Financial Action Task Force Report | How to Understand and Address Gaming and Betting Risks
In September 2026, the Financial Action Task Force (FATF) released a special report, "Risks of Gaming and Gambling," which systematically analyzed the risks of money laundering, terrorist financing, and proliferation financing faced by casinos, sports betting, other betting, and online gaming. The value of this report lies not in categorizing all gaming and gambling activities as high-risk, but in revealing a more significant shift that virtual asset servicing institutions should pay attention to: as online platforms, cross-border transactions, and the integration of multiple products and payment methods occur, gaming and gambling platforms are becoming part of a broader value transfer ecosystem. For exchanges, VASPs, and virtual asset servicing institutions providing services such as crypto payments, funds from this ecosystem should not be understood merely as a "gambling transaction," but should be examined within the context of a complete financial relationship.
Joint Report Interpretation by Japan, the U.S., Australia, and Germany: Job-Application Phishing by the Hacker Group "WaterPlum" and Laptop Farms
On September 18, the Japanese National Police Agency, together with the National Cyber Bureau, as well as the U.S. FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate / Cyber Security Centre, Germany’s Federal Intelligence Service and the Federal Office for the Protection of the Constitution, issued a joint report in a six-party effort. The protagonists are a hacker group with a North Korean background—WaterPlum (also known as "Contagious Interview," literally "Disguised Interview"). This Contagious Interview attack activity has been tracked for years by multiple international security vendors, and it is often believed to be associated with North Korea’s Lazarus Group. This time, for the first time, Japanese police disclosed specific domestic cases and seized evidence under an official name, in cooperation with agencies from multiple countries.
Threat Intelligence | PolinRider Poisoned Nova, On-Chain Transactions Acting as a C2 Manager
Background The sample comes from a development branch of a Laravel Nova extension package, `visanduma/nova-two-factor`, which is associated with the PolinRider campaign. This is a PHP package published on Packagist; as of the time of this analysis, it has been downloaded more than 700,000 times. The delivery chain does not write the C2 address into the sample. The implanted code first queries Ethereum, extracts the IP addresses of two servers from the recipient addresses of a transaction, and then retrieves the next-stage payload via HTTP. To change servers, the attacker only needs to post a new transaction on-chain; there is no need to re-poison this package. The end point of this chain is a cross-platform credential stealer that collects browser accounts and cookies, encrypted wallet data, password manager databases, and development credentials.
Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Recently, the SlowMist security team received multiple reports that users’ assets were stolen. After verification, all the related incidents involved the leakage of private keys. Some affected users had downloaded and used the FomoPeek 1.1–1.2 App versions. Together with the OKX Security team, we jointly analyzed and confirmed that FomoPeek 1.1 and 1.2 implanted two malicious modules, apptrace and libapptracecore, which have the capabilities of remote configuration, kernel vulnerability exploitation, sandbox escape, Keychain decryption, and cross-app data collection. Dynamic verification shows that the app retrieves encrypted C2 addresses from Bitbucket, reports device information to api-a95f0ed200f.assisaint[.]com, and receives remote configurations. During testing, the C2 returned exploit_enabled as false. To verify the subsequent execution chain, in an isolated environment we used Hook to modify relevant switches after the client decrypted them to true. We then obtained a collection manifest targeting 19 wallets and note applications, and captured the full request for packaging and uploading the Apple Notes container.
Analysis of Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted out of Thin Air
Author: Johan & Lisa Edited by: 77 On September 6 at 13:52:10 UTC, two structurally identical transactions appeared in Liquid block #4,050,335. One minute later, block #4,050,336 confirmed a third transaction: approximately 3,998.5 L-BTC entered the UTXO set, with no peg-in behind it. A few minutes later, these nonexistent assets began to be consolidated and spent, and were then converted into real BTC on the Bitcoin mainnet via the federal peg-out channel. The next day, 3,400 BTC was returned to the federal peg wallet. The remaining 598.5 BTC stayed in the attacker’s hands, and as of the time of publication it was still being repeatedly self-transferred. Each transaction includes a segment of OP_RETURN plaintext, demanding from the federal authorities a tenth of a "bounty." Negotiations are still publicly taking place on-chain.
U.S. OFAC and DOJ Team Up to Crack Down on the Xinbi Guarantee, Over $52 Million in Crypto Assets Restricted
On September 9, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) and the U.S. Department of Justice (DOJ) announced a coordinated law-enforcement action targeting the Xinbi Guarantee. OFAC will list the Xinbi Guarantee and two companies that support its operations on its sanctions list, while the DOJ’s Scam Center Strike Force seized relevant platform infrastructure and cryptocurrency wallet assets. According to the DOJ announcement, the coordinated action restricted more than $52 million in cryptocurrency assets associated with the Xinbi Guarantee and its merchant network. This operation is not aimed at a single scammer group, but at the service network that supports the scam activities. U.S. law enforcement agencies say that the Xinbi guarantee connects scam groups with merchants that provide services such as money laundering and scam website development, and that it keeps these illicit transactions running by means including fund escrow and transaction guarantees.
The Vanishing Liability — Analysis of the Notional Finance Hack
Author: Jiujiu Edited: 77 Background On September 4, 2026, the well-known decentralized lending platform Notional Finance was attacked, resulting in a loss of approximately $1.73 million. The following is a detailed analysis of this attack by the SlowMist security team: Prerequisites In Notional Finance V1, fCash can be understood as cash debt with a maturity date. A cash receiver collects payment at maturity, while a cash payer makes payment at maturity. The protocol records both positions in the Portfolio, and then determines whether an account is healthy enough to open a position through a free collateral check.
Background A promotional page offering a free VPS, but in reality it is a lure. As shown by the archived public webpage, the event[.]polarnode[.]vip domain registered at the end of August 2026 designates https[:]//lk[.]wyincc[.]com/lk.js as a preloading script. Once the page becomes interactive, it automatically loads, without requiring visitors to click. After decoding the saved loader sample, we confirmed that it is designed for delivery to iPhones running pure Safari on iOS 18.4–18.6.2. Ultimately, it targets file access, Keychain, and keyboard input collection, with the goal of three wallet applications. This chain closely matches the DarkSword iOS exploit chain published by Google Threat Intelligence Group (GTIG), covering six CVEs and falling under n-day reuse.
From “who is depositing” to “where the money comes from”: the on-chain source-of-funds risk behind OKX’s risk-control strategy
Recently, OKX CEO responded to a user post stating that a gambling platform directly transfers funds to an exchange, causing deposits to trigger verification. According to his publicly stated comments, depositing to OKX from high-risk addresses may trigger more stringent anti-money laundering (AML) and risk reviews. Depending on the specific situation, the review may last 15 days or even longer; during this period, some account functions and funds may be restricted. For accounts confirmed to be involved in high-risk or illegal activities, the platform may also terminate service. https://x.com/star_okx/status/2094980124236251207 OKX also reminds that funds obtained through channels such as escrow trading via Telegram groups, Huiwang and its variants may involve a higher risk of the source of funds.
SlowMist: MistTrack & SlowMist KYT Partner Program Officially Launched
As crypto assets, stablecoin payments, and digital financial services continue to grow, on-chain AML, KYT, and fund risk analysis are becoming practical needs for an increasing number of institutions. For this purpose, MistTrack & SlowMist KYT officially launches a Partner Program, recruiting individual and institutional partners worldwide with resources in Web3, finance, payments, compliance, security, and local markets. After joining the program, you can receive: An exclusive customer discount code to help your customers subscribe at a more favorable price; Automatic order attribution and commission-rebate records, with a maximum commission rebate validity period of 3 years;
“Gray Rhinos” and “Black Swans”: Yu Xuan, founder of SlowMist, discusses security risks and protection in the crypto world
On August 28, at the Cypher Asia Intelligent Crypto Finance Summit, Yu Xuan, founder of SlowMist, delivered a keynote titled (Gray Rhinos and Black Swans in the Crypto World). He started with security issues commonly seen in the crypto space, systematically organized core risks such as funds being stolen, scammed, lost, and frozen, and shared his thoughts on security protection. The following is a整理 of现场 sharing content. In the world of encryption, it’s not uncommon for funds to be stolen, scammed, lost, or frozen. When many security incidents happen, they may seem like a sudden and unexpected event at first glance. But when you look back, many risks actually showed signs long before. The issue isn’t necessarily that people “don’t know risks exist,” but rather that the risks have already materialized without receiving enough attention, or that existing security measures haven’t truly been effective.
Event Recap | SlowMist Participated in Multiple Web3 Events in Hong Kong, Sharing Security and Compliance Practices
On August 28, SlowMist (SlowMist), together with ME Group, hosted an industry exchange event titled “Crossing the Mist to Trusted Payments | New Frontiers in Global Stablecoin Compliance and Agent-Based Payments,” and also participated in multiple industry exchanges including “Cypher Asia Intelligent Crypto Finance Summit” and the “AI x BTC - BTC Asia Side Event.” Centering on topics such as stablecoin compliance and payment applications, crypto security, and the foundational infrastructure of the digital economy, it shared practical experience and security perspectives with industry partners. Now, let’s take a look back at the highlights of the day— Focusing on stablecoin compliance and agent-based payments, exploring the building of trusted payments
Threat Intelligence|StealC Data-Stealing Chain Behind a Qwen Impersonation Repository
Background Download an open-source large model. The usual things you worry about are whether it runs properly and whether the weights are real. This time, the real concern is hidden elsewhere: a repository labeled with 27B parameters that, when it gets into your hands, only contains 487 KB—inside there are not weights, but a data-stealing trojan horse. On August 20, 2026, the GitHub repository unburdened-jackinthebox365/qwen38-uncensored submitted a file named uncensored_qwen_v2.6.zip to the assets/ directory. The file size was 487,153 bytes. The repository packaged it in a way that was almost airtight. The homepage claimed to provide locally quantized weights for Qwen 3.8 27B. The README emphasized fully offline operation, no telemetry, and that no data leaves your machine. Every line hit the exact concerns of local model users. Four days later, on August 24, the README was modified again—the download button, the download link in the body, and even the two external links that originally pointed to the Ollama and LM Studio official websites were all changed to point to the raw address of the same ZIP.
Countdown: 2 Days|SlowMist and ME Group’s Hong Kong Event Agenda Officially Announced
On August 28, SlowMist will partner with ME Group to host an industry exchange event in Hong Kong titled “Crossing the Mist to Trusted Payments: A New Frontier for Global Stablecoin Compliance and Agent-Based Payments.” This event will bring together industry guests from areas including stablecoins, payments, AI agents, compliance, and blockchain security. Through discussions focused on global stablecoin compliance, the development of agent-based payments, and the establishment of a trusted payments ecosystem, we will jointly explore the technical, security, and compliance challenges involved in the evolution of payment models. Time: August 28, 09:30 – 12:30 Location: CAI Building, Hong Kong
A cross-chain attack spanning a month: Analysis of the Allbridge hack
Author: Jiujiu Edited: 77 Background On August 19, 2026, the well-known cross-chain bridge project Allbridge was attacked, suffering a loss of approximately $190,000. However, this attack took nearly a month to complete. Below is a detailed analysis of this incident by the SlowMist Security team: Prerequisite knowledge To understand this attack, we first need to understand Circle’s CCTP protocol and its cross-chain message transfer system. CCTP is Circle’s cross-chain transfer protocol. Its basic approach is to destroy USDC on the source chain and then mint an equivalent amount of USDC on the destination chain. This avoids bridge contracts increasing balances out of thin air.
See you in Hong Kong on August 28|From Stablecoins to AI Agents, SlowMist Will Appear at Multiple Industry Events in Hong Kong
On August 28, Hong Kong will host multiple industry events focusing on stablecoins, intelligent agent payments, AI agents, and Bitcoin infrastructure. As a company dedicated to security in the blockchain ecosystem, SlowMist will host and participate in several events in Hong Kong. Drawing on its own security research and practical experience, it will communicate with industry partners on related topics. Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments Time: August 28, 09:30–12:30 Location: Hong Kong CAI Building Registration: https://luma.com/0c4fawzv On the morning of August 28, SlowMist will join forces with ME Group to host an industry exchange event in Hong Kong titled “Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments.” At the event, ecosystem partners from areas including stablecoins, payments, AI agents, compliance, and security will gather in Hong Kong to exchange ideas on global stablecoin compliance and applications, the technological evolution of agent-based payments, and the security-building of trusted payment systems.
Threat Intelligence|Beware of Targeted Poisoning of Web3 Developers by Solidity Pro
Background Solidity Pro is a VS Code extension for Solidity/Web3 developers. It is positioned as a development aid tool and offers features such as gas lookups, token prices, code snippets, and compilation hints. Its GitHub repository has also previously advertised security capabilities such as AI Audit and Security Scanner. In public events, Solidity Pro used two publishers—helper-beeps and web3devtoolsx—for the publisher identity, with Extension IDs (unique extension identifiers) of helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, respectively. Although the publishing identity changed, later build artifacts still retained the old publisher, repository address, and copyright information, indicating a direct engineering inheritance relationship between the two.
MistTrack Agent officially joins AgentOn, bringing on-chain investigation capabilities to AI Agents
Recently, MistTrack Agent, built by SlowMist, officially joined AgentOn as a third-party Agent. Focused on crypto AML and on-chain investigations, MistTrack Agent brings capabilities such as on-chain funds tracing and risk analysis to the AgentOn platform, providing users with a more efficient and automated way to conduct on-chain investigations. Welcome to MistTrack Agent: https://agenton.me/agent/market/external/fe204dba-05d1-49c8-8659-03ca24988185 🎁 Limited-time offer: Each user can enjoy 10 free calls, valid for 30 days. After the free call quota is used up or the validity period ends, charges will apply according to AgentOn’s standard pricing.
SlowMist × ME Group invites you to explore stablecoin compliance and agent-based payments together
The continuous development of digital asset and artificial intelligence technologies is driving payments into a new application stage. On the one hand, stablecoins are accelerating their move beyond on-chain scenarios and are being integrated into real business functions such as payments, settlements, and treasury management. On the other hand, AI Agents are gradually evolving from supporting tools into payment participants capable of representing users and enterprises to conduct inquiries, make decisions, call services, and even initiate transactions. As stablecoins move into real payment scenarios, how can compliance be truly implemented? As AI Agents begin to participate in transactions, how can secure and trustworthy transaction mechanisms be established? These have also become new issues the industry needs to address.
Coldcard $111 Million Theft Incident: In-depth Analysis of the Private Key Cracking Vulnerability
Author: Johan & Lisa Edit: 77 This article is co-created by humans and machines—you can reproduce it by importing the AI. Background On July 30, 2026, on-chain there was a batch of addresses that continuously transferred funds outward. Over 41 minutes, 1,196 single-sig addresses were emptied, with about 1,082 bitcoins disappearing. This was only the first wave. By early August, confirmed losses were at least 1,719 bitcoins—about $111 million—covering more than 5,200 addresses, and the attacker split the activity into three to four waves before and after the attack. What’s most puzzling is the state of these wallets. Most of the money sat in cold wallets; some had been untouched for months or even years. What was lost was the layer of the private key. All of the private keys were generated by the Coldcard hardware wallet; the owner hadn’t clicked the dice entropy additional times, nor had they enabled a BIP-39 passphrase. Victims were using the most effortless way of doing things.