#cryptocurrencysecurity
Trezor Customers Hit by Sophisticated Phishing Campaign Following Third-Party Email Provider Compromise

Trezor has confirmed its third-party email provider was breached, allowing attackers to send highly convincing phish…

#cryptocurrencysecurity #databreach #dkim #emailsecurity
Trezor Customers Hit by Sophisticated Phishing Campaign Following Third-Party Email Provider Compromise
Trezor has confirmed its third-party email provider was breached, allowing attackers to send highly convincing phishing emails from the official trezor.io domain that passed all standard email authentication checks, including SPF, DKIM, and DMARC.
fxcrypto24.com
September 10, 2026 at 9:41 AM
Mythos Discovers Critical Crypto Vulnerabilities Unknown for Years

#CryptocurrencySecurity #BlockchainVulnerabilities #VantaWire #TechNews

🔗 https://www.vantawire.com/mythos-discovers-critical-crypto-vulnerabilities-unknown-for/
July 29, 2026 at 11:30 PM
Browser Memory Becomes New Target in JavaScript Malware Campaign #BrowserBasedMalware #cryptocurrencysecurity #CyberCrime
Browser Memory Becomes New Target in JavaScript Malware Campaign
  Security researchers have discovered a large-scale malvertising campaign that uses fake cryptocurrency and trading websites to assemble malware inside the web browser of the victim, making it increasingly difficult to detect using traditional security tools.  A security firm named Confiant claims the operation has been in operation since late 2024 and primarily targets retail traders and cryptocurrency investors in 12 countries. Asia-Pacific and Latin America regions are particularly targeted. In addition to supporting 25 languages, the campaign employs sophisticated filtering techniques to prevent researchers, automated scanners, and security bots from reaching malicious sites, as well as redirecting researchers and automated scanners to harmless blank pages to avoid damage.  Security researchers, automated scanners, and bots are served empty pages before the fake websites are displayed in order to determine whether or not the users are legitimate targets. In contrast, retail traders and cryptocurrency investors receive convincing replicas of legitimate platforms when using selective filtering. By doing so, routine security scans are significantly reduced in the likelihood of detecting the infrastructure.  Users are presented with websites that appear legitimate that offer software downloads by impersonating popular platforms such as Solana, Luno, and TradingView. By utilizing JavaScript techniques, the websites construct malware locally within the victim's browser memory rather than delivering a malicious file directly to the victim. It is said that the browser acts as a "local assembly pipeline" because it is capable of assembling malware rather than downloading a complete executable file. As part of the attack, a Service Worker is registered to manage the download process, whereas a SharedWorker is created directly from JavaScript embedded within the webpage, so that the source code does not appear as a separate network request.  After receiving the configuration file, the worker requests instructions for assembling the malware, including a template, randomized session values, and instructions. Each download is uniquely generated based on randomized parameters, thus producing a unique file hash for each victim. By utilizing this approach, the malware can bypass static detection methods that depend upon identifying known file signatures.  Browsers download legitimate Bun runtimes from a secondary domain as part of the assembly process, and they combine them with attacker-controlled executable components and locally generated data as part of the assembly process. Since Bun is a legitimate component for building standalone Windows applications, attackers exploit this feature to disguise the final executable.  Each session generates a unique file hash based on a random seed and file size, reducing the effectiveness of hash-based malware detection. By delivering the executable through the same domain that the website uses, the download appears legitimate from the browser's perspective, so that the download appears legitimate.  Despite receiving Microsoft's Mark-of-the-Web security tag, network-based detection and forensic analysis are significantly more difficult without a fully transmitted malicious file. According to Confident, earlier versions of the campaign, tracked as SourTrade, used the open-source StreamSaver project to deliver malware. Since April 2026, however, the operators have switched to using more sophisticated Service Worker-based delivery mechanisms. Researchers did not publicly identify the malicious payload for this campaign, but they linked it to Bitdefender's previous findings, which documented malware capable of intercepting internet traffic, stealing passwords and browser cookies, logging keystrokes, capturing screenshots, harvesting cryptocurrency wallet data, and maintaining persistence on compromised systems for a period of time.  A Confident representative noted that the campaign does not exploit browser vulnerabilities or bypass Microsoft's Mark-of-the-Web (MotW) security features. Instead, it utilizes legitimate browser capabilities to deliver malware without transmitting a full executable over the network. In addition, researchers noted that there is currently no software patch available for this technique, which requires users to remain aware of and to practice safe software downloading practices to protect themselves.  Earlier versions of the campaign used the open-source StreamSaver project hosted on GitHub to facilitate malware downloads, allowing investigators to trace its evolution from earlier versions. The operators replaced that approach in April 2026 with a Service Worker-based download mechanism, which encapsulates the entire delivery process within the impersonated website, making it increasingly difficult to analyze the network and detect malware.  A security expert recommends downloading cryptocurrency and financial software from official vendor websites, avoiding sponsored advertisements or social media promotions, and verifying the digital signature and publisher of the application before installation. In light of the increasing stealthy techniques used by attackers to compromise users, these precautions remain critical. In light of the increasing sophistication of cybercriminals' malware delivery techniques, campaigns such as SourTrade underscore the challenges that defenders face.  Through the use of legitimate browser functionality in order to assemble malware locally, attackers are able to bypass many traditional detection methods. It is recommended that you only download software from legitimate sources, verify digital signatures, and be wary of sponsored advertisements and promotional links relating to cryptocurrencies and financial institutions.
dlvr.it
July 27, 2026 at 2:16 PM
Suspicious Polymarket Bets Spark Insider Trading Fears After Maduro’s Capture #cryptocurrency #cryptocurrencysecurity #CryptocurrencyUsers
Suspicious Polymarket Bets Spark Insider Trading Fears After Maduro’s Capture
 A sudden, massive bet surfaced just ahead of a major political development involving Venezuela’s leader. Days prior to Donald Trump revealing that Nicolás Maduro had been seized by U.S. authorities, an individual on Polymarket placed a highly profitable position. That trade turned a substantial gain almost instantly after the news broke. Suspicion now centers on how the timing could have been so precise. Information not yet public might have influenced the decision. The incident casts doubt on who truly knows what - and when - in digital betting arenas. Profits like these do not typically emerge without some edge.  Hours before Trump spoke on Saturday, predictions about Maduro losing control by late January jumped fast on Polymarket. A single user, active for less than a month, made four distinct moves tied to Venezuela's political situation. That player started with $32,537 and ended with over $436,000 in returns. Instead of a name, only a digital wallet marks the profile. Who actually placed those bets has not come to light.  That Friday afternoon, market signals began shifting - quietly at first. Come late evening, chances of Maduro being ousted edged up to 11%, starting from only 6.5% earlier. Then, overnight into January 3, something sharper unfolded. Activity picked up fast, right before news broke. Word arrived via a post: Trump claimed Maduro was under U.S. arrest. Traders appear to have moved quickly, moments prior. Their actions hint at advance awareness - or sharp guesswork - as prices reacted well before confirmation surfaced. Despite repeated attempts, Polymarket offered no prompt reply regarding the odd betting patterns.  Still, unease is growing among regulators and lawmakers. According to Dennis Kelleher - who leads Better Markets, an independent organization focused on financial oversight - the bet carries every sign of being rooted in privileged knowledge Not just one trader walked away with gains. Others on Polymarket also pulled in sizable returns - tens of thousands - in the window before news broke. That timing hints at information spreading earlier than expected. Some clues likely slipped out ahead of formal releases. One episode sparked concern among American legislators.  On Monday, New York's Representative Ritchie Torres - affiliated with the Democratic Party - filed a bill targeting insider activity by public officials in forecast-based trading platforms. Should such individuals hold significant details not yet disclosed, involvement in these wagers would be prohibited under his plan. This move surfaces amid broader scrutiny over how loosely governed these speculative arenas remain. Prediction markets like Polymarket and Kalshi gained traction fast across the U.S., letting people bet on politics, economies, or world events.  When the 2024 presidential race heated up, millions flowed into these sites - adding up quickly. Insider knowledge trades face strict rules on Wall Street, yet forecasting platforms often escape similar control. Under Biden, authorities turned closer attention to these markets, increasing pressure across the sector. When Trump returned to influence, conditions shifted, opening space for lighter supervision. At Kalshi and Polymarket, leadership includes Donald Trump Jr., serving behind the scenes in guiding roles.  Though Kalshi clearly prohibits insider trading - even among government staff using classified details - the Maduro wagering debate reveals regulatory struggles. Prediction platforms increasingly complicate distinctions, merging guesswork, uneven knowledge, then outright ethical breaches without clear boundaries.
dlvr.it
January 24, 2026 at 5:24 PM
Lazarus Group Suspected in $11M Crypto Heist Targeting Taiwan’s BitoPro Exchange #CryptoPlatform #cryptocurrency #cryptocurrencysecurity
Lazarus Group Suspected in $11M Crypto Heist Targeting Taiwan’s BitoPro Exchange
 Taiwanese cryptocurrency platform BitoPro has blamed North Korea’s Lazarus Group for a cyberattack that resulted in $11 million in stolen digital assets. The breach occurred on May 8, 2025, during an upgrade to the exchange’s hot wallet system.  According to BitoPro, the tactics and methods used by the hackers closely resemble those seen in other global incidents tied to the Lazarus Group, including high-profile thefts via SWIFT banking systems and other major crypto platforms. BitoPro serves a primarily Taiwanese customer base, offering fiat transactions in TWD alongside various cryptocurrencies.  The exchange currently supports over 800,000 users and processes approximately $30 million in daily trades. The attack exploited vulnerabilities during a system update, enabling the unauthorized withdrawal of funds from a legacy hot wallet spread across several blockchain networks, including Ethereum, Tron, Solana, and Polygon. The stolen cryptocurrency was then quickly laundered through decentralized exchanges and mixers such as Tornado Cash, Wasabi Wallet, and ThorChain, making recovery and tracing more difficult.  Despite the attack taking place in early May, BitoPro only publicly acknowledged the breach on June 2. At that time, the exchange assured users that daily operations remained unaffected and that the compromised hot wallet had been replenished from its reserve funds. Following a thorough investigation, the exchange confirmed that no internal staff were involved.  However, the attackers used social engineering tactics to infect a cloud administrator’s device with malware. This allowed them to steal AWS session tokens, bypass multi-factor authentication, and gain unauthorized access to BitoPro’s cloud infrastructure. From there, they were able to insert scripts directly into the hot wallet system and carry out the theft while mimicking legitimate activity to avoid early detection.  After discovering the breach, BitoPro deactivated the affected wallet system and rotated its cryptographic keys, though the damage had already been done. The company reported the incident to authorities and brought in a third-party cybersecurity firm to conduct an independent review, which concluded on June 11.  The Lazarus Group has a long history of targeting cryptocurrency and decentralized finance platforms. This attack on BitoPro adds to their growing list of cyber heists, including the recent $1.5 billion digital asset theft from the Bybit exchange.
dlvr.it
June 29, 2025 at 3:45 PM
Sanctioned Russian Crypto Exchange Garantex Allegedly Rebrands as Grinex #CryptoExchange #cryptocurrency #cryptocurrencysecurity
Sanctioned Russian Crypto Exchange Garantex Allegedly Rebrands as Grinex
 International efforts to dismantle illicit financial networks are facing new challenges, as the recently sanctioned Russian cryptocurrency exchange Garantex appears to have rebranded and resumed operations under a new name—Grinex. Reports from blockchain analytics firm Global Ledger suggest that Grinex may be a direct successor to Garantex, which was shut down earlier this month in a joint operation by law enforcement agencies from the U.S., Germany, and Finland.  Despite the crackdown, Global Ledger researchers have identified on-chain movements linking the two exchanges, including the transfer of Garantex’s holdings in a ruble-backed stablecoin, A7A5, to wallets controlled by Grinex. Off-chain clues further support the connection, such as the sudden surge in trading volume—Grinex reportedly handled over $40 million in transactions within two weeks of its launch. According to Lex Fisun, CEO of Global Ledger, social media activity also suggests a direct relationship between the platforms. In a Telegram post, Sergey Mendeleev, a known figure associated with Garantex, downplayed the similarities between the two exchanges while making light of the situation. Meanwhile, reports indicate that former Garantex users have been transferring funds at the exchange’s physical offices in Europe and the Middle East, strengthening claims that Grinex is simply a rebranded version of the defunct platform. While leading blockchain analytics firms such as Chainalysis and TRM Labs have yet to verify these findings, Andrew Fierman, Head of National Security Intelligence at Chainalysis, acknowledged that early indicators point to a connection between Garantex and Grinex.  However, a full assessment of Grinex’s infrastructure is still underway. If Grinex is indeed a rebranded Garantex, it would not be the first time a sanctioned exchange has attempted to evade regulatory scrutiny through rebranding. Similar cases have been observed in the past—BTC-E, a Russian exchange taken down by U.S. authorities in 2017, later reemerged as WEX, only to collapse due to internal conflicts. Likewise, Suex, another Russian exchange sanctioned for facilitating illicit transactions, resurfaced as Chatex before facing renewed enforcement actions.  The reappearance of Garantex in another form underscores the persistent difficulties regulators face in enforcing financial sanctions. Despite the seizure of its servers and domain, the exchange’s infrastructure appears to have been quickly reestablished under a new identity. Experts warn that non-compliant exchanges operating in high-risk regions will continue to find ways to circumvent restrictions. Before its takedown, Garantex had been identified as a hub for money laundering and illicit financial transactions.  The U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned the exchange in 2022, citing its involvement in facilitating payments for ransomware groups such as Black Basta and Conti, as well as its ties to darknet marketplaces like Hydra. Court documents also revealed that Garantex provided financial services to North Korea’s Lazarus Group, a state-backed hacking organization responsible for some of the largest cryptocurrency heists in history, including the $1.4 billion Bybit hack. Additionally, Russian oligarchs reportedly used the platform to bypass economic sanctions imposed after Russia’s invasion of Ukraine. Two individuals linked to Garantex’s operations, Lithuanian national and Russian resident Aleksej Besciokov and Russian citizen Aleksandr Mira Serda, have been charged with conspiracy to commit money laundering. Besciokov was arrested in India earlier this month while on vacation with his family and is expected to be extradited to the U.S. to face trial.  While authorities work to contain illicit financial activity in the crypto space, the rapid emergence of Grinex serves as a reminder of how easily such operations can adapt and reappear under new identities. Analysts warn that other high-risk exchanges in Russia, such as ABCEX and Keine-Exchange, are poised to take advantage of regulatory loopholes and fill the void left by Garantex’s shutdown.
dlvr.it
April 1, 2025 at 5:05 PM
Getting spammed by foreign Bitcoin emails? You're not alone! How do you handle suspicious emails? #CryptocurrencySecurity

https://support.google.com/mail/thread/321044464/is-these-bitcoin-cryptocurrency-email-real?hl=en
Is these Bitcoin cryptocurrency email real - Gmail Community
support.google.com
January 27, 2025 at 11:31 PM
A fraudster must repay £3.1m in stolen Bitcoin. How can we better protect ourselves in the crypto world?#CryptocurrencySecurityy

https://www.accountancydaily.co/bitcoin-fraudster-ordered-repay-ps31
m
Bitcoin fraudster ordered to repay £3.1m
Former takeaway worker turned crypto currency launderer has been ordered to pay back over £3m or face a further seven years in jail
www.accountancydaily.co
January 15, 2025 at 6:30 PM
December 12, 2024 at 7:07 PM
Coinbase's confusing 2FA alerts sparked panic—users thought their accounts were under attack even when they weren't. What's really behind the mix-up?

#coinbase
#2fa
#cryptocurrencysecurity
#usertrust
#securitycommunication
Coinbase's 2FA Error Messages: A Call for Clearer Communication in Cryptocurrency Security | The DefendOps Diaries
Coinbase's 2FA error messages cause confusion, highlighting the need for clearer communication in cryptocurrency security.
thedefendopsdiaries.com
April 5, 2025 at 3:46 PM
#CryptocurrencySecurity sees major gains, yet $2B still lost to scams & hacks. Fund recovery rate jumped from 2% to 10% recently. #CryptoNews According to FinanceMagnates.
Security Gains in Cryptocurrency, Yet $2 Billion Lost to Scams and Hacks
#CryptocurrencySecurity sees major gains, yet $2B still lost to scams & hacks. Fund recovery rate jumped from 2% to 10% recently. #CryptoNews According to FinanceMagnates.
cryptonews.blue
December 27, 2023 at 2:14 PM
Fortifying Your Assets: Best Practices in Cryptocurrency Security

In an age where technology is advancing at an overwhelming speed, securing your digital assets is more important than ever. We will discuss the best practices in cryptocurrency security in this article. The… #Cryptocurrencysecurity
Fortifying Your Assets: Best Practices in Cryptocurrency Security
Fortifying Your Assets: Best Practices in Cryptocurrency Security In an age where technology is advancing at an overwhelming speed, securing your digital assets is more important than ever. We will discuss the best practices in cryptocurrency security…
dlvr.it
February 13, 2024 at 3:34 PM
Understanding Cold Storage and Its Importance in Crypto Security

Security is a concept that can not be overemphasized in cryptocurrencies, given that it is solely virtual and not physical. Cold storage is one of the effective ways cryptocurrency security has… #ColdStorage #Cryptocurrencysecurity
Understanding Cold Storage and Its Importance in Crypto Security
Understanding Cold Storage and Its Importance in Crypto Security Security is a concept that can not be overemphasized in cryptocurrencies, given that it is solely virtual and not physical. Cold storage is one of the effective ways cryptocurrency…
dlvr.it
February 9, 2024 at 1:24 PM
How Multi-Signature Wallets Enhance Cryptocurrency Security

In the dynamic realm of cryptocurrency, security remains a paramount concern. Multi-Signature Wallets, or multisig wallets, stand out as a pivotal advancement in fortifying the safeguarding… #Cryptocurrencysecurity #MultiSignatureWallets
How Multi-Signature Wallets Enhance Cryptocurrency Security
How Multi-Signature Wallets Enhance Cryptocurrency Security In the dynamic realm of cryptocurrency, security remains a paramount concern. Multi-Signature Wallets, or multisig wallets, stand out as a pivotal advancement in fortifying the safeguarding of…
dlvr.it
January 23, 2024 at 9:35 AM