According to blockchain security firm SlowMist, a new Linux-based attack method exploits expired domain hijacking of Snap Store publisher accounts and distributes malicious updates disguised as crypto wallets like Exodus and Ledger Live to steal recovery phrases. This supply chain tactic reflects a trend of attackers shifting their targets to distribution channels, as evidenced by the two major supply chain incidents in 2025 that resulted in a loss of $1.45 billion.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
According to blockchain security firm SlowMist, a new Linux-based attack method exploits expired domain hijacking of Snap Store publisher accounts and distributes malicious updates disguised as crypto wallets like Exodus and Ledger Live to steal recovery phrases. This supply chain tactic reflects a trend of attackers shifting their targets to distribution channels, as evidenced by the two major supply chain incidents in 2025 that resulted in a loss of $1.45 billion.