PSA: Another phishing spree has hit crypto — ignore all emails about airdrops
They say money never sleeps. In crypto, that means the phishers, fraudsters and other cyberbaddies are also always working
The recent spate of cyberattacks on crypto projects continued Tuesday morning, with a number of teams urging users not to interact with malicious emails sent from official accounts.
Data provider Token Terminal, decentralized finance superapp De.Fi, authentication protocol WalletConnect and crypto media outlet Cointelegraph have all sent warnings about their respective incidents.
“Unauthorized airdrop email sent from Token Terminal — do not connect wallets,” Token Terminal told users in an email about 40 minutes after the illegitimate one.
“We are currently investigating a phishing attack involving an unauthorized email sent from us, directing recipients to an unverified site. This email was not authorized by us and may pose a risk to your security.”
Token Terminal and the other three known affected teams then told users not to click on any links in emails that “look suspicious or unexpected.”
The unofficial email promised users access to an early access airdrop for a purported new cryptocurrency tied to the platform.
“I hope this email finds you well! We’re thrilled to share some exciting news that will surely pique your interest. As a valued member of our community, we wanted to personally inform you about the upcoming TokenTerminal Beta Access Airdrop!”
“We’re on the verge of unveiling the beta version of TokenTerminal, and we want you to be among the first to explore its innovative features and capabilities. To express our gratitude for your continued support, we’ve decided to celebrate this milestone with a special airdrop exclusively for our community members.”
A button underneath directed recipients to claim the airdrop by linking their crypto wallets. Instead of receiving an airdrop, the wallets would instead be drained and sent to the attacker. A similar email was sent to WalletConnect users.
Web3 cybersecurity unit Blockaid, which has been working with affected teams, told Blockworks that in the case of WalletConnect, the perpetrators had used the same wallet draining code utilized in the Ledger Connect Kit phishing spree in December.
Read more: ‘Wallet drainer’ code added to Ledger library has crypto on edge
At this stage, it appears that only the email domains for each project were compromised. Blockworks has reached out to Blockaid to learn more about the potential connection to the other three known incidents.
It could be that other projects’ emails have been successfully attacked. So for now, it’s best to ignore any and all emails referencing token airdrops (and never connect your wallet to any protocol or service that you have not thoroughly vetted yourself!).
Updated Jan. 23, 2022 at 9:07 am ET: Added reference to fourth victim Cointelegraph.
Don’t miss the next big story – join our free daily newsletter .
- airdrop
- Phishing
- wallets
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Trump’s Republican allies unsettled by Elon Musk’s D.O.G.E
Share link:In this post: Elon Musk’s D.O.G.E. has gutted the CFPB, firing employees, shutting down enforcement, and wiping the agency’s name off its headquarters—leaving Trump allies worried it could backfire in court. Russell Vought and other Trump officials fear Elon’s reckless approach could bring lawsuits, allowing the CFPB to survive instead of being quietly dismantled. Government employees are suing the Trump administration anonymously, afraid Elon’s attacks on X and mass firings could put them at ri
Netflix faces backlash for using AI-generated voice of Gabby Petito
Share link:In this post: Netflix used AI to recreate Gabby Petito’s voice in its new docuseries, and people are calling it disturbing and unethical. Viewers slammed Netflix online, saying AI shouldn’t be used to digitally recreate a murder victim’s voice for a documentary. Gabby’s family approved it, but experts argue that murder victims don’t get a say in how their voice is used after death.
Vitalik Buterin joins the resistance against the UK government’s push for Apple user data
Share link:In this post: Vitalik Buterin criticized the UK government for its recent demands for backdoor access to Apple user data. This will be the first time Apple is disabling its data security tool. Apple reassures users that some data, such as health app data, passwords, and communications on iMessage and FaceTime, will remain end-to-end encrypted.
President Trump Declares End to Biden’s Crypto War, Pledges US Bitcoin Dominance
Trending news
MoreCrypto prices
More








