Phishing Scam Offering A Fake Airdrop Succeed To Rob Uniswap Users

Phishing Scam Offering A Fake Airdrop Succeed To Rob Uniswap Users

The global crypto market is now in a downtrend condition. Investors are eagerly waiting for the next bull run. The digital assets are held by crypto investors for a long time. In this unfavorable situation, a phishing scam has shaken the Ethereum blockchain. The overall market has already been impacted by this $8.6 million scam. A phishing scam took place on the Uniswap exchange. The aim was to steal the Uniswap users' assets with a smart contract.

Uniswap is the largest decentralized crypto exchange in the global market. This exchange user have been scammed on July 12, 2022. The phishing scam offered some fake UNI tokens and grabbed all the assets of the users with laundering tricks. Over $8 million loss was faced in the Ethereum blockchain.

Phishing

How Did The Phishing Scam Happen?

Phishing is a hacking process that is implemented through fake mimicking websites and well-planned techniques. The current phishing scam was led by a hacker through a smart airdrop. Airdrop is the malicious or fake offer of a free token given by unknown sources or hackers.

This phishing started by mimicking the Uniswap website. The scammer offered free UNI tokens to Uniswap users. There were about 400 free UNI tokens. Which is priced at around $2,200. The website seemed like the real Uniswap website. Though there was a red alert in its domain. The official domain is .org. Whereas the phishing happened with .com.

The scammer's aim was only to convince the users to redirect to this fake website. Then they were offered free UNI tokens which were fake. In this stage, users were asked to click to claim the reward. After clicking on the button, unknowingly users gave the entire control of their Ethereum wallet to the scammer. Then it succeeded.

The Amount Of The Phishing Scam :

The total amount of the loss led by this phishing is around $8.6 million. It has robbed a total of 7,574 Ethereum tokens. Which is priced at over $8 million.

It was reported that the fake reward link was circulated among 73,399 users, who held UNI tokens. The sender of the airdrop had no validation. Though it acted like the original Uniswap source.

The scammer created a mask for the 'setApprovalForAll' function. It helped to allow redeeming all Uniswap V3 LP tokens for Ethereum in the user's wallet.

In the first attempt, the hacker succeeded in stealing 7,574 Ethereum tokens. Then immediately, 7,500 Ethereum was moved to Tornado cash service with laundering tricks.

How to protect yourself from a phishing scam?

Nowadays, the airdrop is the most popular weapon to get the phishing victim the hackers. Airdrop means free cryptocurrency which seems like it is offered by the original service provider. But airdrop is the initial stage to getting a successful phishing scam.

First of all, if any free product is given to someone then it is blindly considered that the user is the product. In the case of free currencies, it can happen a few times by authentic sources. But not always. If you are a crypto trader or investor, you should be aware of this basic thing to protect yourself. The protection can be implemented by analyzing main three ambits-

  1. The domain name of the source should be checked well. It should be verified if the source's website is authentic or if it is different from the real one. If not, then go back and don't look into it.
  2. Next is the validation. The validation of the offer can be checked easily. You can search the original website. If there are the same offer for the users and valid ones given to you then it is favorable.
  3. Last but not the least, the source of the offer can be verified. Verifying the source exposes all the blunders in it.
Hackers evacuated $1.4 million worth of ether from Omni

Hackers evacuated $1.4 million worth of ether from Omni

With the emergence of new technological methods and software, the world is surely progressing at a very high pace and is trying to bring development in each sphere of life. Technology, undoubtedly, has many advantages that have helped mankind achieve the heights of success. However, there are certain aspects where it has also proven to be a bane for society. And most recently, the financial sector has to bear the brunt of it as well.

What happened and how?

The Omni, which functions as an NFT platform that has taken on the responsibility of lending crypto in exchange for NFTs got hacked by some hackers. It became the story of re-entrancy exploit and had to incur huge losses that propelled the whole system to distress. It lost somewhat about 1.4 million dollars, which is estimated to be the value at the time this event occurred.

There are numerous reasons, as cited by experts, why the system was hacked and how it lost so much money. One of the reasons cited was that it was due o the bad faith staking of NFTs. The project, in focus, lost the money from the Doodle collection, to be more specific. The hack was carried out with proper planning and was executed quite systematically as well.

How did the hacker carry out the job?

It has been exposed that the hacker first deposit doodles in a form of collateral and took wrapped ETh as a loan from the same system. After successfully securing the loan, the perpetrator was then able to draw all of the deposited doodles with utmost ease but left behind only one.

After carrying out this task quite successfully and after the completion of the tasks, the doodle that was left in the system was insufficient to cover the debt taken. It gave rise to a situation where the position was liquidated, which led to the doodles getting back to the hacker again. The attack, in other words, tool the loan and did not have to deposit anything in return for it as well.

What steps have been taken to stop such hackers?

Various steps have been taken to attempt to stop such hacks from being done by the attackers. In one such attempt, an open appeal was made to the attackers to return whatever they have stolen from the system. In the appeal, they even mentioned that the events that occurred would be treated as a white-hat event if all the stolen items were returned to the system. They appealed to the attackers to return if not all, but most of the items that were stolen by them.

This appeal, which may sound weird to some, has worked out quite efficiently in some cases. There have been instances where the perpetrators have quite easily returned the stolen items. However, in m this ca such appeals have been rejected or ignored by the perpetrators who kept on hacking systems and stealing from them.

Conclusion 

There have also been some cases where the importance of an appeal boils down to nothing. In these cases, the hackers as soon as they get their hands on the funds, end it to Tornado which uses away the origin of the funds. This source, that is, Tornado, is often said to be used by those who are involved in such illegal activities to carry out the act of stealing from different systems. THE Omni protocol which was still in beta mode has been closed down by the Devs who are in charge of it. However, it has been confirmed by those in charge, that the funds that belonged to the customers were not affected by it.