Recently, there are many traps in on-chain dog fighting, be careful of scam links and malicious pools.

CN
2 hours ago
Someone lost 600,000 USD to a phishing link.

Written by: Rhythm

Recently, the risks in the crypto space have noticeably increased. We have gotten used to the ups and downs, but mainly we should avoid being scammed.

For example, by clicking on a fraudulent link.

Crypto KOLs @insidecalls and @cladzsol recently revealed that during their routine chain scanning, they clicked on a meme coin homepage, resulting in a pop-up that pretended to be a "cloudflare verification," instructing them to perform a ctrl V operation, which was actually a malicious script. After following the prompt to "complete verification," the victim's on-chain funds were stolen, with @cladzsol losing around 600,000 USD in assets.

BlockBeats found that on several popular meme coin display pages, their homepages would redirect to a "cloudflare verification" page, which was actually a phishing link. If users followed the prompt and performed the operation, their computer systems would download and execute malicious scripts, leading to asset losses.

This phenomenon is rampant now, likely related to the delayed audits of mainstream trading aggregation platforms like DexScreener. The current display logic of related platforms is to directly reference the "official website" or social media links filled in the token metadata. These fields can be updated by token creators or people who later claim "community takeover." Hackers have exploited this audit loophole to turn meme coin display pages into new "fishing grounds" for phishing attacks.

Another example is the recent discussions around Uniswap V4 pool issues.

The trading aggregator 0x released an analysis report titled "Uniswap v4 hooks were a mistake." They pulled data from six chains showing 84,163 Hooks for examination, with shocking results: over half (54.2%) were malicious contracts, and another 26.4% were suspected malicious.

This malicious activity leads to retail investors losing money; buying 1,000 USD worth of coins might mean 200 USD goes into these hook addresses, comparable to an MEV attack.

So how can retail investors protect themselves?

Set low slippage

This is likely the best defense for retail investors on-chain. Low slippage means malicious hooks can't profit. Some low-cap coins might indeed not execute trades at low slippage, but those with slightly larger market caps should take note.

Confirm "Minimum Received"

The estimated amount obtainable is simulated off-chain, and in the face of malicious Hooks, it can easily become a worthless promise.

Check the minimum received amount (Minimum Received); if this number drops below your mental tolerance, it’s best to cancel the trade.

There are also some suggestions from Uniswap’s official guidance, which are basically useless, advising to use the official Uniswap front end, as it has a hook whitelist that malicious ones won’t pass. But who wants to trade on an Uniswap front end that feels terrible?

In conclusion, everyone should pay more attention while trading; the opportunities can be plentiful when the chain heats up, but protecting your capital is more important.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink