Scan to download
BTC $75,097.73 -2.13%
ETH $2,065.48 -2.30%
BNB $652.20 -1.29%
XRP $1.32 -1.93%
SOL $83.43 -1.52%
TRX $0.3731 -0.63%
DOGE $0.1013 -0.59%
ADA $0.2386 -2.31%
BCH $342.30 -2.78%
LINK $9.35 -1.93%
HYPE $61.73 -0.54%
AAVE $85.14 -2.19%
SUI $0.9967 -3.80%
XLM $0.1492 -0.07%
ZEC $571.47 -7.22%
BTC $75,097.73 -2.13%
ETH $2,065.48 -2.30%
BNB $652.20 -1.29%
XRP $1.32 -1.93%
SOL $83.43 -1.52%
TRX $0.3731 -0.63%
DOGE $0.1013 -0.59%
ADA $0.2386 -2.31%
BCH $342.30 -2.78%
LINK $9.35 -1.93%
HYPE $61.73 -0.54%
AAVE $85.14 -2.19%
SUI $0.9967 -3.80%
XLM $0.1492 -0.07%
ZEC $571.47 -7.22%

phishing

Google's false encryption ads continue unabated, with a phishing site impersonating Uniswap stealing another $400,000

On-chain analyst "b-block" posted on social media on Monday that a counterfeit Uniswap website is stealing funds from multiple wallets, with assets held by the scammers valued at over $400,000. Stacy Muur, founder of the Web3 marketing agency Green Dots, shared screenshots of false sponsored results from search engines, criticizing Google for ignoring this issue for years, leading to fake links ranking above real ones, resulting in users continuously being scammed.According to Etherscan data, the two flagged addresses hold a total of about 146 ETH, valued at approximately $306,000. DeFiLlama pointed out that fake ads on Google are a common source of phishing attacks. The crypto nonprofit organization Security Alliance (SEAL) reported in April that phishing activities on Google searches significantly increased in March, with attackers deploying highly deceptive fake ads by paying for or hijacking legitimate ad accounts, using seemingly real URLs to bypass Google's automatic checks, and loading malicious payloads through hidden iframes.SEAL has blocked over 356 malicious ad links and stated that the volume of Google ads deployed by attackers has remained stable for over a year, with no slowdown in attack activities. Reports indicate that between March 13 and 30 alone, a total of $1.27 million was stolen. Additionally, earlier this month, there were malicious ad campaigns targeting Mac users that utilized Google ads and the AI chatbot Claude for shared chats. Malwarebytes also reported that Facebook is similarly a hotspot for fake ads and scams.

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.

Binance participates in a joint operation with the UK's NCA to combat crypto authorization phishing scams

Binance announced its participation in the international law enforcement operation "Operation Atlantic," led by the UK's National Crime Agency (NCA), in collaboration with multiple countries' law enforcement agencies to combat cryptocurrency and investment fraud, focusing on "approval phishing" scams.The operation was jointly initiated by the NCA, the U.S. Secret Service, and relevant law enforcement and regulatory agencies in Ontario, Canada, aiming to identify victims who have been compromised or are at risk. Approval phishing typically disguises itself as an investment opportunity, luring users into granting wallet access permissions, thereby transferring assets. During the operation, Binance's special investigation team provided on-site support in London, including fraud identification processes, risk screening, and intelligence analysis, and assisted in identifying potential victims and related malicious websites.At the same time, Binance also provided law enforcement agencies with addresses and suspect intelligence related to the case, supporting asset tracking and enforcement actions. The NCA stated that this operation has successfully protected thousands of potential victims in the UK and overseas. Binance emphasized that it will continue to cooperate with global law enforcement agencies to strengthen the fight against cryptocurrency fraud.
app_icon
ChainCatcher Building the Web3 world with innovations.