Go Back   Carder.life > [en] International Forum > Carding News



Reply
 
Thread Tools Display Modes
  #1  
Old 05-17-2025, 04:29 PM

Artifact Artifact is offline
Administrator
Join Date: Jan 2024
Posts: 0
Default


Multiple fake accounts impersonating cryptocurrency scam investigators and blockchain security companies are promoting phishing pages to drain wallets in an ongoing campaign on X (former Twitter).
To lure potential victims, the scammer uses a breach on major cryptocurrency exchange platforms. The scenario urges users to act swiftly to safeguard their digital assets from potential theft.
The scammers impersonate accounts on X belonging to blockchain analytics or crypto fraud investigation firms and researchers, like CertiK, ZachXBT, and Scam Sniffer, to promote fabricated security breaches on Uniswap and Opensea.
To impersonate the legitimate accounts, the threat actors created new X accounts with similar account names. For example, ZachXBT has the account @zachxbt, while the threat actors created and tweeted from @zacheryxbt.
Many legitimate X users fell for the trick and shared the scam on their accounts, some with hundreds of thousands of followers without double-checking the validity of the claims.
One example is a tweet from malware analysis platform vx-underground, whose admins falsely assumed the information came from a trustworthy account. In the tweet below, VX-Underground clarifies how they fell for the trick.

https://twitter.com/vxunderground/st...03374572601855
The scale of the campaign is also notable, with bot accounts promoting hashtags like #UniswapExploit to the point of them reaching top trending topics in the U.S. on X.
ZachXBT, one of the accounts impersonated in this scam, told BleepingComputer that the first time he saw this threat group utilizing this tactic was on November 9th.
This was when Hayden Adams - the developer of Uniswap's web application interface, warned the cryptocurrency community of the scam, clarifying that there was no Uniswap exploit leveraged in the wild and that tweets about this came from fake X accounts impersonating ZachXBT, Certik, and other well-known users in the cryptocurrency community.
Operation details
The scammers impersonate accounts on X belonging to blockchain analytics and investigation firms or users, like CertiK, ZachXBT, and Scam Sniffer, to promote a fabricated security breach on Uniswap or Opensea.

Fake X accounts promoting the crypto phishing page
The scenario alleges that hackers exploited a signature verification vulnerability in the said protocols/exchanges to steal tokens.
Users are advised to revoke the permissions as soon as possible to prevent losing their assets by following a link to a malicious website at 'revoketokens[.]io' or 'revokea[.]sh' which are still online at the time of writing.
Once visitors click on the ‘Revoke Approvals’ button and connect their wallet, the scam drains their funds, which is a non-reversible process.

Phishing page draining cryptocurrency wallets
After publication of this article, ZachXBT says that the threat actors have successfully stolen over $305k in cryptocurrency as part of this ongoing scam.

Zach said that the cryptocurrency stolen from victims in this attack are stored in the following Ethereum addresses:
  • 0x85a5b2968fae4e7f60f14e3bfc2ebda67050740f

  • 0xe91fa37c3c5cf801cc8c6cd25a4d2399b3fba4e8

Impersonation risk
Impersonating the ‘good guys’ is a powerful deception trick capable of increasing success rate of the scam.
In July 2022, phishing actors were seen impersonating cybersecurity companies to gain initial access to corporate networks.
In June 2023, hackers created fake accounts on GitHub that impersonated existing cybersecurity researchers, even linking to fake X accounts for added legitimacy.
The repositories contained malware downloaders disguised as proof-of-concept (PoC) exploits for popular software.
There’s no precaution more effective than double-checking that an account is authentic and that its claims accurately represent the truth. Because even legitimate accounts can be compromised to propagate scams, users should verify the claims from official sources.
Finally, never connect your wallet to dubious or unofficial platforms, and avoid signing smart contracts you don’t fully understand.
If you’re overly worried about the likelihood of losing your digital assets to hacks and breaches, consider moving them to a cold wallet.
https://www.bleepingcomputer.com/new...o-researchers/
  #2  
Old 05-17-2025, 05:06 PM

maksim73 maksim73 is offline
Join Date: Sep 2023
Posts: 0
Default


kinda smart, if you think about. .
  #3  
Old 05-17-2025, 05:16 PM

Killmonroe Killmonroe is offline
Junior Member
Join Date: Feb 2025
Posts: 16
Default


такое можно повторить, как вы думаете? или разок сработало и усё...? ну и ещё дьявол как говорится в деталях...
Reply

Tags
NULL


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT. The time now is 01:20 AM.