SlowMist headlines
-
Analysis | Joint Report by Japan, the US, Australia, and Germany: Job-Seeking Phishing and Laptop…
Analysis | Joint Report by Japan, the US, Australia, and Germany: Job-Seeking Phishing and Laptop Farms Operated by the North Korean Hacker Group “WaterPlum” On September 18, Japan’s National Police Agency, together with the National Cybersecurity Office, the U.S. Federal Bureau of Investigation,...
-
Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager
Background The sample comes from a development branch of the Laravel Nova extension package visanduma/nova-two-factor, associated with the PolinRider campaign. This is a PHP package published on Packagist, with more than 700,000 cumulative downloads as of the time of this analysis. The delivery...
-
Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Recently, the SlowMist security team received multiple reports of user assets being stolen. Upon verification, all of the incidents involved private key exposure, and some of the affected users had previously downloaded and used FomoPeek App versions 1.1–1.2. Through a joint analysis with the OKX...
-
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of…
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of Thin Air At 13:52:10 UTC on September 6, two transactions with the same structure appeared in Liquid block 4,050,335. One minute later, a third transaction was confirmed in block 4,050,336, bringing...
-
U.S. OFAC and DOJ Join Forces to Crack Down on Xinbi Guarantee, Restricting More Than $52 Million…
U.S. OFAC and DOJ Join Forces to Crack Down on Xinbi Guarantee, Restricting More Than $52 Million in Crypto Assets On September 9, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) and the U.S. Department of Justice (DOJ) announced coordinated enforcement actions against...
-
The Vanishing Debt — An Analysis of the Notional Finance Hack
Background On September 4, 2026, the well-known decentralized lending platform Notional Finance was attacked, resulting in approximately $1.73 million in losses. The following is a detailed analysis of this attack by the SlowMist Security Team: Prerequisite Knowledge In Notional Finance V1, fCash...
-
Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft
Background A campaign offering free VPS services was actually a decoy. A page recovered from a public web archive shows that event[.]polarnode[.]vip, registered in late August 2026, declared https[:]//lk[.]wyincc[.]com/lk.js as a preload script and automatically loaded it once the page became...
-
On-Chain Fund Source Risks Behind OKX’s Risk Control Strategy
Recently, the CEO of OKX responded to a user post about a situation where a “gambling platform directly transferred funds to an exchange, causing the deposit to trigger a review.” According to his public statement, deposits to OKX from high-risk addresses may trigger stricter anti-money laundering...
-
SlowMist: MistTrack & SlowMist KYT Partner Program Officially Launches
As crypto assets, stablecoin payments, and digital financial services continue to develop, on-chain AML, KYT, and fund risk analysis are becoming practical needs for an increasing number of institutions. To this end, MistTrack & SlowMist KYT has officially launched its Partner Program, recruiting...
-
“Gray Rhinos” and “Black Swans”: SlowMist Founder Cos on Security Risks and Protection in the…
“Gray Rhinos” and “Black Swans”: SlowMist Founder Cos on Security Risks and Protection in the Crypto World On August 28, at the Cypher Asia Intelligent Crypto Finance Summit, SlowMist Founder Cos delivered a keynote speech titled “Gray Rhinos and Black Swans in the Crypto World.” Starting from...