News linked to this event type.
Odaily reports: SlowMist Chief Information Security Officer 23pds has stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, take control of devices, and extract private keys and other data from self-custodial crypto wallets. The vulnerability was previously used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 through 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this assessment has not yet been officially verified.Attacks typically begin with social engineering. After users click on malicious links sent via social media or messaging apps, their devices may be rooted and wallet data extracted. Users should promptly update their phone's operating system and avoid visiting website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from Apple's official App Store have filed a lawsuit against Apple. (Bitcoin.com News)
Odaily News: According to monitoring by Galaxy's head of research, Coldcard white hat funds consolidated 52.37 BTC from Wave 2, Footprints AA, AU, and AX into a new address, which inscribed the OP_RETURN message "claim:cryptorecoverytrust dot com" in block 967,948. These white hat funds account for 2.8% of the Coldcard exploit attack funds.
Odaily reports: Bitcoin News posted on X that China launched a next-generation commercial cryptography algorithm initiative in 2025, aimed at developing and evaluating cryptographic standards capable of withstanding future quantum computers. Independent researcher @mjos_crypto, while analyzing the candidate algorithms, has discovered critical vulnerabilities in multiple proposed algorithms, including publicly reproducible private keys, easily constructible hash collisions, and signature implementations that accept invalid signatures. Bitcoin currently relies on well-validated elliptic curve cryptography, which quantum computers may pose a threat to its security model in the future; however, prematurely adopting insufficiently tested post-quantum cryptography schemes could also introduce vulnerabilities before quantum threats emerge.
Odaily reports, according to monitoring by Bitcoin News, security researchers have discovered that versions 1.1 and 1.2 of FomoPeek, distributed through the Apple App Store, contain an iOS exploit framework capable of escaping the app sandbox, enabling the extraction of keychain data, wallet files, and mnemonic phrases. SlowMist has linked the app to multiple theft incidents and traced nearly $580,000 in stolen USDT flowing into a primary address. Users who have installed either of the aforementioned versions should treat any keys accessible on that iPhone as compromised, generate new mnemonic phrases on a clean device, and immediately transfer their funds.
Odaily reports: Bitcoin News posted on X that Core Lightning is urging node operators to immediately disable experimental features, as developers are investigating a vulnerability that could put channel funds at risk. This is Core Lightning's second warning within a few weeks, following an August patch and the release of the 26.06.7 upgrade after a series of AI-generated CVE reports. Core Lightning has not yet disclosed how the experimental feature could be exploited.
Odaily News: Bitcoin fork project Bitcoin BLAKE2b developers plan to restrict miners from unlocking newly mined tokens, with a waiting period set at 45 days. The related change is proposed to be executed at block height 973440. The chain forked from Bitcoin on August 8.Its native token BTCB2 is also labeled by some trading platforms as Bitcoin BLAKE2b, Bitcoin BIP-110, or XBT. BTCB2 has fallen 84% from its September high of $1,799, trading at approximately $270 to $315 in recent hours.Developer Luke Dashjr stated that some BLAKE2b mining pools are "attacking" the network. After forking, the chain inherited Bitcoin's difficulty, mining only about 8 blocks in the first 22 days, before resuming operation by enabling BLAKE2b hashing and adjusting difficulty.Currently, the chain is not listed by most trading platforms or CoinGecko and CoinMarketCap. Trading platform Neoxa has stated it supports the upcoming soft fork. (Bitcoin.com News)
Crypto wallet app SecondFi announced that some wallet holders affected by the security incident were originally scheduled to claim NIGHT tokens the following day. After consulting with the Midnight Foundation, it was confirmed that NIGHT token allocations can only be claimed via the original wallets; the system does not support switching to an unaffected wallet address for claims.
According to an official announcement, Upbit has placed MultiversX (EGLD) on its trading warning list. Deposit and withdrawal services are currently suspended. Previously, it was reported that MultiversX suspended its network due to a virtual machine atomicity vulnerability, and a patch is now undergoing testing.
Bank of America notes that AI security concerns are emerging as a sustained catalyst for the cybersecurity sector, as market focus shifts from fears of AI disruption to new attack surfaces, identity requirements, and governance demands. Identity management is central to protecting AI agents, with leading platform security providers poised to benefit. The bank advises monitoring whether AI security spending exceeds current expectations, citing it as a key signal marking the transition from valuation expansion to earnings-driven growth.
北韩黑客利用虚假招聘陷阱感染近 3 万台设备,并窃取价值超 1.07 亿美元的加密货币。
Odaily reports: Owen Simonin, founder and CEO of French crypto platform Meria, stated that following several recent data breach incidents in France, there has been an increase in scam calls impersonating customer service representatives from legitimate platforms such as Binance and Meria.Scammers falsely claim that users' accounts or funds are at risk, inducing them to urgently transfer their crypto assets to designated addresses. Simonin emphasized that platforms will not ask users to initiate transactions or provide personal information when users have not proactively contacted them.In August, the French General Directorate of Public Finances (DGFiP) disclosed that a data breach incident allowed hackers to obtain the data of 678,000 taxpayers. (Bitcoin.com News)
Odaily reports: The North Korean hacker group WaterPlum has been posing as recruiters for cryptocurrency, AI, and NFT companies, targeting software developers and IT professionals with malware disguised as coding assignments or video conferencing fix files.The group has infected at least 30,000 devices across more than 100 countries, and between December 2025 and July 2026, extracted funds or account credentials from over 7,000 cryptocurrency wallets, stealing at least $10.7 million. (Cointelegraph)
Visa is closing a checkout loophole supported by crypto payment infrastructure company Crossmint. The loophole previously allowed users purchasing Meme coins with credit cards to have transactions classified under a merchant category code intended for digital media such as e-books, movies, and music.Visa has notified payment processors, including Checkout.com, that it will no longer accept that code for Meme coin transactions, giving processors a grace period to stop the practice, which is expected to end next week. Thereafter, Meme coin purchases must be processed as cryptocurrency transactions and are subject to Visa's corresponding rules.Chase had disputed a Visa transaction that was not flagged as a cryptocurrency transaction, arguing that its merchant category code was incorrect and that it should not have earned credit card rewards. The New York State Attorney General's Office is also aware of and reviewing the matter. (Decrypt)
According to on-chain analyst PeckShield (@PeckShieldAlert), the same attacker successively exploited vulnerabilities in the @SingularityNET bridge contract to illicitly mint 260 million AGIX and 53.838 million WMTx on Ethereum. The attacker currently holds approximately $16.77 million in crypto assets, including 198.3 million AGIX (approximately $14.42 million), 649 ETH (approximately $1.67 million), and 33.538 million WMTx (approximately $627,000).
Fetch.ai officially announced that it was hacked, with attackers breaching the system via stolen signing keys and transferring funds to withdrawal wallets. An on-chain attack analysis report tracing the complete path from the key leak to the attacker's withdrawal has been published on the ASI:One platform. Currently, Fetch.ai has collaborated with SingularityNET to disable the affected wallets and related contracts. The investigation is ongoing, and updates will be provided continuously.
According to an official tweet from the Artificial Superintelligence Alliance (@ASI_Alliance), a security vulnerability occurred in the FET token migration and bridging architecture, enabling an unauthorized party to withdraw approximately $1.56 million worth of FET from the converter. The team responded immediately and has launched an investigation in coordination with security partners.
Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
MultiversX has confirmed that attackers attempted to exploit atomicity issues at the virtual machine level, resulting in invalid state changes. To prevent further escalation, block production on the network remains paused. The development team has completed the fix and will validate it in a shadow fork environment. Upon successful testing, the update will be deployed to the mainnet in coordination with validators, trading platforms, and infrastructure partners.
Odaily News: According to MultiversX monitoring, attackers attempted to exploit a VM-level atomicity issue, causing invalid state changes on the network. To prevent the incident from escalating further, the network has been paused.The development team has prepared a fix, which will first be verified in a shadow fork environment; after successful testing, it will be coordinated with validators, exchanges, and infrastructure partners for deployment to mainnet. Currently, the team is evaluating a targeted recovery plan to process only the invalid state changes related to this incident while preserving confirmed transaction history and normal user state.Users do not need to take any action. Until the official recovery notice is issued, please do not submit or rebroadcast transactions, and do not deposit or withdraw EGLD and ESDT assets through trading platforms or cross-chain bridges. After the incident is resolved and the investigation results are confirmed, MultiversX will release a full technical report.
According to Forbes, seven agencies including the U.S. Federal Bureau of Investigation and Japan’s National Police Agency jointly disclosed that the North Korean hacker group “WaterPlum” (also known as “Infectious Interview”) spreads malware through fake recruitment and coding tests, infecting over 30,000 devices in more than 100 countries worldwide and stealing approximately $10.71 million from over 7,000 crypto wallets.