Tag: cryptocurrency
260 articles

Cronos Restarts After $74 Million Tectonic Exploit
Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Cosmos EVM Flaw Exploited to Drain Funds from Six Blockchains
Cosmos Labs revealed a critical flaw in the Cosmos EVM system was exploited to drain funds from six blockchains, after initially downplaying the bug's impact. The vulnerability was eventually patched on August 19, 2026, with a state-breaking update requiring coordinated network upgrades.

FBI, Australian Police Disrupt TeamPCP Cybercrime Syndicate
In a major cybercrime crackdown, the Australian Federal Police has arrested two men in Perth suburbs for their key roles in the notorious TeamPCP syndicate, seizing electronic devices and cryptocurrency-linked evidence. The FBI collaborated on the investigation, which may lead to further arrests and charges.

Manic Malware Exploits Offline Phones via Nearby Infected Devices
Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

SafePal Breach Exposes 39,798 Customer Records
Good news: SafePal's recent data breach didn't compromise wallet access or funds, but 39,798 customers had their personal info exposed, including names, emails, and shipping addresses. The breach appears to be limited, with sensitive credentials like wallet seed phrases and private keys remaining secure.

DeadLock Ransomware Exploits Polygon Smart Contracts
DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Malicious VS Code Extensions Target Crypto Wallets, API Keys
Beware: malicious VS Code extensions are targeting crypto wallets and API keys, putting cryptocurrency holders and developers at risk of having their sensitive information stolen. These sneaky extensions, including helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, start off harmless but soon morph into information stealers that siphon off valuable data.

US Targets Shelbit in $6bn Crypto Sanctions Crackdown
The US Treasury Department has cracked down on crypto sanctions, targeting Shelbit, a shadowy crypto conduit, and its founder Siavash Kayvanpour in a $6bn blow to Iran's financial apparatus. This move underscores the Treasury's determination to disrupt Tehran's reliance on digital assets and secret banking networks.

Malware Exploits ClickFix Attacks to Drain macOS Crypto Wallets
Beware: a sneaky malware called ClickFix is targeting macOS crypto wallets, slowly draining their contents into the pockets of cyber thieves. This cunning attack starts with a simple trick: victims are duped into pasting a malicious command into the Terminal app, unleashing a stealthy thief that siphons off cryptocurrency.

Crypto Thefts Surge Via Violent Physical Attacks
Criminals are targeting crypto holders with violent physical attacks, exploiting the fact that they possess wealth that can be transferred instantly and irreversibly. In the first half of 2026, these brutal tactics have resulted in $30 million in direct losses and a staggering $107 million when including attempted thefts.

Weak RNG in CryptoJS Library Enables $5.7 Million in Crypto Wallet Drains
A weakness in the CryptoJS library's random number generator has led to a staggering $5.7 million in cryptocurrency wallet drains, highlighting a critical vulnerability that has been lurking since 2014. This flaw has been exploited in multiple wallet apps, putting countless users at risk of financial loss.

Malware Exploits Ethereum Transfers to Conceal C2 Server IPs
Meet NullReceiver, a sneaky new technique that hides command-and-control server IPs within Ethereum transfers by encoding them directly into the recipient address of an empty transaction. This clever hack allows malware to communicate with its masters without leaving a trail.

COLDCARD Wallet Flaw Exploited in $88 Million Bitcoin Heist
In a shocking heist, hackers exploited a flaw in COLDCARD Wallet firmware to steal approximately $70.2 million worth of Bitcoin in a mere 41 minutes, targeting 1,196 addresses in a single wave of automated transactions. The attackers used a telltale signature - overpaying 30-75 times the median transaction fee - that pointed to their use of an automated tool.

Coldcard Hardware Wallet Flaw Enables $70 Million Bitcoin Heist
A sneaky attacker just pulled off a massive $70 million Bitcoin heist by exploiting a flaw in a popular hardware wallet, draining 1,196 addresses in a lightning-fast 41 minutes. The thief's clever move has left experts warning of a potential vulnerability in the widely-used Coldcard wallet.

Hackers Exploit Adform Script to Swap Crypto Wallet Addresses
Beware: hackers have cleverly manipulated a popular ad script to swap crypto wallet addresses, allowing them to intercept your transactions even if you double-check and recopy the address. This sneaky tactic uses a cleverly hidden code to override your wallet details in real-time.

SourTrade Malvertising Campaign Builds Malware in Browser
Meet SourTrade, a sneaky malvertising campaign that's assembling malware right in your browser - all while security tools and network logs show nothing out of the ordinary. Its operators impersonate popular trading and crypto platforms to trick victims into a stealthy malware delivery process.

BlueNoroff Phishing Kit Targets Crypto Wallets with Zoom Lures
BlueNoroff's phishing kit is a masterclass in deception, using Zoom lures and compromised industry contacts to trick victims into divulging their crypto wallet info. This sophisticated scam combines social engineering and malware to selectively target high-value victims.

North Korean Hackers Expose Web3 Pros to Sophisticated ClickFake Scams
One in three employees have admitted to using company tech for personal gain, and North Korean hackers are exploiting this vulnerability with a clever recruitment scam that can give them access to corporate funds. The sophisticated scheme, attributed to the notorious Famous Chollima group, targets Web3 and cryptocurrency pros with fake job offers on popular platforms like LinkedIn and Telegram.

OkoBot Malware Targets Crypto Wallets with 20 Payloads
Beware of OkoBot malware, a sneaky threat that's using clever tactics like fake GitHub repositories and ClickFix attacks to steal your cryptocurrency wallet secrets and sensitive data. This malicious framework is armed with over 20 payloads, making it a formidable foe in the world of cybercrime.

OkoBot Malware Targets Crypto Users Worldwide
Meet OkoBot, a sneaky malware framework that's got crypto users worldwide in its crosshairs, with over 20 malicious payloads and implants that can be assembled in different ways to wreak havoc. It spreads through clever tactics like ClickFix attacks and fake GitHub packages masquerading as legitimate software.

Ryuk Ransomware Operative Pleads Guilty in US Court
A major player behind the notorious Ryuk Ransomware gang has taken responsibility for their crimes, with Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleading guilty in a US court to conspiracy and computer fraud. As part of his plea deal, Vardanyan will pay over $1.1m in restitution for his role in the massive cyberattack that netted over $15m in bitcoin payments.

Bulgarian Money Launderer Accused of Stealing Seized Crypto
Rossen G. Iossifov, already serving 121 months for a money laundering scheme, now faces new charges for allegedly trying to steal $290,000 in government-seized cryptocurrency while behind bars. He and his co-conspirators are accused of moving the digital assets to prevent seizure, according to a federal indictment in Kentucky.

Attackers Drain $3.1 Million Using 'Ill Bloom' Crypto Wallet Flaw
A single coordinated attack exploited the Ill Bloom flaw on May 27, draining a staggering $3.1 million from 431 wallets in a single day. This shocking theft was made possible by a weak random-number generator in certain wallet software that created easily guessable recovery phrases.

DCloud Uni-App Framework Fuels 236,000 Scam Sites
Over the past two years, a staggering 236,000 scam sites have sprouted up using the DCloud Uni-App Framework, with operators continually launching sophisticated schemes to deceive victims. These sites are being used for a wide range of fraudulent activities, from fake cryptocurrency exchanges to crypto wallet drainers.