RelayShield
4 subscribers
18 links
Real-time crypto security alerts. SIM swap, wallet monitoring, address poisoning detection. Try free: @RelayShield_bot
Download Telegram
πŸ’Έ $442 billion lost to crypto fraud in 2025.

Bitget launched Anti-Scam Month in response. Educational content, explainer videos, fraud guides. Good initiative but it is not enough.

Here's why:

Every major attack on that list including SIM swap, address poisoning, AI deepfakes, malicious contracts is designed to bypass the moment of user decision. Education works when you have a choice. These attacks remove the choice.

The real fix is detection:

β€’ SIM swap β†’ carrier APIs catch the port-out before the attacker resets your credentials
β€’ Address poisoning β†’ the dust transaction flags the lookalike before you copy it
β€’ Infostealer β†’ stolen credentials surface in underground markets within hours of infection

And the attack surface is expanding fast. A SIM swap doesn't just reset your Binance password anymore. It also resets your brokerage, your RWA platform, and your forex app. Every platform using SMS 2FA falls in a single chain.

Monitoring your wallet but not your phone number is the equivalent of one room in a house with open windows.

Full breakdown β†’ https://www.linkedin.com/pulse/442-billion-lost-crypto-fraud-2025-education-isnt-enough-heres-le1me/?trackingId=pbezU0h7QsDh8Oy39hcjOQ%3D%3D

πŸ›‘οΈ Real-time monitoring for wallets, SIM swaps, breaches + more: @RelayShield_bot or crypto.relayshield.net
☎️ A phone call is all it takes to empty your Microsoft 365 account.

A criminal group called "Pink" is targeting SMBs right now. No malware. No phishing link, just someone pretending to be IT support.

Here's the attack in 60 seconds:

β€’ Employee gets a call from "IT" and is directed to a fake login page
β€’ Credentials harvested β†’ attacker steals the active session token
β€’ MFA already passed: they're inside your M365 impersonating your employee
β€’ OneDrive and SharePoint drained using Microsoft's own tools
β€’ 72 hours later a ransom demand arrives from your own employee's email

The fix costs nothing:

Any unexpected IT call asking you to log in anywhere β†’ hang up β†’ call back on a number you already have. 30 seconds. Every time.

Two things RelayShield catches in this attack chain:
β†’ Domain lookalike monitoring flags fake IT login pages before your team visits them
β†’ Breach + infostealer monitoring alerts you the moment employee credentials are exposed

Full breakdown β†’ [Source: Hackread β€” https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/]

πŸ›‘οΈ Monitoring for SIM swaps, breaches, domain lookalikes + more: @RelayShield_bot or relayshield.net
🦠 New threat alert: Reaper macOS malware is targeting crypto wallet users

A new macOS infostealer called Reaper is being distributed via typosquatted domains impersonating Ledger, MetaMask, and Exodus. What makes it dangerous: it exploits the applescript:// URL scheme to execute code without triggering macOS's Terminal security prompt. No pop-up. No warning. No chance to stop it.

Once installed, Reaper silently exfiltrates wallet seed phrases, private keys, and browser-saved credentials β€” everything stored on the device β€” and sends it to a C2 server within minutes. One click on the wrong "download Ledger Live" link is all it takes.

It also contains a Russian keyboard kill-switch: if the device has a Russian keyboard layout active, the malware doesn't execute. This is a common fingerprint of Eastern European threat actors protecting domestic users while targeting everyone else.

How to protect yourself:
πŸ”— Only download wallet software from official domains β€” bookmark them now
πŸ” Check the exact URL before any crypto software install
πŸ›‘οΈ RelayShield monitors your credentials and device fingerprint for infostealer exposure β€” alerts fire within hours of a log appearing in criminal channels Full breakdown β†’ https://relayshield.hashnode.dev/reaper-malware-blog
πŸ“Š New data: Online scams are now a cross-platform criminal industry

Bitdefender's 2026 Global Scam Intelligence Report dropped and the numbers reframe everything:

β€’ 1 in 6 Americans was scammed last year.
β€’ 60% of risky WhatsApp conversations came from Business accounts β€” the verified kind
β€’ 100+ malicious Facebook ads launched from one page in a single day
β€’ 15% of all incoming calls globally are unwanted or fraudulent
β€’ Hundreds of fake accounts impersonating Binance, MetaMask, TradingView on Facebook

This isn't opportunistic crime anymore. It's an industry with deepfake call centers, and coordinated ad operations running 24/7.

The platforms you trust most, WhatsApp and Facebook, are the primary delivery vectors.

Full breakdown: https://relayshield.hashnode.dev/online-scams-industrial-2026-bitdefender-report
🦠 11.1 million devices. 3.3 billion stolen credentials. One $60 subscription.

That's the infostealer economy in 2025.

Infostealer malware is now sold as a monthly subscription starting at $60 and it gives attackers every saved password, session cookie, and crypto wallet key on your device within minutes of infection. No brute force. No phishing link you have to click twice. Just a silent harvest and a log posted to criminal markets within 24–72 hours.

The five families behind 11 million infections in 2025: Lumma, Acreed, Rhadamanthys, Vidar, StealC. By early 2026 Vidar alone accounts for 73% of infected hosts.

And it's not just account takeover. Stolen VPN and RDP credentials are how ransomware gets inside the perimeter as a legitimate logged-in user, weeks before the attack fires.

The 24–72 hour window between infection and log publication is the only moment to act. https://hashnode.com/edit/cmqau7g5y000204l86uka8o36
🚨 OnyxC2: $250/month buys everything on your employees' devices

A new Malware-as-a-Service platform evades 71 antivirus engines on first run and harvests 4,717 cookies, 55 passwords, and active session tokens from a single machine β€” in one pass.

The stolen VPN credentials it lifts are how ransomware gets in weeks later.

Full breakdown β†’ https://relayshield.hashnode.dev/onyxc2-when-250-month-buys-everything-on-your-employees-devices?utm_source=hashnode&utm_medium=feed
⚠️ Rug pulls are now 54% of all crypto scams β€” 425,000+ detected

A token can have a rising chart, an active community, and polished marketing β€” and still be a rug pull waiting to execute. One hidden owner-side action and everything goes to zero.

How they work and how to screen counterparties before you send funds: https://relayshield.hashnode.dev/rug-pulls-are-now-54-of-all-crypto-threats-here-s-how-they-stay-hidden-until-it-s-too-late?utm_source=hashnode&utm_medium=feed
🚨 24 billion credentials just surfaced in one of the largest leaks ever found.

Cybernews researchers found an exposed database this week: 8.3TB of infostealer logs, breach compilations, and credential dumps β€” sourced from over 30 criminal Telegram channels.

Plaintext passwords. Login URLs. Session cookies that bypass 2FA.

The database is offline. The Telegram channels are still posting new logs daily.

Full breakdown and what to do now β†’ https://hashnode.com/@relayshieldsecurity

RelayShield monitors these channels in near real-time. If your credentials appear, you'll know within hours β€” not weeks.
🚨 $2.9M stolen from Polymarket β€” the signals were in stealer logs before a single line of malicious code fired.

A compromised third-party vendor pushed malicious JavaScript to Polymarket's frontend. Users were silently robbed while everything looked normal.

We mapped the full signal chain attackers leave behind before supply chain attacks execute and which monitoring calls catch each one:

β†’ Vendor credential exposure in infostealer archives
β†’ Service account & CI/CD token theft (NHI exposure)
β†’ Identity risk score elevation on the vendor domain
β†’ ATT&CK TTP T1195 β€” Supply Chain Compromise

Full breakdown with API examples: [https://relayshield.hashnode.dev/how-relayshield-would-have-caught-the-polymarket-attack-before-it-cost-2-9-million?utm_source=hashnode&utm_medium=feed]
RelayShield is now live on AWS Marketplace.

Our Threat Intelligence & Identity Security API is now available as a self-serve SaaS listing for any AWS customer β€” same intelligence pipeline that powers our identity protection product, now accessible directly through AWS procurement.

What's inside:
β€’ 2M+ indicator IOC corpus across 20+ feed sources
β€’ 37+ monitored criminal Telegram channels, surfacing threats 24–72 hours before public disclosure
β€’ STIX/TAXII 2.1 and MISP feed export for direct SIEM/SOAR integration
β€’ Correlated signals across breach exposure, infostealer logs, SIM-swap, and session hijacking

If your org already buys through AWS, this is now the fastest way to plug identity-layer threat intelligence into your existing stack.

πŸ”— https://aws.amazon.com/marketplace/pp/prodview-z3izf6val3jb2
Crypto Shield Mobile is live on the Solana dApp Store.

Built on the same threat-intelligence pipeline as RelayShield's core platform β€” 2.1M+ indicator IOC corpus, 37+ monitored criminal Telegram channels β€” now packaged into a native wallet-security app.

What's new in this release:
β€’ Mobile Wallet Adapter β€” connect your Solana wallet directly, no manual address entry (still fully read-only, no signing ever requested)
β€’ NFT Security scanning β€” catches drainer contracts disguised as reward NFTs
β€’ Address poisoning detection across transaction history
β€’ Jupiter token verification status on Solana token scans

Read-only across Solana, EVM (including Base), TON, Bitcoin, and XRP. We never ask for your seed phrase β€” Crypto Shield can't move your funds.

πŸ”— Available now on the Solana dApp Store: https://cryptoshieldmobile.relayshield.net
Threat actors don't need to write new malware anymore. They just need $250/month.

Remus Stealer showed up in criminal marketplaces this spring β€” Google OAuth cookie restoration built in, meaning even after a victim changes their password, the attacker can regenerate access to their session. It's not novel code. It's Lumma's proven playbook, repackaged and resold as a subscription, three tiers, priced like SaaS.

We wrote up what it actually does, why "I changed my password" doesn't mean an incident is over, and what to actually check if you suspect compromise:

[https://www.linkedin.com/pulse/remus-stealer-new-250-a-month-infostealer-renting-out-your-e1goc/?trackingId=1qeb%2Bv0Gd2NBf6e%2B3%2B%2BZig%3D%3D]

RelayShield tracks 1,000+ malware families including Remus, in real time, from the same channels these logs get sold in.
Shipped: an AI agent on AWS Bedrock AgentCore autonomously found and paid for one of our threat-intel APIs through Coinbase's x402 Bazaar: real USDC, real on-chain settlement, zero custom payment code.

tx: 0x1cb95ce37d54201b4def745269c42790fdb9bc7255f102aa648cf6f91fab0e3a (Base)

23 RelayShield endpoints are now discoverable and payable by any AI agent on AWS or x402-compatible frameworks with no integration needed on their end. This is what "agentic attack surface" defense looks like when the defender is also agent-native.

relayshield.net
πŸ›‘οΈ New: RelayShield security tools for smolagents agents, published on Hugging Face.

Four checks your agent can run before it trusts an MCP server or ingests content: mcp-registry-risk, prompt-injection-breach, tech-stack-cve, bulk-identity-risk. Pay-per-call, no subscription needed.

Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools
πŸ›‘οΈ Update: RelayShield's agent security tools just went from 4 to 9 β€” direct response to community feedback on the original release.

New: oauth_watchlist, nhi_exposure, session_risk (grouped as one "agent authority" check), plus supply_chain and secret_scan. Every tool now returns a typed, explainable result instead of a plain string.

Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools-v2
New research from the RelayShield team πŸ”

We checked 24 well-known DeFi, prediction market, and fintech companies for lookalike domains which are the typosquat variants attackers register before launching phishing campaigns.

The number: 341 registered, resolving lookalikes across those 24 brands.

The alarming part: only 1 is currently flagged by public blocklists as active phishing. The rest sit unclassified. Some are the brands' own defensive registrations, but plenty are dormant infrastructure that hasn't been activated yet. Blocklists only catch domains after they're already being used.

We didn't stop at "is it registered": For every hit we also check registration age and TLS certificate issuance timing, which is the closest thing to an early-warning signal before a domain shows up on anyone's blocklist.

Full research + methodology: [https://relayshield.hashnode.dev/341-lookalikes-1-alarm-domain-hygiene-research?utm_source=hashnode&utm_medium=feed]

Want to check your own domain? It's free, no signup: badge.relayshield.net
πŸ›‘οΈ New: a mandatory security gate for AI agents, not just an optional check.

Built on LangChain's wrap_tool_call middleware, it blocks an agent from connecting to an unfamiliar MCP server unless a security check clears first. Fails closed (never silently allows on error), 12 passing tests against the real framework.

Repo: https://github.com/nzdsf2-gif/relayshield-langchain-gate