DeFi Safety and Phishing Scams

DeFi Safety and Phishing Scams

By Michael @ CryptoEQ | CryptoEQ | 8 Nov 2023


You are reading an excerpt from our free but shortened abridged report! While still packed with incredible research and data, for just $20/month you can upgrade to our FULL library of 50+ reports (including this one) and complete industry-leading analysis on the top crypto assets. 

67cbbf4723857b85c151585aa280e6d940346c501cef75bafd7dea02b44b24c9.png

Becoming a Premium member means enjoying all the perks of a Basic membership PLUS:

  • Full-length CORE Reports: More technical, in-depth research, actionable insights, and potential market alpha for serious crypto users
  • Early access to future CORE ratings: Being early is sometimes just as important as being right!
  • Premium Member CORE+ Reports: Coverage on the top issues pertaining to crypto users like bridge security, layer two solutions, DeFi plays, and more
  • CORE report Audio playback: Don’t want to read? No problem! Listen on the go.

 

The Rising Threat of Crypto Phishing

Crypto phishing stands as one of the predominant digital threats today, pivoting around the premise that malevolent entities use sophisticated techniques of social manipulation to procure confidential data from unsuspecting individuals. This data can range from wallet private keys to engaging unsuspecting users with malicious smart contracts or counterfeit dapps.

Common Strategies Employed by Scammers

  1. Phishing Emails: Often camouflaged as genuine communications, these emails redirect users to fabricated websites, inviting them to inadvertently share sensitive data such as seed phrases, private keys, or engage with harmful smart contracts. Such interactions could grant these dubious contracts access to the victim's assets, allowing the scammer to commandeer funds or endorse malicious content.

  2. Malicious Links on Social Media: The rapid spread and vast reach of social media amplify the threat vector. Unsuspecting users often fall prey to detrimental links masquerading as legitimate content.

  3. Fake Advertisements: Ad platforms, including Google and Twitter, can be infested with faux advertisements redirecting to malicious websites. The sophistication of such scams hinges on their ability to mimic genuine platforms, thereby hoodwinking even the wary user.

  4. Counterfeit Wallet Updates: Scammers, in a bid to further their reach, present fraudulent crypto wallet updates, capitalizing on recognized names such as Trust Wallet or Metamask to bolster their credibility.

Phishing remains a menacing specter in the crypto domain, often perpetuated through a myriad of social engineering tactics. These tactics differ in their level of personalization and duration, ranging from highly targeted campaigns that unfold over prolonged periods to fleeting, split-second deceptions.

The notorious Lazarus Group's relentless crypto heists, as evidenced in their recent attacks on entities like Atomic Wallet, AlphaPo, Stake, and CoinEx, amassing a staggering sum surpassing $250 million, typically zeroes in on the personnel of custodial ventures. Here, the malicious strategy is characterized by sustained engagement with the target, sometimes spanning considerable durations. By wielding influence through tools like blackmail, faux romantic engagements, or plain trust-building, these fraudsters coax their victims into financial transfers, often masquerading as promising investment avenues.

Contrasting with drawn-out schemes, certain scams unfold at a breathtaking pace. A case in point from recent memory involves a seasoned DeFi participant who found themselves lighter by $24 million within moments of endorsing increaseAllowance messages. This swift action enabled the perpetrator to appropriate the victim's stETH, valued at $15.6 million, and rETH, pegged at $8.6 million, rerouting these funds straight to the assailant's wallet.

These swift, wallet-emptying maneuvers, often marketed as Scam-as-a-Service, are essentially malware tools. They cater to fraudsters orchestrating social engineering drives without demanding deep technical proficiency. The illicit gains from such endeavors are typically split between the scam propagators, who disseminate the malware links through compromised platforms like Twitter or Discord, and the original malware creators.

Delving into the Mechanisms: Token Approvals and Message Signings

One pivotal aspect that investors must grasp is the underlying mechanics of token approvals and message signings. These operations, though integral to routine crypto transactions, have been identified as hotspots for phishing activities.

Token Approvals: DeFi scams, beyond just phishing, lean heavily on manipulating token approvals. To articulate simply, when an individual wishes to interact with a dapp, they need to sanction token approvals, thereby granting the right to spend specific tokens from their balance. Essentially, this means that the user permits a contract—managed by the dapp—to expend a particular ERC-20 token on their behalf.

But how does this transpire in the technical realm? Consider a scenario where an individual wishes to deposit USDC into a vault. Conventionally, this entails transferring the staking token from the user's balance to a designated vault strategy. This action facilitates the yield generation on the deposited amount and is achieved by invoking the transferFrom() function—an inherent trait of ERC-20 tokens. However, an essential caveat to note here is that only user-approved contracts can initiate a token transfer from their balance. Hence, prior to actions like deposits, swaps, or lending, one must invoke the approve() function on the token's contract.

The Mechanism of Signing Messages

Those who frequently navigate the DeFi landscape are likely familiar with the necessity of signing messages. This process often serves to verify access to dapps, facilitate DAO voting, or orchestrate sell/buy orders on DEXs and NFT marketplaces, among other applications. Cryptographic signatures have become a gold standard for scenarios where authentication is required, but the transaction should not entail gas expenditure.

Technically, when a user is prompted to sign a message, they receive specific message data. Using their private keys, users subsequently acknowledge the reception of said data and validate its authenticity. This procedure ensures that the dapps can correlate the message data with a user's public key, all the while being certain that the message received the endorsement of the corresponding private key of that public key.

While a rudimentary diagram might serve to illustrate this, it's paramount to understand that signatures don't expose or compromise private keys. This inherent design provides a secure medium for authentication. The catch, however, lies in user comprehension. If a user doesn't fully grasp what they are authenticating, they might inadvertently lend their trust to malicious entities.

3604453c596a2b758b57282c50ebbc7522831a5c502712744f7b80afd8f78e68.png

Source

 

Strategies to Counteract Phishing: Preserving Your Assets

The allure of digital currencies, while lucrative, is fraught with pitfalls. Here's a compilation of measures to help you stay guarded:

  1. Domain Verification: Whenever you're searching for a DeFi protocol on platforms like Google or Twitter, be wary. The topmost links are not always authentic. Before making a decision, take a moment to confirm the legitimacy of the domain. One efficient way to do this is to cross-reference with the project's official Twitter account.

  2. Bookmarking: For platforms you frequent, make it a habit to save the site in your browser's bookmarks to reduce the chances of landing on a fake site.

  3. Anti-Phishing Codes: Embrace these codes, which can easily differentiate genuine emails from dapp imposters. This unique character set accompanying each email ensures that the sender is indeed the genuine dapp you're familiar with.

  4. Email Vigilance: Pay close attention to email addresses sending you suspicious links or alerts. Often, these are craftily designed to mimic official channels, with minor spelling tweaks. Always avoid clicking on dubious links.

  5. Guard Your Recovery Phrase: Under no circumstance should you share your secret wallet recovery phrase. Especially be skeptical of individuals on platforms like Discord or Telegram posing as project administrators.

  6. Discerning Signatures: Abstain from signing cryptographic messages outside of genuine protocol websites. Moreover, never sign messages if you're unclear about their content.

  7. Contract Revocation: In the unfortunate event of endorsing a malicious contract, you can still safeguard your assets by rescinding approvals for the dubious contract. Tools like De.Fi Shield can assist in this process.

  8. Wallet Interactions: Should you notice unexpected content in your wallet, exercise caution. If no official announcement was made regarding an airdrop, be skeptical.

  9. Official Announcements: If you encounter airdrop declarations, corroborate the source's authenticity. Always verify through multiple official channels and even consider contacting the project's technical support for clarity.

  10. Beware of Simultaneous Airdrops: Scammers have been known to orchestrate counterfeit airdrops around the same timeline as genuine project airdrops. Always be discerning and check domain names meticulously.

Additional Safety Measures and Crypto Security

Most of these below, as well as much, much more, can be found here.

  • Use 2FA (not SMS-based): 2-Factor Authentication (2FA) is used to ensure accounts are protected by more than a password but need an additional randomly generated code or device to grant access.
    1. How to Set Up Google Authenticator
    2. How to restore access to your accounts if you lose/destroy your device w/ Google Authenticator (2FA)
  • Whitelisting of addresses is often used by businesses to ensure funds can only be sent to previously approved addresses. This forces a hacker to gain access to both the wallet and the mechanism that manages this list.
  • Bookmark your favorite/most frequented sites
  • Use a password manager
  • Use burner wallets/addresses, especially when interacting with a new protocol for the first time
  • Geographical distribution of these keys and/or participants to protect against physical attacks
  • Cold storage
  • A crypto vault has a built-in, predetermined delay when you try to move funds. This is also known as a timelock. It prevents cryptocurrency from being moved until a certain amount of time has passed.
  • Yubi keys or other security hardware
  • What to do if you signed a scam transaction
  • Don’t link a device to your home address
    1. Buy with cash if possible
  • Use separate email
  • Have “crypto computer”

 

Wrapping Up

The world of digital assets offers vast potential, but it also brings inherent risks. By understanding the nuances of cryptographic signatures and following precautionary measures, one can substantially reduce the likelihood of falling prey to phishing attacks.

How do you rate this article?

58


Michael @ CryptoEQ
Michael @ CryptoEQ

I am a Co-Founder and Lead Analyst at CryptoEQ. Gain the market insights you need to grow your cryptocurrency portfolio. Our team's supportive and interactive approach helps you refine your crypto investing and trading strategies.


CryptoEQ
CryptoEQ

Gain the market insights you need to grow your cryptocurrency portfolio. Our team's supportive and interactive approach helps you refine your crypto investing and trading strategies.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?