Gate 广场「创作者认证激励计划」优质创作者持续招募中!
立即加入,发布优质内容,参与活动即可瓜分月度 $10,000+ 创作奖励!
认证申请步骤:
1️⃣ 打开 App 首页底部【广场】 → 点击右上角头像进入个人主页
2️⃣ 点击头像右下角【申请认证】,提交申请等待审核
立即报名:https://www.gate.com/questionnaire/7159
豪华代币奖池、Gate 精美周边、流量曝光等超 $10,000 丰厚奖励等你拿!
活动详情:https://www.gate.com/announcements/article/47889
某合规平台社工诈骗案:加拿大骗子冒充客服盗取200万美元
Source: CryptoNewsNet Original Title: Fake Coinbase support scammer allegedly stole $2M from users Original Link: https://cryptonews.net/news/security/32203152/ An alleged scammer posing as a support desk worker has reportedly stolen around $2 million in crypto from users, according to blockchain sleuth ZachXBT.
In a Monday X post, ZachXBT claimed that he had managed to pinpoint the identity of the alleged scammer after cross referencing Telegram group chat screen shots, social media posts and wallet transactions.
ZachXBT alleged that the “Canadian threat actor” had “stolen $2M+ via support impersonation social engineering scams in the past year blowing the funds on rare social media usernames, bottle service, & gambling.”
The Canadian allegedly deployed social engineering tactics to dupe users into believing he worked for the exchange. In his post, ZachXBT shared a leaked video of the alleged scammer on the phone with the victim offering fake customer support.
While the specifics were not detailed, social engineering generally consists of scammers posing as someone from a legitimate organisation to gain trust and elicit private data from unsuspecting victims, or to make dubious transactions.
The alleged scammer attempted to hide their tracks by continually buying “expensive Telegram usernames” and deleting old accounts. However, ZachXBT claimed it was easy to pinpoint their identity and movements due to constant gloating on social media, and posted screenshots of numerous examples of “stories and selfies flaunting his lifestyle with little regard for opsec and was also caught simping for eGirls.”
ZachXBT even claimed to worked out the alleged scammer’s home address using publicly available information, but did not share them due to X’s terms of service.
How can users protect themselves against social engineering?
While seasoned crypto veterans know the best practices to protect themselves after years of trial and error, newcomers often need a heads-up.
It’s important for users to be very vigilant about safe-keeping their private data, don’t use the same password for multiple services and keep significant holdings off an exchange in a hardware wallet.
As a rule of thumb, it’s important to never click on links sent to you or respond to cold calls. Always contact customer support directly through verified avenues such as on the actual website or app.
Additionally, help desk workers will never ask for seed phrases or login credentials, share private wallets to send funds to, or re-direct conversations over to social media apps like Telegram.