All right, so today we got a really interesting, actually straight up like wicked scam that I almost got caught with.
And I really want to kind of bring it into play.
Uh, this, this scam company almost got me.
This scam company almost got me.
Um, there was a couple of little warning signs of putting out this out, this out there as
a notice on what to look for in a sophisticated wallet draining scam.
I did not get caught with this one.
Um, however, I thought it would be very important to like bring this out there.
I'm Brian calling enough growth and let's go over the anatomy of the Norris Capitals
camp. So I get this message. So first warning is like this community that I was a part in,
it's about three years old. And I'm like, okay, so that was like red flag number one.
And I get DMs. I get DMs all the time. It's like, I'll try to be like nice there's business that comes out of it but cool
let me see the dm no pressure that's fine uh they have a couple roles coming up with a new venture
firm this they're they're kind of paraphrasing themselves as a new venture firm bunch of roles
uh send them some information send them my calendar let's chat and then he tried to get me to fill out
this weird little Google sites
thing. And so that was like the first thing, like it's a, it's a Google site and I'm like, all right,
sites.google.com. It's not like an embedded link. I go there and thing number one is it's a 404.
All right. Other also sites.google.com is notorious for like hacking stuff. Now I looked at this form and I'm like, wait a second, that's not a Google form.
So I once first thought it was a Google form and then I was like fast track to partner.
No venture capital firm says that, right?
Like, especially on an online application form.
So that was like a little bit of a gotcha.
The stylistic approach, I remember,
Google.com is basically web domain hosting.
And I'm like, let me verify this guy.
So Norris, I looked at him.
I looked at what he's got, BD Research,
open 24-7, Norris Capital.
And then I started searching around for norris capital
quick little google got me to this page like all right this kind of looks legit they founded in
2017 50 million aum it's pretty impressive but if they were founded in 2017 here's another kind of little hint um only 202 followers okay so if they have all of these portfolio
companies right and then that they showed and then they have a different set of portfolio companies
here so i'm like all right this is this is weird this is strange um i'm a little bit you know
here's co-investors their co-investors in so their
portfolio says one thing and one thing it says another thing and another thing um you know I
know some of these guys I'm not going to call them out specifically uh I could have done a
background check there there's some weird numbers here but looks like Ty but you know whatever um
that isn't the thing that really got me so i was like all
right let me go to the team cool a bunch of asian people this is weird um but like look they could
be like a like an indonesia that could be in asia um and they got the founding partner i was like
let me do here's this mikey lee guy who's connected
there right um you know some of these other links don't work uh they did sign up for a meeting on
wednesday to meet and talk about the role and position so i was like let me check if this mikey
dude is real so let me go to this guy and so here's another indication i followed him and i
started kind of going through his posts or whatnot.
It's like, yeah, whatever.
Some other like venture capital investment bullshit.
But he followed me right back and then he sent me a chat.
So this is where it gets into the nitty gritty details.
Hey, I'm checking out verification of Mikey Lee.
And do you have any info on your fund?
What information are you checking?
Do you meet our fund pitch deck?
I'm doing verification of him.
I don't know if this is the same person or not,
but effectively it's like, okay, cool.
Let me, yeah, I'll take a look at your pitch deck
to like verify it's real.
And now here comes the anatomy of the scam.
Here's the really, really scam thing.
So Google Doc, this is a new one that I saw happen in the last month or two.
This is part is like there's a decryption access key on a Google Doc.
Great. My email's out there um here's the anatomy of the scam so somehow they're doing this like embedded side view thing right inside a google doc and like
it's not doc send it's non-standard there's an access key purpose
you can really type in anything and you can kind of like type in anything in here
right oh no you might actually have to put in the exact access key boom let's do that let's put in
the exact access key acknowledge and decrypt the document oh decrypt the document. Ooh, decrypt the document. Verifying access credentials.
Now it wants me to download something.
But the reality is, is it's not super legit.
This will drain your entire wallet.
Or terminal installation.
I'm even scared and I'm like, copy this install sh shell script and give them
access to your entire computer bro this is crazy i'm like obviously obviously a scam so just calling
this out norris capital a scam this enrico ferrero guy totally a scam um This Enrico Ferraro guy, totally a scam.
I'm going to sign up, report this.
If you get this one, help, report, spam or fraud, 100%.
Look, it's getting gnarly out there, the amount of attacks.
We just had the drift attack happen last week, the Axios supply chain attack.
Buyer beware. This is a 100 scam norris capital is not a real venture capital investing firm they probably
vie coded this site it looks like good enough right that it's like seems semi-legit and this is a fair warning out there on what the anatomy
of a sophisticated crypto scam looks like and how to avoid it uh just report him so i'm gonna report
this dude he's got a verified account um and you know there's some mixed up information i'm gonna report this guy and
see if i can get this stuff taken down report their google report to google sites
but the reason why i'm putting this out there is hopefully they get taken down
but something like that will likely pop up if you're a security researcher no maybe i'll send this out to like
some of the other security guys on on what to do or maybe they can call this out and shut these
guys down um but these are the types of things that get things like drift hacked or you know
there's there's been in the last quarter there's i think it's been like 400 million dollars worth of crypto
hacked and just one person on your team falling for this on a multi-sig and then you had a second
person on your team falling for this on a multi-sig and that's it you're done if you're like
two or five you get three things like this is it this is how the crypto hacks get done
and hundreds of millions of dollars
in the industry is lost so you know separate your computers um separate you like your normal
browsing stuff from your normal uh you know crypto uh ledger wallets etc etc but even that's not safe
if they have an installer and you attach your ledger then they can drain and sign things
the second you attach your ledger so this is just a fair warning enrico
not a good guy nor is capital not real there's no money there's no jobs and this was an anatomy
of a crypto scam please don't fall for it take fair warning and thanks for coming and taking a look at