Hackers Are Cloning Web3 Wallets Like Metamask and Coinbase Wallet to Steal Crypto

Share This Post

metamask

Confiant, an advertising security agency, has found a cluster of malicious activity involving distributed wallet apps, allowing hackers to steal private seeds and acquire the funds of users via backdoored imposter wallets. The apps are distributed via cloning of legitimate sites, giving the appearance that the user is downloading an original app.

Malicious Cluster Targets Web3-Enabled Wallets Like Metamask

Hackers are becoming more and more creative when engineering attacks to take advantage of cryptocurrency users. Confiant, a company that is dedicated to examining the quality of ads and the security threats these might pose to internet users, has warned about a new kind of attack affecting users of popular Web3 wallets like Metamask and Coinbase Wallet.

The cluster, that was identified as “Seaflower,” was qualified by Confiant as one of the most sophisticated attacks of its kind. The report states that common users cannot detect these apps, as they are virtually identical to the original apps, but have a different codebase that allows hackers to steal the seed phrases of the wallets, giving them access to the funds.


Distribution and Recommendations

The report found out that these apps are distributed mostly outside regular app stores, through links found by users in search engines such as Baidu. The investigators state that the cluster must be of Chinese origin due to the languages in which the code comments are written, and other elements like infrastructure location and the services used.

The links of these apps reach popular places in search sites due to the intelligent handling of SEO optimizations, allowing them to rank high and fooling users into believing they are accessing the real site. The sophistication in these apps comes down to the way in which the code is hidden, obfuscating much of how this system works.

The backdoored app sends seed phrases to a remote location at the same time that it is being constructed, and this is the main attack vector for the Metamask imposter. For other wallets, Seaflower also uses a very similar attack vector.

Experts further made a series of recommendations when it comes to keeping wallets in devices secure. These backdoored applications are only being distributed outside app stores, so Confiant advises users to always try to install these apps from official stores on Android and iOS.

What do you think about the backdoored Metamask and Web3 wallets? Tell us in the comments section below.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Cardano’s Pullback Short-Lived, Fresh Rally Underway For ADA?

Cardano (ADA) has made a strong comeback, with bulls stepping in to reverse the recent pullback and drive a fresh rally After a brief period of downward pressure, the cryptocurrency is gaining

Bitcoin Price Pauses In Consolidation: Aiming for New Gains

Bitcoin price started a downside correction and tested the $66,500 zone BTC is now consolidating and might aim for a fresh increase above $67,800 Bitcoin struggled to test the $70,000 resistance zone

Wazirx Security Breach: Liminal’s Analysis Points to Deeper Issues

Liminal Custody has released an update addressing the allegations and misinformation surrounding the Wazirx security breach The company clarified that while Wazirx blamed it for the incident, the

Dogecoin And Shiba Inu Go Head-To-Head For Price Dominance – A New King Emerges For $9,230% In The Next 30 Days

As the Dogecoin price and Shiba Inu price compete for supremacy, a new contender, ETFSwap (ETFS), is capturing attention with an astonishing forecast of a $9,230% increase over the next 30 days,

Dogecoin Rockets 30% In A Week, Sparking Hype For Uptober Rally

At press time, Dogecoin was found to have gained significantly as it jumped to $0141556 following a 177% growth that occurred within the last 24 hours In a week, the meme coin has gone pretty high at

BRICS Nations in ‘Intense Discussions’ to Develop Common Payment System

BRICS nations are actively discussing the development of a common payment system and the use of national currencies for trade, with Indian Foreign Secretary Vikram Misri confirming that intense talks