Public Wi-Fi and a Phone Call: How They Became the Perfect Trap to Steal $5000 in Crypto Assets?

比推Dipublikasikan tanggal 2026-01-09Terakhir diperbarui pada 2026-01-09

Abstrak

An individual lost approximately $5,000 in cryptocurrency assets after connecting to a public hotel Wi-Fi network during a vacation. The attack began when the victim was overheard discussing crypto and using a Phantom wallet in a public area, making them a target. While browsing on the unsecured Wi-Fi, the attacker executed a man-in-the-middle attack, injecting malicious code into a seemingly legitimate webpage. The victim was using Jupiter Exchange to swap tokens when a fraudulent transaction approval request was triggered, disguised as a normal operation. Instead of a direct fund transfer, the request asked for “authorization” or “session approval,” granting the attacker permission to act on the wallet. The victim approved, believing it was part of the Jupiter transaction. The attacker waited until the victim left the hotel to drain the wallet of SOL, tokens, and NFTs. Key mistakes included: using public Wi-Fi instead of a mobile hotspot, discussing crypto in public, and approving a transaction without thorough verification. The wallet was a secondary hot wallet, not the main storage, preventing greater losses. The incident highlights the risks of public networks and the importance of transaction scrutiny.

Author: The Smart Ape

Compiled by: Deep Tide TechFlow

Original title: After Three Days on Hotel Wi-Fi, My Crypto Wallet Was Drained of $5000


A few days ago, I went with my family to a very nice hotel for a year-end holiday. One day after leaving the hotel, my wallet was completely emptied. I was puzzled, as I had neither clicked on any phishing links nor signed any malicious transactions.

After hours of investigation and seeking help from experts, I finally figured out the truth. It turned out to be due to the hotel's Wi-Fi network, a brief phone call, and a series of foolish mistakes.

Like most cryptocurrency enthusiasts, I brought my laptop with me, thinking I could squeeze in some work while on vacation with my family. My wife repeatedly insisted that I not work during these three days—I really should have listened to her.

Like other guests, I connected to the hotel's Wi-Fi network. This network didn't require a password; it only needed to be logged in through a captive portal.

I worked as usual in the hotel without doing anything risky: I didn't create new wallets, click on strange links, or access suspicious decentralized applications (dApps). I just checked X (Twitter), my balances, Discord, Telegram, etc.

At one point, I received a call from a crypto friend, and we chatted about market trends, Bitcoin, and other cryptocurrency-related matters. But what I didn't know was that someone nearby was eavesdropping on our conversation and realized I was involved in cryptocurrency. This was my first mistake. The eavesdropper learned from our conversation that I was using a Phantom wallet and that I was a user with a significant holding.

This made me his target.

In a public Wi-Fi network, all devices share the same network, and the visibility between devices is actually higher than you might think. There is almost no real protection between users, which creates an opportunity for a "Man-in-the-Middle Attack." The attacker acts like a middleman, quietly inserting themselves between you and the internet, much like someone secretly reading and tampering with your mail before it reaches you.

While I was browsing the web on the hotel Wi-Fi, one website appeared to load normally, but in reality, malicious code had been injected behind the page. I didn't notice anything unusual at the time. If I had installed some security tools, I might have detected these issues, but unfortunately, I hadn't.

Normally, a website might request your wallet to sign certain operations. The Phantom wallet would pop up a window where you could choose to approve or reject. Generally, you would trust the website and browser and sign without worry. However, that day, I shouldn't have.

Just as I was performing a token swap on @JupiterExchange, the malicious code triggered a wallet request that replaced my normal swap operation. I could have detected it as a malicious request by carefully checking the transaction details, but because I was already performing a swap on Jupiter, I didn't suspect a thing.

That day, I didn't sign any transaction to transfer funds; instead, I signed an authorization. This was exactly why my assets were stolen days later.

The malicious code didn't directly ask me to send SOL (Solana), as that would have been too obvious. Instead, it requested me to "authorize access," "approve account," or "confirm session." In simple terms, I was actually giving another address permission to operate on my behalf.

I approved it because I mistakenly thought it was related to my operation on Jupiter. At the time, the message popped up by the Phantom wallet looked technical, didn't show any amount, and didn't prompt for an immediate transfer.

And that was all the attacker needed. He patiently waited until I left the hotel before taking action. He transferred my SOL, withdrew my tokens, and moved my NFTs to another address.

I never thought something like this would happen to me. Fortunately, this wasn't my main wallet but a hot wallet used for specific operations, not for long-term asset holding. Even so, I made many mistakes, and I believe I am primarily responsible.

First, I should never have connected to the hotel's public Wi-Fi. I should have used my phone's hotspot instead.

My second mistake was talking about cryptocurrency in the hotel's public area, where many people could have overheard our conversation. My father once warned me never to let others know you're involved in cryptocurrency. This time, I was lucky; some people have even faced kidnapping or worse because of their crypto assets.

Another mistake was approving the wallet request without paying full attention. Because I was sure the request came from Jupiter, I didn't analyze it carefully. In fact, every wallet request should be carefully reviewed, even on trusted applications. Requests can be intercepted and may not actually come from the app you think.

In the end, I lost about $5000 from a secondary wallet. While it's not the worst-case scenario, it's still very frustrating.


Twitter:https://twitter.com/BitpushNewsCN

BitPush TG Discussion Group:https://t.me/BitPushCommunity

BitPush TG Subscription: https://t.me/bitpush

Original article link:https://www.bitpush.news/articles/7601380

Kripto yang Sedang Tren

Pertanyaan Terkait

QWhat was the primary method the attacker used to compromise the victim's crypto wallet?

AThe attacker used a Man-in-the-Middle (MitM) attack by exploiting the insecure public hotel Wi-Fi network. They intercepted the victim's web traffic and injected malicious code into a webpage, which triggered a deceptive wallet authorization request.

QWhat specific mistake did the victim make that allowed the attacker to identify him as a target?

AThe victim discussed cryptocurrency, his use of the Phantom wallet, and his substantial holdings during a phone call in a public area of the hotel, which was overheard by the attacker.

QWhat type of transaction did the victim accidentally sign, instead of a direct fund transfer?

AThe victim signed an authorization or approval request, which granted permission for another address to operate on their behalf. This did not immediately transfer funds but gave the attacker the ability to do so later.

QWhy didn't the victim suspect the malicious transaction request when it appeared?

AThe request appeared while he was performing a legitimate token swap on the Jupiter Exchange platform. He assumed the request was part of that normal operation and did not carefully inspect the technical details of the transaction, which showed no immediate transfer of funds.

QWhat were the two security precautions the victim identified that could have prevented this attack?

AFirst, he should not have used the hotel's public Wi-Fi and instead used his phone's mobile hotspot. Second, he should never have discussed his cryptocurrency activities in a public space where he could be overheard.

Bacaan Terkait

Trading

Spot

Artikel Populer

Apa Itu APECOIN

Memahami Asia Pacific Electronic Coin ($APECoin) Di era di mana persimpangan teknologi dan lingkungan menjadi semakin kritis, cryptocurrency membuat jejaknya sebagai katalis potensial untuk perubahan. Di antara inovasi-inovasi ini, Asia Pacific Electronic Coin ($APECoin) menonjol sebagai proyek yang dirancang untuk mendukung inisiatif lingkungan di seluruh wilayah Asia Pasifik. Artikel ini membahas dasar, fitur unik, dan dampak $APECoin dalam lanskap blockchain yang lebih luas. Apa itu Asia Pacific Electronic Coin ($APECoin)? Asia Pacific Electronic Coin ($APECoin) adalah token ERC20 dan TRC20, yang terwujud pada April 2020 setelah konseptualisasinya pada Desember 2019. Inovasi ini lahir dari keinginan untuk mendorong praktik ramah lingkungan dan mendukung serangkaian proyek lingkungan yang bertujuan pada keberlanjutan dan inisiatif hijau. Tujuan dan Sasaran $APECoin bukan sekadar mata uang digital; ini dibayangkan sebagai alat tukar yang memungkinkan pengguna untuk terlibat dalam transaksi yang secara langsung menguntungkan penyebab lingkungan. Ekosistemnya dirancang untuk memfasilitasi berbagai aktivitas keuangan sambil mempromosikan adopsi praktik ramah lingkungan. Mata uang ini bertujuan terutama untuk: Mendukung Inisiatif Lingkungan: Melalui setiap transaksi, sebagian dialokasikan untuk mendanai proyek berkelanjutan yang bertujuan pada konservasi dan energi terbarukan. Mempromosikan Inovasi Ramah Lingkungan: Mendorong startup dan proyek yang sejalan dengan keberlanjutan lingkungan melalui penggunaan tokennya sebagai sarana nilai. Menciptakan Marketplace Berkelanjutan: Platform ini mencakup sebuah e-marketplace di mana transaksi keuangan dapat terjadi dalam kerangka yang didedikasikan untuk mempromosikan praktik hijau. Pencipta Asia Pacific Electronic Coin ($APECoin) Sementara rincian mengenai pencipta individu dari $APECoin tidak diungkapkan secara publik, proyek ini didukung secara signifikan oleh APEC Group, sebuah konsorsium yang fokus pada advokasi untuk inisiatif lingkungan. Dukungan ini menambah kredibilitas dan pentingnya proyek, menghubungkannya dengan jaringan yang lebih luas yang berkomitmen pada keberlanjutan dan praktik ramah lingkungan. Investor Asia Pacific Electronic Coin ($APECoin) Lanskap investasi di sekitar $APECoin tetap sebagian besar tidak diungkapkan. Nama-nama spesifik dari lembaga atau organisasi investasi yang mendukung cryptocurrency ini belum terungkap. Namun, yang jelas adalah semakin banyaknya minat di antara investor yang ingin mendukung proyek berkelanjutan yang menunjukkan potensi untuk berdampak di ruang crypto. Bagaimana Cara Kerja Asia Pacific Electronic Coin ($APECoin)? $APECoin menonjol karena model operasional inovatifnya, yang memanfaatkan teknologi blockchain dan kontrak pintar. Kombinasi ini tidak hanya memastikan efisiensi transaksi tetapi juga menegakkan kepatuhan terhadap kerangka regulasi, meningkatkan keamanan dan transparansi transaksi. Fitur Unik $APECoin Operasi Berbasis Blockchain: Dengan mendirikan operasinya di platform blockchain, $APECoin memastikan bahwa semua transaksi tidak dapat diubah dan dilindungi melalui teknik kriptografi canggih. Desentralisasi ini menegaskan integritas token dalam ekosistemnya. Kontrak Pintar: $APECoin menerapkan kontrak pintar yang memfasilitasi transaksi yang lancar sambil memastikan kepatuhan terhadap regulasi yang berlaku. Perjanjian otomatis ini meminimalkan kemungkinan perselisihan, memperlancar proses, dan berkontribusi pada kerangka transaksi yang dapat diandalkan. E-Marketplace: Salah satu fitur unggulan dari $APECoin adalah e-marketplace yang didedikasikan. Lingkungan digital ini berfungsi sebagai pusat layanan yang mendukung praktik ramah lingkungan, menyediakan platform untuk pertukaran yang lebih jauh mengembangkan visi hijau proyek ini. Melalui atribut-atribut ini, $APECoin menciptakan ceruk untuk dirinya sendiri dalam luasnya pasar cryptocurrency, secara efektif menggabungkan prinsip-prinsip blockchain dengan pengelolaan lingkungan. Garis Waktu Asia Pacific Electronic Coin ($APECoin) Memahami jalur $APECoin memberikan wawasan tentang tonggak perkembangan dan aspirasi masa depannya. Berikut adalah garis waktu yang menyoroti peristiwa signifikan dalam sejarah proyek ini: Desember 2019: Konseptualisasi Asia Pacific Electronic Coin, dimulai dengan ambisi untuk mendorong keberlanjutan melalui cryptocurrency. April 2020: Peluncuran resmi $APECoin, menandai masuknya ke pasar sebagai token khusus untuk proyek lingkungan. 2020-2021: Penyelenggaraan Initial Exchange Offering (IEO), memungkinkan pengguna untuk membeli $APECoin, di samping pendaftaran dengan berbagai platform pertukaran elektronik untuk meningkatkan aksesibilitas. Dalam perjalanannya yang relatif singkat, $APECoin telah membuat kemajuan signifikan dalam meletakkan dasar bagi cryptocurrency yang aman dan berdampak yang didorong oleh tujuan lingkungan. Kesimpulan Asia Pacific Electronic Coin ($APECoin) mencerminkan pernikahan antara teknologi dan tanggung jawab lingkungan, mendorong pertumbuhan dalam ekosistem crypto sambil mengadvokasi keberlanjutan. Dengan struktur unik, dukungan dari entitas terkemuka, dan visi untuk masa depan yang lebih hijau, $APECoin lebih dari sekadar cryptocurrency; ini adalah proyek perintis yang bertujuan untuk memupuk inovasi yang bertanggung jawab di wilayah Asia Pasifik. Melalui komitmennya terhadap inklusi keuangan dan dukungannya terhadap inisiatif lingkungan, $APECoin menjadi contoh yang kuat tentang bagaimana mata uang digital dapat dimanfaatkan untuk dampak sosial yang positif. Saat proyek ini terus berkembang, para pemangku kepentingan dalam komunitas crypto dan seterusnya akan dengan antusias mengamati bagaimana $APECoin membentuk percakapan seputar praktik berkelanjutan di dunia cryptocurrency yang sedang berkembang.

102 Total TayanganDipublikasikan pada 2024.12.03Diperbarui pada 2024.12.03

Apa Itu APECOIN

Cara Membeli APE

Selamat datang di HTX.com! Kami telah membuat pembelian ApeCoin (APE) menjadi mudah dan nyaman. Ikuti panduan langkah demi langkah kami untuk memulai perjalanan kripto Anda.Langkah 1: Buat Akun HTX AndaGunakan alamat email atau nomor ponsel Anda untuk mendaftar akun gratis di HTX. Rasakan perjalanan pendaftaran yang mudah dan buka semua fitur.Dapatkan Akun SayaLangkah 2: Buka Beli Kripto, lalu Pilih Metode Pembayaran AndaKartu Kredit/Debit: Gunakan Visa atau Mastercard Anda untuk membeli ApeCoin (APE) secara instan.Saldo: Gunakan dana dari saldo akun HTX Anda untuk melakukan trading dengan lancar.Pihak Ketiga: Kami telah menambahkan metode pembayaran populer seperti Google Pay dan Apple Pay untuk meningkatkan kenyamanan.P2P: Lakukan trading langsung dengan pengguna lain di HTX.Over-the-Counter (OTC): Kami menawarkan layanan yang dibuat khusus dan kurs yang kompetitif bagi para trader.Langkah 3: Simpan ApeCoin (APE) AndaSetelah melakukan pembelian, simpan ApeCoin (APE) di akun HTX Anda. Selain itu, Anda dapat mengirimkannya ke tempat lain melalui transfer blockchain atau menggunakannya untuk memperdagangkan mata uang kripto lainnya.Langkah 4: Lakukan trading ApeCoin (APE)Lakukan trading ApeCoin (APE) dengan mudah di pasar spot HTX. Cukup akses akun Anda, pilih pasangan perdagangan, jalankan trading, lalu pantau secara real-time. Kami menawarkan pengalaman yang ramah pengguna baik untuk pemula maupun trader berpengalaman.

170 Total TayanganDipublikasikan pada 2025.02.24Diperbarui pada 2026.06.02

Cara Membeli APE

Diskusi

Selamat datang di Komunitas HTX. Di sini, Anda bisa terus mendapatkan informasi terbaru tentang perkembangan platform terkini dan mendapatkan akses ke wawasan pasar profesional. Pendapat pengguna mengenai harga APE (APE) disajikan di bawah ini.

活动图片