BTC $63,940.54 -1.61%
ETH $1,852.66 -2.51%
BNB $557.20 -1.75%
XRP $1.09 -1.98%
SOL $74.16 -3.39%
TRX $0.3302 +1.19%
DOGE $0.0686 -2.70%
ADA $0.1642 -4.42%
BCH $208.29 -2.86%
LINK $8.31 -2.31%
HYPE $58.21 -1.71%
AAVE $93.87 -2.54%
SUI $0.7191 -4.95%
XLM $0.1804 -0.83%
ZEC $498.38 -3.31%
BTC $63,940.54 -1.61%
ETH $1,852.66 -2.51%
BNB $557.20 -1.75%
XRP $1.09 -1.98%
SOL $74.16 -3.39%
TRX $0.3302 +1.19%
DOGE $0.0686 -2.70%
ADA $0.1642 -4.42%
BCH $208.29 -2.86%
LINK $8.31 -2.31%
HYPE $58.21 -1.71%
AAVE $93.87 -2.54%
SUI $0.7191 -4.95%
XLM $0.1804 -0.83%
ZEC $498.38 -3.31%

ito

All
Article
Flash

The Russian Financial Supervisory Authority will be authorized to monitor all cryptocurrency transactions, with those over 60,000 rubles required to be reported

According to Bits.media, a new draft bill submitted by the Russian government aims to grant the Financial Supervisory Authority the power to monitor all cryptocurrency transactions. For cryptocurrency transactions exceeding 60,000 rubles and foreign trade cryptocurrency transactions exceeding 1,000,000 rubles, the agency will collect complete information such as the full names or corporate names of the payer and payee, wallet addresses, actual addresses, birth dates, and taxpayer identification numbers. Transactions below 60,000 rubles only require the provision of names and wallet addresses.The bill also stipulates that the new limit for digital asset transactions by banks is 1% of the bank group's capital, and banks must hold corresponding funds to cover risks for the purchased cryptocurrencies. The central bank will be authorized to restrict or prohibit specific cryptocurrency operations when they threaten investor interests or may "undermine the stability of the financial system," with the scope extending from non-bank financial institutions to banks. The bill is expected to take effect simultaneously with the main cryptocurrency regulatory legislation, originally scheduled for implementation on July 1, but the review has been postponed. The first deputy governor recently stated that the relevant laws may take effect on September 1.

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.
app_icon
ChainCatcher Building the Web3 world with innovations.