Security news
-
White-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'
Galaxy Research says white-hat actors consolidated coins tied to the exploit into a fresh address tagged for a "Crypto Recovery Trust," though the funds represent just 2.8% of the total haul.
-
White Hats Move Over $4.5 in Bitcoins From Coldcard to Recovery Trust
Bitcoin Magazine White Hats Move Over $4.5 in Bitcoins From Coldcard to Recovery Trust White hats have moved bitcoin from the hacked Coldcard signing devices to a trust for would-be victims to reclaim, Galaxy Digital's Alex Thorn has said. Writing on X on Monday, Thorn said that the funds were...
-
Crypto-draining FOMO app was available on Apple store for a week
Analysts have urged iPhone users to update their IOS after crypto-stealing malware was discovered in malicious Safari browser links and the FOMO app. SlowMist's Chief Information Security Officer, Shān Zhang, encouraged his followers last Saturday to update to the latest version of IOS following...
-
White hats outrun Coldcard hackers in 52-Bitcoin evacuation
White hats secured about 40% of the Bitcoin moved in the Coldcard exploit’s second wave, transferring it to a Wyoming trust for victims.
-
Analysis | Joint Report by Japan, the US, Australia, and Germany: Job-Seeking Phishing and Laptop…
Analysis | Joint Report by Japan, the US, Australia, and Germany: Job-Seeking Phishing and Laptop Farms Operated by the North Korean Hacker Group “WaterPlum” On September 18, Japan’s National Police Agency, together with the National Cybersecurity Office, the U.S. Federal Bureau of Investigation,...
-
Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust
According to Galaxy Digital, the good guys have moved 52 BTC to an address carrying an OP_RETURN message reading "claim:cryptorecoverytrust dot com."
-
Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks
Google learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks.
-
Crypto casinos might get doxxed after Curaçao regulator hacked
Crypto casinos registered in Curaçao face having their sensitive data doxxed after the island's gambling regulator announced last week that it had been hacked. Curaçao became a magnet for online casinos thanks to its relaxed gambling laws under the Curaçao Gaming Authority (CGA). The CGA revealed...
-
$2M stolen in triple attack on Fetch.ai, NuNet, and SingularityNET
It’s been a busy weekend for one black hat who stole hundreds of millions of tokens from Fetch.ai, NuNet and SingularityNET, netting around $2.25 million of realized profits. According to a report from Bitquery, however, the nominal value of the tokens minted was several times higher at the time of...
-
Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager
Background The sample comes from a development branch of the Laravel Nova extension package visanduma/nova-two-factor, associated with the PolinRider campaign. This is a PHP package published on Packagist, with more than 700,000 cumulative downloads as of the time of this analysis. The delivery...
-
Polymarket faced $10 million fraud attempt as its CEO pushed growth over compliance concerns: WSJ
In a separate attack, hackers compromised nearly 500 users' accounts using stolen personal information, according to the report.
-
Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Recently, the SlowMist security team received multiple reports of user assets being stolen. Upon verification, all of the incidents involved private key exposure, and some of the affected users had previously downloaded and used FomoPeek App versions 1.1–1.2. Through a joint analysis with the OKX...
-
Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand
Blockchain dead drop attacks — campaigns that use public chains to hide malware instructions — increased 420% over the past 12 months, Chainalysis said, as state-linked groups came to account for roughly two-thirds of new activity in the second quarter of 2026. Chainalysis described the 420%...
-
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of…
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of Thin Air At 13:52:10 UTC on September 6, two transactions with the same structure appeared in Liquid block 4,050,335. One minute later, a third transaction was confirmed in block 4,050,336, bringing...
-
U.S. OFAC and DOJ Join Forces to Crack Down on Xinbi Guarantee, Restricting More Than $52 Million…
U.S. OFAC and DOJ Join Forces to Crack Down on Xinbi Guarantee, Restricting More Than $52 Million in Crypto Assets On September 9, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) and the U.S. Department of Justice (DOJ) announced coordinated enforcement actions against...
-
The Vanishing Debt — An Analysis of the Notional Finance Hack
Background On September 4, 2026, the well-known decentralized lending platform Notional Finance was attacked, resulting in approximately $1.73 million in losses. The following is a detailed analysis of this attack by the SlowMist Security Team: Prerequisite Knowledge In Notional Finance V1, fCash...
-
Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft
Background A campaign offering free VPS services was actually a decoy. A page recovered from a public web archive shows that event[.]polarnode[.]vip, registered in late August 2026, declared https[:]//lk[.]wyincc[.]com/lk.js as a preload script and automatically loaded it once the page became...
-
On-Chain Fund Source Risks Behind OKX’s Risk Control Strategy
Recently, the CEO of OKX responded to a user post about a situation where a “gambling platform directly transferred funds to an exchange, causing the deposit to trigger a review.” According to his public statement, deposits to OKX from high-risk addresses may trigger stricter anti-money laundering...
-
SlowMist: MistTrack & SlowMist KYT Partner Program Officially Launches
As crypto assets, stablecoin payments, and digital financial services continue to develop, on-chain AML, KYT, and fund risk analysis are becoming practical needs for an increasing number of institutions. To this end, MistTrack & SlowMist KYT has officially launched its Partner Program, recruiting...
-
“Gray Rhinos” and “Black Swans”: SlowMist Founder Cos on Security Risks and Protection in the…
“Gray Rhinos” and “Black Swans”: SlowMist Founder Cos on Security Risks and Protection in the Crypto World On August 28, at the Cypher Asia Intelligent Crypto Finance Summit, SlowMist Founder Cos delivered a keynote speech titled “Gray Rhinos and Black Swans in the Crypto World.” Starting from...