Social engineering scams have become the biggest threat to encryption assets, and platform users need to be alert to new types of attack methods.

robot
Abstract generation in progress

Social engineering attacks have become a major threat to encryption asset users

In recent years, social engineering attacks targeting cryptocurrency users have shown an upward trend, attracting widespread attention in the industry. These attacks not only have characteristics of persistence and organization but also result in huge financial losses.

On May 15, a trading platform announced that it had confirmed an internal data leak incident and stated that the U.S. Department of Justice has intervened in the investigation. This once again highlights the serious threat that social engineering scams pose to the security of user assets.

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

Analysis of Fraud Techniques

Fraudsters typically carry out attacks through the following steps:

  1. Impersonate official customer service to contact users, claiming that there is an abnormal situation with their account.

  2. Inducing users to install specific wallet applications and transfer assets.

  3. Provide fake mnemonic phrases, claiming to be the "official new wallet".

  4. Once the user transfers funds to the new wallet, the scammers immediately withdraw the assets.

Some scammers also use false "class action" news to create a sense of urgency to prompt users to take action.

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When social engineering scams target Coinbase users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

Characteristics of Scam Organizations

These attacks are usually carried out by organized gangs and have the following characteristics:

  • Use advanced tools to imitate official communication channels
  • Accurately identify target user groups
  • Design a coherent phishing process
  • Make good use of social psychology strategies

Capital Flow Analysis

On-chain data shows that scammers mainly target mainstream assets such as BTC and ETH, with single profits reaching millions of dollars. They typically quickly convert the proceeds into stablecoins and transfer assets through various means to evade tracking.

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

"Customer Service" in the Dark Forest: When Social Engineering Scams Target Coinbase Users

Coping Suggestions

On the platform side:

  • Strengthen user education and security training
  • Improve the mechanism for identifying abnormal behavior
  • Standardize customer service channels and verification processes

User aspect:

  • Implement identity isolation policy
  • Set transfer whitelist and cooling period
  • Stay vigilant and pay attention to security news.
  • Pay attention to offline security and privacy protection

"Customer Service" in the Dark Forest: When social engineering scams target Coinbase users

Conclusion

This incident has once again exposed the industry's shortcomings in customer data protection and asset security. The platform needs to comprehensively enhance the security level of internal personnel management and outsourced services, incorporating social engineering defense into the overall security strategy. Moreover, once systemic threats are detected, the platform should respond promptly and take measures to maintain user trust and asset security.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Share
Comment
0/400
MysteriousZhangvip
· 07-18 15:37
Speechless, there are still people who believe in customer service.
View OriginalReply0
CrashHotlinevip
· 07-16 20:32
Who has been fooled? Let's talk about it.
View OriginalReply0
DeFiGraylingvip
· 07-15 22:25
Yelling fake customer service as soon as you see someone, that's right.
View OriginalReply0
ValidatorVibesvip
· 07-15 22:17
crypto natives still falling for basic phishing smh... this is why we need decentralized identity asap
Reply0
ForkTonguevip
· 07-15 22:13
A group of suckers got rolled.
View OriginalReply0
MetaMiseryvip
· 07-15 22:10
What should I do if I lost money again?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)