16/01/2023 Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

A sponsored advertising link on Google hid malware that siphoned thousands of dollars worth of crypto and NFTs from an influencer’s wallet.

Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

An NFT influencer claims to have lost “a life-changing amount” of their net worth in nonfungible tokens (NFTs) and crypto after accidentally downloading malicious software found via a Google Ad search result.

The pseudo-anonymous influencer known on Twitter as “NFT God” posted a series of tweets on Jan. 14 describing how his “entire digital livelihood” came under attack including acompromise of his crypto walletand multiple online accounts.

NFT God, known also as “Alex,” said he used Google's search engine to download OBS, an open-source video streaming software. But instead of clicking on the official website, he clicked the sponsored advertisement for what he thought was the same thing.

It wasn’t until hours later — after a series of phishing tweets posted by attackers on two Twitter accounts that Alex operates — that he realized malware was downloaded from the sponsored advertisement alongside the software he wanted.

Following a message from an acquaintance, Alex noticed his crypto wallet was also compromised. The next day, attackers breached his Substack account and sent phishing emails to his 16,000 subscribers.

Blockchain data shows that at least 19 Ether worth nearly $27,000 at the time, a Mutant Ape Yacht Club (MAYC) NFT with a current floor price of 16 ETH ($25,000), and multiple other NFTs were siphoned from Alex’s wallet.

The attacker moved most of the ETH through multiple wallets before sending it to the decentralized exchange (DEX) FixedFloat, where it was swapped for unknown cryptocurrencies.

Alex believes the “critical mistake” that allowed the wallet hack was setting up his hardware wallet as ahot wallet by entering its seed phrase“ in a way that no longer kept it cold,” or offline, which allowed the hackers to gain control of his crypto and NFTs.

Unfortunately, NFT God’s experience isn’t the first time the crypto community has dealt with crypto-stealing malware in Google Ads.

A Jan. 12 report from cybersecurity firm Cyble warned of an information-stealing malware called “Rhadamanthys Stealer” spreading through Google Ads on “highly convincing phishing webpage[s].”

In October, Binance CEO Changpeng “CZ” Zhao warned that Google search results were promoting crypto phishing and scamming websites.

Cointelegraph contacted Google for comment but did not receive a response. In its help center, however, Google said it “actively works with trusted advertisers and partners to help prevent malware in ads.”

It also describes its use of “proprietary technology and malware detection tools” to regularly scan Google Ads.

Cointelegraph was unable to replicate the results of Alex’s search nor verify if the malicious website was still active.

Arts

google-ads-delivered-malware-drains-nft-influencers-entire-crypto-wallet

Interesting NFTs
ˈSÄ-V(Ə-)RƏN-TĒ
"I'm not smart enough to be an astronaut." That is what 7 year old Rayden told Micah the first time they met. How can a 7-year-old already feel limitations on his dreams? For centuries, the black community has been the target of a system designed to limit their power, their earning potential, their dreams. Now is your opportunity to help destroy the system. For the next 11 years, on each brother's birthday, (Rayden, Aug. 10/ Jacque Nov. 6), you the viewer, will be able to directly contribute Bitcoin to a wallet that will be given to each child upon turning 18. In what is one of the most powerful use cases for Bitcoin, 100% of your contributions and earnings will open all new doors for these special young men.
Fuku-Shiva
The term “Fuku” refers to fortune or good luck. “Shiva” refers to the Hindu deity who represents strongly polar qualities, both severe and delicate. On a beach inspired by adventures on Phi Phi island in Thailand, three youths cavort. Two are representational figures and the third is psychologically rendered. A dynamic relationship ensues between the triad; a reciprocity of active and passive states. The boy on the right engages in maneuvers of evasion, defense, and is dressed in a speedo which reiterates the colors and symbolism of the caution tape on the left and upper right frame of the composition. In concurrent reaction the psychedelic figure shoots out a rocket powered paper airplane. The nude boy seated in the froth and sand approaches in passive repose, and is met with active attention but equal physical reserve by the psychedelic being. Perhaps the most naked figure is also the least representational. Looming large, dynamic, and active, it engages its companions playfully. Various symbols interject into the otherwise naturalistic scene, most notably a beach ball and two contaminated barrels nested in the sand. The upright barrel reads “FukuShima” in Kanji. The barrel laying down reads “Dharma”. To the left the scene is bounded by caution tape, reiterating the danger of the nuclear waste while also hosting alien archetypes, whose presence, as is the nature of these entities, runs up and just behind the consciousness of the psychedelic figure’s eggshell-like skull.
The Switch
The Switch is a unique, “one of one” NFT that demonstrates the evolution of artwork in the digital realm. The Switch is developed to change form at a specific point of time in the future, known by Pak. The evolution is determined and rendered immutable by smart contracts, or self-executing code on the Ethereum blockchain.
#60649
By OthersideDeployer
CryptoFinney 131 of 131
name CryptoFinney img QmdpUhYbJBz1mcBWUSUijMcbDZYSrVtn2WtNuHfrzxS38G/finney_1_1_2_0_0_0_6_4_5_2_1_2_4_a.png backimg QmdpUhYbJBz1mcBWUSUijMcbDZYSrVtn2WtNuHfrzxS38G/finney_1_1_2_0_0_0_6_4_5_2_1_2_4_b.png cardimg QmUyUF2PPcuiapEuDHdrjfjZXzXDyNe4mZEDqAdFJWyh8N metal Palladium skin Dark eyes Brown torso Black T-Shirt legs Beige Shorts feet Common Shoes rarity Blue Cap, Stubble, Brown Jacket, Pink Watch artist Jon Trafford release CryptoFinney Genesis url writer.io