Blockchain security firm warns of new MetaMask phishing campaign

Share This Post

Blockchain security firm Halborn has warned users of the latest phishing emails doing the rounds.

A cybersecurity firm has issued warnings over a new phishing campaign targeting users of the popular crypto wallet MetaMask.

In a July 28 post written by Halborn’s technical education specialist Luis Lubeck, the active phishing campaign used emails to target MetaMask users and trick them into giving out their passphrase. 

The firm analyzed scam emails it received in late July to warn users of the new scam. Halborn noted that at initial glance, the email looks authentic with a MetaMask header and logo, and with messages that tell users to comply with KYC regulations and how to verify their wallets.

However, Halborn also noted there are several red flags within the message. Spelling errors and a fake sender’s email address were two of the most obvious. Furthermore, a fake domain called metamaks.auction was used to send the phishing emails.

Phishing is a social engineering attack using targeted emails to lure victims into revealing more personal data or clicking links to malicious websites that attempt to steal crypto.

There was also no personalization in the message, the firm noted, which is another warning sign. Hovering over the call to action button reveals the malicious link to a fake website which prompts users to enter their seed phrases before redirecting to MetaMask to empty their crypto wallets.

Halborn, which raised $90 million in a Series A round in July, was founded in 2019 by ethical hackers offering blockchain and cyber security services.

In June, Halborn researchers discovered a case where a user’s private keys could be found unencrypted on a disk in a compromised computer. MetaMask patched its extension versions 10.11.3 and later following the discovery.

However, there was no mention of the new email phishi threat on MetaMask’s Twitter feed at the time of writing.

Related: Phishing risks escalate as Celsius confirms client emails leaked

Last week, Celsius users were warned of a phishing threat following the leak of customer emails by a third-party vendor employee.

In late July, security researchers warned of a new malware strain called Luca Stealer appearing in the wild. The information stealer has been written in the Rust programming language and targets Web3 infrastructure such as crypto wallets. Similar Malware called Mars Stealer was discovered targeting MetaMask wallets in February.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

POPCAT Aims for 30% Rally, 1:4 Risk-Reward Opportunity

The post POPCAT Aims for 30% Rally, 1:4 Risk-Reward Opportunity appeared first on Coinpedia Fintech News Amid this price correction, Popcat (POPCAT), a popular Solana-based meme coin appears bullish

US Treasury Yield Curve Bear Steepens as 2024 Election Looms, Economic Concerns Mount

The US Treasury yield curve is undergoing a notable bear steepening, a trend signaling rising economic jitters as the 2024 election nears, with the Federal Open Market Committee (FOMC) meeting close

Bitcoin ETFs Crucial To Sustain Current Buying Pressure – Details

The price of Bitcoin recorded significant leaps in the past month rising by 1474% according to data from CoinMarketCap During this price rally, the premier cryptocurrency came close to establishing a

Time for Trump (or Kamala) to pledge to buy 20% of the entire Bitcoin supply

The following is a guest post by Kadan Stadelmann, CTO of Komodo Blockchain After weeks of a neck-to-neck presidential campaign between the Democratic and Republican nominees, Donald Trump’s odds

Presidential Advisor Ramaswamy Unveils Bitcoin Integration In Strive’s $1.7 Billion Strategy

On Friday, Strive Asset Management, a firm co-founded by investor and presidential advisor Vivek Ramaswamy, announced the launch of a new wealth management division The initiative aims to provide

Doge2014 Prepares for Major Exchange Listings and Airdrop for VIP Investors – Next 100x Meme Coin?

The post Doge2014 Prepares for Major Exchange Listings and Airdrop for VIP Investors – Next 100x Meme Coin appeared first on Coinpedia Fintech News With its current presale, Doge2014 is