MetaMask and Phantom send alarming warnings about crypto wallets

The key to your seemingly secure cryptocurrency wallet is potentially not as well hidden as most think. As it turns out, there’s a vulnerability within your browser that may give threat actors unbridled access to your crypto investments. MetaMask and Phantom are both concerned.

MetaMask DOWNLOAD

The vulnerability was first spotted by Halborn, an organization dedicated to the safety of blockchain and cryptocurrency. Halborn discovered a flaw in how browsers save information in September of 2021 and subsequently reported it to wallet vendors like MetaMask and Phantom for further investigation. 

Anyone who’s had any exposure to the world of cryptos will know that wallets don’t work with passwords like everything else. Instead, most require you to enter a key comprised of numerous words in a specific order. This essentially makes it impossible for threat actors to use the usual means of determining your password, as there isn’t a password to speak of. Instead, you have a phrase of random common nouns that means nothing to anyone except you. 

The newly discovered vulnerability, tracked as CVE-2022-32969, is caused by how browsers handle the safekeeping of this randomly generated phrase. There’s a difference in the way browsers regard information entered into password fields – the box where you enter a standard password – and any other text field.

Unfortunately, the text fields used for the randomly generated key you use for your crypto wallets don’t count as password fields and therefore any text entered into them saves to the device’s disk drive as plain text. The reason why standard text fields are handled this way is so that your PC can recover information you’ve entered after a crash. That information shouldn’t include cryptocurrency wallet credentials, but unfortunately, it does. 

According to Halborn, the issue is intensified when users check the ‘Show Secret Recovery Phrase’ checkbox while accessing their wallets. This check box specifically triggers local storage and is unfortunately incredibly commonly used due to crypto wallet phrases being long and difficult to memorize due to their randomly generated and illogical nature. Once this seed phrase is stored on your device’s disk drive, it doesn’t matter if you restart or reboot your system; the wallet key will remain on your device and accessible to threat actors. 

In other news, there are numerous phishing pop-ups known to appear on big crypto websites. It seems the future may not rest safely with cryptocurrency until all of these vulnerabilities are sorted out.

Beware these phishing pop-ups on big crypto websites READ MORE

Beware these phishing pop-ups that are appearing on big crypto websites

With Bitcoin, cryptocurrencies, blockchain technology, and Web3 gaining more and more traction and widespread adoption every day, we are seeing increasing numbers of scams and cyberattacks targeting the crypto sector. We recently reported on NFT scams targeting a Pokémon-inspired project and another attack that was hiding malware in fake job offers sent to potential NFT artists. These are rife right now and a new scam has been spotted that is targeting MetaMask users.

MetaMask Download Now

Metamask is an extremely popular and easy to use cryptocurrency wallet that allows users to interact with blockchains and Web3 decentralized apps (dapps). Chances are, if you are into crypto you will have a Metamask and if you are just getting started, the first thing you’ll likely do is get yourself one. Metamask is available as a mobile app or as a browser plugin for web browsers like Chrome.

This new phishing scam that is targeting MetaMask users has been popping up on some of the biggest and most used sites in crypto including Etherscan, CoinGecko and DexTools. The pop-up includes a Bored Apes logo and the common words “Connect with MetaMask”. The scammers hope the pop-up looks official enough for users to connect their wallets. Then if users connect their wallets to the scam pop-up, the scammers will empty them of all funds.

Again here, we have to stress that these new types of attacks are not searching for data, they are direct ways for scammers to steal funds from you immediately. As such, if you are using cryptocurrencies and holding them in wallets such as MetaMask, you have to be extremely careful whenever you connect your wallet to any third-party site. It is more important than ever to know how to spot a phishing scam.

Fortunately, the affected websites seem to have spotted this new scam quickly and acted upon it before it could cause too much damage. TechRadar reports that CoinGecko identified the source of the popup as Coinzilla, which is a crypto industry advertising network. It has since been removed from the website.

This latest scam just further reiterates the need for vigilance when online. If you are a Microsoft Windows user, you should check out our Best Windows Security Tips guide now to get ahead of the game.