immensefox
23 posts

immensefox retweetledi
immensefox retweetledi

🎉Omnichain Carnival Wave 1 is now live with early access!
TL;DR
-Early access for Wave 1 starts on 3/26 at 14:00 UTC and lasts for 4 days
-Register during early access to receive a 15% bonus in wave 1
-3% of the total supply will be allocated in Wave 1.
Lead Wave 1 with extra rewards!
Register at: carnival.stakestone.io
Anticipate Wave 2, plus even more to come.
Learn more about omnichain carnival: @official_42951/stakestone-omnichain-carnival-6a4fc10ebe4f" target="_blank" rel="nofollow noopener">medium.com/@official_4295…

English
immensefox retweetledi

Just entered a #Nobody giveaway with 2500 spots for @realnobodyxyz on @okxweb3, come and join!twitter.com/okxweb3/status…
OKX Wallet@wallet
✨ Introducing #Nobody on #OKXNFT 🥂 To celebrate the collaboration between Stephen Chow, @realnobodyxyz & #OKX, we're giving away 2,500 Nobody NFT whitelists spots. Open for a limited time, join now! okx.com/web3/marketpla…
English

@evilcos 老师您好,我去年被钓鱼了900个bnb。我不是推会员,没办法给您发消息。您能私聊我一下,我向您汇报一下具体情况。非常非常感谢
中文

[UPDATE] Crypto 钓鱼常见手法
Drainer-as-a-Service (DaaS) 功能:
注:DaaS 可以理解为针对 Crypto 行业的钓鱼工具,知名的如 Inferno/MS/Angel/Monkey/Venom/Pink/Pussy/Medusa 等这些 Crypto Drainers,牛鬼蛇神们购买这些 Drainers 结合成千上万钓鱼网站、营销账号、各类骗术、漏洞利用、渗透、垃圾广告等等,如洪水猛兽冲进这个行业。
- eth_sign/personal_sign/eth_signTypedData_* 这种原生签名利用,eth_sign 已经被钱包们封堵得越来越少了
- Token/NFT 类似 approve/permit 这些授权函数的利用
- 类似 Uniswap swapExactTokensForTokens/permit2 等这些强大函数的利用
- OpenSea/Blur 等协议函数的利用(五花八门)
- TX data 4byte 利用,Claim Rewards/Security Update 等
- 用 Create2 预创建资金接收地址,绕过相关检测
- Solana 一笔签名钓走目标钱包地址里的所有资产
- 比特币铭文一键批量钓鱼,UTXO 机制
- 各 EVM 链/Solana/Tron 等切换钓鱼
钓鱼路径(不一定使用 DaaS):
- Google/X 等广告投毒、X 评论或私信投毒
- 黑掉官方号(X、Discord、Telegram 等)发布钓鱼链接或其他骗术,黑掉的方法常见如:SIM 卡劫持、第三方应用 OAuth 授权、骗取 Discord token、骗取 Telegram Login code 等方式
- BGP/DNS 等劫持或入侵手法在官方网站植入恶意代码
- 供应链攻击在官方网站植入恶意代码(如之前 Ledger 模块 ledgerhq/connect-kit 被投毒事件)
- 隐蔽的陷阱合约(貔貅盘、套利陷阱等)
- 知名项目合约存在授权漏洞
- 空投代币买卖或以取消授权名义偷走用户过大的 Gas
- 伪造事件/零转账等障眼法
- 污染钱包的转账历史(首尾号一样),坐等用户复制
- 伪装记者、资方、项目方等诱骗用户下载打开带木马的文档、游戏程序、工具等
- 带后门的薅毛工具
- 假 Telegram/WhatsApp/Binance 等替换钱包地址
- 假钱包直接采集助记词或者给 Tron 地址加把权限锁,坐等目标入账
- 诱骗用户转账时填写存在猫腻(如授权)的 data
- 假币、假官网、假官方人员等等骗局
- 诱骗用户直接“上供”自己的助记词...
- 明文助记词/私钥陷阱:窃取手续费或诱导安装带木马的钱包程序
- 类“杀猪盘”线上套路
- 类“扳手攻击”“色诱”“大生意”等这种线下套路
- 硬件钱包售卖渠道被中间人动手脚
- ...
钓鱼是个广泛概念,还有不少手法,但基本大同小异。除了钓鱼,还有一些其他主流作恶手法,这里先不展开了。我特别提钓鱼,是因为这种手法实在过于泛滥,大家一定要谨慎谨慎再谨慎。
相关案例见黑手册扩展阅读:
github.com/evilcos/darkha…
中文

🚨 $SSWP @suiswap_app, a native token within the Sui blockchain @SuiNetwork ecosystem, gets listed on #OKX!
▶ Deposits are OPEN 🟢
📈 $SSWP/USDT Spot Trading: 8:00 am Jun 12 (UTC)
English
immensefox retweetledi

🎉 In celebration of @WingSwapFTM launching $WIS token on @FantomStarter
We are thrilled to announce the first-ever Community Airdrop Event for 1000 luckiest participants & top 100 referrals
💵 200.000 $WIS
⏰ Ends on: Dec 10
JOIN NOW: gleam.io/XFr4a/wingswap… 😉
#WingSwap

English

DaoStarter@DaoStarter
The @sportfiofficial is ecosystem is the perfect combination of NFT gaming and DeFi that enables users to have fun and earn profit simultaneously. @mhventures @R8Capital @CapitalRedhat @YellowRoad__ @AnyPadio #GameFi #NFT @DAOStarter_/sportfi-whitelist-for-daostarter-private-sale-is-now-open-29fcbdadcd8e" target="_blank" rel="nofollow noopener">medium.com/@DAOStarter_/s…
English
immensefox retweetledi

The @sportfiofficial is ecosystem is the perfect combination of NFT gaming and DeFi that enables users to have fun and earn profit simultaneously.
@mhventures @R8Capital @CapitalRedhat @YellowRoad__ @AnyPadio
#GameFi #NFT
@DAOStarter_/sportfi-whitelist-for-daostarter-private-sale-is-now-open-29fcbdadcd8e" target="_blank" rel="nofollow noopener">medium.com/@DAOStarter_/s…
English

@mis660066 this is really super gamefi!come to have a try
@DoctorMbitcoin
@Jiangzhuoer2
@BTC521
My Telegram ID:Xiaoliclassmate
English

星鲨Starsharks新手入门教学视频视频(最新版本内测版本1.0.9),手把手带你入门,如果想进阶学习,欢迎加入我们的Discord和电报群交流。
youtube.com/watch?v=kReZ7A…
bilibili.com/video/BV1qS4y1…

YouTube
中文





