Yearn Finance doppelganger scam tries to trick visitors out of their keys

Published at: Oct. 22, 2020

Decentralized finance yield farming platform Yearn Finance has a doppelganger that is tricking visitors into sharing the private keys of their cryptocurrency wallets.

The scam website of Yearn Finance perfectly copies almost every aspect of the original yearn.finance website down to its design, website copy and even domain name. The scammers behind the website chose the domain name “yaerm.finance,” making it look extremely similar to “yearn.finace.” 

They have also promoted their landing page for the search keyword “yearn finance” so it shows up on top of the search results when people search for the actual real website.

Once a user clicks the ad, it directs them to the yaerm.finance page that looks exactly like Yearn Finance’s official website. However, after scrolling down from the first window that appears, one finds that the website contains a strange guide to "seven easy hairstyles."

Similar to the original website, the scam website also has six different options in the first window. These include Dashboard, Vaults, Earn, Zap, Cover and Stats.

Irrespective of what option a user clicks, it directs them to a page that prompts users to connect their wallets.

When users try to connect their wallets, the scam site presents a list of crypto wallets they may choose from. Then, it shows a pop up that asks the users to share the private key or passphrase.

Doppelganger scams are relatively common in the crypto space. Another website is posing as Trust Wallet to cheat crypto users. 

Crypto India wrote on Twitter that scammers have been sending Binance Coin (BNB) dust — a very small fraction of a cryptocurrency that cannot be exchanged or transacted — to random cryptocurrency wallets. Each of these transactions had a memo that notified users that they had won 30 or 50 BNB tokens and contained an external link to “claim” those tokens.

The Trust Wallet-like website has a call-to-action button that reads “Claim Prize” and upon clicking, opens a window that requests the users to enter their private keys.

Users who are new to crypto and are not aware of the importance of keeping their private keys “private” may easily fall for these scams and give the scammers easy access to their funds.

Tags
Related Posts
Coin Bureau Youtube channel hacked despite 2FA protection
Coin Bureau, a popular information portal for cryptocurrency developments with over 600,000 followers on Twitter, experienced a security breach on its Youtube channel on Monday. Hackers allegedly uploaded a video with links to scam fiat/cryptocurrency addresses soliciting a token sale before being taken down by Youtube. According to Coin Bureau staff, they were baffled by the incident as its accounts were "secured with ultra-strong passwords and Google security keys." So our YouTube channel was just hacked. Have absolutely no idea how this happened. All accounts are secured with ultra strong passwords and Google security keys. @YouTubeCreators this is a serious …
Technology / Jan. 24, 2022
HEX Still Can't Shake Scam Label as Token Approaches $1B Market Cap
While widely written off as a scam earlier this year, Richard Heart’s controversial HEX is fast approaching a $1 billion market cap. According to crypto analytics site CoinMarketCap, the HEX token had a market cap of over $979 million on May 14 with a value of $0.006 at the time of writing. Prior to mid-February, the value of the coin was so small, many sites simply couldn’t measure it. HEX is an ERC-20 token that pays holders for rewards instead of miners, essentially a crypto version of a traditional fixed deposit account. Users can lock up funds, then receive their …
Technology / May 15, 2020
Crypto Scammers Turn Toward Terrorism With a Japanese Bomb Threat
Crypto terrorists threatened to bomb a government office on the Japanese island of Hokkaido. They told authorities that they would only disable the alleged explosive device if their crypto ransom was paid. According to FNN, the terrorists sent the Numata Town Hall an email stating they had installed a bomb in a women’s second-floor toilet. They claimed that as long as officials met their payment demands before 03:00 UTC on June 29, the bomb would not be detonated. However, this appears to have been a fake threat. The deadline set by the criminals has passed and the hall remains intact …
Bitcoin / July 29, 2020
Indian Authorities Arrest 4 Individuals Accused of Crypto Ponzi Scheme
The Criminal Investigation Department (CID) of India has arrested Vijay Prajapati, Dhiraj Patel, Kamruddin Syed, and Ashiq Shaikh, the alleged creators of the cryptocurrency KBC Coin, according to a report by The Times of India on July 4. As per the report, the CID argues that KBC is a Ponzi Scheme. KBC reportedly launched 6 months ago, and its price has not moved since. KBC coins were reportedly issued at 10 paisas apiece, with the promise that they would skyrocket in value to 10 rupees in a short time ⁠— a 100-fold return on investment. According to a CID member, …
Cryptocurrencies / July 5, 2019
US SEC Issues Fresh Investor Alert Against Fraudulent Digital Asset Trading Sites
The United States Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) have jointly issued an alert warning investors against fraudulent websites purporting to operate advisory and trading businesses. The alert, issued by the SEC’s Office of Investor Education and Advocacy and the CFTC’s Office of Customer Education and Outreach, was published on April 24. The warning states that staff from both agencies have recently observed crypto-related investment scams where bad actors are touting “digital asset or ‘cryptocurrency’ advisory and trading businesses,” in some cases claiming they can invest clients’ funds in special crypto trading systems or …
United States / April 25, 2019