Web3.0 mobile Wallet faces new threats from modal window phishing attacks

robot
Abstract generation in progress

New Security Threats to Web3.0 Mobile Wallets: Modal Window Phishing Attacks

Recently, security researchers have discovered a new type of phishing technique targeting Web3.0 mobile Wallets, known as "modal phishing attacks." This attack primarily exploits the modal windows in mobile Wallet applications to mislead users, thereby tricking them into approving malicious transactions.

Unveiling the New Scam of Web3.0 Mobile Wallets: Modal Phishing Attack

The Principle of Modal Phishing Attacks

Modal phishing attacks primarily target user interface elements in Web3.0 cryptocurrency Wallets, particularly modal windows. Attackers can manipulate the information displayed in these windows to make it appear as if it comes from legitimate decentralized applications (DApp), thereby deceiving users into approving transactions.

The reason this type of attack is effective is that many wallet applications fail to fully verify the legitimacy of the information presented. For example, some wallets directly trust metadata from external SDKs without conducting additional verification.

Unveiling New Scam in Web3.0 Mobile Wallet: Modal Phishing Attack

Attack Cases

  1. Wallet Connect phishing: Attackers can control information such as the name, icon, and website address of the DApp, making phishing sites appear to be legitimate DApps. When users connect their wallets via Wallet Connect, this false information will be displayed in the modal window of the wallet.

Unveiling the New Type of Scam in Web3.0 Mobile Wallets: Modal Phishing Attack

  1. Smart Contract Information Phishing: Certain wallets (such as MetaMask) display the function names of smart contracts in a modal window. Attackers can create malicious contracts with misleading names, for example naming the transfer function "SecurityUpdate" to deceive users into approving the transaction.

Unveiling the New Type of Scam in Web3.0 Mobile Wallets: Modal Phishing Attack

Prevention Suggestions

  1. Wallet Developer:
    • Always treat externally provided data as untrusted.
    • Carefully select the information displayed to users and verify its legality.
    • Consider filtering keywords that may be used for phishing attacks.

Unveiling New Scam of Web3.0 Mobile Wallet: Modal Phishing Attack

  1. User:
    • Remain vigilant for every unknown transaction request.
    • Carefully check the transaction details and do not approve the transaction based solely on the information displayed in the modal window.
    • Use official channels to download and update the Wallet application.

Revealing the New Scam of Web3.0 Mobile Wallets: Modal Phishing Attack

  1. Protocol Developer:
    • Consider adding verification mechanisms at the protocol level, such as Wallet Connect, which can verify the validity of DApp information in advance.

Unveiling the New Type of Scam in Web3.0 Mobile Wallets: Modal Phishing Attack

With the development of Web3.0 technology, these new types of security threats are also continuously evolving. Both users and developers need to enhance their security awareness and work together to maintain the safety of the Web3.0 ecosystem.

Revealing the New Scam of Web3.0 Mobile Wallet: Modal Phishing Attack

Unveiling the New Scam of Web3.0 Mobile Wallets: Modal Phishing Attack

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
ApeDegenvip
· 07-15 06:34
Here comes the Be Played for Suckers again.
View OriginalReply0
CoconutWaterBoyvip
· 07-15 04:55
What new tricks are there? Please elaborate.
View OriginalReply0
GraphGuruvip
· 07-13 18:39
Been played for suckers again.
View OriginalReply0
TerraNeverForgetvip
· 07-13 04:59
Be careful with your dad's Wallet
View OriginalReply0
MetaLord420vip
· 07-13 04:57
Be careful not to let others take advantage of you...
View OriginalReply0
GweiTooHighvip
· 07-13 04:53
It's so scary, the attackers have various traps.
View OriginalReply0
YieldWhisperervip
· 07-13 04:45
same old phish, new wrapper... saw this exact pattern in metamask 2021. devs never learn smh
Reply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)