Warning of Phishing Attacks on friend.tech
Recently, SlowMist, a blockchain security firm, alerted users about a rise in phishing attacks from individuals pretending to be journalists on the decentralized social network friend.tech. The attacks were first identified on October 14 when a Twitter user reported a malicious code targeting the platform for account theft. SlowMist’s investigation revealed that the attacker shared a link containing a malicious JavaScript script.
How the Attacks Happened
The findings of SlowMist’s investigation showed that the attacker specifically targeted users on friend.tech, particularly Key Opinion Leaders (KOLs) who were likely to receive interview invitations due to their popularity. The attacker followed people within the target’s Twitter network to create a sense of community and then scheduled interviews with them. During these interviews, the attackers guided users to join Telegram and provide personal information.
Afterward, the attackers requested that users fill out a form and open a provided phishing link under the pretext of verification. This link instructed users to verify their friend.tech account by dragging a “Verify” button to the bookmark bar and clicking on it after visiting the friend.tech website. By doing this, users unknowingly exposed their account credentials, including passwords and tokens associated with Privy, an embedded wallet.
Preventing Phishing Attacks
To prevent such attacks, SlowMist recommended increasing awareness of social engineering attacks, refraining from clicking on unfamiliar links, and learning how to recognize phishing links. Additionally, they encouraged users to install anti-phishing plugins and be cautious of misspellings or excessive punctuation in domain names.
This is not the first time that friend.tech users have faced security breaches. Previously, they were targeted by SIM card manipulation. As a result, the platform introduced 2FA password features to enhance user security.
Hot Take: Protecting Yourself from Phishing Attacks
It is crucial to remain vigilant against phishing attacks when using decentralized social networks like friend.tech. Be wary of unfamiliar links and always verify the legitimacy of requests for personal information before sharing any details online.