Binance Square
LIVE
Alvosec
@Alvosec
Web3 security advisor. You can follow us also on twitter.com/alvosec.
Following
Followers
Liked
Shared
All Content
LIVE
--
💡 Apart from Binance wallet, what other DeFi wallets do you use? a) MetaMask b) WebAuth c) TrustWallet
💡 Apart from Binance wallet, what other DeFi wallets do you use?

a) MetaMask

b) WebAuth

c) TrustWallet
⚠️ #Lazarus, a notorious #hacking group, now targets Linux users and devs who work on #DeFi platforms. They used a trick with leader dot U+2024, where file appears as PDF but it is ELF or executable malware.
⚠️ #Lazarus, a notorious #hacking group, now targets Linux users and devs who work on #DeFi platforms. They used a trick with leader dot U+2024, where file appears as PDF but it is ELF or executable malware.
⚠️ Ordinals Finance rug pulls for at least $1 million! They swapped all OFI tokens to ETH worth around $1 million. They then laundered the funds through the Tornado Cash crypto mixer. The project creator deleted the project's Twitter account and took down its website.
⚠️ Ordinals Finance rug pulls for at least $1 million! They swapped all OFI tokens to ETH worth around $1 million. They then laundered the funds through the Tornado Cash crypto mixer. The project creator deleted the project's Twitter account and took down its website.
⚠️ Users being rug pulled is bad enough, but to make matters worse, someone created a fake Twitter account @ordinaIsfinance after the original page had been deleted. 👉 Scam website: etherseums-airdrops[.]io ⛔ ProtonDNS status: blocked!
⚠️ Users being rug pulled is bad enough, but to make matters worse, someone created a fake Twitter account @ordinaIsfinance after the original page had been deleted.

👉 Scam website: etherseums-airdrops[.]io

⛔ ProtonDNS status: blocked!
⚠️ Warning! New #phishing & wallet #drainer at dogecoinreward[.]net! 🖥️ Hosted at: Russia There is a file, that's literally called drainer.js. #security
⚠️ Warning! New #phishing & wallet #drainer at dogecoinreward[.]net!

🖥️ Hosted at: Russia

There is a file, that's literally called drainer.js. #security
⚠️ Think twice before using the iOS markup tool to redact any crypto-related sensitive information (private keys, mnemonic seed etc.), as hackers may easily uncover your content. #privacy #security 📢 Private keys in this example are not real!
⚠️ Think twice before using the iOS markup tool to redact any crypto-related sensitive information (private keys, mnemonic seed etc.), as hackers may easily uncover your content. #privacy #security

📢 Private keys in this example are not real!
⚠️ Warning! New #phishing & wallet #drainer at claim.optinism[.]io! 🥷 Attacker address: 0xdc54Ddeae33a65A232622Ede8F7E30c7bd0b0F9E 🖥️ Hosted at: @Hostinger 💰 Stolen ETH balance: 4.92 $ETH
⚠️ Warning! New #phishing & wallet #drainer at claim.optinism[.]io!

🥷 Attacker address: 0xdc54Ddeae33a65A232622Ede8F7E30c7bd0b0F9E

🖥️ Hosted at: @Hostinger

💰 Stolen ETH balance: 4.92 $ETH
Scammer gave me access to his wallet?In the crypto and blockchain world, unfortunately, we find scammers who strive to be able to directly or indirectly steal the funds of the unfortunate who for one reason or another fall victim to the same scammers. There are several scams and tricks that criminals use but this time we will focus on a really devious one that few know or recognize, which is the one that concerns the seed or the private key. Before going into detail and understanding how it works, this scam is based on the fact that we must never reveal our private key or our seed to anyone because if we do, we will lose all the funds within it. Knowing this, criminals deliberately publish their private key or seed in chat or private messages, in the hope that someone can insert the private key or seed into the wallet and see that there are crypto with a value and ready to be moved to our wallet with a simple transaction. We will take one example that was circulating on Twitter and dig into the case. Here we have a scammer wallet address: TUr8tTfMmr2ML88C65xLHPT4JGNgUkvh9Z Here is also a secret phrase: damage muscle dilemma year useful toast siege sustain hero property lucky home Now let's check what is going on, and why scammer "generously" shares his private key? Scammer wallet Let's check account permissions.  It is important to notice that threshold of Owner permission is set to 4. For those who don't know what threshold is, here is a brief definition: Minimum threshold to validate multisig transactions, a multisig transaction will only take effect when the total weight of signing addresses is greater than the threshold. So basically we are looking at msig wallet, with 2 accounts and second account has weight of 3 - meaning that first account + second will satisfy msig condition of threshold and by that, action will be executed.  This means that without access to that second wallet, this first account is useless. And from that point anyone that has access will be unable to send funds to another address. If victim persist to send funds, he will be asked to top up TRX to cover transaction fee - which will be quickly pulled by criminals to another address.

Scammer gave me access to his wallet?

In the crypto and blockchain world, unfortunately, we find scammers who strive to be able to directly or indirectly steal the funds of the unfortunate who for one reason or another fall victim to the same scammers.

There are several scams and tricks that criminals use but this time we will focus on a really devious one that few know or recognize, which is the one that concerns the seed or the private key.

Before going into detail and understanding how it works, this scam is based on the fact that we must never reveal our private key or our seed to anyone because if we do, we will lose all the funds within it.

Knowing this, criminals deliberately publish their private key or seed in chat or private messages, in the hope that someone can insert the private key or seed into the wallet and see that there are crypto with a value and ready to be moved to our wallet with a simple transaction.

We will take one example that was circulating on Twitter and dig into the case.

Here we have a scammer wallet address: TUr8tTfMmr2ML88C65xLHPT4JGNgUkvh9Z

Here is also a secret phrase: damage muscle dilemma year useful toast siege sustain hero property lucky home

Now let's check what is going on, and why scammer "generously" shares his private key?

Scammer wallet

Let's check account permissions.



It is important to notice that threshold of Owner permission is set to 4. For those who don't know what threshold is, here is a brief definition:

Minimum threshold to validate multisig transactions, a multisig transaction will only take effect when the total weight of signing addresses is greater than the threshold.

So basically we are looking at msig wallet, with 2 accounts and second account has weight of 3 - meaning that first account + second will satisfy msig condition of threshold and by that, action will be executed.



This means that without access to that second wallet, this first account is useless. And from that point anyone that has access will be unable to send funds to another address. If victim persist to send funds, he will be asked to top up TRX to cover transaction fee - which will be quickly pulled by criminals to another address.

⚠️ Warning! New #phishing & wallet #drainers targeting $DOGE holders! 🔗 claims-dogecoin[.]com, twitter-dogecoin[.]com, airdrop-dogecoin[.]com, join-dogecoin[.]com, rewards-doge[.]com! 🥷 Attacker address: 0x10D4763549cA0017522CE286cab5E92E2E3688ac 🖥️ Proxied via Cloudflare.
⚠️ Warning! New #phishing & wallet #drainers targeting $DOGE holders!

🔗 claims-dogecoin[.]com, twitter-dogecoin[.]com, airdrop-dogecoin[.]com, join-dogecoin[.]com, rewards-doge[.]com!

🥷 Attacker address: 0x10D4763549cA0017522CE286cab5E92E2E3688ac

🖥️ Proxied via Cloudflare.
⚠️ Warning! New #phishing & wallet #drainer at yuga-gucci[.]com! 🥷 Attacker address: 0x71F191FCa1b38e85fcBE2aFA90AA3590164677Ef 🖥️ Hosted at: @regru (Russia) 💰 Stolen ETH balance: 42.67 $ETH Never connect wallet to unofficial websites!
⚠️ Warning! New #phishing & wallet #drainer at yuga-gucci[.]com!

🥷 Attacker address: 0x71F191FCa1b38e85fcBE2aFA90AA3590164677Ef

🖥️ Hosted at: @regru (Russia)

💰 Stolen ETH balance: 42.67 $ETH

Never connect wallet to unofficial websites!
⚠️ Beware of promoted #phishing domains via Google Ads, never connect your wallet on unofficial or unauthorized website! #security
⚠️ Beware of promoted #phishing domains via Google Ads, never connect your wallet on unofficial or unauthorized website! #security
👤 KYC is an important part of the crypto ecosystem. It helps prevent financial crimes, build trust and credibility, and ensure compliance with regulations. #KYC
👤 KYC is an important part of the crypto ecosystem. It helps prevent financial crimes, build trust and credibility, and ensure compliance with regulations. #KYC
⚠️ New type of scam! The attacker creates a vanity address (clone last 4-5 characters) and uses it to send small amounts of stablecoin to the victim in order to trick them into copying the wrong address when sending funds. #crypto #security
⚠️ New type of scam! The attacker creates a vanity address (clone last 4-5 characters) and uses it to send small amounts of stablecoin to the victim in order to trick them into copying the wrong address when sending funds. #crypto #security
🎯 If there were one rule that could be applied to most types of scams, it would be this one! #crypto #security
🎯 If there were one rule that could be applied to most types of scams, it would be this one! #crypto #security
Do you know what to do if you lose your iPhone and you have your crypto funds on it?If you lost your iPhone, iPad, or iPod touch or you think it might be stolen, use Find My iPhone - where you will be able to locate your device, notify the finder or erase you device. 1. Look for your device on a map To find your device, sign in to iCloud.com/find. Or use the Find My app on another Apple device that you own. If your iPhone, iPad, or iPod touch doesn’t appear in the list of devices, Find My was not turned on. But you can still protect your account if Find My was not turned on. 2. Mark as Lost By marking your device as lost, you can secure your information by remotely locking it with a passcode. This action also deactivates Apple Pay on the missing device. Additionally, you have the option to showcase a customized message on the lost device that includes your contact information. 3. Remotely erase your device If you erase a device that had iOS 15, iPadOS 15, or later installed, you can still use Find My to locate the device or play a sound on it. Otherwise, you won't be able to locate the device or play a sound after you erase it. If you have AppleCare+ with Theft and Loss, do not remove the device from Find My or your Apple ID. 4. Contact your wireless carrier If the missing device is an iPhone or an iPad with cellular, it is recommended to notify your wireless carrier about the lost device. Request the carrier to deactivate your account so that no calls, texts, or data can be used on the device. Moreover, if your wireless carrier plan covers the lost device, you should file a claim. 5. Protect your sensitive information Change passwords for sensitive accounts and private keys of your crypto wallets: If you have any sensitive accounts or cryptocurrency wallets associated with your lost iPhone, it is essential to change the passwords immediately. This will prevent unauthorized access to your accounts and protect your digital assets. You should also consider transferring your cryptocurrency funds to a new wallet to ensure their safety. Use a passcode and enable Find My app: It is important to use a passcode and enable the Find My app on your iPhone before it gets lost or stolen. This can help you locate your device and prevent others from accessing your personal information.

Do you know what to do if you lose your iPhone and you have your crypto funds on it?

If you lost your iPhone, iPad, or iPod touch or you think it might be stolen, use Find My iPhone - where you will be able to locate your device, notify the finder or erase you device.

1. Look for your device on a map

To find your device, sign in to iCloud.com/find. Or use the Find My app on another Apple device that you own.

If your iPhone, iPad, or iPod touch doesn’t appear in the list of devices, Find My was not turned on. But you can still protect your account if Find My was not turned on.

2. Mark as Lost

By marking your device as lost, you can secure your information by remotely locking it with a passcode. This action also deactivates Apple Pay on the missing device. Additionally, you have the option to showcase a customized message on the lost device that includes your contact information.

3. Remotely erase your device

If you erase a device that had iOS 15, iPadOS 15, or later installed, you can still use Find My to locate the device or play a sound on it. Otherwise, you won't be able to locate the device or play a sound after you erase it.

If you have AppleCare+ with Theft and Loss, do not remove the device from Find My or your Apple ID.

4. Contact your wireless carrier

If the missing device is an iPhone or an iPad with cellular, it is recommended to notify your wireless carrier about the lost device. Request the carrier to deactivate your account so that no calls, texts, or data can be used on the device. Moreover, if your wireless carrier plan covers the lost device, you should file a claim.

5. Protect your sensitive information

Change passwords for sensitive accounts and private keys of your crypto wallets: If you have any sensitive accounts or cryptocurrency wallets associated with your lost iPhone, it is essential to change the passwords immediately. This will prevent unauthorized access to your accounts and protect your digital assets. You should also consider transferring your cryptocurrency funds to a new wallet to ensure their safety.

Use a passcode and enable Find My app: It is important to use a passcode and enable the Find My app on your iPhone before it gets lost or stolen. This can help you locate your device and prevent others from accessing your personal information.

Explore the lastest crypto news
⚡️ Be a part of the latests discussions in crypto
💬 Interact with your favorite creators
👍 Enjoy content that interests you
Email / Phone number

Latest News

--
View More
Sitemap
Cookie Preferences
Platform T&Cs