Researchers predict that a wave of social engineering attacks will dominate web3 and the metaverse.
See also: Ukrainian coders: They divide their time between work and cyberwar

Web3 is the term coined for what could become the next face of the Internet. The Web has shifted from pages containing content to the growth of social media, and now, the concept of a decentralized Internet is being discussed under the Web3 banner.
Part of this transformation could include the 'metaverse' — a 3D environment and virtual world to facilitate social connections, whether personal or for work. Your ID in the metaverse could end up linked to cryptocurrency wallets, Non Fungible Tokens (NFTs), and various smart contracts.
As technology vendors work on these concepts, cybersecurity researchers from Cisco Talos have offered their perspective on the potential threats that Web3 and the metaverse will face.
See also: Microsoft: Confirms hack and source code theft by Lapsus$
The recent wave of phishing experienced by OpenSea users, in which victims were tricked into signing malicious contract transactions and surrendering their NFTs, may highlight the types of attack we may see more frequently in the future.
The first topic discussed by the group is the use of the Ethereum Name Service (ENS) and possibly upcoming similar services used to condense wallet addresses into an easily remembered format.
As some of us assume the potential future value of ENS domains and register them — such as 'businessname.eth' — these addresses could be used as leverage in phishing attacks, especially since ENS domains are recorded on the blockchain and cannot be easily removed through trademark disputes.
Additionally, those who register an ENS domain can use their names, anonymizing an address and signaling to others the money an individual has in their cryptocurrency wallet, potentially increasing the risk of being selectively targeted by a threat actor.
A brief search by Cisco Talos of .ENS domain holders who have made their addresses public revealed a number of 'whales' holding huge amounts of cryptocurrency and some quite lucrative NFTs.
Some owners also reveal their hometowns, full names, and social media profiles — giving attackers a broader picture of the individuals they are targeting for social engineering attacks.

See also: ELTA cyberattack: Target is the encryption of critical systems
As Web3 will be a new concept that users will need time to learn about, a general lack of education may make individuals more susceptible to scams.
Additionally, wallet cloning may become a more popular attack method in the future. This requires victims to “give up” their passphrase, the secret key used to recover lost wallets and can be requested through social engineering, posing as customer support, or by tricking wallet holders into fake verification processes.
While Web3 is still in development, it's worth taking the time to familiarize yourself with this technology — especially if you plan to explore the decentralized world in the future.
Cisco Talos also recommends implementing basic security measures, password management, multi-factor authentication (MFA), and most importantly, remembering to never give out your passphrases.
Information source: zdnet.com
