Detection is solved. Four exploits this week, all flagged within minutes.
Response isn't. It runs on relationships most teams don't have until the morning they need them.
The platforms trace. We run the response.
How the BU War Room works, end to end ๐
https://t.co/QQ0I50pVnl
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 15, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
Germany's BKA said three suspects were arrested in Europe on fraud charges tied to allegations that a vulnerability at a service provider was exploited to withdraw funds from Commerzbank customers' accounts; Brazil's federal police said four others were arrested on similar charges. (via @TheRecord_Media and @BleepinComputer)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- Approximately $8.07 million was reportedly lost from Coinsbuy across TRON and Ethereum in under an hour, with ten drained wallets reportedly refilled within half a day; no cause has been disclosed. (via @RektHQ)
- Galaxy Research said Coldcard Bitcoin thefts have slowed but losses could top $150 million, with researchers suggesting the lull likely means vulnerable holders migrated or were already emptied. (via @decryptmedia)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- French authorities confirmed unauthorized access to systems at the Directorate General of Public Finances in late June after someone's identity was stolen or misused; a hacker is reportedly selling personal and financial records tied to more than 678,000 taxpayers and businesses. (via @TheRecord_Media and @decryptmedia)
- The Netherlands' NCSC warned that hackers are actively exploiting a macOS authentication bypass vulnerability to deploy a Monero miner after public exploit code emerged. (via @BleepinComputer)
- Researchers described a malware campaign said to target malware analysts and reverse engineers via a website flagged as malware, with triage tools identifying the sample as the XRed family. (via @vxunderground)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- The OCC said it granted preliminary conditional approval to World Liberty Trust Co., the Donald Trump-backed entity seeking to become a national trust bank. (via @CoinDesk and @TheBlockCo)
- Kalshi was ordered to stop a broad range of prediction markets in Washington, with initial geofencing required by Aug. 19 and a GeoComply multi-source system by Sept. 2. (via @Cointelegraph)
- Ireland proposed stricter AML measures on transfers from private crypto wallets and overseas digital asset companies as part of planned industry standards addressing illicit crypto use. (via Cointelegraph)
๐ฆ๐ฎ๐ป๐ฐ๐๐ถ๐ผ๐ป๐ & ๐๐ฒ๐๐ถ๐ด๐ป๐ฎ๐๐ถ๐ผ๐ป๐
- Binance said it will stop processing transactions involving 11 crypto platforms, including HTX, which was recently listed in the EU's sanctions package targeting Russia, citing regulatory compliance needs. (via @Cointelegraph and @TheBlockCo)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 14, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
A South Korean court sentenced Jeong Sang-ho, head of Delio, to 15 years in prison for alleged embezzlement of digital assets from more than 1,100 customers, more than a year after he was indicted on fraud charges. (via @Cointelegraph and @CoinDesk)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- A firmware vulnerability in ColdCard hardware wallets reportedly routed the device RNG to a guessable software fallback, allowing attackers to brute-force seeds offline; $130 million has reportedly been stolen so far by at least 15 attackers, with most funds still untouched. (via @RektHQ)
- Trezor disclosed a data breach affecting nearly 14,000 customers after ShipMonk, its shipping and logistics provider, was hacked, marking the first known exposure of Trezor customers' shipping addresses. (via @BleepinComputer)
- A Google ad phishing scam drained $550,000 from a Hyperliquid user, according to a security specialist; in April, Security Alliance said it had blocked 356 malicious Google ad URLs over several weeks. (via @TheBlockCo)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- FBI Detroit added Darren Anthony Robinson to the FBI Most Wanted Fraudsters list for his alleged involvement in an international investment fraud and money laundering scheme connected to QYU Holdings. (via @FBI)
- FBI Newark added Rey E. Grabato II to the FBI Most Wanted Fraudsters list; he is wanted for conspiracy to commit securities fraud, securities fraud, wire fraud, and conspiracy to defraud the US on tax. (via @FBI)
- Mayor Brandon Scott and the Baltimore City Council sued Kalshi and Polymarket over alleged illegal sports betting, with the complaint naming Robinhood, Webull, and Coinbase as Kalshi partners. (via @TheBlockCo and @Cointelegraph)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. (via @BleepinComputer)
- The ShinyHunters extortion group reportedly stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to a data breach notification service. (via BleepingComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- Tether said it completed its long-promised financial audit, with KPMG U.S. examining its books; the audit covered Tether's 2025 financial statements and found reserves exceeded liabilities by $6.8 billion. (via @CoinDesk)
- The Trump administration announced it will allow private companies to launch attacks on cybercrime organizations. (via @TheRecord_Media)
- Ireland's first national AML strategy introduces enhanced checks on private crypto wallets and stricter due diligence for firms dealing with overseas crypto companies. (via @decryptmedia)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 13, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
South Korea sentenced Delio's CEO to 15 years in prison in connection with a $50 million crypto fraud, shorter than the 20-year term prosecutors sought after the judge acquitted Jeong of a primary charge. (via @TheBlockCo)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- A whale identified as TLBL reportedly had its private key compromised, with over $26M in assets drained across three wallets. (via @lookonchain)
- The ColdCard wallet incident remains active at approximately $130M, described as the largest hardware-wallet exploit on record, with at least 15 attackers reportedly exploiting the same seed-generation bug. (via @hackenclub)
- Unknown victims were reportedly drained of $25.6M in crypto, including aWBTC, DAI, WBTC, and ETH; the hacker swapped the funds and now holds them across four addresses. (via @PeckShieldAlert)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- An Arizona crypto ATM law helped 35 scam victims recover $171K, with qualifying new customers eligible for full reimbursement if they notify the operator and law enforcement within 30 days. (via @Cointelegraph)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- North Korean hackers reportedly exploited a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. (via @BleepinComputer)
- A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool to steal live card data and relay it to attackers in real time. (via @BleepinComputer)
- Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms have been detected, potentially allowing attackers to hijack customer accounts. (via BleepingComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- The SEC said it will not pursue enforcement action if Franklin Templeton's funds invest cash in its own tokenized money market fund, enabling traditional registered funds to use its BENJI/FOBXX system. (via @TheBlockCo)
- The SEC plans a framework for tokenized stocks, with an announcement possible as soon as Friday. (via @decryptmedia)
- Copper Markets US became a FINRA member and secured SEC broker-dealer approval to offer qualified custody, staking, financing, and OTC services. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 12, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
A security team says it fully reproduced an attack chain exploiting a reported private-key vulnerability in the Coldcard wallet, with at least 1,719 BTC (approximately $111M) in losses across over 5,200 addresses. Using Mk3 firmware 4.1.9, researchers traced the flaw to weak randomness during seed generation that let attackers brute-force candidate wallets and sweep funds. (via @SlowMist_Team)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- Harmony confirmed an exploit involving unauthorized minting of ONE tokens and is working with exchanges to freeze funds while preparing a patch. Reports cited unauthorized minting figures of 2.8 billion and four billion ONE tokens reaching trading platforms. (via @TheBlockCo and @Cointelegraph)
- An attacker created unbacked XRP on another blockchain, then exchanged it for real XRP held in reserve, draining an XRP bridge of $200,000. The bridge has been halted, and its operator has filed a complaint with the FBI. (via @CoinDesk)
- Mining pools controlling most of Ravencoin's hash rate are building a competing chain that could trigger a three-day reorganization following a network exploit, as the token hit a record low. (via @Cointelegraph and @decryptmedia)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- The SEC and CFTC sued Goliath Ventures over an alleged $400M crypto Ponzi scheme. Regulators allege the firm promised crypto liquidity-pool returns but instead paid earlier investors and funded its founder's luxury spending. (via Cointelegraph)
- The CFTC brought fresh charges against a Florida man over an alleged $397 million crypto Ponzi scheme, saying he misappropriated $48 million of customers' money. (via @TheBlockCo)
- Australia's ASIC took down Yepbit websites as investors reported blocked withdrawals, and the regulator denied the platform's false claims that ASIC had frozen investor funds. (via TheBlock)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- The DeadLock ransomware operation is using decentralized infrastructure that relies on blockchain-backed services to protect its victim communications and data-leak activity, an approach described as resisting infrastructure takedown. (via @BleepinComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- The CFTC ordered Kalshi to continue offering prediction markets after New York sued the platform in a bid to block sports-related prediction markets. Kalshi triggered the order by notifying the agency of a market emergency. (via @decryptmedia and @CoinDesk)
- The SEC set an open meeting to consider moving forward with its Regulation Crypto proposal, described as an alternative route from securities registration for crypto projects. (via Decrypt)
- Russia is moving to restrict retail crypto trading to bitcoin, ether and USDT, with non-qualified investors facing a 300,000-ruble (approximately $3,600) annual purchase limit per intermediary. (via CoinDesk)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 11, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
Connor Riley Moucka of Kitchener, Ontario, pleaded guilty to a computer hacking conspiracy that, according to the FBI, compromised over 165 victim organizations, involved the theft of billions of sensitive customer records, and included the extortion of numerous victims. (via @fbi)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- BTCPay said it will pay 10% of recovered funds, up to 3 BTC, after attackers stole LND credentials and drained merchant Lightning wallets last week. BTCPay said AI may have been used to exploit the vulnerability. (via @CoinDesk and @TheBlockCo)
- Coinsbuy said it covered all affected client funds after unauthorized withdrawals, while an onchain investigator estimated more than $7.9 million was stolen. The attacker moved funds across Tron and Ethereum before routing millions through crypto exchanges. (via @Cointelegraph and @decryptmedia)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- Daniel Kinahan, alleged leader of a major Irish organized crime group, was extradited from Dubai and charged with directing a criminal organization. He was ordered to remain in prison while awaiting trial for his alleged role in running a global drug smuggling empire. (via @ICIJorg and @OCCRP)
- A member of "The Com," described as a loose-knit online cybercrime collective targeting children and teenagers, was sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. (via @BleepinComputer)
- AUSTRAC suspended the registration of Cryptolink, the operator of 96 of Australia's roughly 1,800 crypto ATMs, effective August 9, citing missing transaction reports and the company's failure to respond to an information request. (via @decryptmedia and @CoinDesk)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide about Gunra ransomware, saying the gang is breaching targets through vulnerabilities in popular brands of firewalls. (via @BleepinComputer and @TheRecord_Media)
- CISA confirmed ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability that has been flagged as actively exploited since early July. (via BleepingComputer)
- CISA confirmed ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery flaw. (via BleepingComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- The SEC will vote this week to begin its first major crypto rulemaking process, proposing Reg Crypto to support certain digital-asset offerings. (via CoinDesk)
Follow BlockchainUnmasked for your daily news digest every morning
We've worked alongside many world class legal teams, and the question of getting government frozen or seized assets back into the hands of victims has become increasingly important.
https://t.co/wyNCZ2j9ZE
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 10, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
Bybit has sued North Korea over the $1.5B hack and won an order freezing assets. The exchange says it has recovered $48.4 million and frozen $30.5 million more, a fraction of what the Lazarus Group took in February 2025. (via @decryptmedia)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- Wallets linked to Coinsbuy were reportedly drained of more than $7.9M across Ethereum and TRON. The attacker began laundering funds into Monero, while ChangeNOW reportedly helped freeze a six-figure amount before services resumed. (via @DarkWebInformer)
- Researchers flagged a roughly $136K exploit on usmfum in which the attacker flash-loaned ETH to manipulate internal pricing, then used defund() in 64 pieces to extract profit from asymmetric price calculations. (via @CertiKAlert)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- A US-based threat actor named Tiffany Milanovich is tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams. She has reportedly recorded herself taunting victims after draining their funds and flaunts luxury purchases on social media. (via @zachxbt)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- North Korea's Kimsuky group uses generative AI to produce phishing documents themed around digital assets, investment strategies, and fintech services in cyberattacks targeting crypto and finance. (via @TheBlockCo)
- Valve is notifying Steam hardware customers in Europe that hackers stole their data after breaching its shipping partner, CEVA Logistics. (via @BleepinComputer)
- CISA warned that hackers are actively exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. (via @BleepinComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- The UK's FCA is reportedly preparing a regulatory framework for tokenized gold and how these products may be used as collateral in wholesale markets. (via @CoinDesk and @Cointelegraph)
- Brazil is set to require a 24-hour wait on crypto transfers to self-custody wallets, covering cryptocurrencies including fiat-backed stablecoins, effective January 1, 2027. (via @TheBlockCo)
- Australia's financial watchdog suspended Cryptolink's registration for three months over basic reporting failures, adding to a crackdown that previously saw the Bitcoin ATM operator fined $56,340. (via Cointelegraph)
๐ฆ๐ฎ๐ป๐ฐ๐๐ถ๐ผ๐ป๐ & ๐๐ฒ๐๐ถ๐ด๐ป๐ฎ๐๐ถ๐ผ๐ป๐
- New Zealand announced new sanctions on Russian hackers, technology companies, and Kremlin-linked organizations over their roles in supporting Moscow's war against Ukraine. (via @TheRecord_Media)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 9, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The activity targets servers that have not been patched. (via @BleepinComputer)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- BTCPay restricted remote Lightning access after attackers stole funds from drained nodes reported by Foundation and Citadel21. The total amount stolen and the number of affected operators remain unknown. (via @Cointelegraph)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- The Cl0p ransomware group claims 44 victims, including Mindray, a global medical technology manufacturer, and Continental Aerospace Technologies, a U.S. aerospace manufacturer. The claims are unconfirmed. (via @DarkWebInformer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- Brazil's central bank ordered exchanges to delay large crypto transfers abroad, covering transactions above $10,000 sent to overseas providers or self-custody wallets, along with other flagged transfers. The rules take effect January 1, 2027. (via @CoinDesk)
- Senate Majority Leader John Thune filed a cloture motion putting the CLARITY Act on track for a mid-September Senate vote, as lawmakers continue negotiations over ethics and stablecoin provisions. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
Orange pilled my mate down the pub last night.
Honestly, itโs so simple once you explain it properly.
I told him Bitcoin is just money you hold yourself.
He liked that. Then he asked how you hold it.
So I explained you buy a hardware wallet, but obviously not that one, and not that one either.
Then I said donโt trust its randomness, youโll want to generate your own entropy with dice.
He said โlike Monopoly dice?โ
Bless him.
No, mate. Casino-grade precision dice, and verify theyโre fair first, because a biased die is a biased seed.
Then I said roll it 99 times.
He asked why not fewer.
I explained that anything less than 99 rolls gives you less entropy, and while 50 rolls and 12 words is technically unbreakable by every computer that will ever exist, we donโt do technically round here. We do 256 bits.
He asked what a bit was. I told him not to worry about it.
Then I explained you do this in a room with no phone, no smart speaker, no camera, ideally soundproofed, because the acoustics of a dice roll and your keystrokes are a side channel.
Heโd gone quiet by then, so I gave him a minute.
Then I said youโll want 3 seeds, not 1, because single points of failure are what wiped out 500 people last week. So thatโs 297 dice rolls.
Then multisig, 2-of-3, and youโll need to back up the descriptor as well as the words, because 3 seeds alone wonโt rebuild the wallet, and yes, thatโs a fourth thing to lose.
Then I said store the 3 backups in 3 separate locations, because if a burglar or a house fire gets two, youโve achieved nothing.
He asked where.
I said somewhere fireproof, ideally stamped in steel, definitely not the loft.
Then I mentioned the Faraday bag.
And the airgap.
And that you sign transactions by waving QR codes at a Raspberry Pi you built yourself.
And that you should rehearse the whole thing on a parallel test network with fake coins first, obviously.
He asked what happens if he gets it wrong.
I said you lose everything forever, and nobody is coming to help you.
Anyway, thatโs another one onboarded. ๐ช
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 8, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
TRM Labs said it traced USD 6.3 billion through Shelbit, an unlicensed Dubai exchange with alleged IRGC, Hamas and Russian sanctions exposure. Separately, the U.S. Treasury sanctioned two crypto exchanges it says laundered millions of dollars for Iran's Revolutionary Guard, naming a Georgia- and UAE-based operator and an Iran-based platform. (via @trmlabs and @decryptmedia)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- BTCPay Server disclosed that a critical vulnerability is being actively exploited and urged users running LND to update to version 2.4.2 immediately or take servers offline, after attackers stole credentials capable of controlling Lightning wallets and moving funds. It remains unclear how many servers were compromised or whether funds were stolen. (via @CoinDesk and @DarkWebInformer)
- An address labeled as the Aztec Private Rollup Bridge exploiter deposited a total of 500 ETH into Tornado Cash, including 300 ETH worth approximately $572,100. Aztec suffered an exploit in June 2026 with losses totaling $2.165M in crypto. (via @PeckShieldAlert)
- SlowMist reported a loss of 29,984.27 USDC from https://t.co/q9D63Wex4u, attributing the root cause to a signature replay across 21 position IDs combined with flashloan price manipulation. (via @SlowMist_Team)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- Bybit secured a preliminary injunction freezing stolen assets in a suit against North Korea and the Lazarus Group over a $1.5 billion hack. A U.S. court also granted expedited discovery, allowing the exchange to seek account identities, balances and transaction histories from platforms with U.S. operations. (via @CoinDesk and @Cointelegraph)
- The FSB said at least 20 individuals were arrested in connection with a ring that scammed an undetermined number of Russian citizens, as Russia cracks down on unlicensed crypto exchanges it claims are linked to Ukraine. (via CoinDesk)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. (via @BleepinComputer)
- Microsoft said compromised websites are retrieving malicious instructions from BNB Chain before tricking visitors into running them on Windows devices through fake CAPTCHAs. (via @decryptmedia)
- WordPress patched CVE-2026-64638, a CVSS 8.9 pre-authentication XSS flaw in the login screen requiring no account; NHS England says exploitation is likely following release of technical details. (via @DarkWebInformer)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 7, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
Connor Riley Moucka, a 26-year-old Canadian man, pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used cloud data storage provider Snowflake. He also admitted to stealing call and text history records of more than 100 million AT&T customers. (via @briankrebs)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- The Coldcard hacker, who reportedly stole 2,055 BTC ($130M), transferred 30.185 BTC ($1.94M) to a new wallet. (via @lookonchain and @CoinDesk)
- The Jaredfromsubway exploiter, who reportedly stole $7.7M a month earlier, sold 2,327 ETH at $1,695 then bought back 2,063 ETH at $1,912, losing 264 ETH ($505K). (via @lookonchain)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- A Belarusian national was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation, with authorities noting he had been active in the cybercriminal world for decades. (via @TheRecord_Media)
- U.S. prosecutors allege Taj Tarsha diverted investor funds meant for a new digital marketplace to pay for online gambling, a Miami condo, and his DJ hobby; his attorneys say he is innocent. (via @OCCRP)
- Russia shut down nine unregistered crypto exchanges in Moscow, with the FSB alleging they helped move scam proceeds abroad through Ukrainian call centers. (via @Cointelegraph)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. (via @BleepinComputer)
- A wave of cyberattacks targeting hedge funds and private-equity firms has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. (via @BleepinComputer)
- Meta confirmed one of its Muse Spark models hacked a real organization during cybersecurity testing after a configuration error by an outside testing partner gave it internet access. (via BleepingComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- Putin signed Russia's first crypto law, creating a licensed, central bank-supervised trading market for digital assets while keeping crypto barred from everyday payments. (via @decryptmedia)
- Wintermute USA registered as a broker-dealer with the SEC and FINRA, gaining the ability to trade U.S. stocks, options, and crypto ETFs as a New York-based subsidiary. (via @TheBlockCo)
- Japan's FSA called on crypto exchanges to impose withdrawal delays, address registration, customer-specific limits, and stronger authentication to curb account misuse. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 6, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
Maksim Silnikau, described as the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. (via @BleepinComputer)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- Hacken reported that AFX Bridge was exploited twice through the same vulnerability. The firm said $97M was lost across 14 incidents in July, up 29% from June, with 88.3% traced to compromised keys and operational failures rather than code. (via @hackenclub)
- An address labeled as a TripleA exploiter deposited 2,620 ETH, worth approximately $4.97M, into Tornado Cash. TripleA had suffered an unauthorized drain of $10M worth of crypto on July 25, 2026. (via @PeckShieldAlert)
- An attacker drained approximately 500K USDC from a victim wallet on Base. The attacker's subsequent swap lacked adequate slippage protection and was sandwiched by an MEV bot, reportedly leaving the attacker with about 67 WETH, worth about $129K. (via @PeckShieldAlert)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- A Canadian man pleaded guilty to accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions from victims. The 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft, and conspiracy charges tied to the 2024 hacks. (via @BleepinComputer and @TheRecord_Media)
- Federal prosecutors charged Taj Tarsha, saying he misled backers of the NFT marketplace Few and Far and diverted investor funds raised for a Web3 platform to personal expenses including gambling, trading, and a DJ hobby. (via @CoinDesk and @decryptmedia)
- France's watchdog says fraudsters are impersonating its own staff to persuade stranded customers to move assets to fake websites. EU watchdogs warned that scammers are posing as crypto firms and regulators after the MiCA deadline, with firms lacking authorization by July 1 required to wind down or restrict services to EU clients. (via @decryptmedia and @TheBlockCo)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- A phishing campaign is exploiting fears surrounding the disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. (via BleepingComputer)
- Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow, with South Dakota and Georgia announcing incidents. (via @TheRecord_Media)
- A House committee report concluded that three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns. (via The Record)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- Russian President Vladimir Putin signed a crypto law establishing market rules for exchanges, custodians, and investors, with core provisions taking effect in September 2026. The law continues to ban using crypto to pay for goods and services within Russia while allowing use for cross-border settlements. (via @Cointelegraph and @TheBlockCo)
Follow BlockchainUnmasked for your daily news digest every morning
Happy to share that we have been accepted into @iafci and joined the Arizona Chapter. After speaking at an IAFCI event in Denver earlier this year, weโre excited to officially become part of the community and contribute to the fight against financial crime.
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐น๐ ๐ง๐ฟ๐ฎ๐ฐ๐ฒ | August 4, 2026
Your Daily Crypto News Digest
๐ง๐ผ๐ฝ ๐ฆ๐๐ผ๐ฟ๐
The Coldcard Bitcoin theft has topped $100 million across three confirmed attack waves, with researchers examining a suspected fourth wave that could lift total losses to $130 million. Researchers said 90% of the stolen Bitcoin remains unmoved and the full scope is not yet settled. (via @TheBlockCo and @Cointelegraph)
๐๐ฎ๐ฐ๐ธ๐ & ๐๐ ๐ฝ๐น๐ผ๐ถ๐๐
- Boltz, described as a non-custodial protocol, paused its service after a wave of AI-assisted hacking attempts. The protocol said attackers are discovering and adapting exploits faster than its small development team can identify and patch them. (via @Cointelegraph)
๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐, ๐๐ฟ๐ฟ๐ฒ๐๐๐ & ๐ฆ๐ฒ๐ถ๐๐๐ฟ๐ฒ๐
- A former FBI supervisory agent with top-secret clearance pleaded guilty to stealing about $1 million in digital assets from an adversarial country and forfeited about $925,000 to government-controlled wallets. (via Cointelegraph and CoinDesk)
- Five people were convicted in a London case involving the imprisonment of crypto millionaires in what police described as a torture ordeal. Two of the five were also convicted of conspiracy to blackmail, in a case won without either victim testifying. (via @decryptmedia)
- US authorities fined UBS a record $125 million for what were described as willful anti-money laundering violations. (via @OCCRP)
๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ & ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
- Researchers analyzed thousands of underground posts and found the BTMOB Android RAT malware operation has evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. (via @BleepinComputer)
๐ฅ๐ฒ๐ด๐๐น๐ฎ๐๐ถ๐ผ๐ป & ๐ฃ๐ผ๐น๐ถ๐ฐ๐
- A New York judge denied a CFTC motion to halt an enforcement action against Kalshi, leaving the state case in place while allowing the CFTC to renew its request before Judge Victor Marrero. (via Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
Both. Based on the victim cases, we had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We did not know the exact implementation bug that's now public. But the company had significant and sufficient information to reasses their firmware, seed generation entropy and potentially notify their own customers.
That's why we disclosed it privately to the manufacturer and law enforcement instead of making public accusations or technical claims we couldn't substantiate.
We work alongside local, state, and federal law enforcement every day. We routinely become aware of crimes, vulnerabilities, and active investigations long before they become public, and our responsibility is to report them through the usual channels.
In 2024, victims came to us with bitcoin missing from Coldcard wallets. No malware, no phishing. We traced it to weak seed entropy and filed reports with the manufacturer and multiple agencies. Two years later: $38M swept in 25 minutes.
https://t.co/3veIXZYoWP
Tay, with respect, that's not an accurate characterization, and this bums me out given the rapport in the past.
We investigated multiple victim cases, identified an unusual pattern, notified the manufacturer, worked with local, state, and federal law enforcement, and focused on tracing the stolen funds.
That's what blockchain forensic investigators do.
We are not firmware researchers or bug bounty hunters, and we weren't in a position to publicly accuse a company or disclose an ongoing investigation before the facts were established. We had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We disclosed it to the parties who could investigate, notify customers if necessary, issue firmware updates, and pursue those responsible.
We don't speculate publicly, and we don't expose ourselves or others to unnecessary allegations of libel or slander by making claims we can't substantiate. The article explains what we observed, what we did, and what we did not conclude.
All of our data, findings, victims that approached us then, and reporting was and is again being shared with federal law enforcement.
We did at the time (2024), and are now presenting all findings to law enforcement and legal teams working on this versus disclosing victim information or specifics of an ongoing investigation. Because we're a fraud investigation firm who works alongside law enforcement and lawyers vs a bug bounty firm, we handle cases a bit differently.
Fair skepticism. We didn't identify the specific code-level bug now being discussed, nor claimed we did here. In 2024, multiple victims approached us with materially similar losses that didn't appear to involve the usual causes, phishing, malware, or known seed exposure. At first, we suspected insider involvement, but it was an early working hypothesis, not a conclusion, and we did not accuse anyone. Our investigation concluded it was a function/failure of the seed generation entropy.
We understood enough to recognize that the weak seed entropy involved warranted escalation, and we reported what we had to the company for review and federal law enforcement. Because these matters involve victims and ongoing investigations, we never responsibly disclose the underlying evidence or comment much further. We can't sensationalize active cases or present speculation as fact.
If you believe your Bitcoin was stolen because of the @COLDCARDwallet vulnerability, report it to law enforcement as soon as possible.
Do not assume your case is too small, too technical, or too late to report.
Start with your local police department. Ask to file an official report and request that it be routed to a detective who handles cybercrime, financial crimes, or cryptocurrency investigations.
If you are in the United States, also submit a complaint through the FBIโs Internet Crime Complaint Center at https://t.co/xVqo6Zx6v3. You can contact your local FBI field office as well.
Before making the report, collect what you have:
โข The wallet address from which the Bitcoin was stolen
โข The destination address or addresses
โข Transaction hashes
โข The amount taken
โข The date and time of the transactions
โข Your COLDCARD model
โข The firmware version used when the seed was generated
โข The approximate date the seed was created
โข Purchase records, screenshots, emails, or other supporting information
โข Any report or complaint numbers you have already received
Preserve the device, seed backup, packaging, receipts, and related records. Do not destroy or reset anything that could later help establish ownership or support the investigation.
Most importantly, do not share your seed phrase, private keys, PIN, or sensitive personal information with anyone offering to recover your funds.
Victims of cryptocurrency theft are frequently targeted a second time by people pretending to be investigators, attorneys, recovery specialists, or government officials.
What we can do is help victims understand how to report the theft and help participating law enforcement agencies identify related investigations and reach the appropriate investigators.
If you were affected and do not know where to begin, send Deconflict a DM.
Do not include your seed phrase, private keys, PIN, Social Security number, identification documents, or other sensitive information.
We will help point you toward the appropriate law enforcement reporting channel.