Wiki
Biturai Trading Wiki
The Biturai crypto encyclopedia: AI-assisted, data-informed, and continuously quality-audited.
Pig-Butchering Scam (Sha Zhu Pan): The Long-Term Trust Trap
The Pig-Butchering Scam, or Sha Zhu Pan, is a sophisticated, long-term investment fraud where perpetrators build deep personal relationships with victims over months. They then manipulate victims into investing in fake cryptocurrency
Evil Twin Wi-Fi Attacks: Crypto Theft via Fake Hotspots
An Evil Twin Wi-Fi attack involves a fraudulent access point mimicking a legitimate one to intercept user data. This deceptive tactic can be exploited by attackers to steal sensitive information, including cryptocurrency credentials, from
IPFS Phishing: Abusing Decentralized Storage for Fraud
IPFS phishing involves attackers hosting malicious websites on the InterPlanetary File System, leveraging its decentralized nature to evade traditional detection and takedown efforts. This method makes it more challenging to identify and
Frontend Hijacking: Compromised dApp Interfaces
Frontend hijacking involves attackers compromising the user interface of a decentralized application to deceive users. This can lead to unauthorized transactions or the theft of digital assets.
BGP Hijacking as an Attack Vector for Crypto Services
BGP hijacking involves the illegitimate redirection of internet traffic by manipulating routing tables. This network-level attack can severely impact crypto services by rerouting user connections or data to malicious destinations.
DNS Hijacking: When Crypto Websites Are Redirected
DNS hijacking is a sophisticated cyberattack where malicious actors manipulate the Domain Name System to redirect users from legitimate websites to fraudulent ones. This often occurs without the user's knowledge, leading them to fake
Typosquatting: The Phishing Trap of Misspelled Domains
Typosquatting is a deceptive cyberattack where criminals register misspelled domain names to trick users into visiting fraudulent websites. This scam aims to steal sensitive information or funds by mimicking legitimate platforms.
Understanding Homograph Attacks: Deceptive URLs with Similar Characters
Homograph attacks exploit visual similarities between characters from different alphabets to create fake URLs that appear legitimate. This sophisticated form of cyber deception can trick users into visiting malicious websites, posing
Whaling: Targeted Phishing Attacks on High-Value Crypto Holders
Whaling is a highly sophisticated form of phishing specifically designed to target wealthy individuals, often in the cryptocurrency space. These attacks are meticulously personalized, aiming to deceive high-net-worth individuals into
Quishing: QR Code Phishing in Crypto
Quishing describes a sophisticated cyberattack where malicious QR codes are used to trick individuals into revealing sensitive information or installing malware. This method bypasses traditional security measures, making it a significant
Fake Browser Extensions: Impersonating Crypto Wallets
Malicious browser extensions mimic legitimate cryptocurrency wallets like MetaMask to steal users' private keys and seed phrases. These fraudulent tools often appear convincing with fake reviews and professional branding, posing a
Ledger Connect Kit Supply Chain Attack Incident
The Ledger Connect Kit, a crucial component for connecting hardware wallets to decentralized applications, was compromised in a sophisticated supply chain attack. This incident led to the theft of user funds by redirecting transactions
Counterfeit Hardware Wallets: Identifying Manipulated Devices
Counterfeit hardware wallets pose a severe threat to cryptocurrency security by mimicking legitimate devices to steal private keys. Users must exercise extreme caution in sourcing and verifying their hardware wallets to prevent
Fake Seed Phrase Lures: How Scammers Empty Wallets with Given-Away Seeds
Fake seed phrase scams trick users into using a recovery phrase controlled by an attacker, granting them full access to the associated crypto wallet. This deceptive tactic is highly effective in draining digital assets from unsuspecting
Seed Phrase Splitting: Dividing Recovery Phrases for Enhanced Security
Seed phrase splitting is a security strategy that divides a cryptocurrency wallet's master recovery phrase into multiple distinct parts. This method enhances security by requiring several parts to be reassembled to regain access to funds,
Metal Seed Phrase Backups: Cryptosteel and Steel Plates
A seed phrase is the master key to your digital assets, providing access to all cryptocurrencies stored in a wallet. Metal backups like Cryptosteel and steel plates offer an unparalleled level of physical durability, safeguarding these
Burner Wallets: Disposable Wallets for Risky dApp Interactions
A burner wallet is a temporary cryptocurrency wallet designed for short-term use, typically holding minimal funds for specific interactions with decentralized applications. It acts as a security measure, isolating your main assets from
Blind Signing: The Dangers of Unverified Crypto Transactions
Blind signing refers to approving a blockchain transaction or smart contract without being able to fully view or verify its actual details. This practice, common in decentralized finance and NFT interactions, exposes users to significant
Eth_sign Phishing: The Danger of Blind Signatures
Eth sign phishing is a sophisticated scam where users unknowingly authorize malicious transactions by signing data they cannot fully understand. This attack vector exploits the trust in seemingly innocuous off-chain messages, leading to
Permit2 Phishing: Exploiting the Uniswap Standard
Permit2 is Uniswap Labs' innovative token approval standard designed to streamline interactions with decentralized applications. However, its reliance on off-chain signatures has been exploited by malicious actors for sophisticated