police
Security community - help users avoid every risk (and burning money) on Farcaster
KMac pfp

@kmacb.eth

@shawmakesmagic where you at on this‽
0 reply
2 recasts
5 reactions

Disky.eth pfp

@disky.eth

I guess this scammer is drunk or something..
2 replies
1 recast
7 reactions

Icetoad 🍕 🎩 🐈 pfp

@icetoad.eth

Oof, not a good look https://youtu.be/-L-EH5dryuU?is=B1yd4fUGdwOUQWSm
3 replies
2 recasts
7 reactions

COMPΞZ 🧬 pfp

@compez.eth

🚨 Major data leak: 124 million passwords and 56 million emails exposed! This time, it is not just about one hacked website. Malware has stolen saved passwords, cookies, and browser data from infected devices. Check your email on Have I Been Pwned: https://haveibeenpwned.com If your data was exposed, change your passwords immediately and enable 2FA.
2 replies
1 recast
11 reactions

Disky.eth pfp

@disky.eth

They just tried to break into my house will I'm home. Damn scary! They tried to move my camera's but might have forgotten that these things recorded them.. But police says they can't do much if they didn't actually steal anything yet...
2 replies
0 recast
6 reactions

Disky.eth pfp

@disky.eth

Somehow I'm a mod of /police now. Not sure how that happend or even why that happend? @wallstreetguy.eth seems to AFK for a few months making it even more of a mystery why I'm a mod now? Guess I'll do my best to curate ;) Any changes or requests?
2 replies
2 recasts
19 reactions

farmoar pfp

@farmoar

support for scammers is beyond my understanding what happened to his 10 other projects and tokens he launched & rugged on fc?
1 reply
0 recast
1 reaction

William pfp

@william0x.eth

Everyone says not to store your wallet seed phrases online, but almost no one touches upon the fact that storing them offline (via paper, metal, safeboxes) is a pain. Sure, there are hardware wallets, but to be honest, not everyone's going to be able to get a hardware wallet, and even then there's always the possibility of losing the "paper"/"metal sheet" or having someone stumble upon it. Initially (we're talking around 5 - 6 years ago) I wrote my phrases down on paper, but after a bit, I found that it was not convenient (or secure for that matter). I moved to storing them in Google Docs (the Google account I used had no connection to any third-party apps, wasn't used to sign up for any service, wasn't signed into any other device, and exclusively hosted the file containing the phrases), but I've also come to realise, that this is not ideal either. Not only can Google lock you out.... but there was also the possibility of them accessing your data (yes, I know policies and safeguards exist to prevent this, but if we are being honest, we have to acknowledge that there's always a chance your data could be exposed/read by an employee or anyone with required admin credentials.) Plus, if the Google account itself got compromised, the wallet would be as good as gone. To circumvent these issues, I've resorted to using SHA-256 encryption to secure my seed phrases. Here's how the process goes: -> I have Claude create a Python script that uses SHA-256 (via the cryptography library) to encrypt the inputted seed phrase using a master passphrase of my choosing. -> I move the script to a VM and run it offline to generate the encrypted output. (this step isn't necessary, but I tend to get paranoid about malware, even when I'm fairly confident there's none on my PC. 😂 ) -> After encrypting, I take the ciphertext and store it in Google Docs or Fileverse, while also keeping offline copies on external drives. {Images depicting the workflow below} With this setup, even if someone gains access to the document containing the ciphertext, they still can't access the wallet without the master password that decrypts the ciphertext. This method isn't without its flaws - you could lose data on the drives due to degradation or forget the master password - but as long as you maintain regular backups across multiple drives and never forget your encryption key, I'd argue it's one of the more practical options for anyone who needs to store phrases online. That said, I'd still advise against keeping large amounts on such a wallet - When it comes to security (especially with crypto wallets), you have to assume any system could be compromised. So if you absolutely must, consider getting a hardware wallet or a separate software wallet and configuring it as a multi-sig --> one that requires approval from two or more wallets before any transaction goes through. So, what do you guys think? Is this approach solid enough? Plus, what do you use for storing your seed phrases? 👀 p.s. To help with not losing access because you forgot your master password, consider having it engraved on a metal plate. You could commission a small decorative piece - a keychain or a medallion, for example - and have the words engraved discreetly on the back (the engraver doesn't need to know what it's for.).
5 replies
6 recasts
35 reactions

Disky.eth pfp

@disky.eth

Seems that the scammers in our dm's are trying romance scams now.. I met the very real Jenna Ortega 5 times this week already! 🤦‍♂️
2 replies
3 recasts
11 reactions

XBorn ID pfp

@xbornid.eth

⚠️ [CRITICAL] PHISHING ALERT Author: @monteluna · Risk: 60/100 "@neynar another scammer posting a fake phishing link" 🛡 Detected by ScamWatch
0 reply
0 recast
0 reaction

Pichi pfp

@pichi

「 ✦ WARNING ✦ 」 This is a scam. The same bot network that’s trying to drain your wallet with fake hypersnap claims is now trying to take over your computer with a fake F̰a̰r̰c̰s̰t̰ḛr̰D̰ḛs̰k̰t̰o̰p̰ ̰™̰ website. Please be extra cautious! This network of automated accounts is malicious and is trying every tactic possible to get you to click!
23 replies
46 recasts
120 reactions

XBorn ID pfp

@xbornid.eth

⚠️ [CRITICAL] GENERAL RISK Author: @nikolaii.eth · Risk: 100/100 "Beware: THIS IS NOT UCI! We will never ask for your seed phrase, recovery phras…" 🛡 Detected by ScamWatch
0 reply
0 recast
0 reaction

Disky.eth pfp

@disky.eth

Lol the contradiction of this one..
0 reply
0 recast
6 reactions

Kelvin🎩 pfp

@kel66.eth

Scam 🚨
1 reply
8 recasts
17 reactions

Icetoad 🍕 🎩 🐈 pfp

@icetoad.eth

Trump is the biggest grifter of all time, that you can take to the bank. That said, this post that is going around (Twitter and Threads mostly) the last day or two is not an actual Trump post and the site in question is not affiliated with him. It appears to be some kind of phish or pig butchering platform. As the former CTO of Global Anti-Scam Organization, I feel like it is my duty to help people avoid scams like this one. First off, the easiest way to determine if a post like this is real is to go right to truthsocial.com/@realdonaldtrump and check. The lazy way would be to use Gemini or something like reallens.org. - this screen looks to be Arial or maybe Helvetica. Truth Social uses the Inter font - the purported gambling site says it has been operating since 2017, but a domain lookup shows the domain was registered last month and this post says the site is new - most of the links on the site just circle back around to the main page - a Google search shows no journalists talking about this gambling platform
0 reply
0 recast
5 reactions