Share this article

Fake MetaMask App on Google Play Store Hosted Crypto Malware

Ethereum dapp service MetaMask was targeted by crypto-stealing malware found on Google's Play Store.

Updated Sep 13, 2021, 8:53 a.m. Published Feb 11, 2019, 2:00 p.m.
Google Play Store

A form of malware that replaces victims' cryptocurrency wallet addresses has been discovered for the first time in an app on Google Play Store.

Security firm ESET published a blog post on Friday, saying that the malware, known as a “clipper,” intercepts the content of the clipboard and, if it finds the addresses of online cryptocurrency wallets, can replace them with addresses owned by the attacker.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The malware-laden app, discovered by ESET, impersonates a service called MetaMask that provides access to ethereum decentralized applications, or dapps. The malware's main purpose is to steal MetaMask users' credentials and private keys to be able to access their ethereum funds. However, it can also intercept bitcoin and ethereum wallet address copied to the clipboard.

MetaMask does not currently offer an app product for mobile devices.

The fake app's description can be seen below:

metamask-app-malware

The app was removed from the Play Store after ESET reported it to Google's security team.

In response to the malware's discovery, MetaMask tweeted:

"We would appreciate if @GooglePlayDev would reserve trademarked names for apps, especially repeat phishing targets like us.”

This isn't MetaMask's first issue with Google. Back in July, the firm's browser extension was erroneously removed from Google's Chrome Web Store for about five hours before being restored.

To stay safe from such mobile malware, ESET advised users to keep devices updated and double-check every step in all crypto transactions, including wallet addresses copied on a clipboard.

Earlier this month, another form of malware was discovered by cybersecurity firm Palo Alto Networks that steals browser cookies and other information on victims’ Apple Mac computers to steal cryptocurrencies.

Google Play Store image via Shutterstock; malware screenshot courtesy of ESET

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Bitcoin Rebounds to $93K From Post-Fed Lows, but Altcoins Remain Under Pressure

Bitcoin (BTC) price (CoinDesk)

Downward pressure on bitcoin is losing steam, with the market stabilizing but not yet out of the woods, said one analyst.

What to know:

  • Bitcoin rebounded from a sharp early selloff on Thursday to trade above $93,000 shortly after the close of U.S. stocks.
  • The late-day gain in bitcoin came alongside a rebound in the Nasdaq from big morning losses; the tech index closed with just a 0.25% loss.
  • Downward pressure on bitcoin is losing steam, said one analyst, but the market is not yet out of the woods.