7 ms·
This is true of crypto wallets and NFTs as well. More than one project has attempted to send NFTs or assets to high profile wallets (ex: trillions of dog-coins
by quartz 4y ago
This is true of crypto wallets and NFTs as well. More than one project has attempted to send NFTs or assets to high profile wallets (ex: trillions of dog-coins sent to Vitalik's wallet that he ultimately donated to get rid of but not before drawing the intended media attention[1]) and the whole concept of airdrops is based around the idea of permissionless receiving.
Unfortunately, re: swatting via an non-tech-savy LEA and domain registrars: you could likely just update the contact details on a domain you own to the intended target and that'd probably be enough.
[1] https://www.coindesk.com/markets/2021/10/20/vitalik-buterin-sent-away-trillions-of-unwanted-dog-coins-but-more-keep-rolling-in/ https://www.coindesk.com/markets/2021/10/20/vitalik-buterin-...
- jonny_eh 4y agoAlso true of text messages and email, which can include unsavory content.
- simonw 4y agoText messages and email are different because they're private: if someone sends you an abusive text only you can see it. The problem with NFT wallets is that you can send someone something which will then be publicly visible and associated with them, without their consent.
- munificent 4y ago> Text messages and email are different because they're private: if someone sends you an abusive text only you can see it. https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM
- soco 4y agoPRISM is not even needed, a warrant is often enough (and sometimes only pressure).
- PaulDavisThe1st 4y agoNo, text messages and email are different because they contain implicit sender/origination information, which even if fake, shows that the material in the messages comes from someone else. Domain ownership does not have this property. "WhoUsedToBe" is not a well-known database.
- TremendousJudge 4y agoThe NFT can also be a program that when you try to move the token or interact with it in any way, it can do things such as transferring funds to another wallet.
- pcthrowaway 4y agoThere is no way this would work without approving the NFT contract to spend your tokens. Realistically, lots of people would do this because the complexity of blockchain tech is beyond most peoples' grasp, but there is a reasonable failsafe at least.
- deleted 4y ago[deleted]
- TremendousJudge 4y agoafaik it's already been done: https://bitcoinist.com/hackers-are-now-trying-to-steal-crypto-via-malicious-nfts/ https://bitcoinist.com/hackers-are-now-trying-to-steal-crypt...
- pcthrowaway 4y ago> The source of the problem was not just the NFT and the airdrop. However, by releasing an NFT to a victim, they will see it. Then, there comes a follow-up message that demands a signature for connecting to a wallet. > Furthermore, a prompting request for a secondary signature will come up. If the user accepts it, the hackers will access the unsuspecting user’s wallet and funds. This is light on details, but as I said, the only way another address can spend a users tokens is if the victim address approves it (or if the token is not ERC20 conforming). This approval might be what the article refers to here as signatures. Alternately, this attack could somehow get a user to reveal their private key, in which case, of course an attacker has access to their funds.
- WalterSear 4y agoA while ago I read an amusing tweet about some person airdropping racist NFTs on people, that were then automagically displayed as their avatars.
- tgsovlerkhgsel 4y agoYou left out the best part: I believe there was some kind of attack where attempting to send them could drain your wallet if you weren't careful.
- Animats 4y ago> non-tech-savy LEA Yes. Someone owns the location that's the "center of the United States" for broken IP address lookups. MaxMind gave 38 north, 97 west as the default location for 600 million IP addresses. It's a farm in Kansas.[1] MaxMind did that for 14 years. The farm was regularly visited by law enforcement, looking for various people. [1] https://web.archive.org/web/20160817013603/http://fusion.net/story/287592/internet-mapping-glitch-kansas-farm/ https://web.archive.org/web/20160817013603/http://fusion.net...
- wildrhythms 4y agoWow this was a great (and terrifying) article. I feel like companies like MaxMind shouldn't be allowed to just advertise a pin on a map and point queries for IP addresses to it. Why even have a "default" latitude and longitude? Just return null. Just terrible, irresponsible, dangerous behavior.
- bragr 4y agoI believe MaxMind finally updated the default US location into the middle of nearby lake to help stop this issue. How long it takes everyone to update their GeoIP DBs.... who can say? edit: >Following Hill’s extraordinary piece in Fusion, MaxMind shifted its default “United States” location to the center of a lake, west of Wichita. https://archive.ph/i6gao https://archive.ph/i6gao
- zeckalpha 4y agoMaxMind is pretty aggressive about getting people to update, or booting you as a customer.