pwshub.com

Fake Crypto Wallet on Google Play Steals $70,000 in Digital Assets After Being Downloaded 10,000 Times: Report

A fake crypto wallet application on the Google Play Store has reportedly stolen tens of thousands of dollars worth of crypto assets from unsuspecting customers after seeing 10,000 downloads.

According to a new report from cybersecurity firm Checkpoint Research (CPR), a malicious wallet drainer on Google Play stole $70,000 worth of digital assets from users after being available in the store for over five months.

CPR says the malware disguised itself as an app associated with WalletConnect – which itself doesn’t have an app – to take advantage of confused users. WalletConnect is a protocol for web browsers and mobile phones that establishes connections between crypto wallets and decentralized applications (DApps).

Says CPR,

“Given all the complications with WalletConnect, an inexperienced user might conclude that it is a separate wallet application that needs to be downloaded and installed. Attackers hijack the confusion, hoping that users will search for a WalletConnect app in the application store.

However, when searching WalletConnect in Google Play, users find the malicious app ‘WalletConnect – Crypto Wallet’ at the top of the list.”

According to the CPR, the creators of the exploit used social engineering and other clever tactics to carry out and obfuscate their complicated crypto scheme, scamming hundreds of victims.

“The attackers leveraged a combination of social engineering, technical manipulation, and clever exploitation of user confusion to carry out a sophisticated crypto-draining operation.

By capitalizing on a well-known and trusted name like WalletConnect and exploiting the shortcomings of simple and undemanding applications, they were able to deceive over 150 victims and accumulate significant amounts of cryptocurrency without triggering immediate suspicion.”

The cybersecurity firm goes on to say that the exploit was unique in that it relied on smart contracts rather than attacking conventional targets, such as keyloggers.

Generated Image: DALLE3

Source: dailyhodl.com

Related stories
3 weeks ago - Scammers made off with more than $70,000 before a fake ‘WalletConnect’ app was taken down.
7 hours ago - UPDATE: Bitcoin is making a move for $69,000 as "Uptober" takes root, and you can earn more BTC by playing these games.
1 month ago - Crypto wallet owners in Korea should be wary of a new type of mobile malware designed to steal seed phrases, warns the cybersecurity firm McAfee. A seed phrase is a collection of 12 to 24 random words used to restore access to a crypto...
1 month ago - It’s alleged the group intimidated the entrepreneur, accusing him of collaborating with Russia and threatening him with prison.
1 month ago - If you asked Ikigai’s Travis Kling, he’d say that there’s a new attitude taking over in crypto: “Pervasive quiet quitting.”
Other stories
35 minutes ago - Shiba Inu (SHIB) is now priced at about $0.00001783, just below a key resistance zone which means that the market is in a good mood. Market analysts are ready to witness another possible rally in the meme coin space. Related Reading:...
44 minutes ago - JPMorgan Chase, Wells Fargo, Bank of America and Citi are unloading billions of dollars in bad debt that they’ve given up on recovering. New earnings data shows the four largest banks in the country collectively recorded $6.9 billion in...
44 minutes ago - A crypto whale is looking at a massive multi-million dollar gain on a Solana (SOL)-based memecoin after just five days. According to on-chain data tracker Lookonchain, a deep-pocketed investor turned $727 worth of Goatseus Maximus (GOAT)...
2 hours ago - The approvals by the SEC come less than a month after the agency granted Nasdaq permission to list similar options.
2 hours ago - Aave, the decentralized lending platform, is among the largest DeFi protocols by total value locked (TVL). Over the years, despite the crypto price boom and bust cycle, the platform has operated flawlessly without any technical hitches....