A new cryptocurrency scam involving QR codes is emerging, according to the analytics firm Bitrace.
Bitrace reports that scammers are using QR codes to deceive users into authorizing their wallets. This scam lures traders with attractive over-the-counter (OTC) trade offers and rewards in the cryptocurrency TRX, which is native to the Tron protocol.
(2/n)
How QR Codes Steal User AuthorizationsBitrace tested the QR code with an empty wallet and was directed to a third-party website, https://sktnid[.].com/, supporting USDT transfers.
Click Confirm to interact with a Phishing smart contract, at which point the wallet… pic.twitter.com/06b80Ko1k7
— Bitrace (@Bitrace_team) August 8, 2024
The scheme typically begins with scammers making a small payment in USDT to build trust. They then propose a transaction at below-market rates and offer TRX incentives for continued engagement. As part of their ruse, they request a small test repayment.
Bitrace tested the scam by using an empty wallet and found that it redirected them to a third-party site designed to facilitate USDT transfers. By confirming the transaction, users unknowingly interact with a phishing smart contract that steals their wallet authorization.
The firm reports that between July 11 and July 17, 2024, this scam resulted in the theft of $120,000 worth of USDT from 27 victims. Bitrace advises investors to verify the counterparty’s address and perform due diligence before making any transactions.
Loopscale, a decentralized finance platform built on Solana, was forced to pause its lending operations after a major security breach led to losses of around $5.8 million.
Alex Mashinsky, co-founder and former CEO of the defunct crypto lending platform Celsius, is scheduled to be sentenced on May 8, 2025, following his guilty plea to two federal criminal charges late last year.
A decentralized exchange targeted in a multi-million-dollar exploit has recovered its losses just days after the incident, thanks to an unexpected twist involving the hacker themselves.
A recent cyberattack targeting a UK government official’s social media account has highlighted ongoing concerns over digital impersonation and crypto scams.