~snip
While iOS once seemed like a secure system, attackers have now found a way to bypass its defenses - not by "hacking" it directly, but by circumventing protections through "trojan horse" tactics. This method reminds me of the
this incident, where a malicious program was passed off as the desired trading bot. It appears we have entered an active phase of the industry where malware increasingly masquerades as legitimate apps.
It is time to become seriously alarmed and exercise the utmost vigilance.
I saw a news report stating that attackers have already siphoned off over $500k. in USDT from victim's wallets. I wonder why only USDT? Why not other crypto assets? Did the victims hold only USDT, or is this somehow related to the trojan's (Ghostblade) limitations?
What conclusion did I reach after learning about this incident? I am increasingly convinced of the need to use dedicated devices (or OS's) for handling cryptocurrencies. While I previously thought this applied only to PCs and laptops, I now believe the same rule should apply to mobile devices - unless, of course, you are willing to risk losing the contents of your wallet (for instance, if you are holding only small amounts). Essentially, you need a second smartphone specifically for cryptocurrency transactions - one free of unnecessary apps and used for no risky activities (like browsing dubious websites), and linked to a dedicated email (used nowhere else) and other measures that could otherwise serve as a "backdoor" into your funds. An even better solution is to use a combination of a smartphone and a hardware wallet.
What times we live in! Hardware wallets, smartphones, and even people (via social engineering) are being hacked. Where, then, should the humble investor keep their assets?