Cover photo

Hacking Your Wallet, by NOT Hacking Your Wallet

No, no, I’m NOT going to hack your wallet or use any of these techniques. Besides I practically dox myself all the time if you follow my Twitter. But you know these times, and you gotta title how you gotta title you know?

Many times - far too many to count - I attend a San Francisco Web3 event and in my intro spiel I mention security and I’m met with the question, “why would I care about security in Web3?” I laugh, and say that’s a good one. No really, “why would I care about security in Web3???” Ruh roh, they’re serious. The first couple of times I probably fired back with “what do you mean?!?!?!?!” accompanied by some very animated hand waving. But every once in a while I shut up long enough to listen. And I figured out the problem.

Part of the marketing and branding behind blockchains (hey, let’s be honest about what it is) has been that they are “secure”. If you’re a security professional or have dabbled, you probably know the C-I-A triad. No, not that CIA. This one is a mnemonic: C = Confidentiality, I = Integrity, and A = Availability. Security topics broadly fit into one of these three categories. The immutability of blockchains does provide a very robust defense for information integrity. Availability? Well, that has many, many, many times over proven to be a weakness of blockchains with transaction fee markets. Transaction flooding causes the price of transactions to increase and delays transactions from posting to the chain. How many of you have been part of a NFT project where minting had to be delayed because of out of control gas prices? Or seen a click-to-earn game cause a chain to grind to a halt. If the chain is too expensive to use or can’t process transactions fast enough to satisfy users - this is an availability weakness. Yes, it IS a security weakness. Confidentiality? Well, that one is a little tricky given the design of blockchains. Perhaps that’s a good topic for a future article…

So lesson 1 - blockchains are NOT 100% secure. They provide a defense for information integrity but are subject to availability denial attacks and other unique vectors. But that’s the blockchain. Unless you’re running a blockchain node, you’re not a member of that network. You simply interact with the blockchain, likely through far more layers than you realize. The most common tool for interacting with a blockchain is a crypto wallet. The wallet provides your address and a set of public/private key pairs that allows you to sign blockchain interactions for transferring digital assets or interacting with smart contracts. Fundamentally, a wallet is as secure as you can secure your private key. Thus, wallets are designed to minimize interactions with this private key. Hacking a wallet searching for cryptographic collisions - theoretically possible - is likely not worth the extreme effort. That’s why you hack a wallet, by NOT hacking the wallet.

Just this week, MetaMask drew attention by warning their users to disable iCloud backups if they have the iOS app installed. Are the wallet key pairs being backed up to iCloud? No, that doesn’t appear to be the issue, but a user’s wallet was compromised to the tune of $655k USD through phishing their Apple credentials. The MetaMask iCloud backup contained the Apple keychain that likely allowed the attackers to image a jailbroken device with that user’s iCloud backup populating a MetaMask instance with enough information to access that wallet and transfer the assets.

I know what you’re thinking - “I’m gonna delete my mobile wallets right now and only use my browser plugin!” I’m going to have to ask your thumb to please move away from that screen. I have some bad news for you. Browser plugin security? Yeah…same problem for starters. Most browsers ask you to create profiles so that you can have a more seamless browser experience across multiple devices. Guess what, if you have an account profile, plugin data is likely being stored as a backup or to enable cross-device access. If someone can access the browser account profile you use with your crypto wallet, they’ll be able to access that wallet as if it were you.

There are some even scarier vectors. I’m sure you’ve heard people say, “don’t screenshot your recovery seed phrase!” And that’s good advice. But what do you do? Do you copy and paste into some text file? If someone is able to gain access to your machine they will be able to recover even text that you’ve copy and pasted. And even worse, how would you know? A fundamental concept in security is IOCs - Indicators of Compromise. These are signals that a system has been compromised. For a wallet, there is only one IOC - when your assets are gone. And by then, it’s far, far, far too late.

You’ve probably even heard of cases where people have interacted with malicious contracts. You hear rumors of a hot new NFT airdrop and you paste your address into a website, and all of a sudden you’re signing some interaction with a smart contract. And then your assets are gone. In this case, this attack isn’t from a weakness of the wallet but a successful phishing attack. It’s a great example of a honeypot, when you entice victims with information that seems to be too good to be true - because it is.

But how would you find potential victims? Twitter. I am continually dumbfounded by the number of people that post screenshots of their wallets. Yes, I realize you’re proud of how much ETH or SOL you’ve made from degening NFTs. But, when you publicly broadcast that you’re sitting over $1M USD in a single crypto wallet, you’re making yourself a target. Think about that screenshot. It’s easy to identify which wallet you’re using based on the color scheme and fonts. Depending on the layout, you can probably even tell if it’s a mobile or browser wallet. And mostly importantly, if you’re as rich as you say you are, it’s YOURS. So now I know WHO to phish. You think you’re anonymous, but have you posted pictures of places you’ve been? Maybe a friend called you by your real name in a reply? Or someone tagged you in a group photo of friends? Sure it’s work, but when there’s a $1M USD worth of tokens at the end of trail, and it’s a trail hackers will follow - with glee.