Skip to content

Instantly share code, notes, and snippets.

@tobtoht
Last active September 21, 2024 12:38
Show Gist options
  • Save tobtoht/4039fa3cf922d4fe8bca2f8e3ddac63b to your computer and use it in GitHub Desktop.
Save tobtoht/4039fa3cf922d4fe8bca2f8e3ddac63b to your computer and use it in GitHub Desktop.
Targeted phishing attack against several non-custodial cryptocurrency wallets

This document is a work in progress.

Affected projects


Caution: from here on, links in this gist may point to phishing sites.


Timeline

  • On April 27, 2024 the domain electrum[.]is is registered.
  • On May 09, 2024 the domain sparrowwallet[.]net is registered with Gname.com.
  • On May 11, 2024 the domain feather-wallet[.]org is registered with Namesilo.
  • On June 27, 2024 user Andyl98 adds these sites to the ArchLinux wiki. (The links have since been removed.)
  • On July 11, 2024 user welpok in #feather on OFTC first reports the existence of feather-wallet[.]org.
  • On September 18, 2024 the domains were added to uBlockOrigin's badware list.
  • On September 21, 2024 the client status code for feather-wallet[.]org was changed to clientHold.
  • As of September 21, 2024 the phishing sites for electrum and feather wallet are offline.

What we know so far

Additional resources

Extensive discussion on this topic can be found in Feather Wallet's matrix room.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment