{"id":58943,"date":"2023-08-25T01:39:15","date_gmt":"2023-08-25T01:39:15","guid":{"rendered":"http:\/\/egrowonline.com\/?p=58943"},"modified":"2023-08-25T01:39:15","modified_gmt":"2023-08-25T01:39:15","slug":"agency-loses-55k-in-address-poisoning-scam","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=58943","title":{"rendered":"Agency loses $55K in address poisoning scam"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=840\/https:\/\/s3.cointelegraph.com\/uploads\/2023-08\/373446bf-5aa5-4f19-a0a8-0ef278e4b325.jpg\" \/><\/p>\n<div data-v-2649fa34=\"\">\n<p>The United States Drug Enforcement Administration (DEA) \u2014 the agency tasked with enforcing the country\u2019s drug laws \u2014 lost $55,000 in seized Tether (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/tether-price-index\" rel=\"noopener\">USDT<\/a>) earlier this year at the hands of a scammer.<\/p>\n<p>Forbes <a target=\"_blank\" href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2023\/08\/24\/dea-accidentally-sends-50000-in-drug-proceeds-to-crypto-scammer\/?sh=71f845d53d12\" rel=\"noopener nofollow\">reported<\/a> on Aug. 24 that in May, the agency seized over $500,000 worth of USDT from two Binance accounts it suspected of laundering money from drug sales as part of a multi-year investigation.<\/p>\n<p>The funds were put in DEA-controlled Trezor crypto wallets and stored securely, according to a search warrant seen by Forbes. As part of standard forfeiture processing the DEA sent a test amount of just over $45 worth of USDT to the U.S. Marshals Service.<\/p>\n<p>An on-chain sleuth picked up on the transaction and then quickly set up a crypto wallet with the same first five and last four characters of the Marshals account \u2014 a <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/etherscan-hides-zero-value-token-transfers-to-deter-address-poisoning-attacks\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/etherscan-hides-zero-value-token-transfers-to-deter-address-poisoning-attacks\/amp\" rel=\"noopener\">scam tactic<\/a> known as \u201caddress poisoning.\u201d<\/p>\n<p>The scammer airdropped a token to the DEA\u2019s wallet so that the spoofed address will appear as a recent transaction, and thus tricking the owner into accidentally transferring funds to the wrong address. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">I almost got hit by an address poisoning scam.<\/p>\n<p>Sent a second tx to someone just after the first, and was lazy and just copy pasted his address from my transaction history.<\/p>\n<p>Yup, copy pasted the poison tx address.<\/p>\n<p>Just before confirming, <a target=\"_blank\" href=\"https:\/\/twitter.com\/Rabby_io?ref_src=twsrc%5Etfw\" rel=\"noopener\">@Rabby_io<\/a> informed me that I had never\u2026 <a target=\"_blank\" href=\"https:\/\/t.co\/XlHPTs8PZy\" rel=\"noopener\">pic.twitter.com\/XlHPTs8PZy<\/a><\/p>\n<p>\u2014 N\u0334\u035d\u0329\u035c\u0320\u0321\u033b\u0329a\u0334\u0305\u034d\u0359\u032b\u0339u\u0336\u0358\u0350\u0302\u033c\u0320\u032dh\u0337\u031a\u0347\u033b\u032dc\u0334\u030e\u0302\u0305\u0357\u0309\u0344\u0306\u0351\u030d\u0300\u0349\u0348 (@nauhcner) <a target=\"_blank\" href=\"https:\/\/twitter.com\/nauhcner\/status\/1648229154054352897?ref_src=twsrc%5Etfw\" rel=\"noopener\">April 18, 2023<\/a><\/p><\/blockquote>\n<p>The tactic worked against the DEA agent, who sent over $55,000 to the scammer. <\/p>\n<p>By the time the Marshals noticed and alerted the DEA who in turn asked Tether to <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/bitcoin-crypto-fbi-flags-6-bitcoin-wallets-linked-to-north-korea\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/bitcoin-crypto-fbi-flags-6-bitcoin-wallets-linked-to-north-korea\/amp\" rel=\"noopener\">freeze the fund<\/a>s it was too late.<\/p>\n<p>The USDT had already been swapped for Ether (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/ethereum-price\" rel=\"noopener\">ETH<\/a>) and Bitcoin (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/bitcoin-price\" rel=\"noopener\">BTC<\/a>) and then <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/criminals-prefer-stablecoins-over-bitcoin-for-illicit-use\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/criminals-prefer-stablecoins-over-bitcoin-for-illicit-use\/amp\" rel=\"noopener\">shifted to different crypto wallets<\/a>.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/sec-charges-former-corrections-officer-for-role-bizarre-crypto-scam\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/sec-charges-former-corrections-officer-for-role-bizarre-crypto-scam\/amp\" rel=\"noopener\"><strong><em>SEC charges former corrections officer with role in bizarre crypto scam<\/em><\/strong><\/a><\/p>\n<p>The DEA alongside the FBI is investigating the incident and is yet to find whose behind the attack. All they\u2019ve found so far are two Binance accounts that paid for the attacker wallet gas fees which used two Gmail email addresses to sign up.<\/p>\n<p>It&#8217;s hoped Google has some information that can be used to nab the owner of the Gmail accounts.<\/p>\n<p>The DEA did not immediately respond to a request for comment.<\/p>\n<p><strong><em>Magazine: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/3-4-billion-bitcoin-popcorn-tin-silk-road-hacker\/\" rel=\"noopener\"><strong><em>$3.4B of Bitcoin in a popcorn tin \u2014 The Silk Road hacker\u2019s story<\/em><\/strong><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/dea-loses-tether-in-address-poisoning-scam\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The United States Drug Enforcement Administration (DEA) \u2014 the agency tasked with enforcing the country\u2019s drug laws \u2014 lost $55,000 in seized Tether (USDT) earlier this year at the hands of a scammer. Forbes reported on Aug. 24 that in May, the agency seized over $500,000 worth of USDT from two Binance accounts it suspected [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":58944,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[17128,3883,8420,774,17129,1301],"class_list":["post-58943","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-55k","tag-address","tag-agency","tag-loses","tag-poisoning","tag-scam"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/08\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDgvMzczNDQ2YmYtNWFhNS00ZjE5LWEwYTgtMGVmMjc4ZTRiMzI1LmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=58943"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58943\/revisions"}],"predecessor-version":[{"id":58945,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/58943\/revisions\/58945"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/58944"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=58943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=58943"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=58943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}