Linux users should be aware of a new type of attack on the Snap Store, where hackers can take over developers' identities to trick users into submitting their seed phrase.
BlockBeats News, January 21st, SlowMist CISO 23pds posted on social media that Linux users need to be aware of a new attack in the Snap Store. A hijacked domain name is used as a backdoor to steal users' encrypted assets. Tampered apps masquerade as well-known crypto wallets like Exodus, Ledger Live, or Trust Wallet, tricking users into entering their "wallet recovery seed phrase," leading to fund theft.
It is reported that the attackers have now shifted to monitoring developer accounts in the Snap Store with expired associated domains. Once a target domain is found to be expired, the attacker promptly registers it, then uses the domain's email to initiate a password reset on the Snap Store, thus taking over the identity of a long-established trusted publisher.
23pds explained that this means software that users installed and trusted for years may overnight be compromised by hackers injecting malicious code through the official update channel. It has been confirmed that two publisher domains, storewise[.]tech and vagueentertainment[.]com, have been hijacked using this method. The tampered apps usually pretend to be reputable crypto wallets like Exodus, Ledger Live, or Trust Wallet, with interfaces almost indistinguishable from the genuine ones.
Upon app launch, it will first connect to a remote server for network verification, then lure users into entering their "wallet recovery seed phrase." Once users submit this sensitive information, it is immediately sent to the attacker's server, resulting in fund theft. Due to exploiting the existing trust relationship, such attacks often succeed before the victims realize.
You may also like

Business Opportunities of Tokenized Stocks

In-depth research report on the Resolv protocol hacking incident, who is the final payer?

Crypto Market Sees Large Liquidations: $272 Million in Long Positions Affected
Key Takeaways In the last 24 hours, $272 million worth of contracts were liquidated across the entire crypto…

Whale Increases BTC Shorts and Bets on Crude Oil: A Strategic Crypto Move
Key Takeaways A prominent whale, known as “UnRektCapital,” has strategically escalated its short position in Bitcoin while simultaneously…

Hackers in Brazil Use Fake Google Play Store to Steal Cryptocurrency
Key Takeaways Hackers in Brazil are exploiting fake Google Play Store pages to spread Android malware. Infected devices…

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets

Understanding x402 and MPP in One Article: Two Routes for Agent Payments

Particle Founder: The entrepreneurial insights I have gained the most from in the past year

Huang Renxun's latest podcast transcript: The future of Nvidia, the development of embodied intelligence and agents, the explosion of inference demand, and the public relations crisis of artificial intelligence

OKX Ventures Research Report: AI Agent Economic Infrastructure Research Report (Part 1)

The migration of settlement rights: B18 and the institutional starting point of on-chain banks

From Tencent and Circle: Looking at the Simple and Difficult Questions of Investment

The second half of stablecoins no longer belongs to the crypto circle

Cursor "Shell" Kimi Controversy Reversed: From Copyright Infringement Allegations to Authorized Collaboration, China's Open Source Model Once Again Becomes a Global AI Foundation

The Real Reason Tokens Don't Sell: 90% of Crypto Projects Overlook Investor Relations
Business Opportunities of Tokenized Stocks
In-depth research report on the Resolv protocol hacking incident, who is the final payer?
Crypto Market Sees Large Liquidations: $272 Million in Long Positions Affected
Key Takeaways In the last 24 hours, $272 million worth of contracts were liquidated across the entire crypto…
Whale Increases BTC Shorts and Bets on Crude Oil: A Strategic Crypto Move
Key Takeaways A prominent whale, known as “UnRektCapital,” has strategically escalated its short position in Bitcoin while simultaneously…
Hackers in Brazil Use Fake Google Play Store to Steal Cryptocurrency
Key Takeaways Hackers in Brazil are exploiting fake Google Play Store pages to spread Android malware. Infected devices…