iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Not every Snap is compromised, but a January 2026 report describes a serious publisher-account weakness: scammers allegedly reclaimed expired publisher domains, recovered linked email accounts, reset Snap Store credentials and uploaded malicious revisions to established applications. That means an older, popular Snap is not automatically safe—especially when it handles cryptocurrency wallet credentials.
What was reported on 17 January 2026?
Alan Pope, a former Canonical engineering manager, community manager and developer advocate, described a campaign targeting Snap publishers. The reported sequence was:
- Scammers registered expired domains previously associated with Snap publishers.
- They recovered email accounts linked to those domains.
- They triggered password resets for Snap Store accounts.
- They used the recovered publisher accounts to push malicious revisions to applications with an existing history.
Pope identified storewise.tech and vagueentertainment.com as domains involved in recent takeovers. He warned that a Snap installed three years ago from a publisher that looked reputable could later receive a malicious update.
Recommended Free Tools
"The scammers swoop in, register the expired domain, trigger a password reset on the Snap Store account, and boom – they now control a legitimate, trusted publisher account with an established history."
#1 Best Overall
Alan Pope, January 2026
The report concerns control of publisher identities and account recovery. It is not evidence that every package in the Snap Store is malicious.
Why an established publisher can still be dangerous
Users commonly treat an application’s age, download history and familiar publisher name as trust signals. Those signals describe the account’s past, not necessarily who controls it today. If an attacker takes over the account, a new revision can arrive through the same listing that users previously trusted.
Rank #2
That is why checking only the application name, icon, ratings or installation date is insufficient. The relevant question is whether the current publisher account and release can be independently tied to the software vendor.
Free tools Windows power users keep installed
One-click scans. No signup required.
What the fake wallet Snaps did
Impersonated wallet brands
The reported campaign focused on cryptocurrency-wallet applications and updates impersonating Exodus, Ledger Live and Trust Wallet. The material does not establish that those companies’ official software or corporate systems were breached; it describes malicious Snap listings using their names.
Rank #3
Recovery-phrase theft
The apps asked users for wallet recovery phrases, transmitted those phrases to criminals, displayed an error and left the associated wallets exposed. A recovery phrase can provide the control needed to move assets, making this a higher-consequence attack than ordinary adware or nuisance software.
How large is the known exposure?
| Question | What is established |
|---|---|
| How many published Snaps were in the surrounding ecosystem? | More than 7,000 publicly published Snaps from hundreds of developers, according to Pope’s January 2026 count. It was his count, not an independently audited Canonical statistic. |
| How many Snaps were compromised? | No verified total is published for this expired-domain campaign. |
| How many users or how much money was lost? | No verified total of affected users or stolen funds is published. |
| Has Canonical completed specific remediation? | The available account describes the allegation and proposed safeguards, but does not establish a completed Canonical remediation program. |
The 7,000-plus figure should not be read as 7,000 malicious packages. It indicates the scale of the publisher population that could contain dormant or abandoned accounts, not the number proven to be taken over.
Rank #4
What this means when deciding whether to use the Snap Store
The Snap Store remains a software distribution channel, but this incident shows why publisher identity and account recovery deserve the same scrutiny as package contents. Use a risk-based approach rather than treating the store as uniformly safe or uniformly unsafe.
| Signal | What it can tell you | What it cannot prove |
|---|---|---|
| Old listing, reviews or download history | The account and package have existed for some time. | That the current publisher still controls the account. |
| Publisher name matching a well-known product | The listing is using that identity. | That the listing is authorized by the real vendor. |
| Link from the vendor’s official website | A stronger route to the vendor’s intended Linux distribution method. | That every similarly named listing elsewhere is genuine. |
| Two-factor authentication on a publisher account | Additional protection against password-only takeover. | That the account or recovery process is risk-free. |
How to verify a Snap publisher before installing
- Start with the vendor. Visit the product maker’s official website and follow its Linux installation instructions. Do not begin with a store search for a high-value wallet and assume the first matching result is official.
- Match the identity exactly. Compare the package name, publisher name, website and support contact with the vendor’s own documentation. A familiar brand name by itself is not authorization.
- Check the domain carefully. Treat a recently changed, expired-looking or unrelated publisher domain as a warning. The reported attack depended on control of domains tied to publisher email accounts.
- Look for an independent release trail. Compare the version and release information with the vendor’s official announcements or documentation. A listing that cannot be corroborated outside the store deserves extra caution.
- Never surrender a recovery phrase to an unexpected prompt. If an update, support message or error screen suddenly asks for the phrase, stop using the application. If you are intentionally restoring a wallet, first verify the software and instructions through the vendor’s official channel.
- Do not rely on a hardware wallet alone. A hardware device may protect keys in some setups, but it does not prove that the desktop application came from the genuine publisher or that the store account was not taken over.
What to do if you entered a recovery phrase
- Assume the phrase is exposed and stop entering further information into the application.
- Using a separately trusted device and wallet application obtained through a verified vendor channel, create a new wallet and move remaining assets as quickly as practical.
- Do not reuse the exposed phrase. Treat it as permanently compromised, even if the application later appears to work.
- Preserve the package name, publisher details, version and screenshots, then report the listing to the store operator and the wallet vendor.
Speed matters because anyone holding the phrase may be able to move funds without further interaction from the victim.
Best Value
Which safeguards would address the weakness?
Pope proposed three controls: monitoring for publisher-domain expiry, stronger checks on dormant publisher accounts and mandatory two-factor authentication. These measures target the account-recovery path that the report describes; they are proposals attributed to Pope, not confirmation that Canonical has implemented each one.
Canonical’s terms place account-security responsibility on account holders and state that Snap Store use is at the user’s sole risk. That allocation does not tell a user whether a particular publisher is genuine, so independent verification remains important for sensitive software.
Do not confuse this report with CVE-2026-15226
A separate 2026 issue identified as CVE-2026-15226 concerns snap-confine and sandbox confinement. It is a vulnerability in the confinement component, not the publisher-account takeover described above. The two issues require different mitigations and should not be treated as one incident.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Bottom line
Linux users are not facing proof that all Snaps are unsafe, but the reported expired-domain campaign demonstrates a credible way for a trusted-looking publisher account to deliver malicious updates. Treat cryptocurrency-wallet Snaps as high risk: obtain them through a vendor-verified path, confirm the current publisher identity and never provide a recovery phrase to an unexpected application prompt.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

