Fake Solana wallet security update is trying to steal your crypto: Reports

Share This Post

Password-stealing malware is being spread by hackers through NFT airdrops purporting to be Solana Phantom security updates.

For the last two weeks, unknown hackers have been airdropping nonfungible tokens (NFTs) to Solana cryptocurrency users masquerading as a new Phantom wallet security update, however, instead of an update, it’s malware designed to steal their crypto.

According to BleepingComputer, the hackers are claiming to be from the Phantom team and using NFTS titled “PHANTOMUPDATE.COM” or “UPDATEPHANTOM.COM.”

After opening the NFT, users are told a new security update has been issued for the Phantom wallet and can be downloaded by using the enclosed link or the listed website.

To add urgency, the message claims that failing to download the fake security update, “may result in a loss of funds due to hackers exploiting the Solana network.”

The fake NFTs being used to spread malware. Source: BleepingComputer

The urgency piece is likely related to the Solana-based wallet hack which saw roughly $8 million stolen from 8,000 wallets in August, including those of Phantom wallet users. The security exploit was later linked to vulnerabilities within the Solana-based Web3 wallet service Slope. 

Should a victim follow the fake Phantom update instructions, the process ends with malware being downloaded from GitHub which attempts to steal browser information, history, cookies, passwords, SSH keys and other information from the user. 

Users who may have inadvertently fallen prey to this scam are recommended to take security precautions such as scanning their computer with antivirus software, securing crypto assets, and changing passwords on sensitive platforms such as bank accounts and crypto trading platforms.

Related: Blockchain security firm warns of new MetaMask phishing campaign

In the past, similar malware-spreading campaigns have employed malware dubbed “Mars Stealer” to steal crypto from unsuspecting users.

An upgrade of the information-stealing Oski trojan of 2019, Mars Stealer targets more than 40 browser-based crypto wallets, along with popular two-factor authentication (2FA) extensions, with a grabber function that steals users’ private keys.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

LBank x 7 Meme Projects: Don’t Miss the Halloween Campaign with $7,000 in Prizes

PRESS RELEASE LBank, leading global cryptocurrency exchange, has officially launched its “Spooky Season” Halloween Campaign, running from October 22 to November 3, 2024 With a total

XRP News: Ripple Partners with Garanti BBVA and IBM to Boost Crypto Security in Türkiye

The post XRP News: Ripple Partners with Garanti BBVA and IBM to Boost Crypto Security in Türkiye appeared first on Coinpedia Fintech News In an exciting move for the Turkish crypto market, Garanti

India About to Ban Bitcoin, Eth As Government Favors CBDC Expansion

The post India About to Ban Bitcoin, Eth As Government Favors CBDC Expansion appeared first on Coinpedia Fintech News India is moving closer to a major decision on cryptocurrencies like Bitcoin and

SPX6900 Price Prediction: Sell The Broken Parabola Or Buy Dip For Next Meme Coin Supercycle

The post SPX6900 Price Prediction: Sell The Broken Parabola Or Buy Dip For Next Meme Coin Supercycle appeared first on Coinpedia Fintech News SPX6900 recently witnessed one of the biggest rallies in

Ripple Price Analysis: Will XRP Price Reclaim $0.63 or Fall to $0.48? 

The post Ripple Price Analysis: Will XRP Price Reclaim $063 or Fall to $048  appeared first on Coinpedia Fintech News Following the SEC appeal, the XRP coin price had experienced a major price

ECB’s Attack on Bitcoin Backfires! Here’s Why Experts Are Furious

The post ECB’s Attack on Bitcoin Backfires! Here’s Why Experts Are Furious appeared first on Coinpedia Fintech News A group of researchers, Dr Murray A Rudd, Dennis Porter, Allen Farrington, and