市值: $2.2043T 0.58%
體積(24小時): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 體積(24小時): $56.8553B 3.76%
  • 恐懼與貪婪指數:
  • 市值: $2.2043T 0.58%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

BlockFi 騙子利用復原過程獲利

2024/04/09 23:14

As I noted last month, the crypto lending firm BlockFi has started to send back to its customers some of their funds which had been frozen for over a year, since the demise of Sam Bankman-Fried’s FTX exchange led to BlockFi likewise vanishing into the mists of Chapter 11.  As BlockFi emerges from bankruptcy, they are reimbursing customers in two tiers. Those who had crypto sitting in their “wallet” on the platform (not lent out and not earning interest), got back 100%. In my case, nearly all my assets on BlockFi were on the lending platform, earning juicy interest. For that class of assets, only a partial recovery is expected. Also, BlockFi will only send to you the crypto (e.g. Bitcoin or USDC) you owned as the crypto coin itself, not as the liquidated dollar value.

正如我上個月指出的那樣,自從 Sam Bankman-Fried 的 FTX 交易所倒閉導致 BlockFi 同樣消失在迷霧中以來,加密貨幣借貸公司 BlockFi 已開始向客戶退還部分被凍結一年多的資金第11 章。隨著BlockFi 走出破產,他們正在分兩級向客戶提供補償。那些在平台上的「錢包」裡有加密貨幣的人(沒有借出也沒有賺取利息),100% 拿回了。就我而言,我在 BlockFi 上的幾乎所有資產都在藉貸平台上,賺取了豐厚的利息。對於此類資產,預計只會部分復甦。此外,BlockFi 只會將您擁有的加密貨幣(例如比特幣或 USDC)作為加密貨幣本身發送給您,而不是作為清算的美元價值。

Therefore, you must establish an outside crypto wallet, and give them the external wallet address, so they can transfer the coin over a blockchain. This prospect of a connection between BlockFi (or its bankruptcy agent, Kroll) and your crypto wallet has brought out the scammers in force: if they can trick you into connecting them to your wallet, they can suck it dry in a flash.

因此,您必須建立一個外部加密錢包,並向他們提供外部錢包位址,以便他們可以透過區塊鏈轉移硬幣。 BlockFi(或其破產代理Kroll)與您的加密錢包之間的這種連接前景已經引來了詐騙者的攻擊:如果他們能夠欺騙您將它們連接到您的錢包,他們就可以立即將其吸乾。

The first thing I noticed back in early March was the proliferation of web sites that looked legit, but weren’t. When I browsed for “BlockFi withdrawal” or “BlockFi recovery,” up came a number of sites that had “BlockFi” or “Kroll” somewhere in their names, as clickbait. I don’t see any of these sites now, a month later. I assume that either those sites have been taken down as the thieves move onto the next heist, or the search engines have blotted them out.

早在三月初,我注意到的第一件事就是看似合法但實際上並不合法的網站激增。當我瀏覽“BlockFi撤回”或“BlockFi恢復”時,出現了許多名稱中包含“BlockFi”或“Kroll”的網站,作為點擊誘餌。一個月後,我現在再也看不到這些網站了。我認為,要么這些網站已被盜賊轉移到下一次搶劫,要么搜尋引擎已將其刪除。

Bogus phishing emails have also been sent out. Most insidious was an expertly-crafted email that I and other BlockFi customers received. Here is a screen shot of the now-infamous message:

虛假的網路釣魚電子郵件也已發出。最陰險的是我和其他 BlockFi 客戶收到的一封精心製作的電子郵件。這是現在臭名昭著的消息的屏幕截圖:

As folks have pointed out, this looks pretty good. It has got the official company logo, and no misspellings. The return address on the email was BlockFi Holdings at www.everbridge.com. Unless you were vigilant, this address did not immediately raise suspicions like a random Gmail address or .ru address might.

正如人們所指出的,這看起來相當不錯。它有官方公司徽標,並且沒有拼寫錯誤。電子郵件中的回信地址是 BlockFi Holdings,網址為 www.everbridge.com。除非您保持警惕,否則該地址不會像隨機的 Gmail 地址或 .ru 地址那樣立即引起懷疑。

Plus, this email was targeted to BlockFi customers, and came right when we were expecting further emails to tell us what steps to take to recovery our funds. How did the thieves have our email addresses? One speculation centers around the “Mother of All Breaches” (MOAB) when the Mailer Lite database was hacked in January. But we know that Kroll’s database was breached last year, where the lost data includes BlockFi customers’ names, email addresses, and amounts held at BlockFi, so that seems a more direct source.

另外,這封電子郵件是針對 BlockFi 客戶的,當我們期待更多電子郵件告訴我們應採取哪些步驟來收回資金時,它就來了。竊賊是如何獲得我們的電子郵件地址的?一種猜測圍繞著「所有漏洞之母」(MOAB),當時 Mailer Lite 資料庫在一月份遭到駭客攻擊。但我們知道 Kroll 的資料庫去年遭到破壞,遺失的資料包括 BlockFi 客戶的姓名、電子郵件地址以及在 BlockFi 中持有的金額,因此這似乎是更直接的來源。

Anyway, lots of BlockFi customers clicked on the link in this email. The thieves were pretty clever. First, they had you scrawl your signature on the screen. So now they have that archived, in order to do further ID theft mischief. And then, they had you connect their app to your wallet, as a trusted dApp. Over on Reddit (here and here), you can read the howls of pain from folks who got their wallets cleaned out. They are not alone – -as of late March, this scam had netted something like $5 million in digital assets.

不管怎樣,很多 BlockFi 客戶點擊了這封電子郵件中的連結。盜賊們還是很聰明的。首先,他們讓你在螢幕上寫下你的簽名。所以現在他們已經將其存檔,以便進一步進行身份盜竊惡作劇。然後,他們讓你將他們的應用程式連接到你的錢包,作為可信的 dApp。在 Reddit 上(這裡和這裡),你可以讀到錢包被掏空的人們的痛苦嚎叫。他們並不孤單——截至 3 月底,這個騙局已經賺得了大約 500 萬美元的數位資產。

An eerie thing about crypto is that the holdings at any address on the blockchain are public knowledge, even though you don’t know who the owner of that address is. So crypto sleuth Plumferno was able to display at least one of the BlockFi scammer’s wallets in the process of accumulating stolen assets:

關於加密貨幣的一個令人毛骨悚然的事情是,即使你不知道該地址的所有者是誰,但區塊鏈上任何地址的持有量都是公共知識。因此,加密貨幣偵探 Plumferno 在累積被盜資產的過程中能夠顯示至少一個 BlockFi 詐騙者的錢包:

This wallet (0x6C0e83422cD73fFD3A5EC4506638F6A0A8e22b38) currently holds well over $1million in Eth + various tokens combined, and as you can see, this scam is still very active – new victims are showing up in the transaction list quite regularly. Current holdings on Debank:

這個錢包(0x6C0e83422cD73fFD3A5EC4506638F6A0A8e22b38)目前持有超過 100 萬美元的 Eth + 各種代幣,正如你所看到的,這個騙局仍然非常活躍——新的受害者經常出現在交易列表中。目前持有的 Debank 股份:

I am embarrassed to admit that I got taken in by this email. I tried clicking on the links, but fortunately my wallet was empty and my anti-malware resisted having me connect to the phishing site, so I did not lose any coin.  Some takeaways are:

我很尷尬地承認我被這封電子郵件欺騙了。我嘗試點擊這些鏈接,但幸運的是我的錢包是空的,而且我的反惡意軟體拒絕讓我連接到網絡釣魚網站,所以我沒有丟失任何硬幣。一些要點是:

( 1 ) Always be suspicious of emails; especially scrutinize the return address, to make sure it really is from a source you trust. Watch for almost-legit email addresses.

(1)對電子郵件始終保持懷疑態度;尤其要仔細檢查退貨地址,以確保它確實來自您信任的來源。留意幾乎合法的電子郵件地址。

( 2 ) If at all possible, avoid clicking on links in emails; try to go to the actual company website and click links from there.

(2) 如果可能的話,避免點擊電子郵件中的連結;嘗試訪問實際的公司網站並點擊那裡的連結。

( 3 ) See ( 1 )

(3)參見(1)

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月12日 其他文章發表於