Wiki
Biturai Trading Wiki
The Biturai crypto encyclopedia: AI-assisted, data-informed, and continuously quality-audited.
Evil Twin Wi-Fi Attacks: Crypto Theft via Fake Hotspots
An Evil Twin Wi-Fi attack involves a fraudulent access point mimicking a legitimate one to intercept user data. This deceptive tactic can be exploited by attackers to steal sensitive information, including cryptocurrency credentials, from
IPFS Phishing: Abusing Decentralized Storage for Fraud
IPFS phishing involves attackers hosting malicious websites on the InterPlanetary File System, leveraging its decentralized nature to evade traditional detection and takedown efforts. This method makes it more challenging to identify and
Frontend Hijacking: Compromised dApp Interfaces
Frontend hijacking involves attackers compromising the user interface of a decentralized application to deceive users. This can lead to unauthorized transactions or the theft of digital assets.
BGP Hijacking as an Attack Vector for Crypto Services
BGP hijacking involves the illegitimate redirection of internet traffic by manipulating routing tables. This network-level attack can severely impact crypto services by rerouting user connections or data to malicious destinations.
DNS Hijacking: When Crypto Websites Are Redirected
DNS hijacking is a sophisticated cyberattack where malicious actors manipulate the Domain Name System to redirect users from legitimate websites to fraudulent ones. This often occurs without the user's knowledge, leading them to fake
Phishing Through Paid Search Ads: Fake Google Ads
Fake Google Ads are a sophisticated phishing tactic where scammers use paid advertisements to trick users into visiting malicious websites. These deceptive ads mimic legitimate platforms, primarily targeting cryptocurrency users searching
Punycode Attacks: Recognizing Deceptive Domains
Punycode attacks exploit a web standard designed for international domain names to create visually identical but malicious URLs. Understanding these homograph attacks is essential for protecting against sophisticated phishing attempts.
Typosquatting: The Phishing Trap of Misspelled Domains
Typosquatting is a deceptive cyberattack where criminals register misspelled domain names to trick users into visiting fraudulent websites. This scam aims to steal sensitive information or funds by mimicking legitimate platforms.
Understanding Homograph Attacks: Deceptive URLs with Similar Characters
Homograph attacks exploit visual similarities between characters from different alphabets to create fake URLs that appear legitimate. This sophisticated form of cyber deception can trick users into visiting malicious websites, posing
Fake Support Scams: Impersonating Customer Service as a Lure
Fake support scams involve fraudsters impersonating legitimate customer service to trick individuals into revealing sensitive information or transferring digital assets. These deceptive tactics often lead to significant financial losses
Angler Phishing: Social Media Support Scams
Angler phishing is a sophisticated social engineering attack where malicious actors impersonate legitimate customer support on social media platforms. They aim to trick users into revealing sensitive information or clicking malicious links
Whaling: Targeted Phishing Attacks on High-Value Crypto Holders
Whaling is a highly sophisticated form of phishing specifically designed to target wealthy individuals, often in the cryptocurrency space. These attacks are meticulously personalized, aiming to deceive high-net-worth individuals into
Vishing: Voice Phishing Attacks on Crypto Users
Vishing, or voice phishing, is a social engineering tactic where attackers use phone calls to trick individuals into revealing sensitive information. These scams often impersonate trusted entities to manipulate victims into actions like
Quishing: QR Code Phishing in Crypto
Quishing describes a sophisticated cyberattack where malicious QR codes are used to trick individuals into revealing sensitive information or installing malware. This method bypasses traditional security measures, making it a significant
Recognizing Malicious Approvals in Fake dApps
Malicious approvals occur when users unknowingly grant harmful decentralized applications excessive permissions to their digital assets. This often leads to unauthorized access and potential loss of funds from their cryptocurrency wallets.
Fake Browser Extensions: Impersonating Crypto Wallets
Malicious browser extensions mimic legitimate cryptocurrency wallets like MetaMask to steal users' private keys and seed phrases. These fraudulent tools often appear convincing with fake reviews and professional branding, posing a
Pre-installed Seed Phrase Scam in Used Wallets
The pre-installed seed phrase scam involves attackers providing a recovery phrase they control with a seemingly new or used cryptocurrency wallet. Users who input this pre-generated phrase unknowingly grant the attacker full access to
Ledger Connect Kit Supply Chain Attack Incident
The Ledger Connect Kit, a crucial component for connecting hardware wallets to decentralized applications, was compromised in a sophisticated supply chain attack. This incident led to the theft of user funds by redirecting transactions
Counterfeit Hardware Wallets: Identifying Manipulated Devices
Counterfeit hardware wallets pose a severe threat to cryptocurrency security by mimicking legitimate devices to steal private keys. Users must exercise extreme caution in sourcing and verifying their hardware wallets to prevent
Fake Seed Phrase Lures: How Scammers Empty Wallets with Given-Away Seeds
Fake seed phrase scams trick users into using a recovery phrase controlled by an attacker, granting them full access to the associated crypto wallet. This deceptive tactic is highly effective in draining digital assets from unsuspecting