⚠️ JUST IN: Meta and Coinbase are directly working with the FBI to arrest online scammers.
So far, law enforcement has arrested 60+ suspected threat actors, Coinbase has seized over $3M in stolen crypto, and Meta has disabled more than 1.4M accounts linked to scam activity.
⚠️ JUST IN: The owner of the Instagram user @i in distress after exploiters used the new Meta AI exploit to pull their account multiple times
The owner was able to get it back multiple times but due to the exploit still working , it was pulled back each time.
The exploiter tried extorting the owner for the account via WhatsApp but ultimately got it banned.
Meta allowed my single character Instagram username (@i) to be stolen through an exploit in their platform, dating back to February this year.
My email, password and phone number were never compromised — yet somehow a hacker was able to gain access to my account 🧵
⚠️ JUST IN: A victim lost ~$310K after connecting their wallet to a fake crypto exchange
The malicious site tricked them into connecting their wallet, which allowed the attacker to drain the funds shortly after.
⚠️ BREAKING: Multiple 1L Instagram usernames appear to have been claimed via the Instagram exploit.
Around 10 minutes ago, both @e and @f on Instagram were claimed through the active exploit.
Previous one letter Instagram handles have sold for $100K+
⚠️ JUST IN: Radiant Capital is shutting down after failing to recover from a $50M exploit
The team says it spent 18 months tracing the attacker, but after failing to recover the stolen funds, Radiant is now closing the project and giving up on the investigation.
⚠️ UPDATE: The 2 major Instagram exploits we posted about are getting abused after quietly working for months.
The method lets attackers take over accounts by using a VPN to match the account’s country region, starting a password reset, then convincing Meta’s AI support to swap the email.
High-value usernames like @hey have reportedly been stolen, with over $1M+ in accounts already pulled over the past 3 days.
⚠️ JUST IN: Gravity exploited with $5.4M+ stolen
11 employees were social engineered into signing a malicious signature, which gave the attackers withdrawal access and allowed them to drain the funds.
⚠️ UPDATE: John Daghita (John Lick) will now be extradited to the US to start his trial
Yesterday John's extradition request was approved with John’s lawyer reportedly saying he had requested the extradition himself.
⚠️ JUST IN: Multiple victims have lost $500K+ after signing malicious phishing approvals.
Over $500K was drained from victim wallets after they unknowingly signed phishing approvals, granting attackers permission to access and steal their funds.
✏️ JUST IN: Telegram Will Add a “Markdown” Feature
In the next update, Telegram plans to add full Markdown formatting support for messages and posts.
Users will be able to use:
• headings
• tables
• formulas
• code blocks, and other formatting elements.
This feature is currently being tested in the beta version.