• bitcoinBitcoin (BTC) $ 66,662.00
  • ethereumEthereum (ETH) $ 2,005.09
  • tetherTether (USDT) $ 0.999230
  • bnbBNB (BNB) $ 613.13
  • xrpXRP (XRP) $ 1.34
  • usd-coinUSDC (USDC) $ 0.999714
  • solanaSolana (SOL) $ 82.60
  • tronTRON (TRX) $ 0.315655
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.091204
  • usdsUSDS (USDS) $ 0.999912
  • whitebitWhiteBIT Coin (WBT) $ 51.47
  • bitcoin-cashBitcoin Cash (BCH) $ 483.38
  • hyperliquidHyperliquid (HYPE) $ 39.63
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.246218
  • leo-tokenLEO Token (LEO) $ 9.61
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 329.63
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.50
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.154674
  • ethena-usdeEthena USDe (USDE) $ 0.999015
  • stellarStellar (XLM) $ 0.167906
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999542
  • daiDai (DAI) $ 0.999542
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 54.08
  • memecoreMemeCore (M) $ 2.25
  • hedera-hashgraphHedera (HBAR) $ 0.089878
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • rainRain (RAIN) $ 0.008051
  • avalanche-2Avalanche (AVAX) $ 8.77
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 214.85
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.865367
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 318.70
  • the-open-networkToncoin (TON) $ 1.24
  • crypto-com-chainCronos (CRO) $ 0.071414
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.097831
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,485.94
  • pax-goldPAX Gold (PAXG) $ 4,495.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.674916
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • uniswapUniswap (UNI) $ 3.39
  • polkadotPolkadot (DOT) $ 1.26
  • global-dollarGlobal Dollar (USDG) $ 0.999741
  • pi-networkPi Network (PI) $ 0.181049
  • okbOKB (OKB) $ 83.97
  • falcon-financeFalcon USD (USDF) $ 0.997476
  • aster-2Aster (ASTER) $ 0.659871
  • skySky (SKY) $ 0.069792
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.17
  • aaveAave (AAVE) $ 97.10
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.95
  • bfusdBFUSD (BFUSD) $ 0.999300
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ondo-financeOndo (ONDO) $ 0.269632
  • ethereum-classicEthereum Classic (ETC) $ 8.04
  • internet-computerInternet Computer (ICP) $ 2.23
  • siren-2Siren (SIREN) $ 1.70
  • gatechain-tokenGate (GT) $ 6.58
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 7.92
  • quant-networkQuant (QNT) $ 70.47
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001714
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.092077
  • kaspaKaspa (KAS) $ 0.035152
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • nexoNEXO (NEXO) $ 0.888993
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • usdtbUSDtb (USDTB) $ 1.00
  • render-tokenRender (RENDER) $ 1.67
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • midnight-3Midnight (NIGHT) $ 0.051712
  • worldcoin-wldWorldcoin (WLD) $ 0.273577
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.66
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • morphoMorpho (MORPHO) $ 1.49
  • usddUSDD (USDD) $ 0.999037
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.091050
  • aptosAptos (APT) $ 0.937204
  • wbnbWrapped BNB (WBNB) $ 759.61
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.081981
  • official-trumpOfficial Trump (TRUMP) $ 2.94
  • flare-networksFlare (FLR) $ 0.007793
  • ousgOUSG (OUSG) $ 114.73
  • filecoinFilecoin (FIL) $ 0.810119
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • hash-2Provenance Blockchain (HASH) $ 0.010919
  • beldexBeldex (BDX) $ 0.080669
  • xdce-crowd-saleXDC Network (XDC) $ 0.030629
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • yldsYLDS (YLDS) $ 0.999673
  • ghoGHO (GHO) $ 0.998945
  • vechainVeChain (VET) $ 0.006672
  • usual-usdUsual USD (USD0) $ 1.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.241741
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • arbitrumArbitrum (ARB) $ 0.090041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • stable-2​​Stable (STABLE) $ 0.025444
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • justJUST (JST) $ 0.060512
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.144482
  • layerzeroLayerZero (ZRO) $ 2.01
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.997566
  • a7a5A7A5 (A7A5) $ 0.012291
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.37
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.659079
  • euro-coinEURC (EURC) $ 1.15
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • chilizChiliz (CHZ) $ 0.039881
  • blockstackStacks (STX) $ 0.220665
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 32.07
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006391
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998758
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • kinesis-goldKinesis Gold (KAU) $ 158.00
  • tezosTezos (XTZ) $ 0.343983
  • decredDecred (DCR) $ 21.12
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • hastra-primePRIME (PRIME) $ 1.03
  • ether-fiEther.fi (ETHFI) $ 0.459861
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.053736
  • usxUSX (USX) $ 0.999400
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • dexeDeXe (DEXE) $ 7.18
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017115
  • cocaCOCA (COCA) $ 1.30
  • apenftAINFT (NFT) $ 0.00000033
  • adi-tokenADI (ADI) $ 4.04
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • curve-dao-tokenCurve DAO (CRV) $ 0.210622
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 117.99
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • usdaiUSDai (USDAI) $ 0.999611
  • kite-2Kite (KITE) $ 0.167986
  • aerodrome-financeAerodrome Finance (AERO) $ 0.324739
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • conflux-tokenConflux (CFX) $ 0.056745
  • injective-protocolInjective (INJ) $ 2.83
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • bitcoin-svBitcoin SV (BSV) $ 13.81
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • fraxLegacy Frax Dollar (FRAX) $ 0.997899
  • kaiaKaia (KAIA) $ 0.046440
  • riverRiver (RIVER) $ 13.77
  • kinesis-silverKinesis Silver (KAG) $ 70.38
  • flokiFLOKI (FLOKI) $ 0.000028
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • celestiaCelestia (TIA) $ 0.294202
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • jasmycoinJasmyCoin (JASMY) $ 0.005304
  • noonNoon (NOON) $ 0.751949
  • official-foOfficial FO (FO) $ 0.262868
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • lido-daoLido DAO (LDO) $ 0.306908
  • venice-tokenVenice Token (VVV) $ 5.80
  • the-graphThe Graph (GRT) $ 0.023745
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • spx6900SPX6900 (SPX) $ 0.272543
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • monadMonad (MON) $ 0.023225
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • olympusOlympus (OHM) $ 15.47
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • iotaIOTA (IOTA) $ 0.055140
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • doublezeroDoubleZero (2Z) $ 0.068763

New advanced X account takeover attack targets crypto community

0 0


A new sophisticated phishing campaign is targeting the X accounts of crypto personalities, using tactics that bypass two-factor authentication and appear more credible than traditional scams.

According to a Wednesday X post by crypto developer Zak Cole, a new phishing campaign leverages X’s own infrastructure to take over the accounts of crypto personalities. “Zero detection. Active right now. Full account takeover,” he said.

Cole highlighted that the attack does not involve a fake login page or password stealing. Instead, it leverages X application support to gain account access while also bypassing two-factor authentication.

MetaMask security researcher Ohm Shah also confirmed seeing the attack “in the wild,” suggesting a broader campaign, and an OnlyFans model was also targeted by a less sophisticated version of the attack.

Related: Blockstream sounds the alarm on new email phishing campaign

Crafting a credible phishing message

The notable feature of the phishing campaign is how credible and discreet it is. The attack begins with an X direct message containing a link that appears to redirect to the official Google Calendar domain, thanks to how the social media platform generates its previews. In the case of Cole, the message pretended to be coming from a representative of venture capital firm Andressen Horowitz.

The phishing link is in the message. Source: Zak Cole

The domain that the message links to is “x(.)ca-lendar(.)com” and was registered on Sept. 20. Still, X shows the legitimate calendar.google.com in the preview thanks to the site’s metadata exploiting how X generates previews from its metadata.

“Your brain sees Google Calendar. The URL is different.“

Phishing site’s metadata. Source: Zak Cole

When clicked, the page’s JavaScript redirects to an X authentication endpoint requesting authorization for an app to access your social media account. The app appears to be “Calendar,” but technical examination of the text reveals that the application’s name contains two Cyrillic characters looking exactly like an “a” and an “e” — making it a distinct app compared to the actual “Calendar” app in X’s system.

Phishing X authorization request. Source: Zak Cole

Related: Phishing scams cost users over $12M in August — Here’s how to stay safe

The hint revealing the attack

So far, the most obvious sign that the link was not legitimate may have been the URL that briefly appears before the user is redirected. This is likely to appear for only a fraction of a second and is rather easy to miss.

Still, on the X authentication page, we can find the first hint that this is indeed a phishing attack. The app requests a long list of comprehensive account control permissions, including following and unfollowing accounts, updating profiles and account settings, creating and deleting posts, engaging with posts by others, and more.

Those permissions seem unnecessary for a calendar app and may be the hint that saves a careful user from the attack. If permission is granted, the attackers gain access to the account as the users are given another hint with a redirection to calendly.com despite the Google Calendar preview.

“Calendly? They spoofed Google Calendar, but redirect to Calendly? Major operational security failure. This inconsistency could tip off victims,” Cole highlighted.

According to Cole’s GitHub report on the attack, to check if your profile was compromised and oust the attackers from the account, it is recommended that you visit the X connected apps page. Then he suggests revoking any apps named “Calendar” or “Cаlеndar.” Still, it is likely a good recommendation to revoke any apps that you are not actively using.

Magazine: Fake JD stablecoins, scammers impersonate Solana devs: Asia Express



Source link

Leave A Reply

Your email address will not be published.