A new attack targeting Linux users is abusing the Snap Store to deliver malicious wallet updates designed to steal crypto recovery phrases. SlowMist said the scheme leans on the trust users place in official app distribution channels and familiar publisher accounts, turning routine software updates into a path for wallet theft.
Expired domains let attackers reclaim publisher access
According to SlowMist chief information security officer 23pds, who disclosed the issue on X, the attackers are taking over long-standing Snap Store publisher accounts by exploiting expired domains tied to developer identities. Once a domain expires, it can be re-registered. That gives the attacker a way to regain access to email addresses linked to the developer account, reset credentials, and publish malicious updates under what appears to be a legitimate app listing.
The method is subtle. It does not rely on breaking a wallet protocol or finding a smart contract bug. It targets the software distribution layer instead, where users are less likely to suspect that an established application has been altered.
Wallet brands are impersonated to capture seed phrases
SlowMist said the tampered apps were presented as trusted wallet software, including Exodus, Ledger Live, and Trust Wallet. Users who install or update these apps can be prompted to enter their recovery phrases. Once that information is submitted, attackers can use it to drain funds, often before the victim realizes the wallet has been compromised.
The firm identified two compromised publisher domains tied to the malicious apps: storewise[.]tech and vagueentertainment[.]com. By abusing these publisher identities, the attackers were able to slip malicious wallet impersonations into a trusted-looking channel.
Supply-chain attacks are taking a larger share of crypto losses
The case points to a broader shift in crypto-related attacks. As protocol-level defenses improve, attackers are spending more effort on supply-chain weaknesses such as software updates, publisher accounts, and distribution systems. The Snap Store incident fits that pattern closely: the code delivery path is manipulated, and the user ends up handing over the wallet secret voluntarily.
Data from CertiK shows how large that category has become. In 2025, just two supply-chain attacks led to $1.45 billion in losses. That figure highlights how a small number of incidents can have an outsized impact when trusted software channels are compromised.
The Snap Store is widely seen as an official Linux app store, which makes this attack especially deceptive. What looks like a normal update can in fact install malware built to harvest seed phrases. Once the recovery phrase is exposed, control of the funds can be transferred without any direct breach of the wallet service itself.

