Advertisement
Cronos Blockchain Halted After $6M Tectonic DeFi Exploit
A price manipulation attack on Tectonic’s TONIC token led to a $6M Ethereum theft from the Cronos blockchain, forcing an emergency network restart.
SafePal Data Breach Exposes 39,798 Customer Order Details
SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.
ClickFix Attacks Deliver macOS Stealer Targeting Crypto
ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.
Banking Malware, Crypto Clippers Hijack H1 2026 Payments
Gen Threat Labs details two H1 2026 campaigns: banking malware abusing compromised mailboxes and a Rust crypto clipper hijacking wallet addresses.
ClickFix Attack Deploys macOS Infostealer for Crypto Theft
The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.
Adform Script Poisoning: Crypto Wallet Swapping Attack
Adform's JavaScript was poisoned to swap crypto wallet addresses on customer sites.
Advertisement
DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft
North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.
OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps
The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.
Injective Labs npm Package Compromise Steals Crypto Keys
Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.
Injective SDK npm Compromise: Crypto Wallet Stealer Detected
A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.
Metamask Phishing Campaign Targets Secret Recovery Phrases
Threat actors are targeting Metamask users with phishing emails designed to harvest Secret Recovery Phrases, leading to the total loss of cryptocurrency assets.
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.
Zcash Orchard Pool Logic Error Enables Infinite ZEC Minting
A critical vulnerability in the Zcash Orchard privacy pool allowed attackers to bypass validation and counterfeit ZEC via zero-knowledge proof flaws.
OFAC Sanctions Nobitex: Disrupting Ransomware & Terror Finance
The U.S. Treasury sanctions Nobitex, Iran's largest crypto exchange, for facilitating terrorist financing and ransomware payments.
JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures
The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.
FBI Warns: $388M Lost to Crypto ATM Scams in 2023 – Defense Guide
The FBI reports Americans lost over $388 million to crypto ATM scams in 2023, driven by social engineering. Learn how to protect against these financial frauds.
BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware
BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.
Malicious Crypto Apps on Apple App Store Target Private Keys
Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…
Malicious Crypto Wallets Infiltrate China's Apple App Store
26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.
Grinex Crypto Exchange Suffers $13.7M Hack, Blames Intelligence
Kyrgyzstan's Grinex crypto exchange suspended operations after a $13.7M hack. The exchange attributes the breach to Western intelligence agencies, highlighting sector…
REF6598 Exploits Obsidian Plugins to Deploy PHANTOMPULSE RAT
Attackers are targeting finance and crypto sectors by abusing Obsidian plugins to deliver the PHANTOMPULSE RAT via sophisticated social engineering.