pwshub.com

A Fake Wallet App Was Downloaded 10,000 Times on Google Play

A fake wallet app available for four months on the Google Play Store stole over $70,000 worth of cryptocurrency in a phishing attack before it was shut down. The malware posed as WalletConnect, a popular Web3 protocol, and directed unsuspecting users to a site that tricked them into authorizing transactions, granting access to their funds. In total, the app was downloaded 10,000 times, though only 150 people fell for the ruse, according to a report by Checkpoint Research.

The actual WalletConnect enables secure communication between cryptocurrency wallets and dApps via QR codes, allowing users to approve transactions and interact with dApps without exposing private keys.

“Basic cybersecurity hygiene, even on your mobile devices, is paramount,” Michael McLaughlin, who co-leads the Cybersecurity and Data Privacy Practice Group at the law firm of Buchanan Ingersoll & Rooney. “If you're using a crypto trading platform—and it could be Coinbase, it could be Kraken, it could be any of those— they offer multi-factor authentication even on their mobile applications. And you have to implement them.”

McLaughlin emphasized the need to scrutinize cryptocurrency applications more, especially in digital stores that allow anyone to upload applications quickly. McLaughlin advised prospective downloaders to look at how many stars and reviews an application has before downloading it. “If it has only three users and no stars, you're not going to trust it," he said.

McLaughlin also said users should check the history of the application for any suspicious or sudden changes, such as how the product is referenced by previous users. He cited as an example a flashlight app that has thousands of users but then suddenly pivoted to a cryptocurrency app.

“It would still have the same number of users, it would still have the same rating, but now you just change the name of it, and so it no longer is a strobe flashlight app, now it's a cryptocurrency trader app,” he said. “So now it looks legitimate, even though it's not.”

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source: decrypt.co

Related stories
3 weeks ago - An interview with Craig Raw, creator of the popular Sparrow Wallet, on Bitcoin privacy best practices and pain as a teacher. From "The Privacy Issue".
1 month ago - Bitcoin Miner turns the crypto mining grind into a colorful mobile game, plus it pays you actual BTC for playing. Here’s what you need to know.
1 month ago - Plus, Google is facing a lawsuit after a Florida woman claims she lost $5 million in a scam involving a fake crypto wallet app.
2 weeks ago - Crypto wallet owners in Korea should be wary of a new type of mobile malware designed to steal seed phrases, warns the cybersecurity firm McAfee. A seed phrase is a collection of 12 to 24 random words used to restore access to a crypto...
1 month ago - Sports supplements company Insane Labz allegedly paid trolls to impersonate MMA celebs Dana White, Nate Diaz, and Hasbulla and pump its token.
Other stories
15 minutes ago - Bitcoin has been the subject of recent media attention, not only due to its price increase above $65,000 but also due to the extraordinary inflows into spot Bitcoin ETFs. These inflows, according to Farside Investors, have reached a...
58 minutes ago - A data breach at Wells Fargo is affecting an unknown number of the banking giant’s customers. A new filing with the Office of the Vermont Attorney General shows the lender is warning customers that an insider at the bank has accessed and...
58 minutes ago - The native token of the synthetic dollar protocol developer Ethena (ENA) surged by more than 45% this week as the project rolled out multiple new products. Ethena aims to provide a crypto-native solution for money not reliant on...
1 hour ago - Shiba Inu is experiencing a notable price breakout, surging over 19% and positioning itself toward the critical resistance level of $0.00002631. This significant rally indicates a shift in market momentum, characterized by robust buying...
2 hours ago - New ETFs giving leveraged exposure to Bitcoin treasury firm MicroStrategy are sure to be spicy, but they're already pulling in investors.