Cybersecurity is a major concern in technological advancement. Hackers are prone to conducting malicious practices against unsuspecting users. The cryptocurrency space is not immune to this issue. The steep rise in crypto and those investing in it make it a hackers’ target. According to security researchers, there have been large-scale malicious operations in crypto platforms like CoinBase, TokenPocket, and MetaMask. Hackers can clone users’ crypto mobile wallets and steal their funds. So, you may be wondering how they do this. Please read on to find out.
The SeaFlower
Are you wondering what this is all about? Well, it was birthed in March this year, at a time when some crypto platforms; CoinBase, imToken, TokenPocket, and MetaMask had malicious operations going on. The security researchers in charge named the malicious activity “SeaFlower”. According to the researchers, it was “the most technically sophisticated threat targeting web3 users, right after the infamous Lazarus Group.”
Therefore, the cyber threat to web3 users is not a new phenomenon in the cryptocurrency space. Unfortunately, hackers are devising new ways of targeting users and the increasing rise in crypto is giving them more opportunities. What’s more, their operations are getting more technically sophisticated. This puts the users at risk of losing their tokens. Therefore, the cyber security concern in the world of crypto is a matter worth looking deep into.
Notably, there are malicious crypto apps. When not careful, a user may not know the difference between this and the real one. The thieves can impersonate popular wallet apps without the users’ knowledge. Sadly, both Apple and Android users are victims since these impersonated applications are on their platforms too.
This is a real threat as the hackers can steal their seed phrases and access their digital assets. As in the SeaFlower case, the cybercriminals behind it seem to be from China. This can be traced from the kind of language in the comments, the frameworks, services used, and the infrastructure location. Therefore, the main target of this campaign is individuals using Chinese search engines linked to malicious crypto wallets.
Therefore, the SeaFlower is an example of malware. Hackers are tapping on to this and evidently, this is not the only theft and fraud plaguing the crypto space. Let us find out more.

Read: How to Become a Certified Blockchain Expert?
A New Phase of Crypto Wallet Theft
Malware threat is not a new term. The oldest cryptocurrencies like Bitcoin and Ethereum experienced security problems. With more browser-based crypto wallets emerging, the issue seems more complicated. Crypto wallet theft keeps popping in new forms. The new target is in wallets with browser extensions such as MetaMask and Coinbase wallets.
The following are some of the prevalent crypto-malware;
- Mars Stealer
This was a new form, an upgraded version of the older one in 2019. It targets over 40 browser crypto wallets and is designed for theft of user private keys. This malware is across different online channels.
How does it work? It targets the file in a user’s device where he stores the private keys. Once it identifies this file, it steals the available information and erases any evidence of theft. Crypto users browsing from Chrome are the most vulnerable to this malware.
- Clipper
This malware has been around since back in 2017 and some of the victims are Bitcoin and Ethereum. As the name suggests, it utilizes the user’s clipboard to facilitate the theft. How? It replaces the destination of the user’s crypto address with that of the hacker.
This way, when a user quickly copy-pastes an address for payment, for instance, it doesn’t reach the target. Rather, the hacker gets the payment. This malware has thrived because most crypto users overlook the crypto addresses that are usually very long.
Read: How Organizations can Evade the Deepfake Voice Clone Fraud?
Crypto Threats for Android vs Apple Phones
As earlier noted, no crypto user is safe, whether an android or apple user. However, the malware operates in the two systems quite differently;
- Android Devices
These victims are usually newbies to cryptocurrency. They don’t have a legitimate wallet application on their phones. Also, Android has a security protocol that does not allow malware to overwrite the already present apps. Therefore, the users download crypto sites. Unfortunately, the criminals dupe them into accessing the fake ones.
Therefore, to protect yourself from such sneaky threats, ensure you download the wallet application from trusted sources. The best places are either from the developer’s website or an official app store such as Google Play.

- Apple Devices
Apple also has a protocol against malicious downloading of apps from the Apple App Store. The hackers grab this opportunity and redirect the users to third-party websites from where they download the malware. These cybercriminals convince the user with alerts and notifications to bypass their systems’ built-in protections. Instead, they unknowingly install the malicious application.
So, how do apple smartphone users protect themselves? Ensure you first check how legitimate a request is before installing or accepting any provisional profile on your IOS.
Prevent Malware and Crypto Theft; How?
The following tips can help protect you against crypto wallet malware;
- Always lock your hot wallets and disconnect any connected sites when not actively trading.
- Have a complex text format as storage for your private key information. Also, do not share the information or your seed phrases.
- Always be keen when cop pasting your passwords and important information.
- Always terminate a browser session once you complete a transaction.
- Beware of any suspicious links directing you to third-party websites and apps.
- Opt for wallets with multifactor authentication and hardware wallets that allow offline storage of private keys.
- Always crosscheck the full file extensions of whatever file you download.
Read: 5 Biggest Cryptocurrency Scams to Watch out for in 2022
Protect Yourself and Your Assets
As a crypto user and enthusiast, you don’t want to fall victim to cyber theft. You wouldn’t want a cyber-criminal to steal your digital assets from a crypto app you are using. Therefore, to protect yourself against crypto wallet malware, you can apply the tips previously mentioned. Also, you can get a cybersecurity certification to help fight any new form of malware hackers present to you. With IT security mastery, you can protect yourself from malware and potential crypto threats. Embracing yourself with the techniques the malicious hackers can apply helps keep you ahead and less vulnerable.
Related articles you might be interested in:
5 Safest Ways to Keep and Transact with Crypto
How to Accept Bitcoin and Other Crypto Payments on Your Website






























