Security Warning - If you use MetaMask on an iOS device with iCloud backup enabled,
#1
Security Warning - If you use MetaMask on an iOS device with iCloud backup enabled,

<table> <tr><td> <a href="https://www.reddit.com/r/CryptoCurrency/comments/u5to4g/security_warning_if_you_use_metamask_on_an_ios/"> <img src="https://external-preview.redd.it/EK9bIo_EtVS77n_WNpiU8ynGqwq3pUkBy_m5lsQjm4c.jpg?width=320&amp;crop=smart&amp;auto=webp&amp;s=bead8f5394bc80f0aae20a0565f84c38d9ea08e5" alt="Security Warning - If you use MetaMask on an iOS device with iCloud backup enabled, then your vault seed is automatically backed up by default. People are being phished for AppleID resets with one victim losing $650K yesterday." title="Security Warning - If you use MetaMask on an iOS device with iCloud backup enabled, then your vault seed is automatically backed up by default. People are being phished for AppleID resets with one victim losing $650K yesterday." /> </a> </td><td> <!-- SC_OFF --><div class="md"><p><strong>TLBig GrinR</strong> </p> <p>If you have MetaMask on an iPhone or Mac, then you're likely also using iCloud backup. MetaMask backup your Valut containing your seed by default, so turn that off from Settings\Profile\iCloud\Manage Storage!</p> <p>&#x200B;</p> <p><strong>Summary</strong></p> <p>I have been following this developing story on Twitter about a user that lost $650K yesterday due to the following phishing method with others coming forward claiming that the same has also happened to them.</p> <p><strong>Background</strong> </p> <p>When you create a wallet using MetaMask on an iPhone, the app will create a JSON containing your wallet, this is stored on your device. Most users use iCloud to automatically backup their phone and app data, but unbeknown to many users, MetaMask include this file as part of the backup. From a google search, this isn't new, it was discovered in 2019, but MetaMask have today acknowledged (addressed) it <a href="https://nitter.net/MetaMask">HERE</a> after a number of users were targeted resulting in lost funds.</p> <p>&#x200B;</p> <p><a href="https://preview.redd.it/zwx26nnww4u81.png?width=744&amp;format=png&amp;auto=webp&amp;s=46e5360122bdbed0ef700bee43cab95cbfc5ec25">MetaMask iCloud Backup</a></p> <p><strong>Phishing Method</strong></p> <p>For the user that lost $650K, it appears to be a very sophisticated attack. They fell victim as follows...</p> <p>The malicious attacker requested several password resets against their AppleID/iCloud generating several emails to their account. From there, they using a spoofed caller id to call the victim and claimed that they were from Apple and calling about suspicious activity on their account. They asked them to generate their MFA one time pass to confirm that they were the account owner. The hacker used this to reset the password and take control of the Apple account. From there, they were able to restore from a backup and drain the wallet of all funds. </p> <p><strong>More reading / source</strong></p> <p><a href="https://twitter.com/Serpent/status/1515545806857990149">HERE</a></p> </div><!-- SC_ON --> submitted by <a href="https://www.reddit.com/user/_s79"> /u/_s79 </a> <br/> <span><a href="https://www.reddit.com/r/CryptoCurrency/comments/u5to4g/security_warning_if_you_use_metamask_on_an_ios/">[link]</a></span> <span><a href="https://www.reddit.com/r/CryptoCurrency/comments/u5to4g/security_warning_if_you_use_metamask_on_an_ios/">[comments]</a></span> </td></tr></table>Kind Regards R
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  ‘XRP is not a security. Period’ — Crypto lawyers on Ripple’s case amid SEC a Dato 0 117 08-11-2023, 12:44 PM
Last Post: Dato
  Telegram trading bots are hot, but don’t trust them for custody — Security firms Dato 0 109 08-11-2023, 06:35 AM
Last Post: Dato
  BNB Chain hard fork to improve security and compatibility with EVM chains Dato 0 110 08-10-2023, 08:18 AM
Last Post: Dato
  Two-thirds of AI Chrome extensions could endanger user security: Data Dato 0 95 08-09-2023, 05:25 AM
Last Post: Dato
  Users said CertiK’s warning was a false alarm — then the project rugged Dato 0 99 08-06-2023, 06:47 AM
Last Post: Dato



Users browsing this thread: 1 Guest(s)