Security
The Defiant Security posts
Top Stories

Fake AI Bot Tutorials Tricked 224 Victims Into Deploying Their Own Drainers
TRM traced 274.60 ETH to six operator addresses after victims signed and funded malicious contracts themselves between February and August.

Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand
Chainalysis says North Korean operators use Tron, Aptos and BNB Smart Chain as redundant command paths, while suspected Iranian actors encode routing data in Bitcoin transactions.
Free newsletters
The Defiant Daily
Independent reporting on crypto and DeFi. The stories that matter, in your inbox.
Monday–Friday. Free. Unsubscribe anytime.
Advertisement
Videos
Recent articles

Fake AI Bot Tutorials Tricked 224 Victims Into Deploying Their Own Drainers
TRM traced 274.60 ETH to six operator addresses after victims signed and funded malicious contracts themselves between February and August.

Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand
Chainalysis says North Korean operators use Tron, Aptos and BNB Smart Chain as redundant command paths, while suspected Iranian actors encode routing data in Bitcoin transactions.

Blockstream Rejects Ransom Demand After Liquid Bitcoin Exploit
Liquid said on Sept. 8 that 3,400 BTC had been returned and about 598.5 BTC remained outstanding; transactions later resumed with peg-outs disabled.
Liquid Attacker Broadcasts Return Of 3,400 BTC, Keeps 598
The transaction pays 3,400 BTC back to the Liquid federation wallet and 598.50 BTC to the attacker’s own address. It is unconfirmed and flagged replaceable, and neither side has published anything about the split.
Liquid Sidechain Paused After 3,998 BTC Leaves Federation Wallet
Blockstream's Liquid disabled its bridge nodes on Sunday after almost the entire bitcoin reserve backing L-BTC was withdrawn to a single address, whose owner wrote “we are whitehats” into a bitcoin transaction.

Fogo Mainnet Has Been Stopped For 46 Hours With No Restart Timeline
The chain has produced no blocks since Saturday, the halt notice is still the Foundation's most recent update, and an impersonator account is circulating a fake compensation vote.
Core Lightning Tells Node Operators To Go Offline, With No Patch Published
The CLN team said operators who don’t upgrade should run their nodes --offline, but the fixed binaries aren’t out yet and the details of what they fix are under a two-week embargo.
SafePal Breach Exposes 39,798 Buyers as Stolen Records Hit Cybercrime Forum
The wallet maker says a flaw in an order-tracking plug-in leaked names, phone numbers and shipping addresses over 14 months. A seller is now advertising the file.

Trezor Shipping-Provider Breach Exposes Data of 13,689 Customers
ShipMonk incident exposed names and contact details of recent customers in seven countries; Trezor says its devices and systems were not compromised.

Coldcard Thefts Near $114 Million as Fourth Attack Wave Hits
A firmware bug that shipped in 2021 made Coldcard seeds guessable, and attackers have drained more than 1,800 BTC since Thursday. The latest sweep can still be outbid in the mempool, giving some victims a window to rescue their coins.


