Be wary of fake exchange APP, the security of funds is worrying, and multiple verifications protect assets

Hidden risks of fake exchange apps: user funds are threatened with theft

Recently, a new type of cryptocurrency fraud has attracted a lot of attention. Some users unknowingly transfer funds to the hacker's wallet while using a seemingly normal trading platform app. This scam cleverly exploits the user's trust in the app and steals funds by replacing the transfer address.

It is reported that some users encountered a situation where the funds did not arrive when they were preparing to transfer ETH from other wallets to a well-known trading platform. After verification by customer service, it was found that the recharge address used by the user did not belong to any user of the platform. In another similar incident, a user transferred USDT from another platform, and the first transaction was successfully received, but the second transfer of more than 5,000 USDT was delayed.

Through on-chain data analysis, an address suspected of participating in such scams has received nearly 400 transfers totaling more than 500,000 USDT in the past month. This shows that the scam has caused considerable losses.

Security experts point out that the core of this scam lies in the fact that malicious code is precisely implanted into a normal-looking APP. When a user makes a top-up operation, the malicious code will quietly replace the displayed top-up address with an address controlled by the hacker. Unlike other methods of coin theft, this method does not require bypassing any additional security verification steps.

To combat this threat, experts recommend that users take the following precautions:

  1. Use the private browsing mode to visit the official website of the trading platform.
  2. Carefully compare whether the recharge address displayed on the APP and the official webpage are consistent.
  3. When withdrawing, verify whether the address entered is the same as the address in the email notification.
  4. When using a new address for the first time, make a small test transfer first.
  5. Be sure to download the APP from the official website, especially for Android users.

The security team explained that this fake APP is no different from the genuine one in terms of basic functions such as user login, but it implants malicious code in the top-up process. When a user makes a top-up operation, the malicious code is triggered, replacing the correct top-up address with an address controlled by the hacker.

In particular, experts caution not to look for and download cryptocurrency trading apps through search engines, as the download links in the search results are likely to lead to fake apps. The only reliable way to download safely is to go directly to the official website of the trading platform.

This incident once again highlights the importance of vigilance in the cryptocurrency space. Users should be extremely cautious when conducting any fund operations, and always pay attention to the security reminders and update notices issued by the authorities.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 9
  • Share
Comment
0/400
ThreeHornBlastsvip
· 06-27 04:29
If you can't even see the address clearly, you deserve to be scammed.
View OriginalReply0
NFTArchaeologisvip
· 06-25 08:48
The hacking methods that have gone through reincarnation seem like a replay of the 1995 Netscape incident.
View OriginalReply0
GateUser-cff9c776vip
· 06-25 06:47
Schrödinger's test transfer, believe it or not.
View OriginalReply0
ProofOfNothingvip
· 06-25 01:34
Another group of suckers has been played for suckers.
View OriginalReply0
BlockchainTherapistvip
· 06-24 15:47
Be careful, babies. Another wave of suckers has been played.
View OriginalReply0
AirdropLickervip
· 06-24 15:44
Once again, suckers are being played for suckers.
View OriginalReply0
ImpermanentSagevip
· 06-24 15:43
The new trap is here again.
View OriginalReply0
WalletInspectorvip
· 06-24 15:37
Oh no, it's really a scam.
View OriginalReply0
PerennialLeekvip
· 06-24 15:18
play people for suckers orz
View OriginalReply0
View More
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)