Bitcoin Forum
June 01, 2025, 06:54:26 PM *
News: Latest Bitcoin Core release: 29.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Jaxx Liberty Wallet showing link to phishing site  (Read 217 times)
fab12345 (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
November 27, 2024, 03:59:45 PM
 #1

sA friend of mine still had some cryptocurrency stored in the Jaxx Liberty Wallet. However, they were unable to transfer the funds to another wallet or exchange. The app, which was still installed on their phone, displayed a message saying: "Visit jaxxapp.com to update your app" (see attached image). jaxxapp.com will become jaxxupdate.com

When visiting the mentioned site, it asked for the private seed. This raised some concerns:

Is this a scam?
Is it possible for hackers to alter an old version of an official app to redirect users to malicious websites?
If so, how could they achieve this?
Looking forward to any insights or advice on how to proceed safely. Thanks in advance!



https://i.postimg.cc/QdXsMyQw/Whats-App-Image-2024-11-26-at-19-03-00-abdf159e.jpg

https://i.postimg.cc/TwPXcL79/Captura-de-tela-2024-11-27-124530.png
DaveF
Legendary
*
Offline Offline

Activity: 3864
Merit: 6838


Wheel of Whales 🐳


View Profile WWW
November 27, 2024, 04:56:02 PM
Merited by hugeblack (2), ABCbits (1)
 #2

Jaxx Liberty Wallet is gone.

https://blog.jaxx.io/sunsetting-jaxx-liberty-what-you-need-to-know/

Don't put the keys in some wallet / site that you don't know.
Get one of the known ones and use that one.

Without knowing what crypto you have in the wallet can't make a full recommendation but for BTC Electrum is always good https://electrum.org

-Dave

███████████▄
████████▄▄██
█████████▀█
███████████▄███████▄
█████▄█▄██████████████
████▄█▀▄░█████▄████████
████▄███░████████████▀
████░█████░█████▀▄▄▄▄▄
█████░█
██░█████████▀▀
░▄█▀
███░░▀▀▀██████
▀███████▄█▀▀▀██████▀
░░████▄▀░▀▀▀▀████▀
 

█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████

█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
.
...SOL.....USDT...
...FAST PAYOUTS...
...BTC...
...TON...
Pmalek
Legendary
*
Offline Offline

Activity: 3150
Merit: 8087


Top-tier crypto casino and sportsbook


View Profile
November 29, 2024, 01:15:08 PM
 #3

I assume you have made a backup of your recovery phrase. Jaxx Liberty was a non-custodial wallet, meaning you should have a seed phrase. It supports the BIP39 standard, so the seed can be imported in many alternative wallets. Which wallets(s) you should use depends on the assets you own. I would first create a new wallet using a tested software like Electrum, generate and make backups of the new seed, and then import the old Jaxx Liberty seed. When that is done, sweep the BTC to the new wallet. Do the same with your other cryptocurrencies. 

██████▄██▄███████████▄█▄
█████▄█████▄████▄▄▄█
███████████████████
████▐███████████████████
███████████▀▀▄▄▄▄███████
██▄███████▄▀███▀█▀▀█▄▄▄█
▀██████████▄█████▄▄█████▀██
██████████▄████▀██▄▀▀▀█████▄
█████████████▐█▄▀▄███▀██▄
███████▄▄▄███▌▌█▄▀▀███████▄
▀▀▀███████████▌██▀▀▀▀▀█▄▄▄████▀
███████▀▀██████▄▄██▄▄▄▄███▀▀
████████████▀▀▀██████████
.BETFURY.....█████████████
███████████████
███████████████
██▀▀▀▀█▀▀▄░▄███
█▄░░░░░██▌▐████
█████▌▐██▌▐████
███▀▀░▀█▀░░▀███
██░▄▀░█░▄▀░░░██
██░░░░█░░░░░░██
███▄░░▄█▄░░▄███
███████████████
███████████████
░░█████████████
█████████████
███████████████
███████████████
██▀▄▄▄▄▄▄▄▄████
██░█▀░░░░░░░▀██
██░█░▀░▄░▄░░░██
██░█░░█████░░██
██░█░░▀███▀░░██
██░█░░░░▀░░▄░██
████▄░░░░░░░▄██
███████████████
███████████████
░░█████████████
ABCbits
Legendary
*
Offline Offline

Activity: 3262
Merit: 8775



View Profile
December 02, 2024, 09:11:12 AM
 #4

Is this a scam?

Yes, it's a scam.

Is it possible for hackers to alter an old version of an official app to redirect users to malicious websites?
If so, how could they achieve this?

Most likely no. To do that, the hacker usually need to have access to your friend device. And if a hacker actually can do that, he would do soemthing else to steal your friend's coin, credential and other personal data. While i don't know how Jaxx Libetry works, i would speculate the hacker buy expired domain which used by Jaxx Liberty to obtain certain data from internet.

hugeblack
Legendary
*
Offline Offline

Activity: 2884
Merit: 4207



View Profile WWW
December 02, 2024, 09:35:07 AM
 #5

The domain was created less than a month ago and it asks you to enter a wallet seed, so it is definitely a scam. You can recover your coins by downloading electrum with the BIP seed option.

x
logfiles
Copper Member
Legendary
*
Offline Offline

Activity: 2366
Merit: 1995



View Profile WWW
December 08, 2024, 11:48:17 PM
Merited by hugeblack (2)
 #6

The malicious domains now seem to be down, thanks to someone who discovered and probably reported them. What makes me curious is how the hacker manage to push an update or a notification via an app that is run by someone else? Insider job by someone malicious?

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Pmalek
Legendary
*
Offline Offline

Activity: 3150
Merit: 8087


Top-tier crypto casino and sportsbook


View Profile
December 09, 2024, 09:58:13 AM
 #7

What makes me curious is how the hacker manage to push an update or a notification via an app that is run by someone else? Insider job by someone malicious?
Remember Electrum and the arbitrary messages that node owners could push to users who connected to their servers to trick them into downloading fake software? I have never used Jaxx Liberty and I don't think it functions anywhere close to Electrum, but someone might have found a vulnerability. Or like you said, it's an inside job. The wallet isn't being maintained and the people behind it may nor care anymore what happens with it.

██████▄██▄███████████▄█▄
█████▄█████▄████▄▄▄█
███████████████████
████▐███████████████████
███████████▀▀▄▄▄▄███████
██▄███████▄▀███▀█▀▀█▄▄▄█
▀██████████▄█████▄▄█████▀██
██████████▄████▀██▄▀▀▀█████▄
█████████████▐█▄▀▄███▀██▄
███████▄▄▄███▌▌█▄▀▀███████▄
▀▀▀███████████▌██▀▀▀▀▀█▄▄▄████▀
███████▀▀██████▄▄██▄▄▄▄███▀▀
████████████▀▀▀██████████
.BETFURY.....█████████████
███████████████
███████████████
██▀▀▀▀█▀▀▄░▄███
█▄░░░░░██▌▐████
█████▌▐██▌▐████
███▀▀░▀█▀░░▀███
██░▄▀░█░▄▀░░░██
██░░░░█░░░░░░██
███▄░░▄█▄░░▄███
███████████████
███████████████
░░█████████████
█████████████
███████████████
███████████████
██▀▄▄▄▄▄▄▄▄████
██░█▀░░░░░░░▀██
██░█░▀░▄░▄░░░██
██░█░░█████░░██
██░█░░▀███▀░░██
██░█░░░░▀░░▄░██
████▄░░░░░░░▄██
███████████████
███████████████
░░█████████████
hugeblack
Legendary
*
Offline Offline

Activity: 2884
Merit: 4207



View Profile WWW
December 09, 2024, 11:17:23 AM
 #8

The malicious domains now seem to be down, thanks to someone who discovered and probably reported them. What makes me curious is how the hacker manage to push an update or a notification via an app that is run by someone else? Insider job by someone malicious?
If Jaxx Liberty Wallet is a malware or has a backdoor, it will ask users to enter seeds and steal funds, so it looks like a similar exploit to what happened with Electrum, and it seems like the scammer is running some nodes that broadcast phishing links.

x
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!
OSZAR »