Tuesday, May 30, 2023
The Crypto DEFI
  • Home
  • Business
  • Op Eds
  • Press Releases
  • Bitcoin
  • Tech
No Result
View All Result
The Crypto DEFI
  • Home
  • Business
  • Op Eds
  • Press Releases
  • Bitcoin
  • Tech
No Result
View All Result
THE CRYPTO DEFI
No Result
View All Result
Home Tech

Crypto wallet update scam nets criminals more than millions

Dylan by Dylan
in Tech
Share on FacebookShare on Twitter

RELATED POSTS

Monero-mining botnet Lemon Duck records spike in activity

Digital ballots using Elas tokens

Cybercriminals are reportedly tricking owners of Electrum wallets into installing malware so they can steal user funds, according to a ZDNet report. So far, more than $22 million has been stolen per the outlet’s investigation. 

The scam involves sending fake updates to wallet owners. This tactic was first noticed in December 2018. Since then, thieves have reused the attack pattern in multiple campaigns over the past years, with some attacks taking place as recently as last month. 

How it works

The heist begins when users of the Electrum crypto wallet app receive an unexpected update request via a pop-up message. They update their wallet, then discover that the funds contained within were stolen and sent to the attacker’s BTC account.

This attack method works because of the inner workings of the Electrum wallet app and its backend infrastructure.

Developers designed Electrum wallets to connect to the BTC blockchain to process any transactions. It connects through a network of Electrum servers known as ElectrumX. 

While some crypto wallet services control who can manage these servers, Electrum is an open ecosystem where everyone can set up an ElectrumX gateway server. Since 2018, the bad actors have been abusing this system to spin up malicious servers and wait for unsuspecting users to connect to their systems randomly.

Once this happens, the attackers instruct the server to show a pop-up on the user’s screen, leading the victim to access an URL and download and install an Electrum wallet app update on what turns out to be lookalike domains impersonating the official Electrum website or GitHub repositories.  

If users ignore the URL without confirming it is electrum.org, they end up unwittingly installing a malicious version of the Electrum wallet.  

The next time the user tries to use the wallet, it will uncharacteristically ask for a one-time passcode (OTP). The code is only requested before sending funds and not at the wallet’s startup. If users enter the requested code without thinking, they have given the malicious wallet’s official approval to transfer all of their funds to an attacker’s account.

The report tracked down multiple crypto accounts where thieves have allegedly gathered stolen funds from the heist they carried out. These wallets hold 1980 BTC, which is roughly over $22 million in fiat currency. A significant portion of those funds appears to have been stolen during one event in August when one unlucky victim reported losing 1,400 BTC (~$15.8 million) after updating an Electrum wallet.

The Electrum team has taken many steps to mitigate this attack. They implemented a server blacklisting system on Electrum X servers to prevent malicious additions to their networks. They also added a system update, stopping servers from showing HTML formatted pop-ups to end-users.

Nonetheless, a malicious server can still slip through the cracks. The attack still works well on those still using older versions of the Electrum wallet app to manage funds.

Follow thecryptodefi.com Crypto Crime Cartel series, which delves into the stream of groups—from BitMEX to Binance, Bitcoin.com, Blockstream and Ethereum—who have co-opted the digital asset revolution and turned the industry into a minefield for naïve (and even experienced) players in the market.

New to Bitcoin? Check out Thecryptodefi.Com’s Bitcoin for Beginners section, the ultimate resource guide to learn more about Bitcoin—as originally envisioned by Satoshi Nakamoto—and blockchain.

ShareTweetPin

Related Posts

Monero-mining botnet Lemon Duck records spike in activity

by Dylan
May 25, 2023
0

Cybersecurity researchers are warning of a recent spike in activity of a stealthy digital currency mining botnet. Known as Lemon...

Digital ballots using Elas tokens

by Dylan
May 20, 2023
0

This post originally appeared on Elas.Digital site and we republished with permission from the Elas team.Improvements on current systems include that there...

Digital currency mining comes to Arctic Circle

by Dylan
May 10, 2023
0

Russia-based digital currency mining firm BitCluster announced its new BitCluster Nord data center is now officially open. The new mining farm...

Blockchain platform verifies health for 17M Chinese tourists in 1 month

by Dylan
May 5, 2023
0

A blockchain-based health records system is gradually making it possible for mainland China to resume cross-border tourism to Macao. The...

A token ledger system that leverages the simplicity of Bitcoin

by Dylan
April 30, 2023
0

This post originally appeared on Elas.Digital site and we republished with permission from the Elas team.Until now there has been no way...

Next Post
US Senator Calls on SEC Chairman to Provide Regulatory Clarity on Cryptocurrencies

US Senator Calls on SEC Chairman to Provide Regulatory Clarity on Cryptocurrencies

Bitcoin has a red history

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED

BlockFi inches closer to US public listing

BlockFi inches closer to US public listing

May 29, 2023

Thecryptodefi.Com Live 2020 – Antigua Influencers Viewing Event

May 28, 2023

MOST VIEWED

  • What is Pushswap (PUSH)? Details of the PUSH cryptocurrency

    What is Pushswap (PUSH)? Details of the PUSH cryptocurrency

    0 shares
    Share 0 Tweet 0
  • Thecryptodefi.Com Live 2020 – Antigua Influencers Viewing Event

    0 shares
    Share 0 Tweet 0
  • BlockFi inches closer to US public listing

    0 shares
    Share 0 Tweet 0
  • TAAL announces agreement to establish North American Bitcoin SV hosting capacity to support large scale enterprise clients

    0 shares
    Share 0 Tweet 0
  • True peer-to-peer functionality on the Bitcoin network restored and enhanced with latest update to Bitcoin SV Node software

    0 shares
    Share 0 Tweet 0
The Crypto DEFI – Latest News

© 2021 DYLAN | thecryptodefi.com. All rights reserved.

CATEGORY

  • Bitcoin
  • Business
  • Editorial
  • Events
  • News
  • Op Eds
  • Press Releases
  • Tech
  • Tutorial
  • DEFI
  • Bitcoin
  • Ethereum

© 2021 DYLAN | thecryptodefi.com. All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Tech
  • Op Eds
  • Press Releases
  • Bitcoin

© 2021 DYLAN | thecryptodefi.com. All rights reserved.