Hacks

North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report

North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report

Cyber operatives from North Korea infiltrated the US corporate system to launch a malware campaign aimed at crypto developers, Reuters reported Friday. According to US cybersecurity firm Silent Push, North Korean hackers set up two companies, Blocknovas LLC and Softglide LLC, using fake names and addresses in New Mexico and New York. Meanwhile, a third […]

North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report Read More »

ZKSync reclaims stolen  million tokens after hacker claims bounty offer

ZKSync reclaims stolen $5 million tokens after hacker claims bounty offer

ZKSync confirmed that it had fully recovered approximately $5 million in ZK tokens stolen during a recent breach involving its airdrop distribution contracts after reaching an agreement with the exploiter. The announcement, made on social media on April 23, stated that the hacker returned the funds within a 72-hour “safe harbor” window offered by the

ZKSync reclaims stolen $5 million tokens after hacker claims bounty offer Read More »

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21.  The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to

XRP Ledger developer kit compromised with backdoor to steal wallet private keys Read More »

Accused of Laundering Crypto for Bybit Hackers, Platform Bows Out

Accused of Laundering Crypto for Bybit Hackers, Platform Bows Out

Privacy-focused cryptocurrency exchange eXch has confirmed it will officially terminate all operations effective May 1st, following escalating international scrutiny and mounting allegations of its role in laundering funds linked to the February Bybit hack. According to the team, the move comes after internal consensus among its leadership to “cease and retreat” rather than continue under

Accused of Laundering Crypto for Bybit Hackers, Platform Bows Out Read More »

kiloEx recovers .5M after promising attacker 10% bounty

kiloEx recovers $7.5M after promising attacker 10% bounty

Decentralized exchange platform KiloEx revealed that it has recovered the entire $7.5 million stolen from it in a recent exploit. According to an April 18 statement: “We are pleased to announce that we have successful recovery of all stolen funds related to the recent security incident.” The exploit was first flagged by Cyvers, a blockchain

kiloEx recovers $7.5M after promising attacker 10% bounty Read More »

Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds

Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds

Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report. The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered

Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds Read More »

Crypto users targeted in SourceForge malware attack via fake Microsoft Office softwares

Crypto users targeted in SourceForge malware attack via fake Microsoft Office softwares

Cybercriminals are targeting crypto users by exploiting SourceForge, a well-known open-source software platform. According to security experts at Kaspersky, malicious attackers upload fake Microsoft Office installers packed with hidden malware, including crypto miners and clipboard hijackers, to deceive unsuspecting users. They noted that while the SourceForge project pages appear legitimate, the danger lies in their

Crypto users targeted in SourceForge malware attack via fake Microsoft Office softwares Read More »

Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware

Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware

A recent cybersecurity report by Sekoia revealed an evolving threat posed by the Lazarus Group, the notorious North Korea-linked hacking group. It is now leveraging a tactic known as “ClickFix” to target job seekers in the cryptocurrency sector, particularly within centralized finance (CeFi). This approach marks an adaptation of the group’s earlier “Contagious Interview” campaign,

Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware Read More »

North Korean hackers net .5 million profit after WBTC sales

North Korean hackers net $2.5 million profit after WBTC sales

Blockchain intelligence platform SpotOnChain reported that North Korea’s state-backed hacking group, Lazarus, has pocketed over $2.5 million in profit from a recent sale of wrapped Bitcoin (WBTC). On April 3, the group sold 40.78 WBTC for 1,857 ETH, worth roughly $3.51 million. The sale marks a sharp return on their February 2023 investment, when they

North Korean hackers net $2.5 million profit after WBTC sales Read More »

zkLend Hacker Loses .4M to Tornado Cash Scam

zkLend Hacker Loses $5.4M to Tornado Cash Scam

In an ironic twist of fate, the hacker behind February’s $9.57 million exploit on zkLend has allegedly fallen victim to another scam. The suspected criminal claimed in an on-chain message that they lost 2,930 ETH, worth about $5.4 million, while trying to launder the stolen funds through Tornado Cash. The zkLend Hack zkLend also confirmed

zkLend Hacker Loses $5.4M to Tornado Cash Scam Read More »