UNKNOWN

DECEMBER 2019

GLOBAL

SHITCOIN WALLET

DESCRIPTION OF EVENTS

"ShitcoinWallet is an Ethereum wallet that lets you connect to the Ethereum blockchain." "Shitcoin Wallet Safe & Secure Currency. ShitcoinWallet is an Ethereum wallet that lets you connect to the Ethereum blockchain."

 

"Shitcoin Wallet, which launched late last year, is downloadable as an extension for Google Chrome. It invites users to create wallets, which they can then unlock with private keys or an authentication certificate. Shitcoin Wallet claims that these keys are encrypted, meaning the service shouldn’t be able to read them."

 

"Of course, being an Ethereum wallet means you can use it for managing, transferring, receiving your Ethers but also can use this wallet to interact with thousands of ERC20 tokens that thrive on the Ethereum blockchain."

 

"Safe And Secure. ShitcoinWallet is an Ethereum wallet that lets you connect to the Ethereum blockchain. Covered By Insurance. It is a web wallet which has several extensions for different browsers, which I will discuss further in the article. Decentralized Web. ShitcoinWallet also allows you to access the world of the decentralized web by letting you use several Ethereum DApps through it."

 

"AIRDROP 0.05 ETH FOR FI[R]ST 500 USERS." "Shitcoin Wallet is a best choice for holders, users of Shitcoin Wallet will receive many tokens everyday by our team and our partners. With many tokens have value in the market will be airdrop for our users, we hope our community knows more good projects as well as projects that can be introduced to more users."

 

"ShitcoinWallet creates your wallet on the local terminals and communicates with other blockchain networks, therefore the private key of your wallet is only stored on your local PC. Your wallet is 100% secure and you don’t need to worry about assets loss due to any hacker attack to ShitcoinWallet servers. Currently ShitcoinWallet is supported on Chrome."

 

"Just two days ago, Cointelegraph reported on an Ethereum (ETH) wallet Chrome browser extension known as “Shitcoin Wallet” that has reportedly been injecting malicious javascript code from open browser windows to steal data from its users."

 

"A browser crypto wallet is injecting malicious JS to steal secrets from @myetherwallet, @idexio, @binance, @neotrackerio, @SwitcheoNetwork. Extension-native wallet create also sends secrets to their backend!"

 

"Hackedzec’s story surfaced just a few days after Harry Denley, the director of security at MyCrypto, discovered that “Shitcoin Wallet”, a browser based Ethereum wallet that is listed on Google Chrome’s Web Store, was also malicious. Denley found that Shitcoin Wallet stole users private keys, as well as login information for sites such as Binance."

 

"Denley wrote on Twitter that it is injecting malicious javascript code to steal information. This, according to Denley, occurs in two ways. First, the extension snoops for credentials of any wallet created within the extension. Second, when users access Myetherwallet, Idex, Switcheo or NeoTracker, the extension steals log-in credentials and private keys."

 

"Shitcoin Wallet has since been listed on the domain warning list for the popular in-browser Ethereum dapp interface, MetaMask. “MetaMask believes this domain could currently compromise your security and, as an added safety feature, MetaMask has restricted access to the site,” states the message by MetaMask that pops up when entering the website for Shitcoin Wallet."

 

"Luckily, Shitcoin Wallet only has 625 users, according to the extension’s listing on the Chrome Web Store. One of them is already upset: “It steals your login data and your tokens do not download it is a scam,” commented Tony Nicklow today in a one-star review."

The Shitcoin Wallet extension was created as a supposed wallet for storing ethereum and handling ERC20 smart contracts. Multiple locations on the site advertised it as safe and secure, and the privacy policy even specifically states the private key is kept secure. However, the wallet is malicious and instead captures user data on multiple crypto-related websites, enabling the creator to steal people's fund. There were over 650 downloads before the application was removed rom the Google Play store. It's unknown what funds were lost, if any.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.