Security researcher Jeremiah Fowler recently discovered 149 million logins and passwords stolen by a new type of malware called infostealer.
The database includes popular social media accounts such as Facebook, Instagram, TikTok, Gmail, as well as hundreds of thousands of Binance accounts, highlighting the magnitude of the risk for crypto users.
Infostealer disguises itself as a mod or cheat for a popular game, and once installed on a computer or phone, it can steal logins, take over crypto wallets, and even install crypto miners that use the victim’s computer power without permission.
The malware can attack over 100 web browsers, including Chrome, Firefox, Edge, Brave, and Opera, and targets over 80 crypto platforms, such as Binance, Coinbase, MetaMask, SafePal, and Exodus.
It’s important to understand that this is not an attack on Binance itself. The real problem is the users’ devices infected with malware.
Accounts can be stolen if security measures are weak, and this shows that even though crypto platforms are secure, users remain vulnerable if they are not careful.
The attack also warns that malware threats are becoming increasingly sophisticated.
Infostealers can collect sensitive data not only from crypto platforms, but also government, bank, and credit card accounts, opening up opportunities for phishing or impersonation by malicious parties.
Users are encouraged to always install antivirus and anti-malware, enable Multi-Factor Authentication (MFA), and keep their operating systems and web browsers updated.
Crypto security is not just the responsibility of the platform, but starts with the user’s own devices and habits. With the right precautions, digital assets can be protected from being stolen by malware like infostealers.
