• bitcoinBitcoin (BTC) $ 119,886.00
  • ethereumEthereum (ETH) $ 3,744.17
  • xrpXRP (XRP) $ 3.53
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 802.41
  • solanaSolana (SOL) $ 204.85
  • usd-coinUSDC (USDC) $ 0.999808
  • dogecoinDogecoin (DOGE) $ 0.268521
  • staked-etherLido Staked Ether (STETH) $ 3,729.46
  • cardanoCardano (ADA) $ 0.895874
  • tronTRON (TRX) $ 0.316000
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 119,821.00
  • hyperliquidHyperliquid (HYPE) $ 45.67
  • stellarStellar (XLM) $ 0.468861
  • wrapped-stethWrapped stETH (WSTETH) $ 4,508.36
  • suiSui (SUI) $ 3.99
  • chainlinkChainlink (LINK) $ 19.66
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,017.05
  • hedera-hashgraphHedera (HBAR) $ 0.272630
  • avalanche-2Avalanche (AVAX) $ 25.77
  • wrapped-eethWrapped eETH (WEETH) $ 4,006.95
  • bitcoin-cashBitcoin Cash (BCH) $ 524.22
  • litecoinLitecoin (LTC) $ 118.98
  • shiba-inuShiba Inu (SHIB) $ 0.000015
  • leo-tokenLEO Token (LEO) $ 8.98
  • the-open-networkToncoin (TON) $ 3.32
  • wethWETH (WETH) $ 3,744.84
  • polkadotPolkadot (DOT) $ 4.50
  • usdsUSDS (USDS) $ 0.999856
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 119,887.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • whitebitWhiteBIT Coin (WBT) $ 44.90
  • uniswapUniswap (UNI) $ 10.74
  • moneroMonero (XMR) $ 324.09
  • pepePepe (PEPE) $ 0.000014
  • bitget-tokenBitget Token (BGB) $ 4.86
  • aaveAave (AAVE) $ 309.50
  • bittensorBittensor (TAO) $ 448.89
  • crypto-com-chainCronos (CRO) $ 0.124996
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • pi-networkPi Network (PI) $ 0.484182
  • nearNEAR Protocol (NEAR) $ 3.00
  • daiDai (DAI) $ 0.999881
  • ethereum-classicEthereum Classic (ETC) $ 24.38
  • ondo-financeOndo (ONDO) $ 1.14
  • aptosAptos (APT) $ 5.43
  • jito-staked-solJito Staked SOL (JITOSOL) $ 249.20
  • internet-computerInternet Computer (ICP) $ 6.07
  • ethenaEthena (ENA) $ 0.502159
  • kaspaKaspa (KAS) $ 0.113533
  • okbOKB (OKB) $ 48.98
  • bonkBonk (BONK) $ 0.000036
  • mantleMantle (MNT) $ 0.823681
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.042661
  • algorandAlgorand (ALGO) $ 0.292933
  • arbitrumArbitrum (ARB) $ 0.476913
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • worldcoin-wldWorldcoin (WLD) $ 1.35
  • vechainVeChain (VET) $ 0.027820
  • render-tokenRender (RENDER) $ 4.54
  • cosmosCosmos Hub (ATOM) $ 5.08
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.251878
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,746.95
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • official-trumpOfficial Trump (TRUMP) $ 11.04
  • gatechain-tokenGate (GT) $ 17.83
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.810556
  • binance-staked-solBinance Staked SOL (BNSOL) $ 216.99
  • sei-networkSei (SEI) $ 0.350000
  • filecoinFilecoin (FIL) $ 2.91
  • quant-networkQuant (QNT) $ 133.81
  • fasttokenFasttoken (FTN) $ 4.50
  • jupiter-exchange-solanaJupiter (JUP) $ 0.623490
  • skySky (SKY) $ 0.086626
  • spx6900SPX6900 (SPX) $ 1.98
  • susdssUSDS (SUSDS) $ 1.06
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,913.03
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,259.73
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 119,609.00
  • flare-networksFlare (FLR) $ 0.024419
  • fartcoinFartcoin (FARTCOIN) $ 1.66
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.25
  • celestiaCelestia (TIA) $ 2.19
  • xdce-crowd-saleXDC Network (XDC) $ 0.095468
  • kucoin-sharesKuCoin (KCS) $ 12.05
  • injective-protocolInjective (INJ) $ 15.03
  • story-2Story (IP) $ 4.96
  • usdtbUSDtb (USDTB) $ 1.00
  • flokiFLOKI (FLOKI) $ 0.000148
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998355
  • blockstackStacks (STX) $ 0.892944
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,937.17
  • optimismOptimism (OP) $ 0.790601
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,000.67
  • curve-dao-tokenCurve DAO (CRV) $ 0.991539
  • usdt0USDT0 (USDT0) $ 1.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,043.74
  • nexoNEXO (NEXO) $ 1.34
  • pump-funPump.fun (PUMP) $ 0.003702
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,932.19
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.91
  • dogwifcoindogwifhat (WIF) $ 1.25
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 119,683.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 229.91
  • sonic-3Sonic (S) $ 0.380612
  • immutable-xImmutable (IMX) $ 0.632893
  • the-graphThe Graph (GRT) $ 0.112245
  • lido-daoLido DAO (LDO) $ 1.21
  • wbnbWrapped BNB (WBNB) $ 803.68
  • kaiaKaia (KAIA) $ 0.178314
  • msolMarinade Staked SOL (MSOL) $ 267.84
  • tezosTezos (XTZ) $ 0.957196
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.89
  • ethereum-name-serviceEthereum Name Service (ENS) $ 29.80
  • theta-tokenTheta Network (THETA) $ 0.966811
  • jasmycoinJasmyCoin (JASMY) $ 0.019955
  • pax-goldPAX Gold (PAXG) $ 3,429.95
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 119,592.00
  • vaultaVaulta (A) $ 0.599100
  • clbtcclBTC (CLBTC) $ 120,553.00
  • raydiumRaydium (RAY) $ 3.42
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • galaGALA (GALA) $ 0.019920
  • iotaIOTA (IOTA) $ 0.229213
  • saros-financeSaros (SAROS) $ 0.338262
  • conflux-tokenConflux (CFX) $ 0.170740
  • paypal-usdPayPal USD (PYUSD) $ 0.999606
  • tether-goldTether Gold (XAUT) $ 3,423.15
  • pyth-networkPyth Network (PYTH) $ 0.145055
  • aerodrome-financeAerodrome Finance (AERO) $ 0.971403
  • the-sandboxThe Sandbox (SAND) $ 0.339794
  • super-oethSuper OETH (SUPEROETH) $ 3,748.33
  • pendlePendle (PENDLE) $ 4.86
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,995.66
  • tokenize-xchangeTokenize Xchange (TKX) $ 9.83
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,899.33
  • jito-governance-tokenJito (JTO) $ 2.18
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,731.24
  • bittorrentBitTorrent (BTT) $ 0.00000072
  • zcashZcash (ZEC) $ 43.91
  • ousgOUSG (OUSG) $ 111.89
  • heliumHelium (HNT) $ 3.81
  • flowFlow (FLOW) $ 0.440286
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.269236
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • decentralandDecentraland (MANA) $ 0.351994
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.999767
  • tbtctBTC (TBTC) $ 119,599.00
  • walrus-2Walrus (WAL) $ 0.483688
  • falcon-financeFalcon USD (USDF) $ 0.999819
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,745.23
  • morphoMorpho (MORPHO) $ 2.03
  • based-brettBrett (BRETT) $ 0.065026
  • mog-coinMog Coin (MOG) $ 0.000002
  • memecoreMemeCore (M) $ 0.378545
  • chain-2Onyxcoin (XCN) $ 0.018362
  • telcoinTelcoin (TEL) $ 0.006788
  • bitcoin-svBitcoin SV (BSV) $ 30.40
  • coredaoorgCore (CORE) $ 0.598616
  • newton-projectAB (AB) $ 0.008691
  • usual-usdUsual USD (USD0) $ 0.997962
  • stader-ethxStader ETHx (ETHX) $ 3,971.55
  • thorchainTHORChain (RUNE) $ 1.65
  • apecoinApeCoin (APE) $ 0.720390
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 120,044.00
  • reserve-rights-tokenReserve Rights (RSR) $ 0.009752
  • build-onBUILDon (B) $ 0.558350
  • aioz-networkAIOZ Network (AIOZ) $ 0.466573
  • wrapped-hypeWrapped HYPE (WHYPE) $ 45.71
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 119,168.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,744.84
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,131.43
  • arweaveArweave (AR) $ 8.17
  • ether-fiEther.fi (ETHFI) $ 1.27
  • ripple-usdRipple USD (RLUSD) $ 0.999782
  • usddUSDD (USDD) $ 1.00
  • beldexBeldex (BDX) $ 0.073919
  • starknetStarknet (STRK) $ 0.146004
  • neoNEO (NEO) $ 7.32
  • elrond-erd-2MultiversX (EGLD) $ 18.00
  • dydx-chaindYdX (DYDX) $ 0.674777
  • compound-governance-tokenCompound (COMP) $ 53.11
  • true-usdTrueUSD (TUSD) $ 0.999419
  • deepDeepBook (DEEP) $ 0.196726
  • swethSwell Ethereum (SWETH) $ 4,033.56
  • movementMovement (MOVE) $ 0.184333
  • savings-daiSavings Dai (SDAI) $ 1.16
  • axie-infinityAxie Infinity (AXS) $ 2.87
  • ecasheCash (XEC) $ 0.000024
  • syrupMaple Finance (SYRUP) $ 0.438593
  • kavaKava (KAVA) $ 0.431258
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.48
  • wemix-tokenWEMIX (WEMIX) $ 1.02
  • beam-2Beam (BEAM) $ 0.008888
  • treehouse-ethTreehouse ETH (TETH) $ 4,515.81
  • popcatPopcat (POPCAT) $ 0.463125
  • apenftAPENFT (NFT) $ 0.00000046

New Vulnerability Threatens Crypto Wallets: How Hackers Can Steal Your Assets

0 57

New Vulnerability Threatens Crypto Wallets: How Hackers Can Steal Your Assets

Crypto users often focus on user interfaces and pay less attention to the complex internal protocols. Security experts recently raised concerns about a critical vulnerability in Crypto-MCP (Model-Context-Protocol), a protocol for connecting and interacting with blockchains.

This flaw could allow hackers to steal digital assets. They could redirect transactions or expose the seed phrase — the key to accessing a crypto wallet.

How Dangerous is the Crypto-MCP Vulnerability?

Crypto-MCP is a protocol designed to support blockchain tasks. These tasks include querying balances, sending tokens, deploying smart contracts, and interacting with decentralized finance (DeFi) protocols.

Protocols like Base MCP from Base, Solana MCP from Solana, and Thirdweb MCP offer powerful features. These include real-time blockchain data access, automated transaction execution, and multi-chain support. However, the protocol’s complexity and openness also introduce security risks if not properly managed.

Developer Luca Beurer-Kellner first raised the issue in early April. He warned that an MCP-based attack could leak WhatsApp messages via the protocol and bypass WhatsApp’s security.

Following that, Superoo7—head of Data and AI at Chromia—investigated and reported a potential vulnerability in Base-MCP. This issue affects Cursor and Claude, two popular AI platforms. The flaw allows hackers to use “prompt injection” techniques to change the recipient address in crypto transactions.

For example, if a user tries to send 0.001 ETH to a specific address, a hacker can insert malicious code to redirect the funds to their wallet. What’s worse, the user may not notice anything wrong. The interface will still show the original intended transaction details.

“This risk comes from using a ‘poisoned’ MCP. Hackers could trick Base-MCP into sending your crypto to them instead of where you intended. If this happens, you might not notice,” Superoo7 said.

New Vulnerability Threatens Crypto Wallets: How Hackers Can Steal Your Assets

Demonstration of Prompt Injection Via Crypto-MCP. Source: Superoo7

Developer Aaronjmars pointed out an even more serious issue. Wallet seed phrases are often stored unencrypted in the MCP configuration files. If hackers gain access to these files, they can easily steal the seed phrase and fully control the user’s wallet and digital assets.

“MCP is an awesome architecture for interoperability & local-first interactions. But holy shit, current security is not tailored for Web3 needs. We need better proxy architecture for wallets,” Aaronjmars emphasized.

So far, no confirmed cases of this vulnerability being exploited to steal crypto assets exist. However, the potential threat is serious.

According to Superoo7, users should protect themselves by using MCP only from trusted sources, keeping wallet balances minimal, limiting MCP access permissions, and using the MCP-Scan tool to check for security risks.

Hackers can steal seed phrases in many ways. A report from Security Intelligence at the end of last year revealed that an Android malware called SpyAgent targets seed phrases by stealing screenshots.

Kaspersky also discovered SparkCat malware that extracts seed phrases from images using OCR. Meanwhile, Microsoft warned about StilachiRAT, malware that targets 20 crypto wallet browser extensions on Google Chrome, including MetaMask and Trust Wallet.

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights