Linux users beware: Snap Store experiences hacker attacks, impersonating wallets to steal seed phrases

robot
Abstract generation in progress

【BlockBeats】Recently, security research organizations disclosed that a new type of attack has been discovered in the Snap application store on the Linux platform. Attackers take over expired developer domains to successfully hijack long-standing publisher accounts and then deploy malicious applications. This method breaks through the traditional trust mechanisms of app stores and poses a serious threat to cryptocurrency wallet users.

Detailed Explanation of the Attack Method

The core strategy of the hackers is to monitor developer accounts in the Snap store associated with expired domains. Once a target domain is found to be invalid, the attacker immediately registers it, then uses the email associated with that domain to trigger a password reset for the account in the Snap Store, easily taking over the publisher identity that has long been established. The consequences of this are extremely serious—legitimate software installed by users years ago could be compromised overnight through official update channels, with malicious code embedded, often without the user’s awareness.

According to disclosed data, the publisher domains storewise.tech and vagueentertainment.com have been confirmed to be affected by such hijacking.

Deception Tactics and Fund Theft Process

The malicious applications that are tampered with usually disguise themselves as mainstream crypto wallets such as Exodus, Ledger Live, or Trust Wallet. Their interfaces are nearly indistinguishable from the genuine software, enough to confuse most users. After launching, the app first connects to remote servers for network verification, then, under various pretexts (such as “import existing wallet” or “verify account”), it诱导 users to input “wallet recovery seed phrases.” Once users submit these sensitive private key-related details, the data is immediately transmitted to the attacker’s server, and the victim’s funds are instantly transferred.

Because this type of attack cleverly exploits existing trust relationships, victims often suffer losses before they even realize something is wrong. For Linux users holding crypto assets, it is essential to stay vigilant, regularly check the sources of installed applications, and avoid installing wallet apps from third-party sources as current preventive measures.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
GasFeeVictimvip
· 9h ago
Is this the same trick again, taking over expired domains? Ridiculous. My wallet is still installed on Snap, I need to uninstall it quickly.
View OriginalReply0
All-InQueenvip
· 9h ago
Damn, this move is really clever... Even if the domain expires, you can still reclaim the account through reverse takeover. Feels like Snap's security measures are a bit weak.
View OriginalReply0
DataChiefvip
· 9h ago
Damn, that move is incredible... Even such a basic mistake as a domain expiration can be exploited like this, no wonder wallet users are falling for it one after another. Damn, the defense line of the Snap store is too weak, I really don’t dare to use Linux to install wallets anymore. This trick is too ruthless, it disappears after an update, there's no way to defend against it. Brothers, quickly check the sources of your applications, it's safer to compile them yourself. It's outrageous that something like domain renewal can become an attack entry point. Now it's all good, even official channels can't be trusted, it's all up to luck.
View OriginalReply0
NFTArtisanHQvip
· 9h ago
the whole "trust is a blockchain primitive" thing suddenly hits different when your supposedly legitimate wallet app turns into a trojan horse overnight lol... snap store really said "digital provenance? never heard of her"
Reply0
PonziDetectorvip
· 9h ago
Damn, this move is really clever... If a domain expires, you can take over the account? Snap's security design is a bit outrageous. If that's true, wallet users should quickly check if they've installed these apps. Reusing domain names to reset passwords... It seems many app stores have this vulnerability. Security research organizations should expose such trash vulnerabilities and stop the officials from sleeping all day. Official update channels distributing malicious code? If it directly infiltrates the internal system, that's serious. Hurry up and stop installing unknown wallet apps on Linux, it's too dangerous.
View OriginalReply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)