- MetaMask has issued a warning regarding iCloud phishing attacks, saying, In case iCloud backups are enabled, their seed phrase is being kept online.
- MetaMask posted a thread on Twitter, where it noted that folks are going through a threatening path where they can lose their funds.
- This warning from MetaMask came as a response to an NFT collector on Twitter who asserted a loss of $650,000 worth of digital assets due to a security issue.
Phishing Alert !!
MetaMask, a wallet provider owned by ConsenSys, has issued a warning to the community about Apple iCloud phishing attacks.
Security concern for iPad, iPhone, and Mac users is associated with default settings on devices that see a folk’s seed phrase stored in iCloud if they have allowed accessibility to automatic backups for their application data.
As per a Twitter thread posted by MetaMask, users are running on a threatening route where their funds can get lost in case of a “weak” Apple password where a hacker is able to phish their account credentials.
🔒 If you have enabled iCloud backup for app data, this will include your password-encrypted MetaMask vault. If your password isn’t strong enough, and someone phishes your iCloud credentials, this can mean stolen funds. (Read on 👇) 1/3
— MetaMask 🦊💙 (@MetaMask) April 17, 2022
Why Was This Warning Issued?
The warning from MetaMask was a response to an NFT collector dubbed “revive_dom” on Twitter, who stated that their whole wallet got wiped out through a particular security issue. It reportedly was containing $650,000 worth of virtual assets.
Hey y’all, let’s see how amazing this community can be. My entire wallet was just stolen. Totally wiped out,
— Domenic Iacovone (@revive_dom) April 14, 2022
MAYC 28478, MAYC 8952, MAYC 7536
Gutter cat 2280 , 2769, 2325
Also stole 100k in ape coin.
Looking for all the help I can get.
100kreward @BoredApeYC @GutterCatGang
In another thread, “Serpent,” DAPE NFT project founder – who also assisted in gaining traction of MetaMask through posting story with their 277,000 followers — offered a rundown of what had occurred to a victim.
They highlighted that victim got multiple text messages requesting to reset his Apple ID password alongside a supposed call from Apple which was eventually a spoofed caller ID.
As they were purportedly unsuspecting of a caller, “revive_dom” handed over a 6 digit verification code to prove that they were the possessors of the Apple account. The fraudsters subsequently hung up and got accessibility to the MetaMask wallet through data kept in iCloud.
🚨 NEW PHISHING SCAM 🚨
— Serpent (@Serpent) April 17, 2022
Already $650,000 stolen from a single individual and it's going to happen to a lot more people.
This is how it happened 🧵👇
After MetaMask issued a warning, “revive_dom” showed his frustrations with the organization, highlighting that they are not saying that they should not do it but they can tell them. Don’t say that folks cannot store their seed phrase and then do it behind their backs. Only if 90% of the folks knew this, they wouldn’t enable iCloud.
While the majority of community members were supportive, others were swift to emphasize the significance of utilizing cold storage and doing a lot of due diligence when keeping assets in a hot wallet.
ALSO READ: Exploit in DeFi Governance protocol at Beanstalk Farms resulted in $182mn loss
- Crypto Mining Tax Introduced by The Biden Administration - May 4, 2023 12:00 pm EDT
- RPL Price Prediction: Rocket Pool to Propel Near Recent Peak - May 4, 2023 10:00 am EDT
- $22M crvUSD Minted Since its Mainnet launch by Curve Finance - May 4, 2023 9:30 am EDT