Decentralized multi-chain crypto wallet BitKeep confirmed a cyberattack in which the threat actors managed to distribute fraudulent versions of its Android app with the aim of stealing users’ digital currencies.
BitKeep CEO Kevin Como described it as a large-scale hacking incident where the hackers maliciously implanted code and the altered APK led to the leak of user’s private keys thereby allowing the hacker to move funds.
According to blockchain security company PeckShield and multi-chain blockchain explorer OKLink, over $9.9 million worth of assets have been stolen so far.
BiKeep tweeted that the funds stolen are on BNB Chain, Ethereum, TRON and Polygon. More than 200 addresses on the other three chains were used in the heist, and all funds were transferred to 2 main addresses in the end.
The incident occurred on December 26, 2022, with the threat actor exploiting and hijacking version 7.2.9 of the Android app package (.APK) file hosted on its website to distribute the trojanized variant.
However, the digital break-in doesn’t impact BitKeep apps downloaded via Google Play, Apple App Store, or the Google Chrome Web Store.
As many as five different counterfeit versions of the Android app have been identified, which suggests that the apps were distributed through phishing websites. The legitimate package name is “com.bitkeep.wallet.”
BitKeep headquartered in Singapore was founded in 2018. The firm has traced the wallet address used to carry out the theft and some of the siphoned digital assets have been frozen.
Users who have downloaded the APK file for version 7.2.9 are advised to install the latest version (7.3.0) released now and transfer the funds to a newly generated wallet address.
BitKeep was breached in October also, where it disclosed another security incident targeting its BitKeep Swap service that led to losses of about $1 million.














Comments