Several Binance users reported that they became victims of a SMS phishing attack. The scam text appeared in the official message thread of Binance, making it nearly indistinguishable from legitimate communications.
User Reports Binance Scam Incident
A user, Joe Zhou, shared his experience in a LinkedIn post stating: 'I want to report a recent scam related to the Bybit and Binance incident.'
Zhou described receiving an SMS from the same Binance number he usually receives verification codes from. The message claimed that his account was being accessed from North Korea. Dealing with the fallout from the recent Bybit incident, he panicked and called the provided number.
The call was answered by a guide who instructed him to set up a SafePal wallet, claiming it was a partner of Binance and citing an article to support the assertion. This individual continually inquired about the assets in his account and urged him to transfer all of them for investigation.
Following the instructions, Zhou set up the wallet and began withdrawing funds from Binance. However, he soon became suspicious and contacted an acquaintance from the exchange, who confirmed it was a scam.
The user then attempted to recover his funds by transferring them out of the wallet, but the scammer began competing with him to move the assets. Ultimately, Zhou ran out of gas fees. When he tried to swap ETH for fees, his balance was wiped out.
The attack occurred just days after Bybit was hacked, leading to the loss of nearly $1.5 billion worth of ETH from its cold wallet. Blockchain analysts and the FBI have identified the North Korean hacking organization Lazarus Group as likely being the perpetrators.
Sophisticated Phishing Attack
The Chief Information Security Officer (CISO) of SlowMist analyzed the breach, stating that it involved a sophisticated method. He revealed that his friend also received an identical scam message and shared screenshots showing the exact spoofing behavior used.
According to him, one possibility is that the scammer forged the official source through spoofing, using technical methods to manipulate the sender's phone number and embed the text message into official conversations.
Additionally, they may exploit SMS gateway vulnerabilities or conduct supply chain attacks by compromising gateways, targeting operators or third-party providers, or collaborating with SMS providers to forge official responses, making detection difficult.
Online scams remain a significant threat to cryptocurrency users. Blockchain security company Scam Sniffer reported that such scams siphoned off $10.25 million from 9,220 victims in January. Although this figure represents a 56% decrease from the December loss of $23.58 million, the report notes that scammers are evolving and deploying more sophisticated methods.
