Interesting new Crypto Scam targeting smart contract wallets on Binance Smart Chain

Brickbat1

Elite Member
Joined
Mar 22, 2010
Messages
2,366
Reaction score
1,391
So I decided to do an audit of one of my wallet addresses via bscscan and discovered several inflows of different tokens to my wallet that I was unaware of. I fished out the contract addresses of one of the tokens and searched them out via poocoin and discovered it had liquidity of over 100 BNB ,but all the liquidity is held 100% by one address. I decided to test it out, so I added the token to my Metamask and the tokens appeared in my wallet. I then tried to see if I could swap a little , just to see if it would work. What I discovered is that what these guys really want is for people to do exactly just that..test it out. Since they hold all the liquidity, all liquidity holder transaction fees (except PCS fees), tiny as they are, go to them. Checking the transaction attempts to swap on bscscan, I could see that in a matter of 1 week, there were almost 23k such attempts, amounting to almost 3BNB for the liquidity holder. They sent the same amount of tokens (92k tokens, worth $70k as per the token price on poocoin) to over 2 million addresses. i wonder how they did that for free..Somehow, it still doesnt make sense - batch sending thousands of tokens to millions of addresses could'nt have been cheap.

What do you think is really the end game here? Might not just be the transaction fees. Or are they trying to find out which addresses are active with funds? if so what could they possibly do to those addresses? is it possible to brute-force hack a Metamask crypto wallet without knowing the secret key or recovery phrase? What do you think is the end game here?

You can check the contract out on bscscan here : https://bscscan.com/token/0xd35f9ab96d04adb02fd549ef6a576ce4e2c1d935
 
Brute force is a possibility. But they will not be profitable unless they hack elon musk wallet.
 
Brute force is a possibility. But they will not be profitable unless they hack elon musk wallet.
Are you serious? Possible to brute fore a crypto wallet? I thought that was impossible..
 
Looks like they are using batch transfer and sending to 560 for $3.10 - $3.20 at a time.
To send 2 million costs over $10,000.
 
Are you serious? Possible to brute fore a crypto wallet? I thought that was impossible..
The data you gave suggests that they are doing to try this only. It is not that they will succed doing this.
 
Looks like they are using batch transfer and sending to 560 for $3.10 - $3.20 at a time.
To send 2 million costs over $10,000.
So what do you think is their game plan. I mean if you spend $10k to get people to notice you, how do you intend to get that money back? Phishing? hacking? I did attempt a transaction and I am thinking I probably should abandon that wallet..Cant imagine that a cryptowallet can be hacked without the secret key or seed phrase. If that's possible then why do we feel safe with funds in our wallets?
 
So I decided to do an audit of one of my wallet addresses via bscscan and discovered several inflows of different tokens to my wallet that I was unaware of. I fished out the contract addresses of one of the tokens and searched them out via poocoin and discovered it had liquidity of over 100 BNB ,but all the liquidity is held 100% by one address. I decided to test it out, so I added the token to my Metamask and the tokens appeared in my wallet. I then tried to see if I could swap a little , just to see if it would work. What I discovered is that what these guys really want is for people to do exactly just that..test it out. Since they hold all the liquidity, all liquidity holder transaction fees (except PCS fees), tiny as they are, go to them. Checking the transaction attempts to swap on bscscan, I could see that in a matter of 1 week, there were almost 23k such attempts, amounting to almost 3BNB for the liquidity holder. They sent the same amount of tokens (92k tokens, worth $70k as per the token price on poocoin) to over 2 million addresses. i wonder how they did that for free..Somehow, it still doesnt make sense - batch sending thousands of tokens to millions of addresses could'nt have been cheap.

What do you think is really the end game here? Might not just be the transaction fees. Or are they trying to find out which addresses are active with funds? if so what could they possibly do to those addresses? is it possible to brute-force hack a Metamask crypto wallet without knowing the secret key or recovery phrase? What do you think is the end game here?

You can check the contract out on bscscan here : https://bscscan.com/token/0xd35f9ab96d04adb02fd549ef6a576ce4e2c1d935
Where did you try to swap?
On PCS or you connected your wallet to some other website?
 
So what do you think is their game plan. I mean if you spend $10k to get people to notice you, how do you intend to get that money back? Phishing? hacking? I did attempt a transaction and I am thinking I probably should abandon that wallet..Cant imagine that a cryptowallet can be hacked without the secret key or seed phrase. If that's possible then why do we feel safe with funds in our wallets?

Your assumption is invalid

NO crypto is "safe" in an online wallet

You would have to prove the wallet is not back doored, among other things

Can you buy insurance for a wallet?

Sincerely,

The Eye
 
Back
Top