¿Cómo se convirtieron el Wi-Fi público y una llamada telefónica en la trampa perfecta para robar 5000 dólares en criptoactivos?

比推Published on 2026-01-09Last updated on 2026-01-09

Abstract

Resumen: El autor perdió 5000 dólares en criptoactivos de su billetera Phantom tras conectarse a la red Wi-Fi pública de un hotel durante unas vacaciones. El ataque ocurrió mediante un "ataque de intermediario" (Man-in-the-Middle) en la red no segura. Un atacante que escuchó su conversación telefónica sobre criptomonedas identificó su actividad y inyectó código malicioso en una página web. Esto generó una solicitud de autorización fraudulenta que el autor aprobó por error mientras operaba en Jupiter Exchange, creyendo que era legítima. La aprobación otorgó permisos para que el atacante, días después, vaciara la billetera. Errores clave: usar Wi-Fi público, hablar de cripto en público y no verificar minuciosamente las solicitudes de la billetera.

Autor: The Smart Ape

Compilado por: Deep Tide TechFlow

Título original: Tras conectarme tres días al Wi-Fi del hotel, me robaron 5000 dólares de mi cartera cripto


Hace unos días, fui con mi familia a un hotel muy agradable para pasar las vacaciones de fin de año. Un día después de dejar el hotel, mi cartera fue vaciada por completo. No lo entendía, porque no había hecho clic en ningún enlace de phishing ni había firmado ninguna transacción maliciosa.

Después de horas de investigación y con la ayuda de expertos, finalmente entendí lo que sucedió. Todo fue debido a la red Wi-Fi del hotel, una breve llamada telefónica y una serie de errores estúpidos.

Como la mayoría de los entusiastas de las criptomonedas, llevaba mi laptop conmigo, pensando en poder trabajar un poco mientras acompañaba a mi familia de vacaciones. Mi esposa insistió en que no trabajara durante esos tres días, y debería haberle hecho caso.

Como los demás huéspedes, me conecté a la red Wi-Fi del hotel. Esta red no requería contraseña, solo había que iniciar sesión a través de una página de verificación (captive portal).

Trabajé como de costumbre en el hotel, sin hacer nada arriesgado: no creé nuevas carteras, no hice clic en enlaces extraños, ni accedí a aplicaciones descentralizadas (dApps) sospechosas. Solo revisé X (Twitter), mis saldos, Discord y Telegram, entre otros.

En un momento, recibí una llamada de un amigo del mundo cripto, hablamos sobre el mercado, Bitcoin y temas relacionados con las criptomonedas. Pero lo que no sabía era que alguien cerca estaba escuchando nuestra conversación y se dio cuenta de que yo estaba involucrado en temas de criptomonedas. Este fue mi primer error. A través de nuestra conversación, supo que usaba la cartera Phantom y que era un usuario con tenencias considerables.

Esto hizo que me eligiera como objetivo.

En las redes Wi-Fi públicas, todos los dispositivos comparten la misma red, y la visibilidad entre dispositivos es mayor de lo que imaginas. Casi no hay medidas de protección reales entre usuarios, lo que abre la puerta a un "Ataque de Hombre en el Medio" (Man-in-the-Middle Attack). El atacante actúa como un intermediario, insertándose silenciosamente entre tú e Internet, como si leyera y alterara tu correo antes de que te llegue.

Mientras navegaba por la web en el Wi-Fi del hotel, un sitio web parecía cargar normalmente, pero en realidad, detrás de la página, se había inyectado código malicioso adicional. En ese momento no noté nada anormal. Si hubiera tenido instaladas algunas herramientas de seguridad, podría haber detectado estos problemas, pero lamentablemente, no las tenía.

Normalmente, los sitios web pueden solicitar que tu cartera firme ciertas operaciones. La cartera Phantom muestra una ventana emergente donde puedes elegir aprobar o rechazar. Generalmente, firmas con confianza porque confías en el sitio y el navegador. Sin embargo, ese día no debería haberlo hecho.

Justo cuando estaba realizando una operación de intercambio de tokens en la plataforma @JupiterExchange, el código malicioso activó una solicitud de cartera que reemplazó mi operación normal de intercambio. Podría haber descubierto que era una solicitud maliciosa revisando cuidadosamente los detalles de la transacción, pero como ya estaba realizando la operación en Jupiter, no sospeché en absoluto.

Ese día no firmé ninguna transacción que transfiriera fondos, sino que firmé una autorización. Esta fue la razón por la que los activos fueron robados días después.

El código malicioso no me pidió directamente que enviara SOL (Solana), porque eso habría sido demasiado obvio. En su lugar, solicitó que "autorizara el acceso", "aprobase la cuenta" o "confirmase la sesión". En términos simples, en realidad le estaba dando permiso a otra dirección para operar en mi nombre.

Aprobé porque pensé erróneamente que estaba relacionado con mi operación en Jupiter. En ese momento, el mensaje emergente de Phantom parecía muy técnico, no mostraba ningún monto ni indicaba una transferencia inmediata.

Y eso fue todo lo que el atacante necesitó. Esperó pacientemente hasta que me fui del hotel para actuar. Transfirió mis SOL, extrajo mis tokens y trasladó mis NFT a otra dirección.

Nunca pensé que algo así me pasaría a mí. Afortunadamente, esta no era mi cartera principal, sino una cartera caliente para operaciones específicas, no destinada a mantener activos a largo plazo. Pero aun así, cometí muchos errores y creo que soy el principal responsable.

En primer lugar, nunca debería haberme conectado al Wi-Fi público del hotel. Debería haber usado el punto de acceso de mi teléfono móvil.

Mi segundo error fue hablar de criptomonedas en un área pública del hotel, donde muchas personas pudieron escuchar nuestra conversación. Mi padre me advirtió que nunca dejara que los demás supieran que me dedicaba a las criptomonedas. Esta vez tuve suerte, algunas personas incluso han sufrido secuestros o cosas peores por sus criptoactivos.

Otro error fue que aprobé la solicitud de la cartera sin prestar toda mi atención. Como estaba seguro de que la solicitud provenía de Jupiter, no la analicé detenidamente. De hecho, cada solicitud de cartera debe ser revisada seriamente, incluso en aplicaciones de confianza. La solicitud podría haber sido interceptada y en realidad no provenir de la aplicación que creías.

Finalmente, perdí alrededor de 5000 dólares de una cartera secundaria. Aunque no es lo peor, sigue siendo muy frustrante.


Twitter:https://twitter.com/BitpushNewsCN

Grupo de Telegram de Bitpush:https://t.me/BitPushCommunity

Suscripción a Telegram de Bitpush: https://t.me/bitpush

Enlace original:https://www.bitpush.news/articles/7601380

Related Questions

Q¿Cómo logró el atacante robar los activos cripto de la víctima a través del Wi-Fi del hotel?

AEl atacante utilizó un ataque 'Man-in-the-Middle' en la red Wi-Fi pública del hotel, inyectó código malicioso en una página web que visitó la víctima, y engañó al usuario para que aprobara una solicitud de autorización que permitió al atacante transferir los fondos posteriormente.

Q¿Qué error cometió la víctima al hablar por teléfono en el área pública del hotel?

ALa víctima discutió abiertamente sobre criptomonedas, mercados y su uso de la billetera Phantom, lo que alertó al atacante sobre sus posesiones y lo convirtió en un objetivo.

Q¿Por qué la víctima no detectó la transacción maliciosa al firmarla?

ACreía que la solicitud de firma era parte de una operación legítima en Jupiter Exchange, y no revisó detenidamente los detalles técnicos de la transacción, que en realidad otorgaba permisos a una dirección maliciosa.

Q¿Qué medidas de seguridad podrían haber prevenido este robo según el artículo?

AUsar conexión de datos móviles (hotspot) en lugar de Wi-Fi público, evitar hablar de cripto en lugares públicos, y revisar meticulosamente cada solicitud de firma de la billetera, incluso en aplicaciones confiables.

Q¿Qué tipo de autorización firmó la víctima que permitió el robo días después?

AFirmó una autorización de permiso que concedió a otra dirección la capacidad de operar en su nombre, sin transferir fondos inmediatamente, lo que el atacante explotó días después para vaciar la billetera.

Related Reads

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

U.S. Federal Reserve officials who previously advocated for rate cuts, including Governor Christopher Waller, have recently shifted their stance, with many now not ruling out the possibility of future rate hikes. This sets a challenging stage for new Fed Chair Kevin Warsh's first policy meeting. Appointed by President Trump based on his dovish views, Warsh now faces a committee where the debate has pivoted from "when to cut" to "whether to hike," driven by persistent inflation above 3%, a strong labor market, and supply-side pressures from AI infrastructure demands and geopolitical tensions. Key figures illustrate the shift. Governor Waller, once concerned about employment, now says data has pushed him toward considering rate increases. Even moderate voices like Governor Lisa Cook, while expecting inflation to ease, have indicated readiness to hike if it fails to do so. Long-time hawks such as regional Fed presidents Beth Hammack, Lorie Logan, and Neel Kashkari have grown more vocal, arguing that the real policy rate is effectively falling and that action may soon be needed. The upcoming Fed meeting is expected to keep rates steady but will likely remove the "easing bias" from its statement, signaling a neutral stance between cuts and hikes. The quarterly "dot plot" is anticipated to show most officials projecting no cuts this year, with some potentially indicating hikes. Chair Warsh, a critic of the Fed's reliance on forward guidance like the dot plot, must navigate communicating this pivot using tools he has questioned, all while steering policy in a direction counter to the preferences of the president who appointed him. The consensus suggests the Fed's next move could well be a rate increase.

marsbit34m ago

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

marsbit34m ago

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

The article analyzes the three leading Chinese optical module companies, collectively nicknamed "Yi Zhong Tian": Xinyisheng, Zhongji Innolight, and TFC Optical Communication. It evaluates their "cost-performance" not by current stock price, but through three lenses: PEG ratio (growth vs. valuation), earnings quality, and premium/discount for certainty. Xinyisheng shows the most attractive PEG ratio and high profitability, but its valuation reflects discounts for risks like high customer concentration and reliance on overseas markets. Zhongji Innolight, the most expensive, commands a premium for its market leadership, dominant share in key products like 800G/1.6T modules, and higher earnings certainty, though it faces geopolitical risks. TFC Optical, as an upstream component supplier ("water seller"), has the highest gross margin and bets on the long-term CPO/NPO architecture trend, but trades at a high valuation with more stable, less explosive growth. The core argument is that while these companies dominate module assembly, the true profit pool and technological moat lie upstream in laser and switch chips, currently controlled by U.S. firms like Lumentum and Coherent. The long-term "cost-performance" for these Chinese leaders hinges on whether the domestic industry, exemplified by companies like Yuanjie Technology, can successfully move up the value chain into high-power laser chips. Otherwise, their high growth may remain confined to the lower-margin assembly segment.

marsbit44m ago

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

marsbit44m ago

Has the Crypto Market Bottomed? Here's What Institutions Think

The crypto market is in a period of significant debate, with leading institutions offering differing views on whether a bottom has been reached. Three prominent firms have published detailed analyses: * **Galaxy Digital** argues Bitcoin has **not yet bottomed**. Their analysis of 13 historical indicators across six dimensions (valuation, profit-taking, miner pressure, etc.) shows only four are fully met. They project a potential bottom range between $30k and $54k. * **NYDIG** states a bottom is **possible but not likely**. While metrics are close to historic bear market extremes, they note the absence of a classic panic-selling event. They also suggest increased institutional adoption may have structurally altered the market cycle, potentially leading to a shallower downturn. * **Standard Chartered Bank** asserts the **bottom has already occurred** at around $59k. They cite two key factors: potential US-Iran diplomatic progress and the anticipated SpaceX IPO, which they believe absorbed capital and caused ETF selling pressure that is now subsiding. They forecast a year-end price target of $100k. Despite the surface-level disagreement, the reports share critical common ground more valuable for long-term investors: 1. All three believe the market bottom will form **within this year**. 2. All agree the current price is **closer to the bottom than to previous highs**. 3. All maintain a **bullish long-term outlook** for Bitcoin and a new cycle. The core takeaway is that while the exact bottom price ($40k, $50k, or $60k) is debated, the consensus is that a bottom is imminent. For long-term holders, the primary focus should not be pinpointing the absolute low, but on the future potential for prices to reach $100k, $200k, or higher. The fundamental thesis for Bitcoin—sovereign debt accumulation, inflation, declining trust in centralized institutions, global digitization, and improved accessibility—remains intact and is arguably strengthening. The overall landscape is viewed as more favorable than in previous crypto winters.

marsbit54m ago

Has the Crypto Market Bottomed? Here's What Institutions Think

marsbit54m ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

China's Photonics Industry: Bottlenecks and Breakthroughs In the global AI race, computing chips dominate the narrative, but the underlying bottleneck increasingly defining the scale of AI clusters is light—or more specifically, optical connectivity. Optical modules, which translate electrical signals to light and vice versa, are crucial for connecting thousands of GPUs in AI data centers, preventing data congestion and ensuring efficient model training. High-speed modules (800G, 1.6T) are now standard, with performance hinging on advanced DSP (Digital Signal Processor) chips. This is where a critical dependency lies. Two US giants—Marvell and Broadcom—collectively dominate over 90% of the high-end DSP chip market. Chinese optical module leaders like Zhongji Innolight and Eoptolink rely on these chips to manufacture modules for overseas AI customers, primarily in North America. While this creates a supply chain vulnerability, complete decoupling is difficult. Marvell derives over half its revenue from Greater China, and the US firms depend on Chinese partners for chip packaging and optical components. The risk from laser chips (e.g., from Lumentum), another key component, is considered more manageable due to multiple global suppliers and faster progress in domestic alternatives from companies like YOFC and Accelink. To mitigate risks, China's industry is pursuing a multi-pronged strategy: diversifying supply chains and locking in long-term orders; fostering a domestic market ecosystem to adopt homegrown DSPs from firms like Huawei HiSilicon and CETC; accelerating R&D in high-speed DSPs and advanced packaging; and investing in next-gen technologies like silicon photonics and Co-Packaged Optics (CPO) to reduce reliance on discrete DSPs. The ultimate solution lies not in short-term博弈 but in persistent advancement of domestic high-end chip R&D and manufacturing. While challenges remain in performance, certification, and ecosystem building, China's vast domestic market and manufacturing base provide a crucial buffer, buying time for the industry to achieve greater technological independence.

marsbit1h ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

marsbit1h ago

Trading

Spot
Futures

Hot Articles

How to Buy APE

Welcome to HTX.com! We've made purchasing ApeCoin (APE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy ApeCoin (APE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your ApeCoin (APE)After purchasing your ApeCoin (APE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade ApeCoin (APE)Easily trade ApeCoin (APE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

3.9k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy APE

What is APECOIN

Understanding Asia Pacific Electronic Coin ($APECoin) In an era where the intersection of technology and environmentalism is becoming increasingly critical, cryptocurrencies are making their mark as potential catalysts for change. Among these innovations, Asia Pacific Electronic Coin ($APECoin) stands out as a distinct project designed to support environmental initiatives across the Asia Pacific region. This article delves into the foundation, unique features, and impact of $APECoin within the broader blockchain landscape. What is Asia Pacific Electronic Coin ($APECoin)? Asia Pacific Electronic Coin ($APECoin) is an ERC20 and TRC20 token, brought to fruition in April 2020 after its conceptualization in December 2019. This innovation was born out of a desire to foster eco-friendly practices and support a suite of environmental projects aimed at sustainability and green initiatives. Aims and Objectives $APECoin is not merely a digital currency; it is envisioned as a medium of exchange that enables users to engage in transactions that directly benefit environmental causes. Its ecosystem is designed to facilitate various financial activities while promoting the adoption of eco-friendly practices. The currency aims primarily to: Support Environmental Initiatives: Through every transaction, a portion is allocated to funding sustainable projects aimed at conservation and renewable energy. Promote Eco-Friendly Innovations: Encouraging startups and projects that align with environmental sustainability through the use of its token as a means of value. Create a Sustainable Marketplace: The platform includes an e-marketplace where financial transactions can occur within a framework dedicated to promoting green practices. Creator of Asia Pacific Electronic Coin ($APECoin) While the details regarding the individual creator of $APECoin are not publicly disclosed, the project is significantly backed by the APEC Group, a consortium focused on advocating for environmental initiatives. This backing adds credibility and significance to the project, connecting it to a broader network committed to sustainability and eco-friendly practices. Investors of Asia Pacific Electronic Coin ($APECoin) The investment landscape surrounding $APECoin remains largely undisclosed. Specific names of investment foundations or organizations supporting this cryptocurrency have yet to be revealed. However, what is evident is a growing interest among investors keen on supporting sustainable projects that demonstrate potential for impact in the crypto space. How does Asia Pacific Electronic Coin ($APECoin) work? $APECoin stands out due to its innovative operational model, which leverages blockchain technology and smart contracts. This combination not only ensures transactional efficiency but also enforces adherence to regulatory frameworks, enhancing the security and transparency of transactions. Unique Features of $APECoin Blockchain-Based Operations: By establishing its operations on a blockchain platform, $APECoin ensures that all transactions are immutable and secured through advanced cryptographic techniques. This decentralization underscores the integrity of the token within its ecosystem. Smart Contracts: $APECoin employs smart contracts that facilitate seamless transactions while ensuring compliance with applicable regulations. These automated agreements minimize the possibility of disputes, streamline processes, and contribute to a reliable transaction framework. E-Marketplace: One of the hallmark features of $APECoin is its dedicated e-marketplace. This digital environment serves as a hub for services that endorse eco-friendly practices, providing a platform for exchanges that further the project's green vision. Through these attributes, $APECoin carves a niche for itself within the vast expanse of the cryptocurrency market, effectively marrying the principles of blockchain with environmental stewardship. Timeline of Asia Pacific Electronic Coin ($APECoin) Understanding the trajectory of $APECoin provides insight into its developmental milestones and future aspirations. Here’s a timeline highlighting significant events in the project’s history: December 2019: Conceptualization of Asia Pacific Electronic Coin, initiated with an ambition to drive sustainability through cryptocurrency. April 2020: Official launch of $APECoin, marking its entry into the marketplace as a dedicated token for environmental projects. 2020-2021: Conducting of the Initial Exchange Offering (IEO), enabling users to purchase $APECoin, alongside the registration with various electronic exchange platforms to enhance accessibility. In its relatively short journey, $APECoin has made significant strides in laying the groundwork for a secure and impactful cryptocurrency driven by environmental goals. Conclusion Asia Pacific Electronic Coin ($APECoin) embodies the marriage of technology and environmental responsibility, fostering growth in the crypto ecosystem while championing sustainability. With its unique structure, backing by reputable entities, and vision for a greener future, $APECoin is more than just a cryptocurrency; it is a pioneering project aimed at nurturing responsible innovation in the Asia Pacific region. Through its commitment to financial inclusion and its support of environmental initiatives, it stands as a formidable example of how digital currencies can be leveraged for positive societal impact. As the project continues to evolve, stakeholders within the crypto community and beyond will be eagerly watching how $APECoin shapes the conversation around sustainable practices in the burgeoning world of cryptocurrency.

890 Total ViewsPublished 2024.12.03Updated 2024.12.03

What is APECOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of APE (APE) are presented below.

活动图片