There are ways in which people claiming to be from a16z could authenticate themselves in DMs, using services like b2v.xyz
.xyz, the TLD that screams legitimacy.
Phishing scammers impersonate AH employee to drain crypto wallets
11–20 of 40 posts
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#12Re: Phishing scammers impersonate AH employee to drain crypto wallets
#13Personally I installed a few of these. I remember when running Google Meet without Chrome required some plugin and when Zoom required admin password every now and then to perform an update (even after the Mac vulnerability incident[1]).
I hope I'll think twice next time I see a prompt to install a plugin like this.
[1]: https://techcrunch.com/2019/07/10/apple-silent-update-zoom-a...
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#14AH == a16z it seems.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#15Re: Phishing scammers impersonate AH employee to drain crypto wallets
#16This works because we've been conditioned to install videochat plugins, no matter the security warnings. Personally I installed a few of these. I remember when running Google Meet without Chrome required some plugin and when Zoom required admin password every now and then to perform an update (even after the Mac vulnerability incident[1]). I hope I'll think twice next time I see a prompt to install a plugin like this…
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#17Re: Phishing scammers impersonate AH employee to drain crypto wallets
#18Title should be "Phishing scammers impersonate Andreessen Horowitz employee to drain crypto wallets"
I tried that. Too long. Not essential anyway, IMO, the attack is much more interesting than the victim's employer's name.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#19What's scary is if you google Vortax, it comes up like a totally legit videochat app.
Re: Phishing scammers impersonate AH employee to drain crypto wallets
#20This works because we've been conditioned to install videochat plugins, no matter the security warnings. Personally I installed a few of these. I remember when running Google Meet without Chrome required some plugin and when Zoom required admin password every now and then to perform an update (even after the Mac vulnerability incident[1]). I hope I'll think twice next time I see a prompt to install a plugin like this…
It worked partly because the company website listed the scammer’s Twitter handle as legit