Pavel Durov has called out WhatsAppโs โend-to-end encryption by defaultโ as a โgiant consumer fraud.โ
According to Durov, ~95% of private WhatsApp messages end up stored in plain text on Apple iCloud or Google Drive servers completely unencrypted.
WhatsAppโs cloud backups are not end-to-end encrypted by default, meaning they can be easily accessed by authorities or by Apple and Google if requested.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฏ10๐คฃ5๐ฑ2
The Polkadot bridge vulnerability has been exploited, allowing attackers to mint 1 billion $DOT ($1.1 Billion) on Ethereum.
However, due to massive slippage, the attacker was only able to walk away with ~$237,000 (108.2 ETH) after dumping all the minted tokens in a single transaction on platforms like Odos.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ11
Telegram has banned eight NFT usernames for scam activity and impersonating popular trading bots @Maestro and @Trojan.
@maes
@maestr
@mastro
@meastro
@torjan
@troj
@troja
@trojans
โข The usernames had been converted into bots and were allegedly used to mislead users by impersonating legitimate services.
โข All of the usernames were purchased less than a month ago, with total losses now estimated at 21,139 TON ($29,600).
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฅ5๐คฏ4๐คฃ2๐ฑ1๐ฏ1
Per ZachXBT, A fake Ledger Live app on the Apple App Store has been linked to $9.5M stolen from over 50 suspected victims between April 7โ13. The stolen funds were reportedly laundered via 150+ KuCoin deposit addresses.
The malicious app was removed by Apple yesterday. The three largest victims each lost seven-figure amounts during the incident.
โข April 9 - $3.23M
โข April 11 - $2.08M
โข April 8 - $1.95M
Please open Telegram to view this post
VIEW IN TELEGRAM
1๐คฃ8๐คฏ7
Alert
After ZachXBT publicly called out KuCoin for enabling the laundering of $9.5M+, KuCoin started replying to users on X with this standard support message:
โWeโre very sorry to hear about your frustrating experience. Please share your UID & Ticket Number so we can look into this for you.โ
As of now, KuCoin has not issued any full, detailed public statement addressing the $9.5M incident, the use of their deposit addresses for laundering, or any actions taken regarding the traced funds.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ14๐ฑ2๐ฅ1๐ฏ1
This media is not supported in your browser
VIEW IN TELEGRAM
Tether has officially launched Tether Wallet, a new self-custodial wallet that lets you store USDโฎ, BTC, and XAUโฎ.
A key new feature allows Tether Wallet users to claim a username in the format username@tether.me. This enables receiving funds within the app by sharing just the username instead of long blockchain addresses, similar to .eth and .ton domains.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฅ7๐ฑ5
The ban has also affected his vouches channel, which is now inaccessible. As of now, the exact reason for the ban remains unknown.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ44๐ฅ6๐คฏ6๐ฏ1
A 15-year-old teenager scammed a user out of a Pink Galaxy Plush Pepe worth over $20,000 by using a fake middleman. The victim transferred the NFT without realizing it was a scam
This same scammer is also known for scamming user @slim out of a Plush Pepe Pink Latex worth 50,000 TON (~$79,131) back in January.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ19๐คฏ2๐ฑ1
According to the CertiK, the NEAR-based DeFi protocol Rhea Finance suffered an exploit with estimated losses of at least ~$7.6 million.
The attacker reportedly created fake token contracts and added liquidity to new pools, which misled the protocolโs oracle and validation layer and allowed the attacker to drain at least $7.6 million.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฅ5๐คฃ5
Alert
Tether quickly blacklisted the hackerโs wallet and successfully froze $3.29 million of the stolen USDT before it could be moved further. The rest of the stolen funds were mostly swapped for USDC, which did not get frozen.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ9๐คฏ6
Alert
According to the official statement, the total losses from the exploit have now exceeded $18.4 million. The attack reportedly targeted the Margin Trading feature and was the result of a sophisticated vulnerability in the slippage protection mechanism.
The team also revealed that the attack was carefully planned at least 2 days before the actual execution.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฑ7
Major has introduced a new feature called โRoyal Support Chat.โ All Major badge holders will now have access to priority support for a wide range of Telegram-related issues.
This includes:
โข Assistance with accounts, bots, and channels
โข Help with resolving issues such as shadow bans and false restrictions
โข Support handled directly in a private group
The feature is expected to roll out at the end of April. Additionally, Major badge prices are expected to increase going forward.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฏ5๐ฅ1
According to ZachXBT, the attacker exploited KelpDAO's liquid staking token. The attack addresses were funded through Tornado Cash.
The attacker is reported to have stolen over 116,500 ETH across multiple transactions, making it the biggest exploit of 2026 so far.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฑ1
Alert
The official team on X stated that they have paused all rsETH contracts and are actively investigating the incident with top security experts.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฏ4๐คฃ2
RaveDAOโs $RAVE coin is down more than 86% in one day after ZachXBT called out major exchanges like Bitget and Binance to delist the coin.
At its peak, $RAVE had a market cap of over $6B, but now itโs sitting at around $750M, dropping from its ATH of $28 to $2.90
Please open Telegram to view this post
VIEW IN TELEGRAM
Vercel, an American cloud computing company that provides a platform for instant web application development and hosting, has been hacked by the threat actor known as ShinyHunters.
โข The attackers have listed customers' data, source code, databases, and keys for sale.
โข The official Vercel team has confirmed the breach on their website and is recommending that all customers immediately rotate their keys and review their security settings.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ9๐ฅ3
Alert
The official ShinyHunters team also confirmed that it was fake.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
๐คฃ22๐คฏ4
The owner of the Telegram username @boss has listed it for auction on getgems.io with a starting bid of $500,000 (370,497 TON).
The same owner also acquired several OG usernames in 2022, including @oman, @chef, @highroller, @dragon, @city, and @english, which could potentially be listed for auction soon as well.
Please open Telegram to view this post
VIEW IN TELEGRAM