Binance Square
#hack

hack

1.1M views
920 Discussing
VINEVIDIVICI
·
--
Article
Trezor says third-party security breach led to phishing emails from legitimate domainTrezor warned of a phishing email that has been sent out from its official domain due to a third-party security breach. This follows last month’s security breach at shipping provider ShipMonk, which exposed the personal information of Trezor customers. Hardware wallet maker Trezor said its third-party email provider had been breached, enabling phishing emails to be sent from its official domain. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor wrote in an X post on Wednesday. Trezor said it has since taken down the domain and is investigating the situation, including how the hackers were able to use its official domain for the phishing emails. On the same day, BitBox, a Swiss bitcoin BTC-0.50% hardware walletmaker,reporteda similar phishing email circulating under its disguise.  Marcello Paz, a crypto commentator with X username "MHPaz," said he received the phishing email, sharing screenshots showing that it asked customers to update their hardware wallets due to a "critical" vulnerability that could affect newer devices. The email credentials show official domain names and signatures, unlike typical phishing emails that use similar but fake addresses. Not the first Just last month, Trezor disclosed a major security incident in which a breach at its shipping provider, ShipMonk, exposed customers' personal information. While Trezor initially said around 13,700 customers had their names, cities, and email addresses leaked, the company said earlier this month that another 67,000 U.S. customers were affected by the same breach. In June, Ledger's Donjon security research team disclosed a hardware vulnerability in the TROPIC01 chip used inside the Trezor Safe 7, demonstrating a lab-based laser attack that bypassed the chip's firmware verification system. Trezor said at the time no user funds were at risk. A 2020 Ledger breach exposed information belonging to more than 270,000 customers, with names, email addresses, phone numbers and, in some cases, home addresses later published on a hacking forum. Ledger customers have continued to report receiving scam phone calls and physical letters years later. #Bitcoin #Hack #hardware $BTC {future}(BTCUSDT)

Trezor says third-party security breach led to phishing emails from legitimate domain

Trezor warned of a phishing email that has been sent out from its official domain due to a third-party security breach.
This follows last month’s security breach at shipping provider ShipMonk, which exposed the personal information of Trezor customers.
Hardware wallet maker Trezor said its third-party email provider had been breached, enabling phishing emails to be sent from its official domain.
"Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor wrote in an X post on Wednesday.
Trezor said it has since taken down the domain and is investigating the situation, including how the hackers were able to use its official domain for the phishing emails.
On the same day, BitBox, a Swiss bitcoin BTC-0.50%
hardware walletmaker,reporteda similar phishing email circulating under its disguise.
Marcello Paz, a crypto commentator with X username "MHPaz," said he received the phishing email, sharing screenshots showing that it asked customers to update their hardware wallets due to a "critical" vulnerability that could affect newer devices. The email credentials show official domain names and signatures, unlike typical phishing emails that use similar but fake addresses.
Not the first
Just last month, Trezor disclosed a major security incident in which a breach at its shipping provider, ShipMonk, exposed customers' personal information. While Trezor initially said around 13,700 customers had their names, cities, and email addresses leaked, the company said earlier this month that another 67,000 U.S. customers were affected by the same breach.
In June, Ledger's Donjon security research team disclosed a hardware vulnerability in the TROPIC01 chip used inside the Trezor Safe 7, demonstrating a lab-based laser attack that bypassed the chip's firmware verification system. Trezor said at the time no user funds were at risk.
A 2020 Ledger breach exposed information belonging to more than 270,000 customers, with names, email addresses, phone numbers and, in some cases, home addresses later published on a hacking forum. Ledger customers have continued to report receiving scam phone calls and physical letters years later.
#Bitcoin #Hack #hardware
$BTC
💥 US$320 MILLION IN BTC WAS STOLEN The Liquid Network hack caused the theft of about 4.000 $BTC and the temporary suspension of transactions. The impact could affect market confidence. 😰 Prediction: 🔴 Bearish in the short term due to fear and uncertainty. $BTC $USDC #BTC #Bitcoin #Hack #CryptoNews {spot}(BTCUSDT)
💥 US$320 MILLION IN BTC WAS STOLEN
The Liquid Network hack caused the theft of about 4.000 $BTC and the temporary suspension of transactions. The impact could affect market confidence. 😰
Prediction: 🔴 Bearish in the short term due to fear and uncertainty. $BTC $USDC
#BTC #Bitcoin #Hack #CryptoNews
This year, crypto was stolen for 1.73 billion yuan, with 333 cases—an average of one every two days. The hackers are even more diligent than the Federal Reserve. Liquid Network’s 319 million is the largest single incident this year. Getting back 85% is decent; the remaining 47 million is basically tuition. On-chain isn’t without opportunities—it’s that there are too many, and you can’t stop getting burned. $BTC $ETH #CryptoSecurity #Hack
This year, crypto was stolen for 1.73 billion yuan, with 333 cases—an average of one every two days. The hackers are even more diligent than the Federal Reserve. Liquid Network’s 319 million is the largest single incident this year. Getting back 85% is decent; the remaining 47 million is basically tuition. On-chain isn’t without opportunities—it’s that there are too many, and you can’t stop getting burned.

$BTC $ETH #CryptoSecurity #Hack
🚨 JUST IN: Over $1M stolen from users of Solana neobank Avici. A prolonged attack caused the attacker to withdraw more than $1M in users’ assets. The attacker is currently believed to hold: • 10,005 SOL ≈ $1.07M • ~$11.6K USDC + USDT Notably: Avici’s upgrade permission system is said to use a regular Solana account instead of a multisig. And Avici only confirmed the incident 1 hour 53 minutes after the first stolen transaction. DeFi lesson of the day: “Multisig? Nah, one wallet is enough.” 💀 #solana #defi #crypto #Hack
🚨 JUST IN: Over $1M stolen from users of Solana neobank Avici.

A prolonged attack caused the attacker to withdraw more than $1M in users’ assets.

The attacker is currently believed to hold:
• 10,005 SOL ≈ $1.07M
• ~$11.6K USDC + USDT

Notably: Avici’s upgrade permission system is said to use a regular Solana account instead of a multisig.

And Avici only confirmed the incident 1 hour 53 minutes after the first stolen transaction.

DeFi lesson of the day:
“Multisig? Nah, one wallet is enough.” 💀

#solana #defi #crypto #Hack
North Korea’s Lazarus Group moves 19.4M in dormant Bitcoin, stirring market nerves $BTC $ETH #Bitcoin #Hack #Binance
North Korea’s Lazarus Group moves 19.4M in dormant Bitcoin, stirring market nerves $BTC $ETH #Bitcoin #Hack #Binance
⚠️🧠 #hack #Aİ Google, Microsoft, OpenAI, Anthropic, Capital One, MasterCard, Visa, Oracle and IBM and more than 100 other companies have signed an open letter "on AI protection" Companies are urging states and organizations to strengthen their cybersecurity before AI becomes powerful enough to bypass many defenses. —————————— it was previously reported that 700 OpenAI AI agents independently found each other and created a secret chat to hack another AI platform
⚠️🧠 #hack #Aİ Google, Microsoft, OpenAI, Anthropic, Capital One, MasterCard, Visa, Oracle and IBM and more than 100 other companies have signed an open letter "on AI protection" Companies are urging states and organizations to strengthen their cybersecurity before AI becomes powerful enough to bypass many defenses.

—————————— it was previously reported that 700 OpenAI AI agents independently found each other and created a secret chat to hack another AI platform
🫡 WE HACKED KYLIE JENNER — PUMPED $1.2M AND KEPT QUIET Hackers broke into Kylie Jenner’s X account (39.5M followers) and, as usual, launched a pump-and-dump on the $kylie memecoin via Pump.fun. The cap surged to $1.21M at the peak—then the posts were taken down and the usual run began. Most interesting part: no apologies or explanations from her or her team. The posts were just quietly deleted and that was it. Like nothing ever happened. The scheme lives forever because it works forever. A big name plus Pump.fun plus a crowd that jumps in without thinking—the formula hasn’t changed in years. Only the celebrities whose accounts get hacked change. #memecoin #crypto #Hack #pumpfun Follow along—I’m tracking pump-and-dumps while they’re still hot 🔔
🫡 WE HACKED KYLIE JENNER — PUMPED $1.2M AND KEPT QUIET

Hackers broke into Kylie Jenner’s X account (39.5M followers) and, as usual, launched a pump-and-dump on the $kylie memecoin via Pump.fun. The cap surged to $1.21M at the peak—then the posts were taken down and the usual run began.

Most interesting part: no apologies or explanations from her or her team. The posts were just quietly deleted and that was it. Like nothing ever happened.

The scheme lives forever because it works forever. A big name plus Pump.fun plus a crowd that jumps in without thinking—the formula hasn’t changed in years. Only the celebrities whose accounts get hacked change.

#memecoin #crypto #Hack #pumpfun

Follow along—I’m tracking pump-and-dumps while they’re still hot 🔔
❌ THE SANDBOX HACKED — HACKER PRINTED SAND WORTH $700 MILLION A hacker found a vulnerability in the SAND cross-chain bridge and released 14.9 billion tokens — about $700 million at the current rate. The Sandbox confirmed the hack. The bridges on Base and BNB Chain are already disabled, and the issued tokens are isolated. Important: SAND on Ethereum and Polygon was not affected, and users’ funds on these networks are safe. The team urged people not to buy, sell, or trade SAND on Base and BNB Chain — liquidity there has been compromised. Cross-chain bridges remain the most vulnerable point in DeFi — billions have already leaked through them. Minting non-existent tokens via a bridge is a classic: you don’t need to steal real assets—just convince the contract that they exist. #Sandbox #sand #Hack #security Subscribe — I track hacks while the details are still hot 🔔 {spot}(SANDUSDT)
❌ THE SANDBOX HACKED — HACKER PRINTED SAND WORTH $700 MILLION

A hacker found a vulnerability in the SAND cross-chain bridge and released 14.9 billion tokens — about $700 million at the current rate. The Sandbox confirmed the hack. The bridges on Base and BNB Chain are already disabled, and the issued tokens are isolated.

Important: SAND on Ethereum and Polygon was not affected, and users’ funds on these networks are safe. The team urged people not to buy, sell, or trade SAND on Base and BNB Chain — liquidity there has been compromised.

Cross-chain bridges remain the most vulnerable point in DeFi — billions have already leaked through them. Minting non-existent tokens via a bridge is a classic: you don’t need to steal real assets—just convince the contract that they exist.

#Sandbox #sand #Hack #security

Subscribe — I track hacks while the details are still hot 🔔
🤯 CHINESE HACKERS BREACHED THE US FEDERAL RESERVE, NASA, AND THE US SENATE — SINCE 2018 The US Department of Justice, the FBI, and other agencies accused a China-linked group called QTFY, which operated through the company Nanjing Xinjiuwei. The hackers had been active at least since 2018; among the victims were the Federal Reserve, NASA, the Senate, the DOJ, the US Department of Energy, and the US Department of Health. The tool — the QScan platform — automatically searched for vulnerable devices worldwide. On one day in 2024, the system carried out more than 2 million scanning and exploitation operations. The hackers infected thousands of routers, cameras, and IoT devices, and used them as proxies to conceal the origin of the attacks. Among the incidents: in 2019, an attempted breach of NASA was stopped. In May 2024, via a vulnerability in Check Point equipment, they gained access to data from more than 300 organizations. In September 2024, they attacked three national laboratories of the Department of Energy. Among the clients of Nanjing Xinjiuwei are China’s Ministry of State Security and the Chinese military. The US seized QTFY infrastructure domains and disrupted the platforms being used. #Hack #security #usa #china Subscribe — I track the biggest cyber incidents 🔔
🤯 CHINESE HACKERS BREACHED THE US FEDERAL RESERVE, NASA, AND THE US SENATE — SINCE 2018

The US Department of Justice, the FBI, and other agencies accused a China-linked group called QTFY, which operated through the company Nanjing Xinjiuwei. The hackers had been active at least since 2018; among the victims were the Federal Reserve, NASA, the Senate, the DOJ, the US Department of Energy, and the US Department of Health.

The tool — the QScan platform — automatically searched for vulnerable devices worldwide. On one day in 2024, the system carried out more than 2 million scanning and exploitation operations. The hackers infected thousands of routers, cameras, and IoT devices, and used them as proxies to conceal the origin of the attacks.

Among the incidents: in 2019, an attempted breach of NASA was stopped. In May 2024, via a vulnerability in Check Point equipment, they gained access to data from more than 300 organizations. In September 2024, they attacked three national laboratories of the Department of Energy. Among the clients of Nanjing Xinjiuwei are China’s Ministry of State Security and the Chinese military.

The US seized QTFY infrastructure domains and disrupted the platforms being used.

#Hack #security #usa #china

Subscribe — I track the biggest cyber incidents 🔔
❌ TAC HACKED OUT FOR $7.5 MILLION — A VULNERABILITY IN COSMOS EVM IMPACTED SEVERAL NETWORKS A hacker found a vulnerability in the Cosmos EVM module and withdrew 2,985,651,403 TAC from a single escrow account. Important point: no new tokens were issued, and issuance didn’t change—what was stolen was what already existed. The team froze the blockchain to stop the attack. The issue is broader: other networks running on the Cosmos EVM module were also affected by a similar vulnerability—specifically, MANTRA Chain. One vulnerable module — multiple affected networks at the same time. This is the main risk of the ecosystem approach: shared infrastructure scales not only capabilities, but also security holes. #Cosmos #Crypto #Hack #security Subscribe—I’m tracking hacks while the details are still hot 🔔
❌ TAC HACKED OUT FOR $7.5 MILLION — A VULNERABILITY IN COSMOS EVM IMPACTED SEVERAL NETWORKS

A hacker found a vulnerability in the Cosmos EVM module and withdrew 2,985,651,403 TAC from a single escrow account. Important point: no new tokens were issued, and issuance didn’t change—what was stolen was what already existed.

The team froze the blockchain to stop the attack. The issue is broader: other networks running on the Cosmos EVM module were also affected by a similar vulnerability—specifically, MANTRA Chain.

One vulnerable module — multiple affected networks at the same time. This is the main risk of the ecosystem approach: shared infrastructure scales not only capabilities, but also security holes.

#Cosmos #Crypto #Hack #security

Subscribe—I’m tracking hacks while the details are still hot 🔔
🚬 HACKER VOTED FOR HIMSELF — AND WITHDREW $8.5 MILLION FROM TERM FINANCE No code hacking, no vulnerabilities in smart contracts. The hacker simply bought enough TERM tokens, submitted his proposals through the voting process — and gained legitimate access to the protocol’s vaults. He withdrew $8.5 million. All within the rules. The protocol worked exactly as it was programmed. Governance attacks are one of the most underestimated vectors in DeFi. While everyone is watching for code vulnerabilities, it’s enough to simply buy votes. Decentralized governance works exactly until the moment when the tokens are distributed widely enough. When they can be bought up on the open market, it’s no longer protection—it becomes an attack surface. #defi #crypto #Hack #security Subscribe — I break down hacks here, including cases where the code had nothing to do with it 🔔
🚬 HACKER VOTED FOR HIMSELF — AND WITHDREW $8.5 MILLION FROM TERM FINANCE

No code hacking, no vulnerabilities in smart contracts. The hacker simply bought enough TERM tokens, submitted his proposals through the voting process — and gained legitimate access to the protocol’s vaults. He withdrew $8.5 million.

All within the rules. The protocol worked exactly as it was programmed.

Governance attacks are one of the most underestimated vectors in DeFi. While everyone is watching for code vulnerabilities, it’s enough to simply buy votes. Decentralized governance works exactly until the moment when the tokens are distributed widely enough. When they can be bought up on the open market, it’s no longer protection—it becomes an attack surface.

#defi #crypto #Hack #security

Subscribe — I break down hacks here, including cases where the code had nothing to do with it 🔔
⚠️New: BounceBit plans to permanently shut down its Layer 1 after a security vulnerability was reported valued at USD 286.5 million (BB). The project confirms it will return the funds to BounceBit instead of fixing the network, reminding us once again that failures in bridge and chain security can lead to dire consequences. #bouncebit #Layer1 #Hack
⚠️New: BounceBit plans to permanently shut down its Layer 1 after a security vulnerability was reported valued at USD 286.5 million (BB). The project confirms it will return the funds to BounceBit instead of fixing the network, reminding us once again that failures in bridge and chain security can lead to dire consequences.
#bouncebit #Layer1 #Hack
·
--
Bearish
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain. Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything. Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful. #BNBChain #crypto #Hack #Security Subscribe—I track hacks and how projects get out of them 🔔 {future}(BBUSDT)
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK

The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain.

Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything.

Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful.

#BNBChain #crypto #Hack #Security

Subscribe—I track hacks and how projects get out of them 🔔
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes. Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible. The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels. #Coldcard #bitcoin #security #Hack Subscribe — these alerts appear here in real time 🔔
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES

A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes.

Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible.

The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels.

#Coldcard #bitcoin #security #Hack

Subscribe — these alerts appear here in real time 🔔
🚨 YOU DIDN’T RUN THE CODE. YOU JUST BUILT IT. 💀 A supply-chain attack has targeted the Rust ecosystem. The attacker released a malicious version of 3 crates: → arrayref@0.3.10 → internment@0.8.7 → append-only-vec@0.1.9 Most notably is arrayref, a crate found in roughly 3/4 of Rust environments. The attacker installs a fake dependency: proc-macro1 → disguised as proc-macro2 When a developer compiles the project, the build script automatically downloads and runs a remote payload. No need to open a weird file. No need to click a phishing link. Just build the code. 💀 The payload can collect system information, maintain persistence, and target login/browser data. The malicious versions were removed after about 86 minutes, but during that window there was a significant amount of payload delivered. Even more notably, Wiz found that the campaign infrastructure shares substantial similarities with some supply-chain campaigns attributed to North Korean groups, though attribution still requires caution. Crypto devs: “ My wallet is safe because I use a hardware wallet.” Hacker: “ Cool. What about your laptop?” 💀 This is the scariest kind of supply-chain attack: You don’t need to trust the hacker. You just need to trust the dependency. Rust/Solana/Ethereum devs, check your lockfile and dependency tree right now. Do you still have arrayref in your project? 👀 #BrainrotCrypto #Hack
🚨 YOU DIDN’T RUN THE CODE. YOU JUST BUILT IT. 💀

A supply-chain attack has targeted the Rust ecosystem.
The attacker released a malicious version of 3 crates:

→ arrayref@0.3.10
→ internment@0.8.7
→ append-only-vec@0.1.9

Most notably is arrayref, a crate found in roughly 3/4 of Rust environments.

The attacker installs a fake dependency:

proc-macro1 → disguised as proc-macro2

When a developer compiles the project, the build script automatically downloads and runs a remote payload.
No need to open a weird file.
No need to click a phishing link.
Just build the code. 💀

The payload can collect system information, maintain persistence, and target login/browser data. The malicious versions were removed after about 86 minutes, but during that window there was a significant amount of payload delivered.

Even more notably, Wiz found that the campaign infrastructure shares substantial similarities with some supply-chain campaigns attributed to North Korean groups, though attribution still requires caution.

Crypto devs:
“ My wallet is safe because I use a hardware wallet.”
Hacker:
“ Cool. What about your laptop?” 💀

This is the scariest kind of supply-chain attack:
You don’t need to trust the hacker.
You just need to trust the dependency.
Rust/Solana/Ethereum devs, check your lockfile and dependency tree right now.

Do you still have arrayref in your project? 👀

#BrainrotCrypto #Hack
Coldcard Theft Investigation Advances 📢📢 Investigators are making progress on the massive Coldcard hardware wallet thefts that drained over 1,778 BTC (roughly $112 million) from thousands of addresses. Block’s engineering team and Galaxy Research have provided key leads to law enforcement, including tracing unusual on-chain patterns to a paid account at a major blockchain data provider linked to the first wave of attacks. Most of the stolen Bitcoin remains unmoved in attacker-controlled addresses. A reminder of the critical importance of hardware wallet security and proper seed generation. $BTC #Bitcoin #Coldcard #CoinVahini #Security #Hack
Coldcard Theft Investigation Advances 📢📢

Investigators are making progress on the massive Coldcard hardware wallet thefts that drained over 1,778 BTC (roughly $112 million) from thousands of addresses.

Block’s engineering team and Galaxy Research have provided key leads to law enforcement, including tracing unusual on-chain patterns to a paid account at a major blockchain data provider linked to the first wave of attacks. Most of the stolen Bitcoin remains unmoved in attacker-controlled addresses.

A reminder of the critical importance of hardware wallet security and proper seed generation.

$BTC #Bitcoin #Coldcard #CoinVahini #Security #Hack
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨 Crypto hacks hit a record pace in 2026 with 164 incidents and $1.2B stolen YTD, already surpassing every prior full year in number of attacks. #Hack #Hacked $BNB {future}(BNBUSDT)
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨

Crypto hacks hit a record pace in 2026 with 164 incidents and $1.2B stolen YTD, already surpassing every prior full year in number of attacks.

#Hack #Hacked
$BNB
A crypto wallet had already been hacked for $24.2M in 2023... and the attacker returned everything. This week they drained the SAME wallet again: $25.6M, now converted into DAI and ETH. No return. A ghost returning or a targeted hit? #Crypto #Hack #Whale
A crypto wallet had already been hacked for $24.2M in 2023... and the attacker returned everything.

This week they drained the SAME wallet again: $25.6M, now converted into DAI and ETH. No return.

A ghost returning or a targeted hit?

#Crypto #Hack #Whale
🚨 Mac users: update now. Your Mac could be mining Monero for someone else. 💀 Apple has patched CVE-2026-65400, a serious vulnerability in macOS Screen Sharing that is being exploited in the real world. According to the NCSC in the Netherlands: 🔓 Macs with port 5900 exposed to the Internet can be exploited by attackers 💻 The flaw allows unauthenticated connections to be treated as authenticated 👑 Attackers can gain root access ⛏️ Then they can install a Monero miner to use the victim’s CPU to mine XMR 🚨 CVSS: 9.8/10 Huntress has determined the issue lies in the Screen Sharing Secure Remote Password (SRP) process. Notably, changing the password or disabling legacy VNC is not enough to mitigate the vulnerability. Apple released patches on 6/8 for: 🍎 macOS Tahoe 26.6.1 🍎 Sequoia 15.7.9 🍎 Sonoma 14.8.9 You: “My Mac is just sitting there.” Hacker: “Perfect. Let’s make it mine a little.” 💀⛏️ If you don’t need Screen Sharing → turn it off. If you are using it → update macOS now, especially for bare-metal Mac machines that are being hosted. An unpatched Mac + a public port 5900 = a free Monero mining machine for hackers. 💀 Have you checked your Mac yet? 👀 #Hack #XMR
🚨 Mac users: update now. Your Mac could be mining Monero for someone else. 💀

Apple has patched CVE-2026-65400, a serious vulnerability in macOS Screen Sharing that is being exploited in the real world.

According to the NCSC in the Netherlands:
🔓 Macs with port 5900 exposed to the Internet can be exploited by attackers
💻 The flaw allows unauthenticated connections to be treated as authenticated
👑 Attackers can gain root access
⛏️ Then they can install a Monero miner to use the victim’s CPU to mine XMR
🚨 CVSS: 9.8/10

Huntress has determined the issue lies in the Screen Sharing Secure Remote Password (SRP) process. Notably, changing the password or disabling legacy VNC is not enough to mitigate the vulnerability.

Apple released patches on 6/8 for:
🍎 macOS Tahoe 26.6.1
🍎 Sequoia 15.7.9
🍎 Sonoma 14.8.9

You: “My Mac is just sitting there.”
Hacker: “Perfect. Let’s make it mine a little.” 💀⛏️

If you don’t need Screen Sharing → turn it off.
If you are using it → update macOS now, especially for bare-metal Mac machines that are being hosted.

An unpatched Mac + a public port 5900 = a free Monero mining machine for hackers. 💀

Have you checked your Mac yet? 👀

#Hack #XMR
Brainrot Labs
·
--
🚨 Your Mac might be mining Monero for a hacker. 💀

A hacker exploits a vulnerability in macOS Screen Sharing to take control of Macs exposed to the Internet, then installs a Monero miner.

What is a Monero miner?
👉 Software turns the victim’s CPU/GPU into a mining rig for $XMR .
👉 The machine must run continuous calculations → high CPU usage, overheating, loud fan noise, and reduced performance.
👉 The XMR earned flows to the hacker’s wallet, not the machine owner’s.
In simple terms:

Hacker: “Can I borrow your Mac?”
Mac: “For what?”
Hacker: “Mining Monero.” 💀

The vulnerability was patched by Apple in the update on August 6, but un-updated machines are still at risk. NCSC Netherlands said there have already been real-world attacks, and many targeted machines are Macs rented from hosting providers.

You bought a Mac.
The hacker bought Monero with your electricity. 💀

If you’re not using Screen Sharing, turn it off. If you are using it, update macOS immediately and check whether the service is directly exposed to the Internet. Apple also recommends keeping macOS on the latest version to maintain security.

Guys using Macs— is Screen Sharing turned on? 👀
#miners #Monero
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number