Lừa đảo tiền điện tử

Ngày 17 tháng 9, 2022 • César Daniel Barreto

Lừa đảo tiền điện tử

Nếu bạn cập nhật các sự kiện hiện tại, rất có thể bạn đã nghe nói đến Bitcoin hoặc các loại tiền điện tử khác. Tiền điện tử đã thịnh hành trong nhiều năm và nhanh chóng lan rộng trên toàn thế giới như cháy rừng. Điều này đã tạo ra những rủi ro mới cho các nhà đầu tư tiềm năng. Những người háo hức tham gia xu hướng này đầu tư vào các hình thức tiền điện tử khác nhau mà không thực hiện các biện pháp phòng ngừa cơ bản. Do đó, họ có nhiều khả năng bị lợi dụng hơn.

Do thiếu quy định đối với tiền điện tử như Bitcoin, những kẻ lừa đảo và tin tặc đã tìm ra những cách dễ dàng để kiếm tiền nhanh chóng. Có những báo cáo trên phương tiện truyền thông về những người kiếm được hàng triệu đô la từ các hoạt động tiền điện tử bất hợp pháp.

Khi mọi người ngày càng quan tâm đến Bitcoin, thì những kẻ lừa đảo và nghệ sĩ lừa đảo cũng vậy. Hầu hết mọi người đều không quen với phương pháp của chúng, vì vậy những kẻ lừa đảo và kẻ gian đang có một ngày bận rộn trong thế giới tiền điện tử. Những kẻ lừa đảo đã phát triển những cách tinh vi để lừa đảo và kiếm lợi từ các nhà đầu tư không nghi ngờ.

Cách tốt nhất để tránh bị lừa đảo hoàn toàn là nghiên cứu và đọc cách thức hoạt động của những trò lừa đảo này. Trong bài viết này, chúng ta sẽ khám phá một số trò lừa đảo tiền điện tử phổ biến nhất hiện có và xem chính xác cách chúng lừa đảo mọi người. Bạn có thể tự bảo vệ mình khỏi trở thành nạn nhân của một trong những trò lừa đảo này bằng cách hiểu rõ hơn về các rủi ro liên quan và những dấu hiệu cảnh báo cần chú ý.

Sự phát triển của Bitcoin và tiền điện tử

Bitcoin là một số kỹ thuật số được tạo ra bởi một hàm toán học gọi là “HASH”. Nó được truy cập thông qua khóa “công khai” và khóa “riêng tư” và được lưu giữ trong blockchain, là một sổ cái kỹ thuật số. Sổ cái không được lưu giữ ở bất kỳ vị trí nào mà ở nhiều nơi.

Bạn chỉ có thể thêm giao dịch mới vào sổ cái; bạn không thể thay đổi hoặc xóa giao dịch hiện có. Bitcoin và các loại tiền điện tử khác hoạt động theo nguyên tắc tương tự. Vì vậy, bất kỳ ai cũng có thể xem tất cả các giao dịch đã từng xảy ra, nhưng không ai biết ai sở hữu Bitcoin nào.

Khi bạn muốn mua thứ gì đó bằng Bitcoin, bạn phải tìm người bán sẵn sàng chấp nhận Bitcoin làm phương thức thanh toán. Giao dịch có thể được hoàn tất thông qua sàn giao dịch tiền điện tử hoặc trực tiếp giữa mọi người.

Các công ty khác đã đi theo bước chân của Bitcoin bằng cách tạo ra các phiên bản tiền kỹ thuật số của riêng họ. Hiện nay, có rất nhiều loại tiền điện tử thay thế, nhiều trong số đó là các bản sao nhỏ làm thay đổi nguồn cung tiền xu tổng thể hoặc các thuật toán băm. Ripple và Litecoin là hai ví dụ đáng chú ý. Mặt khác, Ethereum được tạo ra để trở thành nhiều hơn một loại tiền kỹ thuật số. Đây là một nền tảng phi tập trung có thể chạy các hợp đồng thông minh hoặc các chương trình máy tính tự động thực thi khi đáp ứng được một số điều kiện nhất định. Điều này cho phép mở ra một thế giới hoàn toàn mới với nhiều khả năng, chẳng hạn như phát triển các ứng dụng phi tập trung (dapp).

Tiền điện tử đã thu hút trí tưởng tượng của nhiều người và mức độ phổ biến của chúng đã tăng vọt trong những năm gần đây. Tuy nhiên, sự quan tâm này đã khuyến khích một lượng lớn các vụ lừa đảo tiền điện tử. Dưới đây, chúng tôi sẽ phác thảo một số loại lừa đảo tiền điện tử phổ biến nhất cần cảnh giác.

Lừa đảo qua mạng

Phishing Scams crypto

Phishing is the illegal act of obtaining sensitive and confidential details, such as usernames, passwords, private keys or payment information, through fake websites and misleading links.

Users are fooled into thinking they are entering their information on a trusted website or following a legitimate link that has been shared with them through emails, messages or Google ads.

What usually happens is that users receive an email giving them the false idea that something has happened to their account or wallet and that they need to fix it by following a link.

The link directs them to a fake website, usually designed to resemble the original website. It may use the same design, color scheme, logo and font style, forcing visitors to believe they are in the right place.

Once the user enters the information, it is passed on to the scammers, who can then use it however they want. They may use the information straight away or store it for later, depending on how much they believe they can gain from the account.

In plain terms: how a phishing attack actually reaches you

Think of it as a fake shopfront. The attacker copies a website you already trust, then needs one thing only: for you to walk through the wrong door.

The usual chain has four links. First, contact — an email, an SMS, a Telegram or Discord message, or a paid ad sitting above the real result in Google. Second, a reason to hurry — a “suspicious login”, a “wallet migration”, a refund waiting for you. Third, the fake page — visually identical to the real one, sitting on a domain that is one character off. Fourth, the harvest — whatever you type is sent straight to the attacker, often while the page shows a spinning loader so you do not realise anything went wrong.

The important part: no software on your computer has been broken. Nothing was hacked. You were persuaded. That is why antivirus rarely stops phishing and why the defence has to be a habit rather than a tool.

MyEtherWallet is a prime example of this style of scam. Fake websites and applications were designed with the same look as the official platform, making users feel safe enough to provide the same information they would normally enter on the real website.

This resulted in huge losses for users. To think that a fake MyEtherWallet app reportedly became one of the top apps in its category is scary. How easily it spread and affected so many users shows how vulnerable the cryptocurrency industry can be and how exposed users are to these attacks.

Another method is the use of fake airdrops. This is when scammers pretend to represent legitimate companies and offer free tokens to large numbers of people.

Along with the offer comes the need to download an application, connect a wallet or visit a portal created by the same individuals looking to make easy money at your expense.

Users may be asked to enter their usernames, passwords, seed phrases or private keys. Once this information is provided, the scammers may gain access to the wallet and drain the account.

In plain terms: why a “free token” airdrop is such an effective hook

An airdrop is a real thing. Genuine projects do hand out free tokens to early users, and that is exactly what makes the fake version work — the offer is not obviously absurd.

The trick is what the offer asks for in return. A real airdrop never needs your seed phrase, your private key or your exchange password, because a seed phrase is not a login: it is the wallet itself. Anyone holding it owns every coin in that wallet, permanently, with no support line to call.

The second version is quieter. Instead of asking you to type anything, the site asks you to “connect wallet” and approve a transaction to claim your tokens. The approval you sign is not a claim — it is permission for the attacker’s contract to move your tokens whenever it likes. The wallet may look untouched for days before it is emptied. Read what you are signing, and treat unlimited spending approvals as a decision, not a formality.

How to Avoid Being Scammed

Now the question is, what needs to be done to avoid these activities?

The answer is simple. Be informed.

Keep yourself up to date. The more you know about what is happening around the world, the better. Subscribe to trusted news websites and read as much as possible.

Discuss these subjects with people who understand them and talk about the latest scams. It requires some effort on your part. Be curious. Know more.

A few things to keep in mind are as follows.

Check the Website Address

Make sure the website address you are visiting is the same one you normally use.

Usually, there are a few small differences that are ignored or difficult to notice. A scammer may change one letter, add an extra word or use a slightly different domain.

But this is your hard-earned money we are talking about here, so you have to be careful every single time you are asked to enter your details.

Double-check the address.

It should start with “https” and not just “http,” but remember that HTTPS alone does not prove that the website is legitimate. Scam websites can also use HTTPS.

The best option is to bookmark the official website or type the address manually into your browser.

In plain terms: what a lookalike address actually looks like

Read a domain from right to left, not left to right. The part that decides where you really are is the last two pieces before the first single slash — everything to the left of that can be invented freely by whoever owns the domain.

So login.yourexchange.com.secure-verify.io is not your exchange. It is secure-verify.io, wearing your exchange’s name as a costume. The same goes for a hyphen where there should be nothing (your-exchange.com), an extra word (yourexchange-wallet.com), a swapped letter (yourexchagne.com), a different ending (.co, .net, .app instead of .com), and characters from another alphabet that render identically to Latin ones.

This is also why HTTPS proves so little. The padlock only means the connection is encrypted between you and whoever owns that address — and a scammer can get a certificate for their own fake domain in minutes, for free. Encrypted does not mean honest. A bookmark, or typing the address yourself, removes the guesswork entirely.

Go With Your Gut Feeling

If the website does not feel right, something looks off or something feels different from your normal routine, stop.

Do not proceed without verifying it.

Call a friend who knows a thing or two. Contact the company through its official website. Do something. Just do not go with the flow.

Watch Out for Urgency

Another very common tactic these fishy websites use is creating a sense of urgency.

They give warnings. They use deadlines. They force the user to take action as quickly as possible, sometimes using big, bold red titles with words such as “HURRY,” “URGENT” or “ACCOUNT SUSPENDED.”

The aim is to create panic and make users act without thinking rationally. Most of the time, the result is terrible.

If a message is rushing you, stop and check the account directly through the official website. Do not use the link in the message.

In plain terms: why urgency is the giveaway, not the emergency

Urgency is not decoration on the scam. It is the scam. Careful checking takes a couple of calm minutes, so the attacker’s whole job is to make sure you never get those minutes.

It works because fear narrows attention. Told that your account is being drained right now, you stop reading the address bar and start looking for the button that makes the problem go away. That is the moment the fake page is built for.

The defence needs no expertise at all: any message that pressures you is, by that fact alone, a message you should not act on from inside the message. Close it. Open the site the way you normally do — your own bookmark, your own typing, your own app. If the emergency is real, it will still be there on the official dashboard. It almost never is.

Use a Strong Password

Always set a strong password.

More importantly, remember that password or store it safely in a trusted password manager. It is very common for people to forget their passwords and lose access to their own wallets or accounts.

Use a different password for every account and enable two-factor authentication whenever possible.

Never give anyone your password, private key or seed phrase. A real wallet company or customer support agent should never ask for this information.

Later on, we will explain in more detail how to avoid scams and the main dos and don’ts.

In plain terms: password, private key and seed phrase are three different things

People use these words interchangeably, and scammers rely on that confusion.

MỘT password unlocks an account on somebody else’s service — an exchange, for example. If it is stolen, the company can freeze the account and give it back to you.

MỘT khóa riêng tư authorises spending from one specific address. Whoever holds it can move those funds. It cannot be changed or revoked.

MỘT seed phrase — the 12 or 24 words written down when you created the wallet — regenerates every private key in that wallet. It is not a password for the wallet: it is the wallet. Type it into a website and the money is gone, usually within minutes, with nobody to appeal to.

So the rule has two halves. Passwords: unique per account, stored in a password manager, with two-factor authentication turned on — and prefer an authenticator app or a hardware key over SMS codes, which can be stolen through a SIM swap. Seed phrase: never typed into any website, any support chat, any “wallet validation” tool, ever. Legitimate support will never ask, because legitimate support cannot use it for anything except stealing from you.

Mining Scams

Lừa đảo khai thác tiền điện tử

Mining scams are another interesting part of the cryptocurrency world. Many of them use cloud mining.

Now, not all cloud mining is illegitimate. Some companies use cloud mining for legitimate purposes. But, as always, there are a few that have used cloud mining negatively and carried out elaborate schemes to scam people.

Cloud mining is the process of mining cryptocurrencies through a remote service. There are companies that allow people to open an account with them and, in return, let users participate in the mining process.

The process is conducted through the company’s equipment, removing the need for users to purchase hardware or deal directly with equipment maintenance and energy costs.

There are legitimate operations out there, and there are people who participate in them. At the same time, there are companies that are completely on the wrong side of the law and every ethical boundary.

In plain terms: what you are actually buying with cloud mining

You are renting a share of someone else’s machines and paying for the electricity they burn. In exchange you receive whatever those machines earn, minus the operator’s fee.

That is the whole model, and it explains why the margins are thin even when everything is honest. The operator has already paid for the hardware and pays the power bill; they only sell you a contract if their cut makes it worth more to them than mining it themselves. You are, by design, on the less profitable side of that trade.

It also explains why the fraudulent version is so easy to run. Nothing about a cloud mining contract is visible to the buyer. There is no machine you can point at, no hash rate you can independently confirm, no way to tell rented capacity from a spreadsheet. A dashboard showing your “daily earnings” costs nothing to fake, and the payouts can be funded entirely by the next customer’s deposit — at which point it has stopped being mining and become a Ponzi scheme with mining-themed graphics.

The Returns

Returns are one way of looking at these operations and judging whether they may be trying to sting you.

But be careful. Very high or guaranteed returns are usually a bigger warning sign than low returns.

Cryptocurrency mining depends on electricity prices, hardware performance, mining difficulty, fees and the value of the cryptocurrency being mined. No legitimate company can guarantee massive profits without any risk.

If a company promises easy money, fixed daily profits or returns that sound too good to be true, there is a good chance something is wrong.

Steer clear of such setups. They are not for you. Or anyone, for that matter.

In plain terms: why a fixed daily return is impossible in mining

Mining income moves every single day, because five separate things underneath it move every single day.

Mining difficulty rises as more machines join the network, so the same hardware earns less over time — this is automatic and continuous. The coin price swings, and your earnings are paid in that coin. Electricity is the largest running cost and is priced by the hour in many markets. Hardware ages, fails and gets outpaced by newer models. Network fees and block rewards change too — Bitcoin’s reward halves roughly every four years, cutting the income from identical work in half overnight.

Any one of those makes a guaranteed number impossible. All five together make it a claim nobody could honour even if they wanted to. So when an operator quotes a flat “1.5% per day”, they are not describing mining output; they are describing a marketing figure they have chosen. The money to pay it has to come from somewhere, and if it is not coming from the machines, it is coming from the next depositor.

Transparency

Is the company allowing you to examine how it works, what tools it uses and how it plans to take the business forward?

If not, you should be concerned that there is something it does not want you, or anyone outside its inner circle, to know.

Transparency is very important. Every user has the right to know about the company they are going to be involved with.

You should be able to find information about the owners, business address, equipment, fees, contracts, withdrawal rules and how returns are calculated.

There should be no question about it.

In plain terms: how to check transparency yourself, in ten minutes

Transparency is not a feeling about a website. It is a list of specific claims you can go and verify.

The people. Are named executives listed, and do those names exist outside this company’s own website — conference talks, an employment history, press coverage? Photographs that appear on stock-image sites, or a team page with no surnames, answers the question on its own.

The company. A registration number and address can be checked in the relevant national companies register in a couple of minutes. A serviced-office address shared with hundreds of other entities, or a registration two months old behind a decade of claimed operating history, is a contradiction worth taking seriously.

The machines. Which model, how many, in which facility, at what power cost? Honest operators publish this because it is their pitch. Photographs of a data centre prove nothing — reverse-image search them.

The exit. Withdrawal minimums, fees, processing times, and whether payouts stop during “maintenance”. This is where the complaints appear first, so search the company name together with the word withdrawal and read what people say when they try to leave.

If asking any of this directly gets you a support agent who changes the subject or offers a bonus for depositing more, that is your answer.

Lừa đảo phần mềm độc hại

Lừa đảo phần mềm độc hại tiền điện tử

A malware portal or infected application can be used to attack your computer and hit you exactly where it hurts.

Malicious software is created and placed inside downloads, wallet applications, browser extensions, email attachments or fake updates.

Once the computer is infected, the malware can take control of certain functions and steal private information or data in the way it was designed to do.

There are numerous ways through which the job can be done.

One example is malware that can compromise a Bitcoin wallet. When you attempt to send coins to a friend in need, the original wallet address may be replaced with a fake one belonging to the scammer.

Cryptocurrency Clipboard Hijackers

One type of malware scam that received attention was known as a cryptocurrency clipboard hijacker.

It used the Windows clipboard as its weapon.

Some of these scammers used the clipboard to monitor thousands of cryptocurrency addresses, but one reported version was much bigger. It was said to monitor around 2.3 million addresses.

The malware used the copy-and-paste mechanism of Windows systems.

Cryptocurrency addresses are usually long and difficult to remember. When users copied and pasted an address, the malware replaced it with a forged address belonging to the scammer.

The transaction would then land in the wrong hands.

Because cryptocurrency transactions are usually irreversible, the money may be impossible to recover once it has been sent.

Always compare the wallet address before confirming a transaction. Check the first and last several characters, and for a large payment, consider sending a small test transaction first.

In plain terms: how a clipboard hijacker steals a payment

Every time you copy something, your computer holds it in one shared pocket called the clipboard. Any program running on that machine can read that pocket, and any program can quietly change what is in it. That is not a flaw being exploited — it is how the clipboard has always worked.

So the malware does nothing dramatic. It sits idle, watching what you copy, and does nothing at all until the thing you copied looks like a crypto address. At that instant it swaps your copied address for one of its own, chosen from its stored list to match the same currency and the same general shape. Then it goes quiet again.

What makes it so effective is the psychology of the paste. You copied the correct address one second earlier, so you already know what should be in the box. Addresses are long, meaningless strings that the eye skims rather than reads, and the substitute often begins with similar characters. You glance, it looks right, you confirm — and the payment is final, on a public ledger, sitting in a stranger’s wallet.

Two habits defeat it completely. Compare characters at the start at the end of the address after pasting, not just at the start. And for anything substantial, send a small test amount first, confirm it arrived, then send the rest.

How to Spot Possible Malware

  • Your computer shows signs of slowing down.
  • Pop-up ads begin appearing far too often and become difficult to ignore.
  • You notice unusual activity that you were not responsible for.
  • Programs open or close by themselves.
  • Your browser settings suddenly change.
  • Your security software becomes disabled.
  • You see login attempts or transactions that you did not authorize.

If you believe your computer is infected, disconnect it from the internet and stop entering passwords or accessing wallets until the device has been checked.

In plain terms: what to do first if you think you are infected

Order matters more than speed here, and the instinct most people follow — log in and check the accounts — is the one that does the damage.

Disconnect first. Pull the Wi-Fi or the cable. Anything still being sent to the attacker stops at that moment.

Do not log in to anything from that machine. Not the exchange, not the email, not the wallet. If the device is compromised, every password you type is simply a new password being handed over.

Change passwords from a different device — a phone on mobile data, another computer — starting with the email account, because that is what resets everything else. Then the exchanges, then whatever shares those passwords.

Assume the seed phrase is gone if it was ever typed, photographed or stored on that machine. Move the funds to a wallet created on a clean device. Changing the password on the old wallet does nothing; the seed phrase still opens it.

Clean the machine properly. A scan that finds nothing is not proof of safety. For a device that held real money, a full wipe and reinstall is the only honest reset.

Fake Wallets

Ví tiền điện tử giả

Fake wallets are also a favorite of scammers.

They create a fake wallet to trick people into revealing their passwords, private keys or seed phrases.

Bitcoin Gold was new to the market, and users who were looking to claim their coins were directed to a fake wallet that went by the name of mybtgwallet.com.

Thinking it was the real thing, users provided information relating to their private keys and were deprived of millions of dollars as a result.

The scam emptied wallets and reportedly cost users a combined amount close to $3.5 million.

Keeping in mind the number of fake Google ads and advertisements being thrown at you every day, you have to be very careful when visiting a website or downloading a wallet.

The ideal thing to do is to keep the original website bookmarked or type the address manually into your browser.

Only download wallets through the official project website or verified app-store page.

How to Spot a Fake Wallet

  • Information about the wallet or its business model is missing.
  • There is no presence on major cryptocurrency or security websites that usually cover important platforms.
  • The platform has only recently been created.
  • The developers or company owners cannot be identified.
  • The wallet asks for your private key or seed phrase without a valid reason.
  • The website uses “http” instead of “https,” meaning the connection is not secure.
  • The app appears mainly through paid advertisements rather than official channels.
  • The reviews seem copied, repetitive or far too positive.

Remember that HTTPS does not automatically mean a website is safe. Always verify the domain, the company and the official download link before entering any sensitive information.

In plain terms: how to verify a wallet before you install it

The dangerous moment is not using the wallet — it is choosing it. Almost every fake wallet is found the same way: through a search result, an ad, or an app store listing, rather than through the project itself.

Start from the project, never from the search box. Find the official website through a source you already trust, then follow its download link to the app store. That single reversal removes the most common trap, because a paid ad can sit above the real result and a store listing can carry the real logo.

Read the listing sceptically. Check the publisher name against the one on the official site, the install count against how well known the wallet is, and the release date — a wallet claiming years of history with a listing from last month is a copy. Reviews that are numerous, five-star, short and posted within the same few days are bought.

Watch the first screen. A genuine wallet either creates a new seed phrase for you or asks you to type an existing one to restore your own wallet — offline, on the device. If the first thing the app or site asks for is a seed phrase in order to “verify”, “sync”, “validate” or “unlock rewards”, close it.

Test small. Before moving anything meaningful, send a small amount in, send it back out, and confirm both transactions on a block explorer. A wallet that accepts deposits but stalls on withdrawals has told you what it is while it still costs almost nothing to find out.

LỪA ĐẢO ICO

LỪA ĐẢO ICO tiền điện tử

Kể từ khi tiền điện tử ra đời, các nhà đầu tư tổ chức đã thể hiện sự quan tâm lớn đến tài sản kỹ thuật số. Tuy nhiên, nhiều ICO đã trở thành trò lừa đảo, với các doanh nghiệp biến mất sau khi họ thu được một số tiền lớn.

Vì tiền đã được huy động và không có cơ quan quản lý nào giám sát quyết định của người sáng tạo liên quan đến ứng dụng của mình, nên các ICO có thể tự do làm bất cứ điều gì họ muốn với số tiền đó. Họ có thể dễ dàng lấy tiền hoặc làm việc trong khuôn khổ của luật pháp.

Vụ lừa đảo Giza là một ví dụ khét tiếng về hoạt động ICO gian lận khi gần $2 triệu đã bị lấy đi từ các nhà đầu tư không hề hay biết. Khi nhà cung cấp chính thông báo họ đã cắt đứt quan hệ với Giza vì những lý do khiến bất kỳ người ủng hộ nào cũng phải bỏ chạy, những lá cờ cảnh báo bắt đầu rung lên. Những cáo buộc gian lận sớm xuất hiện và không ai có thể lấy lại được tiền của họ.

Các nhà phát triển dự án Enigma Catalyst cũng đã bỏ trốn với $45 triệu, mặc dù sản phẩm đã hoạt động.

Làm thế nào để tránh lừa đảo ICO

Khi cân nhắc đầu tư vào ICO, hãy tự nghiên cứu và đừng bao giờ đầu tư nhiều hơn mức bạn có thể mất. Đọc sách trắng và hiểu rõ dự án trước khi đưa ra bất kỳ quyết định nào.

Để tìm một ICO uy tín, hãy tìm kiếm các đánh giá tích cực trực tuyến và sự hiện diện mạnh mẽ của cộng đồng. Ngoài ra, hãy kiểm tra xem dự án có sản phẩm đang hoạt động và lộ trình rõ ràng cho tương lai hay không.

Lừa đảo Pump and Dump

Lừa đảo Pump and Dump

Các chương trình bơm và xả là một hình thức gian lận đầu tư trong đó các cá nhân đầu tư vào một công ty được thổi phồng quá mức hoặc sắp thất bại. Những kẻ gian lận thuyết phục các nhà đầu tư này bỏ tiền vào vụ lừa đảo trước khi bán cổ phiếu của họ với mức giá cao. Vì nạn nhân có thể gặp khó khăn trong việc xác định liệu có tiềm năng phát triển thực sự trong công ty hay không, nên những trò lừa đảo như vậy thường nhắm vào tiền điện tử kỹ thuật số.

Một số nhà đầu tư có thể do dự khi đầu tư vào một dự án, nhưng họ được khuyến khích bởi lời hứa của một bên đầu tư hoặc hợp tác lớn. Điều này khiến mọi người tin vào dự án, mặc dù nó không có vẻ hứa hẹn lắm.

Những kẻ lừa đảo đẩy giá bằng cách khiến nhiều người tin vào nó. Khi chúng hoàn thành và giá không thể tăng cao hơn nữa, chúng bán hết cùng một lúc, khiến giá giảm nhanh chóng.

Việc này có thể xảy ra chỉ trong vài phút!

Một ví dụ về trò lừa đảo bơm và xả tiền điện tử là Lừa đảo Bitconnect.

Bitconnect là một loại tiền điện tử được quảng cáo là chương trình đầu tư có lợi nhuận cao. Nó hứa hẹn lợi nhuận lên tới 40% mỗi tháng, cao hơn nhiều so với bất kỳ loại tiền điện tử nào khác trên thị trường.

Nhiều người đã đầu tư vào Bitconnect, nhưng giá nhanh chóng giảm mạnh và họ mất toàn bộ tiền.

Một ví dụ khác về trò lừa đảo bơm và xả tiền điện tử là Lừa đảo PlusToken.

PlusToken là một loại tiền điện tử được quảng cáo là cách kiếm lãi từ khoản đầu tư của bạn. Nó hứa hẹn lợi nhuận lên tới 9% mỗi tháng, cao hơn nhiều so với bất kỳ loại tiền điện tử nào khác trên thị trường.

Mọi người đã đầu tư vào PlusToken, nhưng giá nhanh chóng giảm mạnh và họ mất toàn bộ tiền.

Làm thế nào để tránh lừa đảo Pump and Dump

Trước khi đầu tư vào bất kỳ loại tiền điện tử nào, hãy làm bài tập về nhà. Đừng đầu tư vào một loại tiền tệ mới nếu có nhiều tin tức, bài đăng trên blog hoặc bài luận về mức độ phổ biến của nó. Tra cứu đồng tiền và đọc sách trắng của nó để tìm hiểu thêm về người đã tạo ra nó và lý do tại sao. Điều này sẽ giúp bạn xác định xem có bất kỳ chương trình bơm và xả nào đang diễn ra với loại tiền tệ này không.

Các chương trình tiền điện tử Ponzi

Lừa đảo Ponzi

Các chương trình Ponzi là một loại gian lận liên quan đến việc nói với các nhà đầu tư tiềm năng rằng họ sẽ kiếm được lợi nhuận bằng cách tuyển dụng các thành viên mới. Vấn đề là cuối cùng, không có đủ người mới đầu tư tiền vào chương trình và nó sụp đổ vì không có đủ doanh thu để hỗ trợ tất cả những người đã đầu tư. Khi điều này xảy ra, tất cả những người đầu tư vào chương trình đều bị lừa đảo, bất kể ban đầu họ đã mang về bao nhiêu tiền hay đã chi tiêu vào đâu. Những kẻ lừa đảo kiếm được lợi nhuận nhanh chóng và sau đó bỏ mặc nạn nhân của chúng. Các chương trình Ponzi đã xâm nhập vào thế giới tiền điện tử và đang lừa đảo các nhà đầu tư trên toàn thế giới.

Thiệt hại tài chính do những kiểu lừa đảo này gây ra là rất lớn.

Forsage-crypto, một chương trình Ponzi tiền điện tử kéo dài hơn hai năm, đã lừa các nhà đầu tư bằng cách cho họ tham gia vào các giao dịch sử dụng hợp đồng thông minh Ethereum, Tron và Binance. Mô hình kinh doanh tiếp thị liên kết của Forsage-crypto đã thu hút các nhà đầu tư bằng sự đảm bảo về lợi nhuận. Như đã nêu trên Trang web của SEC, Forsage đã thu hút hàng triệu nhà đầu tư bán lẻ bằng cách cung cấp một nền tảng thân thiện với người dùng cho các blockchain Ethereum, Trons và Binance. Hơn nữa, nó luôn sử dụng tiền mới đầu tư để trả lại cho những người tham gia trước đó - một đặc điểm đặc trưng của các chương trình kim tự tháp.

Một ví dụ khác về chương trình Ponzi tiền điện tử là Lừa đảo OneCoin. Kế hoạch OneCoin được quảng bá như một cách kiếm tiền bằng cách đầu tư vào một loại tiền điện tử mới. Tuy nhiên, công ty đã bị cáo buộc là một kế hoạch Ponzi. Theo trang web của công ty, nó được thành lập tại Việt Nam, nhưng sau đó quốc gia này đã phản đối tuyên bố này. Ngoài ra, một số thảm họa trên nhiều quốc gia và vùng lãnh thổ trên toàn thế giới đã tiết lộ rằng OneCoin là gian lận.

Cách nhận biết một vụ lừa đảo Ponzi

  • Doanh thu tăng theo cấp số nhân
  • Các nhà môi giới không có giấy phép
  • Thiếu sự minh bạch
  • Thiếu thông tin về công ty
  • Đầu tư chưa đăng ký

Nếu bạn đã bị lừa đảo, có một số điều bạn có thể làm:

  • Liên hệ với SEC tại https://www.sec.gov/tcr. SEC là cơ quan quản lý chứng khoán của Hoa Kỳ và họ sẽ có thể cung cấp cho bạn thêm thông tin về những việc cần làm tiếp theo.
  • Nộp đơn khiếu nại với FBI tại https://www.ic3.gov/Home/ComplaintChoice. Họ sẽ có thể điều tra vụ lừa đảo và giúp bạn lấy lại tiền.
  • Liên hệ với Ủy ban Thương mại Liên bang tại https://www.ftccomplaintassistant.gov/. Họ sẽ có thể giúp bạn lấy lại tiền và ngăn chặn kẻ lừa đảo tiếp tục lừa đảo người khác.
  • Liên hệ với FINRA tại https://www.finra.org/. FINRA là cơ quan quản lý tài chính tại Hoa Kỳ. Bạn có thể nộp khiếu nại và báo cáo bất kỳ hành vi lừa đảo hoặc hoạt động đáng ngờ nào của một công ty môi giới.

Suy nghĩ kết thúc

Cách tốt nhất để tránh lừa đảo tiền điện tử là làm bài tập về nhà. Nghiên cứu bất kỳ loại tiền điện tử hoặc dự án nào trước khi bạn đầu tư vào nó. Ngoài ra, hãy kiểm tra nguồn của bất kỳ tin tức hoặc bài đăng trên blog nào về tiền điện tử trước khi bạn tin chúng. Cuối cùng, nếu điều gì đó nghe có vẻ quá tốt để trở thành sự thật, thì có lẽ là vậy!

César Daniel Barreto, Tác giả về An ninh mạng tại Security Briefing

César Daniel Barreto

César Daniel Barreto là một nhà văn và chuyên gia an ninh mạng được kính trọng, nổi tiếng với kiến thức sâu rộng và khả năng đơn giản hóa các chủ đề an ninh mạng phức tạp. Với kinh nghiệm sâu rộng về bảo mật mạng và bảo vệ dữ liệu, ông thường xuyên đóng góp các bài viết và phân tích sâu sắc về các xu hướng an ninh mạng mới nhất, giáo dục cả chuyên gia và công chúng.

Login

Already have an account? Sign in to pick up where you left off.

Register

New here? Create an account to follow our latest security briefings.

viVietnamese