Disclaimer: Information found on CryptoreNews is those of writers quoted. It does not represent the opinions of CryptoreNews on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoreNews covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.
Friend.tech Introduces Login Management Update Following SIM-Swap Attacks
The decentralized social network Friend.tech announced an updated feature on social media that allows users to add and remove various login methods for their accounts, following reports of SIM-swap attacks.
On October 4, Friend.tech stated that the settings were now accessible via the app, with users required to tap their wallet balance to make changes.
You can now add and remove log in methods for your https://t.co/YOHabcBL3H account. To access these settings, tap your wallet balance in the top right corner of the app pic.twitter.com/d37VWVk2Eb
— friend.tech (@friendtech) October 4, 2023
The platform addressed user inquiries regarding the absence of a two-factor authentication passcode feature. Friend.tech explained that, in its current state, enabling this feature would likely cause users to lock themselves out of their accounts. The company noted it had suggested UX updates to Privy, the provider handling its privacy features.
“Privy is working diligently to implement this and we will integrate the feature when they have finished.”
During a Q&A session on October 2, some users reported that they were not prompted to confirm their passcodes and that neither Privy nor Friend.tech could reset them if mistyped.
Users have responded to the update, with many noting they were already locked out of their accounts.
Been locked out of my account for over a month. Where do I get help now that your help desk account is banned?
— Crossover (@crossover_step) October 4, 2023
One user complained that although they removed their phone number and replaced it with an alternative authentication method, existing sessions on other devices were not logged out, potentially allowing hackers to remain active.
Related: Decentralized social networks have a retention problem, say execs
These updates followed exploits on October 4, where users reported account compromises after hackers took control of their mobile numbers through SIM-swap attacks.
Reports indicate that over 100 Ether (ETH) was drained within a week as a result of these incidents.
The exploits continued into October 5, by which time the scammers had netted at least $385,000 worth of Ether.
This security activity coincided with significant revenue growth for Friend.tech, with surges totaling 10,663 ETH and its total value locked exceeding 30,000 ETH.
Magazine: Blockchain detectives: Mt. Gox collapse saw birth of Chainalysis