Home / Blockchain / Tether Freezes $20 Million Linked To Phishing Scammer

Tether Freezes $20 Million Linked To Phishing Scammer

Summary:
A phishing scammer recently nabbed million in USDT from an unsuspecting victim using a zero transfer phishing attack, reported blockchain security firm PeckShield on Tuesday. The stolen funds were frozen in short order by Tether – the issuer behind USDT – raising questions about who the victim was given the speed of their response. The Zero Transfer Phishing Attack According to PeckShield, the victim address intended to send funds to one wallet, but was fooled into sending the USDT to a phishing address that began and ended with the same set of characters. Days earlier, the victim had received 10 million USDT from Binance, and had sent those funds to the desired alternative address. However, at the time of that transfer, the scammer conducted a zero-value token

Topics:
Andrew Throuvalas considers the following as important: ,

This could be interesting, too:

Andrew Throuvalas writes Crypto Twitter Skeptical As MicroStrategy Proposes Bitcoin-Based Identity Solution

Chayanika Deka writes Aave Labs Unveils Major Upgrades and Expansions with Aave V4 Proposal

Mandy Williams writes Coinbase Adds Support for Bitcoin Lightning Network

Mandy Williams writes US DOJ Arrests ‘Bitcoin Jesus’ Roger Ver for M Tax Evasion

A phishing scammer recently nabbed $20 million in USDT from an unsuspecting victim using a zero transfer phishing attack, reported blockchain security firm PeckShield on Tuesday.

The stolen funds were frozen in short order by Tether – the issuer behind USDT – raising questions about who the victim was given the speed of their response.

The Zero Transfer Phishing Attack

According to PeckShield, the victim address intended to send funds to one wallet, but was fooled into sending the USDT to a phishing address that began and ended with the same set of characters.

Days earlier, the victim had received 10 million USDT from Binance, and had sent those funds to the desired alternative address. However, at the time of that transfer, the scammer conducted a zero-value token transfer from the victim’s address to their phishing address.

As explained by Coinbase in a February blog post, scammers started developing smart contracts in November 2022 designed to create spoofed zero-value transactions from a victim’s address to a scammer’s, the latter of which is designed to look much like one of the victim’s actual addresses.

Since the transfers have zero value, they do not require the approval of the victim’s private key to execute. Though this transfer itself cannot steal funds, it can fool victims into later sending real funds to the spoof address – especially if the user often relies on their transaction history to verify addresses that they can send funds to.

Users often don’t check every character of the address they send coins to, instead only checking the first and last characters, making them more vulnerable to such a scam.

Tether’s Freeze

Moments after the transfer, Tether froze the USDT held at the scammer’s address by adding the address to its blacklist.

On-chain sleuth ZachXBT, who has investigated and exposed numerous phishing scams in the past, found the speed of the company’s response unusual. “Curious who this would be if it was blacklisted within ~1hr,” he tweeted on Tuesday.

Twitter user 0xG00gly also expressed confusion, saying they “couldn’t remember a single precedent like this where Tether would have acted so quickly.” ZachXBT suggested the transfer might be related to an OTC transaction.

Rival stablecoin issuer Circle has previously frozen transactions connected to the Ethereum privacy mixer Tornado Cash, at the request of the U.S. Treasury Department. Tether did not follow through on a similar freeze.

You Might Also Like:

Leave a Reply

Your email address will not be published. Required fields are marked *