ZeroHour
Schneier on Securitypublished ()ingested

Chrome Extension Stealing Cryptocurrency Keys and Passwords

lowPhishing & fraudimportance 30

Indicators of compromiseAll →

TypeIndicatorContext
domainerc20wallet.tkd through its interface to a third-party website located at erc20wallet[.]tk . Second, the extension also actively injects malicious J
Full article151 words · extracted from schneier.com · click to collapse

A malicious Chrome extension surreptitiously steals Ethereum keys and passwords:

According to Denley, the extension is dangerous to users in two ways. First, any funds (ETH coins and ERC0-based tokens) managed directly inside the extension are at risk.

Denley says that the extension sends the private keys of all wallets created or managed through its interface to a third-party website located at erc20wallet[.]tk.

Second, the extension also actively injects malicious JavaScript code when users navigate to five well-known and popular cryptocurrency management platforms. This code steals login credentials and private keys, data that it’s sent to the same erc20wallet[.]tk third-party website.

Another example of how blockchain requires many single points of trust in order to be secure.

Tags: blockchain, Chrome, cryptocurrency, fraud, keys, passwords, theft

Posted on January 3, 2020 at 6:09 AM15 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2020/01/chrome_extensio.html