• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • Hackers attack MetaMask users via phishing and steal $655,000
  • Cyber Security

Hackers attack MetaMask users via phishing and steal $655,000

Ddos April 19, 2022 3 minutes read
MetaMask hacker

Showing off your wealth on social networking sites is an easy thing to encounter, but if you are a cryptocurrency investor, it is recommended to be cautious about showing off your wealth on social networking sites. Hackers seem to be looking for investors who hold large amounts of assets through social networking sites, and then collect information in various ways and then conduct targeted phishing. At present, hackers steal $655K after picking MetaMask seed from iCloud backup.

🔒 If you have enabled iCloud backup for app data, this will include your password-encrypted MetaMask vault. If your password isn’t strong enough, and someone phishes your iCloud credentials, this can mean stolen funds. (Read on 👇) 1/3

— MetaMask 🦊🫰 (@MetaMask) April 17, 2022

According to the reminder issued by the official Twitter of MetaMask, if the user turns on iCloud automatic backup, the password-encrypted MetaMask vault will also be uploaded to the cloud. The seed refers to a secret recovery phrase consisting of 12 words that protect access to the wallet’s content. In theory, anyone who obtains the seed can restore the wallet and transfer wallet assets. The advantage of turning on the backup is that even if the phone is lost or the wallet is accidentally uninstalled, the data can be restored. The disadvantage is that it will be miserable if the Apple account is phished. For this reason, MetaMask reminds investors to turn off the backup function.

In the configuration file set by MetaMask, click iCloud and then turn off the backup function in the management storage (Settings > Profile > iCloud > Manage Storage > Backups), and the data will not be uploaded again.

The hackers first looked for potential targets on social networking sites, namely wealthy investors who used cryptocurrency wallets, and then collected the data. How the data is collected is unknown, but various social engineering must be indispensable. The hacker’s goal is to find the target user’s mobile phone number to send a phishing link. The hacker then sent multiple text messages to the target user to remind the user that the Apple account password needs to be reset, the account password may have been leaked elsewhere, and so on. After considering these circumstances, the user clicked the link to enter the phishing website made by the hacker, submitted the Apple account and password, and then the hacker logged in to the account.

https://twitter.com/Serpent/status/1515545808703488006

Apple account has two-step verification, but the hacker directly contacted the user to ask for the verification code. After getting the verification code, the hacker successfully logged in to the account to obtain data and then stole the wallet.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Webflow Weaponized: Phishing Attacks Target Crypto Wallets
  2. New Phishing Campaigns from Scattered Spider Target Finance and Insurance Industries
  3. Cyber Espionage and Influence: Unmasking APT28’s Tactics Sources and related content
  4. Salt Typhoon: China’s State-Sponsored Espionage Group Infiltrates Global Telecoms for Long-Term Cyber Warfare
  5. Fancy Bear Returns: APT28 Exploits Office Flaw in “Operation Neusploit”
Tags: MetaMask

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-3660CVSS 9.8
    IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0...
  • CVE-2026-8633CVSS 9.8
    IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5,...
  • CVE-2026-46624CVSS 9.9
    Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical...
  • CVE-2026-44668CVSS 9.8
    FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3,...
  • CVE-2026-45721CVSS 9.0
    Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when...
  • CVE-2026-7251CVSS 9.8
    Eppendorf BioFlo 320Β is vulnerable to due to VNC server using a hard-coded...
  • CVE-2026-7374CVSS 9.9
    A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an...
  • CVE-2026-45247CVSS 9.8
    Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains...
  • CVE-2026-9543CVSS 9.8
    A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.