Live data from Hacker News

Phishing scammers impersonate AH employee to drain crypto wallets

web3isgoinggreat.com

21–30 of 40 posts

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#21
Repudiation is one of the most important features of existing commerce systems and until there's a crypto system that considers that a requirement instead of a cute little non sequitur then nobody serious will ever take crypto currency seriously.

It's just a bunch of pyromaniacs repeatedly burning themselves an each other and saying, "huh, that's weird."

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#22
Twitter (I refuse to use the artist formerly known as bs), considering its great leader, should have detected this before it even went out.

Instead, a user who hasn't been active on Twitter for some time can do something totally benign, not even including messaging or posting, and get flagged as suspicious.

Meanwhile, an account handle changes, and the old one is reclaimed by someone else. And then very suspicious messages get sent. This should be reasonably detectable with less false negatives than what they subject the rest of us to already.

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#23

Title should be "Phishing scammers impersonate Andreessen Horowitz employee to drain crypto wallets"

Or "A16z" at least...

I had to quickly check that my Albert Heijn bonus account hadn't been robbed!

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#24
post #10
post #6

What's scary is if you google Vortax, it comes up like a totally legit videochat app.

Was able to find one article calling it out, https://davidgerard.co.uk/blockchain/2024/04/03/vortax-a-fak... Genius approach on their part tho. The landing page looks legit, the site even has blog posts.

nowadays this is so much easier to generate.

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#26
post #5

Earlier quoted context omitted.

I tried that. Too long. Not essential anyway, IMO, the attack is much more interesting than the victim's employer's name.

The only reason I clicked the link was to know what AH meant. Phishing for crypto assets is nothing new, I wouldn’t have clicked it for that.

If I understand the attack correctly:

Twitter followers were migrated, but anyone "following" using something like a crontab that retrieves a link based on the old Twitter name might be fooled.

Even that is apparently not to fringe to work for phishing.

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#27

Why installing an app allows to "drain wallets"? Why does a video chat app, which is installed from untrusted source, have an access to a wallet private key? Why OS allows this?

There is no way to prevent this on the OS level without making an OS as locked down as iOS.

Anything less, and the user will find a way to accidentally give admin permissions to random apps.

NB: I don't believe that it's the OS's job to protect the user from themselves. Shielding people from consequences of their own actions results in people making worse mistakes later on.

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#29
post #10

Earlier quoted context omitted.

Was able to find one article calling it out, https://davidgerard.co.uk/blockchain/2024/04/03/vortax-a-fak... Genius approach on their part tho. The landing page looks legit, the site even has blog posts.

nowadays this is so much easier to generate.

The barrier to entry of making legit-looking scams has never been very high, to the point where I don't believe them being even easier to generate makes any difference

Re: Phishing scammers impersonate AH employee to drain crypto wallets

#30
post #26

Earlier quoted context omitted.

The only reason I clicked the link was to know what AH meant. Phishing for crypto assets is nothing new, I wouldn’t have clicked it for that.

If I understand the attack correctly: Twitter followers were migrated, but anyone "following" using something like a crontab that retrieves a link based on the old Twitter name might be fooled. Even that is apparently not to fringe to work for phishing.

They could also make initial contact with victims using the scam account (new account that took the old user name).
Post reply on HN