Category: cryptocurrency
-
U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors
U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran’s largest cryptocurrency exchange, for facilitating payments related to terrorist activities. […] Bill Toulas Go to bleepingcomputer
-
SHub macOS infostealer variant spoofs Apple security updates
SHub macOS infostealer variant spoofs Apple security updates A new variant of the ‘SHub’ macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. […] Bill Toulas Go to bleepingcomputer
-
China’s Apple App Store infiltrated by crypto-stealing wallet apps
China’s Apple App Store infiltrated by crypto-stealing wallet apps A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […] Bill Toulas Go to bleepingcomputer
-
British National Admits Hacking Companies and Stealing Millions in Virtual Currency
British National Admits Hacking Companies and Stealing Millions in Virtual Currency A British man has pleaded guilty in the United States to his role in a large cybercrime scheme that used SMS phishing, company network intrusions, and SIM swapping to steal at least $1 million in virtual currency from victims across the country. Tyler Robert…
-
Is “Satoshi Nakamoto” Really Adam Back?
Is “Satoshi Nakamoto” Really Adam Back? The New York Times has a long article where the author lays out an impressive array of circumstantial evidence that the inventor of Bitcoin is the cypherpunk Adam Back. I don’t know. The article is convincing, but it’s written to be convincing. I can’t remember if I ever met…
-
Grinex exchange blames “Western intelligence” for $13.7M crypto hack
Grinex exchange blames “Western intelligence” for $13.7M crypto hack Kyrgyzstan-based cryptocurrency exchange Grinex has suspended its operations after suffering a $13.7 million hack attributed to Western intelligence agencies. […] Bill Toulas Go to bleepingcomputer
-
Singer loses life savings to fake wallet downloaded from the Apple App Store
Singer loses life savings to fake wallet downloaded from the Apple App Store If you hold cryptocurrency, there’s a very simple golden rule that you should always follow. Never hand over your seed phrase. Garrett Dutton, better known as G. Love – the front man of blues-hip-hop outfit G. Love & Special Sauce – has…
-
Crypto-exchange Kraken extorted by hackers after insider breach
Crypto-exchange Kraken extorted by hackers after insider breach The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data. […] Bill Toulas Go to bleepingcomputer
-
Over 20,000 crypto fraud victims identified in international crackdown
Over 20,000 crypto fraud victims identified in international crackdown An international law enforcement action led by the U.K.’s National Crime Agency (NCA) has identified over 20,000 victims of cryptocurrency fraud across Canada, the United Kingdom, and the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
AI and cryptocurrency scams are costing Americans billions, FBI reports
AI and cryptocurrency scams are costing Americans billions, FBI reports The fraud landscape has been changed by AI and cryptocurrency in a way that should concern organisations and individuals alike. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you’re job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned…
-
Drift loses $280 million North Korean hackers seize Security Council powers
Drift loses $280 million North Korean hackers seize Security Council powers The Drift Protocol lost at least $280 million after a threat actor took control of its Security Council administrative powers in a planned, sophisticated operation. […] Bill Toulas Go to bleepingcomputer
-
Possible US Government iPhone Hacking Tool Leaked
Possible US Government iPhone Hacking Tool Leaked Wired writes (alternate source): Security researchers at Google on Tuesday released a report describing what they’re calling “Coruna,” a highly sophisticated iPhone hacking toolkit that includes five complete hacking techniques capable of bypassing all the defenses of an iPhone to silently install malware on a device when it…
-
Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished
Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 – and now sits on a fortune worth $400 million. There’s just one small problem: the access codes were tucked inside his fishing rod case,…
-
Hacker charged with stealing $53 million from Uranium crypto exchange
Hacker charged with stealing $53 million from Uranium crypto exchange U.S. prosecutors have charged a Maryland man with stealing more than $53 million after hacking the Uranium Finance crypto exchange twice and laundering the proceeds through a cryptocurrency mixer. […] Sergiu Gatlan Go to bleepingcomputer
-
New Torg Grabber infostealer malware targets 728 crypto wallets
New Torg Grabber infostealer malware targets 728 crypto wallets A new info-stealing malware called Torg Grabber is stealing sensitive data from 850 browser extensions, more than 700 of them for cryptocurrency wallets. […] Bill Toulas Go to bleepingcomputer
-
South Korean Police Accidentally Post Cryptocurrency Wallet Password
South Korean Police Accidentally Post Cryptocurrency Wallet Password An expensive mistake: Someone jumped at the opportunity to steal $4.4 million in crypto assets after South Korea’s National Tax Service exposed publicly the mnemonic recovery phrase of a seized cryptocurrency wallet. The funds were stored in a Ledger cold wallet seized in law enforcement raids at…
-
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code The AppsFlyer Web SDK was temporarily hijacked this week with malicious code used to steal cryptocurrency in a supply-chain attack. […] Bill Toulas Go to bleepingcomputer
-
Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets
Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets JFrog security researchers Guy Korolevski and Meitar Palas uncovered a sophisticated supply chain attack on the npm ecosystem on March 12, 2026, in which threat actors disguised an information-stealing malware as a legitimate Roblox script executor. The campaign, self-named Cipher stealer, used…
-
Smashing Security podcast #458: How not to steal $46 million from the US government
Smashing Security podcast #458: How not to steal $46 million from the US government A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn’t stirred since 2024 – and within minutes, giant woodpecker images are plastered across the internet’s favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized…
-
New BeatBanker Android malware poses as Starlink app to hijack devices
New BeatBanker Android malware poses as Starlink app to hijack devices A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. […] Sergiu Gatlan Go to bleepingcomputer
-
They seized $4.8m in crypto… then gave the master key to the internet
They seized $4.8m in crypto… then gave the master key to the internet South Korea’s National Tax Service (NTS) has found itself in the middle of a deeply embarrassing – and costly – blunder after accidentally handing thieves the master key to a seized cryptocurrency wallet. Read more in my article on the Hot for…
-
$4.8M in crypto stolen after Korean tax agency exposes wallet seed
$4.8M in crypto stolen after Korean tax agency exposes wallet seed South Korea’s National Tax Service accidentally exposed the mnemonic recovery phrase of a seized cryptocurrency wallet in an official press release, allowing hackers to steal 6.4 billion won ($4.8M) worth in cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
Phishing Attacks Against People Seeking Programming Jobs
Phishing Attacks Against People Seeking Programming Jobs This is new. North Korean hackers are posing as company recruiters, enticing job candidates to participate in coding challenges. When they run the code they are supposed to work on, it installs malware on their system. News article. Bruce Schneier Go to bruce schneier
-
Marquis sues SonicWall over backup breach that led to ransomware attack
Marquis sues SonicWall over backup breach that led to ransomware attack Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. […] Bill Toulas Go to bleepingcomputer
-
Fake job recruiters hide malware in developer coding challenges
Fake job recruiters hide malware in developer coding challenges A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. […] Bill Toulas Go to bleepingcomputer
-
North Korean hackers use new macOS malware in crypto-theft attacks
North Korean hackers use new macOS malware in crypto-theft attacks North Korean hackers are running tailored campaigns using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. […] Bill Toulas Go to bleepingcomputer
-
Incognito Market admin sentenced to 30 years for running $105 million dark web drug empire
Incognito Market admin sentenced to 30 years for running $105 million dark web drug empire He promised “the best security there is” to hundreds of thousands of drug buyers, while quietly making the kind of mistake that guaranteed a 30-year sentence. And maybe training police on cryptocurrency while running a running a vast Tor-hidden drug…
-
Coinbase insider who sold customer data to criminals arrested in India
Coinbase insider who sold customer data to criminals arrested in India Police in India have arrested a former Coinbase customer service agent who is believed to have been bribed by cybercriminal gangs to access sensitive customer information. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Ledger customers impacted by third-party Global-e data breach
Ledger customers impacted by third-party Global-e data breach Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e. […] Bill Toulas Go to bleepingcomputer
-
New GlassWorm malware wave targets Macs with trojanized crypto wallets
New GlassWorm malware wave targets Macs with trojanized crypto wallets A fourth wave of the “GlassWorm” campaign is targeting macOS developers with malicious VSCode/OpenVSX extensions that deliver trojanized versions of crypto wallet applications. […] Bill Toulas Go to bleepingcomputer
-
Hackers drain $3.9M from Unleash Protocol after multisig hijack
Hackers drain $3.9M from Unleash Protocol after multisig hijack The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals. […] Bill Toulas Go to bleepingcomputer
-
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts Amazon’s AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Access Management (IAM). […] Bill Toulas Go to bleepingcomputer
-
Police takes down Cryptomixer cryptocurrency mixing service
Police takes down Cryptomixer cryptocurrency mixing service Law enforcement officers from Switzerland and Germany have taken down the Cryptomixer cryptocurrency-mixing service, believed to have helped cybercriminals launder stolen funds. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious NPM packages abuse Adspect redirects to evade security
Malicious NPM packages abuse Adspect redirects to evade security Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. […] Bill Toulas Go to bleepingcomputer
-
Five plead guilty to helping North Koreans infiltrate US firms
Five plead guilty to helping North Koreans infiltrate US firms The U.S. Department of Justice announced that five individuals pleaded guilty to aiding North Korea’s illicit revenue generation schemes, including remote IT worker fraud and cryptocurrency theft. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals over $120 million from Balancer DeFi crypto protocol
Hacker steals over $120 million from Balancer DeFi crypto protocol The Balancer Protocol announced that hackers had targeted its v2 pools, with losses reportedly estimated to be more than $128 million. […] Bill Toulas Go to bleepingcomputer
-
Fake LastPass death claims used to breach password vaults
Fake LastPass death claims used to breach password vaults LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process. […] Bill Toulas Go to bleepingcomputer
-
Cryptocurrency ATMs
Cryptocurrency ATMs CNN has a great piece about how cryptocurrency ATMs are used to scam people out of their money. The fees are usurious, and they’re a common place for scammers to send victims to buy cryptocurrency for them. The companies behind the ATMs, at best, do not care about the harm they cause; the…
-
Operation Heracles strikes blow against massive network of fraudulent crypto trading sites
Operation Heracles strikes blow against massive network of fraudulent crypto trading sites In a significant crackdown against online cybercriminals, German authorities have successfully dismantled a network of fraudulent cryptocurrency investment sites that has targeted millions of unsuspecting people across Europe. Read more in my article on the Hot for Security blog. Graham Cluley Go to…
-
Verified Steam game steals streamer’s cancer treatment donations
Verified Steam game steals streamer’s cancer treatment donations A gamer seeking financial support for cancer treatment lost $32,000 after downloading from Steam a verified game named Block Blasters that drained his cryptocurrency wallet. […] Bill Toulas Go to bleepingcomputer
-
Canada dismantles TradeOgre exchange, seizes $40 million in crypto
Canada dismantles TradeOgre exchange, seizes $40 million in crypto The Royal Canadian Mounted Police has shut down the TradeOgre cryptocurrency exchange and seized more than $40 million believed to originate from criminal activities. […] Ionut Ilascu Go to bleepingcomputer
-
Hackers left empty-handed after massive NPM supply-chain attack
Hackers left empty-handed after massive NPM supply-chain attack The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it. […] Bill Toulas Go to bleepingcomputer
-
US targets North Korean IT worker army with new sanctions
US targets North Korean IT worker army with new sanctions The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned two individuals and two companies associated with North Korean IT worker schemes that operate at the expense of American organizations. […] Bill Toulas Go to bleepingcomputer
-
Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea
Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea A suspected hacker, believed to be the mastermind behind an organised campaign of attacks that stole millions of dollars worth of stocks from celebrities, including BTS singer Jung Kook, has been extradited to South Korea. Read more in my article on the Hot for…
-
Smashing Security podcast #431: How to mine millions without paying the bill
Smashing Security podcast #431: How to mine millions without paying the bill In episode 431 of the “Smashing Security” podcast, a self-proclaimed crypto-influencer calling himself CP3O thought he had found a shortcut to riches — by racking up millions in unpaid cloud bills. Meanwhile, we look at the growing threat of EDR-killer tools that can…
-
Nebraska man gets 1 year in prison for $3.5M cryptojacking scheme
Nebraska man gets 1 year in prison for $3.5M cryptojacking scheme A Nebraska man was sentenced to one year in prison for defrauding cloud computing providers of over $3.5 million to mine cryptocurrency worth nearly $1 million. […] Sergiu Gatlan Go to bleepingcomputer
-
US sanctions Grinex crypto-exchange, successor to Garantex
US sanctions Grinex crypto-exchange, successor to Garantex The U.S. Department of the Treasury has announced sanctions against Grinex, the successor to Russian cryptocurrency exchange Garantex, which was previously sanctioned for helping ransomware gangs launder their money. […] Sergiu Gatlan Go to bleepingcomputer
-
Over $300 million in cybercrime crypto seized in anti-fraud effort
Over $300 million in cybercrime crypto seized in anti-fraud effort More than $300 million worth of cryptocurrency linked to cybercrime and fraud schemes has been frozen due to two separate initiatives involving law enforcement and private companies. […] Bill Toulas Go to bleepingcomputer
-
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang The United States Department of Justice has revealed that the recent takedown of the BlackSuit ransomware gang’s servers, domains, and dark web extortion site, also saw the seizure of US $1,091,453 worth of cryptocurrency. Read more in my article on the…
-
New Koske Linux malware hides in cute panda images
New Koske Linux malware hides in cute panda images A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory. […] Bill Toulas Go to bleepingcomputer
-
SIM scammer’s sentence increased to 12 years, after failing to pay back victim $20 million
SIM scammer’s sentence increased to 12 years, after failing to pay back victim $20 million Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Bitcoin Depot breach exposes data of nearly 27,000 crypto users
Bitcoin Depot breach exposes data of nearly 27,000 crypto users Bitcoin Depot, an operator of Bitcoin ATMs, is notifying customers of a data breach incident that has exposed their sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Employee gets $920 for credentials used in $140 million bank heist
Employee gets $920 for credentials used in $140 million bank heist Hackers stole nearly $140 million from six banks in Brazil by using an employee’s credentials from C&M, a company that offers financial connectivity solutions. […] Bill Toulas Go to bleepingcomputer
-
Police dismantles investment fraud ring stealing €10 million
Police dismantles investment fraud ring stealing €10 million The Spanish police have dismantled a large-scale investment fraud operation based in the country, which has caused cumulative damages exceeding €10 million ($11.8M). […] Bill Toulas Go to bleepingcomputer
-
Malware on Google Play, Apple App Store stole your photos—and crypto
Malware on Google Play, Apple App Store stole your photos—and crypto A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices. […] Bill Toulas Go to bleepingcomputer
-
BitoPro exchange links Lazarus hackers to $11 million crypto heist
BitoPro exchange links Lazarus hackers to $11 million crypto heist The Taiwanese cryptocurrency exchange BitoPro claims the North Korean hacking group Lazarus is behind a cyberattack that led to the theft of $11,000,000 worth of cryptocurrency on May 8, 2025. […] Bill Toulas Go to bleepingcomputer
-
US recovers $225 million of crypto stolen in investment scams
US recovers $225 million of crypto stolen in investment scams The U.S. Department of Justice has seized more than $225 million in cryptocurrency linked to investment fraud and money laundering operations, the largest crypto seizure in the history of the U.S. Secret Service. […] Bill Toulas Go to bleepingcomputer
-
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto The pro-Israel “Predatory Sparrow” hacking group claims to have stolen over $90 million in cryptocurrency from Nobitex, Iran’s largest crypto exchange, and burned the funds in a politically motivated cyberattack. […] Lawrence Abrams Go to bleepingcomputer
-
North Korean hackers deepfake execs in Zoom call to spread Mac malware
North Korean hackers deepfake execs in Zoom call to spread Mac malware North Korean advanced persistent threat (APT) ‘BlueNoroff’ (aka ‘Sapphire Sleet’ or ‘TA444’) are using deepfake company executives during fake Zoom calls to trick employees into installing custom malware on their computers. […] Bill Toulas Go to bleepingcomputer
-
Coinbase breach tied to bribed TaskUs support agents in India
Coinbase breach tied to bribed TaskUs support agents in India A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals $223 million in Cetus Protocol cryptocurrency heist
Hacker steals $223 million in Cetus Protocol cryptocurrency heist The decentralized exchange Cetus Protocol announced that hackers have stolen $223 million in cryptocurrency and is offering a deal to stop all legal action if the funds are returned. […] Bill Toulas Go to bleepingcomputer
-
Israel arrests new suspect behind Nomad Bridge $190M crypto hack
Israel arrests new suspect behind Nomad Bridge $190M crypto hack An American-Israeli national named Osei Morrell has been arrested in Israel for his alleged involvement in exploiting the Nomad bridge smart-contract in August 2022 that allowed hackers to siphon $190 million. […] Bill Toulas Go to bleepingcomputer
-
US charges 12 more suspects linked to $230 million crypto theft
US charges 12 more suspects linked to $230 million crypto theft Twelve more suspects were charged in a RICO conspiracy for their alleged involvement in the theft of over $230 million in cryptocurrency and laundering the funds using crypto exchanges and mixing services. […] Sergiu Gatlan Go to bleepingcomputer
-
Smashing Security podcast #417: Hello, Pervert! – Sextortion scams and Discord disasters
Smashing Security podcast #417: Hello, Pervert! – Sextortion scams and Discord disasters Don’t get duped, doxxed, or drained! In this episode of “Smashing Security” we dive into the creepy world of sextortion scams, and investigate how crypto wallet firm Ledger’s Discord server was hijacked in an attempt to phish for cryptocurrency recovery phrases. All this…
-
Germany takes down eXch cryptocurrency exchange, seizes servers
Germany takes down eXch cryptocurrency exchange, seizes servers The Federal police in Germany (BKA) seized the server infrastructure and shut down the ‘eXch’ cryptocurrency exchange platform for alleged money laundering cybercrime proceeds. […] Bill Toulas Go to bleepingcomputer
-
Grinex exchange suspected rebrand of sanctioned Garantex crypto firm
Grinex exchange suspected rebrand of sanctioned Garantex crypto firm A new cryptocurrency exchange named Grinex is believed to be a rebrand of Garantex, a Russian cryptocurrency exchange whose domains were seized by the U.S. authorities and an admin arrested. […] Bill Toulas Go to bleepingcomputer
-
Coinbase fixes 2FA log error making people think they were hacked
Coinbase fixes 2FA log error making people think they were hacked Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
Cryptocurrency Thefts Get Physical
Cryptocurrency Thefts Get Physical Long story of a $250 million cryptocurrency theft that, in a complicated chain events, resulted in a pretty brutal kidnapping. Bruce Schneier Go to bruce schneier
-
Smashing Security podcast #414: Zoom.. just one click and your data goes boom!
Smashing Security podcast #414: Zoom.. just one click and your data goes boom! Graham explores how the Elusive Comet cybercrime gang are using a sneaky trick of stealing your cryptocurrency via an innocent-appearing Zoom call, and Carole goes under the covers to explore the extraordinary lengths bio-hacking millionaire Bryan Johnson is attempting to extend his…
-
Hackers abuse Zoom remote control feature for crypto-theft attacks
Hackers abuse Zoom remote control feature for crypto-theft attacks A hacking group dubbed ‘Elusive Comet’ targets cryptocurrency users in social engineering attacks that exploit Zoom’s remote control feature to trick users into granting them access to their machines. […] Bill Toulas Go to bleepingcomputer
-
Fake Microsoft Office add-in tools push malware via SourceForge
Fake Microsoft Office add-in tools push malware via SourceForge Threat actors are abusing SourceForge to distribute fake Microsoft add-ins that install malware on victims’ computers to both mine and steal cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
Six arrested for AI-powered investment scams that stole $20 million
Six arrested for AI-powered investment scams that stole $20 million Spain’s police arrested six individuals behind a large-scale cryptocurrency investment scam that used AI tools to generate deepfake ads featuring popular public figures to lure people. […] Bill Toulas Go to bleepingcomputer
-
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors A Florida man, linked to the notorious Scattered Spider hacking gang, has pleaded guilty to charges related to cryptocurrency thefts which have netted hundreds of thousands of dollars. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Coinbase to fix 2FA account activity entry freaking out users
Coinbase to fix 2FA account activity entry freaking out users Coinbase is fixing an incorrect account activity message that freaks out customers and makes them think their credentials were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
PoisonSeed phishing campaign behind emails with wallet seed phrases
PoisonSeed phishing campaign behind emails with wallet seed phrases A large-scale phishing campaign dubbed ‘PoisonSeed’ compromises corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets. […] Bill Toulas Go to bleepingcomputer
-
New Crocodilus malware steals Android users’ crypto wallet keys
New Crocodilus malware steals Android users’ crypto wallet keys A newly discovered Android malware dubbed Crocodilus tricks users into providing the seed phrase for the cryptocurrency wallet using a warning to back up the key to avoid losing access. […] Bill Toulas Go to bleepingcomputer
-
U.S. seized $8.2 million in crypto linked to ‘Romance Baiting’ scams
U.S. seized $8.2 million in crypto linked to ‘Romance Baiting’ scams The U.S. Department of Justice (DOJ) has seized over $8.2 million worth of USDT (Tether) cryptocurrency that was stolen via ‘romance baiting’ scams. […] Bill Toulas Go to bleepingcomputer
-
US removes sanctions against Tornado Cash crypto mixer
US removes sanctions against Tornado Cash crypto mixer The U.S. Department of Treasury announced today that it has removed sanctions against the Tornado Cash cryptocurrency mixer, which North Korean Lazarus hackers used to launder hundreds of millions stolen in multiple crypto heists. […] Sergiu Gatlan Go to bleepingcomputer
-
Mandatory Coinbase wallet migration? It’s a phishing scam!
Mandatory Coinbase wallet migration? It’s a phishing scam! An ingenious phishing scam is targeting cryptocurrency investors, by posing as a mandatory wallet migration. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Microsoft: New RAT malware used for crypto theft, reconnaissance
Microsoft: New RAT malware used for crypto theft, reconnaissance Microsoft has discovered a new remote access trojan (RAT) that employs “sophisticated techniques” to avoid detection, maintain persistence, and extract sensitive data. […] Sergiu Gatlan Go to bleepingcomputer
-
OKX suspends DEX aggregator after Lazarus hackers try to launder funds
OKX suspends DEX aggregator after Lazarus hackers try to launder funds OKX Web3 has decided to suspend its DEX aggregator services to implement security upgrades following reports of abuse by the notorious North Korean Lazarus hackers, who recently conducted a $1.5 billion crypto heist. […] Bill Toulas Go to bleepingcomputer
-
North Korean Lazarus hackers infect hundreds via npm packages
North Korean Lazarus hackers infect hundreds via npm packages Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. […] Bill Toulas Go to bleepingcomputer
-
US seizes $23 million in crypto stolen via password manager breach
US seizes $23 million in crypto stolen via password manager breach U.S. authorities have seized over $23 million in cryptocurrency linked to the theft of $150 million from a Ripple crypto wallet in January 2024. Investigators believe hackers who breached LastPass in 2022 were behind the attack. […] Sergiu Gatlan Go to bleepingcomputer
-
US seizes domain of Garantex crypto exchange used by ransomware gangs
US seizes domain of Garantex crypto exchange used by ransomware gangs The U.S. Secret Service has seized the domain of the sanctioned Russian cryptocurrency exchange Garantex in collaboration with the Department of Justice’s Criminal Division, the FBI, and Europol. […] Sergiu Gatlan Go to bleepingcomputer
-
Ethereum private key stealer on PyPI downloaded over 1,000 times
Ethereum private key stealer on PyPI downloaded over 1,000 times A malicious Python Package Index (PyPI) package named “set-utils” has been stealing Ethereum private keys through intercepted wallet creation functions and exfiltrating them via the Polygon blockchain. […] Bill Toulas Go to bleepingcomputer
-
Fake police call cryptocurrency investors to steal their funds
Fake police call cryptocurrency investors to steal their funds Have you had a phone call from police about your cryptocurrency wallet? Be on your guard – you could be about to be scammed. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
U.S. recovers $31 million stolen in 2021 Uranium Finance hack
U.S. recovers $31 million stolen in 2021 Uranium Finance hack U.S. authorities recovered $31 million in cryptocurrency stolen in 2021 cyberattacks on Uranium Finance, a Binance Smart Chain-based DeFi protocol. […] Bill Toulas Go to bleepingcomputer
-
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist FBI has confirmed that North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit on Friday in the largest crypto heist recorded until now. […] Sergiu Gatlan Go to bleepingcomputer
-
North Korean Hackers Steal $1.5B in Cryptocurrency
North Korean Hackers Steal $1.5B in Cryptocurrency It looks like a very sophisticated attack against the Dubai-based exchange Bybit: Bybit officials disclosed the theft of more than 400,000 ethereum and staked ethereum coins just hours after it occurred. The notification said the digital loot had been stored in a “Multisig Cold Wallet” when, somehow, it…
-
Fake CS2 tournament streams used to steal crypto, Steam accounts
Fake CS2 tournament streams used to steal crypto, Steam accounts Threat actors are exploiting major Counter-Strike 2 (CS2) competitions, like IEM Katowice 2025 and PGL Cluj-Napoca 2025, to defraud gamers and steal their Steam accounts and cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals record $1.46 billion from Bybit ETH cold wallet
Hacker steals record $1.46 billion from Bybit ETH cold wallet Cryptocurrency exchange Bybit revealed today that an unknown attacker stole over $1.46 billion worth of cryptocurrency from one of its ETH cold wallets. […] Sergiu Gatlan Go to bleepingcomputer
-
Smashing Security podcast #405: A crypto con exchange, and soaring ticket scams
Smashing Security podcast #405: A crypto con exchange, and soaring ticket scams From shadowy Bitcoin exchanges to Interpol’s most wanted, Alexander Vinnik was the alleged kingpin behind BTC-e, a $4bn crypto laundering empire. Learn more about him, and how he became a geopolitical pawn between the US, France, and Russia. Plus! Hear how concert-goers are…
-
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners A large-scale malware campaign dubbed “StaryDobry” has been targeting gamers worldwide with trojanized versions of cracked games such as Garry’s Mod, BeamNG.drive, and Dyson Sphere Program. […] Bill Toulas Go to bleepingcomputer
-
zkLend loses $9.5M in crypto heist, asks hacker to return 90%
zkLend loses $9.5M in crypto heist, asks hacker to return 90% Decentralized money lender zkLend suffered a breach where threat actors exploited a smart contract flaw to steal 3,600 Ethereum, worth $9.5 million at the time. […] Lawrence Abrams Go to bleepingcomputer
-
Hacker pleads guilty to SIM swap attack on US SEC X account
Hacker pleads guilty to SIM swap attack on US SEC X account Today, an Alabama man pleaded guilty to hijacking the U.S. Securities and Exchange Commission (SEC) account on X in a January 2024 SIM swapping attack. […] Sergiu Gatlan Go to bleepingcomputer