Evolution of Scams by Ohm | Devcon SEA
Devcon·Thu, Oct 9, 2025, 12:00 AM
The goal of this talk will be to give a quick history of the evolution of scams and the new techniques employed to combat them. I was previously the co-founder of Wallet Guard, which has since been acquired by Consensys. I now am responsible for the research and development of the security engine employed by MetaMask to protect its users. Speaker(s): Ohm Skill level: Intermediate Track: Security Keywords: metamask, Hacks, Security Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] [Music] everybody my name is m i was previously one of the co-founders of wallard now I do security R&D at metamask today we're going to talk about the evolution of scams uh throughout the crypto space specifically pertaining to end users so let's start with some of the OG scams in web 3 first off we have our enter your seed phase here scams your typical seed pH Steelers when you end up on a fishing website you also have those send your money here and we'll double it I'm sure everybody has seen this across Twitter or some of these other platforms and then you also have some of these other types of scam methodologies where people reply to tweets and uh link this way to uh earn yield um by using this Arbitrage bot now talking about some of the more interesting scams in the space that we've seen over the last couple of years are drainer kits a lot of drainer kits actually started um around May of 2022 uh with monkey drainer being one of the first uh drainer kits that kind of originated now what's really interesting about monkey drainer and uh the origins of drainer kits is that it kind of replicates a business model that you see throughout the traditional cyber security space for like Mau as a service but now introducing it in a different aspect as drainers as a service so how this actually works often times by approval farming so when the early days of monkey drainer came about they kind of uh were very targeted towards the nft space so what they did was they leveraged your open approvals that you already had on assets uh you've listed in the past on openc or other platforms and they essentially leveraged those approvals to essentially create a zero e listing to themselves effectively draining you of your assets now throughout his notoriety he stole around 16 million USD before shutting down his operations and from then you had the rise of Inferno drainer and Angel drainer which are some of the other more prevalent kits in the space Inferno drainer has stolen roughly around 80 million in assets employing a lot of the similar tactics that monkey drainer had used in the past but also leveraging newer techniques by using things like uh potentially over engineering of certain protocols like Unis swap for example has a uh functionality where you can actually swap to another wallet address um and the intention behind this feature was so that you could swap directly into a cold wallet but now from an attacker's perspective you can swap directly into their wallet so by leveraging things like this you can see um what the pop-up might look like on wallet guard um this was an actual uh transaction that was blocked and the idea was just swapping directly into the um attacker's wallet Now angel drainer is another really prevalent kit um now what they really employ that's a little bit different about them is their multi M chain draining strategy as of recently through efforts of metamask and the security Alliance uh Inferno drainer has uh kind of shut down and starting to work with Angel drainer um so there have been a lot of changes and Evolutions in the draining industry as a whole um but it's a constantly evolving field and that's constantly affecting end users given the um idea that a lot of people sign transactions without really thinking about them and what we're really trying to do nowadays um through transaction simulation that a lot ofall use um is trying to portray to end users what exactly happens when you are actually committing a transaction on chain now Pig butchering and dating scams are also a massive massive massive plague on the industry you see you know hits from like $55,000 to like hundreds of thousands of dollars so these are very targeted attacks they typically start on dating sites like Tinder or whatever else and the idea is it can be as simple as a hey message and then lead to somebody um asking to invest on some investment platform um often times it acts kind of like a Ponzi scheme in the beginning where you uh put money on there you start earning and then you trust it and you start investing even more money um often times they that's why they call it Pig butchering because they fatten it up before they actually take the big hit and take every every asset you have there now this is also the um out of all the scam methodologies this has the highest um amount of return for the attacker per hit now security is an Ever evolving cat and mouse game um but be assured that there are you know companies like metamask security Alliance blockade and many other security vendors that exist out there that are constantly working on mitigating these threats and that's all I have for you today but um happy to take any questions thank you oh questions please raise your hand we're getting more crowded oh there U do you want to give it a try I don't think I can make it that far thanks it might be embarrassing uh so question about the future of uh all those sophisticated techniques and drainers basically um we discuss the current uh state of them from your experience and just looking at you know all the different smart contracts um that are malicious what is the future of that like operation um that malicious Hors are performing where is it all going right now yeah it's an interesting one because it's an Ever evolving field like metamask has released some features as of recently to do a lot more on the uh client side detection feature uh fature sets and it's actually mitigated attackers very much so to the point where in Inno drainer has Consolidated into Angel drainer um and other drainers have completely shut down and we've made the barrier to entry for draining significantly harder than it's ever been um so it's a constant cat Mouse game where when we take out or disrupt one piece of infrastructure they're going to migrate to another piece of infrastructure um you know typically right now we see a lot of infrastructure being leveraged like Cloud flare um so some of the bottlenecks that exist in the industry for example is you know people like Cloud flare who aren't taking as active measures to mitigate these threats um so it it constantly evolves though so like if Cloud Flair were to do something they're going to migrate to something else and uh that's why I called it a captain Mouse game uh there's a question at the F row lady oh this one at the back first okay please um so I have a question what are the techniques to for detection for these malicious transactions for example what differentiates a malicious approval from a non-malicious one yeah so that's a good question um so in the case of like Inferno drainer or monkey drainer or some of these past draining kits it's actually leveraging legitimate approvals so like if you leave an open approval um on your let's say you have you were on Unis Swap and you left an approval open for your uh for an asset you're going to swap um and you never revoke that approval afterwards um that approval could be leveraged to steal your assets in the future so this is why like having good hygiene on your wallets by like revoking things that you don't need um is like a really important tactic um so like back at wallgard we released a product called like uh our security dashboard and it would run a whole scan of your wallet to check like all the different assets you might have and the open approvals you have so the idea was that lingering approvals are not a good thing and if you're not using that approval you should have it closed out um I think the microphone is not working oh yeah okay there it goes um my question is essentially it might be a little bit more philosophical but uh I feel like there's a lot of creativity applied on the other side with black hats how do you feel we can be more creative from our side in terms of protecting our assets and being proactive about preventing um hacks you know I think a lot of those responsibilities um security is actually falling on the wallets themselves um more and more like one of the reasons that we were so Keen to do the acquisition with metamask was because I truly fundamentally believe that security should be built at the wallet level um and it allows like by having security built at a wallet level you get to impact transactions at a different level um back in the days when we were um operating as wallet guard we were essentially a browser extension that would be kind of a companion to your wallet and as good as it was it wasn't the level of the stack we wanted to be at and I think that's why like security really should be built at the wallet level um where the transactions actually being controlled um so taking control of that transaction life cycle is the most important thing we can do as um on The Blue Team side thank you thank you so much gim let's give it up to Gim sorry to oh
Automatic transcript — names and jargon may be misspelled.