit card information by distributing false information involving the Deputy Prime Minister of Singapore.

2018-9-21 09:00


Myetherwallet Suffers More Attacks than Any Other Ethereum Wallet

MyEtherwallet has been known to be one of the Largest Ethereum wallets in the Crypto sphere and has major encounters and breach of security which puts users tokens at huge risks. Phishing Attacks have been on the rise with popular exchanges like binance,bittrex and bitfinex always getting cloned by impersonators and most time they still […] The post Myetherwallet Suffers More Attacks than Any Other Ethereum Wallet appeared first on ZyCrypto.

2018-9-17 16:31


Фото:

Fake Phishing Website Mimicking Jaxx Wallet Shut Down

A few weeks ago a group of scammers set up a fake website similar to that of Jaxx Wallet with the aim of stealing the cryptocurrencies of users through illegal practices. On September 12, Flashpoint, a cybersecurity firm which provides Business Risk Intelligence advice, posted an article on its official blog commenting that the fraudulent […] The post Fake Phishing Website Mimicking Jaxx Wallet Shut Down appeared first on Ethereum World News.

2018-9-14 09:11


EtherScamDB: Ethereum (ETH) Scam Database For Active Threats?

The continued rise of cryptocurrency popularity has created a breeding ground for malicious attacks, phishing attempts, and the occasional PC hacks. While a large popularity of crypto users is earning from their efforts, there is another group that has chosen to earn a living by stealing from the hard workers. What Is EtherScamDB? EtherScamDB was […]

2018-7-15 14:09


Action Fraud Warning: High Incidence Of Prowling Wannacry Ransomware, Phishing, Targeting Crypto users

Action Fraud, UK’s cyber crime watchdog has warned cryptocurrency users to be watchful of phishing emails which use Ransomware WannaCry. Issuing the red alert, the regulator said, “The WannaCry emails are designed to cause panic and trick you into believing that your computer is infected with WannaCry Ransomware,” and users have to be careful not […] The post Action Fraud Warning: High Incidence Of Prowling Wannacry Ransomware, Phishing, Targeting Crypto users appeared first on ZyCrypto.

2018-6-26 19:58