πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.85K subscribers
1.13K photos
63 videos
1K links
Download Telegram
🚨13,323 Coldcard-linked wallets allegedly swept in mass drain operation
β €
A forum actor claims to have conducted an August 2026 cryptocurrency draining operation targeting wallets described as associated with Coldcard Q1 MK4 devices.
β €
The published operation log allegedly contains:
β €
β€’ 8,716 recovered seed phrases
β€’ 13,323 Bitcoin addresses
β€’ Approximately 1.5 BTC reportedly drained
β€’ 1,092.91 BTC in historical incoming transactions
β€’ 64,720 recorded transactions
β€’ 11,432 addresses previously holding funds
β€’ Mnemonic phrases and private keys for wallets now showing zero balances
β €
The actor published the alleged output as a full dataset and included several samples, along with a ranking of addresses by historical Bitcoin received.
β €
The seller says the tool still requires improvements to UTXO selection and fee estimation and claims additional runs are planned. The post does not explain how the seed material was obtained or establish that Coldcard hardware or firmware was compromised.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Hansa: The Infiltration of the Dark Web

Video Credit: youtube.com/@fern-tv
❀5😈1
Server crashed, restarting. Give me a little bit. No alerts are missed and once it is backup it will catch everything.
‼️ New Ransomware Group: Panzer

http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion

Panzer ransomware operation launches affiliate recruitment program
β €
The Panzer ransomware operation is recruiting penetration testers and other affiliates, offering access to a management platform, multi-platform lockers and an 80/20 revenue-sharing model.
β €
Advertised affiliate features include:
β €
β€’ Individual dashboards with unique access links
β€’ Earnings, balances, active builds, tickets and team activity tracking
β€’ Cryptocurrency deposits, withdrawals and transaction histories
β€’ Lockers supporting Windows, Linux, ESXi and FreeBSD
β€’ More than 15 customizable commands and claimed anti-detection features
β€’ Real-time monitoring and configurable panels deployed with each build
β€’ Automatically generated onion-based victim negotiation chats
β€’ File attachments, searchable histories and real-time messaging
β€’ Bitcoin invoice generation directly inside victim chats
β€’ Automatic crediting of confirmed payments to affiliate balances
β€’ Team accounts with configurable permissions
β€’ Support tickets, platform announcements and operational rules
β €
The operation also provides a leak-site publishing system where affiliates can submit victim names, stolen-data samples, download links and descriptions for approval. Higher-profile attacks may reportedly receive additional promotion to increase pressure on victims.
β €
Panzer advertises an 80% share for affiliates and 20% for the operators, automatically deducted from each payment.
β €
Recruitment rules reportedly prohibit:
β €
β€’ Targeting organizations in CIS countries
β€’ Targeting companies involved in abuse of children or minors
β€’ Violating the operation’s internal rules
β€’ Remaining inactive for more than one week after joining
β €
Applications are handled through the operation’s Tox support channel.
β €
This claim is currently unverified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2
πŸš¨πŸ‡©πŸ‡ΏπŸ‡¬πŸ‡§πŸ‡ͺπŸ‡¨ VPN credentials for three organizations allegedly offered for sale
β €
A forum actor is advertising access to three organizations across Algeria, the United Kingdom and Ecuador. The seller claims the credentials have been verified and requires transactions to use escrow.
β €
The listings include:
β €
β€’ πŸ‡©πŸ‡Ώ Algeria Ministry of Commerce VPN access: $500
β€’ πŸ‡¬πŸ‡§ UK cloud-based provider web VPN access: $200
β€’ πŸ‡ͺπŸ‡¨ Ecuador national university access: $200
β €
The UK provider is described as generating more than $8 million in revenue. No revenue figures or further access details were provided for the Algerian ministry or Ecuadorian university.
β €
These claims are currently unverified.
β €
πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Ransomware Group: Dark Project

http://darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid[.]onion
❀2
ZeroOsintX: A powerful OSINT toolkit designed for security researchers and penetration testers.

GitHub: https://github.com/roothackerslab/ZeroOsintX

It gathers intelligence on domains, IP addresses, email addresses, phone numbers, and social media accounts, then presents the findings in polished, interactive reports.
❀1
⚠️ Boltz has disabled swap services until further notice after a sharp rise in automated, AI-assisted attacks targeting its infrastructure. They state no user funds were at risk, refunds remain available, and support is still online.

Source: https://boltz.exchange/
❀1
β€ΌοΈπŸ‡ΊπŸ‡Έ A forum user is seeking to buy or take a percentage cut of network accesses to US healthcare/pharma organizations, requesting details such as AV, access type, revenue, and host/credential counts (DU/DA).

The buyer specifies target company revenue ranging from 50 million to 100 billion USD and offers escrow.