The popularity and hype around purchasing digital assets such as art, video, and music in the form of Non-fungible tokens (NFTs) has rapidly made them a lucrative investment opportunity, with NFT-based sales surpassing $25B in 2021 alone. However, the volatility and scarcity of NFTs, combined with the general lack of familiarity with the technical aspects of this ecosystem, encourage the spread of several scams. The success of an NFT is majorly impacted by its online virality. There have been sparse reports about scammers emulating this virality by either promoting their fraudulent NFT projects on social media or imitating other popular NFT projects. This paper presents a longitudinal analysis of 439 unique Twitter accounts that consistently promote fraudulent NFT collections through giveaway competitions and 1,028 NFT phishing attacks. Our findings indicate that most accounts interacting with these promotions are bots, which can rapidly increase the popularity of the fraudulent NFT collections by inflating their likes, followers, and retweet counts. This leads to significant engagement from real users, who then proceed to invest in the scams. On the other hand, we identify two novel attack vectors which are utilized by NFT phishing scams to steal funds and digital assets from the victim's wallet. We also identify several gaps in the prevalent anti-phishing ecosystem by evaluating the performance of popular anti-phishing blocklists and security tools against NFT phishing attacks. We utilize our findings to develop a machine learning classifier that can automatically detect NFT phishing scams at scale.
翻译:购买艺术、视频和音乐等数字资产(如艺术、视频和音乐)的受欢迎程度和杂乱无章,迅速使其成为一个有利可图的投资机会,光是2021年,NFT的销售额就超过25B美元。然而,NFT的波动性和稀缺性,加上普遍不熟悉这一生态系统的技术方面,鼓励了多种骗局的蔓延。NFT的成功受到其在线病毒性的主要影响。关于欺骗者模仿这种病毒的报告很少,要么在社交媒体上宣传其欺诈性NFT项目,要么模仿其他流行的NFT项目。本文对439个独特的Twitter账户进行了纵向分析,这些账户通过提供竞争和1 028 NFT的网络钓鱼袭击,不断促进欺诈性NFT收藏。我们的研究结果表明,大多数与这些推广活动互动的账户都是机器人,这可以通过粉饰其像、追随者以及Retweet 来迅速增加欺诈性NFT收藏的受欢迎程度。我们从真实用户那里学到大量接触,然后通过对正反面的NFT工具进行投资进行投资,我们利用了两处的货币变变的货币。