A report summarizing 'How is clever social engineering done?' From the victim's perspective is released
Social engineering is a method of stealing important data, property, access rights, etc. using human psychology and mistakes. A person who said, ' Aave , a cryptocurrency token, was about to be stolen by clever social engineering,' summarizes the social engineering techniques he received from the victim's point of view.
For the past two weeks, I've been targeted in an extremely thorough social engineering scam that nearly cost me all of my ETH. I'm super lucky to have made it through unscathed. Here's the story ????
— Thomasg.eth (@thomasg_eth) February 13, 2022
This time, it was Thomas (@thomasg_eth) , who runs Arrow , an open source vertical take-off and landing aircraft (VTOL aircraft) development project, who was about to take away the cryptocurrency tokens he had. 'We're still in the early stages, we're accepting help from a lot of people, and we're not refusing to help,' Thomas explains.
1 / First a quick background. I'm the founder of Arrow, a DAO working to build open-source VTOL aircraft and air taxi protocol. We're still fairly early-stage and focused on growing the team. We're open to contribution and don't turn anyone away if they're excited to help.
— Thomasg.eth (@thomasg_eth) February 13, 2022
One day, a user named 'heckshine' joined Arrow's Discord channel. Introducing himself, heckshine said he works for game development company Ubisoft , working on 3D design and animation. Heckshine also said he was passionate about VTOL, his brother-in-law was Boeing's vice president, and he had friends working on the Metaverse project.
3 / Heckshine also has a friend that is really passionate about VTOLs, and is working on a metaverse project. Her brother in law is a VP at Boeing. Wow, what a connection! Pic.twitter.com/Hvf1l5lZyB
— Thomasg.eth (@thomasg_eth) February 13, 2022
Although heckshine's English had some strange parts, Mr. Thomas said he didn't care much because there was a language barrier. In the next few days, heckshine set about creating the animations for use on Arrow's website, submitting good data, and even starting to render the aircraft. At this point, Thomas and other Arrow members were impressed with heckshine's dedication.
Meanwhile, heckshine introduced his friend 'Linh' to Mr. Thomas and asked if he could send me an email because Linh is interested in Arrow. When Thomas, who was told that Linh's participation was beneficial to Arrow, sent an email, Linh replied with a thoughtful email and talked about his own Metaverse project called 'Space Falcon'. .. At this point, Thomas wasn't particularly interested in NFTs , so he didn't ponder Linh's Metaverse project.
In subsequent interactions, Linh shared his connections with Boeing and the electric aircraft startup Wisk , some thoughts on Arrow, and eventually joined Arrow as an advisor. Linh's English also seemed strange, but he didn't realize that this was also due to the language barrier.
8 / Linh and I move the conversation over to Discord. We talk more about our backgrounds and end up deciding that she can best help out as an advisor. She offers to provide guidance and advice around what would work well regarding partnerships for us. 'm excited for her support. pic.twitter.com/a0MF0ZqtKa
— Thomasg.eth (@thomasg_eth) February 13, 2022
After that, Linh talked about Space Falcon as a mechanism called 'staking' that allows users to continuously earn income according to the NFTs they own. When Thomas investigated around here, it turned out that there is certainly a game project called Space Falcon, and it is quite popular with the blockchain Solana . In addition, it seems that Linh's name was also displayed on the team page.
11 / Somewhere in here I actually look up Space Falcon. I had never heard of it, but it seems like a fairly popular gaming project on Solana. I see Linh's name on the team page. Linh and I agree to stay in touch, and I move on to other things.
— Thomasg.eth (@thomasg_eth) February 13, 2022
Since then, heckshine has devotedly cooperated with Arrow's project and submitted some ultra-high quality rendering data. And one day, two weeks after heckshine joined the project, when Thomas and heckshine were talking about aircraft design on Discord, Linh came up with some amazing news. Linh reported that he had successfully secured an appointment with the Wisk team and Mr. Thomas, and pasted a screenshot of the email thread he interacted with with Wisk's Vice President. Though unrealistic when you think about it later, Thomas was delighted for no reason to believe this to be a lie.
15 / As we're wrapping up, Linh reaches back out to me with some crazy exciting news. She's going on a tour of the Wisk facility and has invited me along to meet the team. She includes a screenshot of an email thread with Sebastien , who is actually a VP at Wisk. Pic.twitter.com/EpXM3Ri2mK
— Thomasg.eth (@thomasg_eth) February 13, 2022
At this point, Linh said the Space Falcon staking app was released and asked Thomas to send an NFT to his Ethereum wallet to test the app. Thomas, who is grateful for Linh's help with Arrow, accepts it as a matter of course to help with testing the app. At this time, Thomas decided to store the NFT in a new Ethereum account, considering that Space Falcon is a new project. This was in case of future Space Falcon related issues and misuse. The website page that Linh showed to Thomas stated that he would use a token called 'Armstrong ETH.'
18 / She sends me some instructions on the staking app. The site seems fine and it has prompts for three transactions: The NFT approval, a token approval for Armstrong wrapped ETH, and a stake function. The token approval seems little strange but I don 't hold it so I don't worry pic.twitter.com/byKlGFgP2Y
— Thomasg.eth (@thomasg_eth) February 13, 2022
As a result, Thomas reported that the staking process was completed successfully and was easy to operate. Linh then offered to send another NFT and asked, 'I want you to keep it in your main account to support the growth of Space Falcon.' Although it was troublesome, Mr. Thomas who accepted it informed Linh that 'Before staking with the main account, read through the contract firmly', and for some reason Linh's attitude began to be forcible. As a result, Mr. Thomas noticed something was wrong.
21 / I let Linh know that I'm going to read through the contracts before I stake it on my main account, and she starts getting pushy. This is when I finally realize that something sketchy is going on. Pic.twitter.com/ D3aXCc7puR
— Thomasg.eth (@thomasg_eth) February 13, 2022
When I first checked the transaction history of the address where the NFT was sent from Linh, the Ethereum token approved at the time of staking was not the 'Armstrong ETH' written on the website, but another token, Aave . Turned out. Thomas had a lot of Aaves in his main account. At this point Linh et al. Began deleting all Discord messages. Further scrutiny of the deal by Thomas revealed that it included 'a feature that allows you to transfer any amount of Ethereum tokens from your account.' This means that if you don't store your first NFT in your new account, but in your main account, Linh and colleagues will not only be able to send Aaves to Thomas's main account, but you'll be free to do so. It was also possible to withdraw.
24 / I dig further into the contract that I almost approved to spend my aWETH and find this truly terrifying function. This is where the scammers would have been able to transfer any amount of aWETH out of my account.
— Thomasg.eth (@thomasg_eth) February 13, 2022
I'm at the limit for this thread. Stand by for part 2 pic.twitter.com/Cn9Xl9XCSJ
Subsequent investigations revealed that Linh et al.'S account had as much as 100 ETH (about 33 million yen), and Linh et al. Was a very well-funded group. From this point, Thomas believes Linh and his colleagues hired a 3D design contractor to outsource the work of heckshine. Also, although a project called Space Falcon actually exists, Linh was a fake of the same name 'Linh' actually related to the project.
28 / So the Linh that I've been interacting with is probably just an imposter of the real Linh working on the real space falcon ...
— Thomasg.eth (@thomasg_eth) February 13, 2022
From this case, Thomas said, 'Authorization of tokens is very dangerous and requires the latest attention.' 'Scammers are becoming very smart and use more sophisticated and thorough techniques than ever before.' He claims that he can learn the lesson of 'always check no matter how reliable you are.' Linh and his colleagues have been involved in the project for two weeks and have earned the trust of Thomas, and the only reason they were able to avoid the damage was because they were concerned about the security of the new app.
'I'm very fortunate to be able to overcome all of this with minimal damage. Everyone, be careful!' Concludes the report.
32 /
— Thomasg.eth (@thomasg_eth) February 13, 2022
I'm super lucky to have made it through all of this with minimal damage. You guys all stay careful out there!
Related Posts:
in Software, Web Service, Security, Posted by log1h_ik