Đề nghị kết nối ví là dấu hiệu của trang web kiểm tra rửa tiền giả mạo

cryptonews.ruPublicado a 2026-08-21Actualizado a 2026-08-21

Resumen

Các trang web giả mạo kiểm tra chống rửa tiền (AML) đang đánh cắp tiền của nhà đầu tư tiền điện tử. Những trang này yêu cầu người dùng kết nối ví và ký giao dịch, điều không cần thiết cho việc xác minh ví thực tế. Một cuộc tấn công như vậy được Malwarebytes phát hiện. Để kiểm tra AML hợp pháp, chỉ cần địa chỉ công khai của ví để phân tích lịch sử giao dịch. Các trang web lừa đảo sao chép giao diện của dịch vụ thật như AMLBot hoặc dùng tên chung chung như "AML Check". Sau khi người dùng chọn tiền điện tử và bấm quét, họ được nhắc kết nối ví. Một phiên bản hiển thị tiến trình giả với thông báo như "Đang kiểm tra lịch sử ví..." rồi báo lỗi và yêu cầu nạp một khoản phí nhỏ. Nếu bấm "Thử lại", trang sẽ hiện kết quả "Sạch, rủi ro thấp" và đề nghị tải báo cáo. Malwarebytes cảnh báo: yêu cầu kết nối ví thay vì chỉ nhập địa chỉ công khai là dấu hiệu đáng ngờ. Kết nối ví tiết lộ địa chỉ và tài sản, cho phép kẻ gian tạo giao dịch giả mạo để nạn nhân phê duyệt, dẫn đến mất tiền. Các nhà nghiên cứu phát hiện cùng một mẫu mã độc được dùng dưới nhiều tên và logo khác nhau. Một bộ công cụ giá 500 USD được rao bán trên diễn đàn hacker tạo ra đợt bán trước giả mạo token $TSLA, quét ví và lừa người dùng tiết lộ cụm từ khôi phục với lời hứa thưởng 15%. Các vụ lừa đảo tương tự đã xảy ra, như chiến dịch phân phối token $CJUP giả trên Solana. Sàn CoinDCX báo cáo phát hiện hơn 1.212 trang web giả mạo họ từ 4/2024 đến 1/2025. Khuyến nghị của Malwarebytes: Nếu chỉ kết nối ví, hãy ngắt kết nối tra...

Các trang web giả mạo chuyên kiểm tra rửa tiền đang đánh cắp tiền của các nhà đầu tư tiền mã hóa.

Các trang web này yêu cầu người dùng kết nối ví và ký vào một giao dịch, điều không cần thiết để xác minh tính xác thực của ví. Công ty Malwarebytes đã phát hiện cuộc tấn công này vào tuần này.

Chỉ cần cung cấp địa chỉ công khai để xác minh tính xác thực của ví

Theo các quy định chống rửa tiền, ngân hàng và các công ty được quản lý phải kiểm tra xem khách hàng của họ có liên quan đến hoạt động tội phạm hay không.

Trong lĩnh vực tiền mã hóa, việc kiểm tra này có nghĩa là phân tích lịch sử giao dịch công khai của địa chỉ ví để tìm các liên hệ với các vụ hack, trộm cắp, cá nhân bị trừng phạt hoặc các hoạt động đáng ngờ khác.

Theo nhà nghiên cứu Stefan Dasic của Malwarebytes, các trang web lừa đảo lấy ý tưởng này và biến nó thành vũ khí.

Một số sao chép phong cách thương hiệu của AMLBot, một dịch vụ kiểm tra rửa tiền hợp pháp. Những trang khác hoạt động dưới các tên chung chung như "AML Check".

Người truy cập chọn loại tiền mã hóa, nhấn nút quét, sau đó được đề nghị kết nối ví để xem kết quả.

Một phiên bản được Malwarebytes nghiên cứu hiển thị thanh tiến trình với các thông báo như "Đang kiểm tra lịch sử ví..." và "Đang kiểm tra sự tuân thủ...", sau đó xuất hiện lỗi giả mạo yêu cầu nạp một khoản tiền nhỏ để "trả phí".

Nhấn "Thử lại" và hoạt ảnh sẽ chạy lại, sau đó đưa ra kết luận an tâm "Sạch sẽ, rủi ro thấp" và đề nghị tải xuống báo cáo.

Đối với việc kiểm tra cơ bản đầy đủ, chỉ cần địa chỉ công khai của ví. Đây chỉ là một tìm kiếm, không cần ký tài liệu, cấp quyền hoặc kết nối ví.

"Nếu một chương trình kiểm tra rửa tiền yêu cầu bạn kết nối ví của mình thay vì chỉ nhập địa chỉ công khai của nó, hãy coi đó là dấu hiệu cảnh báo," nhóm Malwarebytes viết.

Việc kết nối ví không chuyển giao khóa riêng tư, nhưng tiết lộ địa chỉ công khai. Điều này cho phép những kẻ điều hành nhìn thấy tài sản nào đang có trong ví và tạo ra các giao dịch nhắm mục tiêu cụ thể vào ví đó.

Sau đó, giao dịch này được gửi đến nạn nhân để phê duyệt. Thời điểm phê duyệt là khi tiền bắt đầu chuyển đi.

Các nhà nghiên cứu khuyến cáo không nên phê duyệt các giao dịch bất ngờ.

Malwarebytes phát hiện ra rằng cùng một mẫu mã độc được sử dụng dưới các tên và biểu trưng khác nhau. Bộ công cụ phần mềm được đổi tên và bán lại.

Bộ công cụ 500 USD sử dụng cụm từ khôi phục để lừa đảo, hứa hẹn thưởng 15%

Trong tháng này, Cryptopolitan đã đưa tin về một bộ công cụ có sẵn trị giá 500 USD trên một diễn đàn dành cho tội phạm mạng. Bộ công cụ này tạo ra một đợt bán trước $TSLA giả mạo và quét ví của mỗi người truy cập để tìm các tài sản có giá trị.

Sau đó, những kẻ lừa đảo cố gắng lừa lấy cụm từ khôi phục 12 từ bằng cách hứa hẹn thưởng 15%. Bảng điều khiển quản trị tự động làm giả số dư để nạn nhân tiếp tục thanh toán.

Vào tháng 5, Solana Floor đã phát hiện một âm mưu mà các ví Solana bị tấn công bằng token giả "$CJUP", bắt chước đợt airdrop Jupuary từ Jupiter Exchange và chuyển hướng người nhận đến một trang web giả mạo, như Cryptopolitan đã đưa tin lúc đó.

Công ty CoinDCX báo cáo đã phát hiện hơn 1212 trang web giả mạo mạo danh nền tảng của họ từ tháng 4 năm 2024 đến tháng 1 năm 2026. Cảnh sát Mumbai đã ghi nhận một báo cáo về gian lận được thực hiện thông qua một trang web mạo danh CoinDCX.

Malwarebytes khuyên tất cả những ai chỉ kết nối ví nên ngắt kết nối khỏi trang web đó. Bất kỳ ai đã cấp quyền truy cập vào ví cho một token nên kiểm tra các quyền không quen thuộc và thu hồi chúng.

Bất kỳ ai đã ký vào thứ gì đó không rõ ràng nên kiểm tra hoạt động gần đây và nếu quỹ bị xâm phạm, hãy chuyển tất cả sang một ví mới. Bất kỳ ai đã nhập cụm từ khôi phục hoặc khóa riêng tư nên cho rằng ví đã bị xâm phạm.

Criptos en tendencia

Lecturas Relacionadas

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

Just now, Sam Altman strongly criticized Dario (Amodei, co-founder of Anthropic), denouncing his "doomsday marketing" as "anti-human dictator rhetoric." This came alongside the accidental exposure of OpenAI's next-generation model, codenamed "gpt-nathree," hinting at the imminent release of GPT-6 Astra. The leak occurred when an OpenAI employee's public GitHub commit mentioned the codename. Combined with previous leaks of "gpt-mewfour," it suggests these are iterative checkpoints for OpenAI's upcoming agent model, Astra. Astra is known for multi-agent collaboration and long-duration task handling, having reportedly solved previously unsolved mathematical problems. Meanwhile, two new Anthropic model codenames, "claude-marshmallow-eap" and "claude-melon-eap," were also exposed but are believed to be iterations of the Claude 5 series, not a new flagship. In a wide-ranging podcast interview, Altman admitted he was wrong about the speed of AI-driven disruption, acknowledging societal inertia slows adoption. He fiercely criticized rivals' marketing that simultaneously promises immense benefits (like curing cancer) and warns of existential risk, calling it a dangerous "benevolent dictator" narrative that seeks to concentrate power. He emphasized that people are the ultimate purpose of AI. Altman also revealed OpenAI's unconventional, consensus-defying path: spending four and a half years in the "dark" without a public product before ChatGPT's breakthrough, driven by scaling laws rather than early customer feedback. He concluded that even with superintelligent AI, genuine human connection will remain irreplaceably valuable.

marsbitHace 37 min(s)

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

marsbitHace 37 min(s)

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

"Rescuing US Treasuries" Relay: After Bessent's Miss, All Eyes Are on Walsh Last week, US Treasury Secretary Bessent's announcement to at least double long-term Treasury buybacks failed to sustainably lower yields, which quickly rebounded. The market response saw a drop in the dollar alongside surges in gold and Bitcoin, interpreted as a "pressure release valve" for anxiety. The focus now shifts to Fed Chairman Walsh's upcoming Jackson Hole speech. Markets are highly sensitive to his message, seeking clarity on the Fed's policy response to stubborn inflation and worsening fiscal conditions. Analysts warn that a lack of new guidance could disappoint markets and worsen the sell-off in long-dated bonds. Analysts question the scale of Bessent's operations, noting they are too small relative to the overall debt market and do not constitute quantitative easing. A key issue is the Fed's massive holdings of long-term bonds, which distorts the market. With the Fed holding low-yielding short-term bonds that are losing money relative to its policy rate, discussion is growing around a potential Fed-led "Operation Twist." This would involve selling short-term bonds to buy long-term ones, aiming to lower long-end yields without expanding the balance sheet. The upcoming PCE inflation data will set the stage for Walsh's speech. However, the window for action is narrowing amid political pressures. A critical threshold is the 30-year yield at 5%; holding above it could increase stress on the dollar and leveraged sectors. Overall, the article suggests that without coordinated Fed action to anchor inflation expectations, Treasury interventions may ultimately fail, with investors increasingly looking to assets like gold as hedges.

marsbitHace 1 hora(s)

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

marsbitHace 1 hora(s)

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

Hyperliquid’s Compliance Path: From Permissionless to Permissioned HIP-3 Hyperliquid currently blocks U.S. access because its permissionless, on-chain infrastructure conflicts with U.S. market structure laws, which restrict futures trading to registered exchanges, clearinghouses, and brokers. Through its Hyperliquid Policy Center (HPC), the project is advocating for regulatory modernization, proposing that regulated entities be allowed to build products on HyperCore (its exchange and clearing layer) while fulfilling their compliance obligations. The platform’s modular stack separates roles like a traditional exchange (DCM), clearinghouse (DCO), and broker (FCM), but reconstructs them on-chain with code. This enables permissionless access, self-custody, and 24/7 global trading, but clashes with U.S. rules requiring KYC, specific margin models, and custodial arrangements. To resolve this, HPC is engaging with U.S. regulators (CFTC, SEC) to seek clarity that deploying on-chain software does not itself trigger licensing, and to establish exemptions allowing non-custodial wallets to route users to regulated derivatives. Recent political signals suggest openness to this approach. On the technical side, Hyperliquid Labs has introduced permissioned HIP-3 deployers on testnet. These allow regulated entities to launch markets, perform KYC, and whitelist compliant users. While these create separate order books, whitelisted market makers can bridge liquidity between them, ensuring deep, shared liquidity across the same L1. Features like payload-based “PA” permissions enable DEX-level account controls (e.g., reduce-only orders), mirroring traditional broker authorities. The strategy is not to open the native, permissionless front-end to U.S. users, but to position Hyperliquid as neutral infrastructure that U.S. regulated firms can use while meeting their legal duties. This paves a compliant path for U.S. investor access while preserving the protocol’s core, permissionless nature.

marsbitHace 1 hora(s)

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

marsbitHace 1 hora(s)

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

Investment Community AI has learned that Beijing Zhongshu Ruizhi Technology Co., Ltd., a domestic industrial-grade causal intelligence and high-reliability decision-making AI company, has recently completed a strategic financing round worth hundreds of millions of RMB. This round saw participation from China Internet Investment Fund, Suzhou Chuangtou National Social Security Fund, Financial Street Capital, ICBC Capital, Kunlun Capital, among others, with existing shareholders also increasing their investment. This follows a Series B funding round in the hundreds of millions completed just three months prior. The rapid succession of two major funding rounds signifies strong market recognition of the company's underlying original technology and scaled commercial implementation. Often referred to as the "Chinese version of Palantir," Zhongshu Ruizhi is entering a new phase of accelerated technological iteration, widespread scenario replication, and scaled performance release, mirroring the explosive growth of China's AI market. Founded in April 2020 by Dr. Han Han, a Tsinghua University Ph.D. and former core drafter of national AI policies, the company is mission-driven to "move AI from the digital world to the physical world." It focuses on the high-reliability, strong-decision industrial AI track and enterprise-grade AI Agent full-stack infrastructure. The team tackles the challenge of applying AI to China's vast and complex industrial and energy systems by developing a new intelligent operating system from scratch. Its core technological breakthrough lies in three proprietary底层 technologies: meta-causal cognitive theory, causal models, and a dynamic ontology engine. These address critical pain points of generative large models in industrial settings—such as AI hallucinations, insufficient reasoning, lack of temporal logic, unverifiable decisions, and multi-source rule conflicts—thereby providing trustworthy, explainable, and executable智能决策 capabilities. Commercially, Zhongshu Ruizhi has achieved scaled deployment, serving over 50 central state-owned enterprises and industrial groups in sectors like power, petroleum, and aerospace, with implementations in more than 800 highly complex production scenarios. The company reported doubled revenue in 2025, demonstrating strong self-sufficiency and a viable business model—a rarity among new-generation AI firms. The latest funds will be allocated towards advancing foundational theoretical research, replicating successful application models to expand market presence (including overseas), and attracting top-tier talent. Lead investor China Internet Investment Fund highlighted that in the current shift from general AI capability contests to deep industrial empowerment, industrial-grade causal intelligence is crucial for building China's modern digital foundation and fostering new quality productive forces. They expressed support for the company's efforts to define decision-making paradigms and trustworthy standards for industrial intelligence, aiming to secure a rule-making voice in the global physical AI arena.

marsbitHace 1 hora(s)

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

marsbitHace 1 hora(s)

Trading

Spot

Artículos destacados

Cómo comprar CHECK

¡Bienvenido a HTX.com! Hemos hecho que comprar Checkmate (CHECK) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Checkmate (CHECK) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Checkmate (CHECK)Después de comprar tu Checkmate (CHECK), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Checkmate (CHECK)Tradear fácilmente con Checkmate (CHECK) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

721 Vistas totalesPublicado en 2026.01.19Actualizado en 2026.06.02

Cómo comprar CHECK

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de CHECK (CHECK).

活动图片