Bitcoin Forum
July 31, 2026, 09:04:15 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 ... 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 [105] 106 »
  Print  
Author Topic: Report Malware and Suspicious Links here so Mods can take Action !  (Read 53323 times)
$crypto$
Legendary
*
Offline

Activity: 3178
Merit: 1255


Smart is not enough, there must be skills


View Profile WWW
July 22, 2026, 12:42:19 PM
 #2081

QSDM is a new project with a Github account created 15 hours ago created a repository and immediately spread on the bitcointalk forum, after the scan results from Virustotal contained Raspberry Robin malware and this was very dangerous.

Account: QuantResistance please ban please ban
Fake ANN: [ANN] (CELL) QSDM - a post-quantum-secure ledger (POW, CPU/GPU)

Adding - - - this thread re-appeared with several different users, 1] on a local Chinese forum, 2] on an Ann altcoin board.

Account: ChrisMesh please ban
Fake ANN: [ANN] QuantumLedger - 抗后量子安全工作量证明(PoW)账本 (CPU+GPU)

Account: PostQuantumM please ban
Fake ANN: [ANN] Quantum-Secure Dynamic Ledger - mineable project (PoW, Nvidia)

The thread has been reported to the moderator!
Github has been reported!

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Charcol
Full Member
***
Offline

Activity: 294
Merit: 239



View Profile
July 22, 2026, 03:28:15 PM
Merited by Lafu (1)
 #2082

User: pravi0007 <-----  Please Ban this User

Fake ANN thread: [ANN] ORIONKAW - KawPow | Fair Launch | GPU Mining | Zero Premine

Fake File:
Code:
https://github.com/ORIONKAW/ORIONKAW/releases/download/v1.0.0/ORIONKAW-v1.0.0.zip

Reference:
https://www.virustotal.com/gui/file/e52e98e6c18950d048bfbc5b4d2816cae2e836d321bb86b19f8b400021135140

$crypto$
Legendary
*
Offline

Activity: 3178
Merit: 1255


Smart is not enough, there must be skills


View Profile WWW
July 23, 2026, 06:39:55 AM
 #2083

Fake thread --- PULSEFORGE (PLF), possibly hacked account

Account: Mukesh268 This user recently woke up from a long period of inactivity. please ban
Fake ANN: [ANN] PULSEFORGE - Welcome to the official thread!

Code:
[size=11pt][color=#9400D3][b] Download from GitHub - [/b][/color][/size] https://github.com/PULSEFORGE-core/PULSEFORGE/releases/download/v1.0.0/PULSEFORGE-v1.0.0-win-x64.zip

Virustotal: https://www.virustotal.com/gui/file/5c7f8462066349d8287a2492f46d3c9b599efe38527c67b2d6b1628567f77821?nocache=1

Reported to Moderator!

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
P2PKH_dude
Copper Member
Newbie
*
Offline

Activity: 10
Merit: 4


View Profile
July 23, 2026, 11:52:56 PM
 #2084

The Wallet files on their GitHub are dangerous and contain a lot of Trojan Malware. 16/69 security vendors flagged this file as malicious

Account: btc-man21M<= Please Banned
Fake ANN Thread: [ANN][BC3][SHA3-256T][POW] BitcoinIII (BC3) - SHA3-256t Bitcoin relaunch
archive

Code:
https://github.com/PinkStarrySky/BitcoinIII-Core/releases

I just compiled the source code from the GitHub repo, and the resulting Windows NSIS installer produces a similar VirusTotal report.

Given that the source code looks clean (as far as I can tell), I'd lean towards this being a false positive.

Nothing is certain in life, but VirusTotal is notorious for producing false positives when it comes to crypto software. I'd suggest also compiling from source to see if you get a similar report.
AakZaki
Legendary
*
Online Online

Activity: 2674
Merit: 2377


Lightning⚡zkNodes


View Profile
July 24, 2026, 07:53:02 PM
Merited by logfiles (1)
 #2085

This file wallet is not secure Microsoft detects trojans, it is really suspicious if the file wallet has a collection - "capture webcam image".
4/70 security vendors flagged this file as malicious
In addition, This user recently woke up from a long period of inactivity

Account: Vistoce<= Please Banned
Fake ANN Thread: [ANN][TESTNET] Helix (HLX) — Blockchain Layer-1 Pasca-Kuantum | Sumber Terbuka (MIT)
archive

Code:
LINKS Code (MIT): https://github.com/silvra-net/helix
https://github.com/silvra-net/helix/releases/tag/v0.7.3


VirusTotal Scan Result: https://www.virustotal.com/gui/file/75c9a517b175edf45eba94c883d351cdad5cb2d4ffa45aed7f0a9e357eed7f56/detection
They come back again with a new account and the same file, according to what I understand about "Sysmon File Executable Creation Detected" is to be able to try new files that can be injected remotely.

While the "Load Of RstrtMgr.DLL" It can also be used for anti-analysis purposes by shutting down certain processes.

Account: SILVRA<= Please Banned
Fake ANN Thread: [ANN] [TESTNET LIVE] HELIX (HLX) — Post-Quantum L1 Blockchain | Free Faucet & Va
archive

Code:
[url=https://github.com/silvra-net/helix/releases][b]DOWNLOAD DESKTOP WALLET[/b][/url]



VirusTotal Scan Result:https://www.virustotal.com/gui/file/5738c2eeaa7fdafc642d7025ea92073362580b5f79ad1e7bc93570bf6b956ec0/behavior

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
logfiles
Copper Member
Legendary
*
Offline

Activity: 2786
Merit: 2376



View Profile WWW
July 24, 2026, 11:48:18 PM
 #2086

I just compiled the source code from the GitHub repo, and the resulting Windows NSIS installer produces a similar VirusTotal report.

Given that the source code looks clean (as far as I can tell), I'd lean towards this being a false positive.

Nothing is certain in life, but VirusTotal is notorious for producing false positives when it comes to crypto software. I'd suggest also compiling from source to see if you get a similar report.
Yes it does but the attempts to spread malware through the forum are quite rampant which is why these folks are doing a good job to clean the forum off malware. False positives can be contested as the reports can never be 100% accurate but most of them at least are. I think I have seen it happen before, but the member hasn't bothered to come around and appeal.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
$crypto$
Legendary
*
Offline

Activity: 3178
Merit: 1255


Smart is not enough, there must be skills


View Profile WWW
July 25, 2026, 06:49:26 PM
 #2087

Fake thread --- KADIKAMA is a fake project, the file from Github download is quite dangerous, while the file from its website does not show virus detection.

Account: kadikama please ban
Fake ANN: [ANN] Kadikama (KAD) | RandomX v2 CPU Mining | No Premine | 150s Blocks

Code:
Kadikama Miner source:
[url=https://github.com/kadikamateam/kadikama-miner]https://github.com/kadikamateam/kadikama-miner/releases/tag/v1.0.0[/url]

Virustotal: https://www.virustotal.com/gui/file/fc5c491163ae4183f16a08473767fd19a8b02b0b2f53757f4edc5f1bdd973024



Reported!

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
kad_crypto
Copper Member
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 25, 2026, 10:28:18 PM
 #2088

Fake thread --- KADIKAMA is a fake project, the file from Github download is quite dangerous, while the file from its website does not show virus detection.

Account: kadikama please ban
Fake ANN: [ANN] Kadikama (KAD) | RandomX v2 CPU Mining | No Premine | 150s Blocks

Code:
Kadikama Miner source:
[url=https://github.com/kadikamateam/kadikama-miner]https://github.com/kadikamateam/kadikama-miner/releases/tag/v1.0.0[/url]

Virustotal: https://www.virustotal.com/gui/file/fc5c491163ae4183f16a08473767fd19a8b02b0b2f53757f4edc5f1bdd973024



Reported!


Hello,

I am the owner of the permanently banned Bitcointalk account "kadikama".

I am writing regarding the malware accusation and the VirusTotal report referenced in this post:

https://bitcointalk.org/index.php?topic=5182222.msg66978675#msg66978675

I have also sent a formal appeal to the email address provided in the ban notice:

banappeals...@bitcointalk.org

I understand why a moderator would treat an antivirus report seriously. However, I would appreciate clarification
about the specific evidence used to conclude that Kadikama Miner is malicious.

Kadikama Miner is openly presented as cryptocurrency-minining software. It is based on the public XMRig source code
and was modified to support the Kadikama rx/kad algorithm and block format. It is not presented as another type of
application, installed silently or distributed without informing users that it performs cryptocurrency mining.

Kadikama Miner source code:
https://github.com/kadikamateam/kadikama-miner

Upstream XMRig source code:
https://github.com/xmrig/xmrig

Mining software is frequently classified as Coin Miner, Riskware or potentially unwanted software because the same
functionality can be abused when installed without the computer owner’s consent. Therefore, the number of VirusTotal
detections alone does not establish that a deliberately downloaded and clearly labelled miner contains malicious
functionality.

Could you please clarify:

1. Which specific VirusTotal detections were considered evidence of malware?
2. Was any malicious behaviour found beyond the expected cryptocurrency-mining functionality?
3. Was the published binary compared with the public source code or independently compiled from it?
4. Is there any evidence of hidden installation, persistence, credential theft, unauthorised mining or unrelated
network activity?

To address the concerns about precompiled binaries, I am prepared to remove all miner download links from the
Bitcointalk announcement. Instead, I can provide only the public source code and detailed instructions allowing users
to compile the miner themselves.

This would allow every user to inspect the code, build the executable independently and verify exactly what is
included in it. If required, I can also provide the compiler version, build configuration, dependency versions, build
logs and SHA-256 checksums.

I hope this proposed solution demonstrates that my intention is to provide transparent mining software rather than
distribute an unverified executable.

I did not intend to distribute malware or mislead forum users. I respectfully request that the evidence be reviewed in
the context of the software’s disclosed purpose and public source code, and that the permanent ban of the "kadikama"
account be reconsidered.

I will not use another account to bypass the ban and am contacting you through the official appeal process.

Thank you.
logfiles
Copper Member
Legendary
*
Offline

Activity: 2786
Merit: 2376



View Profile WWW
July 25, 2026, 11:13:10 PM
Merited by $crypto$ (1)
 #2089

<...>
@$crypto$, firstly you are doing an incredibly good job curbing malware around the forum, but you might want to be very careful reporting detections from most AV vendors on virustotal especially when it has something to do with coinminer, Xmrminer, Bitminer etc. In most cases when you see those tags, they call for more investigations otherwise you might end up putting some genuine folks in the same wagon of malicious guys and that won't really go well for the former.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 06:59:23 AM
Last edit: July 26, 2026, 07:18:46 AM by lightbit
Merited by Mitchell (1), Lafu (1)
 #2090

Suspicious ANN — QUANTUMRIFT claims to be a fully open-source cryptocurrency project, but its GitHub repository contains only a one-line README and no visible wallet or blockchain source code. Despite this, the ANN immediately directs users to download and execute a precompiled Windows wallet ZIP.

Please investigate this thread and the downloadable file before more users install it.

Account: roni rahman

Suspicious ANN: [ANN] QUANTUMRIFT - Welcome to the official thread!

Quote from: roni rahman link=topic=5589437.msg66979957#msg66979957
Windows wallet is already available and ready for download.

Download here - https://github.com/QUANTUMRIFT-dev/QUANTUMRIFT/releases/download/v1.0.0/QUANTUMRIFT-v1.0.0-win-x64.zip

This project is fully open-source and community-oriented.

GitHub repository:
https://github.com/QUANTUMRIFT-dev/QUANTUMRIFT

The repository currently contains only README.md with one line and does not contain the source code required to independently verify or reproduce the distributed wallet binary.

I have not executed the wallet and am not claiming a confirmed malware detection. I am reporting it because distributing an unverifiable binary while claiming that the project is fully open-source presents a serious security risk.

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
Mitchell
Staff
Legendary
*
Offline

Activity: 4718
Merit: 3157


Verified awesomeness ✔


View Profile
July 26, 2026, 08:52:27 AM
Merited by Lafu (1)
 #2091

Definitely malware. I've nuked the account. If you see any topics exactly like this (self-moderated, claiming to be open-source, but no actual code, Windows wallet only, linux "coming soon"), feel free to report it (here or via the Report to moderator button).

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 10:09:49 AM
 #2092

Suspicious ANN — VORTEXIUM claims to be a fully open-source cryptocurrency project, but its GitHub repository contains only a one-line README and no visible wallet or blockchain source code. Despite this, the ANN directs users to download and execute a precompiled Windows wallet ZIP.

Please investigate this thread and the downloadable file before more users install it.

Account: zulu99

Suspicious ANN: [ANN] VORTEXIUM - Welcome to the official thread!

Quote from: zulu99 link=topic=5589449.msg66980257#msg66980257
Windows wallet is already available and ready for download.

Download from GitHub - https://github.com/VORTEXIUM-core/VORTEXIUM/releases/download/v1.0.0/VORTEXIUM-v1.0.0-win-x64.zip

This project is fully open-source and community-oriented.

GitHub repository:
https://github.com/VORTEXIUM-core/VORTEXIUM

The repository currently contains only README.md, consisting of a single line, and does not contain the source code required to independently inspect, verify or reproduce the distributed wallet binary.

I believe this is the same person recreating new threads.

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 10:13:15 AM
 #2093

Definitely malware. I've nuked the account. If you see any topics exactly like this (self-moderated, claiming to be open-source, but no actual code, Windows wallet only, linux "coming soon"), feel free to report it (here or via the Report to moderator button).

Thank you for confirming and nuking the account. I’ll watch for similar self-moderated ANN threads with unverifiable Windows-only wallets and report them here.

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 12:12:40 PM
Last edit: July 26, 2026, 02:43:51 PM by lightbit
 #2094

Another suspicious ANN following the same malware pattern previously confirmed by forum staff: it claims to be open-source, provides no actual source code, distributes a precompiled Windows wallet only, and says the Linux wallet will be released later.

Account: mamali1387

Suspicious ANN: [ANN] VORTHAK - Welcome to the official thread!

Quote from: mamali1387 link=topic=5589462.msg66980623#msg66980623
Open-source codebase with regular security reviews

Windows Wallet: Already released and available for download - https://github.com/Vorthak/Vorthak/releases/download/v1.0.0/VORTHAK-v1.0.0-win-x64.zip

Linux Wallet: Will be released later
macOS wallet — planned for future release

GitHub repository:
https://github.com/Vorthak/Vorthak

The repository currently contains only README.md and no visible blockchain or wallet source code that could be inspected or used to reproduce the distributed executable.

This follows the same pattern previously identified by Mitchell: claiming to be open-source while providing no actual code, distributing a Windows-only binary and promising Linux support later.

Please investigate the download, remove the ANN and take appropriate action against the account.

ANOTHER ANN FROM THIS PERSON BELOW —

Another suspicious ANN following the same malware pattern previously confirmed by forum staff: self-moderated thread, claims to be fully open-source, provides no actual source code, distributes a precompiled Windows wallet only, and says Linux will be released later.

Account: aschain

Suspicious ANN: [ANN] ZENTHOS - Welcome to the official thread!

Quote from: aschain link=topic=5589477.msg66980974#msg66980974
Fully open-source and auditable code.

Windows Wallet: Already released and available for download - https://github.com/ZENTHOS-core/ZENTHOS/releases/download/v1.0.0/ZENTHOS-v1.0.0-win-x64.zip

Linux Wallet: Will be released later.
macOS version planned after Linux release.

GitHub repository:
https://github.com/ZENTHOS-core/ZENTHOS

The repository currently contains only README.md and no visible blockchain or wallet source code that could be inspected, audited or used to reproduce the distributed Windows executable.

This follows the exact pattern identified by Mitchell: a self-moderated ANN claiming to be open-source while providing no actual code, offering a Windows-only wallet and promising Linux support later.

Please investigate the download, remove the ANN and take appropriate action against the account.

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
Charcol
Full Member
***
Offline

Activity: 294
Merit: 239



View Profile
July 26, 2026, 12:15:07 PM
Merited by Lafu (1)
 #2095

User: mamali1387 <-----  Please Ban this User

Fake ANN thread: [ANN] VORTHAK - Welcome to the official thread!

Fake File:
Code:
https://github.com/Vorthak/Vorthak/releases/download/v1.0.0/VORTHAK-v1.0.0-win-x64.zip

Lafu (OP)
Legendary
*
Offline

Activity: 3626
Merit: 4622



View Profile
July 26, 2026, 01:34:57 PM
 #2096

~~~~~
I really appreciate your Help what you are doing  about against all that Malware Fake Shit !
But mayby its possible you can edit your Post that have made on that Day and dont post 3 more New !
If you have some proof of other Fake Anns you can  edit your post that you made today ! Would be nice  Cool
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 02:43:05 PM
Merited by Lafu (1)
 #2097

~~~~~
I really appreciate your Help what you are doing  about against all that Malware Fake Shit !
But mayby its possible you can edit your Post that have made on that Day and dont post 3 more New !
If you have some proof of other Fake Anns you can  edit your post that you made today ! Would be nice  Cool

Aye aye captain! Will do. Posted another fake ANN on my previous message by editing it. Apologies for the mistake, I am new to this.  Wink

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
$crypto$
Legendary
*
Offline

Activity: 3178
Merit: 1255


Smart is not enough, there must be skills


View Profile WWW
July 26, 2026, 03:15:09 PM
 #2098

1. Which specific VirusTotal detections were considered evidence of malware?
XMRig source code is often marked red by virustotal, even considered dangerous malware, but I report here according to the results reported above, plus marked like this.
Code:
The sandbox Zenbox flags this file as: MALWARE EVADER
I refer to this source.
Evader malware is specifically designed to avoid detection by antivirus software and other security measures. It employs techniques such as code obfuscation, encryption, and polymorphism to hide its presence and actions from security systems, making it difficult to detect and remove.

Maybe I'm wrong, I reported as per my knowledge.

@$crypto$, firstly you are doing an incredibly good job curbing malware around the forum, but you might want to be very careful reporting detections from most AV vendors on virustotal especially when it has something to do with coinminer, Xmrminer, Bitminer etc. In most cases when you see those tags, they call for more investigations otherwise you might end up putting some genuine folks in the same wagon of malicious guys and that won't really go well for the former.
Okay, thanks for the input, I may have to pay more attention often, related to the source code you mentioned.
I don't mean to generalize, this is based on virustotal results.

Aye aye captain! Will do. Posted another fake ANN on my previous message by editing it. Apologies for the mistake, I am new to this.  Wink
The link you quote to the file must use the code [ code]  [ /code]
If you don't use the table Code, other people who click the link will automatically download it.
Perhaps you should immediately edit her.

Good work has been reported. Smiley

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
lightbit
Member
**
Offline

Activity: 417
Merit: 84


View Profile WWW
July 26, 2026, 03:43:43 PM
Last edit: July 27, 2026, 05:30:20 AM by lightbit
 #2099

Aye aye captain! Will do. Posted another fake ANN on my previous message by editing it. Apologies for the mistake, I am new to this.  Wink
The link you quote to the file must use the code [ code]  [ /code]
If you don't use the table Code, other people who click the link will automatically download it.
Perhaps you should immediately edit her.

Good work has been reported. Smiley

Understood! I am still learning how things work around here. Thanks for teaching me.  Wink

Reporting Another Fake ANN

Another suspicious ANN following the same pattern previously identified by forum staff: self-moderated thread, claims open-source development, provides no actual source code, distributes a precompiled Windows wallet only, and says the Linux wallet will be released later.

Account: coinpork

Suspicious ANN: [ANN] QUORATH - Welcome to the official thread!

Quote from: coinpork link=topic=5589484.msg66981143#msg66981143
Open-source development with community input.

Windows Wallet: Already released and available for download -
Code:
https://github.com/QUORATH/QUORATH/releases/download/v1.0.0/QUORATH-v1.0.0-win-x64.zip

Linux Wallet: Will be released later.

GitHub repository:
https://github.com/QUORATH/QUORATH

The repository currently contains only README.md, consisting of one line, and no visible blockchain or wallet source code that could be inspected, audited or used to reproduce the distributed Windows executable.

This follows the exact warning pattern described by Mitchell: a self-moderated ANN claiming open-source development while providing no actual code, offering a Windows-only wallet and promising Linux support later.

Please investigate the downloadable file, remove the ANN and take appropriate action against the account.

—————

User: lakmali123 <----- Please Ban this User

Fake ANN thread: [ANN] PYTHRAX - Welcome to the official thread!

Fake File:
Quote from: lakmali123 link=topic=5589540.msg66983005#msg66983005
Code:
https://github.com/PYTHRAX/PYTHRAX/releases/download/v1.0.0/PYTHRAX-v1.0.0-win-x64.zip

CHAINQUIRY — Discover, Research & Verify Crypto Projects
Free Project Listings | Official Thread
kad_crypto
Copper Member
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 26, 2026, 07:38:38 PM
 #2100

1. Which specific VirusTotal detections were considered evidence of malware?
XMRIG source code is often marked red by virustotal, even considered dangerous malware, but I report here according to the results reported above, plus marked like this.
Code:
The sandbox Zenbox flags this file as: MALWARE EVADER
I refer to this source.
Evader malware is specifically designed to avoid detection by antivirus software and other security measures. It employs techniques such as code obfuscation, encryption, and polymorphism to hide its presence and actions from security systems, making it difficult to detect and remove.

Maybe I'm wrong, I reported as per my knowledge.




Thank you for explaining. I understand that you submitted the report in good faith based on the information
available to you. However, after checking the evidence, I do not believe that the Zenbox label alone is sufficient
to establish that Kadikama Miner contains malware.

The following SHA-256 belongs to the official Xmrig 6.26.0 Windows x64 archive:

bba8097cb37d9b458a1cb1137876b27cde6740d17fe4ccbc086ba07d87d9e147

Official XMRig release:

https://github.com/xmrig/xmrig/releases/tag/v6.26.0

VirusTotal behavior report:

https://www.virustotal.com/gui/file/bba8097cb37d9b458a1cb1137876b27cde6740d17fe4ccbc086ba07d87d9e147/behavior

This is not an unknown third-party XMRIG build: the exact hash is published in the official release’s SHA256,
which is also accompanied by a GPG signature. Nevertheless, Zenbox assigns the same MALWARE EVADER classification to
it.

The Xygeni page you quoted provides a general definition of evader malware. It does not demonstrate that Kadikama
Miner contains obfuscation, polymorphism, credential theft, persistence, an additional payload or any other specific
malicious functionality.

This comparison does not prove by itself that the Kadikama binary is safe. It does, however, demonstrate that the
Zenbox label is not unique to Kadikama Miner and cannot by itself distinguish an official cryptocurrency miner from
a miner containing additional malicious code.

I therefore invite you to verify it directly:

1) Review the public Kadikama Miner source code and compare it with upstream XMRIG
2) Compile the miner yourself from the published source
3) Submit your locally compiled binary to Virustotal
4)Identify any specific malicious behavior or added source-code section unique to the Kadikama fork

Kadikama Miner source:

https://github.com/kadikamateam/kadikama-miner

A locally compiled file may have a different hash because of the compiler and build environment, but its source
changes and actual behavior can still be independently inspected.

If you find any malicious addition, please identify the relevant file, source-code lines and behavior so that it can
be investigated. If no such addition is found, I respectfully ask you to update your report and inform the moderator
that the original conclusion was based on a non-specific automated sandbox classification.

If distributing compiled mining binaries is the main concern, I am also willing to remove the binary links and
provide only the public source code and compilation instructions.
Pages: « 1 ... 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 [105] 106 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!