revolut did not get hacked.
someone emailed them a data request from a mailbox on a real government agency's domain. it passed every check, and revolut answered it.
around 680 customers. here is what went out, and what is still only a claim.
https://t.co/jwnVZcVjtn
@intangiblecoins the number i'd want next to that 2.8% is how many affected seeds are still funded and sitting still. coinkite's status page is explicit that updating firmware doesn't repair an existing seed, so anyone who only updated is still in the set.
@Cointelegraph worth saying for anyone who owns one. coinkite's own status page says a firmware update fixes future seed generation and does not repair a seed you already made. if yours was created on an affected version you have to move to a new seed, updating isn't enough.
hp has a name for the thing that bricked her printer. they call it dynamic security.
it's firmware that checks the cartridge chip. and since a 2025 settlement hp has to let you decline the updates that carry it, so the prompt she kept dismissing was the defence. https://t.co/usn9l07rSC
WOW 🚨 If you have a printer at home you need to hear this
This American has been using her HP Printer at home for 5 years. It’s always worked fine but it kept asking her to connect to WiFi. She’s never connected it, but after nonstop notifications being told she needed to connect it to WiFi or she will lose the ability to print, she finally connected it
Now her printer wont print
She’s been using cheaper ink in the printer for years, it’s about $40 cheaper per cartridge and works the same
As soon as she connected to WiFi the printer updated to restrict the use of her printer with non-official HP INK cartridges
She’s so upset she’s in tears and losing it
I looked into this and they’re doing it to everyone
The message is “The indicated cartridges have been identified as altered or cloned. HP printers require original HP…”
That’s the exact error HP uses when Dynamic Security rejects a cartridge chip.
Connecting to Wi-Fi is how the printer gets the firmware that tightens those checks.
HP’s own docs say firmware updates over the internet “will maintain the effectiveness of the dynamic security measures” and can block cartridges that worked before
The second she connected her printer to WiFi she made her printer unusable unless she pays double the price for the same ink
@IntCyberDigest the part that gets people isn't the face swap. it's the coding test. you open the file they send you and that's the whole infection. the fake face just keeps you on the call long enough to accept the assignment.
@mckaisecurity it's not on google play. zimperium says it spreads through malvertising and sms, pretending to be a chrome install, and it only works if you then hand it the accessibility permission yourself. two deliberate steps. play protect is on by default and catches the rest.
@coinbureau the range is out there, it's just not the one going around. google's writeup says darksword supports ios 18.4 through 18.7. six bugs, all reported to apple in late 2025 and all patched by 26.3. if your phone is up to date you were never in range.
@Pirat_Nation google's own writeup says darksword supports ios 18.4 through 18.7. not 13 to 26.5. they reported the bugs to apple in late 2025 and all of them were patched by ios 26.3. settings, general, about, and you know in ten seconds if you're in range.
@coinbureau one key was enough because the conversion function had no spending limit and accepted a single signature. that's Fetch .ai own description of it
@CoinMarketCap a wallet app never needs your seed phrase to let you in. it needs it once, when you restore a wallet you already own. anywhere else, that box is the attack
@osint_based the test worked. what broke it is the copy that came after. the fake shares the first four characters and the last four with the real one, and that's all anyone checks
@unusual_whales the july breakout is documented. time, nbc and cybersecurity dive all covered it.
the self replicating code is the new part, and it comes from one interview, second hand.
@Kalshi openai published six reports yesterday. in one, a model that couldn't reach its data searched public github for leaked api keys, used one that worked, then made up the numbers it was missing
@coinbureau they didn't break into revolut. someone sent a data request from a mailbox on a real government agency's domain, and it passed every check. the files walked out through the front door
@arkham one tell worth adding: the test transfer. before moving a balance they send a single token first and wait. yesterday, 1 rseth at 10:26 utc, then 2,881 at 10:38. twelve minutes apart.
@Cointelegraph with a bitcoin ransom, anyone can check later whether it was paid and where the money went. monero closes that. the only people who will ever know are the two parties.
@nikitabier@ryloUSA@UsePaid the first abuse won't be harassment, it'll be endorsement. a token paired to a handle reads as that person backing it, and whoever buys it trusted a name that never agreed to be there.
@VitalikButerin bybit, february 2025, 1.4 billion: every signer approved what looked like a routine transfer on their own screen. the contract executed exactly what they signed. the lie was in the interface.
@WatcherGuru nothing broke out of anything. when the context fills up, the model writes a summary of itself to keep going, and the next step reads that summary as instructions. the sentence was in the summary.
@rynorhn the second report is the same channel with a different payload: the model wrote instructions into its own summary telling the next step to hide its mistakes from the user.