• bitcoinBitcoin (BTC) $ 123,388.00
  • ethereumEthereum (ETH) $ 4,510.46
  • xrpXRP (XRP) $ 2.96
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,163.76
  • solanaSolana (SOL) $ 228.10
  • usd-coinUSDC (USDC) $ 0.999749
  • staked-etherLido Staked Ether (STETH) $ 4,503.95
  • dogecoinDogecoin (DOGE) $ 0.251668
  • tronTRON (TRX) $ 0.341334
  • cardanoCardano (ADA) $ 0.833611
  • wrapped-stethWrapped stETH (WSTETH) $ 5,477.03
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,862.96
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 123,345.00
  • chainlinkChainlink (LINK) $ 21.94
  • ethena-usdeEthena USDe (USDE) $ 0.999579
  • hyperliquidHyperliquid (HYPE) $ 48.05
  • suiSui (SUI) $ 3.55
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • avalanche-2Avalanche (AVAX) $ 30.07
  • stellarStellar (XLM) $ 0.394678
  • wrapped-eethWrapped eETH (WEETH) $ 4,857.72
  • bitcoin-cashBitcoin Cash (BCH) $ 592.72
  • wethWETH (WETH) $ 4,505.81
  • hedera-hashgraphHedera (HBAR) $ 0.215635
  • litecoinLitecoin (LTC) $ 118.77
  • leo-tokenLEO Token (LEO) $ 9.66
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 123,381.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999670
  • usdsUSDS (USDS) $ 0.999753
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • crypto-com-chainCronos (CRO) $ 0.210732
  • the-open-networkToncoin (TON) $ 2.79
  • mantleMantle (MNT) $ 2.11
  • usdt0USDT0 (USDT0) $ 1.00
  • whitebitWhiteBIT Coin (WBT) $ 44.33
  • polkadotPolkadot (DOT) $ 4.12
  • moneroMonero (XMR) $ 320.54
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199024
  • uniswapUniswap (UNI) $ 8.03
  • okbOKB (OKB) $ 222.23
  • daiDai (DAI) $ 0.999601
  • aaveAave (AAVE) $ 284.47
  • ethenaEthena (ENA) $ 0.582176
  • pepePepe (PEPE) $ 0.000010
  • bitget-tokenBitget Token (BGB) $ 5.56
  • aptosAptos (APT) $ 5.42
  • nearNEAR Protocol (NEAR) $ 2.94
  • jito-staked-solJito Staked SOL (JITOSOL) $ 281.71
  • memecoreMemeCore (M) $ 2.04
  • aster-2Aster (ASTER) $ 1.86
  • bittensorBittensor (TAO) $ 314.36
  • story-2Story (IP) $ 9.53
  • ethereum-classicEthereum Classic (ETC) $ 19.35
  • ondo-financeOndo (ONDO) $ 0.912462
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • binance-staked-solBinance Staked SOL (BNSOL) $ 245.60
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,502.55
  • zcashZcash (ZEC) $ 165.25
  • worldcoin-wldWorldcoin (WLD) $ 1.25
  • usd1-wlfiUSD1 (USD1) $ 0.999146
  • c1usdCurrency One USD (C1USD) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999826
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.236685
  • internet-computerInternet Computer (ICP) $ 4.51
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.87
  • arbitrumArbitrum (ARB) $ 0.430190
  • pump-funPump.fun (PUMP) $ 0.006383
  • susdssUSDS (SUSDS) $ 1.07
  • pi-networkPi Network (PI) $ 0.259834
  • kucoin-sharesKuCoin (KCS) $ 16.03
  • gatechain-tokenGate (GT) $ 16.95
  • rocket-pool-ethRocket Pool ETH (RETH) $ 5,161.19
  • kaspaKaspa (KAS) $ 0.074502
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.031283
  • vechainVeChain (VET) $ 0.022710
  • cosmosCosmos Hub (ATOM) $ 4.13
  • algorandAlgorand (ALGO) $ 0.218097
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 48.02
  • flare-networksFlare (FLR) $ 0.024159
  • usdtbUSDtb (USDTB) $ 0.999109
  • hash-2Provenance Blockchain (HASH) $ 0.036367
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,752.75
  • render-tokenRender (RENDER) $ 3.47
  • sei-networkSei (SEI) $ 0.287527
  • falcon-financeFalcon USD (USDF) $ 0.998522
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,751.35
  • doublezeroDoubleZero (2Z) $ 0.495920
  • bfusdBFUSD (BFUSD) $ 0.999696
  • plasmaPlasma (XPL) $ 0.916623
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,871.48
  • filecoinFilecoin (FIL) $ 2.32
  • skySky (SKY) $ 0.067201
  • official-trumpOfficial Trump (TRUMP) $ 7.76
  • bonkBonk (BONK) $ 0.000020
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 123,219.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.574880
  • wbnbWrapped BNB (WBNB) $ 1,163.25
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,777.98
  • spx6900SPX6900 (SPX) $ 1.57
  • tether-goldTether Gold (XAUT) $ 3,898.39
  • immutable-xImmutable (IMX) $ 0.739957
  • jupiter-exchange-solanaJupiter (JUP) $ 0.452014
  • xdce-crowd-saleXDC Network (XDC) $ 0.073590
  • optimismOptimism (OP) $ 0.715678
  • nexoNEXO (NEXO) $ 1.27
  • injective-protocolInjective (INJ) $ 12.61
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 122,626.00
  • celestiaCelestia (TIA) $ 1.47
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 260.47
  • pax-goldPAX Gold (PAXG) $ 3,909.38
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,851.97
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999557
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.19
  • blockstackStacks (STX) $ 0.596607
  • curve-dao-tokenCurve DAO (CRV) $ 0.764291
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997387
  • lido-daoLido DAO (LDO) $ 1.16
  • sonic-3Sonic (S) $ 0.273853
  • aerodrome-financeAerodrome Finance (AERO) $ 1.14
  • msolMarinade Staked SOL (MSOL) $ 303.25
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 123,159.00
  • flokiFLOKI (FLOKI) $ 0.000100
  • clbtcclBTC (CLBTC) $ 123,680.00
  • ether-fiEther.fi (ETHFI) $ 1.80
  • pyth-networkPyth Network (PYTH) $ 0.159931
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,384.76
  • kaiaKaia (KAIA) $ 0.149077
  • the-graphThe Graph (GRT) $ 0.082685
  • fasttokenFasttoken (FTN) $ 2.02
  • myx-financeMYX Finance (MYX) $ 4.54
  • pendlePendle (PENDLE) $ 4.68
  • ripple-usdRipple USD (RLUSD) $ 0.999791
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,504.66
  • tbtctBTC (TBTC) $ 123,051.00
  • raydiumRaydium (RAY) $ 2.85
  • iotaIOTA (IOTA) $ 0.187391
  • dogwifcoindogwifhat (WIF) $ 0.757688
  • tezosTezos (XTZ) $ 0.710869
  • ousgOUSG (OUSG) $ 112.81
  • conflux-tokenConflux (CFX) $ 0.143947
  • theta-tokenTheta Network (THETA) $ 0.732841
  • galaGALA (GALA) $ 0.015688
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.86
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.08
  • stader-ethxStader ETHx (ETHX) $ 4,823.82
  • global-dollarGlobal Dollar (USDG) $ 0.999658
  • ethereum-name-serviceEthereum Name Service (ENS) $ 20.99
  • gtethGTETH (GTETH) $ 4,517.96
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998339
  • saros-financeSaros (SAROS) $ 0.257383
  • fartcoinFartcoin (FARTCOIN) $ 0.669811
  • the-sandboxThe Sandbox (SAND) $ 0.275378
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • newton-projectAB (AB) $ 0.008339
  • dexeDeXe (DEXE) $ 11.74
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.84
  • morphoMorpho (MORPHO) $ 1.87
  • starknetStarknet (STRK) $ 0.150811
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.251524
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,508.37
  • aethirAethir (ATH) $ 0.052604
  • vaultaVaulta (A) $ 0.401315
  • decentralandDecentraland (MANA) $ 0.331948
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,842.27
  • jasmycoinJasmyCoin (JASMY) $ 0.012639
  • zero-gravity0G (0G) $ 3.14
  • jito-governance-tokenJito (JTO) $ 1.59
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,962.84
  • swethSwell Ethereum (SWETH) $ 4,944.67
  • flowFlow (FLOW) $ 0.369761
  • bittorrentBitTorrent (BTT) $ 0.00000060
  • walrus-2Walrus (WAL) $ 0.400698
  • solmevSolMev (SN116) $ 2,398.72
  • beldexBeldex (BDX) $ 0.079771
  • swissborgSwissBorg (BORG) $ 0.596486
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.39
  • bitcoin-svBitcoin SV (BSV) $ 28.22
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 123,325.00
  • wormholeWormhole (W) $ 0.117690
  • usual-usdUsual USD (USD0) $ 0.997958
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,848.51
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 48.08
  • usdaiUSDai (USDAI) $ 1.06
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 36.84
  • wrapped-avaxWrapped AVAX (WAVAX) $ 30.07
  • apecoinApeCoin (APE) $ 0.558205
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,504.77
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • bybit-staked-solBybit Staked SOL (BBSOL) $ 252.90
  • wrapped-hypeWrapped HYPE (WHYPE) $ 48.23
  • instadappFluid (FLUID) $ 6.46
  • loaded-lionsLoaded Lions (LION) $ 0.016246
  • true-usdTrueUSD (TUSD) $ 0.999902
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,506.05
  • frax-etherFrax Ether (FRXETH) $ 4,478.52
  • ai-companionsAI Companions (AIC) $ 0.483432
  • sun-tokenSun Token (SUN) $ 0.024776

How a Trust Wallet User Lost Funds Overnight: Uncovering the Risks of Malicious Approvals

0 135

How a Trust Wallet User Lost Funds Overnight: Uncovering the Risks of Malicious Approvals

Last week, a Trust Wallet user suffered a sudden overnight loss of his funds, as detailed in a recent report shared with BeInCrypto. When he contacted the wallet to find out what had happened, they informed him that he had unknowingly granted permissions to malicious websites or applications.

Eve Lam, Chief Information Security Officer at Trust Wallet, said in an interview with BeInCrypto that most unauthorized cryptocurrency withdrawals originate from user issues. Dmytro Yasmanovych, Head of Compliance at Hacken, shared this perspective and provided guidance on steps users should take if they suspect their cryptocurrency wallet has been compromised.

An Overnight Loss

Last week, Matias, a crypto user from Chile, went to sleep without a care in the world. By the time he woke up, however, that all changed. According to details shared with BeInCrypto, when Matias accessed his Trust Wallet, he saw that his funds had been withdrawn from his account.

A situation like this had never happened to him in his five years using his mobile wallet. Matias soon noticed that at 8 a.m., a small amount of crypto had been deposited in his account. Shortly after that, his account was emptied.

Matias had no idea how such a thing could happen. After contacting Trust Wallet’s security team for an explanation, he learned that the problem originated from something he had done inadvertently.

“Based‬‭ on‬‭ our‬‭ internal‬‭ data‬‭ and‬‭ incident‬‭ response‬‭ investigations,‬‭ the‬‭ vast‬‭ majority‬‭ of‬‭ unauthorized‬‭ withdrawals are traced back to user-side issues,” Lam told BeInCrypto.

She explained many ways users can accidentally share sensitive information with malicious actors.

The Reality of User-Side Vulnerabilities

Trust Wallet’s analysis of its internal data and incident response investigations indicates that user-side issues cause most unauthorized cryptocurrency withdrawals.

These frequently involve leaked or compromised seed phrases, often resulting from social engineering tactics, insecure storage, and malicious smart contract approvals granted by users.

Device-level compromises and other incidents, like SIM swap attacks or theft of unlocked devices, also contribute to these unauthorized withdrawals.

“In‬‭ all‬‭ these‬‭ cases,‬‭ the‬‭ Trust‬‭ Wallet‬‭ app‬‭ itself‬‭ is‬‭ not‬‭ breached—the‬‭ issue‬‭ stems‬‭ from‬‭ the‬‭ external‬‭ environment‬‭ in‬‭ which‬‭ it’s‬‭ being‬‭ used‬‭ or‬‭ from‬‭ actions‬‭ taken‬‭ prior‬‭ to‬‭ installation,” Lam detailed.

These exploitation methods are now among the most common attack techniques for stealing cryptocurrency from mobile wallets.

User Error vs. Wallet Hacks: Where Do Most Losses Occur?

While Hacken lacks specific internal data on evolving mobile wallet attack trends, Yasmanovych explained to BeInCrypto that fund losses enabled by user actions are increasingly evident in the cases the cybersecurity company investigates.

“What‬‭ we’re‬‭ seeing‬‭ in‬‭ our‬‭ investigations‬‭ and‬‭ tooling‬‭ points‬‭ to‬‭ a‬‭ much‬‭ broader‬‭ issue:‬‭ most‬‭ large‬‭ scale‬‭ losses‬‭ in‬‭ crypto‬‭ today‬‭ are‬‭ less‬‭ about‬‭ mobile‬‭ malware‬‭ and‬‭ more‬‭ about‬‭ failures‬‭ in‬‭ signer‬‭ workflows,‬‭ interface‬‭ security,‬‭ and‬‭ access‬‭ control,” ‭Yasmanovych outlined.

Signer workflows involve authorizing cryptocurrency transactions with private keys. If these keys are compromised, it enables direct, unauthorized transaction signing. Meanwhile, flawed user interfaces (UIs) in crypto wallets and dApps can mislead users into harmful transactions. Attack methods include address poisoning, where attackers create similar-looking addresses to intercept funds.

They also deploy spoofed or malicious dApps designed to steal credentials or induce harmful transaction signings. Additionally, UI redressing involves deceptive overlays that trick users into performing unintended actions.

Oftentimes, users also unknowingly authorize malicious smart contracts.

“‬That’s‬‭ an‬‭ important‬‭ point—malicious‬‭ approvals‬‭ can‬‭ exist‬‭ before‬‭ Trust‬‭ Wallet‬‭ is‬‭ ever‬‭ installed, especially‬‭ if‬‭ a‬‭ user‬‭ interacted‬‭ with‬‭ Web3‬‭ apps‬‭ using‬‭ other‬‭ wallets‬‭ or‬‭ browsers,” Lam warned.

Once such a scenario occurs, it’s extremely hard to recover funds.

The Challenge of Fund Recovery

Given its status as a non-custodial wallet, Trust Wallet cannot reverse crypto transactions after a scam. Nevertheless, it assists users by performing on-chain analysis to trace stolen funds. It also provides detailed incident reports for law enforcement and sometimes collaborates with forensic firms.

Despite these efforts, the likelihood of recovering funds remains very low.

“Success‬‭ depends‬‭ heavily‬‭ on‬‭ early‬‭ action.‬‭ When‬‭ funds‬‭ reach‬‭ CEXs‬‭ and‬‭ users‬‭ promptly‬‭ file‬‭ [law enforcement] reports,‬‭ there’s‬‭ a‬‭ non-zero‬‭ chance‬‭ of‬‭ asset‬‭ freezes.‬‭ Across‬‭ all‬‭ scam-related‬‭ cases,‬‭ the‬‭ recovery‭ success‬‭ rate‬‭ is‬‭ low‬‭, but‬‭ when‬‭ centralized‬‭ endpoints‬‭ are‬‭ involved‬‭ and‬‭ law‬‭ enforcement‬‭ is‬‭ engaged‭ quickly, we’ve seen funds recovered, like a case we assisted in with ~$400k traced,” Lam told BeInCrypto.

As a result, user education remains the most effective way to prevent the issues that cause these losses.

Beyond Detection: What Preventative and Reactive Steps Are Crucial?

Trust Wallet has a built-in Security Scanner that flags real-time threats such as interactions with known scammer addresses, phishing sites, and suspicious approvals. But sometimes, these warning signs aren’t enough.

To safeguard cryptocurrency wallets, Yasmanovych advised that organizations and individuals should implement Cryptocurrency Security Standard (CCSS) controls for managing keys and ensuring operational security.

“Define‬‭ clear‬‭ actions‬‭ for‬‭ when‬‭ a‬‭ key‬‭ is‬‭ suspected‬‭ compromised,‬‭ including‬‭ revocation,‬‭ fund‬‭ migration, and audit, require [Multi-factor authentication] for all access to wallet systems and key handling interfaces, use‬‭ quorum-based‬‭ access‬‭ to‬‭ prevent‬‭ any‬‭ single‬‭ actor‬‭ from‬‭ compromising funds, [and] implement‬‭ encrypted,‬‭ geo-distributed‬‭ backups‬‭ with‬‭ clearly‬‭ defined‬‭ restore‬‭ procedures‬‭ to‬‭ ensure resilience without centralizing risk,” he explained.

Yasmanovych also stressed the importance of knowing what to do after these exploits happen.

“If you suspect your cryptocurrency wallet has been compromised, act immediately:‬ Report‬‭ the‬‭ incident‬‭ to‬‭ law‬‭ enforcement‬‭ and‬‭ engage‬‭ crypto forensics professionals‭, track‬‭ stolen‬‭ funds‬‭ using‬‭ chain‬‭ analysis‬‭ tools‬‭ to‬‭ monitor‬‭ movement‬‭ and‬‭ identify‬‭ mixers‬‭ or‬‭ exchanges involved, [and] submit requests to exchanges with KYC data for frozen fund attempts,” he added.

Despite these measures, the reality remains that user-side vulnerabilities continue to lead to losses.

The Enduring Challenge of User Vulnerabilities in Mobile Wallets

Even with proactive security measures, the ongoing regularity of fund losses raises significant concern. The regularity of these events highlights the persistent challenge of user-end vulnerabilities when using mobile wallets.

The path to a safer Web3 inherently requires a balance between strong security protocols and proactive user preparedness. Consequently, a sustained commitment to user education and the widespread adoption of these protective measures remains vital for effectively reducing exploits and establishing a more secure environment across the industry.

Source

Leave A Reply

Your email address will not be published.