Contact us
  • Home
  • Tech
  • Gaming
  • Social Networks
  • Blockchain
    • Crypto News
  • NFTs
  • Metaverses
    • Second Life
  • Reviews
  • Store
  • More!
    • Advertising and Services
    • Partners and Resources
No Result
View All Result
  • Home
  • Tech
  • Gaming
  • Social Networks
  • Blockchain
    • Crypto News
  • NFTs
  • Metaverses
    • Second Life
  • Reviews
  • Store
  • More!
    • Advertising and Services
    • Partners and Resources
No Result
View All Result
Geek Metaverse
No Result
View All Result

MetaMask adds feature to stop NFT scams by wallet drainer

by geekmetaverse
29/07/2022
ADVERTISEMENT
Share on FacebookShare on TwitterShare on LinkedinShare on RedditShare on PinterestShare on WhatsappShare on Telegram

Following a spate of NFT scams on social networks, MetaMask adds an additional step that could help users avoid attacks by ” wallet drainers.”

Social media scams are booming in the NFT space, with Twitter and Discord users being tricked into connecting their cryptocurrency wallets to malicious smart contracts and having their NFTs and other tokens stolen as a result.

Metamask’s wallet has been updated

Now, Ethereum’s main wallet, MetaMask, has updated its interface to try to help users recognize and avoid these scams.

MetaMask released a new 10.18.0 update to the wallet this week, which includes a change to the way the software presents a requested setApprovalForAll permission.

Granting that permission allows the smart contract code that powers NFTs and decentralized applications the ability to access and transfer all NFTs and tokens in a wallet.

Following the update, as noted by security firm Wallet Guard on Twitter, MetaMask now makes it clearer that a smart contract requests broad permissions, including access to any funds found in the wallet a feature that can be used for so-called “wallet drainer” exploits.

.@Metamask 10.18.0 is out 🙌

This update includes the much-needed emphasis for when a transaction is requesting "Set Approval For All"

Kudos to the team for addressing this quickly pic.twitter.com/zWHVVPszzR

— Wallet Guard (@wallet_guard) July 27, 2022

Screenshots posted on MetaMask’s GitHub software development repository GitHub show a new prompt that uses a larger font than the rest of the interface.

The sample text reads, “Give permission to access your entire BAYC?” (or Bored Ape Yacht Club), with an additional warning that reads, “By granting permission, you are allowing the following account to access your funds.”

MetaMask software engineer Alex Donesky wrote on GitHub on June 22 that “there is some urgency to get something out, as this method is widely used.” He also added that the “timeline is compressed,” and admitted that it wasn’t how he would approach the change if there was more time to develop it.

Hacked social network scams

This update comes on the heels of a spate of scams spread primarily through hacked social media accounts. In the spring, the verified accounts of numerous Twitter users were hijacked and used to share scam links inspired by prominent NFT projects such as Azuki and Otherside, and to steal the NFTs and tokens of users who unknowingly connected their wallets to smart contracts.

More recently, the Twitter accounts of several notable NFT projects and collectors were hacked to share similar types of links, billing them as a delivery of free NFTs or tokens.

These scams have also occurred through hacked Discord and Instagram accounts. This has led to a debate over whether creators and projects should compensate users who lose assets through these scams.

Earlier this month, NFT drop registration platform Premint was hit by a hack of its website that used the setApprovalForAll feature to steal a number of valuable NFTs and tokens from affected users.

In the end, the company refunded users more than $500,000 in ETH, and also purchased and returned a couple of valuable collectible NFTs.

“The user interface of the most popular wallets needs to be drastically improved to make it nearly impossible for someone to connect to a wallet drainer,” said Premint founder Brenden Mulligan, “this is a fixable problem, but it’s crazy that it’s so easy to drain a wallet and there aren’t more warnings to protect people.”

To be clear, the MetaMask update makes no judgment about the contract users are trying to connect to, and does not specifically call out the scams identified.

Furthermore, there are potentially legitimate uses for the setApprovalForAll function for certain dapps, such as in NFT markets, which only further confuses the user’s decision.

Still, the MetaMask update could help minimize the impact of scams. Some NFT collectors who have fallen for such scams on social media have been accused of recklessly approving trades due to FOMO and the speculative frenzy around NFTs, and this additional step could give users pause and a chance to reconsider their actions.

Solana has a similar feature (signAllTransactions), and a notable NFT collector just fell victim to such a scam via his Phantom wallet.

MonkeDAO’s pseudonymous co-founder Nom tweeted last night how his wallet was drained in an attack when he interacted with a smart contract he thought was secure.

Follow us on our social networks and keep up to date with everything that happens in the Metaverse!.

                                  Twitter   Linkedin   Facebook   Telegram   Instagram

Recent Posts

  • These jobs will appear thanks to Generative AI, such as Chatgpt and Midjourney
  • Argentine Airline Flybondi to issue all Tickets as NFT
  • A selection of Eye-Opening Mobile Gaming Statistics
  • Snoop Dogg and Cordell Broadus close Paris Blockchain Week with The Champ Medici Lounge
  • Clinique Unveils Metaverse Experience “Clinique Lab”
ADVERTISEMENT
Tags: metamasknftNFT scamsnftsscamssocial networkswalletwallet drainerWallet Guard

geekmetaverse

Related Posts

burger-king-now-accepts-crypto-payments-in-paris
Crypto News

Burger King now accepts Crypto payments in Paris

28/03/2023
vitalik-buterin-among-the-top-speakers-at-edcon-2023-in-montenegro
Crypto News

Vitalik Buterin among the Top Speakers at EDCON 2023 in Montenegro

27/03/2023
bitcoin-could-be-worth-1-million-in-90-days-says-former-coinbase-cto
Crypto News

Bitcoin could be worth $1 million in 90 days, says former Coinbase CTO

26/03/2023
magic-eden-launches-bitcoin-marketplace-for-digital-artifacts
Crypto News

Magic Eden Launches Bitcoin Marketplace for Digital Artifacts

21/03/2023
Next Post
Miami teams up with TIME, Mastercard and Salesforce to launch NFTs

Miami teams up with TIME, Mastercard and Salesforce to launch NFTs

Recommended.

best-blockchain-cryptocurrency-and-nft-events-to-attend-in-2022

The best Blockchain, Cryptocurrency and NFT events to attend in 2022

27/03/2022
queen-paris-hilton-lands-in-the-sandbox-metaverse

Queen Paris Hilton Lands in The Sandbox Metaverse

09/08/2022
ZenGo – The first Crypto Wallet without Private ZenGo – The first Crypto Wallet without Private ZenGo – The first Crypto Wallet without Private
ADVERTISEMENT

Trending.

Epic Games launches Verse, the Metaverse programming language

Epic Games launches Verse, the Metaverse programming language

14/12/2022
the-best-web3-conferences-to-attend-in-2023

The Best Web3 Conferences to attend in 2023

28/03/2023
chatgpt-how-can-ai-help-bitcoin-and-cryptocurrency-users

ChatGPT: How can AI help Bitcoin and Cryptocurrency users?

30/01/2023
second-life-goes-mobile-20-years-of-the-pioneering-metaverse

Second Life goes Mobile: 20 years of the Pioneering Metaverse

19/03/2023
top-10-nft-projects-to-invest-in-2023

Top 10 NFT Projects to invest in 2023

21/02/2023
Geek Metaverse

Geek Metaverse

Tech, Gaming, Metaverses, NFTs and Crypto News!

Contact

info@geekmetaverse.com

Categories

  • Blockchain
  • Crypto News
  • Gaming
  • Giveaway
  • Metaverses
  • NFTs
  • Reviews
  • Second Life
  • Social Networks
  • Start your Blog
  • Tech

Recent Posts

  • These jobs will appear thanks to Generative AI, such as Chatgpt and Midjourney
  • Argentine Airline Flybondi to issue all Tickets as NFT
  • A selection of Eye-Opening Mobile Gaming Statistics
  • Snoop Dogg and Cordell Broadus close Paris Blockchain Week with The Champ Medici Lounge
  • Clinique Unveils Metaverse Experience “Clinique Lab”
  • Advertise
  • Privacy & Policy
  • Contact
  • Store

© 2022 Geekmetaverse

No Result
View All Result
  • Reviews
  • Blockchain
  • Gaming
  • Crypto News

© 2022 Geekmetaverse

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.