Chrome Extension Caught Stealing Crypto-Wallet Private Keys (zdnet.com) 28
A Google Chrome extension was caught injecting JavaScript code on web pages to steal passwords and private keys from cryptocurrency wallets and cryptocurrency portals. From a report: The extension is named Shitcoin Wallet (Chrome extension ID: ckkgmccefffnbbalkmbbgebbojjogffn), and was launched last month, on December 9. According to an introductory blog post, Shitcoin Wallet lets users manage Ether (ETH) coins, but also Ethereum ERC20-based tokens -- tokens usually issued for ICOs (initial coin offerings). Users can install the Chrome extension and manage ETH coins and ERC20 tokens from within their browser, or they can install a Windows desktop app, if they want to manage their funds from outside a browser's riskier environment. However, the wallet app wasn't what it promised to be. Yesterday, Harry Denley, Director of Security at the MyCrypto platform, discovered that the extension contained malicious code. According to Denley, the extension is dangerous to users in two ways. First, any funds (ETH coins and ERC0-based tokens) managed directly inside the extension are at risk.
Nobody Could Have Foreseen... (Score:5, Insightful)
Re: (Score:2)
Re: (Score:2)
Freakin' Lahey [wikipedia.org]
The NAME didn't provide a clue? (Score:4, Insightful)
The name wasn't a dead giveaway? (Score:5, Interesting)
I mean really, if you're going to put your crypto coins in an extension called "Shitcoin Wallet", you should've seen this coming.
It's like lighting one of those compressed sawdust firelogs on your coffee table, then being genuinely surprised when it burns your house down.
Of course it attacked BTC and ETH... (Score:2)
Re: (Score:2)
Much value! Very stability!
Re: (Score:2)
With a name like that (Score:3)
Folks deserve what they got if they actually use something with that name
Re: (Score:1)
Re: (Score:3)
The first rule of crypto is to treat your wallet like cash.
If you fail at that, you deserve to be fucked.
If you think that's "victim blaming" and that's not okay, then I lost $100 last week. I was holding it while walking down the street and a pigeon came by and took it.
Clearly, I as the victim have no personal responsibility. Please make sure to coddle me, tell me it's not my fault, and donate to replace my $100.
Re: (Score:2)
In two ways. What is the tooth? (Score:3)
Are there actual editors anymore?
Re: (Score:2)
No. MissMash and BeauHD captured Patrick, Jeff, Rob, and Keith and fed them to a pack of ravinous wolves. The wolves said they where delicious.
Re: (Score:2)
So, Wall Street wolves then?
Omg I'm wiped out! (Score:1)
Re: (Score:2)
Wait..... you can sell your kids to science?
Re: (Score:2)
step kids too?
Hail 1% (Score:1)
This is the same month that google has banned legit wallet (metamask). If I didn't know better I'd think google is trying to make cryptocurrency look bad. Well done Google.
The only real investment is spy500, millennials with imaginary currencies should forever stay poor. In tendies we trust!
Re: (Score:2)
https://medium.com/@jimmysong/... [medium.com]
https://www.whatbitcoindid.com... [whatbitcoindid.com]
https://www.reddit.com/r/Bitco... [reddit.com]
Seriously? (Score:2)
I know we're all supposed to be too cool for school these days, but "shitcoin wallet"?
Yeah, nothing could go wrong there, with a serious operation like that.
625 Stupid people (Score:2)
"At the time of writing, the extension was still available for download through the official Google Chrome Web Store, where it listed 625 installs."
Help me out here. I'm not into cryptocurrency, other than a tangential knowledge of what it is and a general idea of how it works. Why would someone want/need a chrome plugin to manage their wallet? What value does it add? (assuming you use one that isn't stealing your shit)
Re: (Score:2)
Because they are Windows users and the OS is not secure ;-}
Re: (Score:2)
Re: (Score:2)
The idea is that it's a bridge that lets you use web apps to move crypto. The web-wallet just takes commands from the website but the cryptography is done locally, even maybe talking to a hardware wallet.
The other options are a fat desktop app or giving the website your private key (never do that). Apparently installing software is too hard for most humans.
Webassembly targets will be the next iteration.
2020: It's time to forget about Shitcoins (Score:3)
A shitcoin is anything promoted as a form of money whose supply is easy to increase. In other words, anything other than gold or bitcoin.