×Foudres Profile picture
Jun 18 32 tweets 7 min read Twitter logo Read on Twitter
Yesterday, I prevented a $50k scam.

How do you recognize this scam with @exodus_io and why would it have been impossible thanks to one of @xPortalApp's great features ?

#HyperGrowthX Image
We often think that a good application should be able to switch from one functionality to another with a minimum of clicks. To anywhere? I promise you, there's one place you wouldn't want to have easy access to...
Yesterday I accompanied a friend who was to sell luxury watches to a person supposedly specializing in the field.

The transaction was to be carried out in crypto.
My friend has a good knowledge of crypto, but preferred my presence as he knew I was more experienced than him and better able to detect any dubious attempts.
Our interlocutor tells us that he's already had a bad experience with crypto transactions, telling us that he was scammed with a transaction on an ETH wallet, and had his entire wallet emptied an hour or so after the transaction had been carried out.
First redflag on my part, this is impossible, unless you interact with a smart contract and sign an approval allowing you to siphon a wallet.
This is where I come in, pretending to have already been the victim of a similar scam, saying that I'd been forced to create a new wallet, and that the man had taken a photo of my seed without my knowledge during the transaction.
An unsuccessful attempt to make him understand that any attempt on his part would be in vain.

Despite my subliminal message that the man didn't understand, after multiple justifications, he insists that we use a @exodus_io wallet.
It was at this point that I became completely convinced that this person was trying to scam us, so I paid close attention to his every move, because it was the wallet (Exodus) used in the scam I knew about and was careful not to reveal.
I then give a sign to my friend, telling him to be very careful and never to let his telephone out of his hands.
Despite my justifications that using a new wallet wouldn't change anything and that no one in their right mind would create a new wallet in a public place, nothing would change his mind.

So, my friend downloads an Exodus wallet.
Just as he was handing him the QR code of his mobile without giving it to him, the man received a call from his father (it was he who had contacted us first about the watches), saying he wanted to speak to my friend to make sure everything went smoothly.
During this time I do the same on my side to check what's going on, and bingo, the wallet is automatically created without asking for a pin code or faceID.
This is where the man tried to take my friend's phone, handing him his own (second phone) with his father's call.
This is where they hope you'll take your attention away from your phone, concentrating on the call, so that you'll give it to them naturally, without even really realizing it.
I stepped right in, preventing my friend from letting the scammer take his phone with the QR code displayed.
But why would you want to use an Exodus wallet and BTC transfer ? Here's why ⬇

Exodus has a design flaw: in just 5 clicks and less than 4 seconds you can switch from the payment QR code to the seed!
While they take your phone to pretend to scan the QR code, they make sure to look you in the eye to talk to you, while they quickly take a picture of the seed.
Then, once you've received the transaction, they offer you a drink or a bite to eat to celebrate, while someone else siphons off your wallet, and then goes off with the watches as if nothing had happened.
You return home, and when you make the decision to transfer the funds to a more secure wallet, the wallet is empty, and you find yourself in total confusion.
So how did xPortal come up with this dual-purpose feature?

xPortal asks you each time you want to access your seed to type the message "if i share my secret phrase i will lose my money", and a faceID is requested when finished before before displaying the seed. Image
Making it not only time-consuming to get from the QR code to the seed, but also impossible for anyone but you to access it.
Having wallets that don't even have a pin code to display the seed phrase is a huge security flaw, so when it's displayed with just a few clicks, it's even worse.
@exodus_io, your wallet seems to be used extensively in this type of scam, you should definitely find a way to stop it.

The fact that password and FaceID creation have to be activated manually, and not requested just after download the application, is a flaw.
It's a good thing I was aware of this type of scam, because even if I'd been positioned between the two men to check that no dubious attempts were being made, with enough skill and not knowing their modus operandi,
I could certainly have missed out as it seemed to happen so naturally.
I also think they had a more elaborate technique that they failed to make with an NFC hack because the person had an NFC tag on one of his Iphones.

By making you download a virus beforehand, they can hack your phone and retrieve your passwords and pin code. Image
They had asked my friend to download a pdf file few day ago which was a summary of the transaction, with the different watch models and their prices as an invoice to signed on the day of the transaction.
That's why they also suggested we use a Coinbase wallet when we refused to use Exodus, which has a pin code activated as soon as the wallet is created, but told us that the "transaction" would take about an hour because of network fees.
(which is also when I realized that something not quite right was happening).

Maybe they'd managed to install the virus, but it would have taken a long time to hack the phone and get the pin code to perform the same technique on Coinbase Wallet, but that's speculative.
I cut the negotiation short and we left.

Be careful when making large transactions with strangers, never be alone, never let someone take your phone when you've unlocked your wallet, and above all, never create a new wallet at someone's request.
Thanks to @HakimKorso, who told me about this scam a few weeks ago, otherwise we might have fallen into their trap.

Be careful friends 🙏⚡

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with ×Foudres

×Foudres Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @xFoudres

May 30
[@blok_project / $BKT and $Blok Token]

New week rhymes with new Thread on Blok to give you a complete view and as deep an understanding as possible, today we're digging into the project's tokens

RT very appreciated ⚡

#MultiversX Image
If you haven't read the previous threads, which gave an overview of the project and a tradFi-oriented explanation of Blok's Bond and SPV concepts, I'll leave them here for you!

Read 36 tweets
May 21
[THREAD / #xMoneyFuture 🇫🇷 🇬🇧 Article]

What if the virtual and isolated aspect of our cryptos is about to disappear?

Web3 lovers, you should not miss this attempt to give you the keys to understand the future, and what we will call the #xMoney.

RT very appreciated ⚡ Image
For French people, the article is available especially for you here :

Pour les personnes française, l'article est disponible spécialement pour vous ici, N'oubliez pas que vous pouvez gagner 10k UTK en retweetant ce thread! Merci pour votre soutiens 🫶

medium.com/@xFoudres/xmon…
My application to the #xMoney contest will be through this Medium article, although this thread is a faithful transcription.

Don't forget that you can win 10k UTK by retweeting this thread! Thank you for your support 🫶 :

medium.com/@xFoudres/xmon…
Read 107 tweets
May 15
[🚨 RUG ALERT 🚨/ @xBurn_Token ]

"Ihbou", "Mister xMEX", "CaviarEggs", "Worst Scammers Ever", call him as you like, is behind xBurn or at least strongly linked to it !

Keep it simple, no long thread just the facts ⬇

RT ABSOLUTELY NECESSARY Image
The xBurn team wallet has cashout their Launchpad revenue from @OneDex_X to a MEXC wallet, shared with a second wallet actively trading spread differences on @jexchangeP2P. Image
Given the low usage of MEXC, it was very easy to find the wallet where the cashout occurred, a few minutes after it was sent to the platform, ELGDs return directly on CaviarEggs wallet, Image
Read 9 tweets
May 5
[🧵#MultiversX Project Analysis / @blok_project]
 
Tokenization, one of the most powerful blockchain narratives, but also one of the most complex topics.

Blok's ambition is to apply it to real estate, a subject that we will develop throughout this month!

RT very appreciated ⚡ Image
This thread aims to introduce the project in a simple way, but will be followed in the next few weeks by a complete analysis through several other threads for what will certainly be on of my most thorough analysis to date!

/2
The planned breakdown of the different threads (which can still change) : 
 
- The real estate market and the legal mechanisms of Blok 
 
- Token, NFT and Ecosystem
 
- Study of the Tokenomics Paper
 
- Global and fundamental analysis

/3
Read 23 tweets
Apr 29
[NFT AMM / @JewelSwapX]

Another day, Another Thread!

Today we will discuss NFT AMM and how they can reinvent the whole NFT market ⚡

RT very appreciated 🙏

#MultiversX
1/ Birth of NFT AMM

2/ AMM Explanation

3/ How it's useful for the ecosystem

4/ Strategies

/2
1/ Birth of NFT AMM

The arrival of NFT AMMs is rather recent since the first protocol, @sudoswap, was launched in July 2022 on Ethereum.

They try to recreate what already exists today on DEX with tokens, but with NFTs and adapted to their non-fungibility.

/3 Image
Read 44 tweets
Mar 2
[@xPortalApp 🧵]

Finally out and no doubt, #xPortal is an absolute banger.

But I'm not here, to tell you how great it is, you already know that.

Let's see how to push this wallet to its full potential to become the real SuperApp !

🔁 RT very appreciated ⚡

#EGLD #MultiversX @beniaminmincu @luciantodea @lucianmincu @the_economystic @T
@xPortalApp @beniaminmincu @the_economystic @DBCrypt0 @AndreiMX_ @TCryptomonnaies @BitcoinCouteau @lucianmincu @mvgrigoras We will review the App features by features to see how to push even further, what is missing and what it should become.

But before that, let's try to understand the ultimate goal, a SuperApp, but for whom?
@xPortalApp @beniaminmincu @the_economystic @DBCrypt0 @AndreiMX_ @TCryptomonnaies @BitcoinCouteau @lucianmincu @mvgrigoras The ambition of @MultiversX is clear, 1 billion users. So an App not only for the Web3, a SuperApp for everyone. 

That's why the most important feature for me will be the possibility to deposit Fiat currencies. In non-custodial way.
Read 67 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(