News linked to both this project and an event.
Odaily reports: Cross-chain swap service Near Intents announced that the $3.8 million in funds stolen in a previous exploit has been fully returned, and the team has closed its investigation. Near Intents General Manager Alex Shevchenko had previously issued a 48-hour return deadline to the attacker, providing Bitcoin, BNB, Ethereum, and Solana addresses.The attacker acknowledged wrongdoing in an on-chain message, stating that all funds had been returned and urging others to report issues through the bug bounty program. The incident stemmed from a vulnerability in the interaction between its Omni deposit and withdrawal layer and the main smart contract. Near Intents had suspended services and promised full compensation to users. (Decrypt)
According to Decrypt, Spanish police arrested a 16-year-old Romanian suspect in Alicante for allegedly serving as an administrator and primary operator of the KillSec ransomware group. The operation is part of "Operation KillSwitch," with law enforcement agencies from across Europe taking control of five of the organization's core servers and its data leak site, and securing at least 110 TB of stolen data.
Odaily News: Spanish police have arrested a 16-year-old Romanian national in Alicante on suspicion of being the administrator and primary operator of the KillSec ransomware group. Europol stated that law enforcement agencies have seized control of the group's servers and leak site, and preserved at least 110 TB of stolen data.The operation involved searches at 8 residences across Spain, Greece, Romania, and the United Kingdom, investigating approximately 1,000 suspected attacks worldwide, of which about 500 have been confirmed successful. Two other suspects in their 20s were arrested in the UK and Romania respectively, while a Dutch national residing in the UK was indicted and arrested in Puerto Rico, awaiting extradition.KillSec has been active since around 2024, often demanding ransoms in cryptocurrency and carrying out double extortion through encrypted servers and threats to publish stolen data. Investigators are tracing the group's proceeds, including cryptocurrency; Europol's European Cybercrime Centre provided cryptocurrency tracing and digital forensics support. (Decrypt)
former UK National Crime Agency (NCA) officer Paul Chowles has been ordered by a court to forfeit £1,810,700, approximately $2.4 million, for stealing 50 bitcoins from a wallet seized during the Silk Road 2.0 investigation. The bitcoins were worth about $77,000 at the time of the theft in 2017.Of those, 30 bitcoins have been recovered, and the forfeiture order accounted for their current total value. Paul Chowles pleaded guilty in 2025 to theft, transfer, and concealment of criminal property, was sentenced to 5 years and 6 months in prison, and was dismissed by the NCA in July of the same year. (Decrypt)
Odaily News: North Korean hacker group WaterPlum obtained funds or credentials from over 7,000 crypto wallets through fake recruitment processes and transferred approximately $10.71 million to North Korea. Between December 2025 and July 2026, the group infected at least 30,000 devices across more than 100 countries.WaterPlum impersonates AI, crypto, or NFT companies and approaches developers through social media, job platforms, and freelance platforms, luring them into downloading malware-laden files under the guise of technical interviews or coding assignments. Targets include web designers, engineers, and professionals in the crypto, blockchain, and Web3 sectors.Japanese law enforcement dismantled a "laptop farm" within the country for the first time, discovering that hundreds of millions of yen in crypto assets had already been transferred overseas. Investigations suggest that WaterPlum and some North Korean remote IT workers both belong to the 313th General Bureau of North Korea's Ministry of Munitions Industry and share IP addresses used to access the laptop farm and job-seeking services. (Decrypt)
Odaily News: On September 21, a white hat actor transferred 40.71 BTC linked to the Coldcard vulnerability in a single transaction valued at approximately $3.31 million. The transaction consolidated funds from 11 addresses and included an OP_RETURN message pointing to the Crypto Recovery Trust.Alex Thorn, head of Galaxy Research, disclosed that the broader consolidation involved a total of 52.37 BTC across multiple clusters of attacker addresses, accounting for approximately 2.8% of the funds tied to the vulnerability. A firmware flaw in Coldcard devices dating back to March 2021 resulted in insufficient mnemonic seed randomness, with the total funds involved peaking at approximately $130 million. (Decrypt)
Visa is closing a checkout loophole supported by crypto payment infrastructure company Crossmint. The loophole previously allowed users purchasing Meme coins with credit cards to have transactions classified under a merchant category code intended for digital media such as e-books, movies, and music.Visa has notified payment processors, including Checkout.com, that it will no longer accept that code for Meme coin transactions, giving processors a grace period to stop the practice, which is expected to end next week. Thereafter, Meme coin purchases must be processed as cryptocurrency transactions and are subject to Visa's corresponding rules.Chase had disputed a Visa transaction that was not flagged as a cryptocurrency transaction, arguing that its merchant category code was incorrect and that it should not have earned credit card rewards. The New York State Attorney General's Office is also aware of and reviewing the matter. (Decrypt)
Odaily reports: Earlier this month, the verified Reddit account of streaming service HBO Max was hijacked by hackers, who deployed 108 malicious ads over approximately 48 hours, tricking Mac and Windows users into executing commands to install infostealer malware.The malware can steal browser credentials, Telegram data, Apple Notes, saved passwords, and crypto wallet recovery phrases, and may also alter wallet addresses in the clipboard. Reddit has suspended the relevant ads and launched a security investigation. The number of infections and crypto asset losses have not yet been confirmed. (Decrypt)
According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.
: The G7 cybersecurity working group stated in its latest report that quantum computing poses both a security threat and an economic threat to public and private institutions, and related organizations should immediately begin migrating to post-quantum cryptography (PQC).The working group noted that the migration process could take several years, as attackers can already collect and store encrypted data today and decrypt it once sufficiently powerful quantum computers emerge. Quantum computing could also break digital signatures, leading to identity theft and exposing companies and their supply chains.The report did not mention cryptocurrencies, but similar public-key cryptography is used for blockchain wallets and transaction authorization. Current quantum computers are not yet capable of breaking Bitcoin's cryptography, but developers are considering post-quantum solutions such as BIP-360.Ethereum researchers plan to replace multiple cryptographic components used by accounts, validators, and applications. The Solana Foundation has tested post-quantum signatures on its testnet and launched an optional hash-based vault. The G7 working group also urged governments to support related research, public-private cooperation, and national PQC strategies. (Decrypt)
According to Decrypt, privacy-focused Bitcoin wallet Sparrow Wallet released version 2.5.4 on August 28. Developer Craig Raw stated that the update was driven by an AI-assisted code review, with the majority of fixes originating from it. This review was prompted by the recent seed generation code vulnerability exploit affecting Coldcard, as well as the release of unrestricted AI models in China, which has significantly enhanced vulnerability scanning capabilities across large codebases. Key updates include: validating the authenticity of transactions returned by Electrum servers, enforcing stricter BitBox02 hardware wallet security requirements (firmware v9.4.0 or higher required), patching local DNS leaks, and masking sensitive credentials in debug logs. Raw noted that there are no indications of any exploits being leveraged, user funds remain secure, and he still advises all users to update at their earliest convenience.
Odaily News reported that Galaxy Research tracking found that 6 bitcoin wallets, dormant since 2011, 2012, and 2014, transferred a total of 553.59 BTC between August 16 and 26, valued at $40.15 million at the time of transfer. Two of the wallets carry the "Salomon Client Dusted" tag linked to a New York lawsuit involving Noah Doe.One of the transfers involved 40 BTC from a wallet dormant since May 28, 2012, with the funds moved on August 26 to German crypto custodian bank Boerse Stuttgart Digital. Calculated at a cost of approximately $5, the funds appreciated by roughly 1,535,911%.The remaining transfers included 212 BTC, 150 BTC, and 132.31 BTC, originating from wallets inactive since 2012, 2014, and 2011, respectively. The Noah Doe lawsuit seeks to declare 39,069 dormant bitcoin addresses in New York State as lost property. Additionally, several long-term holding addresses moved funds following the July Coldcard hardware wallet vulnerability incident. (Decrypt)
Odaily News - Digital asset manager Grayscale's Zcash ETF began trading on NYSE Arca on Tuesday under the ticker ZCSH. The product is the world's first exchange-traded product offering spot exposure to Zcash, allowing investors to track ZEC prices through securities accounts without needing to directly purchase or store the token.ZCSH was formerly known as the Grayscale Zcash Trust, established in October 2017 through a private placement. Grayscale filed an application with the U.S. Securities and Exchange Commission in November 2025 to convert the trust into an ETF, with shareholders holding shares that track the fund's ZEC holdings rather than holding ZEC directly.In May of this year, security researcher Taylor Hornby, using Anthropic's Claude Opus 4.8, discovered a vulnerability in Zcash's Orchard shielded pool that had existed for four years, which could potentially allow attackers to mint counterfeit ZEC. Developers deployed an emergency patch on June 1, but due to privacy mechanisms, it was not possible to cryptographically confirm whether the vulnerability had been exploited.Zcash activated the Ironwood upgrade in July, replacing Orchard with a new shielded pool and introducing accounting rules that limit the amount of ZEC exiting the old shielded pool to no more than the amount entering. Grayscale stated it will monitor the adoption of the Ironwood upgrade, network security, exchange support, and regulatory conditions for privacy assets. (Decrypt)
Odaily News CME Group Chairman Terry Duffy, the operator of the world's largest futures exchange, and Luana Lopes Lara, co-founder of prediction market platform Kalshi, clashed verbally during a U.S. Commodity Futures Trading Commission (CFTC) roundtable in Washington. Duffy questioned whether prediction markets face the same regulatory scrutiny as established exchanges and noted that certain contracts could be subject to manipulation.Terry Duffy stated that CME Group is not a "barker at the circus" and mocked some contracts offered by Kalshi, including the Nathan's Hot Dog Eating Contest contract. Luana Lopes Lara responded that traditional markets and exchanges carry risks as well and that regulators are responsible for identifying and addressing such issues. DraftKings CEO Jason Robins subsequently called on both sides to stop attacking each other's business models.The dispute comes amid ongoing disagreements between federal regulators and states over the regulatory authority of prediction markets, with the central question being whether contracts involving sports, elections, and other real-world events are federally regulated derivatives or gambling products subject to state law. Last week, a Washington state judge ordered Kalshi to stop offering certain contracts. Two days ago, the CFTC instructed Kalshi to continue trading, pushing back against New York state's efforts to block its contracts. (Decrypt)
Odaily News: Cybersecurity firm Check Point Research has discovered that the StopAndProtect ransomware operation has been using nearly 2,000 compromised WordPress websites to spread malware, steal data, monitor victims, and deploy ransomware. The operation was first identified in mid-May.As of July 24, the operation had compromised more than 6,000 unique IP addresses, with 1,852 in the United States, and 630 each in Russia and India. The compromised websites were also used to host malware, relay commands, and store stolen files, screenshots, and activity logs.Attackers lured Windows users into running PowerShell commands through fake CAPTCHA prompts, enabling them to steal credentials and cryptocurrency wallet seed phrases, and spread further across networks and USB devices. Researchers collected more than 31,000 screenshots and over 700 compressed data archives, and believe the attackers may have accidentally infected themselves at some point. (Decrypt)
Odaily News, Cybersecurity firm Malwarebytes has discovered that multiple fake cryptocurrency anti-money laundering (AML) detection websites are impersonating legitimate services such as AMLBot, tricking users into connecting their wallets and authorizing transactions. Legitimate AML checks only require a wallet's public address—there is no need to connect a wallet, approve permissions, or sign transactions.These websites simulate the service process through fake progress prompts and detection results. One of the sites even asks users to deposit a small amount of funds to pay so-called detection fees, after which it displays a "clean, low-risk" result regardless of whether a real check was completed. Connecting a wallet does not directly lead to asset theft, but it does expose the address and asset information, making it easier for scammers to craft transactions for users to approve.Malwarebytes noted that similar scams use the same design and process, only changing the names and logos. Users who have approved suspicious token permissions should revoke those permissions; users who have entered their mnemonic phrases or private keys should treat their wallets as compromised and transfer assets to a new wallet. (Decrypt)
According to Decrypt, cybersecurity company Bitdefender has issued a warning that malware disguised as HD pirated copies of the movie "Odyssey" has spread rapidly within days of the film's release. These files are disguised as normal torrent files with naming conventions such as WEBRip and Blu-ray, but are actually Windows executable programs that automatically install the Lumma Stealer information-stealing trojan upon execution. Lumma Stealer can steal browser passwords, payment information, autofill data, remote desktop credentials, and cryptocurrency wallets, and can also steal authentication cookies; even if the target account has two-factor authentication (MFA) enabled, it is not spared. Attackers also deliberately disguised the malicious file icons to resemble the VLC player, exploiting Windows' default feature of hiding extensions to deceive users.
据 Decrypt 报道,荷兰国家网络安全中心(NCSC)发出警告,攻击者正在积极利用 macOS 屏幕共享功能中的一个身份验证漏洞(CVE-2026-65400,严重性评分 7.1),对将 5900 端口暴露于公网的 Mac 设备发起攻击,成功获取 root 权限后植入门罗币挖矿程序。
Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)
Odaily News – Cybersecurity firm Bitdefender has reported that, days after the theatrical release of *The Odyssey*, pirated files disguised as HD WEBRips and Blu-ray rips have begun circulating. These files are actually executables that infect Windows devices upon execution and carry the information-stealing malware Lumma Stealer. Attackers disguise the malware using icons that mimic VLC Media Player or video files. Lumma Stealer can harvest browser passwords, payment information, autofill data, remote desktop credentials, and cryptocurrency wallets, as well as steal authentication cookies, potentially compromising accounts even when multi-factor authentication is enabled. Bitdefender states that its products have blocked related downloads and flagged the command-and-control domains associated with this campaign, which bears strong similarities to an operation in 2025 that distributed the same malware disguised as files for *Mission: Impossible – The Final Reckoning*. (Decrypt)