BTC $82,922.23 -0.73%
ETH $2,654.50 +0.12%
BNB $754.56 -2.46%
XRP $1.47 -2.25%
SOL $116.47 -3.31%
TRX $0.3345 +0.24%
DOGE $0.0918 -3.34%
ADA $0.2398 -5.34%
BCH $303.75 -6.83%
LINK $15.02 +7.14%
HYPE $86.01 -5.17%
AAVE $146.25 -3.26%
SUI $1.10 -11.82%
XLM $0.2230 +3.94%
ZEC $1,374.43 -12.82%
AAPL $338.00 -0.74%
AMZN $246.30 -0.98%
GOOGL $342.43 +0.17%
MSFT $508.75 -1.55%
META $716.44 -2.43%
NVDA $228.74 +1.99%
TSLA $357.24 -3.48%
SNDK $1,700.19 -2.09%
INTC $114.58 -4.30%
SPCX $145.82 -2.15%
MU $1,050.64 -1.57%
AMD $606.53 -2.27%
BTC $82,922.23 -0.73%
ETH $2,654.50 +0.12%
BNB $754.56 -2.46%
XRP $1.47 -2.25%
SOL $116.47 -3.31%
TRX $0.3345 +0.24%
DOGE $0.0918 -3.34%
ADA $0.2398 -5.34%
BCH $303.75 -6.83%
LINK $15.02 +7.14%
HYPE $86.01 -5.17%
AAVE $146.25 -3.26%
SUI $1.10 -11.82%
XLM $0.2230 +3.94%
ZEC $1,374.43 -12.82%
AAPL $338.00 -0.74%
AMZN $246.30 -0.98%
GOOGL $342.43 +0.17%
MSFT $508.75 -1.55%
META $716.44 -2.43%
NVDA $228.74 +1.99%
TSLA $357.24 -3.48%
SNDK $1,700.19 -2.09%
INTC $114.58 -4.30%
SPCX $145.82 -2.15%
MU $1,050.64 -1.57%
AMD $606.53 -2.27%

keys

All
Article
Flash

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code, which may lead to the leakage of private keys and mnemonic phrases

SlowMist released a security warning stating that it has recently received multiple reports of FomoPeek users' assets being stolen. After a joint investigation with the OKX security team, it was found that some affected users had previously installed or used FomoPeek versions 1.1 to 1.2, which contained malicious code. SlowMist stated that there are modules in FomoPeek unrelated to normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting eight different attack methods that can automatically select the exploitation method based on device model and iOS version. Affected systems include iOS 12 to 18.7 and iOS 26 to 26.1. If the exploitation is successful, the application may break through the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files. In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist indicated that its analysis of captured plaintext traffic shows that the related attack functions are currently enabled and will run automatically on a regular basis. SlowMist recommends that users who have installed or used FomoPeek versions 1.1 to 1.2 immediately check for any anomalies in their assets, generate new private keys and mnemonic phrases on trusted devices that have never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and not continuing to use or reinstall FomoPeek.

first_img Hacken Report: Half of USDT is controlled by only two signing keys

Blockchain security company Hacken released an assessment report indicating that approximately half of the circulating USDT (about $91.3 billion on the Tron network) is controlled by a 2-of-3 multi-signature contract, which lacks built-in delays, cancellation processes, or reliable revocation mechanisms. Attackers only need to compromise two signature keys to change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees without accessing any user wallets. Hacken also discovered that Tether reuses the same set of six signature keys across three chains: Ethereum, Avalanche, and Celo, posing a risk of cross-chain spread.Meanwhile, stablecoin rating agency Bluechip upgraded Tether's company rating from D to C, citing that KPMG's audit showed Tether's reserves exceeded liabilities by $6.8 billion as of December 31, 2025. This is the first time Bluechip has adopted the expanded SMIDGE methodology, which incorporates Hacken's technical risk analysis. However, Hacken only gave USDT a cybersecurity score of 3.3 out of 10 and pointed out that the USDT smart contract does not have automatic reserve proof checks or a token minting cap. Once signers authorize a transaction, the contract can mint an unlimited number of tokens without a bank reserve proof.Hacken stated that it has not yet completed an equivalent assessment of Circle's USDC, and Bluechip's previous B+ rating for USDC was based on an old methodology, which cannot be directly used for technical comparison.

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.

The cryptocurrency industry is once again debating "who should hold the private keys" due to the $130 million theft case involving the Coldcard wallet

A wallet security incident involving approximately $130 million in Bitcoin losses is reigniting discussions in the crypto industry about asset custody models: should Bitcoin holders rely on personal self-custody or turn to institutional custody? Hardware wallet manufacturer Coldcard had a vulnerability in its firmware in 2021 that led to some mnemonic phrases generated by the device being predictably risky. This vulnerability was discovered years later, and approximately 5,200 addresses and about 2,000 BTC have been stolen, with losses amounting to around $130 million.After the incident, some investors began to turn to Wall Street custody products. Data shows that the U.S. spot Bitcoin ETF saw a net inflow of about $626 million within days of the incident. Bloomberg ETF analyst Eric Balchunas stated that such security incidents could further drive funds into ETFs. However, the Bitcoin core community still insists on the self-custody concept. Casa co-founder Jameson Lopp stated that recent events should not undermine users' confidence in self-custody and pointed out that third-party custody also carries risks. Bitcoin Core early developer Peter Todd also believes that self-custody has a better long-term safety record than centralized institutions.Onramp co-founder Michael Tanguma believes that both options have flaws. He stated that concentrating a large amount of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Tanguma proposed a "multi-institution custody" solution, where multiple regulated institutions hold keys through a multi-signature mechanism, requiring multiple institutions to jointly sign any transaction to reduce single points of failure. However, this model has also sparked controversy. Critics argue that while multi-institution custody enhances security, it also introduces permissioned management, conflicting with the decentralized ideals originally pursued by Bitcoin. As Bitcoin gradually enters the fields of pensions, trusts, and institutional asset allocation, the industry is seeking new custody solutions suitable for long-term wealth management. The Coldcard vulnerability incident once again highlights that achieving a balance between security, decentralization, and usability remains a core challenge facing the Bitcoin ecosystem.

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.
app_icon
ChainCatcher Building the Web3 world with innovations.