News linked to both this project and an event.
Odaily News: According to on-chain detective Specter's monitoring, the victim claimed that due to a Coldcard hack, funds were transferred from Bitcoin to Ethereum. However, on-chain data shows that the 73 BTC ($4.6 million) originally came from the Whirlpool coin mixer two weeks ago, with some of it bridged to Ethereum and subsequently deposited through a phishing Tornado Cash interface. Two coin mixers were used during the fund transfer process. The individual was also found to have appeared in Telegram groups involving private key searches and brute-force attacks. On-chain detective Specter stated that the victim may be a threat actor, and their funds may have been stolen by another threat actor.
Odaily News: Peer-to-peer cryptocurrency trading platform NoOnes announced that it will begin gradually winding down operations after running for over three years. The company stated that it had been continuously seeking to resolve and lift the sanctions imposed on NoOnes, but ultimately failed. The sanctions caused the platform to lose key partners, and blockchain monitoring firms also flagged transactions associated with NoOnes as high-risk, making it increasingly difficult for the platform to continue normal operations. According to the plan, the business contraction began on August 17, and the P2P marketplace will close at 23:59 UTC on August 21. Services such as Swap, NoOnes Visa, fiat withdrawals, the gift card store, and the Bitcoin Lightning Network will also be discontinued progressively. After that, the platform will only support withdrawals, and users will still be able to log in, view balances, and withdraw remaining assets. The company advises users to complete asset withdrawals as soon as possible, no later than August 23. Previously, on January 26, 2025, NoOnes revealed that the platform had suffered a major security breach earlier that month, resulting in losses of approximately $8 million in crypto assets. CEO Ray Youssef confirmed the news after on-chain detective ZachXBT disclosed the hacking incident on his Telegram channel.
: Bitcoin News posted on the X platform stating that a security analysis revealed a repository distributed on GitHub, disguised as a proof-of-concept tool for a COLDCARD random number generator, is malicious in nature. The software claims to be a research tool that reproduces a flawed wallet random number generator to help recover Bitcoin wallets created with vulnerable seeds. According to the report, the tool contains a remote code execution backdoor that downloads an information-stealing program capable of collecting wallet mnemonic phrases, private keys, browser passwords, SSH keys, and other credentials, exfiltrating the data via Telegram while installing persistent malware on Windows, macOS, and Linux. Researchers stated that any user who has executed the code should treat the affected device as fully compromised, rotate credentials, transfer crypto assets to a newly generated wallet, and report the repository. The analysis also warned against running proof-of-concept code for vulnerabilities on devices containing wallets or sensitive data without independent verification.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Telegram founder and CEO Pavel Durov stated that Telegram was briefly removed from the App Store by Apple recently, after a user implanted illegal pornographic content in a public group. The app was restored within hours.Durov said the attacker exploited a technical vulnerability to insert AI-modified illegal content into old messages within active groups, hiding the content by editing historical messages, making it difficult for regular group members to detect and report in time. This type of attack constitutes "takedown extortion," where attackers use automated accounts to implant violative content in public groups and report it to platforms like Apple, attempting to force group administrators to pay a ransom, or else exploit platform rules to get the community banned.Durov added that Telegram continuously combats illegal content through mechanisms such as user reports, AI filtering, and content hashing. This incident is not a systemic issue with the platform, but rather a targeted attack exploiting rule loopholes. He also warned that Apple's removal of the app without prior contact with Telegram could pose a risk to all mobile applications offering user-generated content (UGC), and platform developers need to strengthen their defenses against malicious reporting and "takedown attacks."
Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.
Odaily news "On-chain detective" ZachXBT posted in his personal channel, stating that Telegram continues to allow scam advertisements to be displayed to subscribers in his channel, impacting user experience and posing potential security risks.ZachXBT stated that if users are Telegram Premium members and wish to support upgrading his channel, they can help it reach the required level by using the channel's Boost function, thereby unlocking the ability to disable ads. Currently, the channel needs to reach Level 50 to enable the ad-disabling option.ZachXBT has long focused on scams, hacker attacks, and on-chain fund tracking within the crypto industry, and has repeatedly exposed incidents involving phishing attacks, fake projects, and fund theft.This time, he raised concerns about Telegram's advertising mechanism, arguing that the platform allowing scam advertisements to appear in crypto community channels may increase the risk of users encountering malicious links and fraudulent activities.
security researchers have discovered an information-stealing malware targeting MacOS devices that is attacking crypto users. It can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Affected wallets and applications include: Exodus, Atomic, Electrum, Wasabi, Monero, and others.Security experts advise that users with potentially infected devices should immediately treat them as "untrusted devices," terminate all active Telegram sessions, and change both their Telegram two-factor authentication password and desktop app password. Additionally, users should not enter seed phrases, private keys, or wallet passwords on the infected device, and should generate a new wallet and migrate their assets. (FinanceFeeds)
According to Cryptopolitan, the North Korea–linked hacker group Lazarus Group has been found deploying the fileless remote access Trojan RemotePE, primarily targeting banks, cryptocurrency exchanges, and fintech companies. This malware runs entirely in memory and employs process hollowing, anti-analysis detection techniques, and encrypted C2 communications—making it difficult for traditional antivirus and forensic tools to detect. The report states that attacks typically begin with Telegram-based social engineering: attackers impersonate employees of trading firms and lure victims into installing malicious software using forged Calendly and Picktime links, ultimately executing the payload without touching the file system.
on-chain detective ZachXBT has exposed US threat actor Dritan Kapllani Jr., alleging his involvement in social engineering thefts targeting crypto users, totaling approximately $19 million.ZachXBT stated that Dritan has long been flaunting luxury cars,名牌 watches, private jets, and nightclub lifestyles on social media. On April 23, 2026, during a "Band 4 Band (B4B)" voice call on Discord, in an attempt to prove he was wealthier than another hacker, he publicly displayed an Exodus wallet containing $3.68 million in assets.The relevant ETH address is: 0x4487db847db2fc99372a985743a26f46e0b2bba6ZachXBT's tracking revealed that this address is linked to a social engineering theft incident on March 14, 2026, involving 185 BTC (approximately $13 million). The following day, Dritan's Exodus wallet received about $5.3 million from that theft. By the time of the B4B call six weeks later, approximately $1.6 million had already been spent or laundered.On May 11, the US Department of Justice unsealed a criminal indictment against Trenton Johnson, charging him with participation in the theft of 185 BTC. He faces a potential maximum sentence of 40 years in prison. The indictment refers to "Co-Conspirator 1 (CC-1)," believed to be Dritan, who has not yet been formally charged.ZachXBT also noted that Dritan is connected to hacker John Daghita (Lick), who was previously arrested for stealing $46 million from the US government. John had previously exposed Dritan's old wallet address on Telegram. On-chain analysis shows that this address is linked to multiple high-confidence social engineering thefts in 2025, with a cumulative total exceeding $5.85 million.ZachXBT stated that Dritan has long been active in the "The Com" hacker circle and had seemingly avoided formal prosecution due to being a minor. Now that he has turned 18, his "borrowed time may finally be over."
According to SlowMist, its security monitoring system MistEye has detected a counterfeit TronLink Chrome MV3 extension targeting TRON wallet users with a two-layer phishing attack. The extension disguises itself as the official plugin using Unicode obfuscation and brand spoofing. Upon installation, it first loads a remote iframe-based pop-up page designed to trick users into entering their mnemonic phrases, private keys, keystore files, and passwords—then exfiltrates this sensitive data via same-origin APIs to a Telegram bot. The malicious infrastructure involved includes the domains tronfind-api[.]tronfindexplorer[.]com and trx-scan-explorer[.]org; the malicious extension ID is ekjidonhjmneoompmjbjofpjmhklpjdd. SlowMist advises users to immediately uninstall the extension. If sensitive information has already been submitted, users should promptly migrate their assets and discontinue use of the compromised wallet.
Bybit’s Security Operations Center has identified a multi-stage malware campaign targeting macOS users of Claude Code, an AI-powered search and development tool. Attackers used search engine optimization (SEO) poisoning to push malicious domains to the top of Google search results, luring users to counterfeit installation pages. Once installed, the malware steals browser credentials, macOS Keychain data, Telegram sessions, VPN configurations, and cryptocurrency wallet information. Bybit stated that the malware can also establish persistent access via backdoor functionality and attempts to target over 250 browser wallet extensions and multiple desktop wallet applications. This malicious infrastructure was identified on March 12, and related analysis, mitigation, and detection measures were completed the same day.
Odaily News Telegram founder Pavel Durov posted on X, stating that the "age verification app" proposed by the EU has design flaws and was compromised in just a few minutes. The reason lies in the fundamental security issues of its architecture that trusts user devices. The solution is positioned as "privacy-friendly," but it can actually be easily cracked. Its development path is summarized as follows: first, launch a system that appears to protect privacy but has vulnerabilities; after being compromised, use "fixes" as a reason to weaken privacy protection, eventually evolving into a surveillance tool in the name of privacy. Such "accidental vulnerability incidents" may be used to expand regulation, and the public is urged to stay vigilant.
According to Elastic Security Labs, threat actors impersonated venture capital firms and lured targets into opening malicious Obsidian note vaults via LinkedIn and Telegram. This attack leveraged Obsidian’s Shell Commands plugin to execute malicious payloads without exploiting any vulnerabilities when victims opened the note vaults. The PHANTOMPULSE malware discovered in this campaign is a previously undocumented Windows Remote Access Trojan (RAT) that uses Ethereum transaction data to achieve blockchain-based C2 communication. The macOS payload employs an obfuscated AppleScript dropper and uses a Telegram channel as a fallback C2. Elastic Defend detected and blocked the PHANTOMPULSE execution before it could run.
Zerion disclosed that some of its corporate hot wallets were recently targeted by an AI-driven social engineering attack linked to North Korean hackers, resulting in losses of approximately $100,000. Zerion stated that user funds, applications, and infrastructure remain unaffected and proactively disabled its web application to mitigate risk. This incident marks the second such attack this month, following the $280 million breach of Drift Protocol, underscoring how North Korean hackers are leveraging AI to refine social engineering tactics—primarily targeting employees and developers at crypto firms. The Security Alliance (SEAL) tracked the hacker group UNC1069, which conducts low-pressure, multi-week social engineering campaigns across platforms including Telegram, LinkedIn, and Slack, using AI tools to edit images and videos to enhance attack efficiency.