Smartphone text prediction guesses crypto hodler’s seed phrase

0

[ad_1]

Seed phrases, a random combination of words from the Bitcoin Improvement Protocol (BIP) 39 list of 2048 words, act as one of the primary layers of security against unauthorized access to a user’s crypto holdings. But, what happens when your “smart” phone’s predictive typing remembers and suggests the words next time you try to access your digital wallet?

Andre, a 33-year-old IT professional from Germany, recently posted on the r/CryptoCurrency subreddit after discovering his mobile phone’s ability to predict the entire recovery seed phrase as soon as he typed down the first word.

As a fair warning to fellow Redditors and crypto enthusiasts, Andre’s post highlighted the ease with which hackers can use the feature to drain a user’s funds just by being able to type the first word out of the BIP 39 list:

“This makes it easy to attack, get your hands on a phone, start any chat app, and start typing any words off the BIP39 list, and see what the phone suggests.”

Speaking to Cointelegraph, Andre, otherwise known as u/Divinux on Reddit, shared his shock when he first experienced his phone literally guessing the 12-24 word seed phrase. “First, I was stunned. The first couple words could be a coincidence, right?”

As a tech-savvy individual, the German crypto investor was able to reproduce the scenario wherein his mobile phone could accurately predict the seed phrases. After realizing the possible impact of this information if it went out to the wrong hands, “I thought I should tell people about it. I’m sure there are others who also have typed seeds into their phone.”

Andre’s experiments confirmed that Google’s GBoard was the least vulnerable as the software did not predict every word in the correct order. However, Microsoft’s Swiftkey keyboard was able to predict the seed phrase right out of the box. The Samsung keyboard, too, can predict the words if “Auto replace” and “Suggest text corrections” have been manually turned on.

Andre’s initial stint with crypto dates back to 2015 when he momentarily lost interest until he realized he could buy goods and services using Bitcoin (BTC) and other cryptocurrencies. His investment strategy involves purchasing and staking BTC and altcoins such as Terra (LUNA), Algorand (ALGO) and Tezos (XTZ) and “then dollar-cost averaging out into BTC when/if they moon.” The IT professional also develops his own coins and tokens as a hobby.

A safety measure against possible hacks, according to Andre, is to store significant and long-term holdings in a hardware wallet. To Redditors across the world, he advises “not your keys not your coins, do your own research, don’t FOMO, never invest more than you are willing to lose, always double-check the address you are sending to, always send a small amount beforehand and disable your PMs in settings,” concluding:

“Do yourself a solid and prevent that from happening by clearing your predictive type cache.”

Related: STEPN impersonators stealing users’ seed phrases, warn security experts

Blockchain security firm PeckShield warned the crypto community about a large number of phishing websites targeting users of the Web3 lifestyle app STEPN.

As Cointelegraph recently reported, based on PechShield’s findings, hackers insert a forged MetaMask browser plugin through which they can steal seed phrases from unsuspecting STEPN users.

Access to seed phrase guarantees complete control over the user’s crypto funds via the STEPN dashboard.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 64,518.00
ethereum
Ethereum (ETH) $ 1,682.70
tether
Tether (USDT) $ 0.999526
bnb
BNB (BNB) $ 609.20
usd-coin
USDC (USDC) $ 0.999809
xrp
XRP (XRP) $ 1.15
solana
Solana (SOL) $ 69.11
tron
TRON (TRX) $ 0.317029
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.02
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
dogecoin
Dogecoin (DOGE) $ 0.087918
hyperliquid
Hyperliquid (HYPE) $ 60.52
usds
USDS (USDS) $ 0.999793
leo-token
LEO Token (LEO) $ 9.81
rain
Rain (RAIN) $ 0.012990
zcash
Zcash (ZEC) $ 421.51
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
cardano
Cardano (ADA) $ 0.172103
monero
Monero (XMR) $ 339.29
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
canton-network
Canton (CC) $ 0.162852
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
stellar
Stellar (XLM) $ 0.187216
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
whitebit
WhiteBIT Coin (WBT) $ 52.51
chainlink
Chainlink (LINK) $ 7.98
the-open-network
Toncoin (TON) $ 1.72
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
ethena-usde
Ethena USDe (USDE) $ 0.999666
usd1-wlfi
USD1 (USD1) $ 1.00
susds
sUSDS (SUSDS) $ 1.08
dai
Dai (DAI) $ 0.999696
bitcoin-cash
Bitcoin Cash (BCH) $ 208.74
memecore
MemeCore (M) $ 3.04
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
litecoin
Litecoin (LTC) $ 44.33
hedera-hashgraph
Hedera (HBAR) $ 0.078358
sui
Sui (SUI) $ 0.766314
weth
WETH (WETH) $ 2,268.37
hashnote-usyc
Circle USYC (USYC) $ 1.13
shiba-inu
Shiba Inu (SHIB) $ 0.000005
lab
LAB (LAB) $ 9.39
usdt0
USDT0 (USDT0) $ 0.998824
avalanche-2
Avalanche (AVAX) $ 6.73
paypal-usd
PayPal USD (PYUSD) $ 0.999988
near
NEAR Protocol (NEAR) $ 2.12
crypto-com-chain
Cronos (CRO) $ 0.060085
global-dollar
Global Dollar (USDG) $ 0.999929
tether-gold
Tether Gold (XAUT) $ 4,211.92
bittensor
Bittensor (TAO) $ 265.57
Shares