Linux Snap Store Hijack Used to Steal Crypto Recovery Phrases via Fake Wallet Updates

Linux Snap Store Hijack Used to Steal Crypto Recovery Phrases via Fake Wallet Updates

N
News Editor 01
2026-07-22 18:40:13
SlowMist warned that attackers are abusing expired domains to seize Snap Store publisher accounts and push malicious wallet updates that steal recovery phrases from Linux users.
Linux securitySnap Storerecovery phrasewallet securitysupply chain attack

A new attack targeting Linux users is abusing the Snap Store to deliver malicious wallet updates designed to steal crypto recovery phrases. SlowMist said the scheme leans on the trust users place in official app distribution channels and familiar publisher accounts, turning routine software updates into a path for wallet theft.

Expired domains let attackers reclaim publisher access

According to SlowMist chief information security officer 23pds, who disclosed the issue on X, the attackers are taking over long-standing Snap Store publisher accounts by exploiting expired domains tied to developer identities. Once a domain expires, it can be re-registered. That gives the attacker a way to regain access to email addresses linked to the developer account, reset credentials, and publish malicious updates under what appears to be a legitimate app listing.

The method is subtle. It does not rely on breaking a wallet protocol or finding a smart contract bug. It targets the software distribution layer instead, where users are less likely to suspect that an established application has been altered.

Wallet brands are impersonated to capture seed phrases

SlowMist said the tampered apps were presented as trusted wallet software, including Exodus, Ledger Live, and Trust Wallet. Users who install or update these apps can be prompted to enter their recovery phrases. Once that information is submitted, attackers can use it to drain funds, often before the victim realizes the wallet has been compromised.

The firm identified two compromised publisher domains tied to the malicious apps: storewise[.]tech and vagueentertainment[.]com. By abusing these publisher identities, the attackers were able to slip malicious wallet impersonations into a trusted-looking channel.

Supply-chain attacks are taking a larger share of crypto losses

The case points to a broader shift in crypto-related attacks. As protocol-level defenses improve, attackers are spending more effort on supply-chain weaknesses such as software updates, publisher accounts, and distribution systems. The Snap Store incident fits that pattern closely: the code delivery path is manipulated, and the user ends up handing over the wallet secret voluntarily.

Data from CertiK shows how large that category has become. In 2025, just two supply-chain attacks led to $1.45 billion in losses. That figure highlights how a small number of incidents can have an outsized impact when trusted software channels are compromised.

The Snap Store is widely seen as an official Linux app store, which makes this attack especially deceptive. What looks like a normal update can in fact install malware built to harvest seed phrases. Once the recovery phrase is exposed, control of the funds can be transferred without any direct breach of the wallet service itself.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.