Attacks
A wallet app or browser extension that is a working copy, plus a copy of your keys. Counterfeit wallets appear in app stores, extension stores and search adverts. They look and work exactly like the real thing, right up to the moment they send your seed phrase to somebody else. Some sit quietly for weeks before emptying everything at once.
What it is
Counterfeit wallets appear in app stores, extension stores and search adverts. They look and work exactly like the real thing, right up to the moment they send your seed phrase to somebody else. Some sit quietly for weeks before emptying everything at once.
How it plays out
It ranks where you look
A paid search advert above the real site, or a store listing with a name one character out and fabricated reviews.
It behaves normally
You create or import a wallet and everything works.
The seed phrase leaves
At creation or at import, sent straight to the attacker.
It waits
Often until the balance is worth taking, which is why the loss can arrive long after the install.
What gives it away
- Found through an advert or a search result rather than the official site.
- A publisher name that is not the real company.
- A recent listing with a suspiciously high number of short reviews.
- An app asking to import a seed phrase before it has done anything useful.
How to not be caught by it
- Install only from the link on the project’s own website, which you typed yourself.
- Scroll past every advert. Attackers buy the top slot because it works.
- Check the publisher and the install count before installing anything.
- Buy hardware wallets only direct from the manufacturer, never from a marketplace.
- Never enter a seed phrase into anything except the device it belongs to.
If it already happened
- Assume the seed phrase is compromised and move funds from a clean device now.
- Generate a completely new wallet with a new seed. Do not reuse the old one, ever.
- Uninstall, then rebuild the device if a desktop extension was involved.
- Report the listing so it is pulled faster.
Common questions
How common is counterfeit wallets and extensions?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.