深度分析“NFT零元购”钓鱼骗局

慢雾科技Pubblicato 2022-09-05Pubblicato ultima volta 2022-09-05

Introduzione

进入网站连接钱包后,立即弹出签名框,而当我尝试点击除签名外的按钮都没有响应,看来只有一张图片摆设。

据慢雾区情报,发现 NFT钓鱼网站如下:

钓鱼网站 1:https://c01.host/

钓鱼网站 2:https://acade.link/

我们先来分析钓鱼网站 1:

进入网站连接钱包后,立即弹出签名框,而当我尝试点击除签名外的按钮都没有响应,看来只有一张图片摆设。

我们先看看签名内容:

Maker:用户地址

Taker:0xde6135b63decc47d5a5d47834a7dd241fe61945a

Exchange:0x7f268357A8c2552623316e2562D90e642bB538E5,查询后显示是 OpenSea V2 合约地址。

大概能看出,这是欺骗用户签名 NFT 的销售订单,NFT 是由用户持有的,一旦用户签名了此订单,骗子就可以直接通过 OpenSea 购买用户的 NFT,但是购买的价格由骗子决定,也就是说骗子不花费任何资金就能“买”走用户的 NFT。

此外,签名本身是为攻击者存储的,不能通过 Revoke.Cash 或 Etherscan 等网站取消授权来废弃签名的有效性,但可以取消你之前的挂单授权,这样也能从根源上避免这种钓鱼风险。

查看源代码,发现这个钓鱼网站直接使用 HTTrack 工具克隆 c-01nft.io 站点(真实网站)。对比两个站点的代码,发现了钓鱼网站多了以下内容:

查看此 JS 文件,又发现了一个钓鱼站点 https://polarbears.in。

如出一辙,使用 HTTrack 复制了 https://polarbearsnft.com/(真实站点),同样地,只有一张静态图片摆设。

跟随上图的链接,我们来到https://thedoodles.site,又是一个使用HTTrack 的钓鱼站点,看来我们走进了钓鱼窝。

对比代码,又发现了新的钓鱼站点 https://themta.site,不过目前已无法打开。

通过搜索,发现与钓鱼站点 thedoodles.site 相关的 18 个结果。同时,钓鱼网站2(https://acade.link/)也在列表里,同一伙骗子互相 Copy,广泛撒网。

再来分析钓鱼站点 2,同样,点击进去就直接弹出请求签名的窗口:

且授权内容与钓鱼站点 1 的一样:

Maker:用户地址

Exchange:OpenSea V2 合约

Taker:骗子合约地址

先分析骗子合约地址(0xde6...45a),可以看到这个合约地址已被 MistTrack 标记为高风险钓鱼地址。

接着,我们使用 MistTrack 分析该合约的创建者地址(0x542...b56):

发现该钓鱼地址的初始资金来源于另一个被标记为钓鱼的地址(0x071...48E),再往上追溯,资金则来自另外三个钓鱼地址。

总结

本文主要是说明了一种较为常见的 NFT 钓鱼方式,即骗子能够以 0 ETH(或任何代币)购买你所有授权的 NFT,同时我们顺藤摸瓜,扯出了一堆钓鱼网站。建议大家在尝试登录或购买之前,务必验证正在使用的 NFT 网站的 URL。同时,不要点击不明链接,也不要在不明站点批准任何签名请求,定期检查是否有与异常合约交互并及时撤销授权。最后,做好隔离,资金不要放在同一个钱包里。

Letture associate

A Hard-Fought Battle to Defend Par Value: STRC Drifts Further Away from $100

STRC, the dividend-paying stock issued by Michael Saylor's bitcoin reserve firm Strategy (formerly MicroStrategy), is trading far below its intended $100 par value, closing recently at $80.84. With a key dividend snapshot date approaching, Saylor aims to pull the price back to $100, as per SEC filings stating the company's goal to stabilize the stock near that level. The situation is complicated by the June volume-weighted average price (VWAP) falling below $95, triggering an internal rule that mandates the next dividend increase to be at least double the standard 0.25% per cycle, potentially pushing the annualized dividend yield to 12%. However, attracting buyers with this higher yield faces challenges: the payout is spread over 24 bi-monthly installments, the board can alter or suspend dividends at any time, and there is no guarantee against further price declines. Beyond raising dividends, Strategy has limited tools to boost the stock. These include direct share buybacks (never utilized), halting new share issuances above $100 (which currently cap the price), selling ordinary MSTR shares to build a cash buffer for dividends (with limited effect so far), or announcing special shareholder benefits. Historically, STRC has reclaimed the $100 mark, such as in October last year, driven by a combination of dividend fulfillment, a rate hike, and a pause in share sales. The core question remains how much cost and effort Strategy is willing to bear to attract the necessary buying pressure to restore the $100 par value.

Foresight News6 min fa

A Hard-Fought Battle to Defend Par Value: STRC Drifts Further Away from $100

Foresight News6 min fa

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

Fable 5, a previously restricted AI model from Anthropic, appears poised for a comeback. Evidence from leaked code in the Claude Code v2.1.190 version suggests a shift in its business model from a separate purchase to a potentially limited weekly usage allowance within standard Claude subscriptions. Furthermore, the model has reportedly reappeared in Amazon Bedrock documentation. This potential revival coincides with significant internal changes at Anthropic. According to a report by The Wired, CEO Dario Amodei was reportedly sidelined from negotiations with the Trump administration over Fable 5's export restrictions. Government officials found him difficult to communicate with. Co-founder Tom Brown and policy head Sarah Heck took over discussions, leading to more productive technical talks aimed at addressing White House security concerns about the model being "jailbroken." External pressure is mounting as a bipartisan group of US lawmakers has demanded answers from the Commerce Department by a June 26 deadline regarding the criteria and timeline for potentially reinstating public access to Fable 5. The potential return of Fable 5 comes as competitors OpenAI and Google have reportedly delayed their own major model releases. If Anthropic successfully navigates the government's security review, Fable 5 could gain a significant "safety-certified" advantage in the enterprise market. The countdown to the June 26 deadline is now underway.

marsbit38 min fa

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

marsbit38 min fa

Trading

Spot
Futures
活动图片