BTC $86,690.03 +1.03%
ETH $2,770.04 +0.68%
BNB $791.44 -0.17%
XRP $1.60 +5.65%
SOL $119.09 +1.14%
TRX $0.3428 -1.06%
DOGE $0.1015 +2.03%
ADA $0.2561 +4.49%
BCH $342.69 +28.88%
LINK $13.11 +0.84%
HYPE $97.39 +4.48%
AAVE $149.06 +3.17%
SUI $1.02 -1.82%
XLM $0.2181 +2.70%
ZEC $1,608.29 +9.20%
AAPL $339.98 +0.35%
AMZN $255.43 -1.47%
GOOGL $352.39 -1.11%
MSFT $499.29 -0.33%
META $740.28 +0.14%
NVDA $228.49 +0.42%
TSLA $378.88 +0.57%
SNDK $1,883.46 +5.38%
INTC $123.60 +0.60%
SPCX $154.22 +0.87%
MU $1,090.15 +3.98%
AMD $621.53 +0.09%
BTC $86,690.03 +1.03%
ETH $2,770.04 +0.68%
BNB $791.44 -0.17%
XRP $1.60 +5.65%
SOL $119.09 +1.14%
TRX $0.3428 -1.06%
DOGE $0.1015 +2.03%
ADA $0.2561 +4.49%
BCH $342.69 +28.88%
LINK $13.11 +0.84%
HYPE $97.39 +4.48%
AAVE $149.06 +3.17%
SUI $1.02 -1.82%
XLM $0.2181 +2.70%
ZEC $1,608.29 +9.20%
AAPL $339.98 +0.35%
AMZN $255.43 -1.47%
GOOGL $352.39 -1.11%
MSFT $499.29 -0.33%
META $740.28 +0.14%
NVDA $228.49 +0.42%
TSLA $378.88 +0.57%
SNDK $1,883.46 +5.38%
INTC $123.60 +0.60%
SPCX $154.22 +0.87%
MU $1,090.15 +3.98%
AMD $621.53 +0.09%

cio

All
Article
Flash

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code, which may lead to the leakage of private keys and mnemonic phrases

SlowMist released a security warning stating that it has recently received multiple reports of FomoPeek users' assets being stolen. After a joint investigation with the OKX security team, it was found that some affected users had previously installed or used FomoPeek versions 1.1 to 1.2, which contained malicious code. SlowMist stated that there are modules in FomoPeek unrelated to normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting eight different attack methods that can automatically select the exploitation method based on device model and iOS version. Affected systems include iOS 12 to 18.7 and iOS 26 to 26.1. If the exploitation is successful, the application may break through the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files. In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist indicated that its analysis of captured plaintext traffic shows that the related attack functions are currently enabled and will run automatically on a regular basis. SlowMist recommends that users who have installed or used FomoPeek versions 1.1 to 1.2 immediately check for any anomalies in their assets, generate new private keys and mnemonic phrases on trusted devices that have never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and not continuing to use or reinstall FomoPeek.

first_img Fake AI trading robot tutorial deceives 224 victims into deploying malicious contracts

On September 14, blockchain intelligence company TRM Labs released a report revealing that fake YouTube tutorials lured 224 victims into deploying and funding malicious smart contracts under the guise of building AI-based crypto arbitrage bots, resulting in the theft of 274.6 ETH. TRM identified a total of 234 contracts deployed by the victims, with funds ultimately flowing into six collection addresses controlled by the operators. The stolen ETH was worth approximately $517,000 at the time of the transfer, with a median loss of 1 ETH per incident.Unlike common wallet theft attacks, this scam did not involve phishing links, spoofed domains, or malicious authorization prompts. Victims chose the tutorials themselves, copied the code, deployed the contracts, and funded them from their own wallets, with each step authorized by the victims themselves. As a result, wallet security warnings and phishing blacklists could not be triggered. TRM discovered nine nearly identical YouTube tutorials disguised as different creators, using AI-generated virtual hosts and voiceovers, promising to build fully automated crypto trading bots with Claude, and guiding victims to a compiler website controlled by the operators, some of which mimicked the commonly used Remix development environment.In one variant analyzed by TRM, a backend script would discard the source code pasted by the victims and retrieve another contract from the operator's server, with the clean code displayed on the screen never being on-chain. The replaced contract accepted deposits and transferred any balance over 0.05 ETH to the operators when the victims pressed Start or Withdraw, with no arbitrage logic or AI functionality included in the contract.

first_img OpenAI malicious agent detected Hugging Face in May, two months earlier than the July intrusion

Independent researcher Jonas Wiedermann-Moeller discovered that OpenAI's malicious AI agents hijacked two Hugging Face user accounts and probed the platform's network vulnerabilities as early as May 13, nearly two months before the publicly disclosed intrusion incident in July. An internal incident report released by OpenAI last month disclosed only a small part of this, specifically that an agent stole a user's login credentials to access a biology-related document, while the new findings point to ongoing reconnaissance activities.According to Reuters, these agents used the hijacked accounts to send malformed files to the servers of the open-source AI repository Hugging Face, and researchers believe this appears to be an attempt to map the network to find intrusion pathways. Researchers reviewing the evidence did not find that the activities in May caused an actual intrusion, but Wiedermann-Moeller believes missing this signal is significant. He stated that if this behavior had been detected in May, it might have prevented a later, larger-scale incident. Hugging Face, which is currently being acquired by NVIDIA for $12.93 billion, has not disclosed whether it was aware of this new information.Researchers from Nightingale Collective also linked a spam attack on the code repository RubyGems on May 11 to OpenAI agents, which temporarily forced the platform to suspend new account registrations for four days.

first_img HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

Stack BTC plans to acquire a precious metals dealer for £12 million to fund cryptocurrency purchases, and OSL Group has established legal currency payment channels across five countries

According to BBX data, yesterday and in recent days, global listed treasury companies and digital asset trading platforms disclosed the latest developments in strategic mergers and acquisitions and fiat currency clearing infrastructure. The core information is as follows:Stack BTC plans to acquire precious metals dealer Direct Bullion for up to £12 million: Stack BTC, a Bitcoin treasury company under former UK Chancellor Kwasi Kwarteng, announced that it has officially signed a non-binding letter of intent to fully acquire the well-known UK precious metals dealer Direct Bullion for up to £12 million (approximately $16 million). The company clearly stated that this acquisition aims to obtain ample and stable cash flow income through the physical precious metals sales business and plans to continuously use all net cash flow generated by this business to increase its Bitcoin holdings in the secondary market.Banking Circle deepens cooperation with OSL Group, adding five major mainstream currency channels: Next-generation financial infrastructure service provider Banking Circle announced further deepened strategic cooperation with Hong Kong-listed stablecoin payment and trading platform OSL Group (00863.HK). Based on the existing euro clearing business between the two parties, Banking Circle has officially added multi-currency payment and clearing channels for five major fiat currencies: Australian Dollar (AUD), British Pound (GBP), Hong Kong Dollar (HKD), Singapore Dollar (SGD), and US Dollar (USD) for OSL, fully supporting OSL in accelerating the expansion of its B2B cross-border payment landscape for global institutional clients.

first_img Stack BTC, supported by Farage, plans to acquire the precious metals dealer Direct Bullion for 16 million USD

The UK Bitcoin Treasury Company Stack BTC (STAK) proposed to acquire the precious metals dealer Direct Bullion for up to £12 million (approximately $16 million) and plans to use the operating cash flow generated from precious metal sales to support Bitcoin accumulation. This non-binding agreement includes £3 million in cash, approximately £4 million in shares, and £5 million in performance-linked cash payments, with a minimum share issuance price of 6 pence and a lock-up period of four years.As Stack director Paul Withers controls the seller Direct Bullion, this transaction constitutes a related party transaction and is classified as a reverse acquisition, which still requires due diligence and the signing of a final agreement. Direct Bullion achieved revenue of £52.1 million and a post-tax profit of £2.15 million for the fiscal year ending January 2026. This acquisition will be Stack's first transaction under the strategy of "acquiring profitable companies to fund Bitcoin purchases." Stack BTC currently holds approximately 68 Bitcoins (around $5.2 million), and its stock price fell by 1% on the day the news was announced.Nigel Farage invested £215,000 through his company Thorn In The Side, holding approximately 6.3% of Stack. Previously, Reform UK received donations of $48.5 million each from crypto billionaires Christopher Harborne and Ben Delo within 24 hours, totaling approximately $97 million, setting a record for political donations in the UK.

first_img The U.S. FinCEN links $12.7 billion in suspicious activities to Southeast Asian cryptocurrency investment scams

The Financial Crimes Enforcement Network (FinCEN) of the U.S. Department of the Treasury released an analysis and alert on Thursday, linking approximately $12.7 billion in suspicious financial activities to cryptocurrency investment scams operated by Southeast Asian parks. About 1,300 institutions submitted 33,904 suspicious activity reports covering the period from September 2023 to December 2025. Cryptocurrency-focused money service businesses submitted 55% of the reports, involving $5.5 billion; banks submitted 41%, involving $6.4 billion; and securities firms accounted for the remaining $784.5 million.The number of reports has been growing at an average monthly rate of 10.9%, with the amount involved increasing by 18%. Scammers used at least 22 types of digital assets, with Ethereum, USDT, and USDC being the most common. On-chain analysis shows that regardless of the asset victims initially purchased, the funds are almost always converted into stablecoins, with nearly all converted to USDT, and then transferred through DeFi protocols or exchanges outside the U.S. Scammers also reused collection addresses across multiple victims, which is one way some institutions identified this pattern.The report indicates that about 25% involved elderly individuals, which is comparable to the 24.4% of the population that is over 60 years old, leading FinCEN to conclude that the elderly are not disproportionately targeted. The FBI estimates that in 2024, the U.S. population over 60 lost $4.8 billion to scams. These parks are primarily located in Cambodia, Laos, and Myanmar, and U.S. authorities have seized over $25 million related to the associated scams this year.

first_img Securitize will issue tokenized sports equity for Socios

According to The Defiant, Securitize has announced a partnership with Socios.com, where Securitize will provide regulated securities issuance, investor onboarding, and ownership record services for Socios.com’s plan to sell tokenized minority equity in professional sports clubs.The token product branded as Socios Equity Tokens will be subject to applicable securities laws, league requirements, club approvals, and jurisdictional restrictions. Fan Tokens and Socios Equity Tokens will function as separate products, with the former used for participation and utility, while the latter represents regulated financial rights.Carlos Domingo, co-founder and CEO of Securitize, stated that professional sports clubs represent an important asset class that has largely remained private and difficult to access. Securitize's regulated infrastructure in the U.S. and Europe can provide clubs and their owners with new ways to issue and manage equity. Alexandre Dreyfus, founder and CEO of Chiliz Group, mentioned that the collaboration with Securitize will explore entering the next phase through regulated tokenized equity.It is reported that this plan is expected to become the first tokenized project launched by Securitize under the EU DLT pilot regime, which only accepts issuers with a market capitalization of less than 500 million euros. Securitize received authorization from Spain's CNMV for DLT trading and settlement systems in November 2025.
app_icon
ChainCatcher Building the Web3 world with innovations.