SlowMist Uncovers Fraudulent ImToken Wallet on Third-party Stores

The SlowMist Security Team has investigated and analyzed fake Web3 wallets from third-party app stores, warning users about the dangers of downloading wallet apps from questionable sources.

In a recent tweet, the team shared their findings and urged users to stay vigilant in enhancing their security awareness when using wallets in the blockchain space.

According to the team, third-party app stores like apkcombo and uptodown pose significant risks as anyone can publish apps with minimal cost, making phishing attacks more accessible. The team found a fraudulent version of the well-known imToken wallet on apkcombo, which transmits sensitive data, like mnemonics, to the attacker’s server.

The report read:

We found a widespread fraudulent version of the well-known imToken wallet on apkcombo. It has a high version number, possibly to mask itself as the latest version. The download count is also substantial, likely sourced from Google Play’s info.

The security firm encourages users to always use official download channels for wallets and exchanges, stay vigilant, and enhance their security awareness.

Last week, a well-known Chinese reporter, Collin Wu, revealed that the top ad for imToken on Chinese Google search was a phishing website that uses Google Docs to commit fraud. Wu highlighted that many fake wallets were flooding search engines and forming an industrial chain, posing a threat to unsuspecting users.

SlowMist expressed shock that such a scam could occur and warned users to exercise caution, noting that the phishing attack was a new type that uses Google Docs to deceive users.

Comments

Popular posts from this blog

How Ethereum Price Could Race to $3K Bolstered by Accelerated Staking Post-Shapella Upgrade

Avalanche (AVAX) Price Prediction: Will AVAX reach $30 in 2023?

Bitcoin 'not undervalued yet' says research as BTC price drifts nearer $16K