News: 1675863006

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Scammers steal $4 million in crypto during face-to-face meeting

(2023/02/08)


Ahad Shams, the co-founder of Web3 metaverse gaming engine startup Webaverse, discovered in late November 2022 that someone had stolen $4 million of his cryptocurrency – during a real world interaction.

Stolen crypto isn't unusual: [1]billions of digi-dollars were stolen last year, some by crime gangs or nations like North Korea.

What made this case different is that the scammers stole the funds from a newly created Trust Wallet account when Shams and a Webaverse colleague met in the lobby of a Rome hotel. By the premature end of the meeting, the money – and the miscreants – were gone.

We thought it was weird but no private keys or seed phrases were showing, so we humored them

In a detailed [2]statement posted on Twitter this week, Shams outlined how the scammers posed as possible investors, courted him over several weeks, arranged the meeting in Rome, convinced him to shift $4 million in crypto into the new Trust Wallet account, and eventually disappeared, followed by the funds minutes later.

"We aren't 100 percent sure as to technically how this happened yet, but in short it involved the scammers convincing us to move funds into a fresh wallet (which we created and controlled) in order to provide 'proof of funds'," Shams wrote.

Not the first victim

What he found in the wake of the theft and the following investigation is that such scams, while not typical, are not unheard of. He pointed to a [3]Twitter thread from 2021 in which NFT entrepreneur Jacob Riglin, founder of Dream Lab, wrote that $90,000 in crypto was stolen from him in a similar scheme that involved a meeting in Barcelona.

Also in that case, Riglin was talked into opening his crypto wallet and showing it to the scammers, again to show the "investors" that he had the money to make the deal.

[4]

In the Webaverse case, Shams wrote that he was working to close a Series A fundraising round when he was contacted by man calling himself the lawyer for a person – "Joseph Safra" – who wanted to invest in Webaverse. The email seemed to be from a legitimate law firm – Shams checked the website – and the lawyer sent him know your customer (KYC) information, which eventually turned out to be fake.

[5]

[6]

After weeks of negotiations via emails and video calls with the lawyer and "Mr. Safra," Shams agreed to meet with them in Rome. The miscreant posing as Safra said he needed proof of funds and suggested a Trusted Wallet account would be sufficient evidence.

Meeting in a hotel in Rome

Shams said he and a colleague met with Safra and his lawyer for dinner and then the next day to close the deal. He had created a fresh Trust Wallet account while still at home, using a device that Webaverse didn't typically use. The idea was that without Shams' private keys or seed phrases, the funds would be safe.

"We sat across from these men and transferred 4M USDC [USD Coin] into the Trust Wallet," Shams wrote. "'Mr Safra' asked to see the balances on the Trust Wallet app and took out his phone to 'take some pictures'. We thought it was weird but since no private keys or seed phrases were showing, we humored them."

He said Mr Safra was satisfied but needed to step outside to discuss it over with his colleagues.

[7]

"We never saw him again," Shams wrote. "Minutes later the funds left the wallet. I was in shock … I had absolutely no idea how these guys had stolen the money from us."

He said he has reported the theft to Rome police and the FBI. The ongoing investigation – including by a private lawyer hired by the Webaverse co-founder – hasn't determined exactly how the crypto was stolen. They're still working to get more information from Trust Wallet about what was going on with the wallet when the fund was drained.

Others targeted

The lawyer also said that the group that scammed Shams had reached out to other of his clients earlier in 2022, as proven by matching signatures in documents. In addition, investigators have put crypto exchanges about the miscreants.

Webaverse also is offering bounties to anyone who can help track down the scammers or recover the stolen money.

The laundering of the stolen money was extensive. Investigators found that the funds taken from Shams' wallet were split into six transactions that were sent to six previously unused addresses. Almost all the USDC was converted into Ethereum, Wrapped Bitcoin (wBTC), and Tether (USDT) and then run through a group of 14 addresses.

[8]

From there, the funds were sent to four new addresses, with about 83 percent currently sitting in one of the addresses.

Shams wrote that while the crypto theft hurt his company – as losing $4 million would – Webaverse has enough money for the next 12 to 16 months and looking to raise more money. And while the investigation continues, he's looking ahead.

"The event haunts me to this day but it has not broken me," Shams wrote. ®

Get our [9]Tech Resources



[1] https://www.theregister.com/2022/09/01/fbi_cybercrime_defi_cryptocurrency/

[2] https://docs.google.com/document/d/1qmAwMN6s2x3xOB5spyaHCTkzFjZWnUW3RU0nbuUFIy0/edit

[3] https://twitter.com/jacobriglin/status/1417797276613947393

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y@PVL3dL8EuGOOy0ytnBmQAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@PVL3dL8EuGOOy0ytnBmQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y@PVL3dL8EuGOOy0ytnBmQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@PVL3dL8EuGOOy0ytnBmQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y@PVL3dL8EuGOOy0ytnBmQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/



Whereas, in real life . . .

Pascal Monett

You want proof of funds ? I can provide you with a printout of my bank account balance.

I can even give you my IBAN number, for all the good it will do you.

If that is not enough, I can point you to my bank, where you can phone and ask questions yourself. But you won't be getting a cent either before, during or after the meeting. Not unless I actually transfer money to you, and why would I do that ?

Only in the funny-money universe can you feel obliged to actually give someone you don't know your own money just to prove that you have it.

Re: Whereas, in real life . . .

Jim Mitchell

If the article is correct, the victim did not give anyone any money. They showed them the "bank account" page with the balance on it, which was somehow enough information to initiate a transfer out.

Re: Whereas, in real life . . .

Mike 137

This is why, in high value business transactions, escrow accounts get used by the wise.

Re: Whereas, in real life . . .

Andy The Hat

Didn't need to be Escrow as *no funds were apparently moved beyond the control of the owner*.

The question is only how the scammers gained control of the wallet. It seems that everything was done correctly but the scammers were always one step ahead ... which, to be honest, is the sign of a very good scammer.

Re: Whereas, in real life . . .

Anonymous Coward

Plenty of people fall prey to fiat scams involving them logging into their bank accounts while a scammer watches, most commonly in the refund scam. In fact, it would be easier to provide secure proof of funds with a blockchain currency because you can simply give your address and transfer a tiny amount from that wallet into a designated one (absolutely no need to transfer the entire balance) in a way that's far harder to fake than a balance sheet. The balance is publicly viewable and the small transfer demonstrates control.

Who loves cryptocurrency?

Version 1.0

Cryptocurrency has just become criminal financing in recent years - I thought it was a great idea when cryptocurrency first appeared but it seems that a huge amount of criminals also thought the same thing. I've quit cryptocurrency 100% now to avoid the risks that this story describes - returning to checks, bank-transfers and credit cards is depressing but much safer and nowhere near are expensive as $4 million these days.

Re: Who loves cryptocurrency?

AndrueC

returning to checks, bank-transfers and credit cards is depressing

Is anyone still writing (sic)checks? I last saw my cheque book many years ago when I burnt it along with other old documents in a bonfire. I think in the 40 years that I've had a bank account I've only ever written a dozen cheques and none in the last 30 years.

Re: Who loves cryptocurrency?

Andy The Hat

yes

Anonymous Coward

Yes, indeed. On average about two cheques a month. When I was working in the USA I even wrote a few checks as well.

Re: Who loves cryptocurrency?

cookieMonster

In the supermarket on Saturday, bloke paying by cheque. I felt I was back in 1980.

Re: Who loves cryptocurrency?

fidodogbreath

Is anyone still writing (sic)checks?

Not if it can be avoided, but sometimes it can't. In our US state, some local taxing authorities still only take payments by paper check -- and if we want it credited properly (which we do), we also have to include the tear-off coupon from the bottom of the paper bill when we send our payment by snail mail. (This also means we still have to have postage stamps...)

Wait, there's more. Seemingly every criminal in the US has [1]keys to the postal drop boxes now , so we also have to drive to the post office and physically carry the envelope inside the building to mail it if we don't want to risk having the payment stolen (which we don't). Note: the linked article is from three years ago; the problem has gotten worse since then.

The above is not satire. This is something that we still have to do in the year of our Lord 2023, in {Jeremy Clarkson voice, although he would never say this about the US} "the greatest country...in the woooorld" -- at least for certain agencies that remain deeply stuck in the 1970s.

Also, many of the small contractors that we've hired to do work on our house don't take credit cards because of the transaction fees; nor do they use Venmo and its ilk, I suppose out of concern for being scammed or ripped off. So, checks for them as well.

[1] https://www.nbcnews.com/news/crime-courts/thieves-are-stealing-checks-usps-boxes-it-mailbox-fishing-or-n1237320

Natalie Gritpants Jr

They're not raising any money from me

Nor me. But..

Chris Evans

I don't know if his business is a good long term investment prospect but I applaud his openness. It doesn't sound like he did anything risky so I wouldn't hold that against him if I was considering investing.

NFC?

localgeek

Is it possible that some kind of NFC vulnerability was exploited? If the thief had to get close enough to take photos of a small screen, would that be close enough?

Re: NFC?

Blazde

Someone should go over the Trusted Wallet app with a fine-toothed comb. Could be some kind of NFC vulnerability, or I was thinking a backdoor inserted that leaks the private key bits via the display?

Re: NFC?

zuckzuckgo

Since they insisted on a new account, created on the spot, it could also be some kind of man-in-the middle attack using the local wifi.

Re: NFC?

The Oncoming Scorn

from the story, he created this at home on a private device, prior to the meeting.

Icon - Wheres me f**king (crypto) wallet?

Re: NFC?

zuckzuckgo

I missed that. Thanks for pointing it out.

A man in-the-middle ploy might still be able to intercept the current security token, which combined with the picture, might get them access. The location could have been chosen (whose chose it?) for its bad cell reception and the ability to setup a rogue hot spot. Obviously not a good idea to rely on restaurant WiFi but there was a security failure somewhere.

I don't know if NFC or Bluetooth are more likely but the criminals risked meeting in person so proximity and/or location were key.

Re: NFC?

jollyboyspecial

"Since they insisted on a new account, created on the spot, it could also be some kind of man-in-the middle attack using the local wifi."

Shirley nobody is foolish enough to carry out any form on financial transaction on public wifi?

Re: NFC?

DJO

Shirley nobody is foolish enough to carry out any form on financial transaction on public wifi?

Meanwhile in the real world - Yes of course they would, possibly through a VPN but then you are just transferring trust to an additional player which is no problem, until it is.

Seeing as the raison-d'etre of crypto-currency is to avoid regulatory oversight (or in plain English - money laundering & tax evasion) expecting people involved in crypto-currency to be honest and trustworthy is, to use a technical term, "fucking idiocy".

They should have been a little more

Anonymous Coward

Web-averse.

Couldn't wait till Friday :)

Timop

Cryptocurrency - to the people who are capable of auditing everything properly themselves just to prevent getting scammed.

Anonymous Coward

When Crypto Currency first became a thing a recall a lot of its fans telling us that one of it's major plus points was that because every single "coin" was unique and traceable theft was impossible.

How's that working out for them?

Inventor of the Marmite Laser

The information to make the heist must have come from SOMEWHERE. I Wonder if setting airplane mode would have made a difference.

only 2 ways it happened I see

Anonymous Coward

Since the funds were transferred out so fast, seems they already had access to the account. I expect his home PC or phone was already compromised. 99% likely once they had access to the account, they removed any spyware to hide their tracks - before transferring the funds. NFC,, could be but, that means a huge can of worms is about to burst open on NFC vulnerabilities to wallet apps, which they should have discovered by now if that was the case.

Re: only 2 ways it happened I see

jollyboyspecial

The thing about any vulnerability is you can always say on day zero that should have been discovered by now

Re: only 2 ways it happened I see

nintendoeats

log4j should have been discovered before it was even written.

As Oscar WIlde remarked

Arthur the cat

you'd have to have a heart made of stone not to laugh.

How many hors d'oeuvres you are allowed to take off a tray being carried by
a waiter at a nice party?
Two, but there are ways around it, depending on the style of the hors
d'oeuvre. If they're those little pastry things where you can't tell what's
inside, you take one, bite off about two-thirds of it, then say: "This is
cheese! I hate cheese!" Then you put the rest of it back on the tray and
bite another one and go, "Darn it! Another cheese!" and so on.
-- Dave Barry, "The Stuff of Etiquette"