Phishing in Cryptocurrency: How to Avoid Scams and Save your Money

in #cryptocurrency6 years ago (edited)

Nobody wants to become a victim of scams. Just like any new industry, the crypto world is full of various shady “businesses” trying to fool you. One of the most tricky methods to steal your savings is phishing. Phishing uses malicious websites disguised as legitimate links of well-known services. A typical phishing link is misspelt. It misses or contains a letter or domain which is hard to define. Even your are tech-savvy, you may easily fall prey to phishing scams without noticing it.

Changelly team is deeply concerned about phishing. We want you to learn about how cryptocurrency phishing scams spread and what to do in order to avoid them and save your money. Let’s look into this box of tricks using the examples of Changelly and Myetherwallet, one of the most prominent wallets for Ether and tokens.

What is actually phishing?


Imagine that when checking your inbox, you noticed a very important update from the wallet where you store your coins. The message in the update says you must sync your wallet with a network that recently has been hardforked. To do that, you need to unlock your account by using your private key or Keystore file, otherwise, you will be unable to send/receive coins.

Sounds spooky, doesn’t it?

So you are clicking the link provided but don’t notice a typo in the URL. You open the scammy web page and put in all your data hoping to update your wallet. Now frauds have access to your wallet and steal all your savings from it. You’re frantically trying to contact your wallet’s support, but they, unluckily, have no idea what’s going on and hence cannot refund the money you lost. So you may label them as scam although they have nothing to do with the phishing affair you’ve been involved into.

How is phishing scam spreading?


Email phishing


Phishing attackers use email databases and send malicious messages to pull the wool over your eyes. At the first glance, they don’t look suspicious but contain scammy and viral URLs, such as myetherwaliet instead of myetherwallet.


Fake Twitter accounts

Phishing scams spread through social media, especially Twitter.

You may receive a malicious message asking you to send your coins or provide your data. Neither of real cryptocurrency services requires you to do it. Check Twitter accounts for up-to-date posts, followers and date of joining. The real account should be verified or at least have reputable brand accounts as followers.

Slack and forums attack

When using Slack or forums, you may also be targeted by phishing scams asking you to log in to your wallet by clicking the link that contains not typos, but additional domains, e.g. myetherwallet.com.co instead of myetherwallet.com


Fake ads


One of the most clever ways to fool you is slipping a scammy URL into advertising on search engine platforms. So if you see ads of some wallets, it might be scammy. Make sure that the URL provided is correct.


Your own misspelling


While surfing the net, you may occasionally make a typo in a website's name that is likely to take you to a totally unknown service.


Phishy wallets


Before entrusting your savings to any wallet, google information on it including a team of developers, social media, reviews. Nothing valuable found? Chances are, it’s not secure.

Prevention


Phishing is a deceptive set of stealthy tricks you should beware of. Luckily, you can take some measures to unmask frauds and keep your funds away from them.

  • Make sure whether your wallet provider requires your email. If not, you will never get a message from it. Most of the wallets including Myetherwallet never ask you for the email.
  • Pay attention to URL, as it will contain a malicious typo like myetherwaliet.com. The original one never contains typos.
  • Always check your own spelling. The only true link to Changelly is https://Changelly.com
  • Search the suspicious URL in EtherScamDB. If you found the link in the database, most likely it would be a scam.
  • Check the security certificate. Most of all reliable cryptocurrency services (including Changelly) are protected with a security protocol aimed to prevent your data from stealing.


  • When participating in ICO or sending your coins elsewhere, always check a token wallet address at Etherscan. If the address is detected in phishing activity, you will see the notice as follows.

  • Use MetaMask or other phishing detectors. Once detected, fake will be blocked.
  • NEVER give anyone your private key. Unless your wallet is custodial, wallet providers will not ask you to provide them with your private keys under any circumstances.
  • Always think twice before clicking any doubtful link.
Detected phishing scams? Please report us at [email protected]
Sort:  

DEAR CHANGELLY,

I have sent to you 92SBD a couple of weeks ago and you told me you were going to refund me... I am still waiting to receive those money sent!

I am still waiting for an email or a comment in here dear @changelly

Hi there! Have you contacted our support team?

You dont ahve a live supprt system and this is because u have system in place to passively cheating by not processing the exchange and by taking the money from user u sit idle and even after sending email u dont even respond......why r u doing this thing....do u think this will help u in the long...u may cheat one day but not everyday...

Reference - TRANSACTION # 079ac35fbc68

U cheated 29 SBD

Dang I had to do triple take on that phishing wording: myetherwaliet versus myetherwallet.

Congratulations @changelly! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the number of posts published

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

Everyones excited as the countdown has begun.. looking eagerly for very good outcomes...good wishes to you.. and everyone..

Phishing attacks are really becoming more and more sophisticated and successful in crypto world. One main reason being that most of us are not fully that techy to dodge these attacks. For example, phishers are now sending emails where the sender address is of official companies, without any typo. Most people who will see such kind of emails having correct sender address will click the link provided in the email. But the truth is that anyone can now send emails and show the sender address as official email address.

That's why we ask our customers to report any phishing activities. We should learn all the tricks they use.

iNTRO pIC-01.jpg

This post was resteemed & upvoted by @superbot - the Best Resteem bot on Planet !
Good Luck!

Follow for 10 minutes ,
Send 0.100 Steem/Steem Dollar and the URL in the memo that you want resteemed and upvoted.

So don't waste any time ! Get More Followers and gain more Visibility With Superbot .

I m very very grateful to u for making us aware of scams.

Congratulations @changelly! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the total payout received

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

Nyc Post!! Thnx for sharing Useful Info!! I lyk your posts!!

Coin Marketplace

STEEM 0.29
TRX 0.12
JST 0.033
BTC 62559.43
ETH 3092.10
USDT 1.00
SBD 3.86