@kitto
Crypto users on MacBook, please be extra careful! According to recent industry analysis, including from security firm SlowMist, a new type of macOS malware called 'MacSync Stealer' is on the rise. It typically lures users into running scripts that bypass Gatekeeper, the Mac's security feature, through fake ads or developer community support forms.
The most frightening aspect is the 'wallet app replacement' tactic. It locates legitimate hardware wallet management apps installed on your Mac, like Ledger Live or Trezor Suite, and deletes them entirely. It then replaces them with fake WKWebView-based apps that look identical to the real ones. The moment you launch the app as usual and enter your 24-word recovery phrase (seed phrase) without suspicion, your assets are completely drained. On top of that, it steals local data from the Telegram desktop app, allowing it to hijack entire accounts without even going through 2FA.
If you launch a wallet app and it suddenly asks you to re-enter your recovery phrase or security passphrase, stop immediately and be suspicious. For protection, we highly recommend setting a local password lock on your Telegram desktop app. If you think you've already entered information into a suspicious app, move your assets to a new seed phrase generated on another secure device without delay. It looks like it's time to abandon the complacent idea that Macs are inherently secure haha.
Related Links