• bitcoinBitcoin (BTC) $ 78,684.00
  • ethereumEthereum (ETH) $ 1,569.11
  • tetherTether (USDT) $ 0.999514
  • xrpXRP (XRP) $ 1.92
  • bnbBNB (BNB) $ 553.73
  • usd-coinUSDC (USDC) $ 0.999931
  • solanaSolana (SOL) $ 107.64
  • dogecoinDogecoin (DOGE) $ 0.148086
  • tronTRON (TRX) $ 0.226799
  • cardanoCardano (ADA) $ 0.576745
  • staked-etherLido Staked Ether (STETH) $ 1,574.82
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 79,121.00
  • leo-tokenLEO Token (LEO) $ 8.84
  • usdsUSDS (USDS) $ 0.999991
  • the-open-networkToncoin (TON) $ 3.07
  • chainlinkChainlink (LINK) $ 11.43
  • stellarStellar (XLM) $ 0.233230
  • avalanche-2Avalanche (AVAX) $ 16.47
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • wrapped-stethWrapped stETH (WSTETH) $ 1,893.55
  • suiSui (SUI) $ 2.00
  • hedera-hashgraphHedera (HBAR) $ 0.146528
  • mantra-daoMANTRA (OM) $ 6.32
  • polkadotPolkadot (DOT) $ 3.60
  • bitcoin-cashBitcoin Cash (BCH) $ 272.32
  • litecoinLitecoin (LTC) $ 70.70
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 0.999800
  • bitget-tokenBitget Token (BGB) $ 4.07
  • wethWETH (WETH) $ 1,580.72
  • pi-networkPi Network (PI) $ 0.586502
  • whitebitWhiteBIT Coin (WBT) $ 27.56
  • hyperliquidHyperliquid (HYPE) $ 11.04
  • moneroMonero (XMR) $ 196.36
  • wrapped-eethWrapped eETH (WEETH) $ 1,682.12
  • daiDai (DAI) $ 1.00
  • uniswapUniswap (UNI) $ 5.15
  • okbOKB (OKB) $ 50.39
  • susdssUSDS (SUSDS) $ 1.05
  • pepePepe (PEPE) $ 0.000006
  • aptosAptos (APT) $ 4.38
  • nearNEAR Protocol (NEAR) $ 2.17
  • gatechain-tokenGate (GT) $ 21.05
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 79,343.00
  • tokenize-xchangeTokenize Xchange (TKX) $ 29.93
  • ondo-financeOndo (ONDO) $ 0.761368
  • mantleMantle (MNT) $ 0.690480
  • crypto-com-chainCronos (CRO) $ 0.082923
  • internet-computerInternet Computer (ICP) $ 4.65
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.16
  • ethereum-classicEthereum Classic (ETC) $ 14.45
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997505
  • aaveAave (AAVE) $ 131.08
  • cosmosCosmos Hub (ATOM) $ 4.40
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • vechainVeChain (VET) $ 0.020241
  • fasttokenFasttoken (FTN) $ 4.05
  • kaspaKaspa (KAS) $ 0.064558
  • bittensorBittensor (TAO) $ 198.26
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 79,215.00
  • ethenaEthena (ENA) $ 0.293678
  • official-trumpOfficial Trump (TRUMP) $ 7.92
  • filecoinFilecoin (FIL) $ 2.38
  • render-tokenRender (RENDER) $ 2.92
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.172320
  • celestiaCelestia (TIA) $ 2.48
  • algorandAlgorand (ALGO) $ 0.167826
  • sonic-3Sonic (prev. FTM) (S) $ 0.442113
  • arbitrumArbitrum (ARB) $ 0.275776
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 79,557.00
  • eosEOS (EOS) $ 0.751601
  • story-2Story (IP) $ 4.25
  • kucoin-sharesKuCoin (KCS) $ 8.49
  • makerMaker (MKR) $ 1,226.61
  • optimismOptimism (OP) $ 0.611552
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.391291
  • jupiter-exchange-solanaJupiter (JUP) $ 0.342007
  • usdt0USDT0 (USDT0) $ 0.998134
  • xdce-crowd-saleXDC Network (XDC) $ 0.062395
  • nexoNEXO (NEXO) $ 0.952502
  • binance-peg-wethBinance-Peg WETH (WETH) $ 1,582.02
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 1,640.44
  • binance-staked-solBinance Staked SOL (BNSOL) $ 111.82
  • dexeDeXe (DEXE) $ 15.42
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999621
  • blockstackStacks (STX) $ 0.542126
  • worldcoin-wldWorldcoin (WLD) $ 0.657129
  • movementMovement (MOVE) $ 0.326511
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.997450
  • bonkBonk (BONK) $ 0.000010
  • rocket-pool-ethRocket Pool ETH (RETH) $ 1,782.99
  • usual-usdUsual USD (USD0) $ 0.998235
  • flare-networksFlare (FLR) $ 0.011734
  • tether-goldTether Gold (XAUT) $ 3,032.43
  • the-graphThe Graph (GRT) $ 0.075004
  • theta-tokenTheta Network (THETA) $ 0.713716
  • paypal-usdPayPal USD (PYUSD) $ 0.999199
  • injective-protocolInjective (INJ) $ 7.30
  • sei-networkSei (SEI) $ 0.147771
  • immutable-xImmutable (IMX) $ 0.399451
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 79,310.00
  • wbnbWrapped BNB (WBNB) $ 560.53
  • pax-goldPAX Gold (PAXG) $ 3,042.16
  • lido-daoLido DAO (LDO) $ 0.712753
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 78,951.00
  • tezosTezos (XTZ) $ 0.591476
  • usdx-money-usdxStables Labs USDX (USDX) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 0.462153
  • mantle-staked-etherMantle Staked Ether (METH) $ 1,657.55
  • galaGALA (GALA) $ 0.013654
  • the-sandboxThe Sandbox (SAND) $ 0.242576
  • kaiaKaia (KAIA) $ 0.098627
  • bittorrentBitTorrent (BTT) $ 0.00000057
  • walrus-2Walrus (WAL) $ 0.451132
  • iotaIOTA (IOTA) $ 0.149914
  • bitcoin-svBitcoin SV (BSV) $ 27.36
  • fartcoinFartcoin (FARTCOIN) $ 0.529125
  • flowFlow (FLOW) $ 0.331453
  • honey-3Honey (HONEY) $ 0.999418
  • grassGrass (GRASS) $ 1.84
  • msolMarinade Staked SOL (MSOL) $ 139.21
  • berachain-beraBerachain (BERA) $ 4.57
  • jito-governance-tokenJito (JTO) $ 1.57
  • zcashZcash (ZEC) $ 31.30
  • flokiFLOKI (FLOKI) $ 0.000051
  • stargate-bridged-usdc-berachainStargate Bridged USDC (Berachain) (USDC.E) $ 1.01
  • beldexBeldex (BDX) $ 0.071262
  • true-usdTrueUSD (TUSD) $ 0.994304
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.67
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 1,634.16
  • spx6900SPX6900 (SPX) $ 0.518455
  • pendlePendle (PENDLE) $ 2.89
  • raydiumRaydium (RAY) $ 1.61
  • jasmycoinJasmyCoin (JASMY) $ 0.009565
  • kavaKava (KAVA) $ 0.425199
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.998240
  • heliumHelium (HNT) $ 2.59
  • sonic-bridged-usdc-e-sonicSonic Bridged USDC.e (Sonic) (USDC.E) $ 0.999462
  • pumpbtcpumpBTC (PUMPBTC) $ 78,185.00
  • pyth-networkPyth Network (PYTH) $ 0.120542
  • ethereum-name-serviceEthereum Name Service (ENS) $ 13.23
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 117.54
  • dydx-chaindYdX (DYDX) $ 0.555196
  • resolv-usrResolv USR (USR) $ 0.999542
  • coredaoorgCore (CORE) $ 0.422088
  • usdbUSDB (USDB) $ 1.03
  • saros-financeSaros (SAROS) $ 0.153754
  • decentralandDecentraland (MANA) $ 0.215693
  • axie-infinityAxie Infinity (AXS) $ 2.48
  • apenftAPENFT (NFT) $ 0.00000040
  • hashnote-usycHashnote USYC (USYC) $ 1.06
  • ousgOUSG (OUSG) $ 110.58
  • telcoinTelcoin (TEL) $ 0.004502
  • clbtcclBTC (CLBTC) $ 79,814.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 78,788.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.149959
  • olympusOlympus (OHM) $ 23.24
  • elrond-erd-2MultiversX (EGLD) $ 13.41
  • reserve-rights-tokenReserve Rights (RSR) $ 0.006752
  • chilizChiliz (CHZ) $ 0.039529
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 1,659.49
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.07
  • thorchainTHORChain (RUNE) $ 1.05
  • starknetStarknet (STRK) $ 0.126453
  • conflux-tokenConflux (CFX) $ 0.071673
  • compound-governance-tokenCompound (COMP) $ 40.38
  • ubtcuBTC (UBTC) $ 79,580.00
  • infrared-beraInfrared Bera (IBERA) $ 4.71
  • ecasheCash (XEC) $ 0.000018
  • roninRonin (RON) $ 0.563625
  • dogwifcoindogwifhat (WIF) $ 0.345650
  • neoNEO (NEO) $ 4.88
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.992615
  • tbtctBTC (TBTC) $ 78,953.00
  • wormholeWormhole (W) $ 0.075800
  • arweaveArweave (AR) $ 5.20
  • fraxFrax (FRAX) $ 0.999914
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 1,579.41
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 1,577.40
  • super-oethSuper OETH (SUPEROETHB) $ 1,601.29
  • solayerSolayer (LAYER) $ 1.54
  • apecoinApeCoin (APE) $ 0.400156
  • cheems-tokenCheems Token (CHEEMS) $ 0.000002
  • beam-2Beam (BEAM) $ 0.006024
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 1,629.82
  • binance-peg-busdBinance-Peg BUSD (BUSD) $ 1.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.746616
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.478429
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000056
  • matic-networkPolygon (MATIC) $ 0.171664
  • plumePlume (PLUME) $ 0.147945
  • layerzeroLayerZero (ZRO) $ 2.66
  • justJUST (JST) $ 0.029892
  • chain-2Onyxcoin (XCN) $ 0.008706
  • usddUSDD (USDD) $ 0.999445
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 79,612.00
  • axelarAxelar (AXL) $ 0.301508
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 1,576.17
  • amp-tokenAmp (AMP) $ 0.003315

CertiK Discusses the Growing Frequency of Social Engineering Crypto Scams

0 9

CertiK Discusses the Growing Frequency of Social Engineering Crypto Scams

The state of security across the crypto and blockchain space has changed significantly in the past few months. Traditional smart contracts exploited or brute force attacks on blockchain networks are being superseded by crypto scams like rug pulls and pump-and-dump schemes.

BeInCrypto spoke with a spokesperson from security firm CertiK to understand how blockchain and security threats are evolving and how projects and users can safeguard against future exploits.

Social Media Hacks on the Rise

Over the past few months, the crypto community has seen a rise in social media-related hacks. This increasingly common tendency has pivoted away from the orchestration of more sophisticated blockchain attacks that have traditionally plagued headlines.

Whereas smart contract exploits or blockchain hacks require more knowledge, hackers have found an easier avenue by targeting social media accounts instead.

“Social‬‭ media‬‭ accounts‬‭ have‬‭ become‬‭ attractive‬‭ targets‬‭ due‬‭ to‬‭ their‬‭ broad‬‭ reach‬‭ and‬‭ the‬‭ trust‬‭ followers‬‭ place‬‭ in‬‭ verified‬‭ profiles.‬‭ Compared‬‭ to‬‭ complex‬‭ blockchain‬‭ attacks,‬‭ hijacking‬‭ a‬‭ social‬‭ media‬‭ account‬‭ offers‬‭ a‬‭ quicker,‬‭ less‬‭ technically‬‭ demanding‬‭ way‬‭ to‬‭ spread‬‭ scams‬‭ to‬‭ a‬‭ massive‬‭ audience.‬‭ The‬‭ growing‬‭ frequency‬‭ of‬‭ such‬‭ breaches‬‭ suggests‬‭ hackers‬‭ are‬‭ focusing‬‭ more‬‭ on‬‭ social‬‭ engineering‬‭ and‬‭ credential theft over direct blockchain exploitation,” a CertiK spokesperson told BeInCrypto.

The accessibility of social media hacking has, in turn, expanded the pool of malicious actors capable of these attacks.

“‬This‬‭ trend‬‭ may‬‭ also‬‭ be‬‭ due‬‭ to,‬‭ in‬‭ part,‬‭ a‬‭ skills‬‭ gap‬‭ among‬‭ malicious‬‭ actors.‬‭ For‬‭ instance,‬‭ drainer-as-a-service‬‭ has‬‭ opened‬‭ doors‬‭ to‬‭ scammers‬‭ who‬‭ don’t‬‭ necessarily‬‭ understand‬‭ how‬‭ to‬‭ manipulate‬‭ smart‬‭ contracts.‬‭ Many‬‭ of‬‭ these‬‭ scammers‬‭ are‬‭ from‬‭ the‬‭ younger‬‭ generation,‬‭ which‬‭ means‬‭ they‬‭ are‬‭ more‬‭ likely‬‭ to‬‭ speak‬‭ about‬‭ their‬‭ financial‬‭ pursuits‬‭ online,‬‭ which‬‭ fuels‬‭ more‬‭ users‬‭ attempting‬‭ to‬‭ use‬‭ social‬‭ media‬‭ for‬‭ malicious‬‭ purposes,” the spokesperson added.

X (formerly Twitter) has quickly become the social media platform of choice among Web3 hackers.

Social Media is Now a Prime Target for Web3 Hackers

After US President Donald Trump launched his meme coin only two days before assuming office, hackers began to take advantage of the hype to hack high-profile X accounts and convince followers to invest in scam meme coins.

Last month, anonymous hackers took over the X account of the former Malaysian Prime Minister Mahathir Mohamad to promote MALAYSIA, a fake meme coin promoted as the country’s official cryptocurrency.

The post was removed within an hour, but the damage was done. Analysis shows that these hackers were probably related to the infamous Russian Evil Corp and that they stole $1.7 million in this rug pull.

“Given‬‭ that‬‭ X‬‭ is‬‭ the‬‭ most‬‭ popular‬‭ crypto‬‭ social‬‭ media‬‭ application,‬‭ it‬‭ makes‬‭ sense‬‭ that‬‭ popular‬‭ accounts‬‭ on‬‭ the‬‭ platform‬‭ have‬‭ been‬‭ targeted‬‭ to‬‭ attract‬‭ the‬‭ most‬‭ victims,” Certik spokesperson said.

The MALAYSIA token scam happened only two weeks after hackers exploited former Brazilian President Jair Bolsonaro’s social media account. In that instance, scammers promoted the BRAZIL token, which rose over 10,000% in minutes, netting the scammers over $1.3 million.

These scams have also affected technological companies.

Attacks on Tech Companies

In December, AI research and development company Anthropic also saw its X account hacked. A fraudulent post claimed that a fake token called CLAUDE would incentivize AI and crypto projects and included a wallet address for investors.

Attackers managed to collect around $100,000 from speculative investors.

“The‬‭ trend‬‭ is‬‭ real‬‭ and‬‭ concerning.‬‭ The‬‭ breaches‬‭ of‬‭ accounts‬‭ belonging‬‭ to‬‭ global‬‭ leaders‬‭ and‬‭ tech‬‭ companies‬‭ highlight‬‭ how‬‭ threat‬‭ actors‬‭ are‬‭ targeting‬‭ platforms‬‭ with‬‭ wide-reaching‬‭ influence,‬‭ using‬‭ them‬‭ to‬‭ amplify‬‭ fraudulent‬‭ crypto‬‭ schemes.‬‭ It‬‭ reflects‬‭ a‬‭ shift‬‭ in‬‭ tactics‬‭ where‬‭ social‬‭ media‬‭ is‬‭ becoming‬‭ a‬‭ primary‬‭ vector‬‭ for‬‭ crypto-related‬‭ scams,” the CertiK spokesperson told BeInCrypto.

These situations also highlight a broader issue of weak account security on social media platforms. As a result, even prominent individuals are susceptible to security breaches that directly affect the crypto community.

TRUMP Meme Coin Launch Was a Catalyst For Crypto Scams

After the launch of TRUMP, the frequency of socially engineered scams has become more apparent. In January, Ethereum co-founder Vitalik Buterin published a cathartic social media post criticizing TRUMP and meme coins.

“Now is the time to talk about the fact that large-scale political coins cross a further line: they are not just sources of fun, whose harm is at most contained to mistakes made by voluntary participants, they are vehicles for unlimited political bribery, including from foreign nation states,” Buterin claimed.

Buterin highlighted the tokens’ role in enabling scams and political corruption in crypto and blamed a regulatory loophole former SEC Chair Gary Gensler created for allowing bad actors to exploit governance tokens.

However, these crypto scams extend beyond political themes.

Growth of Social Engineering Exploits

A week after Buterin cautioned against political meme coins, a Coinbase user lost $11.5 million after falling victim to a social engineering scam on Base.

Crypto sleuth ZackXBT uncovered the exploit, pointing out that this incident is part of a growing trend, with multiple Coinbase users suffering similar losses. He also estimates that crypto scams of this nature have drained at least $150 million from Coinbase customers.

“Coinbase has a serious fraud problem. I just uncovered many more recent thefts from Coinbase users. The $150 million stolen from Coinbase users in a year is just from thefts I independently confirmed. So it’s more than likely multiples of this number,” ZachXBT stated.

In social engineering scams, attackers use phishing emails, spoofed calls, and other deceptive tactics to trick victims into revealing private keys or login credentials. Once they gain access, they drain wallets, move funds, and take control of accounts.

For CertiK, these situations stipulate the need for stronger security measures.

“Web3‬‭ security‬‭ platforms‬‭ are‬‭ adapting‬‭ by‬‭ expanding‬‭ their‬‭ focus‬‭ beyond‬‭ smart‬‭ contract‬‭ vulnerabilities‬‭ to‬‭ include‬‭ broader‬‭ threat‬‭ detection,‬‭ particularly‬‭ around‬‭ social‬‭ engineering‬‭ risks.‬‭ Many‬‭ are‬‭ integrating‬‭ AI-driven‬‭ monitoring‬‭ tools‬‭ to‬‭ flag‬‭ unusual‬‭ account‬‭ activity,‬‭ especially‬‭ on‬‭ social‬‭ media,‬‭ and‬‭ are‬‭ educating‬‭ users‬‭ about‬‭ the‬‭ dangers‬‭ of‬‭ impersonation‬‭ scams.‬‭ The‬‭ evolving‬‭ threat‬‭ landscape‬‭ has‬‭ prompted‬‭ a‬‭ more‬‭ holistic approach to security, blending traditional blockchain defenses with social platform safeguards,” the spokesperson said.

Addressing these security challenges is crucial as new crypto projects increase exponentially.

Prioritizing Proactive Security in a Rapidly Growing Industry

The Web3 sector is experiencing consistent growth, marked by a surge in new crypto project launches. This innovative momentum is expected to continue, but it’s also fueling security concerns.

Notably, the increasing rate of scams and hacks in the first three months of 2025 makes it clear that security efforts are struggling to keep up with innovation.

A study by Precedence Research estimates the Web 3.0 market will expand from USD 4.62 billion in 2025 to approximately USD 99.75 billion by 2034, with a projected compound annual growth rate (CAGR) of 41.18% during that period.

CertiK Discusses the Growing Frequency of Social Engineering Crypto Scams

Predicted market size of Web3 in the next ten years. Source: Precedence Research.

Yet, CertiK believes that project developers are pushing security considerations toward the end of the priority list.

“Despite‬‭ the‬‭ surge‬‭ in‬‭ new‬‭ projects,‬‭ adherence‬‭ to‬‭ proper‬‭ audit‬‭ protocols‬‭ remains‬‭ inconsistent.‬‭ While‬‭ some‬‭ projects‬‭ prioritize‬‭ thorough‬‭ smart‬‭ contract‬‭ audits,‬‭ others‬‭ rush‬‭ to‬‭ the‬‭ market,‬‭ sidelining‬‭ security‬‭ to‬‭ capitalize‬‭ on‬‭ market‬‭ trends‬‭ in‬‭ an‬‭ attempt‬‭ to‬‭ generate‬‭ rapid‬‭ profits,” said the CertiK spokesperson.

Understandably, the considerable rise in Web3 projects makes it more difficult for security firms to keep up with the pace and width of demand.

“Although‬‭ there‬‭ is‬‭ growing‬‭ awareness‬‭ around‬‭ the‬‭ importance‬‭ of‬‭ audits,‬‭ the‬‭ pace‬‭ of‬‭ new‬‭ launches‬‭ often‬‭ outstrips‬‭ the‬‭ capacity‬‭ of‬‭ security‬‭ firms,‬‭ leading‬‭ to‬‭ such‬‭ gaps.‬‭ Consequently,‬‭ many‬‭ projects‬‭ are‬‭ vulnerable‬‭ to‬‭ exploits,‬‭ highlighting‬‭ the‬‭ need‬‭ for‬‭ more standardized auditing requirements across the space,” the spokesperson concluded.

As the Web3 ecosystem evolves, a proactive and adaptive security approach is critical. Prioritizing both blockchain integrity and social media vigilance will be essential for safeguarding the growing Web3 ecosystem.

The battle against these exploits requires a future where security is not an afterthought but a foundational pillar of every Web3 project and user interaction.

Source

Leave A Reply

Your email address will not be published.