Connect with us

Crypto

Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign

Published

on

Crypto Scam App Disguised as WalletConnect Steals K in Five-Month Campaign

Sep 28, 2024Ravie LakshmananCryptocurrency / Mobile Security

Cybersecurity researchers have discovered a malicious Android app on the Google Play Store that enabled the threat actors behind it to steal approximately $70,000 in cryptocurrency from victims over a period of nearly five months.

The dodgy app, identified by Check Point, masqueraded as the legitimate WalletConnect open-source protocol to trick unsuspecting users into downloading it.

“Fake reviews and consistent branding helped the app achieve over 10,000 downloads by ranking high in search results,” the cybersecurity company said in an analysis, adding it’s the first time a cryptocurrency drainer has exclusively targeted mobile device users.

Over 150 users are estimated to have fallen victim to the scam, although it’s believed that not all users who downloaded the app were impacted by the cryptocurrency drainer.

Advertisement
Cybersecurity

The campaign involved distributing a deceptive app that went by several names such as “Mestox Calculator,” “WalletConnect – DeFi & NFTs,” and “WalletConnect – Airdrop Wallet” (co.median.android.rxqnqb).

While the app is no longer available for download from the official app marketplace, data from SensorTower shows that it was popular in Nigeria, Portugal, and Ukraine, and linked to a developer named UNS LIS.

The developer has also been associated with another Android app called “Uniswap DeFI” (com.lis.uniswapconverter) that remained active on the Play Store for about a month between May and June 2023. It’s currently not known if the app had any malicious functionality.

Crypto Scam App

However, both apps can be downloaded from third-party app store sources, once again highlighting the risks posed by downloading APK files from other marketplaces.

Once installed, the fake WallConnect app is designed to redirect users to a bogus website based on their IP address and User-Agent string, and if so, redirect them a second time to another site that mimics Web3Inbox.

Users who don’t meet the required criteria, including those who visit the URL from a desktop web browser, are taken to a legitimate website to evade detection, effectively allowing the threat actors to bypass the app review process in the Play Store.

Besides taking steps to prevent analysis and debugging, the core component of the malware is a cryptocurrency drainer known as MS Drainer, which prompts users to connect their wallet and sign several transactions to verify their wallet.

Advertisement
Crypto Scam App

The information entered by the victim in each step is transmitted to a command-and-control server (cakeserver[.]online) that, in turn, sends back a response containing instructions to trigger malicious transactions on the device and transfer the funds to a wallet address belonging to the attackers.

“Similar to the theft of native cryptocurrency, the malicious app first tricks the user into signing a transaction in their wallet,” Check Point researchers said.

“Through this transaction, the victim grants permission for the attacker’s address 0xf721d710e7C27323CC0AeE847bA01147b0fb8dBF (the ‘Address’ field in the configuration) to transfer the maximum amount of the specified asset (if allowed by its smart contract).”

In the next step, the tokens from the victim’s wallet are transferred to a different wallet (0xfac247a19Cc49dbA87130336d3fd8dc8b6b944e1) controlled by the attackers.

Cybersecurity

This also means that if the victim does not revoke the permission to withdraw tokens from their wallet, the attackers can keep withdrawing the digital assets as soon as they appear without requiring any further action.

Check Point said it also identified another malicious app exhibiting similar features “Walletconnect | Web3Inbox” (co.median.android.kaebpq) that was previously available on Google Play Store in February 2024. It attracted more than 5,000 downloads.

“This incident highlights the growing sophistication of cybercriminal tactics, particularly in the realm of decentralized finance, where users often rely on third-party tools and protocols to manage their digital assets,” the company noted.

Advertisement

“The malicious app did not rely on traditional attack vectors like permissions or keylogging. Instead, it used smart contracts and deep links to silently drain assets once users were tricked into using the app.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Crypto

XRP Stalls Despite Bullish Developments and Ripple’s Institutional Momentum

Published

on

XRP Stalls Despite Bullish Developments and Ripple’s Institutional Momentum
XRP is consolidating near a key level as Ripple expands its regulated global finance footprint, signaling patience in price action while adoption, institutional integration, and regulatory clarity quietly strengthen the crypto asset’s long-term foundation.
Continue Reading

Crypto

This Popular Cryptocurrency Could Soar by 177% in 2026, According to Wall Street Analyst Tom Lee

Published

on

This Popular Cryptocurrency Could Soar by 177% in 2026, According to Wall Street Analyst Tom Lee

Key Points

  • Ethereum is the leading platform for developers who want to build decentralized software applications, which are popular in areas like gaming and finance.

  • Ether, which is Ethereum’s native cryptocurrency, set a new record high during 2025, but it ended the year in the red.

  • Wall Street analyst Tom Lee thinks Ether could soar in the early stages of 2026, and he chairs a company that owns over $13 billion worth of coins.

Cryptocurrencies had a tough year in 2025, with most popular coins and tokens suffering losses. Not even the industry leaders like Bitcoin and Ethereum(CRYPTO: ETH) were spared, ending the year down 5% and 11%, respectively.

But 2026 is here, and Wall Street analyst Tom Lee recently came out with a set of very bullish forecasts. He thinks Ether, which is the native cryptocurrency of the Ethereum network, could soar to $9,000 per coin early in the year, implying a potential upside of 177% from where it’s trading as I write this.

Where to invest $1,000 right now? Our analyst team just revealed what they believe are the 10 best stocks to buy right now. Continue »

Lee founded Fundstrat Global Advisors, but he’s also the chairman of BitMine Immersion Technologies(NYSEMKT: BMNR), which owns approximately $13.4 billion worth of Ethereum, so he certainly has some skin in the game. How realistic is his latest forecast?

Image source: Getty Images.

Advertisement

What is Ethereum?

Ethereum is a platform where people develop decentralized software applications, which are increasingly popular in industries like gaming and financial services. These apps are governed by smart contracts, which are pieces of computer code that live on the Ethereum blockchain. They typically can’t be changed, so no person or company can manipulate the app’s core set of rules, ensuring it stays decentralized.

The Ethereum network itself is also completely decentralized. Instead of using one large data center, it’s hosted on thousands of nodes (computers) all over the world that store an updated copy of its blockchain. Therefore, the network won’t be compromised even if some nodes go down, and that’s how Ethereum has boasted 100% uptime over the last decade.

Ether is like the fuel that makes the Ethereum network function. Every time a person activates a smart contract by using an app, or even transfers a crypto token built on Ethereum, they incur a fee that is payable in Ether. Therefore, the larger the network grows, the more demand there is for Ether, and the more valuable the coin becomes (in theory).

Thousands of decentralized apps have been built on Ethereum so far. Uniswap, for instance, is a popular exchange where people can trade their cryptocurrencies for other cryptocurrencies. Pricing and execution is handled entirely by smart contracts with no intermediaries, creating a lightning-fast and cost-effective experience. Users don’t even need to create an account, because they can connect their crypto wallets directly to Uniswap and immediately start transacting.

How realistic is Lee’s target?

Tom Lee thinks decentralized apps will take over the financial industry, and as the largest platform of its kind, he’s betting Ethereum will lead the transition. The world’s largest asset manager, BlackRock, is already exploring plans to tokenize some of its exchange-traded funds (ETFs) by moving them onto the blockchain, where they can trade more efficiently compared to using traditional stock exchanges.

Advertisement

That is just one example suggesting Lee could eventually be right. But the growing adoption of stablecoins — many of which are built on Ethereum — is another sign. These cryptocurrencies are designed to maintain a stable value (hence their name), and they can be sent anywhere in the world practically instantly. Therefore, they are far more efficient than traditional payment rails that often take several days to move money across borders.

According to Cathie Wood’s Ark Investment Management, over $15 trillion in payment volume was processed using stablecoins in 2024, which was more volume than both Visa and Mastercard processed.

But could all of this send Ether soaring by 177% to $9,000 per coin in the early stages of 2026? I’m not so sure. Ether climbed to a record price of $4,946 per coin in 2025, which was a win for investors, but it was the first new high in four years. Plus, the coin has already lost 32% of its peak value, so I’m not sure if it can muster enough momentum to almost triple in value in the next few months like Lee predicts.

With that said, $9,000 per coin would give Ether a market capitalization of around $1.08 trillion, so it would still be much smaller than Bitcoin, which has a market cap of $1.85 trillion. Therefore, I wouldn’t rule out Lee’s target, especially if the decentralized revolution continues to gather momentum, but I would certainly be cautious about the timing. Plus, it’s important to remember Lee chairs the BitMine Immersion Technologies company, which owns 4.1 million Ether coins, so he has a vested interest in putting forward highly bullish targets.

Advertisement

Should you buy stock in Ethereum right now?

Before you buy stock in Ethereum, consider this:

The Motley Fool Stock Advisor analyst team just identified what they believe are the 10 best stocks for investors to buy now… and Ethereum wasn’t one of them. The 10 stocks that made the cut could produce monster returns in the coming years.

Consider when Netflix made this list on December 17, 2004… if you invested $1,000 at the time of our recommendation, you’d have $488,222!* Or when Nvidia made this list on April 15, 2005… if you invested $1,000 at the time of our recommendation, you’d have $1,134,333!*

Now, it’s worth noting Stock Advisor’s total average return is 969% — a market-crushing outperformance compared to 196% for the S&P 500. Don’t miss the latest top 10 list, available with Stock Advisor, and join an investing community built by individual investors for individual investors.

See the 10 stocks »

Advertisement

*Stock Advisor returns as of January 10, 2026.

Anthony Di Pizio has no position in any of the stocks mentioned. The Motley Fool has positions in and recommends Bitcoin, Ethereum, Mastercard, and Visa. The Motley Fool recommends BlackRock. The Motley Fool has a disclosure policy.

Continue Reading

Crypto

Fed ‘Sweet Spot’ Sends Signal for Bitcoin as Jobs Data Quietly Sets Stage for $100K BTC

Published

on

Fed ‘Sweet Spot’ Sends Signal for Bitcoin as Jobs Data Quietly Sets Stage for 0K BTC
Bitcoin’s march toward $100,000 is gaining momentum as cooling U.S. labor data, shifting Fed policy expectations, and geopolitical tensions converge, setting the stage for renewed price discovery and a possible breakout beyond prior all-time highs.
Continue Reading

Trending