CryptoMediaClub
Friday, August 1, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home Blockchain

Security platforms warn about hidden phishing and wallet drainer links

08.09.2023
A A
0
129
VIEWS
ShareShare

With millions of dollars worth of assets being lost to phishing attacks after signing malicious permissions, the threat of losing crypto assets to questionable links is very real. When these are paired with platforms that allow hidden links, users are subjected to a different kind of risk.

On Sept. 4, Web3 security provider Pocket Universe shared how scammers are able to hide wallet drainer links in any text on the instant messaging platform Discord. While some users report that the feature has only been enabled for Discord users recently, the ability to embed links in any text has been available on many different social platforms for a while now.

Scammers can now hide links in any discord text ☠️
Watch out for hidden wallet drainer links
e.g. pic.twitter.com/mgqG18sOF9

— Pocket Universe (@PocketUniverseZ) September 4, 2023

Cointelegraph reached out to several cybersecurity professionals to learn more about how users can protect themselves from such attempts and how platforms can improve their security so that users are not subjected to such attacks.

Christian Seifert, who works as a researcher in residence at Web3 security firm Forta Network, said that this type of attack has been the bread and butter of hackers since the internet was created. He explained:

“Whatever a platform creates, there will be a hacker ready to find a way to hack it. Hyperlinks with text are a feature supported as part of HTML and have been a source for phishing attacks since the early days of the internet.”

According to Seifert, security requires an in-depth defense approach. “Both platforms and users need to work towards protecting themselves,” he said. From the user’s side, the security professional highlighted that there are plugins that they can use to protect themselves from such scams.

When it comes to Discord, Seifert pointed out that the platform does provide information on the true destination of the URL after the user clicks on it. However, the platform also allows users to “trust” a domain going forward. This can be abused by scammers, according to Seifert. He explained:

“Imagine a domain like foo.bar, which the user trusted. A scammer can craft a potentially malicious link that performs some action on this domain, such as an ‘oauth’ request to the scammer, like foo.bar/oauth/scammer-account.”

The cybersecurity professional said that an issue with the platform’s current implementation is that links and text can be deceptive and misaligned with users’ expectations. “If a text link clearly resembles a domain or URL and it is mismatched to the true destination URL, Discord should disallow such links,” he added.

Related: Exploits, hacks and scams stole almost $1B in 2023: Report

Meanwhile, Hugh Brooks, director of security operations at the blockchain security firm CertiK, echoed some of Seifert’s sentiments. According to Brooks, users and platforms have a collective responsibility to watch out for malicious actors. He explained that it’s essential for platforms to continually review and refine their security features and for users to stay vigilant and educated.

For users, Brooks said that they should be proactive and cautious when it comes to links, especially when being asked for signatures and permissions. The executive urged users to verify the authenticity of the site address before giving it access to crypto wallets. Brooks shared:

“A good practice is to cross-check web addresses with recognized phishing warning lists. PhishTank, Google Safe Browsing and OpenPhish are valuable resources here, along with browser extensions like HTTPS Everywhere and ad blockers like uBlock.”

Brooks explained that these tools can alert users in real time whenever they are about to visit known phishing or malicious websites. “Furthermore, by simply hovering over a URL link, the actual web address will be displayed, allowing users to confirm its legitimacy before engaging further,” he added.

On the platform’s side, the cybersecurity professional said that there are measures that can be implemented, such as being able to only receive messages from trusted contacts. Brooks said that a good example of this is Meta’s “Facebook Protect,” which lets users have heightened security features for their accounts.

“As the saying goes, the only constant is change. Platforms owe it to their users and to their continued relevance to make security a priority. This involves not only updating security measures but also fostering a culture of vigilance and awareness among users,” he added.

Magazine: Should crypto projects ever negotiate with hackers? Probably

Share10Tweet6ShareSharePin2

Related Posts

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei
Blockchain

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei

18.07.2025
0

Skip to content

Read moreDetails
Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

17.07.2025
LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

14.07.2025
Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

14.07.2025
Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

08.07.2025
Load More
Next Post
Cardano’s Future Uncertain as Cardax Exchange Bites the Dust

Cardano’s Future Uncertain as Cardax Exchange Bites the Dust

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Nebraska Governor Says State “Open for Companies” in Crypto Area, Enacts Crypto ATM Invoice

Nebraska Governor Says State “Open for Companies” in Crypto Area, Enacts Crypto ATM Invoice

5 months ago
Bitcoin Revolution: Coinbase CEO’s Daring Imaginative and prescient for US Strategic Reserve

Bitcoin Revolution: Coinbase CEO’s Daring Imaginative and prescient for US Strategic Reserve

5 months ago
PEPE Whales Accumulate Amid Market Volatility: Is a 200x Rally Coming?

PEPE Whales Accumulate Amid Market Volatility: Is a 200x Rally Coming?

4 weeks ago
Bitcoin price sets up for an explosive move as ADA, XLM, AAVE and CFX turn bullish

Bitcoin price sets up for an explosive move as ADA, XLM, AAVE and CFX turn bullish

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

BNB Holders Can Now Earn Daily Passive Income Through the Officially Launched BNB Payment Integration by Find Mining

BlackRock’s BUIDL fund hit by $447M outflow after 18-month record breaking $2.8B inflow

23% of CFOs in North America Ready to Implement Crypto

Coinbase Accuses FDIC of Hiding Operation Chokepoint 2.0 Files 

Altcoins lead crash as $751M liquidated in last 24 hours and Bitcoin falls to July low

Trump Tariffs Return — What Does It Mean for Bitcoin, Ether, XRP, Crypto?

Trending

Visa Expands Crypto Capabilities of Its DLT Platform
All news

Visa Expands Crypto Capabilities of Its DLT Platform

01.08.2025
0

Visa integrated three new stablecoins into its payment DLT platform and increased the number of supported blockchains...

WEPE Pullback Finds Strong Support Before New Test of Resistance at $0.0001249

WEPE Pullback Finds Strong Support Before New Test of Resistance at $0.0001249

01.08.2025
Tourists in South Korea to Exchange USDT via Crypto ATMs

Tourists in South Korea to Exchange USDT via Crypto ATMs

01.08.2025
BNB Holders Can Now Earn Daily Passive Income Through the Officially Launched BNB Payment Integration by Find Mining

BNB Holders Can Now Earn Daily Passive Income Through the Officially Launched BNB Payment Integration by Find Mining

01.08.2025
BlackRock’s BUIDL fund hit by $447M outflow after 18-month record breaking $2.8B inflow

BlackRock’s BUIDL fund hit by $447M outflow after 18-month record breaking $2.8B inflow

01.08.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz