Tag: crypto
-
OpenSSL’s new alpha build speeds up post-quantum crypto
Tags: cryptoThe OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/openssl-4-1-0-alpha1-released/
-
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese…
-
‘White hat’ hackers take $47 million bounty after $320 million crypto theft
Public negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most, but not all, of what they took. First seen on therecord.media Jump to article: therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward
-
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.”The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
-
A hacker stole $340M in a crypto heist, then returned most of it
The latest heist is one of the largest thefts of cryptocurrency to date. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/08/a-hacker-stole-340m-in-a-crypto-heist-then-returned-most-of-it/
-
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
-
Liquid Network: Hacker stehlen 4.000 Bitcoin und geben 3.400 wieder zurück
Ein Hackerangriff auf eine beliebte Bitcoin-Sidechain erschüttert die Krypto-Branche. Ein Millionenvermögen wechselt unerwartet den Besitzer. First seen on golem.de Jump to article: www.golem.de/news/liquid-network-hacker-stehlen-4-000-bitcoin-und-geben-3-400-wieder-zurueck-2609-212767.html
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clearfake-webdav-infection-chain/
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clickfix-moves-into-the-browser/
-
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trezor-supply-chain-breach-impacts/
-
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
-
JSCeal Hides Crypto Malware in V8 Bytecode
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest…
-
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.The company named the four programs ProManager, WinUpdate, SoftManager, and First seen on thehackernews.com…
-
Cryptohack Roundup: US Seizes Hamas-Linked Crypto
Also: ClickFix Attack Abuses Polygon Blockchain. This week, U.S. seizes Hamas-linked funds, ClickFix attack abuses Polygon blockchain, Bithumb wins lawsuit over bitcoin credit error, software flaw exposes six Cosmos networks, Cronos restarts after Tectonic attack and Moonwell investigates $8.7 million exploit. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-us-seizes-hamas-linked-crypto-a-32734
-
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs.The vulnerabilities are as follows – CVE-2026-83548 (CVSS score: 10.0) – A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated First seen…
-
Fake Software Update Installs a Real Crypto Wallet Rigged So It Can Never Open
Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations…
-
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign prioritizes long-term interactive access over direct cryptocurrency theft, combining hidden VNC, SOCKS proxying, file management and browser-data theft in an…
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.”The injected code runs two operations against a site’s visitors: a mobile ad-fraud and…
-
JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS
A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by some vendors as WEEVILPROXY or MeadowLocust, is not delivered as readable JavaScript. Instead, operators package the final payload as a .jsc file compiled V8 bytecode executed with a bundled Node.js runtime. This approach frustrates conventional JavaScript…
-
Scammers Running Fake Cryptocurrency AML Wallet-checking Sites Hoodwink Users, Drain Wallets
Fake crypto AML checker sites are tricking users into approving malicious transactions that can drain wallets, Malwarebytes researchers warn. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/scammers-running-fake-cryptocurrency-aml-wallet-checking-sites-hoodwink-users-drain-wallets/
-
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic’s Claude Opus 5. Instead a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation. The primary lure, branded “Claude Opus 5…
-
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware, gambling redirects, ad fraud, and cryptocurrency-wallet theft. Once an operator installs one of the trojanized themes through Composer, the bundled front-end JavaScript is served to every visitor. Mobile users are selectively targeted, while iPhone…
-
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cronos-blockchain-restarts-after-74-million-tectonic-exploit/
-
Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend. First seen on therecord.media Jump to article: therecord.media/crypto-tectonic-hack-cronos
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active…
-
Cryptohack Roundup: Term Finance Hack
Also: Fraud Convictions for Profit Connect and Block Bits Capital. This week, hackers stole $8.5M from Term Finance, BounceBit to shutter blockchain after hack, Profit Connect and Block Bits Capital founders convicted in fraud cases, Roman Storm’s retrial delayed and AI use in crypto-linked crime jumped 40%. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-term-finance-hack-a-32668
-
Die Quanten-Uhr tickt: Warum Unternehmen jetzt Krypto-Agilität aufbauen sollten
Quantencomputer sind noch Zukunft das Sicherheitsrisiko nicht. Warum Unternehmen jetzt Krypto-Agilität und Post-Quantum Cryptography vorbereiten müssen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/die-quanten-uhr-tickt-warum-unternehmen-jetzt-krypto-agilitaet-aufbauen-sollten/a46277/

