Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Fake WalletConnect App Steals $70K From Google Play Users

Fake WalletConnect App Steals $70K From Google Play Users

CryptotimesCryptotimes2024/09/30 11:48
By:Ronak KumarDhara Chavda

The fake app, initially named "Mestox Calculator," emerged in March, changing names to evade detection while draining users' crypto wallets.

A crypto wallet drainer app posing as WalletConnect has stolen over $70,000 from unsuspecting users on the Google Play Store, according to a report by Check Point Research. The malicious app used “advanced evasion techniques” to avoid detection for over five months, tricking more than 150 users into linking their wallets.

The fake app, originally called “Mestox Calculator,” first appeared in March and underwent several name changes to stay undetected. By using a harmless calculator front, the app passed Google Play’s security checks. However, once installed, it redirected mobile users to a backend that housed the wallet-drainer software, MS Drainer.

Fake WalletConnect App Steals $70K From Google Play Users image 0 Source: X

The app fooled users by asking them to connect their wallets and approve permissions, which allowed the attackers to steal funds. Not everyone was affected — only those who connected a wallet or met the malware’s specific targeting criteria were affected.

Users are asked to accept various permissions to “verify their wallet,” which grants permission for the attacker’s address “to transfer the maximum amount of the specified asset,” Check Point Research said.

According to a report by Check Point Research , after being downloaded more than 10,000 times, the app has since been removed from the store. This is the first time a drainer app has exclusively targeted mobile users, making it a significant security concern for crypto holders.

“Fake reviews and consistent branding helped the app achieve over 10,000 downloads by ranking high in search results,” Check Point Research said.

This incident highlights the growing threat of mobile-targeted scams in the cryptocurrency space. Users should always be cautious and verify the authenticity of apps, especially when it comes to connecting their wallets to unknown platforms.

Follow The Crypto Times on Google News to Stay Updated!
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!