{"id":55019,"date":"2023-07-05T06:21:43","date_gmt":"2023-07-05T06:21:43","guid":{"rendered":"http:\/\/egrowonline.com\/?p=55019"},"modified":"2023-07-05T06:21:43","modified_gmt":"2023-07-05T06:21:43","slug":"darknet-bad-actors-work-together-to-steal-your-crypto-heres-how-binance-cso","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=55019","title":{"rendered":"Darknet bad actors work together to steal your crypto, here\u2019s how \u2014 Binance CSO"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-0c8d7d80=\"\">\n<p>Lurking in the shadiest corners of the dark web is a \u201cwell-established\u201d ecosystem of hackers that target cryptocurrency users with poor \u201csecurity hygiene,\u201d according to Binance\u2019s chief security officer.<\/p>\n<p>Speaking to Cointelegraph, Binance CSO Jimmy Su said in recent years, hackers have shifted their gaze toward crypto end-users. <\/p>\n<p>Su noted when Binance first opened in July 2017, the team saw plenty of hacking attempts on its internal network. However, as crypto exchanges continued to beef up their security, the focus has shifted. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Phishing scams are particularly prevalent in emails.<\/p>\n<p>They are used as a way to collect your sensitive information by impersonating someone you trust.<\/p>\n<p>Use the blog below to learn how to stay safe from them. <a target=\"_blank\" href=\"https:\/\/t.co\/UtKBvR52lX\" rel=\"noopener\">https:\/\/t.co\/UtKBvR52lX<\/a><\/p>\n<p>\u2014 Binance (@binance) <a target=\"_blank\" href=\"https:\/\/twitter.com\/binance\/status\/1676350277350313985?ref_src=twsrc%5Etfw\" rel=\"noopener\">July 4, 2023<\/a><\/p><\/blockquote>\n<p>\u201cHackers always choose the lowest bar to achieve their goals, because for them it\u2019s a business as well. The hacker community is a well-established ecosystem.\u201d<\/p>\n<p>According to Su, this ecosystem comprises four distinct layers \u2014 intelligence gatherers, data refiners, hackers and money launderers. <\/p>\n<h3>Data gatherers<\/h3>\n<p>The most upstream layer is what Su described as \u201cthreat intelligence.\u201d Here, bad actors collect and collate ill-gotten intel about crypto users, creating entire spreadsheets filled with details about different users. <\/p>\n<p>This could include crypto websites a user frequents, what emails they use, their name, and whether they\u2019re on Telegram or social media.<\/p>\n<p>\u201cThere is a market for this on the dark web where this information is sold [&#8230;] that describes the user,\u201d explained Su in a May interview.<\/p>\n<p>Su noted this information is usually gathered in bulk, such as previous <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/ledger-data-leak-a-simple-mistake-exposed-270k-crypto-wallet-buyers\" rel=\"noopener\">customer information leaks<\/a> or hacks targeting other vendors or platforms. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">An employee of our email vendor, <a target=\"_blank\" href=\"https:\/\/t.co\/6vM4WAcJal\" rel=\"noopener\">https:\/\/t.co\/6vM4WAcJal<\/a>, misused their employee access to download &amp; share email addresses with an unauthorized external party. <\/p>\n<p>Email addresses provided to OpenSea by users or newsletter subscribers were impacted.<a target=\"_blank\" href=\"https:\/\/t.co\/Osb6qqkqZZ\" rel=\"noopener\">https:\/\/t.co\/Osb6qqkqZZ<\/a><\/p>\n<p>\u2014 OpenSea (@opensea) <a target=\"_blank\" href=\"https:\/\/twitter.com\/opensea\/status\/1542338816551243776?ref_src=twsrc%5Etfw\" rel=\"noopener\">June 30, 2022<\/a><\/p><\/blockquote>\n<p>In April, a research paper by Privacy Affairs revealed cybercriminals have been selling hacked crypto accounts <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/darknet-hackers-are-selling-crypto-accounts-for-as-low-as-30-a-pop\" rel=\"noopener\">for as little as $30 a pop<\/a>. Forged documentation, often used by hackers to open accounts on crypto trading sites can also be bought on the dark web.<\/p>\n<h3>Data refiners<\/h3>\n<p>According to Su, the data gathered is then sold downstream to another group \u2014 usually made up of data engineers that specialize in refining data.<\/p>\n<p>\u201cFor example, there was a data set last year for Twitter users. [&#8230;] Based on the information there, they can further refine it to see based on the tweets to see which ones are actually crypto-related.\u201d<\/p>\n<p>These data engineers will then use \u201cscripts and bots\u201d to figure out which exchanges the crypto enthusiast may be registered with.<\/p>\n<p>They do this by attempting to create an account with the user\u2019s email address. If they get an error that says the address is already in use, then they\u2019ll know if they use the exchange \u2014 this could be valuable information that could be used by more targeted scams, said Su. <\/p>\n<h3>Hackers and phishers<\/h3>\n<p>The third layer is usually what creates headlines. Phishing scammers or hackers will take the previously refined data to create \u201ctargeted\u201d phishing attacks. <\/p>\n<p>\u201cBecause now they know \u2018Tommy\u2019 is a user of exchange \u2018X,\u2019 they can just send an SMS saying, \u2018Hey Tommy, we detected someone withdrew $5,000 from your account, please click this link and reach customer service if it wasn\u2019t you.\u2019\u201d<\/p>\n<p>In March, hardware wallet provider Trezor warned its users about a phishing attack <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/trezor-warns-users-of-new-phishing-attack\" rel=\"noopener\">designed to steal investors\u2019 money<\/a> by making them enter the wallet\u2019s recovery phrase on a fake Trezor website.<\/p>\n<p>The phishing campaign involved attackers posing as Trezor and contacting victims via phone calls, texts, or emails claiming that there has been a security breach or suspicious activity on their Trezor account.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-07\/7bb17273-afec-4c73-b8bf-31f1c6136daa.png\" \/><figcaption style=\"text-align: center\">A screenshot from a phishing domain copying Trezor\u2019s website. Source: Bleeping Computer<\/figcaption><\/figure>\n<h3>Getting away with it<\/h3>\n<p>Once the funds are stolen, the final step is getting away with the heist. Su explained this could involve leaving the funds dormant for years and then moving them to a crypto mixer such as Tornado Cash.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/arbitrum-based-jimbos-protocol-hacked-losing-7m-in-ethereum\" rel=\"noopener\"><strong><em>Arbitrum-based Jimbos Protocol hacked, losing $7.5M in Ether<\/em><\/strong><\/a><\/p>\n<p>\u201cThere are groups that we know that may sit on their stolen gains for two, three years without any movement,\u201d added Su. <\/p>\n<p>While not much can stop crypto hackers, Su urges crypto users to practice better \u201csecurity hygiene.\u201d<\/p>\n<p>This could involve revoking permissions for decentralized finance projects if they no longer use them, or ensuring communication channels such as email or SMS that are used for two-factor authentication are kept private. <\/p>\n<p><strong><em>Magazine: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/tornado-cash-2-0-the-race-to-build-safe-and-legal-coin-mixers\/\" rel=\"noopener\"><strong><em>Tornado Cash 2.0 \u2014 The race to build safe and legal coin mixers<\/em><\/strong><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/how-darknet-hackers-steal-crypto-binance-cso\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lurking in the shadiest corners of the dark web is a \u201cwell-established\u201d ecosystem of hackers that target cryptocurrency users with poor \u201csecurity hygiene,\u201d according to Binance\u2019s chief security officer. Speaking to Cointelegraph, Binance CSO Jimmy Su said in recent years, hackers have shifted their gaze toward crypto end-users. Su noted when Binance first opened in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":55020,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[9706,834,267,62,9370,13484,164,4372,348],"class_list":["post-55019","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-actors","tag-bad","tag-binance","tag-crypto","tag-cso","tag-darknet","tag-heres","tag-steal","tag-work"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/07\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDcvNjU4N2FjYjMtYzk4Ni00MjhkLWFiOTMtMGEzNjIxZTA4YjIzLmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=55019"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55019\/revisions"}],"predecessor-version":[{"id":55021,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/55019\/revisions\/55021"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/55020"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=55019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=55019"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=55019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}