Crypto Scam Alert: Pudgy Penguins NFT Users Targeted by Google Ad Network Phishing

Share This Post

Crypto Scam Alert

The post Crypto Scam Alert: Pudgy Penguins NFT Users Targeted by Google Ad Network Phishing appeared first on Coinpedia Fintech News

An elaborate scam has been detected, where attackers are now utilizing ad networks to perpetrate phishing attacks affecting the users of the Pudgy Penguins NFT project. 

According to ScamSniffer, the attack was uncovered after a user complained of being led to a fake Pudgy Penguins site through a Singapore news site. Subsequent research showed that this case is part of a malicious advertising campaign aimed at deceiving Web3 wallet users.

The Attack Mechanism That Is Quite Sophisticated

The high novelty of the campaign is that the Google Ad Network is being used to spread phishing messages. These ads run unpleasant scripts stored in the Adloox tracking domain with the extension .com. 

In its current form, the code incorporated in the ads searches the users’ browsers for Web3 wallets. If a wallet is found, the user gets transferred to a fake Pudgy Penguins site – pudqypenguin[.]com – which is created only to capture wallet credentials.

Although at this moment, it looks like the creators of this campaign focus on Pudgy Penguins NFT users, it is indicated that the same approach can be used against any other Web3 project. This is why the attack remains worrisome to the general crypto world given the flexibility it promises to attackers.

The attack also reveals that sites using Prebid.js, a header bidding application programming interface library, may be vulnerable. When these sites use the Adloox analytics module, they run the risk of transmitting scripts in the ads to the user, a clear sign of malware existence. 

Steps Toward Mitigation

As a result of this event, calls for users to be cautious in their interaction with Web3 interfaces have rapidly intensified. To avoid or reduce interaction with such threats, it is suggested to install ad blockers, open cryptocurrency-related sites, and use associated wallets in another browser. Be extremely cautious when entering any wallet directly, and check the URL first. ScamSniffer is another tool that can be used to detect and prevent phishing instances.

After the campaign was exposed, the security researcher ZachXBT was very active in notifying Adloox about the problem. The latest Adloox CDN JavaScript files containing the malicious code were removed preventing more harm to users.

Never Miss a Beat in the Crypto World!

Stay ahead with breaking news, expert analysis, and real-time updates on the latest trends in Bitcoin, altcoins, DeFi, NFTs, and more.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

South Korea Sees Crypto Boom: 30% of Population Now Owns Digital Assets

South Korea has seen a significant surge in cryptocurrency adoption, with the number of users jumping by 610,000 in November to reach 1559 million Trump Victory Sparks Renewed Interest in Crypto The

Bitcoin Reserve Idea Sparks Cautious Response From Japan PM: Report

According to a recent report by Japanese cryptocurrency publication CoinPost, Japan’s Prime Minister Shigeru Ishiba has taken a cautious stance on the proposal to establish a national Bitcoin (BTC)

BlackRock doubles down on IBIT exposure through its Global Allocation Fund

BlackRock reported holding 430,770 shares of its spot Bitcoin (BTC) exchange-traded fund (ETF) IBIT through its Global Allocation Fund According to a filing with the US Securities and Exchange

Dogecoin Price Repeats Bullish Fractal From 2021, Why January 2025 Is Important

The Dogecoin price is replicating a bullish fractal from 2021, signaling the potential for a price breakout to new highs A crypto analyst has shared a price chart comparing this historically

Defi Doesn’t Sleep—Mystery Whale Dumps 125,000 ETH Into Aave on Christmas Day

The Head of Research at Intotheblockcom revealed that on Christmas Day, someone stashed 125,000 ETH into the decentralized finance (defi) platform Aave The platform has been buzzing with activity

Join HTX’s Festive Season Party: Enjoy Superior Crypto Trading and Open the Door to Wealth

PRESS RELEASE As the year draws to a close, the festive spirit of Christmas and New Year fills the air HTX, a leading global digital assets trading platform, is kicking off its Festive Season Party,