BTC $77,541.73 -2.79%
ETH $2,433.86 -2.51%
BNB $688.20 -2.95%
XRP $1.38 -3.11%
SOL $103.32 -3.08%
TRX $0.3385 -0.28%
DOGE $0.0844 -3.76%
ADA $0.1994 -4.90%
BCH $244.00 -7.39%
LINK $11.31 -3.35%
HYPE $81.12 -3.51%
AAVE $121.30 -3.67%
SUI $0.7344 -3.87%
XLM $0.1771 -3.67%
ZEC $791.04 -0.34%
BTC $77,541.73 -2.79%
ETH $2,433.86 -2.51%
BNB $688.20 -2.95%
XRP $1.38 -3.11%
SOL $103.32 -3.08%
TRX $0.3385 -0.28%
DOGE $0.0844 -3.76%
ADA $0.1994 -4.90%
BCH $244.00 -7.39%
LINK $11.31 -3.35%
HYPE $81.12 -3.51%
AAVE $121.30 -3.67%
SUI $0.7344 -3.87%
XLM $0.1771 -3.67%
ZEC $791.04 -0.34%

phishing

All
Article
Flash

SafePal updates on security incident progress: launching anti-phishing actions and will commission a third-party agency to review the order system

The cryptocurrency wallet project SafePal has released updates on the security incident, stating that it is continuously tracking phishing websites and impersonation accounts, and plans to introduce a professional anti-phishing security company to expedite the removal of malicious information to protect user asset security. SafePal mentioned that it is currently in the final selection process among four professional anti-phishing security companies, and once a partner is selected, it will further enhance the efficiency of handling threats such as counterfeit websites and scam accounts.The team is also continuously monitoring whether the affected data has been sold or made public, including channels such as dark web forums and trading markets. Once signs of data leakage are detected, affected users will receive risk alerts immediately. Regarding security audits, SafePal stated that it is in the final selection among three mature independent security institutions, which will conduct a comprehensive security review of the order system. Meanwhile, the team is reassessing the order and logistics processes to reduce the amount of data that needs to be stored in the initial phase of the system, thereby reducing potential risks from the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating the fraud protection page, providing updates on the incident, FAQs, and analysis of fraud cases. SafePal once again reminds users: the official will never ask users to provide their seed phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify the source of information through official channels.

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.

The Ethereum Foundation provides security funding to WEBCAT to assist in wallet verification front-end code to prevent phishing attacks

According to official news, the Ethereum Foundation's "Trillion Dollar Security" (1TS) has announced a special grant to the Freedom of the Press Foundation (FPF) to support the ongoing development of the open-source tool WEBCAT, aimed at addressing the long-standing front-end code verification security gap in Ethereum wallets and decentralized applications (DApps).WEBCAT (Web-based Code Assurance and Transparency) is an open-source tool designed to help browsers verify whether the code loaded by a website matches the version publicly released by the developer.This funding will promote the expansion of WEBCAT to Ethereum wallets and application scenarios, enabling users to verify whether the front-end pages they access have been tampered with.The Ethereum Foundation stated that while HTTPS can verify the website a user is connected to and encrypt communication, it cannot prove that the front-end code actually running on the website is the same version released by the developer. If an attacker controls the website's front-end code, they may modify the transaction receiving address without the user's knowledge or induce the user to sign transactions that do not match the content displayed on the page.The Ethereum Foundation noted that front-end attacks have become a significant security risk for blockchain infrastructure, with malicious modifications to web interfaces potentially leading to supply chain attacks, DNS hijacking subsequent attacks, and user interface deception.WEBCAT was initially developed by the Freedom of the Press Foundation to enhance the code credibility of secure communication systems like SecureDrop.With this expansion into the Ethereum ecosystem, it will complement security measures such as "Clear Signing" in the 1TS program: the former helps wallets confirm that the application front-end has not been tampered with, while the latter helps users understand the transaction content they are approving.

The IRS warns cryptocurrency holders that scammers are mailing fake letters to steal assets or data

According to Bloomberg, the Internal Revenue Service (IRS) has warned cryptocurrency holders that scammers are contacting some taxpayers by mailing fake letters in an attempt to steal their digital assets or personal data. The IRS stated that these letters may ask taxpayers to register for a so-called "Digital Asset Compliance Portal," which does not exist. The IRS also reminds users not to scan suspicious QR codes and not to answer or cooperate with calls requesting payment.While phishing and digital scams are not new in the cryptocurrency industry, sending fake IRS notices through physical mail seems to be a new scam tactic. Since the IRS has indeed sent letters related to digital assets to taxpayers in the past, and last year saw a surge in cryptocurrency tax filing notifications, many taxpayers are confused, which may lead scammers to exploit this familiarity for disguise. As the U.S. tax system requires taxpayers to disclose cryptocurrency activities on their tax returns, communication between the IRS and cryptocurrency holders has become more common. This also makes counterfeit tax notices more misleading. For cryptocurrency users, encountering "IRS letters" involving portal registration, QR code scanning, wallet connections, or payment requests should be treated with caution, and verification should be done through official channels.
app_icon
ChainCatcher Building the Web3 world with innovations.