{"id":60520,"date":"2022-04-22T16:25:16","date_gmt":"2022-04-22T13:25:16","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=60520"},"modified":"2025-09-05T03:45:49","modified_gmt":"2025-09-05T00:45:49","slug":"terra-users-lose-over-4-million-in-phishing-attack","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/terra-users-lose-over-4-million-in-phishing-attack\/","title":{"rendered":"Terra users lose over $4 million in phishing attack"},"content":{"rendered":"<p>From April 12 to 21, dozens of Terra network users fell victim to a phishing attack. Crypto assets worth $4.31 million were transferred to the attacker\u2019s address, according to SlowMist researchers.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">According to the SlowMist intelligence zone, numerous users on the Terra network had their funds stolen recently.<\/p>\n<p>From 4\/12 to 4\/21, close to $4.31 million in assets were maliciously transferred to terra1fz57nt6t3nnxel6q77wsmxxdesn7rgy0h27x3 from about 52 different addresses.<\/p>\n<p>\u2014 SlowMist (@SlowMist_Team) <a href=\"https:\/\/twitter.com\/SlowMist_Team\/status\/1516961951032692736?ref_src=twsrc%5Etfw\">April 21, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The attacker used phishing ads on Google. According to the firm&#8217;s analysts, the plan was that users would search for well-known Terra ecosystem projects such as Anchor or Astroport.<\/p>\n<p>The search results in the top lines resembled a real site. In some cases, even a correct domain name was shown, but it changed after following the link.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">Our security team conducted an analysis of this incident and discovered that the bulk of this attack was from google phishing ads. Users would search well know projects on the Terra blockchain such as <a href=\"https:\/\/twitter.com\/anchor_protocol?ref_src=twsrc%5Etfw\">@anchor_protocol<\/a> or <a href=\"https:\/\/twitter.com\/astroport_fi?ref_src=twsrc%5Etfw\">@astroport_fi<\/a> only to click on the first link by google. <a href=\"https:\/\/t.co\/aucIcnsCd7\">pic.twitter.com\/aucIcnsCd7<\/a><\/p>\n<p>\u2014 SlowMist (@SlowMist_Team) <a href=\"https:\/\/twitter.com\/SlowMist_Team\/status\/1516962155211407360?ref_src=twsrc%5Etfw\">April 21, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>In the opened window, victims were prompted to connect their wallet and enter their seed phrase. This allowed unauthorized withdrawal of assets.<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">These may look like normal ads and some even show the same domain names, but once you click on the link, the domain name actually changes. When clicked, it&#8221;ll prompt you to connect your wallet, however instead of connecting, users are asked to input their seed phrase. <a href=\"https:\/\/t.co\/OZjifaJ17m\">pic.twitter.com\/OZjifaJ17m<\/a><\/p>\n<p>\u2014 SlowMist (@SlowMist_Team) <a href=\"https:\/\/twitter.com\/SlowMist_Team\/status\/1516962344055808001?ref_src=twsrc%5Etfw\">April 21, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>SlowMist specialists recommended Terra users not to click on Google ads or links to dubious resources.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cThis should help reduce the likelihood of becoming a phishing victim,\u201d they emphasised.\u00a0<\/p>\n<\/blockquote>\n<p>Within ten days, funds were received by the attacker\u2019s wallet from 54 different addresses.<\/p>\n<p>The non-custodial wallet MetaMask <a href=\"https:\/\/u1f987.com\/en\/news\/metamask-warns-apple-users-of-risk-to-funds-from-icloud-backups\">warned users<\/a> about the risks of storing data in Apple iCloud due to possible phishing attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From April 12 to 21, dozens of Terra network users were victims of a phishing attack. Crypto assets worth $4.31 million were transferred to the attacker\u2019s address, according to SlowMist researchers.<\/p>\n","protected":false},"author":1,"featured_media":60521,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"Dozens of Terra users were phished, with $4.31 million stolen.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,852],"class_list":["post-60520","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-terra"],"aioseo_notices":[],"amp_enabled":true,"views":"18","promo_type":"1","layout_type":"1","short_excerpt":"Dozens of Terra users were phished, with $4.31 million stolen.","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/60520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=60520"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/60520\/revisions"}],"predecessor-version":[{"id":60522,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/60520\/revisions\/60522"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/60521"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=60520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=60520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=60520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}