Close Menu
    What's Hot

    Lion Group ‘Secures $600 Million’ to Launch HYPE Treasury

    June 18, 2025

    VanEck’s Spot Solana ETF Appears on DTCC List as VSOL, Still Awaits SEC Approval

    June 18, 2025

    Ethereum Staking Hits Record 35 Million ETH, Locking 28% of Supply

    June 18, 2025
    Facebook Instagram X (Twitter)
    Token FlashToken Flash
    Subscribe
    • Home
    • Categories
      • CoinDesk Indices
      • Markets
      • News
      • Bitcoin
      • Policy
      • Blockchain
      • Cryptocurrency
      • Partner Content
      • Prediction
      • Opinion
      • Price Analysis
      • Technology
    • Price
    • NFT
    • Memecoins
    Token FlashToken Flash
    Home»Arbitrum»Over 13k Android and iOS crypto wallets compromised by malicious app: SlowMist
    Arbitrum

    Over 13k Android and iOS crypto wallets compromised by malicious app: SlowMist

    Token FlashBy Token FlashFebruary 27, 2025No Comments2 Mins Read

    Blockchain security experts uncovered a malicious mobile app that stole sensitive wallet data from users’ devices, leading to the theft of over $1.8 million in cryptocurrency.

    A fake app called BOM stole over $1.82 million in crypto by secretly accessing users’ private keys and mnemonic phrases, according to blockchain security firms SlowMist and OKX Web3 Security. In a Feb. 27 research report, SlowMist reported that the first unauthorized transactions with the app were noticed on Feb. 14.

    Over 13k Android and iOS crypto wallets compromised by malicious app: SlowMist - 1
    Analysis of stolen funds movement from the BOM creator across multiple DEXs | Source: SlowMist

    On-chain analysis showed identified main leaks, which led to further revealing that BOM was in fact a scam app luring victims into giving file access. Once granted, the app scanned device storage, took wallet data, and sent it to a remote server.

    The app asked for unnecessary permissions, like access to photos and media, what security experts called a “highly suspicious” behavior.

    “On iOS, the app first requests permissions, deceiving users with a message claiming the access is necessary for normal operation. This behavior is highly suspicious — as a blockchain-related application, it has no legitimate reason to require access to the photo gallery.”

    SlowMist

    SlowMist tracked stolen funds across multiple blockchains, estimating that the main hacker address (0x49aDd3E…) stole assets from at least 13,000 victims and transferred the funds through BNB Chain, Ethereum, Polygon, Arbitrum, and Coinbase’s Base.

    The stolen crypto included Tether (USDT), Ethereum (ETH), Wrapped Bitcoin (WBTC), and Dogecoin (DOGE).

    While it’s unclear who is behind the scheme, SlowMist analysts pointed out that the app’s backend services were offline during analysis, suggesting the attackers are already trying to cover their tracks. Some funds were swapped on decentralized exchange platforms such as PancakeSwap and OKX-DEX.

    Previous ArticleBinance to List MyShell (SHELL), Price Soars by 40%
    Next Article Ethereum Foundation Donates $1.25M to Alexey Pertsev's Defense in Netherlands Case Over Privacy Protocol
    Token Flash
    • Website

    Related Posts

    Lion Group ‘Secures $600 Million’ to Launch HYPE Treasury

    June 18, 2025

    VanEck’s Spot Solana ETF Appears on DTCC List as VSOL, Still Awaits SEC Approval

    June 18, 2025

    Ethereum Staking Hits Record 35 Million ETH, Locking 28% of Supply

    June 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Lion Group ‘Secures $600 Million’ to Launch HYPE Treasury

    June 18, 2025

    VanEck’s Spot Solana ETF Appears on DTCC List as VSOL, Still Awaits SEC Approval

    June 18, 2025

    Ethereum Staking Hits Record 35 Million ETH, Locking 28% of Supply

    June 18, 2025

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo
    Top Insights

    Lion Group ‘Secures $600 Million’ to Launch HYPE Treasury

    June 18, 2025

    VanEck’s Spot Solana ETF Appears on DTCC List as VSOL, Still Awaits SEC Approval

    June 18, 2025

    Ethereum Staking Hits Record 35 Million ETH, Locking 28% of Supply

    June 18, 2025
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.