{"id":29049,"date":"2021-03-26T04:27:05","date_gmt":"2021-03-25T17:27:05","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/29049\/"},"modified":"2021-03-26T04:27:25","modified_gmt":"2021-03-25T17:27:25","slug":"cryptoscam-in-discord-fake-dex-airdrop","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/29049\/","title":{"rendered":"Discord cryptoscam: Revenge of the fraudsters"},"content":{"rendered":"<p>Following recent scams involving <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord\/38661\/\" target=\"_blank\" rel=\"noopener nofollow\">fake cryptocurrency exchanges<\/a> and <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord-fake-news-services\/38764\/\" target=\"_blank\" rel=\"noopener nofollow\">fake news sites<\/a>, we recently uncovered a third campaign, one using fake DEX exchanges and aimed at cryptocurrency enthusiasts on the Discord messaging app. Here\u2019s how the new scheme works.<\/p>\n<h2>A word about cryptocurrency exchanges<\/h2>\n<p>First, what\u2019s a DEX? Two types of cryptocurrency exchanges exist: centralized (CEX) and decentralized (DEX).<\/p>\n<p>With a CEX exchange, clients transfer money to the exchange and the funds are moved to a wallet, the private key for which is stored on the platform. Accordingly, exchange operators are also responsible for security. CEX exchanges belong to specific legal entities, and their clients undergo <a href=\"https:\/\/en.wikipedia.org\/wiki\/Know_your_customer\" target=\"_blank\" rel=\"nofollow noopener\">know-your-customer<\/a> checks to fight money laundering. In general, such sites are convenient and reliable, but some users are put off by the need to transfer funds to the exchange and the possibility of having their account frozen during verification.<\/p>\n<p>Unlike CEX platforms, DEX exchanges are essentially just intermediaries between buyers and sellers. Traders can use <a href=\"https:\/\/www.kaspersky.com\/blog\/safe-cryptotrading-for-dummies\/37224\/\" target=\"_blank\" rel=\"noopener nofollow\">any wallet<\/a> and don\u2019t need to transfer private keys. DEX exchanges tend not to be owned by any particular organization, they don\u2019t necessarily verify their clients, and they\u2019re not typically very invested in stopping illegal transactions.<\/p>\n<p>The decentralized approach provides greater anonymity. In addition, DEX exchanges often have lower fees, which is perhaps why they have been attracting ever more cryptocurrency traders of late.<\/p>\n<p>Decentralization also means more security concerns for users \u2014 and on top of the ordinary added risk DEX users accept, cybercriminals recently created a phishing site disguised as a DEX exchange called Uniswap.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-banking\">\n<h2>How DEX clients get duped<\/h2>\n<p>Potential victims \u2014 users of popular Discord cryptocurrency servers \u2014 receive phishing messages that appear to come from Uniswap and offer free tokens. The authors pass their scheme off as an <a href=\"https:\/\/www.investopedia.com\/terms\/a\/airdrop-cryptocurrency.asp\" target=\"_blank\" rel=\"nofollow noopener\">airdrop<\/a> \u2014 a giveaway of coins, usually to promote a new cryptocurrency but sometimes for user loyalty or for simple tasks such as reposting on social networks. (Such \u201cgifts\u201d are sometimes called <a href=\"https:\/\/en.wikipedia.org\/wiki\/Helicopter_money\" target=\"_blank\" rel=\"nofollow noopener\">helicopter money<\/a>.)<\/p>\n<p>In their message, the scammers claim that several cryptocurrency services have just launched such a campaign, and the addressee is among the lucky recipients of the drop. The prize is juicy, too: 2.5 Ethereum and 25,000 ZKSwap coins \u2014 more than $75,000 at the time of posting.<\/p>\n<div id=\"attachment_39143\" style=\"width: 1058px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/03\/26042712\/cryptoscam-in-discord-fake-dex-airdrop-screenshot-1.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-39143\" class=\"size-full wp-image-29050\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/03\/26042712\/cryptoscam-in-discord-fake-dex-airdrop-screenshot-1.png\" alt=\"A scam message from a fake exchange about winning helicopter ETH and ZKS\" width=\"1048\" height=\"805\"><\/a><p id=\"caption-attachment-39143\" class=\"wp-caption-text\">A scam message from a fake exchange about winning helicopter ETH and ZKS<\/p><\/div>\n<p>If one ignores the unusually generous airdrop, the message looks credible: The language is awkward but not riddled with major errors, the level of emoji use is reasonable, and the list of exchanges includes reputable names. It even includes believable T&amp;Cs for receiving the prize.<\/p>\n<p>The brevity of the link to the giveaway might arouse suspicion, but that\u2019s unlikely; many are already accustomed to shortened addresses such as t.co or bit.ly links.<\/p>\n<p>The link leads to a page very similar to the Uniswap website \u2014 and the fairly well-known exchange actually held a helicopter money promotion for clients not so long ago. The scam website, however, prominently features a button labeled <em>Claim accumulated rewards<\/em>.<\/p>\n<div id=\"attachment_39144\" style=\"width: 1080px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/03\/26042720\/cryptoscam-in-discord-fake-dex-airdrop-screenshot-2.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-39144\" class=\"size-full wp-image-29052\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/03\/26042720\/cryptoscam-in-discord-fake-dex-airdrop-screenshot-2.png\" alt=\"A page disguised as Uniswap offers 2.5 ETH\" width=\"1070\" height=\"700\"><\/a><p id=\"caption-attachment-39144\" class=\"wp-caption-text\">A page disguised as Uniswap offers 2.5 ETH<\/p><\/div>\n<p>Clicking the button takes the victim to a screen requesting the private key or mnemonic phrase for their cryptowallet (in our story, the scammers requested a Metamask wallet). In this case, a <a href=\"https:\/\/en.bitcoinwiki.org\/wiki\/Mnemonic_phrase\" target=\"_blank\" rel=\"nofollow noopener\">mnemonic phrase<\/a>, or seed phrase, is a sequence of normal human words that restores access to a wallet in the event of a technical failure or a change of device.<\/p>\n<h2>How not to fall for DEX scams<\/h2>\n<p>To avoid swallowing the cybercriminal bait, follow these simple rules:<\/p>\n<ul>\n<li>Be wary of any offers of free cryptocurrency. Bona fide promotional giveaways tend to be reserved for early investors;<\/li>\n<li>Pay attention to the criteria. If a message about a prize or a giveaway contains a condition you have not fulfilled, then even if the promotion is real, you still won\u2019t be eligible;<\/li>\n<li>Consult <a href=\"https:\/\/claimable.vercel.app\/\" target=\"_blank\" rel=\"nofollow noopener\">Claimable<\/a> if you have any doubts. It\u2019s a free service that lets you check whether you can claim a prize and requires only the public key for your cryptowallet, no confidential data;<\/li>\n<li>Check on official websites to see if a particular promotion is actually running;<\/li>\n<li>Add the websites you use to your bookmarks and visit them from there; do not follow links in messages or e-mails;<\/li>\n<li>Read the terms of use of the services, paying attention to which data they might request from you and which they won\u2019t.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-banking\">\n","protected":false},"excerpt":{"rendered":"<p>A new scam is targeting users of popular Discord cryptocurrency servers.<\/p>\n","protected":false},"author":2513,"featured_media":29054,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2646],"tags":[2620,3395,2672,80,726],"class_list":{"0":"post-29049","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-cryptocurrencies","9":"tag-discord","10":"tag-ethereum","11":"tag-fraud","12":"tag-scam"},"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/29049\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/22665\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/18158\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/24461\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/22485\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/21508\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/24968\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/24256\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/30332\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/9479\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/39140\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/16669\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/cryptoscam-in-discord-fake-dex-airdrop\/14616\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/26447\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/cryptoscam-in-discord-fake-dex-airdrop\/30316\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/26846\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/cryptoscam-in-discord-fake-dex-airdrop\/23704\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/cryptoscam-in-discord-fake-dex-airdrop\/28850\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/scam\/","name":"scam"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/29049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2513"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=29049"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/29049\/revisions"}],"predecessor-version":[{"id":29053,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/29049\/revisions\/29053"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/29054"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=29049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=29049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=29049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}