Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (2024)

Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (1)

A malicious Firefox add-on named "Safepal Wallet" scammed users by emptying out their wallets and lived on the Mozilla add-ons store for seven months.

Safepalis a cryptocurrency wallet application capable of securelyholdingmore than 10,000 types ofassets, including Bitcoin, Ethereum, and Litecoin.

Although the malicious browser add-on has been taken down, BleepingComputer has seen the phishing website set up by the threat actors is still up.

$4,000 lost to maliciousFirefox add-on

"Today I browsed [through] the add-on list of Mozilla Firefox, I was searching for Safepal wallet extensionto use my cryptocurrency wallet also in the web browser," explains a Mozilla add-ons user who goes by the name, Cali.

Little did Cali know what was coming for them. A few hours after installing and logging in to the add-onwith their real Safepal credentials, the user saw their wallet balance drop to $0.

"I was deep in shock... I saw my last transactions and saw that [$4,000 of my funds]were transferred to another wallet. I could not believe it [was an] add-on that is deployed in the add-on list of Mozilla Firefox," continuesthe user in Mozilla's support forum.

Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (2)

The add-on page for 'Safepal Wallet', seen by BleepingComputer, stated the add-onwas up since at least February 16th, 2021.

On the same page, the 235 KB add-on touts itself to bea Safepal application that securely "saves private keylocally," along withconvincing product imagesandmarketing materials.

To publishan add-on on Mozilla's website, developers are required to follow a submission processthat states submitted add-ons are "subject to review by Mozilla at any time." But, it isn't clear to what extent are submissions reviewed with regards to their safety.

Within five days of Cali's public report of the incident this month, a Mozilla spokesperson responded that they were investigating.The page has since beenremoved by Mozilla.

Although Safepal has officialsmartphoneapps available on bothApple AppStore and Google Play, we arenot aware of there being authentic 'Safepal' browser extensions.

Thankfully, on Mozilla add-ons store, someusers had posted one-star reviews warning others not to download 'Safepal Wallet':

Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (3)

But, for Cali, it seems a little too late in the game, and the chances of themgetting their funds back are bleak.

"I already talked with the police they can do nothing for me. They told me that there is no way they can trace the hacker. The only solution is left for me is maybe some of you can help me out by figuring out who the hacker was and how I can get my funds back," states the user.

BleepingComputer reached out to Mozilla to learn more about the issue:

"Extension security is important to Mozilla, and our ecosystem continually responds to changing threats," aMozilla spokesperson told BleepingComputer.

"Our recent focus has been on limiting the damage malicious extensions can do, helping users discover Recommended Extensions that we vet and monitor, helping users understand the risks that come with installing extensions, and making it easier for users to report potentially malicious extensions to us."

"When we become aware of add-ons that pose a risk to security and privacy according to our Add-on Policies, we take steps to prevent them from running in Firefox. In this instance, shortly after we became aware of potential abuse by this extension, we took action to block and remove it from the Firefox Add-on store."

"Users should be especially cautious about installing software that might have access to private information or financial resources."

'Safepal' phishing domainstill up, collecting recovery phrases

While investigating the malicious Firefoxadd-on, BleepingComputer came across the phishing domain used by the add-on. Thiswebpage, shown below,was also listed asthe "support site" link on the fake add-on's home page:

https://safeuslife.com/tool/

WHOIS recordsindicate the phishing site was registeredin January this year viaNamecheap. At the time of writing, the webpage is still liveand instructs the victim to key intheir "12-word Backup Phrase in the correct order to pair your SafePal Wallet."

Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (4)

But once the recovery phrase is entered and the form is submitted, the page simply refreshes without any noticeable response.The recovery phrase is silently sent to the attacker.

Cryptocurrency wallets, like many online services, use abackup phrase consisting of twelve randomly generated wordsthat can be used forrecovering the user's private key and wallet, shouldthey forget their password. But, the recovery phrase isa crucial secretmeant to be used under exceptionalcirc*mstances and only on thetrusted app or websiteof the service provider.

A stolen recovery phrase can grant attackers control over your wallet along with the ability to access andtransfer funds.

In recent times, cryptocurrency scams are growing, with threat actors are finding innovative and hard-to-detect ways to trick users. Just last week, someonehacked the official Bitcoin.org websiteandsuccessfully scammedvisitors for $17,000.

In previously seen attacks, open-source repositories, including npm, PyPI, and GitHub have been abused for spreading both cryptostealing and cryptomining malware.

With the increasing presence of threat actors on online platforms, users should be careful when providing their security phrases or transferringcryptocurrencyonline.

Mozilla additionallyrecommendsthe following steps for assessing the safety of any browser extension:

  1. Ask yourself: Is the extension from a brand or developer that I trust? Does the brand or developer’s official website link to an extension?
  2. Check to see if the developer’s website, blog, or social media activity is consistent with features of the extension
  3. Look at how many other users have installed the extension. Does it have a good star rating and positive reviews?

BleepingComputer has reached out toSafepalforcomment and we are awaiting their response. We have also reported the phishing domain in question to Namecheap.

Update, Sep 28th, 00:16: Added statement received from Mozilla after publishing.

Malicious 'Safepal Wallet' Firefox add-on stole cryptocurrency (2024)

FAQs

How do I withdraw Cryptocurrency from SafePal wallet? ›

A Guide to Withdrawing Funds from SafePal
  1. Step 1: Open the SafePal App. ...
  2. Step 2: Access Your Wallet. ...
  3. Step 3: Choose the Cryptocurrency to Withdraw. ...
  4. Step 4: Initiate the Withdrawal. ...
  5. Step 5: Enter the Recipient Address. ...
  6. Step 6: Specify the Amount to Withdraw. ...
  7. Step 7: Confirm the Withdrawal Details. ...
  8. Step 8: Confirm the Withdrawal.
Mar 26, 2024

Is SafePal wallet safe? ›

No data storage or leakage

SafePal is a decentralized wallet accessible to all users. It doesn't require any registration, KYC or identity verification. We don't store any personal information, including those for purchase orders. All purchase information is removed every 12 months.

How does SafePal hardware wallet work? ›

The SafePal Hardware Wallet stores the private key in a completely offline hardware device. To use it, users will need to pair the device with the SafePal App in order to send a withdrawal transaction or approve a Dapp login. Most people choose hardware wallet due to its advanced security in protecting the key.

How to get money from your crypto wallet to your bank account? ›

Browser
  1. Sign in to your Coinbase.com account.
  2. Select My Assets.
  3. Select your local currency balance.
  4. Select the Cash out tab and enter the amount you want to cash out.
  5. Select Transfer to and choose your cash out destination.
  6. Select Review.
  7. Select Withdraw cash to complete your transfer.

Who is the owner of SafePal Wallet? ›

Who is the founder of SafePal? Veronica Wong is the founder of SafePal.

Is SafePal a Chinese company? ›

Compare SafePal to Competitors

The company was founded in 2017 and is based in Zug, Switzerland.

What network does SafePal use? ›

SAFEPAL ASSETS
NameTypeNetwork
Litecoin(LTC)CoinLitecoin
Ethereum Classic(ETC)CoinEthereum Classic
Cosmos(ATOM)CoinCosmos
Stellar(XLM)CoinStellar
16 more rows

How many people use SafePal? ›

About SafePal:

The SafePal platform is backed by industry leaders Binance Labs, Animoca Brands, and SuperScrypt; serving over 10 million users globally and supporting 15 languages, 100+ blockchains with their fungible and non-fungible tokens.

What happens if I lose my SafePal Wallet? ›

After setting up the SafePal App, you can continue to recover the wallet. Choose 'Software Wallet' ---> 'Import Wallet' ---> ' Import via Mnemonic Phrase', and enter the Security Password you set at Step 2. At this step, enter your mnemonic phrase to recover the wallet.

How much is the network fee on SafePal? ›

Are there any fees? There are no account creation or management fees. The banking gateway and Visa card also offer the most competitive rates, with fiat transfer and deposit fees being as low as 0.6%.

How to get bitcoin off of SafePal? ›

This article shows how to withdraw crypto in the Binance DApp within the SafePal App.
  1. Step 1 Log in to the Binance DApp, and go to the 'Wallets' tab.
  2. Step 2 Select the token/coin you want to withdraw and click Withdrawal.
  3. Step 3 Enter the destination address and withdrawal amount, select the network, and click Withdrawal.
Dec 18, 2023

Can you buy coins with SafePal? ›

App. SafePal Wallet is the best crypto wallet for beginners and experts alike. Buy, sell and trade crypto – securely and on the go.

How do I authenticate my SafePal wallet? ›

By generating a 6-digit code, the hardware wallet device can be verified through a carefully designed algorithm. At the end of the authentication, the result will show whether the device is genuine and whether it has been used before.

How do I withdraw money from my wallet? ›

- Click on 'Paytm Wallet'. - Now, select the 'Transfer to Bank' option. - Enter the desired amount you want to transfer and click on the 'Transfer' button. - Enter your bank details, such as the bank account number, IFSC code, and account holder's name, to which you want to transfer the money.

How do I withdraw crypto from paper wallet? ›

Funds in a paper wallet can be retrieved by "sweeping" them into a software wallet (like Trezor or Exodus) or an exchange platform (such as Coinbase).

How do I withdraw bitcoins from my wallet? ›

A: To transfer Bitcoin to a bank account, sell your Bitcoin on a crypto exchange for fiat currency. Link your bank account to the exchange, complete identity verification, and then withdraw the fiat cash to your bank account. Withdrawal times and fees vary depending on the exchange.

Top Articles
Delete Transaction History in Google Pay: Check Transaction History
Sustained inflows in June narrowed H1 losses
Craigslist Niles Ohio
Fusion
Hay day: Top 6 tips, tricks, and cheats to save cash and grow your farm fast!
Heska Ulite
Snowflake Activity Congruent Triangles Answers
Camstreams Download
Kinkos Whittier
Cyndaquil Gen 4 Learnset
Libinick
Scout Shop Massapequa
We Discovered the Best Snow Cone Makers for Carnival-Worthy Desserts
Chaos Space Marines Codex 9Th Edition Pdf
Target Minute Clinic Hours
Elbert County Swap Shop
EVO Entertainment | Cinema. Bowling. Games.
Jurassic World Exhibition Discount Code
Jazz Total Detox Reviews 2022
Schooology Fcps
Craigslist Sf Garage Sales
Dtlr On 87Th Cottage Grove
Broken Gphone X Tarkov
Tmj4 Weather Milwaukee
Unm Hsc Zoom
Gideon Nicole Riddley Read Online Free
Kagtwt
Vanessa West Tripod Jeffrey Dahmer
Games R Us Dallas
Petsmart Northridge Photos
Muziq Najm
Bbc Gahuzamiryango Live
Lyca Shop Near Me
Evil Dead Rise (2023) | Film, Trailer, Kritik
Mvnt Merchant Services
Rs3 Bis Perks
Entry of the Globbots - 20th Century Electro​-​Synthesis, Avant Garde & Experimental Music 02;31,​07 - Volume II, by Various
sacramento for sale by owner "boats" - craigslist
Sand Castle Parents Guide
Garland County Mugshots Today
Ehome America Coupon Code
Login
✨ Flysheet for Alpha Wall Tent, Guy Ropes, D-Ring, Metal Runner & Stakes Included for Hunting, Family Camping & Outdoor Activities (12'x14', PE) — 🛍️ The Retail Market
Kjccc Sports
Sc Pick 3 Past 30 Days Midday
60 Days From August 16
Spn 3464 Engine Throttle Actuator 1 Control Command
Strange World Showtimes Near Century Federal Way
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 6116

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.