GoPlus Security is building Web3's first decentralized security layer, providing comprehensive protection across all blockchain networks. Through its open, permissionless, and user-driven architecture, GoPlus can be seamlessly integrated by any blockchain or project to protect their users throughout their entire transaction lifecycle. By leveraging AVS and cutting-edge AI powered security solutions, it conducts thorough risk analysis and delivers smart, efficient and decentralized security services for users. GoPlus aims to create a more secure and user-friendly Web3 on-chain interaction environment by filling the gap of security layer in the current blockchain's architecture, providing users with more effective and better-experienced on-chain security protection.
GoPlus Security reported that a user fell victim to a typical address poisoning attack: the user mistakenly sent 100,000 DAI to a spoofed address after copying a visually similar address from their transaction history. In this incident, the user had previously sent 300,000 DAI to the legitimate target address; the attacker then sent 0.0003 DAI to the user from a malicious address with characters nearly identical to the legitimate one—before and after the address—thereby tricking the user into selecting the wrong address during their subsequent transfer. GoPlus Security advises users not to copy wallet addresses from transaction history, always verify the full address before sending funds, and conduct a small test transaction prior to any large transfer.
According to disclosures from the GoPlus Chinese community, a user lost approximately $316,000 worth of USDC after signing a malicious Permit2 transaction, which allowed attackers to drain funds from their wallet. GoPlus recommends users follow the “Four Don’ts” anti-phishing principles: don’t click on suspicious links; don’t install software from untrusted sources; don’t sign transactions with unclear or unverified content; and don’t send funds to unverified addresses. GoPlus also recommends installing the GoPlus security plugin to intercept phishing risks in real time.