Algorand DeFi platform GARD criticized for advertising using "dusting attacks". Anonymous user strikes back tricking users with a harmless phishing demo
<table> <tr><td> <a href="https://www.reddit.com/r/CryptoCurrency/comments/y2721m/algorand_defi_platform_gard_criticized_for/"> <img src="https://b.thumbs.redditmedia.com/PfhCodqYM4-K-UdhjnVfza2qbbxj1qmJlkpPmv9sbYY.jpg" alt="Algorand DeFi platform GARD criticized for advertising using &quot;dusting attacks&quot;. Anonymous user strikes back tricking users with a harmless phishing demo" title="Algorand DeFi platform GARD criticized for advertising using &quot;dusting attacks&quot;. Anonymous user strikes back tricking users with a harmless phishing demo" /> </a> </td><td> <!-- SC_OFF --><div class="md"><p>I thought this was a good demonstration of why this was a problematic way to advertise and how many users still are unaware of many possible scams out there.</p> <p>&#x200B;</p> <p>As someone who participated in algorand governance my wallet has received some tiny random transactions over the past two days with spammy looking messages. This is commonly referred to as a &quot;dusting attack&quot; where attackers will send miniscule amounts of crypto with the hope that you will either interact with some sketchy contract or read some note from them and follow a shady link.</p> <p>The first txn I received contains a note advertising some staking app called GARD</p> <p>&#x200B;</p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/srd2ivqj7et91.jpg?width=622&amp;format=pjpg&amp;auto=webp&amp;s=3f27d6bc10ad7dc5102339e6cf9e3b3efa90cc49">https://preview.redd.it/srd2ivqj7et91.jpg?width=622&amp;format=pjpg&amp;auto=webp&amp;s=3f27d6bc10ad7dc5102339e6cf9e3b3efa90cc49</a></p> <p>Sadly this was confirmed to be a legitimate advertisement for the project. I thought this was a scam at first though and ignored it.</p> <p>&#x200B;</p> <p>However, then I received another</p> <p>&#x200B;</p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/tdfvlvzu7et91.jpg?width=578&amp;format=pjpg&amp;auto=webp&amp;s=17b45fc3703fabf70909c35229ac5f6d3c520d9a">https://preview.redd.it/tdfvlvzu7et91.jpg?width=578&amp;format=pjpg&amp;auto=webp&amp;s=17b45fc3703fabf70909c35229ac5f6d3c520d9a</a></p> <p>Wow no phishing! And 78% APR! How legit! Now at this point there has been some pushback, at least from what I read here on Reddit. Then, everyone receives another transaction, seemingly from GARD apologizing:</p> <p>&#x200B;</p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/31avrum18et91.jpg?width=504&amp;format=pjpg&amp;auto=webp&amp;s=7dba94e5c8a07a43d196b4a84e876be925f8cca1">https://preview.redd.it/31avrum18et91.jpg?width=504&amp;format=pjpg&amp;auto=webp&amp;s=7dba94e5c8a07a43d196b4a84e876be925f8cca1</a></p> <p>&#x200B;</p> <p>Hmm. Good on them I think, maybe it was just some new marketing guy that didn&#39;t know what they were doing. Let&#39;s check out that thread: <a href="https://twitter.com/algo_gard/status/1580000082568818689?s=20&amp;t=P67XlEDa10Zt8v3EssvYyQ">https://twitter.com/algo_gard/status/1580000082568818689?s=20&amp;t=P67XlEDa10Zt8v3EssvYyQ</a></p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/4hfrpflc8et91.jpg?width=589&amp;format=pjpg&amp;auto=webp&amp;s=700834caade6ab06fde3445c8cf0b593647a3398">https://preview.redd.it/4hfrpflc8et91.jpg?width=589&amp;format=pjpg&amp;auto=webp&amp;s=700834caade6ab06fde3445c8cf0b593647a3398</a></p> <p>&#x200B;</p> <p>Seems legit right?</p> <p>&#x200B;</p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/cbsr7fnd8et91.jpg?width=591&amp;format=pjpg&amp;auto=webp&amp;s=1a98db5281b09b1e89593aa93e0f3fafc2bd9594">https://preview.redd.it/cbsr7fnd8et91.jpg?width=591&amp;format=pjpg&amp;auto=webp&amp;s=1a98db5281b09b1e89593aa93e0f3fafc2bd9594</a></p> <p>&#x200B;</p> <p>Nope! And you can see people in the replies praising GARD for the apology! IMO an excellent demonstration of how these attacks work, how they can be dangerous, and why it should be avoided by legitimate projects. One of the best parts I think is that the anonymous transaction actually came from a wallet address whose public key starts with &quot;GARD&quot; making it look even more legit than the real GARD ads!</p> <p>&#x200B;</p> <p>Personally because of this I will never touch GARD. And I recommend you assume any message like this you receive in a txn is a scam.</p> </div><!-- SC_ON --> &#32; submitted by &#32; <a href="https://www.reddit.com/user/lazystylediffuse"> /u/lazystylediffuse </a> <br/> <span><a href="https://www.reddit.com/r/CryptoCurrency/comments/y2721m/algorand_defi_platform_gard_criticized_for/">[link]</a></span> &#32; <span><a href="https://www.reddit.com/r/CryptoCurrency/comments/y2721m/algorand_defi_platform_gard_criticized_for/">[comments]</a></span> </td></tr></table>