5 Stealthy Cryptocurrency Scams to Watch Out For

·

Blockchain security firm SlowMist has reported a significant rise in psychologically manipulative attacks targeting cryptocurrency users during the second quarter. According to the company’s quarterly analysis, hackers are employing increasingly cunning methods—even if their technical skills haven’t necessarily advanced.

Lisa, SlowMist's Operations Director, emphasized that while core hacking techniques may not have evolved dramatically, scammers are now using more sophisticated and deceptive strategies. These include fake browser extensions, compromised hardware wallets, and advanced social engineering ploys.

She noted a clear shift from purely on-chain attacks to off-chain entry points. Browser extensions, social media accounts, authentication processes, and user behavior have all become common attack surfaces.

Malicious Browser Extensions Disguised as Security Tools

One emerging threat involves malicious browser extensions posing as security plugins. A prominent example is the “Osiris” Chrome extension, which claimed to detect phishing links and suspicious websites.

In reality, the extension intercepted all downloads of .exe, .dmg, and .zip files, replacing them with malware. What made this attack particularly effective was the manipulation of trusted websites.

“Attackers lured users to legitimate platforms like Notion or Zoom,” Lisa explained. “When users attempted to download software from these official sites, the files were swapped without their knowledge. Since the browser still displayed the download as coming from a legitimate source, users had almost no way of detecting the fraud.”

Sensitive information from the victim’s computer was sent to the attacker’s server. Source: SlowMist

These malicious programs harvested sensitive data from the victim’s device, including Chrome browser data and macOS Keychain credentials. This allowed attackers to obtain seed phrases, private keys, or login information.

👉 Learn how to protect your digital assets

Preying on Investor Anxiety With Hardware Wallet Scams

Another common tactic involved tricking cryptocurrency investors into using compromised hardware wallets. In some instances, hackers mailed tampered cold wallets to users, claiming they had won the device in a giveaway.

In other cases, scammers informed victims that their current hardware wallet had been compromised and advised them to transfer their assets to a new—and malicious—device.

One victim lost $6.5 million after purchasing a tampered hardware wallet advertised on TikTok. In another incident, an attacker sold a pre-activated hardware wallet and drained the funds as soon as the new user transferred cryptocurrency into it.

Source: Intelligence on Chain

Social Engineering Through Fake Revocation Sites

SlowMist also assisted a user who reported being unable to revoke “risky authorizations” in their wallet. Upon investigation, they discovered the user had been interacting with a fake website.

The phishing site was a near-perfect clone of the popular Revoke Cash interface. It prompted users to enter their private key to “check for risky signatures.”

“By analyzing the front-end code, we confirmed that the phishing site used EmailJS to send user input—including private keys and wallet addresses—directly to the attacker’s email,” Lisa stated.

Phishing, fraud, and private key leaks were the top causes of stolen funds in Q2. Source: SlowMist

“These social engineering attacks are not technically complex, but they are highly effective at exploiting urgency and trust,” she added. Messages like “risk signature detected” trigger panic, leading users to act hastily. Once in this state, victims are more likely to click malicious links or share sensitive information.

Emerging Threats: EIP-7702 Exploits and WeChat Account Takeovers

Other attack methods are also on the rise. Some hackers are already exploiting phishing techniques related to EIP-7702, a new proposal introduced in Ethereum’s recent Pectra upgrade.

Another concerning trend involves attackers targeting WeChat users. By exploiting WeChat’s account recovery system, scammers can take over an account and impersonate the real owner.

They then offer contacts discounted Tether (USDT), exploiting established trust to lure victims into fraudulent deals.

SlowMist’s Q2 data is based on 429 stolen fund reports the company received during that period. Through its efforts, the firm managed to freeze and recover approximately $12 million for 11 affected victims.

Frequently Asked Questions

What is a common sign of a malicious browser extension?
Malicious extensions often mimic legitimate security tools. Be cautious if an extension requests excessive permissions, intercepts downloads, or prompts you to enter private keys. Always download software and extensions from official sources.

How can I verify my hardware wallet is authentic?
Purchase hardware wallets only from official vendors or authorized resellers. Check the packaging for signs of tampering, and never use a device that was mailed to you unexpectedly or sold at a significant discount.

What should I do if I suspect I’ve visited a phishing site?
Immediately disconnect from the internet, run a security scan on your device, and revoke any contract approvals from a trusted platform like Revoke.cash. Monitor your accounts for suspicious activity and consider moving assets to a new wallet.

Why are social engineering attacks so effective in crypto?
Cryptocurrency transactions are irreversible, and the fear of losing funds makes users vulnerable to urgency-based scams. Attackers exploit this anxiety by creating scenarios that demand immediate action, bypassing logical judgment.

How can I safely revoke smart contract permissions?
Use only well-known, official revocation tools. Never enter your private key or seed phrase on any website. Bookmark trusted revocation sites and avoid clicking on links from unknown sources or unofficial channels.

What steps can I take to enhance my overall security?
Enable two-factor authentication on all accounts, use a hardware wallet for large holdings, regularly update your software, and educate yourself on common phishing tactics. Stay vigilant and verify information through multiple sources before taking action.