BTC $77,733.39 -3.62%
ETH $2,442.79 -3.06%
BNB $691.13 -3.14%
XRP $1.38 -4.39%
SOL $103.98 -4.90%
TRX $0.3409 +0.87%
DOGE $0.0851 -4.43%
ADA $0.2027 -5.49%
BCH $246.09 -8.66%
LINK $11.43 -4.34%
HYPE $80.26 -4.47%
AAVE $121.98 -5.70%
SUI $0.7421 -5.08%
XLM $0.1790 -4.21%
ZEC $802.15 -1.10%
BTC $77,733.39 -3.62%
ETH $2,442.79 -3.06%
BNB $691.13 -3.14%
XRP $1.38 -4.39%
SOL $103.98 -4.90%
TRX $0.3409 +0.87%
DOGE $0.0851 -4.43%
ADA $0.2027 -5.49%
BCH $246.09 -8.66%
LINK $11.43 -4.34%
HYPE $80.26 -4.47%
AAVE $121.98 -5.70%
SUI $0.7421 -5.08%
XLM $0.1790 -4.21%
ZEC $802.15 -1.10%

fei

All
Article
Flash

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.

hot_img ByteDance adjusts ToB architecture: Feishu product line merged into Doubao, GTM integrated into Volcano Engine

According to exclusive reports from Titanium Media, ByteDance released an internal email on July 30, announcing the integration of the Feishu product team and the Doubao product team to form a new Doubao product team, which will be unified under the leadership of Doubao head Zhao Qi, while Feishu head Xie Xin will report to Zhao Qi. In terms of the GTM system, the Feishu GTM team will integrate with the Volcano Engine team to establish a new ToB GTM organization called the "Creativity Service Platform," which will be responsible for the marketing, sales, and customer service of ByteDance's MaaS and SaaS cloud services, led by Volcano Engine head Tan Dai, with Feishu sales head Lin Chan and Feishu strategy and marketing head Shi Zhijun reporting to Tan Dai.This integration is the largest adjustment to ByteDance's ToB business since it implemented business segmentation in 2021. After the reorganization, Feishu's products and services will remain unchanged, and Feishu will collaborate more deeply with Doubao on productivity scenarios. The Doubao enterprise version, developed with deep involvement from the Feishu product team, has already begun internal testing among some Feishu clients. Feishu currently covers over 10 million enterprise users, and this integration will further enhance the integrated collaborative capabilities of the ToB business.

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.
app_icon
ChainCatcher Building the Web3 world with innovations.