- Messages
- 87
- Likes
- 10
- Points
- 8
In many cases, attackers gain access to a device or account long before the actual theft of funds. Certain signs can help spot a problem early.
The first warning sign is the appearance of unknown permissions to debit tokens. Perpetual permissions or access granted to unfamiliar smart contracts are particularly dangerous. Users often agree to these when connecting their wallet to the service without carefully examining the details.
The second sign is suspicious signature requests: a series of incomprehensible characters, a lack of a clear transaction description, or a request from a website the user accessed via a link in a messenger or advertisement. Pay particular attention to permit() and setApprovalForAll() requests: they can grant the contract the right to debit tokens without further confirmation.
A third sign is the appearance of unknown transfers, tokens with similar names, or small transfers from other addresses in the transaction history. Such actions may be part of preparation for an address spoofing attack, where scammers hope the user will copy a fake address from the transaction history.
The fourth sign is unexpected requests from a wallet or browser extension to reconnect, restore access, enter a seed phrase, or update the app via a third-party website. Reliable services don't request a secret phrase on unauthorized pages.
The fifth signal is related to the device itself. One common tool used by attackers is clipboard hijacker: malware monitors the clipboard and surreptitiously replaces the copied crypto address with the attacker's. Even using a hardware wallet doesn't guarantee complete protection: the device stores keys securely, but the user can independently confirm a transfer to a spoofed address or a malicious transaction.
Other warning signs include: the appearance of unknown devices in the login history, unexpected notifications about authorization attempts, automatic account logouts, suspicious browser extension activity, and sudden changes to security settings.
If suspicious activity is detected, it's best not to wait for actual loss of funds. In this situation, we recommend transferring your assets to a new wallet created on a trusted device and running a malware scan.
The first warning sign is the appearance of unknown permissions to debit tokens. Perpetual permissions or access granted to unfamiliar smart contracts are particularly dangerous. Users often agree to these when connecting their wallet to the service without carefully examining the details.
The second sign is suspicious signature requests: a series of incomprehensible characters, a lack of a clear transaction description, or a request from a website the user accessed via a link in a messenger or advertisement. Pay particular attention to permit() and setApprovalForAll() requests: they can grant the contract the right to debit tokens without further confirmation.
A third sign is the appearance of unknown transfers, tokens with similar names, or small transfers from other addresses in the transaction history. Such actions may be part of preparation for an address spoofing attack, where scammers hope the user will copy a fake address from the transaction history.
The fourth sign is unexpected requests from a wallet or browser extension to reconnect, restore access, enter a seed phrase, or update the app via a third-party website. Reliable services don't request a secret phrase on unauthorized pages.
The fifth signal is related to the device itself. One common tool used by attackers is clipboard hijacker: malware monitors the clipboard and surreptitiously replaces the copied crypto address with the attacker's. Even using a hardware wallet doesn't guarantee complete protection: the device stores keys securely, but the user can independently confirm a transfer to a spoofed address or a malicious transaction.
Other warning signs include: the appearance of unknown devices in the login history, unexpected notifications about authorization attempts, automatic account logouts, suspicious browser extension activity, and sudden changes to security settings.
However, a crypto wallet compromise doesn't always result in obvious changes to the device or account. Sometimes, attackers gain access to assets through invisible mechanisms related to smart contract permissions. Particularly dangerous are so-called unlimited permissions—permanent granting of rights to a smart contract to manage tokens. In this case, funds can be withdrawn at any time without further confirmation from the wallet owner.
If suspicious activity is detected, it's best not to wait for actual loss of funds. In this situation, we recommend transferring your assets to a new wallet created on a trusted device and running a malware scan.