BTC $84,858.08 +0.68%
ETH $2,686.82 +0.86%
BNB $788.28 +3.00%
XRP $1.49 +1.15%
SOL $119.91 +1.82%
TRX $0.3356 +0.35%
DOGE $0.0932 +2.04%
ADA $0.2456 +2.52%
BCH $316.02 +3.40%
LINK $14.07 +3.70%
HYPE $89.39 +3.37%
AAVE $180.86 +0.09%
SUI $1.18 +5.09%
XLM $0.2164 +2.31%
ZEC $1,327.98 +3.52%
AAPL $333.40 -0.03%
AMZN $251.87 +0.32%
GOOGL $343.44 +0.06%
MSFT $518.20 +0.14%
META $729.82 +0.35%
NVDA $234.87 +0.37%
TSLA $370.84 +0.17%
SNDK $1,716.33 -0.14%
INTC $117.95 -1.18%
SPCX $159.08 +0.18%
MU $1,070.58 -0.23%
AMD $634.32 +0.17%
BTC $84,858.08 +0.68%
ETH $2,686.82 +0.86%
BNB $788.28 +3.00%
XRP $1.49 +1.15%
SOL $119.91 +1.82%
TRX $0.3356 +0.35%
DOGE $0.0932 +2.04%
ADA $0.2456 +2.52%
BCH $316.02 +3.40%
LINK $14.07 +3.70%
HYPE $89.39 +3.37%
AAVE $180.86 +0.09%
SUI $1.18 +5.09%
XLM $0.2164 +2.31%
ZEC $1,327.98 +3.52%
AAPL $333.40 -0.03%
AMZN $251.87 +0.32%
GOOGL $343.44 +0.06%
MSFT $518.20 +0.14%
META $729.82 +0.35%
NVDA $234.87 +0.37%
TSLA $370.84 +0.17%
SNDK $1,716.33 -0.14%
INTC $117.95 -1.18%
SPCX $159.08 +0.18%
MU $1,070.58 -0.23%
AMD $634.32 +0.17%

leak

All
Article
Flash

first_img The Cyberspace Administration of China is investigating DeepSeek and the Dark Side of the Moon for allegedly leaking data to Claude

According to The Information, citing informed sources, China's National Internet Information Office has launched an investigation into AI companies DeepSeek and Moonshot AI, triggered by Anthropic's allegations that the two companies secretly routed sensitive user data to their servers. Reports indicate that regulators visited the offices of both companies, interviewing executives and employees, focusing on whether sensitive data related to law enforcement, military, and state-owned enterprises has flowed into U.S. servers.The trigger for this investigation was Anthropic's fourth threat intelligence report released on September 10. This 154-page document accuses seven Chinese labs—Alibaba, Moonshot AI, DeepSeek, Z.ai, MiniMax, SenseTime, and Xiaomi—of engaging in what it calls "illegal distillation," which involves using the outputs of large models to train smaller models. Anthropic states that distillation itself is a legitimate practice, but it opposes its implementation through fraudulent accounts. The National Internet Information Office initially summoned all seven companies named in the report, but later narrowed the investigation to DeepSeek and Moonshot AI. Anthropic claims that Moonshot AI routed over 23 million interactions to Claude through 5,380 fraudulent accounts, while DeepSeek generated over 12.1 million interactions within a 14-day window in July.The timing of the investigation is quite delicate for both companies.

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code, which may lead to the leakage of private keys and mnemonic phrases

SlowMist released a security warning stating that it has recently received multiple reports of FomoPeek users' assets being stolen. After a joint investigation with the OKX security team, it was found that some affected users had previously installed or used FomoPeek versions 1.1 to 1.2, which contained malicious code. SlowMist stated that there are modules in FomoPeek unrelated to normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting eight different attack methods that can automatically select the exploitation method based on device model and iOS version. Affected systems include iOS 12 to 18.7 and iOS 26 to 26.1. If the exploitation is successful, the application may break through the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files. In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist indicated that its analysis of captured plaintext traffic shows that the related attack functions are currently enabled and will run automatically on a regular basis. SlowMist recommends that users who have installed or used FomoPeek versions 1.1 to 1.2 immediately check for any anomalies in their assets, generate new private keys and mnemonic phrases on trusted devices that have never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and not continuing to use or reinstall FomoPeek.

ZachXBT: Revolut allegedly caused the leakage of information for some high-net-worth users due to mistakenly trusting a forged government request

On-chain detective ZachXBT posted on his personal channel that Revolut allegedly leaked some users' personal identifiable information (PII) due to failing to recognize a forged government agency information request.According to his disclosure, Revolut previously received a request for customer information retrieval that appeared to come from a real government agency and was sent through the agency's official email domain. Because the email had valid domain authentication information, Revolut believed the request was legitimate and responded accordingly.The potentially involved data includes users' names, birth dates, occupations, addresses, email addresses, and phone numbers, as well as copies of passports or driver's licenses, identity verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories, including Bitcoin transaction records. Revolut stated in the notification sent to users that no biometric facial telemetry data was leaked.ZachXBT indicated that the scale of the incident may currently be limited, but it appears to primarily target high-net-worth users. Several Revolut users received notifications regarding the related security incident yesterday. Revolut officials had previously reminded users to verify suspicious information through in-app customer service to avoid providing personal or financial information.
app_icon
ChainCatcher Building the Web3 world with innovations.