• Advertise
  • Submit a Press Release
  • Contact Us
Blockchain & Cryptocurrencies Tabloid
  • Finance & Blockchain News
  • Bitcoin News
    Bitcoin sees BIP 110 debate after 66kB image transaction

    Bitcoin sees BIP-110 debate after 66kB image transaction

    Bitcoin reserve plan stalls as Vancouver cites charter rules

    Bitcoin reserve plan stalls as Vancouver cites charter rules

    Bitcoin 2024 halving pressures miners as EMCD pivots

    Bitcoin 2024 halving pressures miners as EMCD pivots

    TRON TRX rises as SEC ends Sun case with 10M deal

    TRON (TRX) rises as SEC ends Sun case with $10M deal

    Stablecoins face yield fight as Senate eyes March markup

    Stablecoins face yield fight as Senate eyes March markup

    Bitcoin holds as Brazil sets 2027 crypto reserve rules

    Bitcoin holds as Brazil sets 2027 crypto reserve rules

  • Altcoin News
    • All
    • Bitcoin Cash
    • Cardano
    • EOS
    • Ethereum
    • Litecoin
    • Monero
    • Ripple
    • Stellar
    Solana Gains $8.2M Despite Broader Crypto Outflows

    Solana Gains $8.2M Despite Broader Crypto Outflows

    Aave CEO Criticizes Bank of England's Stablecoin Cap

    Aave CEO Criticizes Bank of England’s Stablecoin Cap

    Ripple Expands Custody Services to Ethereum and Solana

    Ripple Expands Custody Services to Ethereum and Solana

    MegaETH Mainnet Goes Live: Launch Details and Expectations

    MegaETH Mainnet Goes Live: Launch Details and Expectations

    Tom Lee Defends Ethereum Crash as V-Shaped Recovery

    Tom Lee Defends Ethereum Crash as V-Shaped Recovery

    Buterin Sells Over $13M Ethereum for Charity

    Buterin Sells Over $13M Ethereum for Charity

    Trending Tags

    • Ethereum
    • Bitcoin Cash
    • Litecoin
    • Monero
    • Ripple
  • Crypto 101
    • All
    • Cryptocurrencies
    • Services
    Benefits Of Choosing the Right AI Trading Bot

    4 Benefits Of Choosing the Right AI Trading Bot

    Crypto Trading

    A Beginner’s Guide to Crypto Trading: Unlocking the World of Digital Coins

    BitcoinGames.com

    BitcoinGames.com Introduces the Ultimate Casino Gaming Experience with Bitcoin

    How AI is Helping Athletes and Fans Get the Most out of the Game

    From Training to Judging, AI is Entering the Ring

    Top 5 Websites for Buying Gift Cards with Crypto

    Clutch Savours – Gift Certificates You Can Buy with Crypto

    Layer 2 Blockchains

    Everything You Need To Know About Layer 2 Blockchains

  • Blockchain Event
No Result
View All Result
Blockchain & Cryptocurrencies Tabloid
No Result
View All Result

Major Coinomi Wallet Vulnerability Exposed

Anca Florentis by Anca Florentis
February 27, 2019
in News
Coinomi vulnerability

A critical vulnerability was found in the crypto mobile wallet Coinomi when a user lost $60k-70k of cryptocurrency after he installed the app. According to users, the platform sent plain text seed phrases to Google API for spellchecking.

IT security consultant, Warith Al Maawali, is the person attributed to first discovering the problem. But he made this discovery at the cost of his own crypto, and because of this he made a website avoid-coinomi.com detailing the events and cautioning others to not use the service.

“First of all I admit it was my mistake trusting Coinomi wallet by inserting one of my main wallets (Exodus wallet) passphrase into their application,” Al Maawali wrote on his website.

“I wanted to shift some of the assets that were not supported by Exodus wallet using the same passphrase/seed.”

The consultant went on to explain that their main application, which was installed on February 14 by the user, was not digitally signed, and he alerted the Coinomi team through Twitter about this issue- but he had already entered his passphrase for his Exodus wallet into the non-signed one.

He noticed afterward on February 22nd that “more than 90% of my Exodus wallet assets were transferred to multiple wallet addresses and the first transaction began with BTC on 19th February 2019 around UTC 3:30 AM. Then followed by ETH (including ERC20 tokens), LTC and finally BCH.”

When he began delving deeper into the matter, he found out that the entire passphrase, which was written in plain text, was sent to a third party domain (googleapis.com) for spellchecking purposes.

“As a result, someone from Google’s team or whoever had access to the HTTP requests that are sent to googleapis.com found the passphrase and used it to steal my USD 60K – USD 70K worth crypto assets (at current market price). Anyone who is involved in technology and crypto-currency knows that a 12 random English words separated by spaces will probably be a passphrase to a cryptocurrency wallet,” u/warith wrote.

He alerted Coinomi of what he discovered, but he did not get the response he was expecting.

“Coinomi’s team did not reflect any responsible behavior and they kept asking me about the technical issue behind the bug because they were worried about their public image and reputation. They kept reminding me (kinda threatening me) of the legal implications if I go public with the information I have and they forgot their legal responsibility for my stolen crypto assets as well as the risk that impacts other users of the wallet.”

The user said he will be taking legal action against Coinomi LTD, should the company not take assume fault for the technical issue that has caused him financial damage. He also received a reward from Coinomi for finding the bug, but he is not satisfied with the response given to him in relation to his lost funds.

Coinomi apparently solved the bug and kept quiet. They have identified the addresses and blacklisted them, and the funds have not been touched since the incident.

This isn’t the first privacy breach Coinomi has experienced. Last year, user addresses were leaked by the wallet in plain-text on opening.

Tags: Coinomi walletCoinomi wallet vulnerabilitylost fundsSecurity bug
Previous Post

Wirex Extends Support to Include 10 New Fiat Currencies

Next Post

Best Cardano Wallets: Where to Store Your ADA

Anca Florentis

Anca Florentis

Joshua Trelawen is a veteran blockchain researcher, crypto reporter, and on-chain analyst with over 10 years of experience in digital assets and decentralized finance. As a contributor to Theccpress.com, he specializes in dissecting blockchain data, analyzing tokenomics, and uncovering DeFi and NFT market trends with precision. Joshua has advised research firms, hedge funds, and media outlets, providing actionable insights on liquidity flows, whale movements, and regulatory narratives. Backed by advanced studies in economics and certified expertise in blockchain analytics, he bridges the gap between complex on-chain data and clear, trustworthy reporting. His work embodies transparency, expertise, and authority — empowering both institutional and retail investors to make informed decisions in the evolving crypto market.

Related Posts

Bitcoin sees BIP 110 debate after 66kB image transaction

Bitcoin sees BIP-110 debate after 66kB image transaction

by Noah Carter
March 6, 2026

After a 66kB image was embedded via script paths, analysts cite how BIP-110, OP_RETURN limit, arbitrary data in Bitcoin transactions...

Bitcoin reserve plan stalls as Vancouver cites charter rules

Bitcoin reserve plan stalls as Vancouver cites charter rules

by Noah Carter
March 6, 2026

City staff say a legal review found the Vancouver Charter and B.C. rules bar crypto in reserves, halting the Vancouver...

Bitcoin 2024 halving pressures miners as EMCD pivots

Bitcoin 2024 halving pressures miners as EMCD pivots

by Noah Carter
March 6, 2026

EMCD mining pool, crypto infrastructure platform, Bitcoin halving 2024: Data shows pressure drove a pivot to wallets and yield under...

TRON TRX rises as SEC ends Sun case with 10M deal

TRON (TRX) rises as SEC ends Sun case with $10M deal

by Noah Carter
March 6, 2026

SEC drops lawsuit against Justin Sun, TRON (TRX) price bounce, settlement with prejudice; filing says Rainberry to pay $10M as...

Stablecoins face yield fight as Senate eyes March markup

Stablecoins face yield fight as Senate eyes March markup

by Noah Carter
March 6, 2026

CLARITY Act, stablecoin yield, Senate Banking Committee markup: Talks weigh yield rules and DeFi scope, with Tillis’ vote pivotal as...

Bitcoin holds as Brazil sets 2027 crypto reserve rules

Bitcoin holds as Brazil sets 2027 crypto reserve rules

by Noah Carter
March 6, 2026

New rules protect clients via audits and custody and raise costs, analysts say; daily proof of reserves, asset segregation, Brazil...

  • Terms and Conditions
  • Privacy Policy
  • Advertise
  • About Us
  • Contact Us

© 2018-2019 theccpress.com by Brantell Media.

No Result
View All Result
  • Finance & Blockchain News
  • Bitcoin News
  • Altcoin News
  • Crypto 101
  • Blockchain Event

© 2018 - 2019 theccpress.com, a Brantell Media project.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.