Hacker News new | ask | show | jobs
by drcross 2480 days ago
Please read the following if you use chrome password manager on your phone:

https://www.reddit.com/r/Bitcoin/comments/cxtfak/coinomi_wal...

TL;DR; Someone in google is sniffing autocorrect text and when they find 12 word bitcoin seed phrases they are stealing the bitcoin. This is a serious breach of trust. If someone from Google is reading this please take it seriously.

EDIT: On further research it may not categorically be someone in google if the autocorrect text is sent in plain text. Autocorrect text should not be sent in the clear though. See here for more information: https://avoid-coinomi.com

2 comments

It looks like autocorrect wasn't sent in the clear at least according to one report.

This[1] report on this incident (commissioned by the wallet creators) makes me skeptical that autocorrect or Google was involved at all. I think some sort of malware or phishing to steal the seed was a much more likely attack.

[1] https://medium.com/@cipherblade/how-not-to-react-when-your-c...

I'm not sure if I believe that, but I'd never trust anyone with bitcoin seeds. I'm not sure what the risk is for passwords I'd type in my browser anyway and that I could reset with my Gmail account.