Airdrop Farmers Beware! Your Fingerprint Browser Might Be Under Attack! MoreLogin Hacking Incident

2026-03-24 89 0


Summary

On March 17, SlowMist founder Cos issued an urgent alert on X platform: a mass hacking incident was ongoing. In subsequent posts, he mentioned a hacker address 0x913e…ef had already obtained over $200,000 in assets, with the amount still increasing, involving funds across multiple public chains.

On March 17, SlowMist founder Cos issued an urgent alert on X platform: a mass hacking incident was ongoing. In subsequent posts, he mentioned a hacker address 0x913e…ef had already obtained over $200,000 in assets, with the amount still increasing, involving funds across multiple public chains.

Cos specifically noted that if you are using MoreLogin fingerprint browser, be vigilant, but also clarified that there is currently no evidence that the problem is caused by MoreLogin itself or its plugins.

![](http://img.528btc.com.cn/pro/2026-03-18/img/1773815210194bj2jaj983359281a95j82h8158a78292.png)

From community feedback, this group mainly consists of airdrop farmers/players, whose private keys/seed phrases were collected in advance by hackers.

Many users shared their situations on X; some lost thousands of dollars, and others mentioned that wallet assets in over 20 environments were transferred out one after another on the evening of the 17th. Last year, AdsPower fingerprint browser also experienced a similar batch coin theft incident, causing many users to switch to MoreLogin. Now a similar situation has occurred again, raising concerns.

![](http://img.528btc.com.cn/pro/2026-03-18/img/1773815219069j5jj84j6h69ab18914341960a44bb54a.png)

Cos's post directly provided the hacker address and stated that funds were being consolidated. According to public reports, the hacker transferred assets through multi-chain operations, involving activities on Ethereum, BNB Chain, and other chains. Community feedback shows that victims are mostly players who batch operate wallets, often using fingerprint browsers to run multiple OKX wallets or MetaMask plugins simultaneously.

The official MoreLogin account @MoreloginCN quickly responded: "Today, we have received reports from users about wallet theft. We take this very seriously and have launched a comprehensive investigation immediately. The MoreLogin fingerprint browser itself does not provide plugin downloads, enables plugin protection by default, and all plugin-related data is encrypted and stored locally on the user's device, strictly ensuring user asset and data security from a technical perspective. We will continue to follow up on the investigation progress and update the community with results in a timely manner."

This response emphasizes the browser's localized design: data is not transmitted over the network, and plugin protection is enabled by default. However, some users still question, **If local encryption is so strict, why were private keys collected?**

To understand the risks, we first need to know the role of fingerprint browsers in the crypto ecosystem.

They can fake Canvas fingerprints, WebGL information, fonts, and hardware parameters to create multiple virtual devices. This allows users to run multiple wallet environments on the same computer without being detected as multi-account operations by project parties. This is very useful for those participating in Layer2 airdrops, meme coin trading, or task farming, saving time and reducing the risk of account bans. Tools like MoreLogin have become popular, especially during active periods.

![](http://img.528btc.com.cn/pro/2026-03-18/img/17738154656829c8xa7a69x8x6j71515514c9xh725502.png)

However, wallet plugins run in the browser environment, and private keys are theoretically stored locally, but if there are vulnerabilities in the update process, plugin loading, or system, hackers may inject code in advance to collect information.

Cos emphasized that there is currently no direct evidence pointing to MoreLogin, which is important. The problem may stem from third-party plugins installed by users, computer security issues, or data cross-contamination between different environments. Wallet plugin leaks are not uncommon in Web3, and the risk of private key export has always existed.

In addition, many airdrop farmers keep hot wallets in fingerprint browsers for a long time and do not transfer funds elsewhere immediately after use; or to save fees, they reuse seed phrases across multiple environments; some even operate on public networks. These practices combined with third-party tools increase risks.

![](http://img.528btc.com.cn/pro/2026-03-18/img/1773815476534405269hcb18caxj33hh6h9haxc53xa79.jpeg)

If you are using a fingerprint browser, take action immediately: check wallet balances in all fingerprint environments, transfer funds to mobile wallets or hardware devices as soon as possible; do not store seed phrases in the browser for a long time; only use official channels to update systems and browsers; form the habit of transferring funds immediately after operations.

MoreLogin official is investigating, and the community is waiting for results. Regardless of the final conclusion, personal vigilance is always the most important protection.

At the end of the day, what are we pursuing in Web3? Financial freedom, class leapfrogging. But remember one sentence: **In the crypto world, your ownership of assets depends solely on your ability to protect your private keys.**

If you sacrifice vigilance over underlying security for the convenience of "multi-opening," you are not investing; you are gambling. And in this gamble, the hacker holds your trump card.

The lesson from this incident is not just about switching tools. It reminds us: **In this era of rapidly changing technology and deep integration of AI and Web3, all "shortcuts" come at a cost.**

Fingerprint browsers are still useful; they can help you improve efficiency, but they are not worthy of keeping your entire assets. Opportunities for wealth will always exist—airdrops, Meme, Layer3, Layer4... plenty of projects—but you only have one principal.

**Security first, wealth second**—this is the real Web3 veteran.

Last updated on 2026-06-15 17:15:24

Related Posts

2026 LinkedIn Multi-Account Management Guide: Compliance, Anti-Association, a...
Amazon Multi-Store Anti-Association Practical Guide: From Risk Control Logic ...
Facebook Multi-Account Anti-Association Guide: How to Build Independent Envir...
TikTok Multi-Account Management Guide: From Official Risk Control Updates to ...
Technical Analysis of Cross-Border E-commerce Fingerprint Browser and Practic...
2026 Multi-Account Management Browser Selection Guide: Practical Compliance O...