{"id":24337,"date":"2022-04-18T14:06:17","date_gmt":"2022-04-18T18:06:17","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=24337"},"modified":"2022-04-18T14:06:25","modified_gmt":"2022-04-18T18:06:25","slug":"metamask-warns-apple-users-of-phishing-attack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/metamask-warns-apple-users-of-phishing-attack\/","title":{"rendered":"MetaMask warns Apple users of phishing attack"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">After an <a href=\"https:\/\/coinscreed.com\/staging\/metamask-integrates-apple-pay-feature.html\" target=\"_blank\" data-type=\"post\" data-id=\"22470\" rel=\"noreferrer noopener\">iPhone user<\/a> complained of losing over $650,00 in NFTs and ApeCoin, MetaMask issued a warning to Apple users about phishing attacks and how to protect themselves from getting defrauded.<\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-117.png\" alt=\"MetaMask warns Apple users of phishing attack\" class=\"wp-image-24347\" width=\"843\" height=\"493\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-117.png 739w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-117-300x175.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-117-150x88.png 150w\" sizes=\"(max-width: 843px) 100vw, 843px\" \/><figcaption>MetaMask warns Apple users of phishing attack<\/figcaption><\/figure><\/div>\n\n\n\n<p>On April 17, MetaMask issued a warning to Apple users about phishing attacks after an iPhone user was defrauded of $650,000 in NFTs and <a href=\"https:\/\/coinscreed.com\/staging\/fake-apecoin-airdrop-scams-unsuspecting-users-of-1-million.html\" target=\"_blank\" data-type=\"post\" data-id=\"21914\" rel=\"noreferrer noopener\">ApeCoin <\/a>(APE).<\/p>\n\n\n\n<p>The default settings on devices like the iPhone, iPad, and MacBook, according to MetaMask, allow hostile actors to read the seed phrase or &#8220;password-encrypted MetaMask vault&#8221; kept on <a href=\"https:\/\/www.google.com\/search?q=MetaMask+warns+Apple+users+of+phishing+attack&source=lmns&bih=625&biw=1366&rlz=1C1SQJL_enNG889NG889&hl=en&sa=X&ved=2ahUKEwiKh_H-l573AhUMsxQKHbz5D_QQ_AUoAHoECAEQAA\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=MetaMask+warns+Apple+users+of+phishing+attack&source=lmns&bih=625&biw=1366&rlz=1C1SQJL_enNG889NG889&hl=en&sa=X&ved=2ahUKEwiKh_H-l573AhUMsxQKHbz5D_QQ_AUoAHoECAEQAA\" rel=\"noreferrer noopener\">Apple's iCloud storage service<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udd12 If you have enabled iCloud backup for app data, this will include your password-encrypted MetaMask vault. If your password isn\u2019t strong enough, and someone phishes your iCloud credentials, this can mean stolen funds. (Read on \ud83d\udc47) 1\/3<\/p>&mdash; MetaMask.eth \ud83e\udd8a (@MetaMask) <a href=\"https:\/\/twitter.com\/MetaMask\/status\/1515727239391809536?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 17, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">About the Hack<\/h2>\n\n\n\n<p>Domenic Iacovone, a Twitter user, claimed on April 15 that he had lost all of his non-fungible tokens (NFTs) in his wallet. Three Mutant Apes, three Gutter Cats, and $100,000 in ApeCoin were among the items.<\/p>\n\n\n\n<p>Iacovone stated he received a call on his phone from an Apple number, according to caller ID. He didn't pick up the phone at first but phoned it back because the caller ID showed it was from Apple.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"435\" height=\"327\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-116.png\" alt=\"\" class=\"wp-image-24338\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-116.png 435w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-116-300x226.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-116-150x113.png 150w\" sizes=\"(max-width: 435px) 100vw, 435px\" \/><\/figure>\n\n\n\n<p>The caller, however, was a scammer using a phony phone number. Under the guise of being an Apple official, he asked Iacovone for a code to be transmitted to his phone. Iacovone claimed that seconds after sharing the code with the scammer, he lost everything in his <a href=\"https:\/\/coinscreed.com\/staging\/metamask-wallet-integrates-4-crypto-custodians.html\" target=\"_blank\" data-type=\"post\" data-id=\"23999\" rel=\"noreferrer noopener\">Metamask wallet<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Hey y\u2019all, let\u2019s see how amazing this community can be. My entire wallet was just stolen. Totally wiped out, <br><br>MAYC 28478, MAYC 8952, MAYC 7536<br><br>Gutter cat 2280 , 2769, 2325<br>Also stole 100k in ape coin. <br>Looking for all the help I can get. <br><br>100kreward  <a href=\"https:\/\/twitter.com\/BoredApeYC?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BoredApeYC<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/GutterCatGang?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@GutterCatGang<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Domenic Iacovone (@revive_dom) <a href=\"https:\/\/twitter.com\/revive_dom\/status\/1514751885126914051?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 14, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Explaining the Hack<\/h2>\n\n\n\n<p>The phishing attack was explained by Twitter user @Serpent, the founder of crypto threat mitigation system Sentinel. According to him, the attacker pretended to be from Apple and reported that there was suspicious activity on the account using a caller ID spoofer.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/twitter.com\/Serpent\/status\/1515545806857990149\n<\/div><\/figure>\n\n\n\n<p>The scammer then demanded that the victim's Apple ID password be reset. The victim will be given a code to reset their password, and the fraudster will ask for it, stating it is to prove their ownership of the Apple ID.<\/p>\n\n\n\n<p>The scammer really uses the code to reset the victim's password, giving them access to their iCloud account. They can access MetaMask data stored on iCloud and take the victims' assets.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">MetaMask gives a solution<\/h2>\n\n\n\n<p>According to MetaMask, users can turn off iCloud backups for their app by &#8220;Settings &gt; Profile &gt; iCloud &gt; Manage Storage &gt; Backups,&#8221; <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">You can disable iCloud backups for MetaMask specifically by turning off the toggle here:<br>Settings &gt; Profile &gt; iCloud &gt; Manage Storage &gt; Backups.<br>2\/3<\/p>&mdash; MetaMask.eth \ud83e\udd8a (@MetaMask) <a href=\"https:\/\/twitter.com\/MetaMask\/status\/1515727240343957508?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 17, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>For those who want to turn off the feature entirely, they can do so at \u201cSettings &gt; Apple ID\/iCloud &gt; iCloud &gt; iCloud Backup.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After an iPhone user complained of losing over $650,00 in NFTs and ApeCoin, MetaMask issued a warning to Apple users about phishing attacks and how to protect themselves from getting defrauded. On April 17, MetaMask issued a warning to Apple users about phishing attacks after an iPhone user was defrauded of $650,000 in NFTs and [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":24347,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[408,8542,5100],"class_list":["post-24337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-apple","tag-iphone-2","tag-metamask"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-117.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/24337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=24337"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/24337\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/24347"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=24337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=24337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=24337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}