Dubai Chinese takeaway app comecome exposed to major security vulnerabilities
2026-08-27 16:18:12
According to CoinMeta, it has been reported that Dubai's leading Chinese food delivery app comecome (Please Please) has been exposed to a major security vulnerability. Independent security analysis shows that this app, in its version 2.9.3 on app and store, contains malicious statistical code named “dkstatistics” which attempts to escape the sandbox when opened by users, and can read common encrypted wallets, memos, and application directories such as whatsapp in the background. On-chain data indicates that users had their USDT stolen on August 22nd, and the hacker’s collection address received approximately 1.3 million USDT in total over 4 days, which were then all exchanged for Ethereum on August 25th to be used for coin mixing and money laundering in tornado and cash. As early as February 2025, Kaspersky disclosed a data theft campaign targeting crypto users called “sparkcat” and specifically mentioned comecome. Although the app was updated to version 2.9.5 on August 27th, it remains to be verified whether the malicious components have been completely removed.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.