Peckshield alerts STEPN users of phishing sites

cryptoslate发布于2022-04-27更新于2022-04-27

文章摘要

Blockchain analytics and security firm, PeckShield, has revealed that malicious actors are targeting users of the Solana-based gaming platform STEPN through several phishing sites.

Blockchain analytics and security firm, PeckShield, has revealed that malicious actors are targeting users of the Solana-based gaming platform STEPN through several phishing sites.

STEPN’s popularity attracts bad actors

These sites have a malicious MetaMask plugin that allows them to steal seed phrases of unsuspecting visitors.

The link also prompts these visitors to connect their wallets to claim a false giveaway, which gives these hackers complete access to the users’ wallets, where they can steal crypto assets.

STEPN is a Web3 gaming and lifestyle platform that allows players to earn Green Satoshis (GST) based on their movement. The platform tracks this through the GPS on their players’ mobile devices.

The platform has become increasingly popular in recent weeks, and per data on its Twitter account, it has recorded over 1.5 million users within the last 30 days. This is largely fueled by the massive rise of its token from a low of $0.01 to as high as over $3 within the same time frame.

Source: STEPN

In its tweet, PeckShield urged the community to add its PeckShield free extension to their wallet so that they can detect any phishing site. The firm also advised them to report any suspicious activity on their account to the dev team.

https://twitter.com/cristianronal24/status/1518500075034615808?s=20&t=MdUNFJlOcPF5V1Or72z4lg

While STEPN is yet to release an official statement about this phishing attack, one user revealed that he had successfully contacted the support team to help him fix an issue he was facing.

As of press time, we couldn’t verify if any user had suffered a loss due to this phishing attempt.

Phishing attacks are becoming more prevalent

This STEPN incident shows how common phishing attacks have become within the crypto space. In the past few months, there have been multiple phishing attacks and attempts that have resulted in the loss of millions for many crypto holders.

DeFiance Capital founder Arthur Cheong was the victim of one spear-phishing attack that led to losing $1.7 million worth of NFTs. Another attack saw a leading NFT marketplace, OpenSea, reveal that some users had lost millions of their NFTs to “phishing.”

Earlier this month, CryptoSlate reported that there was a phishing attack attempt that was targeted at users of Trezor wallet after its mailing list was compromised.

The increase in these attacks has led to increased calls within the crypto community for investors to be wary of connecting their wallets to random sites and clicking on random links.

你可能也喜欢

数字银行的宿命:再花哨的 App,不如一张银行牌照

本文探讨了数字银行(新银行)普遍面临的盈利困境与发展路径。大多数新银行以零手续费、无最低存款的支票账户吸引用户,但仅依靠消费支付产生的小额手续费难以盈利,平均每用户年收入远低于传统银行。文章指出,银行业的利润核心始终是信贷业务(如贷款利息),而非支付服务。缺乏银行牌照的新银行无法大规模放贷,因此陷入持续亏损。 以Nubank、Revolut等为例,成功的新银行最终都依靠信贷业务实现盈利:Nubank大部分收入来自信用卡和个人贷款利息;Revolut通过外汇手续费、订阅服务等积累资金后,逐步扩大信贷规模。Chime则在推出预支薪资和小额贷款业务后首次扭亏为盈。文章强调,流畅的App只是获客手段,持牌放贷才是生存根本。 此外,文章揭示了新银行依赖第三方服务商的风险,如Synapse破产导致用户资金冻结,凸显了自主持牌运营的重要性。近年来,加密金融企业(如Paxos、Circle等)纷纷申请全国信托牌照,以摆脱中间商控制,实现资产托管和支付的自主合规。 最后,文章指出DeFi领域无抵押借贷规模极小,因链上匿名性导致违约追偿困难。现实中的信贷风控仍需传统金融机制支撑,因此银行牌照对于规模化信贷业务至关重要。结论是:无论技术如何革新,银行业的本质仍是信贷获利,幸存的新银行最终都回归了这一传统逻辑。

Foresight News5分钟前

数字银行的宿命:再花哨的 App,不如一张银行牌照

Foresight News5分钟前

交易

现货
合约
活动图片