Pages:
Author

Topic: Which is the best to use now? - page 2. (Read 309 times)

legendary
Activity: 1064
Merit: 1228
Playgram - The Telegram Casino
January 20, 2022, 03:15:53 PM
#5
-snip-How can we ignore these kind of hijacking/malware application as it is now a threat to those who mostly uses Android phones?
If you read the whole thread, then you probably won't have any trouble finding the answer to your question as LoyceV has also added a few ways to prevent this.

How to prevent this
1. Don't use Windows, but we both know you're not going to change that.
2. Check the entire address after copy/pasting, and not just the first few (or last few) characters. Check some in the middle too. That's a lot of work, so chances are you won't do that either.
3. I came up with something else: don't copy the entire Bitcoin address, copy only a part, and manually type the last few characters. Even if the malware exchanges the incomplete Bitcoin address by their own, your wallet won't accept the (invalid) address if you've typed a few more characters by yourself.
You'll still need to follow Step 2 after this: check the address!
4. Use copy/paste to verify part of your address. Suppose you want to send funds to address 1PjpEgknyKxQKXtMcYFDym8odkfohFGkui. After copy/pasting, select "yKxQKXtMc" from the pasted address, then press CTRL-C. Then, use CTRL-F followed by CTRL-V to see if the partial address matches the original source of the address. And make sure the source is authentic: email can be spoofed too!
5. I'll add o_e_l_e_o's suggestion here:
Any time I am sending coins from any wallet I physically place the address I know is correct directly from the source, right next to the address I have entered to send to. That usually means either holding my hardware wallet or phone up next to my computer screen, or resizing two windows on my phone or computer to put the two address physically right next to each other. Once you have two addresses which are less than inch apart, its very easy to check the entire address and not just a few characters at the start or end.

If you are using a mobile then you should be able to download the app based on the correct link both in the web store and from the original site. I think the other most helpful advice is to not install unsafe apps for your phone that you use specifically for financial transactions be it crypto or other financial transactions.
legendary
Activity: 2212
Merit: 7064
January 20, 2022, 03:12:54 PM
#4
How can we ignore these kind of hijacking/malware application as it is now a threat to those who mostly uses Android phones?
Best way is to use custom operating system for Android phones (Lineage, Graphene, Calyx, Divest) instead of default Android OS, but for most people this is a bit extreme step.
Regular people that still Android OS should limit the use of all apps and stop using Google Store, but move on some alternative like F-Droid or Aurora Store.
Anything related with cryptocurrencies should be verified with signature when download from official websites.
Electrum wallet have Android OS 5 support on their website, and don't use any unknown crypto apps that can't be verified.
You should be much safer after doing this.
hero member
Activity: 2268
Merit: 669
Bitcoin Casino Est. 2013
January 20, 2022, 02:52:36 PM
#3
It's up to you as long as the application you want to download is provided by the real site and not from a fake site. There are legit apps on playstore too like ethereum mobile version wallet which I used and I didn't have problem with it. Although, downloading something using browser could also download malwares that you aren't aware of that it is downloaded. Avoid downloading anything you see that it might be helpful but it is not.
legendary
Activity: 3290
Merit: 16489
Thick-Skinned Gang Leader and Golden Feather 2021
January 20, 2022, 12:48:30 PM
#2
The basics apply to any OS: don't keep a lot of funds in hot wallets, don't install weird software, install as few apps as possible, or even better: use a dedicated system for your wallet.
sr. member
Activity: 588
Merit: 251
January 20, 2022, 12:44:56 PM
#1
I came across this post How to lose your Bitcoins with CTRL-C CTRL-V in the forum, Which brought a question to my heart, is it better to use the website to download any wallet or exchange application for Android (as it is a normal thing to use for desktop/laptops) or use the Google play store which is now said to have some applications that hijacks clipboard and changes the address to the hijacker's address and when the transaction has been executed, nothing can be done to cancel the transaction (which is normal)?
First Cryptocurrency Clipboard Hijacker Found on Google Play Store
A cloned MetaMask away from the original is now a victim from the Google play store.
It is said that
Quote
The first attack method the app used was to attempt to steal the private keys and seeds of an Ethereum wallet when a user adds it to the app. When BleepingComputer analyzed the app's APK file, we found that the app contains information that can be used to send this stolen data to a Telegram account.

How can we ignore these kind of hijacking/malware application as it is now a threat to those who mostly uses Android phones?
Pages:
Jump to: