Several Binance users reported that they had fallen victim to a phishing SMS attack. The scam text appeared in the official message thread of Binance, making it nearly indistinguishable from legitimate communications.
User Reports Binance Scam Incident
A user, Joe Zhou, shared his experience in a LinkedIn post stating, "I want to report a recent scam related to the Bybit and Binance incidents."
Zhou describes receiving an SMS from the same Binance number he usually gets verification codes from. The message claimed that his account was being accessed from North Korea. In the aftermath of a recent Bybit incident, he panicked and called the provided number.
The call was answered by a guide who instructed him on setting up a SafePal wallet, claiming it was a partner of Binance and citing an article to support the claim. This individual continuously inquired about the assets in his account and urged him to transfer all of them for investigation.
Following the instructions, Zhou set up the wallet and began withdrawing funds from Binance. However, he soon became suspicious and contacted an acquaintance from the exchange, who confirmed it was a scam.
The user then attempted to recover his funds by transferring them out of the wallet, but the scammer began competing with him to move the assets. Eventually, Zhou ran out of gas fees. When he tried to exchange ETH for fees, his balance was wiped out.
The attack occurred just days after Bybit was hacked, resulting in nearly $1.5 billion worth of ETH being lost from its cold wallet. Blockchain analysts and the FBI identified the North Korean hacking organization Lazarus Group as likely being the perpetrators.
Sophisticated Phishing Attack
The Chief Information Security Officer (CISO) of SlowMist analyzed the breach, stating that it involved a sophisticated method. He revealed that his friend also received the exact scam message and shared screenshots showing the precise spoofing behavior used.
According to him, one possibility is that the scammer forged the official source through spoofing, using technical methods to manipulate the sender's phone number and inject text messages into official conversations.
Additionally, they may exploit SMS gateway vulnerabilities or conduct supply chain attacks by compromising gateways, targeting operators or third-party providers, or collaborating with SMS providers to spoof official responses, making detection difficult.
Online scams remain a major threat to cryptocurrency users. The security company Blockchain Scam Sniffer reported that such scams have siphoned off $10.25 million from 9,220 victims in January. Although this figure is a 56% decrease from the $23.58 million loss in December, the report notes that scammers are evolving and deploying more sophisticated methods.
