How to avoid getting hooked by crypto 'ice phishing' scammers ...

MARKET_WATCH Overview

Blockchain security company CertiK has reminded the crypto community to stay alert over “ice phishing” scams — a unique type of phishing scam targeting Web3 users — first identified by Microsoft earlier this year. In a Dec. 20 analysis report, CertiK described ice phishing scams as an attack that tricks Web3 users into signing permissions which end up allowing a scammer to spend their tokens. This differs from traditional phishing attacks which attempt to access confidential information such as private keys or passwords, such as the fake websites set up which claimed to help FTX investors recover funds lost on the exchange. 

 

A Dec. 17 scam where 14 Bored Apes were stolen is an example of an elaborate ice phishing scam. An investor was convinced to sign a transaction request disguised as a film contract, which ultimately enabled the scammer to sell all of the user's apes to themselves for a negligible amount.

 

The firm noted that this type of scam was a “considerable threat” found only in the Web3 world, as investors are often required to sign permissions to decentralized finance (DeFi) protocols they interact with, which could be easily faked.“The hacker just needs to make a user believe that the malicious address that they are granting approval to is legitimate. Once a user has approved permissions for the scammer to spend tokens, then the assets are at risk of being drained.”Once a scammer has gained approval, they are able to transfer assets to an address of their choosing. An example of how an ice phishing attack works on Etherscan. Source: CertikTo protect themselves from ice phishing, CertiK recommended that investors revoke permissions for addresses they don’t recognize on blockchain explorer sites such as Etherscan, using a token approval tool.Related: $4B OneCoin scam co-founder pleads guilty, faces 60 years jailAdditionally, addresses that users are planning to interact with should be looked up on these blockchain explorers for suspicious activity. In its analysis, CertiK points to an address that was funded by Tornado Cash withdrawals as an example of suspicious activity. CertiK also suggested that users should only interact with official sites they are able to verify, and to be particularly wary of social media sites like Twitter, highlighting a fake Optimism Twitter account as an example.Fake Optimism Twitter account. Source: CertikThe firm also advised users to take a couple of minutes to check a trusted site such as CoinMarketCap or Coingecko, users would have been able to see that the linked URL was not a legitimate site and should be avoided. 

 

Tech giant Microsoft was the first one to highlight this practice in a Feb. 16 blog post, saying at the time that while credential phishing is very predominant in the Web2 world, ice phishing gives individual scammers the ability to steal a chunk of the crypto industry while maintaining “almost complete anonymity.” They recommended that Web3 projects and wallet providers increase the security of their services on the software level in order to prevent the burden of avoiding ice phishing attacks being placed solely on the end-user. 

 

Source : [How to avoid getting hooked by crypto 'ice phishing' scammers ...](news.google.com/__i/rss/rd/articles/CBMiYWh0dHBzOi8vY29pbnRlbGVncmFwaC5jb20vbmV3cy9ob3ctdG8tYXZvaWQtZ2V0dGluZy1ob29rZWQtYnktY3J5cHRvLWljZS1waGlzaGluZy1zY2FtbWVycy1jZXJ0aWvSAQA?oc=5) undefined - December 21, 2022

Join our 70k+
tribe of Akters

Have any questions?

Check our Q&A

About the AKTIO coin

Benefit fully from our ecosystem

What’s new in the App?

We’re adding new features

Customer support

support@akt.io

+353 1 574 7382

+39 06 4525 6900

Opening hours:

Monday to Friday: 9am - 5pm CET

Learn

News

Glossary

AKT Academy

Automata Pay

65-66 Warwick House 4th

Floor, Queen Street, London

England, EC4R 1EB

Automata ICO Ltd

3rd Floor Ormond Building,

31-36 Ormond Quay Upper,

Dublin 7, D07 Ee37

Automata Pay Europe Ltd

3rd Floor Ormond Building,

31-36 Ormond Quay Upper,

Dublin 7, D07 Ee37

Automata ICO Ltd

Italian Branch

Via Archimede, 161,

00197 Roma

Italy

Automata Pay Ltd, Reg number 12208424 and incorporated in the United Kingdom is the registered agent of Modulr FS Limited, a company registered in England with company number 09897919, authorised and regulated by the Financial Conduct Authority as an Electronic Money Institution (Firm Reference Number: 900573). Traditional currency will be safeguarded by a licensed bank in segregated accounts in accordance with regulatory requirements.

Automata Pay Europe Limited, Reg number 69028 and incorporated in Ireland is the registered agent of Modulr FS Europe Limited, a company registered in Ireland with company number 638002, authorised and regulated by the Central Bank of Ireland as an Electronic Money Institution (Institution Code C191242). Traditional currency is safeguarded as e-money in accordance with our regulatory obligations. Traditional currency will be safeguarded by a licensed bank in segregated accounts in accordance with regulatory requirements.

Automata ICO Limited, Reg number 690280 and incorporated in Ireland has applied for a Virtual Asset Service Provider registration with the Central Bank of Ireland. Whilst the application is ongoing we are permitted to continue business as a Virtual Asset Service Provider in line with the Central Bank of Ireland's regulatory disclosure statement as required under section 106L of the CJA 2010 in relation to registered VASPS. It is important to note that a registration as a VASP is a registration for Anti-Money Laundering (AML) and Combatting the Financing of Terrorism (CFT) purposes only. While Automata ICO Limited does have certain financial crime control obligations under this registration, cryptoasset services remain largely unregulated. The Financial Ombudsman Service or the Financial Services Compensation Scheme do not apply to the cryptoasset activities carried on by Automata ICO Limited.