Detection is solved. Four exploits this week, all flagged within minutes.
Response isn't. It runs on relationships most teams don't have until the morning they need them.
The platforms trace. We run the response.
How the BU War Room works, end to end 👇
https://t.co/QQ0I50pVnl
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 16, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
DefiLlama's founder says the company delayed its mobile launch over phishing apps on Apple's store. The founder said Apple removed one fake app within days after the company documented it draining funds from a small crypto wallet. (via @Cointelegraph)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- A Nevada police bodycam reportedly captured a suspect's crypto seed phrase, and the wallet was drained of more than $1.1 million shortly after the video was published, according to a post that also urged obscuring seed-phrase words. (via @officer_secret)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 15, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
Germany's BKA said three suspects were arrested in Europe on fraud charges tied to allegations that a vulnerability at a service provider was exploited to withdraw funds from Commerzbank customers' accounts; Brazil's federal police said four others were arrested on similar charges. (via @TheRecord_Media and @BleepinComputer)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- Approximately $8.07 million was reportedly lost from Coinsbuy across TRON and Ethereum in under an hour, with ten drained wallets reportedly refilled within half a day; no cause has been disclosed. (via @RektHQ)
- Galaxy Research said Coldcard Bitcoin thefts have slowed but losses could top $150 million, with researchers suggesting the lull likely means vulnerable holders migrated or were already emptied. (via @decryptmedia)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- French authorities confirmed unauthorized access to systems at the Directorate General of Public Finances in late June after someone's identity was stolen or misused; a hacker is reportedly selling personal and financial records tied to more than 678,000 taxpayers and businesses. (via @TheRecord_Media and @decryptmedia)
- The Netherlands' NCSC warned that hackers are actively exploiting a macOS authentication bypass vulnerability to deploy a Monero miner after public exploit code emerged. (via @BleepinComputer)
- Researchers described a malware campaign said to target malware analysts and reverse engineers via a website flagged as malware, with triage tools identifying the sample as the XRed family. (via @vxunderground)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- The OCC said it granted preliminary conditional approval to World Liberty Trust Co., the Donald Trump-backed entity seeking to become a national trust bank. (via @CoinDesk and @TheBlockCo)
- Kalshi was ordered to stop a broad range of prediction markets in Washington, with initial geofencing required by Aug. 19 and a GeoComply multi-source system by Sept. 2. (via @Cointelegraph)
- Ireland proposed stricter AML measures on transfers from private crypto wallets and overseas digital asset companies as part of planned industry standards addressing illicit crypto use. (via Cointelegraph)
𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀
- Binance said it will stop processing transactions involving 11 crypto platforms, including HTX, which was recently listed in the EU's sanctions package targeting Russia, citing regulatory compliance needs. (via @Cointelegraph and @TheBlockCo)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 14, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
A South Korean court sentenced Jeong Sang-ho, head of Delio, to 15 years in prison for alleged embezzlement of digital assets from more than 1,100 customers, more than a year after he was indicted on fraud charges. (via @Cointelegraph and @CoinDesk)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- A firmware vulnerability in ColdCard hardware wallets reportedly routed the device RNG to a guessable software fallback, allowing attackers to brute-force seeds offline; $130 million has reportedly been stolen so far by at least 15 attackers, with most funds still untouched. (via @RektHQ)
- Trezor disclosed a data breach affecting nearly 14,000 customers after ShipMonk, its shipping and logistics provider, was hacked, marking the first known exposure of Trezor customers' shipping addresses. (via @BleepinComputer)
- A Google ad phishing scam drained $550,000 from a Hyperliquid user, according to a security specialist; in April, Security Alliance said it had blocked 356 malicious Google ad URLs over several weeks. (via @TheBlockCo)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- FBI Detroit added Darren Anthony Robinson to the FBI Most Wanted Fraudsters list for his alleged involvement in an international investment fraud and money laundering scheme connected to QYU Holdings. (via @FBI)
- FBI Newark added Rey E. Grabato II to the FBI Most Wanted Fraudsters list; he is wanted for conspiracy to commit securities fraud, securities fraud, wire fraud, and conspiracy to defraud the US on tax. (via @FBI)
- Mayor Brandon Scott and the Baltimore City Council sued Kalshi and Polymarket over alleged illegal sports betting, with the complaint naming Robinhood, Webull, and Coinbase as Kalshi partners. (via @TheBlockCo and @Cointelegraph)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. (via @BleepinComputer)
- The ShinyHunters extortion group reportedly stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to a data breach notification service. (via BleepingComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- Tether said it completed its long-promised financial audit, with KPMG U.S. examining its books; the audit covered Tether's 2025 financial statements and found reserves exceeded liabilities by $6.8 billion. (via @CoinDesk)
- The Trump administration announced it will allow private companies to launch attacks on cybercrime organizations. (via @TheRecord_Media)
- Ireland's first national AML strategy introduces enhanced checks on private crypto wallets and stricter due diligence for firms dealing with overseas crypto companies. (via @decryptmedia)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 13, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
South Korea sentenced Delio's CEO to 15 years in prison in connection with a $50 million crypto fraud, shorter than the 20-year term prosecutors sought after the judge acquitted Jeong of a primary charge. (via @TheBlockCo)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- A whale identified as TLBL reportedly had its private key compromised, with over $26M in assets drained across three wallets. (via @lookonchain)
- The ColdCard wallet incident remains active at approximately $130M, described as the largest hardware-wallet exploit on record, with at least 15 attackers reportedly exploiting the same seed-generation bug. (via @hackenclub)
- Unknown victims were reportedly drained of $25.6M in crypto, including aWBTC, DAI, WBTC, and ETH; the hacker swapped the funds and now holds them across four addresses. (via @PeckShieldAlert)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- An Arizona crypto ATM law helped 35 scam victims recover $171K, with qualifying new customers eligible for full reimbursement if they notify the operator and law enforcement within 30 days. (via @Cointelegraph)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- North Korean hackers reportedly exploited a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. (via @BleepinComputer)
- A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool to steal live card data and relay it to attackers in real time. (via @BleepinComputer)
- Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms have been detected, potentially allowing attackers to hijack customer accounts. (via BleepingComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- The SEC said it will not pursue enforcement action if Franklin Templeton's funds invest cash in its own tokenized money market fund, enabling traditional registered funds to use its BENJI/FOBXX system. (via @TheBlockCo)
- The SEC plans a framework for tokenized stocks, with an announcement possible as soon as Friday. (via @decryptmedia)
- Copper Markets US became a FINRA member and secured SEC broker-dealer approval to offer qualified custody, staking, financing, and OTC services. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 12, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
A security team says it fully reproduced an attack chain exploiting a reported private-key vulnerability in the Coldcard wallet, with at least 1,719 BTC (approximately $111M) in losses across over 5,200 addresses. Using Mk3 firmware 4.1.9, researchers traced the flaw to weak randomness during seed generation that let attackers brute-force candidate wallets and sweep funds. (via @SlowMist_Team)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- Harmony confirmed an exploit involving unauthorized minting of ONE tokens and is working with exchanges to freeze funds while preparing a patch. Reports cited unauthorized minting figures of 2.8 billion and four billion ONE tokens reaching trading platforms. (via @TheBlockCo and @Cointelegraph)
- An attacker created unbacked XRP on another blockchain, then exchanged it for real XRP held in reserve, draining an XRP bridge of $200,000. The bridge has been halted, and its operator has filed a complaint with the FBI. (via @CoinDesk)
- Mining pools controlling most of Ravencoin's hash rate are building a competing chain that could trigger a three-day reorganization following a network exploit, as the token hit a record low. (via @Cointelegraph and @decryptmedia)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- The SEC and CFTC sued Goliath Ventures over an alleged $400M crypto Ponzi scheme. Regulators allege the firm promised crypto liquidity-pool returns but instead paid earlier investors and funded its founder's luxury spending. (via Cointelegraph)
- The CFTC brought fresh charges against a Florida man over an alleged $397 million crypto Ponzi scheme, saying he misappropriated $48 million of customers' money. (via @TheBlockCo)
- Australia's ASIC took down Yepbit websites as investors reported blocked withdrawals, and the regulator denied the platform's false claims that ASIC had frozen investor funds. (via TheBlock)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- The DeadLock ransomware operation is using decentralized infrastructure that relies on blockchain-backed services to protect its victim communications and data-leak activity, an approach described as resisting infrastructure takedown. (via @BleepinComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- The CFTC ordered Kalshi to continue offering prediction markets after New York sued the platform in a bid to block sports-related prediction markets. Kalshi triggered the order by notifying the agency of a market emergency. (via @decryptmedia and @CoinDesk)
- The SEC set an open meeting to consider moving forward with its Regulation Crypto proposal, described as an alternative route from securities registration for crypto projects. (via Decrypt)
- Russia is moving to restrict retail crypto trading to bitcoin, ether and USDT, with non-qualified investors facing a 300,000-ruble (approximately $3,600) annual purchase limit per intermediary. (via CoinDesk)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 11, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
Connor Riley Moucka of Kitchener, Ontario, pleaded guilty to a computer hacking conspiracy that, according to the FBI, compromised over 165 victim organizations, involved the theft of billions of sensitive customer records, and included the extortion of numerous victims. (via @fbi)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- BTCPay said it will pay 10% of recovered funds, up to 3 BTC, after attackers stole LND credentials and drained merchant Lightning wallets last week. BTCPay said AI may have been used to exploit the vulnerability. (via @CoinDesk and @TheBlockCo)
- Coinsbuy said it covered all affected client funds after unauthorized withdrawals, while an onchain investigator estimated more than $7.9 million was stolen. The attacker moved funds across Tron and Ethereum before routing millions through crypto exchanges. (via @Cointelegraph and @decryptmedia)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- Daniel Kinahan, alleged leader of a major Irish organized crime group, was extradited from Dubai and charged with directing a criminal organization. He was ordered to remain in prison while awaiting trial for his alleged role in running a global drug smuggling empire. (via @ICIJorg and @OCCRP)
- A member of "The Com," described as a loose-knit online cybercrime collective targeting children and teenagers, was sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. (via @BleepinComputer)
- AUSTRAC suspended the registration of Cryptolink, the operator of 96 of Australia's roughly 1,800 crypto ATMs, effective August 9, citing missing transaction reports and the company's failure to respond to an information request. (via @decryptmedia and @CoinDesk)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide about Gunra ransomware, saying the gang is breaching targets through vulnerabilities in popular brands of firewalls. (via @BleepinComputer and @TheRecord_Media)
- CISA confirmed ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability that has been flagged as actively exploited since early July. (via BleepingComputer)
- CISA confirmed ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery flaw. (via BleepingComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- The SEC will vote this week to begin its first major crypto rulemaking process, proposing Reg Crypto to support certain digital-asset offerings. (via CoinDesk)
Follow BlockchainUnmasked for your daily news digest every morning
We've worked alongside many world class legal teams, and the question of getting government frozen or seized assets back into the hands of victims has become increasingly important.
https://t.co/wyNCZ2j9ZE
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 10, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
Bybit has sued North Korea over the $1.5B hack and won an order freezing assets. The exchange says it has recovered $48.4 million and frozen $30.5 million more, a fraction of what the Lazarus Group took in February 2025. (via @decryptmedia)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- Wallets linked to Coinsbuy were reportedly drained of more than $7.9M across Ethereum and TRON. The attacker began laundering funds into Monero, while ChangeNOW reportedly helped freeze a six-figure amount before services resumed. (via @DarkWebInformer)
- Researchers flagged a roughly $136K exploit on usmfum in which the attacker flash-loaned ETH to manipulate internal pricing, then used defund() in 64 pieces to extract profit from asymmetric price calculations. (via @CertiKAlert)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- A US-based threat actor named Tiffany Milanovich is tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams. She has reportedly recorded herself taunting victims after draining their funds and flaunts luxury purchases on social media. (via @zachxbt)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- North Korea's Kimsuky group uses generative AI to produce phishing documents themed around digital assets, investment strategies, and fintech services in cyberattacks targeting crypto and finance. (via @TheBlockCo)
- Valve is notifying Steam hardware customers in Europe that hackers stole their data after breaching its shipping partner, CEVA Logistics. (via @BleepinComputer)
- CISA warned that hackers are actively exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. (via @BleepinComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- The UK's FCA is reportedly preparing a regulatory framework for tokenized gold and how these products may be used as collateral in wholesale markets. (via @CoinDesk and @Cointelegraph)
- Brazil is set to require a 24-hour wait on crypto transfers to self-custody wallets, covering cryptocurrencies including fiat-backed stablecoins, effective January 1, 2027. (via @TheBlockCo)
- Australia's financial watchdog suspended Cryptolink's registration for three months over basic reporting failures, adding to a crackdown that previously saw the Bitcoin ATM operator fined $56,340. (via Cointelegraph)
𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀
- New Zealand announced new sanctions on Russian hackers, technology companies, and Kremlin-linked organizations over their roles in supporting Moscow's war against Ukraine. (via @TheRecord_Media)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 9, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The activity targets servers that have not been patched. (via @BleepinComputer)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- BTCPay restricted remote Lightning access after attackers stole funds from drained nodes reported by Foundation and Citadel21. The total amount stolen and the number of affected operators remain unknown. (via @Cointelegraph)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- The Cl0p ransomware group claims 44 victims, including Mindray, a global medical technology manufacturer, and Continental Aerospace Technologies, a U.S. aerospace manufacturer. The claims are unconfirmed. (via @DarkWebInformer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- Brazil's central bank ordered exchanges to delay large crypto transfers abroad, covering transactions above $10,000 sent to overseas providers or self-custody wallets, along with other flagged transfers. The rules take effect January 1, 2027. (via @CoinDesk)
- Senate Majority Leader John Thune filed a cloture motion putting the CLARITY Act on track for a mid-September Senate vote, as lawmakers continue negotiations over ethics and stablecoin provisions. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
Orange pilled my mate down the pub last night.
Honestly, it’s so simple once you explain it properly.
I told him Bitcoin is just money you hold yourself.
He liked that. Then he asked how you hold it.
So I explained you buy a hardware wallet, but obviously not that one, and not that one either.
Then I said don’t trust its randomness, you’ll want to generate your own entropy with dice.
He said “like Monopoly dice?”
Bless him.
No, mate. Casino-grade precision dice, and verify they’re fair first, because a biased die is a biased seed.
Then I said roll it 99 times.
He asked why not fewer.
I explained that anything less than 99 rolls gives you less entropy, and while 50 rolls and 12 words is technically unbreakable by every computer that will ever exist, we don’t do technically round here. We do 256 bits.
He asked what a bit was. I told him not to worry about it.
Then I explained you do this in a room with no phone, no smart speaker, no camera, ideally soundproofed, because the acoustics of a dice roll and your keystrokes are a side channel.
He’d gone quiet by then, so I gave him a minute.
Then I said you’ll want 3 seeds, not 1, because single points of failure are what wiped out 500 people last week. So that’s 297 dice rolls.
Then multisig, 2-of-3, and you’ll need to back up the descriptor as well as the words, because 3 seeds alone won’t rebuild the wallet, and yes, that’s a fourth thing to lose.
Then I said store the 3 backups in 3 separate locations, because if a burglar or a house fire gets two, you’ve achieved nothing.
He asked where.
I said somewhere fireproof, ideally stamped in steel, definitely not the loft.
Then I mentioned the Faraday bag.
And the airgap.
And that you sign transactions by waving QR codes at a Raspberry Pi you built yourself.
And that you should rehearse the whole thing on a parallel test network with fake coins first, obviously.
He asked what happens if he gets it wrong.
I said you lose everything forever, and nobody is coming to help you.
Anyway, that’s another one onboarded. 💪
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 8, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
TRM Labs said it traced USD 6.3 billion through Shelbit, an unlicensed Dubai exchange with alleged IRGC, Hamas and Russian sanctions exposure. Separately, the U.S. Treasury sanctioned two crypto exchanges it says laundered millions of dollars for Iran's Revolutionary Guard, naming a Georgia- and UAE-based operator and an Iran-based platform. (via @trmlabs and @decryptmedia)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- BTCPay Server disclosed that a critical vulnerability is being actively exploited and urged users running LND to update to version 2.4.2 immediately or take servers offline, after attackers stole credentials capable of controlling Lightning wallets and moving funds. It remains unclear how many servers were compromised or whether funds were stolen. (via @CoinDesk and @DarkWebInformer)
- An address labeled as the Aztec Private Rollup Bridge exploiter deposited a total of 500 ETH into Tornado Cash, including 300 ETH worth approximately $572,100. Aztec suffered an exploit in June 2026 with losses totaling $2.165M in crypto. (via @PeckShieldAlert)
- SlowMist reported a loss of 29,984.27 USDC from https://t.co/q9D63Wex4u, attributing the root cause to a signature replay across 21 position IDs combined with flashloan price manipulation. (via @SlowMist_Team)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- Bybit secured a preliminary injunction freezing stolen assets in a suit against North Korea and the Lazarus Group over a $1.5 billion hack. A U.S. court also granted expedited discovery, allowing the exchange to seek account identities, balances and transaction histories from platforms with U.S. operations. (via @CoinDesk and @Cointelegraph)
- The FSB said at least 20 individuals were arrested in connection with a ring that scammed an undetermined number of Russian citizens, as Russia cracks down on unlicensed crypto exchanges it claims are linked to Ukraine. (via CoinDesk)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. (via @BleepinComputer)
- Microsoft said compromised websites are retrieving malicious instructions from BNB Chain before tricking visitors into running them on Windows devices through fake CAPTCHAs. (via @decryptmedia)
- WordPress patched CVE-2026-64638, a CVSS 8.9 pre-authentication XSS flaw in the login screen requiring no account; NHS England says exploitation is likely following release of technical details. (via @DarkWebInformer)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 7, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
Connor Riley Moucka, a 26-year-old Canadian man, pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used cloud data storage provider Snowflake. He also admitted to stealing call and text history records of more than 100 million AT&T customers. (via @briankrebs)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- The Coldcard hacker, who reportedly stole 2,055 BTC ($130M), transferred 30.185 BTC ($1.94M) to a new wallet. (via @lookonchain and @CoinDesk)
- The Jaredfromsubway exploiter, who reportedly stole $7.7M a month earlier, sold 2,327 ETH at $1,695 then bought back 2,063 ETH at $1,912, losing 264 ETH ($505K). (via @lookonchain)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- A Belarusian national was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation, with authorities noting he had been active in the cybercriminal world for decades. (via @TheRecord_Media)
- U.S. prosecutors allege Taj Tarsha diverted investor funds meant for a new digital marketplace to pay for online gambling, a Miami condo, and his DJ hobby; his attorneys say he is innocent. (via @OCCRP)
- Russia shut down nine unregistered crypto exchanges in Moscow, with the FSB alleging they helped move scam proceeds abroad through Ukrainian call centers. (via @Cointelegraph)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. (via @BleepinComputer)
- A wave of cyberattacks targeting hedge funds and private-equity firms has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. (via @BleepinComputer)
- Meta confirmed one of its Muse Spark models hacked a real organization during cybersecurity testing after a configuration error by an outside testing partner gave it internet access. (via BleepingComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- Putin signed Russia's first crypto law, creating a licensed, central bank-supervised trading market for digital assets while keeping crypto barred from everyday payments. (via @decryptmedia)
- Wintermute USA registered as a broker-dealer with the SEC and FINRA, gaining the ability to trade U.S. stocks, options, and crypto ETFs as a New York-based subsidiary. (via @TheBlockCo)
- Japan's FSA called on crypto exchanges to impose withdrawal delays, address registration, customer-specific limits, and stronger authentication to curb account misuse. (via @Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 6, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
Maksim Silnikau, described as the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. (via @BleepinComputer)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- Hacken reported that AFX Bridge was exploited twice through the same vulnerability. The firm said $97M was lost across 14 incidents in July, up 29% from June, with 88.3% traced to compromised keys and operational failures rather than code. (via @hackenclub)
- An address labeled as a TripleA exploiter deposited 2,620 ETH, worth approximately $4.97M, into Tornado Cash. TripleA had suffered an unauthorized drain of $10M worth of crypto on July 25, 2026. (via @PeckShieldAlert)
- An attacker drained approximately 500K USDC from a victim wallet on Base. The attacker's subsequent swap lacked adequate slippage protection and was sandwiched by an MEV bot, reportedly leaving the attacker with about 67 WETH, worth about $129K. (via @PeckShieldAlert)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- A Canadian man pleaded guilty to accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions from victims. The 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft, and conspiracy charges tied to the 2024 hacks. (via @BleepinComputer and @TheRecord_Media)
- Federal prosecutors charged Taj Tarsha, saying he misled backers of the NFT marketplace Few and Far and diverted investor funds raised for a Web3 platform to personal expenses including gambling, trading, and a DJ hobby. (via @CoinDesk and @decryptmedia)
- France's watchdog says fraudsters are impersonating its own staff to persuade stranded customers to move assets to fake websites. EU watchdogs warned that scammers are posing as crypto firms and regulators after the MiCA deadline, with firms lacking authorization by July 1 required to wind down or restrict services to EU clients. (via @decryptmedia and @TheBlockCo)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- A phishing campaign is exploiting fears surrounding the disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. (via BleepingComputer)
- Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow, with South Dakota and Georgia announcing incidents. (via @TheRecord_Media)
- A House committee report concluded that three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns. (via The Record)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- Russian President Vladimir Putin signed a crypto law establishing market rules for exchanges, custodians, and investors, with core provisions taking effect in September 2026. The law continues to ban using crypto to pay for goods and services within Russia while allowing use for cross-border settlements. (via @Cointelegraph and @TheBlockCo)
Follow BlockchainUnmasked for your daily news digest every morning
Happy to share that we have been accepted into @iafci and joined the Arizona Chapter. After speaking at an IAFCI event in Denver earlier this year, we’re excited to officially become part of the community and contribute to the fight against financial crime.
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 4, 2026
Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆
The Coldcard Bitcoin theft has topped $100 million across three confirmed attack waves, with researchers examining a suspected fourth wave that could lift total losses to $130 million. Researchers said 90% of the stolen Bitcoin remains unmoved and the full scope is not yet settled. (via @TheBlockCo and @Cointelegraph)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
- Boltz, described as a non-custodial protocol, paused its service after a wave of AI-assisted hacking attempts. The protocol said attackers are discovering and adapting exploits faster than its small development team can identify and patch them. (via @Cointelegraph)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
- A former FBI supervisory agent with top-secret clearance pleaded guilty to stealing about $1 million in digital assets from an adversarial country and forfeited about $925,000 to government-controlled wallets. (via Cointelegraph and CoinDesk)
- Five people were convicted in a London case involving the imprisonment of crypto millionaires in what police described as a torture ordeal. Two of the five were also convicted of conspiracy to blackmail, in a case won without either victim testifying. (via @decryptmedia)
- US authorities fined UBS a record $125 million for what were described as willful anti-money laundering violations. (via @OCCRP)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
- Researchers analyzed thousands of underground posts and found the BTMOB Android RAT malware operation has evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. (via @BleepinComputer)
𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆
- A New York judge denied a CFTC motion to halt an enforcement action against Kalshi, leaving the state case in place while allowing the CFTC to renew its request before Judge Victor Marrero. (via Cointelegraph)
Follow BlockchainUnmasked for your daily news digest every morning
Both. Based on the victim cases, we had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We did not know the exact implementation bug that's now public. But the company had significant and sufficient information to reasses their firmware, seed generation entropy and potentially notify their own customers.
That's why we disclosed it privately to the manufacturer and law enforcement instead of making public accusations or technical claims we couldn't substantiate.
We work alongside local, state, and federal law enforcement every day. We routinely become aware of crimes, vulnerabilities, and active investigations long before they become public, and our responsibility is to report them through the usual channels.
In 2024, victims came to us with bitcoin missing from Coldcard wallets. No malware, no phishing. We traced it to weak seed entropy and filed reports with the manufacturer and multiple agencies. Two years later: $38M swept in 25 minutes.
https://t.co/3veIXZYoWP
Tay, with respect, that's not an accurate characterization, and this bums me out given the rapport in the past.
We investigated multiple victim cases, identified an unusual pattern, notified the manufacturer, worked with local, state, and federal law enforcement, and focused on tracing the stolen funds.
That's what blockchain forensic investigators do.
We are not firmware researchers or bug bounty hunters, and we weren't in a position to publicly accuse a company or disclose an ongoing investigation before the facts were established. We had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We disclosed it to the parties who could investigate, notify customers if necessary, issue firmware updates, and pursue those responsible.
We don't speculate publicly, and we don't expose ourselves or others to unnecessary allegations of libel or slander by making claims we can't substantiate. The article explains what we observed, what we did, and what we did not conclude.
All of our data, findings, victims that approached us then, and reporting was and is again being shared with federal law enforcement.
We did at the time (2024), and are now presenting all findings to law enforcement and legal teams working on this versus disclosing victim information or specifics of an ongoing investigation. Because we're a fraud investigation firm who works alongside law enforcement and lawyers vs a bug bounty firm, we handle cases a bit differently.
Fair skepticism. We didn't identify the specific code-level bug now being discussed, nor claimed we did here. In 2024, multiple victims approached us with materially similar losses that didn't appear to involve the usual causes, phishing, malware, or known seed exposure. At first, we suspected insider involvement, but it was an early working hypothesis, not a conclusion, and we did not accuse anyone. Our investigation concluded it was a function/failure of the seed generation entropy.
We understood enough to recognize that the weak seed entropy involved warranted escalation, and we reported what we had to the company for review and federal law enforcement. Because these matters involve victims and ongoing investigations, we never responsibly disclose the underlying evidence or comment much further. We can't sensationalize active cases or present speculation as fact.