Posts

Showing posts with the label hack

New Cryptocurrency Releases, Listings, & Presales Today – Metadrip, RELIGN, GENEX

Image
Bybit exchange suffered a devastating $1.5 billion hack, triggering massive outflows and impacting new crypto listings . The hack, attributed to North Korea’s Lazarus Group, drained seventy percent of client Ethereum holdings. The incident sparked widespread panic, causing total exchange assets to plummet by $5.5 billion. The exchange struggled to process withdrawals while Safe temporarily shut down its smart wallet functionality. Bybit’s team worked overnight to manually verify signatures and move three billion in stablecoins. Market confidence wavered as users rushed to withdraw funds, creating significant pressure on exchange reserves. New Cryptocurrency Releases, Listings, & Presales Today Metadrip integrates AI with automated trading, providing real-time insights and personalized strategies for investors. RELIGN advances artificial intelligence with reinforcement learning, optimizing problem-solving in gaming, software, and research. GENEX secures genetic data on...

US prosecutors urge judge to hand Bitfinex hack mastermind five-year sentence

The Bitfinex crypto hack resulted in the theft of 120,000 Bitcoin Ilya Lichtenstein used a series of sophisticated methods to hide the stolen funds between 2016 and 2022 He told his wife and co-conspirator about the hack in 2020 who then helped him to hide the stolen assets US prosecutors have told a judge that the mastermind behind the Bitfinex exchange hack should receive five years in prison. Ilya Lichtenstein, who pleaded guilty last year after stealing 120,000 Bitcoin, was arrested in 2022. His wife and co-conspirator Heather Morgan was also taken into custody, in connection to the 2016 Bitfinex crypto hack. During their arrest, police seized Bitcoin worth around $71 million at the time of the hack. According to Bloomberg, a court filing was submitted to the US District Court of Columbia, US prosecutors say Lichtenstein should receive a longer sentence than Morgan, also known as rapper Razzlekhan. Last week, federal prosecutors recommended that Morgan...

Chelsea FC sponsor BingX tried to hide $40M hack behind ‘wallet maintenance’

BingX, a Singapore-based crypto exchange, has lost a total of almost $45 million in assorted cryptocurrencies after its hot wallets were drained across 11 chains. News of the attack, which began shortly after 10pm UTC on Thursday, spread via X (formerly Twitter) with both security audit firm Peckshield and crypto commentator MartyParty remarking on the suspicious outflows. BingX did not initially confirm the loss; instead, it informed users of “Temporary Wallet Maintenance” via a post on X. The accompanying article makes no mention of a security incident, either, simply telling users to “ deposit or withdraw later .” [️ Temporary Wallet Maintenance Notice] ■ Schedule: ~24 hours ■ When maintenance is done, we will announce it through a notice. We sincerely apologize for any inconvenience this may cause and appreciate your patience. Learn more: https://t.co/Tx8PE6H76Q — BingX (@BingXOfficial) September 20, 2024 Read more: DeFi app Delta Prime loses $6M after being warned of L...

Kylian Mbappé’s X Account Hacked: Millions Lost in Crypto Scam

Image
Source: Crypto.com On August 29, 2024, a significant cryptocurrency scam unfolded when the X account of renowned footballer Kylian Mbappé was hacked. The breach led to a fraudulent token being promoted to Mbappé’s millions of followers, causing substantial financial losses and raising concerns over social media security. Hack and Immediate Impact The hack occurred on Mbappé’s X account, where attackers posted promotional messages for a cryptocurrency token named ‘$MBAPPE’. According to reports, the scam token’s market capitalisation surged dramatically to $460 million before plummeting to less than $100,000. This rapid rise and fall caused devastating losses for many investors. All of Kylian Mbappe’s hacked tweets incase you missed it… A thread pic.twitter.com/4XEpWpnXQA — george (@StokeyyG2) August 29, 2024 One notable victim, whose identity remains undisclosed, invested over $1 million worth of Solana (SOL) into the $MBAPPE token ...

Finnish police can’t find suspected bitcoin blackmailer they just released

Finnish police are once again hunting a suspected hacker accused of blackmailing 30,000 psychotherapy patients for more than $500,000 in bitcoin after he gave them the slip when he was released from pre-trial detention. Finnish national Aleksanteri Tomminpoika Kivimäki pleaded not guilty to Hack ing into the database of the Vastaamo psychotherapy center in 2018. Kivimäki allegedly told the center to pay 40 bitcoin , worth around $518,000 at the time of the breach, before sharing private documents in 2020. According to the terms of Kivimäki’s release, he was banned from leaving the Espoo area and was ordered to remain at a certain address between seven in the evening and eight in the morning each day. He was also supposed to report to the police three times a week and be contactable on a certain phone number at all times. However, since prosecutors filed a complaint last week, police have been unable to locate Kivimäki . Finnish police trace crypto to accused blackmailer of ...

dYdX exchange reveals post-mortem results of $9m November attack

Decentralized exchange dYdX has released a comprehensive report analyzing the “targeted attack” it encountered on its v3 platform in November. The incident led to a substantial loss of $9 million from its insurance fund, a figure that constitutes about 40% of the fund’s total value. dYdX stated in their Jan. 3 report that their investigation has successfully revealed the identity of the attacker, with whom they are now in communication. 1/ After looking into the YFI incident on dYdX v3, we’ve successfully tracked down the individual responsible & made a report to law enforcement. This is our in-depth analysis & next steps https://t.co/JGxebpERYl — dYdX (@dYdX) January 3, 2024 Additionally, the platform is considering various legal measures to take against the perpetrator responsible for the attack. “dYdX is assisting law enforcement in their investigation of this matter and is assessing all legal options. dYdX is committed to taking any leg...

OKX DEX suffers exploit resulting in over $430k loss

Image
An X wallet for OKX Web3 confirmed in a post that a deprecated smart contract on OKX DEX had been compromised. While the official post-mortem is yet to come, analysts at SlowMist said in an X post that OKX DEX proxy admin owner’s private key was likely leaked, allowing hackers to take over the protocol and change its functionality. Once the protocol was upgraded with malicious functions, attackers began calling the DEX proxy contract to steal tokens from users, who previously gave the protocol permission to interact with their wallets. SlowMist Security Alert: OKX DEX Proxy Admin Owner's Private Key Suspected to be Leaked According to information from SlowMist Zone, the OKX DEX contract appears to have encountered an issue. After SlowMist's Analysis , it was found that when users exchange, they authorize… — SlowMist (@SlowMist_Team) December 13, 2023 You might also like: Smart contract exploit in TIME token leads to $188k loss According to preliminary...

Hackers hijack Frax Finance DNS domain

The domain of the decentralized internet protocol Frax Finance has been captured by attackers. The protocol posted the news on X (formerly Twitter) on Nov. 1. Please don’t use https://t.co/cADe5RLjqv and https://t.co/AcTF8hlzaS domain s until further notice. If you know anyone at @namedotcom please reach out asap. https://t.co/v0KlM5FoLk — Frax Finance (¤, ¤) (@fraxfinance) October 31, 2023 The project team later reported that they had brought the domain back under control thanks to their domain registry. https://t.co/gnEI5kjDki has reached out & confirmed https://t.co/cADe5RLjqv & https://t.co/AcTF8hlzaS domain s are now routed back to their proper nameservers & configuration. We’ve been told they’ll explain what led to the incident after they conduct a full investigation tomorrow https://t.co/h1eE11P5wZ — Frax Finance (¤, ¤) (@fraxfinance) November 1, 2023 Domain Name System (DNS) hijacking occurs when a domain name registrar redirects users to ...

FBI: Lazarus Group hacked and stole $41m from crypto casino, Stake

In a Sep. 6 press release, the Federal Bureau of Investigation (FBI) said North Korea-backed hacker group Lazarus was behind the attack on crypto casino, Stake. Stake reported unauthorized transactions from some of its hot wallets on Sep. 4. Withdrawals and deposits were halted then later resumed, but not before hackers stole $41 million in digital assets.  The FBI, along with multiple blockchain security firms, confirmed that the attackers drained funds from Stake via  Ethereum, BNB Chain, and Polygon. Additionally, federal investigators listed 33 wallets including 22 Bitcoin (BTC) addresses tied to the Stake hack. These addresses either received funds directly from Stake’s hot wallets or were used to siphon illicit gains through various networks. Security shops Arkham and CertiK both said the hacker bridged funds to Avalanche and then to Bitcoin’s blockchain. At press time, the culprits held $36 million on Ethereum , BNB Chain, and Polygon. Over the past 24 hours, the Hack...

Breaking: CoinsPaid targeted in $37.3 million hack

An official update on July 26 reveals that CoinsPaid, an Estonia-based crypto payment provider, was hacked and lost $37.3 million on July 22.  CoinsPaid is pointing fingers at the Lazarus Group, a notorious hacker organization known for targeting high-profile companies in the past. The hacker group, believed to be sponsored by North Korea, has been accused of hacking and stealing from several crypto firms and bridges, including CoinCheck and Ronin. You might also like: Ronin Hackers Have Moved Some Stolen Funds From Ether to Bitcoin Network Following the breach, CoinsPaid’s said they swiftly fortified their systems to prevent further damage. For their action, the payment processor said customer funds are secure. However, considering lost funds, their availability and revenue were impacted.  CoinsPaid is currently investigating the hack using advanced crypto analytics tools. At the same time, it has received support from the broader crypto community, ...

Pro-XRP attorney’s Twitter hacked to promote fake giveaways 

Image
Attorney Jeremy Hogan, known for his pro-XRP stance, has fallen victim to a Twitter account hack. It currently promotes fake XRP giveaways. The hackers offer users “free XRP” to celebrate the XRP triumph, allegedly linking to the recent SEC vs. Ripple case moves. The post leads to fake Ripple website. Hacked account promoting fake giveaways | Source: Jeremy Hogan’s Twitter As of 09:00 UTC on July 25, Hogan has not yet restored access to his account. Jesse Hynes, lawyer and founder of Seedstarter, and attorney James Filan quickly shared the news of the compromised account. They warned others to be cautious and not fall for fake giveaway advertisements. @ attorney jeremy1 looks like @ attorney jeremy1 was hacked , help spread the word. @JohnEDeaton1 @CryptoLawUS @FilanLaw Really annoying in general. But he’s also just trying to vacation with his family. Let the man relax for once. So tired of scammers. — Jesse Hynes (@jesse_hynes) July 24, 2023 Attorney...

Trezor developer confirms private keys can be extracted if firmware is corrupt

A developer has acknowledged that a malicious firmware update can “exfiltrate” the seed and record the passphrase of a Trezor device. This revelation emerged during a discussion on Trezor’s official forum. It is weeks after the Ledger Recover feature suggestion that drew even more concern about the security of assets stored in popular hardware wallets. Trezor confirmation The developer emphasized that although open-source software allows for global community scrutiny and the use of hashes and signatures to verify authenticity, these measures do not eliminate the possibility of harmful code being included in an official software release. He said: “The firmware running on your Trezor must have access to private keys – otherwise, it could not sign your transactions. That means if the firmware turned malicious, it could exfiltrate the private keys. The only way to prevent that would be to freeze the device so that it could never be updated – and pray that...