Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

America has been discovered before, but it has always been hushed up. -- Oscar Wilde


tech / sci.math / Re: OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum NFTs

SubjectAuthor
* OT Monkey Drainer Steals $800K in CryptoPunks, Otherside EthereumSergi o
`- Re: OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum NFTsDan joyce

1
OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum NFTs

<tk8jvc$1erk$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/tech/article-flat.php?id=118372&group=sci.math#118372

  copy link   Newsgroups: sci.math
Path: i2pn2.org!i2pn.org!aioe.org!jq9Zon5wYWPEc6MdU7JpBw.user.46.165.242.75.POSTED!not-for-mail
From: inva...@invalid.com (Sergi o)
Newsgroups: sci.math
Subject: OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum
NFTs
Date: Sun, 6 Nov 2022 09:30:51 -0600
Organization: Aioe.org NNTP Server
Message-ID: <tk8jvc$1erk$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="47988"; posting-host="jq9Zon5wYWPEc6MdU7JpBw.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.4.1
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: Sergi o - Sun, 6 Nov 2022 15:30 UTC

Amid a rash of crypto scams that have pilfered millions of dollars’ worth of Ethereum NFTs from unsuspecting users’ wallets, the unknown pseudonymous
entity referred to as “Monkey Drainer” has claimed a fresh cache of valuable CryptoPunks and Otherside NFTs.

Self-described “on-chain sleuth” ZachXBT—a pseudonymous Twitter user with a history of publishing data on crypto scams and controversial figures—shared
Thursday evening that Monkey Drainer had stolen 520 ETH worth of NFTs from those two valuable Yuga Labs collections, which works out to roughly $800,000.

Some of the NFTs were funneled between multiple wallets and ultimately sold. Based on public blockchain data visible through Etherscan, the attacker
then funneled 400 ETH through Tornado Cash, a crypto privacy tool for Ethereum that was sanctioned by the U.S. government in August and cannot legally
be used by citizens.

Monkey Drainer just stole another 7 Crypto Punks and 20 Otherside NFTs worth $800k (520 ETH)

ZachXBT previously estimated that Monkey Drainer had stolen well over $3.5 million worth of crypto and NFTs. Monkey Drainer was also used for an exploit
perpetrated through the hijacked Twitter account of Gabriel Leydon, CEO of Web3 gaming startup Limit Break, on Wednesday.

Web3 security firm Wallet Guard similarly believes Monkey Drainer is a type of malware-as-service, meaning the creator of the “drainer” smart
contract—that is, the code that powers NFTs and decentralized applications—is selling their phishing toolkit to others.

“Monkey sells his drainer for 30% cut of an attack,” ZachXBT tweeted. “So other scammers are coming to him with these accounts.”

Monkey sells his drainer for 30% cut of an attack. So other scammers are coming to him with these accounts

“The attacks are somewhat unsophisticated, and with some proper cyber hygiene, NFT holders can easily protect themselves,” Schwed told Decrypt via
email. “For the scam to work, the NFT holders have to grant the malicious actor access to effectuate a transaction.”

The NFT space has seen a surge in these scams over the course of 2022. Many are shared through hacked social media accounts, which point to what
collectors believe is a legitimate NFT mint or airdrop

claim. Instead, they unwittingly give full access to their wallet holdings to the attacker, and typically have their NFTs and crypto swiped before they
realize it.

Monkey Drainer may be running amok across the Ethereum network for now, but at least one ethical hacker is trying to slow its reign of chaos.

He attacked their API keys!
So one of Monkey's attack moves is

1) Trick you into signing a gasless OS offer that gives him your NFTs for free

2) Broadcast that offer to the ETH blockchain and 'activates' the offer to steal your assets

Re: OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum NFTs

<8a91b420-6eac-4c9a-b126-373a1676dca2n@googlegroups.com>

  copy mid

https://www.novabbs.com/tech/article-flat.php?id=118379&group=sci.math#118379

  copy link   Newsgroups: sci.math
X-Received: by 2002:a05:622a:4889:b0:3a5:18e3:8310 with SMTP id fc9-20020a05622a488900b003a518e38310mr33753868qtb.511.1667751331526;
Sun, 06 Nov 2022 08:15:31 -0800 (PST)
X-Received: by 2002:a05:6808:1294:b0:35a:500d:878c with SMTP id
a20-20020a056808129400b0035a500d878cmr9866525oiw.242.1667751331229; Sun, 06
Nov 2022 08:15:31 -0800 (PST)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: sci.math
Date: Sun, 6 Nov 2022 08:15:31 -0800 (PST)
In-Reply-To: <tk8jvc$1erk$1@gioia.aioe.org>
Injection-Info: google-groups.googlegroups.com; posting-host=32.221.202.28; posting-account=MMV3OwoAAABxhPndZPNv6CW6-fifDabn
NNTP-Posting-Host: 32.221.202.28
References: <tk8jvc$1erk$1@gioia.aioe.org>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <8a91b420-6eac-4c9a-b126-373a1676dca2n@googlegroups.com>
Subject: Re: OT Monkey Drainer Steals $800K in CryptoPunks, Otherside Ethereum NFTs
From: danj4...@gmail.com (Dan joyce)
Injection-Date: Sun, 06 Nov 2022 16:15:31 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Received-Bytes: 4539
 by: Dan joyce - Sun, 6 Nov 2022 16:15 UTC

On Sunday, November 6, 2022 at 10:31:02 AM UTC-5, Sergi o wrote:
> Amid a rash of crypto scams that have pilfered millions of dollars’ worth of Ethereum NFTs from unsuspecting users’ wallets, the unknown pseudonymous
> entity referred to as “Monkey Drainer” has claimed a fresh cache of valuable CryptoPunks and Otherside NFTs.
>
> Self-described “on-chain sleuth” ZachXBT—a pseudonymous Twitter user with a history of publishing data on crypto scams and controversial figures—shared
> Thursday evening that Monkey Drainer had stolen 520 ETH worth of NFTs from those two valuable Yuga Labs collections, which works out to roughly $800,000.
>
> Some of the NFTs were funneled between multiple wallets and ultimately sold. Based on public blockchain data visible through Etherscan, the attacker
> then funneled 400 ETH through Tornado Cash, a crypto privacy tool for Ethereum that was sanctioned by the U.S. government in August and cannot legally
> be used by citizens.
>
> Monkey Drainer just stole another 7 Crypto Punks and 20 Otherside NFTs worth $800k (520 ETH)
>
> ZachXBT previously estimated that Monkey Drainer had stolen well over $3.5 million worth of crypto and NFTs. Monkey Drainer was also used for an exploit
> perpetrated through the hijacked Twitter account of Gabriel Leydon, CEO of Web3 gaming startup Limit Break, on Wednesday.
>
> Web3 security firm Wallet Guard similarly believes Monkey Drainer is a type of malware-as-service, meaning the creator of the “drainer” smart
> contract—that is, the code that powers NFTs and decentralized applications—is selling their phishing toolkit to others.
>
> “Monkey sells his drainer for 30% cut of an attack,” ZachXBT tweeted. “So other scammers are coming to him with these accounts.”
>
> Monkey sells his drainer for 30% cut of an attack. So other scammers are coming to him with these accounts
>
> “The attacks are somewhat unsophisticated, and with some proper cyber hygiene, NFT holders can easily protect themselves,” Schwed told Decrypt via
> email. “For the scam to work, the NFT holders have to grant the malicious actor access to effectuate a transaction.”
>
> The NFT space has seen a surge in these scams over the course of 2022. Many are shared through hacked social media accounts, which point to what
> collectors believe is a legitimate NFT mint or airdrop
>
> claim. Instead, they unwittingly give full access to their wallet holdings to the attacker, and typically have their NFTs and crypto swiped before they
> realize it.
>
> Monkey Drainer may be running amok across the Ethereum network for now, but at least one ethical hacker is trying to slow its reign of chaos.
>
> He attacked their API keys!
> So one of Monkey's attack moves is
>
> 1) Trick you into signing a gasless OS offer that gives him your NFTs for free
>
> 2) Broadcast that offer to the ETH blockchain and 'activates' the offer to steal your assets

And they say crypto currency will take over the dollar.
I can't wait for that!

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor