Crypto Wallet Bitkeep Points To Malicious APK Packages For $8 Million Exploit

[ad_1]

Multi-chain crypto wallet BitKeep today reported a hacking incident that caused users to lose around $8 million in various cryptocurrencies.

The project team said preliminary investigation indicated that some APK package downloads were hacked and installed with malicious code injected by hackers.

APK, which stands for Android Package, is the file format used by Android to distribute and install applications. Often available outside of Google Play, APKs allow users to install apps on their Android phones from third-party sources, which, in turn, can lead to higher security risks.

If your funds are stolen, the app you download or update may be an unknown version (unofficial version) hijacked, the BitKeep team wrote in its official Telegram group.

BitKeep also advised users who downloaded the APK version to transfer their funds to the wallet downloaded from the App Store or Google Play. Ideally, users are prompted to do so using a newly created wallet address, since addresses created through the malicious APK may have been leaked to hackers.

$8 million reportedly drained from Bitkeep

Security firm PeckShield meanwhile estimated the total amount of stolen funds to be around $8 million from various digital assets.

Although some Twitter users are questioning this version of events, reporting instances of funds being stolen from officially downloaded wallets, Singapore-based BitKeep has doubled down on its preliminary investigation.

Today’s theft incident is mainly due to the hijacking of APK 7.2.9. If users are using the APK version, it is very likely that it is not the official version. So we have already let users transfer the funds to BitKeep Chrome plugin wallet as soon as possible, or to the app downloaded from the official store, and create a new wallet address, a Bitkeep spokesperson told Decrypt, adding that there is no problem. with the application downloaded from the official App Store or Google Play.

In a separate report, security firm Hacken said around $6 million worth of crypto assets were stolen, adding that the attack was still ongoing and the attacker was directly transferring user assets to multiple addresses. .

1. So far, about $6 million in assets have been stolen

But the attack is still ongoing and the attacker is directly transferring user assets to multiple addresses

Hacken (@hackenclub) December 26, 2022

According to Hacken, the top addresses with stolen funds were identified as a Binance Smart Chain Wallet and an Ethereum Wallet, with the latter seeing two large outgoing transactions worth 709 Ethereum (around $865,000) and 504 Ethereum (around $615). $000), respectively.

This isn’t the first hacking incident targeting BitKeep this year, as the wallet suffered an exploit in October that resulted in the loss of $1 million in Binance Coin (BNB) tokens.

Stay up to date with crypto news, get daily updates in your inbox.

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMiWGh0dHBzOi8vZGVjcnlwdC5jby8xMTc5MjAvY3J5cHRvLXdhbGxldC1iaXRrZWVwLXBvaW50cy1tYWxpY2lvdXMtYXBrLXBhY2thZ2VzLThtLWV4cGxvaXTSAQA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts