16/01/2023 Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

A sponsored advertising link on Google hid malware that siphoned thousands of dollars worth of crypto and NFTs from an influencer’s wallet.

Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

An NFT influencer claims to have lost “a life-changing amount” of their net worth in nonfungible tokens (NFTs) and crypto after accidentally downloading malicious software found via a Google Ad search result.

The pseudo-anonymous influencer known on Twitter as “NFT God” posted a series of tweets on Jan. 14 describing how his “entire digital livelihood” came under attack including acompromise of his crypto walletand multiple online accounts.

NFT God, known also as “Alex,” said he used Google's search engine to download OBS, an open-source video streaming software. But instead of clicking on the official website, he clicked the sponsored advertisement for what he thought was the same thing.

It wasn’t until hours later — after a series of phishing tweets posted by attackers on two Twitter accounts that Alex operates — that he realized malware was downloaded from the sponsored advertisement alongside the software he wanted.

Following a message from an acquaintance, Alex noticed his crypto wallet was also compromised. The next day, attackers breached his Substack account and sent phishing emails to his 16,000 subscribers.

Blockchain data shows that at least 19 Ether worth nearly $27,000 at the time, a Mutant Ape Yacht Club (MAYC) NFT with a current floor price of 16 ETH ($25,000), and multiple other NFTs were siphoned from Alex’s wallet.

The attacker moved most of the ETH through multiple wallets before sending it to the decentralized exchange (DEX) FixedFloat, where it was swapped for unknown cryptocurrencies.

Alex believes the “critical mistake” that allowed the wallet hack was setting up his hardware wallet as ahot wallet by entering its seed phrase“ in a way that no longer kept it cold,” or offline, which allowed the hackers to gain control of his crypto and NFTs.

Unfortunately, NFT God’s experience isn’t the first time the crypto community has dealt with crypto-stealing malware in Google Ads.

A Jan. 12 report from cybersecurity firm Cyble warned of an information-stealing malware called “Rhadamanthys Stealer” spreading through Google Ads on “highly convincing phishing webpage[s].”

In October, Binance CEO Changpeng “CZ” Zhao warned that Google search results were promoting crypto phishing and scamming websites.

Cointelegraph contacted Google for comment but did not receive a response. In its help center, however, Google said it “actively works with trusted advertisers and partners to help prevent malware in ads.”

It also describes its use of “proprietary technology and malware detection tools” to regularly scan Google Ads.

Cointelegraph was unable to replicate the results of Alex’s search nor verify if the malicious website was still active.

Arts

google-ads-delivered-malware-drains-nft-influencers-entire-crypto-wallet

Interesting NFTs
Christmas Sleigh
First Christmas-themed Visual Toy. For this work the artist has created a fantastic sleigh, ornamented in detail and with all the Christmas spirit that transports us to childhood, illusion, innocence. With its gift wrapping machinery, its Santa, a snow globe, the nutcracker, the European-style village and its soundtrack (first time with music) it is a whole Christmas mosaic for the imagination.
trump 2020
This is a photo i took of my son playing around in one of our cat carriers, redressed to express the concern and damage the continuation of the trump administration could bring to the world in 2020 and beyond. Unlike the majority of my historic work found on opensea, all content was conceived and taken by me, so felt perfect to use as my first piece on Known Origin.
#50925
By OthersideDeployer
Lulu Green
Heyo! I'm Lulu Green. I'm a Foreign Film Director by day, and I like volunteering at the local kitten rescue shelter by night. I once dreamed of being a Dispensary Clerk. Now I can be found siring for status all day. I think you'll love me beclaws I have cattitude.
HaCKittieZ
Who will be the most Meowfool of the Meowfoolest?! 6 HaCKittieZ are fighting for the crown of madness! It is time for crowns to change their history: people, this is the crown of insanity we are talking about. So tell us, who is insaner than the insanest of collectors? Only the artists - the creators - would know, while crowning the one who is brave enough to play with the craziest possibilities of Async programmable art, on these 6 HaCKittieZ. Welcome to the feast of fools. HaCKittieZ is a collaboration of Hackatao, CryptoKitties and Async. The 6 KittieZ are a reinterpretation by Hackatao of the CryptoKitties’ classic elements, following their own style and getting inspiration from their own art pieces.