Skip to main content

Browser Extensions Can Help Scammers Steal Your Bitcoin: Casa CE



Browser extensions can help scammers steal your crypto Casa CEO Jeremy Welch warned the audience at the Baltic Honeybadger conference in Riga this weekend.
"Browser extensions impose major risks, and these risks haven't been discussed until this point," Welch said.

Extensions can gather a wealth of data, which can be leaked, stolen, and used by scammers. One example is browser history, which can expose users' online habits, including crypto-related site visits.
"Make sure you don't expose your bitcoin addresses anywhere," Welch warned.

Another thing to keep in mind is that some extensions capture users' KYC information and can leak it to scammers. The only major multisig system that requires KYC at the moment is the one supplied by Unchained Capital, Welch said. He warns against commonly-used consumer software that gathers identity data.

As an example, Welch demonstrated how an extension providing wallpapers with inspiring quotes or other content was actually stealing data as you filled in KYC forms. The malware stole graphical data, like a photo of your driver's license, which is captured as a code and then easily decoded, providing an actual picture of your ID document to hackers.

Quiet data thefts
All this is happening on the background, without the user noticing.
"You got a nice background here and you don't realize that your browser is actually dumping data," Welch said.

The same wallpaper extension can alter a receiving address when you're trying to send your crypto to somebody else (or to yourself), sending it to a scammer's wallet instead. The ubiquity and popularity of browser extensions makes the situation quite dangerous, Welch noted:
"It's terrifying, right? We all are using browser extensions all the time."

Even if a user is very careful and selective in what they're using, the software can be upgraded and get new, unsafe features without a consumer noticing, Welch added.

Welch noted that many well-known applications request enough permissions to gather personal data, including password managers, text editing app Grammarly, Joule extension for in-browser Lighting transactions, Casa's own Sats extension and the Lolli bitcoin-earning extension.

The solution? There is no easy one, Welch says. Developers can only keep building better tools that will make users' experience safer and better.
"We all need to be discussing this issues more, because we're not even in the phase yet when real attacks will be taking place."

Welch added that Casa is planning to publish more security research soon and encouraged bitcoin developers and entrepreneurs to approach the company and share their concerns and ideas on how to address security issues.

Comments

Popular posts from this blog

What is iDice?

iDice is a dice betting Dapp fueled by the use of the Ethereum organize. eg. iDice lets in players do several things and having such an innovative new token on the ETHEREUM Platform, we had to write an article about this new project. Guess on the space by the use of keeping up iDice tokens and best of all 100% of all benefit iDice acquires is dispersed among token holders, related to the amount of tokens they dangle. iDice amusement code is decentralized and changeless. Such gigantic building fees highlight a rising requirement for experienced, fair and cast Dapps. iDice iDice is an control which gives a provably affordable and simple, virtual Ethereum dice betting Dapp. The house edge will be set intensely and token holders have an atypical esteem that is dependably equiva- loaned to the house edge. iDice has a fully simple provide code accessible at etherscan.io. The payout of recreations is many times speedy. Provably Fair iDice uses open provide blockchain...

DENT: THE World First Tokenizing Portable Information Trade

You may be confused on all the exciting Ethereum projects, but therefore i make sure to follow allof them and choose the best for you. If you want to read about a more interesting project, then DENT is the way to go. I will be able to advice on a few tokens that can be bought out there which clearly we likewise might occu : Estimated token incentive on ETH presented within the token deal: 152,000 ETH (Relying on sorts via crowdsale) 100 Billion (100,000,000,000) the amount of DENT Tokens made, of which 70% is bought on token deal, a minimum of 35% can be stored for customers with littler spending plans. For the ones of you who're eager about ico smartcontract prolong that we regularly listen in non-obligatory cryptographic cash or altcoin without a doubt no longer outdoor to the workings of undertakings like this. Evaluated swapping scale: 1 ETH = 400,000 DENT 30% will keep on DENT Wi-fi for DENT shopper motivating forces and compensations Bills may well be made via ETH...

Fake Libra scams pose new challenge for Facebook

Almost a year after Facebook's Libra was first announced, the outlook for the stablecoin looks starkly different. Once hailed as a game-changer for digital currency, the project has been beset by delays and regulatory difficulties. Now, fake Libra scams are presenting an increasingly pressing new challenge for Libra and Facebook, with a proliferation of websites claiming to offer investment schemes denominated in fake Libra tokens. Dante Disparte, Deputy Chairman and Head of Policy and Communications for The Libra Association, said the organization was now constantly working to suppress fake Libra scams: "As we become aware of these sites, we work diligently to address them. We respond to inquiries concerning the validity of these pages, indicating that the only official website is Libra.org." "We are still in the early stages of this project and work to address issues like these as they arise," Disparte told Finance Magnates, urging people to report the scams. ...