# Phishing Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Phishing", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

The Danger of Old Bookmarks: How an Expired Tornado Cash Domain Cost a User 1,000 ETH

A user lost over 1,010 ETH (worth millions) due to a phishing attack via an expired official domain of the Tornado Cash protocol. As reported on August 20, 2026, the domain `tornado.cash` was not renewed by the original developers amid U.S. OFAC sanctions and was subsequently registered by malicious actors. They deployed a fake frontend mimicking the legitimate Tornado Cash interface. Through this site, the attackers gained access to the user's deposit notes—the data required to withdraw funds from the protocol's pools—and drained the ETH within 12 hours. On-chain data shows the stolen funds (e.g., wallet 0xd8B356...) were withdrawn from Tornado Cash pools. However, on-chain analyst Specter cast doubt on the victim's story. He suggested the individual might be involved in illicit activity, noting that a large sum of BTC was received from a coin-mixing service (Whirlpool) and converted to ETH before being sent to the fake Tornado Cash site. The victim's explanation of urgently moving funds due to a compromised hardware wallet was questioned, as the fund trail indicated deliberate obfuscation. Specter speculated this might be a conflict between malicious actors rather than a simple phishing case. The incident highlights the danger of expired domains for major protocols, where old bookmarks can lead to compromised sites. WHOIS records show the domain was registered in March 2025. Broader analysis notes that in 2025, over $1.8 billion was lost to scams and exploits, largely through social engineering like phishing via familiar but hijacked links. This case underscores the persistent risk when a domain's legal status changes but user trust and search engine reputation remain.

cryptonews.ru08/23 17:40

The Danger of Old Bookmarks: How an Expired Tornado Cash Domain Cost a User 1,000 ETH

cryptonews.ru08/23 17:40

India Orders Closure of Hundreds of Google Firebase Accounts Used in Banking Frauds

India's cybercrime agency ordered Google to block hundreds of accounts on its Firebase app development platform. The move came after investigators traced numerous fake banking apps and phishing websites to the service. The Indian Cyber Crime Coordination Centre (I4C) sent multiple notices to Google, identifying at least 57 websites and databases on Firebase allegedly used to distribute malware and steal victims' financial data. Among these, seven were phishing pages mimicking login screens of major Indian banks like State Bank of India, ICICI Bank, and Axis Bank. The rest were reportedly data collection points for stolen information like credit card numbers and one-time passwords. The fraud scheme involved Android malware disguised as legitimate banking apps, luring victims with promises of new credit cards, rewards, or credit limit increases. Once installed, the app secretly forwarded device data to a Firebase database controlled by scammers, granting them access to other apps and the victim's funds. One scam specifically targeted beneficiaries of a government farmer aid program. This action marks a shift in India's approach. Previously focused on blocking individual fraudulent websites, authorities are now targeting the broader infrastructure enabling these scams. The move highlights how fraudsters exploit widely accessible platforms like Firebase, attracted by its free tier and database capabilities, to target India's vast digital payment user base.

cryptonews.ru08/22 10:43

India Orders Closure of Hundreds of Google Firebase Accounts Used in Banking Frauds

cryptonews.ru08/22 10:43

Wallet Connection Prompts Are a Sign of a Fake AML Check Website

Fake anti-money laundering (AML) verification sites are stealing from cryptocurrency investors. These websites trick users into connecting their wallets and signing transactions, which is unnecessary for a basic wallet check, as discovered by Malwarebytes. Legitimate wallet verification only requires a public address to analyze transaction history for links to hacks, thefts, or sanctioned entities. The fraudulent sites, some copying brands like AMLBot, mimic this process. After a user initiates a scan, they are prompted to connect their wallet, shown fake progress bars, and sometimes asked to pay a small "fee." Eventually, a false "clean, low risk" verdict is given to download a report. Connecting a wallet reveals the public address and assets, allowing scammers to craft targeted transactions for the victim to approve, which can drain funds. Malwarebytes warns that any AML checker requesting wallet connection instead of just a public address is a major red flag. The report details that the same malicious template is repackaged under different names. It also mentions a $500 scam kit advertised on cybercrime forums that creates fake token presales, scans visitor wallets for valuable assets, and attempts to steal secret recovery phrases by offering a bonus. The article advises users who connected only a wallet to revoke the site's permissions. Those who signed suspicious transactions should check activity and move funds to a new wallet if compromised. Anyone who entered a recovery phrase or private key should assume the wallet is breached.

cryptonews.ru08/21 05:26

Wallet Connection Prompts Are a Sign of a Fake AML Check Website

cryptonews.ru08/21 05:26

Web3 Wallets in a 'Turbulent Autumn': In the AI Era, How to Understand the Evolution of 'Spear and Shield' in Crypto Security?

The recent spate of incidents involving Coldcard, Trezor, and SafePal highlights a critical evolution in cryptocurrency wallet security, moving the focus beyond simple private key protection to a holistic, multi-layered attack surface. These events—spanning a random number generator flaw, supply chain data leaks, and plugin permission issues—underscore that vulnerabilities now exist across the entire wallet lifecycle: from secure element and code generation to logistics, user data, and daily interactions with dApps. This broadening threat landscape is accelerating with the advent of AI. Attackers are leveraging AI to automate and scale previously labor-intensive tasks like vulnerability discovery, sophisticated social engineering, and targeted phishing campaigns. This effectively lowers the cost of attacks, eroding the security margin once provided by the high effort required to find and exploit flaws. In response, defense strategies must also evolve by integrating AI. The future of wallet security lies not just in static rules and blacklists, but in proactive, AI-powered risk assessment. This includes pre-transaction simulation, behavioral analysis to detect anomalies (like sudden large approvals), and contextual awareness of dApps and counterparties. The goal is to transform wallets from passive signing tools into active guardians that can understand intent, predict outcomes, and clearly communicate risks to users—all while preserving user sovereignty and control through minimal permissions and human confirmation for critical actions. Ultimately, self-custody does not guarantee inherent safety; it returns absolute control to the user. Protecting that control requires a dynamic, evolving security posture where AI becomes a essential tool on both sides of an ongoing "spear and shield" arms race in the Web3 ecosystem.

marsbit08/19 08:41

Web3 Wallets in a 'Turbulent Autumn': In the AI Era, How to Understand the Evolution of 'Spear and Shield' in Crypto Security?

marsbit08/19 08:41

活动图片