ID:
myalgo-wallet-1479
100 pts
Platform:
Type:
Category:
Method:
Data Sources:
Algorand
Wallet
Assets
Key Management
Extended Method:
Man-in-the-middle attack (MITM)
Days in Operation:
1277
(3.50 Years)





100 pts each
Approx. 17 wallets were compromised with at least $7.2M stolen. Approx. $1.4M may be compromised in another 4 addressed. These two scenarios as leading/most probable:
1. Each individual has had their seed phrase compromised through social engineering/phishing.
2. A MyAlgo.com compromise leading to targeted exfiltration of unencrypted private keys.
Updated 3/21: Preliminary analysis indicated that the attacker employed a MITM attack to inject malicious code between the actual MyAlgo wallet and the user. The malicious proxy fetched the original MyAlgo code, modifying it with harmful code before presenting a malicious version to the user.
The injected code was designed to record users' passwords and encrypted seed phrases and transmit them to a server controlled by the attacker.
DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose.
​
Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.