Malicious code implanted in the wallet to upload mnemonic phrases and private keys has previously appeared in the Huobi wallet, and now it is in the iToken wallet. Relatively speaking, open-source wallets are somewhat safer, as all the code is on GitHub and there is a record of code uploads, making it easier to investigate. You can try the completely open-source wallet SafeWallet, with the code available at github.com/SAFE-anwang, and it can be downloaded from anwang.com.