threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign, dubbed ‘Superior’ by Socket, has been active since February 2024 and involves acquiring legitimate… The Hacker News · 1d ago High extensionmalwarewallet
threat-intel 2,3 millions de détenteurs crypto français ciblés A ZATAZ report has uncovered two separate cybercrime listings offering access to a database of 2.3 million French cryptocurrency holders, containing sensitive information like identities, contact details, addresses, and… ZATAZ · 2d ago High FRcryptokidnappingdata-breach
threat-intel Cartes Pokémon, fuite de données et réseaux sociaux : les vols ciblés se multiplient en France A growing trend of targeted crime involving Pokémon cards and cryptocurrency is emerging in France. Since 2022, a series of increasingly sophisticated and violent thefts have been documented, driven by the rising value o… ZATAZ · 2d ago High cybercrimecollectioncrypto
threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of… Graham Cluley · 6d ago High browsercryptomalware
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps A vulnerability in the CryptoJS library's random number generator has led to approximately $5.7 million in cryptocurrency drains affecting five wallet applications. Coinspect discovered that the weak random number genera… The Hacker News · Aug 6, 2026 High cryptowalletvulnerability
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
vulnerability Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes A flaw in Coldcard hardware wallets, manufactured by Coinkite, was exploited to steal $70 million in Bitcoin within 41 minutes. The vulnerability stems from a deterministic PRNG used during seed generation, allowing an a… The Hacker News · Aug 1, 2026 Critical hardware walletseed generationbitcoin
threat-intel 'Wrench' attacks against crypto holders appear to be on the rise Crypto theft is increasingly shifting from online attacks to physical coercion, known as ‘wrench’ attacks. CertiK reports a 33% year-over-year increase in these in-person attacks, with a significant rise in associated fi… The Record · Jul 24, 2026 High FRUNGEcryptophysical-securityself-custody
threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams
threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager info… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
vulnerability Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched Researchers at Ledger's Donjon security team have discovered a method to bypass the password protection on Tangem crypto wallet cards using a precisely timed laser pulse. The attack requires physical access to the card a… The Hacker News · Jul 10, 2026 High hardware walletlaser attackfirmware
threat-intel Fresh ATM Crypto Software Bugs: Jackpot or Bust? A researcher, Matt Burch, discovered nine vulnerabilities in CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturer Diebold Nixdorf. These vulnerabilities could allow attackers to bypass encrypti… Dark Reading · Jul 10, 2026 High USatmencryptionjackpotting
threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity
threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
phishing Scammers race to cash in on Venezuelan earthquake disaster Following a devastating earthquake in Venezuela, a surge of newly registered domain names emerged, many referencing aid and rescue efforts. Researchers discovered that a significant portion of these domains lacked identi… Graham Cluley · Jun 30, 2026 Medium VEdisasterfraudscams
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto