#CryptoHack

2025-12-26

Hello everyone! It's been a busy day in the cyber world with significant breaches affecting cryptocurrency users and national services, new insights into nation-state APT activity, and a look at how AI is reshaping both attacks and defences. Let's dive in:

Trust Wallet Chrome Extension Breach ⚠️
- Trust Wallet's Chrome extension version 2.68.0 was compromised, leading to an estimated $6-7 million in cryptocurrency losses for users.
- Malicious code was embedded in the extension, exfiltrating mnemonic phrases to an attacker-controlled server, api.metrics-trustwallet[.]com, which was registered shortly before the incident.
- Trust Wallet has confirmed the incident, urged users to update to version 2.69 immediately, and committed to refunding all affected users, while a parallel phishing campaign exploited the panic.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu
📰 The Hacker News | thehackernews.com/2025/12/trus

French Postal Service Hit by Pro-Russian Hackers 🚨
- Pro-Russian group NoName057(16) claimed responsibility for a DDoS attack that disrupted France's national postal service, La Poste, and its banking arm, La Banque Postale, just before Christmas.
- The attack temporarily knocked key digital systems offline, affecting parcel tracking and slowing mail distribution, though La Poste stated no customer data was compromised.
- French authorities have opened an investigation, with the domestic intelligence agency DGSI taking over the probe, focusing on the deliberate disruption of a data processing service.

🗞️ The Record | therecord.media/pro-russia-hac

GrubHub Phishing Scam via Legitimate Subdomain 🎣
- Grubhub users received fraudulent emails from a legitimate company subdomain (b.grubhub.com) promising a tenfold return on sent cryptocurrency as part of a "Holiday Crypto Promotion."
- This is a classic crypto reward scam, luring victims to send Bitcoin to a specified wallet with the false promise of a larger return.
- Grubhub has acknowledged "unauthorized messages" to merchant partners, stating they have contained the issue and are working to prevent future occurrences, though the exact cause (e.g., DNS takeover) remains unconfirmed.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Evasive Panda APT Uses DNS Poisoning for MgBot Malware 🐼
- China-linked APT group Evasive Panda (also known as Bronze Highland, Daggerfly, StormBamboo) conducted a highly targeted cyber espionage campaign using DNS poisoning.
- The group manipulated DNS requests to deliver its MgBot backdoor, masquerading as updates for legitimate software like SohuVA, Baidu's iQIYI Video, IObit Smart Defrag, and Tencent QQ.
- MgBot is a modular implant capable of extensive data harvesting, including keystrokes, clipboard data, audio streams, and browser credentials, allowing for long-term stealthy persistence.

📰 The Hacker News | thehackernews.com/2025/12/chin

Hacker Mindset for Cyber Defence 🧠
- Remedio CEO Tal Kollender, a former video game hacker, advocates for adopting a "hacker mindset" to effectively defend against cyber threats, stating that understanding adversarial thinking is crucial.
- Her company uses AI to proactively identify and auto-remediate vulnerabilities, misconfigurations, and compliance gaps across corporate devices.
- The increasing use of AI by attackers to accelerate reconnaissance and exploitation means defenders must also leverage AI to keep pace, making cybersecurity a battle of AI versus AI.

🕵🏼 The Register | go.theregister.com/feed/www.th

AI's Impact on Cybersecurity Tabletop Exercises 🛡️
- Cybersecurity tabletop exercises are evolving to account for AI, both in terms of how attackers use AI to find and exploit bugs faster, and how defenders can integrate AI into their response strategies.
- Organisations need to simulate scenarios involving rapid exploitation of CVEs (within minutes of publication) and AI-powered phishing, while also securing their own AI systems against prompt injection and data exfiltration.
- Experts recommend incorporating "analog friction" like mandatory out-of-band verification for deepfake-driven requests and practising offline business operations, emphasising process over technology when trust in digital information is compromised.

🕵🏼 The Register | go.theregister.com/feed/www.th

#CyberSecurity #ThreatIntelligence #CryptoHack #DDoS #Phishing #APT #EvasivePanda #MgBot #AIinCyber #TabletopExercises #InfoSec #IncidentResponse

BGDon 🇨🇦 🇺🇸 👨‍💻BrentD@techhub.social
2025-12-18

Crypto Hacking = BIG Business!

Chainalysis reports that more than $3.4B in cryptocurrency has been stolen in 2025 (flat overall with 2024).

North Korea remains dominant crypto threat actor with North Korean hackers having a banner year pilfering ~ $2.02B, a 51% increase over last year.

While the total # of hacks is down, there has been a shift toward dramatically larger attacks, with the top three hacks accounting for 69% of losses. Individual wallet compromises jumped up to 158,000 incidents affecting 80,000 unique victims in 2025.

chainalysis.com/blog/crypto-ha #Chainalysis #Crypto #CryptoCurrencies #CryptoHack #DPRK #NorthKorea #CryptoLaundering #Hackers #CryptoWallet

Chart: CryptoCurrecny $ Hack Volumes Over Time
𝕯𝖔𝖔𝖒𝖘𝖈𝖗𝖔𝖑𝖑™Doomscroll@zirk.us
2025-12-17

💰🕵️♂️🔥 Yearn Finance walked back into a dark alley and got rolled again. Weeks after a $6.6 million beating, a dusty v1 contract got cracked with a flash loan con. The perp juked token prices, cleaned out the vault, and skipped with 103 ETH. Fourth hit so far. Same town, same blood on the pavement. #CryptoHack web3isgoinggreat.com/single/ye

𝕯𝖔𝖔𝖒𝖘𝖈𝖗𝖔𝖑𝖑™Doomscroll@zirk.us
2025-09-08

💻🎭💰 A dev’s NPM account got hijacked, laced with poison code in popular JS tools. Two billion downloads a week turned into a highway robbery. The malware rewrites crypto transfers, swapping in crook wallets. The biggest supply chain hit yet. Watch your keys, trust your eyes. #CryptoHack web3isgoinggreat.com/single/ma

2025-07-29

Coinbase May Acquire CoinDCX as India Preps Crypto Law.
Coinbase is eyeing a discounted buyout of CoinDCX after a $44M hack, betting big on India’s crypto future just as national regulation nears.

#Coinbase #CoinDCX #CryptoIndia #Blockchain #Web3 #CryptoRegulation #CryptoHack #Mergers #DigitalAssets #TECHi

Read Full Article Here :- techi.com/coinbase-may-acquire

मोहित ठाकुरrightnewshindi@rightnewsindia.com
2025-07-25

क्रिप्टो हैक: भारत और विश्व में क्रिप्टोकरेंसी घोटालों का बढ़ा खतरा, जानें हिला देने वाले पांच बड़े स्कैम

India News: क्रिप्टोकरेंसी की दुनिया में हलचल मची है। भारत में क्रिप्टो हैक की घटनाएं बढ़ रही हैं, लेकिन कोई नियामक संस्था जैसे सेबी जिम्मेदारी नहीं ले रही। इससे निवेशकों में चिंता बढ़ रही है। […]

rightnewsindia.com/crypto-hack

2025-07-19

The Indian centralized exchange CoinDCX has reportedly been drained for nearly $44.2 million almost 17 hours ago, the on-chain sleuth ZachXBT claimed...

#cryptocurrency #zachxbt #coindcx #indiancryptoexchange #hacking #CryptoHack #CryptoNews #Cryptomarkets

thestreet.com/crypto/markets/i

IT InsightsITinsights
2025-07-18

🚨 CRYPTO-RAMP: $27M GESTOLEN! BigONE gehackt! Heeft dit invloed op jouw crypto-strategie? 🤔  
itinsights.nl/cybersecurity/cr

CoinpediaCoinpedia
2025-06-05

May’s Loss & Recovery

🔹In May 2025, losses totaled $302.4 million, with alone responsible for $225.7 million, nearly 75% of the total.

🔹Despite the heavy losses, the industry bounced back, recovering 53.7% of the stolen funds.

2025-05-24

Hey Crypto Fam! 👋 Cetus offers $6M bounty after $220M hack on Sui. Emergency responses spark decentralization debate. Is this progress or a setback? 🤔 #DeFi #CryptoHack #Sui

2025-05-23

Hey crypto fam! 🚨Sui-based DEX Cetus may have suffered a $200M+ exploit! Funds are being bridged to ETH. Scallop halted borrowing. Investigation ongoing. Stay safe! ⚠️ #DeFi #Sui #CryptoHack

2025-05-12

Cryptohack. Решение Oh SNAP. Атака Флюрера-Мантина-Шамира (Fluhrer, Mantin, Shamir)

Приветствую, Хабр! В нескольких предыдущих статьях я рассматривал различные режимы шифрования для блочных шифров, постепенно сдвигаясь в сторону режимов, превращающих блочные шифры в потоковые. В новой статье в фокусе будет чисто потоковый шифр - RC4. Я расскажу о самом шифре, а также об атаке FMS и применении её для решения задачи Oh, SNAP с платформы Cryptohack.

habr.com/ru/articles/908094/

#rc4 #fms #cryptography #cryptohack #ctf

Diana Barbosa :cravo:🇺🇦🇵🇸diraquel@masto.pt
2025-03-10

Fascinating! And 😬
The Global Story: How North Korean hackers launched history's biggest heist
#LazarusGroup #Ethereum #Heist #Hacking #NorthKorea #CryptoHack #CryptoCurrency
bbc.co.uk/programmes/p0kwt2j3

2025-03-04

Cryptohack. Решение Logon zero

Приветствую, Хабр! Я к вам возвращаюсь с новой статьёй о режимах шифрования и решении задачи с Cryptohack. Сегодня в центре внимания будет режим CFB-8 и уязвимость CVE-202–1472.

habr.com/ru/articles/887886/

#aes #cfb #cryptography #ctf #cryptohack

Mega-Hack bei Bybit! Hacker stehlen Krypto im Wert von 1,5 Mrd. USD – mutmaßlich Lazarus-Gruppe. CEO ruft Blockchain-Bounty-Hunter zur Jagd auf! 🔍🚨 #CryptoHack #Bybit #LazarusGroup #Blockchain

TheDoctorTheDoctor512
2025-02-26

Mega-Hack bei Bybit! Hacker stehlen Krypto im Wert von 1,5 Mrd. USD – mutmaßlich Lazarus-Gruppe. CEO ruft Blockchain-Bounty-Hunter zur Jagd auf! 🔍🚨

2025-02-22

#crypto #cryptohack #Bybit

La bourse de crypto-monnaies Bybit aurait perdu 1,4 milliard de dollars US lors du plus grand piratage de crypto-monnaies à ce jour.

- Source : The Daily Rip by Stocktwits, 21 février 19:35

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst