吴说区块链|Aug 27, 2026 08:22
According to WuShuo, the leading Chinese food delivery app in Dubai, ComeCome (拜托拜托), has been exposed for a major security vulnerability. Independent security analysis reveals that the app’s version 2.9.3 on the App Store contains malicious tracking code named 'DKStatistics,' which attempts to escape the iOS sandbox when users open the app. It can access directories of common crypto wallets, notes, and apps like WhatsApp in the background. On-chain data shows that over 50,000 USDT was stolen from users on August 22, with the hacker’s collection address receiving approximately 1.3 million USDT in stolen funds within four days. By August 25, all the funds were converted to Ethereum and laundered through Tornado Cash. Back in February 2025, Kaspersky had flagged ComeCome during its disclosure of the crypto-targeting espionage campaign 'SparkCat.' Although the app was updated to version 2.9.5 on August 27, whether the malicious components have been completely removed remains to be verified. https://www.(wublock123.com)/news/news-67300
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink