BTC $79,789.78 -0.22%
ETH $2,506.73 +0.04%
BNB $748.56 -2.09%
XRP $1.41 -0.70%
SOL $105.40 +0.84%
TRX $0.3352 +0.63%
DOGE $0.0898 -1.08%
ADA $0.2207 -0.32%
BCH $256.74 -1.96%
LINK $13.07 +6.77%
HYPE $86.35 +0.65%
AAVE $133.91 -1.29%
SUI $0.8014 +0.47%
XLM $0.1874 +0.50%
ZEC $1,192.09 +11.89%
BTC $79,789.78 -0.22%
ETH $2,506.73 +0.04%
BNB $748.56 -2.09%
XRP $1.41 -0.70%
SOL $105.40 +0.84%
TRX $0.3352 +0.63%
DOGE $0.0898 -1.08%
ADA $0.2207 -0.32%
BCH $256.74 -1.96%
LINK $13.07 +6.77%
HYPE $86.35 +0.65%
AAVE $133.91 -1.29%
SUI $0.8014 +0.47%
XLM $0.1874 +0.50%
ZEC $1,192.09 +11.89%

nem

All
Article
Flash

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.

Coldcard releases new firmware to enhance security; affected users need to regenerate their mnemonic phrases and migrate their assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following an emergency fix, focusing on addressing the security risks posed by previous mnemonic phrase generation attacks. Each newly generated mnemonic phrase must include at least one user entropy source, such as irregular key presses at least 65 times, physical dice rolls 50 times, or physical coin tosses 128 times, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2.The new firmware also adds pre-signing phased PSBT verification, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard states that this update aims to further reduce the risk of the device being attacked.The official reminder is that updating the firmware cannot fix existing mnemonic phrases generated by previously affected firmware. If a user's mnemonic phrase falls within the scope of this security announcement, they should first update the device, then generate and verify a brand new mnemonic phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signatures of the downloaded firmware.
app_icon
ChainCatcher Building the Web3 world with innovations.