The Wallet support bot got hacked last night. The attackers used it to send out messages urging people to transfer funds to a specific wallet address in order to double their money.
Naturally, most users responded by reporting the bot. This put a 'scam' tag next to its name, thanks to the messenger's automated mechanisms and algorithms.
Even considering the wallet's USDT and DOGS staking promotions, this offer clearly smelled like a phishing attempt. Thus, the scammers didn't show much creativity to extract funds.
❗️It's important to understand that no legitimate project will offer any promotion or activity by saying "Send funds to this wallet address, and we’ll handle the rest." Make sure you know what you are giving and getting in return. Also carefully check the transaction confirmation before sending to avoid crypto drainers.
The community is saying that the issue was caused by a vulnerability in a third-party plugin used by the devs to handle support requests.
We also know that the attackers managed to obtain ~$7.5K, with $500 coming from @wallet, and the remaining ~$7K from TON Space, Tonkeeper, and others.
Around 10 users were affected, and the developer team will compensate all user losses, both for those who sent from @wallet and from other wallets. However, in the latter case, it may take longer to collect the necessary corroborating data.
The wallet devs have now fixed the vulnerability and restored the bot without the scam tag to its regular working state:
"To reiterate, funds were always completely secure, and only our customer service plug-in was affected." - Wallet News.
It’s good that the damage was minimal and happened at an early stage. Stay alert and keep your assets safe.
Your secured @TonPost
