SubscribeBTCSCAMWallet Test
The Wire

News

Everything crossing the desk — scam alerts, threat intel, exchange watch and field guides, newest first.

The Latest
No. 1207Threat Intelcritical
How a 2021 Coldcard firmware change made Bitcoin seeds guessable

A software random-number bug weakened Coldcard seed generation for years. On July 30, 2026, attackers drained hundreds of single-sig wallets in under an hour — a firmware update alone won't fix it.

By Lena Vogt · JUL 31, 2026 · 4 min read
No. 1206Security Dispatch
How GitCafe closed a repository-hijack exploit with GitVault end-to-end encryption

GitVault encrypts every commit, branch and blob on the client before it touches a server — neutralising a whole class of repository-takeover attacks. GitCafe unveiled it at a Las Vegas meetup, then demoed it at SKINOX and across the DEFCON villages.

By Lena Vogt · NOV 12, 2025 · 6 min read
No. 1205Enforcement · Crypto mixershigh
Samourai Wallet's founders moved $2 billion in bitcoin. They're going to prison

The mixer's chief executive drew five years and its technology chief four, US prosecutors say, after both admitted knowingly moving criminal proceeds — from online fraud to a child-exploitation site — for a fee.

By Jules Renner · NOV 6, 2025 · 4 min read
No. 1204Threat intel · Fake wallet extensionshigh
Forty fake wallet extensions flooded Firefox's store, phishing seed phrases

The FoxyWallet campaign cloned MetaMask, Coinbase and Trust Wallet add-ons, padding each with hundreds of fake five-star reviews to harvest keys, Koi Security found.

By Dev Patel · JUL 2, 2025 · 4 min read
No. 1203Threat intel · Clipper malwarehigh
Clipper malware rewrites the wallet address between your copy and paste

Clipboard hijackers sit dormant for months, then replace a copied crypto address with the attacker's own. One booby-trapped GitHub campaign siphoned five Bitcoin, per Kaspersky.

By Jules Renner · FEB 24, 2025 · 4 min read
No. 1202Blind-signing attack · DeFihigh
Radiant Capital's signers approved a $50 million theft they couldn't see

Malware showed developers one transaction on screen while their hardware wallets signed another. Mandiant ties the October 2024 DeFi heist to North Korea; the protocol later wound down.

By Mara Okafor · OCT 16, 2024 · 5 min read
No. 1201Threat Intelhigh
Inferno Drainer and the rise of rent-a-scam crimeware

A phishing kit rented to affiliates for a cut of every theft faked its own retirement in 2023 — then came back bigger. The whole attack is one signature you can learn to withhold.

By Lena Vogt · FEB 15, 2024 · 4 min read
No. 1200Smart-contract exploit · Web3 gaminghigh
A stolen key let PlayDapp's attacker mint 1.8 billion tokens

The Web3 gaming platform lost about $290 million in February 2024 after an intruder made themselves an authorized minter of the PLA token and printed coins at will, per Elliptic.

By Dev Patel · FEB 9, 2024 · 4 min read
No. 1199Threat intelhigh
The $59 million ad buy: how MS Drainer rode Google and X to victims

Scam Sniffer traced 63,000 victims to fake DeFi front-ends served as paid search and social posts. The clicks were real; the destinations were counterfeits wired to a drainer kit.

By Jules Renner · DEC 21, 2023 · 4 min read
No. 1198Threat Intelhigh
One stolen npm token, a hundred poisoned dapps: inside the Ledger Connect Kit attack

In December 2023 a single compromised library loaded straight into web3 front-ends and drained roughly $600,000 across SushiSwap, Zapper and dozens more — in under two hours of active theft.

By HexDiver · DEC 16, 2023 · 4 min read
No. 1197Archive · state actorshigh
The FBI blamed North Korea's Lazarus Group for Stake.com's $41M theft

Days after a crypto casino's hot wallets were emptied in September 2023, U.S. investigators publicly named the DPRK-linked crew — a rare, fast attribution where thieves usually stay anonymous.

By HexDiver · SEP 4, 2023 · 3 min read
No. 1196Threat Intelhigh
How more than $100 million drained from Atomic Wallet

In June 2023, thousands of non-custodial wallets emptied within days. Elliptic and the FBI traced the theft to North Korea's Lazarus Group — but the way in was never confirmed.

By Lena Vogt · JUN 15, 2023 · 4 min read

NOT FINANCIAL ADVICE · VERIFY EVERYTHING