注册并分享邀请链接,可获得视频播放与邀请奖励。

与「Attackers」相关的搜索结果

Attackers 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 Attackers 的内容
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen laundering funds from the Kelp DAO $292M exploit earlier this year. I've observed the same pattern after multiple TraderTraitor attributed exploits, and I've closely tracked these groups. I plan to share more of my data on them in coming weeks. Currently, funds are being chain-hopped via bridges and being deposited into mixing services such as Wasabi. Alias 1 - Cc Discord: cc02006 Discord ID: 1351486674386948148 Txn: F08657EFAEAE7B58217CD17A22BF4779582E5D080C2E92E173BC239A5D828363 Alias 2 - jack Discord: jack_34808 Discord ID: 1553705721768714377 Txn: 68583D313A0CCC99F2702D61D05A242A69C86CAE09ED252B65F34B677C377F69 Alias 3 - Melon Discord: under0346 Discord ID: 1394240539108573215 Txn 1: ABE2AEF8B10057E60F8259CA2CA2CD5D71D38D254960FEEE89CB3C95A964873F Txn 2: 7BE290865901DEB1680A6D692A11392D1FDDACA0D31C48F26DCB249F2444BD6B Alias 4 - lolo / Marin TG: pvpcz TGID: 6223514198 Discord: losern Discord ID: 1024415186527985704 Txn: 8E935C19D00F40639B78BF1FD094FE48C92118F3E586AB52DF93851080CCCE15 Alias 5 - HELP ME Discord: helpme031897 Discord ID: 1554035533817188384 Txn: 7C58CAD760EBBED54F2CA4D2146D056910B7B6688B4F524396DC8807353C2379
显示更多
0
556
5.7K
750
转发到社区
THORChain and Stolen Funds: The Industry Needs Answers After the $1.46B @Bybit_Official hack last year, nearly $1.2B in stolen funds was reportedly traced through @THORChain as the attackers moved assets across chains. Today, following another major security incident at @Bitget , we are once again observing Bitget Exploiter funds being sent into the THORChain for asset swaps and cross-chain transfers. The question is no longer: “Does THORChain know these funds are associated with hackers?” The attacker addresses have already been publicly flagged and are being actively tracked by exchanges, blockchain security/aml firms, and the wider crypto industry. The real question is: When a protocol is aware that funds originate from a publicly identified major hack, yet continues to facilitate large-scale cross-chain swaps, how should the industry view this under the banner of “decentralization”? Decentralization should not become a blanket excuse when dealing with known stolen funds. If, after every major crypto hack, attackers can continue using THORChain as a route to move funds from ETH → BTC, BNB → BTC, and across other chains, the industry needs to seriously ask: What responsibility should THORChain bear when handling known stolen funds? @GracyBitget @xiejiayinBitget @benbybit
显示更多
0
157
392
50
转发到社区
We stand with @bitget and its users after the recent incident. Our security team has been working closely with their side since it was detected, sharing intelligence, tracing funds, and supporting recovery. In moments like this, the industry unites against the attackers. The work continues.
显示更多
0
178
1.6K
122
转发到社区
🚨 Recently, @COLDCARDwallet suffered a major private key vulnerability. Multiple waves of attacks resulted in at least 1,719 BTC (~$111M) in losses, involving over 5,200 addresses. Using Mk3 firmware 4.1.9 as an example, the SlowMist Security Team fully reproduced the attack chain and uncovered the truth behind the theft of thousands of bitcoins. 🧩 Attack flow: 1️⃣ After power-on, the remaining unpredictable state is reduced primarily to a single enumerable 32-bit pad (UID ^ SysTick), with the remaining state values either fixed or coming from very small enumerable spaces. 2️⃣ Attackers precisely model the three typical button-press consumption profiles (retail first-boot, empty-NVRAM, paper wallet) that advance the PRNG before seed generation. 3️⃣ From the weak random_bytes(32), the full deterministic pipeline (SHA-256 → BIP-39 → PBKDF2-HMAC-SHA512 → BIP-32 → address derivation) is reproduced offline. 4️⃣ GPU clusters brute-force the candidate pad space and button-count variations, then match the derived addresses against the global set of single-signature P2WPKH addresses to identify vulnerable wallets and sweep their funds. ⚙️ Root Cause: A build configuration error set MICROPY_HW_ENABLE_RNG to 0, disabling the STM32 hardware TRNG. The random number generation path silently fell back to the non-cryptographic Yasmarang software PRNG, whose state was almost entirely predictable, reducing effective entropy to ~40 bits (Mk2/Mk3) or ~72 bits (Mk4/Mk5/Q). 🔒 SlowMist Insight: Affected users should immediately upgrade to the patched firmware, generate a completely new seed, transfer a small amount of funds as a test, confirm the new address works correctly, then migrate all remaining funds. Full analysis 👉
显示更多
We’re expanding our cybersecurity initiative Daybreak and introducing GPT-5.6-Cyber, a new model for advanced, authorized cybersecurity work. As the threat landscape evolves, we’re putting frontier intelligence in the hands of trusted defenders before attackers can deploy offensive AI at scale.
显示更多
0
354
6.1K
515
转发到社区
Phishing, explained How attackers impersonate trusted sources to steal logins, seed phrases, or wallet approvals Read more 👇
Last night Apple briefly removed Telegram from the AppStore because a user had planted illegal porn in a public chat. Telegram was restored within hours. But I want to explain what happened — to warn other app developers and help protect online communities from similar attacks. Because Telegram quickly removes illegal content from public groups using all kinds of moderation tools, the attacker had to resort to a technical trick. He inserted AI-modified illegal content by editing an old message in an active group chat. As a result the content was effectively hidden from the group’s members, preventing them from seeing/reporting it. The attacker was a takedown extortionist: someone who demands ransom from group owners in exchange for not targeting their communities. These extortionists use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger the removal of legitimate communities whose owners refused to pay them. From a practical standpoint, illegal pornographic content in Telegram’s public groups is not a systemic problem. Our moderation is effective. The fact that attackers must resort to backdated, effectively invisible content and other technical tricks proves this. ⚠️ However, there are two important lessons here for app developers and online communities: — Extortionists have found a way to manipulate Apple into overreacting. Apple removed Telegram from the App Store before contacting us. This creates a potential systemic risk for every mobile app that hosts user-generated content. If an app used by more than a billion people can be removed from the App Store without prior warning, any app can be. — The tactics used by takedown extortionists are evolving, putting communities across social platforms at risk. Telegram has extensive experience identifying the tricks used by coordinated reporting gangs and protecting legitimate communities (even when doing so risks our own app being temporarily removed from the App Store). Other platforms may not be equally prepared. Stay vigilant! ☝️
显示更多
0
118
701
109
转发到社区
🚨SlowMist TI Alert🚨 💸 @LienFinance Loss: ~542k USD 🔍 Root Cause: The `exchangeEquivalentBonds` function in BondMakerCollateralizedEth lacks proper multiset integrity checks. It only counts total exception occurrences instead of verifying each bondID's appearance per group. By repeating a single exception bondID in the output group, attackers consumed the exception count twice, masking a missing input exception. This allowed minting new non-exception BondTokens without burning the corresponding input bonds, which were then sold for USDC from a pre-approved victim address. 📌 Attacker: 0x0d7d9023531ad1a88414e216ee2715f63561808a 📌 Victim: 0xa961684a3a654fb2cca8f8991226c0cefc514d80 📌 Vulnerable Contract: 0xda6fc5625e617bb92f5359921d43321cebc6bef0, 0x843225cf6e663e4454732d6b551a737ac7b47de0 Attackers exploited the flawed exception-counting logic to mint unbacked bond tokens, swapped them for USDC via three pre-authorized endpoints, and drained 542,144.628604 USDC from the victim. Powered by Tx:
显示更多
⚠️HACKS GALORE: Three exploits drain $35.5 Million within hours in a brutal day for DeFi. - AFX Trade- $24.15M hack The AFX-operated USDC custody bridge on Arbitrum was exploited, forcing the team to suspend bridge operations. - Verus - $7.55M hack The Verus Ethereum Bridge was exploited after an attacker abused the bridge's import mechanism to trigger unbacked payouts, marking the second exploit using the same failure mode since May. - B² Network $3.86M hack Attackers gained unauthorized access to the $B2 staking contract's upgrade authority, prompting the team to suspend staking while security reviews are completed. The issue has since been contained, with no further impact expected.
显示更多
0
21
54
8
转发到社区
You can’t call a product secure without a way to measure it. NEAR AI’s George Zeng on trusting agents that hold credentials and move value: formal verification for what the code does, adversarial benchmarks for how it holds up against attackers that constantly adapt.
显示更多
0
12
257
37
转发到社区