Connect with us

Crypto World

Fake Wasabi Wallet app steals 6 BTC after landing on Apple Store

Published

on

Fake Wasabi app on the Apple App store.

A fake Wasabi Wallet application has appeared on Apple’s App Store and has already been linked to the theft of roughly 6 BTC from one user, according to crypto security monitoring reports.

Summary

  • A fake Wasabi Wallet app on Apple’s App Store has been linked to the theft of about 6 BTC from one user.
  • The fraudulent Wasabi Wallet listing is the 27th reported crypto wallet clone on the App Store this year.
  • A fake Ledger app remains the largest reported case, with about $9.3 million stolen.

According to Com Feed monitoring, the malicious application was presented as Wasabi Wallet, with reports circulating on X showing that one victim lost about 6 BTC after encountering the fraudulent software. The listing has also been identified as the 27th crypto wallet clone found on Apple’s App Store so far this year.

Fake Wasabi app on the Apple App store.

Fake Wasabi app on the Apple App store. Source: X/thecomfeed

Details about how the victim interacted with the application, including whether a recovery phrase was entered or another method was used to drain the wallet, have not been disclosed in the initial reports. Com Feed warned users to verify the Wasabi Wallet application carefully before downloading software presented under the wallet’s name.

Advertisement

Fake Wasabi Wallet becomes 27th reported App Store clone

The reported Wasabi Wallet impersonator adds to a series of fraudulent crypto applications that have passed through Apple’s App Store review process in 2026.

According to the monitoring report, 27 wallet clones have now been identified on the App Store since the beginning of the year. The fake Ledger application remains the largest case among the reported clones, with approximately $9.3 million linked to thefts.

Fraudulent wallet applications commonly imitate the branding and interface of established crypto products, making it difficult for users to distinguish them from legitimate software based on appearance alone. In the current case, the initial report specifically identified the application as a fake Wasabi Wallet drainer rather than an official release from the wallet project.

Advertisement

The reported loss of about 6 BTC also places the latest case among the larger individual thefts tied to wallet impersonation apps this year. The exact dollar value depends on Bitcoin’s price when the assets were taken, while the initial monitoring report quantified the victim’s loss in BTC rather than providing a confirmed dollar figure.

No information in the initial report identified the developer behind the application or explained how long the listing had been available through Apple’s marketplace. Details about whether Apple had removed the application were also not included in the information available at the time of the report.

Fake Ledger app previously drained musician’s 5.9 BTC

A similar incident in April showed how fraudulent applications can obtain control of crypto wallets by convincing users to disclose their recovery credentials.

On April 20, American musician Garrett Dutton, known professionally as G. Love, said he had lost 5.9 BTC worth about $420,000 at the time, after downloading software disguised as the Ledger Live manager from Apple’s App Store.

Advertisement

Dutton said he installed the malicious program on a new MacBook Neo and entered his seed phrase after the application prompted him to do so. The attacker subsequently emptied a Bitcoin stash that Dutton said he had accumulated for nearly a decade and intended to use for retirement.

On-chain investigator ZachXBT later tracked the stolen funds and reported that they had been transferred to addresses associated with KuCoin through nine transactions.

KuCoin told crypto.news at the time that it maintained procedures for monitoring and addressing potentially suspicious activity in line with regulatory requirements. The exchange disputed any characterization that it had allowed illicit activity and said the matter was under review, while declining to discuss specific details because of security, privacy and investigative considerations.

The April incident followed earlier cases involving software impersonating hardware wallet companies. In 2023, a fake Ledger application appeared on Microsoft’s store and was linked to nearly $600,000 in losses before Microsoft acknowledged that the program had passed its review process.

Advertisement

Crypto wallet impersonation has extended beyond app stores

Wallet owners have also faced impersonation attempts through physical mail, with scammers using leaked customer information to send letters carrying forged Ledger and Trezor branding.

As previously reported by crypto.news, some letters instructed recipients to complete a supposed mandatory authentication process before a stated deadline. QR codes included in the mail directed users to malicious websites where they were asked to provide 12-word or 24-word recovery phrases.

Once entered, the recovery phrases could give attackers control over the corresponding wallets, allowing them to transfer assets without requiring further authorization from the victim.

The FBI has separately documented rising losses from cryptocurrency-related fraud in the United States. Crypto-related losses reached approximately $11 billion in 2025, compared with about $9 billion a year earlier.

Advertisement

The latest fake Wasabi Wallet report concerns an impersonation application and does not indicate that Wasabi Wallet itself was compromised. The reported theft is instead tied to software presented to users under the wallet’s identity.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

H100 becomes Europe’s No. 2 Bitcoin treasury after 2,455 BTC deal

Published

on

H100 becomes Europe’s No. 2 Bitcoin treasury after 2,455 BTC deal

H100 becomes Europe’s No. 2 Bitcoin treasury after 2,455 BTC deal

Sweden’s H100 more than tripled its Bitcoin holdings to 3,506 BTC after completing an acquisition involving 2,455 BTC.

Source link

Continue Reading

Crypto World

As ICE Detention Expands, Deaths Reach a 22-Year High

Published

on

As ICE Detention Expands, Deaths Reach a 22-Year High

La is one of more than 30 people who have died in ICE detention since October amid a surge in fatalities that has raised alarm from experts and left rights groups and a growing number of families searching for answers—and, perhaps, a measure of accountability.

The fatality rate in ICE custody reached a 22-year high in the opening months of this fiscal year, according to a report published in the medical journal JAMA earlier this year. Between the beginning of October and Jan. 19, the latest date in the report’s analysis, 18 immigration detainee deaths were reported; since then, at least 17 other people have died while being held by ICE. 

By comparison, 3 people died in ICE detention in the full 2022 fiscal year, per the report.

A spokesperson from the Department of Homeland Security (DHS), which houses ICE, maintained in a statement to TIME that “there has been NO spike in deaths.” 

Advertisement

“Consistent with data over the last decade, as of May 29, death rates in custody under the Trump administration are 0.009% of the detained population,” the spokesperson said. “As bed space has rapidly expanded, we have maintained a higher standard of care than most prisons that hold U.S. citizens—including providing access to proper medical care. For many illegal aliens this is the best healthcare they have received their entire lives.”

Source link

Continue Reading

Crypto World

MARA sold $1.63B in Bitcoin as treasury holdings fell in 2026

Published

on

Bitcoin traders face possible 70% drawdown with $38k target in play

MARA Holdings has sold about 23,093 Bitcoin for roughly $1.63 billion during the first half of 2026, turning a large part of its BTC treasury into cash as it funded operations, investments and liquidity needs.

Summary

  • MARA sold about 23,093 BTC for roughly $1.63 billion during the first half of 2026.
  • The company ended June with 35,577 BTC valued at about $2.1 billion.
  • Bitcoin sales were used to fund operations, growth investments and liquidity needs.
  • MARA later pledged 18,750 BTC to secure $600 million of incremental borrowing from Coinbase and Two Prime.
  • The company is using its Bitcoin reserves alongside debt financing to support projects including the planned Long Ridge acquisition.

According to MARA’s Aug. 6 Form 10-Q filing with the U.S. Securities and Exchange Commission, the Bitcoin was sold at an average price of $70,631 during the six months ended June 30. The company said the sales were part of its strategy to fund operations, support growth opportunities and manage liquidity.

The transactions came after MARA changed how it manages its Bitcoin reserves. Having allowed sales of newly mined Bitcoin in 2025, the company expanded the policy in 2026 to permit sales of BTC already held on its balance sheet. MARA can now hold Bitcoin as a long-term investment, sell coins based on market conditions and capital needs, or make opportunistic purchases.

Advertisement

By June 30, MARA still held 35,577 BTC with a fair value of about $2.08 billion, based on a quarter-end Bitcoin price of $58,524. Its holdings had fallen from 53,822 BTC at the end of 2025 and 49,951 BTC a year earlier, though they were slightly higher than the 35,303 BTC reported at the end of March.

MARA Bitcoin sales supplied most of its first-half investing cash

The $1.63 billion raised from Bitcoin became MARA’s largest source of investing cash during the period. Its filing showed net cash provided by investing activities of about $1.47 billion, compared with $337 million of cash used in investing activities during the same period in 2025.

Against the Bitcoin proceeds, MARA spent $94.3 million on property and equipment and $61.1 million, net of cash acquired, on its Exaion and Meerkat acquisitions. The company has been adding infrastructure that can support Bitcoin mining alongside artificial intelligence, high-performance computing and critical IT workloads.

At the same time, operating activities consumed $471.3 million of cash during the first half, up from $378.9 million a year earlier. MARA attributed the increase mainly to lower revenue and higher operating costs.

Advertisement

The Bitcoin sales also took place while MARA reduced debt. Financing activities used about $1.12 billion during the six months, including $912.8 million used for partial repayments of its March 2030 and June 2031 convertible notes and $350 million used to repay a previous credit line. Another $150 million credit facility partly offset those outflows.

MARA said it repurchased approximately $1 billion of its 0% convertible senior notes through privately negotiated transactions during the half, helping reduce total debt from $3.6 billion at Dec. 31 to about $2.4 billion by June 30.

MARA has put more of its remaining Bitcoin to work

Alongside outright sales, MARA has increasingly used its remaining BTC for lending and collateralized borrowing.

At June 30, 4,742 BTC had been loaned to third parties, while another 4,528 BTC were pledged as collateral. That left 26,307 unrestricted BTC with a fair value of about $1.5 billion. MARA reported $10.7 million in interest income from Bitcoin lending during the first six months of the year.

Advertisement

MARA describes Bitcoin as both a treasury asset and a source of liquidity. Under its digital asset management strategy, the company can use portions of its holdings for lending, structured trading and collateralized financing rather than keeping the entire balance inactive.

The strategy became more pronounced after the second quarter. On Aug. 4,MARA pledged 18,750 BTC as initial collateral for new lending arrangements with Coinbase Credit and Two Prime Lending that provided $600 million of incremental borrowing.

Coinbase’s $450 million facility included $300 million of new funding and refinanced MARA’s existing $150 million credit line. The facility carries a floating interest rate equal to the midpoint of the federal funds target range plus 3.875% and matures on Aug. 4, 2028, with an automatic one-year extension unless either side cancels it.

Two Prime separately provided a $300 million term loan carrying a fixed annual rate of 7.65%, with maturity scheduled for Aug. 3, 2028. Both facilities require MARA to maintain collateral ratios, according to the Aug. 9 report, with additional collateral required if the pledged assets fall below contractual margin levels.

Advertisement

Bitcoin treasury fell as MARA absorbed a $1.87 billion first-half loss

The sales occurred during a difficult first half for MARA’s reported earnings. The company generated $349.5 million of revenue during the six months ended June 30, down from $452.4 million in the same period of 2025, while recording a net loss of $1.87 billion compared with net income of $274.8 million a year earlier.

Bitcoin price movements accounted for a large part of the earnings swing. MARA reported that the fair value of its Bitcoin holdings fell by about $1.4 billion during the first six months as the market price declined. For the second quarter alone, the reduction was about $343 million.

MARA nevertheless increased its mining capacity over the year. Energized hashrate reached 70.3 EH/s at June 30 from 57.4 EH/s a year earlier, while miner efficiency improved to 17.3 joules per terahash from 18.3. Total energy capacity increased to 1.9 GW from 1.7 GW.

During the second quarter, MARA produced 2,422 BTC and sold 2,213 BTC at an average price of $73,078, according to its Aug. 7 earnings report. Most of the first-half reduction in its Bitcoin treasury therefore occurred during the first quarter, when the company sold 20,880 BTC for about $1.5 billion.

Advertisement

Long Ridge links MARA’s liquidity strategy to infrastructure expansion

Part of MARA’s latest Bitcoin-backed borrowing may now finance its proposed purchase of Long Ridge Energy & Power in Ohio, connecting its treasury strategy with its expansion into energy and computing infrastructure.

MARA entered an agreement on April 29 to acquire 100% of Long Ridge. The property includes a 485 MW combined-cycle gas power plant in Hannibal, Ohio, which the company expects to increase to 505 MW in the first quarter of 2027, as well as more than 1,600 contiguous acres with water, fiber and rail access. The site sits next to MARA’s existing Hannibal data center operations.

The transaction carries an enterprise value of about $1.5 billion, including up to roughly $900 million of assumed debt, according to MARA’s Aug. 9 financing disclosure. The company has also secured a Barclays commitment for a 364-day senior secured bridge facility of up to $785 million that can serve as backstop financing for part of the acquisition debt.

MARA has pursued another large powered site in Texas as part of the same infrastructure buildout. Under the agreement announced in July, the company is acquiring more than 1,200 acres in Matagorda County, with access to an initial 1 GW of grid capacity expected by October 2027 and up to 2 GW by April 2028.

Advertisement

Working with Starwood Digital Ventures, MARA plans to develop the property for high-performance computing, flexible compute services and Bitcoin mining. Its SEC filing describes the Starwood structure as site-specific joint ventures formed after Starwood secures qualifying tenants, with MARA contributing sites and Starwood supplying capital against the value of those assets before MARA is required to invest additional cash.

On June 30, MARA reported $421.3 million of cash and cash equivalents and about $2.1 billion of Bitcoin, putting the combined value of its cash and digital assets at roughly $2.5 billion. The company also had approximately $1.5 billion of unused capacity under its at-the-market equity program, through which it sold no shares during the first six months of 2026.

Source link

Advertisement
Continue Reading

Crypto World

LBank Launches Crypto Resilience Initiative, Building on Its Security Collaboration with CertiK

Published

on

[PRESS RELEASE – Singapore, Singapore, August 10th, 2026]

LBank today announced the launch of the Crypto Resilience Initiative, an effort to support the security of its platform. As part of this initiative, LBank will continue to work with CertiK, the largest Web3 security services provider, through CertiK’s penetration testing services and LBank’s participation in CertiK’s Bug Bounty program.

The initiative is intended to support LBank’s ongoing security efforts by applying CertiK’s professional penetration testing capabilities and extensive blockchain security expertise into LBank’s platform security practices.

As digital assets continue to see broader adoption, exchanges and blockchain infrastructure providers are facing increasingly sophisticated threats, including cross-chain exploits, smart contract vulnerabilities, and AI-assisted attack techniques. The Crypto Resilience Initiative is designed to support more proactive security practices through enhanced technical assessments and external blockchain security expertise.

Advertisement

“Security is becoming increasingly collaborative,” said Eric He, Community Angel Officer and Risk Control Advisor at LBank. “As the blockchain ecosystem grows more interconnected, protecting users requires not only stronger internal controls but also closer cooperation across the industry. Through the Crypto Resilience Initiative, we look forward to working with CertiK to contribute to a safer digital asset ecosystem.”

Alongside external security partnerships, LBank continues to maintain a multi-layered security framework that includes cold wallet custody, multi-signature authorization, behavioral analytics, AI-assisted risk detection, and continuous monitoring designed to safeguard user assets and maintain platform stability.

Looking ahead, LBank plans to continue working with CertiK to further advance the Crypto Resilience Initiative. The companies expect the initiative to support stronger security practices across the industry while contributing to the long-term resilience of the digital asset ecosystem.

About CertiK

CertiK is the largest Web3 security service provider, headquartered in New York. Since its founding in 2017, the company has grown into a trusted risk management partner for regulators, institutions, and Web3 innovators worldwide.

Advertisement

CertiK delivers AI-powered, full-lifecycle risk management solutions that integrate directly into institutional clients’ system development lifecycles (SDLC). To date, CertiK has detected more than 119,000 vulnerabilities and protected over $600 billion in digital assets across 150+ countries and regions. Operating under SOC 2 Type II and ISO 27001 standards, CertiK works closely with regulators worldwide on digital asset policy development and regulatory consultation.

About LBank

Founded in 2015, LBank is a leading global cryptocurrency exchange serving over 25 million registered users in 160 countries and regions. With a daily trading volume exceeding $23.81 billion and 10 years of safety with zero security incidents, LBank is dedicated to providing a comprehensive and user-friendly trading experience. Through innovative trading solutions, the platform has enabled users to achieve average returns of over 130% on newly listed assets.

LBank has listed over 300 mainstream coins and more than 50 high-potential gems. Ranked No. 1 in 100x Gems, Highest Gains, and Meme Share, LBank leads the market with the fastest altcoin listings, unmatched liquidity, and industry-first trading guarantees, making it the go-to platform for crypto investors worldwide.

Advertisement

Follow LBank for Updates

Website: https://www.lbank.com/

Twitter: https://twitter.com/LBank_Exchange

Telegram: https://t.me/LBank_en

Advertisement

Instagram: https://www.instagram.com/lbank_exchange

LinkedIn: https://www.linkedin.com/company/lbank

For media requests, please contact:

Email: press@lbank.com

Advertisement

The post LBank Launches Crypto Resilience Initiative, Building on Its Security Collaboration with CertiK appeared first on CryptoPotato.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin’s BVIV ‘fear gauge’ has crashed. Still, downside protection isn’t cheap

Published

on

Bitcoin's BVIV 'fear gauge' has crashed. Still, downside protection isn't cheap

With bitcoin’s price stubbornly range-bound, the appetite for “directional optionality,” or bets on big price moves in either direction, has evaporated, he said.

Directional optionality involves traders buying call or put options, or both, to profit from anticipated big moves in the underlying asset, but they aren’t doing that now. The demand for bitcoin options has weakened, and this is reflected in BVIV’s decline.

A call option offers a way of buying an asset on the cheap should the price rise, in return for a small upfront cost. A put option offers insurance against price drops in the underlying asset.

Despite the weaker demand, the supply remains elevated. Although every option contract involves both a buyer and a seller, “high supply” in this context means that investors are increasingly writing (selling) options to market makers. Market makers, who are generally market-neutral and provide liquidity, take the opposite side by buying these options.

Advertisement

“A growing number of market participants, including bitcoin miners and corporate treasuries, are utilizing “systematic overwriting programs,” Sears noted.

These strategies involve writing call options to generate yield on their spot BTC holdings, which effectively suppresses volatility by flooding the market with options supply.

The impact of this systematic selling of options on the BVIV is likely accentuated by the typical midyear lull in prices and a cooling spot market. With fewer traders active during the vacation period, realized volatility (how much the price actually moves) has compressed, putting further downward pressure on implied volatility (how much the market expects it to move), Sears said.

Source link

Advertisement
Continue Reading

Crypto World

3 Altcoins Post Double-Digit Gains as Bitcoin (BTC) Reclaims $65K: Market Watch

Published

on

Bitcoin’s price hasn’t made a major move for days, as it continues to remain stuck at around $65,000 since Friday. The good news for the bulls is that it now stands on the upper side.

Most larger-cap alts perform similarly, with little to no actual moves. XMR is up by 3%, NEAR by 2.5%, while WLD and PUMP have stolen the show.

BTC Rises Above $65K (Slightly)

The previous business week began on a significantly more volatile note. At first, BTC was rejected at $64,000 after an eventful weekend on the Middle East war front, and dipped to $62,200 within hours. However, the bulls stepped up and helped it recover the lost ground almost immediately.

The following few days were more positive as bitcoin tapped $65,000 by Wednesday. It remained at around that level before the CLARITY Act faced another setback in the US Senate, and BTC dipped toward $64,000. The weak US jobs report from Friday, though, brought some hopes that the Fed won’t hike the rates in September, and BTC reacted with a price pump to $65,400.

Advertisement

That was short-lived, though, as the cryptocurrency failed to maintain its run. It retreated to around $65,000 and has spent the following 72 hours or so trading sideways. It currently sits above that level after dipping to $64,800 yesterday, but more volatility is expected as the week progresses.

Its market cap has seemingly reclaimed the $1.3 trillion level, while its dominance over the alts remains above 57% on CG.

BTCUSD Aug 10. Source: TradingView
BTCUSD Aug 10. Source: TradingView

3 Alts Pump Hard

Bitway (BTW) is the altcoin that has entered the top 100 coins by market cap, after surging by another 20% in the past day. The asset has rocketed by triple digits since this time last Monday.

WLD and PUMP follow suit in terms of daily gains. Both assets have jumped by around 13% to $0.345 and $0.0028, respectively. VVV is up by 9% to $12.

In contrast, there’s little volatility among the top 15 alts. ETH, BNB, XRP, SOL, and TRX are slightly in the green, while HYPE, DOGE, RAIN, ZEC, and ADA have posted insignificant losses.

Advertisement

The cumulative market capitalization of all crypto assets remains close to $2.3 trillion on CG.

Cryptocurrency Market Overview August 10. Source: QuantifyCrypto
Cryptocurrency Market Overview August 10. Source: QuantifyCrypto

The post 3 Altcoins Post Double-Digit Gains as Bitcoin (BTC) Reclaims $65K: Market Watch appeared first on CryptoPotato.

Source link

Continue Reading

Crypto World

Europe Will Get Its First Total Solar Eclipse in Over 25 Years. Here’s What You Should Know

Published

on

Europe Will Get Its First Total Solar Eclipse in Over 25 Years. Here's What You Should Know

A total solar eclipse is not just an occasion for skygazing, it’s an occasion for science. The most celebrated experiment conducted during an eclipse occurred on May 29, 1919. Four years earlier, in Nov., 1915, Albert Einstein first presented his theory of general relativity, arguing, among other things, that gravity can warp space-time and bend light as it passes around a massive object like the sun. That bending would be slight. Starlight passing by the sun would, Einstein calculated, be diverted by just 1.75 arc seconds, with a single arc second measuring one=3,600th of a degree. It would be impossible to observe that phenomenon in real time, of course, since the brilliant fires of the sun would wash out something as faint as starlight. During an eclipse, however, those fires would be briefly blotted.

To take advantage of that opportunity, two expeditions of astronomers—one from the Greenwich Observatory and one from Cambridge University—set out for Sobral, Brazil and the island of Principe off the west coast of Africa, where the approaching 1919 eclipse would be visible. During the brief minutes of totality, they charted the precise positions of stars near the sun that popped into view when the lights went out. On subsequent evenings, after the sun had set, they mapped the positions of the same stars and found that they indeed differed slightly from the measurements taken during the eclipse.

Source link

Continue Reading

Crypto World

North Korean hackers use local AI to automate attacks on crypto firms

Published

on

Consensys halts releases after North Korea-linked developer gains access

North Korea-linked hacking group Kimsuky has built three local AI environments as part of preparations for cyberattacks targeting cryptocurrency and financial companies, according to new cybersecurity research.

Summary

  • Kimsuky has built three local AI environments using Ollama, GPT4All and Msty.
  • The North Korea-linked group is using AI for malware development, data analysis and attack automation.
  • Kimsuky has produced AI-generated phishing material targeting crypto, investment and fintech firms.
  • North Korean hackers stole an estimated $2.02 billion in cryptocurrency during 2025.

Genians, a South Korean cybersecurity firm, said in a report released Monday that it found evidence of Kimsuky operating local large language model environments through Ollama, GPT4All and Msty, giving the group access to AI tools that can run without relying on external cloud services.

Kimsuky has built local AI systems for cyberattacks

Running models locally allows operators to make queries without sending potentially sensitive attack information to third-party AI providers. According to the research, the environments also support retrieval-augmented generation, which can connect an AI model with additional information supplied by its operator.

Advertisement

Alongside the three environments, researchers found libraries and frameworks that can embed language models into custom software. Kimsuky had also collected the AI coding assistant Cursor and speech-to-text tools as it assembled its AI infrastructure.

Rather than developing new AI models, the activity examined by Genians centered on putting existing open-source technology to work across malware development, data analysis and attack automation.

The firm assessed that the activity had moved beyond isolated tests because Kimsuky was continuously preparing to incorporate AI into operational attack capabilities. However, its findings did not show that the group was developing proprietary AI models from scratch.

Advertisement

Keeping the models on local infrastructure could also allow the hackers to work with information without submitting it to external cloud systems, according to the report. The collection of supporting software indicates that the AI environments form part of a larger technical setup rather than functioning only as standalone chat tools.

AI-generated phishing documents target crypto firms

Kimsuky has also continued using generative AI to prepare phishing material focused on cryptocurrency, investment strategies and fintech services, according to Genians.

Researchers identified polished documents that closely copied material associated with a Korean AI-powered investment platform. The files used natural language, consistent formatting and professional design elements that the cybersecurity firm associated with AI-generated content.

Such material provides another use for the group’s AI infrastructure beyond coding and data processing. Instead of relying only on poorly written phishing emails, the operators can use generative tools to prepare documents designed around financial subjects relevant to their intended targets.

Advertisement

The findings add Kimsuky to a series of North Korea-linked operations using newer technical and social-engineering methods against the cryptocurrency industry.

In July, cybersecurity firm JUMPSEC reported that BlueNoroff, another North Korea-linked group, was operating fake Zoom and Microsoft Teams meetings that profiled cryptocurrency users before malware was delivered.

JUMPSEC recovered source code from an active phishing kit after its operators accidentally exposed JavaScript source maps. The code contained wallet-scanning functions, operator controls, and separate malware delivery routes for Windows and macOS.

Once a target entered a fake meeting page, the system checked for Ethereum wallet connections and non-EVM wallets, including Solana tools, before sending the results to an operator panel. Windows implants could also identify browser extensions across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants, allowing operators to check for wallets such as MetaMask.

Advertisement

The attackers could then decide whether to continue the intrusion based on information gathered from the target, JUMPSEC found.

North Korean hackers are combining AI with social engineering

AI also appeared inside BlueNoroff’s fake meeting operation, although in a different role from the local models identified in the Kimsuky research.

According to JUMPSEC, operators combined AI-generated headshots with body movements taken from previous meetings to create convincing participants for fake video calls. Victims could arrive through a Telegram account belonging to a real contact whose account had already been compromised, before receiving a Calendly invitation that redirected them to a fake meeting domain.

During the call, an operator could display a prepared video, send messages about a supposed microphone problem, and trigger a fake Zoom software update. On Windows, the resulting ClickFix process used PowerShell and VBScript, while the macOS route delivered a fake meeting installer alongside information-stealing malware.

Advertisement

Arctic Wolf had previously identified more than 80 lookalike Zoom and Teams domains associated with related operations. About 80% of the targets it identified worked in crypto, blockchain finance or connected investment sectors, while founders and chief executives represented 45% of the identified targets.

North Korean operations have also sought access from inside crypto companies rather than relying solely on phishing or malware.

In July, Consensys temporarily stopped product releases after discovering that a consultant linked to North Korea had gained access to its systems for roughly one month, according to Drop Site News.

The consultant, who operated under the name Tyler Knapp and used the GitHub handle “imyugioh,” contributed to core MetaMask platform code, including components connecting cryptocurrency users with third-party fiat payment providers.

Advertisement

Consensys general counsel Matt Corva said a third-party service provider had introduced the consultant to the company. The company terminated his access after identifying the threat and said its investigation found no stolen assets or data, malicious code or impact on user security.

Separate research from the Ketman Project identified about 100 suspected North Korean IT workers operating under false identities across 53 crypto and Web3 projects. Investigators also traced suspected groups across 11 code repositories where projects had already merged 62 pull requests before the activity was detected.

North Korea stole more than $2 billion in crypto in 2025

The development of AI-assisted attack infrastructure comes after North Korean hacking groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data previously reported by crypto.news.

Most of the year’s losses came from the February 2025 attack against Bybit, where more than 400,000 Ether and staked Ether worth about $1.5 billion were stolen. The FBI attributed the breach to North Korea and identified the actors responsible under its TraderTraitor designation.

Advertisement

Bybit has since taken the dispute into a U.S. federal court. On Aug. 8, the exchange sued the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group in the U.S. District Court for the District of Columbia.

The exchange also obtained a preliminary injunction covering certain stolen assets held by unidentified defendants. The order prevents the identified assets from being transferred, sold or otherwise disposed of while the civil case proceeds, although it does not constitute a final ruling over ownership or liability.

Blockchain tracing became increasingly difficult after the Bybit theft as the attackers converted assets into Bitcoin and dispersed funds across thousands of wallets. By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked.

Researchers have also warned that AI could reduce the time attackers need to identify weaknesses in software. NEAR Protocol co-founder Illia Polosukhin has said AI is increasing hackers’ ability to locate vulnerabilities faster than conventional security processes can patch them.

Advertisement

The $100 million Coldcard Bitcoin hardware wallet exploit has also been suspected of originating from an obscure vulnerability uncovered with AI. Separately, North Korean operators continue to use phishing, fake remote workers and compromised online identities, while the latest Genians research shows Kimsuky preparing local AI models for malware development, data analysis and attack automation.

Source link

Advertisement
Continue Reading

Crypto World

Holders earn $7,000 in ETH monthly through ASDeFi

Published

on

Ethereum Foundation begins staking 70,000 ETH from treasury

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

ETH investors are increasingly exploring alternatives to holding as market volatility persists, with ASDeFi highlighting cloud mining and automated asset management.

Advertisement

Summary

  • ETH holders are exploring cloud mining and automated asset management as alternatives to relying solely on price gains.
  • Ethereum’s evolving investment case is pushing some long-term holders to consider ways of putting their assets to work.
  • ASDeFi promotes cloud mining as a way for crypto users to access managed computing power without owning mining hardware.

As of August 2026, Ethereum remains a key component of the global cryptocurrency market. With the continued development of blockchain infrastructure, stablecoins, and on-chain financial applications, the investment rationale for ETH is gradually shifting from a focus solely on price fluctuations to the long-term management and practical applications of cryptocurrency assets.

For investors who hold ETH long-term, a rising market can present opportunities for capital appreciation, but when the market enters a period of volatility, relying solely on price movements to generate returns often means a long wait. Against this backdrop, some investors are beginning to explore investment options beyond simply buying and holding ETH, including hashrate services and automated cryptocurrency asset management.

ETH investors are beginning to explore options beyond “holding”

ETH investors typically follow a straightforward investment strategy: buy ETH and wait for the market price to rise. However, the cryptocurrency market has changed. Investors are now focusing on the efficiency of asset utilization, including how to lower the equipment barriers to traditional mining, how to reduce daily operating costs, and how to manage cryptocurrency-related services using automation tools.

Advertisement

ASDeFi cloud mining is a model that has attracted the attention of some market participants amid this trend. Compared to purchasing mining rigs on one’s own, cloud mining centralizes the management of equipment, data centers, power, and operations and maintenance. Users select the appropriate hashrate contracts through the platform, eliminating the need to set up specialized equipment at home.

Why are ETH holders interested in ASDeFi cloud mining?

One key reason is that traditional mining models present a high barrier to entry for individual investors. Participating in mining on one’s own not only requires covering the costs of purchasing mining rigs and electricity, but also involves addressing issues such as the equipment’s operating environment, cooling and maintenance, network and technical management, while also having to contend with the impact of constantly changing mining difficulty.

In contrast, the cloud mining model entrusts the management of complex aspects — such as mining rigs, facilities, electricity, and day-to-day operations — to professional operators, thereby lowering the equipment and operational barriers to entry for individuals wishing to participate in mining. For investors who already hold cryptocurrency assets but do not wish to invest significant capital in purchasing and maintaining mining rigs, this model offers a relatively convenient way to participate.

What is ASDeFi?

Founded in 2020 and headquartered in the United Kingdom, ASDeFi primarily provides AI-powered cloud computing power and cryptocurrency-related services. Through centralized management of computing resources, intelligent scheduling, and automated operations and maintenance, the platform offers users cloud mining services that eliminate the need to purchase mining equipment or build mining farms. Users can manage their accounts and view service status via a web browser or mobile app. Currently, it supports mining for major cryptocurrencies such as ETH, BTC, XRP, SOL, DOGE, BNB, and USDT.

Advertisement

How to Join ASDeFi Cloud Mining?

1. Register for a cloud mining account.

Once registration is complete, the user receives a free $15 bonus that can be used to purchase mining contracts, which yield a daily return of $0.60.

2. Update Account Information

Log in to the account dashboard and add a linked cryptocurrency wallet address to receive earnings.

Advertisement

3. Purchase a Mining Contract

Go to the Contracts page and purchase the $15 Check-in Contract. Users can also choose a mining contract that fits a particular budget and investment plan.

4. Start Mining and Withdraw Earnings

After purchasing the contract, the platform will automatically allocate computing power resources, and the cloud mining contract will begin running. View earnings in real time on the phone, and withdraw mining earnings at any time.

Advertisement

Currently popular mining contracts:

Contract Purchase Amount Term Daily Return Total Return
Daily Check-in Contract $15 1 day $0.60 $15.60
New User Experience Contract $100 2 days $4.00 $108.00
Basic Hashrate Contract No. A2300 $600 5 days $8.10 $640.50
Basic Hashrate Contract No. A2297 $3,000 15 days $45.00 $3,675.00
Stable Hashrate Contract No. S3177 $12,000 25 days $204.00 $17,100.00
Stable Hashrate Contract No. S3167 $20,000 30 days $360.00 $30,800.00

Summary

As the Ethereum ecosystem continues to evolve, the focus of ETH investors has gradually shifted from simply waiting for price increases to more flexible approaches to asset management. Through smart cloud computing power and automated management, ASDeFi offers users who hold ETH long-term an alternative way to participate in the cryptocurrency ecosystem. Some users have reported monthly returns of up to approximately $7,000; however, actual returns are subject to factors such as the amount invested and contract terms, and investors should approach this opportunity with caution.

For more information, visit the official website and download the app.

Advertisement

Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.

Source link

Advertisement
Continue Reading

Crypto World

Australia Forces Cryptolink Bitcoin ATMs Offline for Reporting Gaps

Published

on

Crypto Breaking News

Australia’s financial crime watchdog has ordered Cryptolink’s Bitcoin ATM network offline for three months, citing unresolved compliance concerns under anti-money laundering rules.

According to the Australian Transaction Reports and Analysis Centre (AUSTRAC), the suspension of Cryptolink’s Virtual Asset Service Provider (VASP) registration—effective for a three-month period starting Sunday—means the company’s crypto ATMs will not be permitted to operate during that time. The move comes as Australian regulators have intensified scrutiny of crypto ATM activity, including alleged misuse by criminals.

Key takeaways

  • AUSTRAC suspended Cryptolink’s VASP registration for three months, taking its crypto ATMs out of service during the suspension.
  • The regulator cited failures to meet basic reporting obligations, especially threshold transaction reports, and said the company did not respond to information requests.
  • AUSTRAC said it remains concerned about the ability to manage “high-risk transactions” through crypto ATMs (CATMs).
  • The action follows prior enforcement steps in 2025, including an enforceable undertaking tied to alleged late reporting and risk assessment gaps.

AUSTRAC suspends Cryptolink’s ability to operate

AUSTRAC CEO Brendan Thomas said Monday that Cryptolink’s VASP registration has been suspended for three months, beginning Sunday. In practical terms, the suspension prevents Cryptolink’s Bitcoin ATMs from operating because the company lacks active authorization to provide virtual asset services during the period.

AUSTRAC also pointed to specific compliance shortfalls. The regulator said Cryptolink failed to satisfy core reporting requirements, “particularly threshold transaction reports.” AUSTRAC added that the company did not respond to the regulator’s request for information—an issue that, in AUSTRAC’s framing, compounded the broader monitoring and oversight concerns.

“As part of our continued focus on digital currency as a money laundering risk, AUSTRAC has ongoing concerns about the company’s ability to manage high-risk transactions through its CATMs,” Thomas said.

Advertisement

Why regulators are targeting crypto ATMs

Australia has the highest concentration of crypto ATMs across the Asia-Pacific region, and regulators have been focused on how these machines can be exploited for illicit activity. AUSTRAC’s latest action underscores that the compliance expectations for crypto ATM operators are not merely formalities; they are intended to prevent gaps in reporting and oversight that can enable money laundering.

Late 2024 onward, authorities have increasingly discussed criminal use of crypto ATMs, including cases involving the targeting of vulnerable users. Against that backdrop, the operational suspension of a major ATM operator signals that regulators are willing to use enforcement tools that immediately restrict market access when compliance standards are not met.

Enforcement history: from an undertaking to a paid infringement notice

AUSTRAC’s decision does not arrive in isolation. The suspension follows steps taken in 2025 after issues were identified during Cryptolink’s compliance review process.

In October 2025, Cryptolink entered an enforceable undertaking with AUSTRAC after its Cryptocurrency Taskforce identified alleged breaches. AUSTRAC cited issues including late transaction reporting and shortcomings in Cryptolink’s risk assessments. The undertaking was accompanied by further enforcement: AUSTRAC also issued a $56,340 infringement notice, which Cryptolink paid.

Advertisement

While the October 2025 undertaking and infringement notice reflect earlier remedial and punitive measures, Monday’s suspension indicates AUSTRAC still viewed compliance performance as insufficient—particularly around reporting to AUSTRAC and responsiveness to information requests.

What the suspension means for users and the ATM footprint

Cryptolink operates 96 ATMs in Australia, enabling customers to exchange cash for Bitcoin. The network includes machines in major cities such as Sydney, Melbourne, and Brisbane.

During the three-month suspension window, these ATMs will be prevented from operating because AUSTRAC has removed the company’s ability to run as a VASP under its registration. That restriction affects not just new transactions but also ongoing consumer access to crypto acquisition through ATM channels.

Cointelegraph contacted Cryptolink for comment, but the company’s response was not included in the information provided with AUSTRAC’s announcement.

Advertisement

What to watch next

Crypto ATM operators in Australia—and users who rely on them—will be looking closely at whether Cryptolink can address AUSTRAC’s specific concerns around threshold reporting, high-risk transaction controls, and regulatory engagement. The suspension ends after three months, but the key question is whether the underlying compliance gaps that AUSTRAC described are actually resolved in time to restore authorization.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025