Anul trecut a fost unprecedented for NFTs. From blue-chip collections to celebrities joining in to a huge influx of community members, the space has endured a meteoric rise compared to 12 months ago.
Although that’s brought liquidity to the space, opportunities, and vast potential to grow, it’s also attracted potential scammers. Due to the decentralized nature of the NFT world, many have been left vulnerable to a number of scams. And in many cases, there’s been little anyone can do to counter them.
Scammers are becoming more sophisticated, and every day someone tweets about losing their most prized digital gems. Collectors need to be more cautious than ever. Here’s how.
Țintele principale
The NFT space is still in its experimental stages; many have compared it to the Wild West. There’s no overarching customer support, so you can’t report losses to “the authorities.” Yet the space still generated billions of dollars in 2021. That’s what makes it a perfect breeding ground for scammers.
So-called “blue chip” NFTs are being target the most, perhaps none more frequently than Bored Ape Yacht Club, which now boasts a floor price of 96 ETH. This means a scammer could rake in hundreds of thousands of dollars with a single click. In a space built on a strong sense of community and positivity, it’s still frighteningly easy for anonymous scammers to infiltrate conversations and manipulate holders. AlEste nevoie cu adevărat de o lipsă momentană de judecată.
The blockchain and NFTs provided autonomy, but it also means we’re responsible for our assets—no bank is watching over them for you. Understanding different types of scams will help keep your NFTs safe.
Tipuri de escrocherii
Pagini de mentă false
Often during highly anticipated NFT drops, a number of OpenSea pages pop up, which can make it difficult to verify which is the legitimate collection, especially if the collection isn’t verified. With FOMO percolating and time ticking, many collectors fail to take the extra step of authenticating where the assets are minting from, and they mint the wrong NFT.
Soon after, the illegitimate collection is removed from OpenSea along with that NFT, but the scammers still have the buyer’s money. This recently occured with Punks Comic, where many were tricked into minting from a fake OpenSea page, losing hundreds of dollars.
Pași de făcut
Nu faceți niciodată clic pe linkuri neverificabile.
Verificați de două ori linkul de domeniu-un site web înșelătorie poate fi adesea distins printr-un singur caracter diferit.
Confirm you’re minting the verified link by going to the official collection’s Twitter or Discord first.
Airdrops false
Due to NFTs existing on the blockchain, your wallet address is public to everyone, and so is your every move. This means anyone can interact with your account, and they can send NFTs to your wallet without asking—as in an Airdrop.
Scammers will often send NFTs to your wallet to get you to interact with them and to try to obtain your personal details, so it’s best not to interact with any new NFTs unless you’ve verified their origin.
Impersonarea
Impersonation is perhaps the most malicious scam, and it can entail a variety of methods.
Recently, a Twitter account was brought to my attention that HAD my profile picture, a copy of my bio, had tweeted some identical tweets to my own, and had amassed 5,000 followers. The only difference between my account and the fake one was that the fake one’s username included an extra s: NFTs1nsight instead of NFT1nsight. That account could have easily fooled someone who hadn’t seen my real account.
I can’t be sure how the account was used, or if DMs were sent to potential scam victims, but I can only assume it was created maliciously. Such scams have become increasingly common, with some fake accounts adding thousands of followers to look more real.
Pași de făcut
A avea o mulțime de urmăritori nu înseamnă că un cont este real.
Verificați întotdeauna identificatorii Twitter și cine urmărește contul.
Dacă verificați că este un cont fals, raportați-l pe Twitter.
There are also brand impersonations, where scammers similarly create a profile to offer support to victims of hacks, often on Discord or Twitter.
Legături false
Scammers will send fake OpenSea offers to people’s emails, asking recipients to click the “view” button. Those links often will take you to a fake page asking for your wallet and seed phrase. (Never ever send someone your seed phrase.) Similar scams are rife on Discord. Once a scammer has your info, they’ll transfer all of your assets to another wallet and sell them— și nu există nicio modalitate de a-i opri. Te vei găsi într-o cursă pentru a salva cât mai multe NFT-uri.
Mulți escroci vor vinde NFT-uri la prețuri minime doar pentru a le descărca, iar cumpărătorii suspecti le pot obține pur și simplu în loc să se întrebe cum le-a achiziționat vânzătorul. Uneori, eforturile comunității pot ajuta la contracararea acestui lucru, dar nu întotdeauna.
Impostorul Jenkins: Un studiu de caz
Just recently, the Discord server of the prominent NFT project Jenkins Valetul was compromised by hackers after a moderator shared his screen and they were able to lock down the Discord, banning the mods and the founders themselves. The hackers impersonated Jenkins, which then enabled them to drop a fake mint link to a stealth drop, which many members believed to be legitimate. Not only was the link almost identical to the original site’s, the hackers also created a stage to talk about the mint, banning anyone who questioned the authenticity of what was happening.
Unfortunately, many fell for it, and the community was scammed out of a few dozen ETH.
The lead moderator was tricked by scammers via Discord DMs that accused him of being a scammer himself. In a moment of panic and confusion, he tried to prove his innocence by sharing his messages. He shared his screen, which allowed the scammers to hack his Discord, and take control of the server.
The second issue was that Jenkins did not have full ownership of the server. Because of this, he was banned, which would have been impossible if he had owned the server. Since then, the permissions and ownership have been transferred and control has been regained, which should help prevent future scams.
The Jenkins team reacted decisively in response to the hack, rebooting its Discord from top to bottom, introducing 24/7 moderation via bots, conducting an audit, and compensating everyone who lost ETH in the scam. Jenkins also gave away one Bored Ape Kennel Club NFT as a way to apologize for the unfortunate incident.
A small upside is that the hack means they’re now better equipped to battle future scammers. (You can read more about the timeline of events and the full situation aici.)
Există un hack/scam (ocolește 2fa) pe care escrocii îl folosesc pentru a compromite conturile discord. Dacă sunteți fondator/administrator de proiect, acest lucru este IMPORTANT.
Iată mai multe modalități de a vă păstra bunurile în siguranță:
Asigurați-vă că aveți linkuri verificate înainte de a da clic pe ele-nu faceți niciodată clic pe link-uri aleatorii sau întrerupte trimise din surse necunoscute.
Nu partajați niciodată ecranul dvs.
Înainte de a bate ceva, asigurați-vă că verificați adresa contractului, care ar trebui să specifice unde a fost bătut NFT. Dacă a fost verificat pe OpenSea, ar trebui să fie legitim. Dacă pare prea frumos pentru a fi adevărat, probabil că este.
Nu împărtăși niciodată nimănui fraza ta de recuperare.
Păstrați fraza de bază departe de telefon și computer— păstrează-l offline (“cold storage”), with multiple copies in safe places.
Confirmați întotdeauna că scrieți pe site-ul web verificat.
For many, it’s easier and safer to turn off Discord DMs completely due to bots and scammers abusing them.
Marcați site-uri verificate, cum ar fi OpenSea— ajută la prevenirea aterizării pe pagini false.
Dacă aveți nevoie de asistență, nu vi se va trimite niciodată un DM mai întâi— apelați la site-urile oficiale pentru asistență, nu la rețelele sociale.
Ask trusted friends questions, turn to official teams for answers, and don’t be afraid to ask questions that prioritize your safety and security.
Utilizați autentificarea cu doi factori, un nivel suplimentar de securitate.
Utilizați parole puternice și unice— este înțelept pentru a utiliza o parolă diferită de fiecare dată când creați un cont.
Utilizați un portofel hardware, cum ar fi un Ledger sau Trezor—aceste portofele reci sunt offline, astfel încât nimeni să-l poată accesa în afară de dvs. prin cheia dvs. privată.
DYOR. Before you do anything in the NFT world, make sure to research the collection, the seller, the contract, the link, and other details.
On Securing your NFTs 🔒
Săptămâna aceasta m-am uitat la 5 cazuri diferite în care portofelele au fost compromise și NFT au fost furate de la proprietari.
Îmi rupe inima de fiecare dată când se întâmplă asta, dar tiparele sunt întotdeauna aceleași.
1/ Mai jos sunt câteva reguli după care trebuie să trăiți pentru a rămâne în siguranță 🇧🇷