Beware of Phishing: How to Protect Yourself from Scams

January 2, 2025 at 05:48 PM

Dear BloFin Users,

Phishing scams are a widespread form of online fraud in which attackers replicate legitimate websites to steal sensitive information, such as bank details, passwords, and personal data. These fake links are often distributed via SMS, email, and social media to deceive users. Here, we will explore common phishing techniques and offer practical tips to safeguard your assets. Stay vigilant and take proactive measures to protect yourself from these phishing email scams.

Common Phishing Techniques

Phishing attacks often involve tactics like email phishing and pharming:
  • Email Phishing: Attackers send deceptive emails with links to fake websites or malware downloads. Emails may appear to come from the official website but often use slight misspellings or unofficial domains. If users click these links or download malicious files, sensitive information like passwords and financial details may be stolen.
  • Pharming: By exploiting system vulnerabilities, attackers modify DNS files on users' devices, redirecting legitimate web addresses to phishing sites. Users may unknowingly enter personal data on these fake sites.
Crypto-Specific Scams
In the crypto space, scammers often impersonate platform staff, using SMS, email, or social media to spread fake messages about account upgrades, crypto refunds, suspicious asset inflows, or withdrawal closures. These messages contain phishing links or QR codes that trick users into providing sensitive account details, enabling scammers to steal funds. Please stay alert and verify all messages to protect your assets.
 
A recent email phishing case:
A BloFin user reported that he received an email (seemingly from BloFin), notifying him of suspicious asset inflows in his account. The email instructed him to provide the required information to confirm this asset. However, the email addresses shown in the screenshot are unofficial BloFin email addresses.

0b902335-443d-4feb-a686-b0d54badb30f.png

 

Tips to Prevent Phishing Scams

1. Be Wary of Unsolicited Emails: Treat unexpected emails with caution, especially those urging immediate action. Scammers often create urgency to pressure you into hasty decisions. Users can check the authenticity of BloFin channels at https://blofin.com/official-verification  
2. Verify Sender Email Addresses: Phishing emails may appear genuine, but the sender's email address often reveals the truth. Be cautious of slight variations or misspellings that mimic official exchange addresses.
3. Don't Click on Suspicious Links: Always navigate to the exchange's website by typing the URL directly into your browser instead of clicking on links in emails. If you suspect a link is malicious, visit the official BloFin site (https://blofin.com) to change your login and fund passwords, and contact our official service ([email protected]) immediately.
4. Enable Two-Factor Authentication (2FA) and Passkeys: Strengthen your account security by requiring a second form of verification. This makes unauthorized access significantly harder.
5. Protect Your Personal Information: BloFin will never ask for your passwords, private keys, or sensitive account details via email.
6. Stay Updated: Phishing tactics constantly evolve. Keep informed about the latest scams to better safeguard your assets.
7. Set Up an Anti-Phishing Code on BloFin: Setting up an anti-phishing code ensures that all legitimate emails from the BloFin exchange include a specific identifier. This helps you distinguish genuine communications from fraudulent ones.

Here is a guide on how to set up anti-phishing code on BloFin:

  1. Click the avatar in the upper right corner and select [Account & Security].0001.jpeg
  2. Scroll down the page, find the Anti-Phishing Code, and click [Set up] to set up your anti-phishing code.001.jpeg
  3. After the anti-phishing code is set successfully, the code will be present in all official emails from BloFin. Kindly verify its presence whenever you receive emails from BloFin.mceclip0003.png

If You’ve Been Scammed

  • Report the Scam: Contact our support team at [email protected].
  • If you’ve fallen victim to a scam, be cautious of further attempts by the same fraudsters. Avoid processing any withdrawals or transfers initiated by strangers.
We recommend seeking assistance from local authorities if you’ve been scammed by someone impersonating BloFin. Additionally, we encourage all users, both new and experienced, to review our anti-scam resources to protect themselves from common crypto scams.

 

Further Reading:

  1. Risk Warning: Recent Fake BloFin Platform Scam
  2. How to Set Anti-Phishing Code?
  3. How to Link Google Authenticator (2FA)?
  4. How to Create a Passkey?

Thanks for your attention and support!

BloFin Team
Jan 2, 2025

Was this article helpful?