SeaFlower Backdoor Campaign Exploits Web3 Wallets To Harvest Seed Phrases

A newly discovered cybersecurity threat, dubbed SeaFlower, has targeted users of popular Web3 wallets, attempting to exfiltrate sensitive seed phrases.

This campaign, launched in early 2022, highlights the growing risks to Web3 wallet users and emphasizes the importance of security vigilance.

By using backdoor code embedded in legitimate apps, attackers aim to steal user credentials without altering the wallet’s apparent functionality.

What Is SeaFlower?

The SeaFlower campaign is believed to be one of the most technically sophisticated threats targeting Web3 wallets, following closely behind high-profile attackers such as the Lazarus Group.

The name “SeaFlower” was chosen after discovering Chinese-language references, including a username linked to a Chinese author.

During their investigation, security researchers uncovered macOS usernames, Chinese IP addresses, and the attack’s signing infrastructure. These findings pointed to a Chinese-speaking group behind the campaign, though full attribution remains challenging.

SeaFlower’s primary attack method is to modify legitimate Web3 wallet apps such as MetaMask, Coinbase Wallet, TokenPocket, and imToken.

The attackers inject a backdoor into these apps, allowing them to send user seed phrases to an external server.

Intercepting HTTPS traffic of SeaFlower backdoor (Source: confiant)
Intercepting HTTPS traffic of SeaFlower backdoor (Source: confiant)

This backdoor code is undetectable to the average user, as the wallet’s functionality remains unchanged. However, monitoring network traffic reveals that these modified apps communicate with suspicious domains, potentially exposing sensitive user data.

How Does SeaFlower Work?

SeaFlower’s modus operandi is highly stealthy. When a user installs a backdoored version of a wallet app, the user interface and overall experience remain normal, with no obvious signs of malicious activity.

However, when users set up their wallet and enter their seed phrase, the app sends this data over an encrypted network connection to an attacker-controlled server. This process uses custom code modifications to the app that run in the background.

Researchers have reverse-engineered several backdoored wallet versions, including those for MetaMask and Coinbase Wallet, and discovered that attackers use various techniques to harvest seed phrases.

imToken cloned website (courtesy of DomainTools) hosted at: appim[.]xyz (Source: confiant)
imToken cloned website (courtesy of DomainTools) hosted at: appim[.]xyz (Source: confiant)

For instance, the MetaMask iOS app contains a backdoor that activates when the seed phrase is stored. This code uses the startupload() function to send the seed phrase to an attacker’s server.

In some cases, the attacker utilizes modified libraries, such as MonkeyDev, to inject code that exfiltrates the seed phrase when the app accesses the wallet’s storage.

To distribute these backdoored apps, SeaFlower uses fake, cloned websites that mimic the official wallet download pages.

These websites are often promoted through Chinese search engines like Baidu, which serve as one of the main entry points for potential victims.

Once a user clicks on a misleading search result, they are directed to these fraudulent sites, where they unwittingly download a compromised app.

SeaFlower’s use of cloned websites, fake app downloads, and sophisticated backdoor code makes it one of the most complex Web3 wallet attacks identified so far.

According to Confiant, while the backdoor itself remains undetected during normal app use, the exfiltration of user seed phrases is a clear risk.

cloned Coinbase Wallet website hosted at som-coinbase[.]com (Source: confiant)

Web3 wallet developers must implement stronger security measures to protect users from such sophisticated threats.

Additionally, users are urged to download apps only from official app stores and to avoid trusting third-party provisioning profiles, as these could expose them to similar attacks.

Follow us on Google NewsLinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories