import bcc from electrum to coinomi, Flurbos/coinomi-android
Yesterday, Reddit users reported that a serious vulnerability in Coinomi's wallet had led to the theft of $60,000 to $70,000 worth of cryptocurrencies. In response, johnwick.io intelligence from the Health Security Laboratory analyzed it. The results showed that there was a serious vulnerability in Coinomi wallets. During a user's configuration of a Coinomi wallet, when a user enters a password, the Coinomi application crawls the user's input in the password text box and sends it silently in clear text to Google's spell-checking service, a process that, if attacked by a man-in-the-middle (MitM), allows an attacker to record the password and steal digital assets from the wallet. Low-dimensional Security Labs recommends that users of Coinomi wallets pay close attention to the security of their digital assets, and that other wallet APPS check whether they have similar risks to avoid further losses to customers. Earlier, Reddit user "u/warith77" posted that a vulnerability in Coinomi's multi-currency wallet resulted in the sharing of plain text passwords with third-party servers and the theft of cryptocurrencies worth $60,000 to $70,000, but Coinomi refused to take responsibility. Subsequently, Trustnodes reported that a representative for Coinomi said that a vulnerability in Coinomi's wallet had been fixed three days earlier and that it affected only the computer version of the wallet and not the phone, and that no one had encountered the problem since the computer version was released on January 1, 2019.