Pages:
Author

Topic: Bitsler casino phishing attack underway (Read 282 times)

sr. member
Activity: 1848
Merit: 373
<------
January 10, 2025, 05:00:06 PM
#23
No you did not lock. :p
sr. member
Activity: 1491
Merit: 320
🐪
January 10, 2025, 04:56:44 PM
#22

Indeed, we changed some settings with our email provider so players using our mirror domains to log in (like bitsler.gg) can still click our emails, but this leads to the issue you described. We made some adjustments, and you should now see only bitsler.com links (or whatever mirror you’re using) on transactional email CTAs.

Hello Gabriel. This is great if e-mail shows links of just main domain and not mirror domains. But if, for the reason you described, you must use mirror domain I suggest that you make note in e-mail that explains that the links are from mirror domain. Highlighting this will not come across like someone is trying to hide a phishing link in e-mail. Also it would be good idea to make domains of mirror links on main domain(bitsler.com), and and reference to this list in e-mail, just making a note that you are sending links from mirror domain and users can check that everything is legit on main bitsler domain.


Obviously, if you have any doubts you can always log in to Bitsler on your side without clicking that link in the email. Would it sound safer if we wrote that option in the email?
This would definitely sound safer, and it would also promote good practice of avoiding of link clicking to your users.



The amount of your balance was correct. When your account becomes dormant, all your balances are converted into USDT.

Sorry this was my mistake, I read the mail too quick and understood it wrong.


That said, I agree it makes no sense to mention so many decimals for USDT (old crypto habits :sweat_smile:). We will fix that asap.
Also, as others have mentioned, it’s kind of dumb to mention that more fees will be charged next month if the balance is already empty. As a quick fix, we will mention, “and if you still have balance.” Then, when time permits, we’ll try to make the mailing process more dynamic based on account balances, so we send those emails only if the balance is not empty yet.
These are good improvements, the message would be sent just to those who have balance, so it would be less space for misunderstanding.


I hope this helps answer your worries. If you guys have any other (doable:stuck_out_tongue:) suggestions, we’ll be happy to review them, but preferably in a more constructive section than the scam one.
Best,
Gabriel

Thanks for your clarifications and feedback, I will now lock the topic.
sr. member
Activity: 1848
Merit: 373
<------
January 09, 2025, 09:04:36 AM
#21
Hi ovcijisir,
Again, there is no problem with false alarms. However, I agree that the email template is a bit sloppy, and I’m happy to get feedback to improve it.
Indeed, we changed some settings with our email provider so players using our mirror domains to log in (like bitsler.gg) can still click our emails, but this leads to the issue you described. We made some adjustments, and you should now see only bitsler.com links (or whatever mirror you’re using) on transactional email CTAs.
About the urgency, if you received this email, it means you also received the 1st one 1 month ago, explaining that after 6months of inactivity, your account was now considered dormant. Then, after that, you will receive 1 email every month (like this one) until your account gets closed. We will give more context so it makes more sense to players who did not get/read the first email. Obviously, if you have any doubts you can always log in to Bitsler on your side without clicking that link in the email. Would it sound safer if we wrote that option in the email?
The amount of your balance was correct. When your account becomes dormant, all your balances are converted into USDT. That said, I agree it makes no sense to mention so many decimals for USDT (old crypto habits :sweat_smile:). We will fix that asap.
Also, as others have mentioned, it’s kind of dumb to mention that more fees will be charged next month if the balance is already empty. As a quick fix, we will mention, “and if you still have balance.” Then, when time permits, we’ll try to make the mailing process more dynamic based on account balances, so we send those emails only if the balance is not empty yet.
I hope this helps answer your worries. If you guys have any other (doable:stuck_out_tongue:) suggestions, we’ll be happy to review them, but preferably in a more constructive section than the scam one.
Best,
Gabriel

1st, welcome back boss Gabriel.

Yeah this if already resolved should either be closed or moved to, scam-accusation (not guilty section).

To Theymos, maybe thats a good suggestion.
hero member
Activity: 984
Merit: 503
January 08, 2025, 10:09:20 AM
#20
Hi ovcijisir,
Again, there is no problem with false alarms. However, I agree that the email template is a bit sloppy, and I’m happy to get feedback to improve it.
Indeed, we changed some settings with our email provider so players using our mirror domains to log in (like bitsler.gg) can still click our emails, but this leads to the issue you described. We made some adjustments, and you should now see only bitsler.com links (or whatever mirror you’re using) on transactional email CTAs.
About the urgency, if you received this email, it means you also received the 1st one 1 month ago, explaining that after 6months of inactivity, your account was now considered dormant. Then, after that, you will receive 1 email every month (like this one) until your account gets closed. We will give more context so it makes more sense to players who did not get/read the first email. Obviously, if you have any doubts you can always log in to Bitsler on your side without clicking that link in the email. Would it sound safer if we wrote that option in the email?
The amount of your balance was correct. When your account becomes dormant, all your balances are converted into USDT. That said, I agree it makes no sense to mention so many decimals for USDT (old crypto habits :sweat_smile:). We will fix that asap.
Also, as others have mentioned, it’s kind of dumb to mention that more fees will be charged next month if the balance is already empty. As a quick fix, we will mention, “and if you still have balance.” Then, when time permits, we’ll try to make the mailing process more dynamic based on account balances, so we send those emails only if the balance is not empty yet.
I hope this helps answer your worries. If you guys have any other (doable:stuck_out_tongue:) suggestions, we’ll be happy to review them, but preferably in a more constructive section than the scam one.
Best,
Gabriel
sr. member
Activity: 1491
Merit: 320
🐪
January 06, 2025, 04:57:05 PM
#19
Hi,
Thank you for contacting us and trying to protect the community.
However, in this case, those emails are legit automated emails from Bitsler.
Our email provider uses our online domain to track clicks on the emails and redirect to the original domain we used on the backend (either bitsler.com or any of our mirror domains like bitsler.gg)
If we use a bitsler.com subdomain (like we did for some time), players using bitsler.gg would be unable to register or click the links from our emails.

Hello BitSler support, thank you for the feedback and sorry about raising false alarm, but your e-mail triggered too many red flags:

  • url of link did not match website url
  • e-mail demanded urgent action to avoid losing funds
  • btc balance was not matching

I would thank you for clarifying the situation, it would be great if there would be some action to avoid false alarms like this in future, because crypto community must be extra cautious because tiny mistake like clicking wrong link could cost us our funds and mismatch between legit domain and link in e-mail is big red flag.
hero member
Activity: 984
Merit: 503
January 06, 2025, 12:17:41 PM
#18
Hi,
Thank you for contacting us and trying to protect the community.
However, in this case, those emails are legit automated emails from Bitsler.
Our email provider uses our online domain to track clicks on the emails and redirect to the original domain we used on the backend (either bitsler.com or any of our mirror domains like bitsler.gg)
If we use a bitsler.com subdomain (like we did for some time), players using bitsler.gg would be unable to register or click the links from our emails.
legendary
Activity: 2534
Merit: 1713
Top Crypto Casino
December 15, 2024, 06:30:24 PM
#17
Was it ever ascertained where the scammers obtain the email addresses from?

If someone had funds on Bitsler and found this email  while being inactive on this gambling for a while, he would be affected by the panic. With Spear Phishing from the official email, the casino player may feel that the message is from a trusted source and rush to log in to his account through the phishing link.

Attention and caution are two important factors when dealing with these emails, whether the messages are related to a casino, exchange, or any other financial company. Any platform could be vulnerable to a breach of user data or other methods through which scammers could target the affected casino players. I will now report the phishing domain that ends with .info.


legendary
Activity: 3850
Merit: 4674
Contact @yahoo62278 on telegram for marketing
December 14, 2024, 09:47:09 PM
#16
I stopped using bitsler more than a year ago. I think I received the same time but I can't remember the details also, I have not checked the URL as I had stopped using the site. And I had just deleted the message and as the message was more than a month ago the trash has also gone.
Same for me as far as I stopped using Bitsler more than a year ago. I do have the phishing email but I'm not dumb enough to click nor did I care to login and check anything.

I hope Bitsler didn't get breached somehow or sell any info. I always got the feeling they were pretty good as far as security on the site went.
copper member
Activity: 2422
Merit: 1313
Playbet.io - Crypto Casino and Sportsbook
December 14, 2024, 06:39:19 PM
#15
I stopped using bitsler more than a year ago. I think I received the same time but I can't remember the details also, I have not checked the URL as I had stopped using the site. And I had just deleted the message and as the message was more than a month ago the trash has also gone.
legendary
Activity: 1932
Merit: 1549
December 13, 2024, 05:15:45 PM
#14
If someone had funds on Bitsler and found this email  while being inactive on this gambling for a while, he would be affected by the panic. With Spear Phishing from the official email, the casino player may feel that the message is from a trusted source and rush to log in to his account through the phishing link.

Attention and caution are two important factors when dealing with these emails, whether the messages are related to a casino, exchange, or any other financial company. Any platform could be vulnerable to a breach of user data or other methods through which scammers could target the affected casino players. I will now report the phishing domain that ends with .info.

legendary
Activity: 2730
Merit: 7065
December 13, 2024, 04:52:43 AM
#13
Not a bad attempt, considering that there is such a thing as dormant account fee where casinos and centralized services charge your account a fee if you haven't used it for a long time. But it's usually much longer than 30 days. 12 months is more likely. I have also had dummy accounts at online casinos deleted for never using them and only creating them to check certain data for the threads I have on Bitcointalk.

The scammers were a bit too hasty with their message and contradict themselves.
They state that your balance will expire soon, but also that your balance is 0. Not only that, but they warn you that they will charge another dormant account fee next month (from an account with a 0 balance). Roll Eyes I have never heard or seen a casino account with a negative balance.

Other than that, I believe this could trick careless players and beginners.
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
December 12, 2024, 05:10:38 AM
#12
That's why it's important to always scam the URLs you are going to before you use them. VirusTotal helps a lot here, but I am not sure if it can consistently detect phishing pages, as opposed to malware which it finds really well.
legendary
Activity: 2534
Merit: 1713
Top Crypto Casino
December 12, 2024, 04:00:57 AM
#11
Your thread is a very important warning and message for those that do use Bitsler. If they click the links and enter their details they are going to make huge problems for themselves.

Not specifically related to this email but in the general sense, sometimes the scammers work very hard to try to fool potential victims and the attempts are both elaborate and sophisticated. People have to always be aware of possible phishing before they click any links no matter how genuine any emails might appear to be.

It seems that today was launched phishing attack that targets Bitsler casino users.
legendary
Activity: 2212
Merit: 7064
December 10, 2024, 03:57:33 PM
#10
This looks like a typical phishing attack but it is a bit strange if they actually used real Bitsler email account.
It's more likely coming from similar domain or scammers used punycodes for that, but I would always check destination link before clicking on it.
Every time we register on some website we are increasing chances of our email and personal information being leaked, so be careful everyone.
hero member
Activity: 2716
Merit: 904
December 10, 2024, 09:31:56 AM
#9
How do they get your email? I’m just curious because if they have your email, and you only use it for your Bitsler account, then it’s possible that it was leaked from Bitsler. I’ve received some phishing attempts as well, but mine were from an exchange, Coinbase. I wasn’t too surprised, though, since I use that email for various online activities.

I do not remember that I used that username anywhere else, so there is high probability of user database leak.

Also, note that link to bitsler.info is exact scam copy of bitsler.com

Actually, I just checked my email to see if I had a similar message like the one you posted, and surprisingly, there was one - it was an old message from 2023. So, these scammers have been doing this for quite some time. Luckily, I didn’t have any balance in my Bitsler account back then, so I just ignored it.

Anyway, thanks for sharing! It’s a good warning for those who have accounts to be cautious and not fall for these scammers.
sr. member
Activity: 1491
Merit: 320
🐪
December 10, 2024, 08:50:44 AM
#8
The username in e-mail is the same I have on my Bitsler account. It is good idea to check spam folder too, e-mail could be there.
Checked all, and nothing suspicious for now.
If the campaign has just started, scammers may be working in batches, maybe in time other Bitsler users will receive similar emails.

Please keep us informed if you receive anything, so we know if the scam is still going.

How do they get your email? I’m just curious because if they have your email, and you only use it for your Bitsler account, then it’s possible that it was leaked from Bitsler. I’ve received some phishing attempts as well, but mine were from an exchange, Coinbase. I wasn’t too surprised, though, since I use that email for various online activities.

I do not remember that I used that username anywhere else, so there is high probability of user database leak.

Also, note that link to bitsler.info is exact scam copy of bitsler.com
legendary
Activity: 2898
Merit: 1253
So anyway, I applied as a merit source :)
December 10, 2024, 08:50:00 AM
#7
How do they get your email?
You have to assume that the people who buy these email address lists in bulk try to correlate emails used on crypto related sites like for example coinbase to casinos that use crypto like bitsler. It is how scammers usually approach and if you are trying this in real life at least 10-20% will be correctly corelated.

Hence they send these scam emails in mass and those few people if they are frightened they will fall for the trap. The only way to prevent this is to learn how this scam works and delete those emails as soon as you get them.
hero member
Activity: 2716
Merit: 904
December 10, 2024, 08:09:29 AM
#6
How do they get your email? I’m just curious because if they have your email, and you only use it for your Bitsler account, then it’s possible that it was leaked from Bitsler. I’ve received some phishing attempts as well, but mine were from an exchange, Coinbase. I wasn’t too surprised, though, since I use that email for various online activities.
legendary
Activity: 3542
Merit: 3625
Crypto Swap Exchange
December 10, 2024, 07:28:36 AM
#5
The username in e-mail is the same I have on my Bitsler account. It is good idea to check spam folder too, e-mail could be there.
Checked all, and nothing suspicious for now.
If the campaign has just started, scammers may be working in batches, maybe in time other Bitsler users will receive similar emails.
sr. member
Activity: 1491
Merit: 320
🐪
December 10, 2024, 07:11:48 AM
#4
nice catch!

have you informed Bitsler about it? it might be a good a Idea to do that so they can send caution to the gambling site's users about the Phishing attack targeting their gamblers.

I have not yet informed Bitsler, but thank you for reminder.


Edit. Bitsler support informed
https://bitcointalksearch.org/topic/m.64831827


It seems that today was launched phishing attack that targets Bitsler casino users.

I recieved e-mail from scammers that looked like it was sent from bitsler.com casino.
I did not receive anything similar to the email address I used when registering on Bitsler. It seems that not all users are affected, so either someone reached a partial number of users or this is coming from something else.
Is the username that you use on Bitsler specified in the critical email or is it random?

The username in e-mail is the same I have on my Bitsler account. It is good idea to check spam folder too, e-mail could be there.
Pages:
Jump to: