# How to prevent the cryptoassets being stolen
如何防止加密资产被盗走

By [SoloClover](https://paragraph.com/@1980s) · 2022-04-23

---

1/ Based on our research and conversation with leading cyber security experts, we believe BlueNorOff are running an organized campaign to target all the prominent organizations in the crypto space.

1/ 根据我们与领先网络安全专家的研究和对话，我们认为 BlueNorOff 正在开展有组织的活动，以针对加密领域的所有知名组织。

2/ Given how sophisticated their social engineering attack is, I believe that they already have the relationship graph of the entire crypto space mapped out and know what kind of phishing emails are most likely to slip through our mental defense.

2/ 考虑到他们的社交工程攻击有多精密，我相信他们已经绘制了整个加密空间的关系图，并且知道哪种网络钓鱼电子邮件最有可能穿过我们的心理防御。

3/ I highly recommend reading this article to further understand how this attack is being carried out and implement the recommended suggestions. Below is the example of phishing email they sent: [https://www.kaspersky.com/about/press-releases/2022\_snatch-that-crypto-bluenoroff-threat-actor-drains-cryptocurrency-startups-accounts](https://www.kaspersky.com/about/press-releases/2022_snatch-that-crypto-bluenoroff-threat-actor-drains-cryptocurrency-startups-accounts)

3/ 我强烈建议阅读这篇文章，以深入了解这种攻击是如何进行的并实施推荐的建议。以下是他们发送的网络钓鱼电子邮件示例： [https://www.kaspersky.com/about/press-releases/2022\_snatch-that-crypto-bluenoroff-threat-actor-drains-cryptocurrency-startups-accounts](https://www.kaspersky.com/about/press-releases/2022_snatch-that-crypto-bluenoroff-threat-actor-drains-cryptocurrency-startups-accounts)

4/ It is critical that this industry is highly aware that we are being actively targeted by a state-sponsored cyber crime organization that is extremely resourceful and sophisticated. They might even change the tools and attack pattern in future.

4/ 至关重要的是，这个行业高度意识到我们正成为一个国家资助的网络犯罪组织的积极目标，该组织非常机智和老练。他们甚至可能在未来改变工具和攻击模式。

5/ Once the current attack method gets less effective, such as a trojanized DeFi App and Wallet attack discovered lately. Given the success, it is likely North Korea will dedicate more resources to this group to scale up the intensity of the attack. [https://securelist.com/lazarus-trojanized-defi-app/106195/](https://securelist.com/lazarus-trojanized-defi-app/106195/)

5/ 一旦当前的攻击方法变得不那么有效，例如最近发现的木马化 DeFi App 和 Wallet 攻击。为了攻击成功，朝鲜很可能会为该组织投入更多资源，以扩大袭击的强度。 [https://securelist.com/lazarus-trojanized-defi-app/106195/](https://securelist.com/lazarus-trojanized-defi-app/106195/)

6/ All standard cyber security suggestions aside, below are some of the non-exhaustive crypto specific security suggestions I have produced with assistance of my cyber security minded friend @junhaotan\_, I hope this will prevent similar incidents from happening to any of us.

6/ 除了所有标准的网络安全建议，以下是在我的具有网络安全思维的朋友帮助下提出的一些非详尽的特定加密安全建议@junhaotan\_, 我希望这将防止类似的事件发生在我们任何人身上。

7/ Storing on-chain cryptoassets on enterprise grade custody solution: An EOA secured by one hardware wallet is insufficient as they can insert a false Metamask browser extension leading to approval of unintended transactions.

7/ 在企业级托管解决方案上存储链上加密资产：由一个硬件钱包保护的 EOA 是不够的，因为它们可以添加错误的 Metamask 浏览器扩展，从而导致非预期交易的批准。

8/ At the very least it should be a multi-signature wallet like Gnosis Safe secured by a few hardware wallets. I highly recommend going for the next level of custody solution like Fireblocks, Copper, Qredo etc. As they come with native multisig 2FA for transaction approval.

8/ 至少它应该是一个多重签名钱包，例如由几个硬件钱包保护的 Gnosis Safe。我强烈建议使用 Fireblocks、Copper、Qredo 等更高级别的托管解决方案。因为它们带有用于交易批准的原生2FA多重签名。

9/ Exercise extra due diligence in hiring remote teams especially software engineers/developers: “The Lazarus APT group has even engaged in the creation of fake companies for the development of cryptocurrency software."

9/ 在聘用远程团队，尤其是软件工程师/开发人员时，要进行额外的尽职调查：“Lazarus APT 集团甚至参与创建虚假公司来开发加密货币软件。”

10/ We have heard of this case from one of our portfolio companies where applicants for their software engineer role appear to be suspicious in interview, and unable to match up with their profile in their resume.

10/ 我们从我们的一家投资组合公司那里听说过这个案例，那里的软件工程师职位的申请人在面试中似乎很可疑，并且无法与他们在简历中的个人资料相匹配。

11/ Dedicated computers for crypto transactions. There should be dedicated computers only for engaging in crypto transactions that do not interact with any emails, internet link, messaging apps, opening MS words documents, PDF etc.

11/ 专用于加密交易的计算机。应该有专门的计算机只用于进行不与任何电子邮件、互联网链接、消息应用程序、打开 MS Word 文档、PDF 等交互的加密交易。

12/ Implement 2FA for all sign-in: This is non-crypto specific but is important enough to warrant a mention. Cloud storage, Emails, Messaging apps like Telegram should all have 2FA for logins, do not use SMS 2FA and use Google authenticator instead,

12/ 所有登录执行2FA：这确切地来说不是加密措施，但其重要性足以值得一提。云存储、电子邮件、Telegram 等消息应用程序都应该有 2FA 用于登录，不要使用 SMS 2FA 而是使用 Google 身份验证器，

13/ whenever possible a hardware 2FA like YubiKey should be used. Apply to both company and personal accounts.

13/ 应尽可能使用像 YubiKey 这样的硬件 2FA。适用于公司和个人帐户。

14/ Bookmark your commonly used crypto DApp website. From time to time, phishing websites are being served out by search engine apps. If not careful during the search, you may end up accessing a phishing site. It will be better to access them through your bookmark list.

14/ 将您常用的加密应用网站加入书签。钓鱼网站会不时被搜索引擎应用程序引用。如果在搜索过程中不细心，您最终可能会访问钓鱼网站。最好通过您的书签列表访问它们。

15/ Revoke unnecessary token approval. Token approvals allow another party to move your assets. It is required to interact with most smart contracts. Avoid unlimited token approvals and revoke unnecessary approval routinely. You can use [https://revoke.cash](https://revoke.cash) to do that. [https://revoke.cash/](https://revoke.cash/)

15/ 撤销不必要的通证批准。通证批准允许另一方移动您的资产。它需要与大多数智能合约进行交互。避免无限制的通证批准并定期撤销不必要的批准。您可以使用[https://revoke.cash来做到这一点。](https://revoke.cash%E6%9D%A5%E5%81%9A%E5%88%B0%E8%BF%99%E4%B8%80%E7%82%B9%E3%80%82) [https://revoke.cash/](https://revoke.cash/)

16/ Implement an address monitoring system: Internal crypto wallet addresses should be monitored closely so that when unauthorized transactions happen, the team can be made aware immediately and take action as soon as possible. Both Etherscan and Nansen have such solutions.

16/ 实施地址监控系统：应密切监控内部加密钱包地址，以便当未经授权的交易发生时，团队可以立刻意识到并尽快采取行动。Etherscan 和 Nansen 都有这样的解决方案。

17/ Regular cyber security training for team members: All team members should be required to go through cyber security training for their on-boarding, this is something that tends to be neglected as the organization grows.

17/ 定期对团队成员进行网络安全培训：应要求所有团队成员在入职时接受网络安全培训，随着组织的发展，这件事往往会被忽视。

18/ Improve phishing and spam email detection by properly configuring your DNS setting for your email. Use hard fail or strict mode where possible for SPF, DKIM and DMARC

18/ 通过正确配置电子邮件的 DNS 设置来改进网络钓鱼和垃圾邮件检测。尽可能为 SPF、DKIM 和 DMARC 使用硬故障或严格模式

19/ Trust the browser and not the website. Any content below the browser bar should be deemed insecure and can be a potential attack vector. Some DApp may pop up a window to ask you to login into your crypto extension wallet if you are not logged in. Do not type your password in.

19/相信浏览器而不是网站。浏览器栏下方的任何内容都应视为不安全，并且可能是潜在的攻击媒介。如果您未登录，某些 DApp 可能会弹出一个窗口要求您登录您的加密扩展钱包，这种情况下不要输入您的密码。

原文来自：[https://twitter.com/arthur\_0x/status/1514890456596840449?s=21&t=CXoRsN6fzkjw0spdwWD5CA](https://twitter.com/arthur_0x/status/1514890456596840449?s=21&t=CXoRsN6fzkjw0spdwWD5CA)

本文译者：SoloClover

本人推特：[https://twitter.com/ZhiyuanQi](https://twitter.com/ZhiyuanQi)

discord: Music760#8308

打赏地址：0xa4454ADE45Cb368A8941191Af9Ecb55374f4FF0e

---

*Originally published on [SoloClover](https://paragraph.com/@1980s/how-to-prevent-the-cryptoassets-being-stolen)*
