Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Policy & Regulation·

May 24, 2024

Thai regulator takes action against deceptive crypto ads

In an effort to safeguard crypto investors from falling prey to misleading advertisements, the Securities and Exchange Commission (SEC) of Thailand has intensified its scrutiny of promotional campaigns within the crypto sphere. Photo by Dave Kim on UnsplashBroker agent eventsOn April 29, the Bangkok Post reported that the SEC has raised concerns regarding the potential violation of local regulations through introducing broker agent (IBA) events. These events, the SEC clarified, may breach regulations as IBAs are only permitted to promote digital token services to deter speculation on cryptocurrencies, categorized as high-risk assets. IBAs, acting as local conduits for partner digital asset exchanges, typically earn commissions by onboarding clients within a specific market. Such practices are common for exchanges or brokers that don't directly operate in certain markets. Deputy Secretary-General Anek Yooyuen conveyed the commission's unease over crypto exchanges offering preferential treatment to onboard users. Yooyuen stated: "When operators organise sales promotions by offering rewards to entice people to use the service, this could encourage use of the service without considering the investment risks. This is especially the case for cryptocurrencies.” Warning of consequencesHe cautioned that failure to adhere to these guidelines would result in “punishment according to the law.” While cryptocurrency exchanges are legal in Thailand, they must secure local approval. Notably, last month, Thailand even greenlit asset management firms to launch private funds, offering Bitcoin exchange-traded funds (ETFs) exclusively to institutional and ultra-high-net-worth investors. Nonetheless, the country recently prohibited the sale of cryptocurrency lending products and mandated that exchanges prominently display risk warning messages. International regulatory trendThis move by the Thai SEC mirrors actions taken by regulators in other major crypto markets. For instance, the United Kingdom's Financial Conduct Authority (FCA) issued 450 alerts for illegal crypto ads in 2023 alone. Similarly, Spain’s principal securities market regulator, the National Stock Market Commission, denounced fraudulent crypto asset promotions in November 2023, emphasizing companies’ obligations to adhere to local laws. Thai advertising guidelines mandate businesses and advertisers to substantiate the “facts” presented in their campaigns, failing which could lead to legal repercussions. A recent incident provides a case in point. Hackers hijacked advertisements on Etherscan, redirecting users to phishing sites aimed at draining crypto wallets. Scam Sniffer, a blockchain investigation firm, attributed the widespread phishing campaign to the inadequate oversight by advertisement aggregators. The company made the following statement on the matter: “Etherscan aggregates ads from platforms like Coinzilla and Persona, where insufficient filtering could lead to exposure to phishing attempts.” The wallet drainer scam involves enticing users to counterfeit websites and coercing them to link their crypto wallets, enabling scammers to siphon funds into their own wallets without user authentication or consent. This is not the first time that the authorities in Thailand have homed in on crypto-related advertising. In August 2023, the Southeast Asian country’s Ministry of Digital Economy and Society (MDES) outlined that it had engaged with social media firm Meta, owner of Facebook, informing it that its response to the proliferation of fraudulent platform ads relative to crypto had been inadequate. 

news
Web3 & Enterprise·

Aug 04, 2023

Animoca Brands Partners With Yuga Labs on ‘Wreck League’ Launch

Animoca Brands Partners With Yuga Labs on ‘Wreck League’ LaunchHong Kong’s Animoca Brands and its San Francisco-based subsidiary nWay, a developer and publisher of multiplayer games, have partnered with Yuga Labs, unveiling their latest creation: “Wreck League.”Photo by Haidan on UnsplashLeveraging Web3Diving into uncharted waters in the realm of esports, this game leverages Web3 technology to empower players with the ability to construct, possess, and engage in battles with their very own distinctive Mech fighters.“Wreck League” challenges the traditional boundaries of gaming by permitting enthusiasts to craft their fighters, engage in fierce competitions, and secure on-chain rewards. Set to debut its maiden season, the game will draw inspiration from the Web3 stalwart, Yuga Labs.The game boasts a dual-pronged design, encompassing both Web2 and Web3 versions. In a savvy maneuver to capture a wide-ranging audience, nWay has devised a marketing strategy that seamlessly integrates effective user acquisition techniques from their previous ventures while circumventing complex blockchain terminology.Clarifying the ingenious concept behind the game, Taehoon Kim, the CEO of nWay, explained: “Wreck League stands as a fusion of Web3 and Web2 concepts. Our mission revolves around unifying communities and players, tapping into the creative wellspring of the Web3 community to consistently elevate the game’s content.”Designed for player retentionWithin the player community, creators, owners, and participants converge to partake in league events. The crux of the game revolves around the assembly of high-performance Mechs, crafted from a collection of 10 distinct Mech Parts NFTs.Player retention is a cornerstone of its design, driven by an engaging trajectory of in-game progression through upgradable mech parts, enhancing gameplay dynamics, and embedding the notion of asset ownership. The more players invest in refining their assets and advancing through levels, the stronger their bond with the game becomes. Active participation in events and tournaments further reinforces player allegiance.Yat Siu, the Co-Founder and Executive Chairman of Animoca Brands, is optimistic regarding the transformative potential of “Wreck League” within the esports sector. Siu envisions the game, where digital asset ownership is the norm, as a harbinger of a monumental shift in competitive gaming dynamics.Expanding market reachFor Yuga’s part, the NFT and metaverse company is using gaming, through this particular partnership, as a mechanism to broaden the reach of its well-established NFT brand. That said, it has also made its own individual efforts in that regard recently. The Web3 studio, best known for having created the Bored Ape Yacht Club (BAYC) NFT collection, has released two games, Dookey Dash and Forge, independently.nWay and Animoca Brands get to benefit from access to Yuga’s well-known NFT collections through the partnership. The companies confirmed that as part of the gaming experience, gamers will be able to collect and take ownership of in-game digital assets in the form of NFTs.Animoca acquired nWay in December 2019 for $7.69 million. The games developer and publisher creates and distributes triple A games on console, PC, and mobile platforms. At the time of the acquisition Animoca Brands outlined that it foresaw nWay innovating in the area of blockchain-based games, with the intention of both companies working together relative to that endeavor.

news
Policy & Regulation·

Apr 20, 2023

Do Kwon Loses Fight to Conceal Singapore Records

Do Kwon Loses Fight to Conceal Singapore RecordsDo Kwon, the founder of Terraform Labs has failed in his attempt to deny the United States’ Securities and Exchange Commission (SEC) from accessing company records in Singapore.©Pexels/George BeckerIn February, the SEC filed a complaint against Terraform Labs and its founder in a US court. The move followed an investigation that the agency had carried out into the collapse of a number of digital assets established by the company. The lawsuit claims that both the company and Do Kwon had engaged in fraud, together with the sale of unregistered securities to US citizens.Jurisdictional challengeLawyers for Do Kwon had claimed that in trying to access documents related to the Singapore-domiciled company, the SEC was acting far beyond its jurisdiction. According to court filings, his defense team argued that Do Kwon is a Singapore resident while Terraform Labs is a Singapore-based company that operates on a global basis and not specifically in the United States.The filing pointed to the fact that the Terraform Labs CEO had “limited contact with the US.” “Most of the company’s business is essentially global, and it’s not specifically aimed at the United States,” it stated.His lawyers had filed a request for the SEC to withdraw its documentation request. In a recent hearing, US District Judge Jed Rokoff turned down Terraform’s request. The documents are understood to be held by the Monetary Authority of Singapore (MAS) although the specific nature of the documentation sought remains unclear.The SEC claims that in founding the Terra US dollar stablecoin (TUSD) and associated cryptocurrency LUNA, Terraform Labs and Do Kwon were responsible for wiping out more than $40 billion dollars in value following their collapse. The Luna Foundation Guard (LFG), which was established to provide funds to keep the TUSD stablecoin at a $1 value, is another entity that the SEC intends to access documents from with the court’s permission. Singaporean police had stated last month that they had launched an investigation into the collapse of the TUSD stablecoin.Meanwhile, both the South Korean and US authorities are seeking the extradition of Do Kwon to face related charges. He was arrested last month in the southeastern European country of Montenegro where he was charged with having used forged documentation to enter the country. Although he had denied it on social media, in effect Do Kwon had been on the run from the reach of South Korean authorities over the course of a number of months, spending a portion of that time in Montenegro.Asset huntAn investigation by authorities in South Korea in recent weeks revealed that they were unable to find any assets held in the country owned by the Terraform Labs founder. The trail in chasing down any such assets has led to the United States. It is understood that Do Kwon bought real estate in the United States under his mother’s name. This is a common tactic for those who attempt to evade future confiscation of assets.Earlier this week, South Korean prosecutors confirmed that they are investigating a transfer of funds by Do Kwon to a leading law firm based in Seoul.

news
Loading