[HN Gopher] Phishing scammers impersonate AH employee to drain c...
       ___________________________________________________________________
        
       Phishing scammers impersonate AH employee to drain crypto wallets
        
       Author : Arnt
       Score  : 41 points
       Date   : 2024-06-13 16:32 UTC (6 hours ago)
        
 (HTM) web link (www.web3isgoinggreat.com)
 (TXT) w3m dump (www.web3isgoinggreat.com)
        
       | davidmurdoch wrote:
       | Title should be "Phishing scammers impersonate Andreessen
       | Horowitz employee to drain crypto wallets"
        
         | throwaway290 wrote:
         | Or "A16z" at least...
        
           | michaelteter wrote:
           | I had to quickly check that my Albert Heijn bonus account
           | hadn't been robbed!
        
         | Arnt wrote:
         | I tried that. Too long. Not essential anyway, IMO, the attack
         | is much more interesting than the victim's employer's name.
        
           | Centrino wrote:
           | The only reason I clicked the link was to know what AH meant.
           | Phishing for crypto assets is nothing new, I wouldn't have
           | clicked it for that.
        
             | Arnt wrote:
             | If I understand the attack correctly:
             | 
             | Twitter followers were migrated, but anyone "following"
             | using something like a crontab that retrieves a link based
             | on the old Twitter name might be fooled.
             | 
             | Even that is apparently not to fringe to work for phishing.
        
               | xsmasher wrote:
               | They could also make initial contact with victims using
               | the scam account (new account that took the old user
               | name).
        
       | 0x111 wrote:
       | There are ways in which people claiming to be from a16z could
       | authenticate themselves in DMs, using services like b2v.xyz
        
         | r1ch wrote:
         | .xyz, the TLD that screams legitimacy.
        
           | 0x111 wrote:
           | hah true
        
           | jl6 wrote:
           | TLD proliferation has been a disaster - way more scammy,
           | scummy use than legitimate use.
        
             | dingnuts wrote:
             | that's true for old TLDs too. Do you have data?
        
       | nipponese wrote:
       | What's scary is if you google Vortax, it comes up like a totally
       | legit videochat app.
        
         | skilled wrote:
         | Was able to find one article calling it out,
         | 
         | https://davidgerard.co.uk/blockchain/2024/04/03/vortax-a-fak...
         | 
         | Genius approach on their part tho. The landing page looks
         | legit, the site even has blog posts.
        
           | michaelteter wrote:
           | nowadays this is so much easier to generate.
        
             | squigz wrote:
             | The barrier to entry of making legit-looking scams has
             | never been very high, to the point where I don't believe
             | them being even easier to generate makes any difference
        
         | rendall wrote:
         | My god. Even a marketing article comparing it to Google Meet.
         | https://medium.com/@VorionApp/vortax-vs-google-meet-what-are...
        
       | dboreham wrote:
       | AH == a16z it seems.
        
         | CoastalCoder wrote:
         | And not "Attack Helicopter", which is the only acronym of which
         | I could initially think.
        
         | michaelteter wrote:
         | And here I was wondering why a Dutch grocery store employee had
         | access to any significant amount of crypto...
        
       | thih9 wrote:
       | This works because we've been conditioned to install videochat
       | plugins, no matter the security warnings.
       | 
       | Personally I installed a few of these. I remember when running
       | Google Meet without Chrome required some plugin and when Zoom
       | required admin password every now and then to perform an update
       | (even after the Mac vulnerability incident[1]).
       | 
       | I hope I'll think twice next time I see a prompt to install a
       | plugin like this.
       | 
       | [1]: https://techcrunch.com/2019/07/10/apple-silent-update-
       | zoom-a...
        
         | Angostura wrote:
         | It worked partly because the company website listed the
         | scammer's Twitter handle as legit
        
           | codedokode wrote:
           | And because OS allows a video chat app to access wallet's
           | private key.
        
         | lostmsu wrote:
         | Ah good, looks like avoiding the Zoom, Telegram, etc apps and
         | using website instead, and only installing messengers that are
         | sandboxed is paying off.
        
       | codedokode wrote:
       | Why installing an app allows to "drain wallets"? Why does a video
       | chat app, which is installed from untrusted source, have an
       | access to a wallet private key? Why OS allows this?
        
         | matsz wrote:
         | There is no way to prevent this on the OS level without making
         | an OS as locked down as iOS.
         | 
         | Anything less, and the user will find a way to accidentally
         | give admin permissions to random apps.
         | 
         | NB: I don't believe that it's the OS's job to protect the user
         | from themselves. Shielding people from consequences of their
         | own actions results in people making worse mistakes later on.
        
       | hinkley wrote:
       | Repudiation is one of the most important features of existing
       | commerce systems and until there's a crypto system that considers
       | that a requirement instead of a cute little non sequitur then
       | nobody serious will ever take crypto currency seriously.
       | 
       | It's just a bunch of pyromaniacs repeatedly burning themselves an
       | each other and saying, "huh, that's weird."
        
       | michaelteter wrote:
       | Twitter (I refuse to use the artist formerly known as bs),
       | considering its great leader, should have detected this before it
       | even went out.
       | 
       | Instead, a user who hasn't been active on Twitter for some time
       | can do something totally benign, not even including messaging or
       | posting, and get flagged as suspicious.
       | 
       | Meanwhile, an account handle changes, and the old one is
       | reclaimed by someone else. And then very suspicious messages get
       | sent. This should be reasonably detectable with less false
       | negatives than what they subject the rest of us to already.
        
       | spacecadet wrote:
       | Probably run by AH on the side.
        
       ___________________________________________________________________
       (page generated 2024-06-13 23:01 UTC)