Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

Monad Airdrop被黑?慢雾余弦:有人 Wallet 地址被偷偷换了

robot
Abstract generation in progress

[Coin World] On November 25, the Slow Fog security team member Yu Xian issued an important reminder: Many people may not have received the Monad Airdrop at all, so it's urgent to check if the wallet Address bound at that time is correct.

A user called Onefly fell victim to this - the address linked on the Airdrop page was secretly replaced with that of a hacker, and the official process sent the coins over, resulting in everything ending up in the hacker's pocket. Yu Xian had heard a white hat hacker mention this before, claiming that there is a rather hidden vulnerability.

What is the problem? If someone is watching you and hijacks your session on the Monad Airdrop page, they can stealthily change the receiving Address without you needing to confirm the authorization again. By the time you realize it, the money has already flown away.

So hurry up and verify the bound address, don't wait until the Airdrop disappears before you regret it. Session hijacking is not a new attack method, but being able to change the address directly on the claim page without triggering secondary verification is indeed a bit careless.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
DegenWhisperervip
· 11-27 19:14
Wow, session hijacking can change the Address directly without secondary verification? This is too absurd, hurry up and check your bound Address.
View OriginalReply0
AirdropHunter420vip
· 11-26 01:01
I need to hurry and check if my Address has been tampered with, this is so disgusting.
View OriginalReply0
LiquidationWatchervip
· 11-25 01:52
Damn, here we go again. Is it really possible to hijack the conversation and change the address without any verification? How crappy does the code have to be? Let me check my bound address... all good, all good. What is the project team doing? Even the airdrop can get hacked like this. Onefly really took a huge loss this time, totally cleaned out. Better hurry and ask the official team if there’s any way to recover it. There should be some records, right?
View OriginalReply0
GhostWalletSleuthvip
· 11-25 01:49
Damn, is it session hijacking again? Monad's security awareness is really lacking. Quickly check your address, don't get taken without knowing it. How could such a low-level vulnerability be overlooked? How did the officials audit it? It feels like this airdrop has had a lot of issues from the very beginning, no wonder the reputation has collapsed recently. Haven't we learned enough from last year's lessons? Not even adding two-factor authentication? I checked once, luckily I wasn't swapped, but this is really quite creepy.
View OriginalReply0
CrossChainMessengervip
· 11-25 01:31
Hurry up and check your bound address, everyone. The session hijacking tricks are too clever. This wave from Monad really raises a question mark. Is the official security review a bit lax? Changing the address in a session hijack doesn't require a second verification? This vulnerability is simply a hacker's carnival. How many people really fell for it? It feels like more than just Onefly got played for suckers. That's why I never put too much information on the airdrop page; it's too dangerous, bro. Thanks to Slow Fog for the timely reminder, otherwise, there would be people losing everything. Web3 is like this; you have to protect yourself. The project party can't be relied on. Hurry up and change your password and wallet. This incident with Monad really raises awareness. As for session hijacking, how many people never thought it would happen to them?
View OriginalReply0
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)