Categories: Trending now

How scammers could be hijacking trusted protocols to steal millions of cryptocurrency

Sophisticated fraudsters are leveraging legitimate blockchain protocols to steal cryptocurrency, according to recent findings by Check Point’s Threat Intel blockchain system. The scams primarily target users of popular platforms like Uniswap and Safe.global, exploiting the trust associated with these well-established services.
Uniswap, the largest decentralised exchange for cryptocurrency tokens, has processed over $1.8 trillion in trading volume since its launch in 2018.Safe.global, a smart contract wallet provider, claims to have facilitated 69 million transactions across 9.5 million accounts, with $100 billion in total assets stored.
The scammers‘ modus operandi involves manipulating functions within these trusted protocols. On Uniswap, hackers exploit the multicall aggregate function, which allows multiple transactions in a single call. This obfuscates their malicious intent. Similarly, on Safe.global, fraudsters utilise the GnosisSafeProxy contract to create seemingly legitimate contracts for their schemes.
One common tactic involves tricking victims into approving transactions that grant the attacker permission to withdraw funds. For instance, an attacker might use Uniswap’s multicall contract as a spender address, exploiting users’ trust in the platform to gain approval for fund transfers.
In a specific case on the Ethereum blockchain, an attacker used Uniswap’s multicall contract to execute a transferFrom function, withdrawing funds from a victim’s wallet after obtaining approval through a manipulated request.
To protect against these evolving threats, experts recommend several precautions:
1. Verify contract legitimacy before approving transactions
2. Avoid blindly accepting transactions, even from trusted sources
3. Perform actions directly on official project websites
4. Exercise caution with emails and social media links
5. Regularly monitor wallet activity
6. Stay informed about the latest scams and best practices
AD
News Today

Recent Posts

Atalanta vs Arsenal live updates: Heroic Raya penalty save earns goalless draw in Bergamo

2024-09-20 06:10:03 So much of the focus on tonight’s game was taken up by Arsenal’s…

34 seconds ago

Japanese company on Hezbollah’s exploding walkie-talkies: Had already warned …

Walkie-talkies belonging to the Lebanese armed group Hezbollah detonated on Wednesday, killing at least 14…

6 mins ago

Barcelona Player Ratings vs. Monaco – Eric Garcia’s Red Card Hands Monaco UCL Victory

2024-09-20 06:00:03 Barcelona suffered its first competitive defeat under Hansi Flick in its Champions League…

11 mins ago

Where Are Lyle And Erik Menendez Now? New Evidence Could Get Them Released From Prison

2024-09-20 05:50:02 TRIAL OF BROTHERS LYLE & ERIK MENENDEZ, PARRICIDES (Photo by Ted Soqui/Sygma via…

21 mins ago

Coinbase Plans to Push Institutional Investors into Web3, Defi, NFTs Amid Rattled India Operations

Coinbase, in a bid to get institutional investors to engage with NFTs and DeFi, has…

26 mins ago

Mark Robinson vows to stay in N.C. governor’s race following report he made inflammatory comments on a porn site

2024-09-20 05:40:05 Mark Robinson, the Republican candidate for governor in North Carolina, vowed Thursday to…

31 mins ago