I get that this attack vector as described is mitigated by reviewing the entire address but most of us don’t do that most of the time. Just trying to see if this is worth worrying about or if it’s old news.
this post was submitted on 16 Nov 2023
1 points (100.0% liked)
Ethereum
5 readers
1 users here now
Resources
- Website & Blog
- White Paper & Yellow Paper
- Documentation & Stack Exchange
- Learn Solidity
- Source Code on Github
- Bounty program
- Chat on Gitter
- Network Status & Gas Price Market
- List of DApps
- Meetups
founded 1 year ago
MODERATORS
1
Is this tech radar post about create2 FUD, old news, or something to worry about?
(www.techradar.com)
The title of the article is pure fud, and I think the article doesn't describe the issue very well, but it looks like the issue itself is real.
The original report describes the issue much better, and without fud: https://drops.scamsniffer.io/post/wallet-drainers-starts-using-create2-bypass-wallet-security-alert/
So it looks like scammers found a way to circumvent wallet warnings (like Rabby has for example) for known scam addresses. I don't understand how users are lured into using the contracts that sends their funds to these addresses though?