BitKeep exploiter used phishing sites to lure in users: Report

Share This Post

The attacker appears to be attempting to cash out funds using Binance and Changenow.

The Bitkeep exploit that occurred on Dec. 26 used phishing sites to fool users into downloading fake wallets, according to a report by blockchain analytics provider OKLink.

The report stated that the attacker set up several fake Bitkeep websites which contained an APK file that looked like version 7.2.9 of the Bitkeep wallet. When users “updated” their wallets by downloading the malicious file, their private keys or seed words were stolen and sent to the attacker.

The report did not say how the malicious file stole the users’ keys in an unencrypted form. However, it may have simply asked the users to re-enter their seed words as part of the “update,” which the software could have logged and sent to the attacker.

Once the attacker had users’ private keys, they unstaked all assets and drained them into five wallets under the attacker’s control. From there, they tried to cash out some of the funds using centralised exchanges: 2 ETH and 100 USDC were sent to Binance, and 21 ETH were sent to Changenow.

The attack happened across five different networks: BNB Chain, Tron, Ethereum, and Polygon, and BNB Chain bridges Biswap, Nomiswap, and Apeswap were used to bridge some of the tokens to Ethereum. In total, over $13 million worth of crypto was taken in the attack.

Related: Defrost v1 hacker reportedly returns funds as ‘exit scam’ allegations surface

It is not yet clear how the attacker convinced users to visit the fake websites. The official website for BitKeep provided a link that sent users to the official Google Play Store page for the app, but it does not carry an APK file of the app at all.

The BitKeep attack was first reported by Peck Shield at 7:30 a.m. UTC. At the time, it was blamed on an “APK version hack.” This new report from OKLink suggests that the hacked APK came from malicious sites, and that the developer’s official website has not been breached.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Crypto Analyst Predicts Bitcoin Price Will Hit New All-Time High If It Breaks This Level

Bitcoin, which started the month on a negative note, has begun to regain some positive momentum and is up by 166% in the past 24 hours This recovery comes amid renewed optimism in the crypto space,

Peter Schiff: Phony Economy Must Die or US Risks Financial Ruin

Economist Peter Schiff has warned that restoring a real economy requires letting the “phony economy” collapse, which would result in significant financial losses for many However, he

Bitcoin Price Could Enter ‘Period Of Positive Seasonal Performance’ — But This Needs To Happen

The Bitcoin price having an outstanding Q4 to close the year 2024 has been one of the most prominent narratives in the cryptocurrency market in recent weeks Interestingly, a popular blockchain firm

Zimbabwe Injects $50 Million to Bolster Devalued Currency

The Reserve Bank of Zimbabwe (RBZ) has injected an additional $50 million into the market to support the foreign exchange system However, industry leaders believe the bank is not doing enough to

Shiba Inu Burn Rate Shoots Up 1,000% – Are New ATH Levels Just Around The Corner?

Shiba Inu is making waves after wrapping up an astounding 1,000% increase in its burn rate, Shibburn data shows This has occurred simultaneously with a nearly 7% increase in the value of the meme

Nigeria Introduces System to Boost Forex Market Transparency

The Central Bank of Nigeria (CBN) is launching a new electronic system (EFEMS) to improve transparency in the foreign exchange market This comes as the Nigerian currency weakens Authorized dealers