Hacker News new | past | comments | ask | show | jobs | submit login
Bitcoin Scam App Approved by Apple Robs iPhone User of $600k (macrumors.com)
24 points by keleftheriou on March 30, 2021 | hide | past | favorite | 11 comments



I'm most concerned about how they accomplished what's described here:

> Apple says the fake Trezor app got through the App Store through "a bait-and-switch." It was called Trezor and used the Trezor logo and colors, but said that it was a "cryptography" app that would encrypt iPhone files and store passwords. The developer of the fake app told Apple that it was "not involved in any cryptocurrency." After the fake Trezor app was submitted, it changed itself into a cryptocurrency wallet, which Apple was not able to detect.


Considering how much of a dick apple is during the app reviews and pretentious about their quality, I hope they will be liable for this.


Funny considering Apple’s argument for disallowing alternate app stores is that their App Store curation creates a safe experience for the user.


A single app slipping through the net in how many years of app store? 10? Yes, very funny.


Would you wager that this is the only app that ever slipped through?


Why should I not considering how widely iOS is deployed and under what scrutiny Apple is?


Maybe because the article actually covered this:

> Apple acknowledged that it has discovered other cryptocurrency scams on the App Store , but did not provide specific details on numbers nor whether there had been fake Trezor apps in the past. Trezor does not offer an iOS app at all, and Trezor spokesperson said that it had been notifying Apple and Google about fake Trezor apps "for years."


Thanks.


Sounds horrible but what was the user thinking? Why did they get a hardware wallet and hope to magically access that wallet without his hardware device? What would the hardware wallet be doing if this was possible?

Didn't they find it fishy that they were inputting their recovery phrase into the app? This is why I tell friends to just keep it in Coinbase. The odds of Coinbase being hacked and going insolvent <<<<<< non-technical user messing up in a myriad of different ways.


Bitcoin lets you be your own bank, so I hear. Should have checked with his bank's anti-fraud department.


Original post had paywalled source: https://news.ycombinator.com/item?id=26638131




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: