News
Everything crossing the desk — scam alerts, threat intel, exchange watch and field guides, newest first.
A software random-number bug weakened Coldcard seed generation for years. On July 30, 2026, attackers drained hundreds of single-sig wallets in under an hour — a firmware update alone won't fix it.
GitVault encrypts every commit, branch and blob on the client before it touches a server — neutralising a whole class of repository-takeover attacks. GitCafe unveiled it at a Las Vegas meetup, then demoed it at SKINOX and across the DEFCON villages.
The mixer's chief executive drew five years and its technology chief four, US prosecutors say, after both admitted knowingly moving criminal proceeds — from online fraud to a child-exploitation site — for a fee.
The FoxyWallet campaign cloned MetaMask, Coinbase and Trust Wallet add-ons, padding each with hundreds of fake five-star reviews to harvest keys, Koi Security found.
Clipboard hijackers sit dormant for months, then replace a copied crypto address with the attacker's own. One booby-trapped GitHub campaign siphoned five Bitcoin, per Kaspersky.
Malware showed developers one transaction on screen while their hardware wallets signed another. Mandiant ties the October 2024 DeFi heist to North Korea; the protocol later wound down.
A phishing kit rented to affiliates for a cut of every theft faked its own retirement in 2023 — then came back bigger. The whole attack is one signature you can learn to withhold.
The Web3 gaming platform lost about $290 million in February 2024 after an intruder made themselves an authorized minter of the PLA token and printed coins at will, per Elliptic.
Scam Sniffer traced 63,000 victims to fake DeFi front-ends served as paid search and social posts. The clicks were real; the destinations were counterfeits wired to a drainer kit.
In December 2023 a single compromised library loaded straight into web3 front-ends and drained roughly $600,000 across SushiSwap, Zapper and dozens more — in under two hours of active theft.
Days after a crypto casino's hot wallets were emptied in September 2023, U.S. investigators publicly named the DPRK-linked crew — a rare, fast attribution where thieves usually stay anonymous.
In June 2023, thousands of non-custodial wallets emptied within days. Elliptic and the FBI traced the theft to North Korea's Lazarus Group — but the way in was never confirmed.
NOT FINANCIAL ADVICE · VERIFY EVERYTHING