NFT EveningNFT Evening
    Facebook Twitter Instagram Reddit
    NFT Evening NFT Evening
    • NFT News
      • Collectibles
      • Crypto Art
      • Blockchain games
      • Metaverse
      • Music
      • Interviews
      • Columns
    • NFT Guides
      • Top NFT Projects
      • Top Blockchain Games
      • NFT Marketplaces and Tools
    • Learn here!
      • What is an NFT?
      • How to keep your NFTs safe
      • NFT Glossary
    • NFT Calendar
      • NFT Drops
      • NFT Conferences
      • NFT Launchpad
    • Newsletter
    NFT EveningNFT Evening
    NFT News

    Home » NFT News » Not Even Word Docs Are Safe: How Hackers Can Steal Your Seed Phrase

    Not Even Word Docs Are Safe: How Hackers Can Steal Your Seed Phrase

    By Janelle BorgJune 1, 2022Updated:September 20, 20222 Mins Read

    Thinking of saving the keys or seed phrase to your wallet on a Microsoft Word document? Think again. Crypto researchers have exposed a severe 0-day vulnerability called #Follina. This allows crypto hackers to take full control of your computer without opening any files. Here’s how.

    seed phrase crypto hackers microsoft word
    Crypto hackers are finding new ways to steal seed phrases.

    How crypto hackers are stealing seed phrases via Microsoft Word

    According to web3 security advocate @wallet_guard: “The 0-day starts with a feature in MS Word called Templates. This feature allows Word to load and execute HTML and JS from external sources. Using the Template’s HTML and Javascript the payload then runs the following Powershell command to run a service called Microsoft Support Diagnostic Tool, or MSDT.”

    While MSDT is usually used as a diagnostic tool to debug problems in your operating system, it also allows IT experts and Microsoft personnel to remotely control your computer. Although it normally requires a user to enter a password, it also has a buffer that overcomes the password requirement. Therefore, crypto hackers can easily use this buffer to gain access to your documents.

    The whole affair is a 0-click exploit, because.rtf file previews execute the malicious code simply by downloading the file and viewing it in file explorer. Therefore, any word document can be malicious without knowing.

    Why is this crucial for web3 enthusiasts?

    Since some web3 and crypto enthusiasts store their keys and seed phrases on a Word Doc, knowing about this exploit is crucial. Therefore, all files must be considered vulnerable, and everyone must take additional precautions to protect their information.

    According to @wallet_guard, web3 and crypto enthusiasts should not use Microsoft Word at this point in time, but instead, use Google Docs. In addition, they must disable MSDT and use.pdf instead of other file extensions.

    This Microsoft Word loophole is another nail in the coffin for the crypto community; especially as it has been battling Discord hackers for the last few months.

     


    All investment/financial opinions expressed by NFTevening.com are not recommendations.

    This article is educational material.

    As always, make your own research prior to making any kind of investment.

    Previous ArticleNFT Artist Pink Cat Uninvited From Toronto Comic Festival After Scandal
    Next Article Tom Sachs Rocket Factory NFT: Everything To Know
    Janelle Borg
    • Website

    Janelle is a freelance content writer with a passion for all things related to music, marketing and tech. She looks forward to bringing you more news relating to the fast-paced world of Crypto and NFTs from her home office in Brighton.

    More great NFT Evening content:

    GameStop Terminates CEO Matt Furlong Amidst NFT Expansion: What’s Next for the Retailer?

    June 8, 2023
    An illustration for the blockchain game "Life Beyond".

    Life Beyond: Journey into a Spatial Metaverse with Seasoned Video Game Veterans

    June 8, 2023
    Blend: An 82% Share of the NFT Lending Market

    The Problem with NFT Lending

    June 8, 2023

    NFC Lisbon 2023 to Announce NFT Art Prize Winner on June 7th!

    June 8, 2023
    Paris Hilton Icons Only show for Avatar holders

    Get Ready to Party: tokenproof Empowers 11 Fans to Attend Paris Hilton’s Sold-Out Show!

    June 8, 2023

    Experience Digital Fashion: Weekday and The Fabricant Introduce Artifact 001

    June 7, 2023
    A picture from British artist Robert Alice.

    Robert Alice: NFT Artist Takes on Historic La Monnaie de Paris

    June 7, 2023
    Cathie Wood is one of the headline speakers for Christie's Art + Tech Summit

    Gucci and MoonPay Join Christie’s for Art+Tech Summit at Rockefeller Center

    June 7, 2023

    NFTevening is the biggest website for NFT news. We cover; breaking news, upcoming mints, plus, interviews with top NFT artists and projects. Put simply, we are the best place for new and experienced non-fungible token fans — making content fun & accessible

    Privacy policy
    Terms and conditions

    Article Categories
    • Blockchain games
    • Collectibles
    • Columns
    • Crypto Art
    • Interviews
    • Metaverse
    • Music
    • NFT Guides
    • NFT Marketplaces and Tools
    • NFT News
    • Sponsored Content
    • Top Blockchain Games
    • Top NFT Projects
    NFT Calendar
    • Today’s NFT Drops
    • Upcoming NFT Drops
    • Solana NFT Drops
    • NFT Calendar
    • NFT Calendar : Add Your NFT Event
    Get In Touch
    • Advertise (Media Kit)
    • Job Opportunities
    • About Us
    • Contact Us
    • Newsletter
    NFT Beginners Guides
    • How to Sell NFT Art
    • How to Create NFT Art
    • How to Display NFT Art
    • How To Make Passive Income With NFTs
    • Best Crypto Wallet
    • Best NFT Coins
    • Best NFT Rarity Tools
    • What is a DAO ?
    • What Are Crypto Gas Fees ?

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version