<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Cryptocurrency</title><description>Cybersecurity articles tagged #Cryptocurrency on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cronos Blockchain Halted After $6M Tectonic DeFi Exploit</title><link>https://runtimerebel.com/blog/cronos-blockchain-halted-after-6m-tectonic-defi-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cronos-blockchain-halted-after-6m-tectonic-defi-exploit</guid><description>A price manipulation attack on Tectonic’s TONIC token led to a $6M Ethereum theft from the Cronos blockchain, forcing an emergency network restart.</description><pubDate>Tue, 01 Sep 2026 02:39:19 GMT</pubDate><category>Cryptocurrency</category><category>Cronos</category><category>Tectonic</category><category>DeFi</category><category>Blockchain</category></item><item><title>SafePal Data Breach Exposes 39,798 Customer Order Details</title><link>https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</link><guid isPermaLink="true">https://runtimerebel.com/blog/safepal-data-breach-exposes-39798-customer-order-details</guid><description>SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.</description><pubDate>Mon, 17 Aug 2026 00:40:25 GMT</pubDate><category>SafePal</category><category>Data Breach</category><category>Phishing</category><category>Cryptocurrency</category><category>Social Engineering</category></item><item><title>ClickFix Attacks Deliver macOS Stealer Targeting Crypto</title><link>https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</guid><description>ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.</description><pubDate>Mon, 10 Aug 2026 00:59:16 GMT</pubDate><category>macOS</category><category>Malware</category><category>Cryptocurrency</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Banking Malware, Crypto Clippers Hijack H1 2026 Payments</title><link>https://runtimerebel.com/blog/banking-malware-crypto-clippers-hijack-h1-2026-payments</link><guid isPermaLink="true">https://runtimerebel.com/blog/banking-malware-crypto-clippers-hijack-h1-2026-payments</guid><description>Gen Threat Labs details two H1 2026 campaigns: banking malware abusing compromised mailboxes and a Rust crypto clipper hijacking wallet addresses.</description><pubDate>Sun, 09 Aug 2026 00:58:21 GMT</pubDate><category>Clipboard Hijacker</category><category>Cryptocurrency</category><category>Financial Fraud</category><category>Banking Malware</category><category>GepyS</category></item><item><title>ClickFix Attack Deploys macOS Infostealer for Crypto Theft</title><link>https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</guid><description>The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.</description><pubDate>Fri, 07 Aug 2026 02:08:44 GMT</pubDate><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Cryptocurrency</category><category>Golang</category></item><item><title>Adform Script Poisoning: Crypto Wallet Swapping Attack</title><link>https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</guid><description>Adform&apos;s JavaScript was poisoned to swap crypto wallet addresses on customer sites.</description><pubDate>Sat, 01 Aug 2026 10:00:39 GMT</pubDate><category>Adform</category><category>JavaScript</category><category>Cryptocurrency</category><category>Wallet Swapping</category><category>Supply Chain Attack</category><category>Client Side Attack</category></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft</title><link>https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</guid><description>North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.</description><pubDate>Thu, 30 Jul 2026 21:11:51 GMT</pubDate><category>macOS</category><category>Lazarus Group</category><category>Malvertising</category><category>Cryptocurrency</category><category>DPRK</category></item><item><title>OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps</title><link>https://runtimerebel.com/blog/okobot-framework-injects-phishing-modules-into-ledger-and-trezor-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-injects-phishing-modules-into-ledger-and-trezor-apps</guid><description>The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.</description><pubDate>Wed, 15 Jul 2026 17:19:11 GMT</pubDate><category>OkoBot</category><category>Ledger</category><category>Trezor</category><category>Phishing</category><category>Hardware Wallet</category><category>Cryptocurrency</category></item><item><title>Injective Labs npm Package Compromise Steals Crypto Keys</title><link>https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</guid><description>Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.</description><pubDate>Fri, 10 Jul 2026 17:48:42 GMT</pubDate><category>Injective Labs</category><category>NPM</category><category>Supply Chain Attack</category><category>Cryptocurrency</category><category>Wallet Theft</category><category>Malicious Package</category><category>SDK</category></item><item><title>Injective SDK npm Compromise: Crypto Wallet Stealer Detected</title><link>https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</guid><description>A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.</description><pubDate>Fri, 10 Jul 2026 03:32:02 GMT</pubDate><category>Injective SDK</category><category>NPM</category><category>Cryptocurrency</category><category>Wallet Stealer</category><category>Supply Chain Attack</category><category>Malware</category><category>Injective Js</category></item><item><title>Metamask Phishing Campaign Targets Secret Recovery Phrases</title><link>https://runtimerebel.com/blog/metamask-phishing-campaign-targets-secret-recovery-phrases</link><guid isPermaLink="true">https://runtimerebel.com/blog/metamask-phishing-campaign-targets-secret-recovery-phrases</guid><description>Threat actors are targeting Metamask users with phishing emails designed to harvest Secret Recovery Phrases, leading to the total loss of cryptocurrency assets.</description><pubDate>Wed, 01 Jul 2026 09:23:12 GMT</pubDate><category>Metamask</category><category>Cryptocurrency</category><category>Phishing Campaign</category><category>Seed Phrase Theft</category><category>Credential Harvesting</category></item><item><title>Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets</title><link>https://runtimerebel.com/blog/silent-swap-crypto-clipper-fake-google-notes-ext-steals-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/silent-swap-crypto-clipper-fake-google-notes-ext-steals-wallets</guid><description>Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.</description><pubDate>Tue, 30 Jun 2026 16:48:05 GMT</pubDate><category>Silent Swap</category><category>Crypto Clipper</category><category>Cryptocurrency</category><category>Browser Extension</category><category>Malware</category><category>Financial Theft</category></item><item><title>Critical SimpleHelp Vulnerability Exploited for Malware Delivery</title><link>https://runtimerebel.com/blog/critical-simplehelp-vulnerability-exploited-for-malware-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-simplehelp-vulnerability-exploited-for-malware-delivery</guid><description>A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.</description><pubDate>Tue, 30 Jun 2026 09:19:14 GMT</pubDate><category>SimpleHelp</category><category>Exploitation</category><category>Malware</category><category>Credentials</category><category>SSH Keys</category><category>Cryptocurrency</category><category>Remote Support</category></item><item><title>Zcash Orchard Pool Logic Error Enables Infinite ZEC Minting</title><link>https://runtimerebel.com/blog/zcash-orchard-pool-logic-error-enables-infinite-zec-minting</link><guid isPermaLink="true">https://runtimerebel.com/blog/zcash-orchard-pool-logic-error-enables-infinite-zec-minting</guid><description>A critical vulnerability in the Zcash Orchard privacy pool allowed attackers to bypass validation and counterfeit ZEC via zero-knowledge proof flaws.</description><pubDate>Mon, 08 Jun 2026 17:14:14 GMT</pubDate><category>Zcash</category><category>Orchard Pool</category><category>Zero Knowledge Proofs</category><category>Cryptocurrency</category><category>Blockchain Security</category></item><item><title>OFAC Sanctions Nobitex: Disrupting Ransomware &amp; Terror Finance</title><link>https://runtimerebel.com/blog/ofac-sanctions-nobitex-disrupting-ransomware-terror-finance</link><guid isPermaLink="true">https://runtimerebel.com/blog/ofac-sanctions-nobitex-disrupting-ransomware-terror-finance</guid><description>The U.S. Treasury sanctions Nobitex, Iran&apos;s largest crypto exchange, for facilitating terrorist financing and ransomware payments.</description><pubDate>Wed, 03 Jun 2026 21:10:45 GMT</pubDate><category>Nobitex</category><category>OFAC</category><category>Sanctions</category><category>Cryptocurrency</category><category>Ransomware</category><category>Iran</category><category>Terrorist Financing</category></item><item><title>JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures</title><link>https://runtimerebel.com/blog/jinx-0164-targets-crypto-firms-with-macos-malware-and-fake-lures</link><guid isPermaLink="true">https://runtimerebel.com/blog/jinx-0164-targets-crypto-firms-with-macos-malware-and-fake-lures</guid><description>The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.</description><pubDate>Thu, 28 May 2026 09:22:52 GMT</pubDate><category>JINX 0164</category><category>macOS</category><category>Cryptocurrency</category><category>CI CD</category><category>Social Engineering</category></item><item><title>FBI Warns: $388M Lost to Crypto ATM Scams in 2023 – Defense Guide</title><link>https://runtimerebel.com/blog/fbi-warns-388m-lost-to-crypto-atm-scams-in-2023-defense-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-388m-lost-to-crypto-atm-scams-in-2023-defense-guide</guid><description>The FBI reports Americans lost over $388 million to crypto ATM scams in 2023, driven by social engineering. Learn how to protect against these financial frauds.</description><pubDate>Tue, 19 May 2026 20:41:06 GMT</pubDate><category>Crypto ATM</category><category>Scams</category><category>Social Engineering</category><category>FBI</category><category>Financial Fraud</category><category>Cryptocurrency</category><category>Consumer Protection</category></item><item><title>BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware</title><link>https://runtimerebel.com/blog/bluenoroff-exploits-fake-zoom-meetings-to-deploy-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-exploits-fake-zoom-meetings-to-deploy-macos-malware</guid><description>BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.</description><pubDate>Wed, 29 Apr 2026 08:53:57 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Hidden Risk</category><category>macOS Malware</category><category>Cryptocurrency</category></item><item><title>26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis</title><link>https://runtimerebel.com/blog/26-fakewallet-apps-infiltrate-apple-app-store-research-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/26-fakewallet-apps-infiltrate-apple-app-store-research-analysis</guid><description>Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.</description><pubDate>Fri, 24 Apr 2026 12:32:02 GMT</pubDate><category>Apple App Store</category><category>FakeWallet</category><category>Cryptocurrency</category><category>Phishing</category><category>iOS Security</category><category>Seed Phrase Theft</category></item><item><title>Malicious Crypto Apps on Apple App Store Target Private Keys</title><link>https://runtimerebel.com/blog/malicious-crypto-apps-on-apple-app-store-target-private-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-crypto-apps-on-apple-app-store-target-private-keys</guid><description>Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users&apos; recovery phrases and private keys, leading to…</description><pubDate>Tue, 21 Apr 2026 20:25:52 GMT</pubDate><category>Cryptocurrency</category><category>Malware</category><category>Phishing</category><category>Apple App Store</category><category>Mobile Security</category><category>Private Keys</category><category>Recovery Phrases</category></item><item><title>Malicious Crypto Wallets Infiltrate China&apos;s Apple App Store</title><link>https://runtimerebel.com/blog/malicious-crypto-wallets-infiltrate-china-s-apple-app-store</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-crypto-wallets-infiltrate-china-s-apple-app-store</guid><description>26 fake cryptocurrency wallet apps infiltrated China&apos;s Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.</description><pubDate>Tue, 21 Apr 2026 00:45:03 GMT</pubDate><category>Cryptocurrency</category><category>Malware</category><category>iOS</category><category>Apple App Store</category><category>Wallet</category><category>Seed Phrase Theft</category><category>China</category><category>Supply Chain Attack</category></item><item><title>Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack</title><link>https://runtimerebel.com/blog/grinex-exchange-shuts-down-after-13-74m-state-sponsored-hack</link><guid isPermaLink="true">https://runtimerebel.com/blog/grinex-exchange-shuts-down-after-13-74m-state-sponsored-hack</guid><description>Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.</description><pubDate>Sat, 18 Apr 2026 12:18:02 GMT</pubDate><category>Grinex</category><category>Cryptocurrency</category><category>State Sponsored</category><category>Sanctions</category><category>Financial Cybercrime</category></item><item><title>Grinex Crypto Exchange Suffers $13.7M Hack, Blames Intelligence</title><link>https://runtimerebel.com/blog/grinex-crypto-exchange-suffers-13-7m-hack-blames-intelligence</link><guid isPermaLink="true">https://runtimerebel.com/blog/grinex-crypto-exchange-suffers-13-7m-hack-blames-intelligence</guid><description>Kyrgyzstan&apos;s Grinex crypto exchange suspended operations after a $13.7M hack. The exchange attributes the breach to Western intelligence agencies, highlighting sector…</description><pubDate>Sat, 18 Apr 2026 00:40:22 GMT</pubDate><category>Grinex</category><category>Cryptocurrency</category><category>Cyberattack</category><category>Financial Sector</category><category>Intelligence Claims</category><category>Breach</category></item><item><title>REF6598 Exploits Obsidian Plugins to Deploy PHANTOMPULSE RAT</title><link>https://runtimerebel.com/blog/ref6598-exploits-obsidian-plugins-to-deploy-phantompulse-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/ref6598-exploits-obsidian-plugins-to-deploy-phantompulse-rat</guid><description>Attackers are targeting finance and crypto sectors by abusing Obsidian plugins to deliver the PHANTOMPULSE RAT via sophisticated social engineering.</description><pubDate>Thu, 16 Apr 2026 12:31:23 GMT</pubDate><category>REF6598</category><category>PHANTOMPULSE</category><category>Obsidian</category><category>Finance</category><category>Cryptocurrency</category></item><item><title>CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets</title><link>https://runtimerebel.com/blog/cve-2024-21390-engagelab-sdk-vulnerability-risks-android-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21390-engagelab-sdk-vulnerability-risks-android-crypto-wallets</guid><description>Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.</description><pubDate>Fri, 10 Apr 2026 08:39:29 GMT</pubDate><category>CVE-2024-21390</category><category>Android</category><category>EngageLab</category><category>Cryptocurrency</category><category>SDK Vulnerability</category></item><item><title>Bitcoin Depot Breach: $3.6M Exfiltrated from Crypto Wallet Systems</title><link>https://runtimerebel.com/blog/bitcoin-depot-breach-3-6m-exfiltrated-from-crypto-wallet-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitcoin-depot-breach-3-6m-exfiltrated-from-crypto-wallet-systems</guid><description>Bitcoin Depot reports a $3.6 million theft following a breach of internal systems. Analyze the impact and learn how to mitigate cryptocurrency ATM breaches.</description><pubDate>Thu, 09 Apr 2026 08:38:23 GMT</pubDate><category>Bitcoin Depot</category><category>Cryptocurrency</category><category>Wallet Security</category><category>Financial Theft</category><category>Sec Filing</category></item><item><title>Drift Protocol Hacked for $285M via Durable Nonce Attack</title><link>https://runtimerebel.com/blog/drift-protocol-hacked-for-285m-via-durable-nonce-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/drift-protocol-hacked-for-285m-via-durable-nonce-attack</guid><description>Solana-based DEX Drift Protocol lost $285 million due to a social engineering and durable nonce attack, leading to Security Council takeover.</description><pubDate>Fri, 03 Apr 2026 12:21:37 GMT</pubDate><category>Drift Protocol</category><category>Solana</category><category>Durable Nonce</category><category>Social Engineering</category><category>DPRK</category><category>Cryptocurrency</category><category>DeFi</category></item><item><title>Drift Protocol Compromise: Admin Control Seized, $280M Lost</title><link>https://runtimerebel.com/blog/drift-protocol-compromise-admin-control-seized-280m-lost</link><guid isPermaLink="true">https://runtimerebel.com/blog/drift-protocol-compromise-admin-control-seized-280m-lost</guid><description>Analysis of the Drift Protocol incident where a threat actor seized Security Council powers, leading to a $280 million loss. Learn about the attack vector and mitigation.</description><pubDate>Thu, 02 Apr 2026 20:15:38 GMT</pubDate><category>Drift Protocol</category><category>Cryptocurrency</category><category>DeFi</category><category>Administrative Control</category><category>Security Council</category><category>Financial Loss</category><category>Access Control</category></item><item><title>Torg Grabber Infostealer: Threat to 728 Crypto Wallets</title><link>https://runtimerebel.com/blog/torg-grabber-infostealer-threat-to-728-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/torg-grabber-infostealer-threat-to-728-crypto-wallets</guid><description>Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.</description><pubDate>Wed, 25 Mar 2026 20:17:25 GMT</pubDate><category>Torg Grabber</category><category>Infostealer</category><category>Cryptocurrency</category><category>Wallets</category><category>Browser Extensions</category><category>Data Exfiltration</category></item><item><title>Bitrefill Attributes Cyberattack to North Korean Lazarus Group</title><link>https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</guid><description>Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.</description><pubDate>Thu, 19 Mar 2026 20:16:23 GMT</pubDate><category>Lazarus Group</category><category>BlueNoroff</category><category>Bitrefill</category><category>Cryptocurrency</category><category>APT</category><category>North Korea</category></item><item><title>UNC4899 Exploits AirDrop for Crypto Firm Breach — Analysis</title><link>https://runtimerebel.com/blog/unc4899-exploits-airdrop-for-crypto-firm-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc4899-exploits-airdrop-for-crypto-firm-breach-analysis</guid><description>UNC4899 breached a crypto firm using AirDrop to bypass network security. This analysis explores the TTPs of North Korean threat actors in 2025.</description><pubDate>Mon, 09 Mar 2026 16:30:09 GMT</pubDate><category>UNC4899</category><category>Jade Sleet</category><category>macOS Security</category><category>AirDrop</category><category>North Korea</category><category>Cryptocurrency</category></item><item><title>FBI Arrests Suspect in $46M US Marshals Crypto Theft</title><link>https://runtimerebel.com/blog/fbi-arrests-suspect-in-46m-us-marshals-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-arrests-suspect-in-46m-us-marshals-crypto-theft</guid><description>A suspect linked to the theft of $46 million in cryptocurrency from the U.S. Marshals Service has been arrested.</description><pubDate>Thu, 05 Mar 2026 20:16:44 GMT</pubDate><category>Cryptocurrency</category><category>Theft</category><category>US Marshals Service</category><category>Government</category><category>Cybercrime</category><category>FBI</category></item><item><title>QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware</title><link>https://runtimerebel.com/blog/quicklens-chrome-extension-hijacked-to-deploy-clickfix-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/quicklens-chrome-extension-hijacked-to-deploy-clickfix-malware</guid><description>Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.</description><pubDate>Sat, 28 Feb 2026 20:09:10 GMT</pubDate><category>QuickLens</category><category>ClickFix</category><category>Chrome Extension</category><category>Credential Theft</category><category>Cryptocurrency</category></item><item><title>Korean Tax Agency Leak Leads to $4.8M Cryptocurrency Theft</title><link>https://runtimerebel.com/blog/korean-tax-agency-leak-leads-to-4-8m-cryptocurrency-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/korean-tax-agency-leak-leads-to-4-8m-cryptocurrency-theft</guid><description>South Korea&apos;s National Tax Service accidentally leaked a wallet&apos;s mnemonic seed phrase in a press release, allowing hackers to drain $4.8 million.</description><pubDate>Sat, 28 Feb 2026 16:08:53 GMT</pubDate><category>South Korea</category><category>National Tax Service</category><category>Cryptocurrency</category><category>Mnemonic Phrase</category><category>Operational Security</category><category>OPSEC</category></item><item><title>Fake Recruiters Deploy Malware via Malicious Coding Challenges</title><link>https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</guid><description>North Korean threat actors are targeting software developers with fake job offers and malicious coding tests to deploy malware on developer workstations.</description><pubDate>Fri, 27 Feb 2026 12:18:39 GMT</pubDate><category>Lazarus Group</category><category>North Korea</category><category>Social Engineering</category><category>Malicious Coding Challenges</category><category>Cryptocurrency</category><category>Trojanized Software</category></item></channel></rss>