Skip to main navigation Skip to search Skip to main content

Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway Scams

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

44 Scopus citations

Abstract

As cryptocurrencies increase in popularity and users obtain and manage their own assets, attackers are pivoting from just abusing cryptocurrencies as a payment mechanism, to stealing crypto assets from end users. In this paper, we report on the first large-scale analysis of cryptocurrency giveaway scams. Giveaway scams are deceptively simple scams where attackers set up webpages advertising fake events and promising users to double or triple the funds that they send to a specific wallet address. To understand the population of these scams in the wild we design and implement CryptoScamTracker, a tool that uses Certificate Transparency logs to identify likely giveaway scams. Through a 6-month-long experiment, CryptoScamTracker identified a total of 10,079 giveaway scam websites targeting users of all popular cryptocurrencies. Next to analyzing the hosting and domain preferences of giveaway scammers, we perform the first quantitative analysis of stolen funds using the public blockchains of the abused cryptocurrencies, extracting the transactions corresponding to 2,266 wallets belonging to scammers. We find that just for the scams discovered in our reporting period, attackers have stolen the equivalent of tens of millions of dollars, organizing large-scale campaigns across different cryptocurrencies. Lastly, we find evidence that attackers try to re-victimize users by offering fund-recovery services and that some victims send funds multiple times to the same scammers.

Original languageEnglish
Title of host publication30th Annual Network and Distributed System Security Symposium, NDSS 2023
PublisherThe Internet Society
ISBN (Electronic)1891562835, 9781891562839
DOIs
StatePublished - 2023
Event30th Annual Network and Distributed System Security Symposium, NDSS 2023 - San Diego, United States
Duration: Feb 27 2023Mar 3 2023

Publication series

Name30th Annual Network and Distributed System Security Symposium, NDSS 2023

Conference

Conference30th Annual Network and Distributed System Security Symposium, NDSS 2023
Country/TerritoryUnited States
CitySan Diego
Period02/27/2303/3/23

Fingerprint

Dive into the research topics of 'Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway Scams'. Together they form a unique fingerprint.

Cite this