Strict Standards: Only variables should be passed by reference in /home/blog/web/masterinvest.info/public_html/core/modules/show.full.php on line 364 Выявлена уязвимость в криптокошельке Coinomi. В криптовалютном кошельке Coinomi обнаружена брешь в безопасности. Coinomi уязвим
0.29%
0.31%
0.26%
BTC
$64,165.16
0.46%
0.39%
3.98%
ETH
$1,728.69
0.35%
0.59%
3.04%
BNB
$589.55
0.59%
0.01%
1.18%
XRP
$1.15
0.62%
3.40%
9.80%
SOL
$74.08
0.04%
0.74%
2.50%
TRX
$0.32631914
0.30%
0.14%
3.31%
DOGE
$0.08348022
0.67%
0.26%
2.77%
ADA
$0.16243269
0.49%
0.33%
1.68%
LINK
$7.97
0.70%
2.59%
3.01%
LTC
$45.39
0.29%
0.31%
0.26%
BTC
$64,165.16
0.46%
0.39%
3.98%
ETH
$1,728.69
0.35%
0.59%
3.04%
BNB
$589.55
0.59%
0.01%
1.18%
XRP
$1.15
0.62%
3.40%
9.80%
SOL
$74.08
0.04%
0.74%
2.50%
TRX
$0.32631914
0.30%
0.14%
3.31%
DOGE
$0.08348022
0.67%
0.26%
2.77%
ADA
$0.16243269
0.49%
0.33%
1.68%
LINK
$7.97
0.70%
2.59%
3.01%
LTC
$45.39
   /   

A Vulnerability Discovered in the Coinomi Crypto Wallet


Programmer Warith Al Maawali has discovered a security breach in the Coinomi cryptocurrency wallet, as a result of which the Coinomi crypto wallet sends users' passphrases to the Google spell-check service in unencrypted form, thereby opening up access for scammers to private information and giving them the opportunity to take over users' funds. This breach in the wallet's security was discovered during the investigation of the mysterious theft of 90% of the programmer's funds. Al Maawali discovered that during the setup of the Coinomi wallet, when users enter the mnemonic phrase (seed), the Coinomi application captures the text data entered by the user and automatically sends it to the Google Spellcheck API service for spelling verification in plain form. "To understand what is happening, I will explain it technically," says Al Maawali. "the wallet interface is written in HTML and Java Script and is rendered using a built-in Chromium-based browser."

Like any other Chromium-based application, the wallet application is integrated with various Google-oriented features, such as the automatic spell-check function for all of the user's text input fields. It appears that the problem is that the Coinomi team did not bother to disable this function in the user interface code of their wallet, which led to a situation in which the backup phrases of all their users' wallets were leaking over HTTP during the wallet installation and setup process. Anyone able to intercept web traffic from the wallet application would be able to see the seed phrase of the Coinomi wallet application in unencrypted form. This phrase allows attackers to gain access, using the recovery function, to all funds stored in the user's wallet.

And although Al Maawali has no conclusive proof that this is exactly how the hackers gained access to his data, he claims that only those funds that were stored in the Coinomi wallet were stolen, and therefore he sees no other way to steal the cryptocurrency except through access to the Coinomi mnemonic phrase. "Anyone involved in technology and cryptocurrency knows that (…) 12 random English words separated by spaces are likely to be a passphrase for a cryptocurrency wallet," said Al Maawali.

The researcher created a dedicated website where he described the problem and the experiment he conducted in trying to get Coinomi to acknowledge the vulnerability. He also published a proof-of-concept video, which was later independently verified and reproduced by Luke Childs, a security researcher.

Coinomi, which offers a multi-cryptocurrency wallet application for Android, iOS, Linux, Mac and Windows, did not respond to the affected user's request with an offer to compensate for the stolen funds. However, an updated version of the application appeared the very next day after the user's appeal. Al Maawali claims that he lost between 60,000 and 70,000 US dollars in various cryptocurrencies. His version of the theft of funds is confirmed by other messages in the Coinomi thread on the Reddit forum, where users complain that one day they woke up and discovered that all their Coinomi wallets had been emptied overnight.
01-03-2019
Безопасность в сети / Кошельки для криптовалют

Безопасность в сети / Кошельки для криптовалют

A New Trojan Disguises Itself as a Browser ExtensionA New Trojan Disguises Itself as a Browser ExtensionCryptopia Cryptocurrency Exchange HackedCryptopia Cryptocurrency Exchange HackedCritical vulnerability in the Beam Wallet crypto walletCritical vulnerability in the Beam Wallet crypto walletDisabling of a number of security features in Samourai WalletDisabling of a number of security features in Samourai Wallet

Random quote about money

"Уберечь свои деньги стоит больших трудов, чем добыть их."

Мишель де Монтень

Interesting posts in other sections of the blog

Information

Users of Guests are not allowed to comment this publication.

Latest articles

all articles →
Weekly: биткоин ищет дно, ФРС «без сюрпризов», кризис и другой курс майнинга и проблемы Binance в ЕСНовости в мире криптовалютWeekly: биткоин ищет дно, ФРС «без сюрпризов», кризис и другой курс майнинга и проблемы Binance в ЕСРедакция Incrypted подготовила для вас очередной дайджест о главных событиях в сфере Web3 за неделю. В нем мы расскажем о сигналах возможного дна биткоина и21-06-2026Axelar сообщил о взломе моста с Secret Network на $4,67 млнНовости в мире криптовалютAxelar сообщил о взломе моста с Secret Network на $4,67 млн19 июня блокчейн-проект Axelar раскрыл взлом моста с протоколом Secret Network. Злоумышленник вывел около $4,67 млн, использовав уязвимость «бесконечного21-06-2026Путать евро-стейблкоины и цифровой евро — дорогая ошибкаНовости в мире криптовалютПутать евро-стейблкоины и цифровой евро — дорогая ошибкаСтарший директор по стратегии и политике ЕС в компании Circle Патрик Хансен подчеркнул, что евро-стейблкоины и будущий цифровой евро от Европейского21-06-2026«Хищник стал добычей»: известный MEV-бот Ethereum потерял до $15 млн после ловушки с фальшивыми токенамиНовости в мире криптовалют«Хищник стал добычей»: известный MEV-бот Ethereum потерял до $15 млн после ловушки с фальшивыми токенамиАналитическая компания Blockaid сообщила об успешной атаке на одного из самых известных MEV-ботов в экосистеме Ethereum — jaredfromsubway.eth. Инцидент21-06-2026Bitdeer за год нарастила добычу биткоина на 370%Новости в мире криптовалютBitdeer за год нарастила добычу биткоина на 370%В мае компания Bitdeer добыла 921 BTC против 196 BTC годом ранее — рост составил 370%. Собственный хешрейт за этот период увеличился почти на 420%, с 13,6 EH/s21-06-2026Мошенник выдал сам себя, пожаловавшись ZachXBT на заморозку биткоиновНовости в мире криптовалютМошенник выдал сам себя, пожаловавшись ZachXBT на заморозку биткоиновОнчейн-детектив ZachXBT рассказал историю о мошеннике, который невольно выдал сам себя. Подписчик под ником AmanKesar11 написал ему с жалобой на21-06-2026Incrypted Conference 2026 — Ukraine's largest crypto conference — was held in KyivНовости в мире криптовалютIncrypted Conference 2026 — Ukraine's largest crypto conference — was held in KyivOn June 13, 2026 Kyiv hosted Incrypted Conference 2026 — the annual crypto conference organized by the team of the leading Ukrainian crypto media Incrypted.21-06-2026A pension fund from Japan to invest 1% of its assets in a crypto fundНовости в мире криптовалютA pension fund from Japan to invest 1% of its assets in a crypto fundThe corporate pension fund Nationwide Business Corporate Pension Fund from Japan will allocate about 1% of its assets to cryptocurrencies in the 2026 financial21-06-2026Turkmenistan accelerates the digitalization of finance after legalizing the crypto marketНовости в мире криптовалютTurkmenistan accelerates the digitalization of finance after legalizing the crypto marketTurkmenistan is continuing its course toward digitalizing the economy and the financial sector, despite its status as one of the most closed countries in the21-06-2026
Sign inMasterInvest