Skip to main content

Tag: blockchain

81 articles

Blockchain network operations center with large screen displaying visualization.

Cronos Restarts After $74 Million Tectonic Exploit

Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Analyst 207
Laptop screen shows a WordPress backend dashboard with a compromised website's source code on a messy desk.

MaaS Operators Combine ErrTraffic, ClickFix to Evade Endpoint Security

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Analyst 207
Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Meet Aeternum, a sneaky botnet loader that's exploiting the Polygon blockchain's smart contracts to operate with a decentralized command structure, making it a formidable and harder-to-stop threat. This innovative approach allows Aeternum to shift parts of its malware operations onto a decentralized infrastructure, giving it a unique advantage.

Analyst 207
Modern cityscape with sleek buildings and subtle tech infrastructure.

DeadLock Ransomware Leverages Blockchain to Evade Takedown

DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

Analyst 207
Technicians walk by rows of server racks and networking equipment in a modern network operations center.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities

Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Analyst 207
Cluttered home office desk with laptop, smartphone, and notebook, cityscape visible through window.

DeadLock Ransomware Exploits Polygon Smart Contracts

DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Analyst 207
Modern podium with abstract seal in background, in formal institutional setting.

US Targets Shelbit in $6bn Crypto Sanctions Crackdown

The US Treasury Department has cracked down on crypto sanctions, targeting Shelbit, a shadowy crypto conduit, and its founder Siavash Kayvanpour in a $6bn blow to Iran's financial apparatus. This move underscores the Treasury's determination to disrupt Tehran's reliance on digital assets and secret banking networks.

Analyst 207
Cryptocurrency wallet app on a smartphone screen on a clean, neutral surface.

Weak RNG in CryptoJS Library Enables $5.7 Million in Crypto Wallet Drains

A weakness in the CryptoJS library's random number generator has led to a staggering $5.7 million in cryptocurrency wallet drains, highlighting a critical vulnerability that has been lurking since 2014. This flaw has been exploited in multiple wallet apps, putting countless users at risk of financial loss.

Analyst 207
Technicians monitor a world map on a large screen in a network operations center, surrounded by rows of routers and servers.

Dysphoria Botnet Spreads to 200k Devices, Enables Global DDoS Attacks

A rapidly growing botnet called Dysphoria has infected over 200,000 devices worldwide, enabling massive global DDoS attacks. This sneaky threat uses blockchain technology to hide its tracks and evade detection.

Analyst 207
Dimly lit server room with rows of network equipment and industrial shelving.

Dysphoria IoT Botnet Evolves With Blockchain Command Centers

The Dysphoria IoT Botnet has reached a staggering 200,000 bots worldwide, with a single-day peak of 239,000 bots abroad, according to recent telemetry data from CNCERT and XLab. This massive network of compromised devices is now being controlled through sophisticated blockchain command centers.

Analyst 207
Hotel staff room with laptop on desk showing suspicious email on blurred screen.

Hackers Exploit Blockchain to Target Japan Hotels via Phishing

TrendAI Research uncovered a sneaky phishing campaign in late May 2026 that targeted hotel staff in Japan, cleverly disguising emails as guest complaints or review requests to trick employees into divulging sensitive info. The attackers stayed one step ahead, constantly updating their tactics to maximize their success.

Analyst 207
Network operations center with large map display and staff working at computer terminals.

CrowdStrike and Google Disrupt Glassworm Botnet Infrastructure

In a major win for cybersecurity, a powerful collaboration between CrowdStrike, Google, and the Shadowserver Foundation successfully dismantled the Glassworm botnet by simultaneously taking down all four of its command-and-control channels. This bold move cut off the botnet's operators from infected devices, preventing further malicious activity.

Analyst 207
Tangled fiber optic cables in a data center, disrupted and severed.

Glassworm botnet disrupted by takedown of resilient C2 infrastructure

In a major win for cybersecurity, researchers from CrowdStrike, Google, and The Shadowserver Foundation have successfully disrupted the Glassworm botnet by dismantling its complex command-and-control infrastructure. This takedown cuts off the lifelines of the threat actors, halting their campaigns that had been ongoing since October 2025.

Analyst 207
Dimly lit, abandoned cryptocurrency trading room with scattered papers and broken equipment.

Grinex Shutdown Won't Curb Russian Sanctions Evasion

The shutdown of Grinex, a Kyrgyzstan-registered cryptocurrency exchange, highlights the cat-and-mouse game of sanctions evasion, where experts warn that the ecosystem's fragmentation will only make it harder to track illicit activity. As Kaitlin Martin, a senior intelligence analyst at Chainalysis, notes, a fractured ecosystem makes it increasingly difficult to target evasive maneuvers.

Analyst 207
Vulnerable computer servers and networking equipment in a dimly lit data center.

Cyberattacks Exploit Known Flaws in Supply Chain, AI Tools

A recent cyberattack exploited weaknesses in a company's infrastructure, resulting in a staggering $290 million heist from KelpDAO, highlighting the vulnerability of supply chains to targeted attacks. The attackers manipulated key nodes to gain control and siphon off funds.

Analyst 207
Mysterious figure in shadows sits before code-filled screen, puzzle, and broken chain link fence.

Evidence Mounts Against Adam Back as Satoshi Nakamoto

The mystery of Satoshi Nakamoto's true identity continues to unravel, with mounting evidence pointing to Adam Back as the creator of Bitcoin. But even expert cryptographer Bruce Schneier remains cautious, saying simply "I don't know" if the circumstantial evidence is enough to prove it.

Analyst 207
DPRK Exploits Solana Exchange in $285 Million Heist

DPRK Exploits Solana Exchange in $285 Million Heist

In a shocking turn of events, a sophisticated social engineering operation by the DPRK culminated in a single-day heist of $285 million from Drift, a Solana-based decentralized exchange, on April 1, 2026. The attack was the result of a six-month campaign of persuasion that left users, engineers, and policymakers stunned.

Analyst 207
Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack

Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack

In a shocking turn of events, the Drift Protocol, a Solana-based decentralized exchange, was exploited for a staggering $285 million in a highly sophisticated social engineering attack involving durable nonces. This novel attack allowed malicious actors to swiftly gain control of the platform's administrative powers, resulting in a massive loss of funds.

Analyst 207
Drift Protocol Exploited for $280 Million by North Korean Hackers

Drift Protocol Exploited for $280 Million by North Korean Hackers

In a shocking and sophisticated attack, North Korean hackers seized control of the Drift Protocol's Security Council, resulting in a staggering loss of at least $280 million. This brazen exploit raises serious questions about the security of even the most trusted blockchain platforms.

Analyst 207
EtherHiding: Exclusive Risky Crypto Heist Warning

EtherHiding: Exclusive Risky Crypto Heist Warning

What if the blockchain meant to protect your funds became a hiding place for thieves? Google warns North Korea-linked hackers are using EtherHiding—embedding malware in Ethereum transactions—to siphon crypto, forcing defenders to rethink how they detect and stop attacks.

Analyst 207
EtherHiding in smart contracts: Exclusive Critical Threat

EtherHiding in smart contracts: Exclusive Critical Threat

Imagine the smart contracts you trust quietly carrying malware — researchers say a North Korean‑linked group used a new EtherHiding trick to embed and trigger malicious payloads in blockchain contracts. Defenders now need to move beyond static code checks and adopt runtime monitoring to stop these covert distribution channels before they steal funds.

Analyst 207
smart contracts Risky: Stunning Malware Supply-Chain Threat

smart contracts Risky: Stunning Malware Supply-Chain Threat

Cybercriminals are hijacking compromised WordPress sites and hiding malware distribution inside blockchain smart contracts — a tactic called EtherHiding that makes takedowns harder and spreads info-stealers like AMOS, Lumma, RADTHIEF and Vidar to Windows and macOS. Protect your site and devices now: patch WordPress, lock down plugins and admin access, and keep endpoints and authentication strong.

Analyst 207
Cryptocurrency ATMs: Risky Reality, Must-Have Alerts

Cryptocurrency ATMs: Risky Reality, Must-Have Alerts

Cryptocurrency ATMs offer quick, cash-to-crypto convenience—but their speed and perceived anonymity make them prime tools for scammers and regulatory headaches, so investors should scrutinize fees, compliance, and fraud controls before betting on the sector.

Analyst 207
North Korean hackers: Stunning $2B Crypto Heist — Alarming

North Korean hackers: Stunning $2B Crypto Heist — Alarming

Elliptic reveals North Korean-linked hackers have grabbed a record $2B in crypto this year, using smart hacks and clever laundering to dodge sanctions — a wake-up call about how quickly digital assets can be weaponized. Stronger defenses, better on-ramps and international cooperation are urgently needed to stop the next haul.

Analyst 207