What is ice phishing? Here is what Microsoft has to say about it:
” ‘ice phishing’… …doesn’t involve stealing one’s private keys. Rather, it entails tricking a user into signing a transaction that delegates approval of the user’s tokens to the attacker. This is a common type of transaction that enables interactions with DeFi [decentralized finance] smart contracts…”
This is yet another example of a social engineering attack to deceive the user, in may cases needing only a little technical knowledge on the side of the hacker. It also shows that the blockchain is not the “all-in-one” security enhancement we have been looking for – the blockchain may be secure but when interface developers, users and hackers start to interact with it, then the holes appear.
However the team at Microsoft has developed some detection methods for this type of attack.
‘Ice phishing’ on the blockchain – Microsoft Security Blog
Microsoft offers defense against ‘ice phishing’ • The Register
Clive Catton MSc (Cyber Security) – by-line and other articles