A quick look into omnerausd (@ColeJacksonUS) and @Shade_L2 ICO scam, where victims were also drained while claiming the ICO tokens
This appears to be part of an ongoing Solana phishing scam (SolPhish) that has been active for some time on the Solana blockchain. The attack relies on victims signing a malicious transaction that allows the attacker to replace the core Owner permission of the wallet.
Victim permissions are commonly transferred to the following address:
GKJBELftW5Rjg24wP88NRaKGsEBtrPLgMiv3DhbJwbzQ
Example case
One victim participated in the omnerausd ICO and later claimed the token. During this process, wallet ownership was transferred to the attacker-controlled address
Victim: BQFiqVQAhkf5WtTRGMSsTaqt6NKopSKVvAckBP1JxJW9
The initial (first funder) $200K deposited into the omnerausd ICO wallet originated from the threat actor (project owned wallet):
ICO wallet:
LDn18YuXHyHWjaHCH3A4QKz6snGbhWmAmoU4oZhF2xC
First funder:
4s9ZytGBG7PZNTJZsmxT1Jd3qBYxc5boy7QdrmqmUCcs
Wallet 4s9ZytG was funded by an address labeled Fake_Phishing on Solscan. Further tracing links this flow to a known drainer address previously reported by @0xmiir in July 2024, associated with approximately $300K in theft.
https://t.co/5rV40hDMe6
Clustered addresses
9htfHryds3YLLjZZxa4RTyegFfsScvGcFTQyFCcVXUVm
3Bitp9awjSEGE1UumthfF6iogTuTkFhaLBHj3xvK7yQa
HbtSzZgPZJabqWgXV9t7S4n6RwkmFuUDze1tQYX22oAP
6Dofca9F1pU2iodvgzGFSUaP8BSooMsWPb8H5saYikCX
H84jE7ZvSQc7JM6BpZX5kBKDShYboM6yYLaAZKdGsvTT
Bo3bz5HiGB8V9vxDPc8p6CujtXdosT1c4CvU3wdYDkyh
9955r2AsxJcbuST11jeE39wGXeQX5FziNhjzeJMK1Zss
HuzNeiRA6MexzQs21AKHUsjLWTseCNkTcFi5iX9MK3pA
The attacker primarily swapped stolen assets into SOL, then launched and traded tokens via @anoncoinit, before depositing funds into nested services.
Some of the threat actors X account
@TaylorMade61016@FredrikSjoedin
@Bullish__Degen
@ColeJacksonUS
@connorcrd@yunaintern
Not every malicious link looks suspicious. In this case, attackers launched projects, and drained victims during routine interactions such as token claims.
Before clicking a link or approving a signature, always pause and ask:
Is the source legitimate?
Is this truly from the official team?
What exactly does this signature authorize?
Are there unfamiliar permissions, unknown addresses, or unusual authorization prompts?
For further reading, see this @SlowMist_Team breakdown on Solana phishing (SolPhish):
https://t.co/GjxO8eyTKH
Stay smart.
OpenSea has evolved.
Beta complete. Full token universe unlocked.
New rewards program live. Welcome to the new OpenSea — the best place to discover, own, and trade anything onchain.
1,274,000 $NXPC are up for grabs on CandyBomb!
🍬 Join now: https://t.co/40YLVwxRmI
Follow to share 86,000 NXPC!
🔹Follow @bitgetglobal @MaplestoryU
🔹RT with #NXPClistBitget
🔹Enter here: https://t.co/WAiPk9rv32
🔹1,000 winners will share the prize pool!