AB Finance Airdrop Scam: Difference between revisions
No edit summary |
(Temp save part way 9 minutes left.) |
||
| Line 1: | Line 1: | ||
{{ | {{Case Study Under Construction}}{{Unattributed Sources}} | ||
{{Unattributed Sources}} | |||
[[File:Abfinance.jpg|thumb|AB Finance]]At some point on August 25th of 2021, millions of Binance smart chain addresses received a mysterious ABFin token, which appeared to be valuable and directed them to abfin.org. On that website, AB Finance claimed to be a regulated company and that all users had to do to sell their tokens was to unlock them. The unlocking process only required users to give full control over their wallet to the website, at which point any other tokens in their wallet could be withdrawn. The website appears to have subsequently upgraded to look more similar to PancakeSwap, which likely enticed more users to attempt the swap. It's unclear how many users were affected, and whether any further investigation was performed to attempt to recover funds. | [[File:Abfinance.jpg|thumb|AB Finance]]At some point on August 25th of 2021, millions of Binance smart chain addresses received a mysterious ABFin token, which appeared to be valuable and directed them to abfin.org. On that website, AB Finance claimed to be a regulated company and that all users had to do to sell their tokens was to unlock them. The unlocking process only required users to give full control over their wallet to the website, at which point any other tokens in their wallet could be withdrawn. The website appears to have subsequently upgraded to look more similar to PancakeSwap, which likely enticed more users to attempt the swap. It's unclear how many users were affected, and whether any further investigation was performed to attempt to recover funds. | ||
This is a global/international case not involving a specific country.<ref name="metamaskmedium-8279" /><ref name="youtube-10155" /><ref name="abfinarchive-10156" /><ref name="abfinarchive-10157" /><ref name="reddit-10158" /><ref name="thebittimes-10159" /><ref name="bscscan-10160" /><ref name="bscscan-10161" /><ref name="coinmarketbag-10162 | This is a global/international case not involving a specific country.<ref name="metamaskmedium-8279" /><ref name="youtube-10155" /><ref name="abfinarchive-10156" /><ref name="abfinarchive-10157" /><ref name="reddit-10158" /><ref name="thebittimes-10159" /><ref name="bscscan-10160" /><ref name="bscscan-10161" /><ref name="coinmarketbag-10162" /> | ||
== About AB Finance == | == About AB Finance == | ||
"ABFIN Token Finance is a regulated [c]ompany. All you need to do in order to exchange your ABFIN Token is going through easy step by clicking on the Claim ABFIN Token Button, after this is done, you will be able to Exchange them to BNB in PancakeSwap." | "ABFIN Token Finance is a regulated [c]ompany. All you need to do in order to exchange your ABFIN Token is going through easy step by clicking on the Claim ABFIN Token Button, after this is done, you will be able to Exchange them to BNB in PancakeSwap." | ||
Homepage: <ref>[https://web.archive.org/web/20210825045422/https://abfin.me/ AB Finance Homepage Archive August 24th, 2021 10:54:22 PM MDT] (Jan 13, 2023)</ref><ref>[https://web.archive.org/web/20210902150640/https://abfin.me/ AB Finance Homepage Archive September 2nd, 2021 9:06:40 AM MDT] (Nov 24, 2023)</ref> | |||
" | == The Reality == | ||
"Today I'm bringing you a token called AB Finance, which you probably received eight million, and you're trying to sell it on PancakeSwap and it doesn't work. So, this is a scam. Let's take a look at the token first. As you can see, one million people - one million four hundred thousand people received this token. Everyone seems to be having this almost nine million tokens."<ref name="youtube-10163" /> | |||
"As you can see, uh, there is, uh, the burn address has 100 percent of the tokens. One of the - this is the scammers address has 99 percent, and everyone seems to have, you know, that - this is more than 100 percent, so. And if you add together that a million people received these tokens you can see that it's way more than 100 percent in total. So, when you're trying to unlock this then, it tells you to, tells you to go to this website called abfin.org, but this is redirected to abfin.me. Which this is the website."<ref name="youtube-10163" /> | |||
Scamdrop warning: <ref name="coinmarketbag-10162" /> | |||
= | |||
== What Happened == | == What Happened == | ||
| Line 56: | Line 29: | ||
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. | |Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. | ||
|- | |- | ||
| | |August 7th, 2021 11:30:07 AM MDT | ||
| | |YouTube Video Warning | ||
| | |Altcoin Detective publishes a YouTube video about the AB Finance token airdrop, which highlights that trading of the tokens is not possible and warns users not to attempt to connect their wallets with the malicious website<ref name="youtube-10163" />. | ||
|- | |||
|August 27th, 2021 7:53:42 PM MDT | |||
|Scamdrop Warning | |||
|The Scamdrop service publishes a warning specifically about the ABFin token airdrop<ref>[https://web.archive.org/web/20210901122325/https://coinmarketbag.com/abfin-org-abfin-token-airdrop-scamdrop-warning/ ABFIN.org (ABFIN) Token Airdrop – Scamdrop Warning Archive September 1st, 2021 6:23:25 AM MDT] (Nov 24, 2023)</ref>. | |||
|} | |} | ||
== Technical Details == | == Technical Details == | ||
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited? | This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited? | ||
"As you can see, uh, there is, uh, the burn address has 100 percent of the tokens. One of the - this is the scammers address has 99 percent, and everyone seems to have, you know, that - this is more than 100 percent, so. And if you add together that a million people received these tokens you can see that it's way more than 100 percent in total. So, when you're trying to unlock this then, it tells you to, tells you to go to this website called abfin.org, but this is redirected to abfin.me. Which this is the website."<ref name="youtube-10163" /> | |||
"The scam only works if you click on this button, right. There is a pop-up and you unlock the wallet. When you do this, you authorize the scammer to take other tokens from your wallet and and take it from you. So whatever you do, don't click this and you know, either MetaMask will pop up and and ask for authorization. Once you do that, you are in trouble." "This is the only way they can take money from you."<ref name="youtube-10163" /> | |||
== Total Amount Lost == | == Total Amount Lost == | ||
| Line 71: | Line 52: | ||
== Immediate Reactions == | == Immediate Reactions == | ||
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed? | How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed? | ||
"From that one million four hundred thousand addresses that received this airdrop, nobody was able to trade the token on poocoin, so it's not possible to get rid of, you know, get rid of the tokens from your wallet. It's not possible to buy or sell this token. So what you can do is just leave it alone in your wallet. Don't go to this website and try to unlock your wallet."<ref name="youtube-10163" /> | |||
== Ultimate Outcome == | == Ultimate Outcome == | ||
"From that one million four hundred thousand addresses that received this airdrop, nobody was able to trade the token on poocoin, so it's not possible to get rid of, you know, get rid of the tokens from your wallet. It's not possible to buy or sell this token. So what you can do is just leave it alone in your wallet. Don't go to this website and try to unlock your wallet."<ref name="youtube-10163" /> | |||
== Total Amount Recovered == | == Total Amount Recovered == | ||
| Line 100: | Line 83: | ||
== References == | == References == | ||
<references><ref name="metamaskmedium-8279">[https://medium.com/metamask/phisher-watch-airdrop-scams-82eea95d9b2a Phisher Watch Airdrop Scams] (Jul 2, 2022)</ref> | <references> | ||
<ref name="metamaskmedium-8279">[https://medium.com/metamask/phisher-watch-airdrop-scams-82eea95d9b2a Phisher Watch Airdrop Scams] (Jul 2, 2022)</ref> | |||
<ref name="youtube-10155">[https://www.youtube.com/watch?v=M4rwlfzYskw ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning - YouTube] (Jul 2, 2022)</ref> | <ref name="youtube-10155">[https://www.youtube.com/watch?v=M4rwlfzYskw ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning - YouTube] (Jul 2, 2022)</ref> | ||
<ref name="abfinarchive-10156">[https://web.archive.org/web/20210826114108/https://abfin.me/ AB FINANCE] (Jan 5, 2023)</ref> | <ref name="abfinarchive-10156">[https://web.archive.org/web/20210826114108/https://abfin.me/ AB FINANCE] (Jan 5, 2023)</ref> | ||
<ref name="abfinarchive-10157">[https://web.archive.org/web/20210902150533/https://abfin.me/ ABFINANCE] (Jan 5, 2023)</ref> | <ref name="abfinarchive-10157">[https://web.archive.org/web/20210902150533/https://abfin.me/ ABFINANCE] (Jan 5, 2023)</ref> | ||
<ref name="reddit-10158">[https://www.reddit.com/r/CryptoCurrency/comments/pb52n7/careful_for_the_scam_abfinorg/ Careful for the scam ABFIN.org : CryptoCurrency] (Jan 5, 2023)</ref> | <ref name="reddit-10158">[https://www.reddit.com/r/CryptoCurrency/comments/pb52n7/careful_for_the_scam_abfinorg/ Careful for the scam ABFIN.org : CryptoCurrency] (Jan 5, 2023)</ref> | ||
<ref name="thebittimes-10159">[https://thebittimes.com/token-ABFIN-BSC-0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6.html ABFIN.org( ABFIN ) info, ABFIN.org( ABFIN ) chart, market cap, and price | TheBitTimes.Com] (Jan 5, 2023)</ref> | <ref name="thebittimes-10159">[https://thebittimes.com/token-ABFIN-BSC-0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6.html ABFIN.org( ABFIN ) info, ABFIN.org( ABFIN ) chart, market cap, and price | TheBitTimes.Com] (Jan 5, 2023)</ref> | ||
<ref name="bscscan-10160">[https://bscscan.com/address/0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 Fake_Phishing73 | Address 0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 | BscScan] (Jan 5, 2023)</ref> | <ref name="bscscan-10160">[https://bscscan.com/address/0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 Fake_Phishing73 | Address 0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 | BscScan] (Jan 5, 2023)</ref> | ||
<ref name="bscscan-10161">[https://bscscan.com/bytecode-decompiler?a=0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 Online EVM Bytecode Decompiler] (Jan 5, 2023)</ref> | <ref name="bscscan-10161">[https://bscscan.com/bytecode-decompiler?a=0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 Online EVM Bytecode Decompiler] (Jan 5, 2023)</ref> | ||
<ref name="coinmarketbag-10162">[https://coinmarketbag.com/abfin-org-abfin-token-airdrop-scamdrop-warning/ ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning - CoinMarketBag] (Jan 5, 2023)</ref> | |||
<ref name="coinmarketbag-10162">[https://coinmarketbag.com/abfin-org-abfin-token-airdrop-scamdrop-warning/ ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning | <ref name="youtube-10163">[https://www.youtube.com/watch?v=qVctR_kdtY4 Altcoin Detective - How to check if your wallet is hacked by an airdrop or your tokens are SAFU? - YouTube] (Jan 5, 2023)</ref> | ||
</references> | |||
<ref name="youtube-10163">[https://www.youtube.com/watch?v=qVctR_kdtY4 How to check if your wallet is hacked by an airdrop or your tokens are SAFU? - YouTube] (Jan 5, 2023)</ref></references> | |||
Revision as of 16:59, 24 November 2023
Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
At some point on August 25th of 2021, millions of Binance smart chain addresses received a mysterious ABFin token, which appeared to be valuable and directed them to abfin.org. On that website, AB Finance claimed to be a regulated company and that all users had to do to sell their tokens was to unlock them. The unlocking process only required users to give full control over their wallet to the website, at which point any other tokens in their wallet could be withdrawn. The website appears to have subsequently upgraded to look more similar to PancakeSwap, which likely enticed more users to attempt the swap. It's unclear how many users were affected, and whether any further investigation was performed to attempt to recover funds.
This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9]
About AB Finance
"ABFIN Token Finance is a regulated [c]ompany. All you need to do in order to exchange your ABFIN Token is going through easy step by clicking on the Claim ABFIN Token Button, after this is done, you will be able to Exchange them to BNB in PancakeSwap."
The Reality
"Today I'm bringing you a token called AB Finance, which you probably received eight million, and you're trying to sell it on PancakeSwap and it doesn't work. So, this is a scam. Let's take a look at the token first. As you can see, one million people - one million four hundred thousand people received this token. Everyone seems to be having this almost nine million tokens."[12]
"As you can see, uh, there is, uh, the burn address has 100 percent of the tokens. One of the - this is the scammers address has 99 percent, and everyone seems to have, you know, that - this is more than 100 percent, so. And if you add together that a million people received these tokens you can see that it's way more than 100 percent in total. So, when you're trying to unlock this then, it tells you to, tells you to go to this website called abfin.org, but this is redirected to abfin.me. Which this is the website."[12]
Scamdrop warning: [9]
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| August 25th, 2021 | Main Event | Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. |
| August 7th, 2021 11:30:07 AM MDT | YouTube Video Warning | Altcoin Detective publishes a YouTube video about the AB Finance token airdrop, which highlights that trading of the tokens is not possible and warns users not to attempt to connect their wallets with the malicious website[12]. |
| August 27th, 2021 7:53:42 PM MDT | Scamdrop Warning | The Scamdrop service publishes a warning specifically about the ABFin token airdrop[13]. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
"As you can see, uh, there is, uh, the burn address has 100 percent of the tokens. One of the - this is the scammers address has 99 percent, and everyone seems to have, you know, that - this is more than 100 percent, so. And if you add together that a million people received these tokens you can see that it's way more than 100 percent in total. So, when you're trying to unlock this then, it tells you to, tells you to go to this website called abfin.org, but this is redirected to abfin.me. Which this is the website."[12]
"The scam only works if you click on this button, right. There is a pop-up and you unlock the wallet. When you do this, you authorize the scammer to take other tokens from your wallet and and take it from you. So whatever you do, don't click this and you know, either MetaMask will pop up and and ask for authorization. Once you do that, you are in trouble." "This is the only way they can take money from you."[12]
Total Amount Lost
The total amount lost is unknown.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
"From that one million four hundred thousand addresses that received this airdrop, nobody was able to trade the token on poocoin, so it's not possible to get rid of, you know, get rid of the tokens from your wallet. It's not possible to buy or sell this token. So what you can do is just leave it alone in your wallet. Don't go to this website and try to unlock your wallet."[12]
Ultimate Outcome
"From that one million four hundred thousand addresses that received this airdrop, nobody was able to trade the token on poocoin, so it's not possible to get rid of, you know, get rid of the tokens from your wallet. It's not possible to buy or sell this token. So what you can do is just leave it alone in your wallet. Don't go to this website and try to unlock your wallet."[12]
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
General Prevention Policies
When self-custodying, users have a responsibility to always take great care with any approvals they make. Approving full permissions to a website is usually not advisable. Another method of reducing risk would be to move the majority of funds to a fully offline wallet which is not interacted with.
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ Phisher Watch Airdrop Scams (Jul 2, 2022)
- ↑ ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning - YouTube (Jul 2, 2022)
- ↑ AB FINANCE (Jan 5, 2023)
- ↑ ABFINANCE (Jan 5, 2023)
- ↑ Careful for the scam ABFIN.org : CryptoCurrency (Jan 5, 2023)
- ↑ ABFIN.org( ABFIN ) info, ABFIN.org( ABFIN ) chart, market cap, and price | TheBitTimes.Com (Jan 5, 2023)
- ↑ Fake_Phishing73 | Address 0xb8a9704d48c3e3817cc17bc6d350b00d7caaecf6 | BscScan (Jan 5, 2023)
- ↑ Online EVM Bytecode Decompiler (Jan 5, 2023)
- ↑ 9.0 9.1 ABFIN.org (ABFIN) Token Airdrop - Scamdrop Warning - CoinMarketBag (Jan 5, 2023)
- ↑ AB Finance Homepage Archive August 24th, 2021 10:54:22 PM MDT (Jan 13, 2023)
- ↑ AB Finance Homepage Archive September 2nd, 2021 9:06:40 AM MDT (Nov 24, 2023)
- ↑ 12.0 12.1 12.2 12.3 12.4 12.5 12.6 Altcoin Detective - How to check if your wallet is hacked by an airdrop or your tokens are SAFU? - YouTube (Jan 5, 2023)
- ↑ ABFIN.org (ABFIN) Token Airdrop – Scamdrop Warning Archive September 1st, 2021 6:23:25 AM MDT (Nov 24, 2023)