Bitcoin Forum
May 21, 2024, 12:27:56 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: A fake app in apple app store stole his life savings in bitcoin  (Read 406 times)
Hydrogen (OP)
Legendary
*
Offline Offline

Activity: 2562
Merit: 1441



View Profile
April 02, 2021, 11:05:37 PM
Last edit: April 03, 2021, 11:18:18 AM by Hydrogen
 #1

Quote
Recent scams show there are holes in Apple’s safety net

March 30, 2021

Phillipe Christodoulou wanted to check his bitcoin balance last month, so he searched the App Store on his iPhone for “Trezor,” the maker of a small hardware device he uses to store his cryptocurrency. Up popped the company’s padlock logo set against a bright green background. The app was rated close to five stars. He downloaded it and typed in his credentials.

In less than a second, nearly all of his life savings — 17.1 bitcoin worth $600,000 at the time — was gone. The app was a fake, designed to trick people into thinking it was a legitimate app.

But Christodoulou is angrier at Apple than at the thieves themselves: He says Apple marketed the App Store as a safe and trusted place, where each app is reviewed before it is allowed in the store.

Christodoulou, once a loyal Apple customer, said he no longer admires the company. “They betrayed the trust that I had in them,” he said in an interview. “Apple doesn’t deserve to get away with this.”

Apple bills its App Store as “the world’s most trusted marketplace for apps,” where every submission is scanned and reviewed, ensuring they are safe, secure, useful and unique. But in fact, it’s easy for scammers to circumvent Apple’s rules, according to experts. Criminal app developers can break Apple’s rules by submitting seemingly innocuous apps for approval and then transforming them into phishing apps that trick people into giving up their information, according to Apple. When Apple finds out, it removes the apps and bans the developers, the company says. But it’s too late for the people who fell for the scam.

Crypto scams are also common on Google’s Android and on the Web. But their presence on the Apple App Store is more surprising because Apple says it curates the store and checks each app, which creates high levels of consumer trust. The 15 to 30 percent commission Apple collects on all sales on the App Store goes to fund the “highly curated” customer experience, the company has said.

“User trust is at the foundation of why we created the App Store, and we have only deepened that commitment in the years since,” said Apple spokesperson Fred Sainz. “Study after study has shown that the App Store is the most secure app marketplace in the world, and we are constantly at work to maintain that standard and to further strengthen the App Store’s protections. In the limited instances when criminals defraud our users, we take swift action against these actors as well as to prevent similar violations in the future.”

The ability of apps to morph into something else entirely after they are approved by the App Store raises questions about the effectiveness of Apple’s review process to stop scammers. Apple wouldn’t say how often these scams appear, or how often it removes them. But it did say it removed 6,500 apps for “hidden or undocumented features” last year. Apple touts user safety as its defense against accusations from lawmakers, regulators and competitors that the company uses its monopoly over app distribution on iPhones anti-competitively.

“Apple frequently pushes myths about user privacy and security as a shield against its anti-competitive App Store practices,” said Meghan DiMuzio, executive director of the Coalition for App Fairness, which was formed to fight Apple’s power over its App Store. “The truth is, Apple’s security ‘standards’ are inconsistently applied across apps and only enforced when it benefits Apple.”

Apple acknowledged there have been other cryptocurrency scams on the App Store but wouldn’t say how many. Apple wouldn’t say whether fake Trezor apps had sneaked into the App Store in the past, or whether new apps called “Trezor” will be flagged as potentially fraudulent in the future.

Coinfirm, a U.K.-based company that specializes in cryptocurrency regulations and conducts fraud investigations, says it has received more than 7,000 inquiries about stolen crypto assets since October 2019. Fake apps in Google’s Android Play Store and Apple’s App Store are common, said Pawel Aleksander, the company’s chief information officer.

Coinfirm said five people have reported having cryptocurrency stolen by the fake Trezor app on iOS, for total losses worth $1.6 million. There have been three reports of fake Trezor apps on Android that stole a total of $600,000 in cryptocurrency
.

Apple would not name the developer of the fake Trezor app or provide the developer’s contact information. Apple wouldn’t say whether it was turning over the name to law enforcement or whether it investigated the developer further. Apple also wouldn’t say whether that developer had developed any other apps in the past or had connections to other developer accounts under different names.

“We don’t allow apps that mislead users by impersonating another app, developer or company, and when we discover an app that violates our policies, we take appropriate action,” said Google spokesperson Colin Smith.

Google said it knows of two fake Trezor apps that have appeared on the Google Play store. It removed both. It didn’t say how the Trezor apps made it onto the store. The company didn’t say whether it notified law enforcement, or how many other scam apps it has found on the store. It didn’t say whether it investigated the developers. Analytics firm App Figures was able to find eight fake Trezor apps that have appeared on the Play Store.

Of all the Internet scams, the theft of cryptocurrency is one of the most lucrative for thieves. Millions of dollars in digital currency can be pilfered in a split-second, and high-profile crypto heists have netted thieves as much as $530 million, which occurred in the Coincheck hack in 2018. In 2014, Apple banned crypto wallets on the App Store but then restored them the same year. Apple does not allow cryptocurrency mining apps, and it places extra restrictions on crypto wallet apps.

'Fortnite’ maker Epic faces uphill antitrust battle with Apple

To better secure their investments, people who own cryptocurrencies transfer their investments to “hardware wallets,” which are like USB thumb drives that store the secret and sensitive information a thief would need to steal someone’s cryptocurrency.

Hardware wallets plug into a computer via a USB connection. By typing in a PIN and sometimes an additional passphrase, the hardware wallet can be accessed and used to make transactions. If a hardware wallet is lost or destroyed, the information can be restored with a secret “seed phrase.” Some people keep the seed phrase in a safe-deposit box, hoping they’ll never have to use it, or etched on durable metal that can survive a fire. Scammers use phishing to trick people into giving up their seed phrases.

Trezor, based in the Czech Republic and owned by a company called Satoshi Labs, is a well-known maker of hardware wallets. Trezor doesn’t have a mobile app, but crypto thieves created a fake one and put it on Apple’s App Store in January and the Google Play Store in December, according to those companies, tricking some unsuspecting Trezor customers into entering their seed phrases.

Kristyna Mazankova, a spokeswoman for Trezor, said the company has been notifying Apple and Google for years about fake apps posing as a Trezor product to scam its customers. Trezor has never had a mobile app, though the company is working on one. She said the process of reporting the apps is “painful” and that representatives of Apple and Google haven’t been in contact.

Mazankova said Trezor notified Apple about a copycat app on Feb 1. Apple removed the app on Feb. 3, but it appeared again days later, according to Christodoulou, before it was removed again.

The fake Trezor app got through the app store through a bait-and-switch, according to Apple. Though it was called Trezor and used the Trezor logo and colors, it represented itself as a “cryptography” app that would encrypt iPhone files and store passwords, according to Apple. The developer of the fake Trezor app told Apple’s review team it “is not involved in any cryptocurrency.” Apple approved the app and it appeared in the App Store on Jan. 22, according to mobile analytics firm Sensor Tower.

Some time later, unbeknown to Apple, the Trezor cryptography app changed itself into a cryptocurrency wallet. Apple does not allow these sorts of changes, but Apple says it does not know when they occur. It relies on users and customers to report it when it happens, the company said.

After Trezor reported the fake app to Apple, Apple says it removed the app and banned the developer. Two days later, another fake Trezor app appeared. Apple removed that app, too. Apple did not say how it found out about the fake apps, but said it removed them because they were fraudulent.

Sensor Tower said the Trezor app was on the Apple App Store from at least Jan. 22 to Feb. 3 and appears to have been downloaded about 1,000 times. The app was downloaded about 1,000 times on Android, but Sensor Tower did not collect data on exactly when it became available.

James Fajcz, a reliability engineer at a paper company who lives in Savannah, Ga., also had his cryptocurrency stolen by the fake Trezor app, he says. In December, as he saw prices of the digital tokens rising, he purchased about $14,000 worth of Ethereum and bitcoin on Coinbase and Binance with money from his savings.

He wanted to make sure his investment was secure, so he purchased a Trezor Model T hardware wallet and downloaded an app on his iPhone called Trezor, which asked for his seed phrase. The app didn’t connect to his Trezor wallet, and he figured it didn’t work.

Weeks later, he purchased more Ethereum on Coinbase. He plugged in his Trezor device, but nothing was there. He went on the Trezor support forum on Reddit for answers. A Reddit poster informed him: There is no Trezor app. “My jaw dropped to the floor. My heart sank,” he said. “I realized what I did.”

Fajcz said he called Apple’s support line. An Apple representative said the company was not responsible, Fajcz says. “This was a trusted app on the App Store claiming to be the best and most trusted app store on any system anywhere,” he said. “And this nefarious app gets on the platform? I feel Apple should be held partially or fully responsible for that.”

Over a few years, Christodoulou had amassed 18.1 bitcoin. At the beginning of the coronavirus pandemic, each was worth about $5,500. By October, the price was starting to skyrocket, topping out at $60,000 early this year.

Christodoulou had hoped his bitcoin holdings would help save his dry-cleaning business, which was decimated during the pandemic. On Feb. 1, he wanted to be able to check his bitcoin balance using his phone, instead of a computer. So he checked the App Store, downloaded the fake Trezor app and entered his seed phrase.

Immediately afterward, he plugged his Trezor hardware wallet into his computer and logged in to check his balance. It was all gone.

That evening, Christodoulou went into the App Store again to look more closely at the reviews. Before it was removed, the Trezor app had 155 reviews on the App Store for a rating of close to five stars, according to App Figures, the analytics firm. When Christodoulou opened up the written reviews, he read complaints from other people who had been scammed in the same way. The five-star ratings that helped make the app seem legitimate must have been fake, he concluded.

Christodoulou called Apple customer support and a representative said he would escalate it to a supervisor. He said he also notified Apple and filed a report with the FBI. Lauren Hagee Glintz, an FBI spokeswoman, declined to comment on the report.

Chainalysis, a commercial blockchain analysis firm, reviewed documents provided by Fajcz and Christodoulou and confirmed that their cryptocurrency was moved from their wallets to a suspicious account. Both thefts appeared related, said Madeleine Kennedy, a spokeswoman for Chainalysis. “There’s evidence this is a substantial scam bringing in hundreds of thousands of dollars,” she said.

Only one of Christodoulou’s 18.1 bitcoin was spared because he transferred it to a bitcoin savings service called BlockFi. At the time of the theft, his 17.1 stolen bitcoin were worth $600,000, but they soon went up in value to $1 million.

Christodoulou says he’s taking medication and seeing a psychiatrist. “It broke me. I’m still not recovered from it,” he said.

He still hasn’t heard from Apple.

https://www.washingtonpost.com/technology/2021/03/30/trezor-scam-bitcoin-1-million/


....



Summary:  fake apps in google & apple app stores are stealing cryptocurrency.

Criminals trend towards targeting a path of least resistance. Browser extensions, apps in app stores, software libraries for languages like python all appear to be the most popular methods of stealing crypto atm. I think many of these attack vectors might be categorized as phishing. Where a malicious app is trusted and has vital seed, login and password data typed directly into it. Which allows criminals to hijack credentials for their own use.

This case is interesting in that I have not seen it receive much attention in terms of what approved safe methods of handling crypto are. Common rule of thumb is having sole access to private key. Not using browser wallets. But there is almost nothing said about avoiding 3rd party apps or browser plug ins which are sometimes known to be utilized to steal crypto.
sheenshane
Legendary
*
Offline Offline

Activity: 2422
Merit: 1228


Cashback 15%


View Profile WWW
April 02, 2021, 11:49:24 PM
 #2

There are common ways to steal our crypto, as long as we are connected to the internet, we are vulnerable to hack or even attack any phishing sites.

There are too many cases of fake apps or clone websites in Scam Accusations board, the worst thing is most commonly in Google Playstore and I don't know if the Apple apps store do the same with the Google store.  The problem is, why they didn't filter those fakes apps instead, there should be a verification of the legitimacy of apps before they will accept to be downloaded by the users.

Those criminals for now are very desperate of making money, especially most people who are unemployed due to the pandemic.  We should extend our diligence upon storing our digital assets on the internet and always verify the apps that we install or even the website that we use, verify first and should always on the official websites, not on the modified ones.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
oktana
Sr. Member
****
Offline Offline

Activity: 1610
Merit: 282


Eloncoin.org - Mars, here we come!


View Profile WWW
April 02, 2021, 11:51:53 PM
 #3

This is very sad. Truth is, it can happen to anyone. Sometimes we may be confident that we know it, yet, there's still that chance of being scammed directly or indirectly. I just hope less - no one fall for these scammers.



 

 

 

 

 

 


▄▄████████▄▄
▄▄████████████████▄▄
▄██
████████████████████▄
▄███
██████████████████████▄
▄████
███████████████████████▄
███████████████████████▄
█████████████████▄███████
████████████████▄███████▀
██████████▄▄███▄██████▀
████████▄████▄█████▀▀
██████▄██████████▀
███▄▄█████
███████▄
██▄██████████████
░▄██████████████▀
▄█████████████▀
████████████
███████████▀
███████▀▀
Mars,           
here we come!
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██████████
███████████
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
▀█
██████████████████████▀
▀██
███████████████████▀
▀███████████████████▀
▀█████████
██████▀
▀▀███████▀▀
ElonCoin.org.
████████▄▄███████▄▄
███████▄████████████▌
██████▐██▀███████▀▀██
███████████████████▐█▌
████▄▄▄▄▄▄▄▄▄▄██▄▄▄▄▄
███▐███▀▄█▄█▀▀█▄█▄▀
███████████████████
█████████████▄████
█████████▀░▄▄▄▄▄
███████▄█▄░▀█▄▄░▀
███▄██▄▀███▄█████▄▀
▄██████▄▀███████▀
████████▄▀████▀
█████▄▄
.
"I could either watch it
happen or be a part of it"

▬▬▬▬▬
TravelMug
Hero Member
*****
Offline Offline

Activity: 2646
Merit: 833



View Profile
April 03, 2021, 12:14:01 AM
 #4

I think it's more on Google Apps store than Apple as the later has a very tough security although hackers can still hide their intent but Apple is very active in removing this apps the soonest.

And this is not the first time that we have heard and going to hear this news. As part of being in crypto, it's our responsibility to really be careful as this hackers are plowing everywhere, from fake and phishing websites to malicious apps.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
April 03, 2021, 03:56:03 AM
 #5

I think it's more on Google Apps store than Apple as the later has a very tough security although hackers can still hide their intent but Apple is very active in removing this apps the soonest.
I wouldn't install anything sensitive without verifying its authenticity first. Apple doesn't allow sideloading apps and thus you can't validate the binaries before installing it. For Android, at least you can validate the signature before pushing the apk to your phone.

The problem with those apps is that they don't usually contain any malware or exploit but steals the key in a very obscure way such that it is hard to detect without any reports.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Kittygalore
Member
**
Offline Offline

Activity: 868
Merit: 63


View Profile
April 03, 2021, 03:58:52 AM
 #6

This is very sad. Truth is, it can happen to anyone. Sometimes we may be confident that we know it, yet, there's still that chance of being scammed directly or indirectly. I just hope less - no one fall for these scammers.
I agree that it can happen to anyone but the problem is that Apple boasts a security when it comes to allowing apps in there Appstore. I wouldn't really say that it is confidence because when you are confident, you are still careful falling for this is more like cockiness.
mk4
Legendary
*
Offline Offline

Activity: 2772
Merit: 3838


Paldo.io 🤖


View Profile
April 03, 2021, 03:59:49 AM
 #7

Quick note: While it's far less likely for shady apps to enter the Apple App Store compared to the Google Play Store, it's still not impossible. Funnily(and sadly) enough in this case, Trezor doesn't even support iOS devices currently..

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Poker Player
Legendary
*
Offline Offline

Activity: 1386
Merit: 2037



View Profile
April 03, 2021, 04:07:01 AM
 #8

While I feel sorry for that person, and understand that by sheer statistics, there are people who end up getting scammed in the end, I have a hard time understanding how someone with $600,000 doesn't take more precautions. On top of that it was almost all of their life savings. I wouldn't have them just in one place. And even less would I transfer them all to my cell phone.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
yhiaali3
Legendary
*
Offline Offline

Activity: 1708
Merit: 1872


#SWGT CERTIK Audited


View Profile WWW
April 03, 2021, 04:16:36 AM
 #9

Of course, the basic rule in Crypto says: You do not have your own keys = You do not own your coins, or in other words your private keys = your coins, the presence of a third party makes your coins under great danger, but often you are forced to deal with the services of the party Third, even in hardware wallets, you need to go to the wallet site to send your coins, for example I own a Trezor wallet, but I cannot send my coins from the wallet. I need to access the wallet via a web browser and this is a security vulnerability that can be exploited by attackers.

btc78
Full Member
***
Offline Offline

Activity: 2506
Merit: 212


Eloncoin.org - Mars, here we come!


View Profile
April 03, 2021, 04:24:35 AM
 #10

This is very sad. Truth is, it can happen to anyone. Sometimes we may be confident that we know it, yet, there's still that chance of being scammed directly or indirectly. I just hope less - no one fall for these scammers.
The saddest part is ? this is APPLE App in which the Highest and strongest security gadget provider in the world . In which majority of user believes they are very safe.

Though this is also a Users diligence yet because of the trust they gave in Apple security they tend to believe everything that pops in their Apple Store.

Try to make your Internet and Gadget using more safer , And do more secure features that we use to have now.

masterrex
Full Member
***
Offline Offline

Activity: 1820
Merit: 107



View Profile
April 03, 2021, 07:05:52 AM
 #11

Thats was a very unfortunate incident imagine that was his life savings and then in seconds it disappears. IMO, it was partly an Appstore fault because it was considered negligence on their side and why they let that fake app listed in their Appstore in the first place, this incident was also happening on Google Playstore thats why for precautionary measures check any app thoroughly for both Appstore and Playstore before using it just to make sure it was safe.
isaac_clarke22
Sr. Member
****
Offline Offline

Activity: 1596
Merit: 264


View Profile
April 03, 2021, 07:28:48 AM
 #12

It's sad that even one of the people from Trezor itself can't even get their voice heard.
App stores these days are more like reactive rather than proactive, wherein they would just respond to people that reported the app instead of dealing with it before the incident happened.

This is why mostly I don't use mobile apps a lot. Aside that I could be connected in an unsafe network outside my home, there are many hounds attempting to make me install malicious apps.
Even sometimes I even get paranoid in installing MEW's official mobile app. Cheesy
joniboini
Legendary
*
Offline Offline

Activity: 2198
Merit: 1792



View Profile WWW
April 03, 2021, 08:09:26 AM
 #13

IMO, it was partly an Appstore fault because it was considered negligence on their side and why they let that fake app listed in their Appstore in the first place, this incident was also happening on Google Playstore thats why for precautionary measures check any app thoroughly for both Appstore and Playstore before using it just to make sure it was safe.
According to some articles that I've read, the app was changed after it got approved by Apple. It was a tech app before (not a wallet) and then the attacker changed it when the app is no longer under scrutiny. Apple store should improve their security of course, but any crypto users should never trust these kinds of platforms in the first place. Should've checked on the official Trezor website before checking the app store.

Well, hopefully, everyone learns from this and stops losing their money due to bad security practices.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Kong Hey Pakboy
Member
**
Offline Offline

Activity: 1120
Merit: 68


View Profile
April 03, 2021, 09:00:00 AM
 #14

Thats was a very unfortunate incident imagine that was his life savings and then in seconds it disappears. IMO, it was partly an Appstore fault because it was considered negligence on their side and why they let that fake app listed in their Appstore in the first place, this incident was also happening on Google Playstore thats why for precautionary measures check any app thoroughly for both Appstore and Playstore before using it just to make sure it was safe.
It is more than unfortunate because it is a life savings and I don't think that I would be able to live with the fact that my life saving is going to get stolen from me, I mean that amount of money that you saved for a long time is frustrating and devastating. The problem with checking apps on the Appstore is that it is difficult because the quality check before publishing it in the appstore is the first line of defense and if that were to be defeated then users will have a hard time.

▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ★ ★ ★ ★ ★ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
PLINKO    |7| SLOTS     (+) ROULETTE    ▼ BIT SPINBITVESTPLAY or INVEST ║ ✔ Rainbot  ✔ Happy Hours  ✔ Faucet
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ★ ★ ★ ★ ★ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Bilgent
Member
**
Offline Offline

Activity: 518
Merit: 13


View Profile
April 03, 2021, 09:17:09 AM
 #15

This man blames Apple for this incident but I don't think that Apple has the full responsibility here. You have $600k worth Bitcoin and you are not being careful about where you keep them. And this causes you to be under a big threat of getting swindled.

██   ▀▀▀▀▀▀▀▀▀▀▀▀▀    ▄       BYBIT │ reddit       ▄    ▀▀▀▀▀▀▀▀▀▀▀▀▀   ██
   Sports & Derivatives Trading        Mobile App for iPhone & Android
   24/7 Customer Support        NFT Marketplace        Launchpad/Launchpool
AniviaBtc
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 272


First 100% Liquid Stablecoin Backed by Gold


View Profile
April 03, 2021, 10:43:30 AM
 #16

This is very sad. Truth is, it can happen to anyone. Sometimes we may be confident that we know it, yet, there's still that chance of being scammed directly or indirectly. I just hope less - no one fall for these scammers.

Sometimes it is not the company's fault when people are getting fooled by fake apps because it is the owner's responsibility to keep their device safe.

Scammers are good at making fake apps and fake schemes in order to lure their victim and there's something more for us to lose when we are not aware about this.

Apple is a famous company and yet it is prone to fake apps, device's security also depends on how the owner will manage to secure his gadget and especially digital wallets.

so98nn
Hero Member
*****
Offline Offline

Activity: 2086
Merit: 603


View Profile
April 03, 2021, 11:09:40 AM
 #17

Fooling user is getting very easy these days because cloning and app is so easy that one can clone the app with app cloner. I mean come on, if they were able to make app cloner then surely App Store can be infected with full of such forged clones. It’s really bad for the industry.

I assume one should not download the apps from App Store but from the Service Providers official website itself. That’s the best way to be safe.
concept2
Sr. Member
****
Offline Offline

Activity: 750
Merit: 258


View Profile
April 03, 2021, 11:12:42 AM
 #18

I heard the story yesterday. What a poor guy. $600,000 is a big amount of money. Furthermore, 17 bitcoin right now worth way more than $60000

Getting rid of centralization is hard because you need to be responsible for your own money and your finance in the world where are too many scammers desperate for money. Raising our awareness and education is the best way to avoid these cases. However, Apple also needs to in charge of the issue. They always claim that their app store is the most secure web store in the world but apparently, there many people losing their money from those "Verified" apps
davis196
Hero Member
*****
Offline Offline

Activity: 2982
Merit: 914



View Profile
April 03, 2021, 11:17:53 AM
 #19

This is nothing new.Malicious and fake smartphone apps have been a problem for years,and Google and Apple aren't going much in order to stop the scammers.It costs a $25 one-time fee to open a Google Play developer account and submit apps on the Google Play store.I don't know how the newly submitted apps are being reviewed,but there's not enough control for sure.
Newbies should be aware about all the smartphone app scams.They must use only proven and verified apps,that belong to trusted companies inside the crypto industry.

lionheart78
Legendary
*
Offline Offline

Activity: 2898
Merit: 1152



View Profile WWW
April 03, 2021, 11:21:15 AM
 #20

However, Apple also needs to in charge of the issue. They always claim that their app store is the most secure web store in the world but apparently, there many people losing their money from those "Verified" apps

Apple should take responsibility for this since they marked the app safe to use.  The user wouldn't use the app if it was never on the app store.  I would love to hear apple side on this but sadly it seems they are not saying anything regarding the issue.  Looks like they are playing safe on this one.

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!