BTC $83,839.67 +1.11%
ETH $2,707.74 +2.36%
BNB $764.03 +0.34%
XRP $1.50 +1.51%
SOL $119.14 +0.77%
TRX $0.3353 +0.49%
DOGE $0.0948 +2.15%
ADA $0.2519 +3.28%
BCH $310.26 +1.34%
LINK $15.21 +11.28%
HYPE $88.12 -1.01%
AAVE $166.73 +12.95%
SUI $1.13 -3.37%
XLM $0.2295 +10.20%
ZEC $1,406.49 -9.34%
AAPL $337.20 -1.02%
AMZN $246.79 -0.70%
GOOGL $342.30 +0.36%
MSFT $508.71 -1.23%
META $718.54 -2.26%
NVDA $230.60 +3.30%
TSLA $358.42 -2.79%
SNDK $1,732.04 +1.07%
INTC $116.49 -1.53%
SPCX $146.83 -1.26%
MU $1,071.47 +1.36%
AMD $612.20 -0.37%
BTC $83,839.67 +1.11%
ETH $2,707.74 +2.36%
BNB $764.03 +0.34%
XRP $1.50 +1.51%
SOL $119.14 +0.77%
TRX $0.3353 +0.49%
DOGE $0.0948 +2.15%
ADA $0.2519 +3.28%
BCH $310.26 +1.34%
LINK $15.21 +11.28%
HYPE $88.12 -1.01%
AAVE $166.73 +12.95%
SUI $1.13 -3.37%
XLM $0.2295 +10.20%
ZEC $1,406.49 -9.34%
AAPL $337.20 -1.02%
AMZN $246.79 -0.70%
GOOGL $342.30 +0.36%
MSFT $508.71 -1.23%
META $718.54 -2.26%
NVDA $230.60 +3.30%
TSLA $358.42 -2.79%
SNDK $1,732.04 +1.07%
INTC $116.49 -1.53%
SPCX $146.83 -1.26%
MU $1,071.47 +1.36%
AMD $612.20 -0.37%

nem

All
Article
Flash

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code, which may lead to the leakage of private keys and mnemonic phrases

SlowMist released a security warning stating that it has recently received multiple reports of FomoPeek users' assets being stolen. After a joint investigation with the OKX security team, it was found that some affected users had previously installed or used FomoPeek versions 1.1 to 1.2, which contained malicious code. SlowMist stated that there are modules in FomoPeek unrelated to normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting eight different attack methods that can automatically select the exploitation method based on device model and iOS version. Affected systems include iOS 12 to 18.7 and iOS 26 to 26.1. If the exploitation is successful, the application may break through the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files. In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist indicated that its analysis of captured plaintext traffic shows that the related attack functions are currently enabled and will run automatically on a regular basis. SlowMist recommends that users who have installed or used FomoPeek versions 1.1 to 1.2 immediately check for any anomalies in their assets, generate new private keys and mnemonic phrases on trusted devices that have never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and not continuing to use or reinstall FomoPeek.

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.

Coldcard releases new firmware to enhance security; affected users need to regenerate their mnemonic phrases and migrate their assets

Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following an emergency fix, focusing on addressing the security risks posed by previous mnemonic phrase generation attacks. Each newly generated mnemonic phrase must include at least one user entropy source, such as irregular key presses at least 65 times, physical dice rolls 50 times, or physical coin tosses 128 times, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2.The new firmware also adds pre-signing phased PSBT verification, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard states that this update aims to further reduce the risk of the device being attacked.The official reminder is that updating the firmware cannot fix existing mnemonic phrases generated by previously affected firmware. If a user's mnemonic phrase falls within the scope of this security announcement, they should first update the device, then generate and verify a brand new mnemonic phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signatures of the downloaded firmware.
app_icon
ChainCatcher Building the Web3 world with innovations.