Cryptocurrencysecurityexpertsarewarninginvestorsaboutanewlydiscoveredmemecoinscamthatbypassesdetectionfiltersonmajortradingdataplatforms.
ThisnewscaminvolvesatokencalledREPUBLICANthathasasecretcodethatallowsitsfoundertowithdrawtokensdirectlyfromanywalletthatholdsthem.
“Whatwe’reseeinghereistheincreasingsophisticationofscamtokensinevadingdetectiontechniques,”MichaelLewellen,HeadofSolutionArchitectureatOpenZeppelin,saidinastatement.Whilescamtokenshavebeenarecurringproblemforcryptocurrencyinvestors,thisnewmemecoinusesadvancedcodingtechniquestobypasstraditionalsecurityscans.
TheREPUBLICANtokenappearslegitimateatfirstglance.However,hiddenwithinitscodeliesafeaturethatallowstheprogrammertowithdrawtokensfrominnocentusers’walletsandcreateanunlimitedbalanceforthemselves.InvestorswhoexchangedETHforREPUBLICANondecentralizedexchangeshavereportedthattheirtokensdisappearedshortlyafterpurchase.
ThescamwasfirstspottedbyuserX@yourfriend_btcandhassincegainedattentionamongcryptosecuritycircles.Whiletheexactprofitsmadebythescammerareunknown,DexScreenerdatasuggeststhat$408,000worthofREPUBLICANtokensweretraded.
Lewellenexplainedthatthescammerusedassemblylanguage,alow-levelprogramminglanguagecloselyalignedwithmachinecode,tohidethemaliciouscodeinsidethetoken.“Assemblylanguagecodeishardertointerpret,whichmakesithardertodetectifitcontainsmaliciousfeatures,”hesaid.ThiscomplexityallowedREPUBLICANtobypasssecuritychecksthatusuallyidentifydangeroustokens.
Despitethegrowthofreal-timemonitoringtoolsintheindustry,thesetoolshavenotflaggedtheREPUBLICANtoken.DexScreener,whichperformedthreeseparatecodeauditsonthetoken,foundnoissuesbutwarnedthatsuchauditsmaynotbefoolproof.
*Thisisnotinvestmentadvice.
en.bitcoinsistemi.com