Crypto phishing scams took almost $300M from 324k victims in 2023: Report

CGPTPublicado a 2023-12-31Actualizado a 2024-01-01

Resumen

Over 324,000 crypto users fell victim to phishing scams in 2023, with around $295 million in digital assets lost to wallet drainers.

Over 324,000 crypto users fell victim to phishing scams in 2023, with around $295 million in digital assets lost to wallet drainers.
In its 2023 Wallet Drainers Report, blockchain security platform Scam Sniffer analyzed the trends surrounding drainers used in crypto phishing scams. The platform highlighted that there has been a continued growth in phishing activities throughout 2023. 

Notable wallet drainers that were active in 2023. Source: Scam SnifferIn addition, Scam Sniffer also reported that despite drainers closing down, “phishing gangs” just take their business elsewhere, as there seems to be no lack of platforms providing services for scammers. 
On March 2, the infamous Monkey Drainer, responsible for high-profile phishing exploits, closed its business. Scam Sniffer estimated that Monkey Drainer stole around $16 million in digital assets before it closed down. However, phishing continued as the drainer recommended a different scam service to their criminal clientele.
Similarly, Inferno Drainer also closed down in 2023 after stealing about $81 million in digital assets. According to Scam Sniffer, Angel Drainer seems to have taken over after Inferno Drainer closed down. 

Wallet Drainers’ phishing activities throughout 2023. Source: Scam Sniffer Meanwhile, Scam Sniffer also analyzed how phishing sites get traffic. One of the methods these crypto thieves employ is hacking official Discord and X (Twitter) accounts of official projects. After taking over the official social accounts, the hackers then spread phishing links through posts. 
Related: Redditors report deepfake Ripple scam on YouTube
Besides hacking, phishing websites get organic traffic by conducting fake airdrops of crypto assets or nonfungible tokens (NFTs). They also take over expired Discord links and perform spam commenting and mentioning on X. 
In addition to organic traffic, the scammers manage to bypass Google and X’s advertising guidelines. Their phishing websites can put out paid Google search ads and Twitter ads, according to Scam Sniffer. 
Magazine: Tencent’s AI leviathan, $83M scam busted, China’s influencer ban: Asia Express

Lecturas Relacionadas

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

A vulnerability involving transaction substitution has been identified and confirmed in the Ethereum application for Ledger hardware wallets. The issue was a race condition between the transaction data displayed on the device's screen and the buffer holding the actual transaction data. This flaw allowed a malicious actor to overwrite a pending transaction while the user was reviewing a legitimate one on the display, potentially leading to the signing of an unseen transaction. The vulnerability was independently discovered by multiple parties. On August 22, 2026, researcher TestMachine disclosed it after detection by the Azimuth scanning tool. Later, on August 27, OneKey's founder Yishi Wang announced his team had successfully replicated the attack in a lab environment on app version 1.22.1. Ledger's security team, Donjon, responded that no real-world exploits or user losses occurred. They stated the flaw was internally identified and patched in Ethereum app version 1.22.2, released on August 13, 2026—prior to the public disclosures. An update to the underlying Ledger Secure SDK (v26.6.1) followed on August 21. Official security bulletin LSB 023, published August 27, details the vulnerability as residing in the SDK's I/O handling. While there is minor public discrepancy over whether version 1.22.2 or 1.22.3 fully resolved the issue, all parties strongly urge users to update their Ethereum application to the latest version via Ledger Live. The incident highlights a critical security principle: the safety of a hardware wallet depends on the entire chain of components—firmware, SDK, and applications—with a flaw in any link compromising the overall system.

cryptonews.ruHace 8 min(s)

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

cryptonews.ruHace 8 min(s)

Trading

Spot
活动图片