• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

How Scammers Use Fake Updates to Target Phantom Wallet

user avatar

by Giorgi Kostiuk

a year ago


Web3 security firm Scam Sniffer has uncovered a new phishing method targeting Phantom Wallet users. Scammers utilize fake pop-ups that mimic update requests to trick users into revealing sensitive information.

New Phishing Attack on Phantom Wallet Users

According to Scam Sniffer, the scam aims to drain user wallets by tricking them with bogus "update extension" requests. Once users comply, the scam escalates by requesting seed phrases, giving attackers full access to the wallet and its funds. Unlike previous phishing attempts mimicking Phantom's website, this method connects directly to legitimate Phantom wallets, making the scam more convincing.

How to Distinguish Fake from Real Pop-Ups

Scam Sniffer provides tips on how to identify fake pop-ups. Legitimate Phantom pop-ups behave like standard system windows that can be resized or minimized. Fake pop-ups remain within the browser tab. Moreover, right-clicking is disabled on phishing pop-ups, preventing users from inspecting URLs. Genuine Phantom pop-ups allow right-clicking and always contain the "chrome-extension://" prefix.

Other Issues Faced by Phantom Wallet Users

This phishing scam is not the only issue faced by Phantom Wallet users recently. A critical bug in a recent iOS update caused wallets to reset, locking users out and requiring them to re-enter recovery phrases. Although the bug was later fixed, the incident raised questions about the reliability of non-custodial wallets during unexpected disruptions.

Launched in 2021 as a Solana-based wallet, Phantom Wallet continues to expand support to other networks. Despite the risks, the company maintains investor confidence, securing significant funding in a recent investment round.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Aztec Connect Smart Contract Exploited for $219 Million

chest

A deprecated Aztec Connect smart contract has been exploited for about $219 million, highlighting the risks associated with old contracts in DeFi.

user avatarAisha Farooq

World Liberty Financial Partners with UFC for USD1 Stablecoin Bonus Pool

chest

World Liberty Financial has partnered with UFC to use its USD1 stablecoin in the event's bonus structure, aiming to promote the token to a mainstream sports audience.

user avatarTenzin Dorje

Binance Reaffirms Commitment to EU Operations Amid License Concerns

chest

Binance has stated its intention to continue serving EU customers despite potential license issues.

user avatarBayarjavkhlan Ganbaatar

Rep. Thomas Massie's Federal Reserve Abolition Act Gains Attention in Bitcoin Community

chest

Rep. Thomas Massie's proposal to abolish the Federal Reserve is gaining traction in Bitcoin circles due to its connection to 'The Bitcoin Standard'.

user avatarMohamed Farouk

Micron Technologies' Role in AI

chest

Micron Technologies is a key player in the AI sector, providing essential memory solutions.

user avatarDiego Alvarez

Bybit Introduces RWA Earn Portal for Tokenized Yield Access

chest

Bybit has launched the RWA Earn portal, enabling eligible users to access tokenized yield products, marking a shift in how exchanges operate.

user avatarElias Mukuru

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.