Đề nghị kết nối ví là dấu hiệu của trang web kiểm tra rửa tiền giả mạo

cryptonews.ruPublicado em 2026-08-21Última atualização em 2026-08-21

Resumo

Các trang web giả mạo kiểm tra chống rửa tiền (AML) đang đánh cắp tiền của nhà đầu tư tiền điện tử. Những trang này yêu cầu người dùng kết nối ví và ký giao dịch, điều không cần thiết cho việc xác minh ví thực tế. Một cuộc tấn công như vậy được Malwarebytes phát hiện. Để kiểm tra AML hợp pháp, chỉ cần địa chỉ công khai của ví để phân tích lịch sử giao dịch. Các trang web lừa đảo sao chép giao diện của dịch vụ thật như AMLBot hoặc dùng tên chung chung như "AML Check". Sau khi người dùng chọn tiền điện tử và bấm quét, họ được nhắc kết nối ví. Một phiên bản hiển thị tiến trình giả với thông báo như "Đang kiểm tra lịch sử ví..." rồi báo lỗi và yêu cầu nạp một khoản phí nhỏ. Nếu bấm "Thử lại", trang sẽ hiện kết quả "Sạch, rủi ro thấp" và đề nghị tải báo cáo. Malwarebytes cảnh báo: yêu cầu kết nối ví thay vì chỉ nhập địa chỉ công khai là dấu hiệu đáng ngờ. Kết nối ví tiết lộ địa chỉ và tài sản, cho phép kẻ gian tạo giao dịch giả mạo để nạn nhân phê duyệt, dẫn đến mất tiền. Các nhà nghiên cứu phát hiện cùng một mẫu mã độc được dùng dưới nhiều tên và logo khác nhau. Một bộ công cụ giá 500 USD được rao bán trên diễn đàn hacker tạo ra đợt bán trước giả mạo token $TSLA, quét ví và lừa người dùng tiết lộ cụm từ khôi phục với lời hứa thưởng 15%. Các vụ lừa đảo tương tự đã xảy ra, như chiến dịch phân phối token $CJUP giả trên Solana. Sàn CoinDCX báo cáo phát hiện hơn 1.212 trang web giả mạo họ từ 4/2024 đến 1/2025. Khuyến nghị của Malwarebytes: Nếu chỉ kết nối ví, hãy ngắt kết nối tra...

Các trang web giả mạo chuyên kiểm tra rửa tiền đang đánh cắp tiền của các nhà đầu tư tiền mã hóa.

Các trang web này yêu cầu người dùng kết nối ví và ký vào một giao dịch, điều không cần thiết để xác minh tính xác thực của ví. Công ty Malwarebytes đã phát hiện cuộc tấn công này vào tuần này.

Chỉ cần cung cấp địa chỉ công khai để xác minh tính xác thực của ví

Theo các quy định chống rửa tiền, ngân hàng và các công ty được quản lý phải kiểm tra xem khách hàng của họ có liên quan đến hoạt động tội phạm hay không.

Trong lĩnh vực tiền mã hóa, việc kiểm tra này có nghĩa là phân tích lịch sử giao dịch công khai của địa chỉ ví để tìm các liên hệ với các vụ hack, trộm cắp, cá nhân bị trừng phạt hoặc các hoạt động đáng ngờ khác.

Theo nhà nghiên cứu Stefan Dasic của Malwarebytes, các trang web lừa đảo lấy ý tưởng này và biến nó thành vũ khí.

Một số sao chép phong cách thương hiệu của AMLBot, một dịch vụ kiểm tra rửa tiền hợp pháp. Những trang khác hoạt động dưới các tên chung chung như "AML Check".

Người truy cập chọn loại tiền mã hóa, nhấn nút quét, sau đó được đề nghị kết nối ví để xem kết quả.

Một phiên bản được Malwarebytes nghiên cứu hiển thị thanh tiến trình với các thông báo như "Đang kiểm tra lịch sử ví..." và "Đang kiểm tra sự tuân thủ...", sau đó xuất hiện lỗi giả mạo yêu cầu nạp một khoản tiền nhỏ để "trả phí".

Nhấn "Thử lại" và hoạt ảnh sẽ chạy lại, sau đó đưa ra kết luận an tâm "Sạch sẽ, rủi ro thấp" và đề nghị tải xuống báo cáo.

Đối với việc kiểm tra cơ bản đầy đủ, chỉ cần địa chỉ công khai của ví. Đây chỉ là một tìm kiếm, không cần ký tài liệu, cấp quyền hoặc kết nối ví.

"Nếu một chương trình kiểm tra rửa tiền yêu cầu bạn kết nối ví của mình thay vì chỉ nhập địa chỉ công khai của nó, hãy coi đó là dấu hiệu cảnh báo," nhóm Malwarebytes viết.

Việc kết nối ví không chuyển giao khóa riêng tư, nhưng tiết lộ địa chỉ công khai. Điều này cho phép những kẻ điều hành nhìn thấy tài sản nào đang có trong ví và tạo ra các giao dịch nhắm mục tiêu cụ thể vào ví đó.

Sau đó, giao dịch này được gửi đến nạn nhân để phê duyệt. Thời điểm phê duyệt là khi tiền bắt đầu chuyển đi.

Các nhà nghiên cứu khuyến cáo không nên phê duyệt các giao dịch bất ngờ.

Malwarebytes phát hiện ra rằng cùng một mẫu mã độc được sử dụng dưới các tên và biểu trưng khác nhau. Bộ công cụ phần mềm được đổi tên và bán lại.

Bộ công cụ 500 USD sử dụng cụm từ khôi phục để lừa đảo, hứa hẹn thưởng 15%

Trong tháng này, Cryptopolitan đã đưa tin về một bộ công cụ có sẵn trị giá 500 USD trên một diễn đàn dành cho tội phạm mạng. Bộ công cụ này tạo ra một đợt bán trước $TSLA giả mạo và quét ví của mỗi người truy cập để tìm các tài sản có giá trị.

Sau đó, những kẻ lừa đảo cố gắng lừa lấy cụm từ khôi phục 12 từ bằng cách hứa hẹn thưởng 15%. Bảng điều khiển quản trị tự động làm giả số dư để nạn nhân tiếp tục thanh toán.

Vào tháng 5, Solana Floor đã phát hiện một âm mưu mà các ví Solana bị tấn công bằng token giả "$CJUP", bắt chước đợt airdrop Jupuary từ Jupiter Exchange và chuyển hướng người nhận đến một trang web giả mạo, như Cryptopolitan đã đưa tin lúc đó.

Công ty CoinDCX báo cáo đã phát hiện hơn 1212 trang web giả mạo mạo danh nền tảng của họ từ tháng 4 năm 2024 đến tháng 1 năm 2026. Cảnh sát Mumbai đã ghi nhận một báo cáo về gian lận được thực hiện thông qua một trang web mạo danh CoinDCX.

Malwarebytes khuyên tất cả những ai chỉ kết nối ví nên ngắt kết nối khỏi trang web đó. Bất kỳ ai đã cấp quyền truy cập vào ví cho một token nên kiểm tra các quyền không quen thuộc và thu hồi chúng.

Bất kỳ ai đã ký vào thứ gì đó không rõ ràng nên kiểm tra hoạt động gần đây và nếu quỹ bị xâm phạm, hãy chuyển tất cả sang một ví mới. Bất kỳ ai đã nhập cụm từ khôi phục hoặc khóa riêng tư nên cho rằng ví đã bị xâm phạm.

Criptomoedas em alta

Leituras Relacionadas

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

Just now, Sam Altman strongly criticized Dario (Amodei, co-founder of Anthropic), denouncing his "doomsday marketing" as "anti-human dictator rhetoric." This came alongside the accidental exposure of OpenAI's next-generation model, codenamed "gpt-nathree," hinting at the imminent release of GPT-6 Astra. The leak occurred when an OpenAI employee's public GitHub commit mentioned the codename. Combined with previous leaks of "gpt-mewfour," it suggests these are iterative checkpoints for OpenAI's upcoming agent model, Astra. Astra is known for multi-agent collaboration and long-duration task handling, having reportedly solved previously unsolved mathematical problems. Meanwhile, two new Anthropic model codenames, "claude-marshmallow-eap" and "claude-melon-eap," were also exposed but are believed to be iterations of the Claude 5 series, not a new flagship. In a wide-ranging podcast interview, Altman admitted he was wrong about the speed of AI-driven disruption, acknowledging societal inertia slows adoption. He fiercely criticized rivals' marketing that simultaneously promises immense benefits (like curing cancer) and warns of existential risk, calling it a dangerous "benevolent dictator" narrative that seeks to concentrate power. He emphasized that people are the ultimate purpose of AI. Altman also revealed OpenAI's unconventional, consensus-defying path: spending four and a half years in the "dark" without a public product before ChatGPT's breakthrough, driven by scaling laws rather than early customer feedback. He concluded that even with superintelligent AI, genuine human connection will remain irreplaceably valuable.

marsbitHá 37m

Just Now, Sam Altman Blasts Dario Amodei as 'Anti-Human', Secret Model Exposed the Same Day

marsbitHá 37m

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

"Rescuing US Treasuries" Relay: After Bessent's Miss, All Eyes Are on Walsh Last week, US Treasury Secretary Bessent's announcement to at least double long-term Treasury buybacks failed to sustainably lower yields, which quickly rebounded. The market response saw a drop in the dollar alongside surges in gold and Bitcoin, interpreted as a "pressure release valve" for anxiety. The focus now shifts to Fed Chairman Walsh's upcoming Jackson Hole speech. Markets are highly sensitive to his message, seeking clarity on the Fed's policy response to stubborn inflation and worsening fiscal conditions. Analysts warn that a lack of new guidance could disappoint markets and worsen the sell-off in long-dated bonds. Analysts question the scale of Bessent's operations, noting they are too small relative to the overall debt market and do not constitute quantitative easing. A key issue is the Fed's massive holdings of long-term bonds, which distorts the market. With the Fed holding low-yielding short-term bonds that are losing money relative to its policy rate, discussion is growing around a potential Fed-led "Operation Twist." This would involve selling short-term bonds to buy long-term ones, aiming to lower long-end yields without expanding the balance sheet. The upcoming PCE inflation data will set the stage for Walsh's speech. However, the window for action is narrowing amid political pressures. A critical threshold is the 30-year yield at 5%; holding above it could increase stress on the dollar and leveraged sectors. Overall, the article suggests that without coordinated Fed action to anchor inflation expectations, Treasury interventions may ultimately fail, with investors increasingly looking to assets like gold as hedges.

marsbitHá 1h

The 'Saving U.S. Treasuries' Baton Pass: Bessent Fumbled Last Week, This Week It's Wash's Turn

marsbitHá 1h

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

Hyperliquid’s Compliance Path: From Permissionless to Permissioned HIP-3 Hyperliquid currently blocks U.S. access because its permissionless, on-chain infrastructure conflicts with U.S. market structure laws, which restrict futures trading to registered exchanges, clearinghouses, and brokers. Through its Hyperliquid Policy Center (HPC), the project is advocating for regulatory modernization, proposing that regulated entities be allowed to build products on HyperCore (its exchange and clearing layer) while fulfilling their compliance obligations. The platform’s modular stack separates roles like a traditional exchange (DCM), clearinghouse (DCO), and broker (FCM), but reconstructs them on-chain with code. This enables permissionless access, self-custody, and 24/7 global trading, but clashes with U.S. rules requiring KYC, specific margin models, and custodial arrangements. To resolve this, HPC is engaging with U.S. regulators (CFTC, SEC) to seek clarity that deploying on-chain software does not itself trigger licensing, and to establish exemptions allowing non-custodial wallets to route users to regulated derivatives. Recent political signals suggest openness to this approach. On the technical side, Hyperliquid Labs has introduced permissioned HIP-3 deployers on testnet. These allow regulated entities to launch markets, perform KYC, and whitelist compliant users. While these create separate order books, whitelisted market makers can bridge liquidity between them, ensuring deep, shared liquidity across the same L1. Features like payload-based “PA” permissions enable DEX-level account controls (e.g., reduce-only orders), mirroring traditional broker authorities. The strategy is not to open the native, permissionless front-end to U.S. users, but to position Hyperliquid as neutral infrastructure that U.S. regulated firms can use while meeting their legal duties. This paves a compliant path for U.S. investor access while preserving the protocol’s core, permissionless nature.

marsbitHá 1h

Hyperliquid's Compliance Journey: From Permissionless to Permissioned via HIP-3

marsbitHá 1h

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

Investment Community AI has learned that Beijing Zhongshu Ruizhi Technology Co., Ltd., a domestic industrial-grade causal intelligence and high-reliability decision-making AI company, has recently completed a strategic financing round worth hundreds of millions of RMB. This round saw participation from China Internet Investment Fund, Suzhou Chuangtou National Social Security Fund, Financial Street Capital, ICBC Capital, Kunlun Capital, among others, with existing shareholders also increasing their investment. This follows a Series B funding round in the hundreds of millions completed just three months prior. The rapid succession of two major funding rounds signifies strong market recognition of the company's underlying original technology and scaled commercial implementation. Often referred to as the "Chinese version of Palantir," Zhongshu Ruizhi is entering a new phase of accelerated technological iteration, widespread scenario replication, and scaled performance release, mirroring the explosive growth of China's AI market. Founded in April 2020 by Dr. Han Han, a Tsinghua University Ph.D. and former core drafter of national AI policies, the company is mission-driven to "move AI from the digital world to the physical world." It focuses on the high-reliability, strong-decision industrial AI track and enterprise-grade AI Agent full-stack infrastructure. The team tackles the challenge of applying AI to China's vast and complex industrial and energy systems by developing a new intelligent operating system from scratch. Its core technological breakthrough lies in three proprietary底层 technologies: meta-causal cognitive theory, causal models, and a dynamic ontology engine. These address critical pain points of generative large models in industrial settings—such as AI hallucinations, insufficient reasoning, lack of temporal logic, unverifiable decisions, and multi-source rule conflicts—thereby providing trustworthy, explainable, and executable智能决策 capabilities. Commercially, Zhongshu Ruizhi has achieved scaled deployment, serving over 50 central state-owned enterprises and industrial groups in sectors like power, petroleum, and aerospace, with implementations in more than 800 highly complex production scenarios. The company reported doubled revenue in 2025, demonstrating strong self-sufficiency and a viable business model—a rarity among new-generation AI firms. The latest funds will be allocated towards advancing foundational theoretical research, replicating successful application models to expand market presence (including overseas), and attracting top-tier talent. Lead investor China Internet Investment Fund highlighted that in the current shift from general AI capability contests to deep industrial empowerment, industrial-grade causal intelligence is crucial for building China's modern digital foundation and fostering new quality productive forces. They expressed support for the company's efforts to define decision-making paradigms and trustworthy standards for industrial intelligence, aiming to secure a rule-making voice in the global physical AI arena.

marsbitHá 1h

Two Funding Rounds in Three Months: The Chinese Version of Palantir is on Fire

marsbitHá 1h

Trading

Spot

Artigos em Destaque

Como comprar CHECK

Bem-vindo à HTX.com!Tornámos a compra de Checkmate (CHECK) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Checkmate (CHECK) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Checkmate (CHECK)Depois de comprar o teu Checkmate (CHECK), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Checkmate (CHECK)Transaciona facilmente Checkmate (CHECK) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

611 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar CHECK

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de CHECK (CHECK) são apresentadas abaixo.

活动图片