ShibaSwap Phishing Site: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/shibaswapphishingsite.php}} thumb|ShibaSwapShibaSwap is a popular decentralized exchange platform used to swap between different tokens in the Shiba Inu ecosystem. While the .com website appears to offer a legitimate exchange, the .co and other variants are phishing websites which trick users into approving malicious wallet-emptying transactions. At least $39k worth of token...")
 
No edit summary
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/shibaswapphishingsite.php}}
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/shibaswapphishingsite.php}}
{{Unattributed Sources}}


[[File:Shibaswap.jpg|thumb|ShibaSwap]]ShibaSwap is a popular decentralized exchange platform used to swap between different tokens in the Shiba Inu ecosystem. While the .com website appears to offer a legitimate exchange, the .co and other variants are phishing websites which trick users into approving malicious wallet-emptying transactions. At least $39k worth of tokens were stolen through this trickery, and there are undoubtedly many more not publicly reported. There is no indication of any funds having been recovered.
[[File:Shibaswap.jpg|thumb|ShibaSwap]]ShibaSwap is a popular decentralized exchange platform used to swap between different tokens in the Shiba Inu ecosystem. While the .com website appears to offer a legitimate exchange, the .co and other variants are phishing websites which trick users into approving malicious wallet-emptying transactions. At least $39k worth of tokens were stolen through this trickery, and there are undoubtedly many more not publicly reported. There is no indication of any funds having been recovered.


This is a global/international case not involving a specific country.
This is a global/international case not involving a specific country.
<ref name="amanusktwitter-8702" /><ref name="0xphil87twitter-8703" /><ref name="dafiarecordtwitter-8704" /><ref name="alucard31400twitter-8705" /><ref name="cxryptocrazee1twitter-8706" /><ref name="shytoshikusamatwitter-8707" /><ref name="etherscan-8708" /><ref name="etherscan-8709" /><ref name="etherscan-8710" /><ref name="publish0x-8711" /><ref name="reddit-8712" /><ref name="reddit-8713" /><ref name="youtube-8714" /><ref name="shibdefendertwitter-8715" /><ref name="shibaswaparchive-8716" /><ref name="realepiczacktwitter-8717" /><ref name="kornykorytwitter-8718" /><ref name="jorgelouisfhtwitter-8719" /><ref name="fotosecuadortwitter-8720" /><ref name="shibneverdie1twitter-8721" /><ref name="shibinformertwitter-8722" /><ref name="shibaswap-8723" /><ref name="coinmarketcap-8724" /><ref name="shibatoken-8725" /><ref name="coindesk-8726" />


== About ShibaSwap ==
== About ShibaSwap ==
Line 88: Line 90:


== Total Amount Recovered ==
== Total Amount Recovered ==
The total amount recovered has been estimated at $0 USD.
There do not appear to have been any funds recovered in this case.


What funds were recovered? What funds were reimbursed for those affected users?
What funds were recovered? What funds were reimbursed for those affected users?
Line 101: Line 103:


== References ==
== References ==
[https://twitter.com/amanusk_/status/1412424005588590595 @amanusk_ Twitter] (Jun 26)
<references><ref name="amanusktwitter-8702">[https://twitter.com/amanusk_/status/1412424005588590595 @amanusk_ Twitter] (Jun 26, 2022)</ref>


[https://twitter.com/0xPhil87/status/1412864442379952132 @0xPhil87 Twitter] (Jul 23)
<ref name="0xphil87twitter-8703">[https://twitter.com/0xPhil87/status/1412864442379952132 @0xPhil87 Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/DafiaRecord/status/1401488131266842628 @DafiaRecord Twitter] (Jul 23)
<ref name="dafiarecordtwitter-8704">[https://twitter.com/DafiaRecord/status/1401488131266842628 @DafiaRecord Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/Alucard31400/status/1408351918536146944 @Alucard31400 Twitter] (Jul 23)
<ref name="alucard31400twitter-8705">[https://twitter.com/Alucard31400/status/1408351918536146944 @Alucard31400 Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/cxryptocrazee1/status/1416585065530863625 @cxryptocrazee1 Twitter] (Jul 23)
<ref name="cxryptocrazee1twitter-8706">[https://twitter.com/cxryptocrazee1/status/1416585065530863625 @cxryptocrazee1 Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/ShytoshiKusama/status/1390021020019421187 @ShytoshiKusama Twitter] (Jul 23)
<ref name="shytoshikusamatwitter-8707">[https://twitter.com/ShytoshiKusama/status/1390021020019421187 @ShytoshiKusama Twitter] (Jul 23, 2022)</ref>


[https://etherscan.io/address/0x15e9e90bec057e56fde50539e5dfb0167b056834 https://etherscan.io/address/0x15e9e90bec057e56fde50539e5dfb0167b056834] (Jul 23)
<ref name="etherscan-8708">[https://etherscan.io/address/0x15e9e90bec057e56fde50539e5dfb0167b056834 https://etherscan.io/address/0x15e9e90bec057e56fde50539e5dfb0167b056834] (Jul 23, 2022)</ref>


[https://etherscan.io/tx/0x42567a0397c2d51ef2614b3bb259179e539fefbbbf75b5a93216e4b4b585464a https://etherscan.io/tx/0x42567a0397c2d51ef2614b3bb259179e539fefbbbf75b5a93216e4b4b585464a] (Jul 23)
<ref name="etherscan-8709">[https://etherscan.io/tx/0x42567a0397c2d51ef2614b3bb259179e539fefbbbf75b5a93216e4b4b585464a https://etherscan.io/tx/0x42567a0397c2d51ef2614b3bb259179e539fefbbbf75b5a93216e4b4b585464a] (Jul 23, 2022)</ref>


[https://etherscan.io/address/0x016dcae1e73ae2ef1192bc3c9b3737c43b06d43c https://etherscan.io/address/0x016dcae1e73ae2ef1192bc3c9b3737c43b06d43c] (Jul 23)
<ref name="etherscan-8710">[https://etherscan.io/address/0x016dcae1e73ae2ef1192bc3c9b3737c43b06d43c https://etherscan.io/address/0x016dcae1e73ae2ef1192bc3c9b3737c43b06d43c] (Jul 23, 2022)</ref>


[https://www.publish0x.com/cryptoinvesting/possible-fake-shibaswap-xlzylvx https://www.publish0x.com/cryptoinvesting/possible-fake-shibaswap-xlzylvx] (Jul 23)
<ref name="publish0x-8711">[https://www.publish0x.com/cryptoinvesting/possible-fake-shibaswap-xlzylvx https://www.publish0x.com/cryptoinvesting/possible-fake-shibaswap-xlzylvx] (Jul 23, 2022)</ref>


[https://www.reddit.com/domain/shibaswap.co/ shibaswap.co on reddit.com] (Jul 23)
<ref name="reddit-8712">[https://www.reddit.com/domain/shibaswap.co/ shibaswap.co on reddit.com] (Jul 23, 2022)</ref>


[https://www.reddit.com/r/SHIBArmy/comments/o09i8m/httpsshibaswapco/ https://shibaswap.co : SHIBArmy] (Jul 23)
<ref name="reddit-8713">[https://www.reddit.com/r/SHIBArmy/comments/o09i8m/httpsshibaswapco/ https://shibaswap.co : SHIBArmy] (Jul 23, 2022)</ref>


[https://www.youtube.com/watch?v=Vuii9xV0oGM SHIBA INU Enjoy the ride! - YouTube] (Jul 23)
<ref name="youtube-8714">[https://www.youtube.com/watch?v=Vuii9xV0oGM SHIBA INU Enjoy the ride! - YouTube] (Jul 23, 2022)</ref>


[https://twitter.com/ShibDefender/status/1402525749622542336 @ShibDefender Twitter] (Jul 23)
<ref name="shibdefendertwitter-8715">[https://twitter.com/ShibDefender/status/1402525749622542336 @ShibDefender Twitter] (Jul 23, 2022)</ref>


[https://web.archive.org/web/20210617054102/https://shibaswap.co/ ShibaSwap Interface] (Jul 23)
<ref name="shibaswaparchive-8716">[https://web.archive.org/web/20210617054102/https://shibaswap.co/ ShibaSwap Interface] (Jul 23, 2022)</ref>


[https://twitter.com/realepiczack/status/1412869582575095812 @realepiczack Twitter] (Jul 23)
<ref name="realepiczacktwitter-8717">[https://twitter.com/realepiczack/status/1412869582575095812 @realepiczack Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/kornykory/status/1412628018217033729 @kornykory Twitter] (Jul 23)
<ref name="kornykorytwitter-8718">[https://twitter.com/kornykory/status/1412628018217033729 @kornykory Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/Jorgelouisfh/status/1412029811443351555 @Jorgelouisfh Twitter] (Jul 23)
<ref name="jorgelouisfhtwitter-8719">[https://twitter.com/Jorgelouisfh/status/1412029811443351555 @Jorgelouisfh Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/Fotos_Ecuador/status/1394352204602134536 @Fotos_Ecuador Twitter] (Jul 23)
<ref name="fotosecuadortwitter-8720">[https://twitter.com/Fotos_Ecuador/status/1394352204602134536 @Fotos_Ecuador Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/ShiBNeverDie1/status/1411907534537904128 @ShiBNeverDie1 Twitter] (Jul 23)
<ref name="shibneverdie1twitter-8721">[https://twitter.com/ShiBNeverDie1/status/1411907534537904128 @ShiBNeverDie1 Twitter] (Jul 23, 2022)</ref>


[https://twitter.com/ShibInformer/status/1411829679137476611 @ShibInformer Twitter] (Jul 23)
<ref name="shibinformertwitter-8722">[https://twitter.com/ShibInformer/status/1411829679137476611 @ShibInformer Twitter] (Jul 23, 2022)</ref>


[https://shibaswap.com/ https://shibaswap.com/] (Jul 23)
<ref name="shibaswap-8723">[https://shibaswap.com/ https://shibaswap.com/] (Jul 23, 2022)</ref>


[https://coinmarketcap.com/exchanges/shibaswap/ https://coinmarketcap.com/exchanges/shibaswap/] (Jul 23)
<ref name="coinmarketcap-8724">[https://coinmarketcap.com/exchanges/shibaswap/ https://coinmarketcap.com/exchanges/shibaswap/] (Jul 23, 2022)</ref>


[https://shibatoken.com/ Shiba Token — A Decentralized Ecosystem] (Jul 23)
<ref name="shibatoken-8725">[https://shibatoken.com/ Shiba Token — A Decentralized Ecosystem] (Jul 23, 2022)</ref>


[https://www.coindesk.com/learn/what-is-shibaswap/ What Is ShibaSwap? What You Need to Know About the ShibaSwap Exchange] (Jul 23)
<ref name="coindesk-8726">[https://www.coindesk.com/learn/what-is-shibaswap/ What Is ShibaSwap? What You Need to Know About the ShibaSwap Exchange] (Jul 23, 2022)</ref></references>

Revision as of 11:32, 22 February 2023

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

ShibaSwap

ShibaSwap is a popular decentralized exchange platform used to swap between different tokens in the Shiba Inu ecosystem. While the .com website appears to offer a legitimate exchange, the .co and other variants are phishing websites which trick users into approving malicious wallet-emptying transactions. At least $39k worth of tokens were stolen through this trickery, and there are undoubtedly many more not publicly reported. There is no indication of any funds having been recovered.

This is a global/international case not involving a specific country. [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21][22][23][24][25]

About ShibaSwap

"Buy, Sell and Trade 10,000 unique Shiboshis. Unique and only available on ShibaSwap. You do not want to miss this unique NFT drop!" "Launched in July 2021, the ShibaSwap exchange provides many of the same functions you would find on Uniswap and other decentralized exchanges, such as token swapping and liquidity pools, with the addition of other features such as staking, governance and a “Shiboshis” non-fungible token (NFT) marketplace."

"SHIB and LEASH are best purchased and sold through ShibaSwap, but can also be found on Uniswap and an ever-growing list of CEXs. Please note that, outside of ShibaSwap, exchanges which support one may not support the other." "ShibaSwap is the native decentralized exchange (DEX) of the shiba inu coin project; a popular meme coin and leading competitor of dogecoin that has risen to fame over the last 18 months. DEXs operate differently from centralized platforms such as Binance and Kraken by allowing users to swap tokens without the need for an intermediary or counterparty."

"Shiba Inu is a popular dog-themed meme coin that was inspired by the success of Dogecoin and has earned itself the title of “Dogecoin killer.” Shiba Inu recently [November 2021] managed to briefly surpass Dogecoin in market capitalization, partly thanks to its ShibaSwap exchange." "ShibaSwap enables users to provide liquidity and swap different tokens while earning its governance token BONE in the process. Users can also trade NFTs, so-called “Shibatoshis,” a collection of 10,000 unique NFTs related to the Shiba Inu ecosystem. Other functionalities include staking, swapping tokens, collecting rewards and checking portfolio analytics."

"I'm not here to tell you what to do with Shibaswap. That's a project I'm just watching from the sidelines. But I did notice there might be a fake Shibaswap trying to take advantage of all you Inus. The one that looks like a scam is at shibaswap.co, while the real one is at shibaswap.com."

"shibaswap[.]co (unlike [.]com) is a phishing site that (as one would expect) asks for you secret seed phrase (in Spanish). This is the leading result for "shibaswap" on @DuckDuckGo."

"If you go to the fake one and you accidentally connect your wallet, I would immediately move everything out of that wallet. You never know what kind of crazy shit could be on the contracts on that page. The page itself could also have malware on it, so I'd also run a malware check if you come off of the fake page."

"Reme[m]ber also shibaswap.co is also SCAMMMM. [B]e careful[,] [t]eam @Shibtoken. [L]et the community know this."

"#ShibaArmy be careful I type shibaswap in google search and it list the http://1.st page http://shibaswap.co I opened It with google chrome with no script protection (Yeah, my fault! I know, stupid!!!) I close the site immediately but It was too late! Lost ALL!"

"I got scammed out of 10k by going to http://shibaswap.co! I'm not a whale but a minnow. It really hurt me bad. What goes around comes around as God sees all."

"@DuckDuckGo IDK how to report sites but https://shibaswap.co and https://shibaswap.works are the 2nd and 3rd results when searching for https://shibaswap.com. The other two are #phishing sites that are stealing peoples seeds #ShibaSwap #ShibaCoin."

"Hi @micomco can you look in to this? This website (http://shibaswap.co) that your company hosts is infringing on at least one copyright owned by @Shibtoken. The original NAME/PHOTO was copied onto your servers without permission. Your prompt response would be appreciated."

"Hello, please send us an email to abuso@mi.com.co attaching the evidence, and we will respond in the shortest possible time, we have already received reports about this domain but we have not received any evidence yet."

"Before you connect your wallets to any new site, check them on the major coin hubs. Coingecko, Coinmarketcap and the rest are by no means perfect. But they are better than nothing. Also, make sure you check the veracity of sites with the Telegram/Clubhouse/Discord group that maintains the community for the protocol before just running around out here in crypto."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - ShibaSwap Phishing Site
Date Event Description
May 22nd, 2021 10:39:11 AM Main Event Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.

Total Amount Lost

The total amount lost has been estimated at $39,000+ USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Prevention Policies

Always bookmark the URLs of popular websites that you use regularly after checking them against multiple independent sources, and never rely on sponsored search results to help you navigate, especially to cryptocurrency-related services.

Carefully check all transactions before approving them. Keep most funds stored offline in a secure and unused wallet. Never have more funds in your active wallet than you are currently using for a single transaction, and consider first running a test transaction with a smaller amount.

References