Crypto Wallet Drainer App Identified on Google Play Store, Report Suggests $70,000 Stolen

Crypto scammers have significantly increased the efficiency of their global cyber attacks, according to recent warnings from the FBI.

Advertisement
Written by Radhika Parashar, Edited by Siddharth Suvarna | Updated: 30 September 2024 17:05 IST
Highlights
  • The app was available on Play Store for five months, the report says
  • The fake app was created using the platform median.co
  • The details about the publishers of this app remain undisclosed

The fake app replicating WalletConnect was published on Google Play Store on March 21, 2024

Photo Credit: Google

A report by Check Point Research (CPR) uncovered a crypto wallet draining app on the Google Play Store, masquerading as the popular WalletConnect app. CPR found that the app used "advanced evasion techniques" to steal $70,000 (roughly Rs. 58.6 lakh) over five months from unsuspecting users. The malicious app, named "MS Drainer" after an analysis of its JavaScript code, is part of a growing trend of increasingly sophisticated crypto scams. Recent FBI reports also warn that cybercriminals have become more efficient in executing global attacks.

“Check Point Research (CPR) uncovered a malicious app on Google Play Store designed to steal cryptocurrency marking the first time a drainer has targeted mobile device users exclusively. To pose as a legitimate tool for Web3 apps, the attackers exploited the trusted name of the WalletConnect protocol, which connects crypto wallets to decentralised apps,” the report said.

The crypto wallet app, that has now been removed, managed to amass over 10,000 downloads. The fake platform emerged on top of the search on Google Play Store on searching for ‘WalletConnect' owing to multiple reviews that the CPR report flagged as ‘fake'.

Advertisement

What is WalletConnect

WalletConnect is an open-source protocol that connects decentralised apps (dApps) with crypto wallets through QR codes, allowing users to interact with blockchain-based apps without exposing their private keys.

Advertisement

According to Check Point Research (CPR), a fake app mimicking WalletConnect's appearance and functions was created using the web service Median.co. The app, initially named "Mestox Calculator," was published on the Google Play Store on March 21, 2024, with its name changed several times since then.

“An inexperienced user might conclude that it is a separate wallet application that needs to be downloaded and installed. Attackers hijack the confusion, hoping that users will search for a WalletConnect app in the application store,” the report noted.

Advertisement

The X handle of WalletConnect acknowledged the development in a note to its followers.

How Did WalletConnet's Malicious Dupe Work

Upon download, the fake app quickly prompted users to connect their crypto wallets. When users clicked the wallet buttons, they were redirected to a malicious website via a deep link. To verify their wallets, the website requested users to approve multiple transactions consecutively, unknowingly authorizing fraudulent activity.

Advertisement

“We assume that users install this malicious app to connect their wallet to Web3 applications that do not support direct connections to wallets like MetaMask, Binance Wallet, or Trust Wallet, but only use the WalletConnect protocol. They likely expect the downloaded WalletConnect app to function as a sort of proxy. Therefore, the connection request does not appear suspicious,” the report explained.

The CPR, in its report, said incidents like these highlight the advance nature of techniques that are being used to target the crypto sector, that is presently valued at $2.27 trillion (roughly Rs. 1,90,20,364 crore). The website has strongly suggested users remain vigilant and wary of the applications they download, even when they appear legitimate.

Back in 2023, a Sophos report stated that crypto scammers have been fishing for victims on Android systems using AI tools. Crypto fraudsters were also identified to be exploiting advertisements on Google Search to promote scam websites.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Son of Sardaar 2 OTT Release: Know When and Where to Watch it Online
  2. DNA Cassette Tapes Could Transform the Future of Digital Storage
  1. Astronomers Predict 90 Percent Chance of Spotting an Exploding Black Hole in Next Decade
  2. DNA Cassette Tapes Could Transform the Future of Digital Storage
  3. Researchers Create Metal That Resists Cracking in Deep Space Cold
  4. The Madras Mystery OTT Release: This Nazriya Nazim Thriller Will Soon Arrive on This Platform
  5. The Treasure Hunters OTT Release: Know When and Where to Watch Manisha Rani's Game Show Online
  6. Sarkeet OTT Release: This Is Where You Can Watch the Asif Ali-Starrer Later This Month
  7. Researchers Reconstruct 2,500-Year-Old Faces From Skulls Found in Tamil Nadu
  8. House Mates OTT Release: When and Where to Watch the Tamil Horror Comedy Online
  9. Black Hole Kicked Away? Gravitational Waves Reveal Einstein’s Ripples in Spacetime
  10. NASA’s Artemis II Astronauts Will Double as Test Subjects for Deep Space Health Research
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.