Settings

Theme

Phishing campaign impersonates Y Combinator using GitHub issue notifications

github.com

8 points by thenickdude 4 months ago · 5 comments

Reader

southwindcg 4 months ago

Discussed (and dealt with) here: https://news.ycombinator.com/item?id=45352610

(Multiple domains are being used.)

nico 4 months ago

Yup, just got it in my email. At first I was intrigued, then I read the part where they say the application requires a refundable deposit for verification

> Next step: To confirm your preliminary registration and secure eligibility, please verify your wallet through Y Combinator. This step ensures fairness, safeguards against Sybil attacks, and does not require personal information. The process takes less than a minute: simply connect your wallet and sign a verification message.

> Important: A refundable deposit is required for authorization. The full amount will be returned once verification is complete

andy99 4 months ago

Also got this about an hour ago. I had previously applied to YC so thought it was about that, then saw

  Important:
  A refundable deposit is required for authorization. 
and realized it was a scam.
thenickdudeOP 4 months ago

At the bottom of each issue is a huge amount of whitespace, then they've stuffed it with a bunch of @'s to notify users.

https://i.imgur.com/LRotRlS.png

The link goes to a typo-squatted domain using an "l" instead of an "i".

slwvx 4 months ago

Such phishing attacks using Github seem common these days.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection