В CoinGecko предупредили о новой мошеннической схеме с криптопутешествиями

cryptonews.ruPublished on 2025-05-27Last updated on 2025-10-28

Сооснователь и гендиректор аналитической платформы CoinGecko Бобби Онг (Bobby Ong) предупредил о новой фишинговой афере, которую придумали мошенники для кражи криптовалют.

Злоумышленники рассылают поддельные электронные письма, якобы отправленные от сервиса бронирования Booking.com, с приглашениями на несуществующий «Эксклюзивный саммит по криптовалютным путешествиям» в Дубае. В сфабрикованных письмах говорится о конференции, которую якобы организовали Booking.com и американская криптобиржа Coinbase. Инвесторов пытаются убедить, что эти компании заключили стратегическое партнерство для запуска сервиса криптовалютных путешествий.

В список основных докладчиков так называемой «конференции» включен гендиректор Coinbase Брайан Армстронг (Brian Armstrong) и сооснователь Эфириума Виталик Бутерин. В письме указано, что мероприятие пройдет в ноябре 2025 года, однако в ранних письмах фигурировала дата 30 сентября. Это говорит о том, что мошенники подготовили текст повторно или в спешке.

Онг посоветовал всем трейдерам, которые получат подобные письма, немедленно удалить их и не переходить по фишинговым ссылкам. Иначе злоумышленники могут получить доступ к их конфиденциальным данным, а затем украсть их криптоактивы. Онг также призвал службу безопасности Booking.com как можно скорее решить этот вопрос. Позже Booking.com признал наличие проблемы, выразив сожаление, что пользователи могут получать фишинговые письма. Сервис запросил подробности для проведения расследования.

В августе другая аналитическая платформа, CoinMarketCap, предупредила о мошенниках, атакующих сотрудников криптопроектов и выдающих себя за бывших фрилансеров компании. Перейдя по фишинговым ссылкам от фальшивых журналистов для проведения интервью, разработчики лишались своих цифровых активов.

Related Reads

Claude Code Easily Compromised with Just a Fake Tool

Researchers have demonstrated a novel attack, dubbed ToolLeak, that can easily compromise AI coding assistants like Claude Code. The method exploits a "mode gap" by stealing the system prompts (instructions) not through direct chat queries, but by tricking the model into leaking them as parameters during tool calls. This extracted information is then used to craft a "two-channel prompt injection" attack. Attackers register a malicious tool with a description formatted to mimic legitimate instructions, prompting the AI agent to call it. The tool's return value then instructs the agent to execute a malicious command (e.g., `curl | bash`), achieving Remote Code Execution (RCE). In tests against six major AI programming tools (Cursor, Claude Code, Copilot, Windsurf, Cline, Trae) using older versions, all were fully compromised, with attack success rates reaching up to 1.0. Notably, Claude Code's secondary guard model (Haiku) was overridden by the main model (Sonnet), which had been manipulated by the injected instructions. Newer versions show improved defenses. Claude Code and Cursor implemented mitigations like "progressive tool description exposure," reducing RCE success to 0 and 0.3 respectively in some configurations. However, tools like Cline, Windsurf, and Trae paired with certain models remained fully vulnerable. The research underscores that architectural isolation is crucial for defense, as long as tool return values can ambiguously function as both data and executable instructions, the threat of tool hijacking persists. The paper "TIPExploit: Tool-Invocation Prompt Extraction and Exploitation in AI Coding Agents" has been accepted at ISSTA 2026.

marsbit2m ago

Claude Code Easily Compromised with Just a Fake Tool

marsbit2m ago

Bernstein Analysis: Samsung's HBM4 Accelerates Volume, Q3 Revenue May Overtake SK Hynix

South Korea’s July memory export data, serving as an early indicator for HBM business in Q3, shows overall HBM demand remains robust. While total exports to Taiwan and Malaysia declined 32% month-on-month from June’s peak—largely due to seasonality—they were still up 13% compared to April and rose 64% year-on-year. However, a divergence emerged between Samsung and SK Hynix. Samsung’s exports from Chungcheongnam-do (a proxy for its HBM shipments) surged, reaching $2.2 billion in July, up 122% from April. Based on regression analysis, Bernstein estimates Samsung’s Q3 HBM revenue could hit around $12 billion, roughly 30% above its prior forecast, driven by a rapid ramp in higher-value HBM4. The unit value of Samsung’s exports has doubled since April, signaling a shift toward HBM4, which carries a significantly higher price. In contrast, exports linked to SK Hynix from Chungcheongbuk-do and Icheon fell 28% month-on-month and 27% versus April. Bernstein’s base model suggests SK Hynix’s Q3 HBM revenue could drop to about $5.6 billion, though this could rebound to $12 billion if shipments concentrate later in the quarter as historically seen. The weakness may relate to potential delays in HBM4 shipments for Nvidia’s Rubin platform. Notably, HBM pricing is decoupling from general DRAM, with HBM4 mix driving average selling prices rather than broad-based hikes. Exports to Malaysia also surged, possibly linked to Intel’s EMIB packaging facilities, though the exact drivers remain unclear. While July data reinforces Samsung’s accelerating momentum in HBM4, it is insufficient to confirm a full-year market share reversal. Key factors to watch are Samsung’s August-September export performance, whether SK Hynix recovers lost ground, and upcoming 2027 HBM contract pricing negotiations.

marsbit2m ago

Bernstein Analysis: Samsung's HBM4 Accelerates Volume, Q3 Revenue May Overtake SK Hynix

marsbit2m ago

The New Rules of the AI Race: Nvidia Shifts from Chips to Energy Resources and Construction Sites

Nvidia is providing a $105 billion financial guarantee for the construction of OpenAI's data center campus in Ohio, signaling a strategic shift in the AI industry from competing on chips to battling for physical infrastructure and energy resources. The guarantee, detailed in an SEC filing, acts as insurance against tenant default rather than direct construction funding. OpenAI must repay any sums drawn. Nvidia will also invest $1.5 billion in SB Energy for the project's power component. The planned campus has a capacity of 4.25 GW, with OpenAI's current commitments to Nvidia reaching 12 GW. This move underscores that leading AI development now requires securing space, power, and financial backing for massive, long-term projects. Tech giants are taking on roles akin to developers and financial institutions. Concurrently, AI firms are diversifying suppliers: OpenAI and Anthropic have signed major deals with AMD for GPU deployments. Nvidia is also scaling its financial model through partnerships with investment firms to mobilize over $500 billion in external capital. The paradigm in AI is shifting from hardware supremacy to building comprehensive ecosystems. Future industry growth will depend on balancing innovation with real-world infrastructure capabilities, turning abstract computations into tangible industrial projects. An AI analysis notes the deal's resemblance to vendor financing schemes from the telecom bubble of the late 1990s and questions the long-term viability of gas-dependent energy infrastructure for AI, should market growth slow.

cryptonews.ru12m ago

The New Rules of the AI Race: Nvidia Shifts from Chips to Energy Resources and Construction Sites

cryptonews.ru12m ago

Trading

Spot
活动图片