Hodlers beware! New malware targets MetaMask and 40 other crypto wallets

Hodlers beware! New malware targets MetaMask and 40 other crypto wallets

Security was never the strong suit of browser-based crypto wallets to store Bitcoin (BTC), Ether (ETH) and other cryptocurrencies. However, new malware makes the safety of online wallets even more complicated by directly targeting crypto wallets that work as browser extensions such as MetaMask, Binance Chain Wallet or Coinbase Wallet.

Named Mars Stealer by its developers, the new malware is a powerful upgrade on the information-stealing Oski trojan of 2019, according to security researcher 3xp0rt. It targets more than 40 browser-based crypto wallets, along with popular two-factor authentication (2FA) extensions, with a grabber function that steals users’ private keys.

Our top trading bots

MetaMask, Nifty Wallet, Coinbase Wallet, MEW CX, Ronin Wallet, Binance Chain Wallet and TronLink are listed as some of the targeted wallets. The security expert notes that the malware can target extensions on Chromium-based browsers except Opera. Sadly, it means some of the most common browsers such as Google Chrome, Microsoft Edge and Brave made it to the list. Also, while they are safe from extension-specific attacks, Firefox and Opera are also vulnerable to credential-hijacking.

Related: 'Less sophisticated' malware is stealing millions: Chainalysis

Mars Stealer can be spread through various channels such as file-hosting websites, torrent clients and any other shady downloaders. After infecting a system, the first thing the malware does is check the device language. If it matches the language ID of Kazakhstan, Uzbekistan, Azerbaijan, Belarus or Russia, the software leaves the system without any malicious action.

For the rest of the world, the malware targets a file that holds sensitive information such as crypto wallets’ address info and private keys. It then leaves the system by deleting any presence once the theft is complete.

Hackers are currently selling Mars Stealer for $140 on dark web forums, meaning the barrier to access the trojan is relatively low for malicious actors. Users who hold their crypto assets on browser-based wallets or use browser extensions like Authy to utilize 2FA are warned to be cautious against clicking dubious links or downloads.

Read on relating to Cointelegraph
South Korea to invest $187M in national Metaverse project
South Korea’s Ministry of ICT, Science, and Future Planning pledged 223.7 billion KRW ($186.7 million) to create a broad Metaverse ecosystem to support...
Happy to be regulated? Fallout from BlockFi settlement is a matter of speculation
It might seem unlikely that BlockFi founder and CEO Zac Prince would describe a prosecution that resulted in a $100-million fine for his company as “a win...
BREAKING: BlockFi files for physically-backed Bitcoin ETF
Cryptocurrency lending firm BlockFi has filed paperwork with the United States Securities and Exchange Commission, or SEC, to launch a physically-backed...
Analysts say ‘impulse move’ could send Ethereum price into the $6K to $14K range
Crypto markets have hit the ground running right from the start of November and as of Nov. 2, a near uncountable number of tokens have rallied to swing...
U.S. government goes to court over $11M USDT purportedly stolen by fake Coinbase rep
On September 17, a group of officials led by U.S. attorney Tracy Wilkinson have filed a civil complaint in the United States District Court for the Central...
Bitcoin's power consumption this year has already surpassed all of 2020's
A new study suggests that Bitcoin has already used more power so far this year than it did in all of 2020. By the end of the year, the Bitcoin network will...
NFT space is an exciting challenge to remain competitive, says Sean Kelly
Chibi Dinos are a collection of 10,000 unique dinosaur-themed non-fungible tokens, or NFTs. The chibis — a phrase denoting the Japanese slang word for small...
Mass appeal: Could a Bitcoin futures EFT electrify US investors?
Are crypto exchange-traded funds (ETFs) finally coming to the United States of America? Dozens of cryptocurrency-based ETFs or ETF-like products are currently...
Japanese financial regulator considers imposing stricter crypto rules
Japan’s financial regulator, the Financial Services Agency (FSA), has started discussions around imposing stricter regulations for cryptocurrencies in an...
Mintable platform raises $13M, will integrate 'carbon neutral' NFTs on XRP Ledger
An oversubscribed funding round has netted the Mintable nonfungible token (NFT) minting platform and marketplace a cool $13 million.The Series A funding...
Trust is key to mainstream adoption for stablecoins, says Paxos CEO
Paxos CEO Charles Cascarilla believes that stablecoins need solid regulation to go beyond being just a tool for crypto enthusiasts and achieving mainstream...
The Graph Foundation taps protocol infrastructure developer for $60M grant
The Graph Foundation, the grants program behind the Ethereum (ETH) indexing protocol, has tapped StreamingFast to further the development of its so-called...
Litecoin Climbs 10% In a Green Day
Investing.com - Litecoin was trading at $280.216 by 06:40 (10:40 GMT) on the Investing.com Index on Thursday, up 10.36% on the day. It was the largest one-day...
Macau poised to amend laws to enable digital yuan trials
Macau is pushing forward with preparations fo the roll out China’s digital yuan, which could help crack down on tax evasion in its opaque gambling industry....
Report: Leaders of South Korean Crypto Exchange Komid Face Jail After Fraud
This week the Asian crypto-market has been rich in the news. Earlier it was reported that Japan finally approved Coincheck’s official status as cyber money...