On July 17, India's securities regulator warned listed companies about a fraud its national cybercrime agency calls the "Boss Scam". The advisory describes two strategies for it. Only one of them impersonates anyone.
Huge respect to @huggingface for the full technical timeline and transparency on the first autonomous agent cyberattack.
This is the new threat model: ~17,600 actions, 4.5 days, with no human operator. Pod to root to self-respawning fleet to supply-chain attempt, constantly rebuilding its own C2.
Every cybersecurity company should treat this post-mortem as required reading. AI-native threats won't wait for us to update our playbooks.
A Belarusian activist received a fake Telegram alert as part of a phishing operation that had been running for 22 months across the region.
The phishing link was individualized and traditional scanners missed it because of sophisticated device-aware cloaking. The fake site only appeared when the target user opened it.
We built Common Defense because Telegram needs stronger security.
Veltrix Capital, a fake blockchain trading firm, spent ten months building a recruiting pipeline to get crypto developers to run its code. Developers were contacted by fake recruiters on LinkedIn, Reddit and Facebook.
The firm had everything a candidate would check. A domain registered in April 2025, GitHub organisations hosting the projects, and an interview that ended in a take-home task: build this, run our package. The packages were real and bigmathutils gathered more than 10,000 downloads while it was still clean.
But on February 11 the authors pushed bigmathutils v1.1.0, which added a remote-access trojan with file transfer and a MetaMask wallet stealer. It was live for two hours before npm's security team pulled it and seized the account. The package saw more than 1,000 downloads that day, though only part of that window served the malicious version.
It's unknown how many developers were directly affected, but this was a patient and sophisticated phishing attack targeting crypto developers with access to wallet keys, likely orchestrated by Lazarus group.
Get protected at https://t.co/0p7vElkBkx
https://t.co/JbwWwGl743
Dear @SiloFinance team,
I am speaking on behalf of the community and as someone who is personally affected.
Following the xUSD depeg, approximately $60M in user funds remain frozen in Silo's xUSD and xBTC markets.
@StreamDefi is the primary bad actor, but Silo enabled them by:
• Allowing concentration risk
• Relying on Stream's oracle
• Insufficient due diligence on managed vaults
Legal action is necessary. Silo should join forces with Euler, Morpho, and other affected protocols to maximize pressure on Stream
While I appreciate the transparency report, critical questions remain unanswered:
1. How did Stream Finance become the dominant borrower without triggering concentration risk limits?
2. What is the relationship between Silo and @VarlamoreCap, which managed vaults heavily exposed to xUSD?
3. Why did Silo rely on Stream's self-reported NAV for oracle feeds without independent verification?
4. Why did you hide affected markets? It is terrible optics – it looks like Silo is trying to sweep the problem under the rug while promoting new products
I urge Silo to:
1. Restore UI visibility for affected markets with clear risk warnings (hiding them erodes trust)
2. Propose DAO vote on bad debt socialization options:
> Protocol treasury bailout (if feasible)
> SILO token dilution to compensate affected users
> Haircut distribution across all Silo users vs. isolated to affected markets
3. Implement structural reforms: concentration limits, independent oracles, vault management decentralization
4. Announce a schedule of regular legal action updates to keep the affected users well informed.
The DeFi community deserves to know:
• Was Varlamore's relationship with Silo disclosed to users?
• Were risk warnings provided for xUSD's leveraged nature?
• What safeguards failed, and how will they be fixed?
I publish this message because you never answered to my dm.
Transparency and decisive action are essential to restore trust. The longer funds remain frozen while new products are promoted, the more it appears users are being deprioritized.
Look forward to your response and concrete action plan.
Yesterday we enabled USDT markets in @0xARMAgeddon's logic and integrated @VelodromeFi. Let’s take a look at what ARMA did autonomously:
• Screened the entire @modenetwork ecosystem
• Identified a better strategy in USDT over USDC
• Analyzed risk-adjusted returns across all lending markets
• For $200K under management, examined each position's:
•• Size vs market depth
•• Gas costs vs yield differential
•• Swap fees and expected slippage
• Simulated multiple execution paths
• Orchestrated optimal migration strategy
• Withdrew strategically from USDC pools
• Executed gas-efficient swaps via Velo
• Deployed capital into superior USDT positions
0 humans were harmed during this process.
2024 was a watershed year for Ethereum
In 2025, it’s now time for the Ethereum ecosystem to step up its aggressiveness
The institutional adoption moment for blockchains is here
We’re at the start of a crypto Renaissance - and it’s Ethereum’s race to win.
Happy 2025 🚀
(6/6)