Hackers Are Cloning Web3 Wallets Like Metamask and Coinbase Wallet to Steal Crypto
Confiant, an advertising security agency, has found a cluster of malicious activity involving distributed wallet apps, allowing hackers to steal private seeds and acquire the funds of users via backdoored imposter wallet...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Confiant, an advertising security agency, has found a cluster of malicious activity involving distributed wallet apps, allowing hackers to steal private seeds and acquire the funds of users via backdoored imposter wallets. The apps are distributed via cloning of legitimate sites, giving the appearance that the user is downloading an original app.
Malicious Cluster Targets Web3-Enabled Wallets Like MetamaskHackers are becoming more and more creative when engineering attacks to take advantage of cryptocurrency users. Confiant, a company that is dedicated to examining the quality of ads and the security threats these might pose to internet users, has warned about a new kind of attack affecting users of popular Web3 wallets like Metamask and Coinbase Wallet.
The cluster, that was identified as “Seaflower,” was qualified by Confiant as one of the most sophisticated attacks of its kind. The report states that common users cannot detect these apps, as they are virtually identical to the original apps, but have a different codebase that allows hackers to steal the seed phrases of the wallets, giving them access to the funds.
Distribution and RecommendationsThe report found out that these apps are distributed mostly outside regular app stores, through links found by users in search engines such as Baidu. The investigators state that the cluster must be of Chinese origin due to the languages in which the code comments are written, and other elements like infrastructure location and the services used.
The links of these apps reach popular places in search sites due to the intelligent handling of SEO optimizations, allowing them to rank high and fooling users into believing they are accessing the real site. The sophistication in these apps comes down to the way in which the code is hidden, obfuscating much of how this system works.
The backdoored app sends seed phrases to a remote location at the same time that it is being constructed, and this is the main attack vector for the Metamask imposter. For other wallets, Seaflower also uses a very similar attack vector.
Experts further made a series of recommendations when it comes to keeping wallets in devices secure. These backdoored applications are only being distributed outside app stores, so Confiant advises users to always try to install these apps from official stores on Android and iOS.
What do you think about the backdoored Metamask and Web3 wallets? Tell us in the comments section below.
Why this matters
This blockchain story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Bitcoin NewsRelated market context
Hackers breach Italian state email to target Revolut crypto users
This breach highlights vulnerabilities in emergency data request protocols, emphasizing the need for stricter verification to prot...
Major Bitcoin Core update changes default wallet protocols, risking temporary disruption across popular apps
Bitcoin Core v32.0rc1 has turned the Sept. 14–Oct. 10 window into a concentrated compatibility test for node operators, wallet pro...
A new XRPL upgrade could concentrate XRP ownership inside banks instead of retail wallets
A proposed XRP Ledger (XRPL) upgrade could let banks and fintechs absorb XRP costs so customers never need to hold the token. The...
Kraken Lets Users Earn DeFi Yield on Nvidia and ETF xStocks
Kraken has launched on-chain yield vaults for three tokenised securities, enabling qualified clients to earn variable rewards from...
XRP News: XRPL Records 2K Transactions from 20 Wallets
The XRP Ledger processed a record 3,254 transactions in ledger 106,965,249 yesterday, but 2,000 of the news came from just 20 acco...
SEC Stock-Token Exemption Will Likely Let Companies Opt Out, Securitize’s Brett Redfearn Says
Brett Redfearn, president of Securitize and director of the SEC’s Division of Trading and Markets from 2017 to 2020, expects the a...