{"id":69275,"date":"2024-01-19T01:51:53","date_gmt":"2024-01-19T05:51:53","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=69275"},"modified":"2024-01-19T01:56:24","modified_gmt":"2024-01-19T05:56:24","slug":"rocket-pool-x-users-alerted-to-fake-hack-by-hijacked-account","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/rocket-pool-x-users-alerted-to-fake-hack-by-hijacked-account\/","title":{"rendered":"Rocket Pool X Users Alerted to Fake Hack by Hijacked Account"},"content":{"rendered":"\n<p>On January 17, a hacker compromised the Ethereum staking protocol <a href=\"https:\/\/coinscreed.com\/staging\/forbes-impersonator-hacks-certiks-x-account-in-phishing-scam.html\" target=\"_blank\" rel=\"noreferrer noopener\">Rocket Pool's X account<\/a>. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-1024x576.jpg\" alt=\"Rocket Pool X Users Alerted to Fake Hack by Hijacked Account\" class=\"wp-image-69277\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-18x10.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Rocket Pool X Users Alerted to Fake Hack by Hijacked Account<\/figcaption><\/figure>\n\n\n\n<p>The hacker requested that users move their assets by clicking on a fraudulent link. The hijacker of Rocket Pool sent a message outlining the bright contract flaws that the purported team had found. In order to prevent losses, the message instructed customers to click on a link and move their assets to a version 2 contract.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">WARNING!!!<br><br>Rocket Pool Twitter compromised!<br><br>The Rocket Pool Twitter account has been compromised! Do not click any links in tweets on that account!<br><br>The account that is compromised is [DO NOT CLICK] <a href=\"https:\/\/twitter.com\/Rocket_Pool?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Rocket_Pool<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>&mdash; Hudson Jameson (@hudsonjameson) <a href=\"https:\/\/twitter.com\/hudsonjameson\/status\/1747690755471143294?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">January 17, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>The Rocket Pool crew acknowledged the event on Discord and advised users not to interact with any links the account had posted till later. At the time of publishing, no information was available regarding potential losses or <a href=\"https:\/\/coinscreed.com\/staging\/circle-proposes-recoverable-token-standard-to-address-crypto-theft.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency theft<\/a>.<\/p>\n\n\n\n<p>The bug has already been used in several hacks this year in response to attacks on companies such as CoinGecko. On January 10, the Bitcoin price aggregator disclosed that its X account had been compromised. <\/p>\n\n\n\n<p>On January 9, hackers also gained access to the US Securities and Exchange Commission (SEC) account by posting a fictitious notice of approving a Bitcoin ETF. SEC Chairman Gary Gensler stated that no new breaches had been found, but senators insisted on more information. <\/p>\n\n\n\n<p>Additionally, it is said that the FBI is looking into the SEC hack. Olaf Carlson-Wee, the <a href=\"https:\/\/www.google.com\/search?q=Rocket+Pool+X+Users+Alerted+to+Fake+Hack+by+Hijacked+Account&rlz=1C1JJTC_enNG1049NG1049&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">CEO of Polychain Capital<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, had his Twitter account hacked a few days prior to the SEC's security breach, and the hackers were pushing a bogus airdrop link. <\/p>\n\n\n\n<p>These kinds of breaches draw attention to a larger security issue in cryptocurrency since they affect stakeholders and expose certain protocols to sophisticated social engineering attack vectors.<\/p>\n\n\n\n<p>Crypto security may be a barrier to widespread adoption as we enter a <a href=\"https:\/\/coinscreed.com\/staging\/cz-predicts-bitcoin-bull-market-in-2025-addresses-regulatory-issues.html\" target=\"_blank\" rel=\"noreferrer noopener\">bull market<\/a> marked by a defi comeback and a surge of retail capital driven by institutional adoption.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On January 17, a hacker compromised the Ethereum staking protocol Rocket Pool&#8217;s X account. The hacker requested that users move their assets by clicking on a fraudulent link. The hijacker of Rocket Pool sent a message outlining the bright contract flaws that the purported team had found. In order to prevent losses, the message instructed [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":69277,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[12002,17894,143],"class_list":["post-69275","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hacks","tag-rocket-pool","tag-sec"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/croc_1705641999974.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=69275"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69275\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/69277"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=69275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=69275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=69275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}