SlideShare a Scribd company logo
Web3 + scams =


HiTB Singapore, 2022


Zoltan Balazs, CUJO AI
Web3 + scams = It's a match
Head of Vulnerability Research Lab @ CUJO AI
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP


https://github.com/Z6543/hwfwbypass
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP


https://github.com/Z6543/hwfwbypass
Malware Analysis Sandbox Tester tool


https://github.com/Z6543/Sandbox_tester
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP


https://github.com/Z6543/hwfwbypass
Malware Analysis Sandbox Tester tool


https://github.com/Z6543/Sandbox_tester
Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai


https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html


https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP


https://github.com/Z6543/hwfwbypass
Malware Analysis Sandbox Tester tool


https://github.com/Z6543/Sandbox_tester
Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai


https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html


https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html
Invented the idea of encrypted exploit delivery via Dif
fi
e-Hellman key exchange, to bypass exploit
detection appliances


https://www.mrg-ef
fi
tas.com/generic-bypass-of-next-gen-intrusion-threat-breach-detection-systems/
Head of Vulnerability Research Lab @ CUJO AI
Zombie Browser Toolkit

https://github.com/Z6543/ZombieBrowserPack
HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP


https://github.com/Z6543/hwfwbypass
Malware Analysis Sandbox Tester tool


https://github.com/Z6543/Sandbox_tester
Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai


https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html


https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html
Invented the idea of encrypted exploit delivery via Dif
fi
e-Hellman key exchange, to bypass exploit
detection appliances


https://www.mrg-ef
fi
tas.com/generic-bypass-of-next-gen-intrusion-threat-breach-detection-systems/
Co-organizer of the Hackersuli meetup

Programme committee member of the Hacktivity conference

Volunteer at IoTVillage
Web3 + scams = It's a match
I ❤ Singapore
I ❤ Singapore
I ❤ Singapore
I ❤ Singapore
What and why
What and why
This is a 2 hour presentation compressed into 25 minutes
What and why
This is a 2 hour presentation compressed into 25 minutes
Fasten your seatbelts
What and why
This is a 2 hour presentation compressed into 25 minutes
Fasten your seatbelts
I love playing with new technologies
What and why
This is a 2 hour presentation compressed into 25 minutes
Fasten your seatbelts
I love playing with new technologies
I
fi
nd blockchain + Web3 fascinating
This presentation is NOT about/for
This presentation is NOT about/for
WHOLE CRYPTO WORLD IS A SCAM!!!!
This presentation is NOT about/for
WHOLE CRYPTO WORLD IS A SCAM!!!!
Smart contract developers
This presentation is NOT about/for
WHOLE CRYPTO WORLD IS A SCAM!!!!
Smart contract developers
Financial advise on which shitcoin to invest in
This presentation is NOT about/for
WHOLE CRYPTO WORLD IS A SCAM!!!!
Smart contract developers
Financial advise on which shitcoin to invest in
Crypto exchange hacks - see six/David's presentation
This presentation is NOT about/for
WHOLE CRYPTO WORLD IS A SCAM!!!!
Smart contract developers
Financial advise on which shitcoin to invest in
Crypto exchange hacks - see six/David's presentation
Cryptocurrency is used as a form of payment, e.g. ransomware
How did we get here?
How did we get here?
Lot of people got rich from cryptocurrencies
How did we get here?
Lot of people got rich from cryptocurrencies
Lot of people want to get rich from cryptocurrencies
How did we get here?
Lot of people got rich from cryptocurrencies
Lot of people want to get rich from cryptocurrencies
Total market capitalisation is around 2 1 trillion USD
How did we get here?
Lot of people got rich from cryptocurrencies
Lot of people want to get rich from cryptocurrencies
Total market capitalisation is around 2 1 trillion USD
2 1,000,000,000,000
How did we get here?
Lot of people got rich from cryptocurrencies
Lot of people want to get rich from cryptocurrencies
Total market capitalisation is around 2 1 trillion USD
2 1,000,000,000,000
New complex technology with crappy UI
How did we get here?
Lot of people got rich from cryptocurrencies
Lot of people want to get rich from cryptocurrencies
Total market capitalisation is around 2 1 trillion USD
2 1,000,000,000,000
New complex technology with crappy UI
What could possibly go wrong?
Web3 + scams = It's a match
Web3 + scams = It's a match
What is Bitcoin anyway?
Let’s hear it from a trusted,


3 Grammy award winner Blockchain expert!
What is Bitcoin anyway?
Let’s hear it from a trusted,


3 Grammy award winner Blockchain expert!
What is Bitcoin anyway?
https://youtu.be/5AN5veSPfY4
Let’s hear it from a trusted,


3 Grammy award winner Blockchain expert!
Web3 + scams = It's a match
Web3 + scams = It's a match
Introducing the lamb-o-meter
Web3 + scams = It's a match
Step 1: Buy a lot from something what is
cheap and has low volume
Step 1: Buy a lot from something what is
cheap and has low volume
Step 2: Advertise as the NEXT BIG THING
Step 1: Buy a lot from something what is
cheap and has low volume
Step 2: Advertise as the NEXT BIG THING
Step 3: Sell on top
Step 1: Buy a lot from something what is
cheap and has low volume
Step 2: Advertise as the NEXT BIG THING
Step 3: Sell on top
Step 4: PROFIT
Step 1: Buy a lot from something what is
cheap and has low volume
Step 2: Advertise as the NEXT BIG THING
Step 3: Sell on top
Step 4: PROFIT
Optional Step 5: Short on top
Step 1: Buy a lot from something what is
cheap and has low volume
Step 2: Advertise as the NEXT BIG THING
Step 3: Sell on top
Step 4: PROFIT
Optional Step 5: Short on top
Rug pull
Rug pull
Similar to pump and
dump
Rug pull
Similar to pump and
dump
But you are the owner/
developer of the
cryptocurrency/token/
whatever
Rug pull
Similar to pump and
dump
But you are the owner/
developer of the
cryptocurrency/token/
whatever
Even Conti ransomware
group knew about
SQUID
Rug pull
Similar to pump and
dump
But you are the owner/
developer of the
cryptocurrency/token/
whatever
Even Conti ransomware
group knew about
SQUID
Rug pull
Similar to pump and
dump
But you are the owner/
developer of the
cryptocurrency/token/
whatever
Even Conti ransomware
group knew about
SQUID
Giveaway scam
Giveaway scam
Giveaway scam
Giveaway scam
Giveaway scam
Giveaway scam
Advance fee fraud
https://www.proofpoint.com/us/blog/threat-insight/
advance-fee-fraud-emergence-elaborate-crypto-
schemes
Advance fee fraud
https://www.proofpoint.com/us/blog/threat-insight/
advance-fee-fraud-emergence-elaborate-crypto-
schemes
Advance fee fraud
https://www.proofpoint.com/us/blog/threat-insight/
advance-fee-fraud-emergence-elaborate-crypto-
schemes
Advance fee fraud
https://www.proofpoint.com/us/blog/threat-insight/
advance-fee-fraud-emergence-elaborate-crypto-
schemes
Advance fee fraud
https://www.proofpoint.com/us/blog/threat-insight/
advance-fee-fraud-emergence-elaborate-crypto-
schemes
What is an NFT anyway?
https://twitter.com/zh4ck/nft


https://etherscan.io/nft/0x06012c8cf97bead5deae237070f9587f8e7a266d/634517


https://etherscan.io/tx/
0xfe21bd24d7748890c4deb2453bcd22ab451349fdacb5e812422e16772a664723#eventlog


https://etherscan.io/address/0xb77feddb7e627a78140a2a32cac65a49ed1dba8e#code
The “magical” world of NFTs …
1 ETH = 1700 USD
The “magical” world of NFTs …
1 ETH = 1700 USD
The “magical” world of NFTs …
1 ETH = 1700 USD
The “magical” world of NFTs …
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Justin Bieber - 500 ETH
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Justin Bieber - 500 ETH
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Snoop Dog - 2500 ETH
Justin Bieber - 500 ETH
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Snoop Dog - 2500 ETH
Justin Bieber - 500 ETH
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Snoop Dog - 2500 ETH
Justin Bieber - 500 ETH
Eminem - 123.45 ETH
Paris Hilton BAYC - 119 ETH
1 ETH = 1700 USD
The “magical” world of NFTs …
Snoop Dog - 2500 ETH
Justin Bieber - 500 ETH
Eminem - 123.45 ETH
Paris Hilton BAYC - 119 ETH
https://etherscan.io/token/0xbc4ca0eda7647a8ab7c2061c2e118a18a936f13d#readContract


https://ipfs.io/ipfs/QmeSjSinHpPnmXmspMjwiXyN6zS4E9zccariGR3jxcaWtq/9055


https://cid.ipfs.io/#QmTHcV6mGxHGeeXCnYtV129eRiR8Exni4sT8dDikBWBgzY
1 ETH = 1700 USD
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
https://www.youtube.com/watch?
v=IjtPe1h4Ca0
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Web3 + scams = It's a match
Discord scam
Discord scam
Discord servers hacked via bookmarklets
Discord scam
Discord servers hacked via bookmarklets
Discord scam
Discord servers hacked via bookmarklets
Discord scam
Discord servers hacked via bookmarklets
Discord scam
Web3 + scams = It's a match
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
https://whotookmycrypto.com/
ledger-wallet-scams/
HW wallets - Ledger, Trezor
HW wallets - Ledger, Trezor
HW wallets - Ledger, Trezor
Best practices
Best practices
don’t trust random people (or celebrities) on social media
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
use HW wallet if you have a lot to protect
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
use HW wallet if you have a lot to protect
keep PC free of malware
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
use HW wallet if you have a lot to protect
keep PC free of malware
cold wallet for valuables - like you don’t store your life savings in your pocket wallet
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
use HW wallet if you have a lot to protect
keep PC free of malware
cold wallet for valuables - like you don’t store your life savings in your pocket wallet
take time, don’t rush
Best practices
don’t trust random people (or celebrities) on social media
check source of the app/dapp
don’t send funds to someone you don't trust, or verify via phone
block people/email sharing login, password, private key, seed phrase, backup phrase
extra careful to interact with KNOWN and unknown smart contracts
use password manager
enable 2fa, don’t use SMS based
use HW wallet if you have a lot to protect
keep PC free of malware
cold wallet for valuables - like you don’t store your life savings in your pocket wallet
take time, don’t rush
install security extensions like "Wallet Guard" or "Sunrise: NFT scam protector"
Conclusion
I can send white-paper if you want
Hack the planet
One computer at a time
zoltan.balazs@cujo.com
https://hu.linkedin.com/in/zbalazs


Twitter – @zh4ck


www.slideshare.net/bz98


JumpESPJump.blogspot.com

More Related Content

PDF
Having Honeypot for Better Network Security Analysis
PPTX
Embracing Legacy: Learnings from Argentum Online
PDF
Adversary Pattern Analysis - A Journey with APNIC Honeypot
PPTX
BITcoin Presentation Financial Management.pptx
PDF
Release The Hounds: Part 2 “11 Years Is A Long Ass Time”
PPTX
Hacking the world
PDF
Drupal Camp Bristol 2017 - Website insecurity
PDF
Hacktivity 2016: The real risks of the IoT security-nightmare: Hacking IP cam...
Having Honeypot for Better Network Security Analysis
Embracing Legacy: Learnings from Argentum Online
Adversary Pattern Analysis - A Journey with APNIC Honeypot
BITcoin Presentation Financial Management.pptx
Release The Hounds: Part 2 “11 Years Is A Long Ass Time”
Hacking the world
Drupal Camp Bristol 2017 - Website insecurity
Hacktivity 2016: The real risks of the IoT security-nightmare: Hacking IP cam...

Similar to Web3 + scams = It's a match (20)

PPTX
Hacking and Cyber Security.
PDF
Os Nightingale
PDF
Befargo
PDF
The Revolution of Crypto Funding - Building towards a Scamless Future
PPTX
Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...
PDF
Crypto currency secrets
PDF
Using Blockchain to Increase Supply Chain Transparency
PDF
IoT security is a nightmare. But what is the real risk?
PPT
An Investigator’s Guide to Blockchain, Bitcoin and Wallet Transactions
PPTX
Ransomware - what is it, how to protect against it
PPT
What is future of Cryptocurrency | Omega Prime Group
PDF
Dylan Butler & Oliver Hager - Building a cross platform cryptocurrency app
PDF
Cryptocurrencies and Blockchain technology
PPT
Beyond Ethical Hacking By Nipun Jaswal , CSA HCF Infosec Pvt. Ltd
PDF
Cryptocurrency a-quick-guide-to-understanding-cryptocurrencies
DOCX
Cryptocurrency
DOCX
Crypto Future
PDF
KEYNOTE: Nullcon 2021 - Security Research and Disclosure - The Unauthorized B...
PDF
BugBounty Roadmap with Mohammed Adam
PPTX
Country domination - Causing chaos and wrecking havoc
Hacking and Cyber Security.
Os Nightingale
Befargo
The Revolution of Crypto Funding - Building towards a Scamless Future
Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...
Crypto currency secrets
Using Blockchain to Increase Supply Chain Transparency
IoT security is a nightmare. But what is the real risk?
An Investigator’s Guide to Blockchain, Bitcoin and Wallet Transactions
Ransomware - what is it, how to protect against it
What is future of Cryptocurrency | Omega Prime Group
Dylan Butler & Oliver Hager - Building a cross platform cryptocurrency app
Cryptocurrencies and Blockchain technology
Beyond Ethical Hacking By Nipun Jaswal , CSA HCF Infosec Pvt. Ltd
Cryptocurrency a-quick-guide-to-understanding-cryptocurrencies
Cryptocurrency
Crypto Future
KEYNOTE: Nullcon 2021 - Security Research and Disclosure - The Unauthorized B...
BugBounty Roadmap with Mohammed Adam
Country domination - Causing chaos and wrecking havoc
Ad

More from Zoltan Balazs (20)

PPTX
[ Hackersuli ] Privacy on the blockchain
PPTX
MLSEC 2020
PDF
PPTX
How to hide your browser 0-day @ Disobey
PPTX
Explain Ethereum smart contract hacking like i am a five
PDF
How to hide your browser 0-days
PPTX
Test & Tea : ITSEC testing, manual vs automated
PDF
Hacking Windows 95 #33c3
PPTX
Sandboxes
PPTX
Sandbox detection: leak, abuse, test - Hacktivity 2015
PDF
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
PPTX
Hacking with Remote Admin Tools (RAT)
PDF
[ENG] Hacktivity 2013 - Alice in eXploitland
PPTX
[ENG] OHM2013 - The Quest for the Client-Side Elixir Against Zombie Browsers -
PPTX
[HUN] Védtelen böngészők - Ethical Hacking
PDF
[ENG] Hacker halted 2012 - Zombie browsers, spiced with rootkit extensions
PDF
[ENG] Zombie browsers spiced with rootkit extensions - Hacktivity 2012
PPTX
[HUN] Zombi tűzróka, avagy mire képes egy rosszindulatú böngősző kiegészitő
PPT
[ENG] IPv6 shipworm + My little Windows domain pwnie
PPT
[HUN] Hacktivity2009 - M&M’s: Mafia & Malware’s
[ Hackersuli ] Privacy on the blockchain
MLSEC 2020
How to hide your browser 0-day @ Disobey
Explain Ethereum smart contract hacking like i am a five
How to hide your browser 0-days
Test & Tea : ITSEC testing, manual vs automated
Hacking Windows 95 #33c3
Sandboxes
Sandbox detection: leak, abuse, test - Hacktivity 2015
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
Hacking with Remote Admin Tools (RAT)
[ENG] Hacktivity 2013 - Alice in eXploitland
[ENG] OHM2013 - The Quest for the Client-Side Elixir Against Zombie Browsers -
[HUN] Védtelen böngészők - Ethical Hacking
[ENG] Hacker halted 2012 - Zombie browsers, spiced with rootkit extensions
[ENG] Zombie browsers spiced with rootkit extensions - Hacktivity 2012
[HUN] Zombi tűzróka, avagy mire képes egy rosszindulatú böngősző kiegészitő
[ENG] IPv6 shipworm + My little Windows domain pwnie
[HUN] Hacktivity2009 - M&M’s: Mafia & Malware’s
Ad

Recently uploaded (20)

PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PPTX
QR Codes Qr codecodecodecodecocodedecodecode
PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PPT
tcp ip networks nd ip layering assotred slides
PPTX
innovation process that make everything different.pptx
PPTX
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
PPTX
presentation_pfe-universite-molay-seltan.pptx
PPTX
artificial intelligence overview of it and more
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
Paper PDF World Game (s) Great Redesign.pdf
Module 1 - Cyber Law and Ethics 101.pptx
Design_with_Watersergyerge45hrbgre4top (1).ppt
QR Codes Qr codecodecodecodecocodedecodecode
Tenda Login Guide: Access Your Router in 5 Easy Steps
PptxGenJS_Demo_Chart_20250317130215833.pptx
Job_Card_System_Styled_lorem_ipsum_.pptx
RPKI Status Update, presented by Makito Lay at IDNOG 10
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
INTERNET------BASICS-------UPDATED PPT PRESENTATION
SASE Traffic Flow - ZTNA Connector-1.pdf
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Slides PDF The World Game (s) Eco Economic Epochs.pdf
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
tcp ip networks nd ip layering assotred slides
innovation process that make everything different.pptx
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
presentation_pfe-universite-molay-seltan.pptx
artificial intelligence overview of it and more

Web3 + scams = It's a match

  • 1. Web3 + scams = HiTB Singapore, 2022 Zoltan Balazs, CUJO AI
  • 3. Head of Vulnerability Research Lab @ CUJO AI
  • 4. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack
  • 5. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP 
 https://github.com/Z6543/hwfwbypass
  • 6. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP 
 https://github.com/Z6543/hwfwbypass Malware Analysis Sandbox Tester tool 
 https://github.com/Z6543/Sandbox_tester
  • 7. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP 
 https://github.com/Z6543/hwfwbypass Malware Analysis Sandbox Tester tool 
 https://github.com/Z6543/Sandbox_tester Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai 
 https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html 
 https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html
  • 8. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP 
 https://github.com/Z6543/hwfwbypass Malware Analysis Sandbox Tester tool 
 https://github.com/Z6543/Sandbox_tester Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai 
 https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html 
 https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html Invented the idea of encrypted exploit delivery via Dif fi e-Hellman key exchange, to bypass exploit detection appliances 
 https://www.mrg-ef fi tas.com/generic-bypass-of-next-gen-intrusion-threat-breach-detection-systems/
  • 9. Head of Vulnerability Research Lab @ CUJO AI Zombie Browser Toolkit
 https://github.com/Z6543/ZombieBrowserPack HWFW Bypass tool   Similar stuff was used in PacketRedirect in Danderspritz FlewAvenue by EQGRP 
 https://github.com/Z6543/hwfwbypass Malware Analysis Sandbox Tester tool 
 https://github.com/Z6543/Sandbox_tester Played with crappy IoT devices – my RCE exploit code running on ~600 000 IP cameras via Persirai 
 https://jumpespjump.blogspot.hu/2015/09/how-i-hacked-my-ip-camera-and-found.html 
 https://jumpespjump.blogspot.hu/2015/08/how-to-secure-your-home-against.html Invented the idea of encrypted exploit delivery via Dif fi e-Hellman key exchange, to bypass exploit detection appliances 
 https://www.mrg-ef fi tas.com/generic-bypass-of-next-gen-intrusion-threat-breach-detection-systems/ Co-organizer of the Hackersuli meetup
 Programme committee member of the Hacktivity conference
 Volunteer at IoTVillage
  • 16. What and why This is a 2 hour presentation compressed into 25 minutes
  • 17. What and why This is a 2 hour presentation compressed into 25 minutes Fasten your seatbelts
  • 18. What and why This is a 2 hour presentation compressed into 25 minutes Fasten your seatbelts I love playing with new technologies
  • 19. What and why This is a 2 hour presentation compressed into 25 minutes Fasten your seatbelts I love playing with new technologies I fi nd blockchain + Web3 fascinating
  • 20. This presentation is NOT about/for
  • 21. This presentation is NOT about/for WHOLE CRYPTO WORLD IS A SCAM!!!!
  • 22. This presentation is NOT about/for WHOLE CRYPTO WORLD IS A SCAM!!!! Smart contract developers
  • 23. This presentation is NOT about/for WHOLE CRYPTO WORLD IS A SCAM!!!! Smart contract developers Financial advise on which shitcoin to invest in
  • 24. This presentation is NOT about/for WHOLE CRYPTO WORLD IS A SCAM!!!! Smart contract developers Financial advise on which shitcoin to invest in Crypto exchange hacks - see six/David's presentation
  • 25. This presentation is NOT about/for WHOLE CRYPTO WORLD IS A SCAM!!!! Smart contract developers Financial advise on which shitcoin to invest in Crypto exchange hacks - see six/David's presentation Cryptocurrency is used as a form of payment, e.g. ransomware
  • 26. How did we get here?
  • 27. How did we get here? Lot of people got rich from cryptocurrencies
  • 28. How did we get here? Lot of people got rich from cryptocurrencies Lot of people want to get rich from cryptocurrencies
  • 29. How did we get here? Lot of people got rich from cryptocurrencies Lot of people want to get rich from cryptocurrencies Total market capitalisation is around 2 1 trillion USD
  • 30. How did we get here? Lot of people got rich from cryptocurrencies Lot of people want to get rich from cryptocurrencies Total market capitalisation is around 2 1 trillion USD 2 1,000,000,000,000
  • 31. How did we get here? Lot of people got rich from cryptocurrencies Lot of people want to get rich from cryptocurrencies Total market capitalisation is around 2 1 trillion USD 2 1,000,000,000,000 New complex technology with crappy UI
  • 32. How did we get here? Lot of people got rich from cryptocurrencies Lot of people want to get rich from cryptocurrencies Total market capitalisation is around 2 1 trillion USD 2 1,000,000,000,000 New complex technology with crappy UI What could possibly go wrong?
  • 35. What is Bitcoin anyway? Let’s hear it from a trusted, 3 Grammy award winner Blockchain expert!
  • 36. What is Bitcoin anyway? Let’s hear it from a trusted, 3 Grammy award winner Blockchain expert!
  • 37. What is Bitcoin anyway? https://youtu.be/5AN5veSPfY4 Let’s hear it from a trusted, 3 Grammy award winner Blockchain expert!
  • 42. Step 1: Buy a lot from something what is cheap and has low volume
  • 43. Step 1: Buy a lot from something what is cheap and has low volume Step 2: Advertise as the NEXT BIG THING
  • 44. Step 1: Buy a lot from something what is cheap and has low volume Step 2: Advertise as the NEXT BIG THING Step 3: Sell on top
  • 45. Step 1: Buy a lot from something what is cheap and has low volume Step 2: Advertise as the NEXT BIG THING Step 3: Sell on top Step 4: PROFIT
  • 46. Step 1: Buy a lot from something what is cheap and has low volume Step 2: Advertise as the NEXT BIG THING Step 3: Sell on top Step 4: PROFIT Optional Step 5: Short on top
  • 47. Step 1: Buy a lot from something what is cheap and has low volume Step 2: Advertise as the NEXT BIG THING Step 3: Sell on top Step 4: PROFIT Optional Step 5: Short on top
  • 49. Rug pull Similar to pump and dump
  • 50. Rug pull Similar to pump and dump But you are the owner/ developer of the cryptocurrency/token/ whatever
  • 51. Rug pull Similar to pump and dump But you are the owner/ developer of the cryptocurrency/token/ whatever Even Conti ransomware group knew about SQUID
  • 52. Rug pull Similar to pump and dump But you are the owner/ developer of the cryptocurrency/token/ whatever Even Conti ransomware group knew about SQUID
  • 53. Rug pull Similar to pump and dump But you are the owner/ developer of the cryptocurrency/token/ whatever Even Conti ransomware group knew about SQUID
  • 65. What is an NFT anyway? https://twitter.com/zh4ck/nft https://etherscan.io/nft/0x06012c8cf97bead5deae237070f9587f8e7a266d/634517 https://etherscan.io/tx/ 0xfe21bd24d7748890c4deb2453bcd22ab451349fdacb5e812422e16772a664723#eventlog https://etherscan.io/address/0xb77feddb7e627a78140a2a32cac65a49ed1dba8e#code
  • 66. The “magical” world of NFTs … 1 ETH = 1700 USD
  • 67. The “magical” world of NFTs … 1 ETH = 1700 USD
  • 68. The “magical” world of NFTs … 1 ETH = 1700 USD
  • 69. The “magical” world of NFTs … Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 70. The “magical” world of NFTs … Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 71. The “magical” world of NFTs … Justin Bieber - 500 ETH Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 72. The “magical” world of NFTs … Justin Bieber - 500 ETH Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 73. The “magical” world of NFTs … Snoop Dog - 2500 ETH Justin Bieber - 500 ETH Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 74. The “magical” world of NFTs … Snoop Dog - 2500 ETH Justin Bieber - 500 ETH Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 75. The “magical” world of NFTs … Snoop Dog - 2500 ETH Justin Bieber - 500 ETH Eminem - 123.45 ETH Paris Hilton BAYC - 119 ETH 1 ETH = 1700 USD
  • 76. The “magical” world of NFTs … Snoop Dog - 2500 ETH Justin Bieber - 500 ETH Eminem - 123.45 ETH Paris Hilton BAYC - 119 ETH https://etherscan.io/token/0xbc4ca0eda7647a8ab7c2061c2e118a18a936f13d#readContract https://ipfs.io/ipfs/QmeSjSinHpPnmXmspMjwiXyN6zS4E9zccariGR3jxcaWtq/9055 
 https://cid.ipfs.io/#QmTHcV6mGxHGeeXCnYtV129eRiR8Exni4sT8dDikBWBgzY 1 ETH = 1700 USD
  • 105. Discord servers hacked via bookmarklets Discord scam
  • 106. Discord servers hacked via bookmarklets Discord scam
  • 107. Discord servers hacked via bookmarklets Discord scam
  • 108. Discord servers hacked via bookmarklets Discord scam
  • 110. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 111. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 112. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 113. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 114. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 115. HW wallets - Ledger, Trezor https://whotookmycrypto.com/ ledger-wallet-scams/
  • 116. HW wallets - Ledger, Trezor
  • 117. HW wallets - Ledger, Trezor
  • 118. HW wallets - Ledger, Trezor
  • 120. Best practices don’t trust random people (or celebrities) on social media
  • 121. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp
  • 122. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone
  • 123. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase
  • 124. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts
  • 125. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager
  • 126. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based
  • 127. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based use HW wallet if you have a lot to protect
  • 128. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based use HW wallet if you have a lot to protect keep PC free of malware
  • 129. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based use HW wallet if you have a lot to protect keep PC free of malware cold wallet for valuables - like you don’t store your life savings in your pocket wallet
  • 130. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based use HW wallet if you have a lot to protect keep PC free of malware cold wallet for valuables - like you don’t store your life savings in your pocket wallet take time, don’t rush
  • 131. Best practices don’t trust random people (or celebrities) on social media check source of the app/dapp don’t send funds to someone you don't trust, or verify via phone block people/email sharing login, password, private key, seed phrase, backup phrase extra careful to interact with KNOWN and unknown smart contracts use password manager enable 2fa, don’t use SMS based use HW wallet if you have a lot to protect keep PC free of malware cold wallet for valuables - like you don’t store your life savings in your pocket wallet take time, don’t rush install security extensions like "Wallet Guard" or "Sunrise: NFT scam protector"
  • 132. Conclusion I can send white-paper if you want
  • 133. Hack the planet One computer at a time zoltan.balazs@cujo.com https://hu.linkedin.com/in/zbalazs Twitter – @zh4ck www.slideshare.net/bz98 JumpESPJump.blogspot.com