Coinmarketcap tests community security awareness with ‘token address’ in fake hack situation

Source Cryptopolitan

Earlier today, Coinmarketcap posted a token contract address that looked like a post aggressive token promoters often share after hijacking social media accounts. The post caused fears of a possible hack when it appeared the account was compromised to create hype and exposure for a scam token. 

Coinmarketcap’s X account looked to have been compromised when it displayed a CA for an unknown token for over 50 minutes.

It turned out the crypto market aggregator used its X platform to warn users that it has no official token and will not promote it with a direct link. The data platform did not lose access to its account, instead warning its community that the link could have easily been malicious.

Coinmarketcap was not compromised

In this case, Coinmarketcap demonstrated how attacks often happen. The CA, “1xCh3ck0utTh32o2425CmcY3Ar8o0kR1gHtn0w2vpump,” does not lead to a token. Instead, it links to the CMC crypto yearbook. 

Impersonation attacks on X are common, and most services recover their accounts afterward. However, account thefts can be very expensive, especially if they are used to distribute wallet-draining links.

The Coinmarketcap impersonation drill came just days after the Litecoin account suffered a similar attack. Other recent hijacked accounts include PokerGPT and DAWN (@dawninternet).

Reports point to a dozen X accounts compromised over the weekend, usually due to exploited logs on different devices. 

New wave of Solana scams use X account hacks

X account hacks have become more common, affecting even prominent accounts like OpenAI

The attackers have switched from promoting Ethereum to Solana tokens. The chain allows for much easier token creation, either through Pump.fun or through a smart contract. The extremely low fees on Solana and the prevalence of trading bot users help attackers quickly gain more liquidity from FOMO buyers. 

The link distribution relies on the culture of sniping tokens early, often using bots to automate the process. 

Some of the recent account hijackings include WebWeaver. In that case, the attacker launched a live token, reaching the end of the bonding curve in 10 minutes and immediately rug-pulling all liquidity. The exploit was extremely fast and targeted, relying on the initial reaction of automated sniping. Since then, the REPLICATE token has been completely abandoned.

Usually, risky tokens or other types of rug pulls or honeypots will only take minutes or seconds to inflict damage. Hacking a high-profile account can quickly increase traffic to the assets launched on other platforms.

traders will probably become more skeptical of these types of attacks the more the pattern is repeated.

Stolen accounts pose malicious link threats

The token address posted in Coinmarketcap’s recent test was not dangerous or malicious. In other cases, hijacked X accounts may post riskier wallet-drainer links, requiring a wallet connection.

For Ethereum users, the exposed wallets can be secured by revoking permissions. However, once a Solana wallet is exposed, it remains at risk and the user needs to migrate to a new address. 

The initial trend of posting CAs still required traders to engage with the token. Investigators noted the trend had shifted, and some of the hijacked accounts posted links requiring Telegram login credentials. While this looks safer than connecting a wallet, such malicious logins can steal private Telegram information. 

Using that data, hackers can hijack a user’s Telegram account and drain the funds of any trading bots linked to a wallet. 

Those attacks still rely on users not noticing the threat, with almost no active engagement from the hackers. A riskier type of attack often includes chats with attackers, who convince users to download malicious links. 

A recent attack identified by ScamSniffer includes a fake CloudFlare verification. Users may also be urged to open the command prompt and use ‘clipboard verification,’ which pastes a command line to download a malicious file.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
3 Top Bargain Stocks Ready for a Bull RunThe market is coming off two strong years in 2023 and 2024, and that has led to a lot of expensive valuations for the better-performing stocks. But there are still some bargains to
Author  The Motley Fool
7 hours ago
The market is coming off two strong years in 2023 and 2024, and that has led to a lot of expensive valuations for the better-performing stocks. But there are still some bargains to
placeholder
Gold recovers ahead of US CPI inflation dataGold’s price (XAU/USD) recovers initial weekly losses and edges higher for the second day in a row, trading in the $2,680s on Wednesday, after a softer-than-expected United States (US) Producer Price Index (PPI) release the previous day triggered substantial easing in US yields.
Author  FXStreet
7 hours ago
Gold’s price (XAU/USD) recovers initial weekly losses and edges higher for the second day in a row, trading in the $2,680s on Wednesday, after a softer-than-expected United States (US) Producer Price Index (PPI) release the previous day triggered substantial easing in US yields.
placeholder
GBP/USD: Set to face significant support at 1.2100 – UOB GroupThe Pound Sterling (GBP) is likely to trade in a 1.2150/1.2275 range. In the longer run, deeply oversold conditions signal GBP could trade in a range for a couple of days; any decline is expected to face significant support at 1.2100, UOB Group's FX analysts Quek Ser Leang and Peter Chia note.
Author  FXStreet
8 hours ago
The Pound Sterling (GBP) is likely to trade in a 1.2150/1.2275 range. In the longer run, deeply oversold conditions signal GBP could trade in a range for a couple of days; any decline is expected to face significant support at 1.2100, UOB Group's FX analysts Quek Ser Leang and Peter Chia note.
placeholder
JPMorgan Predicts $14 Billion Inflows For Proposed Crypto ETFs If Approved By US SECJPMorgan Chase & Co. Analysts have made a significant projection regarding the potential impact of a new wave of exchange-traded funds (ETFs) focused on alternative crypto assets.  Should these
Author  NewsBTC
8 hours ago
JPMorgan Chase & Co. Analysts have made a significant projection regarding the potential impact of a new wave of exchange-traded funds (ETFs) focused on alternative crypto assets.  Should these
placeholder
Gensler Calls Bitcoin ‘Highly Speculative’ Yet In-demand: 7 Billion Want To Trade ItIn a recent interview with CNBC’s Squawk Box, outgoing US Securities and Exchange Commission (SEC) Chair Gary Gensler offered a nuanced perspective on the digital asset landscape, particularly focusing on Bitcoin (BTC) and the broader crypto market.  His remarks come amid increased scrutiny of the industry, which has faced regulatory challenges and calls for greater […]
Author  Bitcoinist
8 hours ago
In a recent interview with CNBC’s Squawk Box, outgoing US Securities and Exchange Commission (SEC) Chair Gary Gensler offered a nuanced perspective on the digital asset landscape, particularly focusing on Bitcoin (BTC) and the broader crypto market.  His remarks come amid increased scrutiny of the industry, which has faced regulatory challenges and calls for greater […]
goTop
quote