Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Fake Crypto Wallet on Google Play Steals $70,000 in Digital Assets After Being Downloaded 10,000 Times: Report

Fake Crypto Wallet on Google Play Steals $70,000 in Digital Assets After Being Downloaded 10,000 Times: Report

Daily HodlDaily Hodl2024/09/28 16:00
By:by Mehron Rokhy

A fake crypto wallet application on the Google Play Store has reportedly stolen tens of thousands of dollars worth of crypto assets from unsuspecting customers after seeing 10,000 downloads.

According to a new report from cybersecurity firm Checkpoint Research (CPR), a malicious wallet drainer on Google Play stole $70,000 worth of digital assets from users after being available in the store for over five months.

CPR says the malware disguised itself as an app associated with WalletConnect – which itself doesn’t have an app – to take advantage of confused users. WalletConnect is a protocol for web browsers and mobile phones that establishes connections between crypto wallets and decentralized applications (DApps).

Says CPR,

“Given all the complications with WalletConnect, an inexperienced user might conclude that it is a separate wallet application that needs to be downloaded and installed. Attackers hijack the confusion, hoping that users will search for a WalletConnect app in the application store.

However, when searching WalletConnect in Google Play, users find the malicious app ‘WalletConnect – Crypto Wallet’ at the top of the list.”

According to the CPR, the creators of the exploit used social engineering and other clever tactics to carry out and obfuscate their complicated crypto scheme, scamming hundreds of victims.

“The attackers leveraged a combination of social engineering, technical manipulation, and clever exploitation of user confusion to carry out a sophisticated crypto-draining operation.

By capitalizing on a well-known and trusted name like WalletConnect and exploiting the shortcomings of simple and undemanding applications, they were able to deceive over 150 victims and accumulate significant amounts of cryptocurrency without triggering immediate suspicion.”

The cybersecurity firm goes on to say that the exploit was unique in that it relied on smart contracts rather than attacking conventional targets, such as keyloggers.

Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Follow us on X , Facebook and Telegram

Surf The Daily Hodl Mix

Generated Image: DALLE3

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!