Odaily Planet Daily News ENS core developer nick.eth posted on the X platform that he encountered a highly complex phishing attack. The attack exploited two unpatched vulnerabilities in Google's infrastructure, successfully bypassed DKIM verification and passed the Gmail security warning, disguising it as a real Google security reminder email. Attackers can build fake "support pages" through Google Sites to induce users to log in and steal credentials.
nick.eth said that he had reported the relevant issues to Google, but received a reply of "working as expected". Google refused to fix the relevant logical vulnerabilities, and this attack method may appear frequently in the future.