Introduction
We get it. Avoiding hacks and scams is hard, especially when crypto crime accounts for over $1 billion in lost funds every year. It can feel like protecting your wallet and hard-earned money is an uphill battle, like you're always one step behind the bad guys.
That's where Harpie comes in. Harpie gives you the tools to secure you and your wallet from the most basic to the most complex attacks.
How people become victims of theft
We've spent a considerable amount of time researching the behavior of those who have fallen victims to scams versus those that have never. We've determined 2 major factors that decide whether someone becomes a victim of crypto crime or not. These two factors are:
Not knowing common Web3 attacks and how to spot them
Not being 100% when using crypto, usually caused by:
Fatigue
FOMO
It's impossible to ask people to double, triple-check every transaction. And even then, people make mistakes. That's how Harpie helps. We fill in the gaps for your security, so that even when you do make a mistake, there's someone watching your back.
Read on to learn about common Web3 attacks and how Harpie can prevent them. Read more at What does Harpie protect me from?
Common Web3 Attacks
1. Frontend Attacks
Frontend attacks are one of the most effective attack vectors, able to trick even the most experienced crypto veterans. Attackers hijack legitimate websites, through methods like malicious code injection or DNS take-overs, and replace a website's code with code that steals your crypto.
Key Points:
Effective against experienced individuals
Difficult to detect, can remain dormant for extended periods
Exploit user trust for wallet access
Sure, you might not approve your tokens to a website you've never heard of, but what about a website trusted by millions like Coinbase or Uniswap?
2. Fake Sites and Phishing Sites
Fake sites and phishing sites are another common attack.
Attacks like this use a clean, well-designed website to trick victims into trusting the site. Afterwards, victims are asked to sign malicious smart contracts or send over their private keys to the attacker as part of a "user onboarding" process.
Key Points:
Common and convincingly designed
Prey on users during time-sensitive events (e.g., token airdrops, NFT mints)
Advertised under reputable company posts, relying on unnoticed URL errors
3. Accidental Transfers
Though not always an attack in the traditional sense, accidental transfers are still a devastating financial mistake. Any transaction that you send to a wallet that you don't own or control cannot be reversed.
There's no support line that you could call if you accidentally sent your NFT to address 0x123...ABC
instead of 0xABC...123
. Transactions on the blockchain are permanent and there's no way to recover that NFT after it's been sent.
Accidental transfers can happen for many different reasons:
Mistyping an address
Copy and pasting the wrong address
... or even targeted attacks like "Copy Paste" viruses
How Harpie helps
We've covered a few ways that attackers can gain access to your wallet. Luckily, Harpie helps keep you safe by making sure that you don't fall victim to these types of attacks.
1. Wallet 2-Factor Authentication (2FA)
Harpie 2FA identifies potentially dangerous transactions and stops these dangerous transactions from completing.
Dangerous transactions can be anything from wallet drainers, like the ones you'll see on a frontend attack or phishing site, to more innocuous ones like accidental transfers.
The image above shows an email from Harpie warning you of a transaction that gives ownership of your NFT to an Unknown Address. From your email, you can choose to either let the transaction through or cancel it.
2. Advanced Security
Harpie Advanced Security is designed to protect your tokens by preventing transactions with untrusted addresses.
It's akin to a high-security vault, ideal for tokens that are valuable and not frequently moved or traded. This feature is perfect for long-term holdings or assets of significant worth that you want to safeguard at all costs.
It's a way to protect your wallet even when you're asleep. Harpie Advanced Security works 24/7, monitoring your wallet for any potential attacks or unexpected transfers. Read more about Harpie Advanced Security here: Is Harpie Advanced Security right for me?
3. Approval Revoking
Open Token Approvals are like backdoors into your wallet. Without careful management of what apps have access to your wallet's tokens, you may find yourself a victim.