• About Us
  • FAQ
Login/Registration
Blog
  • Home
  • Blog
    • Guide
    • Regulation
    • Ripple
  • Market
  • Blockchain
  • Bitcoin
  • Ethereum
  • Reviews
  • Contact Us
No Result
View All Result
  • Home
  • Blog
    • Guide
    • Regulation
    • Ripple
  • Market
  • Blockchain
  • Bitcoin
  • Ethereum
  • Reviews
  • Contact Us
No Result
View All Result
Blog
No Result
View All Result
Home Bitcoin

Crypto-Sec: Phishing scammer goes after Hedera users, address poisoner gets $70K

189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Crypto-Sec is our bi-weekly round-up of crypto and cybersecurity stories and tips.

Biggest phish of the week: Attacker targets Hedera users

Related articles

Crypto projects prepare to battle for privacy in Switzerland

April 28, 2025

Crypto ETPs hit 3rd-largest inflows on record at $3.4B — CoinShares

April 28, 2025

On June 26 a marketing email for Hedera was hacked, with the attacker sending out phishing emails to the teams subscribers. Hedera is the developer of Hedera Hashgraph, a proof-of-stake blockchain network launched in 2018.

The team acknowledged the hack in a post to X and warned users not to interact with any links in emails from marketing@hedera.

Hedera

@hedera

The marketing@hedera email has been compromised. Do not open any emails or links from this address. We’ll provide more details soon.

Jun 26, 2024

Phishing is a technique where an attacker poses as a trusted source and convinces the user to give away information or to perform an action the attacker desires. In this case, the attacker used the compromised Hedera email to pretend to be a representative of the development team.

The team has not yet disclosed what was in the phishing emails. However, most crypto phishing emails offer the user an enticing reward, such as a token airdrop, if they click on a link to navigate to the attackers fake website, which often appears to be from a trusted source. When the user connects to the website with their wallet, they are asked to authorize token approvals to receive the airdrop.

But instead of allowing the user to obtain the airdrop, these approvals allow the attacker to drain the users wallet. Users should consider being extra cautious when clicking links from emails, even if the emails come from what appears to be a trusted source. As the Hedera example illustrates, even trusted email addresses can be hacked or spoofed.

The Hedera team promised to provide more details soon. Cointelegraph could not determine how much crypto, if any, was lost due to the phishing emails at the time of publication.

White hat corner: MoveIt file transfer vulnerability is patched

Security researchers discovered a critical vulnerability in the MoveIt file transfer software developed by Progress, according to an official bulletin from the softwares development team. However, the vulnerability has been patched in its current version.

Some large businesses use MoveIt Transfer to transfer files between employees. These files could contain customer data, private keys or other sensitive information. According to a report from cybersecurity firm Watchtower Labs, the vulnerability allowed an attacker to impersonate any user on an enterprises network as long as the attacker knew the users username.

To perform the attack, the hacker needed to supply the server with a username. In response, the server would ask for the users private key. But instead of producing the real key (which the attacker presumably wouldnt know), they could supply a file path containing a fake key they generated themselves.

Because of peculiarities in the way the MoveIt software handled this situation, it would produce an empty string as the public key. As a result, the authentication would appear to fail. However, Watchtower discovered that although the authentication would produce an error message and seem to fail, the crucial statuscode variable used to block invalid users would treat the attacker as if they had properly authenticated.Read also Features

Aligned Incentives: Accelerating Passive Crypto AdoptionFeatures

NFT collapse and monster egos feature in new Murakami exhibition

As a result, the attacker would be able to access any files that the real user could access, allowing them to gain sensitive client or customer data.

Progress patched the vulnerability on June 25. However, some businesses may not have upgraded to the latest version yet. The developer stated, We strongly urge all MOVEit Transfer customers on versions 2023.0, 2023.1 and 2024.0 to upgrade to the latest patched version immediately.

The company said that MoveIt Cloud is unaffected by the vulnerability, as it has already been patched.

Address poisoning attack

Blockchain security firm Cyvers detected a large address poisoning attack on June 28. The victim lost over $70,000 worth of USDT.

Cyvers Alerts

@CyversAlerts

ALERTOur AI-powered system has detected an address poisoning attack. https://t.co/P9B1inEQ9N

The attacker initiated the poison transaction two days ago: https://t.co/VEQrT4VXYL

Unfortunately, 23 hours ago, the victim mistakenly sent 70k USDT to the scammer.

The funds are pic.twitter.com/Klq9KUSlTo

Jun 28, 2024

The attack began on June 25, when the victim transferred 10,000 USDT to a Binance deposit address that began with 0xFd0C0318 and ended with 1630C11B.

Shortly afterward, the attacker sent 10,000 fake USDT from the victims account to an account under the attackers control. This transfer was not authorized by the victim, but because the fake token contained a malicious transfer function, it was successful.

The address these fake tokens were sent to began with 0xFd0Cc46B and ended with 6430c11B, containing the same first six and last four characters as the victims Binance deposit address. The attacker likely used a vanity address generator to create this similar-looking address.

Two days later, on June 27, the victim sent 70,000 USDT to this malicious address. The victim probably cut and pasted the address from their transaction history, intending to deposit the funds to Binance. However, Binance did not receive the funds, and they are now in the attackers hands.

The Tether development team can freeze wallet addresses holding USDT. However, they will generally only freeze an address after a request from law enforcement. At the time of publication, this wallet still holds USDT and has not yet swapped it for other tokens, so a freeze may have already occurred. If the address has not yet been frozen, there is still time to make a complaint, and the victim may yet get their funds back.

However, it is also possible that the attacker may swap the USDT for Ether or other cryptocurrencies before the address is frozen, in which case the funds will be much more difficult to recover.

Crypto users should be aware that some wallet applications load transaction history directly from the blockchain. As a result, they sometimes show transactions as being from the user when they are, in fact, from a third party. Users are advised to check all characters of an address before sending a transaction, not just the first and last characters.

Unfortunately for this user, they may have learned this lesson at a high price, as they could be $70,000 poorer as a result of this mistake.

Centralized exchanges

On June 22, Istanbul-based crypto exchange BtcTurk was exploited via a stolen private key. The exchange acknowledged the attack on the following day. According to a Google translation, the statement read in part, Dear user, our teams have detected that there was a cyber attack on our platform on June 22, 2024, which caused uncontrollable [losses] to be taken. 

The exchange stated that the attack was only performed against its hot wallets, and the bulk of its assets remain safe. It also claimed that it has enough financial strength to pay back users for the losses and that customer balances will be unaffected.

Cybersecurity firm Halborn estimated that BtcTurk lost over $55 million in the attack.

According to onchain sleuth ZackXBT, the attacker likely deposited 1.96 million AVAX ($54.2 million) to centralized exchanges Coinbase, Binance and Gate, which was subsequently swapped for Bitcoin, as onchain data shows nearly equivalent values of BTC being transferred out of these exchanges right after the AVAX was transferred in.

AVAX fell by 10%, apparently as a result of these swaps.

Cointelegraph

Reported attacker deposits to and from centralized exchanges. Source: (ZachXBT, Telegram)

Since the attack, BtcTurk has launched new hot wallets with private keys that are not under the attackers control. The exchange has strongly advised users not to use old deposit addresses, as any funds sent to them will likely be stolen by the attacker. Instead, users should deposit using new addresses found within the apps interface.Subscribe The most engaging reads in blockchain. Delivered once a week.

Email address

SUBSCRIBE

Subscribe to Magazine by Cointelegraph Newsletter.
Cointelegraph
Share76Tweet47

Related Posts

Crypto projects prepare to battle for privacy in Switzerland

by Gulfam Tasawar
April 28, 2025
0

Switzerland has long been seen as a beacon of privacy where companies, organizations and wealthy people put down roots in...

Crypto ETPs hit 3rd-largest inflows on record at $3.4B — CoinShares

by Gulfam Tasawar
April 28, 2025
0

Cryptocurrency exchange-traded products (ETPs) bounced back with their third-largest inflows on record last week, according to CoinShares. Global crypto ETPs...

Bitcoin, crypto ‘dip buy hype’ is now at its highest level in 7 months

by firoz
February 28, 2025
0

Social media mentions of crypto dip buying have rocketed to their highest level since last July amid a crypto market...

Bitcoin Threat – Last chance is now! Or crash to 40k! (-63%)

by firoz
February 27, 2025
0

Bitcoin crashed by 12% in the past few days to 86,800, exactly to the last available support of the whole...

Bitconnect Shuts Down After Accused Of Running A Ponzi Scheme

by firoz
February 27, 2025
0

Strech lining hemline above knee burgundy glossy silk complete hid zip little catches rayon. Tunic weaved strech calfskin spaghetti straps...

Load More
  • Trending
  • Comments
  • Latest

112,000 ETH Moved To Crypto Exchanges In The Past Day — Impact On Ethereum Price?

September 27, 2024

US Commodities Regulator Beefs Up Bitcoin Futures Review

February 16, 2024

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

February 15, 2024
USD/JPY: Dollar Edges Higher Above ¥157 in Sixth Straight Day of Gains

USD/JPY: Dollar Edges Higher Above ¥157 in Sixth Straight Day of Gains

May 30, 2024

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0

Crypto projects prepare to battle for privacy in Switzerland

April 28, 2025

Crypto ETPs hit 3rd-largest inflows on record at $3.4B — CoinShares

April 28, 2025

Bitcoin, crypto ‘dip buy hype’ is now at its highest level in 7 months

February 28, 2025

Bitcoin Threat – Last chance is now! Or crash to 40k! (-63%)

February 27, 2025

Blog




We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.





Categories tes

  • 1w
  • 1Win AZ Casino
  • 1Win Brasil
  • 1win Brazil
  • 1win India
  • 1WIN Official In Russia
  • 1win Turkiye
  • 1win uzbekistan
  • 1winRussia
  • 1xbet Casino AZ
  • 1xbet Korea
  • 1xbet Morocco
  • 1xbet russia
  • 1xbet russian1
  • 22bet IT
  • 888starz bd
  • anonymous
  • Aviator
  • aviator brazil
  • aviator ng
  • Bankobet
  • Basaribet
  • bbrbet colombia
  • bbrbet mx
  • Bitcoin
  • bizzo casino
  • Blockchain
  • Business
  • casino
  • casino en ligne fr
  • casino onlina ca
  • casino online ar
  • casinò online it
  • casinos
  • crazy time
  • Crypto
  • Ethereum
  • Gama Casino
  • general
  • Guide
  • KaravanBet Casino
  • Kasyno Online PL
  • king johnnie
  • Market
  • Masalbet
  • mostbet hungary
  • mostbet ozbekistonda
  • Mostbet Russia
  • mostbet tr
  • online casino au
  • Pin Up Brazil
  • Pin Up Peru
  • pinco
  • plinko_pl
  • Qizilbilet
  • Ramenbet
  • Regulation
  • ricky casino australia
  • Ripple
  • se
  • slot
  • Slots
  • sweet bonanza TR
  • Uncategorized
  • verde casino hungary
  • Комета Казино
  • Швеция

Tags

Altcoin Bitcoin drops Bitcoin Wallet Cointelegraph Cryptocurrency ICO Investment Lending Market Stories Mining Bitcoin Промокоды ПокерДом при регистрации мотоцикл

Newsletter

  • About
  • FAQ
  • Contact Us

© 2024 copyright by Trading-Tracker.com

No Result
View All Result
  • Home
  • Blog
    • Guide
    • Regulation
    • Ripple
  • Market
  • Blockchain
  • Bitcoin
  • Ethereum
  • Reviews
  • Contact Us

© [current_year] copyright by Trading-Tracker.com