Dear Poloniex Users,
In light of the increasing sophistication of recent cyberattacks targeting cryptocurrency exchange accounts, Poloniex is issuing an urgent security alert to our worldwide users to enhance your security vigilance to safeguard assets.
Recent Cyberattacks and Analysis
Case 1: A user's Chrome browser was infiltrated via the malicious "Aggr" plugin, resulting in the hijacking of browser cookies. Attackers exploited these cookies to access the user's account of a certain exchange without a login password and 2FA code and transfer out $1 million assets by wash trading.
Case 2: Another user fell victim to a sophisticated attack where attackers purchased their personal information on Telegram. The attackers manipulated the user's exchange account through email login and the forgot password option. Subsequently, they applied to change account settings, such as phone number, email address, and even Google Authenticator with AI-generated videos. This breach culminated in the theft of over $2 million assets after 24 hours of changing the account password.
These cases underscore the evolvement of cyber threats, particularly as AI technology is increasingly leveraged by malicious actors. It would be the best if you adopt robust security measures to protect your personal information and assets. For those holding substantial investments, it is critical to implement measures for stringent privacy and isolation, such as disabling third-party plugins and regularly logging out of accounts.
Our Commitment to User Asset Security: Timely Upgrade of Security System
We advise users to adhere to the following security practices:
1. Phone Security: When accessing Poloniex on smartphones, ensure your device security by avoiding the installation of untrusted third-party apps. Only download the Poloniex app from official app stores and authorized channels.
2. PC Security: For login via PC, ensure your device is protected with robust antivirus software. Avoid installing untrusted third-party applications and browser extensions.
We are unwavering in our priority for user asset security. Our security team continuously enhances security management including real-time security upgrades to counteract emerging threats. Looking ahead, we are poised to employ even higher financial standards to ensure the long-term security of user assets.
Poloniex Team
June 4, 2024