Your BTC can be swiped by spoofers without them even contacting you
Cybersecurity researchers have published fascinating new details of communication-free theft affecting bitcoin (BTC) savers. Purposefully targeting hard-working laborers who dollar cost average (DCA) into BTC with regular purchases, a new attack steals coins without even establishing contact with the victim. Jameson Lopp blogged notes for his MIT Bitcoin Club Expo speech about this tactic that he calls an “address poisoning attack.” A form of spoofing, the exploit manipulates wallet interfaces’ displays and copy-and-pastes defaults. Here’s a step-by-step guide to how the attack works. The bitcoin address poisoning attack First, the attacker identifies someone who is regularly sending BTC to the exact same hardware wallet address for a consistent period of time — usually weeks or months. These might be DCA BTC savers, BTC merchants, or other users who reuse addresses consistently. Next, the attacker utilizes a vanity address creator to create a fake w...