One holder says 2 BTC (~$128,000) — eight years of stacking — was drained from his Coldcard hardware wallet.
The root cause: a March 2021 firmware bug that made seed phrases predictable. Attackers brute-forced the seeds offline, then emptied the wallets with no on-device interaction needed.
Anyone who generated a seed on affected firmware should treat those funds as compromised and move to a freshly generated wallet.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Prosecutors tied him to attacks on at least 18 companies worldwide. Silnikau was extradited to the US after his arrest in Spain.
He's also linked to earlier cybercrime infrastructure, including the Angler exploit kit and long-running malvertising schemes that pushed scareware and ransomware to victims' machines.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The 26-year-old from Kitchener, Ontario hit at least 165 organizations, exposing records on at least 100 million people.
Attackers used stolen credentials to log into Snowflake customer environments that lacked multi-factor authentication, then extorted victims. Sentencing follows.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Researchers identified three WebKit features that bypass the browser proxy and connect directly from the device — triggered simply by visiting a website.
Because Apple mandates WebKit for browsers on iOS, the issue extends beyond Safari to third-party browsers, including iOS Tor browsers, where an IP leak can deanonymize the user.
• Affects iOS and macOS WebKit-based browsers
• Bypasses proxy protections silently, with no user interaction
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The attacker swapped the stolen DAI into 2,620 ETH before routing it into the mixer, a standard move to break on-chain tracing.
• $4.99M laundered so far
• 2,620 ETH converted from DAI
• $6.7M in stolen DAI still held by the attacker
More funds are expected to move, with the remaining balance still sitting in wallets under watch.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The listing opened at a minimum bid of just 10 $GRAM and still drew no takers before being removed.
The same username previously sold for roughly $13,000, raising questions about collapsing demand in the Telegram username market.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣2
The attackers are laundering only part of the haul — the bulk of the stolen assets still sits in traceable, attacker-controlled wallets.
Mixer use suggests an active cash-out attempt, giving investigators a narrow window to flag the outputs before they hit exchanges.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Researchers documented 46 attempts, though only 12 ended in an actual payout — kidnappers and home invaders increasingly target victims' families when the holder won't hand over keys.
Analysts tie the surge to data leaks exposing wallet ownership and personal addresses, turning online exposure into real-world risk.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The pattern: whenever a sequence like #3333, #5555 or #7777 was up for upgrade, a user named "Tanya" allegedly upgraded the numbers immediately before and after it — then the prize number surfaced minutes later already in her possession.
"Tanya" has reportedly been linked to a second account, "Artem," raising suspicion of insider access or a scripted advantage over ordinary users.
Telegram has not publicly responded to the allegations.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
A flaw in several crypto wallet apps produced seed phrases with far less randomness than the standard requires, shrinking the pool of possible combinations.
That let attackers mass-generate phrases until one matched a live wallet — no phishing, no malware, no user mistake required. Funds were swept the moment a hit landed.
Affected users should assume any wallet created in a vulnerable app is compromised and move assets to a newly generated wallet from a trusted source.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The transfer signals renewed laundering of proceeds from the $130 million breach, after a period of dormancy.
Investigators and chain-analysis firms are tracking the addresses as the funds get shuffled, with exchanges the likely next chokepoint.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
A U.S. federal judge has frozen identified assets tied to the attack, as the exchange moves to claw back stolen funds.
The FBI previously attributed the breach to North Korean state actors.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
The packages use randomly generated or AI-generated typosquatted names mimicking legitimate libraries, hitting developers on Windows, macOS, and Linux.
The payload grants full remote access and harvests credentials, tokens, and crypto wallet data — turning any infected build machine into a foothold for supply chain compromise.
Developers should audit recent installs and lockfiles for unfamiliar dependencies.
@fraudwatcher
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣1😭1