Breaking
June 1, 2025

Warning: The Telegram Verification Bot Could Empty Your Crypto Wallet Oliver Dale | usagoldmines.com

TLDR:

  • Crypto scammers have dramatically shifted to Telegram malware scams, showing a 2,000% increase since November 2023, surpassing traditional phishing methods
  • Instead of typical wallet connection scams, attackers are now using fake verification bots in trading, airdrop, and alpha groups to distribute sophisticated malware
  • Two identified fake verification bots – OfficiaISafeguardRobot and SafeguardsAuthenticationBot – are being used to steal passwords, wallet files, and browser data
  • Scammers have evolved from impersonating crypto influencers to targeting legitimate project communities with seemingly harmless invites
  • Total crypto theft reached $2.3 billion across 165 incidents in 2024, marking a 40% increase from 2023, though December saw the lowest monthly losses at $29 million

Security researchers have detected a major shift in cryptocurrency scamming tactics, with malware attacks through Telegram showing an unprecedented 2,000% increase since November 2023.

This new trend marks a departure from traditional phishing methods as scammers adapt their strategies to bypass growing user awareness.

Security firm Scam Sniffer reported on January 15 that crypto thieves are moving away from the common “connect wallet” schemes. These older scams typically tried to trick users into connecting their digital wallets to fake websites. The new approach uses sophisticated malware distributed through seemingly legitimate verification bots in Telegram groups.

Two specific fake verification bots have been identified as tools in these attacks: OfficiaISafeguardRobot and SafeguardsAuthenticationBot. These bots serve as entry points for malware that can access passwords, scan for wallet files, monitor clipboards, and steal browser data from unsuspecting users.

The evolution of these scams began with bad actors creating fake social media accounts that impersonated popular crypto influencers. These accounts would then invite users to Telegram groups with promises of exclusive investment insights and trading opportunities.

Once users join these groups, they encounter what appears to be a standard verification process. However, the verification step secretly installs crypto-stealing malware onto their systems, giving scammers access to private keys and crypto wallets.

A particularly deceptive variant of these scams uses fake Cloudflare verification pages. Users are asked to copy and paste verification text that contains hidden malicious code, which then compromises their system through their clipboard.

Attackers are impersonating multiple crypto influencers and using malicious bots for verification
Attackers are impersonating multiple crypto influencers and using malicious bots for verification

By January 4, Scam Sniffer observed that these tactics had evolved further. Scammers began targeting legitimate cryptocurrency project communities, moving beyond influencer impersonation. They now send what appear to be harmless invitations to community members.

The security firm notes that this tactical shift reflects the scammers’ adaptation to increased user awareness about phishing links. Instead of relying on suspicious URLs, they now focus on social engineering through Telegram bots, making their attacks harder to detect and avoid.

In December, Cado Security Labs identified a related scheme where scammers used fake meeting applications to distribute malware. These apps served as vectors for stealing credentials to various websites, applications, and crypto wallets.

The financial impact of these attacks has been substantial. According to Cyvers’ 2024 Web3 Security Report, crypto thieves stole $2.3 billion across 165 separate incidents in 2024. This represents a 40% increase from the previous year’s total of $1.69 billion.

However, this figure still remains below the 2022 peak, when hackers made off with $3.78 billion in cryptocurrency assets. The 2024 total represents a 37% decrease from that high point.

December 2024 showed some positive developments, with both security firms reporting the lowest monthly losses of the year at approximately $29 million. This decrease in successful thefts suggests that some security measures may be having an effect.

Tracking the exact scope of these malware attacks presents challenges for security researchers. Scam Sniffer reports that losses from malware attacks are particularly difficult to measure accurately, unlike more traditional forms of crypto theft.

The security firm emphasizes that while precise numbers remain elusive, the dramatic shift in scammer tactics toward Telegram-based malware attacks indicates these methods are proving effective for the perpetrators.

Current security recommendations focus on careful verification of any Telegram bots or groups, particularly those promising exclusive access or requiring special verification steps. Users are advised to be especially wary of any verification processes that require downloading or running external software.

The latest data shows these scams continuing to evolve, with bad actors constantly refining their approaches to bypass security measures and user awareness. Security firms are actively monitoring these developments to identify new variants of these attacks as they emerge.

The post Warning: The Telegram Verification Bot Could Empty Your Crypto Wallet appeared first on Blockonomi.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Crypto Security Breach at Lido DAO Triggers Governance Response Maisie Morrison | usagoldmines.com

Darkweb Threat Actors Claim to Possess Massive Leak of Gemini, Binance American User Data Nicholas S...

Don’t Take the Bait: Coinbase & Gemini Exchange Users Targeted by Phishing Attack Oliver Dale | ...

North Korean Hackers Transfer $750,000 in ETH to Tornado Cash, Deploy New Malware Oliver Dale | usag...

Dark Storm Hacktivist Group Claims Responsibility for X Platform Disruption Oliver Dale | usagoldmin...

Russian Cybercrime Group Uses Fake Job Interviews and ‘GrassCall’ App to Drain Crypto Wallets Nichol...

World Network in Philippines to Battle Scams with Human ID Nicholas Say | usagoldmines.com

Kaspersky Uncovers Mobile Malware Targeting Crypto Users on iOS and Android Oliver Dale | usagoldmin...

Animoca Brands Co-founder Yat Siu’s X Account Hacked to Promote Fake Solana Memecoin Nicholas Say | ...

Hyperliquid Token Falls 21% Following North Korean Hacking Concerns Oliver Dale | usagoldmines.com

LastPass Hackers Steal $5.36M From Users Days Before Holidays Nicholas Say | usagoldmines.com

Ledger Hardware Wallet User Reports $2.5M Digital Asset Loss Oliver Dale | usagoldmines.com

Google’s Willow Quantum Chip: A Step Forward in Computing, But Bitcoin Remains Secure Oliver Dale | ...

Cardano Foundation X Account Compromised, False SEC Claims Circulate Oliver Dale | usagoldmines.com

Japanese Exchange DMM Bitcoin to Cease Operations After $320 Million Hack Nicholas Say | usagoldmine...

Sumsub Partners with Elliptic to Strengthen Crypto Fraud Prevention and Compliance Tools Oliver Dale...

Crypto Platform’s $12M Nightmare: Inside the Polter Finance Hack Oliver Dale | usagoldmines.com

Phantom Wallet iOS Update Error Results in User Fund Access Problems Oliver Dale | usagoldmines.com

X Account Hack Forces Terminal of Truths Developer to Relocate $1.8M in Crypto Oliver Dale | usagold...

Radiant Capital Hit by $50M Blockchain Security Breach Nicholas Say | usagoldmines.com

US, UK, and Australia Target Russian Cybercrime Syndicate | usagoldmines.com

LEGO Website Experiences Brief Hack Promoting Fake Cryptocurrency | usagoldmines.com

Google Play Hosts Crypto Wallet Drainer for Five Months, $70,000 Stolen | usagoldmines.com

Bedrock Protocol Reports $2M Exploit: Reimbursement Plan in Progress | usagoldmines.com

MEV Bot’s $12 Million Flash Loan Yields Meager $20 Profit | usagoldmines.com

Binance Collaborates with Indian Authorities to Uncover $47.6M Gaming Scam | usagoldmines.com

FBI Warns of “Pig Butchering” Schemes Targeting Crypto Investors | usagoldmines.com

Binance Investigates and Refutes Alleged 12.8 Million User Data Leak | usagoldmines.com

Sam Altman’s Company Falls Victim to Online Crypto Fraud | usagoldmines.com

BingX Exchange Hacked: $43 Million Stolen, Users to be Reimbursed | usagoldmines.com

Truflation Reports $5 Million Loss in Malware Attack on Blockchain Platform | usagoldmines.com