NEWS

Google Play Store Crypto Phishing Uncovered

A sophisticated phishing campaign has infiltrated the Google Play Store, using over 20 malicious apps to steal crypto mnemonic phrases from Android users. These fake wallet tools are designed to siphon vital credentials, leading to complete and irreversible financial loss for victims.

By
LNGFRM Team
Published June 15, 2025
Smartphone displaying a webpage connected to a network of nodes.
Illustration by Addison Smith for LNGFRM

The digital frontier of cryptocurrency, often hailed as a bastion of financial freedom, has once again been exposed as a treacherous landscape for the unwary.

A sophisticated and highly deceptive phishing campaign, unearthed by Cyble Research and Intelligence Labs (CRIL), has infiltrated the Google Play Store.

It is luring unsuspecting Android users into a trap designed to steal their most vital crypto credentials: the immutable 12-word mnemonic phrases that unlock their entire digital fortunes.

This isn’t just about losing a few dollars; it’s about a complete, irreversible financial wipeout at the hands of invisible adversaries.

CRIL’s investigation peeled back the layers of a meticulously crafted scam involving over 20 Android applications, all masquerading as legitimate cryptocurrency wallet tools.

The audacity of these operations is striking.

These apps, once downloaded, serve as digital pickpockets, quietly siphoning off the critical “seed phrases” that grant total access to a user’s crypto wallet.

For anyone caught in this net, the outcome is catastrophic: all cryptocurrency holdings vanish, with zero possibility of recovery.

In the decentralized world of crypto, your mnemonic phrase isn’t just a password; it is your bank vault, and once compromised, there’s no central authority to call for a refund or a reversal.

The technical cunning behind these malicious apps is particularly insidious.

Many were built using the Median framework, a tool that simplifies the conversion of websites into Android applications.

This seemingly innocuous method becomes a weapon in the wrong hands, allowing threat actors to embed phishing URLs directly into the app’s core code or cleverly hide them within seemingly benign privacy policy documents.

When a user interacts with these apps, these hidden links spring to life, loading deceptive login pages via a WebView.

These pages are chillingly convincing, mimicking the authentic interfaces of popular crypto services like PancakeSwap, SushiSwap, Raydium, and Hyperliquid.

Users, believing they are logging into a trusted platform, unwittingly hand over their mnemonic phrases, sealing their own financial doom.

Consider the cold reality: a fraudulent PancakeSwap app, for instance, would direct users to a URL like hxxps://pancakefentfloyd[.]cz/api.php, presenting a perfect replica of the legitimate exchange.

Similarly, a fake Raydium app would reroute to hxxps://piwalletblog[.]blog, executing the same deceit.

Despite different brandings, the underlying objective remained singular across all these variants: to extract those precious 12-word keys.

This unified approach points to a highly organized and resourced operation, not just a smattering of individual bad actors.

CRIL’s forensic analysis further solidifies this suspicion of a centralized criminal enterprise.

The IP address 94.156.177[.]209, identified as a host for these malicious pages, was found to be linked to over 50 other phishing domains.

These domains, all designed to imitate popular crypto platforms, are systematically reused across multiple apps, painting a picture of a sophisticated, well-oiled machine churning out digital traps.

Adding another layer of deception, some of these malicious apps were even published under developer accounts previously associated with legitimate software, such as gaming or streaming applications.

This cunning tactic is designed to lower user suspicion, exploiting trust built on past positive experiences and making detection a significant challenge, even for advanced mobile security tools.

The implications are profound.

In an ecosystem where self-custody is both a freedom and a burden, the onus of security falls squarely on the individual.

The fact that these apps made their way onto the Google Play Store, despite its supposed safeguards, serves as a stark reminder that even official app marketplaces are not impervious to determined cybercriminals.

This ongoing cat-and-mouse game between security researchers and threat actors highlights the constant need for vigilance in the digital age.

So, what’s a crypto holder to do in the face of such pervasive threats?

CRIL’s advice is both practical and urgent.

The golden rule: never, under any circumstances, provide your full mnemonic phrase through a login prompt within a mobile app. A legitimate wallet app will never ask for this. Learn more about cryptocurrency security best practices.

Beyond that, users must commit to downloading applications only from verified developers, scrutinizing every app for suspicious requests for sensitive information.

Employing reputable Android antivirus or endpoint protection software, coupled with ensuring Google Play Protect is enabled, adds a crucial, though not infallible, layer of defense. Find out how Google Play Protect keeps apps safe.

Strong, unique passwords, multi-factor authentication, and biometric security features should be standard practice for every digital interaction. Learn about Two-Factor Authentication (2FA) in crypto.

And finally, the age-old wisdom holds: avoid clicking on suspicious links, whether received via SMS or email, and never, ever enter sensitive information into a mobile app unless its legitimacy is absolutely, unequivocally certain.

The list of 22 compromised apps, including various iterations of Pancake Swap, Suiet Wallet, Hyperliquid, Raydium, and SushiSwap, underscores the breadth of this particular campaign.

Each name represents a potential victim, a lost fortune, and a shattered trust.

In the volatile world of cryptocurrency, where fortunes can be made or lost in an instant, the greatest threat often comes not from market fluctuations, but from the insidious, unseen hand of cybercrime.

The price of complacency, in this realm, is total ruin.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

The New AI Economy Under Abhishek Saxena

Abhishek Saxena’s work at Sentient targets the gap where open-source AI keeps losing: not capability, but economics—and his answer is infrastructure that automatically pays builders, maintainers, and evaluators every time their artifact is used, enforced by smart contracts rather than legal goodwill. By combining cryptographic fingerprinting, on-chain attribution, and grant funding with no equity attached, Sentient is building the coordination layer that would make open-source development financially rational enough to compete with a corporate salary.

By LNGFRM Team
Published August 17, 2026
© 2026 LNGFRM. All rights reserved.