Hackers steal $655K after picking MetaMask seed from iCloud backup

2022-04-19
Mirsad

MetaMask, cryptocurrency wallet provider, has sent out a notification to its community warning them that they may be susceptible to ongoing phishing attacks if they make use of Apple iCloud.

The security issue for Mac, iPad, and iPhone users relates to the default device settings. These settings store and automatically backup the users’ app data if they opted for automatic backups on their devices.

MetaMask has warned its community that the MetaMask app data includes the user’s seed phrase for their wallets and that the seed phrase will be stored online with automatic backups–posing a serious threat to the security of the user’s cryptocurrency funds.

Real phishing case

Unfortunately, the scenario above was already used against at least one MetaMask user who has lost over $655k as a result of a well-crafted phishing attack.

https://twitter.com/Serpent/status/1515545806857990149

We at Alvosec always advise users to protect the entire environment where you deal with your cryptocurrency funds. If you are using backup then that backup must be properly secured, if you are using wallet on your PC then OS must be secured, if wallet is used on mobile device, then it must be protected.

How attack happened

From what we know, attacker spoofed caller ID, in order to gain higher level of trust and from there this individual unfortunately gave attackers OTP code, so that they were able to login in his iCloud.

What we did, we tried to spoof ID to show users that it is possible to do that. Here is an example of it:

How to protect yourself — 5 tips

  • Double-check callers’ phone numbers, but keep in mind that caller IDs can be spoofed. Besides, remember that Apple will most likely not call you.
  • Never share any verification code with anyone.
  • Use a cold wallet to store your crypto assets to avoid phishing scams.
  • Disable iCloud backups for your MetaMask data via Settings > Profile > iCloud > Manage Storage > Backups. Also, turn off automatic iCloud backups via Settings > Apple ID/iCloud > iCloud > iCloud Backup.
  • Be smart with your personal information — scammers can use leaked information for phishing attempts.

Keep educating yourself by reading our blog.

Join our team

If you're interested in joining our team to assist in researching modern threats across web3, please don't hesitate to reach out to us.

Contact Us

Ready for Action?

Don’t hesitate to contact us if you need more information.
Let's Go!
ALVOSEC
BTC: bc1qnn4zfqqtexl4fkjk2vz6tk74sn92x326wwn0ph

linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram