‹ BackNewsWallet Security

Wallet Security

SlowMist CSO 23pds warns of full iOS attack chain targeting wallet users
SafePal
2026-09-18 03:45:29

SafePal outlines how crypto users can spot and avoid social engineering scams

SafePal has published a security guide warning crypto users that many losses begin not with a technical exploit, but with a scammer persuading the victim to hand over control. The guide says social engineering attacks often rely on impersonation, urgency, fake websites, malicious software, long-term trust building, and even offline delivery tactics rather than direct wallet or system compromise. According to the guide, common setups include fake customer support messages on Telegram, Discord, X, WeChat, or by phone; phishing links distributed through email, text messages, search ads, QR codes, and direct messages; and pressure tactics built around claims that assets are being stolen or accounts are about to be frozen. SafePal also warns about scams tied to airdrops, NFT rewards, high-yield investment offers, recovery services, and unsolicited hardware devices sent through offline channels. The company breaks these attacks into three stages: building credibility, creating a reason that demands action, and then pushing the victim to visit a site, scan a QR code, download software, connect a wallet, sign a transaction, share a screen, reveal credentials, or transfer funds. SafePal says users should never share seed phrases, private keys, PINs, or wallet passwords, should not verify a sender through links or numbers provided by that sender, and should avoid approving signatures or permissions they do not understand. If a seed phrase or private key has already been exposed, the guide says the wallet should be treated as compromised and assets should be moved to a newly created wallet on a trusted device.

500
SafePal outlines how crypto users can spot and avoid social engineering scams
DeBot isolates affected wallets after security alert, asks users to stop using old addresses
Security firms say $7.8 million wallet drain came from authorized helper contract, not Safe
MetaMask adds wallet protections with transfer and scam alerts
MetaMask Rolls Out New Scam Defenses Across Mobile App and Browser Extension
BlueWallet CTO flags 45 iOS non-custodial wallet apps as high or severe risk
Policy Regula
2026-09-11 09:40:27

Fake AML screening sites lure crypto users into wallet approvals that drain funds

A report carried by Foresight and written by Zero Hour Technology warns that a new phishing playbook is exploiting crypto users’ compliance anxiety by posing as anti-money laundering, or AML, screening tools. According to the article, Malwarebytes disclosed on Aug. 19, 2026, that numerous fake AML check sites were actively operating, tricking users into connecting wallets and approving malicious transactions that later emptied their balances. Some pages reportedly impersonated AMLBot, while others used generic branding such as "AML Check," though the report said they were built from the same malicious template. The piece says a legitimate AML screening process is a read-only query that only needs a public wallet address to review on-chain history for links to sanctions, hacks, theft, or suspicious activity. It does not require a wallet connection, a signature, a token approval, or any payment. By contrast, the fake sites simulate a professional workflow with scan progress bars, compliance messages, fake errors, and small "verification fee" prompts before returning a reassuring "Clean, Low Risk" result. The key risk comes after the wallet is connected and the user clicks approve, granting token access that attackers can later use to move funds. The article’s advice is direct: do not connect a wallet for an AML check, do not pay any fee for such a check, and regularly review and revoke unknown token approvals.

880
Fake AML screening sites lure crypto users into wallet approvals that drain funds