{"id":192587,"date":"2020-01-04T15:55:50","date_gmt":"2020-01-04T12:55:50","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/dodgy-google-chrome-extension-reportedly-causes-16k-crypto-theft\/"},"modified":"2020-01-04T15:55:50","modified_gmt":"2020-01-04T12:55:50","slug":"dodgy-google-chrome-extension-reportedly-causes-16k-crypto-theft","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/dodgy-google-chrome-extension-reportedly-causes-16k-crypto-theft\/","title":{"rendered":"Dodgy Google Chrome extension reportedly causes $16K crypto theft"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/zcash-796x448.jpg\" \/><\/p>\n<div>\n<p>A malicious Google Chrome extension reportedly cost one user around $16,000 worth of cryptocurrency.<\/p>\n<p>A bogus extension called \u201cLedger Secure,\u201d that passes itself off as a cryptocurrency wallet, is believed to be responsible for the loss, Decrypt reports. The app allegedly sends a user\u2018s seed phrase back to its creators. With the seed phrase, bad actors can access another individual\u2019s cryptocurrency illegitimately.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">In <a href=\"https:\/\/twitter.com\/hackedzec?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">@hackedzec<\/a>&#8216;s case, 600ZEC were taken from his Ledger Nano by the extension author.<\/p>\n<p>That&#8217;s around 2.3BTC \/USD$16k \u2013 bigtime pain.<a href=\"https:\/\/twitter.com\/jeremyrwelch?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">@jeremyrwelch<\/a> from <a href=\"https:\/\/twitter.com\/CasaHODL?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">@CasaHODL<\/a> presented on precisely this risk at Baltic HoneyBadger 2019 in Riga \u2013 malign browser extensions.<\/p>\n<p>What&#8217;s to learn??<\/p>\n<p>\u2014 WizardofAus ??\u26a1? [Jan3?] (@BTCSchellingPt) <a href=\"https:\/\/twitter.com\/BTCSchellingPt\/status\/1212675633261596677?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">January 2, 2020<\/a><\/p>\n<\/blockquote>\n<p>It should be noted that French company Ledger is not affiliated to the \u201cLedger Secure\u201d extension.<\/p>\n<p>In a tweet following the phishing scam, Ledger warned that \u201cLedger Secure\u201d is not a legitimate application. It urged users to report the extension to encourage Google to remove it.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u26a0\ufe0fPHISHING ALERT\u26a0\ufe0f<\/p>\n<p>A Chrome extension malware has been detected called &#8220;Ledger Secure&#8221;. This is NOT a legitimate Ledger application<\/p>\n<p>DO NOT use it and contact us if you&#8217;ve installed it:https:\/\/t.co\/bRaDjYHZbY<\/p>\n<p>You can help by reporting the extension:https:\/\/t.co\/oltHbtA8RR<\/p>\n<p>\u2014 Ledger Support (@Ledger_Support) <a href=\"https:\/\/twitter.com\/Ledger_Support\/status\/1212678944207585280?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">January 2, 2020<\/a><\/p>\n<\/blockquote>\n<p>The affected Twitter user, now going by the handle \u201chackedzec\u201d, claims the extension led to them losing 600 ZEC \u2014 about $16,000 at the time of writing.<\/p>\n<p>The victim says they only entered their seed phrase into their computer once, about two years ago. They also say they photocopied their seed phrase using a WiFi-connected printer once as well. It\u2019s difficult to say if these two instances were to blame. How the malicious extension got hold of their seed phrase is unclear.<\/p>\n<p>The victim became aware of the shady extension after they reportedly found a file on their computer that linked to a <a href=\"https:\/\/twitter.com\/Tester79265062\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Twitter account for the fake<\/a> \u201cLedger Secure\u201d extension. The Twitter account appears to pass itself off as a legitimate Ledger account.<\/p>\n<p>It seems Google is still a bit hit-and-miss when it comes to removing illicit cryptocurrency apps from its Play Store and browser extensions.<\/p>\n<p>This news comes in the same week that MetaMask was removed from \u2014 and swiftly reinstated to \u2014 Google\u2019s Play Store after thinking it was a cryptocurrency mining app.<\/p>\n<p class=\"c-post-pubDate\">\n                                    Published January 3, 2020 \u2014 12:39 UTC\n                                <\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script data-src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&amp;appId=378011798897423&amp;version=v2.6\" id=\"socialSrcFacebook\" type=\"text\/template\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/hardfork\/2020\/01\/03\/dodgy-google-chrome-extension-seed-phrase-leak-16k-theft-zcash\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] A malicious Google Chrome extension reportedly cost one user around $16,000 worth of cryptocurrency. A bogus extension called \u201cLedger Secure,\u201d that passes itself off as a cryptocurrency wallet, is believed to be responsible for the loss, Decrypt reports. The app allegedly sends a user\u2018s seed phrase back to its creators. With the seed phrase, &hellip;<\/p>\n","protected":false},"author":1,"featured_media":192588,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-192587","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/192587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=192587"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/192587\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/192588"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=192587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=192587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=192587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}