🔎 Had your crypto stolen? We can help investigate the trail, identify linked wallets, document transactions, and work with the appropriate authorities to help identify those responsible and pursue recovery options.
Message us with the details of what happened, and we’ll assess what can be done.
#CryptoRecovery #CryptoSecurity #Blockchain #Cybersecurity #Bitcoin #FraudPrevention
🚨 NEW: Crypto payments platform Coinsbuy was drained of more than $7.9M across Ethereum and TRON, according to on-chain investigator @SpecterAnalyst.
The attacker reportedly moved stolen funds through exchanges and converted them to Monero (XMR) to obscure the trail.
Meanwhile, @SpecterAnalyst says they helped freeze six figures of the stolen funds.
#Crypto #CyberSecurity #Blockchain #Ethereum #TRON #Monero #CryptoCrime
Did you know there's a type of phishing attack that defeats MFA completely.
It's called a reverse proxy phishing kit and it's one of the fastest-growing attack techniques in cybersecurity.
Traditional phishing works by using fake login page. you type your password. attacker gets it. if you have MFA enabled, the stolen password alone is useless. attacker gets stopped at the second gate.
reverse proxy is different.
instead of a fake page, the attacker sets up a live proxy server between you and the real website. when you click the phishing link, you connect to the attacker's server. the server connects to the real Microsoft, Google, or Okta on your behalf. it fetches the real login page and serves it directly to you, pixel for pixel in real time.
you're looking at the actual login page. you type your real password. the proxy relays it to Microsoft. Microsoft sends back an MFA prompt. the proxy relays that to you. you approve it. Microsoft sends back a session cookie.
the proxy intercepts the cookie before it reaches your browser.
You're logged in, so is the attacker using the same session.
Tools used: Evilginx, Modlishka, Muraena. all open source. all free. all with pre-built templates for Microsoft 365, Google Workspace, Okta, and PayPal.
commercial versions: EvilProxy, Tycoon 2FA, Mamba 2FA, Starkiller. Sold as subscription services on Telegram.
Reverse proxy phishing surged 139% between September 2025 and March 2026, nearly 1 in 4 phishing links now carries a reverse proxy payload.
18 US universities hit last year. Microsoft 365 campaigns targeting thousands of organizations globally.
The only authentication method that stops this completely: FIDO2 passkeys and hardware security keys. They bind credentials to the real domain. The proxy can't replay them because the credential was never issued for the proxy's domain.
Everything else, SMS codes, authenticator apps, push notifications can all be relayed.
🚨 Did you know attackers can bypass MFA without exploiting a single line of code?
Sometimes, they simply overwhelm you until you approve the login.
It’s called MFA fatigue, also known as push bombing.
The attacker already has your password from a breach, phishing campaign, or leaked credentials. They attempt to log in, MFA blocks them, and your phone gets an approval request.
You deny it.
They try again.
And again.
Dozens of notifications later, you’re tired, distracted, or frustrated enough to hit “Approve” just to make the alerts stop.
That’s the entire attack.
In September 2022, an attacker reportedly used this technique against an Uber contractor, repeatedly sending MFA requests until one was approved. The attacker then reportedly posed as Uber IT and convinced the contractor to confirm the login, gaining access to internal systems.
🔐 How to make MFA fatigue attacks harder:
• Use number-matching prompts instead of simple “Approve/Deny” notifications.
• Consider FIDO2 security keys or passkeys.
• Never approve an MFA request you didn’t initiate.
• If you receive unexpected prompts, deny them and change your password immediately.
MFA is powerful, but how you configure and use it matters.
#Cybersecurity #MFA #InfoSec #Phishing #AccountSecurity #FIDO2 #Passkeys
🚨 A roughly $136K exploit has reportedly hit @usmfum.
The attacker used a flashloan to manipulate the protocol’s internal pricing through fund(), then called defund() across 64 separate transactions.
The exploit appears to stem from an asymmetric average-price calculation involving geometric and arithmetic means, allowing the attacker to extract profit from the pricing discrepancy.
Stay vigilant. 🔎
#CertiK #DeFi #CryptoSecurity #BlockchainSecurity #SmartContracts
🚨 Another disturbing death has emerged from the crypto world.
On the morning of August 7, the body of crypto investor Harry Yeh (叶俊德) was reportedly found beneath the Jade Park luxury apartment complex in Asunción, Paraguay, after a fall from the 30th floor.
Reports say he was found naked and covered with a black plastic bag. Police reportedly found the door to his 30th-floor apartment open and the residence in disarray. Yeh also had another apartment on the 27th floor, where his 29-year-old Brazilian partner lived, who reportedly said they were unaware of what happened.
Authorities are investigating multiple possibilities, including an accident, suicide, and homicide. An autopsy is reportedly still pending.
Yeh was an early crypto investor, entering the market around 2013 when Bitcoin was trading near $60. He later founded Quantum Fintech Group and claimed to manage more than $2.4B in assets.
He was also closely involved with the Fantom ecosystem, including taking over Tomb Finance and backing projects such as LIF3 and L3USD.
May he rest in peace. 🕊️
Beyond the circumstances of this case, it highlights a serious issue for high-profile crypto holders: blockchain transactions can offer financial privacy, but personal security is much harder to keep private.
When large holdings, public wallets, and an expensive lifestyle become associated with a real-world identity, the risks can increase significantly.
Crypto investors often focus heavily on protecting private keys and assets—but personal safety deserves the same attention.
#Crypto #Bitcoin #CryptoSecurity #Cybersecurity #Blockchain #SelfCustody
🚨 275 contracts were flagged for the same suspicious pattern between July 30 and August 1, linked to two exploits that drained roughly $34K.
Glider Monitor detected both incidents:
• Unverified contract - ~$32K lost, 269 contracts exposed
• AscensionLaunch_v1_14 - ~$2K lost, 6 contracts exposed
The activity affected both Ethereum and BNB Chain.
💡 The losses were relatively small, but the number of exposed contracts shows how wide the potential impact can be.
#CryptoSecurity #DeFi #Ethereum #BNBChain #SmartContracts #Cybersecurity
🚨 THREAT INTEL: A threat actor appears to be operating an entire cybercrime infrastructure from a single unsecured VPS.
An exposed directory reportedly reveals a complete Pequod botnet toolkit, including exploit tooling, SSH credentials, proxy accounts, bot infrastructure, and prebuilt target lists.
After compromising exposed Docker, Ray, Kubernetes, Redis, Jupyter, and Jenkins services, the attackers reportedly deploy persistence, XMRig for Monero mining, and reverse-proxy infrastructure.
Compromised systems are then allegedly used for crypto mining, AI/ML abuse, residential proxy fraud, affiliate fraud, and large-scale spam campaigns. Stolen databases are also reportedly being promoted through Telegram.
The biggest failure? The infrastructure appears to have almost no operational separation. C2, staging, proxy services, and logs are reportedly hosted on the same server, with sensitive credentials left exposed.
In other words, the attackers may have built a sophisticated operation, but their OPSEC appears anything but sophisticated.
#PequodBotnet #ThreatIntel #OpSecFail #CryptoMining #AffiliateFraud #AIThreat #CyberSecurity
🚨 The death of crypto investor Harry Yeh after a reported fall from a building in Paraguay highlights a darker issue facing the industry.
Over the past seven years, at least 10 crypto figures have reportedly died or experienced serious violent incidents.
Some notable cases include:
• 2018 - QuadrigaCX founder Gerald Cotten died, leaving roughly C$250M in customer funds inaccessible.
• 2021 - Bitcoin holder Mircea Popescu, reportedly holding more than $100M in BTC, drowned in Costa Rica.
• 2022 - MakerDAO co-founder Nikolai Mushegian died after posting alarming claims about the CIA and Mossad. He later drowned in Puerto Rico.
• 2022 - Amber Group co-founder Tiantian Kullander died suddenly at age 30.
• Aiden Pleterski, dubbed the “Crypto King,” was kidnapped and reportedly tortured by investors.
• 2024 - Montreal crypto influencer Kevin Mirshahi was kidnapped and later found dead.
• 2024 - Russian crypto couple Roman and Anna Novak were reportedly kidnapped in the UAE and murdered after being forced to surrender wallet credentials.
• 2025 - Ledger co-founder David Balland was kidnapped and suffered serious hand injuries before being rescued.
The common thread is disturbing: individuals believed to control significant crypto holdings becoming targets of kidnapping, coercion, social engineering, and other forms of violence.
Crypto self-custody gives people direct control over their assets, but it can also make the individual holding the keys the primary target.
Decentralization protects financial control. It doesn’t eliminate the need for personal security.
#Crypto #Bitcoin #Cybersecurity #CryptoSecurity #SelfCustody #Blockchain
🚨 ZachXBT reportedly links Tiffany Milanovich to more than $5M in alleged crypto thefts.
Blockchain investigator ZachXBT has published an investigation into the U.S.-based threat actor, alleging involvement in social-engineering schemes that targeted cryptocurrency users.
• The alleged operations impersonated hardware-wallet and centralized-exchange support teams.
• Recordings reportedly show Milanovich taunting victims after their funds were drained.
• The investigation also highlights alleged displays of stolen crypto, luxury spending, and gambling activity.
• ZachXBT reportedly links Milanovich to John “Lick” Daghita, who was arrested earlier this year in connection with the alleged theft of more than $46M in crypto from U.S. government-controlled wallets.
⚠️ These remain allegations from an independent investigation and should not be treated as established criminal findings unless supported by court records or law-enforcement action.
#Crypto #CryptoSecurity #Cybercrime #DarkWeb #Intelligence #Blockchain #Cybersecurity #DDW
🚨 GoPlus Security Alert:
B2B crypto payment processor @coinsbuycom reportedly had associated wallets drained across Ethereum and TRON, with losses estimated at around $7.9M.
The attacker then began moving the stolen funds through Monero (XMR), using CEXs including ChangeNOW, FixedFloat, and BingX.
🔎 A few notable points:
1️⃣ Coinsbuy’s X account has been inactive since 2020, while its developer documentation continues to receive updates.
2️⃣ The attack pattern appears consistent with a possible hot-wallet private-key or administrative-privilege compromise. A July 10, 2026 release note also highlighted fixes involving transfer verification, node balances, and fund-consolidation logic. This doesn’t establish the root cause, but it shows the complexity of the system’s operational and accounting infrastructure.
3️⃣ Reported attacker addresses:
0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3
0x66790b54B891e2ebdef58a15B969Ff6fb4374b17
TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR
#CryptoSecurity #Cybersecurity #Ethereum #TRON #Monero #XMR #CryptoHack #BlockchainSecurity
🚨 BIP-110 developers are reportedly preparing a proof-of-work change for a planned September 1 fork, as Luke Dashjr is said to have lost permission to access the BIP content repository.
Dashjr says a recent developer meeting “went well,” with plans reportedly moving ahead for a Bitcoin hard fork that would introduce a new PoW algorithm.
The team is expected to reveal the selected hashing algorithm tomorrow, with RTDS reportedly active from the first block. A blocksize reduction and replay protection are also being discussed.
The development comes as Dashjr is reportedly no longer a permitted user of the BIP content repository.
If the fork goes ahead with a new PoW system, it would create a separate blockchain and effectively a new altcoin, with existing BTC holders potentially receiving an equivalent balance on the forked chain
#Bitcoin #BIP110 #BTC #Crypto #BitcoinFork #ProofOfWork
🚨 SHOCKING: The parents of a 19-year-old accused of stealing $245M in Bitcoin were reportedly targeted by two separate kidnapping crews.
Six Florida men allegedly rammed the family’s Lamborghini, assaulted them, and attempted to kidnap them in broad daylight before an off-duty FBI agent and witnesses intervened.
Then, according to the DOJ, three men from Missouri allegedly followed the same family for two days using air rifles and walkie-talkies while planning a home invasion.
Even more bizarrely, the 19-year-old later allegedly stole another $2M while cooperating with federal investigators.
#Bitcoin #Crypto #Cybercrime #CryptoCrime #Cybersecurity #BTC #DOJ
🚨 1/ Meet Tiffany Milanovich, a US-based threat actor reportedly linked to at least $5M in losses through hardware-wallet and centralized-exchange support impersonation scams.
She has allegedly recorded calls with victims and taunted them after their funds were drained.
She also reportedly flaunts luxury purchases, casino gambling, and alleged proceeds from the stolen funds across social media.
#CryptoScam #CryptoSecurity #Cybercrime #HardwareWallet #Bitcoin #BlockchainSecurity #Fraud #Cybersecurity
���️ LATEST: A US court has granted Bybit a preliminary injunction to freeze assets linked to the $1.5B Lazarus Group hack in 2025.
The court reportedly found that Bybit had “demonstrated a likelihood of success on the merits.”
#Bybit #LazarusGroup #Crypto #Cybersecurity #CryptoSecurity
🚨 This developer sent Bitcoin to a compromised Coldcard Mk3 wallet just to test how quickly the stolen funds would be swept.
A real-world demonstration of just how fast an exploited wallet can be drained once funds hit the compromised address. 😳
#Bitcoin#Coldcard #CryptoSecurity #Cybersecurity #BTC
🚨 THIS WAS ONE OF THE BIGGEST CRYPTO HEISTS IN HISTORY.
$1.5 BILLION was stolen from Bybit in an attack linked to the Lazarus Group, a North Korea-linked hacking collective that has been active for years.
Previous attacks attributed to Lazarus include:
• Axie Infinity / Ronin Bridge — $625M
• Harmony Bridge — $100M
• Atomic Wallet — $100M
• Stake — $41M
• Alphapo — $60M
• WazirX — $230M
Bybit’s attack targeted an ETH multisig cold wallet.
According to Bybit’s CEO, the attackers used a fake interface to deceive wallet signers while secretly altering the transaction details.
Instead of approving a routine transfer, the signers unknowingly approved a change to the wallet’s smart-contract logic, giving the attackers control over the funds and allowing them to drain the ETH balance.
The Lazarus Group has been linked to billions in stolen crypto over the years.
Now Bybit is fighting back, reportedly taking legal action against North Korea over the attack.
Absolutely insane. 💀
#Bybit #LazarusGroup #Crypto #Bitcoin #Ethereum #Cybersecurity #CryptoSecurity #NorthKorea
Coldcard says the bug remained public for five years without being discovered, even by third-party researchers, and suggests that newer LLMs may have been needed to uncover it.
But the public record tells a different story: someone flagged the issue in May 2025, traced it to the specific library without using a frontier AI model, and was told the company would already know if there were a problem.
After disclosure, others found it using ordinary code-analysis tools on a public repository.
The real five-year problem wasn’t finding the flaw; it was looking for it
😂 It’s understandable to be upset, but there’s always hope. Your lost assets may be recoverable, and we specialize in helping with cases like this. We can help you look into it, just let us know what happened
Don’t be too hard on yourself. It’s usually a lack of awareness that gives perpetrators the opportunity. We can help you look into your stolen assets and see if it can be recovered. Tell us your story
It’s really a bad experience having all your coins/crypto/assets stolen. But all hope isn’t lost. Crypto is traceable, and your assets can sometimes be recovered with the right approach. We specialize in this and can help you