MultiversX Tracker is Live!

Possible "Copycat Address" phishing scheme targeting Ethereum transactions?

Etherum Reddit

More / Etherum Reddit 76 Views

TL;DR: today I found out about "address poisoning"


Today I noticed that some actors on Ethereum are performing a "copycat phishing address" attack (I am not sure if this is the proper term).

What I think is happening:

  • They listen to the network for transactions that move ETH

  • They try to generate a "copycat address" whose hex representation begins and ends with the same character as either the source or the destination address of that transaction

  • They send enough ETH to the copycat address to cover the transaction fees for the next step

  • From the copycat address they send a 0 ETH transaction to the other (i.e. not copycated) address

This way, they try to trick the recipient of that 0 ETH transaction to accidentally use the copycat address for future transactions, if they are not careful.

For example, this is one of the actors in question: https://etherscan.io/address/0xa5cef461646012abd0981a19d62661838e62cf27

Notice that at some point, they started sending ETH to brand new addresses, for example: https://etherscan.io/address/0x71cc48943ebb14612a76ae424970584e0c2b0585 or https://etherscan.io/address/0x6433997e07f5b2a8a492578f11d7c89a1ffa31e3

The target victims of those two copycat addresses are: https://etherscan.io/address/0x5fa359ad5f2081088a6bc96f3ad244b03c77bfe1 and https://etherscan.io/address/0x5109ebf8da80411187f861592c0af48b95376dc9

Notice when victim #1 sent 10 ETH to 0x71cC44EfFA0c7CEa4Fb9842702A99a253F2b0585, quickly after it they received 0 ETH from 0x71cC48943EbB14612A76Ae424970584E0c2b0585

And when victim #2 sent 20.88 ETH to 0x6433978185F0127c933328fE9f5217a91eFa31E3, they received 0 ETH from 0x6433997e07f5b2a8A492578F11D7c89A1FFa31E3

Is this a known phenomenon? (Edit: yes)
Does it have a name? (Edit: yes, "address poisoning")

submitted by /u/minute-journey
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments