Binance Square
#hack

hack

1M views
851 Discussing
Sika4
·
--
A shocking security breach has rocked the Bitcoin community as a Canadian entrepreneur lost $1.6M in BTC from a Coldcard hardware wallet in just seven minutes. This incident, potentially part of a larger attack totaling 1,367 BTC, raises serious questions about cold storage security. While hardware wallets are considered the gold standard for crypto security, this breach demonstrates that even the most secure solutions can be vulnerable. The market may react to this news with increased caution, particularly around self-custody solutions. Traders should watch for any impact on BTC price and broader market sentiment toward storage solutions. This event serves as a stark reminder of the importance of security in crypto asset management. #Bitcoin #BTC #Hack #Security
A shocking security breach has rocked the Bitcoin community as a Canadian entrepreneur lost $1.6M in BTC from a Coldcard hardware wallet in just seven minutes. This incident, potentially part of a larger attack totaling 1,367 BTC, raises serious questions about cold storage security. While hardware wallets are considered the gold standard for crypto security, this breach demonstrates that even the most secure solutions can be vulnerable. The market may react to this news with increased caution, particularly around self-custody solutions. Traders should watch for any impact on BTC price and broader market sentiment toward storage solutions. This event serves as a stark reminder of the importance of security in crypto asset management.

#Bitcoin #BTC #Hack #Security
硬件钱包被爆漏洞!8900万美元BTC被盗吓坏散户 💡 利空📉:硬件钱包失窃引发信任危机,散户恐慌可能转砸盘。 Coldcard硬件钱包出事了,黑客直接利用固件漏洞,从几千个钱包里洗走了8900万美元的BTC。 说白了,大家买硬件钱包就是为了图个安全,结果冷钱包的固件代码有漏洞,直接被黑客端了老巢。这波被盗涉及几千个地址,总额高达8900万美元。黑客找到底层固件的漏洞绕过了安全机制,这笔巨量BTC目前大概率正在被黑客通过各种混币器分散洗白。 短期内,这事对市场情绪是个直接打击。BTC今天本身就在跌,当前报价$62,932.4,24小时跌了0.82%。现在冷钱包暴雷,现货市场大概率会出现恐慌性抛售,避险情绪急速升温。很多刚入场的新韭菜会被吓得不轻,甚至可能直接割肉提现。 中期来看,原文说得好,这事会引发行业信任大转移。既然硬件钱包都不安全,大资金可能会把BTC重新存回头部中心化交易所(CEX),毕竟大平台的资产安全和风控体系比小厂硬件强得多。另外,这种级别的安全事故,大概率会招来更严格的监管审查。 讲真,现在这盘面本来就弱,ETH也跟着遭殃,24小时跌0.92%到了$1,859.44。冷钱包暴雷这种突发黑天鹅,短时间会加剧空头情绪。我的建议很直接:别去接飞刀,BTC接下来12小时内大概率要测试下方的支撑位。如果$62,000这个整数关口守不住,下方空间还会被打开,现货建议多看少动。没仓位的耐心等企稳信号,别盲目进去抄底。 - 币种:BTC - 方向:利空📉 预测跌 - 时长:12小时 点赞收藏,遇到黑天鹅行情时翻出来看看,提醒自己少动手。 $BTC $ETH #BTC #ETH 📊 历史回测 - 类似「衰退担忧下,比特币资金流出4亿美元」(2024-08-05) 发布后 BTC 12h 涨跌 +2.16%,预判看跌❌错误 - 历史BTC看跌类新闻共136条,其中64条预判方向与实际走势一致(准确率47%) #Hack ⚠️ 不构成投资建议
硬件钱包被爆漏洞!8900万美元BTC被盗吓坏散户

💡 利空📉:硬件钱包失窃引发信任危机,散户恐慌可能转砸盘。

Coldcard硬件钱包出事了,黑客直接利用固件漏洞,从几千个钱包里洗走了8900万美元的BTC。

说白了,大家买硬件钱包就是为了图个安全,结果冷钱包的固件代码有漏洞,直接被黑客端了老巢。这波被盗涉及几千个地址,总额高达8900万美元。黑客找到底层固件的漏洞绕过了安全机制,这笔巨量BTC目前大概率正在被黑客通过各种混币器分散洗白。

短期内,这事对市场情绪是个直接打击。BTC今天本身就在跌,当前报价$62,932.4,24小时跌了0.82%。现在冷钱包暴雷,现货市场大概率会出现恐慌性抛售,避险情绪急速升温。很多刚入场的新韭菜会被吓得不轻,甚至可能直接割肉提现。

中期来看,原文说得好,这事会引发行业信任大转移。既然硬件钱包都不安全,大资金可能会把BTC重新存回头部中心化交易所(CEX),毕竟大平台的资产安全和风控体系比小厂硬件强得多。另外,这种级别的安全事故,大概率会招来更严格的监管审查。

讲真,现在这盘面本来就弱,ETH也跟着遭殃,24小时跌0.92%到了$1,859.44。冷钱包暴雷这种突发黑天鹅,短时间会加剧空头情绪。我的建议很直接:别去接飞刀,BTC接下来12小时内大概率要测试下方的支撑位。如果$62,000这个整数关口守不住,下方空间还会被打开,现货建议多看少动。没仓位的耐心等企稳信号,别盲目进去抄底。

- 币种:BTC
- 方向:利空📉 预测跌
- 时长:12小时

点赞收藏,遇到黑天鹅行情时翻出来看看,提醒自己少动手。

$BTC $ETH #BTC #ETH

📊 历史回测
- 类似「衰退担忧下,比特币资金流出4亿美元」(2024-08-05) 发布后 BTC 12h 涨跌 +2.16%,预判看跌❌错误
- 历史BTC看跌类新闻共136条,其中64条预判方向与实际走势一致(准确率47%)

#Hack

⚠️ 不构成投资建议
·
--
Bearish
🚨 US$ 38 Milhões Drenados e o Dilema da Autocustódia: O que aprender com o caso Coldcard? Uma das falhas mais comentadas do ano acendeu um alerta vermelho para quem usa hardware wallets. Um erro no firmware da Coldcard afetou a geração de aleatoriedade (RNG) na criação de seeds BIP-39, permitindo que atacantes recreassem chaves privadas via força bruta e levassem quase 600 BTCs. A Coinkite já lançou a correção, mas fica o aviso crucial: atualizar o firmware NÃO protege uma seed que nasceu vulnerável. É preciso gerar uma nova carteira no firmware atualizado e migrar os fundos. 💡 3 Lições Rápidas para a Sua Segurança: 1️⃣ Autocustódia é processo, não um evento: Não existe o conceito de "configurar e esquecer para sempre". Acompanhe os avisos de segurança do fabricante dos seus dispositivos. 2️⃣ Entenda os riscos: Ao sair das corretoras para evitar o risco de contraparte, você assume o risco de hardware, software, backup e OPSEC. Avalie se você tem estrutura para essa gestão. 3️⃣ Atenção aos updates: Se a vulnerabilidade estiver na origem da chave (geração da seed), você obrigatoriamente precisa criar um novo cofre e mover os ativos. Segurança em primeiro lugar, sempre! 🛡️ E você: prefere a responsabilidade total da autocustódia, prefere diversificar em corretoras ou usa uma estratégia mista? Deixe nos comentários! 👇 #Security #Coldcard #SelfCustody #Hack
🚨 US$ 38 Milhões Drenados e o Dilema da Autocustódia: O que aprender com o caso Coldcard?

Uma das falhas mais comentadas do ano acendeu um alerta vermelho para quem usa hardware wallets. Um erro no firmware da Coldcard afetou a geração de aleatoriedade (RNG) na criação de seeds BIP-39, permitindo que atacantes recreassem chaves privadas via força bruta e levassem quase 600 BTCs.

A Coinkite já lançou a correção, mas fica o aviso crucial: atualizar o firmware NÃO protege uma seed que nasceu vulnerável. É preciso gerar uma nova carteira no firmware atualizado e migrar os fundos.

💡 3 Lições Rápidas para a Sua Segurança:

1️⃣ Autocustódia é processo, não um evento: Não existe o conceito de "configurar e esquecer para sempre". Acompanhe os avisos de segurança do fabricante dos seus dispositivos.
2️⃣ Entenda os riscos: Ao sair das corretoras para evitar o risco de contraparte, você assume o risco de hardware, software, backup e OPSEC. Avalie se você tem estrutura para essa gestão.
3️⃣ Atenção aos updates: Se a vulnerabilidade estiver na origem da chave (geração da seed), você obrigatoriamente precisa criar um novo cofre e mover os ativos.

Segurança em primeiro lugar, sempre! 🛡️

E você: prefere a responsabilidade total da autocustódia, prefere diversificar em corretoras ou usa uma estratégia mista? Deixe nos comentários! 👇

#Security #Coldcard #SelfCustody #Hack
Triple-A Suffers $9.7M Multi-Chain Hot Wallet Exploit On-chain analysts have reported that crypto payments company Triple-A has suffered a major hot wallet exploit, resulting in approximately $9.7 million in stolen assets. The attacker reportedly drained funds across Ethereum, TRON, Polygon, and Arbitrum, then bridged and consolidated them into a single Ethereum wallet holding over 5,227 ETH. ⚠️ Even more concerning, analysts claim deposits were still active hours after the exploit, potentially exposing additional user funds. At the time of writing, Triple-A has not issued an official statement confirming the incident or outlining recovery plans. 🔍 Investors should closely monitor: • Official response from Triple-A • Deposit suspension updates • Customer compensation plans • Ongoing blockchain investigations Always protect your assets and DYOR (Do Your Own Research). #Crypto #Bitcoin #Ethereum #TRON #Polygon #Arbitrum #Web3 #Blockchain #Security #Hack
Triple-A Suffers $9.7M Multi-Chain Hot Wallet Exploit
On-chain analysts have reported that crypto payments company Triple-A has suffered a major hot wallet exploit, resulting in approximately $9.7 million in stolen assets.
The attacker reportedly drained funds across Ethereum, TRON, Polygon, and Arbitrum, then bridged and consolidated them into a single Ethereum wallet holding over 5,227 ETH.
⚠️ Even more concerning, analysts claim deposits were still active hours after the exploit, potentially exposing additional user funds.
At the time of writing, Triple-A has not issued an official statement confirming the incident or outlining recovery plans.
🔍 Investors should closely monitor:
• Official response from Triple-A
• Deposit suspension updates
• Customer compensation plans
• Ongoing blockchain investigations
Always protect your assets and DYOR (Do Your Own Research).
#Crypto #Bitcoin #Ethereum #TRON #Polygon #Arbitrum #Web3 #Blockchain #Security #Hack
🚨 Can Bitcoin Really Be Hacked? Most People Get This Wrong.🚨 Can Bitcoin Really Be Hacked? Most People Get This Wrong. Every time cryptocurrency makes the news, you’ll hear someone say: “Bitcoin was hacked.” But here’s the twist… The Bitcoin blockchain itself has never been successfully hacked. So why do people keep losing millions of dollars worth of Bitcoin? The answer has very little to do with Bitcoin itself. 🔍 The Difference Most Beginners Miss Imagine you own the world’s strongest vault. The vault is impossible to break into. But one day, you accidentally hand your key to a stranger. Did they hack the vault? No. They simply used your key. This is exactly how most crypto theft happens. The blockchain remains secure, but users are tricked into giving away access to their wallets. 🛡️ So What Actually Gets Hacked? Most cryptocurrency losses happen because of: Fake investment websites Phishing emails and messagesFake wallet appsMalware on personal devicesSharing a private key or seed phraseSending funds to the wrong address Notice something? Almost every attack targets people—not Bitcoin. 💡 Why Is Bitcoin So Secure? Bitcoin is protected by: ✅ Advanced cryptography ✅ Thousands of independent computers around the world ✅ A decentralized consensus system ✅ Open-source code reviewed by developers globally To change Bitcoin’s transaction history, an attacker would need to control an enormous portion of the network’s computing power—something considered practically infeasible at Bitcoin’s current scale. 🎯 The Real Lesson Learning about Bitcoin isn’t enough. Learning how to protect yourself is just as important. The strongest blockchain in the world can’t protect someone who willingly shares their wallet’s secret recovery phrase. Security starts with you. 🔑 Key Takeaway Bitcoin’s blockchain is designed to be highly secure. Most cryptocurrency theft happens because scammers exploit human mistakes—not weaknesses in the blockchain. 📚 Continue Learning Want to dive deeper? These trusted resources explain today’s topic in more detail: Bitcoin Whitepaper: https://bitcoin.org/bitcoin.pdfBitcoin.org – Security & Wallet Guides: https://bitcoin.orgBinance Academy – Crypto Security: [https://academy.binance.com](https://academy.binance.com)CoinMarketCap Alexandria: https://coinmarketcap.com/alexandria 💬 Question for You If someone offered you 1 Bitcoin today, where would you store it? A centralized exchange?A hardware wallet?A mobile wallet? Tell us why in the comments. Your answer might help another beginner stay safe. Stay Curious. Chain Curious Unlimited Days of Blockchain Knowledge. #Hack #BTC #Binance #Vault #ChainCurious

🚨 Can Bitcoin Really Be Hacked? Most People Get This Wrong.

🚨 Can Bitcoin Really Be Hacked? Most People Get This Wrong.
Every time cryptocurrency makes the news, you’ll hear someone say:
“Bitcoin was hacked.” But here’s the twist…
The Bitcoin blockchain itself has never been successfully hacked.
So why do people keep losing millions of dollars worth of Bitcoin?
The answer has very little to do with Bitcoin itself.
🔍 The Difference Most Beginners Miss
Imagine you own the world’s strongest vault.
The vault is impossible to break into.
But one day, you accidentally hand your key to a stranger.
Did they hack the vault? No.
They simply used your key.
This is exactly how most crypto theft happens.
The blockchain remains secure, but users are tricked into giving away access to their wallets.
🛡️ So What Actually Gets Hacked?
Most cryptocurrency losses happen because of:
Fake investment websites
Phishing emails and messagesFake wallet appsMalware on personal devicesSharing a private key or seed phraseSending funds to the wrong address
Notice something?
Almost every attack targets people—not Bitcoin.
💡 Why Is Bitcoin So Secure?
Bitcoin is protected by:
✅ Advanced cryptography
✅ Thousands of independent computers around the world
✅ A decentralized consensus system
✅ Open-source code reviewed by developers globally
To change Bitcoin’s transaction history, an attacker would need to control an enormous portion of the network’s computing power—something considered practically infeasible at Bitcoin’s current scale.
🎯 The Real Lesson
Learning about Bitcoin isn’t enough.
Learning how to protect yourself is just as important.
The strongest blockchain in the world can’t protect someone who willingly shares their wallet’s secret recovery phrase.
Security starts with you.
🔑 Key Takeaway
Bitcoin’s blockchain is designed to be highly secure. Most cryptocurrency theft happens because scammers exploit human mistakes—not weaknesses in the blockchain.
📚 Continue Learning
Want to dive deeper? These trusted resources explain today’s topic in more detail:
Bitcoin Whitepaper: https://bitcoin.org/bitcoin.pdfBitcoin.org – Security & Wallet Guides: https://bitcoin.orgBinance Academy – Crypto Security: https://academy.binance.comCoinMarketCap Alexandria: https://coinmarketcap.com/alexandria
💬 Question for You
If someone offered you 1 Bitcoin today, where would you store it?
A centralized exchange?A hardware wallet?A mobile wallet?
Tell us why in the comments. Your answer might help another beginner stay safe.
Stay Curious.
Chain Curious
Unlimited Days of Blockchain Knowledge.
#Hack #BTC #Binance #Vault #ChainCurious
🚨 $35.5M DEVI HACKS HIT $BANK AND $RIF – LIQUIDITY BLOODBATH! 💥 Three major exploits in 48 hours – AFX Trade, Verus, and B² Network drained for $35.5M. Attackers ripped through bridges and contracts like wet paper. 🦈 Smart money is already front-running the fear dump; watch for sharp wicks on DeFi altcoins. 📊 This is a classic split: some camps scream for regulation, others see a red carpet for security-first protocols. The market will digest this as a shakeout. Weak hands panic-sell; sharp traders fish for oversold bounces on $BANK and $RIF . 💡 The real play? Wait for the liquidity sweep below recent support then bid aggressively. 💬 Are you selling the news or scanning for the next security-token breakout after the bloodbath? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #DeFi #Hack #$BANK #$RIF #CryptoNews 🛡️ 🔴
🚨 $35.5M DEVI HACKS HIT $BANK AND $RIF – LIQUIDITY BLOODBATH! 💥

Three major exploits in 48 hours – AFX Trade, Verus, and B² Network drained for $35.5M. Attackers ripped through bridges and contracts like wet paper. 🦈 Smart money is already front-running the fear dump; watch for sharp wicks on DeFi altcoins.

📊 This is a classic split: some camps scream for regulation, others see a red carpet for security-first protocols. The market will digest this as a shakeout. Weak hands panic-sell; sharp traders fish for oversold bounces on $BANK and $RIF . 💡 The real play? Wait for the liquidity sweep below recent support then bid aggressively.

💬 Are you selling the news or scanning for the next security-token breakout after the bloodbath? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #DeFi #Hack #$BANK #$RIF #CryptoNews

🛡️ 🔴
$NIGHT 📉 -17% — обвал из-за взлома моста Wanchain. Хакер вывел 515 млн NIGHT ($13 млн) через повторное использование подписей и продал ~300 млн на DEX, обвалив цену на 50%. Midnight Foundation подтвердила: сеть Midnight в безопасности, проблема только в стороннем мосте. Поддержка **$0.015**, сопротивление $0.026. Риск сохраняется — часть токенов ещё не продана. 👉 Жми подписку, чтобы не пропустить сигналы! #NIGHT #Midnight #Hack {future}(NIGHTUSDT) {future}(MINAUSDT) {future}(ROSEUSDT)
$NIGHT 📉 -17% — обвал из-за взлома моста Wanchain. Хакер вывел 515 млн NIGHT ($13 млн) через повторное использование подписей и продал ~300 млн на DEX, обвалив цену на 50%. Midnight Foundation подтвердила: сеть Midnight в безопасности, проблема только в стороннем мосте. Поддержка **$0.015**, сопротивление $0.026. Риск сохраняется — часть токенов ещё не продана.

👉 Жми подписку, чтобы не пропустить сигналы!

#NIGHT #Midnight #Hack
#consensysreportsnorthkoreanhackerinfiltration ​🦊 MetaMask narrowly avoided a catastrophic exploit. Consensys inadvertently brought on a rogue developer—a North Korean operative masquerading under the alias "Tyler Knapp." For an entire month, this insider covertly altered code within the fiat deposit and withdrawal gateways completely undetected. ​Disaster was only averted when an anomalous IP address triggered an alert, leading to an immediate lock on his access. If this security breach had gone unnoticed, the entire ecosystem could have been drained. When even top-tier Web3 giants get compromised, it's a massive wake-up call for everyone. ​Immediate Defensive Moves for Investors: ​🛡️ Isolate with Cold Storage: Diversify your risk and migrate your primary assets into offline hardware wallets. ​🔍 Revoke Smart Contract Permissions: Audit your dApp connections and strictly limit token approvals, especially on unverified projects. ​💎 Leverage Secure Exchanges: Keep liquid capital on heavily regulated, reputable trading platforms with premium security infrastructure. ​⚠️ Not financial advice. Stay vigilant. ​#Consensys #MetaMask #Hack $TWT {spot}(TWTUSDT) $ETH {spot}(ETHUSDT) $BNB {spot}(BNBUSDT)
#consensysreportsnorthkoreanhackerinfiltration

​🦊 MetaMask narrowly avoided a catastrophic exploit. Consensys inadvertently brought on a rogue developer—a North Korean operative masquerading under the alias "Tyler Knapp." For an entire month, this insider covertly altered code within the fiat deposit and withdrawal gateways completely undetected.

​Disaster was only averted when an anomalous IP address triggered an alert, leading to an immediate lock on his access. If this security breach had gone unnoticed, the entire ecosystem could have been drained. When even top-tier Web3 giants get compromised, it's a massive wake-up call for everyone.

​Immediate Defensive Moves for Investors:

​🛡️ Isolate with Cold Storage: Diversify your risk and migrate your primary assets into offline hardware wallets.

​🔍 Revoke Smart Contract Permissions: Audit your dApp connections and strictly limit token approvals, especially on unverified projects.

​💎 Leverage Secure Exchanges: Keep liquid capital on heavily regulated, reputable trading platforms with premium security infrastructure.

​⚠️ Not financial advice. Stay vigilant.

#Consensys #MetaMask #Hack
$TWT
$ETH
$BNB
#consensysreportsnorthkoreanhackerinfiltration 🦊 MetaMask a failli « prendre feu » à cause de Consensys qui a accidentellement recruté un hacker nord-coréen se faisant passer pour un développeur « Tyler Knapp » ! Il s’est infiltré pendant tout le mois, modifiant directement le code de la passerelle de dépôt et de retrait en fiat que le système laissait passer sans difficulté. Heureusement, on a remarqué une adresse IP suspecte à temps et on a pu le bloquer, sinon, mes frères, ça aurait été « la fin » pour tout le monde. À cette période, même le boss de Web3 s’est fait avoir… Si un hack aussi énorme arrive, il faut renforcer sa sécurité soi-même, pas attendre que quelqu’un vienne nous sauver, non ? 🤯 Que faire, trader, en ce moment ? 🛡️ Stratégie : utiliser un portefeuille à froid. Diviser les fonds, et stocker les gros montants hors ligne. 🔍 Vérifier soigneusement les dApps : limiter les approbations (approve) des portefeuilles avec des projets non audités. 💎 Se réfugier sur de grandes plateformes : conserver ses actifs sur des échanges réputés pour être mieux protégé. ⚠️ Ceci n’est pas un conseil financier ! #Consensys #MetaMask #Hack $BANK {future}(BANKUSDT) $TLM {future}(TLMUSDT) $B {future}(BUSDT)
#consensysreportsnorthkoreanhackerinfiltration
🦊 MetaMask a failli « prendre feu » à cause de Consensys qui a accidentellement recruté un hacker nord-coréen se faisant passer pour un développeur « Tyler Knapp » ! Il s’est infiltré pendant tout le mois, modifiant directement le code de la passerelle de dépôt et de retrait en fiat que le système laissait passer sans difficulté. Heureusement, on a remarqué une adresse IP suspecte à temps et on a pu le bloquer, sinon, mes frères, ça aurait été « la fin » pour tout le monde. À cette période, même le boss de Web3 s’est fait avoir… Si un hack aussi énorme arrive, il faut renforcer sa sécurité soi-même, pas attendre que quelqu’un vienne nous sauver, non ? 🤯
Que faire, trader, en ce moment ?
🛡️ Stratégie : utiliser un portefeuille à froid. Diviser les fonds, et stocker les gros montants hors ligne.
🔍 Vérifier soigneusement les dApps : limiter les approbations (approve) des portefeuilles avec des projets non audités.

💎 Se réfugier sur de grandes plateformes : conserver ses actifs sur des échanges réputés pour être mieux protégé.
⚠️ Ceci n’est pas un conseil financier !

#Consensys #MetaMask #Hack
$BANK
$TLM

$B
$SOL WHALE HACKED FOR 180,900 SOL - FUNDS MOVING TO ETHEREUM 🔥 Body: A Solana genesis whale just got hit. On-chain data confirms roughly 180,900 SOL worth $14.2M was unstaked and bridged to Ethereum within hours. The transfer pattern shows deliberate, fast moves — not panic selling. This kind of whale-level theft usually triggers a short-term supply overhang, especially if the hacker starts dumping on a top-tier exchange. The attacker's addresses are known but the method is still under investigation. Do you think this will hit SOL's price in the next 24 hours? Not financial advice. Always manage your risk. #SOL #WhaleAlert #Hack #CryptoNews ⚡
$SOL WHALE HACKED FOR 180,900 SOL - FUNDS MOVING TO ETHEREUM 🔥

Body:

A Solana genesis whale just got hit. On-chain data confirms roughly 180,900 SOL worth $14.2M was unstaked and bridged to Ethereum within hours. The transfer pattern shows deliberate, fast moves — not panic selling.

This kind of whale-level theft usually triggers a short-term supply overhang, especially if the hacker starts dumping on a top-tier exchange. The attacker's addresses are known but the method is still under investigation.

Do you think this will hit SOL's price in the next 24 hours?

Not financial advice. Always manage your risk.

#SOL #WhaleAlert #Hack #CryptoNews

😂 ПРИВАТНЫЙ КЛЮЧ НА GITHUB ДВА ГОДА — ИТОГ $1,7 МЛН Никакого сложного эксплойта. Никакой уязвимости в коде. RSA-3072 ключ для SGX-прувера Raiko просто лежал в публичном репозитории GitHub. Два года. Файл enclave-key.pem. В открытом доступе. Хакер нашёл ключ, зарегистрировал свой прувер как легитимный и начал подписывать фейковые запросы на вывод средств — контракты Ethereum принимали их как настоящие. Без реального депозита на той стороне. Итог: $1,7 млн утекло, сеть встала, токен упал на 20%, около 2 млн токенов успели уйти на MEXC до заморозки. Это даже не «баг» — это просто файл не в том месте. Безопасность проекта на сотни миллионов TVL держалась на том, что никто не догадается заглянуть в репозиторий. Догадались. #Taiko #crypto #Security #Hack Подпишись — здесь разбираю взломы до того как выйдет официальный постмортем 🔔
😂 ПРИВАТНЫЙ КЛЮЧ НА GITHUB ДВА ГОДА — ИТОГ $1,7 МЛН

Никакого сложного эксплойта. Никакой уязвимости в коде. RSA-3072 ключ для SGX-прувера Raiko просто лежал в публичном репозитории GitHub. Два года. Файл enclave-key.pem. В открытом доступе.

Хакер нашёл ключ, зарегистрировал свой прувер как легитимный и начал подписывать фейковые запросы на вывод средств — контракты Ethereum принимали их как настоящие. Без реального депозита на той стороне.

Итог: $1,7 млн утекло, сеть встала, токен упал на 20%, около 2 млн токенов успели уйти на MEXC до заморозки.

Это даже не «баг» — это просто файл не в том месте. Безопасность проекта на сотни миллионов TVL держалась на том, что никто не догадается заглянуть в репозиторий.

Догадались.

#Taiko #crypto #Security #Hack

Подпишись — здесь разбираю взломы до того как выйдет официальный постмортем 🔔
Злам маркетплейсу MRKT у Telegram: хакери викрали рідкісні NFT-подарунки на $1 млн ​Найпопулярніший маркетплейс подарунків у Telegram — MRKT — зазнав масштабної кібератаки. Зловмисники скористалися критичною вразливістю в системі внутрішнього балансу платформи. ​Завдяки виявленому багу (абузу), шахраї змогли масово генерувати фейкові токени $GRAM на балансі мінідодтка. Використовуючи штучно створені кошти, вони почали активно скуповувати та виводити з майданчика найдорожчі цифрові активи. ​Наслідки атаки на MRKT: викрадення Plush Pepe ​У результаті інциденту з платформи MRKT було повністю виведено всі лімітовані NFT-подарунки Plush Pepe, а також велику кількість інших рідкісних цифрових колекційних предметів. ​Зловмисники вже почали перепродавати вкрадені Telegram-подарунки на сторонніх маркетплейсах та TON-майданчиках. За попередніми оцінками експертів, загальні збитки від зламу становлять близько 1 000 000 доларів США. #nft #MRKT #Telegram #Hack
Злам маркетплейсу MRKT у Telegram: хакери викрали рідкісні NFT-подарунки на $1 млн

​Найпопулярніший маркетплейс подарунків у Telegram — MRKT — зазнав масштабної кібератаки. Зловмисники скористалися критичною вразливістю в системі внутрішнього балансу платформи.

​Завдяки виявленому багу (абузу), шахраї змогли масово генерувати фейкові токени $GRAM на балансі мінідодтка. Використовуючи штучно створені кошти, вони почали активно скуповувати та виводити з майданчика найдорожчі цифрові активи.

​Наслідки атаки на MRKT: викрадення Plush Pepe

​У результаті інциденту з платформи MRKT було повністю виведено всі лімітовані NFT-подарунки Plush Pepe, а також велику кількість інших рідкісних цифрових колекційних предметів.

​Зловмисники вже почали перепродавати вкрадені Telegram-подарунки на сторонніх маркетплейсах та TON-майданчиках. За попередніми оцінками експертів, загальні збитки від зламу становлять близько 1 000 000 доларів США.

#nft #MRKT #Telegram #Hack
Step Finance黑客沉寂5个月后突然行动,把手里26.19万枚SOL全部清仓,套现约2140万美元。 链上侦探Lookonchain追踪到,这笔资金随后跨链到以太坊,换成12128枚ETH,再一股脑丢进Tornado Cash洗白。 几个细节值得关注: 一是选在SOL相对高位出货,说明对方对时机判断并不业余; 二是从Solana换到ETH再走混币器,路径已经是老练黑客的标准操作; 三是沉寂期越长,一旦动手往往越果断,这类地址后续大概率还会有第二波、第三波清算动作。 对普通持仓者来说,短期需要留意两点:SOL现货端多了一个几千万美元级别的抛压来源,ETH端则被动多了一批需要消化的混币筹码。混币器进场的资金通常不会立刻回到CEX,但对交易所合规团队来说,接下来几周的入金审查会更紧。 黑客余额清零不代表故事结束,而是资金开始进入难以追踪的阶段。 #StepFinance #Hack #TornadoCash $SOL $ETH
Step Finance黑客沉寂5个月后突然行动,把手里26.19万枚SOL全部清仓,套现约2140万美元。

链上侦探Lookonchain追踪到,这笔资金随后跨链到以太坊,换成12128枚ETH,再一股脑丢进Tornado Cash洗白。

几个细节值得关注:
一是选在SOL相对高位出货,说明对方对时机判断并不业余;
二是从Solana换到ETH再走混币器,路径已经是老练黑客的标准操作;
三是沉寂期越长,一旦动手往往越果断,这类地址后续大概率还会有第二波、第三波清算动作。

对普通持仓者来说,短期需要留意两点:SOL现货端多了一个几千万美元级别的抛压来源,ETH端则被动多了一批需要消化的混币筹码。混币器进场的资金通常不会立刻回到CEX,但对交易所合规团队来说,接下来几周的入金审查会更紧。

黑客余额清零不代表故事结束,而是资金开始进入难以追踪的阶段。

#StepFinance #Hack #TornadoCash
$SOL $ETH
Step Finance黑客沉寂五个月后突然出手,把手里全部261,933枚SOL(约2140万美元)一次性砸盘清空,紧接着跨链到以太坊换成12,128枚ETH,再一股脑塞进Tornado Cash洗白。 几个细节值得盯: 一是节奏——不是慢慢分批,而是抛售、跨链、混币一条龙,明显是在赌市场承接力和链上追踪的时间差; 二是路径——SOL→ETH→Tornado,几乎是老钱包的教科书操作,说明这类黑客对Solana生态的出金深度依然缺乏信心,最终还是回到以太坊做终局清洗; 三是时点——选在沉寂这么久之后动手,往往意味着觉得舆论热度已经过去、监测松懈,这也是链上侦探最容易反向蹲守的时刻。 对普通用户的启示很直接:老案子的赃款钱包不会消失,只是在等一个流动性窗口。看到大额$SOL异动砸向CEX或桥时,多留一分警惕,别当那个接盘的对手方。 #OnChainAnalysis #Hack #TornadoCash
Step Finance黑客沉寂五个月后突然出手,把手里全部261,933枚SOL(约2140万美元)一次性砸盘清空,紧接着跨链到以太坊换成12,128枚ETH,再一股脑塞进Tornado Cash洗白。

几个细节值得盯:
一是节奏——不是慢慢分批,而是抛售、跨链、混币一条龙,明显是在赌市场承接力和链上追踪的时间差;
二是路径——SOL→ETH→Tornado,几乎是老钱包的教科书操作,说明这类黑客对Solana生态的出金深度依然缺乏信心,最终还是回到以太坊做终局清洗;
三是时点——选在沉寂这么久之后动手,往往意味着觉得舆论热度已经过去、监测松懈,这也是链上侦探最容易反向蹲守的时刻。

对普通用户的启示很直接:老案子的赃款钱包不会消失,只是在等一个流动性窗口。看到大额$SOL 异动砸向CEX或桥时,多留一分警惕,别当那个接盘的对手方。

#OnChainAnalysis #Hack #TornadoCash
🥷 $ETH PeckShieldAlert: Hinkal ha sufrido un hackeo por valor de 820 mil dólares. 🕵️‍♂️ Alguien ha creado un nuevo monedero, 0xe069, y ha abierto una posición larga de 20x sobre 230 583 $SOL (18,81 millones de dólares). En menos de un día, la posición ya ha subido 818 000 $. Precio de liquidación: 67,14 $. 🇨🇦🤔 Canadá da a conocer sus planes para construir un oleoducto hacia Asia con el objetivo de convertirse en una «superpotencia energética» y reducir su dependencia de EE. UU. #EEUU #Canada #Hack #solana #ballenas
🥷 $ETH PeckShieldAlert: Hinkal ha sufrido un hackeo por valor de 820 mil dólares.

🕵️‍♂️ Alguien ha creado un nuevo monedero, 0xe069, y ha abierto una posición larga de 20x sobre 230 583 $SOL (18,81 millones de dólares).

En menos de un día, la posición ya ha subido 818 000 $.

Precio de liquidación: 67,14 $.

🇨🇦🤔 Canadá da a conocer sus planes para construir un oleoducto hacia Asia con el objetivo de convertirse en una «superpotencia energética» y reducir su dependencia de EE. UU.

#EEUU #Canada #Hack #solana #ballenas
🥷 PeckShieldAlert: 99 million #TSR were minted and sold (-99%). Hacker has already exchanged #TSR for approximately $2.5 million #USDT. #hack #crypto
🥷 PeckShieldAlert: 99 million #TSR were minted and sold (-99%). Hacker has already exchanged #TSR for approximately $2.5 million #USDT. #hack

#crypto
Verified
👀 #THORChain тоже залетел в сезон эксплойтов По данным ZachXBT, протокол THORChain взломали сразу в нескольких сетях: ⚫️ Bitcoin ⚫️ Ethereum ⚫️ BNB Chain ⚫️ Base Предварительный ущерб уже оценивают более чем в $10 млн 😶 Хакер успел вывести примерно: ⚫️ 36.75 BTC (~$3 млн) ⚫️ ещё около $7 млн в токенах из EVM-сетей После этого команде пришлось экстренно тормозить торги и ограничивать операции в нескольких сетях, чтобы остановить дальнейший вывод средств. Ну а THORChain отреагировал максимально предсказуемо — как только в крипте рядом с токеном появляется слово “exploit”, график автоматически включает режим свободного падения 😭 Самое неприятное в таких историях — мультичейн-архитектура. Если проблема затрагивает сразу несколько сетей, последствия и хаос обычно растут в геометрической прогрессии. Ps: В 2026 году уже ощущение, что DeFi-протокол без эксплойта — это просто проект, который ещё не дошёл до своей очереди 😁 #THORChain #Rune #Hack #defi 👀 Подписывайся, тут самые жёсткие взломы, схемы и разборы крипторынка без фильтров
👀 #THORChain тоже залетел в сезон эксплойтов

По данным ZachXBT, протокол THORChain взломали сразу в нескольких сетях:

⚫️ Bitcoin
⚫️ Ethereum
⚫️ BNB Chain
⚫️ Base

Предварительный ущерб уже оценивают более чем в $10 млн 😶

Хакер успел вывести примерно:
⚫️ 36.75 BTC (~$3 млн)
⚫️ ещё около $7 млн в токенах из EVM-сетей

После этого команде пришлось экстренно тормозить торги и ограничивать операции в нескольких сетях, чтобы остановить дальнейший вывод средств.

Ну а THORChain отреагировал максимально предсказуемо — как только в крипте рядом с токеном появляется слово “exploit”, график автоматически включает режим свободного падения 😭

Самое неприятное в таких историях — мультичейн-архитектура.
Если проблема затрагивает сразу несколько сетей, последствия и хаос обычно растут в геометрической прогрессии.

Ps: В 2026 году уже ощущение, что DeFi-протокол без эксплойта — это просто проект, который ещё не дошёл до своей очереди 😁

#THORChain #Rune #Hack #defi

👀 Подписывайся, тут самые жёсткие взломы, схемы и разборы крипторынка без фильтров
Verified
🚨 Humanity Protocol Hacked for $20M Humanity Protocol ($H ) exploited via leaked private key of a foundation member. Attacker drained $20M from bridges & liquidity pools. Token crashed hard (reports of 80%+ drop). Founder Terence Kwok confirmed the breach team working with security firms. Users advised to avoid bridges & pools. Decentralized identity project takes a heavy hit. Rug or real exploit? Stay safe out there. What’s your take? 👀 #HumanityProtocol #HCrypto #Hack
🚨 Humanity Protocol Hacked for $20M

Humanity Protocol ($H ) exploited via leaked private key of a foundation member.

Attacker drained $20M from bridges & liquidity pools.

Token crashed hard (reports of 80%+ drop). Founder Terence Kwok confirmed the breach team working with security firms. Users advised to avoid bridges & pools.

Decentralized identity project takes a heavy hit. Rug or real exploit? Stay safe out there.

What’s your take? 👀
#HumanityProtocol #HCrypto #Hack
·
--
Contracts of the European stablecoin issuer StablR (a Tether shell company) were hacked. The damage amounts to approximately $10 million—the $EURR and $USDR tokens became unpegged and dropped by more than 20%. The attack was not caused by a bug in the contract, but by the compromise of the private key of one of the owners of the multisig used to create the stablecoins. Since the setup was 1-of-3, the hacker only needed one key: he added himself as an owner, replaced two legitimate participants, gained control of the token issuance, and mined 4.5 million EURR and 8.35 million USDR. These tokens were then quickly swapped to a low-liquidity DEX, generating approximately $1,115 in ETH. StablR is a stablecoin issuer fully compliant with European MiCA regulations. #hack
Contracts of the European stablecoin issuer StablR (a Tether shell company) were hacked.

The damage amounts to approximately $10 million—the $EURR and $USDR tokens became unpegged and dropped by more than 20%.

The attack was not caused by a bug in the contract, but by the compromise of the private key of one of the owners of the multisig used to create the stablecoins.

Since the setup was 1-of-3, the hacker only needed one key: he added himself as an owner, replaced two legitimate participants, gained control of the token issuance, and mined 4.5 million EURR and 8.35 million USDR. These tokens were then quickly swapped to a low-liquidity DEX, generating approximately $1,115 in ETH.

StablR is a stablecoin issuer fully compliant with European MiCA regulations.

#hack
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number