Scammers Employ Bit-flip Attack to Drain Crypto Wallets

By

2 weeks agoMon Feb 12 2024 11:21:37

Scammers-Employ-Bit-flip-Attack-to-Drain-Crypto-Wallets

Reading Time: 2 minutes

  • Scammers have employed a new tactic to drain crypto wallets on the Solana blockchain
  • Known as bit-flip attack, it involves editing Dapp instructions even after transaction signing
  • Researchers have traced the attack to wallet drainers using scam-as-a-service tools

Researchers have unearthed a new method used by scammers to drain wallets, especially those on the Solana blockchain. Known as a bit-flip attack, the malicious actors are manipulating the instructions in a transaction after signing, making it possible for them to fly under the radar. According to the researchers, the tactic enables scammers to hold on to a transaction’s signature after a wallet holder signs a transaction, making it easy to empty a victim’s wallet. 

Vanish and Aqua Caught in Action

Blockchain security firm Blowfish revealed that the tactic is being employed by wallet drainers with links to scam-as-a-service providers.

There’s a completely new breed of scams on the loose, and they’re not like anything we’ve seen before!

Imagine: a transaction that appears safe when you sign it, but the moment it’s submitted on chain, it suddenly drains your assets.

Sounds like a nightmare, doesn’t it? pic.twitter.com/VkD4Cbhnh0

— Blowfish (@blowfishxyz) February 9, 2024

Two of these drainers, Vanish and Aqua, have been caught in action changing a Dapp’s instructions, even after a wallet user has already signed a transaction.

According to the web3 security firm, malicious actors can, for example, initiate a transaction with instructions to send SOL to a wallet but later change the instructions from “send to siphon funds” once a user signs the initial transaction.

The new attack vector comes as wallet drainers become a preferred go-to method of stealing funds instead of directly hacking a crypto wallet.

Three weeks ago, for example, malicious actors hacked Rocket Pool’s X (formerly Twitter) account and directed followers to a wallet drainer. Malicious actors have also masked wallet drainers in Google Ads, a tactic that has netted them over $60 million.

Inferno Drainer Shuts Down

In November last year, scam-as-a-service platform Inferno Drainer announced that it’s completely shutting down after helping scammers steal over $70 million. Inferno Drainer has in the past been accused of also targeting users in the NFT space.

With the bit-flip method enabling scammers to manipulate the instructions in a transaction after signing, it’s likely they’ll net more victims and funds.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Bam adopts AI for risk management thumbnail

Bam adopts AI for risk management

Bam is the launch partner for nPlan Portfolio, making it the first contractor anywhere in the world to use nPlan’s AI and big data to quantify and manage schedule risk across a portfolio of projects. Bam will use the tech to oversee an initial portfolio of 50 projects and work nPlan to refine the product
Read More
China Tech Digest: All Competition Venues Powered By Green Electricity During Winter Games; Loongson Releases Solutions Based On LoongArch Autonomous Instruction Set thumbnail

China Tech Digest: All Competition Venues Powered By Green Electricity During Winter Games; Loongson Releases Solutions Based On LoongArch Autonomous Instruction Set

All competition venues will be powered by green electricity during Winter Games The Information Office of the State Council held a press conference today to introduce the green winter Olympics and sustainable development work of the Beijing Winter Olympics and Paralympic Games. Li Sen, director of the Overall Planning Department of the Beijing Winter Olympics…
Read More
Rabat: Launch of the Bassma project in honor of women thumbnail

Rabat: Launch of the Bassma project in honor of women

L’association Al-Bouchra pour le développement social, culturel et sportif en partenariat avec le ministère de l’Intérieur, a lancé le projet Bassma pour le renforcement des capacités des femmes dans la gestion locale, ce 8 janvier 2022, à Rabat. Grâce à l’initiative de l’association Al-Bouchra pour le développement social, culturel et sportif, accompagné du ministère de…
Read More
Big wins for Countryside thumbnail

Big wins for Countryside

Milton Keynes Council has selected Countryside Partnerships as its development partner for a scheme of 930 homes in Newport Pagnell. This development, which has a gross development value of £275m, will include 50% affordable housing, delivered in affordable rent, shared ownership and social rent tenures. Community facilities to be built include a commercial centre, primary
Read More
FTX the Fastest-Growing Crypto Exchange in 2021: Report thumbnail

FTX the Fastest-Growing Crypto Exchange in 2021: Report

The exchange’s 2021 spot trading volume increased 2,400% from 2020's numbers. Key Takeaways FTX has released an impressive end-of-year report for 2021. The report concludes that FTX was the fastest-growing cryptocurrency exchange in 2021. FTX's success is likely attributable to its aggressive fundraising and advertising campaigns. FTX has released its end-of-year report for 2021, revealing…
Read More
Index Of News
Total
0
Share