市值: $2.1693T -2.59%
成交额(24h): $67.3751B 30.24%
  • 市值: $2.1693T -2.59%
  • 成交额(24h): $67.3751B 30.24%
  • 恐惧与贪婪指数:
  • 市值: $2.1693T -2.59%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

BlockFi 骗子利用恢复过程获利

2024/04/09 23:14

As I noted last month, the crypto lending firm BlockFi has started to send back to its customers some of their funds which had been frozen for over a year, since the demise of Sam Bankman-Fried’s FTX exchange led to BlockFi likewise vanishing into the mists of Chapter 11.  As BlockFi emerges from bankruptcy, they are reimbursing customers in two tiers. Those who had crypto sitting in their “wallet” on the platform (not lent out and not earning interest), got back 100%. In my case, nearly all my assets on BlockFi were on the lending platform, earning juicy interest. For that class of assets, only a partial recovery is expected. Also, BlockFi will only send to you the crypto (e.g. Bitcoin or USDC) you owned as the crypto coin itself, not as the liquidated dollar value.

正如我上个月指出的那样,自从 Sam Bankman-Fried 的 FTX 交易所倒闭导致 BlockFi 同样消失在迷雾中以来,加密货币借贷公司 BlockFi 已开始向客户退还部分被冻结一年多的资金第 11 章。随着 BlockFi 走出破产,他们正在分两级向客户提供补偿。那些在平台上的“钱包”里有加密货币的人(没有借出也没有赚取利息),100% 拿回了。就我而言,我在 BlockFi 上的几乎所有资产都在借贷平台上,赚取了丰厚的利息。对于此类资产,预计只会部分复苏。此外,BlockFi 只会将您拥有的加密货币(例如比特币或 USDC)作为加密货币本身发送给您,而不是作为清算的美元价值。

Therefore, you must establish an outside crypto wallet, and give them the external wallet address, so they can transfer the coin over a blockchain. This prospect of a connection between BlockFi (or its bankruptcy agent, Kroll) and your crypto wallet has brought out the scammers in force: if they can trick you into connecting them to your wallet, they can suck it dry in a flash.

因此,您必须建立一个外部加密钱包,并向他们提供外部钱包地址,以便他们可以通过区块链转移硬币。 BlockFi(或其破产代理 Kroll)与您的加密钱包之间的这种连接前景已经引来了诈骗者的攻击:如果他们能够欺骗您将它们连接到您的钱包,他们就可以立即将其吸干。

The first thing I noticed back in early March was the proliferation of web sites that looked legit, but weren’t. When I browsed for “BlockFi withdrawal” or “BlockFi recovery,” up came a number of sites that had “BlockFi” or “Kroll” somewhere in their names, as clickbait. I don’t see any of these sites now, a month later. I assume that either those sites have been taken down as the thieves move onto the next heist, or the search engines have blotted them out.

早在三月初,我注意到的第一件事就是看似合法但实际上并不合法的网站激增。当我浏览“BlockFi撤回”或“BlockFi恢复”时,出现了许多名称中包含“BlockFi”或“Kroll”的网站,作为点击诱饵。一个月后,我现在再也看不到这些网站了。我认为,要么这些网站已被盗贼转移到下一次抢劫,要么搜索引擎已将其删除。

Bogus phishing emails have also been sent out. Most insidious was an expertly-crafted email that I and other BlockFi customers received. Here is a screen shot of the now-infamous message:

虚假的网络钓鱼电子邮件也已发出。最阴险的是我和其他 BlockFi 客户收到的一封精心制作的电子邮件。这是现在臭名昭著的消息的屏幕截图:

As folks have pointed out, this looks pretty good. It has got the official company logo, and no misspellings. The return address on the email was BlockFi Holdings at www.everbridge.com. Unless you were vigilant, this address did not immediately raise suspicions like a random Gmail address or .ru address might.

正如人们所指出的,这看起来相当不错。它有官方公司徽标,并且没有拼写错误。电子邮件中的回信地址是 BlockFi Holdings,网址为 www.everbridge.com。除非您保持警惕,否则该地址不会像随机的 Gmail 地址或 .ru 地址那样立即引起怀疑。

Plus, this email was targeted to BlockFi customers, and came right when we were expecting further emails to tell us what steps to take to recovery our funds. How did the thieves have our email addresses? One speculation centers around the “Mother of All Breaches” (MOAB) when the Mailer Lite database was hacked in January. But we know that Kroll’s database was breached last year, where the lost data includes BlockFi customers’ names, email addresses, and amounts held at BlockFi, so that seems a more direct source.

另外,这封电子邮件是针对 BlockFi 客户的,当我们期待更多电子邮件告诉我们应采取哪些步骤来收回资金时,它就来了。窃贼是如何获得我们的电子邮件地址的?一种猜测围绕着“所有漏洞之母”(MOAB),当时 Mailer Lite 数据库在一月份遭到黑客攻击。但我们知道 Kroll 的数据库去年遭到破坏,丢失的数据包括 BlockFi 客户的姓名、电子邮件地址以及在 BlockFi 中持有的金额,因此这似乎是更直接的来源。

Anyway, lots of BlockFi customers clicked on the link in this email. The thieves were pretty clever. First, they had you scrawl your signature on the screen. So now they have that archived, in order to do further ID theft mischief. And then, they had you connect their app to your wallet, as a trusted dApp. Over on Reddit (here and here), you can read the howls of pain from folks who got their wallets cleaned out. They are not alone – -as of late March, this scam had netted something like $5 million in digital assets.

不管怎样,很多 BlockFi 客户点击了这封电子邮件中的链接。盗贼们还是很聪明的。首先,他们让你在屏幕上写下你的签名。所以现在他们已经将其存档,以便进一步进行身份盗窃恶作剧。然后,他们让你将他们的应用程序连接到你的钱包,作为可信的 dApp。在 Reddit 上(这里和这里),你可以读到钱包被掏空的人们的痛苦嚎叫。他们并不孤单——截至 3 月底,这个骗局已经赚得了大约 500 万美元的数字资产。

An eerie thing about crypto is that the holdings at any address on the blockchain are public knowledge, even though you don’t know who the owner of that address is. So crypto sleuth Plumferno was able to display at least one of the BlockFi scammer’s wallets in the process of accumulating stolen assets:

关于加密货币的一个令人毛骨悚然的事情是,即使你不知道该地址的所有者是谁,但区块链上任何地址的持有量都是公共知识。因此,加密货币侦探 Plumferno 在积累被盗资产的过程中能够显示至少一个 BlockFi 诈骗者的钱包:

This wallet (0x6C0e83422cD73fFD3A5EC4506638F6A0A8e22b38) currently holds well over $1million in Eth + various tokens combined, and as you can see, this scam is still very active – new victims are showing up in the transaction list quite regularly. Current holdings on Debank:

这个钱包(0x6C0e83422cD73fFD3A5EC4506638F6A0A8e22b38)目前持有超过 100 万美元的 Eth + 各种代币,正如你所看到的,这个骗局仍然非常活跃——新的受害者经常出现在交易列表中。目前持有的 Debank 股份:

I am embarrassed to admit that I got taken in by this email. I tried clicking on the links, but fortunately my wallet was empty and my anti-malware resisted having me connect to the phishing site, so I did not lose any coin.  Some takeaways are:

我很尴尬地承认我被这封电子邮件欺骗了。我尝试点击这些链接,但幸运的是我的钱包是空的,而且我的反恶意软件拒绝让我连接到网络钓鱼网站,所以我没有丢失任何硬币。一些要点是:

( 1 ) Always be suspicious of emails; especially scrutinize the return address, to make sure it really is from a source you trust. Watch for almost-legit email addresses.

(1)对电子邮件始终保持怀疑态度;尤其要仔细检查退货地址,以确保它确实来自您信任的来源。留意几乎合法的电子邮件地址。

( 2 ) If at all possible, avoid clicking on links in emails; try to go to the actual company website and click links from there.

(2) 如果可能的话,避免点击电子邮件中的链接;尝试访问实际的公司网站并单击那里的链接。

( 3 ) See ( 1 )

(3)参见(1)

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月28日 发表的其他文章