SlowMist Flags Snap Store Attack Targeting Crypto Seed Phrases

TheNewsCryptoОпубліковано о 2026-01-21Востаннє оновлено о 2026-01-21

Анотація

Blockchain security firm SlowMist has identified a new Linux-based threat targeting cryptocurrency users through the Snap Store. Attackers hijack trusted publisher accounts by exploiting expired domains, then push malicious updates to popular wallet apps like Exodus, Ledger Live, and Trust Wallet. These fake apps prompt users to enter their recovery phrases, which are then stolen, enabling attackers to drain funds. This supply-chain attack exploits user trust in official update channels, making it highly effective. SlowMist warns users to verify publishers and avoid entering seed phrases on unfamiliar platforms, highlighting a growing trend of infrastructure-focused attacks in crypto security.

Blockchain security firm SlowMist has flagged a new Linux-based threat that targets crypto recovery phrases by exploiting trusted apps distributed through the Snap Store. The company warned that attackers are hijacking long-standing Snap Store publisher accounts and pushing malicious wallet updates through official distribution channels, putting long-time Linux users at risk.

In a post on X, SlowMist chief information security officer 23pds said attackers are abusing expired domains linked to legitimate Snap Store publishers. After regaining control of those domains, the attackers reset account credentials, take over trusted developer accounts, and publish malware disguised as wallet software updates. This tactic gives the attack a dangerous advantage: users often trust updates from established publishers and install them without suspicion.

Once the malicious apps land on a victim’s system, they prompt users to enter crypto wallet recovery phrases. The malware then exfiltrates those phrases, allowing attackers to drain wallets quickly, often before the victim realizes anything went wrong.

Attackers hijack Snap Store publishers using expired domains

The Snap Store is the official app store for Linux, used for the distribution of software that is packaged as “snaps.” It is considered a trusted source by many users, just like the App Store or Microsoft Store, as it provides verified publishers, easy updates, and a centralized distribution.

SlowMist said attackers are targeting publisher accounts tied to domains that have expired. Once a domain expires, criminals can re-register it and gain access to domain-linked email addresses. From there, they can initiate password resets and seize control of Snap Store developer accounts.

This method enables attackers to compromise publishers with active users and existing download histories. Rather than depending on victims to download the malicious new apps, they inject the malware into the regular updates. This supply chain tactic increases the success rate because users are more likely to accept updates and not check all the changes.

SlowMist has identified at least two domains associated with the compromised publisher accounts: “storewise[.]tech” and “vagueentertainment[.]com.” Once the attackers hijacked the accounts, they allegedly used the apps to impersonate popular crypto wallet brands.

Fake wallet apps mimic trusted brands

According to SlowMist, the affected Snap Store apps are clones of popular wallet applications like Exodus, Ledger Live, and Trust Wallet. Attackers use user interfaces that closely resemble legitimate applications, which increases credibility and reduces suspicion.

These apps, after being installed or updated, will ask the user to input their wallet recovery phrase with the intention of wallet setup, sync, or account verification. After the user has provided the wallet recovery phrase, the attacker can use this phrase to restore the wallet and drain its funds without needing any further access to the victim’s device.

This approach remains very effective because seed phrases provide full control of the assets. Even the strongest passwords and device security cannot protect funds once hackers possess the recovery phrase.

Supply-chain hacks grow more damaging

The incident at the Snap Store is part of a larger trend in crypto security, where attackers are moving from exploiting protocols to compromising infrastructure. Instead of attacking smart contracts directly, criminals increasingly target trusted software distribution systems, update channels, and third-party service providers.

CertiK data shared with the media house in December showed crypto hack losses reached $3.3 billion in 2025, even though the number of incidents declined. According to CertiK, the losses were more concentrated in fewer but more serious supply chain events, with $1.45 billion in losses being attributed to only two major incidents.

This trend indicates that attackers are optimizing for scale and impact. With the improvement of DeFi security at the smart contract level, attackers target the weakest links, apps, publishers, and update infrastructure, where trust is the biggest vulnerability.

What users should watch next?

For Linux users who keep crypto, the wallet software download and update processes must be done with extra care. Users need to verify the identity of the publishers, check the official download sources, and avoid entering recovery phrases on unfamiliar platforms. Security teams may also need to monitor Snap Store listings more closely, especially when there are sudden changes in the ownership of publishers.

The takeaway from the SlowMist alert is clear: the greatest danger now often comes from trusted sources, not the obvious phishing scams.

Highlighted Crypto News:

Tom Lee Warns Crypto Markets Could Face Painful Correction in 2026

TagsBlockchaincrypto securitylinuxSmart ContractSupply chain

Пов'язані питання

QWhat is the new threat flagged by SlowMist that targets crypto recovery phrases?

ASlowMist has flagged a new Linux-based threat that targets crypto recovery phrases by exploiting trusted apps distributed through the Snap Store. Attackers hijack long-standing publisher accounts and push malicious wallet updates.

QHow do attackers gain control of trusted Snap Store publisher accounts?

AAttackers abuse expired domains linked to legitimate publishers. They re-register the expired domains, gain access to domain-linked email addresses, reset account credentials, and take over the trusted developer accounts.

QWhich popular crypto wallet brands are being impersonated by the malicious apps in this attack?

AThe malicious apps are clones that impersonate popular crypto wallet brands like Exodus, Ledger Live, and Trust Wallet.

QWhy are supply-chain attacks like the one on the Snap Store becoming more damaging according to the article?

ASupply-chain attacks are becoming more damaging because attackers are targeting trusted software distribution systems and update channels, leading to fewer but more serious incidents with concentrated losses, as seen in the $1.45 billion attributed to just two major events in 2025.

QWhat precautions should Linux users take to protect themselves from such threats?

ALinux users should verify the identity of publishers, check official download sources, avoid entering recovery phrases on unfamiliar platforms, and monitor Snap Store listings for sudden changes in publisher ownership.

Пов'язані матеріали

Hyperliquid, Wall Street's All-Day Trading Convenience Store

**Hyperliquid: Wall Street's 24/7 Trading Convenience Store** Written by Vicky Ge Huang, Wall Street Journal. Hyperliquid, a decentralized crypto trading platform, has become a go-to venue for Wall Street traders, especially during weekends when traditional U.S. markets are closed. Operating 24/7, it allows traders to pre-position or close trades ahead of market opens, capitalizing on events like geopolitical news. The platform, founded by former Hudson River Trading quant Jeff Yan, offers perpetual contracts on a wide range of assets, including Bitcoin, the S&P 500, oil, and even pre-IPO companies like SpaceX. Its growth exemplifies the merging of traditional finance and crypto markets, attracting significant volume from professional traders seeking leverage and constant access. A key differentiator, according to Yan, is user self-custody of assets—a necessity highlighted by the FTX collapse. Despite U.S. regulatory restrictions, some American users reportedly access the platform via VPN, drawn by its ease of use, lack of stringent KYC, and strong community culture on platforms like Discord and X. The platform is not without risks. Perpetual contracts are complex and highly leveraged, leading to massive liquidations during market volatility. Hyperliquid itself saw $10 billion in liquidations during a market crash in October last year. Regulatory warnings emphasize insufficient risk disclosure for retail investors. With about 11 employees, Hyperliquid and its associated blockchain reportedly generated around $800 million in revenue last year. Its native token, HYPE, has surged over 100% since late 2024. The platform plans to expand into prediction markets and options trading, aiming to become a hub for all financial activity.

foresightnews_api2 хв тому

Hyperliquid, Wall Street's All-Day Trading Convenience Store

foresightnews_api2 хв тому

Former Bankless Member Lucas: Why I Still Bullish on Ethereum

Former Bankless member Lucas explains why he remains bullish on Ethereum despite widespread pessimism. He acknowledges ETH's poor price performance over the past five years compared to Bitcoin and traditional markets, but draws parallels to historical multi-year consolidations seen in tech giants like Amazon and NVIDIA before major breakouts. Fundamentally, Ethereum is stronger than ever: record-high daily transactions (2.27 million in May 2026), significantly lower average gas fees ($0.27), over 400 million total addresses, and more than 32% of ETH staked, securing the network. Lucas's core thesis remains unchanged: all valuable assets will eventually be tokenized, Ethereum will become the primary settlement layer for these assets, and ETH will capture the resulting value. This transition is already underway. Stablecoins, the first proven tokenized real-world asset (RWA), have a $300+ billion market cap, with 54% settled on Ethereum. The broader RWA sector has surpassed $30 billion, with over 53% deployed on Ethereum. He compares the current RWA adoption phase to early DeFi in 2019-20, suggesting immense growth potential. Key catalysts like the potential passage of the U.S. CLARITY Act in 2026 could accelerate institutional adoption. While other blockchains will share the market, Lucas argues that traditional finance prioritizes Ethereum's security, stability, and established ecosystem for trillion-dollar asset tokenization. He concludes that as global assets migrate on-chain, the market will reprice ETH accordingly.

foresightnews_api6 хв тому

Former Bankless Member Lucas: Why I Still Bullish on Ethereum

foresightnews_api6 хв тому

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

Democratic Senators Bernie Sanders (I-VT) and Elizabeth Warren (D-MA), along with Rep. Bobby Scott (D-VA), are urging the Labor Department to repeal a proposed rule that would open U.S. retirement savings accounts, like 401(k) plans, to investments in Bitcoin and other cryptocurrencies. In a letter to Acting Labor Secretary Keith Sonderling, they argue the rule would endanger workers' financial futures and contradicts long-standing legal precedents under the Employee Retirement Income Security Act (ERISA). The rule, stemming from a Trump executive order, would shift the legal standard for plan fiduciaries. Instead of requiring them to prove they conducted due diligence on volatile assets, it would presume prudence if they followed a specified process. The lawmakers warn this exposes the $14.2 trillion in 401(k) savings to highly volatile and less-regulated assets, citing FINRA warnings on crypto's risks and FBI data on massive crypto scam losses. The letter also alleges a conflict of interest, noting that President Trump's adult children manage the family's crypto business, which has raised billions. They claim the rule could allow the Trump family to profit at the expense of workers and retirees. Consumer advocates echo concerns that it could turn retirement savings into a lifeline for a risky industry. The Trump administration defends the rule as expanding worker choice, with officials stating it ends the department "picking winners and losers" and requires fiduciaries to follow a prudent process.

foresightnews_api9 хв тому

Trump's 'Bitcoin Retirement Plan' Hits Roadblock: Democrats Claim It Endangers American Workers' Pensions?

foresightnews_api9 хв тому

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

A nearly $150 million prediction market contract on Polymarket is in turmoil after the platform refused to settle in favor of traders who correctly predicted that MicroStrategy (now Strategy) would sell Bitcoin. The core dispute revolves around a sale of 32 BTC, which occurred between May 26-31 but was officially disclosed in an SEC 8-K filing on June 1. The original contract stated it would resolve to "Yes" if Strategy sold any Bitcoin before May 31, 11:59 PM ET, using public disclosures and on-chain data as proof. After the filing on June 1, traders who saw the disclosure rushed to buy "Yes" contracts, believing it was conclusive evidence. However, Polymarket's operators later added a rule that the disclosure itself must occur by the deadline, not just the transaction, invalidating the filing as proof. This retroactive rule change has sparked accusations of market manipulation, leaving traders like "willo2," who invested $527,000, facing total losses. The controversy highlights a deeper structural flaw in Polymarket's decentralized settlement system, which relies on UMA's optimistic oracle. Disputed resolutions are ultimately decided by a vote among UMA token holders, a mechanism critics say is vulnerable to manipulation by large holders ("whales") who can vote in their own financial interest rather than on objective facts. Data suggests a high concentration of voting power and significant overlap between voters and Polymarket traders. The dispute emerges as prediction markets like Polymarket and Kalshi are experiencing massive growth and seeking mainstream financial legitimacy, having recently secured regulatory approval from the U.S. CFTC. However, the incident underscores the unresolved tension between decentralized, token-vote-based settlement and the need for transparent, rules-based outcomes in high-stakes financial contracts.

foresightnews_api12 хв тому

Rules Change Mid-Game, Polymarket’s Billion-Dollar Bitcoin Prediction Market Mired in Settlement Controversy

foresightnews_api12 хв тому

Торгівля

Спот
Ф'ючерси
活动图片