zerohash.x Profile picture
Jun 26 12 tweets 5 min read
So a lil breakdown on how this scam actually works. The scammer used the multisignature feature for individual $TRON address to achieve this.
The corresponding TRON address is tronscan.org/#/address/TKx1…, active since 4 days ago with a total of 499 $USDT in funds, and some shitcoin.
I was contacted by @JoyceBr58080110 stating they can't withdrawal their USDT, and requested my help and be rewarded 200 USDT. They gave their seedphrase and by importing the wallet into Trust Wallet, I found the wallet address: tronscan.org/#/address/TKx1…
A glimpse at the account assets shows that it has some TRX for fees on the TRON network, 499 USDT, and some shitcoin. Crypto newbies will think they have hit jackpot since they can transfer the funds away since they have the private key access. But 1 TRX is not enough for fees. Image
Now, you will realize you need to fund this wallet with additional TRX for fees, which approximates to 20-30 TRX, valued at $1-2 at current market price. Small amount for a few hundred bucks of potential profit. However, as soon as money is sent to this address, it's sent away.
In the first instance, TMp3reLeUkGAjvRssgc78JPAttyHrHCMTw sent 29.30996 $TRX, seen here tronscan.org/#/transaction/….
Seconds later, this amount was transferred away to TDsBEmLHvQk4Y3zNKdbKJnLct2Vs9TKo4M, seen here tronscan.org/#/transaction/….
In the second instance, TM1zzNDZD2DPASbKcgdVoTYhfmYgtfwx9R sent
29.759 $TRX, seen here tronscan.org/#/transaction/….
Similarly, this was sent away seconds later, seen here tronscan.org/#/transaction/….
The speed of transfer is impossible for human execution, so we can only associate this with a fund transfer trigger by an underlying smart contract. This is where the multisignature feature of TRON wallet comes into play, introduced in the v3.5 update.
There are 3 types of permissions in TRON wallets for multisig: owner, witness, and active. Owner permission has the right to execute all the contracts. Witness permission is for SR. Active permission contains a set of contracts selected execution permissions.
For the wallet in question (TKx1TtevcLSMst73ZRZLKfVc7wEfpVwuBn), 4 days ago they called the AccountPermissionUpdateContract function twice. The first tx, tronscan.org/#/transaction/…, updated the active permission of the wallet to TDsBEmLHvQk4Y3zNKdbKJnLct2Vs9TKo4M. Image
A second call for AccountPermissionUpdateContract swapped the owner of TKx1... to TDsB... This means the wallet TKx1... is controlled entirely by TDsB... Third party no longer have rights to TKx1... wallet, they can't do shit as owner permission changed.

tronscan.org/#/transaction/… Image
So how are funds transferred in split seconds? Notice that under active permissions, there is an operational function for automated fund transfers - Smart Contract Trigger (TRC20/TRC721 Transfer). This allows any predetermined token to be transferred away once it hits TKx1... Image
This is similar to many other scams that works in similar fashion but the way the scammers revoked owner permission using the #multisig feature for TRON wallets is ingenious.

Stay safe out there, y'all.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with zerohash.x

zerohash.x Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(