{"id":60743,"date":"2023-10-04T03:20:19","date_gmt":"2023-10-04T07:20:19","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=60743"},"modified":"2023-10-04T03:20:27","modified_gmt":"2023-10-04T07:20:27","slug":"friend-tech-users-suspect-sim-swaps-for-over-100-eth-drain","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/friend-tech-users-suspect-sim-swaps-for-over-100-eth-drain\/","title":{"rendered":"Friend.tech Users Suspect SIM Swaps for Over 100 ETH Drain"},"content":{"rendered":"\n<p>Four user accounts on friend.tech were compromised and drained after <a href=\"https:\/\/coinscreed.com\/staging\/hackers-steal-3-5m-worth-of-digital-assets-from-gmx-whale.html\" target=\"_blank\" rel=\"noreferrer noopener\">hackers gained control <\/a>of their mobile numbers, in a short period.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"819\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-1024x819.webp\" alt=\"\" class=\"wp-image-60746\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-1024x819.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-300x240.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-768x614.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-15x12.webp 15w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-750x600.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG-1140x912.webp 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Friend.tech Users Suspect SIM Swaps for Over 100 ETH Drain<\/figcaption><\/figure>\n\n\n\n<p>Users of Friend. tech has issued a warning about possible SIM-swap attacks following a spate of alleged breaches that resulted in nearly 109 ETH worth approximately $178,000 being drained from four users in less than a week.<\/p>\n\n\n\n<p>On September 30, the X (formerly Twitter) user known as &#8220;froggie. eth&#8221; warned their Friend. tech account was SIM-swapped \u2014 where attackers obtain control of a user's mobile number to intercept two-factor authentication codes, which are then used to access accounts \u2014 and over 20 ETH were subsequently stolen.<\/p>\n\n\n\n<p>On October 3, a series of Friend.Tech users reported similar incidents, with musician Daren Broxmeyer claiming his SIM card was swapped and 22 ETH were stolen.<\/p>\n\n\n\n<p>His phone had previously been &#8220;spammed with phone calls,&#8221; which he believed was an attempt to prevent him from receiving a text message from his service provider warning him that someone was attempting to access his account.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">I was just SIM swapped and robbed of 22 ETH via <a href=\"https:\/\/twitter.com\/friendtech?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@friendtech<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><br> <br>The 34 of my own keys that I owned were sold, rugging anyone who held my key, all the other keys I owned were sold, and the rest of the ETH in my wallet was drained.<br> <br>If your Twitter account is doxxed to your real\u2026 <a href=\"https:\/\/t.co\/5wA86mjYEG\" target=\"_blank\">pic.twitter.com\/5wA86mjYEG<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; daren (friend, friend) (@darengb) <a href=\"https:\/\/twitter.com\/darengb\/status\/1709021872178729409?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 3, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>The same day, another user, &#8220;dipper,&#8221; reported that their account had been compromised, adding that they had &#8220;no idea&#8221; how their account could have been hacked because they use robust passwords.<\/p>\n\n\n\n<p>The fourth victim, &#8220;digging4doge,&#8221; lost approximately 60 ETH after falling victim to a phishing scheme that involved sharing a login code.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">Friendtech user <a href=\"https:\/\/twitter.com\/digging4doge?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@digging4doge<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> just got drained to the tune of ~60 eth worth of keys.<br><br>About an hour ago, he received a text informing him that a number change had been requested for his account.<br><br>He had two hours to respond or the request would be auto approved. This was, of\u2026 <a href=\"https:\/\/t.co\/L21Hr041kP\" target=\"_blank\">pic.twitter.com\/L21Hr041kP<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; quit (\ud83d\udc40,\ud83e\udd84) (@0xQuit) <a href=\"https:\/\/twitter.com\/0xQuit\/status\/1709391410783195384?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 4, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p><a href=\"https:\/\/coinscreed.com\/staging\/top-10-crypto-friendly-investment-management-firms.html\" target=\"_blank\" rel=\"noreferrer noopener\">The crypto investment firm<\/a> Manifold Trading explained that any intruder who gains access to a Friend. tech account can \u201crug the whole account.\u201d<\/p>\n\n\n\n<p>Using the assumption that one-third of Friend.tech accounts are linked to phone numbers, they estimate that $20 million is at risk of being exploited via Friend. Tech user-focused exploits.<\/p>\n\n\n\n<p>Manifold also indicated that technically, the entirety of Friend. Tech is at risk due to the platform's security configuration, and resolving the issues \u201cshould honestly be the number 1 priority.\u201d<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">My FT account was just compromised, hacker dumped all keys and moved everything to another address. Was about 6.5e total. Wallet address here: 0x8D8557e4A7512b81C74efD2874107a7C4e29fE26<\/p>&mdash; dipper (@d1pp3r__) <a href=\"https:\/\/twitter.com\/d1pp3r__\/status\/1708951375793541570?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 2, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>Manifold recommended that Friend. Tech enables 2FA for logins, key decryptions, and transactions. Users should also be able to change the login mechanism from a number to an email address, and third-party wallets should be permitted.<\/p>\n\n\n\n<p>Before September, the X account of Ethereum co-founder <a href=\"https:\/\/en.wikipedia.org\/wiki\/Vitalik_Buterin\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Vitalik Buterin<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> was effectively SIM-swapped and used for phishing attacks, as were the accounts of other prominent crypto figures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Four user accounts on friend.tech were compromised and drained after hackers gained control of their mobile numbers, in a short period. Users of Friend. tech has issued a warning about possible SIM-swap attacks following a spate of alleged breaches that resulted in nearly 109 ETH worth approximately $178,000 being drained from four users in less [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":60746,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[5562,16621,5749,16631],"class_list":["post-60743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-eth-2","tag-friend-tech-2","tag-hacking","tag-sim-swap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/CG.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=60743"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/60746"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=60743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=60743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=60743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}