The post SlowMist Flags Linux Snap Store Attack on Crypto Wallet Apps appeared on BitcoinEthereumNews.com. Blockchain security company SlowMist flagged a new LinuxThe post SlowMist Flags Linux Snap Store Attack on Crypto Wallet Apps appeared on BitcoinEthereumNews.com. Blockchain security company SlowMist flagged a new Linux

SlowMist Flags Linux Snap Store Attack on Crypto Wallet Apps

Blockchain security company SlowMist flagged a new Linux-based attack vector that exploits trusted applications distributed through the Snap Store to steal users’ crypto recovery seed phrases. 

In a post on X, SlowMist’s chief information security officer, 23pds, said attackers are abusing expired domains to hijack long-standing Snap Store publisher accounts and distribute malicious updates through official channels. 

The compromised applications reportedly impersonate popular crypto wallets, including Exodus, Ledger Live and Trust Wallet, using interfaces that closely resemble legitimate software.

Once installed or updated, the malicious apps prompt users to enter wallet recovery phrases, allowing attackers to exfiltrate credentials and drain funds without users realizing they have been compromised.

Source: 23pds

Attackers use expired domains to hijack Snap Store publishers

The Snap Store is the official Linux app store used to distribute software packaged in a format called “snaps.” It is commonly considered Linux’s equivalent of Apple’s App Store on macOS and the Microsoft Store on Windows.

SlowMist said the attack relies on monitoring Snap Store developer accounts linked to domains that have expired but were previously associated with legitimate publishers.

Once a domain expires, attackers can re-register it and use domain-linked email addresses to reset Snap Store account credentials. 

The SlowMist executive said the process allows attackers to quietly take control of established publisher accounts with existing download histories and active users. From there, malicious code can be pushed through routine software updates rather than fresh installations. 

SlowMist confirmed that two publisher domains, namely “storewise[.]tech” and “vagueentertainment[.]com,” have been compromised using the attack vector. Applications tied to the accounts were reportedly modified to impersonate well-known crypto wallets. 

Related: 80% of hacked crypto projects never ‘fully recover,’ expert warns

Supply-chain attacks grow as crypto exploits become more sophisticated

The Snap Store attack vector aligns with a broader shift in crypto-related threats, where attackers are increasingly targeting infrastructure and distribution channels rather than smart-contract code. 

CertiK data shared with Cointelegraph in December showed that total crypto hack losses reached $3.3 billion in 2025, despite a sharp decline in the number of individual incidents.

CertiK said losses became concentrated in fewer but more damaging supply-chain attacks, which accounted for $1.45 billion in losses across just two incidents.

The trend suggests that as protocol-level security improves, attackers are shifting toward higher-impact tactics that exploit trust relationships, software updates and third-party infrastructure. 

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/slowmist-linux-snap-store-crypto-seed-attack?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
RWAX Logo
RWAX Price(APP)
$0.0001849
$0.0001849$0.0001849
+5.83%
USD
RWAX (APP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

US regulators move toward unified crypto oversight as sec project crypto gains CFTC support

US regulators move toward unified crypto oversight as sec project crypto gains CFTC support

SEC PROJECT CRYPTO signals a shift as US regulators align SEC and CFTC oversight toward clearer rules for digital assets and markets.
Share
The Cryptonomist2026/01/30 19:21
SoFi Stock Jumps as Fintech Tops $1 Billion in Quarterly Revenue for First Time

SoFi Stock Jumps as Fintech Tops $1 Billion in Quarterly Revenue for First Time

TLDR SoFi Technologies reported fourth-quarter revenue of $1.01 billion, up 37% year-over-year, marking the first time quarterly revenue exceeded $1 billion The
Share
Blockonomi2026/01/30 21:23
Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

The post Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto appeared on BitcoinEthereumNews.com. Advertisement &nbsp &nbsp Forward Industries, the largest publicly traded Solana treasury company, has filed a $4 billion at-the-market (ATM) equity offering program with the U.S. SEC  to raise more capital for additional SOL accumulation. Forward Strategies Doubles Down On Solana Strategy In a Wednesday press release, Forward Industries revealed that the 4 billion ATM equity offering program will allow the company to issue and sell common stock via Cantor Fitzgerald under a sales agreement dated Sept. 16, 2025. Forward said proceeds will go toward “general corporate purposes,” including the pursuit of its Solana balance sheet and purchases of income-generating assets. The sales of the shares are covered by an automatic shelf registration statement filed with the US Securities and Exchange Commission that is already effective – meaning the shares will be tradable once they’re sold. An automatic shelf registration allows certain publicly listed companies to raise capital with flexibility swiftly.  Kyle Samani, Forward’s chairman, astutely described the ATM offering as “a flexible and efficient mechanism” to raise and deploy capital for the company’s Solana strategy and bolster its balance sheet.  Advertisement &nbsp Though the maximum amount is listed as $4 billion, the firm indicated that sales may or may not occur depending on existing market conditions. “The ATM Program enhances our ability to continue scaling that position, strengthen our balance sheet, and pursue growth initiatives in alignment with our long-term vision,” Samani said. Forward Industries kicked off its Solana treasury strategy on Sept. 8. The Wednesday S-3 form follows Forward’s $1.65 billion private investment in public equity that closed last week, led by crypto heavyweights like Galaxy Digital, Jump Crypto, and Multicoin Capital. The company started deploying that capital this week, announcing it snatched up 6.8 million SOL for approximately $1.58 billion at an average price of $232…
Share
BitcoinEthereumNews2025/09/18 03:42