Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

1–10 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#3
As soon as I read the headline, I knew that the problem was...

> In just 40 minutes, the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account.

One of the many, many benefits of irreversible transactions.

> I made mistakes, yes

His first mistake was keeping six figures worth of 'cash' in a wallet that anyone with less than 40 minutes of access to can swipe.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#4
> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment.

Can somebody explain what exactly this means, and how it works?

Post reply on HN