Get 40% Off
⚠ Earnings Alert! Which stocks are poised to surge?
See the stocks on our ProPicks radar. These strategies gained 19.7% year-to-date.
Unlock full list

Metamask Users Targeted By New Phishing Campaign

Published 08/01/2022, 07:00 AM
Updated 08/01/2022, 08:00 AM
Metamask Users Targeted By New Phishing Campaign

Halborn, a blockchain cybersecurity company, has issued an alert regarding a fresh phishing scam targeting the users of leading cryptocurrency wallet MetaMask.

Tricked into Giving Passphrases

Halborn’s Technical Education Specialist, Luis Lubeck, published a blog post on July 28th, breaking down the newest email phishing campaign targeting MetaMask users. The scam centers around misleading users, thereby tricking them into give up their passphrases.

The phishing email “informs” users that they need to verify their wallets. To do this, users are prompted to click a malicious “call to action” button, which leads to a fake website requesting a user’s seed phrase. Once the seed is entered, the website forwards to the MetaMask wallet, which is then emptied by the malicious program.

Attention to Detail Is Key

Halborn notes that the email appears genuine at first glance, as the scammers mimic MetaMask’s visual identity, including its header and logo. User instructions on how to comply with ‘know your customer (KYC)’ requirements for wallet verification also resembles the company’s typical communication.

However, despite these similarities, Halborn highlighted a few warning signs, oh which the two most noticeable were misspellings, and the sender’s email address, which was not the official MetaMask account.

The phishing emails were sent through a phony domain called “metamaks.auction.The security company further emphasized that the message lacked customization, such as addressing users by specific, individual names—a classic red flag.

Not the First Attack on Crypto Wallets

This latest phishing attempt is not the only MetaMask vulnerability to have been found by the Halborn firm. In June, the firm’s researchers revealed that users’ private crypto wallet could be found unencrypted on a computer hard drive. Following the revelation, MetaMask patched the exploit from extension versions 10.11.3 onward.

In February, malware called ‘Mars Stealer’ was found to be targeting browser-based cryptocurrency wallets like MetaMask, Coinbase (NASDAQ:COIN) Wallet, Nifty Wallet, Ronin Wallet, MEW CX, Binance Chain Wallet, TronLink, and approximately 40 other crypto wallets.

In April, MetaMask warned the public about phishing attacks targeting Apple’s ‘iCloud’ service. If a user had enabled automatic backups for application data, the seed phrase or “password-encrypted MetaMask vault” would be stored on iCloud, thereby imposing severe security risks for iPhone, Mac, and iPad users.

On the Flipside

  • Non-custodial wallets ensure that users’ assets and transactions are safe from censorship or confiscation.
  • On the other hand, non-custodial wallets place high levels of responsibility upon owners to protect their private keys. The lack of a middleman, as found in traditional banking, means that all transactions are irreversible.

Why You Should Care

  • MetaMask is the world’s leading non-custodial crypto wallet with more than 30 million monthly active users.
  • Cryptocurrency scammers have stolen over $1 billion from 46,000 people since the start of 2021, says CNN.

For more information on MetaMmask and how it works, check out:

https://dailycoin.com/a-beginners-guide-to-metamask-what-is-it-and-how-does-it-work/

Cardano ranks as the top target for phishing attacks – find out more below:

https://dailycoin.com/cardano-among-top-targets-of-phishing-attacks-before-vasil-fork/

Continue reading on DailyCoin

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.