Skip to content

Cybersecurity Alert: Fake NFT Game Hacks

North Korean Lazarus Group Exploits Chrome with Fake NFT Game Scheme

  • The Lazarus Group crafted a fake NFT game, DeTankZone, exploiting a Google Chrome vulnerability to target cryptocurrency users.
  • Users who downloaded the game unknowingly installed the Manuscrypt malware, which accessed sensitive data like cookies and passwords.
  • Google patched the vulnerability identified as CVE-2024-4947, effectively neutralizing the immediate threat by May 2024.
  • DeTankZone was a facade, using stolen source code from DeFiTankLand, lacking any real game infrastructure.

One standout insight is the hackers’ use of aggressive marketing, leveraging social media and emails, to effectively deceive users into downloading the malicious software.

This incident highlights the critical need for the cryptocurrency community to prioritize cybersecurity. As cyber threats evolve, timely software updates and strong security practices are essential to protect digital assets. Tech companies play a vital role in safeguarding users against such sophisticated attacks, as demonstrated by Google’s swift patching of the vulnerability.

Share