Public Wi-Fi and a Phone Call: How They Became the Perfect Trap to Steal $5000 in Crypto Assets?

比推Pubblicato 2026-01-09Pubblicato ultima volta 2026-01-09

Introduzione

An individual lost approximately $5,000 in cryptocurrency assets after connecting to a public hotel Wi-Fi network during a vacation. The attack began when the victim was overheard discussing crypto and using a Phantom wallet in a public area, making them a target. While browsing on the unsecured Wi-Fi, the attacker executed a man-in-the-middle attack, injecting malicious code into a seemingly legitimate webpage. The victim was using Jupiter Exchange to swap tokens when a fraudulent transaction approval request was triggered, disguised as a normal operation. Instead of a direct fund transfer, the request asked for “authorization” or “session approval,” granting the attacker permission to act on the wallet. The victim approved, believing it was part of the Jupiter transaction. The attacker waited until the victim left the hotel to drain the wallet of SOL, tokens, and NFTs. Key mistakes included: using public Wi-Fi instead of a mobile hotspot, discussing crypto in public, and approving a transaction without thorough verification. The wallet was a secondary hot wallet, not the main storage, preventing greater losses. The incident highlights the risks of public networks and the importance of transaction scrutiny.

Author: The Smart Ape

Compiled by: Deep Tide TechFlow

Original title: After Three Days on Hotel Wi-Fi, My Crypto Wallet Was Drained of $5000


A few days ago, I went with my family to a very nice hotel for a year-end holiday. One day after leaving the hotel, my wallet was completely emptied. I was puzzled, as I had neither clicked on any phishing links nor signed any malicious transactions.

After hours of investigation and seeking help from experts, I finally figured out the truth. It turned out to be due to the hotel's Wi-Fi network, a brief phone call, and a series of foolish mistakes.

Like most cryptocurrency enthusiasts, I brought my laptop with me, thinking I could squeeze in some work while on vacation with my family. My wife repeatedly insisted that I not work during these three days—I really should have listened to her.

Like other guests, I connected to the hotel's Wi-Fi network. This network didn't require a password; it only needed to be logged in through a captive portal.

I worked as usual in the hotel without doing anything risky: I didn't create new wallets, click on strange links, or access suspicious decentralized applications (dApps). I just checked X (Twitter), my balances, Discord, Telegram, etc.

At one point, I received a call from a crypto friend, and we chatted about market trends, Bitcoin, and other cryptocurrency-related matters. But what I didn't know was that someone nearby was eavesdropping on our conversation and realized I was involved in cryptocurrency. This was my first mistake. The eavesdropper learned from our conversation that I was using a Phantom wallet and that I was a user with a significant holding.

This made me his target.

In a public Wi-Fi network, all devices share the same network, and the visibility between devices is actually higher than you might think. There is almost no real protection between users, which creates an opportunity for a "Man-in-the-Middle Attack." The attacker acts like a middleman, quietly inserting themselves between you and the internet, much like someone secretly reading and tampering with your mail before it reaches you.

While I was browsing the web on the hotel Wi-Fi, one website appeared to load normally, but in reality, malicious code had been injected behind the page. I didn't notice anything unusual at the time. If I had installed some security tools, I might have detected these issues, but unfortunately, I hadn't.

Normally, a website might request your wallet to sign certain operations. The Phantom wallet would pop up a window where you could choose to approve or reject. Generally, you would trust the website and browser and sign without worry. However, that day, I shouldn't have.

Just as I was performing a token swap on @JupiterExchange, the malicious code triggered a wallet request that replaced my normal swap operation. I could have detected it as a malicious request by carefully checking the transaction details, but because I was already performing a swap on Jupiter, I didn't suspect a thing.

That day, I didn't sign any transaction to transfer funds; instead, I signed an authorization. This was exactly why my assets were stolen days later.

The malicious code didn't directly ask me to send SOL (Solana), as that would have been too obvious. Instead, it requested me to "authorize access," "approve account," or "confirm session." In simple terms, I was actually giving another address permission to operate on my behalf.

I approved it because I mistakenly thought it was related to my operation on Jupiter. At the time, the message popped up by the Phantom wallet looked technical, didn't show any amount, and didn't prompt for an immediate transfer.

And that was all the attacker needed. He patiently waited until I left the hotel before taking action. He transferred my SOL, withdrew my tokens, and moved my NFTs to another address.

I never thought something like this would happen to me. Fortunately, this wasn't my main wallet but a hot wallet used for specific operations, not for long-term asset holding. Even so, I made many mistakes, and I believe I am primarily responsible.

First, I should never have connected to the hotel's public Wi-Fi. I should have used my phone's hotspot instead.

My second mistake was talking about cryptocurrency in the hotel's public area, where many people could have overheard our conversation. My father once warned me never to let others know you're involved in cryptocurrency. This time, I was lucky; some people have even faced kidnapping or worse because of their crypto assets.

Another mistake was approving the wallet request without paying full attention. Because I was sure the request came from Jupiter, I didn't analyze it carefully. In fact, every wallet request should be carefully reviewed, even on trusted applications. Requests can be intercepted and may not actually come from the app you think.

In the end, I lost about $5000 from a secondary wallet. While it's not the worst-case scenario, it's still very frustrating.


Twitter:https://twitter.com/BitpushNewsCN

BitPush TG Discussion Group:https://t.me/BitPushCommunity

BitPush TG Subscription: https://t.me/bitpush

Original article link:https://www.bitpush.news/articles/7601380

Crypto di tendenza

Domande pertinenti

QWhat was the primary method the attacker used to compromise the victim's crypto wallet?

AThe attacker used a Man-in-the-Middle (MitM) attack by exploiting the insecure public hotel Wi-Fi network. They intercepted the victim's web traffic and injected malicious code into a webpage, which triggered a deceptive wallet authorization request.

QWhat specific mistake did the victim make that allowed the attacker to identify him as a target?

AThe victim discussed cryptocurrency, his use of the Phantom wallet, and his substantial holdings during a phone call in a public area of the hotel, which was overheard by the attacker.

QWhat type of transaction did the victim accidentally sign, instead of a direct fund transfer?

AThe victim signed an authorization or approval request, which granted permission for another address to operate on their behalf. This did not immediately transfer funds but gave the attacker the ability to do so later.

QWhy didn't the victim suspect the malicious transaction request when it appeared?

AThe request appeared while he was performing a legitimate token swap on the Jupiter Exchange platform. He assumed the request was part of that normal operation and did not carefully inspect the technical details of the transaction, which showed no immediate transfer of funds.

QWhat were the two security precautions the victim identified that could have prevented this attack?

AFirst, he should not have used the hotel's public Wi-Fi and instead used his phone's mobile hotspot. Second, he should never have discussed his cryptocurrency activities in a public space where he could be overheard.

Letture associate

Misjudged A-Shares: Resilience, Expectations, and Confidence

China's A-share market recently faced selling pressure, especially in tech sectors, initially triggered by a global tech sell-off that began in South Korea. However, the article argues this is a case of "mistaken injury" and highlights the market's underlying resilience. This resilience stems from three main pillars: **1) Tech Sector Fundamentals:** Unlike Korea's market dominated by a few memory chip stocks, China's tech sector is diversified across computing, communications, electronics, and semiconductors, supported by dual narratives of global AI supply chains and domestic substitution. Core areas like optical modules and fiber optics continue to show strong earnings growth. **2) "National Team" Support:** State-backed institutions and large corporations have made significant market purchases and announced buybacks, providing liquidity and signaling confidence. This is seen as a stabilizing policy signal, often associated with market bottoms. **3) Broader Market Pillars:** Other major sectors are showing endogenous recovery momentum. Consumer stocks benefit from stabilizing CPI and signs of sector recovery (e.g., liquor price hikes). Cyclical sectors like aluminum have high earnings, potential price increases due to tight supply, and low valuations. The financial sector offers stable dividends and low valuations. The conclusion is that the sell-off was driven by external contagion, not a collapse in fundamentals. With strong policy support and recovering momentum across key sectors, the A-share market possesses the toughness to regain stability.

marsbit29 min fa

Misjudged A-Shares: Resilience, Expectations, and Confidence

marsbit29 min fa

The Clarity Act's Journey Through Congress: The Thorny Path of Bipartisan Compromise in the U.S.

The U.S. Congress is struggling to advance the crypto market structure bill known as the Clarity Act, with bipartisan compromise proving difficult. Key hurdles include unresolved disputes over "yield" products and, more critically, the inclusion of strong ethics provisions for elected officials—a non-negotiable demand for many Democrats. While a compromise on yield was reached in May, securing only limited Democratic support in committee, the separate Senate Agriculture Committee version later passed with no Democratic votes due to the ethics impasse. As Republicans push for a full Senate vote in July, demands for ethics rules have expanded, and other contentious issues like developer protections and concerns from law enforcement and large banks further complicate negotiations. Despite consensus on the need for legislation, the path forward is unclear. Recent discussions between senators and White House officials aim to find acceptable ethics language. Some lawmakers question whether a compromise text can garner enough bipartisan support, with one Democrat stating the current proposal lacks the strong ethics provisions required for their vote. Potential short-term goals for the crypto community include symbolic Senate action before the August recess, a longer-term aim for passage by 2026, or establishing a detailed framework that addresses ethics and other compromises. The process remains arduous, relying on the traditional, vote-by-vote effort to build bipartisan support.

marsbit48 min fa

The Clarity Act's Journey Through Congress: The Thorny Path of Bipartisan Compromise in the U.S.

marsbit48 min fa

Are Kalshi and Polymarket Founders at Odds? This Business Rivalry Is More Brutal Than You Think

"The Rivalry Between Kalshi and Polymarket Founders Turns Bitter and Litigious" The intense feud between Tarek Mansour, CEO of Kalshi, and Shayne Coplan, founder of Polymarket, has escalated far beyond typical business competition into personal animosity and regulatory battles. Both lead billion-dollar prediction market platforms, but their approaches differ sharply. Kalshi positions itself as the compliant operator, securing U.S. regulatory approval before launching. In contrast, Polymarket initially operated offshore, allowing U.S. users to access its platform via VPN, which drew regulatory scrutiny. The conflict reached a peak in November 2024 when FBI agents raided Coplan's New York apartment. While Coplan publicly blamed political motives, his team privately suspected Kalshi was involved. According to sources, Kalshi's lawyers had previously reported Polymarket's operations to federal prosecutors, highlighting its accessibility to U.S. users despite a ban. This incident fueled mutual accusations and underhanded tactics, including social media smear campaigns and attempts to sabotage each other's major business deals. Their rivalry also played out in Washington, influencing regulatory debates. Kalshi actively lobbied against Polymarket's practices, framing them as illegal and unethical. Polymarket, after facing a CFTC fine and investigation, later acquired a licensed U.S. firm to launch a domestic app, regaining a foothold. Despite the hostility, both companies have seen massive growth, with combined trading volumes soaring. However, increased regulatory scrutiny, particularly around insider trading on Polymarket's platform, continues to pose challenges. The founders' deep-seated mutual disdain ensures their battle for market dominance remains as much a personal vendetta as a commercial one.

marsbit57 min fa

Are Kalshi and Polymarket Founders at Odds? This Business Rivalry Is More Brutal Than You Think

marsbit57 min fa

Trading

Spot

Articoli Popolari

Cosa è APECOIN

Comprendere la Moneta Elettronica dell'Asia Pacifico ($APECoin) In un'era in cui l'intersezione tra tecnologia e ambientalismo sta diventando sempre più critica, le criptovalute stanno lasciando il segno come potenziali catalizzatori di cambiamento. Tra queste innovazioni, la Moneta Elettronica dell'Asia Pacifico ($APECoin) si distingue come un progetto unico progettato per sostenere iniziative ambientali nella regione dell'Asia Pacifico. Questo articolo approfondisce le fondamenta, le caratteristiche uniche e l'impatto di $APECoin all'interno del più ampio panorama della blockchain. Cos'è la Moneta Elettronica dell'Asia Pacifico ($APECoin)? La Moneta Elettronica dell'Asia Pacifico ($APECoin) è un token ERC20 e TRC20, realizzato ad aprile 2020 dopo la sua concettualizzazione a dicembre 2019. Questa innovazione è nata dal desiderio di promuovere pratiche ecologiche e sostenere una serie di progetti ambientali volti alla sostenibilità e alle iniziative verdi. Obiettivi e Scopi $APECoin non è semplicemente una valuta digitale; è concepita come un mezzo di scambio che consente agli utenti di partecipare a transazioni che beneficiano direttamente cause ambientali. Il suo ecosistema è progettato per facilitare varie attività finanziarie mentre promuove l'adozione di pratiche ecologiche. La valuta mira principalmente a: Supportare Iniziative Ambientali: Attraverso ogni transazione, una parte è destinata al finanziamento di progetti sostenibili volti alla conservazione e all'energia rinnovabile. Promuovere Innovazioni Eco-Friendly: Incoraggiare startup e progetti che si allineano con la sostenibilità ambientale attraverso l'uso del suo token come mezzo di valore. Creare un Mercato Sostenibile: La piattaforma include un'e-marketplace dove possono avvenire transazioni finanziarie all'interno di un framework dedicato alla promozione di pratiche verdi. Creatore della Moneta Elettronica dell'Asia Pacifico ($APECoin) Sebbene i dettagli riguardanti il creatore individuale di $APECoin non siano divulgati pubblicamente, il progetto è sostenuto in modo significativo dal Gruppo APEC, un consorzio focalizzato sulla difesa di iniziative ambientali. Questo sostegno aggiunge credibilità e significato al progetto, collegandolo a una rete più ampia impegnata nella sostenibilità e nelle pratiche ecologiche. Investitori della Moneta Elettronica dell'Asia Pacifico ($APECoin) Il panorama degli investimenti che circonda $APECoin rimane in gran parte non divulgato. I nomi specifici di fondazioni o organizzazioni di investimento che supportano questa criptovaluta non sono stati ancora rivelati. Tuttavia, ciò che è evidente è un crescente interesse tra gli investitori desiderosi di sostenere progetti sostenibili che dimostrano potenziale impatto nel mondo delle criptovalute. Come funziona la Moneta Elettronica dell'Asia Pacifico ($APECoin)? $APECoin si distingue per il suo innovativo modello operativo, che sfrutta la tecnologia blockchain e i contratti intelligenti. Questa combinazione non solo garantisce efficienza nelle transazioni, ma assicura anche il rispetto dei framework normativi, migliorando la sicurezza e la trasparenza delle transazioni. Caratteristiche Uniche di $APECoin Operazioni Basate su Blockchain: Stabilendo le sue operazioni su una piattaforma blockchain, $APECoin garantisce che tutte le transazioni siano immutabili e protette tramite tecniche crittografiche avanzate. Questa decentralizzazione sottolinea l'integrità del token all'interno del suo ecosistema. Contratti Intelligenti: $APECoin impiega contratti intelligenti che facilitano transazioni senza soluzione di continuità mentre garantiscono conformità alle normative applicabili. Questi accordi automatizzati riducono la possibilità di dispute, semplificano i processi e contribuiscono a un framework di transazione affidabile. E-Marketplace: Una delle caratteristiche distintive di $APECoin è il suo e-marketplace dedicato. Questo ambiente digitale funge da hub per servizi che promuovono pratiche ecologiche, fornendo una piattaforma per scambi che avanzano la visione verde del progetto. Attraverso queste attribuzioni, $APECoin si ritaglia una nicchia all'interno dell'ampio mercato delle criptovalute, sposando efficacemente i principi della blockchain con la responsabilità ambientale. Cronologia della Moneta Elettronica dell'Asia Pacifico ($APECoin) Comprendere la traiettoria di $APECoin fornisce un'idea delle sue pietre miliari di sviluppo e delle aspirazioni future. Ecco una cronologia che evidenzia eventi significativi nella storia del progetto: Dicembre 2019: Concettualizzazione della Moneta Elettronica dell'Asia Pacifico, iniziata con l'ambizione di promuovere la sostenibilità attraverso la criptovaluta. Aprile 2020: Lancio ufficiale di $APECoin, segnando il suo ingresso nel mercato come token dedicato ai progetti ambientali. 2020-2021: Conduzione dell'Offerta Iniziale di Scambio (IEO), che consente agli utenti di acquistare $APECoin, insieme alla registrazione su varie piattaforme di scambio elettronico per migliorarne l'accessibilità. Nel suo relativamente breve viaggio, $APECoin ha fatto significativi progressi nel gettare le basi per una criptovaluta sicura e di impatto guidata da obiettivi ambientali. Conclusione La Moneta Elettronica dell'Asia Pacifico ($APECoin) incarna il matrimonio tra tecnologia e responsabilità ambientale, promuovendo la crescita nell'ecosistema crypto mentre sostiene la sostenibilità. Con la sua struttura unica, il sostegno da parte di enti rinomati e una visione per un futuro più verde, $APECoin è più di una semplice criptovaluta; è un progetto pionieristico volto a nutrire l'innovazione responsabile nella regione dell'Asia Pacifico. Attraverso il suo impegno per l'inclusione finanziaria e il supporto delle iniziative ambientali, si presenta come un esempio formidabile di come le valute digitali possano essere utilizzate per un impatto sociale positivo. Mentre il progetto continua a evolversi, gli stakeholder all'interno della comunità crypto e oltre osserveranno con interesse come $APECoin plasmi la conversazione sulle pratiche sostenibili nel crescente mondo delle criptovalute.

61 Totale visualizzazioniPubblicato il 2024.12.03Aggiornato il 2024.12.03

Cosa è APECOIN

Come comprare APE

Benvenuto in HTX.com! Abbiamo reso l'acquisto di ApeCoin (APE) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente ApeCoinAPE.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva ApeCoin (APE)Dopo aver acquistato ApeCoin (APE), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia ApeCoin (APE)Scambia facilmente ApeCoin (APE) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

107 Totale visualizzazioniPubblicato il 2025.02.24Aggiornato il 2026.06.02

Come comprare APE

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di APE APE sono presentate come di seguito.

活动图片