Algorand
Incident posture
Timeline
Summary
A targeted attack was carried out against a group of high‑profile MyAlgo accounts whose holders kept significant funds in mnemonic wallets with keys stored in the browser and did not use hardware wallets. MyAlgo stated that it employs strong encryption and regular audits, has long advocated hardware and multisig wallets, and will cooperate with authorities to investigate the root cause while planning user‑experience changes to encourage better security practices.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Recently, a targeted attack was carried out against a group of high-profile MyAlgo accounts. MyAlgo has been in communication with the affected victims since the attack happened to identify the root cause of it. The company stated that it is working closely with authorities and will carry out a thorough investigation to determine how the breach occurred. This ongoing dialogue aims to clarify the sequence of events and the methods used by the attackers.
It appears that the attacked users all had significant funds in their accounts and were using mnemonic wallets with the key stored in the browser. None of the affected individuals were using hardware wallets to protect their assets. MyAlgo noted that private keys stored in browsers are vulnerable to malware and phishing attacks, especially on everyday devices. The firm also observed that hardware wallets are much less susceptible to these types of threats.
MyAlgo maintains that it uses state of the art encryption and undergoes security audits regularly. The platform has long advocated for the use of hardware and multisig wallets since its inception. In response to the incident, MyAlgo said it will work on changes to the user experience to help promote the implementation of best practices for fund protection. The company emphasized that the event serves as a learning opportunity and that further steps will be taken to strengthen security measures.
Sources
Sources available to members: 1 source.