Public Wi-Fi and a Phone Call: How They Became the Perfect Trap to Steal $5000 in Crypto Assets?

比推Publicado em 2026-01-09Última atualização em 2026-01-09

Resumo

An individual lost approximately $5,000 in cryptocurrency assets after connecting to a public hotel Wi-Fi network during a vacation. The attack began when the victim was overheard discussing crypto and using a Phantom wallet in a public area, making them a target. While browsing on the unsecured Wi-Fi, the attacker executed a man-in-the-middle attack, injecting malicious code into a seemingly legitimate webpage. The victim was using Jupiter Exchange to swap tokens when a fraudulent transaction approval request was triggered, disguised as a normal operation. Instead of a direct fund transfer, the request asked for “authorization” or “session approval,” granting the attacker permission to act on the wallet. The victim approved, believing it was part of the Jupiter transaction. The attacker waited until the victim left the hotel to drain the wallet of SOL, tokens, and NFTs. Key mistakes included: using public Wi-Fi instead of a mobile hotspot, discussing crypto in public, and approving a transaction without thorough verification. The wallet was a secondary hot wallet, not the main storage, preventing greater losses. The incident highlights the risks of public networks and the importance of transaction scrutiny.

Author: The Smart Ape

Compiled by: Deep Tide TechFlow

Original title: After Three Days on Hotel Wi-Fi, My Crypto Wallet Was Drained of $5000


A few days ago, I went with my family to a very nice hotel for a year-end holiday. One day after leaving the hotel, my wallet was completely emptied. I was puzzled, as I had neither clicked on any phishing links nor signed any malicious transactions.

After hours of investigation and seeking help from experts, I finally figured out the truth. It turned out to be due to the hotel's Wi-Fi network, a brief phone call, and a series of foolish mistakes.

Like most cryptocurrency enthusiasts, I brought my laptop with me, thinking I could squeeze in some work while on vacation with my family. My wife repeatedly insisted that I not work during these three days—I really should have listened to her.

Like other guests, I connected to the hotel's Wi-Fi network. This network didn't require a password; it only needed to be logged in through a captive portal.

I worked as usual in the hotel without doing anything risky: I didn't create new wallets, click on strange links, or access suspicious decentralized applications (dApps). I just checked X (Twitter), my balances, Discord, Telegram, etc.

At one point, I received a call from a crypto friend, and we chatted about market trends, Bitcoin, and other cryptocurrency-related matters. But what I didn't know was that someone nearby was eavesdropping on our conversation and realized I was involved in cryptocurrency. This was my first mistake. The eavesdropper learned from our conversation that I was using a Phantom wallet and that I was a user with a significant holding.

This made me his target.

In a public Wi-Fi network, all devices share the same network, and the visibility between devices is actually higher than you might think. There is almost no real protection between users, which creates an opportunity for a "Man-in-the-Middle Attack." The attacker acts like a middleman, quietly inserting themselves between you and the internet, much like someone secretly reading and tampering with your mail before it reaches you.

While I was browsing the web on the hotel Wi-Fi, one website appeared to load normally, but in reality, malicious code had been injected behind the page. I didn't notice anything unusual at the time. If I had installed some security tools, I might have detected these issues, but unfortunately, I hadn't.

Normally, a website might request your wallet to sign certain operations. The Phantom wallet would pop up a window where you could choose to approve or reject. Generally, you would trust the website and browser and sign without worry. However, that day, I shouldn't have.

Just as I was performing a token swap on @JupiterExchange, the malicious code triggered a wallet request that replaced my normal swap operation. I could have detected it as a malicious request by carefully checking the transaction details, but because I was already performing a swap on Jupiter, I didn't suspect a thing.

That day, I didn't sign any transaction to transfer funds; instead, I signed an authorization. This was exactly why my assets were stolen days later.

The malicious code didn't directly ask me to send SOL (Solana), as that would have been too obvious. Instead, it requested me to "authorize access," "approve account," or "confirm session." In simple terms, I was actually giving another address permission to operate on my behalf.

I approved it because I mistakenly thought it was related to my operation on Jupiter. At the time, the message popped up by the Phantom wallet looked technical, didn't show any amount, and didn't prompt for an immediate transfer.

And that was all the attacker needed. He patiently waited until I left the hotel before taking action. He transferred my SOL, withdrew my tokens, and moved my NFTs to another address.

I never thought something like this would happen to me. Fortunately, this wasn't my main wallet but a hot wallet used for specific operations, not for long-term asset holding. Even so, I made many mistakes, and I believe I am primarily responsible.

First, I should never have connected to the hotel's public Wi-Fi. I should have used my phone's hotspot instead.

My second mistake was talking about cryptocurrency in the hotel's public area, where many people could have overheard our conversation. My father once warned me never to let others know you're involved in cryptocurrency. This time, I was lucky; some people have even faced kidnapping or worse because of their crypto assets.

Another mistake was approving the wallet request without paying full attention. Because I was sure the request came from Jupiter, I didn't analyze it carefully. In fact, every wallet request should be carefully reviewed, even on trusted applications. Requests can be intercepted and may not actually come from the app you think.

In the end, I lost about $5000 from a secondary wallet. While it's not the worst-case scenario, it's still very frustrating.


Twitter:https://twitter.com/BitpushNewsCN

BitPush TG Discussion Group:https://t.me/BitPushCommunity

BitPush TG Subscription: https://t.me/bitpush

Original article link:https://www.bitpush.news/articles/7601380

Perguntas relacionadas

QWhat was the primary method the attacker used to compromise the victim's crypto wallet?

AThe attacker used a Man-in-the-Middle (MitM) attack by exploiting the insecure public hotel Wi-Fi network. They intercepted the victim's web traffic and injected malicious code into a webpage, which triggered a deceptive wallet authorization request.

QWhat specific mistake did the victim make that allowed the attacker to identify him as a target?

AThe victim discussed cryptocurrency, his use of the Phantom wallet, and his substantial holdings during a phone call in a public area of the hotel, which was overheard by the attacker.

QWhat type of transaction did the victim accidentally sign, instead of a direct fund transfer?

AThe victim signed an authorization or approval request, which granted permission for another address to operate on their behalf. This did not immediately transfer funds but gave the attacker the ability to do so later.

QWhy didn't the victim suspect the malicious transaction request when it appeared?

AThe request appeared while he was performing a legitimate token swap on the Jupiter Exchange platform. He assumed the request was part of that normal operation and did not carefully inspect the technical details of the transaction, which showed no immediate transfer of funds.

QWhat were the two security precautions the victim identified that could have prevented this attack?

AFirst, he should not have used the hotel's public Wi-Fi and instead used his phone's mobile hotspot. Second, he should never have discussed his cryptocurrency activities in a public space where he could be overheard.

Leituras Relacionadas

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

U.S. Federal Reserve officials who previously advocated for rate cuts, including Governor Christopher Waller, have recently shifted their stance, with many now not ruling out the possibility of future rate hikes. This sets a challenging stage for new Fed Chair Kevin Warsh's first policy meeting. Appointed by President Trump based on his dovish views, Warsh now faces a committee where the debate has pivoted from "when to cut" to "whether to hike," driven by persistent inflation above 3%, a strong labor market, and supply-side pressures from AI infrastructure demands and geopolitical tensions. Key figures illustrate the shift. Governor Waller, once concerned about employment, now says data has pushed him toward considering rate increases. Even moderate voices like Governor Lisa Cook, while expecting inflation to ease, have indicated readiness to hike if it fails to do so. Long-time hawks such as regional Fed presidents Beth Hammack, Lorie Logan, and Neel Kashkari have grown more vocal, arguing that the real policy rate is effectively falling and that action may soon be needed. The upcoming Fed meeting is expected to keep rates steady but will likely remove the "easing bias" from its statement, signaling a neutral stance between cuts and hikes. The quarterly "dot plot" is anticipated to show most officials projecting no cuts this year, with some potentially indicating hikes. Chair Warsh, a critic of the Fed's reliance on forward guidance like the dot plot, must navigate communicating this pivot using tools he has questioned, all while steering policy in a direction counter to the preferences of the president who appointed him. The consensus suggests the Fed's next move could well be a rate increase.

marsbitHá 52m

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

marsbitHá 52m

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

The article analyzes the three leading Chinese optical module companies, collectively nicknamed "Yi Zhong Tian": Xinyisheng, Zhongji Innolight, and TFC Optical Communication. It evaluates their "cost-performance" not by current stock price, but through three lenses: PEG ratio (growth vs. valuation), earnings quality, and premium/discount for certainty. Xinyisheng shows the most attractive PEG ratio and high profitability, but its valuation reflects discounts for risks like high customer concentration and reliance on overseas markets. Zhongji Innolight, the most expensive, commands a premium for its market leadership, dominant share in key products like 800G/1.6T modules, and higher earnings certainty, though it faces geopolitical risks. TFC Optical, as an upstream component supplier ("water seller"), has the highest gross margin and bets on the long-term CPO/NPO architecture trend, but trades at a high valuation with more stable, less explosive growth. The core argument is that while these companies dominate module assembly, the true profit pool and technological moat lie upstream in laser and switch chips, currently controlled by U.S. firms like Lumentum and Coherent. The long-term "cost-performance" for these Chinese leaders hinges on whether the domestic industry, exemplified by companies like Yuanjie Technology, can successfully move up the value chain into high-power laser chips. Otherwise, their high growth may remain confined to the lower-margin assembly segment.

marsbitHá 1h

The Trillion-Yuan Market Cap 'Yi Zhong Tian': Who is the True Value King?

marsbitHá 1h

Has the Crypto Market Bottomed? Here's What Institutions Think

The crypto market is in a period of significant debate, with leading institutions offering differing views on whether a bottom has been reached. Three prominent firms have published detailed analyses: * **Galaxy Digital** argues Bitcoin has **not yet bottomed**. Their analysis of 13 historical indicators across six dimensions (valuation, profit-taking, miner pressure, etc.) shows only four are fully met. They project a potential bottom range between $30k and $54k. * **NYDIG** states a bottom is **possible but not likely**. While metrics are close to historic bear market extremes, they note the absence of a classic panic-selling event. They also suggest increased institutional adoption may have structurally altered the market cycle, potentially leading to a shallower downturn. * **Standard Chartered Bank** asserts the **bottom has already occurred** at around $59k. They cite two key factors: potential US-Iran diplomatic progress and the anticipated SpaceX IPO, which they believe absorbed capital and caused ETF selling pressure that is now subsiding. They forecast a year-end price target of $100k. Despite the surface-level disagreement, the reports share critical common ground more valuable for long-term investors: 1. All three believe the market bottom will form **within this year**. 2. All agree the current price is **closer to the bottom than to previous highs**. 3. All maintain a **bullish long-term outlook** for Bitcoin and a new cycle. The core takeaway is that while the exact bottom price ($40k, $50k, or $60k) is debated, the consensus is that a bottom is imminent. For long-term holders, the primary focus should not be pinpointing the absolute low, but on the future potential for prices to reach $100k, $200k, or higher. The fundamental thesis for Bitcoin—sovereign debt accumulation, inflation, declining trust in centralized institutions, global digitization, and improved accessibility—remains intact and is arguably strengthening. The overall landscape is viewed as more favorable than in previous crypto winters.

marsbitHá 1h

Has the Crypto Market Bottomed? Here's What Institutions Think

marsbitHá 1h

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

China's Photonics Industry: Bottlenecks and Breakthroughs In the global AI race, computing chips dominate the narrative, but the underlying bottleneck increasingly defining the scale of AI clusters is light—or more specifically, optical connectivity. Optical modules, which translate electrical signals to light and vice versa, are crucial for connecting thousands of GPUs in AI data centers, preventing data congestion and ensuring efficient model training. High-speed modules (800G, 1.6T) are now standard, with performance hinging on advanced DSP (Digital Signal Processor) chips. This is where a critical dependency lies. Two US giants—Marvell and Broadcom—collectively dominate over 90% of the high-end DSP chip market. Chinese optical module leaders like Zhongji Innolight and Eoptolink rely on these chips to manufacture modules for overseas AI customers, primarily in North America. While this creates a supply chain vulnerability, complete decoupling is difficult. Marvell derives over half its revenue from Greater China, and the US firms depend on Chinese partners for chip packaging and optical components. The risk from laser chips (e.g., from Lumentum), another key component, is considered more manageable due to multiple global suppliers and faster progress in domestic alternatives from companies like YOFC and Accelink. To mitigate risks, China's industry is pursuing a multi-pronged strategy: diversifying supply chains and locking in long-term orders; fostering a domestic market ecosystem to adopt homegrown DSPs from firms like Huawei HiSilicon and CETC; accelerating R&D in high-speed DSPs and advanced packaging; and investing in next-gen technologies like silicon photonics and Co-Packaged Optics (CPO) to reduce reliance on discrete DSPs. The ultimate solution lies not in short-term博弈 but in persistent advancement of domestic high-end chip R&D and manufacturing. While challenges remain in performance, certification, and ecosystem building, China's vast domestic market and manufacturing base provide a crucial buffer, buying time for the industry to achieve greater technological independence.

marsbitHá 1h

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

marsbitHá 1h

Trading

Spot
Futuros

Artigos em Destaque

O que é APECOIN

Compreender a Moeda Eletrónica da Ásia-Pacífico ($APECoin) Num era em que a interseção entre tecnologia e ambientalismo se torna cada vez mais crítica, as criptomoedas estão a deixar a sua marca como potenciais catalisadores para a mudança. Entre estas inovações, a Moeda Eletrónica da Ásia-Pacífico ($APECoin) destaca-se como um projeto distinto concebido para apoiar iniciativas ambientais em toda a região da Ásia-Pacífico. Este artigo explora a fundação, características únicas e impacto do $APECoin no panorama mais amplo da blockchain. O que é a Moeda Eletrónica da Ásia-Pacífico ($APECoin)? A Moeda Eletrónica da Ásia-Pacífico ($APECoin) é um token ERC20 e TRC20, realizado em abril de 2020 após a sua concepção em dezembro de 2019. Esta inovação nasceu do desejo de promover práticas ecológicas e apoiar um conjunto de projetos ambientais visando a sustentabilidade e iniciativas verdes. Objetivos e Finalidades $APECoin não é apenas uma moeda digital; é concebida como um meio de troca que permite aos utilizadores realizarem transações que beneficiam diretamente causas ambientais. O seu ecossistema é projetado para facilitar diversas atividades financeiras enquanto promove a adoção de práticas ecológicas. A moeda tem como objetivo principal: Apoiar Iniciativas Ambientais: Através de cada transação, uma parte é alocada para financiar projetos sustentáveis direcionados à conservação e energia renovável. Promover Inovações Ecológicas: Incentivar startups e projetos que se alinhem com a sustentabilidade ambiental através do uso do seu token como meio de valor. Criar um Mercado Sustentável: A plataforma inclui um e-mercado onde transações financeiras podem ocorrer dentro de um quadro dedicado à promoção de práticas ecológicas. Criador da Moeda Eletrónica da Ásia-Pacífico ($APECoin) Embora os detalhes sobre o criador individual do $APECoin não sejam divulgados ao público, o projeto é significativamente apoiado pelo Grupo APEC, um consórcio focado na defesa de iniciativas ambientais. Este apoio acrescenta credibilidade e relevância ao projeto, ligando-o a uma rede mais ampla comprometida com a sustentabilidade e práticas ecológicas. Investidores da Moeda Eletrónica da Ásia-Pacífico ($APECoin) O panorama de investimento em torno do $APECoin permanece em grande parte não divulgado. Nomes específicos de fundações ou organizações de investimento que apoiam esta criptomoeda ainda não foram revelados. Contudo, o que é evidente é um crescente interesse entre investidores ansiosos por apoiar projetos sustentáveis que demonstram potencial de impacto no espaço cripto. Como funciona a Moeda Eletrónica da Ásia-Pacífico ($APECoin)? O $APECoin destaca-se devido ao seu modelo operacional inovador, que utiliza a tecnologia blockchain e contratos inteligentes. Esta combinação não só garante eficiência nas transações, mas também assegura a conformidade com estruturas regulatórias, aumentando a segurança e transparência das transações. Características Únicas do $APECoin Operações Baseadas em Blockchain: Ao estabelecer as suas operações numa plataforma de blockchain, o $APECoin garante que todas as transações são imutáveis e seguras através de técnicas criptográficas avançadas. Esta descentralização sublinha a integridade do token dentro do seu ecossistema. Contratos Inteligentes: O $APECoin emprega contratos inteligentes que facilitam transações sem costura enquanto asseguram conformidade com as regulações aplicáveis. Estes acordos automatizados minimizam a possibilidade de disputas, simplificam processos e contribuem para um quadro de transação fiável. E-Mercado: Uma das características principais do $APECoin é o seu e-mercado dedicado. Este ambiente digital serve como um centro para serviços que promovem práticas ecológicas, proporcionando uma plataforma para trocas que reforçam a visão verde do projeto. Através destas características, o $APECoin carve um nicho para si mesmo dentro da vasta extensão do mercado de criptomoedas, casando efetivamente os princípios da blockchain com a gestão ambiental. Cronologia da Moeda Eletrónica da Ásia-Pacífico ($APECoin) Compreender a trajetória do $APECoin fornece uma visão sobre os seus marcos de desenvolvimento e aspirações futuras. Aqui está uma cronologia que destaca eventos significativos na história do projeto: Dezembro de 2019: Conceção da Moeda Eletrónica da Ásia-Pacífico, iniciada com a ambição de promover a sustentabilidade através da criptomoeda. Abril de 2020: Lançamento oficial do $APECoin, assinalando a sua entrada no mercado como um token dedicado a projetos ambientais. 2020-2021: Realização da Oferta Inicial de Troca (IEO), permitindo aos utilizadores adquirir $APECoin, juntamente com o registro em várias plataformas de troca eletrónica para aumentar a acessibilidade. Na sua jornada relativamente curta, o $APECoin fez progressos significativos na construção das bases para uma criptomoeda segura e impactante, impulsionada por objetivos ambientais. Conclusão A Moeda Eletrónica da Ásia-Pacífico ($APECoin) corporifica a união entre tecnologia e responsabilidade ambiental, promovendo o crescimento no ecossistema cripto enquanto defende a sustentabilidade. Com a sua estrutura única, apoio de entidades respeitáveis e visão para um futuro mais verde, o $APECoin é mais do que apenas uma criptomoeda; é um projeto pioneiro destinado a nutrir a inovação responsável na região da Ásia-Pacífico. Através do seu compromisso com a inclusão financeira e seu suporte a iniciativas ambientais, destaca-se como um exemplo formidável de como as moedas digitais podem ser aproveitadas para um impacto societal positivo. À medida que o projeto continua a evoluir, os intervenientes na comunidade cripto e além estarão ansiosos para ver como o $APECoin moldará a conversa em torno de práticas sustentáveis no mundo em crescimento das criptomoedas.

85 Visualizações TotaisPublicado em {updateTime}Atualizado em 2024.12.03

O que é APECOIN

Como comprar APE

Bem-vindo à HTX.com!Tornámos a compra de ApeCoin (APE) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar ApeCoin (APE) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu ApeCoin (APE)Depois de comprar o teu ApeCoin (APE), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona ApeCoin (APE)Transaciona facilmente ApeCoin (APE) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

126 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar APE

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de APE (APE) são apresentadas abaixo.

活动图片