Crypto Wallet Drainer App Identified on Google Play Store, Report Suggests $70,000 Stolen

Crypto scammers have significantly increased the efficiency of their global cyber attacks, according to recent warnings from the FBI.

Advertisement
Written by Radhika Parashar, Edited by Siddharth Suvarna | Updated: 30 September 2024 17:05 IST
Highlights
  • The app was available on Play Store for five months, the report says
  • The fake app was created using the platform median.co
  • The details about the publishers of this app remain undisclosed

The fake app replicating WalletConnect was published on Google Play Store on March 21, 2024

Photo Credit: Google

A report by Check Point Research (CPR) uncovered a crypto wallet draining app on the Google Play Store, masquerading as the popular WalletConnect app. CPR found that the app used "advanced evasion techniques" to steal $70,000 (roughly Rs. 58.6 lakh) over five months from unsuspecting users. The malicious app, named "MS Drainer" after an analysis of its JavaScript code, is part of a growing trend of increasingly sophisticated crypto scams. Recent FBI reports also warn that cybercriminals have become more efficient in executing global attacks.

“Check Point Research (CPR) uncovered a malicious app on Google Play Store designed to steal cryptocurrency marking the first time a drainer has targeted mobile device users exclusively. To pose as a legitimate tool for Web3 apps, the attackers exploited the trusted name of the WalletConnect protocol, which connects crypto wallets to decentralised apps,” the report said.

The crypto wallet app, that has now been removed, managed to amass over 10,000 downloads. The fake platform emerged on top of the search on Google Play Store on searching for ‘WalletConnect' owing to multiple reviews that the CPR report flagged as ‘fake'.

Advertisement

What is WalletConnect

WalletConnect is an open-source protocol that connects decentralised apps (dApps) with crypto wallets through QR codes, allowing users to interact with blockchain-based apps without exposing their private keys.

Advertisement

According to Check Point Research (CPR), a fake app mimicking WalletConnect's appearance and functions was created using the web service Median.co. The app, initially named "Mestox Calculator," was published on the Google Play Store on March 21, 2024, with its name changed several times since then.

“An inexperienced user might conclude that it is a separate wallet application that needs to be downloaded and installed. Attackers hijack the confusion, hoping that users will search for a WalletConnect app in the application store,” the report noted.

Advertisement

The X handle of WalletConnect acknowledged the development in a note to its followers.

How Did WalletConnet's Malicious Dupe Work

Upon download, the fake app quickly prompted users to connect their crypto wallets. When users clicked the wallet buttons, they were redirected to a malicious website via a deep link. To verify their wallets, the website requested users to approve multiple transactions consecutively, unknowingly authorizing fraudulent activity.

Advertisement

“We assume that users install this malicious app to connect their wallet to Web3 applications that do not support direct connections to wallets like MetaMask, Binance Wallet, or Trust Wallet, but only use the WalletConnect protocol. They likely expect the downloaded WalletConnect app to function as a sort of proxy. Therefore, the connection request does not appear suspicious,” the report explained.

The CPR, in its report, said incidents like these highlight the advance nature of techniques that are being used to target the crypto sector, that is presently valued at $2.27 trillion (roughly Rs. 1,90,20,364 crore). The website has strongly suggested users remain vigilant and wary of the applications they download, even when they appear legitimate.

Back in 2023, a Sophos report stated that crypto scammers have been fishing for victims on Android systems using AI tools. Crypto fraudsters were also identified to be exploiting advertisements on Google Search to promote scam websites.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  2. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  3. Gemini 3 Flash Arrives as Google's Latest High-Speed, Low-Cost AI Model
  4. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  5. OnePlus 15R Review
  6. Dhurandhar OTT Release Date: What We Know So Far
  7. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  8. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  9. Honor Win, Win RT Features Teased; Will Launch in China on This Date
  10. Google's Pixel Phones Get a Second December Update With These Fixes
  1. Xiaomi 17 Ultra Launch Timeline Confirmed; Will Feature Leica-Tuned Cameras: Expected Features, Specifications
  2. Apple's App Store to Introduce Additional Ads Across Search Queries in 2026
  3. Google Pixel Phones Reportedly Receive Second December Update With Fixes for Battery, Touch Issues
  4. Google Releases Gemini 3 Flash, Outperforms 3 Pro Model in Speed and Coding Performance
  5. James Webb Space Telescope Could Help Reveal Dark Matter in a Way Scientists Did Not Anticipate
  6. Interstellar Comet 3I/ATLAS Nears Earth on Dec. 19, Offering Rare Insights Into Cosmic Visitors
  7. Europe’s Ariane 6 Rocket Lifts Off With First Galileo Satellites, Boosting Europe’s Navigation Network
  8. NASA’s Parker Solar Probe Observes Solar Wind Making ‘U-Turn’, Shedding Light on Space Weather
  9. ESA Reveals City-Size ‘Cosmic Butterfly’ Crater on Mars Containing Signs of Ancient Water
  10. The Holy Grail of Eris OTT Release: Know When and Where to Watch it Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.