{"id":10775,"date":"2022-08-30T16:23:47","slug":"the-new-rising-threat-crypto-scams-using-social-engineering","title":{"rendered":"The new rising threat: Crypto scams using social engineering"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-6772 alignleft\" src=\"https:\/\/integrity-asia.com\/wp-content\/uploads\/kanchanara-tqhxlt2npoi-unsplash.jpg\" alt=\"crypto fraud\" width=\"466\" height=\"310\" \/>The popularity of cryptocurrencies has rendered them a target for hackers. Now, crypto owners need to be more vigilant than ever as hackers are always trying to get ahead to trick their targets.<\/p>\n<p><a href=\"https:\/\/www.zawya.com\/en\/legal\/crime-and-security\/cybercriminals-increasingly-targeting-cryptocurrency-gfc8gkxs\">Researchers<\/a> have observed several modus operandi used by hackers to steal crypto tokens, one of which is through social engineering. In many cases of crypto fraud, social engineering is a method used by perpetrators to obtain wallet code access information.<\/p>\n<p>One fundamental of social engineering is exploiting the weakest point in a <a href=\"https:\/\/cms-corporate.integrity-asia.com\/id\/blog\/2022\/07\/04\/the-dangerous-war-on-campus-cybercrime\/\">security system<\/a>: humans. The existence of social media increases a hacker\u2019s efforts and opportunities to target victims. This method was recently used in a hacking case involving a gaming company.<\/p>\n<h3><strong>Social engineering in crypto fraud<\/strong><\/h3>\n<p>A group of hackers managed to steal Ethereum and USDC tokens worth 625 million dollars after hacking a crypto wallet belonging to a game developer, Sky Mavis. The tokens taken were the property of game users.<\/p>\n<p>According to the <a href=\"https:\/\/www.engadget.com\/axie-infinity-blockchain-hack-fake-job-offer-210017305.html\">media<\/a>, the theft occurred not because of a technical error, but because it was carried out using social engineering. This was discovered after an investigation revealed that hackers entered the network using a private &#8216;key&#8217;.<\/p>\n<p>How the perpetrator successfully stole the key is a lesson that the victim\u2019s company learned the hard way. The perpetrator contacted one of Sky Mavis&#8217; employees via LinkedIn, pretending to be a company that wanted to recruit him and offered irresistible benefits.<\/p>\n<p>The employee was enticed by the salary offered to him. He also answered all the questions prepared by the perpetrators. Furthermore, the recruitment process and interviews seemed to be running smoothly and appropriately, so the employee had no reason to raise suspicion.<\/p>\n<p>At one point during the recruitment process, he received a pdf file containing details of the job description. Unfortunately, the file was actually malware used by the perpetrator to infect the employee\u2019s device. The employee opened the file and the malware began infecting the device, until the perpetrator was able to obtain the &#8216;key&#8217; to the company&#8217;s crypto wallet.<\/p>\n<p>This socially engineered crypto scam is not the first of its kind. In 2020, the <a href=\"https:\/\/www.theguardian.com\/technology\/2020\/jul\/15\/twitter-elon-musk-joe-biden-hacked-bitcoin\">twitter accounts<\/a> of several prominent figures were hacked to post the same tweet asking their followers to send bitcoin. In 2021, perpetrators managed to get investors&#8217; money through the crypto token &#8216;<a href=\"https:\/\/thelogicalindian.com\/technology\/squid-coin-32078\">Squid Coin<\/a>&#8216;.<\/p>\n<h3><strong>Preventing crypto fraud<\/strong><\/h3>\n<p>Of the many fraud cases, what victims have in common is that they do not conduct enough due diligence on foreign persons or entities. <a href=\"https:\/\/www.thecoinrepublic.com\/2022\/02\/16\/important-know-about-the-crypto-founder-who-escaped-from-million-dollar-crypto-scam\/\">A founder of a DAO<\/a> (decentralized autonomous organization) once explained how healthy amounts of skepticism saved him from crypto fraud.<\/p>\n<p>First, he conducted due diligence on individuals and entities with which his company cooperated. Aside from that, he always made sure to thoroughly read all agreements. That&#8217;s when he discovered that there was something wrong with a cooperation agreement that supported the perpetrator to transfer all tokens to his wallet.<\/p>\n<p>Learning from the case, companies need to ensure the objective that due diligence should be the cornerstone of their business plans, regardless of whether they are new to cryptocurrencies, a CEO, or an ICO.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>Putri<br \/>\n<span style=\"font-weight: 400\">Photo by<\/span><a href=\"https:\/\/unsplash.com\/@kanchanara?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\"> <span style=\"font-weight: 400\">Kanchanara<\/span><\/a><span style=\"font-weight: 400\"> on<\/span><a href=\"https:\/\/unsplash.com\/s\/photos\/cryptocurrency?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\"> <span style=\"font-weight: 400\">Unsplash<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The popularity of cryptocurrencies has rendered them a target for hackers. Now, crypto owners need to be more vigilant than ever as hackers are always trying to get ahead to trick their targets. Researchers have observed several modus operandi used by hackers to steal crypto tokens, one of which is through social engineering. In many [&hellip;]<\/p>\n","protected":false},"acf":[],"featured_image_url":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-content\/uploads\/sites\/3\/2022\/08\/kanchanara-tqhxlt2npoi-unsplash.jpg","_links":{"self":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts\/10775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/comments?post=10775"}],"version-history":[{"count":0,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/posts\/10775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/media\/10737"}],"wp:attachment":[{"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/media?parent=10775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/categories?post=10775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-corporate.integrity-asia.com\/id\/wp-json\/wp\/v2\/tags?post=10775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}