andywan

Posted on Dec 29, 2021Read on Mirror.xyz

@chriscantino的Crypto Security 101

https://twitter.com/chriscantino/status/1445812716698935300

1/ Crypto Security 101. Avoid getting swindled out of your coins and NFTs—and learn to proactively reduce your risk.

加密安全101。避免被骗去你的币和NFT,学会主动降低风险。

2/ This is a guide for both beginners and experts. The phishing and scam attempts out there are sophisticated and convincing. And being so early in crypto, it’s legitimately hard to know what to look for. Everyone is vulnerable. Don’t be that person who got their ETH drained.

这是初学者和专家的指南。

网络钓鱼和诈骗的企图是复杂和令人叹服的。由于crypto早期,很难知道该寻找什么。每个人都很脆弱。不要做那个让自己的情绪失控的人。

3/ The Price Swap When a NFT project receives a flood of buyers, scammers can subtly change their listing price at the last moment. You might have clicked into a listing at .13, but it could be 1.3 at checkout. Don’t overpay—review the final amount before confirming.

当NFT项目收到大量买家时,骗子可以在最后一刻巧妙地改变他们的挂牌价格。

您可能在.13处点击列表,但在签出时可能是1.3。鬼脸

不要多付,在签名时一定要确认最终金额。

4/ The Fake Collection Fake OpenSea collections are a dime a dozen. Look at these fakes, where scammers add a subtle “s” or “.” to trick buyers. Few collections are verified at launch, so make sure you get an official link from the project’s site or Discord.

4/假收藏品

伪造的OpenSea收藏品非常便宜。看看这些假货,骗子在上面加了一个微妙的“s”或“.”欺骗买家。

很少有收藏在发布时得到验证,所以请确保您从项目的网站或Discord获得官方链接。

5/ The DM Slide If you engage in NFT communities, at some point you will receive a DM from a seemingly authentic account. Know that it is VERY unlikely for any project to DM you out of the blue. Only trust accounts that you can trace back to a project’s official links.

5/DM幻灯片

如果你参与NFT社区,在某个时候你会从一个看似真实的帐户收到DM。要知道,任何项目都不太可能让你一败涂地。

只有可以追溯到项目官方链接的信任帐户。

6/ The Fake Contract Some collectors mint NFTs directly from Etherscan contracts—it can be faster than minting from a project’s website. However, some malicious Discord users circulate fake, official looking contracts that will drain your crypto. Verify, verify, verify.

6/假合同

一些收藏家直接从Etherscan合同中铸造NFT,这比从项目网站铸造NFT要快。然而,一些恶意的Discord用户传播伪造的、看起来像官方的合同,这将耗尽你的Crypto。

验证,验证,验证。

7/ The Malicious Coindrop Ever open your wallet and see a strange coin that appears to have dropped you free money? Yeah, no—that’s a scam. Do not interact with mal-coins.

7/恶意空投币

有没有打开你的钱包,看到一枚奇怪的Coin,似乎天上掉馅饼?

是的,不,那是个骗局。不要与mal-coins互动。

8/ The Fake Agent When receiving customer support, remember there is no context that should require you to click a non-official link. Furthermore, no legitimate agent will ever ask you to share your screen, provide your seed phrase, password, private keys, or QR code image.

8/假Agent

在接受客户支持时,请记住,没有上下文要求您单击非官方链接。

此外,任何合法Agent 都不会要求您共享屏幕、提供种子短语、密码、私钥或二维码图像。

9/ The Anonymous Project If a project is not public about who its leaders are, what’s stopping them from walking away with profits or abandoning it altogether? Sure, there are trustworthy projects with pseudonymous leaders—but be careful.

9/匿名项目

如果一个项目没有公开它的领导者是谁,是什么阻止他们带走利润或完全放弃它?

当然,有一些值得信赖的项目是由化名的领导者完成的,但要小心。

https://www.vice.com/en/article/y3dyem/investors-spent-millions-on-evolved-apes-nfts-then-they-got-scammed

https://www.vice.com/en/article/y3dyem/investors-spent-millions-on-evolved-apes-nfts-then-they-got-scammed

10/ The Spammy Server A project might look legitimate with 20k followers, but is the hype legitimate or manufactured? Is there a multi-level invite system designed to pump the numbers? Are there bots? Review activity on the server to determine how engaged followers really are.

10/垃圾邮件服务器

一个拥有2万粉丝的项目看起来可能是合法的,但炒作是合法的还是捏造的?

是否设计了一个多级邀请系统来发送号码?有机器人吗?

查看服务器上的活动,以确定追随者的实际参与程度。

11/ Let’s talk more about preventative measures. First, buy a cold wallet. A $200 investment could save you thousands, even millions. Always buy directly from the wallet manufacturer. NEVER buy from a third party.

11/让我们进一步讨论预防措施。

首先,买一个冷钱包。200美元的投资可以为你节省数千甚至数百万美元。

始终直接从钱包制造商处购买。永远不要从第三方购买。

https://twitter.com/chriscantino/status/1445084867616669698

https://twitter.com/chriscantino/status/1445084867616669698

12/ Spreading Out Your Holdings Never hold all your assets on a single wallet. In the unfortunate event that you are scammed, this prevents you from losing EVERYTHING. Make ten wallets if you have to. Make twenty. The more crypto you accrue, the more accounts you should create.

12/分散你的财产

永远不要把你所有的资产都放在一个钱包里。在不幸的情况下,你被骗了,这可以防止你失去一切。

如果有必要的话,做十个钱包。二十美元。您累积的加密越多,您应该创建的帐户就越多。

13/ Approving Transactions This may seem obvious, but when you’re in a rush to buy, or you’re signing tons of transactions, you might be tempted to smash “approve“ before a full review. This is a fast way to approve an unintended transaction, or overpay on gas.

13/批准交易

这似乎很明显,但当你急于购买,或签署了大量交易时,你可能会在全面审查之前拒绝“批准”。

这是批准非预期交易或超额支付Gas的快速方法。

14/ Educating ourselves and others on crypto security is necessary for the technology to achieve mainstream adoption. Remember the days of buying Norton Antivirus on CD-ROMs? That’s how early we are. Stay vigilant, report suspicious activity, and help keep our communities safe.