How exactly does a scam like this work? Access to someone's Twitter account only means that you can just post a link. People seem to have connected their wallet, but they still would need to sign a transaction after that. Did the users just auto-pilot click yes? Tangential, I can't believe the name X is actually being used by journalists, it's even worse that I expected from a sentence readability standpoint.
Vitalik Buterin reveals X account hack was caused by SIM-swap attack
81–90 of 187 posts
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#82When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
It’s much of what Elon, Trump and other populists actively foster and exploit in their fan base through relentless conspiracy theories and undermining of trust into anyone who isn’t them.
There’s a paradox here - the more people have their trust violated, the more distrustful they get, the easier they get scam as the overhead of approaching every transaction / interact in life with an adversarial mindset exhausts critical capacity and drives people into desperate savior fantasies - technological miracles, charlatans. snakeoil, the twentieths coin or pump and dump.
Zero trust (non security version - the inability to extend trust) is a miserable desperate state to be in as a human being and makes people highly vulnerable to getting taken advantage of and crypto signaling on social media either identifies you as a scammer or as a mark. You still believe technology can solve societies trust dilemma, you are asking for it at this point.
And the longer the scamming goes on, the stronger the signal of this self identifying audience becomes. It’s like responding to Nigerian prince emails at this point.
Go reddit, look at the safemoon subreddit. It’s … wild how many times you can rip off some people and have them get more militant in their belief they are smart.
As a footnote, more and more tech companies explore this to prop up shrinking profit margins. By selling previously valuable trust marks such as the top result on google (there was a time you could trust this) or flat out verification marks that previously were meant to foster Trust and Safety for money, erosion of trust becomes a profitable feature. It’s good for platforms when users cannot tell placed / bought placement and fake news from actual valuable content.
It’s just terminal for society - each time someone is scammed, has their trust betrayed, they slide a little bit closer into that state that is so exploitable by populists.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#83Earlier quoted context omitted.
Ironically, every SIM card is a cryptographic secure element, and it would've been ideal to do public key login. If you plug SIM card into desktop, you can actually do signing with it, and TLS authentication. I recall, only Nokia S60 series, and A200 had a SIM card API exposed to apps. Ios does not give you access to SIM, Android does only for system apps.
Giving apps access to the sim is a privacy leak. Every app would use it to get a unique user identifier and track you between apps.
Before you all warn me i know it is the worst possible brand to own, i am getting spied on by all the regulars that come with Android - Google/ US agencies but i also get the added bonus of China spying on the device. But i was broke.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#84Earlier quoted context omitted.
I've got an account from 2009 and have never had to enter my phone number (if I ever get asked, that'll be the time when I stop using it).
Nowadays if you create a new account it’ll get briefly banned while they do additional checks to ensure you’re human, which is fixed by giving a phone number. Id almost appreciate just asking for one on signup then the charade
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#85Earlier quoted context omitted.
I try to avoid giving my cell number, precisely because it’s not secure, but also because it changes or I travel, and then I’m locked out of my own account.
As someone who has been moving countries and subsequently changing phone numbers, every couple of years, SMS 2FA is such a pain. It's hard to recall all services that have your phone number for migrating them, and even if you do, many won't accept a foreign number. I've resorted to holding on to my old phone numbers by transferring them to prepaid SIMs.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#86Every time I hear about yet another SIM swapping attack, I feel confirmed in my decision to use Google Voice for SMS-2FA as much as possible (only for services that don't support an actually secure method, of course). Except for one certain bank that won't even accept my "real [cell] phone number" for identity verification purposes, because "it's not verifiable" (probably because it's not with the big three cell prov…
It's pretty wild how baked into modern life insecure 2fa is. Especially with the prevalence of sim swapping. I more or less model most auth as trivially insecure at this point. You think about someone like Vitalik of all people, if he can't keep his account secure...average person has their work cut out for them. Private key auth systems have security challenges of their own (losing access forever when you lose your…
One of my banks basically only accepts what they call “phone number verification” to clear a false fraud alert on my cards (or generally talk to them about anything regarding my account).
What that means is (at least I’m fairly sure) that the agent on the phone will ask me for any phone number, they ask the carrier for the name on that line and compare it with mine, and if it’s a match, they send an OTP to that number.
This is even worse than SMS-OTP, since a fraudster doesn’t even need to change my number on file with my bank – opening a phone line in my name with any of the big three carriers is enough!
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#87Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication. Scary stuff, had to give sooo much personal information over the course of months to recover a single account. Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?
For extra assurance get a hardware key that supports NFC so it can be used with your phone (and some laptops) even if it can’t be plugged in for some reason.
Multi-pronged 2FA also enables things like being able to remove a key from your account without issue if for example one turns up missing while traveling.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#88When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…
Using the account of probably one of the few trustworthy people in crypto probably helps.
The fact that some person is trustworthy by his personality traits does not imply that he does have the (also technological) skills not to become scammed or impersonated.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#89Earlier quoted context omitted.
𝕏 is just a front for a phishing scam in these cases. No money or cryptocurrency is transfered directly. Scammers get access to a popular account with many followers, and tweet something like this: https://static.news.bitcoin.com/wp-content/uploads/2023/09/v... You don't need to get everyone in the cryptocurrency space to believe you, just a few people transferring funds from their wallet will make you rich.
And the "this is free for 24h" is just a red herring, to make it legitimate for people to speculate? Still crazy that such a semi-anonymous scam got 700k, sounds like there's still a lot of money in crypto ready to gamble.
I'm no criminal, but if I were, I would definitely target cryptocurrency enthusiasts. Many of them are the perfect target, having access to large sums of money, having the ability and willingness to transfer funds in a near untraceable way, and often looking for a get-rich-quick scheme like those cryptomultimillionaires.
Things like NFT smart contract that would transfer all of your NFTs when trying to get rid of them, coupled with unpleasant pictures, coupled with cryptoclout, publicly accessible profiles, and no method to refuse a transaction, have produced some ingenious thefts that nobody would even think possible ten years ago. Millions of real world dollars have been spent on pictures of monkeys, and millions have been lost after someone stole those pictures.
Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack
#90I haven't checked, but it is possible to unlink a phone number from X? I always thought it was some anti-spam measure to have a number tied to an account.