Tag: cryptocurrency

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
News

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

UNC1069, a threat actor with ties to North Korea, has been seen targeting the cryptocurrency industry in an attempt to obtain private information from Windows and macOS devices in order to facilitate financial theft. According to Google Mandiant experts Ross Inman and Adrian Hernandez, the breach used a social engineering approach that included a hacked Telegram account, a phony Zoom meeting, a ClickFix infection vector, and reported use of AI-generated video to trick the victim. UNC1069, which has been active since at least April 2018, has a history of using phony meeting invites and impersonating investors from respectable companies on Telegram to carry out social engineering efforts for financial benefit. The larger cybersecurity community also keeps tabs on it under the names MA...
SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips
News

SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips

Several businesses have been charged by the U.S. Securities and Exchange Commission (SEC) for allegedly participating in a complex cryptocurrency scam that defrauded retail investors of over $14 million. In relation to the operation, the complaint accused investment clubs AI Wealth Inc., Lane Wealth Inc., AI Investment Education Foundation (AIIEF) Ltd., and Zenith Asset Tech Foundation, as well as cryptocurrency asset trading platforms Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc. According to the SEC, the scam was a multi-step scheme that used social media advertisements to lure naïve individuals. The scammers then used group conversations to gain their trust by pretending to be financial experts and promising rewards from investment advice created by ...
Police takes down Cryptomixer cryptocurrency mixing service
News

Police takes down Cryptomixer cryptocurrency mixing service

The cryptocurrency-mixing firm Cryptomixer, which is thought to have assisted cybercriminals in laundering stolen assets, has been shut down by law enforcement officials from Germany and Switzerland. The combined activity, which was a component of "Operation Olympia," happened in Zurich, Switzerland, between November 24 and November 28. Three servers, the clear web and Tor.onion names, and €24 million in Bitcoin were taken by authorities with the help of Europol and Eurojust. Cryptomixer was a hybrid mixing service that was available on the dark and clear webs. It permitted the obfuscation of illegal funding for ransomware organizations, underground economy forums and dark web markets, Europol claimed read more about Police takes down Cryptomixer cryptocurrency mixing service. ...
GitHub notifications abused to impersonate Y Combinator for crypto theft
News

GitHub notifications abused to impersonate Y Combinator for crypto theft

The Y Combinator (YC) W2026 program was the victim of a huge phishing attempt that sent phony invitations to GitHub users who were cryptocurrency drainers. Y Combinator is a startup accelerator that links founders with a network of venture capital companies and alumni while also funding and mentoring businesses in their early stages. By tagging specific users and causing problems across several repositories, the attacker took use of GitHub's notification system to spread the false warnings. GitHub notifies users automatically when an account name is mentioned in an issue. The email reached its intended recipients' inboxes directly because it came from a reliable source. An invitation to apply for YC funding in the upcoming Winter 2026 Batch (W2026) served as the campaign's bait r...
N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto
News

N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto

UNC4899, a threat actor associated with North Korea, has been implicated in attacks that targeted two distinct firms by contacting their employees using Telegram and LinkedIn. Google's cloud division stated [PDF] in its Cloud Threat Horizons Report for H2 2025 that UNC4899 used social engineering techniques to successfully persuade the targeted employees to run malicious Docker containers on their workstations under the pretense of freelance opportunities for software development work. Activity monitored under the names Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor coincides with UNC4899. The state-sponsored actor has been active since at least 2020 and is well-known for focusing on the blockchain and cryptocurrency sectors. Significant cryptocurrency heists, such as those...
Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
News

Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord

An ongoing social engineering attack targets cryptocurrency users by using phony startup companies to lure users into downloading malware that can drain digital assets from Windows and macOS devices. In a study posted with The Hacker News, Darktrace researcher Tara Gould said that these malicious operations use fake social media identities and project documentation hosted on trustworthy platforms like Notion and GitHub to imitate AI, gaming, and Web3 companies. It is a sophisticated social media scam that has been going on for a while. In December 2024, it used fake videoconferencing platforms to trick victims into attending a conference that was supposed to be about an investment opportunity after contacting them on Telegram and other messaging applications. Stealer virus, like ...
Europol Dismantles $540 Million Cryptocurrency Fraud Network Arrests Five Suspects
News

Europol Dismantles $540 Million Cryptocurrency Fraud Network Arrests Five Suspects

The dismantling of a cryptocurrency investment fraud ring that laundered €460 million ($540 million) from over 5,000 victims worldwide was reported by Europol on Monday. According to the organization, the Spanish Guardia Civil conducted the operation with assistance from Estonian, French, and American law enforcement. According to Europol, the syndicate's probe began in 2023. On June 25, 2025, the five suspected criminals involved in the bitcoin scam were also taken into custody. Two people were arrested from Madrid, and three others were arrested in the Canary Islands. According to Europol, the criminal network's leaders allegedly raised money through cash withdrawals, bank transfers, and cryptocurrency transfers using a global network of collaborators read more about Europol Di...
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
News

CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup

The well-known cryptocurrency price tracking website CoinMarketCap experienced a supply chain hack that left users vulnerable to a wallet drainer campaign that stole their cryptocurrency. Visitors to CoinMarketCap started seeing Web3 popups requesting that they link their wallets to the website on Friday night, January 20. However, a rogue software depleted visitors' cryptocurrencies when they connected their wallets. The business subsequently acknowledged that threat actors had introduced malicious JavaScript onto the website by exploiting a flaw in the "doodle" image on the homepage. Our security team discovered a flaw in a doodle image that was shown on our homepage on June 20, 2025. According to a statement made on X, this doodle artwork included a link that, when seen on our...
U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network
News

U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network

A civil forfeiture case targeting approximately $7.74 million in cryptocurrencies, non-fungible tokens (NFTs), and other digital assets purportedly connected to a global IT worker scheme hatched by North Korea has been filed in federal court, according to the U.S. Department of Justice (DoJ). According to Sue J. Bai, Head of the Justice Department's National Security Division, North Korea has been using cryptocurrency ecosystems and international remote IT contracting for years to circumvent U.S. sanctions and finance its weapons development. According to the Justice Department, the money were initially blocked in relation to an indictment filed in April 2023 against Sim Hyon-Sop, a representative of the North Korean Foreign Trade Bank (FTB), who is suspected of plotting with the IT...
Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated Cold Wallet Attack
News

Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated Cold Wallet Attack

The greatest cryptocurrency heist in history occurred on Friday when cryptocurrency exchange Bybit disclosed that a "sophisticated" attack had stolen more than $1.5 billion worth of bitcoin from one of its Ethereum cold (offline) wallets. The event happened as a result of a transfer from our ETH multisig cold wallet to our warm wallet. "Unfortunately, this transaction was manipulated through a sophisticated attack that changed the underlying smart contract logic while masking the signing interface and displaying the correct address," Bybit stated in a post on X. Consequently, the attacker managed to take over the compromised Ethereum cold wallet and move its contents to an unspecified address read more about Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated C...