Binance Square
#phishing

phishing

221,371 views
300 Discussing
Trade GTP
·
--
🚨 A massive $245M Bitcoin heist has ended in a guilty plea, exposing the terrifying power of social engineering. By using sophisticated impersonation and stolen security codes, the hacker drained millions before embarking on a wild laundering spree. This case is a stark reminder that security is only as strong as its weakest human link. Always protect your 2FA, double-verify identities, and trust nothing. Stay safe out there! 🛡️ #Bitcoin #CryptoSecurity #Phishing
🚨 A massive $245M Bitcoin heist has ended in a guilty plea, exposing the terrifying power of social engineering.

By using sophisticated impersonation and stolen security codes, the hacker drained millions before embarking on a wild laundering spree.

This case is a stark reminder that security is only as strong as its weakest human link. Always protect your 2FA, double-verify identities, and trust nothing. Stay safe out there! 🛡️

#Bitcoin #CryptoSecurity #Phishing
🔴 $VTHO ALERT: HACKERS SPREAD PHISHING EMAILS – SECURE YOUR WALLET NOW! 🚨 🦈 Smart money operators are already flagging a breach on Trezor’s email gateway; hackers are flooding inboxes with a “Critical Security Alert” lure. 📊 The phishing wave targets holders of $VTHO and $IOST , exploiting the recent soft‑sell sentiment to harvest assets in a single click. 💡 Immediate mitigation: abort any link or attachment from the alleged Trezor mail, revoke all unknown dApp connections, and rotate your device seed. 📌 A clean inbox is your first line of defense against the liquidity hunt that could otherwise turn your portfolio into a shark‑fed pool. 💬 Have you secured your hardware wallet and audited your dApp permissions? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #VTHO #SecurityAlert #Phishing #CryptoSafety 🛡️ 🔥
🔴 $VTHO ALERT: HACKERS SPREAD PHISHING EMAILS – SECURE YOUR WALLET NOW! 🚨

🦈 Smart money operators are already flagging a breach on Trezor’s email gateway; hackers are flooding inboxes with a “Critical Security Alert” lure. 📊 The phishing wave targets holders of $VTHO and $IOST , exploiting the recent soft‑sell sentiment to harvest assets in a single click.

💡 Immediate mitigation: abort any link or attachment from the alleged Trezor mail, revoke all unknown dApp connections, and rotate your device seed. 📌 A clean inbox is your first line of defense against the liquidity hunt that could otherwise turn your portfolio into a shark‑fed pool.

💬 Have you secured your hardware wallet and audited your dApp permissions? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #VTHO #SecurityAlert #Phishing #CryptoSafety

🛡️ 🔥
🚨 $TRZ HACK ALERT: PHISHING EMAILS SWARMING USERS! ⚠️ Trezor just confirmed a third‑party email provider breach—phishers are now blasting fake Trezor messages. 🛡️ The fake domains have been ripped down, but the inbox flood is still active, so every click is a potential trap. Remember, the hardware itself, private keys, and backups remain untouched, but the personal data leak from the August ShipMonk incident still haunts 13k+ users. 📊 Treat any unsolicited link as hostile, verify through official channels, and consider a fresh address for future communications. 🔍 💬 Are you double‑checking every Trezor email before you tap? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #TRZ #Security #Phishing #Crypto 🚀 🔥
🚨 $TRZ HACK ALERT: PHISHING EMAILS SWARMING USERS! ⚠️

Trezor just confirmed a third‑party email provider breach—phishers are now blasting fake Trezor messages. 🛡️ The fake domains have been ripped down, but the inbox flood is still active, so every click is a potential trap.

Remember, the hardware itself, private keys, and backups remain untouched, but the personal data leak from the August ShipMonk incident still haunts 13k+ users. 📊 Treat any unsolicited link as hostile, verify through official channels, and consider a fresh address for future communications. 🔍

💬 Are you double‑checking every Trezor email before you tap? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #TRZ #Security #Phishing #Crypto

🚀 🔥
​🛡️ Incident in Trezor: ​Technical details: This phishing campaign does not compromise the Secure Element or the cryptography of Trezor physical devices. The attack vector focuses on social engineering and domain spoofing, imitating firmware update interfaces or web interfaces (such as Trezor Suite) to trick the user into revealing their seed phrase or connecting malicious signatures. Remember: no legitimate wallet will ever ask you for your seed over the internet. ​🚨 ​"Don't put your assets at risk due to a mistake! Click 'Continue' to receive real-time security technical alerts, support this analysis with a tip, and share your opinion to help keep the community safe." ​#BinanceSquare ​#ciberseguridad ​#Phishing ​$BTC {spot}(BTCUSDT) ​$ETH {spot}(ETHUSDT) ​$BNB {spot}(BNBUSDT)
​🛡️ Incident in Trezor:
​Technical details: This phishing campaign does not compromise the Secure Element or the cryptography of Trezor physical devices. The attack vector focuses on social engineering and domain spoofing, imitating firmware update interfaces or web interfaces (such as Trezor Suite) to trick the user into revealing their seed phrase or connecting malicious signatures. Remember: no legitimate wallet will ever ask you for your seed over the internet.
​🚨
​"Don't put your assets at risk due to a mistake! Click 'Continue' to receive real-time security technical alerts, support this analysis with a tip, and share your opinion to help keep the community safe."
#BinanceSquare
#ciberseguridad
#Phishing
$BTC

$ETH

$BNB
everyone thinks those "complete the security check" screens are just keeping bots out but actually a lot of them are phishing pages that look official and still catch people every week. you rush a popup mid-trade because you don't want to miss the next candle and next thing your account is getting drained. ngl that fake verify screen is how a lot of people lose the bag they spent months stacking. last week a trader i know clicked one after a $BTC spike. same layout, same wording about verifying you are not a bot to protect your account and prevent spam. he typed everything in. eight minutes later they swept 4.2 $BTC plus his $ETH and $BNB. he only noticed when the withdrawals already went through. if you did not start that login yourself from the official app, that check is not protecting you. close the tab and open the app directly. anyone else almost fallen for one of these lately? #cryptosecurity #phishing #BNB
everyone thinks those "complete the security check" screens are just keeping bots out but actually a lot of them are phishing pages that look official and still catch people every week.

you rush a popup mid-trade because you don't want to miss the next candle and next thing your account is getting drained. ngl that fake verify screen is how a lot of people lose the bag they spent months stacking.

last week a trader i know clicked one after a $BTC spike. same layout, same wording about verifying you are not a bot to protect your account and prevent spam. he typed everything in. eight minutes later they swept 4.2 $BTC plus his $ETH and $BNB . he only noticed when the withdrawals already went through.

if you did not start that login yourself from the official app, that check is not protecting you. close the tab and open the app directly.

anyone else almost fallen for one of these lately?
#cryptosecurity #phishing #BNB
** **Third-party provider filtering generates phishing emails from Tre's legitimate domain — Analysis by EmeDotEme #EmeDotEme #Ciberseguridad #Phishing
**

**Third-party provider filtering generates phishing emails from Tre's legitimate domain

— Analysis by EmeDotEme
#EmeDotEme #Ciberseguridad #Phishing
Anti-Phishing Code: Set it up in one minute to block all fake emails. Every incident where a “fake email” tricks away half your position was missing this setting. Anti-Phishing Code: After setting it up, every official email sent by Binance will include your unique code. Any “official email” without this code is fake—verification code emails are the same. · Keep the code unpredictable; don’t use birthdays. Set it in the App Security Center in 1 minute. Codes set in 2021 can be spotted as spam at a glance today. #AccountSecurity #Phishing $BNB
Anti-Phishing Code: Set it up in one minute to block all fake emails.
Every incident where a “fake email” tricks away half your position was missing this setting.
Anti-Phishing Code: After setting it up, every official email sent by Binance will include your unique code. Any “official email” without this code is fake—verification code emails are the same.
· Keep the code unpredictable; don’t use birthdays. Set it in the App Security Center in 1 minute.
Codes set in 2021 can be spotted as spam at a glance today.
#AccountSecurity #Phishing $BNB
Security alert: Musk’s X reportedly sent a wave of unsolicited password reset emails; there’s no evidence of a breach yet. Crypto folks—don’t click suspicious links, verify via official channels, and enable 2FA to protect your wallets. Stay vigilant. #Security #Phishing $BTC
Security alert: Musk’s X reportedly sent a wave of unsolicited password reset emails; there’s no evidence of a breach yet. Crypto folks—don’t click suspicious links, verify via official channels, and enable 2FA to protect your wallets. Stay vigilant. #Security #Phishing $BTC
Article
🚫ALERT: The Hidden “Price” of Airdrops and Faucets Nobody Tells You About🚨 ALERT: The Hidden “Price” of Airdrops and Faucets Nobody Tells You About Have you ever stopped to calculate how much your hour is worth? If you spend 2 hours on faucet sites or clicking tasks to earn just $0.10 in crypto, you’re devaluing your time and, worse, putting your security at risk with malicious links. 3 Golden Rules for Anyone Looking for Opportunities Without Investment: 1️⃣ The Phantom Wallet Rule: Never connect your main wallet (where your BTC, ETH, or savings are) to unknown airdrop or bounty sites. Use a secondary wallet (burner wallet) created specifically for that.

🚫ALERT: The Hidden “Price” of Airdrops and Faucets Nobody Tells You About

🚨 ALERT: The Hidden “Price” of Airdrops and Faucets Nobody Tells You About
Have you ever stopped to calculate how much your hour is worth?
If you spend 2 hours on faucet sites or clicking tasks to earn just $0.10 in crypto, you’re devaluing your time and, worse, putting your security at risk with malicious links.
3 Golden Rules for Anyone Looking for Opportunities Without Investment:
1️⃣ The Phantom Wallet Rule: Never connect your main wallet (where your BTC, ETH, or savings are) to unknown airdrop or bounty sites. Use a secondary wallet (burner wallet) created specifically for that.
Stay sharp or get rekt. Phishing is getting predatory. A new campaign is targeting nearly 900k phone numbers to bait users into fake wallet sites. One wrong tap and your bags are gone. Be extremely careful with any SMS links. #Security #Phishing ‎
Stay sharp or get rekt.

Phishing is getting predatory. A new campaign is targeting nearly 900k phone numbers to bait users into fake wallet sites. One wrong tap and your bags are gone. Be extremely careful with any SMS links.

#Security #Phishing
3 wallet and exchange vendors disclosed data breaches in one week — and not one of them lost a single coin or private key. What happened: SafePal confirmed August 16 that a third-party order-tracking plug-in exposed names, emails, and purchase details for roughly 39,798 customers. The same day, Bits of Gold, Israel's largest regulated crypto broker, disclosed a separate vendor breach reportedly affecting around 200,000 customers. Both land three days after Trezor disclosed its fulfillment partner ShipMonk exposed roughly 14,000 customers. Why it matters: no seed phrases, private keys, or funds were touched in any of the three. But leaked names, emails, and proof of which hardware wallet you own is exactly the targeting data used for convincing "fake support" phishing later — the same playbook that followed Ledger's 2020 breach for years. None of these three companies were breached directly; their vendors were. The nuance: Bits of Gold hasn't officially confirmed the 200,000 figure yet — that number is reported, not company-stated. And this is a phishing-setup story, not a theft story, so don't read it as "funds at risk today." The real risk shows up weeks or months later, in a targeted email that already knows your name and your wallet brand. If you've ever bought a hardware wallet, would you know if your shipping data leaked? Not financial advice. DYOR. $BTC #CryptoSecurity #DataBreach #SelfCustody #Phishing
3 wallet and exchange vendors disclosed data breaches in one week — and not one of them lost a single coin or private key.

What happened: SafePal confirmed August 16 that a third-party order-tracking plug-in exposed names, emails, and purchase details for roughly 39,798 customers. The same day, Bits of Gold, Israel's largest regulated crypto broker, disclosed a separate vendor breach reportedly affecting around 200,000 customers. Both land three days after Trezor disclosed its fulfillment partner ShipMonk exposed roughly 14,000 customers.

Why it matters: no seed phrases, private keys, or funds were touched in any of the three. But leaked names, emails, and proof of which hardware wallet you own is exactly the targeting data used for convincing "fake support" phishing later — the same playbook that followed Ledger's 2020 breach for years. None of these three companies were breached directly; their vendors were.

The nuance: Bits of Gold hasn't officially confirmed the 200,000 figure yet — that number is reported, not company-stated. And this is a phishing-setup story, not a theft story, so don't read it as "funds at risk today." The real risk shows up weeks or months later, in a targeted email that already knows your name and your wallet brand.

If you've ever bought a hardware wallet, would you know if your shipping data leaked?

Not financial advice. DYOR.

$BTC #CryptoSecurity #DataBreach #SelfCustody #Phishing
$BTC SELF-CUSTODY ALERT: TREZOR PII LEAK UNMASKS 13K USERS 🎯 The latest breach isn't on-chain, it's in the physical layer. Trezor's logistics partner, ShipMonk, leaked order data for 13,689 users—names, addresses, and emails. The devices and private keys remain untouched, but the institutional playbook here is clear: the real target is the human behind the wallet. 🎯 This is a classic liquidity hunt via social engineering. Trezor warns of phishing emails and even physical mail spoofing. The Ledger precedent saw 272k users exposed in 2020, followed by extortion. Physical attacks on holders are up 33% YoY, with over $30M siphoned via these methods. 🔐 Meanwhile, 233k BTC exited long-term wallets amid Coldcard firmware fears, showing a flight to multi-sig. Trezor's response? Anonymous delivery rollouts. Do you trust the logistics layer, or is your OPSEC the final frontier? 🧠 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ $BTC #HardwareWallet #CryptoSecurity #SelfCustody #Phishing 👀💡
$BTC SELF-CUSTODY ALERT: TREZOR PII LEAK UNMASKS 13K USERS 🎯

The latest breach isn't on-chain, it's in the physical layer. Trezor's logistics partner, ShipMonk, leaked order data for 13,689 users—names, addresses, and emails. The devices and private keys remain untouched, but the institutional playbook here is clear: the real target is the human behind the wallet. 🎯

This is a classic liquidity hunt via social engineering. Trezor warns of phishing emails and even physical mail spoofing. The Ledger precedent saw 272k users exposed in 2020, followed by extortion. Physical attacks on holders are up 33% YoY, with over $30M siphoned via these methods. 🔐

Meanwhile, 233k BTC exited long-term wallets amid Coldcard firmware fears, showing a flight to multi-sig. Trezor's response? Anonymous delivery rollouts. Do you trust the logistics layer, or is your OPSEC the final frontier? 🧠

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ $BTC #HardwareWallet #CryptoSecurity #SelfCustody #Phishing

👀💡
🚨 WEB3 SECURITY ALERT: Phishing signatures can drain your wallet in seconds Crypto theft has evolved. Scammers no longer need your 12 seed words; they now use scripts called Crypto Drainers designed to trick you with off-chain signatures that can leave you empty with just one click. 🛑💼 How the invisible trap works: * Gasless Signatures (Permit/Permit2): Designed to save fees, these are exploited by fake sites. When they ask you to "sign to connect your wallet or claim an airdrop," you are actually signing an unlimited withdrawal permission. * Deferred Execution: The attacker saves your digital signature and can execute the theft days or weeks later, making you believe initially that the site was secure. * Affects tokens and NFTs: A single malicious signature can authorize the complete draining of your stablecoins (USDT/USDC) or entire collections. 🔒 How to protect yourself today: 1. Read before you sign: If your wallet window shows terms like Permit, Permit2, or Approve on a suspicious site, cancel immediately. 2. Use burner wallets: Never connect your main savings wallet to reward claim sites or new dApps. 3. Audit your accesses: Periodically check tools like Revoke.cash or the ScamSniffer dashboard to revoke old or unlimited permissions. Your signature on the blockchain is final and irreversible. Keep your OpSec at maximum level! 🛡️ What tools do you use to verify the security of your dApps before interacting with them? I'm listening below! 👇 #CryptoSecurity #WalletDrainer #phishing
🚨 WEB3 SECURITY ALERT: Phishing signatures can drain your wallet in seconds
Crypto theft has evolved. Scammers no longer need your 12 seed words; they now use scripts called Crypto Drainers designed to trick you with off-chain signatures that can leave you empty with just one click. 🛑💼
How the invisible trap works:
* Gasless Signatures (Permit/Permit2): Designed to save fees, these are exploited by fake sites. When they ask you to "sign to connect your wallet or claim an airdrop," you are actually signing an unlimited withdrawal permission.
* Deferred Execution: The attacker saves your digital signature and can execute the theft days or weeks later, making you believe initially that the site was secure.
* Affects tokens and NFTs: A single malicious signature can authorize the complete draining of your stablecoins (USDT/USDC) or entire collections.
🔒 How to protect yourself today:
1. Read before you sign: If your wallet window shows terms like Permit, Permit2, or Approve on a suspicious site, cancel immediately.
2. Use burner wallets: Never connect your main savings wallet to reward claim sites or new dApps.
3. Audit your accesses: Periodically check tools like Revoke.cash or the ScamSniffer dashboard to revoke old or unlimited permissions.
Your signature on the blockchain is final and irreversible. Keep your OpSec at maximum level! 🛡️ What tools do you use to verify the security of your dApps before interacting with them? I'm listening below! 👇
#CryptoSecurity #WalletDrainer #phishing
$NOXA X ACCOUNT HACKED - DO NOT INTERACT WITH ANY LINKS 🚨 Onchain Lens just flagged the official Noxa X account as compromised. Community members got their wallets drained after clicking links posted by the account. This is live — attackers are actively posting malicious links. Do not connect your wallet, sign anything, or interact with any links from that account until further notice. Have you already interacted with any recent posts from the Noxa X account? Not financial advice. Always manage your risk. #NOXA #SecurityAlert #CryptoAlert #Phishing ⚡
$NOXA X ACCOUNT HACKED - DO NOT INTERACT WITH ANY LINKS 🚨

Onchain Lens just flagged the official Noxa X account as compromised. Community members got their wallets drained after clicking links posted by the account.

This is live — attackers are actively posting malicious links. Do not connect your wallet, sign anything, or interact with any links from that account until further notice.

Have you already interacted with any recent posts from the Noxa X account?

Not financial advice. Always manage your risk.

#NOXA #SecurityAlert #CryptoAlert #Phishing

$1 MILLION SCAM ALERT: Phishing Attack Drains Massive USDT on Ethereum! Breaking news just 16 seconds ago from Cointelegraph! A crypto user has tragically lost nearly $1,000,000 in $USDT after mistakenly signing a malicious phishing token approval on the Ethereum network. This devastating loss is a harsh and painful reminder for the entire web3 community: always double-check every smart contract interaction and never blindly sign token approvals. Security must always come first! How often do you check and revoke your wallet's token approvals to stay safe from phishing? Stay safe out there! #USDT #Ethereum #phishing #WriteToEarn
$1 MILLION SCAM ALERT: Phishing Attack Drains Massive USDT on Ethereum!

Breaking news just 16 seconds ago from Cointelegraph! A crypto user has tragically lost nearly $1,000,000 in $USDT after mistakenly signing a malicious phishing token approval on the Ethereum network.
This devastating loss is a harsh and painful reminder for the entire web3 community: always double-check every smart contract interaction and never blindly sign token approvals. Security must always come first!
How often do you check and revoke your wallet's token approvals to stay safe from phishing? Stay safe out there!
#USDT #Ethereum #phishing #WriteToEarn
Article
How to protect yourself from phishing and impersonation attacks?Phishing is the most common way to steal cryptocurrencies They don't need to hack Binance or break the blockchain They trick you into giving your data!! In this article, I'll teach you how to recognize and avoid these scams What is phishing? It's a scam where criminals impersonate a legitimate company Binance technical support, a friend, or even a family member They send you a message or email with a fake link If you enter and provide your details, they capture them Most common types of phishing Email phishing

How to protect yourself from phishing and impersonation attacks?

Phishing is the most common way to steal cryptocurrencies
They don't need to hack Binance or break the blockchain
They trick you into giving your data!!
In this article, I'll teach you how to recognize and avoid these scams
What is phishing?
It's a scam where criminals impersonate a legitimate company
Binance technical support, a friend, or even a family member
They send you a message or email with a fake link
If you enter and provide your details, they capture them
Most common types of phishing
Email phishing
$NOXA X ACCOUNT HACKED – WALLETS DRAINED, AVOID ALL LINKS ⚠️ Onchain Lens monitoring confirms the official X account of Meme token launch platform Noxa has been compromised. Community users who interacted with posted links have already reported drained wallets. The attack is live — do not connect your wallet, sign any transactions, or click any links from this account. This isn't a market move, it's a security threat targeting liquidity directly. Have you checked the recent activity in your connected wallets? Not financial advice. Always manage your risk. #NOXA #SecurityAlert #Phishing #CryptoSafety ⚡
$NOXA X ACCOUNT HACKED – WALLETS DRAINED, AVOID ALL LINKS ⚠️

Onchain Lens monitoring confirms the official X account of Meme token launch platform Noxa has been compromised. Community users who interacted with posted links have already reported drained wallets. The attack is live — do not connect your wallet, sign any transactions, or click any links from this account.

This isn't a market move, it's a security threat targeting liquidity directly. Have you checked the recent activity in your connected wallets?

Not financial advice. Always manage your risk.

#NOXA #SecurityAlert #Phishing #CryptoSafety

·
--
⚠️ P2P Alert! Watch out for the "account blocked" scam method and spam emails #phishing #P2P #estafas Community, I want to share a scam attempt that happened to me recently in P2P so you can stay very alert and not fall into the trap. 📍 How does this deception work? - You open a sell order. - The other party writes to you in chat saying they "can't transfer" because supposedly your receiving account (e.g., Zinli or a bank) is blocked. - They insist that you check your Spam folder in your email. - In Spam, you find a fake email (posing as support for the payment method) that includes a link to "unlock" the account. - That link takes you to a fake page that tries to steal your access data or Google/email verification codes. 💡 Always remember: - Official platforms will never ask you to unlock an account via a link in Spam. - Do not release crypto or click on suspicious links without verifying the sender's authenticity. - Report the order immediately through Binance's official support channels. Take care of our funds and always operate with caution! 🛡️
⚠️ P2P Alert! Watch out for the "account blocked" scam method and spam emails
#phishing #P2P #estafas
Community, I want to share a scam attempt that happened to me recently in P2P so you can stay very alert and not fall into the trap.
📍 How does this deception work?
- You open a sell order.
- The other party writes to you in chat saying they "can't transfer" because supposedly your receiving account (e.g., Zinli or a bank) is blocked.
- They insist that you check your Spam folder in your email.
- In Spam, you find a fake email (posing as support for the payment method) that includes a link to "unlock" the account.
- That link takes you to a fake page that tries to steal your access data or Google/email verification codes.

💡 Always remember:
- Official platforms will never ask you to unlock an account via a link in Spam.
- Do not release crypto or click on suspicious links without verifying the sender's authenticity.
- Report the order immediately through Binance's official support channels.

Take care of our funds and always operate with caution! 🛡️
$ETH ONE WRONG APPROVAL COST A TRADER NEARLY $1 MILLION 🚨 A wallet holder lost close to $1M in USDT after unknowingly signing a malicious contract on Ethereum. The blockchain wasn't compromised — the user approved a scam transaction. This isn't a hack of the network. It's a reminder that the weakest link is often between the screen and the chair. Always double-check the contract you're approving and never sign anything you don't fully understand. How do you verify your transaction approvals before signing? Not financial advice. Always manage your risk. #ETH #CryptoSecurity #Phishing #Ethereum 💎
$ETH ONE WRONG APPROVAL COST A TRADER NEARLY $1 MILLION 🚨

A wallet holder lost close to $1M in USDT after unknowingly signing a malicious contract on Ethereum. The blockchain wasn't compromised — the user approved a scam transaction.

This isn't a hack of the network. It's a reminder that the weakest link is often between the screen and the chair. Always double-check the contract you're approving and never sign anything you don't fully understand.

How do you verify your transaction approvals before signing?

Not financial advice. Always manage your risk.

#ETH #CryptoSecurity #Phishing #Ethereum

💎
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number