Nass - nassyweazy.eth, Chief Security Officer of venture capital fund a16z crypto, reveals on Twitter that there is a massive ongoing phishing campaign targeting high profile web3 people.
According to Nass, attackers call the victim and spoof Apple's caller ID (display caller as "Apple, Inc." which is very easy to fake). Then someone very professional pretends they need the recovery pin. Finally, they proceed to lock the victim out of their iCloud, steal all icloud-synced data (photos, videos, keychain passwords, documents, notes..). Once they are in, they ask the victim to pay a ransom or they will share private/sensitive stuff to the public. The hackers also scan through docs / pictures for wallet seed phrases or secrets and empty wallets that way (transferring and selling all the most valuable assets first with clean new addresses).
All Comments