vulnerability Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026. The vulnerability, initially missed due to a misunderstanding of how the system handled vesting accounts, allowed attackers to steal approximately $5.72 million in assets. Despite… The Hacker News · 2d ago High vulnerabilityblockchaincryptocurrency
threat-intel Quand les fuites de données ciblent les victimes This article highlights a concerning trend where data breaches are increasingly used to generate actionable intelligence for criminal activity, particularly targeting wealthy individuals with crypto assets and luxury goo… ZATAZ · 2d ago High FRdata-breachcryptocurrencyphysical-attacks
threat-intel 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have… The Hacker News · Aug 20, 2026 High firefoxwalletextension
threat-intel No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns A new AI platform called ‘Kriminal’ is raising concerns within the cybersecurity community due to its permissive nature and explicit marketing targeting cybercriminals. Despite claims of being for research and educationa… Dark Reading · Aug 19, 2026 Medium aicybercrimeosint
threat-intel SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers SafePal, a hardware wallet maker, disclosed a flaw in its order-tracking plug-in that exposed the personal data of approximately 39,798 customers, including names, addresses, and purchase details, between March 2025 and… The Hacker News · Aug 18, 2026 Medium data breachcryptocurrencyhardware wallet
threat-intel SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted SafePal, a leading crypto hardware wallet manufacturer, suffered a data breach affecting nearly 40,000 customers who placed orders between March 2, 2026 and April 11, 2026. The stolen data included personal information l… The Record · Aug 17, 2026 High data breachcryptocurrencyhardware wallet
data-breach 40,000 Impacted by SafePal Data Breach SafePal, a crypto hardware wallet manufacturer, has been the target of a data breach affecting approximately 40,000 customers. Hackers exploited a vulnerability in the order-tracking plugin to steal customer information,… SecurityWeek · Aug 17, 2026 Medium data breachcryptocurrencyphishing
threat-intel Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach Trezor, a leading cryptocurrency wallet manufacturer, has confirmed that details of approximately 13,000 customer accounts were exposed due to a logistics breach. This incident highlights a significant risk for users hol… The Register · Aug 14, 2026 High cryptocurrencyhardware walletdata breach
threat-intel China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud The China-linked threat actor Jewelbug, operating as a ‘hack-for-hire’ group, is engaged in both sophisticated government espionage targeting nations across the Middle East, Southeast Asia, and South Asia, and cryptocurr… The Hacker News · Aug 14, 2026 High CHMISOespionagecryptocurrencyhack-for-hire
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
threat-intel Commerce pirate : un cybercriminel vend des dizaines de téraoctets de données A cybercriminal is offering a massive stock of personal and corporate data, spanning over 25 countries and multiple sensitive categories, for sale. The offering includes over 100,000 distinct datasets, encompassing phone… ZATAZ · Aug 7, 2026 High FRGEUNdata breachcybercrimedata theft
threat-intel CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps A vulnerability in the CryptoJS library's random number generator has led to approximately $5.7 million in cryptocurrency drains affecting five wallet applications. Coinspect discovered that the weak random number genera… The Hacker News · Aug 6, 2026 High cryptowalletvulnerability
threat-intel Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Graham Cluley recounts a bizarre experience where he was contacted by someone posing as a police detective investigating a cybercrime. The individual claimed to have evidence suggesting they possessed a 24-word seed key… Graham Cluley · Aug 5, 2026 High cryptocurrencyhardware walletphishing
threat-intel Some Claude Chats Are Searchable on Google A vulnerability in Anthropic's Claude chatbot system has led to users' private conversations, including cryptocurrency wallet keys and personal data, becoming searchable on Google. This stems from a user-controlled data… Schneier on Security · Aug 4, 2026 Medium privacyaidata-sharing
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
threat-intel Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen A popular Bitcoin hardware wallet manufacturer, Coinkite, destroyed its remaining inventory after a firmware vulnerability was exploited, leading to the theft of over $88 million in Bitcoin. The vulnerability, discovered… The Record · Aug 3, 2026 Critical bitcoinhardware walletfirmware
supply-chain Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across custom… The Hacker News · Aug 1, 2026 High supply-chainjavascriptcryptocurrency
threat-intel Interpol Leverages Global System to Curtail Fraud Payments Interpol has launched I-GRIP, a global system connecting law enforcement agencies and financial institutions to rapidly intercept fraudulent payments and curb transnational criminal activity. The system, operational sinc… Dark Reading · Jul 31, 2026 High SITIUSfraudcryptocurrencycybercrime
threat-intel North Korean hackers behind major open-source supply chain attacks, Amazon says North Korean hackers, operating under the alias SapphireSleet, have been responsible for a series of attacks targeting widely used open-source JavaScript packages. These attacks, spanning from March 2025 to March 2026, i… The Record · Jul 30, 2026 High KRnorth koreaopen sourcesupply chain