New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Don't get rekt: detecting phishing threats in crypto - tincho | The Red Guild

ETH Belgrade CommunityTue, Oct 7, 2025, 12:00 AM

Don't get rekt: detecting phishing threats in crypto - tincho | The Red Guild

Transcript

Hello. Hello. Hello. Test. Okay.

Right. Hi everyone. Can you hear me? Well,

don't touch. Okay. Don't touch it. Sorry. Um, yeah.

I'm Tinu. I'm a security researcher at the Red Guild. Um, the red guild is essentially a small security organization coming from Latin America. Um, where we do security and education for the public benefit of Ethereum ecosystem. That essentially means that we work with grants from the Ethereum Foundation and we try to pro provide uh educational resources, research and raising awareness in the community uh so that we all stay a little bit safer, right?

Um these days we are working on this intersection between web two and web three. We are kind of uh believers in that security must uh come from many sides and it's not necessarily only about web three stuff like the usual smart contract security stuff but actually there are lots of things that we can learn from web two that we should be implementing in web 3 as well. Some quickly some initiatives that we have in our team including security research backing. Um we contribute to the security alliance. If you have heard about this um nonprofit organization led by some citizen we are contribut contributors to that.

Um we are leading the security frameworks initiative in there. We do community engagement creating events meetups particularly in Latin America. Um and recently we have been working with Ethereum Foundation uh spearheading this initiative called the ETH rangers which is giving grants for the community for individual contributors in the security community that are working in public goods. We also security tooling we also security awareness campaigns in in real life uh events such as the one that is upcoming for dev connect in Argentina. Um and we do educational resources such as blog posts, videos and so on and so forth.

And particularly today I'm going to be talking about by the end of the talk about um gamify learning and how we are building a platform to keep you I don't know aware of fishing threats and scenarios in the ecosystem. But anyway, attacks are real, right? Scams, social engineering, fishing is a real thing these days in crypto. Only last year almost $500 million were involved or almost lost uh in different scams and fishing cases in in our ecosystem. So, it's really one of the most critical threats that we have these days.

I seen 911 the most common case that they handle was actually fishing of over like a thousand tickets that they have and probably you have received an email like this right if you are working in crypto or in it or whatever you have received an email where you have like this weird sender that is pushing you to do something and it's probably hiding links um such as this one that is offering you free money. Um, again, it's hiding a link in a big bottom that you perhaps end up clicking by mistake or you have you have received this one which is kind of a generic body and but has something attached which probably is malware if you download to your computer. Again, look at the email but look at the name. These are totally unrelated and this is these are like the the classic ones, right? But we can get a little bit more sophisticated such as in this one.

Um, this this was a recent campaign, a fishing campaign that we saw in which somebody would invite you to a 15-minute call with somebody from supposedly from Crowd Strike that would take you to a fishing site. In the fishing fishing site, you would actually be downloading a malicious application supposedly to uh install an application to join a Zoom call or whatever. But well, that was actually malware. Um, and this is the email that I received from ETH Belgrade. I was preparing this talk.

um thinking about fishing and fishing scenarios and actually sorry but I didn't know what Moongate was and I received an email from Moonongate and um I didn't see any links and I was supposed to download something or access a page and I really don't know what that was. So actually I moved that to the bin if you actually see it's little up there that's in the bin and so I kind of lost my ticket and today I didn't have a ticket but anyway uh I thought that was actually fishing. Um, fishing also comes in different flavors and probably you have seen ads. If you use Google, you have seen fishing ads uh being paid by attackers. Uh, if you use X or Twitter or any kind of social media, you have also seen this kind of uh airdrops and free money and things that they are offering you.

And that of course is probably coming from bots or that kind of accounts which could be let's say easy for some people to detect not so easy for not so technical people but let's say it's easier to detect but in these cases when we have h compromised accounts like legitimate account accounts that are compromised such as CTO CEOs or investors or really I know influencers in crypto things start becoming a little bit more complicated to understand where they are actually doing something legitimate. or not such as in this case or in this case from rocket pool coin geckos I think vitalix at some point was compromised I don't remember um anyway social media again lots of threats relating to fishing scams and that kind of things we can move on to sites uh let's say you click on a link you move to a fishing site and fishing sites are getting more and more sophisticated particularly with the recent use of AI it's pretty easy to create this kind of sites. In this case, we have a site that is actually opening a popup that looks like a wallet, but that's not a wallet. That's just a fake popup that is prompting you to enter a private seat uic private key whatever and they are trying to mimic the behavior of actual like Ravi or Metam Mask or that kind of extensions. Featuring also comes in SMS.

In this case, we have a case from Binance in which you would be delivered a verification code. Um, some kind of representative would be getting in touch with you. They would try to prompt you to call a number at some point. Anyway, different ways of trying to social engineer you. Yeah.

Right. Um, the Zoom call scam is pretty well known these days. H, sadly, honestly. um somebody would contact you, they will start building rapport with you. They will tell you that they want to interview you or they want to invest in your company or they want to hire you h or they want to work for you and they will set up a call with you and at some point uh near the meeting you won't be able to join that zoom or they won't be able to join and they will actually send you another link to something that looks like Zoom but it's not actually Zoom and if you click on that you would be prompted to download something from a page that really looks like Zoom but it's not Zoom.

and you would actually be downloading an application and they would actually pound you and that's game over for you or your local network of your company networks. Another case which still was recently investigating and they they released this advisory was uh one scam in which you would join actually a zoom call in the zoom call um for perhaps not so technical people uh it could be easier to fall for in which um the attackers would actually prompt to prompt you to accept the remote uh this remote control feature that SUM has. they will actually start taking control of your computer, download malware and so on and so forth. So these are all kind of ways in which um you can be social engineered into doing things such as signing in um transactions. You go you click on a link on a social media uh you go to a site that site has uh some malicious operation you end up um or they end up prompting you with a transaction that you may end up signing that transaction might be a permit signatures.

Uh we have seen cases of millions of dollar loss of people just signing permit signatures. Actually it's one of the most common signatures that people are uh by mistake signing. If you see like the red bar, that's almost like a hund00 million lost just in permit signatures. Follow scam sniffer. Lots of the screenshots and things that I have today come from them.

So big shout out to scammer sniffer. Um they are not a sponsoring the talk, but actually they do good research for the community. So go follow them. Another one is this address poisoning. This is a little bit more complicated and it's just based on the way that block explorers work and show transactions and ways in which attackers can actually pollute transaction histories in block explorers.

Um, in this case uh 130 million lost just by copying the wrong address. In this case, we have uh 68 And if we go to a very simple case, let's say that a friend sends you some ether. That's the transaction that you see at the bottom. Um, they send you 0.25 ether and as soon as that happens, some attacker sends a transaction involving one of the one of those accounts, probably yours, but that uh with the sender that very much looks like this the original sender, right?

They mine that address and the address looks like the one that sent you there. Perhaps you see transaction history. Perhaps you end up copying uh by mistake because it starts with the same characters and you just blind copy it and use it to I don't know return some ether or send some ether later and well you end up sending ether to the wrong account. That not only happens with ether but actually with tokens too. In this case things can get a little bit messier because block explorer have a hard time showing tokens transfers and the way in which they show them it's uh okay.

So uh you may have people actually when when you send let's say one USDC as a test transaction then you can have an attacker sending you back some real USDC just to appear on your transaction history then they can actually send you some whatever fake token or they can actually I don't know what this happen why this happens in block explorers but they can actually send you something that looks like the one at the top it says USDC that's not USDC if you go to the address that's not USDC but in the metadata of the token they just wrote USDC and block explorer just show it because I don't know why um so there are different ways in which attackers can actually pull your transaction history you can end up copying one of those and losing millions again this is not just me telling you this is things that happen in reality and if you have ever sent tokens in real life and you go to your address on the block explorer you will see lots of fake transactions I mean real transactions but fake information in your transaction history that is very complicated. Um what else can happen? Um these days we are seeing lots of impersonation uh cases uh people impersonating recruiters, people impersonating employees, people impersonating interviewers, angel investors um worrying things. If you do just a quick Google search, you will find many many many cases. So you don't have to believe me.

You can go uh read the latest ones. And these are like super waring uh for different reasons. Uh but you if you work in crypto or in IT, you have been probably contacted by somebody via Telegram, WhatsApp and Discord. uh and mostly LinkedIn uh from supposedly recruiters uh that sometimes do and sometimes do not know that are participating in fishing campaigns and social engineering campaigns and these kind of attacks essentially they will try to I don't know um make you download some code for a coding interview for example hey here's this GitHub repository please can you take a look download it to your machine. If you download that to your machine, that's probably compromised with an MPM package, for example, that's malicious.

You will run that h in your machine. Um, and they can excfiltrate data. They can install whatever they want because mpm uh well, you're actually running arbitrary code in your in your machine. Um, that's happening a lot. Again the usual attack vector comes through linkading but could come from other places.

This is an actual an actual article wrote by unit 42 this security research uh well-known team uh where the attack was essentially being contacted by the an recruiter. You would download a GitHub repository. You would run it like mpm install and after mpm install is game over. You're compromised and they can leak whatever data. they can compromise your whole device.

This is another case by sack XPTt in which um they would prompt you to again download some supposedly some application and they would compromise your account. This is a very interesting one because you wouldn't you wouldn't even need to be contacted by a recruiter in this case. You would be job hunting on the internet. you would go to a job listing site and you are very eager to get a new job in crypto or whatever and when you go to that site you start reading the job post and they tell you some instructions on how to prepare for the interview. When you go to those instructions they are telling you to execute this long command on your machine just to I don't know be more prepared so that the audio or the video looks better on your machine.

You copy that, you execute that on your machine and again it's game over. Uh many many other cases right screenshots follow Tiano if you don't on Twitter. This is great. Um again from very local campaigns to global campaigns this is actually happening these days and we have multiple security research teams alerting of this like global threat which is quite worrying. is not only crypto but particularly in crypto I think we are seeing lots of related attacks again more screenshots of um of the different campaigns that one supposedly by Google on on targeting Brazil uh if you see that you we have a script uh that usually comes in a package JSON you could download that and that node config stuff would actually end up um executing code on your machine the other one that we are seeing right uh on the right of the screen h is common is from a Python um program that you would download.

You would need to code some Python code and that Python code would be of course compromised. And we're seeing also lots of MPM packages um compromised. So sometimes just by name spoofing you would end up downloading some malicious package that could have a rat embedded for example. Um I could I could continue right? So if you go to Twitter you can continue seeing this kind of cases of yeah this is recruiter send me this uh code repository angle that's about recruiters but if you have a company if you have a team you have probably been approached but by somebody that wants to work in your company.

So how do you know whether they are legitimate or not? I honestly don't know. Um, lots of cases of uh prospect employees that are applying to your company that are actually trying to infiltrate your company and steal data and compromise uh devices and steal things from you. Um in this case uh out of 10 candidates just five candidates were just lying. Uh there are global campaigns uh that XPTt has been working on and and has been like uncovering uh fake candidates, fake job postings, um fake resumes, fake uh contributions in GitHub, um even sometimes um fake interviews with deep fakes.

Very very complicated. These are like global campaigns. you probably know where these are coming from. Um, and again, it's a kind of a global threat to many IT companies. This is not just me saying it, but it's been heading the headlines of many of many recent events recently.

If you have an open source project, you can be scammed too. You can be attacked too. Contributors these days um come in very different ways. again with uh AI LMS and that kind of things are getting more sophisticated, more complicated, more difficult to detect. Um I don't have the solutions for many of the things but we have seen again multiple cases of contributors um faking uh pull requests sometimes um contributing seemingly benign code just by changing a few lines but that's actually uh hiding some code that's actually including a back door into your repository.

Uh we have also seen cases in which they are opening security advisories uh in your GitHub issues um and that would contain links that would take you to um fishing sites sometimes or again makes you download things uh or put you in contact with attackers. Uh we are also seeing attacks. If you are familiar with GitHub actions, there are lots of recent and not so recent attack vectors that people can just open a pull request and try to compromise the server in which you're running your custom GitHub actions. If you're not paying enough attention to how they are configured. So that's another uh threat too because if that server is within your organization, they can escalate to other places.

Uh if you're interested, go look up some research about that because it's quite interesting. And there's also a screenshot over there in which we had um scammer actually contributing real ERC's um just to build some reputation in the ecosystem to then be able to escalate and and move laterally to other uh to repositories and and be able to contribute some I don't know malicious code probably. So the question is uh what are we doing about this from the red guild again many scenarios many threats um we believe we as a community need to start paying far more attention to these kind of things um AI is going to make things much more complicated to detect. Um so we are creating the fishing dojo and this is a educational platform that we launched a couple of months ago. Here you have the link if you want to open it up if you want to start playing.

The fish do show is a very nice educational platform in which you will find immersive and very very realistic challenges related to fishing to scams to many of the cases that I show you today about emails about people contacting you about people uh trying to build report with you to scam you and to make you click on links and download things about fishing sites in which you will try to um detect where you are actually signing good uh transactions or bad transactions. Just to show you some screenshots, this is kind of an embedded email client that we have in the fishing dojo in which you will have to be clicking on links and be opening this windows. It's all kind of interactive. So we you will have to see sometimes the headers of the emails and the raw content of of the emails and see where that's actually trying to fishing to fish you or not. And through kind of these interactive challenges, you will be able to learn and be exposed safely to many of these threats and hopefully you will learn a thing or two.

Uh many people from big organizations have already kind of starting using the fishing dojo. It's free, right? So you can go and and just use it uh into they are embedding it into their training programs just because it's quite useful to to have uh people actually go through real scenarios. In this case, we also have um fishing sites that will prompt you to open that's not MetaMask. That's kind of our own UI uh but that very much looks like MetaMask.

That's the idea of the fishing show trying to provide you with very lookalike UIs. And in this case, we are showing you different kind of transactions, a permit signature, and I'm not going to spoil you what that is. Uh but that's probably malicious. I don't know. It's for you to tell.

So you will have to detect whether that's one issues or not and then we'll kind of walk you through kind the explanation for that and this is not ether scan this is actually again the fishing dojo um in which we are showing you transaction histories for example and you will be able to click on these addresses and you will be able to explore these transaction histories you will be able to go to the tokens transfers and explore everything that's going on um so that you can actually understand where there are address poisoning H in this case or not. We have many more scenarios coming uh many more features coming into the fishing dojo show. Again it's free. I'm not selling you anything. You can go check it out use it uh use it with your teams use it for your I know share it with your peers with the community.

I think it's a very valuable resource and that we have these days. is a public good that we are delivering for the community from the red guild and just because we think that the most critical threat that we have these days in crypto is fishing is scams. Uh it's not me telling you again we can go back to the the start of the talk where I was showing you the actual statistics. Um so please go to extreme show play it share it. If you're very technical, perhaps it's kind of um easy for you.

But think about like common people, right? Think about HR people in your company or executives or just the layman guy that is just trying to use or starting to use crypto. We need to educate them. We need to raise awareness in how uh cyber criminals are trying to attack us this day. And again, things are just about to get a little bit a little bit more complicated.

So stay safe, don't get wrecked. I have um a few minutes left perhaps if you want to ask questions or even just share some stories. If you have ever been fished or scammed, we are in a safe place. You can share your histories with me. Um so yeah, that's probably it.

Thank you. [Applause] comments, questions, um stories, worries. Is it on? Yeah. Uh thank you for your uh speech.

Um I just wanted to ask you uh have you come across um an example where you mentioned um scams within npm packages. So uh since we're all in AI age uh have you come across any example where AI uh used such packages to um to suggest to developers to import them into their projects.

Yes.

Thanks.

Um thank you for the questions. Thank you for attending. So um what I have seen I don't I don't remember the the actual research right now but what I have seen is that in many cases AIS hallucinating uh mpm packages like inventing mpm packages that don't exist and attackers realizing about that. Um so once they see those kind of hallucinations they actually go and publish malicious packages with those names on the mpm repository. So other people will actually start start downloading those.

Automatic transcript — names and jargon may be misspelled.