Author

Topic: ★ Please read carefully before Install any coin wallet on your device ★ (Read 346 times)

copper member
Activity: 1204
Merit: 737
✅ Need Campaign Manager? TG > @TalkStar675
Just because a wallet is on GitHub, it DOES NOT mean that it is safe or has been audited or is the legit wallet. It is also insanely easy for scammers to fork a GitHub repo... and setup a fake version of the wallet that steals private keys. Very few users will ever bother to fully vet a GitHub repo to check the owner, the history, commits etc and whether the code is legit.

The recent Electrum attack involved directing users to a fake GitHub repo to download a fake version of the wallet.

Yeah that's why I have already mentioned on the thread not to trust any social media platform for wallet download. Honestly you can't trust social platform wallet download link blindly. I suggested here to follow coinmarketcap wallet link to get best results. Otherwise whereever you go there is a chance of being attacked by those wallet scammer.  


 
HCP
legendary
Activity: 2086
Merit: 4361
2. Try to Install wallet from original official website. Every coin have their official website where you will find their wallet download link.
Actually, most (may be all) trusted wallets can be found in a GitHub repostory; it's the, probably, the safest place where wallet's code are verified and audited by coders community.
In the GitHub, you can follow discussions about developement, updates, and fixing errors as well.
Just because a wallet is on GitHub, it DOES NOT mean that it is safe or has been audited or is the legit wallet. It is also insanely easy for scammers to fork a GitHub repo... and setup a fake version of the wallet that steals private keys. Very few users will ever bother to fully vet a GitHub repo to check the owner, the history, commits etc and whether the code is legit.

The recent Electrum attack involved directing users to a fake GitHub repo to download a fake version of the wallet.


So, any one can confirm that that site can give good results and reliable to use, please.
Virustotal results are reliable and you can trust it.
Virustotal is in no way 100% reliable... it will include many false positives... and just like any other virus detection software, it can only detect known viruses/malware.

Also, just because the software scans "clean", it does not mean it is not "malware" that will steal your private keys/wallet/password. If the source code has been modified so that the wallet will connect to an external server and post the keys, it is highly unlikely that a virus scanner will flag that as suspicious... to the scanner it will simply appear as an app that connects to external servers and transmits data back and forth.
copper member
Activity: 1204
Merit: 737
✅ Need Campaign Manager? TG > @TalkStar675
It's good if you can create a guide topic on how to use virustotal.com to scan and detect virus/ malware from online sources.
I believe that the topic, when published officially, will get massvie rounds of applause from bitcointalkers.
I have waited for the sort of topic.
Thanks mate for your suggestion. As a forum member I feel so good when someone encourage to bring another topic. Its the example of a inclusive discussion IMO. Obviously i will try my best to create a topic based on your suggested topic after investigating the whole matter properly.

Personally I will suggest everyone for now to be careful before install a coin wallet. It hurts me when i find someone who lost his/her crypto asset because of this wallet scam incidents.  
legendary
Activity: 2688
Merit: 3983
You must verify the signature before installation. "Hacker can have access to the site and Github links"
Cost: installing and using the wallet should be completely free.

Good point but being a paid wallet does not mean they are scammers, for example, most of Ripple's wallets asks for 20 XRP.

Security: Does the company made a security audit? How many users confirm it's secure? Who is confirming the reliability of the wallet[/li][/list]
If you are not able to check the code or it was a closed source wallet, relying on others' assessment will be a risk.

Reliability: Do I have access to the private keys and the wallet.dat file?
If you can’t access your private key, we can not call it a wallet.
legendary
Activity: 2310
Merit: 4085
Farewell o_e_l_e_o
Honestly It is the most safest way to download a wallet from their orignal website. Otherwise you have a chance to have fake or malware included wallet. I will suggest you to follow the instruction of this thread to be secure from wallet related scam.
It's good if you can create a guide topic on how to use virustotal.com to scan and detect virus/ malware from online sources.
I believe that the topic, when published officially, will get massvie rounds of applause from bitcointalkers.
I have waited for the sort of topic.
copper member
Activity: 1204
Merit: 737
✅ Need Campaign Manager? TG > @TalkStar675
I saw some guys post results of https://www.virustotal.com/ to check malwares or viruses inside wallets before downloading and installing them.
I don't believe results of the site.
So, any one can confirm that that site can give good results and reliable to use, please.
Honestly It is the most safest way to download a wallet from their orignal website. Otherwise you have a chance to have fake or malware included wallet. I will suggest you to follow the instruction of this thread to be secure from wallet related scam.
legendary
Activity: 2310
Merit: 4085
Farewell o_e_l_e_o
Thanks for the information on the usefulness of virustotal's antivirus scanning features.
I will use to pre-check wallet files before downloading.
Virustotal results are reliable and you can trust it. I used to scan any file I wanted to download with it
< ... >
You can use it to scan files or even URLs.
I used it because it shows the results for more than 70 antivirus and its database is always updated.

You made me shock.
I actually have antivirus softwares installed on all of my computers.
I don't want to put all my files under risks of attacks.
Quote
I don't have an antivirus installed on my computer.
copper member
Activity: 1204
Merit: 737
✅ Need Campaign Manager? TG > @TalkStar675
3rd party apps containing malware are notorious that even wallets apps from Google Playstore, Apple App store, and even Microsoft's app store contains malware. The only way to really avoid this is installing the official apps from the website and from the direct link given by this wallets directing you to their app in the app store.

Another thing you should know is that even if you downloaded a clean up but you are still downloading different apps from 3rd party sources you make your mobile phone still vulnerable to spyware, so I suggest that you keep your device clean and download apps from their original source instead.
Yeah completely agree with you. You can't trust blindly to these app store for getting the original wallet app. There is lot of fake apps on these platform. IMO its always better to download from coins original website.

Wallet scam increasing day by day and i beleive the reason behind it is users indolence. So i think our new comers should be careful enough to get rid off this.
member
Activity: 392
Merit: 66
2. Try to Install wallet from original official website. Every coin have their official website where you will find their wallet download link.
Why do you say try? Try is not good enough. Always install the wallet from its original website. And even that is not good enough. The file may be corrupted while you download it. The original website may be hacked. That is why you should learn how to do checksum to verify that you really have the file you are supposed to.
legendary
Activity: 2702
Merit: 3045
Top Crypto Casino
I saw some guys post results of https://www.virustotal.com/ to check malwares or viruses inside wallets before downloading and installing them.
I don't believe results of the site.
So, any one can confirm that that site can give good results and reliable to use, please.
Virustotal results are reliable and you can trust it. I used to scan any file I wanted to download with it as I don't have an antivirus installed on my computer.
You can use it to scan files or even URLs.
I used it because it shows the results for more than 70 antivirus and its database is always updated.
legendary
Activity: 2310
Merit: 4085
Farewell o_e_l_e_o
I saw some guys post results of https://www.virustotal.com/ to check malwares or viruses inside wallets before downloading and installing them.
I don't believe results of the site.
So, any one can confirm that that site can give good results and reliable to use, please.
hero member
Activity: 1806
Merit: 672
3rd party apps containing malware are notorious that even wallets apps from Google Playstore, Apple App store, and even Microsoft's app store contains malware. The only way to really avoid this is installing the official apps from the website and from the direct link given by this wallets directing you to their app in the app store.

Another thing you should know is that even if you downloaded a clean up but you are still downloading different apps from 3rd party sources you make your mobile phone still vulnerable to spyware, so I suggest that you keep your device clean and download apps from their original source instead.
legendary
Activity: 2296
Merit: 1014
As an example you want to Install Monero wallet. You can follow below instruction by visiting Coinmarketcap to get the original wallet download link >
Its some indication but what if coinmarketcap got hacked and this links would follow to scam wallets?
This is only one precaution, then you must confirm actual address that is most "popular" in google also which indicate official website. Many checks before downloading. Then virus scan it after every download at virustotal com and you are good to go.
hero member
Activity: 2338
Merit: 757
Other few tips you can add:
- Find answers to those questions before installng a wallet:
  • Cost: installing and using the wallet should be completely free.
  • Security: Does the company made a security audit? How much users confirms it's secure? Who is confirming the reliability of the wallet
  • Reliability: Do i have access to the private keys and the wallet.dat file?
  • Mobility and user friendly: Is the wallet accessible anytime, anywhere? What users don't like in this wallet?
- Get sure that there is a large community involved in maintain of the wallet developement and the project behind.
- Always, use bitcointalk forum to search and ask about everything related to choosing/finding/installing a cryptocurrency wallet; there is dedicated boards for wallets and technical issues. Many experienced users are very helpful and you can trust their opinions.

I add few notes to the steps you mentioned:
1. Please don't Install/login/Register any wallet from third party websites or social media like facebook, twitter, telegram, reddit, medium and many more like them.
It will be so stupid to use any social platform to Install/login/Register any wallet.

2. Try to Install wallet from original official website. Every coin have their official website where you will find their wallet download link.
Actually, most (may be all) trusted wallets can be found in a GitHub repostory; it's the, probably, the safest place where wallet's code are verified and audited by coders community.
In the GitHub, you can follow discussions about developement, updates, and fixing errors as well.

3. Please try to stay away from searching a wallet on google. It is to notify that there's been a couple of phishing websites who copy the similarities of other coins original websites. If you visit and download wallet from those phishing websites then they will steal your coin instantly. Even on playstore there's been a lot of fake wallet apps too.
Using google to search for a wallet is like using social platforms as you mentioned in the first step.

So i recommend everyone to visit Coinmarketcap first and you can easily find your desired coins original website by searching on there.
Indeed, i don't recommend you to just trust links in a (claimed) original website; it may also leads to a scam wallet. Coinmarketcap will just show links provided from compagnies without verification.

sr. member
Activity: 770
Merit: 268
another tips that you can add: if you're trying to claim forked coins, beware of scammy wallet that aims to steal your private key. some scam forks use malicious wallet that will steal your private key so that they can steal your money. it's better if you move your coins first to another address that you control to avoid getting scammed with malicious wallet.
copper member
Activity: 1204
Merit: 737
✅ Need Campaign Manager? TG > @TalkStar675
Hello Everyone,

Welcome to my thread. Today i am going to talk about an concerning issue. Recently wallet related scam has been very common. If anyone visit our forum's Scam accusation section than he/she can easily findout multiple claim about wallet scam. Its already been a concern for crypto holders to keep their fund secure.

I am going to share some instruction to keep yourself protected from this kind of wallet hacking incidents.

You can follow these steps:

1. Please don't Install/login/Register any wallet from third party websites or social media like facebook, twitter, telegram, reddit, medium and many more like them.

2. Try to Install wallet from original official website. Every coin have their official website where you will find their wallet download link.

3. Please try to stay away from searching a wallet on google. It is to notify that there's been a couple of phishing websites who copy the similarities of other coins original websites. If you visit and download wallet from those phishing websites then they will steal your coin instantly. Even on playstore there's been a lot of fake wallet apps too. So i recommend everyone to visit Coinmarketcap first and you can easily find your desired coins original website by searching on there.

As an example you want to Install Monero wallet. You can follow below instruction by visiting Coinmarketcap to get the original wallet download link >






Jump to: