News

BitKeep Exploiter Enticed Customers By Phishing Websites

Key Points:

  • The attacker created fake Bitkeep websites that each hosted an APK file that seemed to be Bitkeep wallet version 7.2.9.
  • Five networks were affected by the attack: BNB Chain, Tron, Ethereum, Polygon, and BNB Chain bridges.
According to research by blockchain analytics vendor OKLink, the Bitkeep vulnerability that happened on December 26 employed phishing sites to trick users into installing fraudulent wallets.

The attacker created a number of fictitious Bitkeep websites that each hosted an APK file that seemed to be Bitkeep wallet version 7.2.9. Users’ private keys or seed words were taken when they “updated” their wallets by downloading the malicious file, and they were delivered to the attacker.

Previously, Coincu reported that on-chain data services provider OKLink has made public the total loss that was caused by the BitKeep hack, which is close to $31 Million with 50 different hacker addresses.

The malicious software grabbed the users’ keys in an unencrypted form, although the report did not specify how. As part of the “upgrade,” it may have only required the customers to re-enter their seed words, which the program could have recorded and forwarded to the attacker.

After obtaining users’ private keys, the attacker unstacked all assets and transferred all funds to five wallets under their command. From there, they attempted to withdraw part of the money via centralized exchanges: 2 Ethereum (ETH) and 100 USDC were sent to Binance, and 21 ETH were sent to Changenow.

Five networks were affected by the attack: BNB Chain, Tron, Ethereum, Polygon, and BNB Chain bridges. Some of the coins were connected to Ethereum via the bridges Biswap, Nomiswap, and Apeswap. The hack resulted in the theft of cryptocurrency valued at over $13 million in total.

How the attacker persuaded visitors to access the bogus websites is still unclear. The official Google Play Store page for BitKeep has a link that directs people there, but it does not include an APK file for the program at all.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Website: coincu.com

Thana

Coincu News

Thana

I am a news editor at Coincu, where I produce daily editorial packages and manage the knowledge and review article sections. Before journalism, I earned a Bachelor's degree in Global Logistics and Supply Chain Management from Northampton University and studied news journalism at Press Association Training.

Recent Posts

Best Cryptos to Join in November 2024: Top Picks You Can’t Miss!

We've got a few must-watch cryptos that might just be what you’re after. From established…

49 minutes ago

Dogecoin Price Under Pressure: DOGE Could Dive 25% if This Happens, but This Alternative Will Rise 43,230%

The Dogecoin price peak is increasing selling pressure on DOGE, but experts have quickly identified…

1 hour ago

Why Peanut the Squirrel (PNUT) Surged 400% in a Single Day?

As Bitcoin nears $90,000 ATH, Peanut the Squirrel (PNUT) leads the "super cycle of memecoins,"…

2 hours ago

Qubetics Breaks $2M with 2,000+ Holders: Top Crypto to Invest in While ETH Whale Snaps Up $23M and SOL Hits 181,000 Launches

Qubetics tops crypto charts with $2M+ raised and 2,000+ holders. Ethereum whale grabs $23M in…

3 hours ago

Elon Musk Lawsuit Over Dogecoin Manipulation Comes to an End

Investors withdrew their appeal and motions in Elon Musk lawsuit over Dogecoin manipulation and fraud.

5 hours ago

Kraken Layer 2 Ink Launched Fault Proof and First Stage

Kraken Layer 2 Ink introduced self-withdrawal to Ethereum, transaction review capabilities, and a security committee…

7 hours ago

This website uses cookies.