May 19, 2024

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

The ForkLog editor was contacted by the user of the Mycelium Wallet cryptocurrency wallet Anton Z., who became a victimfraudsters acting on behalf of the company.

In late January, Anton discovered a bug in his wallet.Mycelium for iOS, which did not allow you to see the account transaction history. He reported this to the development team, using the mailing address specified in the application.

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

Having not received a response within a week, the userwrote to the Telegram channel @mycelium_wallet - the only group chat that was displayed upon request &#171;@mycelium&#187;. At that time there were more than 150 participants.

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

Note: Telegram nickname @mycelium (indicated in the application) belongs to a private person, Pavel. He told ForkLog that he created this account in the summer of 2019 without any malicious intent. And he noticed that something was wrong when Mycelium Wallet users began to write to him, believing that this was a support contact. According to Pavel, he repeatedly appealed to the wallet team with a request to correct the support contact in the application within six months, but his appeals were ignored.

Anton wrote about the bug in the chat, indicated his email from which he sent the message, and soon received a letter from the address[email protected]:

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

&#171;The letter contained a link, following which II saw five questions, including a request to list the 12 secret words that I enter to access the wallet. I asked the channel if it was normal for me to be asked to enter secret words. The channel admin replied in a private chat that this was necessary to fix the bug. It was already late in the evening, I filled out the form and sent it,- said Anton.

The next day, he discovered that the entire amount with his balance of 0.3366 BTC (about $ 3300 at that time) was withdrawn, and the transaction history was still inaccessible.

&#171;I wrote to the Telegram channel, they were right thereconfirmed that everything is fine - this is troubleshooting. Even someone from the channel began to write that he had the same situation and this is a normal phenomenon. In general, they calmed me down&#187;.

However, when the money never returned, Anton realized that he had been deceived.

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

It is also noteworthy that the fake support service in its channel warns of frequent cases of fraud on behalf of the Mycelium Wallet team.

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

The stolen cryptocurrency Anton and his comrades from the motorcycle community &#171;Bikers of Belarus&#187; independently collected to help children from boarding schools.

Mycelium advises abandoning the iOS wallet: bugs in it indirectly led to the theft of $ 3300 in bitcoins

</p>

&#171;I wrote to all mail addresses of the servicesupport, left a review in the App Store describing the problem. I even found a supposedly valid technical support number on Google, but there I again ran into scammers who lure seed phrases from everyone who calls them,— Anton told the editors of ForkLog.

Previously, the user had complaints about the servicedid not have. However, there is a branch on Bitcointalk from November 2018, where another client of the Android version of Mycelium Wallet complained that when trying to restore access to the wallet, the application created a new account, as a result of which it lost 0.99 BTC.

Mycelium Wallet CEO Alexander Kuzmin in a ForkLog comment said that the project team is aware of all the application bugs.

The iOS version of the wallet is generally onebig bug. But since Mycelium has always been an Android wallet and Apple did not allow Bitcoin applications in the App Store until 2015, iOS was not a priority. All the team's efforts have always been focused on Android, although we made and released a very simple version of iOS, which has continued to exist in this form since 2017.- he said.

Kuzmin emphasized that it makes sense to develop the currentthere is no version of Mycelium wallet for iOS, and within three to four months it is planned to replace it with a new iOS wallet, identical in its characteristics to the Android version.

&#171;Funds stored in iOS wallets are invulnerable provided that the user has made a backup. But we do not recommend actively using it due to the outdated infrastructure.— added the CEO of Mycelium.

Also, ForkLog found out that the project does not have an internal tool for tracking transactions and the Mycelium team cannot assist in finding the stolen funds.

Alexander Kuzmin added that the company does not have an official chat in the Telegram messenger.

&#171;Wrong Telegram contact is a legacy of old times. Most likely, it was our community manager - the fate of this username is unknown to us.

At the end of 2018, hackers stole more than 200 BTC from Electrum wallet users through a phishing attack through many malicious servers.

In April 2019, as a result of a DoS attack on the servers of Electrum cryptocurrency wallets, hackers stole $ 4.6 million from 152 thousand accounts.

Fraudsters are increasingly hiding behind the names of famous brands. Recently, cybercriminals tricked the reader of ForkLog into a Telegram channel allegedly owned by our editorial board.

Be careful: check the identity of the person with whom you communicate, and do not pass confidential information to anyone!