Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
Gate MCP
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
GateRouter
Smartly choose from 30+ AI models, with 0% extra fees
I just saw a concerning report from Moonlock Lab about a ClickFix attack that involves new techniques, and it's quite clever in a bad way.
Hackers are starting to impersonate investment firms, reaching out via LinkedIn with job invitations, then guiding victims to fake Zoom or Google Meet meeting links. The fake web pages have a Cloudflare button that, when clicked, copies malicious commands to the clipboard and tricks users into pasting and running them in the terminal. This method is effective for hackers because it causes victims to run the commands themselves, bypassing natural security protections.
But there's another serious issue: the Chrome extension called QuickLens was compromised after its ownership changed earlier this month. John Tuckner from Annex Security revealed that attackers released a new version containing malicious scripts after two weeks. The extension has about 7,000 users.
What the extension can do is quite dangerous. It scans digital wallet data, recovery phrases, Gmail information, YouTube data, and login or payment information on various websites. It impersonates organizations like SolidBit, MegaBit, Lumax Capital to appear legitimate.
The extension has been removed from the store, but this serves as a good warning to be cautious about where extensions come from and to be wary of job invitations from strangers on LinkedIn.