Deep Tide TechFlow News, January 21 — According to 23pds, Chief Information Security Officer of Slow Fog Technology, a new security vulnerability has been discovered in the Snap Store application store on the Linux platform. Hackers hijack expired domain names to take over application publisher accounts and embed malicious code into cryptocurrency wallet applications.
Attackers monitor and register developer accounts associated with expired domains in the Snap Store, using these domain email addresses to trigger password resets, thereby taking over long-established trusted publisher identities. The compromised applications disguise themselves as well-known crypto wallets such as Exodus, Ledger Live, or Trust Wallet, with interfaces nearly indistinguishable from the genuine versions.
Currently, it has been confirmed that the publisher domains storewise[.]tech and vagueentertainment[.]com have been hijacked. These malicious applications trick users into entering their “wallet recovery seed phrases.” Once submitted, sensitive information is transmitted to the attacker’s server, leading to the theft of digital assets.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Snap Store security vulnerability allows hackers to steal users' crypto assets by hijacking expired domains
Deep Tide TechFlow News, January 21 — According to 23pds, Chief Information Security Officer of Slow Fog Technology, a new security vulnerability has been discovered in the Snap Store application store on the Linux platform. Hackers hijack expired domain names to take over application publisher accounts and embed malicious code into cryptocurrency wallet applications.
Attackers monitor and register developer accounts associated with expired domains in the Snap Store, using these domain email addresses to trigger password resets, thereby taking over long-established trusted publisher identities. The compromised applications disguise themselves as well-known crypto wallets such as Exodus, Ledger Live, or Trust Wallet, with interfaces nearly indistinguishable from the genuine versions.
Currently, it has been confirmed that the publisher domains storewise[.]tech and vagueentertainment[.]com have been hijacked. These malicious applications trick users into entering their “wallet recovery seed phrases.” Once submitted, sensitive information is transmitted to the attacker’s server, leading to the theft of digital assets.