16/01/2023 Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

A sponsored advertising link on Google hid malware that siphoned thousands of dollars worth of crypto and NFTs from an influencer’s wallet.

Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

An NFT influencer claims to have lost “a life-changing amount” of their net worth in nonfungible tokens (NFTs) and crypto after accidentally downloading malicious software found via a Google Ad search result.

The pseudo-anonymous influencer known on Twitter as “NFT God” posted a series of tweets on Jan. 14 describing how his “entire digital livelihood” came under attack including acompromise of his crypto walletand multiple online accounts.

NFT God, known also as “Alex,” said he used Google's search engine to download OBS, an open-source video streaming software. But instead of clicking on the official website, he clicked the sponsored advertisement for what he thought was the same thing.

It wasn’t until hours later — after a series of phishing tweets posted by attackers on two Twitter accounts that Alex operates — that he realized malware was downloaded from the sponsored advertisement alongside the software he wanted.

Following a message from an acquaintance, Alex noticed his crypto wallet was also compromised. The next day, attackers breached his Substack account and sent phishing emails to his 16,000 subscribers.

Blockchain data shows that at least 19 Ether worth nearly $27,000 at the time, a Mutant Ape Yacht Club (MAYC) NFT with a current floor price of 16 ETH ($25,000), and multiple other NFTs were siphoned from Alex’s wallet.

The attacker moved most of the ETH through multiple wallets before sending it to the decentralized exchange (DEX) FixedFloat, where it was swapped for unknown cryptocurrencies.

Alex believes the “critical mistake” that allowed the wallet hack was setting up his hardware wallet as ahot wallet by entering its seed phrase“ in a way that no longer kept it cold,” or offline, which allowed the hackers to gain control of his crypto and NFTs.

Unfortunately, NFT God’s experience isn’t the first time the crypto community has dealt with crypto-stealing malware in Google Ads.

A Jan. 12 report from cybersecurity firm Cyble warned of an information-stealing malware called “Rhadamanthys Stealer” spreading through Google Ads on “highly convincing phishing webpage[s].”

In October, Binance CEO Changpeng “CZ” Zhao warned that Google search results were promoting crypto phishing and scamming websites.

Cointelegraph contacted Google for comment but did not receive a response. In its help center, however, Google said it “actively works with trusted advertisers and partners to help prevent malware in ads.”

It also describes its use of “proprietary technology and malware detection tools” to regularly scan Google Ads.

Cointelegraph was unable to replicate the results of Alex’s search nor verify if the malicious website was still active.

Arts

google-ads-delivered-malware-drains-nft-influencers-entire-crypto-wallet

Interesting NFTs
019 [Silver Edition]
From the original 151 monsters we know today, we thought - what would they actually look like if they were humanized? They are massive. They are muscular. They are ugly. They are Pokémen. Collect 'em all!
The King
Part of a series of three artworks entitled "The Rulers". Inspired by the rulers of the animal kingdom, african mandalas & diamonds. A very complex digital illustration, each lion consists of hundreds of custom diamond shapes. Each background is an intricate custom mandala that compliments the lions facial features.
Her Mind Had Gone Out For A Stroll & Fallen Down The Rabbit Hole
Her Mind Had Gone Out For A Stroll & Fallen Down The Rabbit Hole' is the first programmable piece of art by Kitty Bast. The owner constructs, modifies & tattoos their very own Doll Lady... Is she falling down a rabbit hole, lost in a sea of cats or gazing into the unknown void? Do you like Pink Ladies or Lilac Ladies? Or do you pick the Wild Card? There's always a wild side to an innocent doll face. Is she obsessed with crypto ponies or crypto kitties? Or does she have an insatiable desire for Mr. Honey Badger. Come inside and have a nice cup of NFTea with the bunnies. Is your lady chained to the blockhain? Does your lady shed Bitcoin tears or ETH tears? Does your doll face don a Rotten Heart? Do you HODL to the Moon to meet the ETH Kitty? Do you have an obsession for cyborgs or Puddin'? Would you like a slice of Death by Pink? Is The Cat's Eye green or golden? Little trolls with mini daggers not included. The cheshire cat might trade you his ears for your goggles. Modifications of the Host. How long is forever? Sometimes, just one second.
Right Place & Right Time (bitcoin hourly price offset)
Each day, a new composition for the Master is generated autonomously using a data feed of Bitcoin's last 24 hours of price action. Each hour's price programmatically controls rotation, scale, and position of a correlating layer. Astute viewers will surmise the day's price volatility simply by examining the artwork. While the daily image generation is the result of autonomous API calls, utilizing an algorithm the artist wrote, the artist has chosen to retain a control token. This token allows him to fine-tune variables associated with his algorithm, in addition to addressing aesthetic concerns within the life-cycle of the artwork. Layer state, alpha, hue, saturation, and brightness are elements the artist has retained control of in order that this artwork remain a living work-in-progress. An earlier iteration of this artwork was featured as a nightly projection mapping video on the face of the Daniels Fisher Clocktower, as part of ETH Denver 2020. Access to this and additional exclusive content awaits the master token owner at the artist's NFT Portal: https://collect.mattkane.com/minted-works/right-place-right-time-bitcoin-hourly-price-offset/
#79026
By OthersideDeployer