Crypto Scam: SEAL Team Unveils Verifiable Phishing Reports to Expose Scammers

robot
Abstract generation in progress

The new verifiable phishing reports tool, developed by SEAL, assists researchers in proving and combating crypto scams cryptographically.

This will solve one of the main problems with phishing detection: fraudsters tend to wrap malicious scripts, presenting security scanners with innocent websites

The system created by SEAL enables the researcher to demonstrate, irrefutably, that a URL was used to store phishing content, increasing confidence and cooperation in the war against phishing.​

Seeing Through the Cloak: The Power of TLS Attestations

Older URL scanners have a hard time with anti-bot systems and CAPTCHA. Even worse, scammers hide their true content by showing safe-looking pages to automated scanners, so the malicious material goes unexamined.

SEAL worked around this by developing TLS Attestations – a cryptographic tool which records and signs the precise content that a user viewed over a secure web session

This change allows security researchers to prove that what a user encountered was truly fraudulent, not just a claim.

How It Works: Cryptographic Proof Against Phishing

The tool works by intercepting web connections using a local proxy. The proxy records the session information and connects with some attestation server, which serves as a cryptographic oracle in the TLS-encrypted session

The user is in control of the network connection; this is legitimate because the server is no longer in charge of encryption, as well

Under this method, security researchers produce cryptographically signed verifiable phishing reports that display exact malicious web material

SEAL can then independently verify these reports without direct access to the phishing sites, and it is nearly impossible to conceal malicious content.​

The new tool by SEAL is aimed at targeting those with advanced skills and security researchers, specifically the experienced good guys, and enhance community actions against crypto scams, which have already cost people more than $400 million in losses only this year

Before believing someone’s claim that a URL is malicious, do your own check. This is an undisputed scientific advancement that now equips researchers.​

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)