Security Researchers Warn of Fake Crypto Wallet Apps Stealing User Funds
Security experts at Cyble have uncovered a set of malicious apps on the Google Play Store designed to impersonate legitimate cryptocurrency wallets. These apps mimic the branding and functionality of well-known wallets such as PancakeSwap, SushiSwap, Raydium, and Hyperliquid. Once installed, the fake apps redirect users to phishing sites or use in-app browsers to solicit sensitive information, especially mnemonic phrases. These phrases allow attackers to access and empty users’ real crypto wallets.
The apps appear to originate from compromised or repurposed developer accounts, which previously published legitimate apps. Over 20 malicious apps were identified, using similar descriptions and embedded Command and Control (C&C) URLs within their privacy policies. Cyble emphasizes that these apps form part of an ongoing phishing campaign, linked to over 50 domains, which increases their reach and evades detection.
While Google has removed many of these apps from the Play Store, some are still being reported and taken down. Users are urged to delete any suspicious apps from their devices and to ensure Play Protect is enabled. The researchers strongly advise downloading crypto wallet apps only from official sources and directly linked from the project’s website, as digital wallet losses are often irreversible.
