Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

29 / 29 results
Active filter:tag: #cryptocurrency✕ clear
Cosmos EVM balance flaw exploited on six chains after delayed patchcriticalbug_reportVulnerability
bug_reportVulnerability

Cosmos EVM balance flaw exploited on six chains after delayed patch

Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).

Cosmos Labs28 Aug · 18:38 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Malicious VS Code extensions steal crypto wallets and credentials from devshighbug_reportVulnerability
bug_reportVulnerability

Malicious VS Code extensions steal crypto wallets and credentials from devs

Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.

Microsoft10 Aug · 05:38 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
Two H1 2026 campaigns use compromised email and clipboard hijackinghighbug_reportVulnerability
bug_reportVulnerability

Two H1 2026 campaigns use compromised email and clipboard hijacking

Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…

BleepingComputer7 Aug · 12:00 UTC
ClickFix campaign delivers Go-based macOS stealer targeting crypto walletshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaign delivers Go-based macOS stealer targeting crypto wallets

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.

BleepingComputer6 Aug · 20:37 UTC
CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 yearscriticalbug_reportVulnerability
bug_reportVulnerability

CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years

CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…

CryptoJS6 Aug · 09:49 UTC
Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAThighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT

COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.

COLDCARD5 Aug · 15:49 UTC
COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoincriticalbug_reportVulnerability
bug_reportVulnerability

COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin

COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.

COLDCARD2 Aug · 19:14 UTC
Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutescriticalbug_reportVulnerability
bug_reportVulnerability

Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes

Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).

Coinkite1 Aug · 15:17 UTC
Adform supply chain attack injected crypto wallet swapper into customer siteshighbug_reportVulnerability
bug_reportVulnerability

Adform supply chain attack injected crypto wallet swapper into customer sites

Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…

Adform1 Aug · 07:03 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
SourTrade Campaign Delivers Malware via Browser-Assembled Executableshighperson_alertThreat Actor
person_alertThreat Actor

SourTrade Campaign Delivers Malware via Browser-Assembled Executables

SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…

Bun25 Jul · 16:48 UTC
Malvertising campaign targets crypto users with in-memory malware assemblyhighbug_reportVulnerability
bug_reportVulnerability

Malvertising campaign targets crypto users with in-memory malware assembly

Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.

Solana25 Jul · 13:21 UTC
BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.

Zoom24 Jul · 13:12 UTC
REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lureshighperson_alertThreat Actor
person_alertThreat Actor

REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…

The Hacker News8 Jul · 10:52 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud29 Jun · 09:57 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket26 Jun · 16:04 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer25 Jun · 20:37 UTC
Clipboard-stealing malware spreads via USB, targets crypto walletshighbug_reportVulnerability
bug_reportVulnerability

Clipboard-stealing malware spreads via USB, targets crypto wallets

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

BleepingComputer18 Jun · 14:20 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft18 Jun · 12:30 UTC
Cryptocurrency clipper malware with worm propagation targets Windowshighbug_reportVulnerability
bug_reportVulnerability

Cryptocurrency clipper malware with worm propagation targets Windows

Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.

Microsoft17 Jun · 21:11 UTC
Rokarolla Android banking trojan targets 217 banking and crypto appshighbug_reportVulnerability
bug_reportVulnerability

Rokarolla Android banking trojan targets 217 banking and crypto apps

Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.

BleepingComputer16 Jun · 18:04 UTC
JINX-0164 Targets Cryptocurrency Orgs with macOS Malwarehighperson_alertThreat Actor
person_alertThreat Actor

JINX-0164 Targets Cryptocurrency Orgs with macOS Malware

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…

The Hacker News28 May · 05:54 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News25 May · 07:32 UTC