Officer's Channel
11.7K subscribers
139 photos
7 files
1.72K links
Threat Researcher | Web3/OSINT/OpSec/Privacy

• Articles: @officercia
• Blog: officercia.mirror.xyz
• X: x.com/officer_cia
• Chat: t.me/+t7L20oyq60liMTVi
• DM: @farm42

Thank you!
Download Telegram
I'd also like to attach this image to this post because I completely agree with what is written here and, in case you're wondering, this is not a Zencash shill but a copyright.😅
Gm! Visit my blog:

https://officercia.mirror.xyz

Lots of great articles waiting for you!

Now they only come out in one place and that's Mirror! 🫡

Just in case there are any issues, I'll also upload them to IPFS and my GitHub a little later today!

#announcement
Officer's Channel
Attention! New scam going on TRX/USDT users! Follow my thread: twitter.com/officer_cia/status/1594940104363347968 TLDR: always double-check any address letter by letter, digit by digit! #blockchain #attack
Another malicious contract involved:

0x732e9b5f59c9a442db18f7d57dd2bbfc804281cb

Basically the attacker creates a vanity address very similar to your own, and send you very small amounts of USDT or something in the hope that you'll check balance on blockscan, and one day copy and paste their address and send to it by mistake!

slowmist.medium.com/slowmist-another-airdrop-scam-but-with-a-twist-1666e01b6a6c

#blockchain #security
Questions began to be raised over the discovery of mysterious outgoing zero transactions with supposed approve signatures…

At the same time, all of the customers reported that no one had signed such approves! In a nutshell, it's the identical spam attack as in the previous example:

t.me/officer_cia/694

My colleagues explained it in greater detail: t.me/gfischannel/505

The transferFrom function was called, not transfer, which means that the From address was supposed to give that address who signed the transaction, but since the sum is zero and all new contract memory cells are initialized with zeros, everything runs smoothly (since there is a 0 for any address) (deepl.com) 🤔

TLDR: You must just ignore these transactions!

#blockchain #security
Hacker got away with ~$5.5m in visible assets, plus whatever he's dumped into Tornado!

Source: twitter.com/bowtiedpickle/status/1598505917556957184

Hacker Addresses: https://portfolio.nansen.ai/dashboard/0xf3a465C9fA6663fF50794C698F600Faa4b05c777?tab=transactions

#blockchain #security
Officer's Channel
+1 hack 😭 telegra.ph/Retrospective-hacks-in-web3-10-24 #blockchain #security
Special Notes for this month:

• Retrospective of the hacks in web3: graph.org/Retrospective-hacks-in-web3-10-24

• Is it possible to deduct the transaction fee from the sent amount when using USDT ERC20: graph.org/Is-it-possible-to-deduct-the-txn-fee-from-the-sent-amount-when-using-USDT-ERC20-11-19

• How one can deanonymize Monero to a certain degree of probability: graph.org/How-one-can-deanonymize-Monero-to-a-certain-degree-of-probability-11-19

• All resources to become a smart contract auditor: graph.org/All-resources-to-become-a-smart-contract-auditor-09-11

Check out my blog: officercia.mirror.xyz or officercia.medium.com !

#blockchain #offtopic