Fun

Scammers use memecoin ‘trending’ list to lure victims — Researcher

News Feed - 2024-09-30 11:09:29

Christopher Roark10 hours agoScammers use memecoin ‘trending’ list to lure victims — ResearcherRoffet.eth found that some coins contained obscure, difficult-to-read code that allowed the developer to transfer user’s tokens to themselves.1410 Total views6 Total sharesListen to article 0:00AnalysisOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onScammers are using a “trending” list on memecoin analytics site GMGN to lure in unsuspecting victims and steal their crypto, according to a Sept. 25 X post from security researcher Roffett.eth.


The attackers create coins that allow the developer to transfer any user’s tokens to themselves. They then pass the token back and forth between multiple accounts, artificially inflating its volume and placing it on the GMGN “trending list.”


Once the coin makes it onto the trending list, unsuspecting users buy it up, thinking it is a popular coin. But within minutes, their coins are swiped from their wallets, never to be seen again. The developer then redeposits the coin into its liquidity pool and resells it to another victim.


Roffet listed Robotaxi, DFC, and Billy’s Dog (NICK) as three examples of malicious coins found on the list.


GMGN is an analytics web app that caters to memecoin traders on Base, Solana, Tron, Blast, and Ethereum. Its interface contains several different tabs, including “new pair,” “trending,” and “discover,” each of which lists coins based on different criteria.


Roffett claims to have discovered the scam technique when friends purchased coins on the list and found that they had mysteriously disappeared. One friend believed that his wallet had been hacked, but when he created a new wallet and purchased the coins again, they were again drained from his wallet.


Magazine: ​​Bankroll Network DeFi hacked, $50M phisher moves crypto on CoW: Crypto-Sec


Intrigued by the mystery, Roffett investigated the attacks using a block explorer and found that they appeared to be run-of-the-mill phishing attacks. The attacker called a “permit” function and appeared to have provided the user’s signature, which shouldn’t have been possible unless the user was tricked by a phishing site. However, the friend denied that he had interacted with suspicious websites before either of the two attacks.


One of the stolen coins was NICK. So Roffet investigated NICK’s contract code and found that it was “somewhat strange.” Instead of containing the usual stock code found in most token contracts, it had “some very odd and obfuscated methods.”


As evidence of these odd methods, Roffet posted an image of NICK’s “performance” and “novel” functions, which have unclear text with no obvious purpose.NICK performance and novel functions. Source: Roffett.eth


Eventually, Roffett discovered that the contract had malicious code inside of one of its libraries. This code allowed the “recoverer” (developer) to call the “permit” function without providing the tokenholder’s signature. Roffett stated:“If the caller"s address equals the recoverer, then by constructing a specific signature manually, one can obtain the permit permission of any token holder and then transfer the tokens.”


However, the recoverer’s address was also obscured. It was listed as a 256-bit, positive, non-zero number. Just below this number was a function that the contract used to derive the address from this number. Roffett used this function to determine that the malicious “recoverer” was a contract whose address ended in f261. 


Blockchain data shows that this “recoverer” contract has performed over 100 transactions transferring NICK tokens from the token’s holders to other accounts.Malicious account draining NICK from a user. Source: Basescan.


Having discovered how this scam worked, Roffett investigated the “trending” list and found at least two other tokens that contained similar code: Robotaxi and DFC.


Related:What is a honeypot crypto scam and how to spot it?


Roffett concluded that scammers have probably been using this technique for some time. He warned users to stay away from this list, as using it may result in them losing funds. He stated:“Malicious developers first use multiple addresses to simulate trading and holding, pushing the token onto the trending list. This attracts small retail investors to buy, and eventually, the ERC20 tokens are stolen, completing the scam. The existence of these trending lists is extremely harmful to novice retail investors. I hope everyone becomes aware of this and doesn"t fall for it.”


Scam tokens or “honeypots” continue to pose risks to crypto users. In April, a scam token developer drained $1.62 million from victims by selling them a BONKKILLER token that did not allow users to sell it. In 2022, blockchain risk management firm Solidus released a report warning that over 350 scam coins had been created over the course of the year.# Blockchain# Hackers# Tokens# Scams# Hacks# DeFi# MemecoinAdd reaction

News Feed

BitcoinUSD․com Launches a Market Watch Site
BitcoinUSD․com Launches a Market Watch Site press release PRESS RELEASE.BitcoinUSD.com, a website developed to educate the public on crypto exchanges and current prices, launched
New Study Says Number of Cryptocurrencies Now at 10,000 — Five Coins Account for 75% of Total Market Cap
New Study Says Number of Cryptocurrencies Now at 10,000 — Five Coins Account for 75% of Total Market Cap The number of known cryptocurrencies surged from 6,000 in July 2021 to 10
Top Meme Coins by Market Capitalization Shed Billions, DOGE Down 80% Since All-Time High
Top Meme Coins by Market Capitalization Shed Billions, DOGE Down 80% Since All-Time High As digital asset markets have shed significant value during the last two weeks, the top mem
Value Locked in Defi at Its Lowest Point Since March 2021, Smart Contract Tokens Shed $22 Billion in 36 Days
Value Locked in Defi at Its Lowest Point Since March 2021, Smart Contract Tokens Shed $22 Billion in 36 Days Smart contract platform tokens and decentralized finance (defi) protoco
Report: Nigerian Central Bank Incentive Scheme Failed to Halt Naira Depreciation
Report: Nigerian Central Bank Incentive Scheme Failed to Halt Naira Depreciation The Central Bank of Nigeria (CBN)’s attempt to incentivize the country’s forex market
WazirX launches bounty program to recover stolen assets
Amaka Nwaokocha12 hours agoWazirX launches bounty program to recover stolen assetsThe exchange remains focused on addressing the impact on customer funds and ensuring the security and integrity of their platform.7945 Tot
Alibaba Suspends Sale of Cryptocurrency Mining Hardware on Its Platform
Alibaba Suspends Sale of Cryptocurrency Mining Hardware on Its Platform Alibaba, the Chinese e-commerce giant, has announced it will no longer allow the sale of cryptocurrency mini
Former FTX CEO Sam Bankman-Fried Faces New Charges in Multi-Billion Dollar Fraud Case
Former FTX CEO Sam Bankman-Fried Faces New Charges in Multi-Billion Dollar Fraud Case Sam Bankman-Fried (SBF), the disgraced co-founder of FTX, faces four more charges after a new
Bitcoin Law Critic Arrested in El Salvador Without Warrant
Bitcoin Law Critic Arrested in El Salvador Without Warrant A vocal critic of the upcoming bitcoin law in El Salvador, Mario Gomez, was briefly detained Wednesday. According to repo
Cointext Cofounder Unveils BFP Encrypt – Send Encrypted Data to Bitcoin Cash Addresses
Cointext Cofounder Unveils BFP Encrypt - Send Encrypted Data to Bitcoin Cash Addresses Vin Armani, the cofounder of Cointext, has announced the launch of a Javascript library tha
SWIFT Is Experimenting With Decentralized Technologies to Allow CBDC Interconnection
SWIFT Is Experimenting With Decentralized Technologies to Allow CBDC Interconnection SWIFT, the interbank payments protocol and messaging system, has announced it is working to con
Here’s why US debt is out of control — and Japanese debt isn’t
Lucas Kiely8 hours agoHere’s why US debt is out of control — and Japanese debt isn’tJapanese debt might be high, but it isn"t comparable to American debt, which is set to trigger a financial implosion — and light