MultiversX Tracker is Live!

Crypto Developer Gomtu loses ~$50K after storing his seed phrase in Google Drive & downloading malware

All Cryptocurrencies

by COINS NEWS 29 Views

A crypto dev who goes by Gomtu (@gomtu_xyz) just got drained for around $49K, & the way it happened is worth walking through, because so many have fallen for similar scams.

Here's the chain, from his own posts on X..

He was setting up a new MacBook. Installed Chrome, signed into his main Google account, turned on Sync. Then he searched "homebrew," the package manager basically every Mac dev installs on day one. He clicked the top result. It was a Google sponsored ad. The page behind it was a pixel-perfect clone of the real brew[.]sh, same design, same copy, hosted on a different URL. He copied the install command & pasted it into Terminal, like he's done setting up machines dozens of times.

The command was base64-encoded. Decoded, it pointed at a malicious URL & pulled down malware his scanner later flagged as "MacOS.Stealer.Nova."

The stealer ran a "pass-the-cookie" attack: it lifted his Google login session cookie, used it to open his Google Drive without a password, & found the spreadsheet where he'd kept 50 to 70 seed phrases for years. He confirmed it after the fact from Drive version history, three edits logged on a file he never opened. His main wallet was in that sheet. The attacker drained it, dumped his NFTs, alts, & ETH to the floor, & swapped everything into DAI. About $49K gone, roughly 60% of the funds he actively moves around.

So two failures stacked on top of each other:

  1. Google served a malware clone as the top ad for one of the most-searched dev tools on earth.
  2. He kept his seed phrases in the cloud.

Together, it's a total loss. The malware didn't even need his keys, because his keys were sitting in a Google Drive it could walk right into.

The takeaways, because this is the kind of $50K lesson you don't need to experience

  • Never store a seed phrase or private key anywhere that touches the cloud. Not Google Drive, not iCloud, not Notes, not email, not a cloud-synced password manager. Write it on paper or steel, offline, & keep it that way. A cloud-stored seed is worse than a hardware wallet getting hacked, because there's no device to break into, just a login.
  • Verify what you paste into a terminal. Type the real domain yourself (brew.sh) instead of clicking an ad. If an install command is base64 or obfuscated, decode it & read where it actually goes before you run it. Piping a link you didn't verify straight into bash is how machines get owned.
  • Don't keep everything in one hot wallet. Split it. Bulk in cold storage or a hardware wallet, only working capital in the wallet you touch daily. If he'd done that, this is a bad day instead of a wipe.
  • If you catch a live drain, move fast. He recovered a couple thousand by pushing what was left into a fresh wallet before the attacker swept it.

He's a developer who has set up Macs many times & still got caught, because the trap was well-built & the fatal mistake, seeds on Google drive, was made years earlier.

Self-custody is only as strong as your worst habit and far too many have a seed phrase saved somewhere convenient. Get a steel plate and write it there.

submitted by /u/TimmyXBT
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments