BTC $84,739.78 +0.37%
ETH $2,686.46 +0.96%
BNB $786.59 +2.95%
XRP $1.49 +1.06%
SOL $119.79 +1.65%
TRX $0.3357 +0.37%
DOGE $0.0931 +2.00%
ADA $0.2453 +2.64%
BCH $316.45 +3.55%
LINK $14.06 +3.73%
HYPE $89.23 +3.07%
AAVE $180.98 +0.18%
SUI $1.17 +5.02%
XLM $0.2162 +2.23%
ZEC $1,322.83 +3.51%
AAPL $333.32 -0.05%
AMZN $251.80 +0.34%
GOOGL $343.29 +0.01%
MSFT $518.11 +0.09%
META $729.46 +0.29%
NVDA $235.02 +0.41%
TSLA $370.95 +0.02%
SNDK $1,716.52 -0.18%
INTC $117.94 -1.24%
SPCX $159.00 +0.14%
MU $1,070.51 -0.22%
AMD $634.32 +0.21%
BTC $84,739.78 +0.37%
ETH $2,686.46 +0.96%
BNB $786.59 +2.95%
XRP $1.49 +1.06%
SOL $119.79 +1.65%
TRX $0.3357 +0.37%
DOGE $0.0931 +2.00%
ADA $0.2453 +2.64%
BCH $316.45 +3.55%
LINK $14.06 +3.73%
HYPE $89.23 +3.07%
AAVE $180.98 +0.18%
SUI $1.17 +5.02%
XLM $0.2162 +2.23%
ZEC $1,322.83 +3.51%
AAPL $333.32 -0.05%
AMZN $251.80 +0.34%
GOOGL $343.29 +0.01%
MSFT $518.11 +0.09%
META $729.46 +0.29%
NVDA $235.02 +0.41%
TSLA $370.95 +0.02%
SNDK $1,716.52 -0.18%
INTC $117.94 -1.24%
SPCX $159.00 +0.14%
MU $1,070.51 -0.22%
AMD $634.32 +0.21%

steal

All
Article
Flash

first_img Former NCA officials were sentenced to pay £1.81 million for stealing 50 bitcoins

According to Decrypt, the UK's Crown Prosecution Service obtained a confiscation order under the Proceeds of Crime Act 2002, requiring 44-year-old Paul Chowles, a former officer of the National Crime Agency (NCA) from Bristol, to repay £1,810,678.93, approximately $2.4 million.This amount is related to the 50 bitcoins he stole, which were worth about £60,000, or approximately $77,000, when he took them in 2017. Of the 50 bitcoins, 30 have been recovered, and the Crown Prosecution Service attributes the difference between the two amounts to the appreciation of bitcoin since 2017.Chowles was involved in the NCA's investigation of the dark web market Silk Road 2, responsible for analyzing and extracting cryptocurrency from the devices involved. In May 2017, he transferred 50 bitcoins from Thomas White's reserve wallet over two days, splitting them into smaller amounts and transferring them through the bitcoin mixing service Bitcoin Fog, and cashed out a total of £144,580 through 279 transactions using Cryptopay and Wirex debit cards.For years, this theft was attributed to White, who has always denied it, and by the end of 2021, the missing bitcoins were listed as untraceable. In 2022, devices containing private keys were found during a search of Chowles' residence, and the Merseyside police, with the assistance of Chainalysis, traced the flow of funds.

first_img HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.
app_icon
ChainCatcher Building the Web3 world with innovations.