Terra Users Lost Over $4M in Phishing Attack
From April 12 to April 21, dozens of Terra network users became victims of a phishing attack. The attacker received $4.31 million worth of crypto assets, SlowMist experts said.
According to the SlowMist intelligence zone, numerous users on the Terra network had their funds stolen recently.
From 4/12 to 4/21, close to $4.31 million in assets were maliciously transferred to terra1fz57nt6t3nnxel6q77wsmxxdesn7rgy0h27x3 from about 52 different addresses.
— SlowMist (@SlowMist_Team) April 21, 2022
The attacker used phishing advertisements on Google. According to the firm’s analysts, the calculation was that users would look for well-known projects in the Terra ecosystem like Anchor or Astroport.
The search gave in the first lines the results similar to the real site. In some cases, the correct domain name was even indicated, but it changed after clicking on the link.
Our security team conducted an analysis of this incident and discovered that the bulk of this attack was from google phishing ads. Users would search well know projects on the Terra blockchain such as @anchor_protocol or @astroport_fi only to click on the first link by google. pic.twitter.com/aucIcnsCd7
— SlowMist (@SlowMist_Team) April 21, 2022
In the window that opens, the victim was asked to connect their wallet and enter a seed phrase. This allowed unauthorized withdrawal of assets from it.
These may look like normal ads and some even show the same domain names, but once you click on the link, the domain name actually changes. When clicked, it’ll prompt you to connect your wallet, however instead of connecting, users are asked to input their seed phrase. pic.twitter.com/OZjifaJ17m
— SlowMist (@SlowMist_Team) April 21, 2022
SlowMist experts advised Terra users not to click on Google ads or links to dubious resources.
“This will help reduce the likelihood of becoming a victim of phishing,” they stressed.
In ten days, the attacker’s wallet received funds from 54 different addresses.
As a reminder, the MetaMask non-custodial wallet command warned users about the risks of storing data in Apple iCloud due to possible phishing attacks.
Check Also: Metamask Warns Apple Users About Icloud Phishing Attacks
Leave a Reply