Post
Topic
Board Wallet software
Re: A Non-Custodial wallet, Atomic Wallet, being compromised
by
Cricktor
on 04/06/2023, 13:34:56 UTC
It's sad news, we thought that using a non-custodial wallet is safe, in fact, there's no really safe over the internet.
Transferring their fund by importing the 12 words into other wallets like Electrum might be a good step or any wallets that support importing BIP39 seed phrases.

So IMO it would be better if Atomic wallet move their coins/token by importing recovery words to other wallet rather than opening their Atomic wallet application.


A software wallet is only as safe as the computer and OS used to run it. If the computer is compromised then malware with sufficient elevated rights can compromise the software wallet.

Importing the BIP-39 compatible recovery words of the Atomic Wallet in another wallet only makes sense if you can exclude the possibility that those recovery words or the underlying seed wasn't already compromised. Sure, if the current attack on Atomic Wallet needs some more ongoing interaction with the Atomic Wallet software, then you may gain some ground by importing it in another verified wallet that supports all your coins and tokens. Sadly, many alternatives are closed-source, too, with very few exceptions (I believe Unstoppable Wallet is multi-coin and open-source).

Even more sadly is that those closed-source wallets mostly don't offer the use of a hardware wallet with them. If implemented properly and without malicious intends that would mostly prevent a compromise of the seed and/or private keys that are secured by the hardware wallet.