Bitcoin Forum
September 26, 2026, 07:39:43 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: [General] Crypto scams, attacks and malware  (Read 766 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic. (1 post by 1+ user deleted.)
Myleschetty
Full Member
***
Offline

Activity: 1772
Merit: 133


View Profile
September 21, 2026, 09:19:02 PM
Merited by Alpha Marine (2), Mitchell (1)
 #21

According to a post on Saturday by the Chief Information Security Officer of the blockchain security firm SlowMist regarding Darksword, it was reported that attackers are leveraging this malware to circumvent iOS security measures when a victim accesses an infected website; the malware is set to activate on March 19, 2026 s posted by _act_ , to seize control of devices and extract private keys and other information from self-custodial Bitcoin wallets. The vulnerability is said to only impact iOS versions 18.4 to 18.7 then, but it now extends beyond the specified version. Here is what the Chief Information Security Officer of SlowMist said.

Unexpectedly, in one language, iOS users hurry to upgrade Black-gray industry has already achieved:
1. Clicking links to extract private keys and mnemonic phrases
2. Users access web pages via Safari, WebKit/JSC memory corruption to obtain JS layer read/write
3. Bypassing PAC to gain native call capabilities
4. Escaping the WebContent sandbox
5. Kernel privilege escalation to obtain root permissions, dragging away Keychain + wallet data

 Affected versions iOS 13 to 26.5 (more versions pending)

https://x.com/im23pds/status/2101265052825428144?s=20
cryptomaniac_xxx
Hero Member
*****
Offline

Activity: 2366
Merit: 670



View Profile
September 22, 2026, 12:08:53 PM
Merited by Mitchell (1)
 #22



https://x.com/coinbureau/status/2102279497676681616

So there is another alert with regards to Iphone users. They are being warned about a potential Safari zero-day exploit. And this loophole could exposed your crypto seed phrase and private keys.

Just be very careful if you are a Iphone users and have your crypto wallet in their. Update and patch everything, but you have to verify it first that you are getting it from legit sources.

Although this could also be a warning for everyone to do your due diligence.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
│
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS   ► PLAY NOW     
LoyceV
Legendary
*
Offline

Activity: 4172
Merit: 22802


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
September 22, 2026, 01:05:10 PM
Merited by Mitchell (5)
 #23

They are being warned about a potential Safari zero-day exploit. And this loophole could exposed your crypto seed phrase and private keys.
A more general warning would be to limit exposure to hot wallets to the absolute minimum. Don't keep more on your phone than you need on the road.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
[MUSIC] The Ballad of LoyceV
SatsPH
Full Member
***
Offline

Activity: 210
Merit: 118



View Profile
September 24, 2026, 03:22:35 PM
Last edit: September 25, 2026, 10:44:59 AM by SatsPH
 #24

According to this warning, North Korean hackers are targeting us with this kind of attacks,

Quote
The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries.

Modus:
1. Will ask to download some files to verify your technical abilities
2. You say Yes
3. Download the link from Github, the malware masquerading as harmless in the beginning
4. You execute it as a applicant
5. Malware spread and look for everything related to crypto
6. Steal everything they can find



https://www.ic3.gov/CSA/2026/260918.pdf

The names of the malware might be different, but it has the same goal. So if you are looking for a crypto related jobs you might be a target here.

Myleschetty
Full Member
***
Offline

Activity: 1772
Merit: 133


View Profile
September 25, 2026, 01:41:40 PM
 #25


SlowMist points out that this Safari attack reused the previously disclosed DarkSword exploit chain technique and is independent of another FomoPeek investigation involving malicious components embedded in App Store apps. Google Threat Intelligence (GTIG) disclosed DarkSword in March, stating that it is an iOS exploit chain used by multiple threat actors since November 2025.
SlowMist stated that its investigation has not yet linked the recent iPhone Safari attacks that triggered security warnings to confirmed cryptocurrency thefts. SlowMist told Cointelegraph that it has not independently confirmed any victims harmed by the specific Safari attack samples it analyzed, and its strongest technical evidence covers iOS versions 18.4 to 18.6.2. The company stated that the widely circulated claim of affecting iOS 13 to 26.5 should be considered a preliminary assessment, and it prefers to avoid claiming that iOS 26.5 is affected until reproducible technical evidence is available.

https://cointelegraph.com/news/no-confirmed-crypto-theft-iphone-safari-attack-slowmist
JeromeTash
Legendary
*
Offline

Activity: 3010
Merit: 1602


Heisenberg


View Profile
September 25, 2026, 09:57:37 PM
 #26

According to this warning, North Korean hackers are targeting us with this kind of attacks,

Quote
The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries.
So any form of cyber attack now originates from North Korea?
Someone please help me understand how people come up with such conclusions.
Is it a case of North Korea being a country full of the deadliest hackers around the world, or are their hackers just too stupid that hey cannot even cover their tracks, like, for example, mask their IP addresses?

SatsPH
Full Member
***
Offline

Activity: 210
Merit: 118



View Profile
Today at 10:07:20 AM
 #27

According to this warning, North Korean hackers are targeting us with this kind of attacks,

Quote
The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries.
So any form of cyber attack now originates from North Korea?
Someone please help me understand how people come up with such conclusions.
Is it a case of North Korea being a country full of the deadliest hackers around the world, or are their hackers just too stupid that hey cannot even cover their tracks, like, for example, mask their IP addresses?

I don't know if you have heard about the recent Bybit hack, but the exchange said they suspect that North Korea is behind.

Or maybe you can read the reports here, I'm not the one accusing them, and it has been in crypto space for many years. The big difference here is that the Lazarus group is state sponsored so they are sophisticated, but one mistake might reveal their true identity:

https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/

Quote
North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, pushing their all-time total to $6.75 billion despite fewer attacks.
The DPRK is achieving larger thefts with fewer incidents, often by embedding IT workers inside crypto services or using sophisticated impersonation tactics targeting executives.
The DPRK shows clear preferences for Chinese-language money laundering services, bridge services, and mixing protocols, with a 45-day laundering cycle following major thefts.
Individual wallet compromises surged to 158,000 incidents affecting 80,000 unique victims in 2025, though total value stolen ($713M) decreased from 2024.
Despite increased Total Value Locked in DeFi, hack losses remained suppressed in 2024-2025, suggesting improved security practices are making a meaningful difference.

Or maybe this article might answer your question as how the investigators track it to North Korea:

https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit

Quote
Almost immediately following the ByBit hack, TRM identified and tagged the compromised addresses as “Hacked” or “Stolen Funds” and established a dedicated tracking entity labeled "Bybit Exploiter Feb 2025" to monitor the movement of the stolen assets in real time.

Through blockchain intelligence, TRM Labs confirmed that North Korean hackers were responsible for the breach, linking it to previous state-sponsored crypto heists. The evidence revealed clear overlaps between the wallets used in this operation and those associated with past North Korean thefts. On February 26, 2025, the FBI officially linked the heist to North Korea.

NotATether
Legendary
*
Offline

Activity: 2464
Merit: 10346


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 10:28:15 AM
 #28

So any form of cyber attack now originates from North Korea?
Someone please help me understand how people come up with such conclusions.
Is it a case of North Korea being a country full of the deadliest hackers around the world, or are their hackers just too stupid that hey cannot even cover their tracks, like, for example, mask their IP addresses?

Obviously not, and that is a lazy reference. But we have to acknowledge that they are behind some of the most sophisticated attacks like the one on Bitget recently. They tricked them into signing a malicious contract that appeared to be real.

So they need to start using their funds, these exchanges, to bolster their contract security auditing instead of just blindly creating bounties for returning stolen funds.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!