Shitcoin Wallet Pushing Malicious Codes, Collecting Exchange Credentials
- The wallet has over 2,000 users, per the company.

Revealed by Harry Denley, a security and anti-phishing expert, on Monday, the vulnerable codes are collecting credentials of major crypto platforms, including Binance, MyCryptoWallet, and many others.
⚠️ A browser crypto wallet is injecting malicious JS to steal secrets from @myetherwallet @idexio @binance @neotrackerio @SwitcheoNetwork
Extension-native wallet create also sends secrets to their backend! Bad guys: erc20wallet[.]tk ExtensionID: ckkgmccefffnbbalkmbbgebbojjogffn pic.twitter.com/TE2iw5d8Md — harrydenley.eth ◊ (@sniko_) December 31, 2019
Shitcoin Wallet works as a Chrome extension that downloads javascript files from a remote server. The code then looks for any open tabs on the web browser containing pages of any digital asset exchanges and Ethereum network tools to scrape the data in those windows.
The malicious codes send all the data to a remote server identified as “erc20wallet.tk.” The top-level domain belongs to a group of the south pacific island territory of New Zealand called Tokelau.
A suspiciously named wallet indeed
Designed to hold Ethereum and other ERC-20 tokens, the company claims that it has over 2,000 users. The platform basically operates as browser extensions, even though per the company, there is a desktop application for Windows.
“It is a web wallet which has several extensions for different browsers,” a blog post by the company explained.
Meanwhile, many browser extensions were found in the past with malicious codes. However, most of those were illegally mining digital currencies on victims’ computers.
Most recently, Google banned widely used Ethereum wallet and Dapp Dapp A dapp, or decentralized application, is a computer application that runs on a distributed network. Dapps are most commonly associated with the blockchain networks that support them, such as Ethereum.Because dapps are decentralized, they do not exist under the purview of a centralized custodian or authority. The original Ethereum white paper effectively splits dapps into three types. This includes apps that manage money, apps where money is involved (but also requires another piece), and apps designated as the “other” category, which includes voting and governance systems.The type of app represents one in which a user may need to exchange ether as a way to settle a contract with another user. This uses the network’s distributed computer nodes as a way to facilitate the distribution of this data.Meanwhile, the second type of app melds money with information located outside the blockchain. Finally, in order to execute, ‘smart contracts’ are utilized that rely on so-called “oracles” to relay up-to-date information about the outside world. Understanding Dapps in Real World ApplicationsFor example, a standard application such as Twitter is run by a centralized authority. While these kinds of apps have thousands of users located around the globe, the backend of the app is controlled by a single entity. If there is a problem with the Tweets on Twitter, the company that runs the app can delete them. However, if Twitter was a dapp, all of the tweets that have been posted could not be deleted by the dapp’s creators. Instead, the poster may have the option to edit their posts, but each of the various versions of a post would remain there forever. A dapp, or decentralized application, is a computer application that runs on a distributed network. Dapps are most commonly associated with the blockchain networks that support them, such as Ethereum.Because dapps are decentralized, they do not exist under the purview of a centralized custodian or authority. The original Ethereum white paper effectively splits dapps into three types. This includes apps that manage money, apps where money is involved (but also requires another piece), and apps designated as the “other” category, which includes voting and governance systems.The type of app represents one in which a user may need to exchange ether as a way to settle a contract with another user. This uses the network’s distributed computer nodes as a way to facilitate the distribution of this data.Meanwhile, the second type of app melds money with information located outside the blockchain. Finally, in order to execute, ‘smart contracts’ are utilized that rely on so-called “oracles” to relay up-to-date information about the outside world. Understanding Dapps in Real World ApplicationsFor example, a standard application such as Twitter is run by a centralized authority. While these kinds of apps have thousands of users located around the globe, the backend of the app is controlled by a single entity. If there is a problem with the Tweets on Twitter, the company that runs the app can delete them. However, if Twitter was a dapp, all of the tweets that have been posted could not be deleted by the dapp’s creators. Instead, the poster may have the option to edit their posts, but each of the various versions of a post would remain there forever. Read this Term browser MetaMask for violating its financial policy from Play Store. Though not specified, the tech giant indicated the crypto mining feature, which is strictly bans in its policy. Notably, the platform does not offer any crypto mining services to its users.
Revealed by Harry Denley, a security and anti-phishing expert, on Monday, the vulnerable codes are collecting credentials of major crypto platforms, including Binance, MyCryptoWallet, and many others.
⚠️ A browser crypto wallet is injecting malicious JS to steal secrets from @myetherwallet @idexio @binance @neotrackerio @SwitcheoNetwork
Extension-native wallet create also sends secrets to their backend! Bad guys: erc20wallet[.]tk ExtensionID: ckkgmccefffnbbalkmbbgebbojjogffn pic.twitter.com/TE2iw5d8Md — harrydenley.eth ◊ (@sniko_) December 31, 2019
Shitcoin Wallet works as a Chrome extension that downloads javascript files from a remote server. The code then looks for any open tabs on the web browser containing pages of any digital asset exchanges and Ethereum network tools to scrape the data in those windows.
The malicious codes send all the data to a remote server identified as “erc20wallet.tk.” The top-level domain belongs to a group of the south pacific island territory of New Zealand called Tokelau.
A suspiciously named wallet indeed
Designed to hold Ethereum and other ERC-20 tokens, the company claims that it has over 2,000 users. The platform basically operates as browser extensions, even though per the company, there is a desktop application for Windows.
“It is a web wallet which has several extensions for different browsers,” a blog post by the company explained.
Meanwhile, many browser extensions were found in the past with malicious codes. However, most of those were illegally mining digital currencies on victims’ computers.
Most recently, Google banned widely used Ethereum wallet and Dapp Dapp A dapp, or decentralized application, is a computer application that runs on a distributed network. Dapps are most commonly associated with the blockchain networks that support them, such as Ethereum.Because dapps are decentralized, they do not exist under the purview of a centralized custodian or authority. The original Ethereum white paper effectively splits dapps into three types. This includes apps that manage money, apps where money is involved (but also requires another piece), and apps designated as the “other” category, which includes voting and governance systems.The type of app represents one in which a user may need to exchange ether as a way to settle a contract with another user. This uses the network’s distributed computer nodes as a way to facilitate the distribution of this data.Meanwhile, the second type of app melds money with information located outside the blockchain. Finally, in order to execute, ‘smart contracts’ are utilized that rely on so-called “oracles” to relay up-to-date information about the outside world. Understanding Dapps in Real World ApplicationsFor example, a standard application such as Twitter is run by a centralized authority. While these kinds of apps have thousands of users located around the globe, the backend of the app is controlled by a single entity. If there is a problem with the Tweets on Twitter, the company that runs the app can delete them. However, if Twitter was a dapp, all of the tweets that have been posted could not be deleted by the dapp’s creators. Instead, the poster may have the option to edit their posts, but each of the various versions of a post would remain there forever. A dapp, or decentralized application, is a computer application that runs on a distributed network. Dapps are most commonly associated with the blockchain networks that support them, such as Ethereum.Because dapps are decentralized, they do not exist under the purview of a centralized custodian or authority. The original Ethereum white paper effectively splits dapps into three types. This includes apps that manage money, apps where money is involved (but also requires another piece), and apps designated as the “other” category, which includes voting and governance systems.The type of app represents one in which a user may need to exchange ether as a way to settle a contract with another user. This uses the network’s distributed computer nodes as a way to facilitate the distribution of this data.Meanwhile, the second type of app melds money with information located outside the blockchain. Finally, in order to execute, ‘smart contracts’ are utilized that rely on so-called “oracles” to relay up-to-date information about the outside world. Understanding Dapps in Real World ApplicationsFor example, a standard application such as Twitter is run by a centralized authority. While these kinds of apps have thousands of users located around the globe, the backend of the app is controlled by a single entity. If there is a problem with the Tweets on Twitter, the company that runs the app can delete them. However, if Twitter was a dapp, all of the tweets that have been posted could not be deleted by the dapp’s creators. Instead, the poster may have the option to edit their posts, but each of the various versions of a post would remain there forever. Read this Term browser MetaMask for violating its financial policy from Play Store. Though not specified, the tech giant indicated the crypto mining feature, which is strictly bans in its policy. Notably, the platform does not offer any crypto mining services to its users.