Binance Square
慢雾 SlowMist
292 Posts

慢雾 SlowMist

Square Verified+
​慢雾(SlowMist) 是一家行业领先的区块链安全公司,主要通过安全审计及反洗钱追踪溯源等服务广大客户,已有商业客户上千家,客户分布在十几个主要国家与地区。
原创之星
原创之星
0 Following
32.8K+ Followers
931 Liked
1 Badges
Posts
·
--
Article
Threat Intelligence | iOS Safari DarkSword Steals Wallet AssetsBackground A promotional page offering a free VPS, but in reality it is a lure. As shown by the archived public webpage, the event[.]polarnode[.]vip domain registered at the end of August 2026 designates https[:]//lk[.]wyincc[.]com/lk.js as a preloading script. Once the page becomes interactive, it automatically loads, without requiring visitors to click. After decoding the saved loader sample, we confirmed that it is designed for delivery to iPhones running pure Safari on iOS 18.4–18.6.2. Ultimately, it targets file access, Keychain, and keyboard input collection, with the goal of three wallet applications. This chain closely matches the DarkSword iOS exploit chain published by Google Threat Intelligence Group (GTIG), covering six CVEs and falling under n-day reuse.

Threat Intelligence | iOS Safari DarkSword Steals Wallet Assets

Background
A promotional page offering a free VPS, but in reality it is a lure. As shown by the archived public webpage, the event[.]polarnode[.]vip domain registered at the end of August 2026 designates https[:]//lk[.]wyincc[.]com/lk.js as a preloading script. Once the page becomes interactive, it automatically loads, without requiring visitors to click.
After decoding the saved loader sample, we confirmed that it is designed for delivery to iPhones running pure Safari on iOS 18.4–18.6.2. Ultimately, it targets file access, Keychain, and keyboard input collection, with the goal of three wallet applications. This chain closely matches the DarkSword iOS exploit chain published by Google Threat Intelligence Group (GTIG), covering six CVEs and falling under n-day reuse.
Article
From “who is depositing” to “where the money comes from”: the on-chain source-of-funds risk behind OKX’s risk-control strategyRecently, OKX CEO responded to a user post stating that a gambling platform directly transfers funds to an exchange, causing deposits to trigger verification. According to his publicly stated comments, depositing to OKX from high-risk addresses may trigger more stringent anti-money laundering (AML) and risk reviews. Depending on the specific situation, the review may last 15 days or even longer; during this period, some account functions and funds may be restricted. For accounts confirmed to be involved in high-risk or illegal activities, the platform may also terminate service. https://x.com/star_okx/status/2094980124236251207 OKX also reminds that funds obtained through channels such as escrow trading via Telegram groups, Huiwang and its variants may involve a higher risk of the source of funds.

From “who is depositing” to “where the money comes from”: the on-chain source-of-funds risk behind OKX’s risk-control strategy

Recently, OKX CEO responded to a user post stating that a gambling platform directly transfers funds to an exchange, causing deposits to trigger verification. According to his publicly stated comments, depositing to OKX from high-risk addresses may trigger more stringent anti-money laundering (AML) and risk reviews. Depending on the specific situation, the review may last 15 days or even longer; during this period, some account functions and funds may be restricted. For accounts confirmed to be involved in high-risk or illegal activities, the platform may also terminate service.
https://x.com/star_okx/status/2094980124236251207
OKX also reminds that funds obtained through channels such as escrow trading via Telegram groups, Huiwang and its variants may involve a higher risk of the source of funds.
Article
SlowMist: MistTrack & SlowMist KYT Partner Program Officially LaunchedAs crypto assets, stablecoin payments, and digital financial services continue to grow, on-chain AML, KYT, and fund risk analysis are becoming practical needs for an increasing number of institutions. For this purpose, MistTrack & SlowMist KYT officially launches a Partner Program, recruiting individual and institutional partners worldwide with resources in Web3, finance, payments, compliance, security, and local markets. After joining the program, you can receive: An exclusive customer discount code to help your customers subscribe at a more favorable price; Automatic order attribution and commission-rebate records, with a maximum commission rebate validity period of 3 years;

SlowMist: MistTrack & SlowMist KYT Partner Program Officially Launched

As crypto assets, stablecoin payments, and digital financial services continue to grow, on-chain AML, KYT, and fund risk analysis are becoming practical needs for an increasing number of institutions.
For this purpose, MistTrack & SlowMist KYT officially launches a Partner Program, recruiting individual and institutional partners worldwide with resources in Web3, finance, payments, compliance, security, and local markets.
After joining the program, you can receive:
An exclusive customer discount code to help your customers subscribe at a more favorable price;
Automatic order attribution and commission-rebate records, with a maximum commission rebate validity period of 3 years;
Article
“Gray Rhinos” and “Black Swans”: Yu Xuan, founder of SlowMist, discusses security risks and protection in the crypto worldOn August 28, at the Cypher Asia Intelligent Crypto Finance Summit, Yu Xuan, founder of SlowMist, delivered a keynote titled (Gray Rhinos and Black Swans in the Crypto World). He started with security issues commonly seen in the crypto space, systematically organized core risks such as funds being stolen, scammed, lost, and frozen, and shared his thoughts on security protection. The following is a整理 of现场 sharing content. In the world of encryption, it’s not uncommon for funds to be stolen, scammed, lost, or frozen. When many security incidents happen, they may seem like a sudden and unexpected event at first glance. But when you look back, many risks actually showed signs long before. The issue isn’t necessarily that people “don’t know risks exist,” but rather that the risks have already materialized without receiving enough attention, or that existing security measures haven’t truly been effective.

“Gray Rhinos” and “Black Swans”: Yu Xuan, founder of SlowMist, discusses security risks and protection in the crypto world

On August 28, at the Cypher Asia Intelligent Crypto Finance Summit, Yu Xuan, founder of SlowMist, delivered a keynote titled (Gray Rhinos and Black Swans in the Crypto World). He started with security issues commonly seen in the crypto space, systematically organized core risks such as funds being stolen, scammed, lost, and frozen, and shared his thoughts on security protection.
The following is a整理 of现场 sharing content.
In the world of encryption, it’s not uncommon for funds to be stolen, scammed, lost, or frozen. When many security incidents happen, they may seem like a sudden and unexpected event at first glance. But when you look back, many risks actually showed signs long before. The issue isn’t necessarily that people “don’t know risks exist,” but rather that the risks have already materialized without receiving enough attention, or that existing security measures haven’t truly been effective.
Article
Event Recap | SlowMist Participated in Multiple Web3 Events in Hong Kong, Sharing Security and Compliance PracticesOn August 28, SlowMist (SlowMist), together with ME Group, hosted an industry exchange event titled “Crossing the Mist to Trusted Payments | New Frontiers in Global Stablecoin Compliance and Agent-Based Payments,” and also participated in multiple industry exchanges including “Cypher Asia Intelligent Crypto Finance Summit” and the “AI x BTC - BTC Asia Side Event.” Centering on topics such as stablecoin compliance and payment applications, crypto security, and the foundational infrastructure of the digital economy, it shared practical experience and security perspectives with industry partners. Now, let’s take a look back at the highlights of the day— Focusing on stablecoin compliance and agent-based payments, exploring the building of trusted payments

Event Recap | SlowMist Participated in Multiple Web3 Events in Hong Kong, Sharing Security and Compliance Practices

On August 28, SlowMist (SlowMist), together with ME Group, hosted an industry exchange event titled “Crossing the Mist to Trusted Payments | New Frontiers in Global Stablecoin Compliance and Agent-Based Payments,” and also participated in multiple industry exchanges including “Cypher Asia Intelligent Crypto Finance Summit” and the “AI x BTC - BTC Asia Side Event.” Centering on topics such as stablecoin compliance and payment applications, crypto security, and the foundational infrastructure of the digital economy, it shared practical experience and security perspectives with industry partners.
Now, let’s take a look back at the highlights of the day—
Focusing on stablecoin compliance and agent-based payments, exploring the building of trusted payments
Article
Threat Intelligence|StealC Data-Stealing Chain Behind a Qwen Impersonation RepositoryBackground Download an open-source large model. The usual things you worry about are whether it runs properly and whether the weights are real. This time, the real concern is hidden elsewhere: a repository labeled with 27B parameters that, when it gets into your hands, only contains 487 KB—inside there are not weights, but a data-stealing trojan horse. On August 20, 2026, the GitHub repository unburdened-jackinthebox365/qwen38-uncensored submitted a file named uncensored_qwen_v2.6.zip to the assets/ directory. The file size was 487,153 bytes. The repository packaged it in a way that was almost airtight. The homepage claimed to provide locally quantized weights for Qwen 3.8 27B. The README emphasized fully offline operation, no telemetry, and that no data leaves your machine. Every line hit the exact concerns of local model users. Four days later, on August 24, the README was modified again—the download button, the download link in the body, and even the two external links that originally pointed to the Ollama and LM Studio official websites were all changed to point to the raw address of the same ZIP.

Threat Intelligence|StealC Data-Stealing Chain Behind a Qwen Impersonation Repository

Background
Download an open-source large model. The usual things you worry about are whether it runs properly and whether the weights are real. This time, the real concern is hidden elsewhere: a repository labeled with 27B parameters that, when it gets into your hands, only contains 487 KB—inside there are not weights, but a data-stealing trojan horse.
On August 20, 2026, the GitHub repository unburdened-jackinthebox365/qwen38-uncensored submitted a file named uncensored_qwen_v2.6.zip to the assets/ directory. The file size was 487,153 bytes. The repository packaged it in a way that was almost airtight. The homepage claimed to provide locally quantized weights for Qwen 3.8 27B. The README emphasized fully offline operation, no telemetry, and that no data leaves your machine. Every line hit the exact concerns of local model users. Four days later, on August 24, the README was modified again—the download button, the download link in the body, and even the two external links that originally pointed to the Ollama and LM Studio official websites were all changed to point to the raw address of the same ZIP.
Verified
Article
Countdown: 2 Days|SlowMist and ME Group’s Hong Kong Event Agenda Officially AnnouncedOn August 28, SlowMist will partner with ME Group to host an industry exchange event in Hong Kong titled “Crossing the Mist to Trusted Payments: A New Frontier for Global Stablecoin Compliance and Agent-Based Payments.” This event will bring together industry guests from areas including stablecoins, payments, AI agents, compliance, and blockchain security. Through discussions focused on global stablecoin compliance, the development of agent-based payments, and the establishment of a trusted payments ecosystem, we will jointly explore the technical, security, and compliance challenges involved in the evolution of payment models. Time: August 28, 09:30 – 12:30 Location: CAI Building, Hong Kong

Countdown: 2 Days|SlowMist and ME Group’s Hong Kong Event Agenda Officially Announced

On August 28, SlowMist will partner with ME Group to host an industry exchange event in Hong Kong titled “Crossing the Mist to Trusted Payments: A New Frontier for Global Stablecoin Compliance and Agent-Based Payments.”
This event will bring together industry guests from areas including stablecoins, payments, AI agents, compliance, and blockchain security. Through discussions focused on global stablecoin compliance, the development of agent-based payments, and the establishment of a trusted payments ecosystem, we will jointly explore the technical, security, and compliance challenges involved in the evolution of payment models.
Time: August 28, 09:30 – 12:30
Location: CAI Building, Hong Kong
Article
A cross-chain attack spanning a month: Analysis of the Allbridge hackAuthor: Jiujiu Edited: 77 Background On August 19, 2026, the well-known cross-chain bridge project Allbridge was attacked, suffering a loss of approximately $190,000. However, this attack took nearly a month to complete. Below is a detailed analysis of this incident by the SlowMist Security team: Prerequisite knowledge To understand this attack, we first need to understand Circle’s CCTP protocol and its cross-chain message transfer system. CCTP is Circle’s cross-chain transfer protocol. Its basic approach is to destroy USDC on the source chain and then mint an equivalent amount of USDC on the destination chain. This avoids bridge contracts increasing balances out of thin air.

A cross-chain attack spanning a month: Analysis of the Allbridge hack

Author: Jiujiu
Edited: 77
Background
On August 19, 2026, the well-known cross-chain bridge project Allbridge was attacked, suffering a loss of approximately $190,000. However, this attack took nearly a month to complete. Below is a detailed analysis of this incident by the SlowMist Security team:
Prerequisite knowledge
To understand this attack, we first need to understand Circle’s CCTP protocol and its cross-chain message transfer system.
CCTP is Circle’s cross-chain transfer protocol. Its basic approach is to destroy USDC on the source chain and then mint an equivalent amount of USDC on the destination chain. This avoids bridge contracts increasing balances out of thin air.
Article
See you in Hong Kong on August 28|From Stablecoins to AI Agents, SlowMist Will Appear at Multiple Industry Events in Hong KongOn August 28, Hong Kong will host multiple industry events focusing on stablecoins, intelligent agent payments, AI agents, and Bitcoin infrastructure. As a company dedicated to security in the blockchain ecosystem, SlowMist will host and participate in several events in Hong Kong. Drawing on its own security research and practical experience, it will communicate with industry partners on related topics. Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments Time: August 28, 09:30–12:30 Location: Hong Kong CAI Building Registration: https://luma.com/0c4fawzv On the morning of August 28, SlowMist will join forces with ME Group to host an industry exchange event in Hong Kong titled “Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments.” At the event, ecosystem partners from areas including stablecoins, payments, AI agents, compliance, and security will gather in Hong Kong to exchange ideas on global stablecoin compliance and applications, the technological evolution of agent-based payments, and the security-building of trusted payment systems.

See you in Hong Kong on August 28|From Stablecoins to AI Agents, SlowMist Will Appear at Multiple Industry Events in Hong Kong

On August 28, Hong Kong will host multiple industry events focusing on stablecoins, intelligent agent payments, AI agents, and Bitcoin infrastructure. As a company dedicated to security in the blockchain ecosystem, SlowMist will host and participate in several events in Hong Kong. Drawing on its own security research and practical experience, it will communicate with industry partners on related topics.
Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments
Time: August 28, 09:30–12:30
Location: Hong Kong CAI Building
Registration: https://luma.com/0c4fawzv
On the morning of August 28, SlowMist will join forces with ME Group to host an industry exchange event in Hong Kong titled “Breaking Through the Mist to Trusted Payments|A New Frontier in Global Stablecoin Compliance and Intelligent Agent Payments.” At the event, ecosystem partners from areas including stablecoins, payments, AI agents, compliance, and security will gather in Hong Kong to exchange ideas on global stablecoin compliance and applications, the technological evolution of agent-based payments, and the security-building of trusted payment systems.
Article
Threat Intelligence|Beware of Targeted Poisoning of Web3 Developers by Solidity ProBackground Solidity Pro is a VS Code extension for Solidity/Web3 developers. It is positioned as a development aid tool and offers features such as gas lookups, token prices, code snippets, and compilation hints. Its GitHub repository has also previously advertised security capabilities such as AI Audit and Security Scanner. In public events, Solidity Pro used two publishers—helper-beeps and web3devtoolsx—for the publisher identity, with Extension IDs (unique extension identifiers) of helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, respectively. Although the publishing identity changed, later build artifacts still retained the old publisher, repository address, and copyright information, indicating a direct engineering inheritance relationship between the two.

Threat Intelligence|Beware of Targeted Poisoning of Web3 Developers by Solidity Pro

Background
Solidity Pro is a VS Code extension for Solidity/Web3 developers. It is positioned as a development aid tool and offers features such as gas lookups, token prices, code snippets, and compilation hints. Its GitHub repository has also previously advertised security capabilities such as AI Audit and Security Scanner.
In public events, Solidity Pro used two publishers—helper-beeps and web3devtoolsx—for the publisher identity, with Extension IDs (unique extension identifiers) of helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, respectively. Although the publishing identity changed, later build artifacts still retained the old publisher, repository address, and copyright information, indicating a direct engineering inheritance relationship between the two.
Article
MistTrack Agent officially joins AgentOn, bringing on-chain investigation capabilities to AI AgentsRecently, MistTrack Agent, built by SlowMist, officially joined AgentOn as a third-party Agent. Focused on crypto AML and on-chain investigations, MistTrack Agent brings capabilities such as on-chain funds tracing and risk analysis to the AgentOn platform, providing users with a more efficient and automated way to conduct on-chain investigations. Welcome to MistTrack Agent: https://agenton.me/agent/market/external/fe204dba-05d1-49c8-8659-03ca24988185 🎁 Limited-time offer: Each user can enjoy 10 free calls, valid for 30 days. After the free call quota is used up or the validity period ends, charges will apply according to AgentOn’s standard pricing.

MistTrack Agent officially joins AgentOn, bringing on-chain investigation capabilities to AI Agents

Recently, MistTrack Agent, built by SlowMist, officially joined AgentOn as a third-party Agent. Focused on crypto AML and on-chain investigations, MistTrack Agent brings capabilities such as on-chain funds tracing and risk analysis to the AgentOn platform, providing users with a more efficient and automated way to conduct on-chain investigations.
Welcome to MistTrack Agent:
https://agenton.me/agent/market/external/fe204dba-05d1-49c8-8659-03ca24988185
🎁 Limited-time offer: Each user can enjoy 10 free calls, valid for 30 days. After the free call quota is used up or the validity period ends, charges will apply according to AgentOn’s standard pricing.
Article
SlowMist × ME Group invites you to explore stablecoin compliance and agent-based payments togetherThe continuous development of digital asset and artificial intelligence technologies is driving payments into a new application stage. On the one hand, stablecoins are accelerating their move beyond on-chain scenarios and are being integrated into real business functions such as payments, settlements, and treasury management. On the other hand, AI Agents are gradually evolving from supporting tools into payment participants capable of representing users and enterprises to conduct inquiries, make decisions, call services, and even initiate transactions. As stablecoins move into real payment scenarios, how can compliance be truly implemented? As AI Agents begin to participate in transactions, how can secure and trustworthy transaction mechanisms be established? These have also become new issues the industry needs to address.

SlowMist × ME Group invites you to explore stablecoin compliance and agent-based payments together

The continuous development of digital asset and artificial intelligence technologies is driving payments into a new application stage. On the one hand, stablecoins are accelerating their move beyond on-chain scenarios and are being integrated into real business functions such as payments, settlements, and treasury management. On the other hand, AI Agents are gradually evolving from supporting tools into payment participants capable of representing users and enterprises to conduct inquiries, make decisions, call services, and even initiate transactions.
As stablecoins move into real payment scenarios, how can compliance be truly implemented? As AI Agents begin to participate in transactions, how can secure and trustworthy transaction mechanisms be established? These have also become new issues the industry needs to address.
Article
Coldcard $111 Million Theft Incident: In-depth Analysis of the Private Key Cracking VulnerabilityAuthor: Johan & Lisa Edit: 77 This article is co-created by humans and machines—you can reproduce it by importing the AI. Background On July 30, 2026, on-chain there was a batch of addresses that continuously transferred funds outward. Over 41 minutes, 1,196 single-sig addresses were emptied, with about 1,082 bitcoins disappearing. This was only the first wave. By early August, confirmed losses were at least 1,719 bitcoins—about $111 million—covering more than 5,200 addresses, and the attacker split the activity into three to four waves before and after the attack. What’s most puzzling is the state of these wallets. Most of the money sat in cold wallets; some had been untouched for months or even years. What was lost was the layer of the private key. All of the private keys were generated by the Coldcard hardware wallet; the owner hadn’t clicked the dice entropy additional times, nor had they enabled a BIP-39 passphrase. Victims were using the most effortless way of doing things.

Coldcard $111 Million Theft Incident: In-depth Analysis of the Private Key Cracking Vulnerability

Author: Johan & Lisa
Edit: 77
This article is co-created by humans and machines—you can reproduce it by importing the AI.
Background
On July 30, 2026, on-chain there was a batch of addresses that continuously transferred funds outward. Over 41 minutes, 1,196 single-sig addresses were emptied, with about 1,082 bitcoins disappearing. This was only the first wave. By early August, confirmed losses were at least 1,719 bitcoins—about $111 million—covering more than 5,200 addresses, and the attacker split the activity into three to four waves before and after the attack.
What’s most puzzling is the state of these wallets. Most of the money sat in cold wallets; some had been untouched for months or even years. What was lost was the layer of the private key. All of the private keys were generated by the Coldcard hardware wallet; the owner hadn’t clicked the dice entropy additional times, nor had they enabled a BIP-39 passphrase. Victims were using the most effortless way of doing things.
Article
SlowMist and AgentOn Reach Strategic Partnership to Build an AI Agent Security EcosystemRecently, SlowMist and AgentOn have officially reached a strategic partnership. The two sides will collaborate on AI agent security capability building, security assessment frameworks, and ecosystem practices, jointly推动ing the AI agent ecosystem toward a safer and more trusted direction. Background As AI agents gradually move from demos to real-world scenarios, agent security issues are becoming the most关注 topic across the entire industry. Compared with traditional Web3 products, AI agents have capabilities such as calling tools, accessing data, managing wallets, and executing transactions. Once a security issue occurs, the impact is much broader.

SlowMist and AgentOn Reach Strategic Partnership to Build an AI Agent Security Ecosystem

Recently, SlowMist and AgentOn have officially reached a strategic partnership. The two sides will collaborate on AI agent security capability building, security assessment frameworks, and ecosystem practices, jointly推动ing the AI agent ecosystem toward a safer and more trusted direction.
Background
As AI agents gradually move from demos to real-world scenarios, agent security issues are becoming the most关注 topic across the entire industry. Compared with traditional Web3 products, AI agents have capabilities such as calling tools, accessing data, managing wallets, and executing transactions. Once a security issue occurs, the impact is much broader.
Article
Threat Intelligence | Job Hunting Trap! Interview Software Hides a Data-Stealing TrojanBackground Recently, MistEye detected a credential-stealing campaign targeting Web3 professionals, luring victims with recruitment. The attackers impersonated recruiters to engage job seekers, discussed interview arrangements, and then induced the targets to redirect to relay.lc for further online communication. This website packages itself as an AI meeting collaboration tool called Relay, claiming it can provide real-time transcription, collaborative notes, AI summaries, action items, and cross-platform clients, among other features. For people attending remote interviews, this pitch doesn’t feel out of place: installing a “meeting app” to proceed to the next round of communication looks like a normal part of the hiring process. The public page for relay.lc also builds its product image around these functions, and it offers download entry points for Windows and macOS.

Threat Intelligence | Job Hunting Trap! Interview Software Hides a Data-Stealing Trojan

Background
Recently, MistEye detected a credential-stealing campaign targeting Web3 professionals, luring victims with recruitment. The attackers impersonated recruiters to engage job seekers, discussed interview arrangements, and then induced the targets to redirect to relay.lc for further online communication.
This website packages itself as an AI meeting collaboration tool called Relay, claiming it can provide real-time transcription, collaborative notes, AI summaries, action items, and cross-platform clients, among other features. For people attending remote interviews, this pitch doesn’t feel out of place: installing a “meeting app” to proceed to the next round of communication looks like a normal part of the hiring process. The public page for relay.lc also builds its product image around these functions, and it offers download entry points for Windows and macOS.
AAPLUS-2,50%
Article
MistEye DNS Guard officially released—lightweight host network threat observation defense lineThe MistEye Security Team officially releases MistEye DNS Guard: a lightweight local DNS relay and threat observation tool written in Rust, designed for macOS and Linux hosts. It provides system DNS takeover, domain name and public IP detection, process outbound connection monitoring, malicious event retention, and webhook alerting capabilities. It focuses on common risk scenarios such as accessing malicious domains, DNS responses returning malicious indicators, and programs directly connecting to malicious IPs. MistEye DNS Guard decouples DNS forwarding from subsequent threat detection: DNS queries are completed as usual, while domain names and IP addresses are asynchronously sent to MistEye for detection in the background, minimizing the impact of security checks on normal network access.

MistEye DNS Guard officially released—lightweight host network threat observation defense line

The MistEye Security Team officially releases MistEye DNS Guard: a lightweight local DNS relay and threat observation tool written in Rust, designed for macOS and Linux hosts. It provides system DNS takeover, domain name and public IP detection, process outbound connection monitoring, malicious event retention, and webhook alerting capabilities. It focuses on common risk scenarios such as accessing malicious domains, DNS responses returning malicious indicators, and programs directly connecting to malicious IPs.
MistEye DNS Guard decouples DNS forwarding from subsequent threat detection: DNS queries are completed as usual, while domain names and IP addresses are asynchronously sent to MistEye for detection in the background, minimizing the impact of security checks on normal network access.
Article
Threat Intelligence|Investigation of a Web3 Wallet Phishing Attack: From “Compliance Emails” to Remote ControlBackground Recently, the SlowMist security team identified a phishing attack that persisted for months and was carried out through multiple channels. The attackers posed as multiple Web3 wallet brands. We first became aware of this incident through two phishing emails. The attackers impersonated Keystone and OneKey, using reasons such as “Terms of Service update,” “account verification,” and “regulatory compliance,” urging the recipient to complete the action within a specified deadline. The buttons in the email would take the victim to a fake DocuSign page and coax them into downloading a so-called “desktop signing application.”

Threat Intelligence|Investigation of a Web3 Wallet Phishing Attack: From “Compliance Emails” to Remote Control

Background
Recently, the SlowMist security team identified a phishing attack that persisted for months and was carried out through multiple channels. The attackers posed as multiple Web3 wallet brands.
We first became aware of this incident through two phishing emails. The attackers impersonated Keystone and OneKey, using reasons such as “Terms of Service update,” “account verification,” and “regulatory compliance,” urging the recipient to complete the action within a specified deadline. The buttons in the email would take the victim to a fake DocuSign page and coax them into downloading a so-called “desktop signing application.”
Article
The Distance Between Being and Effectiveness | Looking at Risk Control from FATF’s Latest ReportBackground In July 2026, the Financial Action Task Force (FATF) released its seventh (dedicated progress report on the regulation of virtual assets and virtual asset service providers) [1]. FATF noted that, since 2025, illegal activities involving virtual assets have become more complex and increasingly show a convergence trend. These include the operation of scam centers linked to organized crime groups, “pig-butchering” scams, cyber theft related to North Korea, terrorist financing/proliferation financing (TF/PF), evasion of sanctions, and cross-border money laundering. Stablecoins, peer-to-peer (P2P) transactions conducted via non-custodial wallets, offshore VASPs, OTC brokers, cross-chain tools, and activities related to DeFi continue to pose significant risks. This highlights the need to strengthen public-private cooperation, enhance monitoring, and implement concrete risk-mitigation measures by relevant jurisdictions and the private sector.

The Distance Between Being and Effectiveness | Looking at Risk Control from FATF’s Latest Report

Background
In July 2026, the Financial Action Task Force (FATF) released its seventh (dedicated progress report on the regulation of virtual assets and virtual asset service providers) [1].
FATF noted that, since 2025, illegal activities involving virtual assets have become more complex and increasingly show a convergence trend. These include the operation of scam centers linked to organized crime groups, “pig-butchering” scams, cyber theft related to North Korea, terrorist financing/proliferation financing (TF/PF), evasion of sanctions, and cross-border money laundering. Stablecoins, peer-to-peer (P2P) transactions conducted via non-custodial wallets, offshore VASPs, OTC brokers, cross-chain tools, and activities related to DeFi continue to pose significant risks. This highlights the need to strengthen public-private cooperation, enhance monitoring, and implement concrete risk-mitigation measures by relevant jurisdictions and the private sector.
Article
Threat Intelligence|Analysis of GitHub Poisoning Disguised as RecruitmentBackground Recently, MistEye detected a malicious code delivery campaign that used recruiting as bait and targeted developers. The attacker first contacted developers via LinkedIn, posing as a recruiter for a Web3 project. After discussing the victim’s work experience and interview scheduling, the attacker sent a GitHub repository to the target, claiming it contained the MVP that needed to be tested before the interview. Chat logs show that the attacker first asked the target about their work experience and product expertise, and then discussed follow-up interview arrangements. Afterwards, the other party said they needed the target to experience the product in advance in order to discuss specific issues during the interview, and used this to request the target to run projects in the repository.

Threat Intelligence|Analysis of GitHub Poisoning Disguised as Recruitment

Background
Recently, MistEye detected a malicious code delivery campaign that used recruiting as bait and targeted developers. The attacker first contacted developers via LinkedIn, posing as a recruiter for a Web3 project. After discussing the victim’s work experience and interview scheduling, the attacker sent a GitHub repository to the target, claiming it contained the MVP that needed to be tested before the interview.
Chat logs show that the attacker first asked the target about their work experience and product expertise, and then discussed follow-up interview arrangements. Afterwards, the other party said they needed the target to experience the product in advance in order to discuss specific issues during the interview, and used this to request the target to run projects in the repository.
Article
Threat Intelligence|On-Chain Backdoor in a TRAE Malicious ExtensionA malicious extension that has been removed from Open VSX but is still downloadable from the extension marketplace of the TRAE IDE. The extension masquerades as a common Solidity language support plugin, with the package name juannegro.solidity. As of July 18, 2026, the TRAE plugin marketplace API still provides version 0.0.189 of this extension (VSIX file). Reverse engineering shows that this extension is actually a cross-platform (Windows, macOS, Linux) malware dropper. It automatically runs after the IDE starts, creates a user-level persistence (autostart) entry in the system, and then retrieves the download address of subsequent malicious code via an Ethereum smart contract, or directly connects to a remote control Shell address.

Threat Intelligence|On-Chain Backdoor in a TRAE Malicious Extension

A malicious extension that has been removed from Open VSX but is still downloadable from the extension marketplace of the TRAE IDE. The extension masquerades as a common Solidity language support plugin, with the package name juannegro.solidity. As of July 18, 2026, the TRAE plugin marketplace API still provides version 0.0.189 of this extension (VSIX file).
Reverse engineering shows that this extension is actually a cross-platform (Windows, macOS, Linux) malware dropper. It automatically runs after the IDE starts, creates a user-level persistence (autostart) entry in the system, and then retrieves the download address of subsequent malicious code via an Ethereum smart contract, or directly connects to a remote control Shell address.
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number
Sitemap
Cookie Preferences
Platform T&Cs