• Contact Us
  • Homepages
Newsletter
Today Bitcoin News
Advertisement
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Contact Us
No Result
View All Result
Today Bitcoin News
No Result
View All Result
Home NEWS Cybersecurity

BitKeep exploiter used phishing sites to lure in users: Report

news by news
December 27, 2022
in Cybersecurity, Hackers, Hacks, Mobile Wallet, Phishing, Security, wallet
0
BitKeep exploiter used phishing sites to lure in users: Report
191
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

OpenAI commits $1M to support AI-driven cybersecurity initiatives

OpenAI commits $1M to support AI-driven cybersecurity initiatives

June 3, 2023
Tornado Cash governance control set to be restored as voters approve proposal

Tornado Cash governance control set to be restored as voters approve proposal

May 28, 2023

The attacker appears to be attempting to cash out funds using Binance and Changenow.

The Bitkeep exploit that occurred on Dec. 26 used phishing sites to fool users into downloading fake wallets, according to a report by blockchain analytics provider OKLink.

The report stated that the attacker set up several fake Bitkeep websites which contained an APK file that looked like version 7.2.9 of the Bitkeep wallet. When users “updated” their wallets by downloading the malicious file, their private keys or seed words were stolen and sent to the attacker.

【12-26 #BitKeep Hack Event Summary】
1/n

According to OKLink data, the bitkeep theft involved 4 chains BSC, ETH, TRX, Polygon, OKLink included 50 hacker addresses and total Txns volume reached $31M.

— OKLink (@OKLink) December 26, 2022

The report did not say how the malicious file stole the users’ keys in an unencrypted form. However, it may have simply asked the users to re-enter their seed words as part of the “update,” which the software could have logged and sent to the attacker.

Once the attacker had users’ private keys, they unstaked all assets and drained them into five wallets under the attacker’s control. From there, they tried to cash out some of the funds using centralised exchanges: 2 ETH and 100 USDC were sent to Binance, and 21 ETH were sent to Changenow.

The attack happened across five different networks: BNB Chain, Tron, Ethereum, and Polygon, and BNB Chain bridges Biswap, Nomiswap, and Apeswap were used to bridge some of the tokens to Ethereum. In total, over $13 million worth of crypto was taken in the attack.

Related: Defrost v1 hacker reportedly returns funds as ‘exit scam’ allegations surface

It is not yet clear how the attacker convinced users to visit the fake websites. The official website for BitKeep provided a link that sent users to the official Google Play Store page for the app, but it does not carry an APK file of the app at all.

The BitKeep attack was first reported by Peck Shield at 7:30 a.m. UTC. At the time, it was blamed on an “APK version hack.” This new report from OKLink suggests that the hacked APK came from malicious sites, and that the developer’s official website has not been breached.

Share76Tweet48

Related Posts

OpenAI commits $1M to support AI-driven cybersecurity initiatives

OpenAI commits $1M to support AI-driven cybersecurity initiatives

by news
June 3, 2023
0

As criminals devise innovative ways to exploit AI for malicious intentions, OpenAI remains committed to equipping “defenders” with the necessary...

Tornado Cash governance control set to be restored as voters approve proposal

Tornado Cash governance control set to be restored as voters approve proposal

by news
May 28, 2023
0

A total of 517,000 token votes favored the proposal, with none opposing it. The governance tokenholders of Tornado Cash will...

SEC warns that Filecoin ‘meets definition of a security’ — Grayscale

SEC warns that Filecoin ‘meets definition of a security’ — Grayscale

by news
May 18, 2023
0

The regulator has asked Grayscale to withdraw its application for a Filecoin Trust product, saying it believes its underlying asset...

LayerZero partners with Immunefi to launch $15M bug bounty

LayerZero partners with Immunefi to launch $15M bug bounty

by news
May 17, 2023
0

The program offers a maximum reward of $15 million for anyone who identifies vulnerabilities classified as high severity. Cross-chain messaging...

Coinbase execs respond to SEC’s Wells notice in person and on video

Coinbase execs respond to SEC’s Wells notice in person and on video

by news
April 28, 2023
0

Coinbase founder Brian Armstrong and chief legal officer Paul Grewal spoke about the company’s Wells notice from the SEC on...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

Bitcoin faces do-or-die weekly, monthly close with macro bull trend at stake

February 18, 2023
Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

Ethereum price resistance at $1,750 could reflect traders’ anxiety over the Shanghai upgrade

March 1, 2023
Silvergate stock plunges 31% after delayed filing raises doubts over future

Silvergate stock plunges 31% after delayed filing raises doubts over future

March 2, 2023
ShapeShift responds to Sen. Warren’s comments to ‘set the record straight’

ShapeShift responds to Sen. Warren’s comments to ‘set the record straight’

February 19, 2023

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Cboe Digital receives nod for margin trades on its crypto futures exchange

Cboe Digital receives nod for margin trades on its crypto futures exchange

June 6, 2023
SEC’s Binance suit contains heavy mix of predictable charges, novel revelations

SEC’s Binance suit contains heavy mix of predictable charges, novel revelations

June 6, 2023
Fines and regulation: The ever-growing landscape of crypto compliance

Fines and regulation: The ever-growing landscape of crypto compliance

June 5, 2023
JPMorgan uses blockchain for 24/7 dollar transfers with Indian banks

JPMorgan uses blockchain for 24/7 dollar transfers with Indian banks

June 5, 2023
Today Bitcoin News

© 2022

Navigate Site

  • 2022
  • 2023
  • 5G
  • 5G network
  • Altcoin
  • bank of china
  • bank of england
  • Bank of Japan
  • Bank of Russia
  • Binance Academy
  • BingChatGPT
  • Bitcoin
  • Changpeng Zhao
  • ChatGPT Web3
  • coinbase
  • CoinDesk
  • CoinMarketCap

Follow Us

No Result
View All Result
  • Contact Us
  • Homepages

© 2022