Crypto Scammers Exploit User Interface Flaw to Spread Scams
Crypto scammers have discovered a new method to carry out scams, fake giveaways, and deceptive Telegram channels by exploiting a flaw in the user interface. This flaw allows them to create seemingly legitimate URLs that contain malicious content. The flaw was first identified by a user named @rcwht_, who noticed that scammers were able to publish tweets that imitate those from authentic accounts.
The Vulnerability in Action
According to BleepingComputer, scammers can manipulate the status_id field while using the legitimate tag in the account_name field. For example, a link like “https://x.com/[account_name]/status/[status_id]” would appear as if it were posted by crypto.news. However, when users click on the link, they are redirected to Elon Musk’s post because the status ID retrieves the corresponding post from the website’s database without verifying its association with the account_name field.
Exploiting High-Profile Accounts
This vulnerability allows scammers to modify the account name, even for well-known accounts. As a result, they have been targeting crypto-related accounts such as Binance and Ethereum Foundation with fake airdrops. Security researcher MalwareHunterTeam confirmed this exploitation of the flaw.
Protecting Yourself from Scams
Since this redirect is a standard feature of X and is unlikely to change for improved security, users are advised to carefully examine the address bar when clicking on X links. This will help confirm that they are visiting the intended tweet without being redirected.
Hot Take: Stay Vigilant Against Crypto Scams
Crypto scammers are always finding new ways to deceive users and spread fraudulent schemes. This recent exploit of a user interface flaw highlights the importance of remaining vigilant and cautious when engaging with cryptocurrency-related content online. By verifying the legitimacy of URLs and closely inspecting the address bar, you can protect yourself from falling victim to scams. Remember to exercise caution and skepticism, especially when it comes to offers that seem too good to be true. Stay informed and stay safe in the world of crypto.