SecurityBrief Australia logo
Australia's leading source of cybersecurity and cyber-attack news
Story image

Check Point Research reveals how hackers run token scams and 'Rug Pull' money - and how to avoid them

By Ryan Morris-Reade
Tue 25 Jan 2022

Check Point Research (CPR) has revealed how scammers are altering smart contracts to create fraudulent tokens. They then use methods to "rug pull" money from people with altered smart contracts, leading to money heists.

The findings come after cryptocurrency research from CPR last October, where the research company identified crypto wallet theft on OpenSea, the world's largest NFT marketplace. In November last year, CPR also found that hackers were using search engine phishing campaigns to steal half a million dollars in only a few days.

The company says hackers will continue to set traps, and it shares four safety tips on how to avoid scam coins. 

What scam coins look like

CPR says some tokens contain a 99% buy fee, which will steal all your money at the buying phase. It says some tokens don't allow the buyer to resell, so only the owner can sell. Some tokens contain a 99% sell fee, which will steal all your money at the selling phase. And some allow the owner to create more coins in their wallet and sell them.
 
How it's done - The misconfiguring of smart contracts  

Smart contracts are programs stored on a blockchain, they run when predetermined conditions are met. To create fraudulent tokens, hackers misconfigure these smart contracts. 

CPR outlines the steps that hackers use to take advantage of smart contracts:

  • Leverage scam services: Hackers are usually using scam services to create the contract for them, or they copy an already known scam contract and modify the token name and symbol and some of the function names as well if they are really sophisticated.
  • Manipulate functions: They will then manipulate the functions with the money transfer, prevent you from selling, increase the fee amount, and more. Most manipulations will be when money has been transferred.
  • Create hype via social media: Hackers then open social channels, such as Twitter, Discord, or Telegram, without revealing their identity or using fake identities. They will start hyping the project, so people start buying.
  • "Rug and pull" the money: After they reach the amount of money they want, they pull all the money from the contract and delete all the social media channels.
  • Skip timelocks: You usually won't see those tokens lock a large amount of money in the contract pool or even add timelocks to the contract. Timelocks are generally used to delay administrative actions and are mostly considered a strong indicator of a legitimate project.

 
Tips to avoid scam coins

Having a wallet is the first step to using bitcoins and, by extension, any other cryptocurrency. A key to keeping them safe is diversifying and having a minimum of two different crypto wallets. Use one to store purchases and the others to trade and exchange cryptocurrencies. In this way, they will keep their assets more protected because the wallets also store the passwords of each user. These are a fundamental part of trading cryptocurrencies and having a public key, making it possible for other users to send cryptocurrencies to your wallet. 

Check Point Research says people often search for bitcoin wallet platforms through Google, and this is when they can make one of the biggest mistakes – they click on a Google Ad. Cybercriminals frequently use these links, creating malicious websites, to steal credentials or passwords. It is safer to go to the web pages below the Google Ads. CPR says people typically err on the side of caution, and cybercriminals take advantage of this. Before sending large amounts of crypto, first, send a "test" transaction with a minimum amount to avoid these traps. This way, if the transaction is being sent to a fake wallet, it will be easier to detect the deception and much less will be lost. The company also says activating two-factor authentication is one of the most significant steps that can be taken against any cyberattack. So when an attacker tries to log in, they will receive a message to check their authenticity, preventing them from gaining access. With two-factor authentication, instead of requiring only a password for authentication, logging into an account will require the user to submit a second piece of information, making it more secure.

"Check Point Research is investing significant resources into studying the intersection of cryptocurrencies and security," says Check Point Software head of products, Vulnerabilities Research, Oded Vanunu.

"Last year, we identified the theft of crypto wallets on OpenSea, the world's largest NFT marketplace. And we also alerted crypto wallet users of a massive search engine phishing campaign that resulted in at least half a million dollars being taken in a matter of days. Our latest publication shows what fraud of actual smart contracts looks like and exposes real token fraud in the wild - hiding 100% fees and backdoor functions," he says.

"The implication is that crypto users will continue to fall into these traps and will lose their money. This publication aims to alert the crypto community that scammers are creating fraudulent tokens to steal funds. To avoid scam coins, I recommend crypto users to diversify their wallets, ignore ads and test their transactions."

 

Related stories
Top stories
Story image
Ivanti
Ivanti and Lookout bring zero trust security to hybrid work
Ivanti and Lookout have joined forces to help organisations accelerate cloud adoption and mature their zero trust security posture in the everywhere workplace.
Story image
BeyondTrust
BeyondTrust integrates Password Safe solution with SailPoint
BeyondTrust has announced the integration of BeyondTrust Password Safe with SailPoint identity security offerings.
Story image
SaaS
Absolute Software expands Secure Access product offering
Absolute Software is enhancing its Secure Access product portfolio, enabling minimised risk exposure and optimised user experiences in the hybrid working environment.
Story image
Tech job moves
Tech job moves - Datacom, Micro Focus, SnapLogic and VMware
We round up all job appointments from May 6-12, 2022, in one place to keep you updated with the latest from across the tech industries.
Story image
Cybersecurity
Companies rushing to secure print infrastructure
As the pandemic prioritised communication channels and the shift to remote work, IT departments fell behind in updating the security of print and IT infrastructure.
Story image
Surveillance
Genetec launches new enclosure management system for data centers
Genetec has released a new enclosure management solution that will give data centers the ability to secure, monitor and manage access to racks and cabinets remotely.
Story image
Cryptocurrency
Norton finds deepfakes and crypto scams rising in Australia
Norton says between January and March of this year, it thwarted more than 37,098,261 threats, the equivalent of around 403,241 threats per day.
Story image
Cybersecurity
New precedent for cybersecurity after legal judgement of RI Advice
In an Australian first, the Federal Court has found that RI Advice failed to adequately manage cybersecurity risks.
Story image
Application Security
What are the DDoS attack trend predictions for 2022?
Mitigation and recovery are vital to ensuring brand reputation remains solid in the face of a Distributed Denial of Service (DDoS) attack and that business growth and innovation can continue.
Story image
Application Security
Data Theorem launches "industry first" attack surface management solution
"No solution uses full-stack application runtime analysis and dynamic inventory discovery to support the challenges around vendor management."
Story image
VPN
Palo Alto Networks says ZTNA 1.0 not secure enough
Palo Alto Networks is urging the industry to move to Zero Trust Network Access 2.0 because previous versions have major gaps in security protection.
Story image
Manufacturing
$1 million in cyber skills to stop $100 million in cybercrime
"It is important that the next generation across all industries, including manufacturing, are skilled in cybersecurity."
Story image
Artificial Intelligence
ForgeRock releases Autonomous Access solution powered by AI
ForgeRock has officially introduced ForgeRock Autonomous Access, a new solution that uses AI to prevent identity-based cyber attacks and fraud.
Story image
Cybersecurity
A10 Networks finds over 15 million DDoS weapons in 2021
A10 Networks notes that in the 2H 2021 reporting period, its security research team tracked more than 15.4 million Distributed Denial-of-Service (DDoS) weapons.
Story image
Cybersecurity
CyberArk launches $30M investment fund to advance security
CyberArk has announced the launch of CyberArk Ventures, a $30 million global investment fund dedicated to advancing the next generation of security disruptors.
Story image
Public Cloud
Radware announced launch of CNP spinoff SkyHawk Security
“We recognise the growing opportunities in the public cloud security market and are planning to capitalise on them."
Story image
UiPath
Employee retention increasingly important - automation may help
"Technologies like automation can free workers time, enable a better work-life balance, and create vastly improved efficiencies."
Story image
Malware
Sharp increase in phishing as cybercriminals leverage SEO to lure victims
"Malware lurking everywhere, from cloud apps to search engines, leaving organisations at greater risk than ever before."
Story image
Microsoft
Apple, Google and Microsoft expands plans to get rid of passwords
FIDO Alliance says the world is closer to not relying on passwords after Apple, Google and Microsoft expands their support for a passwordless sign-in standard.
Story image
Forensics
Exterro adds advanced capabilities to digital forensic tool
The launch is in-line with Exterro’s investment in the FTK product line, and underscores the company's commitment to the digital forensics.
Story image
Training
Fortinet training edges toward closing cybersecurity gap
The Fortinet Training Institute has made significant progress in closing the cybersecurity skills gap, on track to train one million people by 2026.
Story image
Secure access service edge / SASE
Versa Networks recognised as SASE leader in Govie Awards
Versa Networks has announced its SASE offering has been recognised in The Govies Government Security Awards competition by Security Today magazine.
Story image
Fortinet
Fortinet sees 34% revenue increase in latest financial results
Fortinet has released its financial results for the first quarter ended March 31, 2022, seeing a total revenue increase of 34.4% compared to the same quarter last year.
Story image
Sift
Sift shares crucial advice for preventing serious ATO breaches
Are you or your business struggling with Account Takeover Fraud (ATO)? One of the latest ebooks from Sift can provide readers with the tools and expertise to help launch them into the new era of account security.
Story image
Training
HubSpot launches 'The Great Upskill' week to inspire learning
Brands across APAC including Google ANZ, MessageMedia, Meltwater, Seismic and Aircall, will give their employees a full workday to dedicate to upskilling.
Story image
Ransomware
Zerto unveils updates to ransomware recovery capabilities
"Organisations face increased risks from the volume and sophistication of ransomware attacks prevalent today."
Story image
Malware
Use of malware, botnets and exploits expands in Q1 2022
"As zero-day attacks and other vulnerabilities among companies like Google and Microsoft come to light, threat actors are quickly adjusting their tactics."
Story image
Appian
Appian awarded billions in damages against Pegasystems Inc.
Appian has been awarded USD$2.036 billion in damages against Pegasystems Inc as the result of a jury verdict in the Circuit Court for Fairfax County, Virginia.
Story image
Cybersecurity
Three key security challenges facing the Australian insurance industry 
Insurance companies must ensure they proactively address security challenges and protect the privacy of customer data.
Story image
Firewall
Sophos named Gartner Peer Insights Customers Choice for network firewalls
The company earned the highest overall customer rating among vendors with at least 150 verified customer reviews.
Story image
Cybersecurity
HackerOne launches Attack Resistance Management solution
HackerOne has launched Attack Resistance Management - a new category of security solution that targets the root causes of the attack resistance gap. 
Story image
Phishing
Google reveals new safety and security measures for users
Google's new measures include automatic two step verification, virtual cards and making it easier to remove contact information on Google Search results.
Story image
Digital Transformation
Physical security systems guide the hybrid workplace to new heights
Organisations are reviewing how data gathered from their physical security systems can optimise, protect and enhance their business operations in unique ways.
Story image
Cybersecurity
Video: 10 Minute IT Jams - An update from IronNet
Michael Ehrlich joins us today to discuss the history of IronNet and the crucial role the company plays in the cyber defence space.
Story image
Tech job moves
Tech job moves - Cisco, Hitachi Vantara, Tricentis & Zscaler
We round up all job appointments from April 28 - May 5, 2022, in one place to keep you updated with the latest from across the tech industries.
Story image
Cybersecurity
New report reveals evolving techniques targeting cloud-native environments
Companies are adopting cloud-native technologies faster than ever before. Unfortunately, with new technology comes new threats and challenges.
Story image
Ransomware
Cybersecurity starts with education
In 2021, 80% of Australian organisations responding to the Sophos State of Ransomware study reported being hit by ransomware. 
Story image
Cybersecurity
ThoughtLab reveals 10 best practices for cybersecurity in 2022
The benchmarking study reveals best practices that can reduce the probability of a material breach and the time it takes to find and respond to those that happen.
Story image
Blue Prism
Blue Prism Desktop uses IA to defend against vulnerabilities
SS&C Blue Prism Desktop aims to help protect businesses against vulnerabilities, using a combination of security measures and intelligent automation tech.
Story image
Ransomware
Anniversaries remind us to review identity risks
World Password Day provides a timely reminder for ordinary citizens and organisations to stop and think about the risks associated with digital identities.
Story image
Mitiga
Mitiga discovers potential hidden dangers in Google Cloud Platform’s (GCP) cloud control plane
The company also says that there is significant risk in cloud development caused by not recognising the differences between cloud and traditional definitions of common architecture terms.
Story image
Ransomware
Ingram Micro Cloud adds Bitdefender solutions to marketplace
Ingram Micro Cloud has announced the expanded availability of Bitdefender solutions on the Ingram Micro Cloud Marketplace.
Story image
Phishing
Developments in phishing and how to protect your business
Phishing, the practice of sending malicious emails to encourage users to perform actions that benefit an attacker, is a key security concern for modern businesses due to its prevalence and impact.
Story image
Cybersecurity
Global bot security market to reach US$2.5 billion by 2032
The global bot security market to reach US$2.5 billion by 2032 driven by a growing need for cyber security, according to a new report.