{"id":90525,"date":"2024-04-16T18:51:46","date_gmt":"2024-04-16T18:51:46","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/04\/16\/a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm-techcrunch\/"},"modified":"2024-04-16T18:51:46","modified_gmt":"2024-04-16T18:51:46","slug":"a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/04\/16\/a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm-techcrunch\/","title":{"rendered":"A crypto wallet maker&#8217;s warning about an iMessage bug sounds like a false alarm | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\">A crypto wallet maker claimed this week that hackers may be targeting people with an iMessage \u201czero-day\u201d exploit \u2014 but all signs point to an exaggerated threat, if not a downright scam.<\/p>\n<p>Trust Wallet\u2019s official X (previously Twitter) account <a href=\"https:\/\/twitter.com\/TrustWallet\/status\/1779961169660280871\" target=\"_blank\" rel=\"noopener\">wrote<\/a> that \u201cwe have credible intel regarding a high-risk zero-day exploit targeting iMessage on the Dark Web. This can infiltrate your iPhone without clicking any link. High-value targets are likely. Each use raises detection risk.\u201d<\/p>\n<p>The wallet maker recommended iPhone users to turn off iMessage completely \u201cuntil Apple patches this,\u201d even though no evidence shows that \u201cthis\u201d exists at all.<\/p>\n<p>The tweet went viral, and has been viewed over 3.6 million times as of our publication. Because of the attention the post received, Trust Wallet hours later <a href=\"https:\/\/twitter.com\/TrustWallet\/status\/1780020931533959229\" target=\"_blank\" rel=\"noopener\">wrote a follow-up post<\/a>. The wallet maker doubled down on its decision to go public, saying that it \u201cactively communicates any potential threats and risks to the community.\u201d<\/p>\n<p>Trust Wallet did not respond to TechCrunch\u2019s request for comment. Apple spokesperson Scott Radcliffe declined to comment when reached Tuesday.<\/p>\n<p>As it turns out, <a href=\"https:\/\/twitter.com\/EowynChen\/status\/1779968264510050731\" target=\"_blank\" rel=\"noopener\">according to Trust Wallet\u2019s CEO Eowyn Chen<\/a>, the \u201cintel\u201d is an advertisement on a dark web site called CodeBreach Lab, where someone is offering said alleged exploit for $2 million in bitcoin cryptocurrency. The advert titled \u201ciMessage Exploit\u201d claims the vulnerability is a remote code execution (or RCE) exploit that requires no interaction from the target \u2014 commonly known as \u201czero-click\u201d exploit \u2014 and works on the latest version of iOS. Some bugs are called zero-days because the vendor has no time, or zero days, to fix the vulnerability. In this case, there is no evidence of an exploit to begin with.<\/p>\n<div id=\"attachment_2692312\" style=\"width: 502px\" class=\"wp-caption alignnone\"><\/p>\n<p id=\"caption-attachment-2692312\" class=\"wp-caption-text\">A screenshot of the dark web ad claiming to sell an alleged iMessage exploit. Image Credits: TechCrunch<\/p>\n<\/div>\n<p>RCEs are some of the most powerful exploits because they allow hackers to remotely take control of their target devices over the internet. An exploit like an RCE coupled with a zero-click capability is incredibly valuable because those attacks can be conducted invisibly without the device owner knowing. In fact, a company that acquires and resells zero-days <a href=\"https:\/\/techcrunch.com\/2024\/04\/06\/price-of-zero-day-exploits-rises-as-companies-harden-products-against-hackers\/\" target=\"_blank\" rel=\"noopener\">is currently offering between $3 to $5 million<\/a> for that kind of zero-click zero-day, which is also a sign of how hard it is to find and develop these types of exploits.<\/p>\n<div class=\"article-block block--callout block--right\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\tDo you have any information about actual zero-days? Or about spyware providers? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2024\/04\/16\/a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm\/mailto:lorenzo@techcrunch.com\" target=\"_blank\" rel=\"noopener\">email<\/a><a href=\"https:\/\/techcrunch.com\/2024\/04\/16\/a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm\/mailto:lorenzo@techcrunch.com\" target=\"_blank\" rel=\"noopener\">.<\/a> You also can contact TechCrunch via <a href=\"https:\/\/techcrunch.com\/got-a-tip\/\" target=\"_blank\" rel=\"noopener\">SecureDrop<\/a>.\t<\/div>\n<p>Given the circumstances of how and where this zero-day is being sold, it\u2019s very likely that it is all just a scam, and that Trust Wallet fell for it, spreading what people in the cybersecurity industry would call FUD, or \u201cfear uncertainty and doubt.\u201d<\/p>\n<p>Zero-days do exist, and <a href=\"https:\/\/techcrunch.com\/2023\/09\/22\/update-apple-devices-pegasus-predator-spyware\/\" target=\"_blank\" rel=\"noopener\">have been used by government hacking units for years<\/a>. But in reality, you probably don\u2019t need to turn off iMessage unless you are a high-risk user, such as a journalist or dissident under an oppressive government, for example.<\/p>\n<p>It\u2019s better advice to suggest people turn on <a href=\"https:\/\/techcrunch.com\/2022\/07\/06\/apple-lockdown-mode\/\" target=\"_blank\" rel=\"noopener\">Lockdown Mode<\/a>, a special mode that disables certain Apple device features and functionalities with the goal of reducing the avenues hackers can use to attack iPhones and Macs.<\/p>\n<p><a href=\"https:\/\/techcrunch.com\/2023\/12\/07\/apple-says-it-is-not-aware-anyone-using-lockdown-mode-got-hacked\/\" target=\"_blank\" rel=\"noopener\">According to Apple<\/a>, there is no evidence anyone has successfully hacked someone\u2019s Apple device while using Lockdown Mode. Several cybersecurity experts like <a href=\"https:\/\/twitter.com\/runasand\/status\/1714942386277957741\" target=\"_blank\" rel=\"noopener\">Runa Sandvik<\/a> and the <a href=\"https:\/\/twitter.com\/jsrailton\/status\/1705276865898856449\" target=\"_blank\" rel=\"noopener\">researchers<\/a> who work at Citizen Lab, who have investigated dozens of cases of iPhone hacks, recommend using Lockdown Mode.<\/p>\n<p>For its part, CodeBreach Lab appears to be a new website with no track record. When we checked, a search on Google returned only seven results, one of which is a post on a well-known hacking forum asking if anyone had previously heard of CodeBreach Lab.<\/p>\n<p>On its homepage \u2014 with typos \u2014 CodeBreach Lab claims to offer several types of exploits other than for iMessage, but provides no further evidence.<\/p>\n<p>The owners describe CodeBreach Lab as \u201cthe nexus of cyber disruption.\u201d But it would probably be more fitting to call it the nexus of braggadocio and naivety.<\/p>\n<p>TechCrunch could not reach CodeBreach Lab for comment because there is no way to contact the alleged company. When we attempted to buy the alleged exploit \u2014 because why not \u2014 the website asked for the buyer\u2019s name, email address, and then to send $2 million in bitcoin to a specific wallet address on the public blockchain. When we checked, nobody has so far.<\/p>\n<p>In other words, if someone wants this alleged zero-day, they have to send $2 million to a wallet that, at this point, there is no way to know who it belongs to, nor \u2014 again \u2014 any way to contact.<\/p>\n<p>And there is a very good chance that it will remain that way.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/04\/16\/a-crypto-wallet-makers-warning-about-an-imessage-bug-sounds-like-a-false-alarm\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A crypto wallet maker claimed this week that hackers may be targeting people with an iMessage \u201czero-day\u201d exploit \u2014 but all signs point to an exaggerated threat, if not a downright scam. Trust Wallet\u2019s official X (previously Twitter) account wrote that \u201cwe have credible intel regarding a high-risk zero-day exploit targeting iMessage on the Dark [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":90526,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-90525","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/90525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=90525"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/90525\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/90526"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=90525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=90525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=90525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}