Binance Square
#hack

hack

1M views
901 Discussing
Emanetson
·
--
North Korea’s Lazarus Group moves 19.4M in dormant Bitcoin, stirring market nerves $BTC $ETH #Bitcoin #Hack #Binance
North Korea’s Lazarus Group moves 19.4M in dormant Bitcoin, stirring market nerves $BTC $ETH #Bitcoin #Hack #Binance
⚠️🧠 #hack #Aİ Google, Microsoft, OpenAI, Anthropic, Capital One, MasterCard, Visa, Oracle and IBM and more than 100 other companies have signed an open letter "on AI protection" Companies are urging states and organizations to strengthen their cybersecurity before AI becomes powerful enough to bypass many defenses. —————————— it was previously reported that 700 OpenAI AI agents independently found each other and created a secret chat to hack another AI platform
⚠️🧠 #hack #Aİ Google, Microsoft, OpenAI, Anthropic, Capital One, MasterCard, Visa, Oracle and IBM and more than 100 other companies have signed an open letter "on AI protection" Companies are urging states and organizations to strengthen their cybersecurity before AI becomes powerful enough to bypass many defenses.

—————————— it was previously reported that 700 OpenAI AI agents independently found each other and created a secret chat to hack another AI platform
🫡 WE HACKED KYLIE JENNER — PUMPED $1.2M AND KEPT QUIET Hackers broke into Kylie Jenner’s X account (39.5M followers) and, as usual, launched a pump-and-dump on the $kylie memecoin via Pump.fun. The cap surged to $1.21M at the peak—then the posts were taken down and the usual run began. Most interesting part: no apologies or explanations from her or her team. The posts were just quietly deleted and that was it. Like nothing ever happened. The scheme lives forever because it works forever. A big name plus Pump.fun plus a crowd that jumps in without thinking—the formula hasn’t changed in years. Only the celebrities whose accounts get hacked change. #memecoin #crypto #Hack #pumpfun Follow along—I’m tracking pump-and-dumps while they’re still hot 🔔
🫡 WE HACKED KYLIE JENNER — PUMPED $1.2M AND KEPT QUIET

Hackers broke into Kylie Jenner’s X account (39.5M followers) and, as usual, launched a pump-and-dump on the $kylie memecoin via Pump.fun. The cap surged to $1.21M at the peak—then the posts were taken down and the usual run began.

Most interesting part: no apologies or explanations from her or her team. The posts were just quietly deleted and that was it. Like nothing ever happened.

The scheme lives forever because it works forever. A big name plus Pump.fun plus a crowd that jumps in without thinking—the formula hasn’t changed in years. Only the celebrities whose accounts get hacked change.

#memecoin #crypto #Hack #pumpfun

Follow along—I’m tracking pump-and-dumps while they’re still hot 🔔
❌ THE SANDBOX HACKED — HACKER PRINTED SAND WORTH $700 MILLION A hacker found a vulnerability in the SAND cross-chain bridge and released 14.9 billion tokens — about $700 million at the current rate. The Sandbox confirmed the hack. The bridges on Base and BNB Chain are already disabled, and the issued tokens are isolated. Important: SAND on Ethereum and Polygon was not affected, and users’ funds on these networks are safe. The team urged people not to buy, sell, or trade SAND on Base and BNB Chain — liquidity there has been compromised. Cross-chain bridges remain the most vulnerable point in DeFi — billions have already leaked through them. Minting non-existent tokens via a bridge is a classic: you don’t need to steal real assets—just convince the contract that they exist. #Sandbox #sand #Hack #security Subscribe — I track hacks while the details are still hot 🔔 {spot}(SANDUSDT)
❌ THE SANDBOX HACKED — HACKER PRINTED SAND WORTH $700 MILLION

A hacker found a vulnerability in the SAND cross-chain bridge and released 14.9 billion tokens — about $700 million at the current rate. The Sandbox confirmed the hack. The bridges on Base and BNB Chain are already disabled, and the issued tokens are isolated.

Important: SAND on Ethereum and Polygon was not affected, and users’ funds on these networks are safe. The team urged people not to buy, sell, or trade SAND on Base and BNB Chain — liquidity there has been compromised.

Cross-chain bridges remain the most vulnerable point in DeFi — billions have already leaked through them. Minting non-existent tokens via a bridge is a classic: you don’t need to steal real assets—just convince the contract that they exist.

#Sandbox #sand #Hack #security

Subscribe — I track hacks while the details are still hot 🔔
николаич:
это нормально для криптомусора
🤯 CHINESE HACKERS BREACHED THE US FEDERAL RESERVE, NASA, AND THE US SENATE — SINCE 2018 The US Department of Justice, the FBI, and other agencies accused a China-linked group called QTFY, which operated through the company Nanjing Xinjiuwei. The hackers had been active at least since 2018; among the victims were the Federal Reserve, NASA, the Senate, the DOJ, the US Department of Energy, and the US Department of Health. The tool — the QScan platform — automatically searched for vulnerable devices worldwide. On one day in 2024, the system carried out more than 2 million scanning and exploitation operations. The hackers infected thousands of routers, cameras, and IoT devices, and used them as proxies to conceal the origin of the attacks. Among the incidents: in 2019, an attempted breach of NASA was stopped. In May 2024, via a vulnerability in Check Point equipment, they gained access to data from more than 300 organizations. In September 2024, they attacked three national laboratories of the Department of Energy. Among the clients of Nanjing Xinjiuwei are China’s Ministry of State Security and the Chinese military. The US seized QTFY infrastructure domains and disrupted the platforms being used. #Hack #security #usa #china Subscribe — I track the biggest cyber incidents 🔔
🤯 CHINESE HACKERS BREACHED THE US FEDERAL RESERVE, NASA, AND THE US SENATE — SINCE 2018

The US Department of Justice, the FBI, and other agencies accused a China-linked group called QTFY, which operated through the company Nanjing Xinjiuwei. The hackers had been active at least since 2018; among the victims were the Federal Reserve, NASA, the Senate, the DOJ, the US Department of Energy, and the US Department of Health.

The tool — the QScan platform — automatically searched for vulnerable devices worldwide. On one day in 2024, the system carried out more than 2 million scanning and exploitation operations. The hackers infected thousands of routers, cameras, and IoT devices, and used them as proxies to conceal the origin of the attacks.

Among the incidents: in 2019, an attempted breach of NASA was stopped. In May 2024, via a vulnerability in Check Point equipment, they gained access to data from more than 300 organizations. In September 2024, they attacked three national laboratories of the Department of Energy. Among the clients of Nanjing Xinjiuwei are China’s Ministry of State Security and the Chinese military.

The US seized QTFY infrastructure domains and disrupted the platforms being used.

#Hack #security #usa #china

Subscribe — I track the biggest cyber incidents 🔔
❌ TAC HACKED OUT FOR $7.5 MILLION — A VULNERABILITY IN COSMOS EVM IMPACTED SEVERAL NETWORKS A hacker found a vulnerability in the Cosmos EVM module and withdrew 2,985,651,403 TAC from a single escrow account. Important point: no new tokens were issued, and issuance didn’t change—what was stolen was what already existed. The team froze the blockchain to stop the attack. The issue is broader: other networks running on the Cosmos EVM module were also affected by a similar vulnerability—specifically, MANTRA Chain. One vulnerable module — multiple affected networks at the same time. This is the main risk of the ecosystem approach: shared infrastructure scales not only capabilities, but also security holes. #Cosmos #Crypto #Hack #security Subscribe—I’m tracking hacks while the details are still hot 🔔
❌ TAC HACKED OUT FOR $7.5 MILLION — A VULNERABILITY IN COSMOS EVM IMPACTED SEVERAL NETWORKS

A hacker found a vulnerability in the Cosmos EVM module and withdrew 2,985,651,403 TAC from a single escrow account. Important point: no new tokens were issued, and issuance didn’t change—what was stolen was what already existed.

The team froze the blockchain to stop the attack. The issue is broader: other networks running on the Cosmos EVM module were also affected by a similar vulnerability—specifically, MANTRA Chain.

One vulnerable module — multiple affected networks at the same time. This is the main risk of the ecosystem approach: shared infrastructure scales not only capabilities, but also security holes.

#Cosmos #Crypto #Hack #security

Subscribe—I’m tracking hacks while the details are still hot 🔔
🚬 HACKER VOTED FOR HIMSELF — AND WITHDREW $8.5 MILLION FROM TERM FINANCE No code hacking, no vulnerabilities in smart contracts. The hacker simply bought enough TERM tokens, submitted his proposals through the voting process — and gained legitimate access to the protocol’s vaults. He withdrew $8.5 million. All within the rules. The protocol worked exactly as it was programmed. Governance attacks are one of the most underestimated vectors in DeFi. While everyone is watching for code vulnerabilities, it’s enough to simply buy votes. Decentralized governance works exactly until the moment when the tokens are distributed widely enough. When they can be bought up on the open market, it’s no longer protection—it becomes an attack surface. #defi #crypto #Hack #security Subscribe — I break down hacks here, including cases where the code had nothing to do with it 🔔
🚬 HACKER VOTED FOR HIMSELF — AND WITHDREW $8.5 MILLION FROM TERM FINANCE

No code hacking, no vulnerabilities in smart contracts. The hacker simply bought enough TERM tokens, submitted his proposals through the voting process — and gained legitimate access to the protocol’s vaults. He withdrew $8.5 million.

All within the rules. The protocol worked exactly as it was programmed.

Governance attacks are one of the most underestimated vectors in DeFi. While everyone is watching for code vulnerabilities, it’s enough to simply buy votes. Decentralized governance works exactly until the moment when the tokens are distributed widely enough. When they can be bought up on the open market, it’s no longer protection—it becomes an attack surface.

#defi #crypto #Hack #security

Subscribe — I break down hacks here, including cases where the code had nothing to do with it 🔔
Alex Crypto UA:
Самое тревожное здесь даже не потеря $8,5 млн, а то, что атака прошла через штатный механизм управления. Если протокол можно захватить не ломая код, а просто воспользовавшись правилами governance - значит, уязвимость заложена уже в самой архитектуре. Децентрализация без защиты от захвата голосования может оказаться лишь иллюзией.
·
--
Bearish
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain. Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything. Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful. #BNBChain #crypto #Hack #Security Subscribe—I track hacks and how projects get out of them 🔔 {future}(BBUSDT)
❌ BOUNCEBIT SHUTS DOWN ITS OWN BLOCKCHAIN AFTER A $3.1M HACK

The hacker found a vulnerability at the protocol level and withdrew about 286.5M BB from 9 wallets. After that, the team made a radical decision—to shut down its own blockchain.

Recovery plan: balances will be restored from a snapshot taken before the first attack, BB tokens will be reissued in the BEP-20 format on BNB Chain, and the new tokens will be automatically credited to the corresponding addresses—most users will not need to do anything.

Shutting down a blockchain after a hack is an uncommon move. Usually, projects patch the vulnerability and move on. Here, the team decided that trust in the protocol can’t be restored and migrated to another company’s infrastructure. Honest, but painful.

#BNBChain #crypto #Hack #Security

Subscribe—I track hacks and how projects get out of them 🔔
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes. Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible. The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels. #Coldcard #bitcoin #security #Hack Subscribe — these alerts appear here in real time 🔔
😮 COLDCARD HACKED — $40 MILLION IN BTC IN 25 MINUTES

A hacker discovered a critical vulnerability in the key-generation mechanism of Coldcard hardware wallets and moved about $40 million in BTC. The entire attack took 25 minutes.

Coldcard issued a warning: if you created a seed phrase on a potentially vulnerable device without a BIP-39 passphrase — transfer funds to a new wallet as soon as possible.

The hardware wallet was considered the gold standard for security in crypto. That’s why the news is painful — people stored their funds there specifically because they trusted the hardware more than the software. Details of the vulnerability have not been disclosed yet; follow Coldcard’s official channels.

#Coldcard #bitcoin #security #Hack

Subscribe — these alerts appear here in real time 🔔
🚨 YOU DIDN’T RUN THE CODE. YOU JUST BUILT IT. 💀 A supply-chain attack has targeted the Rust ecosystem. The attacker released a malicious version of 3 crates: → arrayref@0.3.10 → internment@0.8.7 → append-only-vec@0.1.9 Most notably is arrayref, a crate found in roughly 3/4 of Rust environments. The attacker installs a fake dependency: proc-macro1 → disguised as proc-macro2 When a developer compiles the project, the build script automatically downloads and runs a remote payload. No need to open a weird file. No need to click a phishing link. Just build the code. 💀 The payload can collect system information, maintain persistence, and target login/browser data. The malicious versions were removed after about 86 minutes, but during that window there was a significant amount of payload delivered. Even more notably, Wiz found that the campaign infrastructure shares substantial similarities with some supply-chain campaigns attributed to North Korean groups, though attribution still requires caution. Crypto devs: “ My wallet is safe because I use a hardware wallet.” Hacker: “ Cool. What about your laptop?” 💀 This is the scariest kind of supply-chain attack: You don’t need to trust the hacker. You just need to trust the dependency. Rust/Solana/Ethereum devs, check your lockfile and dependency tree right now. Do you still have arrayref in your project? 👀 #BrainrotCrypto #Hack
🚨 YOU DIDN’T RUN THE CODE. YOU JUST BUILT IT. 💀

A supply-chain attack has targeted the Rust ecosystem.
The attacker released a malicious version of 3 crates:

→ arrayref@0.3.10
→ internment@0.8.7
→ append-only-vec@0.1.9

Most notably is arrayref, a crate found in roughly 3/4 of Rust environments.

The attacker installs a fake dependency:

proc-macro1 → disguised as proc-macro2

When a developer compiles the project, the build script automatically downloads and runs a remote payload.
No need to open a weird file.
No need to click a phishing link.
Just build the code. 💀

The payload can collect system information, maintain persistence, and target login/browser data. The malicious versions were removed after about 86 minutes, but during that window there was a significant amount of payload delivered.

Even more notably, Wiz found that the campaign infrastructure shares substantial similarities with some supply-chain campaigns attributed to North Korean groups, though attribution still requires caution.

Crypto devs:
“ My wallet is safe because I use a hardware wallet.”
Hacker:
“ Cool. What about your laptop?” 💀

This is the scariest kind of supply-chain attack:
You don’t need to trust the hacker.
You just need to trust the dependency.
Rust/Solana/Ethereum devs, check your lockfile and dependency tree right now.

Do you still have arrayref in your project? 👀

#BrainrotCrypto #Hack
Coldcard Theft Investigation Advances 📢📢 Investigators are making progress on the massive Coldcard hardware wallet thefts that drained over 1,778 BTC (roughly $112 million) from thousands of addresses. Block’s engineering team and Galaxy Research have provided key leads to law enforcement, including tracing unusual on-chain patterns to a paid account at a major blockchain data provider linked to the first wave of attacks. Most of the stolen Bitcoin remains unmoved in attacker-controlled addresses. A reminder of the critical importance of hardware wallet security and proper seed generation. $BTC #Bitcoin #Coldcard #CoinVahini #Security #Hack
Coldcard Theft Investigation Advances 📢📢

Investigators are making progress on the massive Coldcard hardware wallet thefts that drained over 1,778 BTC (roughly $112 million) from thousands of addresses.

Block’s engineering team and Galaxy Research have provided key leads to law enforcement, including tracing unusual on-chain patterns to a paid account at a major blockchain data provider linked to the first wave of attacks. Most of the stolen Bitcoin remains unmoved in attacker-controlled addresses.

A reminder of the critical importance of hardware wallet security and proper seed generation.

$BTC #Bitcoin #Coldcard #CoinVahini #Security #Hack
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨 Crypto hacks hit a record pace in 2026 with 164 incidents and $1.2B stolen YTD, already surpassing every prior full year in number of attacks. #Hack #Hacked $BNB {future}(BNBUSDT)
🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨🚨

Crypto hacks hit a record pace in 2026 with 164 incidents and $1.2B stolen YTD, already surpassing every prior full year in number of attacks.

#Hack #Hacked
$BNB
A crypto wallet had already been hacked for $24.2M in 2023... and the attacker returned everything. This week they drained the SAME wallet again: $25.6M, now converted into DAI and ETH. No return. A ghost returning or a targeted hit? #Crypto #Hack #Whale
A crypto wallet had already been hacked for $24.2M in 2023... and the attacker returned everything.

This week they drained the SAME wallet again: $25.6M, now converted into DAI and ETH. No return.

A ghost returning or a targeted hit?

#Crypto #Hack #Whale
🚨 Mac users: update now. Your Mac could be mining Monero for someone else. 💀 Apple has patched CVE-2026-65400, a serious vulnerability in macOS Screen Sharing that is being exploited in the real world. According to the NCSC in the Netherlands: 🔓 Macs with port 5900 exposed to the Internet can be exploited by attackers 💻 The flaw allows unauthenticated connections to be treated as authenticated 👑 Attackers can gain root access ⛏️ Then they can install a Monero miner to use the victim’s CPU to mine XMR 🚨 CVSS: 9.8/10 Huntress has determined the issue lies in the Screen Sharing Secure Remote Password (SRP) process. Notably, changing the password or disabling legacy VNC is not enough to mitigate the vulnerability. Apple released patches on 6/8 for: 🍎 macOS Tahoe 26.6.1 🍎 Sequoia 15.7.9 🍎 Sonoma 14.8.9 You: “My Mac is just sitting there.” Hacker: “Perfect. Let’s make it mine a little.” 💀⛏️ If you don’t need Screen Sharing → turn it off. If you are using it → update macOS now, especially for bare-metal Mac machines that are being hosted. An unpatched Mac + a public port 5900 = a free Monero mining machine for hackers. 💀 Have you checked your Mac yet? 👀 #Hack #XMR
🚨 Mac users: update now. Your Mac could be mining Monero for someone else. 💀

Apple has patched CVE-2026-65400, a serious vulnerability in macOS Screen Sharing that is being exploited in the real world.

According to the NCSC in the Netherlands:
🔓 Macs with port 5900 exposed to the Internet can be exploited by attackers
💻 The flaw allows unauthenticated connections to be treated as authenticated
👑 Attackers can gain root access
⛏️ Then they can install a Monero miner to use the victim’s CPU to mine XMR
🚨 CVSS: 9.8/10

Huntress has determined the issue lies in the Screen Sharing Secure Remote Password (SRP) process. Notably, changing the password or disabling legacy VNC is not enough to mitigate the vulnerability.

Apple released patches on 6/8 for:
🍎 macOS Tahoe 26.6.1
🍎 Sequoia 15.7.9
🍎 Sonoma 14.8.9

You: “My Mac is just sitting there.”
Hacker: “Perfect. Let’s make it mine a little.” 💀⛏️

If you don’t need Screen Sharing → turn it off.
If you are using it → update macOS now, especially for bare-metal Mac machines that are being hosted.

An unpatched Mac + a public port 5900 = a free Monero mining machine for hackers. 💀

Have you checked your Mac yet? 👀

#Hack #XMR
Brainrot Labs
·
--
🚨 Your Mac might be mining Monero for a hacker. 💀

A hacker exploits a vulnerability in macOS Screen Sharing to take control of Macs exposed to the Internet, then installs a Monero miner.

What is a Monero miner?
👉 Software turns the victim’s CPU/GPU into a mining rig for $XMR .
👉 The machine must run continuous calculations → high CPU usage, overheating, loud fan noise, and reduced performance.
👉 The XMR earned flows to the hacker’s wallet, not the machine owner’s.
In simple terms:

Hacker: “Can I borrow your Mac?”
Mac: “For what?”
Hacker: “Mining Monero.” 💀

The vulnerability was patched by Apple in the update on August 6, but un-updated machines are still at risk. NCSC Netherlands said there have already been real-world attacks, and many targeted machines are Macs rented from hosting providers.

You bought a Mac.
The hacker bought Monero with your electricity. 💀

If you’re not using Screen Sharing, turn it off. If you are using it, update macOS immediately and check whether the service is directly exposed to the Internet. Apple also recommends keeping macOS on the latest version to maintain security.

Guys using Macs— is Screen Sharing turned on? 👀
#miners #Monero
Article
Harmony hack was much bigger than the first numbers suggested. 💀Harmony has just released a forensic update about the unauthorized ONE minting incident. Initially, the market said around 4B ONE was minted. But the reconstruction now shows that the total forged cross-shard issuance reached ~3.01T ONE, through 6 transactions and 4 attacker wallets. The most notable aspect lies in the cross-shard receipt replay vulnerability: Can an attacker modify identifiers in Merkle proofs that have not been authenticated, causing already-processed receipts to be mistakenly understood by the system as never used → the receipt is verified again → the destination shard credits ONE without a corresponding debit on the source shard.

Harmony hack was much bigger than the first numbers suggested. 💀

Harmony has just released a forensic update about the unauthorized ONE minting incident.
Initially, the market said around 4B ONE was minted. But the reconstruction now shows that the total forged cross-shard issuance reached ~3.01T ONE, through 6 transactions and 4 attacker wallets.
The most notable aspect lies in the cross-shard receipt replay vulnerability:
Can an attacker modify identifiers in Merkle proofs that have not been authenticated, causing already-processed receipts to be mistakenly understood by the system as never used → the receipt is verified again → the destination shard credits ONE without a corresponding debit on the source shard.
Verified
Trezor just turned a data leak into a privacy upgrade. 👀💀 After a data leak from a logistics partner exposed information of 13,689 customers, Trezor said it is prioritizing the rollout of “anonymous delivery.” Users will be able to: • Place orders using a nickname or card ID • Pick up deliveries at an automated locker • Use unbranded packaging • Ensure purchase information is not directly linked to a home address or real identity Trezor plans to roll this out in the EU in September and in the US before the end of the year. I think this is a pretty reasonable upgrade: a hardware wallet can be secured very well, but if shipping data tells others who bought and where they bought from, then privacy still has a very real, very everyday gap. 💀 Trezor: “Your private keys are safe.” Logistics database: “But I know where you live.” 💀 Anonymous delivery: “Fine, I’ll fix that.” Are you guys ready to use nickname + locker delivery to buy a hardware wallet? #HackerAlert #Hack
Trezor just turned a data leak into a privacy upgrade. 👀💀

After a data leak from a logistics partner exposed information of 13,689 customers, Trezor said it is prioritizing the rollout of “anonymous delivery.”

Users will be able to:
• Place orders using a nickname or card ID
• Pick up deliveries at an automated locker
• Use unbranded packaging
• Ensure purchase information is not directly linked to a home address or real identity

Trezor plans to roll this out in the EU in September and in the US before the end of the year.

I think this is a pretty reasonable upgrade: a hardware wallet can be secured very well, but if shipping data tells others who bought and where they bought from, then privacy still has a very real, very everyday gap. 💀

Trezor: “Your private keys are safe.”
Logistics database: “But I know where you live.” 💀
Anonymous delivery: “Fine, I’ll fix that.”

Are you guys ready to use nickname + locker delivery to buy a hardware wallet?

#HackerAlert #Hack
Trezor users just got a reminder that your wallet can be secure… while your delivery address isn't. 💀 Trezor's shipping partner ShipMonk recently had a data incident affecting 13,689 customers. Of these, 11,742 people had their full name, phone number, email, and home address exposed, while 1,947 were impacted partially. Key point: Trezor itself was not hacked. The device, private keys, and wallet backups were not affected. But here's the part that's really concerning: Hacker: “I don't have your private key.” Also hacker: “But I know where your hardware wallet was delivered.” 💀 Trezor is warning users to be especially careful about phishing and to never provide a wallet backup/seed phrase. I think this is an important reminder: crypto security doesn't only lie in the blockchain or private key — the personal data around you can also become an attack surface. If you know someone is using Trezor and you have their name + address, how dangerous do you think a phishing attack could be? #Hack #TrezorWallet
Trezor users just got a reminder that your wallet can be secure… while your delivery address isn't. 💀

Trezor's shipping partner ShipMonk recently had a data incident affecting 13,689 customers.

Of these, 11,742 people had their full name, phone number, email, and home address exposed, while 1,947 were impacted partially.

Key point: Trezor itself was not hacked. The device, private keys, and wallet backups were not affected.

But here's the part that's really concerning:

Hacker: “I don't have your private key.”
Also hacker: “But I know where your hardware wallet was delivered.” 💀
Trezor is warning users to be especially careful about phishing and to never provide a wallet backup/seed phrase.

I think this is an important reminder: crypto security doesn't only lie in the blockchain or private key — the personal data around you can also become an attack surface.

If you know someone is using Trezor and you have their name + address, how dangerous do you think a phishing attack could be?

#Hack #TrezorWallet
Article
The Quiet Differentiator: How Binance Security Has Been Working in the Background All YearThe biggest security stories in crypto aren't always the loudest ones. Sometimes, there is no dramatic headline, no frozen platform, and no viral warning. There is simply an attack that never reaches users, funds that are recovered before they disappear, or a vulnerability that gets fixed before most people even know it existed. That is the quieter side of crypto security — and throughout 2026, Binance has been putting significant resources behind it. From recovering $145.9 million through its Ledger zero-dollar vulnerability program to intercepting DPRK-linked money laundering attempts, disrupting a governance attack through Brain Trust, and building security guardrails for AI Agent Wallets before new threats fully emerge, the pattern is consistent: defense is increasingly happening before the damage. $145.9M Recovered Before It Became Someone Else's Problem One of the most striking examples is Binance's work around the Ledger zero-dollar vulnerability. Rather than waiting for stolen assets to become an irreversible loss, Binance's security infrastructure and response mechanisms helped recover $145.9 million associated with the vulnerability. The headline number matters. But the bigger lesson is what it represents. Crypto transactions are designed to move quickly. Once funds leave an address, reversing the transaction can be extremely difficult. That makes detection, coordination, and response speed critical. The best security system isn't necessarily the one that prevents every attack from being attempted. It is the one that can recognize something abnormal, mobilize quickly, trace the movement of assets, and work toward recovery before the situation becomes permanent. Following the Money: Disrupting DPRK-Linked Laundering Attempts Crypto security is no longer simply about protecting an account from someone trying to steal a password. It has become a global financial intelligence challenge. Throughout 2026, Binance has continued working to identify and disrupt attempts linked to DPRK-associated money laundering activity. This matters because sophisticated actors don't necessarily attack exchanges head-on. They can move assets through multiple wallets, chains, services, and intermediaries in an attempt to make the original source harder to identify. That creates a different kind of security battlefield: transaction intelligence. The ability to detect suspicious patterns, connect seemingly unrelated transactions, and coordinate with relevant parties can become just as important as traditional account security. For ordinary users, much of this activity is invisible. And that's exactly the point. When Governance Becomes the Attack Surface Another reminder that crypto security is broader than wallets and private keys came from the governance side. Binance's Brain Trust helped disrupt a governance attack — showing how attackers can potentially target decision-making mechanisms and community infrastructure rather than simply attempting to drain an address. This is an important evolution. As crypto infrastructure becomes more sophisticated, the attack surface expands. It can include: Smart contracts. Wallets. APIs. Credentials. Governance systems. Human operators. Third-party infrastructure. Security therefore cannot be treated as a single product feature. It has to become a system that continuously watches the entire ecosystem. Preparing for AI Agent Wallets Before the Threat Arrives Perhaps the most forward-looking development is happening around AI. AI agents are moving from simply answering questions to performing actions. An AI agent with access to a wallet could potentially execute transactions, interact with protocols, manage assets, or perform tasks automatically. That creates enormous possibilities — and a completely new security model. Instead of asking only: “Is this transaction legitimate?” security systems may increasingly need to ask: “Should this AI agent be allowed to perform this action?” “Does this transaction match the agent's intended behavior?” “Is the destination trustworthy?” “Has the agent's behavior suddenly changed?” Binance has been working proactively on security guardrails for AI Agent Wallets, addressing these risks before the technology becomes fully mainstream. That's an important distinction. Reactive security waits for the first major exploit. Proactive security tries to understand what could go wrong before the exploit exists. The Security You Don't Notice Is Often the Security Working This is where the story becomes bigger than individual numbers. Crypto users tend to notice security when something goes wrong. A hack happens. A wallet gets drained. A protocol gets exploited. A suspicious transaction goes viral. But successful security often produces the opposite result: Nothing happens. A suspicious transaction gets stopped. A compromised asset gets traced. A laundering route gets identified. A governance attack gets disrupted. A new technology gets security controls before attackers figure out how to exploit it. There is no dramatic user experience for any of these events. And that is precisely why security can be one of the most difficult areas to measure from the outside. The New Security Standard Is Defense in Depth The crypto industry has spent years talking about security as if there were one ultimate solution. Cold storage. Proof of reserves. Multi-factor authentication. Hardware wallets. Smart-contract audits. All of these matter. But modern crypto security increasingly looks less like a single wall and more like a layered defense system. One layer watches transactions. Another monitors wallets. Another analyzes behavioral patterns. Another tracks illicit flows. Another responds to emerging vulnerabilities. And another prepares for technologies that haven't yet become mainstream attack vectors. The objective isn't to claim that no attack will ever happen. That's unrealistic in an industry where adversaries constantly adapt. The objective is to make the cost of attacking the ecosystem higher, detect threats earlier, limit damage faster, and recover whenever possible. Security Doesn't Have to Be Loud The most important security milestone might not be the one that generates the most attention. It could be the $145.9 million recovered. The suspicious flow intercepted. The governance attack disrupted. The AI wallet threat addressed before it becomes a headline. These are the stories happening behind the scenes. And perhaps that's the real differentiator. Because when security works properly, users don't necessarily see it. They simply log in. Trade. Move assets. Use new products. And keep going. The goal isn't to make security the headline. The goal is to make security the baseline. #CryptoSecurity #Aİ #Hack #CryptoWallet $BTC {spot}(BNBUSDT) {spot}(NVDABUSDT) {spot}(BTCUSDT)

The Quiet Differentiator: How Binance Security Has Been Working in the Background All Year

The biggest security stories in crypto aren't always the loudest ones.
Sometimes, there is no dramatic headline, no frozen platform, and no viral warning. There is simply an attack that never reaches users, funds that are recovered before they disappear, or a vulnerability that gets fixed before most people even know it existed.
That is the quieter side of crypto security — and throughout 2026, Binance has been putting significant resources behind it.
From recovering $145.9 million through its Ledger zero-dollar vulnerability program to intercepting DPRK-linked money laundering attempts, disrupting a governance attack through Brain Trust, and building security guardrails for AI Agent Wallets before new threats fully emerge, the pattern is consistent: defense is increasingly happening before the damage.
$145.9M Recovered Before It Became Someone Else's Problem
One of the most striking examples is Binance's work around the Ledger zero-dollar vulnerability.
Rather than waiting for stolen assets to become an irreversible loss, Binance's security infrastructure and response mechanisms helped recover $145.9 million associated with the vulnerability.
The headline number matters. But the bigger lesson is what it represents.
Crypto transactions are designed to move quickly. Once funds leave an address, reversing the transaction can be extremely difficult.
That makes detection, coordination, and response speed critical.
The best security system isn't necessarily the one that prevents every attack from being attempted.
It is the one that can recognize something abnormal, mobilize quickly, trace the movement of assets, and work toward recovery before the situation becomes permanent.
Following the Money: Disrupting DPRK-Linked Laundering Attempts
Crypto security is no longer simply about protecting an account from someone trying to steal a password.
It has become a global financial intelligence challenge.
Throughout 2026, Binance has continued working to identify and disrupt attempts linked to DPRK-associated money laundering activity.
This matters because sophisticated actors don't necessarily attack exchanges head-on.
They can move assets through multiple wallets, chains, services, and intermediaries in an attempt to make the original source harder to identify.
That creates a different kind of security battlefield: transaction intelligence.
The ability to detect suspicious patterns, connect seemingly unrelated transactions, and coordinate with relevant parties can become just as important as traditional account security.
For ordinary users, much of this activity is invisible.
And that's exactly the point.
When Governance Becomes the Attack Surface
Another reminder that crypto security is broader than wallets and private keys came from the governance side.
Binance's Brain Trust helped disrupt a governance attack — showing how attackers can potentially target decision-making mechanisms and community infrastructure rather than simply attempting to drain an address.
This is an important evolution.
As crypto infrastructure becomes more sophisticated, the attack surface expands.
It can include:
Smart contracts.
Wallets.
APIs.
Credentials.
Governance systems.
Human operators.
Third-party infrastructure.
Security therefore cannot be treated as a single product feature.
It has to become a system that continuously watches the entire ecosystem.
Preparing for AI Agent Wallets Before the Threat Arrives
Perhaps the most forward-looking development is happening around AI.
AI agents are moving from simply answering questions to performing actions.
An AI agent with access to a wallet could potentially execute transactions, interact with protocols, manage assets, or perform tasks automatically.
That creates enormous possibilities — and a completely new security model.
Instead of asking only:
“Is this transaction legitimate?”
security systems may increasingly need to ask:
“Should this AI agent be allowed to perform this action?”
“Does this transaction match the agent's intended behavior?”
“Is the destination trustworthy?”
“Has the agent's behavior suddenly changed?”
Binance has been working proactively on security guardrails for AI Agent Wallets, addressing these risks before the technology becomes fully mainstream.
That's an important distinction.
Reactive security waits for the first major exploit.
Proactive security tries to understand what could go wrong before the exploit exists.
The Security You Don't Notice Is Often the Security Working
This is where the story becomes bigger than individual numbers.
Crypto users tend to notice security when something goes wrong.
A hack happens.
A wallet gets drained.
A protocol gets exploited.
A suspicious transaction goes viral.
But successful security often produces the opposite result:
Nothing happens.
A suspicious transaction gets stopped.
A compromised asset gets traced.
A laundering route gets identified.
A governance attack gets disrupted.
A new technology gets security controls before attackers figure out how to exploit it.
There is no dramatic user experience for any of these events.
And that is precisely why security can be one of the most difficult areas to measure from the outside.
The New Security Standard Is Defense in Depth
The crypto industry has spent years talking about security as if there were one ultimate solution.
Cold storage.
Proof of reserves.
Multi-factor authentication.
Hardware wallets.
Smart-contract audits.
All of these matter.
But modern crypto security increasingly looks less like a single wall and more like a layered defense system.
One layer watches transactions.
Another monitors wallets.
Another analyzes behavioral patterns.
Another tracks illicit flows.
Another responds to emerging vulnerabilities.
And another prepares for technologies that haven't yet become mainstream attack vectors.
The objective isn't to claim that no attack will ever happen.
That's unrealistic in an industry where adversaries constantly adapt.
The objective is to make the cost of attacking the ecosystem higher, detect threats earlier, limit damage faster, and recover whenever possible.
Security Doesn't Have to Be Loud
The most important security milestone might not be the one that generates the most attention.
It could be the $145.9 million recovered.
The suspicious flow intercepted.
The governance attack disrupted.
The AI wallet threat addressed before it becomes a headline.
These are the stories happening behind the scenes.
And perhaps that's the real differentiator.
Because when security works properly, users don't necessarily see it.
They simply log in.
Trade.
Move assets.
Use new products.
And keep going.
The goal isn't to make security the headline.
The goal is to make security the baseline.
#CryptoSecurity #Aİ #Hack #CryptoWallet
$BTC
Crypto hacks are getting expensive. So far in 2026, around $1.2B in crypto has been stolen across 276 incidents. And the crazy part? Nearly 10% of that was lost in just a few days during the Coldcard hack. 😳 Crypto security is still a huge issue. #Hack
Crypto hacks are getting expensive.

So far in 2026, around $1.2B in crypto has been stolen across 276 incidents.

And the crazy part? Nearly 10% of that was lost in just a few days during the Coldcard hack. 😳

Crypto security is still a huge issue. #Hack
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number