Connect with us

Crypto World

Trezor user says life savings stolen via Google phishing ad

Published

on

Trezor user says life savings stolen via Google phishing ad

A crypto user claims he lost his life savings after a sponsored Google result impersonating Trezor directed him to a phishing website.

Summary

  • David said a sponsored Google result led him to a fake Trezor website.
  • The phishing page was hosted on Google Sites and allegedly requested wallet recovery information.
  • Trezor reported an increase in phishing websites appearing in sponsored search results.
  • Similar Google ad campaigns were previously linked to more than $1 million in crypto losses.

Trezor user reports losing his life savings

A crypto user identified as David, who posts on X under the account @ReallyBadDay99, claimed on Aug. 7 that he lost his life savings after searching Google for “Trezor wallet.”

“Hey @Trezor, just lost my life savings. Top sponsored Google result for ‘Trezor wallet’ is a phishing site!” David wrote.

The sponsored result allegedly directed him to a page hosted on Google Sites that impersonated the hardware-wallet provider. David said the phishing operation was collecting funds through an address he shared with on-chain investigators ZachXBT and CertiK.

Advertisement

He also claimed the address was “vacuuming up millions.” However, the value of David’s loss, the total amount allegedly stolen from other users, and the address’s connection to the phishing website had not been independently verified at the time of publication.

A wallet recovery phrase gives its holder control over the associated cryptocurrency. If a victim enters the phrase on a fraudulent website, an attacker can restore the wallet on another device and transfer its assets without access to the original hardware wallet.

Blockchain transactions are generally irreversible, leaving victims with few options after funds have been transferred.

Trezor warns of sponsored phishing results

Trezor issued a broader warning hours after David published his claim, saying it was seeing an increase in phishing websites impersonating the company.

Advertisement

The hardware-wallet provider said some of the fraudulent websites were appearing in sponsored search results and could look highly convincing. It warned that entering a wallet backup on one of those pages could result in stolen funds.

“Never enter your wallet backup on a website or share it with anyone,” Trezor said in its Aug. 7 X post.

Trezor also told customers not to assume that a sponsored search result is legitimate. Users should verify that they are visiting the company’s official website before downloading Trezor Suite or entering information connected to their wallets.

The company’s post did not confirm David’s loss, identify the operators of the reported phishing page or estimate how much the campaign may have stolen. Trezor also did not say whether the specific Google Sites page identified in David’s post had been removed.

Advertisement

Google ads remain a recurring crypto attack vector

Sponsored search results have become a repeated delivery method for crypto phishing campaigns. Attackers purchase advertisements tied to wallet, exchange, and decentralized finance search terms, allowing fraudulent pages to appear above legitimate websites.

As previously reported by crypto.news, fake Uniswap advertisements promoted through Google search reportedly helped scammers steal at least $400,000 from several users in May.

Security Alliance data cited in that report connected malicious Google advertisements to approximately $1.27 million in losses between March 13 and March 30. The organization said it had blocked more than 356 malicious advertising links over the previous year.

The reported Trezor page being hosted on Google Sites also reflects a tactic in which attackers use trusted online services to make fraudulent pages appear safer. Google acknowledged in a June fraud advisory that scammers were abusing reputable cloud platforms to host phishing content and bypass security filters.

Advertisement

The continued use of Google’s advertising and hosting infrastructure makes the threat relevant to U.S. cryptocurrency holders who depend on search results to access wallet services. No U.S. regulator or law-enforcement agency had publicly announced an investigation into David’s reported loss at the time of publication.

Trezor users have faced similar phishing attempts

Crypto.news reported in February that scammers mailed fake Trezor and Ledger letters containing QR codes linked to phishing websites.

Those pages requested 12-, 20- or 24-word recovery phrases under the pretext of verifying wallet ownership. Although the delivery method differed, the campaign also relied on impersonating a trusted hardware-wallet provider and persuading users to disclose their backups.

Trezor advises customers to bookmark its official website and obtain Trezor Suite only through verified company channels. Anyone who entered a recovery phrase on a suspicious page should treat the wallet as compromised and move any remaining assets to a new wallet created with a fresh backup.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Bitcoin price stalls below $65K despite ETF inflows

Published

on

U.S. spot Bitcoin ETFs, source: Farside

Bitcoin held near $64,206 on Aug. 7, according to crypto.news market data, slipping 0.5% over 24 hours and 0.6% over seven days. 

Summary

  • Bitcoin trades near $64K, down 0.5% daily, while four straight ETF inflow sessions support demand.
  • U.S. spot Bitcoin ETFs attracted $137.6 million Thursday, lifting four-day net inflows to $763.6 million.
  • Senate leaders delayed the CLARITY Act vote until September, removing an expected August regulatory catalyst.
  • Bitcoin derivatives open interest is rebuilding, but remains below levels seen near October’s price peak.
  • July employment data arrives Friday before inflation Wednesday, keeping Federal Reserve expectations central for markets.

The asset traded between $64,114 and $64,916, showing that the market remains compressed after failing to reclaim resistance above $66,000.

The price action comes as U.S. spot Bitcoin ETFs extend a four-session inflow streak, while the Senate delays the CLARITY Act vote until September and traders wait for fresh U.S. employment data. Those factors leave Bitcoin supported by institutional demand but without a breakout from its range.

Advertisement

Bitcoin ETF inflows continue supporting the $64K area

Farside’s recorded $137.6 million in net inflows into U.S. spot Bitcoin ETFs on Aug. 6. That followed $170.1 million on Aug. 3, $211.5 million on Aug. 4 and $244.4 million on Aug. 5, bringing the four-day total to about $763.6 million.

BlackRock’s IBIT led Thursday’s flows with $128.3 million, while Fidelity’s FBTC added $11.2 million. VanEck’s HODL recorded $32.8 million in outflows. The positive aggregate flow has provided a steady source of spot demand even though Bitcoin has not cleared nearby resistance.

U.S. spot Bitcoin ETFs, source: Farside
U.S. spot Bitcoin ETFs, source: Farside

As previously reported, renewed inflows have helped stabilize Bitcoin during weak trading periods. However, ETF buying does not guarantee immediate price appreciation when other holders sell into the same demand.

The $62,000 to $65,000 region has contained much of Bitcoin’s recent trading. Analyst Daan Crypto Trades said a move above $67,000 would make the structure more constructive, with $69,000 to $72,000 containing several higher-timeframe resistance levels. Until that breakout occurs, he described BTC as remaining in sideways trade.

Advertisement

CLARITY Act delay removes an August policy catalyst

The Senate will leave Washington without voting on the CLARITY Act before its August work period. Senate Majority Leader John Thune said the legislation would be queued when lawmakers return. The Senate lists Aug. 10 through Sept. 11 as a state work period.

The legislation would establish a federal digital asset market structure and clarify regulatory responsibilities between the SEC and CFTC. Earlier CLARITY Act showed that Republican leaders need Democratic support to overcome a filibuster. The often-cited 60-vote figure applies to cloture, rather than the simple-majority threshold normally required for final passage.

Advertisement

For BTC, the delay removes an expected August policy event but does not change the asset’s legal status. Market reaction also cannot be attributed solely to the bill because ETF flows, interest-rate expectations, positioning and broader risk appetite are moving simultaneously.

Derivatives leverage is rebuilding from lower levels

CryptoQuant analyst Amr Taha reported that Bitcoin open interest is recovering across Binance, Bybit and Gate.io. Binance open interest reached about $3.9 billion on Aug. 7, while Bybit stood near $2.14 billion and Gate.io around $2.09 billion. Deribit diverged, falling to roughly $725 million.

Combined open interest across those four exchanges was about $8.86 billion, according to Taha, nearly 54% below the $19.21 billion recorded around BTC’s October 2025 peak. That suggests leverage is returning gradually rather than approaching the crowded conditions seen near the previous high.

Ali Charts offered a bullish long-term reading, pointing to a TD Sequential buy signal on BTC’s monthly chart, proximity to the 50-month simple moving average and a Chande Momentum Oscillator reading near negative 71. Those signals are technical interpretations, not confirmation that a new bull market has begun.

Advertisement

On the daily chart, BTC remains in a broader downtrend but has stabilized above the $60,000 to $62,000 support zone. Accumulation and Distribution has recovered since late June, while Bull Bear Power is slightly positive. A sustained move through $66,000 to $70,000 would provide stronger evidence of a trend change.

Bitcoin price chart, source: crypto.new
Bitcoin price chart, source: crypto.new

U.S. jobs and inflation data become the next test

The Fed’s kept its target rate at 3.50% to 3.75% on July 29 in a 9-3 vote. Beth Hammack, Neel Kashkari and Lorie Logan dissented because they preferred a 25-basis-point increase.

The next immediate catalyst is the July employment report, for Aug. 7 at 8:30 a.m. ET. July CPI follows on Aug. 12. Stronger employment or persistent inflation could reinforce expectations for tighter monetary policy, while softer data could reduce pressure on risk assets.

Advertisement

The crypto enters the data window with conflicting signals. ETF demand remains positive and leverage is rebuilding from depressed levels, while price is still below the resistance needed to confirm a stronger recovery. Holding $62,000 to $64,000 keeps current stabilization intact, but traders are likely to look toward $67,000 and then $69,000 to $72,000 for clearer evidence that buyers have regained control.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

US Court Upholds Bybit’s Request to Trace Funds From $1.5B Hack

Published

on

Crypto Breaking News

Newly unsealed court records show a US judge granted Bybit expedited discovery in the exchange’s ongoing legal push to identify assets tied to a $1.5 billion North Korea-linked attack. The ruling is aimed at helping Bybit move from broad allegations toward practical, court-backed tracing—an approach that can matter when large portions of stolen crypto have already been obfuscated.

According to the filings, Bybit brought the case under seal on June 18, naming North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unnamed defendants. The court granted the expedited discovery request the following day, giving Bybit a faster route to request information that could pinpoint alleged intermediaries and determine what—if any—stolen funds remain recoverable through identifiable on-chain or account-linked activity.

Key takeaways

  • Unsealed records confirm a federal judge granted Bybit expedited discovery tied to the June 18 lawsuit over the $1.5 billion 2025 North Korea-linked hack.
  • Bybit claims 90.2% of stolen assets became untraceable after moves through mixers, cross-chain bridges, and OTC trading channels.
  • The company reports 9.8% of the funds were traceable to identifiable wallets, including 5.3% (about $75.5 million) that were frozen or recovered.
  • Bybit obtained a temporary restraining order that the court renewed and partially supported with a preliminary injunction decision later in July.
  • The complaint seeks relief that includes compensatory, punitive and treble damages under the US RICO statute.

Expedited discovery: turning allegations into targeted asset recovery

The court documents describe Bybit’s strategy as an attempt to identify alleged actors and intermediaries that may have handled stolen funds after the hack. Expedited discovery typically shortens the timeline for obtaining information from counterparties or other relevant parties—particularly important in high-stakes crypto cases where defendants may move assets quickly or hide trail details behind complex transaction structures.

In the complaint, Bybit alleges that some traceable assets ended up on or through platforms that operate in the United States or maintain US-based infrastructure. Bybit sought account-holder identities, balances and transaction histories, arguing that certain platforms indicated they would cooperate once a court order was issued.

From an investor and market-structure standpoint, this matters because court-ordered discovery can bridge a gap that often exists in crypto investigations: even when chain analytics suggest where funds may have gone, legal access to counterparties’ records is often what enables meaningful recovery efforts.

Advertisement

How much of the stolen crypto was still traceable?

Bybit’s filing includes a key metric about how the attackers allegedly laundered the stolen assets. As of the June 18 submission, the exchange said 90.2% of the funds had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% it said could be tied to identifiable wallets.

Within that smaller traceable portion, Bybit reported that 5.3% of the total theft—about $75.5 million—had been frozen or recovered. The rest of the traceable amount was described as still linked to identifiable wallets, implying it may be recoverable if the legal process can connect those wallets to accountable parties.

Bybit’s numbers also suggest a significant shift compared with more than a year earlier. The exchange previously reported that 68.57% of the stolen funds remained traceable, a claim attributed to Bybit CEO Ben Zhou at the time. In this newer filing, the traceability figure has dropped materially, underscoring how quickly stolen crypto can become harder to recover as it moves through layered obfuscation techniques.

Restraining orders and injunction steps in July

Alongside expedited discovery, Bybit secured legal measures designed to prevent alleged defendants from moving certain traceable assets while the case progresses. The company obtained a temporary restraining order on June 19 against the unnamed defendants, aimed at halting transfers of specific traceable funds.

Advertisement

That restraining order was renewed on July 16. The court also partially granted Bybit’s request for a preliminary injunction on July 30. While the records indicate that some exhibits and related materials remain sealed, the sequence reflects a court willingness to support Bybit’s attempt to preserve at least part of the identifiable asset set while discovery and claims move forward.

Background of the Feb. 21, 2025 hack and FBI attribution

The underlying incident dates to Feb. 21, 2025. Bybit said the attackers compromised the Safe Wallet infrastructure after gaining access through compromised credentials associated with a Safe developer. Forensic investigations cited in earlier coverage described malicious code being injected into Safe’s cloud infrastructure.

The FBI attributed the theft to North Korea on Feb. 26, 2025, according to its public notice on the incident. That attribution has been central to how regulatory and law enforcement narratives have framed the event, and it helps explain why a civil lawsuit targeting North Korea-linked entities would be pursued alongside asset-tracing and recovery measures.

In the complaint, Bybit seeks recovery related to approximately $1.5 billion, including compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. In practical terms, the damages claim indicates Bybit is not only seeking to preserve and identify assets but also to establish broader liability if the court finds actionable wrongdoing and causation.

Advertisement

What to watch next

The immediate question is whether expedited discovery turns the “traceable” wallet subset into actionable, court-backed targets—especially given Bybit’s claim that most of the stolen crypto has already become untraceable. Readers should watch how the case develops as sealed exhibits are gradually revealed and as the court’s preliminary injunction posture evolves, because those steps can determine how much of the remaining identifiable funds can realistically be recovered.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Coldcard temporarily halts customer data deletion over July exploit

Published

on

Coldcard MK5 ships with 5 major wallet upgrades

Coldcard has temporarily suspended its automatic customer data deletion process because of legal obligations tied to the security incident disclosed on July 30, preserving records that would otherwise have been erased after 120 days.

Summary

  • Coldcard has suspended its automatic customer data deletion policy because of legal obligations tied to its July security incident.
  • Customers can still request their records be handled under the company’s original data retention policy by contacting support.
  • The policy change follows a wallet flaw that Galaxy Research linked to 1,596 confirmed stolen Bitcoin across three attack waves.
  • Coldcard said retained customer records will remain restricted to authorized personnel and used only to meet legal requirements.

Coldcard announced the policy change in a post on X, saying it must retain customer records that could be relevant to ongoing and anticipated legal proceedings arising from the wallet security incident.

The company said the temporary measure overrides its published data-retention schedule but added that customers who do not want their information preserved under the legal protocol can still request the application of its existing retention policy by contacting customer support.

Coldcard has paused automatic data deletion

Explaining the change, the company said its standard practice has been to “automatically blank customer records after 120 days,” keeping only customers’ email addresses and country of residence. It also noted that buyers have long been able to request accelerated deletion after their orders were delivered.

Advertisement

The company said the July 30 security incident has changed those procedures because it is now legally required to preserve records that may become relevant during litigation.

As a result, customer records that were scheduled for deletion under the normal 120-day policy will now be retained until further notice.

Coldcard said customers who prefer not to have their records included in that legal preservation process can contact its support team to request that their information be handled under the original retention policy instead.

Advertisement

Addressing privacy concerns, the company wrote that it understood the decision “is a departure from our published practices” and acknowledged that customers value the privacy protections it previously committed to maintaining.

It added that retained customer information will remain securely stored, access will be limited to authorized personnel, and the data “will not be used for any purpose other than compliance with legal obligations.” 

According to the company, the previous automated deletion system will return once legal requirements no longer require record preservation.

Security incident has already triggered investigations

The revised retention policy follows one of the largest known hardware wallet security incidents affecting Bitcoin users.

Advertisement

As previously reported by Galaxy Research, attackers have stolen 1,596 BTC from about 7,300 wallet addresses across three confirmed attack waves linked to the Coldcard vulnerability. The research firm said a fourth suspected wave could increase total losses to about 2,055 BTC, although it has not yet received enough victim confirmations to classify those additional thefts as confirmed.

Galaxy has distinguished its confirmed figures from blockchain-only observations. While earlier on-chain analysis identified approximately 1,815.75 BTC moving across four observed waves, the firm’s latest estimate is based on confirmed reports from affected wallet owners.

Separately, Galaxy’s head of firmwide research, Alex Thorn, said blockchain activity indicates the suspected fourth wave was “substantially comprised of” a single attacker. Even so, the firm has continued treating the additional addresses as unconfirmed until more victims come forward.

Investigators have also shared confirmed attacker and victim addresses with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups so the stolen funds can be monitored if they move through regulated platforms.

Advertisement

Firmware flaw reduced wallet seed randomness

According to Coinkite’s earlier technical disclosure, the vulnerability originated in March 2021 during the integration of a new cryptographic library into Coldcard firmware.

Instead of generating wallet seeds through the intended hardware-backed random-number generator, affected firmware accidentally relied on MicroPython’s deterministic pseudo-random generator during wallet creation.

Block’s Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion, stating that vulnerable versions called the deterministic MicroPython fallback instead of the STM32 hardware random-number generator while generating seed phrases.

Coinkite estimated that affected Mk2 and Mk3 devices provided roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices generated about 72 bits rather than the intended 128 bits.

Advertisement

Because of that weakness, attackers were able to reproduce possible wallet seeds offline, derive Bitcoin addresses from those seeds and compare them with publicly visible blockchain data. The attack did not require physical possession of affected devices, users’ PINs or any weakness in the Bitcoin protocol itself.

Most stolen Bitcoin remains untouched

Although the investigation has expanded, most of the stolen cryptocurrency has not yet moved.

Galaxy previously said about 90% of the stolen Bitcoin remained untouched, giving investigators additional time to monitor attacker-controlled addresses. Later on-chain analysis found that the largest identified attacker still holds 1,159 BTC spread across seven addresses without moving the funds.

Separate blockchain monitoring has identified activity from another attacker, however. According to analysts tracking the transactions, 64 BTC entered a transaction flow associated with a cryptocurrency mixer. Roughly 10 BTC was initially mixed, while approximately 54 BTC returned as change before being split into outputs of about 7 BTC each.

Advertisement

Researchers said the activity appears unrelated to the seven-address cluster holding the 1,159 BTC, indicating that multiple attackers likely exploited the same wallet weakness.

At the same time, Coinkite has continued urging affected users to replace vulnerable wallet seeds even after installing updated firmware. The company has already released patched firmware for all affected Coldcard models and destroyed remaining inventory containing vulnerable versions.

According to Coinkite, firmware updates protect only wallets created after the fix. Users whose seed phrases were generated with vulnerable firmware are advised to create entirely new seeds, verify a receiving address, send a small test transaction and move the remaining balance only after confirming the transfer works. Existing wallets created with at least 50 fair private dice rolls are not affected by this specific random-number-generation flaw.

Advertisement

Source link

Continue Reading

Crypto World

Uniswap Adds Permissioned Pools to Bring Regulated Assets to v4

Published

on

Uniswap Adds Permissioned Pools to Bring Regulated Assets to v4


Uniswap introduced Permissioned Pools, a new hook standard for its v4 protocol that lets regulated assets trade through automated market makers while enforcing compliance rules directly onchain, the company said in a blog post published Thursday. Rather than relying on a frontend gate or an… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Ondo's Oasis Pro Markets Cleared to Offer Tokenized Stocks in US

Published

on

Ondo's Oasis Pro Markets Cleared to Offer Tokenized Stocks in US


Ondo Finance said its broker-dealer subsidiary, Oasis Pro Markets, secured regulatory authorization to offer tokenized equities and funds to U.S. investors under SEC and FINRA oversight, according to a post from the company's official X account on Thursday. Ondo described Oasis Pro Markets as an… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Bitcoin Telegram accounts targeted by North Korean hackers

Published

on

Telegram accounts under attack, source: X

Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings. 

Summary

  • BlueNoroff is hijacking Telegram accounts and using fake Zoom or Teams meetings against crypto professionals.
  • JUMPSEC found the phishing kit profiles cryptocurrency wallets before operators selectively deliver malware to victims.
  • Security Alliance attributed 164 blocked domains to UNC1069 between February and early April 2026 alone.
  • Mandiant observed compromised Telegram accounts, fake Zoom calls, ClickFix commands and malware targeting crypto organizations.
  • FBI guidance recommends independent identity verification and keeping wallet secrets off internet-connected devices whenever possible.

Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified.

JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. JUMPSEC said identified campaign infrastructure remained active as of July 22.

Advertisement
Telegram accounts under attack, source: X
Telegram accounts under attack, source: X

BlueNoroff turns trusted Telegram contacts into lures

The attack begins with trust rather than a blockchain vulnerability. JUMPSEC found operators using compromised Telegram accounts belonging to real industry contacts to invite targets to fake video meetings. Because messages arrive from genuine accounts and can reference existing relationships, sender recognition alone provides limited protection.

Google Mandiant independently documented a similar UNC1069 intrusion in February. A victim received messages from a compromised crypto executive’s Telegram account, scheduled a meeting and was redirected to a spoofed Zoom domain. The victim reported seeing what appeared to be an AI-generated video of another crypto executive during the staged call.

Attribution needs precision. Mandiant tracks the actor as UNC1069 and says it overlaps with BlueNoroff. U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau. Security Alliance likewise attributes the fake-meeting campaign to UNC1069, or BlueNoroff.

Fake meetings push ClickFix commands and malware

JUMPSEC’s reconstructed kit shows a staged meeting interface asking for webcam access before an operator joins with prerecorded video. The victim then sees a supposed audio problem and a fake software update. The displayed troubleshooting text is deceptive: copying it places an attacker-controlled ClickFix command onto the clipboard.

Advertisement

On Windows, JUMPSEC observed PowerShell and VBScript components capable of disabling defenses, conducting reconnaissance and supporting follow-on access. On macOS, researchers found shell scripts and Mach-O payloads designed to steal credentials and other sensitive data. The kit also scans for browser wallet providers before malware delivery, helping operators identify valuable targets.

That means the claim that merely opening a meeting link automatically drains a wallet is too broad. In the documented chains, compromise requires another action, such as running a copied command or malicious update. However, once malware executes, Mandiant found tooling capable of stealing browser data, Keychain credentials and Telegram user data.

As previously reported, Martin Kuchař said his Telegram account was compromised and used in a similar attack. Earlier victim coverage also documented crypto executives being approached through trusted contacts before fake meeting prompts attempted to install malware.

Security researchers say the campaign remains broad

Security Alliance reported that it attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7. Its advisory described multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent Zoom or Teams links were delivered. JUMPSEC later expanded the infrastructure picture and said high- and medium-confidence infrastructure remained active in late July.

Advertisement

The FBI has warned separately that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance specifically flags requests to execute code, install unfamiliar applications, run scripts to fix video calls or move conversations between communication platforms.

The FBI recommends verifying identities through an independent channel and keeping wallet credentials, seed phrases and private keys off internet-connected devices. Two-factor authentication remains useful, but infected devices can expose session data, so compromised sessions should also be revoked from a clean device.

What Bitcoin and crypto users should watch next

The most important correction to the Aug. 7 warning is that researchers have not established one universal method for the initial Telegram takeover. Claims that expired or temporary phone numbers are the main cause remain unverified in the material reviewed. Researchers confirm compromised accounts, but the takeover mechanism can vary.

In separate Telegram platform coverage, Apple briefly removed the messaging app from its App Store over a CSAM policy review before restoring it after Telegram removed the flagged content and banned the responsible user.

Advertisement

Users should treat unexpected meeting requests, domain changes, audio-fix prompts and requests to paste commands as high-risk signals. If suspicious code has already run, the FBI advises disconnecting the affected device from the internet while leaving it powered on for potential forensic recovery, then contacting incident-response specialists and law enforcement.

The campaign is therefore best described as an ongoing, North Korea-linked social-engineering operation targeting the human layer around crypto custody. Its effectiveness comes from exploiting trusted identities and familiar workplace tools, not from breaking Bitcoin itself.

Source link

Advertisement
Continue Reading

Crypto World

Bybit Wins Court Support to Trace $1.5B North Korea Hack Funds

Published

on

Bybit Wins Court Support to Trace $1.5B North Korea Hack Funds

United States court records unsealed on Thursday show that a federal judge backed crypto exchange Bybit’s effort to trace assets stolen in the $1.5 billion North Korea-linked hack by granting the company expedited discovery. 

According to the records,  Bybit filed the lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court granted Bybit’s request for expedited discovery on June 19.

The discovery authority gives Bybit a practical route to identify alleged intermediaries and pursue a small portion of stolen assets that remains traceable, rather than relying solely on a judgment against North Korea. 

In its complaint, Bybit alleged that some traceable assets reached exchanges operating or maintaining infrastructure in the US. The company sought account-holder identities, balances and transaction histories, saying certain platforms had indicated they would cooperate after receiving a court order.

Advertisement

Bybit says 90% of stolen funds became untraceable

Bybit also obtained a temporary restraining order on June 19 preventing the unidentified defendants from transferring certain traceable assets. The court renewed the order on July 16 and partially granted Bybit’s request for a preliminary injunction on July 30. Some exhibits and other records remain sealed.

As of the June 18 filing, Bybit said 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% had been traced to identifiable wallets, including 5.3% of the total, about $75.5 million, that had been frozen or recovered.

The figures mark a sharp drop from more than a year ago, when Bybit CEO Ben Zhou said at the time that 68.57% of the funds remained traceable

Related: Bybit made ‘slow but steady comeback’ in 2025 after massive hack: CoinGecko

Advertisement

The hack occured on Feb. 21, 2025, after attackers compromised Safe Wallet’s infrastructure. Forensic investigators said compromised credentials belonging to a Safe developer allowed the attackers to inject malicious code into its cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26, 2025. 

The lawsuit shows that Bybit is seeking the return of the stolen assets, approximately $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act.

Magazine: 10 weirdest things ever tokenized… including farts

Source link

Advertisement
Continue Reading

Crypto World

HYPE price eyes $57.30 as Q2 buybacks fuel rebound

Published

on

HYPE 4-hour chart shows price holding above $54.44 Supertrend support with RSI near 60.

HYPE price climbed above $56.80 as strong quarterly revenue, token buybacks, and rising RWA trading activity helped it rebound from the $51 support area.

Summary

  • HYPE price gained 2.5% in 24 hours and traded about 3.7% higher over the past week.
  • Hyperliquid generated $169 million in Q2 revenue, allocating $141 million to HYPE buybacks.
  • The daily chart shows a potential breakout from a descending channel, but momentum is nearing overbought levels.
  • Liquidation clusters at $57.20 and $55 could determine HYPE’s next short-term move.

HYPE price rebounds from $51 support

According to data from crypto.news, Hyperliquid (HYPE) price traded near $56.80 on Aug. 7, gaining about 2.5% over 24 hours after recovering from an early-August low around $51.20. The token reached an intraday high near $57.04 before buyers and sellers began competing around the $57 level.

The rebound has lifted HYPE roughly 11% from its weekly low, although its net seven-day gain remained closer to 3.7%. Trading volume stood near $250 million over the previous 24 hours.

Advertisement

The 4-hour chart shows HYPE establishing a sequence of higher lows after defending the $51–$52 region. Price has also moved above the Supertrend indicator, which currently provides dynamic support near $54.44.

HYPE 4-hour chart shows price holding above $54.44 Supertrend support with RSI near 60.
Hyperliquid price 4-hour chart — Aug. 7 | Source: crypto.news

The 4-hour relative strength index stood at 60.08, slightly above its signal average of 59.49. This reading points to improving buying pressure without placing HYPE in overbought territory on the shorter timeframe.

However, the token remains about 26% below its June record near $76.70. The broader chart therefore shows a recovery within a larger correction rather than a confirmed return to its previous uptrend.

Hyperliquid buybacks support the recovery

The latest move followed the release of Hyperliquid’s second-quarter performance figures. The protocol reported $169 million in quarterly revenue and said $141 million was directed toward HYPE buybacks.

Advertisement

Hyperliquid also passed $1 billion in cumulative protocol revenue during the quarter. HIP-3 real-world asset perpetual contracts generated $213 billion in trading volume and represented 32.2% of activity in the category covered by the report.

RWA trading contributed 6.6% of total quarterly revenue, according to the Q2 figures. The data strengthened the view that Hyperliquid is expanding beyond crypto perpetual futures into tokenized commodities, equities and other traditional-market products.

Buybacks can support HYPE by creating recurring demand using protocol revenue. Still, their effect depends on whether platform trading activity and fee generation remain high enough to offset token sales and future supply growth.

HYPE’s fully diluted valuation stood near $54 billion, compared with a circulating market capitalization of approximately $12.6 billion. That gap remains a longer-term risk because only part of the maximum token supply currently circulates.

Advertisement

HYPE price faces $57.30 liquidation wall

The daily chart shows HYPE attempting to move above the upper boundary of a descending channel that has guided price lower since early July. A sustained daily close above $57 would strengthen the breakout case.

HYPE daily chart shows a descending-channel breakout attempt near $57 as the Stochastic RSI enters overbought territory.
Hyperliquid price daily chart — Aug. 7 | Source: crypto.news

The Awesome Oscillator remained negative at -5.39, showing that the broader momentum structure has not fully turned bullish. Its histogram bars have nevertheless shifted higher, indicating that bearish momentum is weakening.

The Stochastic RSI presents a more immediate warning. Its two lines stood at 95.80 and 88.35, placing the indicator deep in overbought territory. That setup does not guarantee a decline, but it raises the chance of consolidation or a short pullback before another advance.

CoinGlass’ 24-hour liquidation heatmap shows the largest nearby liquidity concentration above the market at approximately $57.20–$57.35. A move through that zone could force leveraged short positions to close and push HYPE toward $58 and $60.

HYPE 24-hour liquidation heatmap shows major liquidity clusters near $57.30 and $55.
Hyperliquid liquidation chart | Source: CoinGlass

Below the current price, another major liquidation cluster sits around $54.90–$55. Losing that area could accelerate a decline toward the 4-hour Supertrend support at $54.44. The next lower zones are $52 and the recent low near $51.

Analysts Split Over HYPE’s Next Target

Crypto trader Altcoin Sherpa said HYPE may be building a bottom near its current range, although he expected the outcome to depend on wider market conditions.

Advertisement

“The level to watch is still $50; lose that and I think we see low/mid $40s in a slow fashion,” he wrote in an Aug. 6 post.

The analyst added that he remained constructive on HYPE over the longer term. His chart placed a broader demand zone across the low-to-mid-$40 region if the $50 floor fails.

HypeDojo offered a more bullish scenario, comparing the latest $51.50 bottom with the token’s earlier rebound from $52.50 to its June record. The trader projected a possible move toward $80 by the end of August.

That target would require HYPE to clear several resistance areas, including $60, $64, $68 and the previous record around $76.70. The overbought daily Stochastic RSI also suggests that such a move may not develop in a straight line.

US competition adds risk to HYPE outlook

JPMorgan analysts have warned that momentum in HYPE-linked investment products weakened after strong inflows during May and June. A reported 12-session outflow streak reached approximately $29.8 million through Aug. 3.

Advertisement

The bank also pointed to competition from regulated derivatives and prediction-market platforms, according to Blockhead. That risk is particularly relevant in the United States, where regulated venues are expanding access to perpetual-style contracts.

For now, the HYPE price outlook depends on whether buyers can convert the rebound into a confirmed daily channel breakout. A close above $57.30 would open a path toward $60, while rejection and a break below $54.40 would bring $52 and $50 back into focus.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

Hacker Behind Fake 'Vladhood' Token Still Collecting Fees After Robinhood CEO's X Account Hack

Published

on

Hacker Behind Fake 'Vladhood' Token Still Collecting Fees After Robinhood CEO's X Account Hack


Robinhood CEO Vlad Tenev's X account was compromised on Thursday and used to promote a fake memecoin on Robinhood Chain, the company confirmed. That’s the visible half of an operation that, onchain records show, was set in motion hours earlier and designed to profit from the frenzy without ever… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Cardano price rallied 25% this week, can bulls hold $0.20 support?

Published

on

Cardano daily chart shows ADA holding near $0.20 as the Supertrend turns bullish and Aroon Up reaches 92.86%.

Cardano price traded near $0.20 on Aug. 7 after gaining more than 25% over the past week, with technical momentum and network updates supporting the recovery.

Summary

  • ADA gained more than 25% in seven days, briefly trading above $0.21.
  • The 4-hour chart places immediate support at $0.195, followed by $0.184.
  • A 3-day liquidation heatmap shows dense leveraged positions around $0.196–$0.198.
  • Bulls must clear $0.207–$0.210 to extend the rally toward $0.22.

Cardano price holds after its 25% rally

According to data from crypto.news, Cardano (ADA) price was trading around $0.201 at the time of writing after reaching an intraday high near $0.204. ADA briefly crossed $0.21 earlier in the session before sellers pushed it back toward the psychological $0.20 level.

The 7-day advance marked a sharp change from the weak price action seen through much of 2026. ADA had fallen from above $0.45 late last year to approximately $0.14 in June before forming a base.

Advertisement

The daily chart shows that the token has now moved above its Supertrend resistance at $0.171. That indicator has flipped into support, suggesting that the broader recovery remains intact while ADA trades above the $0.168–$0.171 area.

Cardano daily chart shows ADA holding near $0.20 as the Supertrend turns bullish and Aroon Up reaches 92.86%.
Cardano price daily chart — Aug. 7 | Source: crypto.news

Aroon readings also favor buyers. Aroon Up stood at 92.86%, compared with Aroon Down at 28.57%, showing that recent highs are more dominant than recent lows. However, ADA has not yet established a daily close far above $0.20, leaving the breakout open to a retest.

Network updates and whale demand support ADA

The rally coincided with renewed interest in Cardano’s development roadmap. Intersect said the network had entered the Dijkstra development era following the Van Rossem hard fork in July.

Attention has also turned toward Ouroboros Leios, a planned upgrade intended to increase Cardano’s transaction capacity. A proposed 2.5 million ADA development fund and a Cardano IBC testnet connection with Injective added to expectations for broader ecosystem activity.

Advertisement

On-chain data cited during the rally showed that large holders accumulated roughly 240 million ADA before the breakout. Futures activity also accelerated, with weekly trading volume reportedly rising from about $150 million to nearly $650 million.

That combination of spot accumulation and leveraged positioning helped ADA move through $0.20. Still, a reported decline in open interest and slightly negative funding indicate that some derivatives traders continue to position against further gains.

Advertisement

Fundamental weaknesses also remain. Cardano’s decentralized finance ecosystem holds about $68 million in total value locked, leaving it well behind larger layer-1 networks. That gap raises the risk that price speculation is moving faster than organic activity on the blockchain.

Can ADA hold the $0.20 support level?

The 4-hour chart places ADA inside an ascending channel that began near $0.15 in late July. Price remains above the Bollinger Band midpoint at $0.195, making the $0.195–$0.20 range the first test for buyers.

Cardano 4-hour chart shows ADA consolidating near $0.20 within an ascending channel, with support at $0.195.
Cardano price 4-hour chart — Aug. 7 | Source: crypto.news

The 4-hour Relative Strength Index stood at 60.19, while its signal line was at 58.71. Momentum remains bullish without reaching the 70 level commonly associated with overbought conditions.

ADA’s upper Bollinger Band sits at approximately $0.207. A close above that level could allow bulls to retest $0.21, where the latest rally met selling pressure. The channel’s upper boundary then points toward $0.218–$0.22.

A decisive move through $0.22 could expose the $0.24–$0.25 range. Rand Group said reclaiming $0.25 would be needed to confirm a broader reversal from Cardano’s yearly downtrend.

Advertisement

“Recovering the key 25 cents support range would trigger the full bullish reversal,” the firm said in an Aug. 7 market post.

The daily structure shows why $0.25 matters. Cardano has recovered from its June low, but it remains within a much larger downtrend after losing more than 90% from its historical high of $3.10.

Liquidation clusters increase volatility risk

CoinGlass’ 3-day liquidation heatmap shows a large concentration of leveraged positions just below the market around $0.196–$0.198. This zone overlaps with the 4-hour Bollinger midpoint, strengthening its role as immediate support.

ADA three-day liquidation heatmap shows dense liquidity near $0.196–$0.198 and above $0.207.
Cardano liquidation heatmap | Source: CoinGlass

A move below $0.195 could trigger long liquidations and accelerate a decline toward $0.19. The lower 4-hour Bollinger Band sits near $0.184, providing the next major technical support if sellers take control.

Below that, the rising channel would be invalidated, placing $0.171 and the daily Supertrend level near $0.168 back in focus.

Advertisement

Liquidity also sits above ADA around $0.207–$0.210, followed by additional clusters between approximately $0.212 and $0.218. If buyers reclaim $0.207, short liquidations could help drive another test of the weekly high.

For U.S. traders, expectations for future Federal Reserve rate cuts remain a wider market catalyst. Cardano also faces an Oct. 23 regulatory deadline tied to a proposed spot ADA exchange-traded fund, which could keep institutional access and U.S. regulatory expectations in focus.

The immediate outlook depends on whether ADA can convert $0.20 from resistance into support. Holding $0.195 would preserve the 4-hour uptrend, while a close above $0.21 would strengthen the case for $0.22 and eventually $0.25. Losing $0.195 would instead raise the probability of a deeper pullback toward $0.184.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

Advertisement

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025