SlowMist: How to Choose an Anti-Phishing Plugin

Background

The Current State of NFTs

https://hacked.slowmist.io/

Security Plugin Comparison

  1. This will encompass parameters such as open-source availability, download counts, supported networks, and primary descriptions:

Comparison Results

  1. Rabby wallet + Scam Sniffer
  2. Rabby wallet + Pocket Universe
  3. MetaMask + Pocket Universe
  4. MetaMask + Revoke.cash

After Thoughts

  • Phishing Website Warning: One measure that can be taken is implementing a phishing website warning system that leverages the power of the blockchain community to identify and collect all types of phishing websites. This way, users can be provided with prominent reminders and alerts whenever they interact with these sites to reduce the risk of falling victim to phishing attacks.
  • Signature Identification and Alerts: It is important to implement signature identification and alerts for requests such as eth_sign, personal_sign, and signTypedData to notify users and draw their attention to the risks of blind signing with eth_sign.
  • What You See Is What You Sign: To avoid phishing approvals, it is important to perform a detailed analysis of contract calls in wallets and provide users with specific details of DApp transaction construction.
  • Pre-execution Mechanism: A pre-execution mechanism is useful in helping users understand the potential effects of a transaction before it is broadcast and executed. This allows users to make informed decisions and judgments about whether or not to proceed with the transaction, thereby enhancing their overall security.
  • Fraud Alerts for Identical Ending Digits: A mechanism can be set up to display addresses with an alert, reminding users to check the complete target address to avoid fraud problems with identical ending digits. Additionally, a whitelist address mechanism can be implemented for users to add commonly used addresses to the whitelist, which can prevent similar attacks with identical ending digits.
  • AML Compliance: Using AML mechanisms, users can be reminded whether the target address will trigger AML rules when making transfers

About SlowMist

--

--

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.