⚠️ Cake Wallet's Yesenia Gonzalez's Telegram account was hacked and the account is now attempting to convince people to install malware
Cake knew about this for over a week, but made NO PUBLIC WARNING
Multiple of Cake's partners are already affected
I saw her post on X, I'm not really convinced that a "hack" happened, I'd rather say that she installed or approved something that she shouldn't have.
Also, for partners who still install any add-ons or applications obtained through Telegram
It always surprises me how people who hold such positions that are sensitive to people's funds and data always end up being so dumb and careless through their accounts.
But huge blame goes to her for not making a quick alert in time. Maybe the damage could have been much smaller.
Luckily we haven't lost any money and neither has anyone else that was contact as far as we know.
However, as a result of the warning we published Cake's Vik has been attacking me personally in the DMs all day yesterday sending ominous messages such as:
Nah.. i see what you're doing.
It's not going to work
Everyone sees it
as well as stating:
Maybe your English is not good then
when I said nowhere in the warning did I claim that anyone lost money, just that people were affected (had to quarantine computers, rotate password, sessions, etc). I opted to post
another tweet clarifying this in case someone truly can't read and jumps to conclusions. The pressure didn' t stop. As the clock approached midnight Vik messaged me again to condemn me for making so many Tweets about it asking about "3 new fresh tweets?". At this point I opted to just troll him and told him he's right, 3 is not enough and that we must work together to get millions to see this warning. He replied I ought to "fuck off" and unfollowed the OrangeFren account on Twitter.
I told Vik yesterday that I like him and I like his team and their work. But I suppose he didn't believe me.
Currently I feel compelled to share that I longer hold this position and have migrated to Monfluo wallet on mobile for XMR.
A question that arises is would they share if they had a critical bug for a week? Or would they just roll out a patch, assume it's fine and attack anyone that posts about it?
I have shared the story with a friend that isn't into crypto, she's a neurosurgeon. She listened to the whole thing, then when I was done, she laughed and said "C'mon there was no hack. They're just scammers". She followed this with pointing to Yesenia's warning being on a protected account, to ignoring information about this for a week, to attacking me for sharing the warning... I personally don't believe this theory, but I'm concerned that Cake's PR is such that people draw such conclusions.
Some extra info:
I have contacted Yesenia first
I then reached out to Vik
Then I received evidence that Yesenia knew about the hack for OVER A WEEK and decided fuck it, I'm going public.
Are you guys really just not going to comment on the fact that you had this exchange listed on your website recently?
https://mistex.io/And now an hour after my swap never went through, that exchange has disappeared off your website. What the hell is that?!?!?! Are you serious right now?
This is an interesting case.
We had Mistex listed. You got in touch with a serious accusation against them. Due to them being new and the seriousness of the accusation we opted to immediately delist them to ensure if there's an exit scam underway more users don't end up falling for it. We continued to provide support to you in a timely manner and explained why they were delisted.
Mistex continue to be delisted until they implement a letter of guarantee to ensure no such accusations can be put forth in the future.
That said, you have sent your BTC to KuCoin's aggregate address. Not a deposit address, but an aggregate one (the one they send deposits to after confirming). Mistex does not have your BTC. We don't have your BTC. KuCoin has your BTC. Why did you sign and broadcast such a tx, I don't know. If Mistex showed you this address, then I'm wondering.... why? If a virus replaced your clipboard then why with this address? It's in nobody's interest for you to send your BTC to KuCoin. If I had to guess I would presume that you had KuCoin's address in your clipboard for some reason or Mistex showed you KuCoin's address by mistake due to a bug in some API integration...?
Regardless, as we have advised previously, you now ought to contact KuCoin, explain to them to erroneously sent BTC to their address and they ought to refund it.
Mystery Swapper September edition15 services, one test: 0.001 BTC → XMR, every deposit inside a single fan-out tx
Identical swaps returned anywhere from +1.3% to −3.8% vs market

✅Bitania, Swapuz, WizardSwap and BitcoinVN paid MORE than promised and all fit in 7 min
⚠️BitXchange not only paid considerably below their promise, but took 29 min(!)

⚠️BitXchange's shortfall
Their page quoted 0.13546921 XMR (Variable) → 0.13033374 arrived. −3.8% after market adjustment — the market was flat, nothing explains the gap
0trace (-2.5%) looks similar, but isn't: its order page locked 0.14323674 before deposit and paid exactly that🔒
🔍Plot twist: ChangeNOW and Nanswap paid us in ONE Monero transaction — same tx hash, two amounts summed
📤Our deposit tx:
https://mempool.space/tx/1f007312e761c87090732a15bc91b029220514483477a1bef65308730a0d5915🙌September's hero: Bitania
Paid +1.3% ABOVE their own quote (float upside passed to the user), in 7 minutes, with a Letter of Guarantee and for our users they offer a $50k OrangeFren Guarantee deposit
All tested services, compared live:
OrangeFren.com
OrangeFren Guarantee has grown so much that we now hold >$100k from just the top 3 exchanges on our homepage!
Swap with
OrangeFren.com to stay safe!
