Cryptoscam giveaway: phishers go after seed phrases (2024)

  • scam

We explain how scammers steal cryptowallets through phishing.

  • Roman Dedenok

Cryptoscam giveaway: phishers go after seed phrases (3)

Scammers will stop at nothing when it comes to stealing cryptocurrency. Some try to sell scarce mining equipment, others lure victims with gifts from cryptoexchanges or Elon Musk himself, or even post screenshots on public platforms with passwords for cryptowallets and collect “fees” from cryptoinvestors enticed by the prospect of a free lunch. Today we tell you about a new giveaway scam and underscore once again why the seed phrase for your cryptowallet must be guarded with your life.

Free money

As is often the case, it all starts with an e-mail. The brains behind this scheme chose as bait an offer to take part in a juicy giveaway of cryptocurrency: Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Tron (TRX) or Ripple (XRP). A total of $800 million no less was at stake! The overly generous scammers were kind enough to provide a simple three-point guide for those wanting to get their free cryptocurrency, plus a link to the “promotion” website.

Let’s take a look at the e-mail. It is signed by the support team of a certain Crypto Community: an association of cryptoenthusiasts, one might think. However, the domain in the sender’s e-mail address has nothing to do with any kind of crypto at all. That does not inspire confidence. The message text is slapdash, and full of errors and typos. The scammers are likely counting on the victim being so taken aback by the nine-figure sum that everything else will slip under the radar.

Cryptoscam giveaway: phishers go after seed phrases (4)

Phishing e-mail inviting the recipient to take part in a cryptocurrency giveaway

Clicking the link takes the user to a phishing site. Its domain bears no relation to the sender’s address, and in the minimalist design there is no mention at all of any Crypto Community.

At this point, the victim is asked to specify the wallet they want the funds transferred to. The criminals covered all the most common wallets: Blockchain.com, Trust Wallet, MetaMask, Coinbase, Binance, Crypto.com, and Exodus. But users of more exotic wallets have not been forgotten: for them, an Other Wallets button has been provided. User-friendly, isn’t it?

Cryptoscam giveaway: phishers go after seed phrases (5)

The victim is invited to choose a cryptowallet for the promised transfer of tokens

Now for the most interesting part: to get the coveted tokens, the user must enter a secret series of words, aka – a seed phrase. As soon as they fill in the fields and click the Next button, a notification appears on the screen that everything was successful and the cryptocurrency will be in the lucky winner’s account within 24 hours.

Interestingly, the website has no checks: even if random words or even numerals (which cannot be part of a seed phrase at all) are entered instead, the site still reports a successful transfer. Of course, if the real seed phrase is typed in, far from receiving winnings, the victim will likely be relieved of all their savings.

Cryptoscam giveaway: phishers go after seed phrases (6)

Any sequence of words and numbers will produce a “successful” transfer

Seed phrase, or the key to all doors

The scammers rely on the fact that people are usually very protective of their private key, which immediately opens access to the cryptowallet; but many do not realize their seed phrase is also top-secret, and think nothing of entering it on a website in anticipation of a reward.

In actual fact, the seed phrase is no less valuable. With it, an attacker can generate a new private key and thus gain access to the victim’s wallet. In other words, the seed phrase effectively affords the same opportunities to pillage your savings as the private key. This means you should protect the former from prying eyes and ears as carefully as the latter.

How to protect your cryptofinances

To wrap up, a few tips to avoid falling victim to cryptoscams:

  • Keep your seed phrase secret. Never reveal it to anyone, and enter it only to recover access to your wallet. Do not store the seed phrase in public file-sharing services, or send it via instant messaging apps or by e-mail.
  • Do not click on links in e-mails about giveaways, gift payouts, account suspensions or bank account closures. Such e-mails are most likely from cybercriminals. Read our checklist to learn how to spot online scammers.
  • Use a reliable security solution that warns you in good time about phishing pages and prevents you from handing over sensitive information to the bad guys.
  • Read next

Bank phishing and identity theft

We explain how phishers are swindling Wells Fargo customers out of personal credentials, passwords, card details, and selfies with an ID card.

Tips
  • Tips

Four ways to lock your screen on Windows and macOS

Four handy ways to lock your screen on Windows and macOS.

  • Tips

What to do if someone tries to hack you

You’ve interacted with scammers or visited a phishing site. What steps should you take to avoid being hacked?

  • Tips

What to patch first: prioritizing updates

Some thoughts on what PC software patches should be prioritized and why.

  • Tips

Know your personal threat landscape

You can apply the concept of a threat landscape as used in corporate security to yourself to make it easier to stay protected.

Sign up to receive our headlines in your inbox

I'm an expert in cybersecurity and cryptocurrency, with a deep understanding of the tactics used by scammers to exploit vulnerabilities and deceive users. My expertise comes from years of research and practical experience in the field.

Now, let's delve into the concepts mentioned in the article about crypto wallet scams:

  1. Phishing Scams: The article discusses a phishing scam that begins with an email offering a cryptocurrency giveaway. Phishing is a fraudulent attempt to obtain sensitive information, such as usernames, passwords, and seed phrases, by disguising as a trustworthy entity.

  2. Crypto Wallet Seed Phrase: The seed phrase is highlighted as a crucial element that users need to guard with their lives. The seed phrase is a series of words that serves as a backup and recovery mechanism for a cryptocurrency wallet. It's emphasized that entering the seed phrase on suspicious websites can lead to the loss of funds.

  3. Fake Giveaway Offers: Scammers often use enticing offers, such as fake cryptocurrency giveaways, to lure victims. In this case, the scammers claim to be from a Crypto Community, but the email's domain raises suspicion, and the content contains errors and typos.

  4. Phishing Websites: Clicking on the provided link takes users to a phishing website that mimics the appearance of a legitimate platform. The article points out that the website doesn't have proper checks, allowing even random words to be entered as a seed phrase, indicating the lack of security measures.

  5. Wallet Compatibility: The phishing site targets a variety of popular cryptocurrency wallets, including Blockchain.com, Trust Wallet, MetaMask, Coinbase, Binance, Crypto.com, and Exodus. This broad approach aims to capture users of different wallets.

  6. Seed Phrase Security: The article underscores the importance of keeping the seed phrase secret. It explains that the seed phrase, like a private key, can be exploited by attackers to gain access to the victim's wallet. Users are advised to only enter the seed phrase for wallet recovery purposes.

  7. Tips to Avoid Cryptoscams: The article concludes with practical tips to avoid falling victim to cryptocurrency scams. These include keeping the seed phrase secret, not clicking on suspicious email links, and using reliable security solutions to detect and prevent phishing attempts.

In summary, the article provides valuable insights into the tactics employed by scammers in crypto wallet phishing scams and offers practical advice to users on how to protect themselves from such threats.

Cryptoscam giveaway: phishers go after seed phrases (2024)

FAQs

What if someone steals my seed phrase? ›

If your seed phrase is lost or stolen, the best thing to do is purchase a replacement hardware wallet in order to generate a new key to perform a key replacement on the Unchained platform. It's generally best to purchase hardware directly from the manufacturer.

Is it possible for someone to guess my seed phrase? ›

The large amount of theoretical wallets make it practically impossible for anyone to guess your seed phrase, not to mention “re-creating” your wallet by sheer accident.

How do crypto seed phrases work? ›

A seed phrase, also known as a Secret Recovery Phrase (SRP) or mnemonic, is simply a collection of words that allows you to restore your entire crypto wallet. It's those 12-24 English words that your wallet presented you with while setting it up.

Are seed phrases safe? ›

If your seed phrase is lost or stolen, you risk losing access to your digital wealth permanently, as it cannot be recovered by anyone else. That is why it is important to safeguard key phrases at tangible locations. Trying to memorize them is not enough for most people.

Can someone hack my seed phrase? ›

It is generated during the initial setup of a wallet, and users are instructed to store it securely, offline, and away from unauthorized access. Your crypto wallet security relies heavily on the protection of the seed phrase. Anyone with access to your seed phrase can gain control over your funds.

What if my seed phrase is compromised? ›

Move Your Funds: As an immediate measure, transfer your assets to a new wallet with a secure seed phrase. It's essential to do this as quickly as possible to prevent unauthorized transactions. 2. Set up a New Wallet: Create a new crypto wallet with a new, secure seed phrase.

Is your seed phrase your private key? ›

Seed phrases are typically 12 randomly selected words that give you access to your crypto wallet and all of the private keys within it from a single interface. If you have your seed phrase, you do not need your private key(s). They are algorithmically linked together.

How hard is it to crack a seed phrase? ›

You can break a 12-word seed phrase with 2^128 operations. However, you can break a 24-word seed phrase with the same number of attempts. So, there's no need to add more than 12 words to a mnemonic phrase.

What are the odds of guessing a 12 word seed phrase? ›

It appears that the 12 word seed phrase CAN be the same word repeated 12 times. The logic is that there are 2048 choices at the first round and then it must pick the one chosen in the first round from then on out which has a probability of 1/2048 for the 11 remaining rounds.

How do I recover crypto with seed phrase? ›

To recover a wallet with a seed phrase, follow the steps below:
  1. Download the appropriate wallet app. ...
  2. Select “Recover wallet” or “Import wallet.” The exact wording will vary depending on the app.
  3. Enter the seed phrase. ...
  4. Create a new password. ...
  5. Confirm the password.
  6. The wallet will be restored.
Dec 18, 2023

What is the secret seed phrase? ›

A secret recovery phrase is a set of words that correspond to numbers. These numbers make up a seed integer that generates all of the private keys in your wallet. Each address for every crypto has its own private key. Private keys are used to authorize transactions and prove ownership of your funds.

What is the secret seed in Coinbase? ›

A recovery phrase (sometimes known as a seed phrase) is a series of words generated by your cryptocurrency wallet that gives you access to the crypto associated with that wallet. Think of a wallet as being similar to a password manager for crypto, and the recovery phrase as being like the master password.

What happens if someone finds your seed phrase? ›

A seed phrase, also known as a recovery phrase or backup phrase, is a string of words that serves as a backup for your cryptocurrency wallet. If someone else gets access to your seed phrase, they can use it to restore your wallet and access your funds.

Where is the safest place to keep seed phrases? ›

5 top ways to securely store your recovery phrase
  • Store it offline. If you keep your recovery phrase on any device that connects to the internet, there is a high chance that hackers can gain access to it. ...
  • Splitting your seed phrase. ...
  • Using a hard drive. ...
  • Solid steel backup. ...
  • Stonebook notebook.
Jun 7, 2024

What happens if I lost my seed phrase? ›

If you lose your seed phrase, you can still use your blockchain wallet to recover your crypto. In this situation, you should transfer all your funds out of that blockchain wallet immediately. Send them either to a crypto exchange where you have an account or another wallet that you use.

Can someone steal my crypto with my wallet address? ›

Q: Can someone steal my cryptocurrency if they have my wallet address? A: While it's unlikely someone can steal cryptocurrency with your wallet address alone, crypto wallets can be hacked through other means, such as phishing, malware, or social engineering tactics.

Can seed phrases duplicate? ›

Seed phrase storage must be done in the safest and most private way because anyone with access to the seed phrases can duplicate and import the wallet to their own wallets. This explains why owners whose seed phrases are stolen end up losing their assets. Private keys can be accessed by scammers using seed phrases.

Top Articles
Posting Harmful Information on the Internet
iFOREX Trading Software and Trading Platform
Obituary Times Herald Record
Contact Us - Customer Support | Hertz Car Rental
How To Use Scarabs Poe
Pinellas Fire Active Calls
Hockey Monkey Denver
Tamilblasrer
Godzilla Figures Ebay
Mychart University Of Iowa Hospital
Www Solomon's Words For The Wise
Honey Huxxlee Leaks
Clinton County Correctional Facility Housing Report
What is the distinction between debt and equity financing?
Pteranodon Cheat Codes
What is international trade and explain its types?
Quooker Nordic Zeepdispenser Zwart ZPNBLK | bol
Craigslist Stackable Washer Dryer
Fnv Turbo
Hewn New Bedford
Guilford County Mugshots Zone
Qr 0738
BBC SPORT | Football | Premiership
Ltlv Las Vegas
Anderson Preparatory Academy Skyward
Watch ESPN - Stream Live Sports & ESPN Originals
2068032104
Union Corners Obgyn
Deshuesadero El Pulpo
McCarran International Airport Guide
America First Credit Union Review 2024 | Bankrate
Peekaboo Soft Medium Precious skin Brown | Fendi
Sdsu Fall 2022 Final Exam Schedule
Craiglist Mcallen Texas
Condo Uploader
Palm Coast Permits Online
Petsmart Donations Request
Encore Atlanta Cheer Competition
Ice Dodo Unblocked 76
Sinfuldeeds Married Latina
Best Half Court Trap Defense
Skipthe Games.com
Purplefoxy840127
Twin Cities Live Recipe Replay Today
MLN9658742 – Medicare Provider Enrollment
Branson Shooting Range
Www Getelate.com
Atliens Hip Hop Duo Crossword
Umcu Cd Rates
Syracuseskipthegames
Jazmen Jafar Linkedin
Latest Posts
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5290

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.