Fake CAPTCHAs on BNB Chain used to spread malware

Hackers used fake CAPTCHA prompts on BNB Chain sites and dApps to trick users into downloading malware or approving transactions that allowed attackers to access wallets.

Hackers planted counterfeit CAPTCHA prompts on BNB Chain decentralized apps and token pages over recent weeks, leading users to download malicious files or sign transactions that granted attackers access to wallets.

The fraudulent pages mimicked standard human-verification challenges. After users completed the CAPTCHA, some pages triggered a file download while others prompted a wallet signature. The downloaded files contained malware, and the transaction prompts requested permissions that let attackers transfer tokens from compromised wallets.

Investigators found attackers cloned legitimate token and dApp pages and inserted fake CAPTCHA elements into those interfaces. Many of the cloned pages used domains and decentralized hosting addresses referenced in BNB Chain metadata, so victims encountered the prompts after following links tied to new token launches or airdrop claims promoted on social channels and listing pages.

The campaign focused on browser-based cryptocurrency wallets that users connect to decentralized applications. When a wallet owner approved a transaction granting a smart contract permission to transfer tokens, attackers used that approval to move assets without further user interaction. In other cases, the downloaded malware created persistence mechanisms and extracted credentials or other private data from the device.

Blockchain monitoring groups and security teams cataloged multiple malicious links and smart-contract addresses linked to the scheme. Analysis of on-chain transactions showed many small drains across dozens of wallets rather than a single large theft. The actors used basic obfuscation in contract code and created numerous short-lived domains to host fake CAPTCHA widgets, which complicated takedown efforts.

Security teams advised caution when encountering CAPTCHA prompts on unfamiliar domains, and recommended avoiding downloads or browser extensions prompted by dApp pages. They urged users to review and limit smart-contract approvals, revoke suspicious permissions, and use wallet interfaces that display exact permissions before signing.

Platforms and hosting providers have been notified of the malicious domains and contracts. Security researchers continue mapping links between the malicious pages and the addresses that received stolen funds while tracking related on-chain activity.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author