iPhone crypto app hid code that routed $580K to attacker

An iOS crypto wallet app hid obfuscated code that later triggered transactions sending about $580,000 in tokens to a single attacker-controlled address, researchers reported.

Security researchers say an iPhone cryptocurrency app concealed obfuscated code that allowed an attacker’s wallet to collect roughly $580,000 in tokens. The hidden functionality passed App Store checks and later enabled transfers that routed user funds to an attacker-controlled on-chain address.

The issue came to light after analysts traced transactions tied to a single wallet that received about $580,000 over multiple transfers. Blockchain records show funds moved from several user accounts into the attacker-controlled address. Investigators linked the activity to an iOS app marketed as a crypto wallet or portfolio manager that contained code paths not visible during initial review and that activated after deployment.

Technical analysis found concealed routines that prompted or submitted transactions routing tokens to the attacker’s address. The hidden code executed actions resembling token approval requests and transfer operations once certain conditions were met. Because token movements are recorded on public ledgers, analysts correlated suspicious in-app activity with receipts in the attacker’s wallet and calculated the total taken.

Discovery began when multiple users reported unexpected token transfers. Static and dynamic analysis of the app binary and network behavior revealed logic that did not appear in the app’s visible interface and that appeared designed to evade automated review. Researchers reported the findings to platform maintainers and to owners of affected wallets.

There is no public indication the app directly harvested private keys. Instead, the routines appear to have induced or signed transactions after obtaining consent in an obscured way. Investigators noted that attackers can trick users into authorizing token approvals or transaction signatures that allow sweeping transfers without access to seed phrases.

Additional details remain under investigation, including how many distinct users were affected and whether any single token type made up most of the $580,000. On-chain tracing shows multiple token types and several transfers into the attacker’s address. Researchers continue to map the flow of funds and are working with platform operators to remove the app and block associated accounts where possible.

Researchers recommend users carefully review transaction and approval requests, verify spend limits before consenting to token approvals, and limit permissions granted to mobile wallets. For large holdings, they advise using hardware wallets or well-reviewed open-source wallet software and checking app behavior against official project documentation.

Mobile app stores use automated and manual checks, but obfuscated or remotely activated code can sometimes evade detection. On-chain transparency allowed analysts to quantify the scale of the transfers after the suspicious activity was noticed.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author