Fraud Watch
808 subscribers
66 photos
1 video
2 links
Download Telegram
⚠️ JUST IN: Bybit has sued North Korea and the Lazarus Group over the $1.5B hack — the largest crypto theft on record.

A U.S. federal judge has frozen identified assets tied to the attack, as the exchange moves to claw back stolen funds.

The FBI previously attributed the breach to North Korean state actors.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Nearly 800 malicious npm packages were published in a single campaign dropping a cross-platform RAT and infostealer.

The packages use randomly generated or AI-generated typosquatted names mimicking legitimate libraries, hitting developers on Windows, macOS, and Linux.

The payload grants full remote access and harvests credentials, tokens, and crypto wallet data — turning any infected build machine into a foothold for supply chain compromise.

Developers should audit recent installs and lockfiles for unfamiliar dependencies.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
This is like the 10th this year
This media is not supported in your browser
VIEW IN TELEGRAM
big ginormous voluptuous juicy girthy things coming soon guys
⚠️ JUST IN: popular seller @lunacy spotted in the epstien files
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣1😭1
⚠️ EXPLOIT: Attackers are draining funds from Lightning Network payment servers in a fresh wave of Bitcoin infrastructure exploits.

The targets are node operators running hot-wallet payment infrastructure — channels must stay online and funded, leaving keys exposed on internet-facing servers.

Once a node is compromised, funds move instantly over Lightning and are near-impossible to claw back, unlike on-chain transfers that can be traced through mixers.

Operators are advised to audit node access, rotate credentials, and cap channel balances until patches land.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: A phishing attacker who stole $501K USDC on Base lost nearly all of it minutes later (370k).

The thief swapped the stolen USDC for WETH on Uniswap V4 with no slippage protection.

An MEV bot sandwiched the trade and took the bulk of the funds, leaving the attacker with a fraction of the original haul.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1👏1
This media is not supported in your browser
VIEW IN TELEGRAM
@opensrc my opp
⚠️ JUST IN: Bingo, a known figure on marketplace forum OGUsers, has been banned from the site.

The reason behind the removal is unclear — his profile now shows the ban, but no public explanation has been given.

Open question: whether he stepped away voluntarily or was pushed out over a dispute or rule violation.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Coinsbuy wallets were drained of $7.9M+ across TRON and Ethereum.

The attacker started laundering proceeds into Monero via exchanges. A six-figure sum was frozen before it could move.

Coinsbuy paused deposits and withdrawals during the incident, then resumed both services.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Tiffany Milanovich, a US-based threat actor, has been tied to more than $5 million in crypto thefts.

She allegedly ran support-impersonation scams, posing as help desk staff to drain hardware wallet and exchange users' funds.

Investigators say she taunted victims and flaunted the stolen proceeds on social media.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ JUST IN: Justin Swaddle, a 20-year-old member of The Com, was sentenced to two years in a UK prison for blackmail and child sexual abuse offenses.

Known online as "Epstein," "Rugen," and "Moscow," he groomed and blackmailed victims into producing indecent images.

117 female victims identified worldwide
• Victims aged 13–17
• Sentence: 2 years imprisonment

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: Telegram dice emoji rolls can allegedly be manipulated by abusing server latency.

The claimed technique exploits a ~0.5ms server delay: the attacker sends and deletes the dice emoji within 0.1ms, so the roll never fully registers, then repeats until the desired number lands.

The trick targets Telegram-based gambling bots and casinos, which rely on the dice animation as their randomness source.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
⚠️ EXPLOIT: An attacker minted ~4 billion $ONE tokens worth roughly $5 million on Harmony.

The mint equals more than a quarter of the token's existing supply. Roughly $3.5 million of the fresh tokens was moved to exchanges, and $ONE's price dropped sharply.

Harmony says it is investigating the exploit.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
1
⚠️ EXPLOIT: ZachXBT is refusing to trace Harmony's 4B $ONE exploit — and telling others not to work for free.

The onchain investigator says Harmony "took advantage" of volunteers who helped freeze funds after its $100M DPRK hack in 2022, paying them $0 and offering only a "good job."

His comments came after Harmony asked exchanges to freeze 4 wallets tied to the latest incident.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
😴1
⚠️ JUST IN: A crypto whale lost another $25 million after two wallets were drained in just 15 minutes.

The attacker swept DAI, WBTC, USDC, LDO and ETH into a freshly created wallet. Investigators suspect a private key compromise rather than a contract flaw.

It's the same victim hit in an earlier drain, suggesting the underlying key exposure was never fully remediated.

@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
2💯1
Guys botting people isnt very nice and it really hurt my feelings
😴3
Please apologize whoever dis this you made my hamster cry
🔥3