Skip to main content

Browser Extensions Can Help Scammers Steal Your Bitcoin: Casa CE



Browser extensions can help scammers steal your crypto Casa CEO Jeremy Welch warned the audience at the Baltic Honeybadger conference in Riga this weekend.
"Browser extensions impose major risks, and these risks haven't been discussed until this point," Welch said.

Extensions can gather a wealth of data, which can be leaked, stolen, and used by scammers. One example is browser history, which can expose users' online habits, including crypto-related site visits.
"Make sure you don't expose your bitcoin addresses anywhere," Welch warned.

Another thing to keep in mind is that some extensions capture users' KYC information and can leak it to scammers. The only major multisig system that requires KYC at the moment is the one supplied by Unchained Capital, Welch said. He warns against commonly-used consumer software that gathers identity data.

As an example, Welch demonstrated how an extension providing wallpapers with inspiring quotes or other content was actually stealing data as you filled in KYC forms. The malware stole graphical data, like a photo of your driver's license, which is captured as a code and then easily decoded, providing an actual picture of your ID document to hackers.

Quiet data thefts
All this is happening on the background, without the user noticing.
"You got a nice background here and you don't realize that your browser is actually dumping data," Welch said.

The same wallpaper extension can alter a receiving address when you're trying to send your crypto to somebody else (or to yourself), sending it to a scammer's wallet instead. The ubiquity and popularity of browser extensions makes the situation quite dangerous, Welch noted:
"It's terrifying, right? We all are using browser extensions all the time."

Even if a user is very careful and selective in what they're using, the software can be upgraded and get new, unsafe features without a consumer noticing, Welch added.

Welch noted that many well-known applications request enough permissions to gather personal data, including password managers, text editing app Grammarly, Joule extension for in-browser Lighting transactions, Casa's own Sats extension and the Lolli bitcoin-earning extension.

The solution? There is no easy one, Welch says. Developers can only keep building better tools that will make users' experience safer and better.
"We all need to be discussing this issues more, because we're not even in the phase yet when real attacks will be taking place."

Welch added that Casa is planning to publish more security research soon and encouraged bitcoin developers and entrepreneurs to approach the company and share their concerns and ideas on how to address security issues.

Comments

Popular posts from this blog

The Bitquence Liquidity Network

CryptoCurrency is gaining popularity, however with Bitcoin very user-unfriendly mass adoption is not coming. The Bitquence Platform is aiming to replace Bitcoin with it's many disadvantages with something better. A currency for the people. More and better usability, A wallet which is universal and support several coins, like Bitcoin but also Dash and Ethereum. Please read along to get the latest information about this project which can grow very large. Collection of abnormal pockets programs, With automated sources that oversee a large number of wallets for each and every of your financial paperwork making it exhausting to do. International Cryptocurrencies lately stay on experiencing an especially noteworthy increment, impulsively reaching colossal valuations. The have an effect on at the present economic system modified the psyches of people to take after enhancements within the time of Cryptocurrency. Virtual kinds of cash and blockchain innovation are lat...

BOScoin | Self-Evolving Cryptocurrency Platform

Well, what is BOScoin? BOScoin is a new virtual currency from a South Korean Fintech startup Blockchain OS. And unlike the existing virtual currencies, BOScoin is a new digital currency which also happens to be based on a blockchain. However, according to the company's experts it has a higher transactional speed which will go up to about 1000 transactions per second that is in line with the credit card processing speed. Its platform has been presented in both London and Berlin by Blockchain OS where they have been answering the questions of many with interests in the fields of design, technical, architecture, and governance. BOScoin is designed as a platform for a self-evolving crypto currency as an upgraded and much better version of both the Etherum and Bitcoin. BOScoin is however built to assist in trust contracts that usually provide a more approachable framework for creation and execution of blockchain contracts. Trust contracts are those secure and executable contracts tha...

PRO Commerce - Coin Back Rewards

A new and promising project is the upcoming PRO Commerce Project. In essence the project is about getting Rebates and Crypto currencies into 1 platform. Something which is not new, because the INCENT project is also about that, however the PRO project has a different approach in achieving their goals. Their platform will be the main field where the project and business model should excel and make the project a success. The platform The goal of the PRO Platform is to create awareness and engagement, something which by just offering rebates is not sufficient, however holding PRO makes the user also an spectator and the team behind Pro believes this will make a difference in the way users will be committed and engaged in the project. By holding the coins they will eventually use the coins to speculate and use it. The app within the platform itself consist of 4 main components which according to the team will add a tremendous value to any business, making it the main app to use in compar...