Research Archive

Web3 Phishing

Browse entries by research type, time, topic, and threat domain. This page behaves more like an archive than a feed.

2024

Over a near-black teal-blue background, a disguised Aggr extension icon in the Chrome Web Store alongside a flow of stolen cookie data, malicious nodes marked copper-orange in the network topology, and malicious code fragments planted inside a jQuery file scattered across the backdrop — symbolizing the fake Aggr Chrome extension's cookie theft and wash-trading crypto heist
Security Research

Fake Aggr Chrome Extension Crypto Theft Analysis: Cookie Stealing and Wash Trading

In May 2024, a malicious Chrome extension disguised as an Aggr trading tool was found stealing users' cookies from all websites. The attacker embedded malicious code inside a jQuery file, exfiltrating cookie data to a Russian-language server and using wash trading to steal users' crypto assets. The hacker began plotting 3 years ago, deployed the attack 4 months ago, and leveraged KOLs for promotion.

2024-05-31 4 min #Web3 Phishing

2022

Discord DM Phishing Technique Analysis
Security Research

Discord DM Phishing Technique Analysis

The SlowMist Security Team identified an automated phishing attack on Discord where attackers impersonate Captcha.bot to send fraudulent verification links to new server members, tricking them into revealing their wallet passwords and seed phrases. This article reconstructs two phishing attack chains and provides defense recommendations from both user and project perspectives.

2022-05-17 5 min #Web3 Phishing