Fun

News Feed - 2023-09-08 05:09:00

Ezra Reguerra19 minutes agoSecurity platforms warn about hidden phishing and wallet drainer linksCybersecurity professional Christian Seifert gave an example on how Discord"s measure against malicious links can be abused by scammers.72 Total viewsListen to article 0:00Follow upJoin us on social networksWith millions of dollars worth of assets being lost to phishing attacks after signing malicious permissions, the threat of losing crypto assets from questionable links is very real. When these are paired with platforms allowing hidden links, users are subjected to a different kind of risk. 


On Sept. 4, Web3 security provider Pocket Universe shared how scammers are able to hide wallet drainer links on any text on the instant messaging platform Discord. While some users report that the feature has only been enabled for Discord users recently, the ability to embed links on any text has been available on many different social platforms for a while now.Scammers can now hide links in any discord text ☠️

Watch out for hidden wallet drainer links

e.g. pic.twitter.com/mgqG18sOF9— Pocket Universe (@PocketUniverseZ) September 4, 2023


Cointelegraph reached out to several cybersecurity professionals to learn more about how users can protect themselves from such attempts and how platforms can improve their security so that users are not subjected to such attacks. 


Christian Seifert, who works as a Researcher in Residence at Web3 security firm Forta Network, said that this type of attack has been the bread and butter of hackers since the internet was created. He explained that:“Whatever a platform creates, there will be a hacker ready to find a way to hack it. Hyperlinks with text are a feature supported as part of HTML and have been a source for phishing attacks since the early days of the internet.”


According to Seifert, security requires an in-depth defense approach. “Both platforms and users need to work towards protecting themselves,” he said. From the user’s side, the security professional highlighted that there are plugins that they can use to protect themselves from such scams.


When it comes to Discord, Seifert pointed out that the platform does provide information on the true destination of the URL after the user clicks on it. However, the platform also allows users to “trust” a domain going forward. This can be abused by scammers according to Seifert. He explained:“Imagine a domain like foo.bar which the user trusted. A scammer can craft a potentially malicious link that performs some action on this domain, such as an oauth request to the scammer, like foo.bar/oauth/scammer-account.”


The cybersecurity professional said that an issue with the platform’s current implementation is that links and text can be deceptive and misaligned with users’ expectations. “If a text link clearly resembles a domain or URL and it is mismatched to the true destination URL, Discord should disallow such links,” he added.


Related:Exploits, hacks and scams stole almost $1B in 2023: Report


Meanwhile, Hugh Brooks, the director of security operations at the blockchain security firm CertiK, echoed some of Seifert’s sentiments. According to Brooks, users and platforms have a collective responsibility to watch out for malicious actors. He explained that it’s essential for platforms to continually review and refine their security features and for users to stay vigilant and educated.


For users, Brooks said that they should be proactive and cautious when it comes to links, especially when being asked for signatures and permissions. The executive urged users to verify the authenticity of the site address before giving it access to crypto wallets. Brooks shared:“A good practice is to cross-check web addresses with recognized phishing warning lists. PhishTank, Google Safe Browsing, and OpenPhish are valuable resources here, along with browser extensions like HTTPS Everywhere and ad blockers like uBlock.”


Brooks explained that these tools can alert users in real time whenever they are about to visit known phishing or malicious websites. “Furthermore, by simply hovering over a URL link, the actual web address will be displayed, allowing users to confirm its legitimacy before engaging further,” he added.


On the platform’s side, the cybersecurity professional said that there are measures that can be implemented such as being able to only receive messages from trusted contacts. Brooks said that a good example of this is Meta’s “Facebook Protect,” which lets users have heightened security features for their accounts.


“As the saying goes, the only constant is change. Platforms owe it to their users and to their continued relevance to make security a priority. This involves not only updating security measures but also fostering a culture of vigilance and awareness among users,” he added.


Magazine:Should crypto projects ever negotiate with hackers? Probably# Blockchain# Security# Hackers# Cybersecurity# HacksAdd reactionAdd reactionRead moreWhat is profit and loss (PnL) and how to calculate itIf Worldcoin can improve the world, why not give it a chance?ChatGPT-coded smart contracts may be flawed, could ‘fail miserably’ when attacked: CertiK

News Feed

JPMorgan Lowers Its Bitcoin Fair Price Estimate to $38K Amidst Volatility
JPMorgan Lowers Its Bitcoin Fair Price Estimate to $38K Amidst Volatility Leading investment bank JPMorgan has changed its view on the estimate of bitcoin’s price on a long-
Bank of America’s Survey of Wealthy Americans: Younger People Are 7.5 Times More Likely to Hold Crypto in Their Portfolios
Bank of America"s Survey of Wealthy Americans: Younger People Are 7.5 Times More Likely to Hold Crypto in Their Portfolios Bank of America has found that younger wealthy Americans
Crypto Is a ‘Major Priority’ for Miami Mayor Building City Into Crypto Capital of the World
Crypto Is a "Major Priority" for Miami Mayor Building City Into Crypto Capital of the World Miami Mayor Francis Suarez says that cryptocurrency is a “major priority”
Nigeria’s Binance crackdown threatens Web3 industry
Amaka Nwaokocha10 hours agoNigeria’s Binance crackdown threatens Web3 industryAccording to Uwakwe, the head of Nigeria’s crypto intercommunity working group, investors worry about potential repercussions similar to B
Bank of Russia to Promote Digital Ruble in Foreign Trade as Finance Ministry Pushes for Crypto Option
Bank of Russia to Promote Digital Ruble in Foreign Trade as Finance Ministry Pushes for Crypto Option Days after the two institutions agreed on the need for cross-border crypto pay
Technical Analysis: Cosmos Climbs Higher, While Solana’s Fall Continues
Technical Analysis: Cosmos Climbs Higher, While Solana"s Fall Continues After trading lower for the majority of Monday’s session, cryptocurrency prices were slowly starting
USDC Stablecoin Depegging Causes Concern Among Crypto Advocates, 5 Other Stablecoins Slip Below Parity
USDC Stablecoin Depegging Causes Concern Among Crypto Advocates, 5 Other Stablecoins Slip Below Parity On Saturday, March 11, 2023, crypto advocates are concerned as a few stableco
Cardano Slips to 5th-Largest Crypto Market Position — ADA Down 30% Since All-Time High Last Month
Cardano Slips to 5th-Largest Crypto Market Position — ADA Down 30% Since All-Time High Last Month During the second week of October, bitcoin market values have maintained prices
The World’s Weakest Currency, Kiyosaki Says Greenback Is ‘Toast,’ IRS Crypto Tax Update and More — Bitcoin.com News Week in Review
The World"s Weakest Currency, Kiyosaki Says Greenback Is "Toast," IRS Crypto Tax Update and More — Bitcoin.com News Week in Review In this week’s hottest stories from Bitco
Thai regulator cracks down on deceptive crypto ads
Arijit Sarkar1 hour agoThai regulator cracks down on deceptive crypto adsRegulators from key crypto markets, including the United Kingdom and Spain, have also taken similar measures against misleading crypto advertisemen
Digital Yuan Giveaway: China’s Shenzhen City Hands Out 10 Million Yuan in Central Bank Digital Currency
Digital Yuan Giveaway: China"s Shenzhen City Hands Out 10 Million Yuan in Central Bank Digital CurrencyA major Chinese city is giving away 10 million yuan in the country’s cen
Turner Wright2 hours agoBlackRock’s spot Bitcoin ETF now listed on Nasdaq trade clearing firm — Bloomberg analystExchange-traded fund analyst Eric Balchunas said the addition was “all part of the process” of a cr