{"id":19653,"date":"2022-05-16T15:43:34","date_gmt":"2022-05-16T11:43:34","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/19653\/"},"modified":"2022-05-16T15:44:17","modified_gmt":"2022-05-16T11:44:17","slug":"cryptocurrency-giveaway-scam","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/19653\/","title":{"rendered":"Cryptoscam giveaway: phishers go after seed phrases"},"content":{"rendered":"<p>Scammers will stop at nothing when it comes to stealing cryptocurrency. Some try to sell <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-fake-antminer\/39398\/\" target=\"_blank\" rel=\"noopener nofollow\">scarce mining equipment<\/a>, others <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord\/38661\/\" target=\"_blank\" rel=\"noopener nofollow\">lure victims with gifts<\/a> from cryptoexchanges or <a href=\"https:\/\/www.kaspersky.com\/blog\/safe-cryptotrading-for-dummies\/37224\/\" target=\"_blank\" rel=\"noopener nofollow\">Elon Musk<\/a> himself, or even post screenshots on public platforms with <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-lightshot\/39224\/\" target=\"_blank\" rel=\"noopener nofollow\">passwords for cryptowallets<\/a> and collect \u201cfees\u201d from cryptoinvestors enticed by the prospect of a free lunch. Today we tell you about a new giveaway scam and underscore once again why the seed phrase for your cryptowallet must be guarded with your life.<\/p>\n<h2>Free money<\/h2>\n<p>As is often the case, it all starts with an e-mail. The brains behind this scheme chose as bait an offer to take part in a juicy giveaway of cryptocurrency: Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Tron (TRX) or Ripple (XRP). A total of $800 million no less was at stake! The overly generous scammers were kind enough to provide a simple three-point guide for those wanting to get their free cryptocurrency, plus a link to the \u201cpromotion\u201d website.<\/p>\n<p>Let\u2019s take a look at the e-mail. It is signed by the support team of a certain Crypto Community: an association of cryptoenthusiasts, one might think. However, the domain in the sender\u2019s e-mail address has nothing to do with any kind of crypto at all. That does not inspire confidence. The message text is slapdash, and full of errors and typos. The scammers are likely counting on the victim being so taken aback by the nine-figure sum that everything else will slip under the radar.<\/p>\n<div id=\"attachment_44350\" style=\"width: 910px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154343\/cryptocurrency-giveaway-scam-screen-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-44350\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154343\/cryptocurrency-giveaway-scam-screen-1.jpg\" alt=\"Phishing e-mail inviting the recipient to take part in a cryptocurrency giveaway\" width=\"900\" height=\"640\" class=\"size-full wp-image-19654\"><\/a><p id=\"caption-attachment-44350\" class=\"wp-caption-text\">Phishing e-mail inviting the recipient to take part in a cryptocurrency giveaway<\/p><\/div>\n<p>Clicking the link takes the user to a phishing site. Its domain bears no relation to the sender\u2019s address, and in the minimalist design there is no mention at all of any Crypto Community.<\/p>\n<p>At this point, the victim is asked to specify the wallet they want the funds transferred to. The criminals covered all the most common wallets: Blockchain.com, Trust Wallet, MetaMask, Coinbase, Binance, Crypto.com, and Exodus. But users of more exotic wallets have not been forgotten: for them, an <em>Other Wallets<\/em> button has been provided. User-friendly, isn\u2019t it?<\/p>\n<div id=\"attachment_44351\" style=\"width: 2570px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154353\/cryptocurrency-giveaway-scam-screen-2-scaled-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-44351\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154353\/cryptocurrency-giveaway-scam-screen-2-scaled-1.jpg\" alt=\"The victim is invited to choose a cryptowallet for the promised transfer of tokens\" width=\"2560\" height=\"1600\" class=\"size-full wp-image-19656\"><\/a><p id=\"caption-attachment-44351\" class=\"wp-caption-text\">The victim is invited to choose a cryptowallet for the promised transfer of tokens<\/p><\/div>\n<p>Now for the most interesting part: to get the coveted tokens, the user must enter a secret series of words, aka \u2013 a seed phrase. As soon as they fill in the fields and click the <em>Next<\/em> button, a notification appears on the screen that everything was successful and the cryptocurrency will be in the lucky winner\u2019s account within 24 hours.<\/p>\n<p>Interestingly, the website has no checks: even if random words or even numerals (which cannot be part of a seed phrase at all) are entered instead, the site still reports a successful transfer. Of course, if the real seed phrase is typed in, far from receiving winnings, the victim will likely be relieved of all their savings.<\/p>\n<div id=\"attachment_44352\" style=\"width: 2570px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154407\/cryptocurrency-giveaway-scam-screen-3-scaled-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-44352\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2022\/05\/16154407\/cryptocurrency-giveaway-scam-screen-3-scaled-1.jpg\" alt=\"Any sequence of words and numbers will produce a \" successful transfer width=\"2560\" height=\"2457\" class=\"size-full wp-image-19658\"><\/a><p id=\"caption-attachment-44352\" class=\"wp-caption-text\">Any sequence of words and numbers will produce a \u201csuccessful\u201d transfer<\/p><\/div>\n<h2>Seed phrase, or the key to all doors<\/h2>\n<p>The scammers rely on the fact that people are usually very protective of their private key, which immediately opens access to the cryptowallet; but many do not realize their seed phrase is also top-secret, and think nothing of entering it on a website in anticipation of a reward.<\/p>\n<p>In actual fact, the seed phrase is no less valuable. With it, an attacker can generate a new private key and thus gain access to the victim\u2019s wallet. In other words, the seed phrase effectively affords the same opportunities to <a href=\"https:\/\/www.kaspersky.com\/blog\/metamask-wallets-scam\/43962\/\" target=\"_blank\" rel=\"noopener nofollow\">pillage your savings<\/a> as the private key. This means you should protect the former from prying eyes and ears as carefully as the latter.<\/p>\n<h2>How to protect your cryptofinances<\/h2>\n<p>To wrap up, a few tips to avoid falling victim to cryptoscams:<\/p>\n<ul>\n<li>Keep your seed phrase secret. Never reveal it to anyone, and enter it only to recover access to your wallet. Do not store the seed phrase in public file-sharing services, or send it via instant messaging apps or by e-mail.<\/li>\n<li>Do not click on links in e-mails about giveaways, gift payouts, account suspensions or bank account closures. Such e-mails are most likely from cybercriminals. Read our checklist to learn <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-protect-from-online-scam\/43908\/\" target=\"_blank\" rel=\"noopener nofollow\">how to spot online scammers<\/a>.<\/li>\n<li>Use a <a href=\"https:\/\/me-en.kaspersky.com\/plus?icid=me-en_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kplus___\" target=\"_blank\" rel=\"noopener\">reliable security solution<\/a> that warns you in good time about phishing pages and prevents you from handing over sensitive information to the bad guys.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-banking\">\n","protected":false},"excerpt":{"rendered":"<p>We explain how scammers steal cryptowallets through phishing.<\/p>\n","protected":false},"author":2598,"featured_media":19660,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1486],"tags":[374,1308,1505,1504,80,76,695],"class_list":{"0":"post-19653","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-bitcoin","9":"tag-blockchain","10":"tag-cryptocurrencies","11":"tag-ethereum","12":"tag-fraud","13":"tag-phishing","14":"tag-scam"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/19653\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/cryptocurrency-giveaway-scam\/24171\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/26492\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/cryptocurrency-giveaway-scam\/24448\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/24801\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/cryptocurrency-giveaway-scam\/27170\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/cryptocurrency-giveaway-scam\/26703\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/cryptocurrency-giveaway-scam\/33183\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/cryptocurrency-giveaway-scam\/10691\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/cryptocurrency-giveaway-scam\/44346\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/cryptocurrency-giveaway-scam\/18903\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/cryptocurrency-giveaway-scam\/19437\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/cryptocurrency-giveaway-scam\/28563\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/cryptocurrency-giveaway-scam\/28270\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/cryptocurrency-giveaway-scam\/25035\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/cryptocurrency-giveaway-scam\/30535\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/cryptocurrency-giveaway-scam\/30284\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/scam\/","name":"scam"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/19653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2598"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=19653"}],"version-history":[{"count":3,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/19653\/revisions"}],"predecessor-version":[{"id":19659,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/19653\/revisions\/19659"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/19660"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=19653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=19653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=19653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}