
吴说区块链|Nov 11, 2025 02:26
According to WuShuo, user 25usdc disclosed that hackers are exploiting the comment section of a certain prediction market for scam activities, with losses exceeding $500,000. The hackers use different addresses to simultaneously purchase 'Yes' and 'No' options, allowing their comments to bypass filters. They then post links to their scam websites in an obfuscated, non-plaintext format. These websites mimic legitimate ones, featuring identical logos, and require email login. After verification, a fake Cloudflare window pops up, asking for activity verification. Once clicked, the copied content (which is entirely different from what appears) decodes a Base64-encoded string (actually a server URL), downloads a script from the server, and executes it immediately. This script can contain anything and operates without any warning pop-ups. These scripts collect data, log everything on the system, and steal funds. https://www.(wublock123.com)/index.php?m=content&c=index&a=show&catid=6&id=51652
Timeline