Blockchain security firm SlowMist has flagged a new Linux-based threat that targets crypto recovery phrases by exploiting trusted apps distributed through the SnapBlockchain security firm SlowMist has flagged a new Linux-based threat that targets crypto recovery phrases by exploiting trusted apps distributed through the Snap

SlowMist Flags Snap Store Attack Targeting Crypto Seed Phrases

  • The attackers hijacked the publishers on the Snap Store using expired domains and distributed malicious updates for the wallet.
  • The fake apps imitated Exodus, Ledger Live, and Trust Wallet in order to deceive users into entering their recovery phrases.
  • The attack is indicative of the increasing trend towards supply chain attacks rather than smart contract attacks.

Blockchain security firm SlowMist has flagged a new Linux-based threat that targets crypto recovery phrases by exploiting trusted apps distributed through the Snap Store. The company warned that attackers are hijacking long-standing Snap Store publisher accounts and pushing malicious wallet updates through official distribution channels, putting long-time Linux users at risk.

In a post on X, SlowMist chief information security officer 23pds said attackers are abusing expired domains linked to legitimate Snap Store publishers. After regaining control of those domains, the attackers reset account credentials, take over trusted developer accounts, and publish malware disguised as wallet software updates. This tactic gives the attack a dangerous advantage: users often trust updates from established publishers and install them without suspicion.

Once the malicious apps land on a victim’s system, they prompt users to enter crypto wallet recovery phrases. The malware then exfiltrates those phrases, allowing attackers to drain wallets quickly, often before the victim realizes anything went wrong.

Attackers hijack Snap Store publishers using expired domains

The Snap Store is the official app store for Linux, used for the distribution of software that is packaged as “snaps.” It is considered a trusted source by many users, just like the App Store or Microsoft Store, as it provides verified publishers, easy updates, and a centralized distribution.

SlowMist said attackers are targeting publisher accounts tied to domains that have expired. Once a domain expires, criminals can re-register it and gain access to domain-linked email addresses. From there, they can initiate password resets and seize control of Snap Store developer accounts.

This method enables attackers to compromise publishers with active users and existing download histories. Rather than depending on victims to download the malicious new apps, they inject the malware into the regular updates. This supply chain tactic increases the success rate because users are more likely to accept updates and not check all the changes.

SlowMist has identified at least two domains associated with the compromised publisher accounts: “storewise[.]tech” and “vagueentertainment[.]com.” Once the attackers hijacked the accounts, they allegedly used the apps to impersonate popular crypto wallet brands.

Fake wallet apps mimic trusted brands

According to SlowMist, the affected Snap Store apps are clones of popular wallet applications like Exodus, Ledger Live, and Trust Wallet.  Attackers use user interfaces that closely resemble legitimate applications, which increases credibility and reduces suspicion.

These apps, after being installed or updated, will ask the user to input their wallet recovery phrase with the intention of wallet setup, sync, or account verification. After the user has provided the wallet recovery phrase, the attacker can use this phrase to restore the wallet and drain its funds without needing any further access to the victim’s device.

This approach remains very effective because seed phrases provide full control of the assets. Even the strongest passwords and device security cannot protect funds once hackers possess the recovery phrase.

Supply-chain hacks grow more damaging

The incident at the Snap Store is part of a larger trend in crypto security, where attackers are moving from exploiting protocols to compromising infrastructure. Instead of attacking smart contracts directly, criminals increasingly target trusted software distribution systems, update channels, and third-party service providers.

CertiK data shared with the media house in December showed crypto hack losses reached $3.3 billion in 2025, even though the number of incidents declined. According to CertiK, the losses were more concentrated in fewer but more serious supply chain events, with $1.45 billion in losses being attributed to only two major incidents.

This trend indicates that attackers are optimizing for scale and impact. With the improvement of DeFi security at the smart contract level, attackers target the weakest links, apps, publishers, and update infrastructure, where trust is the biggest vulnerability.

What users should watch next?

For Linux users who keep crypto, the wallet software download and update processes must be done with extra care. Users need to verify the identity of the publishers, check the official download sources, and avoid entering recovery phrases on unfamiliar platforms. Security teams may also need to monitor Snap Store listings more closely, especially when there are sudden changes in the ownership of publishers.

The takeaway from the SlowMist alert is clear: the greatest danger now often comes from trusted sources, not the obvious phishing scams.

Highlighted Crypto News:

Tom Lee Warns Crypto Markets Could Face Painful Correction in 2026

Market Opportunity
Belong Logo
Belong Price(LONG)
$0,003561
$0,003561$0,003561
-0,28%
USD
Belong (LONG) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Price Prediction: Ripple CEO at Davos Predicts Crypto ATHs This Year – $5 XRP Next?

XRP Price Prediction: Ripple CEO at Davos Predicts Crypto ATHs This Year – $5 XRP Next?

XRP has traded near $1.90 as Ripple CEO Brad Garlinghouse has predicted from Davos that the crypto market will reach new highs this year. Analysts have pointed
Share
Coinstats2026/01/22 04:49
What Is Jawboning? Jimmy Kimmel Suspension Sparks Legal Concerns About Trump Administration

What Is Jawboning? Jimmy Kimmel Suspension Sparks Legal Concerns About Trump Administration

The post What Is Jawboning? Jimmy Kimmel Suspension Sparks Legal Concerns About Trump Administration appeared on BitcoinEthereumNews.com. Topline Legal experts have raised concerns that ABC’s decision to pull “Jimmy Kimmel Live” from its airwaves following the host’s controversial comments about the death of Charlie Kirk, could be because the Trump administration violated free speech protections through a practice known as “jawboning.” Jimmy Kimmel speaks at Disney’s Advertising Upfront on May 13 in New York City. Disney via Getty Images Key Facts Disney-owned ABC announced Wednesday Kimmel’s show will be taken off the air “indefinitely,” which came after ABC affiliate owner Nexstar—which needs Federal Communications Commission approval to complete a planned acquisition of competitor Tegna Inc.—said it would not air the program due to Kimmel’s comments Monday regarding Kirk’s death and the reaction to it. The sudden move drew particular concern because it came only hours after FCC head Brendan Carr called for ABC to “take action” against Kimmel, and cryptically suggested his agency could take action saying, “We can do this the easy way or the hard way.” While ABC and Nexstar have not given any indication their decisions were influenced by Carr’s comments, the timing raised concerns among legal experts that the Trump administration’s threats may have unlawfully coerced ABC and Nexstar to punish Kimmel, which could constitute jawboning. Jawboning refers to “the use of official speech to inappropriately compel private action,” as defined by the Cato Institute, as governments or public officials—who cannot directly punish private actors for speech they don’t like—can use strongman tactics to try and indirectly silence critics or influence private companies’ actions. The practice is fairly loosely defined and there aren’t many legal safeguards dictating how violations of it are enforced, the Knight First Amendment Institute notes, but the Supreme Court has repeatedly ruled it can be unlawful and an impermissible First Amendment violation when it involves specific threats. The White…
Share
BitcoinEthereumNews2025/09/19 07:17
Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

TLDR Wormhole reinvents W Tokenomics with Reserve, yield, and unlock upgrades. W Tokenomics: 4% yield, bi-weekly unlocks, and a sustainable Reserve Wormhole shifts to long-term value with treasury, yield, and smoother unlocks. Stakers earn 4% base yield as Wormhole optimizes unlocks for stability. Wormhole’s new Tokenomics align growth, yield, and stability for W holders. Wormhole [...] The post Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future appeared first on CoinCentral.
Share
Coincentral2025/09/18 02:07