Coinomi Wallet Transmits Plain-Text Seed Phrase…For Spellchecking!

Coinomi Wallet Transmits Plain-Text Seed Phrase…For Spellchecking!
фото показано с : bitcoinist.com

2019-2-27 17:00

Bitcoin software (and hardware) wallets are open to a bewildering array of attack vectors, because… well, money. Hackers will always be trying to exploit vulnerabilities or find back-doors. But Coinomi wallet apparently made things a bit too easy, by sending a plain-text seed to Google API for spellchecking.

How Do You Spell ‘Cleaned Out’?

The bug came to light after a user noticed $60k-70k of cryptocurrency had disappeared after installing the wallet. The user had entered the passphrase for another wallet into the restore field, to move some unsupported assets. A week later 90% of his main wallet funds were missing, comprising purely the Coinami-supported assets.

Some further investigation, using software to monitor http traffic from running applications, revealed the bombshell. When entering a passphrase in the ‘Restore Wallet’ field, it is sent as plain-text to googleapis.com for spell-checking. You can witness this in the video below:

https://avoid-coinomi.com/files/coinomi_http_traffic_video.mp4 How Do You Spell ‘WTF’?

In fact, entering any random sentence with a spelling mistake will result in a red-underline once the spellchecker has done its business. But why on earth would a wallet ever need to send the seed (or any other text) to a spellchecker? Spoiler… it wouldn’t.

Apparently the software used to build Coinami wallet has spellchecking enabled as default on any text-field. However, it is easy to disable this, and inexcusable that Coinami did not do this with such sensitive data.

Also worth noting is that the plain-text seed is sent over a secure socket layer. This means it should only be viewable by someone with access to http requests sent to googleapis.com.

HDYS ‘Stay Safe Out There’?

Coinami has apparently ‘quietly’ fixed the problem. But if your seed is already being held in plain text on a Google server somewhere, you might want to move your coins to a different wallet.

The user whose funds were stolen has been awarded a bug-bounty by Coinami, but isn’t happy with their response regarding his funds. For their part, Coinami have identified the addresses where the funds remain untouched since the ‘incident’. These addresses have been blacklisted, so no exchange will deal with them, but the user is demanding a more immediate resolution.

This isn’t the first time that Coinami has faced major privacy issues. Last year, there was an issue whereby the wallet was leaking user addresses in plain-text on opening.

I warned people to stay away from @CoinomiWallet last year after I discovered a major privacy issue where they were leaking all users address in plain text as soon as you open the app.https://t.co/a8UNKVICO7https://t.co/pIUY1eFxmjhttps://t.co/92HwU3Etfghttps://t.co/6oLwRSgvSC

— Luke Childs (@lukechilds) February 27, 2019

Have you used Coinomi? Share your experiences below!

Images courtesy of Shutterstock

The post Coinomi Wallet Transmits Plain-Text Seed Phrase…For Spellchecking! appeared first on Bitcoinist.com.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Money ($$$) на Currencies.ru

$ 0.0004099 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: -2.27 %
Cегодня L: $0.0004099 - H: $0.0004099
Капитализация $18.807k Rank 99999
Доступно / Всего 45.887m $$$

wallet coinomi spellchecking seed plain-text user had

wallet coinomi → Результатов: 14


Декстоп-кошелек Coinomi проверяет правописание seed-фраз. Функция позволила украсть $70 000 в криптовалюте

Пользователь под ником warith сообщил о пропаже $60 000 – $70 000 после установки криптовалютгного кошелька Coinomi с официального сайта. Spell check ur crypto-currency wallet’s passphrase remotely with #Coinomi 😂https://t.

2019-2-27 16:46


Десктоп-кошелек Coinomi проверяет правописание seed-фраз. Функция позволила украсть $70 000 в криптовалюте

Пользователь под ником warith сообщил о пропаже $60 000 – $70 000 после установки криптовалютного кошелька Coinomi с официального сайта. Spell check ur crypto-currency wallet’s passphrase remotely with #Coinomi 😂https://t.

2019-2-27 16:46


Redditor Claims Theft of $70,000 in Life Savings Due to Critical Coinomi Wallet Bug

According to cryptocurrency investor Warith Al Mawali, he has lost all of his life savings in the tune of $60,000 to $70,000 on Coinomi, a widely utilized crypto wallet on Android. In a detailed report, Mawali claimed that a critical vulnerability found on the wallet led to the loss of user funds as it compromised the private key of his wallet.

2019-2-27 16:31


Разработчик решений для хранения криптовалют Trust Wallet присоединился к фонду FIO

Фонд Foundation for Interwallet Operability (FIO) сообщает о присоединении к нему разработчика решений для хранения криптовалют и браузера децентрализованных приложений Trust Wallet, принадлежащего криптовалютной биржи Binance.

2019-2-11 13:00