• bitcoinBitcoin (BTC) $ 57,045.00
  • ethereumEthereum (ETH) $ 3,057.86
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 511.34
  • solanaSolana (SOL) $ 127.12
  • usd-coinUSDC (USDC) $ 0.999727
  • staked-etherLido Staked Ether (STETH) $ 3,055.51
  • xrpXRP (XRP) $ 0.427884
  • the-open-networkToncoin (TON) $ 7.04
  • dogecoinDogecoin (DOGE) $ 0.103508
  • cardanoCardano (ADA) $ 0.358617
  • tronTRON (TRX) $ 0.126468
  • avalanche-2Avalanche (AVAX) $ 24.12
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 57,069.00
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • polkadotPolkadot (DOT) $ 5.49
  • chainlinkChainlink (LINK) $ 12.37
  • bitcoin-cashBitcoin Cash (BCH) $ 325.91
  • uniswapUniswap (UNI) $ 7.53
  • leo-tokenLEO Token (LEO) $ 5.76
  • daiDai (DAI) $ 1.00
  • nearNEAR Protocol (NEAR) $ 4.53
  • litecoinLitecoin (LTC) $ 64.51
  • matic-networkPolygon (MATIC) $ 0.486816
  • wrapped-eethWrapped eETH (WEETH) $ 3,183.80
  • kaspaKaspa (KAS) $ 0.163960
  • pepePepe (PEPE) $ 0.000009
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • internet-computerInternet Computer (ICP) $ 6.55
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,087.93
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.21
  • ethereum-classicEthereum Classic (ETC) $ 20.55
  • moneroMonero (XMR) $ 155.17
  • aptosAptos (APT) $ 5.87
  • render-tokenRender (RNDR) $ 6.46
  • stellarStellar (XLM) $ 0.085479
  • okbOKB (OKB) $ 36.48
  • hedera-hashgraphHedera (HBAR) $ 0.065223
  • cosmosCosmos Hub (ATOM) $ 5.92
  • crypto-com-chainCronos (CRO) $ 0.083602
  • mantleMantle (MNT) $ 0.659777
  • arbitrumArbitrum (ARB) $ 0.665795
  • filecoinFilecoin (FIL) $ 3.66
  • makerMaker (MKR) $ 2,200.05
  • blockstackStacks (STX) $ 1.36
  • immutable-xImmutable (IMX) $ 1.29
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997861
  • injective-protocolInjective (INJ) $ 19.40
  • vechainVeChain (VET) $ 0.022312
  • dogwifcoindogwifhat (WIF) $ 1.70
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,422.73
  • suiSui (SUI) $ 0.661858
  • the-graphThe Graph (GRT) $ 0.172458
  • optimismOptimism (OP) $ 1.42
  • bittensorBittensor (TAO) $ 215.72
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,140.27
  • ondo-financeOndo (ONDO) $ 1.03
  • bitget-tokenBitget Token (BGB) $ 1.06
  • arweaveArweave (AR) $ 22.18
  • lido-daoLido DAO (LDO) $ 1.58
  • flokiFLOKI (FLOKI) $ 0.000138
  • bonkBonk (BONK) $ 0.000020
  • whitebitWhiteBIT Coin (WBT) $ 9.41
  • based-brettBrett (BRETT) $ 0.130703
  • theta-tokenTheta Network (THETA) $ 1.27
  • fantomFantom (FTM) $ 0.433690
  • aaveAave (AAVE) $ 78.31
  • thorchainTHORChain (RUNE) $ 3.47
  • notcoinNotcoin (NOT) $ 0.010802
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,054.02
  • algorandAlgorand (ALGO) $ 0.129267
  • jasmycoinJasmyCoin (JASMY) $ 0.021483
  • quant-networkQuant (QNT) $ 70.85
  • eosEOS (EOS) $ 0.490413
  • pyth-networkPyth Network (PYTH) $ 0.270284
  • jupiter-exchange-solanaJupiter (JUP) $ 0.721260
  • celestiaCelestia (TIA) $ 4.83
  • gatechain-tokenGate (GT) $ 7.08
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,096.19
  • zebec-protocolZebec Protocol (ZBC) $ 0.017766
  • coredaoorgCore (CORE) $ 0.971576
  • flare-networksFlare (FLR) $ 0.020627
  • kucoin-sharesKuCoin (KCS) $ 9.12
  • elrond-erd-2MultiversX (EGLD) $ 30.50
  • sei-networkSei (SEI) $ 0.272397
  • flowFlow (FLOW) $ 0.524219
  • galaGALA (GALA) $ 0.021775
  • tokenize-xchangeTokenize Xchange (TKX) $ 9.81
  • bittorrentBitTorrent (BTT) $ 0.00000077
  • axie-infinityAxie Infinity (AXS) $ 4.96
  • akash-networkAkash Network (AKT) $ 2.98
  • usddUSDD (USDD) $ 0.994818
  • fasttokenFasttoken (FTN) $ 2.28
  • bitcoin-svBitcoin SV (BSV) $ 35.86
  • ethereum-name-serviceEthereum Name Service (ENS) $ 22.29
  • beam-2Beam (BEAM) $ 0.013947
  • dydx-chaindYdX (DYDX) $ 1.15
  • msolMarinade Staked SOL (MSOL) $ 154.79
  • ethenaEthena (ENA) $ 0.399497
  • starknetStarknet (STRK) $ 0.519323
  • neoNEO (NEO) $ 9.48
  • tezosTezos (XTZ) $ 0.671626
  • fraxFrax (FRAX) $ 0.999747
  • ordinalsORDI (ORDI) $ 29.68
  • the-sandboxThe Sandbox (SAND) $ 0.276264
  • gnosisGnosis (GNO) $ 247.19
  • mantra-daoMANTRA (OM) $ 0.737738
  • frax-etherFrax Ether (FRXETH) $ 3,076.36
  • pendlePendle (PENDLE) $ 3.77
  • lido-staked-solLido Staked SOL (STSOL) $ 153.73
  • nexoNEXO (NEXO) $ 1.06
  • tether-goldTether Gold (XAUT) $ 2,357.84
  • safeSafe (SAFE) $ 1.36
  • roninRonin (RON) $ 1.72
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,286.73
  • oasis-networkOasis Network (ROSE) $ 0.082473
  • chilizChiliz (CHZ) $ 0.060983
  • ecasheCash (XEC) $ 0.000028
  • worldcoin-wldWorldcoin (WLD) $ 1.99
  • heliumHelium (HNT) $ 3.27
  • decentralandDecentraland (MANA) $ 0.285463
  • conflux-tokenConflux (CFX) $ 0.122708
  • havvenSynthetix Network (SNX) $ 1.59
  • zksyncZKsync (ZK) $ 0.144460
  • swethSwell Ethereum (SWETH) $ 3,239.99
  • klay-tokenKlaytn (KLAY) $ 0.136951
  • dexeDeXe (DEXE) $ 8.95
  • mina-protocolMina Protocol (MINA) $ 0.441511
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.004966
  • book-of-memeBOOK OF MEME (BOME) $ 0.007241
  • true-usdTrueUSD (TUSD) $ 0.998243
  • iotaIOTA (IOTA) $ 0.146800
  • mog-coinMog Coin (MOG) $ 0.000001
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,322.84
  • aioz-networkAIOZ Network (AIOZ) $ 0.437680
  • wormholeWormhole (W) $ 0.264968
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.78
  • apecoinApeCoin (APE) $ 0.742593
  • wemix-tokenWEMIX (WEMIX) $ 1.13
  • singularitynetSingularityNET (AGIX) $ 0.525625
  • nervos-networkNervos Network (CKB) $ 0.009545
  • 1inch1inch (1INCH) $ 0.339808
  • pax-goldPAX Gold (PAXG) $ 2,325.61
  • apenftAPENFT (NFT) $ 0.00000043
  • theta-fuelTheta Fuel (TFUEL) $ 0.064181
  • livepeerLivepeer (LPT) $ 12.57
  • raydiumRaydium (RAY) $ 1.56
  • popcatPopcat (POPCAT) $ 0.415477
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • bitcoin-goldBitcoin Gold (BTG) $ 23.78
  • usdbUSDB (USDB) $ 0.983084
  • mx-tokenMX (MX) $ 4.03
  • xdce-crowd-saleXDC Network (XDC) $ 0.026798
  • stader-ethxStader ETHx (ETHX) $ 3,159.99
  • kavaKava (KAVA) $ 0.357944
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.919343
  • illuviumIlluvium (ILV) $ 56.68
  • axelarAxelar (AXL) $ 0.522738
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000067
  • astarAstar (ASTR) $ 0.060670
  • safepalSafePal (SFP) $ 0.748696
  • compound-ethercETH (CETH) $ 61.54
  • rocket-poolRocket Pool (RPL) $ 16.67
  • iotexIoTeX (IOTX) $ 0.035780
  • corgiaiCorgiAI (CORGIAI) $ 0.000995
  • arkhamArkham (ARKM) $ 1.44
  • layerzeroLayerZero (ZRO) $ 3.05
  • woo-networkWOO (WOO) $ 0.172763
  • aevo-exchangeAevo (AEVO) $ 0.384017
  • echelon-primeEchelon Prime (PRIME) $ 7.52
  • pepecoin-2PepeCoin (PEPECOIN) $ 2.65
  • kusamaKusama (KSM) $ 20.22
  • osmosisOsmosis (OSMO) $ 0.460186
  • aragonAragon (ANT) $ 7.75
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.003398
  • compound-governance-tokenCompound (COMP) $ 43.94
  • radixRadix (XRD) $ 0.028787
  • manta-networkManta Network (MANTA) $ 0.877227
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000014
  • stepnGMT (GMT) $ 0.129366
  • curve-dao-tokenCurve DAO (CRV) $ 0.236881
  • memecoin-2Memecoin (MEME) $ 0.013856
  • m2-global-wealth-limited-mmxMMX (MMX) $ 2.05
  • zilliqaZilliqa (ZIL) $ 0.014887
  • justJUST (JST) $ 0.028337
  • compound-wrapped-btccWBTC (CWBTC) $ 1,146.88
  • golemGolem (GLM) $ 0.276877
  • zcashZcash (ZEC) $ 17.96
  • blurBlur (BLUR) $ 0.159234
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.053904
  • blastBlast (BLAST) $ 0.015249
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,203.97
  • dydxdYdX (ETHDYDX) $ 1.15
  • h2o-daoH2O Dao (H2O) $ 0.319905
  • celoCelo (CELO) $ 0.475400
  • holotokenHolo (HOT) $ 0.001443
  • dashDash (DASH) $ 21.54
  • origintrailOriginTrail (TRAC) $ 0.640679
  • nxmNexus Mutual (NXM) $ 68.15
  • enjincoinEnjin Coin (ENJ) $ 0.154457

Hackers target Friend.tech users with cunning verification scam

0 142

Hackers target Friend.tech users with cunning verification scam

  crypto.news 24 m

Hackers target Friend.tech users with cunning verification scam

Users of Friend.tech — a decentralized social network — have recently been targeted by numerous hacker attacks.

Jason Janowitz — founder of crypto news outlet Blockworks — described in an Oct. 8 tweet how someone tried to hijack his Friend.tech account.

At first he received a message that posed as coming from Friend.tech’s automated assistance, pretending that the number associated with the account was being changed.

“A number change has been requested for this account. Reply with YES to appprove this change, or NO to decline. If we do not receive a response within 2 hours, the change will proceed as requested.”

The message is meant to cause someone to believe that a bad actor is trying to access his account and that he can prevent access by answering “no” to the message. What should make victims suspicious is that such a system is rather unlikely to automatically approve changes to the account if the user does not confirm the request.

After Janowitz answered “no” to the message, the hackers attempted to gain access to his account by requesting a two-factor authentication code as confirmation for the refusal to change the number. This message was then followed by a verification code sent to the user’s cellphone number after being requested by the hackers.

Someone is trying to hack my @friendtech

1) Text sent saying they’re changing my number

2) I respond no

3) They say to confirm no, send the verification code

4) Receive actual verification code from friend tech

5) After no response, they text again saying they’ll auto… pic.twitter.com/j76vI969jP

— Yano 🟪 (@JasonYanowitz) October 8, 2023

The logic behind Friend.tech asking for confirmation via a text message (to verify you can receive their texts) is flawed, as you wouldn’t be able to read their message in the first place if you didn’t have access to those texts.

Still, it is entirely plausible that a user scared that his account is about to be compromised could act impulsively and fall for the scam, Janowitz claimed.

“Simple but effective method. Sharing here so others don’t fall for it.”

Jason Janowitz

Janowitz’s tweet comes after recent reports that scammers have stolen over $385,000 in Ether from Friend.tech users through SIM-swapping.

You might also like: What is Friend.tech, social platform earning over $1m in fees

SIM-swapping, also known as SIM hijacking, is a type of account takeover where hackers are able to transfer the victim’s phone number to a SIM card controlled by the attackers. Once they have your number, they can often reset account passwords and bypass two-factor authentication.

On Oct. 5, Friend.tech announced new account security features to help users protect themselves, including the ability to add and remove login methods. This followed user complaints that the platform’s 2FA passcode feature had inadvertently locked people out when their phone numbers were swapped.

According to blockchain investigator ZachXBT, a number of SIM-swap attacks targeting Friend.tech users occurred on Oct. 4. Victims reported having their accounts compromised even after taking precautions like enabling two-factor authentication.

While hackers continue to refine their techniques, experts advise all Friend.tech users to be vigilant about enabling extra login protections and not trusting unsolicited requests to share verification codes.


Source

Leave A Reply

Your email address will not be published.