BTC $84,933.37 +0.35%
ETH $2,684.40 +0.14%
BNB $790.23 +2.34%
XRP $1.49 -0.41%
SOL $119.88 +0.24%
TRX $0.3362 -0.04%
DOGE $0.0931 -1.46%
ADA $0.2455 -1.97%
BCH $315.13 +1.99%
LINK $13.88 -1.89%
HYPE $88.92 +0.29%
AAVE $178.77 -2.41%
SUI $1.17 +1.50%
XLM $0.2141 -2.31%
ZEC $1,300.59 -4.75%
AAPL $333.40 +0.01%
AMZN $251.86 +0.29%
GOOGL $343.19 -0.17%
MSFT $517.72 +0.57%
META $728.92 -0.03%
NVDA $234.65 -0.07%
TSLA $370.80 -0.62%
SNDK $1,715.86 -0.34%
INTC $118.32 -1.65%
SPCX $159.06 +0.47%
MU $1,071.65 -0.73%
AMD $633.50 +0.22%
BTC $84,933.37 +0.35%
ETH $2,684.40 +0.14%
BNB $790.23 +2.34%
XRP $1.49 -0.41%
SOL $119.88 +0.24%
TRX $0.3362 -0.04%
DOGE $0.0931 -1.46%
ADA $0.2455 -1.97%
BCH $315.13 +1.99%
LINK $13.88 -1.89%
HYPE $88.92 +0.29%
AAVE $178.77 -2.41%
SUI $1.17 +1.50%
XLM $0.2141 -2.31%
ZEC $1,300.59 -4.75%
AAPL $333.40 +0.01%
AMZN $251.86 +0.29%
GOOGL $343.19 -0.17%
MSFT $517.72 +0.57%
META $728.92 -0.03%
NVDA $234.65 -0.07%
TSLA $370.80 -0.62%
SNDK $1,715.86 -0.34%
INTC $118.32 -1.65%
SPCX $159.06 +0.47%
MU $1,071.65 -0.73%
AMD $633.50 +0.22%

ltin

All
Article
Flash

Phishing websites use meme coin display pages to attract traffic, resulting in significant losses for multiple traders

Recently, the meme coin market has been booming, and on-chain trading has become increasingly active. However, with the warming market, meme coin display pages have frequently shown highly disguised phishing links, and the "novel" attack methods have caused several seasoned traders to fall victim. Crypto KOLs @insidecalls and @cladzsol recently revealed that while scanning chains, they clicked on the meme coin homepage, which resulted in a "cloudfare verification" prompt. After completing the verification as instructed, the victim's on-chain funds were stolen. Among them, @cladzsol lost approximately $600,000 in assets.According to market news, on several recently popular meme coin display pages, the homepage redirects to a "cloudfare verification" page, which is actually a phishing link. If users follow the prompts, their computer systems will download and execute malicious scripts, leading to asset loss. This phenomenon is so rampant that it may be related to the delayed review processes of mainstream trading aggregation platforms like DexScreener. Currently, the display logic of relevant platforms is to directly reference the "official website" or social media links filled in the token metadata. These fields can be updated by token creators or those who later claim "community takeover." Hackers are exploiting this review loophole to transform meme coin display pages into new "fishing grounds" for phishing attacks. Users may inevitably click on unfamiliar links during the chain scanning process; if a "cloudfare verification" or other highly suspicious page appears, they should close it immediately to avoid interaction and protect their asset security.

first_img Cosmos Labs admits to misjudging a vulnerability, resulting in an attack on six chains with a loss of 5.7 million dollars

Cosmos Labs released a technical report, admitting that it previously misjudged an integer underflow vulnerability in the Cosmos EVM, which led to attacks on six blockchain networks between August 20 and 25, resulting in a total theft of approximately $5.7 million in tokens. The attacker exploited the vulnerability to underflow account balances to the maximum value of 2^256-1, then performed a reverse operation to transfer the inflated balance out, thereby stealing tokens from the target accounts without creating tokens out of thin air.The report shows that researchers submitted the defect through a bug bounty program on April 25, but testers were unable to reproduce it on the existing Cosmos chain configuration, so Cosmos Labs silently patched it in May. Independent researchers confirmed in early August that the vulnerability affected all Cosmos EVM chains, and Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later.In terms of specific losses, MANTRA lost 720.9 million tokens (approximately $3.6 million), TAC lost nearly 3 billion TAC, and KiiChain lost about 148 million KII. Both MANTRA and KiiChain criticized Cosmos Labs for not notifying the affected chains in advance and suggesting a shutdown, with KiiChain stating that the patch would take several days to deploy while a shutdown would only take a few minutes. Cosmos Labs stated that it has coordinated responses with 40 chains and assisted 13 chains in completing repairs or shutdowns before being attacked.
app_icon
ChainCatcher Building the Web3 world with innovations.