价格: $0.20874 -0.8519%
市值: 30.94B 1.0952%
成交额 (24h): 2.05B 0%
统治地位: 1.0952%
Price: $0.20874 -0.8519%
市值: 30.94B 1.0952%
成交额 (24h): 2.05B 0%
统治地位: 1.0952% 1.0952%
  • 价格: $0.20874 -0.8519%
  • 市值: 30.94B 1.0952%
  • 成交额 (24h): 2.05B 0%
  • 统治地位: 1.0952% 1.0952%
  • 价格: $0.20874 -0.8519%
首页 > 资讯新闻 > 超过13K Android和iOS加密钱包被恶意应用程序妥协:Slowmist

Over 13k Android and iOS crypto wallets compromised by malicious app: SlowMist

超过13K Android和iOS加密钱包被恶意应用程序妥协:Slowmist

发布: 2025/02/27 15:36 阅读: 656

原文作者:crypto.news

原文来源:https://coinmarketcap.com/community/articles/67c010d01a34621d84dac1e4

Blockchain security experts have uncovered a malicious mobile application, BOM, responsible for stealing over $1.82 million in cryptocurrency. According to blockchain security firms SlowMist and OKX Web3 Security, the app secretly accessed users' private keys and mnemonic phrases.

区块链安全专家发现了一个恶意移动应用程序BOM,负责窃取超过182万美元的加密货币。 根据区块链安全公司的说法,该应用程序秘密访问了用户的私钥和助记符。

Analysis of stolen funds movement from the BOM creator across multiple DEXs | Source: SlowMist

分析来自多个DEX的BOM创建者的偷资金运动|资料来源:慢速派

SlowMist's February 27th report detailed the first unauthorized transactions occurring on February 14th. On-chain analysis revealed BOM as a fraudulent app that tricked users into granting excessive file access permissions. Once granted, the app scanned the device, exfiltrated wallet data, and transmitted it to a remote server.

Slowmist的2月27日报告详细介绍了2月14日进行的首次未经授权的交易。 链分析显示BOM是一个欺诈性应用程序,它欺骗用户授予过多的文件访问权限。 批准后,该应用程序扫描了设备,删除钱包数据,然后将其传输到远程服务器。

The app's request for unnecessary permissions, such as access to photos and media, was flagged as highly suspicious. SlowMist noted, "On iOS, the app deceptively requests permissions, claiming this access is necessary for normal operation. This behavior is highly suspicious—a blockchain application has no legitimate reason to require access to the photo gallery."

该应用程序要求的不必要权限的请求(例如对照片和媒体的访问)被标记为高度可疑。 Slowmist指出:“在iOS上,该应用程序欺骗性请求权限,声称此访问是正常操作的必要条件。此行为高度可疑 - 区块链应用程序没有正当理由需要访问照相馆。”

SlowMist tracked the stolen funds across multiple blockchains, identifying at least 13,000 victims. The main hacker address (0x49aDd3E…) transferred funds through BNB Chain, Ethereum, Polygon, Arbitrum, and Coinbase's Base. Stolen cryptocurrencies included Tether (USDT), Ethereum (ETH), Wrapped Bitcoin (WBTC), and Dogecoin (DOGE).

Slowmist追踪了跨多个区块链中被盗的资金,确定了至少13,000名受害者。主黑客地址(0x49Add3e…)通过BNB链,以太坊,多边形,索赔和Coinbase的基础转移了资金。 被盗的加密货币包括Tether(USDT),以太坊(ETH),包裹的比特币(WBTC)和Dogecoin(Doge)。

While the perpetrators remain unidentified, SlowMist analysts observed the app's backend services were offline during their investigation, suggesting an attempt to conceal their activities. Some funds were laundered through decentralized exchanges like PancakeSwap and OKX-DEX.

虽然肇事者仍然身份不明,但慢慢分析师观察到该应用程序的后端服务在调查过程中脱机,这表明试图掩盖他们的活动。 一些资金通过分散的交易所(如Pancakeswap和Okx-Dex)洗钱。

精选专题

  • 狗狗币鲸鱼活动
    狗狗币鲸鱼活动
    通过我们的综合分析,了解狗狗币鲸鱼活动的最新见解。了解趋势、模式以及这些鲸鱼对狗狗币市场的影响。随时了解我们的专家分析,并在您的加密货币之旅中保持领先。
  • 狗狗币挖矿
    狗狗币挖矿
    狗狗币挖矿是向狗狗币区块链添加新交易块的过程。矿工因其工作而获得新的狗狗币奖励。本主题提供与狗狗币挖矿相关的文章,包括如何挖矿狗狗币、最好的挖矿硬件和软件以及狗狗币挖矿的盈利能力。
  • SpaceX 星舰发射
    SpaceX 星舰发射
    本主题提供与 SpaceX 星舰发射相关的文章,包括发射日期、任务详细信息和发射状态。通过此信息丰富且全面的资源,了解最新的 SpaceX 星际飞船发射情况。
  • 模因之王:狗狗币
    模因之王:狗狗币
    本主题提供与最流行的模因相关的文章,包括“模因之王:狗狗币”。 Memecoin 已成为加密货币领域的主导者。这些数字资产之所以受欢迎有多种原因。他们推动了区块链最具创新性的方面。