Sophos researchers have found that malicious actors stole more than $1 million in a “pig slaughter” cryptocurrency scam in just three months.
According to the investigation, the sophisticated operation used a total of 14 domains and dozens of nearly identical scam sites.
The attackers used fake cryptocurrency trading pools from decentralized finance (DeFi) trading applications to defraud their victims, with one person losing $22,000 in a single week.
These “liquidity pools,” which include different types of cryptocurrencies, allow users to earn profits by trading one cryptocurrency to another. Those who participate receive a percentage of the fee paid when a trade is made – with another account (usually the pool’s operators) being granted permission to access participants’ wallets to facilitate the trade.
Sophos has discovered that pig slaughterhouses are increasingly setting up such pools to siphon funds from users – ultimately draining victims’ entire liquidity pools for themselves.
Victim loses $22,000 in one week
The report highlighted the case of a person named “Frank” who lost $22,000 through such a scheme after being duped by an online dating scam.
Frank was contacted by “Vivian” on the dating app MeetMe, who claimed to be a German woman living in Washington DC for work. During the weeks of romantic news, Vivian made persistent attempts to convince Frank to invest in cryptocurrencies by recommending a liquidity pool site.
Frank eventually opened a Trust Wallet account that allowed him to convert dollars into cryptocurrencies and connected to a link to the liquidity pool site. This was a fraudulent website posing as the decentralized finance provider Allnodes.
Between May 31 and June 5, Frank invested $22,000 in the pool, and just three days later the funds were emptied by the scammers.
He then turned to Vivian, who urged Frank to invest even more in the pool to win back his money and reap the “rewards.” While waiting for his bank to approve a money transfer to Coinbase, Frank did some research and found an article about liquidity mining from Sophos, which he asked for help.
Sean Gallagher, senior threat researcher at Sophos, urged Frank to block Vivian. However, she persisted in her attempts to persuade him to continue the investment, even sending a long, emotional letter that Gallagher believes was created by a generative AI app.
A demanding operation
Sophos highlighted the sophistication of this pig slaughter scam, which did not even require the installation of malware on the victim’s device, but instead used social engineering tactics.
Gallagher noted: “This entire fake liquidity pool was managed through the legitimate Trust Wallet app. At one point, Frank even attempted to contact Trust Wallet support to get his funds back, but he connected to a fake support contact from the fraudulent liquidity pool site.”
Gallagher warned that pig slaughter fraud, also known as Shā zhū pán, is becoming increasingly common and proving extremely effective for threat actors.
“Very few understand how legitimate cryptocurrency trading works, so it is easy for these scammers to defraud their targets. There are now even toolkits for this type of fraud, making it easier for various pig slaughterhouses to add this type of crypto fraud to their arsenal. While Sophos tracked dozens of these fraudulent “liquidity pool” sites last year, we are now seeing more than 500,” he noted.
He urged people to be wary of people they are not in contact with suddenly contacting them on a dating app or social media platform, especially if the “person” who makes contact, wants to move the conversation to a platform like WhatsApp and then talks about investing in cryptocurrency.
Sophos has shared its findings with crypto intelligence experts Chainalysis and exchange platform Coinbase, which continue to investigate the extent of pig slaughter scams.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.