Friday, June 2, 2023

MetaMask Against Automatic iCloud Backups


Metamask issued a series of tweets on Sunday, August 17th, advising users to disable automated iCloud backups to protect themselves against hackers.

This comes after a phishing attack exploiting Metamask’s iCloud capability resulted in the loss of $670k in assets for one Metamask user.

Auto iCloud Backups Disabled

To combat phishing or hacker threats, Metamask recently advised its users to discontinue automatic iCloud backups. One of the most popular Web3 wallets is Metamask. It primarily uses DeFi and NFT assets across many chains, notably BNB and Ethereum.

Metamask said yesterday that its users should turn off automatic iCloud backups. Metamask sent out a slew of tweets. They claim that if they enable iCloud backup for app data, their password-encrypted MetaMask vault will include. If the password isn’t strong enough and their iCloud credentials phishes, money is stolen.

Metamask said in the same discussion that investors might turn off this feature. To do so, go to Settings > Profile > iCloud > Manage Storage > Backups and toggle off the toggle here. They also provided the option to totally disable the service in order to prevent future unrequested backups. Users can simply go to Settings > Apple ID/iCloud > iCloud > iCloud path.

Protection from Phishing

The goal of Metamask’s tweet was to keep users protected from financial threats. A Metamask user lost roughly $655k a few days ago. This happened after their iCloud backup was hacked via phishing. Domenic Iacovone’s account was hacked, and the Keystore was stolen.

According to Domenic, the attack began when he received a call from an Apple phone number. They requested that he provide a code delivered to his phone in order to have his Apple ID password changed. The criminals changed the password and gained access to the private key file almost immediately after receiving the code.

The crooks subsequently gained direct access to Domenic’s wallet and stole his entire contents. A few seconds later, Domenic added, the entire Metamask wallet wiped clean.

Domenic’s wallet contained a variety of NFT and DeFi assets. For example, the wallet included three gutter cats (2280, 2325, and 2769) as well as three Mutant Ape Yacht Club cards (28478, 7536, 8952). Furthermore, the wallet contained APE tokens worth $100,000, according to Lacovone.

Domenic was quick to notice and issued a tweet about the goings-on, even going so far as to clarify the situation. He has even offered a $100,000 reward to anyone who can help recover the entire sum. Domenic, on the other hand, possibly got some of his assets back once Opensea reported them as missing.

This tweet, however, appears to have elicited an immediate response from Metamask. As a result, Metamask advises customers to disable the automatic iCloud backup rather than using it to avoid phishing.

Prevalence of NFT Hacking

In the NFT space, phishing and hacking are common occurrences. In the past, even Metamask has been a target of such attacks. Several incidents of NFT phishing on Opensea and other marketplaces this year have resulted in millions of dollars in losses. In the NFT realm, other types of hack assaults have also become popular.

Last month, 35 NFTs reported stolen in less than a week. Several Twitter accounts hijacked and phishing links sent out. However, delivering security measures to users via such platforms can assist safeguard them from future attacks.


More from Crypto News Constellation

[tds_leads input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="0" input_radius="0" f_msg_font_family="521" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="400" f_msg_font_line_height="1.4" f_input_font_family="521" f_input_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="521" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="600" f_pp_font_family="521" f_pp_font_size="eyJhbGwiOiIxMiIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#fdbf46" pp_check_color_a_h="#000000" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjMwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMjUiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="0" btn_bg="#fdbf46" btn_bg_h="#dd9933" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIwIn0=" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0=" msg_err_radius="0" f_btn_font_spacing="1" title_text="Stay Up to Date"]


Related Crypto News

Coinbase Pay to be Linked on Metamask

One of the most prominent software-based hot wallets, Metamask, recently revealed an interesting new connection with Coinbase Pay. The announcement...