Share this article

Encrypted Messaging Site Privnote Cloned to Steal Bitcoin

The free web service, which lets users send encrypted messages that self-destruct once read, has been copied with the reported aim of redirecting users' bitcoin to criminals.

Updated Sep 14, 2021, 8:51 a.m. Published Jun 15, 2020, 9:18 a.m.
Clones concept (Credit: My Ocean Production/Shutterstock)
Clones concept (Credit: My Ocean Production/Shutterstock)

Privnote, a free web service that lets users send encrypted messages that self-destruct once read, has been copied with the reported aim of redirecting users' bitcoin to criminals.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

In a Sunday post on cybersecurity blog KrebsonSecurity, journalist Brian Krebs warned users of a phishing scam that lures unsuspecting victims to a near-identical version of the privnote.com website known as privnotes.com.

However, the fake site doesn't fully encrypt messages, as Krebs discovered in tests, and can "read and/or modify all messages sent by users."

Just as worrying, it contains a script that hunts out messages containing bitcoin addresses and changes the original address into the bad actor's own address in the sent message. This would mean any funds sent would arrive at the bitcoin address owned by the criminal, not the one intended by the message sender.

"Any messages containing bitcoin addresses will be automatically altered to include a different bitcoin address, as long as the Internet addresses of the sender and receiver of the message are not the same," Krebs said in the post.

"Until recently, I couldn’t quite work out what Privnotes was up to, but today it became crystal clear," he said.

Krebs explained he'd been notified by the owners of privnote.com that someone had built a clone version of their site and that it was tricking users of the legitimate site.

See also: Crypto Scams Targeting Pacific Communities on the Rise, Say New Zealand Regulators

"It’s not hard to see why: Privnotes.com is confusingly similar in name and appearance to the real thing, and comes up second in Google search results for the term “privnote.” Also, anyone who mistakenly types “privnotes” into Google search may see at the top of the results a misleading paid ad for “Privnote” that actually leads to privnotes.com," Krebs wrote.

A Google search for “privnotes” pulls up a paid advert for the phishing site privnotes.com
A Google search for “privnotes” pulls up a paid advert for the phishing site privnotes.com

A quick Google search by CoinDesk verified this finding.

Making the scam harder to spot, the self-destructing nature of these messages means victims are unable to go back and check on the bitcoin addresses the script alters: they are sent, read and deleted. According to Allison Nixon, chief research officer at Unit 221B, who helped identify and test the phishing scam, said the script appears to only alter the first instance of a bitcoin address if it's repeated within a message.

"The type of people using privnote aren’t the type of people who are going to send that bitcoin wallet any other way for verification purposes,” Nixon said in the post. “It’s a pretty smart scam.”

See also: FBI Warns COVID-19 Scammers Are Targeting Crypto Holders

Bitcoin-related scams have been on the rise in recent months, particularly with concerns relating the coronavirus pandemic. U.K residents were warned in late March that scams were being used to exploit fear and uncertainty through text messages and emails posing as an official health organization.

"Even if you never use or plan to use the legitimate encrypted message service Privnote.com, this scam is a great reminder of why it pays to be extra careful about using search engines to find sites that you plan to entrust with sensitive data," Krebs said.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

HYPE token surges 24% as silver futures volume soars on Hyperliquid exchange

(Thomas Lohnes/Getty Images)

Silver futures on the crypto derivatives exchange are currently showing $1.25 billion in volume and $155 million in open interest.

What to know:

  • HYPE, the native token of the Hyperliquid derivatives exchange, jumped 24% in 24 hours as trading in silver, gold and other commodities surged.
  • Silver perpetual futures on Hyperliquid became the platform’s third most active market during Asia hours.
  • Because trading fees from user-created markets are used largely to buy back HYPE on the open market, the spike in commodity activity is fueling demand for the token and signaling broader growth for Hyperliquid.