Bithumb announced Monday that it has released a prevention guide on fake trading app scams.
Fake app scams have evolved beyond simply copying the name and design of legitimate apps. They now operate normally at first, then introduce malicious features through updates — while using fabricated user reviews to build credibility and evading app store screening processes to reach unsuspecting users.
One of the most common attack methods involves tricking users into installing a fake app that impersonates an overseas digital asset platform, then prompting them to enter their wallet recovery seed phrase to steal their digital assets.
Other confirmed cases involve distributing fake apps that mimic official apps from domestic public institutions, then gaining access to contacts, text messages and call logs to extract personal information or remotely control the victim's device.
Bithumb advised users to download apps only through links or QR codes provided on official websites, rather than through search results or advertisements. Users should also verify that the developer name listed in the app store matches the company's official name, and treat a pattern of short, repetitive positive reviews as a potential sign of manipulation.
The company said users should suspect a malicious app infection if an app requests access to contacts, messages or call records unrelated to digital asset trading, or if battery and data usage spikes sharply after installation.
If a fake app has already been installed or launched, users should immediately cut off all network connections, including Wi-Fi and mobile data. They should then use a separate, uncompromised device to change their Bithumb password and reset two-factor authentication, and also review their API key settings and withdrawal address whitelist.
If suspicious transactions are detected on an account, users can contact Bithumb's Investor Protection Center to request an account freeze. Infected devices should be thoroughly scanned using antivirus software or, if necessary, reset to factory settings.
Depending on the type of incident, users can report hacking and malware to the Korea Internet & Security Agency's 118 Counseling Center, cyber fraud and voice phishing to the Korean National Police Agency, and financial fraud to the Financial Supervisory Service.
"Fake app scams have grown sophisticated enough to exploit the trust users place in official app stores," a Bithumb official said. "Making it a habit to verify the official source and developer name before installing any app will be the most reliable shield for protecting your valuable assets."
Meanwhile, Bithumb has designated the second Wednesday of each month as "Information Security Day" and runs regular security campaigns for customers and employees. Last month, the exchange released a guide on preventing impersonation phishing scams, urging users to stay alert to schemes in which fraudsters pose as exchanges or financial institutions to send fake links.
kyoung@heraldcorp.com