β οΈ JUST IN: A new phishing scam is spreading on Telegram. Users receive a message in a secret chat claiming there was a login from another device and asking them to click a link.
The message is fake β scammers use a regular emoji instead of a real verification badge.
@ComUpdates
The message is fake β scammers use a regular emoji instead of a real verification badge.
@ComUpdates
π5β€4π±2
β οΈ JUST IN: A crypto trader was robbed of $800k after being kidnapped by four men in a Hong Kong hotel.
The attackers lured the victim to a hotel in Hong Kong, assaulted him, and forced him to reveal his crypto private keys, fleeing with $680k and 42kg of silver worth $120k.
@ComUpdates
The attackers lured the victim to a hotel in Hong Kong, assaulted him, and forced him to reveal his crypto private keys, fleeing with $680k and 42kg of silver worth $120k.
@ComUpdates
π€©6β€4π―4π₯2π2
β οΈ JUST IN: Trust Wallet has added real-time protection against address poisoning attacks.
Trust Wallet will now automatically run a security check on every transaction before you send money, warning users when something looks suspicious.
@ComUpdates
Trust Wallet will now automatically run a security check on every transaction before you send money, warning users when something looks suspicious.
@ComUpdates
π3β€2π2π€©1
β οΈ JUST IN: A victim lost $50.3M after swapping $50.4M USDT for just 327 aAAVE (~$35.9K).
The victim attempted to swap $50.4M USDT for aAAVE via CoW Protocol, but the trade executed with extremely low liquidity, resulting in only $35K received.
@ComUpdates
The victim attempted to swap $50.4M USDT for aAAVE via CoW Protocol, but the trade executed with extremely low liquidity, resulting in only $35K received.
@ComUpdates
π€©6β€3π±3
β οΈ JUST IN: Telus confirms a major data breach linked to the ShinyHunters group.
Reports indicate ~700TB to 1PB of data was stolen, including client data tied to over 30 high-profile companies serviced through Telus.
@ComUpdates
Reports indicate ~700TB to 1PB of data was stolen, including client data tied to over 30 high-profile companies serviced through Telus.
@ComUpdates
β€3π€©2π1
β οΈ JUST IN: Venus Protocol has been exploited again, marking its 6th exploit this year.
Venus Protocol has now suffered six separate exploits in the last year, which have resulted in millions stolen and making it one of the lowest security crypto platforms.
@ComUpdates
Venus Protocol has now suffered six separate exploits in the last year, which have resulted in millions stolen and making it one of the lowest security crypto platforms.
@ComUpdates
π₯°3π±3β€1π€©1
β οΈ JUST IN: A victim lost 736 ETH (~$1.75M+ ) after interacting with a malicious site.
The attacker gained access after the victim signed a Permit signature, allowing unauthorized transfers.
Funds were drained shortly after and split across three wallets.
@ComUpdates
The attacker gained access after the victim signed a Permit signature, allowing unauthorized transfers.
Funds were drained shortly after and split across three wallets.
@ComUpdates
β€5π±5π3π₯°2
β οΈ JUST IN: +888 8 800 SOLD!
Another 4 digit anon number has just sold for a whopping $555k USD
@ComUpdates
Another 4 digit anon number has just sold for a whopping $555k USD
@ComUpdates
π₯°4β€2π2
β οΈ JUST IN: A LockBit member has been sentenced to 6 years for hacking U.S. companies and carrying out crypto ransom attacks.
Authorities say he was involved in extorting over $24M from victims after breaching companies, deploying ransomware, and demanding payments.
The attacker agreed to pay ~$9.1M in restitution, which contributed to a reduced sentence.
@ComUpdates
Authorities say he was involved in extorting over $24M from victims after breaching companies, deploying ransomware, and demanding payments.
The attacker agreed to pay ~$9.1M in restitution, which contributed to a reduced sentence.
@ComUpdates
β€4π3π€©2
β οΈ JUST IN: Irish authorities have accessed a Bitcoin wallet holding 500 BTC (~$35M) nearly 10 years after it was seized
The wallet was previously believed to be permanently lost due to an incorrect seed phrase. Europol and Irish police have now successfully recovered access and moved the 500 BTC.
@ComUpdates
The wallet was previously believed to be permanently lost due to an incorrect seed phrase. Europol and Irish police have now successfully recovered access and moved the 500 BTC.
@ComUpdates
β€4π₯°2π±2
This media is not supported in your browser
VIEW IN TELEGRAM
β οΈ JUST IN: Footage of Russian police arresting the admin of cybercrime forum LeakBase a few hours ago.
LeakBase was one of the biggest cybercrime forums on the internet and was shut down weeks ago by the FBI and Europol.
@ComUpdates
LeakBase was one of the biggest cybercrime forums on the internet and was shut down weeks ago by the FBI and Europol.
@ComUpdates
β€4π±2π―2π2π€©1
β οΈ JUST IN: Washington has filed a lawsuit against prediction market Kalshi over disguised gambling.
The lawsuit claims the platform has allowed users to bet on anything by simply calling it a prediction market rather than gambling.
Notably, Nevada has already secured a restraining order against the site, suggesting the case could reach the Supreme Court.
@ComUpdates
The lawsuit claims the platform has allowed users to bet on anything by simply calling it a prediction market rather than gambling.
Notably, Nevada has already secured a restraining order against the site, suggesting the case could reach the Supreme Court.
@ComUpdates
β€3π2π±2π€©2π2
β οΈ JUST IN: Malicious crypto drainer compromises Steakhouse Financial app & website
A wallet drainer has been injected, meaning any interaction could result in funds being drained.
@ComUpdates
A wallet drainer has been injected, meaning any interaction could result in funds being drained.
@ComUpdates
β€4π±4π₯°3π€©1
β οΈ JUST IN: FBI arrests threat actor behind $51M theft from a crypto exchange in 2021
The attacker exploited a crypto exchange, stealing ~$51M before laundering the funds through tornado cash and spending a majority of it on PokΓ©mon cards.
He is now facing up to 10 years for fraud and up to 20 years for money laundering.
@ComUpdates
The attacker exploited a crypto exchange, stealing ~$51M before laundering the funds through tornado cash and spending a majority of it on PokΓ©mon cards.
He is now facing up to 10 years for fraud and up to 20 years for money laundering.
@ComUpdates
π±5π4π€©4β€3
β οΈ JUST IN: Cryptocurrency exchange compromised via social engineering, resulting in ~$8.8M stolen
Threat actors targeted an employee with access to the exchangeβs private keys, ultimately gaining control over reserve funds.
Shortly after the compromise, over $8M was stolen, including ~15 BTC.
@ComUpdates
Threat actors targeted an employee with access to the exchangeβs private keys, ultimately gaining control over reserve funds.
Shortly after the compromise, over $8M was stolen, including ~15 BTC.
@ComUpdates
π€©4β€2π2π―2π₯1
β οΈ JUST IN: ZachXBT releases βUSDC Filesβ after ~$420M was stolen since 2022
Per ZachXBT, the USDC contract has a freeze and blacklist function, yet funds tied to exploits and hacks have not been frozen over the past 4 years.
Over $400M+ in USDC has been successfully laundered as a result of this lack of action.
Even in the recent $280M Drift Protocol exploit, the attacker moved funds for 6 straight hours, including through Circleβs native bridge, without any USDC being frozen.
@ComUpdates
Per ZachXBT, the USDC contract has a freeze and blacklist function, yet funds tied to exploits and hacks have not been frozen over the past 4 years.
Over $400M+ in USDC has been successfully laundered as a result of this lack of action.
Even in the recent $280M Drift Protocol exploit, the attacker moved funds for 6 straight hours, including through Circleβs native bridge, without any USDC being frozen.
@ComUpdates
β€4π±4π3π₯2
β οΈ JUST IN: Threat actors lose 59+ BTC (~$4M+) after attempting to launder all of it at once
Threat actors attempting to launder stolen funds were impacted by withdrawal limits, with the platform only allowing ~$50K per transaction.
As a result, over $4M+ remains effectively locked on the exchange.
@ComUpdates
Threat actors attempting to launder stolen funds were impacted by withdrawal limits, with the platform only allowing ~$50K per transaction.
As a result, over $4M+ remains effectively locked on the exchange.
@ComUpdates
β€5π±5π₯°3π3
β οΈ JUST IN: FBI confirms Americans lost a record ~$11.36B to crypto-related fraud in 2025
Per the FBI, social engineering and customer support impersonation were among the most effective methods used for theft, with $2B+ in crypto stolen throughout the year
@ComUpdates
Per the FBI, social engineering and customer support impersonation were among the most effective methods used for theft, with $2B+ in crypto stolen throughout the year
@ComUpdates
β€6π3π±1π€©1π1
β οΈ JUST IN: Victim lost ~$385K after copying the wrong wallet address
A crypto whale was exchanging ~$749K and sent the first portion (~$380K) successfully.
Shortly after, the wallet was targeted with an address poisoning attack, causing the victim to copy a lookalike address and send the remaining ~$385K to the attacker.
@ComUpdates
A crypto whale was exchanging ~$749K and sent the first portion (~$380K) successfully.
Shortly after, the wallet was targeted with an address poisoning attack, causing the victim to copy a lookalike address and send the remaining ~$385K to the attacker.
@ComUpdates
π₯°2π2β€1π₯1
β οΈ JUST IN: Elon Musk and Pavel Durov says WhatsApp's end to end encryption is compromised and fake.
Both CEOs state that WhatsApp misleads users about its end-to-end encryption, even going as far as to read usersβ messages and share data with third-party companies.
@ComUpdates
Both CEOs state that WhatsApp misleads users about its end-to-end encryption, even going as far as to read usersβ messages and share data with third-party companies.
@ComUpdates
π±5β€3π€©3π₯°2π₯1
β οΈ JUST IN: The FBI has allegedly taken control of John Lickβs account following his arrest
Earlier today, the username was detached from the account, suggesting federal authorities may be accessing and exporting DMs linked to past activity.
If you previously worked or associated with John Lick, itβs advised to clear any conversations.
@ComUpdates
Earlier today, the username was detached from the account, suggesting federal authorities may be accessing and exporting DMs linked to past activity.
If you previously worked or associated with John Lick, itβs advised to clear any conversations.
@ComUpdates
π±6π―3β€2π₯°2π1