Victims Lose $70K to Malicious Wallet App on Google Play Store in Latest Crypto Scam
A recent crypto wallet-draining scam has cost victims $70,000, targeting users through a fraudulent app on Google’s Play Store.

A recent crypto wallet-draining scam has cost victims $70,000, targeting users through a fraudulent app on Google’s Play Store.
Dubbed a world-first by researchers, this attack exploited Web3 users by impersonating the widely trusted WalletConnect protocol, which does not have an official app on Google Play.
The malicious app deceived over 10,000 users with fake reviews and promises of seamless decentralized wallet connectivity.
Victims lose $70k to one single wallet-draining app on Google's Play Store https://t.co/MbULEfqhWP
— Nicolas Krassas (@Dinosn) September 26, 2024
However, investigators found that over 150 wallets were compromised, resulting in significant financial losses for unsuspecting users.
How the Malicious App Operated
The fraudulent app leveraged user trust by using the WalletConnect logo and name, tricking individuals into thinking it was a legitimate product.
Once downloaded, users were instructed to link their crypto wallets, believing it would simplify their web3 experience. However, when users authorized transactions through the app, they were directed to a malicious website that captured sensitive wallet data.
⚡️ WalletConnect – just announced registration for AirDrop token $WCT 🪂
✅ What we do❔
🟠 Go to the website (https://t.co/IYwFfMlLHT) (connect via Wallet Connect by QR – from mobile wallet)
🟠 Connect via QR indicated on the photo
💪Likes and reposts💪🏻$LINGO $WCT $TON pic.twitter.com/4C5KMpL3Kz
— Godheit.eth (@Godheit_eth) September 25, 2024
This allowed attackers to manipulate smart contracts and drain victims’ wallets, prioritizing the transfer of high-value tokens.
Key Attack Steps
- Victims were prompted to link wallets to the app.
- Users were misled into authorizing transactions.
- Attackers siphoned funds from linked wallets through smart contract exploits.
Google’s Response and Lessons Learned
Despite Google Play’s vetting process, the app managed to avoid detection for five months after its launch in March. Only after $70,000 was stolen from victims did Google finally remove the app from its platform.
Google claims its Play Protect service can block malicious apps, but incidents like this highlight vulnerabilities in in-app security.
Google’s experience provides software developers a roadmap to address one of the most persistent security problems: memory-safety CVEs. https://t.co/jv0vfr3Lew
— René (@Rene_Telemann) September 26, 2024
This breach serves as a wake-up call for crypto users. Alexander Chailytko, cybersecurity expert at Check Point Research, emphasizes the need for advanced, AI-driven security measures to safeguard digital assets in the rapidly evolving decentralized finance space.
Key Takeaways
- Over 150 victims lost funds due to the fake WalletConnect app.
- Google Play removed the app, but not before $70,000 was stolen.
- Experts stress the importance of advanced security solutions for decentralized finance.
- Check out our free forex signals
- Follow the top economic events on FX Leaders economic calendar
- Trade better, discover more Forex Trading Strategies
- Open a FREE Trading Account
Related Articles
Comments
Sidebar rates
HFM
Related Posts
Doo Prime
XM
Best Forex Brokers
