News linked to both this project and an event.
Odaily News: On-chain detective ZachXBT posted on X that he once posed as a client to infiltrate a criminal group suspected of laundering money for the North Korea-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack.ZachXBT stated that after Bybit suffered a $1.5 billion attack in February 2025, he discovered that more than 15 accounts in public Telegram and Discord groups were seeking help processing transactions related to the stolen funds. He subsequently contacted one of the Telegram users using the alias "Jimmy Green" and built trust through multiple transactions. According to his disclosure, on March 6, 2025, he transferred $3.497 million in USDC to an Ethereum address for a USDC-to-TRON-chain USDT exchange transaction with the counterparty. The source of gas funds for that address can be traced back to the Bybit attack funds and was publicly flagged as a Bybit attack blacklisted address.ZachXBT said that in subsequent communications, the counterparty revealed that their team had been involved in processing the stolen Bybit funds and disclosed in advance that the funds would be moved across chains including Solana. By matching transaction timing, amounts, and on-chain data, he identified a wallet cluster involving more than $12 million in Bybit attack funds, with fund paths spanning multiple networks including BTC→ETH→SOL→TRON. Approximately 442,000 USDT was frozen by Tether, and the group also attempted to launder money through Uniswap liquidity pools and low-liquidity tokens. Additionally, the counterparty disclosed having helped other clients process approximately $3 million in fraudulent proceeds, and ZachXBT traced the related funds to wallets associated with the sanctioned Huione Guarantee.ZachXBT revealed that in this investigation, he initially invested $3.497 million and bore a loss risk of approximately 5% per transaction. The intelligence ultimately obtained was provided to relevant investigative agencies and law enforcement authorities at the earliest opportunity. Since 2022, he has assisted in freezing over $75 million in funds related to North Korea-linked incidents.
On-chain investigator ZachXBT disclosed that illicit actors assisting a suspected North Korean hacker group with money laundering are currently publicly seeking order processing support on the Discord public servers and Telegram channels of relevant service platforms. The laundered funds originate from the $387 million security breach previously suffered by Bitget.
据布鲁克林地区检察官 Eric Gonzalez 宣布,布鲁克林男子 Ronald Spektor(23 岁)因实施大规模 Coinbase 网络钓鱼诈骗,于 2026年 9月 23 日被布鲁克林最高法院判处 4至 12 年有期徒刑。 Spektor 冒充 Coinbase 客服代表,以"账户遭黑客攻击"为由,诱骗全美约 100 名用户将加密资产转入其控制的钱包,累计盗窃金额约 1594.4 万美元。被盗资产随后经多个加密交易所反复兑换洗钱,最终流向赌博平台、礼品卡及数字资产购买渠道。 Spektor 在 Telegram 频道"Blockchain enemies"中以 @lolimfeelingevil 为昵称公开炫耀犯罪所得,并招募他人协助实施社会工程攻击。调查人员通过区块链分析、数字取证及多项搜查令,将其家庭 IP 地址与多个被盗钱包关联,最终锁定其身份。 Spektor 已就全部 31 项指控认罪,包括一级洗钱罪、一级重大盗窃罪等,并被命令没收逾 50 万美元资产,同时赔偿受害者近 1600 万美元。
Odaily reports: Earlier this month, the verified Reddit account of streaming service HBO Max was hijacked by hackers, who deployed 108 malicious ads over approximately 48 hours, tricking Mac and Windows users into executing commands to install infostealer malware.The malware can steal browser credentials, Telegram data, Apple Notes, saved passwords, and crypto wallet recovery phrases, and may also alter wallet addresses in the clipboard. Reddit has suspended the relevant ads and launched a security investigation. The number of infections and crypto asset losses have not yet been confirmed. (Decrypt)
Odaily News: In an operation targeting the Telegram crypto escrow trading platform Xinbi Guarantee, the U.S. Department of Justice's Scam Center Strike Force restricted the handling of approximately $52 million in fraud-related cryptocurrency in a single day, bringing the cumulative total to approximately $938 million. Previously, the cumulative amount frozen, seized, or recovered had already exceeded $580 million.The U.S. Department of the Treasury stated that since its founding around 2022, Xinbi Guarantee has processed over $24 billion in transactions, involving digital assets and fiat currency, primarily serving Southeast Asian transactions. North Korean hackers and sanctioned entities are alleged to have used the platform, including entities under Jin Bei Group and Prince Group.A U.S. federal court approved the seizure on September 7 of the Telegram channel operated by Xinbi Guarantee. Law enforcement authorities also seized two payment wallets totaling approximately $12 million and applied to freeze another 47 cryptocurrency wallets suspected of being used for money laundering or associated with fraud-related service providers.The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) added Xinbi Guarantee and its two supporting companies, Safew Technology and Anwen Technology, to its sanctions list on September 9. The U.S. Department of Justice also dispatched investigators to Madagascar to assist local law enforcement in cracking down on 13 scam compounds operated by Chinese nationals and to process over 3,200 electronic devices. (Bitcoin.com News)
Odaily News On-chain analyst SomaXBT stated on the X platform that suspected Lootbot users have experienced a collective wallet theft incident, with losses now exceeding $600,000 (approximately 245 ETH). Preliminary information shows that about 50% of the victims are Lootbot subscribers.It is worth noting that Lootbot is one of the projects founded by dexter, the founder of gm.ai, a project previously involved in a soft rug pull. Lootbot was originally a trading bot platform within the Telegram ecosystem.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Odaily News: According to on-chain detective Specter's monitoring, the victim claimed that due to a Coldcard hack, funds were transferred from Bitcoin to Ethereum. However, on-chain data shows that the 73 BTC ($4.6 million) originally came from the Whirlpool coin mixer two weeks ago, with some of it bridged to Ethereum and subsequently deposited through a phishing Tornado Cash interface. Two coin mixers were used during the fund transfer process. The individual was also found to have appeared in Telegram groups involving private key searches and brute-force attacks. On-chain detective Specter stated that the victim may be a threat actor, and their funds may have been stolen by another threat actor.
Odaily News: Peer-to-peer cryptocurrency trading platform NoOnes announced that it will begin gradually winding down operations after running for over three years. The company stated that it had been continuously seeking to resolve and lift the sanctions imposed on NoOnes, but ultimately failed. The sanctions caused the platform to lose key partners, and blockchain monitoring firms also flagged transactions associated with NoOnes as high-risk, making it increasingly difficult for the platform to continue normal operations. According to the plan, the business contraction began on August 17, and the P2P marketplace will close at 23:59 UTC on August 21. Services such as Swap, NoOnes Visa, fiat withdrawals, the gift card store, and the Bitcoin Lightning Network will also be discontinued progressively. After that, the platform will only support withdrawals, and users will still be able to log in, view balances, and withdraw remaining assets. The company advises users to complete asset withdrawals as soon as possible, no later than August 23. Previously, on January 26, 2025, NoOnes revealed that the platform had suffered a major security breach earlier that month, resulting in losses of approximately $8 million in crypto assets. CEO Ray Youssef confirmed the news after on-chain detective ZachXBT disclosed the hacking incident on his Telegram channel.
: Bitcoin News posted on the X platform stating that a security analysis revealed a repository distributed on GitHub, disguised as a proof-of-concept tool for a COLDCARD random number generator, is malicious in nature. The software claims to be a research tool that reproduces a flawed wallet random number generator to help recover Bitcoin wallets created with vulnerable seeds. According to the report, the tool contains a remote code execution backdoor that downloads an information-stealing program capable of collecting wallet mnemonic phrases, private keys, browser passwords, SSH keys, and other credentials, exfiltrating the data via Telegram while installing persistent malware on Windows, macOS, and Linux. Researchers stated that any user who has executed the code should treat the affected device as fully compromised, rotate credentials, transfer crypto assets to a newly generated wallet, and report the repository. The analysis also warned against running proof-of-concept code for vulnerabilities on devices containing wallets or sensitive data without independent verification.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
Telegram founder and CEO Pavel Durov stated that Telegram was briefly removed from the App Store by Apple recently, after a user implanted illegal pornographic content in a public group. The app was restored within hours.Durov said the attacker exploited a technical vulnerability to insert AI-modified illegal content into old messages within active groups, hiding the content by editing historical messages, making it difficult for regular group members to detect and report in time. This type of attack constitutes "takedown extortion," where attackers use automated accounts to implant violative content in public groups and report it to platforms like Apple, attempting to force group administrators to pay a ransom, or else exploit platform rules to get the community banned.Durov added that Telegram continuously combats illegal content through mechanisms such as user reports, AI filtering, and content hashing. This incident is not a systemic issue with the platform, but rather a targeted attack exploiting rule loopholes. He also warned that Apple's removal of the app without prior contact with Telegram could pose a risk to all mobile applications offering user-generated content (UGC), and platform developers need to strengthen their defenses against malicious reporting and "takedown attacks."
Odaily News: In the Coldcard security incident involving hardware wallet company Coinkite, the amount of stolen bitcoin has risen to approximately 1,359.882 BTC. According to statistics from the Coldcard Sweep Watch dashboard, most of the identified bitcoin remains in a small number of addresses controlled by the attacker. On August 1, one of the attacker's holding addresses received a transaction containing an OP_RETURN message. The message publicly offered a 10% fee for "washing" bitcoin, KYC assistance, and withdrawal services for stolen funds, along with a Telegram contact. Coinkite has released an urgent firmware update to fix the weak random number generation issue that caused the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot fix seeds already generated on affected versions. Some users have reported that after installing the update, their devices remain stuck on an error screen, fail to boot, or appear bricked. This mainly affects Mk4 and Q devices, though some Mk3 users have also reported similar issues. As of August 2, Coinkite has not publicly confirmed a widespread firmware defect.
Odaily news "On-chain detective" ZachXBT posted in his personal channel, stating that Telegram continues to allow scam advertisements to be displayed to subscribers in his channel, impacting user experience and posing potential security risks.ZachXBT stated that if users are Telegram Premium members and wish to support upgrading his channel, they can help it reach the required level by using the channel's Boost function, thereby unlocking the ability to disable ads. Currently, the channel needs to reach Level 50 to enable the ad-disabling option.ZachXBT has long focused on scams, hacker attacks, and on-chain fund tracking within the crypto industry, and has repeatedly exposed incidents involving phishing attacks, fake projects, and fund theft.This time, he raised concerns about Telegram's advertising mechanism, arguing that the platform allowing scam advertisements to appear in crypto community channels may increase the risk of users encountering malicious links and fraudulent activities.
security researchers have discovered an information-stealing malware targeting MacOS devices that is attacking crypto users. It can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Affected wallets and applications include: Exodus, Atomic, Electrum, Wasabi, Monero, and others.Security experts advise that users with potentially infected devices should immediately treat them as "untrusted devices," terminate all active Telegram sessions, and change both their Telegram two-factor authentication password and desktop app password. Additionally, users should not enter seed phrases, private keys, or wallet passwords on the infected device, and should generate a new wallet and migrate their assets. (FinanceFeeds)
According to Cryptopolitan, the North Korea–linked hacker group Lazarus Group has been found deploying the fileless remote access Trojan RemotePE, primarily targeting banks, cryptocurrency exchanges, and fintech companies. This malware runs entirely in memory and employs process hollowing, anti-analysis detection techniques, and encrypted C2 communications—making it difficult for traditional antivirus and forensic tools to detect. The report states that attacks typically begin with Telegram-based social engineering: attackers impersonate employees of trading firms and lure victims into installing malicious software using forged Calendly and Picktime links, ultimately executing the payload without touching the file system.
on-chain detective ZachXBT has exposed US threat actor Dritan Kapllani Jr., alleging his involvement in social engineering thefts targeting crypto users, totaling approximately $19 million.ZachXBT stated that Dritan has long been flaunting luxury cars,名牌 watches, private jets, and nightclub lifestyles on social media. On April 23, 2026, during a "Band 4 Band (B4B)" voice call on Discord, in an attempt to prove he was wealthier than another hacker, he publicly displayed an Exodus wallet containing $3.68 million in assets.The relevant ETH address is: 0x4487db847db2fc99372a985743a26f46e0b2bba6ZachXBT's tracking revealed that this address is linked to a social engineering theft incident on March 14, 2026, involving 185 BTC (approximately $13 million). The following day, Dritan's Exodus wallet received about $5.3 million from that theft. By the time of the B4B call six weeks later, approximately $1.6 million had already been spent or laundered.On May 11, the US Department of Justice unsealed a criminal indictment against Trenton Johnson, charging him with participation in the theft of 185 BTC. He faces a potential maximum sentence of 40 years in prison. The indictment refers to "Co-Conspirator 1 (CC-1)," believed to be Dritan, who has not yet been formally charged.ZachXBT also noted that Dritan is connected to hacker John Daghita (Lick), who was previously arrested for stealing $46 million from the US government. John had previously exposed Dritan's old wallet address on Telegram. On-chain analysis shows that this address is linked to multiple high-confidence social engineering thefts in 2025, with a cumulative total exceeding $5.85 million.ZachXBT stated that Dritan has long been active in the "The Com" hacker circle and had seemingly avoided formal prosecution due to being a minor. Now that he has turned 18, his "borrowed time may finally be over."
According to SlowMist, its security monitoring system MistEye has detected a counterfeit TronLink Chrome MV3 extension targeting TRON wallet users with a two-layer phishing attack. The extension disguises itself as the official plugin using Unicode obfuscation and brand spoofing. Upon installation, it first loads a remote iframe-based pop-up page designed to trick users into entering their mnemonic phrases, private keys, keystore files, and passwords—then exfiltrates this sensitive data via same-origin APIs to a Telegram bot. The malicious infrastructure involved includes the domains tronfind-api[.]tronfindexplorer[.]com and trx-scan-explorer[.]org; the malicious extension ID is ekjidonhjmneoompmjbjofpjmhklpjdd. SlowMist advises users to immediately uninstall the extension. If sensitive information has already been submitted, users should promptly migrate their assets and discontinue use of the compromised wallet.
Bybit’s Security Operations Center has identified a multi-stage malware campaign targeting macOS users of Claude Code, an AI-powered search and development tool. Attackers used search engine optimization (SEO) poisoning to push malicious domains to the top of Google search results, luring users to counterfeit installation pages. Once installed, the malware steals browser credentials, macOS Keychain data, Telegram sessions, VPN configurations, and cryptocurrency wallet information. Bybit stated that the malware can also establish persistent access via backdoor functionality and attempts to target over 250 browser wallet extensions and multiple desktop wallet applications. This malicious infrastructure was identified on March 12, and related analysis, mitigation, and detection measures were completed the same day.
Odaily News Telegram founder Pavel Durov posted on X, stating that the "age verification app" proposed by the EU has design flaws and was compromised in just a few minutes. The reason lies in the fundamental security issues of its architecture that trusts user devices. The solution is positioned as "privacy-friendly," but it can actually be easily cracked. Its development path is summarized as follows: first, launch a system that appears to protect privacy but has vulnerabilities; after being compromised, use "fixes" as a reason to weaken privacy protection, eventually evolving into a surveillance tool in the name of privacy. Such "accidental vulnerability incidents" may be used to expand regulation, and the public is urged to stay vigilant.