Поделиться этой статьей

Google Yanked MetaMask From the Chrome Store, Left a Phishing Scam Up

Scams are an epidemic in the crypto space, and clumsy actions by big tech companies can open up the opportunities, as MetaMask learned recently.

Автор David Floyd
Обновлено 13 сент. 2021 г., 8:13 a.m. Опубликовано 26 июл. 2018 г., 7:31 p.m. 3 min readПереведено ИИ
fish hooks phishing

It was "an interesting wake-up call."

That was how Kevin Serrano, an employee at ethereum startup and incubator ConsenSys, described the revelation that MetaMask had been removed from Google Chrome's web store in a recently published blog post.

MetaMask, a Consensys "spoke," is an ethereum wallet that also serves as a bridge between web browsers and the ethereum blockchain. A little after 10:00 a.m. EDT Wednesday morning, the MetaMask team announced on Twitter that the extension had been removed from the Chrome store.

The team received no explanation for Google's action, according to Serrano, or even notification that it had happened – though he added that it's possible the email bounced. The extension was restored to the web store around five hours later. According to Serrano, Google explained that delisting MetaMask had been an "error."

And in this way, Serrano said it became clear:

"For a product that enables decentralized technology, [MetaMask] has centralized points of failure."

It's an issue blockchain entrepreneurs have grappled with since the industry first started testing its ideas.

One of the fundamental merits of blockchains and the decentralized applications built on top of them is that no single party can take down or censor them. Yet, this theoretical quality is frequently rendered moot where blockchain networks meet the legacy web or financial system.

Centralized exchanges, where fiat currency is converted into cryptocurrencies, are the most commonly cited example of where censorship-resistance and decentralization fail in practice.

But this incident has highlighted another such choke point: app stores.

Making the app available to users, Serrano continued, requires "placing our trust in browsers, GitHub and the people deploying in order to keep the system working."

Phishing frenzy

It's not only the trust required to keep the extension open to the most users (sufficiently tech-savvy users could have still downloaded it on Chrome), but also the fact that the action opened up opportunities for scammers – an endemic problem in the cryptocurrency space.

With MetaMask proper removed, Serrano wrote, "What was left when one searched the term 'MetaMask' on the store was a few re-branded MetaMask forks and one ambiguously branded lookalike."

Indeed, the situation presented the risk of phishing, in which attackers trick would-be users into downloading fake files that contain malware.

At one point Augur, another ethereum project, tweeted a warning not to download an extension called "MetaMask by Kupi.net," which was available in the Chrome store (it has since been removed). The app "is a fake, phishing app," the Augur team wrote, attaching an image:

metamask phishing chrome

Serrano told CoinDesk in an email that attempts to steal from users were also present on Telegram, a messaging platform popular with cryptocurrency enthusiasts, where attackers were "posing as an alternative support desk." It appears that some users were affected by this scam, he said, as well as an unrelated one on the Google Play Store, which lists apps for Google's Android operating system.

A Google spokesperson declined to comment on these phishing attempts.

While MetaMask continued to work on other browsers – Brave, Opera and Firefox – and those who had already downloaded the Chrome version were still able to use it, the team is looking into more decentralized alternatives such as IPFS, Serrano said.

The team also published a guide to installing the extension manually.

Fish hooks image via Shutterstock

Больше для вас

ETFs (Markus Winkler/Pixabay, modified by CoinDesk)

The S&P 500 posted its longest weekly winning streak since 2023 and Brent oil stabilized near $92 on US-Iran ceasefire hopes. The biggest cryptocurrencies still drifted lower, with Hyperliquid's HYPE the only major name to rally.

Что нужно знать:

  • U.S. stocks and oil rallied, with the S&P 500 logging a ninth straight weekly gain and Brent crude hovering near $92 a barrel on hopes for a U.S.-Iran ceasefire extension.
  • Major cryptocurrencies lagged the macro rally, with bitcoin, ether and other large-cap tokens falling around 2% to 6% amid cooling...