MetaMask is a software wallet (one of the most famous and widely used) that works as an extension to the Internet browser. The MetaMask wallet allows users to use the Ethereum cryptocurrency and native ERC - 20 tokens, which also serve as an interface for currently popular NFT tokens. Crypto-wallets are a frequent target of phishing attacks, with sources reporting that up to 5 million such attacks are detected worldwide annually. Jurisprudence is very strict when it comes to judging such hacker attacks. In this article, however, I will focus on one case of a phishing attack dealt with by the Czech courts recently.
Each user of the software crypto-wallet logs into it using the created passwords, which is The seed phrase associated with this wallet, in the case of the MetaMask crypto-wallet, this is a twelve-word phrase. If a MetaMask crypto-wallet user loses the Seed phrase (forgets it), they will lose access to their crypto-wallet forever, and therefore to the contents stored in this wallet.
Phishing attack
Phishing (or "fishing" whether "grooving") or phishing attack is a fraudulent technique of obtaining security passwords, sensitive user data and codes from Internet users or mobile network operators․[1] In the case of cryptocurrency wallets, the attacker often pushes the victim a fake program or link that looks like a cryptocurrency wallet interface, for example.
The legal doctrine states that a traditionally carried out phishing attack, when the user voluntarily enters his data into a "planted" program, must be considered from a criminal law point of view as fraudulent conduct according to the provisions of § 209 Act No. 40/2009 Coll., Criminal Code. From the point of view of private law, as a result of a phishing attack, in my opinion, we would apply it most often the right to extradite the thing (issuance of stolen MetaMask wallet link), possibly claim for damages, if the contents of the MetaMask wallet could no longer be restored to their previous state.
Judgment of the Regional Court in Prague dated 30 April 4, file no. stamp 2024 Co 22/45
In the case under consideration, the plaintiff sued the defendant issue of six pieces of NFT tokens defined on the OpenSea electronic platform. The facts were that the plaintiff had the subject NFT tokens stolen from his MetaMask wallet in a phishing attack where a hacker impersonated the director and founder of an unnamed virtual world, which is anonymized in the judgment.
Actual status
The hacker offered the plaintiff help with his token mapping issues in the form of virtual plots. He then sent the claimant a phishing link and explained that the first step in the entire token mapping process was for him to log into his MetaMask wallet using that link in order to preview and activate all of its features. Using the authority of the director and founder of the anonymized virtual world, the plaintiff was forced by the hacker to link the MetaMask wallet through the Seed phrase using a fraudulent link. Subsequently, the hacker downloaded all of the plaintiff's tokens to his wallet and began selling them on the OpenSea marketplace. The defendant in the case was the person who bought the 6 NFT tokens in question from the hacker, and it was a lawsuit to issue the case according to the provisions of § 1040 Act No. 89/2012 Coll., Civil Code.
The plaintiff based his claim on the provisions of § 1111 of Act no. 89/2012 Coll., of the Civil Code, incorporated in subsection "Acquisition of a right from an unauthorized person". Given provision excludes the acquisition of ownership rights for things lost through loss or an act of the nature of an intentional crime. At the same time, the provision in question excludes ownership in cases where a person does not prove his good faith in the transferor's authority to transfer ownership of the thing.
Decisions of the Regional Court
The Regional Court in Prague first stated that An NFT token is a unit of data recorded in the blockchain that can be owned and traded, it is a digital work, a movable intangible thing as regulated by the provisions of § 496 par. 2 and § 498 par. 2 of Act no. 89/2012 Coll., Civil Code, and the claim is therefore negotiable and the claim enforceable.
On the merits of the case, the Regional Court in Prague confirmed the judgment of the court of first instance, which it was claim dismissed. The regional court justified its decision as unprecedented, reckless and in the digital world by the unacceptable and incomprehensible procedure of the plaintiff, who, according to the words of the courts of both instances, provided the hacker, i.e. a third party, with his Seed phrase voluntarily. The Court of Appeal added that such behavior is one of the worst offenses against one's property that can be committed in the digital world.
Justification
In the justification of its judgment, the Court of Appeal further stated that Voluntary communication of the passphrase Seed to the contents of your MetaMask wallet is undoubtedly not possible to protect by the norms of criminal law, because the plaintiff was not forced by anyone to disclose his Seed phrase to any third party. If he did so, it was deliberate free action against the rules of the digital world, which the plaintiff was introduced to through MetaMask's terms and conditions. The Court of Appeal concluded that the plaintiff had in fact entrusted the NFT tokens to a third party by his actions and referred to the provisions of § 3 par. 2 letters c) sentences after the semicolon of Act no. 89/2012 Coll., of the Civil Code, according to which no one may unreasonably benefit from their own incapacity to the detriment of others.
Objection of absence of good faith
The Regional Court in Prague also disagreed with the plaintiff's objection about the defendant's lack of good faith. In this regard, he concluded that the challenged account of the plaintiff on the OpenSea market, although at the time of the purchase of the tokens in question by the defendant, a note was marked that "this account may be hacked”, however, the digital world has its own specifics, it is a very predatory, dynamic world where individual contracts are concluded in real time, often under time pressure, and at the same time anonymity is assumed and is very common in the digital world. Therefore, in the opinion of the Court of Appeal, high demands cannot be placed on the defendant in terms of obtaining data on the history of tokens or individual accounts on which these tokens were stored in the past. In view of these facts, according to the opinion of the Court of Appeal the defendant undoubtedly believed that this selling user, i.e. the hacker had proper title to the 6 NFT tokens in question.
Spear phishing - "harpoon fishing"
I do not agree with the conclusions of the courts of both instances. Legal doctrine distinguishes the form of the so-called spear phishing (or "harpoon fishing"). This is defined as a more sophisticated form of phishing, which is aimed at a specific user or a narrower group of users having a certain common characteristic. Fraudulent messages in these cases can be more detailed, accurate and targeted, but at the same time require more effort to prepare.
Marek Dvořák further states that in the most sophisticated ways of realization spear phishing, the attacker is in advance in contact with a specific person more or less known to a defined group of users, whom he then fraudulently impersonates, or through whom he subsequently spreads fraudulent messages. The probability of success of such an attack increases significantly due to the higher trust of the recipients in the sender of the phishing message.[2]
Spear phishing and the above case
In the aforementioned case, in my opinion, the attack on the plaintiff represented a form of spear phishing as described above. The attacker was reacting to a situation where the plaintiff was interested in moving land in the virtual world for a long time and publicly expressed it on the group telecommunication platform. At the time of the attack, he was a relatively new user of the virtual world. Evidence showed that MetaMask had established the wallet 4 months before the phishing. In addition, the hacker posed as the founder and director of an anonymized virtual world. With the authority of this person, the plaintiff sent a phishing link under the pretext of activating all the necessary functions of the MetaMask wallet.
The criminal offense of fraud according to the provisions of § 209 of Act no. 40/2009 Coll., of the Criminal Code, undoubtedly requires a certain degree of prudence on the part of the deceived person. Eliška Dostálová distinguishes 5 points of view for determining the level of necessary caution.[3] They are the ones characteristics of the defrauded person, the sophistication of the perpetrator's actions, the influence of the perpetrator's actions (credibility) and the amount of property disposition. I do not consider the fifth point of view, consisting of the victim's awareness of the accused's (financial) situation, to be relevant for the purposes of this analysis, as the aforementioned case does not have a credit character.
The evidence presented showed that the Plaintiff entered the NFT token market as a natural person in November 2021, i.e. he had only 4 months of experience with metaversions at the time of the hacking attack in question. The hacker did not choose a common form of phishing, but a more sophisticated so-called "spear phishincg" tailored to the plaintiff, in response to his frequent queries raised on the virtual world community platform. In addition, the hacker used the authority of the founder and director of this virtual world. The hacker expressed himself grammatically flawlessly and his professional level appeared sufficiently high. According to the verdict, the total value of the stolen NFT tokens from the MetaMask wallet in question amounted to USD 1 in purchase value.
záver
In the case described in this article, the courts of both instances concluded without further ado that the action by which the plaintiff entered his Seed phrase into the planted phishing link, thereby subsequently stealing the contents of his MetaMask wallet, it represents a fatal and unforgivable flaw in the digital world, which the plaintiff entrusted the contents of his MetaMask wallet to an unknown third party, and which cannot be protected by the norms of criminal law, and therefore the condition of an act of the nature of an intentional crime cannot be fulfilled, as required by the provisions of § 1111 of Act no. 89/2012 Coll., Civil Code.
I fear that such a conclusion may set an unfavorable precedent where every phishing attack in the digital world will be labeled with impunity. In my opinion, the courts were absent from the requirement to examine the appropriate level of prudence of the defrauded party, i.e. persons harmed by a phishing attack, as part of the crime of fraud. If the courts were to examine this prudence, they would perhaps come to the conclusion that the case in question was not an ordinary phishing attack, within which I would not excuse the plaintiff's imprudence either, but that it was a more qualified form of attack, the so-called spear phishing, which normally does not allow a cautious user to recognize in a reasonable way that it is a phishing attack at all.
An appeal was filed against the judgment of the Court of Appeal, so it is possible that the assessment of the matter, especially from a legal point of view, will be changed.
Source: epravo.cz
Do you have any questions about this article or the issue? Have you fallen victim to a phishing attack and want to defend yourself? Do you need any advice regarding IT law? Contact us!
The team of the Vych & Partners law office
[1] Boháček, M. Phishing. In: Hendrych, D. et al. Legal Dictionary. 3rd edition. Prague: CH Beck, 2009.
[2] DVOŘÁK, Marek. Phishing, pharming and their criminal penalties. Criminal law review, 2018, no. 4, p. 84-89.
[3] DOSTÁLOVA, Eliška. Prudence of the defrauded in the light of existing jurisprudence. In: State Prosecutor's Office, 2022, no. 4. Available at: https://www.aspi.cz/products/lawText/7/309558/1/2?vtextu=obez%C5%99etnost%20podveden%C3%A9ho#.