⚠️ SafePal’s order-tracking plugin just got cooked — order data for ~39.8k users (names, addresses, phones & emails) got leaked.
Wallets + seed phrases are still safe fr, but this is pure fuel for precision phishing. Scammers are already loading up.
Real talk: SafePal will NEVER ask for your seed phrase or private keys. Don’t scan random QRs or leak any verification info!
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures introduced.
The incident impacts approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. Exposed information includes name, email address, shipping address, phone number, and purchase details.
All affected customers have been notified individually by email. We have also published this webpage https://t.co/PULScHeNzX for customers to verify if they are affected using order ID number and shipping country.
For a complete disclosure of the incident and the actions we’ve taken, along with FAQs and guidance, please refer to our blog: https://t.co/itKx8jJrdW
This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers.
Never share your seed phrase, private key, or password with anyone, and stay vigilant against phishing or impersonation attempts.
We are extremely sorry to the community and those who are affected. Updates will be posted on our blog as we continue to work through things.
😱A BTC holder just dodged a #Coldcard MK4 theft, moved his stack to a CEX… and got completely wiped in under 12 hours. $750k in #BTC gone. Reason? Google account owned + Google Authenticator cloud sync left on.
This is NOT a one-off. Most Google compromises aren’t brute force — they’re phishing + credential stuffing. The usual plays:
1. Fake Google login pages tricking you into handing over the password
2. Malicious browser extensions / cracked software silently yoinking cookies & creds
3. Weak password reuse → massive credential stuffing
4. Recovery email or phone number taken over → instant password reset.
🛡️GoPlus security playbook so you don’t get rekt:
1️⃣Google account → hardware key or Passkey on. Regularly audit devices, third-party access & recovery options. Password alone is a single point of failure.
2️⃣Cloud backup → keep Google Authenticator cloud sync OFF by default. Store recovery keys offline. Never let email + password + 2FA share the same trust chain.
3️⃣Exchange accounts → dedicated email only. Enable withdrawal address whitelist + cooldown period. Kill API withdrawal perms. Watch for abnormal logins like a hawk.
A very close friend of mine, coldcard MK4
User, after 6 years of suggesting Bitcoin to him, finally allocated and went pretty hard in 2025. 3/4 of a million dollars
Moved ALL to a very well known and solid Australian exchange
Less then 12 hours later, it was withdrawn
ALL gone
⚠️Trezor Data Leak Alert: Fake #Trezor devices, social eng, package swaps, wrench attacks & home invasions — risk is UP❗️
@Trezor confirmed a data leak at their shipping provider ShipMonk.
11,742 customers → full name, address, phone & email exposed.
Another 1,947 → partial data.
Only recent orders (May 10 – Aug 8 2026) in 🇺🇸 🇬🇧 🇸🇪 🇨🇴 🇧🇷 🇮🇹 🇵🇹.
🛡 Stay safe:
1. Don’t click any suspicious links. Extra eyes on anything claiming to be from [email protected] — verify the real official source.
2. Watch for intercepted packages swapped with malicious hardware wallets + address-based physical threats.
3. When your device arrives: check anti-tamper seals, packaging, firmware origin & init process. Never use a pre-loaded seed.
4. OPSEC 101: Don't flex your bags online. Don't leave your identity permanently mapped to your shipping address.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026.
The data exposed:
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email.
Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts.
NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
We are investigating this situation and will post updates on our blog:
https://t.co/JGrttMs4Ev
3/
Aug 12 2026: Suspected private key compromise. Cleaned in under 15 minutes — including native ETH.
Addresses hit:
0x13e382dfe53207e9ce2eeeab330f69da2794179e (same as last time, ~$15M)
0xcb3de9c898b59ff239edd6bf30cc44058e24eb47 (~$10M)
Funds swept to 0x8feb0c6ef08b20ba19c04f951d4408bb5a1f95ae, converted, and currently ~$20M DAI sitting at 0x61cE24326d713641583E6a337A69BEf7458Fcf76.
🚨 GoPlus Security Alert
The “TLBL” whale just got hit AGAIN after 3 years of silence. Cumulative losses now sit north of $50M .
Two completely different attack vectors:
2023 → Approval phishing (only ERC20s taken)
2026 → Suspected private key leak (even native ETH got cleaned)
Victim kept using the same wallet after the first drain. Theory was “just revoke the bad approval and we’re good.” Technically true… until it isn’t. The fact that the attacker returned most of the funds the first time only made the security posture even more relaxed.
GoPlus security reminder (read this twice):
1. Onchain is the darkest forest. Complacency is the real enemy.
2. Sizeable bags → hardware wallet. Seed phrase never touches the internet. Ever.
3. If you don’t fully understand the tx, don’t sign it. Regularly check & revoke dusty/risky approvals.
4. After a drain (even if the attacker refunds), immediately migrate to fresh hardware + new address. No exceptions.
🧵 Details below
An unknown victim was just drained of $25.6M in assets.
The attacker swapped all the assets, including WBTC, cbBTC, LDO, USDS, and CRV, for DAI and ETH.
Interestingly, the same wallet was drained of $24.23M in September 2023 due to malicious token approvals. The attacker eventually returned approximately 90% of the stolen funds.
Theft address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae
Stay Smart.
2/
Sept 2023: Signed a phishing #increaseAllowance
Lost: 9,579 stETH + 4,851 rETH (~$24.23M)
Victim: 0x13e382dfe53207e9ce2eeeab330f69da2794179e
Phishing tx: https://t.co/0Qk9P3jCob
10 months later the attacker (0x0EfD89f99Cf660097a6db249F2342C8c0625Bbf5) returned 10.3M DAI onchain and then negotiated the rest via Telegram.
Excited to join forces with AvengerDAO! 🤝
Together, we’re making top-tier security tools & services accessible for every @BNBCHAIN builder.
#StaySafu | Security First 🫡
Every builder should have a clear path to strong security.
AvengerDAO now brings 11 security firms, an official BNB Chain standard, and bug bounty support for builders, from development through launch and beyond.
The goal is to raise the baseline for every project launching on BNB Chain 🧵👇
🚨 GoPlus Security Alert:
A user lost approximately $100K USDT in an address poisoning attack. The victim received more than 400 poisoning transactions after their previous transfer 69 days ago.
🔍How address poisoning works: Attackers send small transactions from malicious addresses designed to resemble a victim’s intended recipient—often matching the first and last few characters—then wait for a copy-paste mistake.
These attacks are now fully automated, from identifying targets and generating lookalike addresses to deploying spoof tokens, sending dust transactions, and laundering stolen funds through mixers.
Victim:
0x9B4Ded0ab7754428F7eC0f63a42bAe70D2f51D83
Intended recipient:
0xae7C0ffAB6e77BE2D7d7880a4Ce433F59A4e2c85
↕️
Poisoning address:
0xAe7c08afAD91db18666EEAC055D7562c9f4e2c85
☠️ The poisoned address closely mirrors the intended recipient at both ends.
🛡️ Security Reminders:
• Never copy a recipient address from your transaction history.
• Verify the entire address—not just the first and last few characters.
• Always send a small test transaction before transferring a large amount.
🚨GoPlus Security Alert:
Harmony $ONE has suffered an exploit. The attacker illicitly minted approximately 4B $ONE, with more than 2.8B tokens rapidly transferred to exchanges and sold, sending $ONE down over 35% within minutes.
The Harmony team is urgently working to patch the vulnerability and has asked exchanges to immediately freeze the following attacker-linked addresses:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
0xe7427699427821230177dd13f460d6ce43014510
one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5
one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb
one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba
We are asking all exchanges to block and freeze funds that traces back to these 4 wallet addresses:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
0xe7427699427821230177dd13f460d6ce43014510
one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5
one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb
one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba
🚨 GoPlus Security Alert:
B2B crypto payment processor @coinsbuycom had associated wallets drained on Ethereum + TRON for ~$7.9M.
Attacker then laundered via Monero/XMR, routing through CEXs including ChangeNOW / FixedFloat / BingX.
1. Coinsbuy’s X has been dormant since 2020, but their developer docs keep getting updates:
https://t.co/S9Vj1eM0Ac
2. Attack pattern fits hot-wallet private key or admin privilege compromise.
In the 2026-07-10 release notes they just fixed:
“Fixed transportation transfers being confirmed without verifying the collected amount against the deposits actually received on the node — a mismatch now raises an incident instead of silently overstating the Locked in node balance and causing false insufficient funds errors later.”
Doesn’t directly prove the root cause of this drain, but shows how complex their transfer / node / fund-consolidation logic is — high-risk surfaces on both ops and accounting layers.
3. Attacker addresses:
0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3
0x66790b54B891e2ebdef58a15B969Ff6fb4374b17
TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR
h/t: @SpecterAnalyst ’s Telegram channel
🚨GoPlus Community Alert
Microsoft Threat Intelligence has identified malicious websites abusing BNB Chain RPC gateways to fetch live malicious instructions from on-chain smart contracts, then using fake CAPTCHA / “browser repair” prompts to socially engineer users into running them.
These ClickFix / TerminalFix campaigns are hitting thousands of enterprise and consumer devices worldwide every day.
Attack chain:
1. Attackers compromise legitimate sites and inject JS that displays fake CAPTCHA or “fix your browser” screens.
2. The page doesn’t hardcode the payload — it queries a BNB Chain RPC endpoint and dynamically pulls the next-stage commands from a smart contract.
3. Users are instructed to open Win+R / Terminal / PowerShell and paste a “verification” or “repair” command — which actually executes the freshly fetched on-chain payload.
4. Successful execution frequently leads to Lumma and other info-stealers, destructive malware, or full remote-access tools.
Immediate advice:
1️⃣Any page that tells you to press Win+R, open Terminal/PowerShell/cmd, and paste something is malicious. Close it immediately.
2️⃣Never trust “CAPTCHA failed — run this command to fix”, “browser error — execute this script”, or “support needs you to paste a command in the terminal”.
3️⃣Don’t copy, don’t paste, don’t run. Close the tab and clear recent downloads if needed.
4️⃣If you already ran the command: disconnect from the network right away and change critical passwords (email, SSO, company IM, browser sync, VPN, password manager) from a clean device.
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes.
Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification.
We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog.
This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages.
Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise.
Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt.
Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”.
Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
👀Thieves eating thieves? Just stole $500k USDC… MEV bot snatched $320k of it for only $0.03!
A #Base user got phished and lost ~$500k USDC. The attacker immediately tried to swap the loot into WETH — but forgot to set any slippage protection. The trade got routed straight into a low-liquidity #Uniswap V4 WETH/USDC pool (PoolId:0x1d8c55f347727c0fb4f5e1b65cdb93639e0c7102580a7d345e1144cd5a718f54).
Result: $500k USDC → only 67.9 WETH (~$129k).
~$370k vanished to extreme slippage… and an MEV bot scooped most of it (~$320k).
😂The wild part? The bot only needed $0.03 in capital for the arb, but paid a juicy 3.5 ETH in gas.
The victim already sent on-chain messages to both the attacker and the MEV address, offering a 10% bounty for the return of the funds.
Victim: 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c
Attacker: 0x920d3b63541eAFe13E05dc4f3453904102c39708
MEV bot: 0x0000208D547A446BA9059CbB2CfcfbAEAd7d3fA3
Attack tx: https://t.co/TK6Yk1SxDy
🚨 BREAKING: South Korea’s top exchange #Upbit announced it will delist $BONK on Sept 7.
The exchange cited unresolved security incidents and major disclosure shortfalls as the primary reasons.
🧵1/2
🚨GoPlus Security Alert: #BONK Suffers Governance Attack, Resulting in a $20M Loss
Bonk (@bonk_inu) was hit by a malicious governance proposal attack. A total of 4.426T $BONK held in the BonkDAO wallet was transferred to a malicious address (9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ). The malicious proposal remained live for 6 full days without any effective intervention, ultimately resulting in a total loss of approximately $20 million.
Attack proposal details: https://t.co/hZ8LHVpFCo
GoPlus Security is proud to support Robinhood Chain by @RobinhoodCrypto .
As a Web3 security infrastructure provider, GoPlus brings its token and transaction risk detection capabilities to the Robinhood Chain ecosystem.
GoPlus token and transaction risk detection for Robinhood Chain assets are now available across @GeckoTerminal , @DEXToolsApp , @dexscreener , @CoinMarketCap , @BinanceWallet , @wallet , @BitgetWallet , @TokenPocket_TP , @Debot_Official , and @UseUniversalX .
To support builders and developers in the Robinhood Chain ecosystem, simply sign up on our platform to get your API key and access complimentary API quota for our services.
Get started: https://t.co/Xx2ye7eJJs
The @COLDCARDwallet incident has already led to roughly $38M in BTC being stolen. The real warning sign is not simply that a “hardware wallet was compromised,” but that if entropy is flawed at the seed generation stage, even strong cryptography may rest on a broken foundation.
Coinkite has confirmed that affected seeds generated on Mk4/Mk5/Q before the fixed firmware releases had only ~72 bits of entropy instead of the expected 128 bits. Mk3 is also affected, with even higher risk.
More importantly, AI is rapidly reducing the time and cost needed to find weaknesses in cryptographic designs, RNG assumptions, and implementations. Recent results have significantly weakened a post-quantum candidate like HAWK and improved theoretical attacks on 7-round AES by 200-800x. AI has not broken full AES or Bitcoin in the real world, but it is already reshaping how we think about the security margins of traditional cryptographic systems.
For users, the key question is no longer just whether the seed phrase was stored offline, but how the seed was generated in the first place. Per official guidance, affected users should migrate to a new seed ASAP: either generate it on an unaffected device, or upgrade Mk4/Mk5 to 5.6.0+ and Q to 1.5.0Q+ before creating a new one. If Mk3 is the only option, a strong and unique BIP39 passphrase can be used as a temporary isolation layer, but never enter it on a website or any untrusted device. Always verify the XFP, send a small test transaction first, and only then move the full balance.
The future of crypto security is no longer just about algorithm strength. It is about the combined security of entropy sources, implementations, devices, processes, and user operations.
More than $38M has been stolen due to a Coldcard wallet vulnerability.⚠️
Funds from around 500 wallets were transferred to wallet bc1qnk, totaling 594.48 $BTC ($38.2M).
Stay safe.
https://t.co/gUmUfQLvdb
https://t.co/Bg2XS39mWh
🧵1/5
⚠️ Vulnerability Analysis:
Analysis of the attack on @CryptoDAOGlobal
On July 28, the $Pro token of @CryptoDAOGlobal on #BNBChain was exploited due to an access control vulnerability. The attacker profited approximately $52K, while the exploited contract lost 167,200 $Pro. All of these $Pro tokens were swapped into $USDT and transferred to the receivers in the exploited contract.
The attacker repeatedly called the exec function of the exploited contract 0xc44f2a within a single transaction. Each call swapped 50 $Pro into $USDT. After multiple executions, the attacker significantly increased the price of the Pro/USDT trading pair, and finally swapped the $Pro holdings into $USDT to realize the profit.
The root cause was that the exec function in the exploited contract lacked access control and could be called by any contract.