Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
29 / 29 results
criticalbug_reportVulnerabilityCosmos EVM balance flaw exploited on six chains after delayed patch
Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
highbug_reportVulnerabilityMalicious VS Code extensions steal crypto wallets and credentials from devs
Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.
highbug_reportVulnerabilityClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain
macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.
highbug_reportVulnerabilityTwo H1 2026 campaigns use compromised email and clipboard hijacking
Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…
highbug_reportVulnerabilityClickFix campaign delivers Go-based macOS stealer targeting crypto wallets
macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.
criticalbug_reportVulnerabilityCryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years
CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…
highbug_reportVulnerabilityPhishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT
COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
highbug_reportVulnerabilityAdform supply chain attack injected crypto wallet swapper into customer sites
Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…
highperson_alertThreat ActorLazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign
Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…
criticalbug_reportVulnerabilityNorth Korea linked to npm supply chain attacks on debug, chalk, axios
npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…
highperson_alertThreat ActorFraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin
The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.
highperson_alertThreat ActorSourTrade Campaign Delivers Malware via Browser-Assembled Executables
SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…
highbug_reportVulnerabilityMalvertising campaign targets crypto users with in-memory malware assembly
Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.
highperson_alertThreat ActorBlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.
highperson_alertThreat ActorREF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures
REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highperson_alertThreat ActorPolish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets
This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.
highbug_reportVulnerabilityClipboard-stealing malware spreads via USB, targets crypto wallets
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
highbug_reportVulnerabilityWindows cryptocurrency clipper campaign uses USB worms and Tor C2
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
highbug_reportVulnerabilityCryptocurrency clipper malware with worm propagation targets Windows
Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.
highbug_reportVulnerabilityRokarolla Android banking trojan targets 217 banking and crypto apps
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
highperson_alertThreat ActorJINX-0164 Targets Cryptocurrency Orgs with macOS Malware
JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…
highperson_alertThreat ActorLazarus Group deploys RemotePE cross-platform RAT against finance sector
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…