• bitcoinBitcoin (BTC) $ 117,942.00
  • ethereumEthereum (ETH) $ 3,702.10
  • xrpXRP (XRP) $ 3.51
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 746.56
  • solanaSolana (SOL) $ 180.02
  • usd-coinUSDC (USDC) $ 0.999810
  • dogecoinDogecoin (DOGE) $ 0.251456
  • staked-etherLido Staked Ether (STETH) $ 3,693.48
  • cardanoCardano (ADA) $ 0.849634
  • tronTRON (TRX) $ 0.319422
  • wrapped-stethWrapped stETH (WSTETH) $ 4,464.50
  • hyperliquidHyperliquid (HYPE) $ 45.46
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 117,822.00
  • stellarStellar (XLM) $ 0.468387
  • suiSui (SUI) $ 3.95
  • chainlinkChainlink (LINK) $ 19.35
  • hedera-hashgraphHedera (HBAR) $ 0.274224
  • avalanche-2Avalanche (AVAX) $ 24.96
  • bitcoin-cashBitcoin Cash (BCH) $ 526.94
  • wrapped-eethWrapped eETH (WEETH) $ 3,963.74
  • litecoinLitecoin (LTC) $ 117.97
  • shiba-inuShiba Inu (SHIB) $ 0.000015
  • wethWETH (WETH) $ 3,701.03
  • leo-tokenLEO Token (LEO) $ 9.00
  • the-open-networkToncoin (TON) $ 3.26
  • polkadotPolkadot (DOT) $ 4.46
  • usdsUSDS (USDS) $ 0.999856
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • whitebitWhiteBIT Coin (WBT) $ 44.44
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 117,881.00
  • uniswapUniswap (UNI) $ 10.52
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • moneroMonero (XMR) $ 324.72
  • pepePepe (PEPE) $ 0.000014
  • bitget-tokenBitget Token (BGB) $ 5.02
  • aaveAave (AAVE) $ 325.38
  • bittensorBittensor (TAO) $ 427.61
  • crypto-com-chainCronos (CRO) $ 0.121031
  • ethereum-classicEthereum Classic (ETC) $ 24.87
  • daiDai (DAI) $ 0.999909
  • nearNEAR Protocol (NEAR) $ 2.98
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • aptosAptos (APT) $ 5.41
  • pi-networkPi Network (PI) $ 0.445851
  • ondo-financeOndo (ONDO) $ 1.06
  • internet-computerInternet Computer (ICP) $ 5.95
  • ethenaEthena (ENA) $ 0.485473
  • okbOKB (OKB) $ 49.05
  • jito-staked-solJito Staked SOL (JITOSOL) $ 218.71
  • mantleMantle (MNT) $ 0.800999
  • algorandAlgorand (ALGO) $ 0.301229
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bonkBonk (BONK) $ 0.000034
  • kaspaKaspa (KAS) $ 0.096740
  • arbitrumArbitrum (ARB) $ 0.481142
  • vechainVeChain (VET) $ 0.028411
  • cosmosCosmos Hub (ATOM) $ 5.19
  • render-tokenRender (RENDER) $ 4.35
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,711.62
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.246176
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • gatechain-tokenGate (GT) $ 17.57
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.800253
  • worldcoin-wldWorldcoin (WLD) $ 1.19
  • official-trumpOfficial Trump (TRUMP) $ 10.39
  • sei-networkSei (SEI) $ 0.358584
  • filecoinFilecoin (FIL) $ 2.84
  • fasttokenFasttoken (FTN) $ 4.51
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030745
  • susdssUSDS (SUSDS) $ 1.06
  • skySky (SKY) $ 0.083585
  • binance-staked-solBinance Staked SOL (BNSOL) $ 191.30
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,875.24
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,216.31
  • spx6900SPX6900 (SPX) $ 1.83
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 117,788.00
  • quant-networkQuant (QNT) $ 114.97
  • jupiter-exchange-solanaJupiter (JUP) $ 0.553128
  • pump-funPump.fun (PUMP) $ 0.004614
  • xdce-crowd-saleXDC Network (XDC) $ 0.097427
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.98
  • kucoin-sharesKuCoin (KCS) $ 12.10
  • celestiaCelestia (TIA) $ 2.14
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997412
  • fartcoinFartcoin (FARTCOIN) $ 1.47
  • injective-protocolInjective (INJ) $ 14.87
  • usdtbUSDtb (USDTB) $ 0.999643
  • flare-networksFlare (FLR) $ 0.020331
  • story-2Story (IP) $ 4.75
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,890.41
  • curve-dao-tokenCurve DAO (CRV) $ 0.999315
  • usdt0USDT0 (USDT0) $ 1.00
  • blockstackStacks (STX) $ 0.856525
  • optimismOptimism (OP) $ 0.772715
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,952.52
  • nexoNEXO (NEXO) $ 1.34
  • flokiFLOKI (FLOKI) $ 0.000138
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,997.82
  • sonic-3Sonic (S) $ 0.394069
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,893.57
  • immutable-xImmutable (IMX) $ 0.638056
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 117,745.00
  • tezosTezos (XTZ) $ 1.15
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.79
  • the-graphThe Graph (GRT) $ 0.113639
  • dogwifcoindogwifhat (WIF) $ 1.11
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 201.62
  • lido-daoLido DAO (LDO) $ 1.21
  • kaiaKaia (KAIA) $ 0.170726
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • wbnbWrapped BNB (WBNB) $ 747.42
  • vaultaVaulta (A) $ 0.610820
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 117,804.00
  • pax-goldPAX Gold (PAXG) $ 3,355.01
  • theta-tokenTheta Network (THETA) $ 0.943789
  • ethereum-name-serviceEthereum Name Service (ENS) $ 28.35
  • iotaIOTA (IOTA) $ 0.238777
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.68
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • clbtcclBTC (CLBTC) $ 119,225.00
  • galaGALA (GALA) $ 0.019784
  • msolMarinade Staked SOL (MSOL) $ 235.14
  • paypal-usdPayPal USD (PYUSD) $ 0.999891
  • jasmycoinJasmyCoin (JASMY) $ 0.017165
  • the-sandboxThe Sandbox (SAND) $ 0.337363
  • tether-goldTether Gold (XAUT) $ 3,348.35
  • super-oethSuper OETH (SUPEROETH) $ 3,701.11
  • pyth-networkPyth Network (PYTH) $ 0.139363
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,954.65
  • aerodrome-financeAerodrome Finance (AERO) $ 0.915899
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,865.80
  • raydiumRaydium (RAY) $ 2.87
  • pendlePendle (PENDLE) $ 4.62
  • conflux-tokenConflux (CFX) $ 0.147573
  • saros-financeSaros (SAROS) $ 0.279117
  • tokenize-xchangeTokenize Xchange (TKX) $ 9.12
  • zcashZcash (ZEC) $ 44.91
  • bittorrentBitTorrent (BTT) $ 0.00000073
  • jito-governance-tokenJito (JTO) $ 2.00
  • ousgOUSG (OUSG) $ 111.86
  • flowFlow (FLOW) $ 0.439509
  • heliumHelium (HNT) $ 3.78
  • morphoMorpho (MORPHO) $ 2.15
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998352
  • decentralandDecentraland (MANA) $ 0.348284
  • falcon-financeFalcon USD (USDF) $ 0.999966
  • tbtctBTC (TBTC) $ 117,706.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.251798
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,699.78
  • chain-2Onyxcoin (XCN) $ 0.018683
  • telcoinTelcoin (TEL) $ 0.006945
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • mog-coinMog Coin (MOG) $ 0.000002
  • walrus-2Walrus (WAL) $ 0.450952
  • bitcoin-svBitcoin SV (BSV) $ 31.05
  • newton-projectAB (AB) $ 0.008769
  • based-brettBrett (BRETT) $ 0.060038
  • thorchainTHORChain (RUNE) $ 1.69
  • memecoreMemeCore (M) $ 0.353840
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 117,286.00
  • usual-usdUsual USD (USD0) $ 0.997590
  • stader-ethxStader ETHx (ETHX) $ 3,938.65
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,693.41
  • reserve-rights-tokenReserve Rights (RSR) $ 0.009675
  • ether-fiEther.fi (ETHFI) $ 1.33
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 117,979.00
  • coredaoorgCore (CORE) $ 0.553626
  • apecoinApeCoin (APE) $ 0.690604
  • usddUSDD (USDD) $ 1.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,701.03
  • beldexBeldex (BDX) $ 0.074784
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,082.82
  • ripple-usdRipple USD (RLUSD) $ 0.999966
  • wrapped-hypeWrapped HYPE (WHYPE) $ 45.55
  • starknetStarknet (STRK) $ 0.145132
  • dydx-chaindYdX (DYDX) $ 0.691858
  • neoNEO (NEO) $ 7.31
  • build-onBUILDon (B) $ 0.516170
  • savings-daiSavings Dai (SDAI) $ 1.16
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.60
  • compound-governance-tokenCompound (COMP) $ 53.80
  • deepDeepBook (DEEP) $ 0.201573
  • arweaveArweave (AR) $ 7.70
  • elrond-erd-2MultiversX (EGLD) $ 17.40
  • true-usdTrueUSD (TUSD) $ 0.997474
  • aioz-networkAIOZ Network (AIOZ) $ 0.411558
  • swethSwell Ethereum (SWETH) $ 3,984.60
  • ecasheCash (XEC) $ 0.000024
  • venomVenom (VENOM) $ 0.226862
  • syrupMaple Finance (SYRUP) $ 0.433387
  • kavaKava (KAVA) $ 0.427701
  • axie-infinityAxie Infinity (AXS) $ 2.77
  • apenftAPENFT (NFT) $ 0.00000046
  • 1inch1inch (1INCH) $ 0.324097
  • zksyncZKsync (ZK) $ 0.061788
  • frax-etherFrax Ether (FRXETH) $ 3,684.68
  • staked-hypeStaked HYPE (STHYPE) $ 45.42
  • chilizChiliz (CHZ) $ 0.044549

Your BTC can be swiped by spoofers without them even contacting you

0 25

Your BTC can be swiped by spoofers without them even contacting you

Cybersecurity researchers have published fascinating new details of communication-free theft affecting bitcoin (BTC) savers.

Purposefully targeting hard-working laborers who dollar cost average (DCA) into BTC with regular purchases, a new attack steals coins without even establishing contact with the victim.

Jameson Lopp blogged notes for his MIT Bitcoin Club Expo speech about this tactic that he calls an “address poisoning attack.” A form of spoofing, the exploit manipulates wallet interfaces’ displays and copy-and-pastes defaults.

Here’s a step-by-step guide to how the attack works.

The bitcoin address poisoning attack

First, the attacker identifies someone who is regularly sending BTC to the exact same hardware wallet address for a consistent period of time — usually weeks or months. These might be DCA BTC savers, BTC merchants, or other users who reuse addresses consistently.

Next, the attacker utilizes a vanity address creator to create a fake wallet that has identical leading and trailing characters to the victim’s frequently-used wallet.

Then, the attacker dusts a tiny amount of BTC to the victim using the vanity address.

The victim then opens their own wallet software and copies their most recent address from their transaction history.

It’s at this point that the theft occurs. If the victim pastes the spoofed vanity address and checks only a few leading and trailing characters and then sends their BTC, they have just sent money to the thief.

In summary, the attack tricks users into sending BTC to the hacker’s vanity address that shares the same leading and trailing characters as the victim’s otherwise authentic wallet.

Dusting to lure BTC victims

Lopp credited Mononaut with first flagging this attack. Mononaut described it as an “address poisoning dust attack” because the attacker sends a small amount of BTC or “dust” to an address in order to execute it.

Lopp simply removed the word “dust” from his naming convention for simplicity.

The attack is elegant in that the attacker never needs to communicate with the victim. Instead, the hacker simply researches prime targets who regularly re-use addresses, dusts their wallet with a vanity address, and then waits for the victim to copy-and-paste from their transaction history.

This tactic is especially difficult for an average user to detect because the spoofed addresses match many characters of an otherwise legitimate address.

This can trick users who often do not view much more than the beginning and end of the address displayed in their wallet’s transaction history.

Sadly, vanity address generators can mass-produce cheap spoof addresses for this type of attack. Already, victims have fallen for the spoof and voluntarily sent funds to fake wallets.

Less than $1 per poisoning attack

Of course, the attack is not entirely free. The dusting process is the most expensive part because it requires an on-chain transaction and at least some amount of BTC.

Mononaut estimated that one attacker was spending about 60 cents per dust, which definitely adds up across the 1,400 remaining potential victims.

For BTC users interested in protecting themselves from this type of attack, Lopp and Mononaut recommend several practices.

First, users should verify the entire address, character-for-character.

Second, users should avoid reusing addresses. For privacy and security reasons, it’s always best practice to generate a new wallet for every BTC transaction.

Third, they shouldn’t copy addresses from their transaction history and trust that address for a new transaction. Instead, they should independently check every character for each new transaction.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights