Copied


CoinGecko Hit by Phishing Scam

Zach Anderson   Jan 11, 2024 08:20 0 Min Read


On January 10, 2024, CoinGecko, a leading cryptocurrency data aggregator, experienced a significant security breach. The company's account on a major social media platform (formerly known as Twitter) and its terminal were compromised, leading to the unauthorized posting of a phishing scam link. This incident has raised serious concerns about cybersecurity in the rapidly evolving cryptocurrency industry.

CoinGecko's technical team responded swiftly to the breach, regaining control of the account and initiating an investigation. They issued a warning to users, advising them not to interact with suspicious content or follow any dubious links. The fraudulent post advertised a non-existent CoinGecko token airdrop, a common tactic in phishing scams designed to lure unsuspecting victims into revealing sensitive information or transferring funds.

This incident did not occur in isolation. Just a day earlier, the United States Securities and Exchange Commission (SEC) suffered a similar attack on its social media account. Scammers posted a deceptive message claiming that the SEC Chair, Gary Gensler, had approved several applications for Bitcoin spot exchange-traded funds (ETFs). This claim was quickly debunked and the post removed, but it highlighted the effectiveness of such tactics in creating temporary confusion and potential harm.

Both incidents underline the vulnerability of even high-profile organizations to cyberattacks, particularly those involving social engineering. The methods used in these breaches were not sophisticated technical hacks but rather relied on exploiting human factors, such as the lack of two-factor authentication (2FA) and the ability to manipulate telecommunications services to execute SIM-card swap attacks.

The rise of SIM-card swap attacks in the Web3 community is particularly troubling. These attacks involve fraudsters impersonating legitimate account holders to gain control over their phone services. Once achieved, they can access various accounts linked to the phone number, including social media and cryptocurrency wallets. The cryptocurrency community has witnessed several such incidents, including a notable attack on Ethereum co-founder Vitalik Buterin's account in September 2023.

In response to these threats, experts in the field emphasize the importance of robust security measures. Two-factor authentication (2FA) is now considered a basic necessity, not an optional add-on. Users are also advised to be extra cautious about suspicious links and offers, particularly those promising free tokens or other too-good-to-be-true opportunities.


Image source: Shutterstock

Read More
The Hong Kong Monetary Authority has issued a warning about a fraudulent website posing as OCBC Bank (Hong Kong) Limited, urging public vigilance.
Bitcoin (BTC) has held the top spot in the cryptocurrency world since its creation in 2009. It remains the largest and most recognized digital asset by market capitalization.
Institutional interest in crypto surges; regulatory clarity and tokenization reshape the landscape.
AI and blockchain converge, enabling decentralized data ownership and real-time integration for better predictions.
Crypto for Everyone: Crypto must focus on real-world utility and user experience to gain mainstream acceptance and rebuild trust.
Blockchain technology transformed digital transactions, with crypto apps playing a crucial role in this transformation.
Online casinos have experienced rapid growth during the last decade as they have had to overcome security issues all while working to establish transparency.