BTC $63,633.13 -0.73%
ETH $1,878.26 -0.00%
BNB $611.66 +1.86%
XRP $1.01 -0.21%
SOL $75.89 -0.56%
TRX $0.3348 +1.29%
DOGE $0.0714 +2.48%
ADA $0.1858 -3.80%
BCH $212.66 +0.02%
LINK $8.69 +4.98%
HYPE $54.58 -1.63%
AAVE $88.11 -1.78%
SUI $0.6862 -0.60%
XLM $0.1617 -0.49%
ZEC $477.08 -4.31%
BTC $63,633.13 -0.73%
ETH $1,878.26 -0.00%
BNB $611.66 +1.86%
XRP $1.01 -0.21%
SOL $75.89 -0.56%
TRX $0.3348 +1.29%
DOGE $0.0714 +2.48%
ADA $0.1858 -3.80%
BCH $212.66 +0.02%
LINK $8.69 +4.98%
HYPE $54.58 -1.63%
AAVE $88.11 -1.78%
SUI $0.6862 -0.60%
XLM $0.1617 -0.49%
ZEC $477.08 -4.31%

steal

All
Article
Flash

ZachXBT: American female scammer impersonates customer service to steal over 5 million dollars in cryptocurrency assets

On-chain detective ZachXBT posted that U.S. threat actor Tiffany Milanovich participated in the theft of approximately $5 million in crypto assets by impersonating hardware wallet and centralized exchange customer service.Her methods included disguising as Bitcoin IRA email support, during one attack transferring about $1.2 million in BTC and ETH from the victim's Trezor wallet, and in another case stealing about $500,000 in BTC from a Coinbase account. Tiffany induced victims to hand over access to their funds under the guise of "customer service calls," later boasting about the stolen money on social media and Telegram groups, mocking victims with recordings, and collaborating with other threat actors to launder money using phishing panels and instant exchange services, with some of the stolen funds still dormant on-chain.The threat actor codenamed "Tiffany" is suspected of participating in multiple crypto asset thefts, gambling the stolen funds at crypto casinos. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT; Tiffany previously shared a search and seizure warrant from Connecticut, dated before some of the incidents involved.ZachXBT has obtained chat logs, recordings, and on-chain evidence, anticipating that this individual may face further legal consequences. This threat actor is also linked to the John Daghita (Lick) case, who is suspected of stealing over $46 million in crypto assets from a U.S. government-seized wallet.

The IRS warns cryptocurrency holders that scammers are mailing fake letters to steal assets or data

According to Bloomberg, the Internal Revenue Service (IRS) has warned cryptocurrency holders that scammers are contacting some taxpayers by mailing fake letters in an attempt to steal their digital assets or personal data. The IRS stated that these letters may ask taxpayers to register for a so-called "Digital Asset Compliance Portal," which does not exist. The IRS also reminds users not to scan suspicious QR codes and not to answer or cooperate with calls requesting payment.While phishing and digital scams are not new in the cryptocurrency industry, sending fake IRS notices through physical mail seems to be a new scam tactic. Since the IRS has indeed sent letters related to digital assets to taxpayers in the past, and last year saw a surge in cryptocurrency tax filing notifications, many taxpayers are confused, which may lead scammers to exploit this familiarity for disguise. As the U.S. tax system requires taxpayers to disclose cryptocurrency activities on their tax returns, communication between the IRS and cryptocurrency holders has become more common. This also makes counterfeit tax notices more misleading. For cryptocurrency users, encountering "IRS letters" involving portal registration, QR code scanning, wallet connections, or payment requests should be treated with caution, and verification should be done through official channels.

Vitalik: The Diamond iO exploration program "stealth" new paradigm may drive privacy computing into a new stage

Ethereum co-founder Vitalik Buterin published a new article introducing a novel cryptographic obfuscation technology called Diamond iO. This technology aims to address the extremely low efficiency of traditional indistinguishable obfuscation schemes, allowing programs to run while hiding internal logic and critical data. Although traditional iO technology possesses strong privacy protection capabilities, its operational costs are prohibitively high, making it nearly impractical. Diamond iO, by adopting more aggressive new cryptographic assumptions, enhances computational efficiency from "universe-level time consumption" to "planet-level time consumption," bringing it closer to practical application.Diamond iO is built on technologies such as Attribute-Based Encryption (ABE) and Fully Homomorphic Encryption (FHE). By encrypting programs, it allows users to execute the encrypted programs and obtain correct outputs without being able to view the internal code or hidden keys. This solution introduces a new input encoding mechanism and conditional decryption method, reducing computational complexity while ensuring the program logic remains hidden. Its core application scenarios include protecting programs that contain private keys, enabling secure software licensing, constructing trustless cryptographic services, and supporting blockchain and artificial intelligence systems with stronger privacy protection.However, Diamond iO is still in the early research stage, and its security relies on new cryptographic assumptions, including All-Product LWE and Evasive LWE, which require further research validation. At the same time, the technology still faces efficiency challenges such as high computational overhead and circuit depth limitations. Researchers believe that by optimizing underlying hash functions, improving homomorphic encryption schemes, and reducing security parameter requirements, Diamond iO is expected to become an important direction for advancing practical program obfuscation technology in the future.

North Korea dismantles an elite hacking group involved in infiltrating central banks and foreign trade banks to steal funds and launder money through cryptocurrency

According to South Korean media Daily NK, North Korean authorities arrested an elite hacker group on July 12, which is suspected of infiltrating the internal networks of the North Korean central bank and foreign trade bank, stealing national trade funds and laundering money through cryptocurrency. Sources say the group's leader is a veteran from the cyber warfare unit under the North Korean Reconnaissance General Bureau, who recruited talented IT graduates from Kim Chaek University of Technology and Pyongyang University of Science and Technology, using encrypted communications and wireless devices to commit crimes.They split the stolen funds into small amounts and transferred them to overseas cryptocurrency wallets, exchanged them for cash through intermediaries, and then converted them into dollars and other currencies in border areas. Pyongyang officials launched an investigation after discovering anomalies in foreign currency payment approvals and records of overseas IP access, ultimately raiding a safe house and arresting suspects who were laundering money, seizing equipment worth hundreds of thousands of dollars. This case has caused a stir among the elite and military circles in Pyongyang, with senior officials in the Reconnaissance General Bureau and the science and education sector worried about being implicated. North Korea has long been accused of stealing billions of dollars in cryptocurrency assets through hacker organizations like the Lazarus Group, but this incident rarely shows that its own financial system has also become a target of internal attacks.

A man in the United States implanted malware through Steam games to steal cryptocurrency assets, infecting about 8,000 devices

The U.S. federal prosecutors have charged a 21-year-old Florida man, Zyaire Wilkins, accusing him of implanting malware to steal cryptocurrency assets in at least 8 games with accomplices between May 2024 and February 2026, spreading it through gaming platforms, resulting in approximately 8,000 devices being infected and about 80 cryptocurrency wallets being stolen, with the amount involved exceeding $220,000.The indictment documents show that the games involved include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova. Some of these games had previously been removed from Steam due to security risks. Investigators stated that the suspect promoted these games through platforms such as Discord, Telegram, X, and LinkedIn, luring users to download and install them, after which the malware stole sensitive information from victims and siphoned off cryptocurrency wallet assets.The FBI indicated that law enforcement identified the suspect through on-chain fund flow analysis and digital payment records. The investigation found that his associated cryptocurrency wallet had purchased over 150 gift cards on the cryptocurrency gift card platform Bitrefill, including Uber Eats gift cards, ultimately helping investigators confirm his phone number and address. The case has now been filed in the U.S. District Court for the Western District of Washington.

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.

ZachXBT: Indian scam gang suspected of social engineering to steal coins and self-reported to the police to trace and freeze funds

"On-chain detective" ZachXBT published a case analysis stating that in a cryptocurrency asset case involving an Indian scam gang, the relevant individuals reported the case to law enforcement after their assets were frozen, drawing attention. The incident began when a user sought help, claiming that approximately 5.73 BTC (about $475,000) was frozen on Changelly in March 2025.Subsequent on-chain analysis revealed that these funds could be traced back to multiple social engineering attacks and theft cases related to Bitcoin ATMs targeting U.S. users, with a total amount involved exceeding $1 million and several elderly victims. The investigation showed that the individual provided multiple changing explanations for the source of the funds, including "loan," "boss transfer," and "investment from 2014-2015," and there were significant contradictions in the evidence chain.More concerning is that this user had previously filed a police report in India in December 2025, attempting to recover the frozen funds (case number 3207-P/2025). Subsequent on-chain evidence collection and email data analysis indicated that they might be a "mule" for transferring funds, with some bank documents inconsistent with their identity information. ZachXBT noted that such cases demonstrate that social engineering attacks and cross-border fund transfers continue to occur and remind users to avoid interacting with funds from suspicious sources to prevent triggering compliance freezes or legal risks.
app_icon
ChainCatcher Building the Web3 world with innovations.