• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical bug in everscale wallet could've let attackers steal cryptocurrencies

Critical Bug in Everscale Wallet Could’ve Let Attackers Steal Cryptocurrencies

You are here: Home / General Cyber Security News / Critical Bug in Everscale Wallet Could’ve Let Attackers Steal Cryptocurrencies
April 25, 2022

A security vulnerability has been disclosed in the web version of the At any time Surf wallet that, if correctly weaponized, could let an attacker to gain total manage in excess of a victim’s wallet.

“By exploiting the vulnerability, it is doable to decrypt the personal keys and seed phrases that are saved in the browser’s local storage,” Israeli cybersecurity business Examine Position said in a report shared with The Hacker News. “In other phrases, attackers could get entire regulate around the victim’s wallets.”

CyberSecurity

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


At any time Surf is a cryptocurrency wallet for the Everscale (formerly FreeTON) blockchain that also doubles up as a cross-platform messenger and allows users to obtain decentralized apps as properly as send out and get non-fungible tokens (NFTs). It is really explained to have an estimated 669,700 accounts across the world.


By usually means of distinctive attack vectors like destructive browser extensions or phishing one-way links, the flaw will make it achievable to get a wallet’s encrypted keys and seed phrases that are stored in the browser’s neighborhood storage, which can then be trivially brute-compelled to siphon funds.

Supplied that the details in the area storage is unencrypted, it could be accessed by rogue browser insert-ons or information-thieving malware that is able of harvesting these information from distinct web browsers.

CyberSecurity

Next liable disclosure, a new desktop application has been introduced to change the vulnerable web version, with the latter now marked as deprecated and applied only for growth uses.

“Obtaining the keys indicates total regulate about the victim’s wallet, and, thus resources,” Look at Point’s Alexander Chailytko reported. “When working with cryptocurrencies, you constantly need to be cautious, be certain your device is absolutely free of malware, do not open suspicious one-way links, maintain OS and anti-virus application current.”

“Regardless of the point that the vulnerability we identified has been patched in the new desktop version of the Ever Surf wallet, users may possibly experience other threats these types of as vulnerabilities in decentralized applications, or general threats like fraud, [and] phishing.”

Found this short article interesting? Stick to THN on Fb, Twitter  and LinkedIn to examine additional exclusive material we publish.


Some components of this article are sourced from:
thehackernews.com

Previous Post: «Cyber Security News FCA: Challenger Banks Failing to Spot Money Launderers
Next Post: FBI warns Rust-based ransomware has breached over 60 organisations fbi warns rust based ransomware has breached over 60 organisations»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month
  • Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.