Connect with us
DAPA Banner

Crypto World

iPhone Crypto Wallets Under Attack from State-Grade Malware

Published

on

👉🏻

The era of assumed iPhone invincibility is over for mobile crypto traders. A sophisticated new threat, the ‘Coruna exploit kit’, is actively leveraging 23 disparate iOS vulnerabilities to bypass Apple’s top-notch security and drain crypto wallets.

According to a new Google TAG report, the kit does not just crash apps or serve ads. It silently scans for BIP39 seed phrase theft, extracts QR codes, and siphons private keys from unpatched devices. The funds are gone before the user realizes the browser has been compromised.

That matters. For years, advanced exploit chains were the exclusive domain of nation-state intelligence agencies. Coruna marks a terrifying regime change: state-grade surveillance tools have been repackaged for mass-market retail theft.

Advertisement

This iPhone crypto wallet warning comes as Chainalysis reported in 2025 that the crypto theft market is valued at over $75Bn, with wallet drainers accounting for a large amount of that figure.

(SOURCE: CoinGecko)

How Coruna Exploits 23 iOS Vulnerabilities to Drain Crypto Wallets

The Coruna exploit kit is a highly efficient “1-click” attack that activates when a user visits a compromised site, often posing as a gambling or news platform.

It targets vulnerabilities in WebKit to breach the device, then uses local privilege escalation exploits to escape the browser’s sandbox.

Analyzing iOS versions 13.0 to 17.2.1, Coruna employs multiple entry points to deliver a crypto wallets drainer designed to steal blockchain assets.

Advertisement

It scans the file system for cryptocurrency-related strings, checks the photo library for QR codes, and extracts mnemonic phrases from the Notes app.

This automated exploitation can result in immediate and irreversible theft of assets, and any iPhone user who uses their device for crypto trading and asset storing needs to stay vigilant.

DISCOVER: Next Crypto to Explode in 2026

State-Grade Malware Goes Mass Market

Advertisement

Previously, exploit chains of this complexity were hoarded by entities like NSO Group for targeted surveillance of high-value targets—dissidents, journalists, or diplomats.

Coruna flips the script. It takes vulnerabilities weaponized in campaigns like Operation Triangulation, a suspected state-sponsored attack, and hands them to financially motivated criminal groups.

The barrier to entry for executing a sophisticated MetaMask hack or draining a Trust Wallet has collapsed, and even the most inexperienced tech heads can now carry it out.

This follows a disturbing pattern whereby tools developed for espionage inevitably leak into the broader cybercriminal ecosystem. The attackers behind Coruna are not looking for state secrets. They are looking for liquidity.

Advertisement

This is industrial-scale theft. The iVerify security firm documented the exploit affecting at least 42,000 devices, with total losses not yet announced.

Who Is Being Targeted and Why Mobile Crypto Traders Are Especially Exposed

If you trade on mobile and hold self-custody wallets, you are the target profile. The attack vectors are often embedded in sites that crypto users frequent: unregulated gambling interfaces, dubious token claim pages, and third-party app stores.

Advertisement

The malware explicitly targets data directories associated with major non-custodial wallets. It looks for the encrypted vaults of MetaMask, BitKeep (now Bitget Wallet), and Trust Wallet. If the encryption is weak, or if the user has stored the password in a compromised keychain or note, the wallet is drained.

The risk is compounded by user behavior. Mobile traders frequently interact with DApps and sign transactions on the go, often prioritizing speed over security hygiene.

Coruna exploits this complacency. It doesn’t need to trick you into signing a bad transaction; it simply steals the keys to the castle while you browse.

For now, proceed with caution and consider moving your crypto funds to cold wallet storage, such as a Ledger or Trezor.

Advertisement

EXPLORE: Best Crypto Presales to Buy in 2026

The post iPhone Crypto Wallets Under Attack from State-Grade Malware appeared first on Cryptonews.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

MrBeast faces Senate scrutiny over teen crypto app acquisition

Published

on

MrBeast faces Senate scrutiny over teen crypto app acquisition

United States Senator Elizabeth Warren is asking Jimmy Donaldson, aka “MrBeast,” and Beast Industries CEO Jeff Housenbold to explain why they acquired a teen app that coached minors to pressure their parents into buying crypto.

The 12-page letter demands answers about why Donaldson bought the app, called Step, that published word-for-word scripts coaching teens.

“Crypto and stock investing is not taught in my school, but by using Step, it’ll teach me life skills like how to balance risk and rewards,” the script told children to recite to their guardians.

“Mom, you’ve had Apple stock forever, bitcoin has just as much potential,” it continued.

Advertisement

After MrBeast’s acquisition in February, the owner of Step’s YouTube account set most of its videos to private to prevent them from being publicly viewable.

Step claims to serve about 7 million customers and focuses on minors.

In 2022, the company launched crypto trading for teens through Zero Hash LLC. Step claimed to be “the first platform to allow teens, with the consent of a parent or legal guardian, to responsibly participate first-hand in the rapidly evolving investing landscape, starting with buying and selling bitcoin.”

By April 2022, Step boasted that teens under 18 years old would be able to “access 50+ tokens” and would “be able to buy NFTs.”

It didn’t mince words about whether these purchases would be incidental, de minimis values for educational purposes.

To the contrary, it called the offering an “investing platform” to “ensure the next generation is prepared for their financial futures.”

Advertisement

Read more: Esports influencer fired for pumping and dumping ‘Save The Kids’ crypto

Script for kids still live on YouTube in late 2024

While the company claimed minors could invest only with parental consent, Step built the consent bypass toolkit itself with its scripted coaching tutorials.

A review of YouTube URLs confirms that they now return private notices. Several of the original links still display metadata in Google caches.

Although Step promoted crypto heavily before MrBeast acquired it, it discontinued several of its offerings over the years.

Advertisement

However, the script teens were supposed to use to convince their parents to invest in crypto was still live on YouTube as recently as December 28, 2024.

That’s years after the initial crypto investing initiative by Step and more than half a year after Step’s May 1, 2024 claim that it had shut down all crypto investing accounts.

The company appears to have fully ended its crypto investing post-acquisition.

Bitmine’s ETH company helped MrBeast buy Step 

Beast Industries acquired Step after a $200 million investment from Bitmine Immersion Technologies, Tom Lee’s ether (ETH) treasury company.

Advertisement

Bitmine, embarrassingly, has lost more money investing in ETH than even FTX’s customer deposits

MrBeast’s YouTube channel has more than 470 million subscribers. About 39% of his viewers are between ages 13 and 17, with the vast majority of his viewers younger than 25.

In late 2025, Beast Holdings LLC filed a trademark for MrBeast Financial. It mentioned crypto exchange services and decentralized exchange transactions.

MrBeast has an April 3 deadline to respond to the senator’s questions.

Advertisement

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source link

Advertisement
Continue Reading

Crypto World

What infrastructure do companies use to add stablecoin payments?

Published

on

What infrastructure do companies use to add stablecoin payments?

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Stablecoins gain ground as global payment tools bridging blockchain and traditional finance.

Advertisement

Summary

  • Stablecoins power faster payments, but infrastructure providers bridge fiat, compliance, and blockchain access for users.
  • Fintech apps rely on stablecoin APIs to enable fast, compliant payments without building complex global infrastructure.
  • Stablecoin adoption grows as providers handle fiat conversion, KYC, and payments behind the scenes for apps.

Stablecoins are quickly becoming part of the global payments stack.

Fintech apps use them to settle transactions faster. Remittance platforms use them to move money across borders. Payroll companies use them to pay global contractors.

But while stablecoins settle on blockchain networks, users still interact with traditional financial systems.

Advertisement

Someone still needs to convert fiat into stablecoins. Someone needs to handle compliance and identity verification. Someone needs to connect cards, bank transfers, and local payment methods to blockchain networks.

This is where stablecoin payment infrastructure comes in.

Companies like Transak provide the regulated infrastructure that connects traditional payment methods with stablecoin networks, allowing fintech apps, wallets, and marketplaces to integrate stablecoin payments without building the underlying financial rails themselves.

What is stablecoin payment infrastructure?

Stablecoin payment infrastructure refers to the systems that allow applications to convert traditional currencies such as USD, EUR, or GBP into stablecoins and move those funds across blockchain networks.

Advertisement

These systems typically provide several core capabilities.

  • Fiat to stablecoin conversion
  • Payment method connectivity, such as cards and bank transfers
  • Identity verification and compliance infrastructure
  • Fraud monitoring and transaction screening
  • Global regulatory coverage
  • Stablecoin liquidity and settlement

Without this infrastructure, stablecoins would be difficult for most businesses or consumers to access.

Providers such as Transak operate this infrastructure layer, enabling fintech companies to integrate stablecoin payments through a single API while relying on existing regulatory and payment systems.

What infrastructure do companies use to add stablecoin payments?

When a fintech app enables stablecoin payments, several components work together behind the scenes.

Most stablecoin payment flows rely on three main layers.

Advertisement
  1. Blockchain networks like Ethereum, Polygon, or Solana serve as the settlement layer for recording transactions.
  2. Stablecoin issuers like Circle provide fiat-backed digital tokens that maintain a stable value pegged to traditional currencies.
  3. Infrastructure providers like Transak bridge the gap by connecting traditional banking and compliance systems with blockchain networks.

Platforms such as Transak enable users to convert fiat currencies into stablecoins using payment methods like cards, bank transfers, or local payment systems. They also enable the reverse process, allowing users to convert stablecoins back into fiat and withdraw funds to bank accounts.

By integrating providers like Transak, fintech companies can enable stablecoin payments without building their own compliance systems, banking relationships, or payment acquiring infrastructure.

How fiat to stablecoin conversion works

For most users, stablecoin payments begin with converting traditional money into digital tokens.

This process is often referred to as a stablecoin on-ramp.

A typical fiat-to-stablecoin conversion flow looks like this.

Advertisement
  1. A user selects a payment method such as a card or bank transfer.
  2. The payment infrastructure processes the transaction and verifies the user’s identity.
  3. Fiat currency is converted into stablecoins through liquidity providers.
  4. The stablecoins are delivered to the user’s wallet or application.

On-ramp providers like Transak handle the complex parts of this process, including compliance checks, payment processing, fraud monitoring, and regulatory requirements.

This allows applications to provide stablecoin access without operating their own financial infrastructure.

What is a stablecoin on-ramp?

A stablecoin on-ramp allows users to convert traditional currencies into stablecoins using familiar payment methods.

For example, a user might purchase stablecoins using a credit card, a bank transfer, or a regional payment system such as SEPA or PIX.

On-ramp providers like Transak connect these payment systems with blockchain networks, allowing users to access stablecoins directly from within wallets or fintech apps.

Advertisement

This infrastructure is essential for making stablecoins accessible to mainstream users.

Examples of stablecoin payment infrastructure providers

Several companies provide infrastructure that enables applications to integrate stablecoin payments.

These providers focus on connecting traditional financial systems with blockchain networks while handling compliance and regulatory requirements.

Examples of stablecoin payment infrastructure providers include:

Advertisement
  • Transak
  • MoonPay/Iron
  • Coinbase infrastructure tools
  • Stripe’s crypto-related services

Among these providers, Transak focuses specifically on enabling global fiat to stablecoin connectivity for fintech platforms, wallets, remittance services, and digital marketplaces.

Through its infrastructure, companies can allow users to fund transactions using local payment methods and move value through stablecoin networks.

How fintech apps integrate stablecoin payments

Most fintech applications integrate stablecoin infrastructure through APIs provided by payment infrastructure platforms.

For example, when a user opens a wallet or financial application and chooses to buy stablecoins, the application typically connects to a provider such as Transak behind the scenes.

The provider manages payment processing, identity verification, regulatory compliance, and conversion between fiat currencies and stablecoins.

Advertisement

This approach allows fintech companies to add stablecoin functionality without needing to build global payment infrastructure themselves.

As a result, stablecoin payments can be integrated relatively quickly while remaining compliant with financial regulations.

Why infrastructure matters for stablecoin payments

While blockchain networks provide the settlement layer, most users still interact with traditional financial systems when entering or exiting stablecoin networks.

Without infrastructure connecting these systems, stablecoins would remain difficult to use in everyday financial products.

Advertisement

Payment infrastructure providers such as Transak bridge this gap.

They connect cards, bank transfers, and regional payment systems with blockchain networks while managing compliance, fraud monitoring, and regulatory licensing.

This infrastructure allows fintech companies to focus on building products while relying on established payment rails.

The role of infrastructure in the future of stablecoin payments

Stablecoins are increasingly becoming part of the backend infrastructure powering modern financial applications.

Advertisement
  • Remittance platforms use them to move money globally.
  • Payroll companies use them to pay international teams.
  • Fintech apps use them to settle transactions more efficiently.

But for these systems to work at scale, reliable infrastructure is required to connect traditional financial systems with blockchain networks.

Companies like Transak provide this infrastructure layer, enabling applications around the world to integrate stablecoin payments while relying on compliant, regulated financial rails.

As stablecoin adoption continues to grow, the role of infrastructure providers such as Transak will become increasingly important in connecting traditional money with digital settlement networks.

FAQs about stablecoin payment infrastructure

What companies provide stablecoin payment infrastructure?

Examples of stablecoin payment infrastructure providers include Transak, MoonPay, Coinbase infrastructure tools, and Stripe’s crypto-related services.

Among these providers, Transak focuses on enabling fintech platforms, wallets, remittance services, and digital marketplaces to connect traditional payment methods with stablecoin networks through a single API.

Advertisement

How do fintech apps integrate stablecoin payments?

Most fintech applications integrate stablecoin payments by connecting to payment infrastructure providers through APIs.

Providers such as Transak handle the complex parts of the process, including payment processing, identity verification, regulatory compliance, and conversion between fiat currencies and stablecoins.

What is a fiat-to-stablecoin on-ramp?

A fiat-to-stablecoin on-ramp allows users to convert traditional currencies into stablecoins using payment methods like cards, bank transfers, or local payment systems.

On-ramp infrastructure providers such as Transak connect traditional financial systems with blockchain networks, allowing users to access stablecoins directly within wallets, fintech apps, or marketplaces.

Advertisement

This infrastructure is essential for making stablecoins accessible to mainstream users.

Why do companies use infrastructure providers instead of building stablecoin systems themselves?

Building stablecoin payment infrastructure internally can be complex, cost millions, and time-consuming (over 18 months in some cases).

Companies must obtain regulatory licenses, establish banking relationships, implement compliance and identity verification systems, and support multiple payment methods across different regions.

Infrastructure providers like Transak simplify this process by offering regulated payment rails that fintech companies can integrate through APIs.

Advertisement

This allows product teams to launch stablecoin features without managing global financial infrastructure themselves.

How are stablecoins used in cross-border payments?

Stablecoins allow value to move across blockchain networks quickly and globally. This makes them useful for cross-border payments such as remittances, global payroll, and international marketplace payouts.

However, users still need reliable ways to convert between fiat currencies and stablecoins. Infrastructure platforms such as Transak enable these conversions by connecting traditional payment methods with stablecoin networks.

Can stablecoins be used for payroll or contractor payments?

Yes. Many payroll platforms and global businesses are exploring stablecoins as a way to pay international contractors more efficiently.

Advertisement

In this model, companies convert fiat into stablecoins, transfer the funds globally, and allow recipients to convert them back into local currency.

What role does Transak play in the stablecoin ecosystem?

Transak provides a regulated payment infrastructure that connects traditional financial systems with stablecoin networks.

Through its APIs, wallets, fintech companies, remittance platforms, payroll providers, and marketplaces can enable users to convert fiat currencies into stablecoins and withdraw stablecoins back into traditional currencies.

Transak handles compliance, identity verification, payment processing, fraud monitoring, and global payment coverage, allowing applications to integrate stablecoin functionality without building their own financial infrastructure.

Advertisement

Is stablecoin infrastructure different from crypto on-ramps?

Crypto on-ramps were originally designed to help users purchase cryptocurrencies using traditional payment methods.

As stablecoins have become more widely used for financial applications, on-ramp infrastructure has expanded to support payment flows such as remittances, payroll, and treasury operations.

Platforms like Transak operate both as crypto on-ramp providers and as broader stablecoin payment infrastructure, enabling fintech companies to integrate digital asset payments within their applications.

Advertisement

Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.

Source link

Advertisement
Continue Reading

Crypto World

Circle Froze 16 ‘Unrelated’ Stablecoin Wallets, Says ZachXBT

Published

on

Decentralization, Circle, Stablecoin

Stablecoin issuer Circle, the company behind the USDC (USDC) dollar-pegged token, wrongfully froze 16 wallets in connection with an ongoing civil legal case in the United States, according to onchain investigator and security researcher ZachXBT.

The wallets in question belonged to crypto exchanges, online casinos and foreign currency exchange businesses, which “do not appear related at all,” ZachXBT said

“An analyst with basic tools could have identified, within minutes, that these were operational business wallets from the thousands of transactions they process,” he said

Decentralization, Circle, Stablecoin
Source: ZachXBT

In a separate social media post, the onchain investigator wrote that the case is “sealed,” and Circle had “zero basis” to freeze the fiat-pegged tokens. He added:

“In my 5-plus years of investigations, it could potentially be the single most incompetent freeze I have seen. This is what happens when you outsource your freezing decisions to literally any random federal judge instead of having a process.”

Cointelegraph sought comment from Circle about the claims but did not obtain a response by the time of publication. 

Advertisement
Decentralization, Circle, Stablecoin
A simplified illustration of the USDC wallets frozen by Circle. Source: ZachXBT

Centralized stablecoins can be frozen by the issuer, which goes against the core value proposition of cryptocurrencies as permissionless, censorship-resistant assets, critics of the technology say.

Related: ZachXBT says fake X accounts used viral war content to drive crypto scams

Crypto executives warn that regulated stablecoins are gateway to CBDCs

“This is your 10th reminder that centrally issued stablecoins are not actually yours; they can be frozen, unlike cash,” Mert Mumtaz, founder of remote procedure call (RPC) node provider Helius, said in response to the USDC wallet freezes.

Jean Rausis, co-founder of the Smardex decentralized trading platform, said that provisions in the GENIUS stablecoin regulatory framework laid the groundwork for a privately managed central bank digital currency (CBDC) to emerge.

Centralized stablecoins effectively give the issuer the same financial surveillance and asset freezing capabilities that a standard CBDC would provide, he said.

Advertisement

Former US lawmaker Marjorie Taylor Greene echoed Rausis’s warning in May 2025, arguing that regulated stablecoins under the GENIUS bill are a “CBDC Trojan Horse.” 

Magazine: Coinbase hack shows the law probably won’t protect you: Here’s why