Twitter customers must be cautious of a fraudulent account that’s impersonating Coinbase’s official BASE Layer 2 account. The account has acquired a yellow tick from Twitter, which is usually seen as an indication of authenticity by customers, however it’s in actual fact a honeypot which may be used to steal funds. This has been confirmed by PeckShieldAlert, which detected that the account, named BuilldOnBase, is a cast Twitter account and never the actual BuildOnBase.
Additional investigation by PeckShieldAlert discovered that the phishing website base[.]web3claiming[.]com was related to the faux account. A contract “Claimer” was additionally created by a person with the deal with Fake_Phishing38689, which was registered on etherscan.io six days in the past.
#PeckShieldAlert Our neighborhood contributor has detected @BuilldOnBase with a yellow tick is a cast #twitter account, not the actual @BuildOnBase
base[.]web3claiming[.]com is the phishing website, Fake_Phishing38689 created the contract “Claimer” https://t.co/Iw1FdVPgd5 ~6 days in the past pic.twitter.com/ThQ1ub8fOi— PeckShieldAlert (@PeckShieldAlert) March 6, 2023
The fraudulent account is a transparent try to reap the benefits of Twitter’s verification system, which may be simply tricked by attackers. It is very important do not forget that the blue or yellow tick doesn’t assure the authenticity of an account, and customers ought to all the time train warning when partaking with accounts claiming to signify official organizations.
Using social media to unfold phishing scams is nothing new. Attackers usually impersonate respectable accounts to achieve the belief of customers and steal their funds. Since Elon Musk’s takeover, the previous verification system has develop into out of date, and the brand new method of receiving a affirmation occurred, the place nearly any enterprise can get a yellow mark.
To guard themselves from such scams, customers ought to all the time confirm the legitimacy of an account and a contract by visiting an organization’s official web site and utilizing their official social hyperlinks. Moreover, customers ought to by no means share their personal keys or seed phrases with anybody and will all the time double-check any messages they’re signing of their Web3 wallets.