Apple2026-09-29 00:21:02SlowMist CISO says Apple update may have fixed zero-day used to steal crypto walletsSlowMist Chief Information Security Officer 23pds said Apple has released an important update that likely fixes a zero-day vulnerability used to steal crypto wallets. Apple said it is aware of a report indicating the issue may have been exploited in an extremely sophisticated attack targeting specific individuals. The company said the flaw affects iOS versions earlier than iOS 27. The brief was cited by Wu Blockchain and carried by Techub News. No further technical details, affected wallet names, or loss figures were disclosed in the source material.350
SlowMist2026-09-29 00:25:47SlowMist’s Cos warns older iOS versions are being used to steal crypto walletsChainCatcher reported that SlowMist founder Cos said in a post on X that systems running versions earlier than iOS 27 are being exploited by some criminal groups to steal crypto wallets from iPhone users. He urged users to update their iPhone, iPad, Mac and other devices to the latest version as soon as possible. Cos also advised users to be careful when installing apps from unknown sources and to avoid opening suspicious links through Safari or in-app browsers. The warning focuses on device security and basic operational precautions for Apple users who store or access crypto wallets on their devices.310
U.S. Senate2026-09-28 13:09:10U.S. Senate report says 84% of sanctioned Iran-linked wallets transacted in USDTA report from Democratic members of the U.S. Senate Permanent Subcommittee on Investigations examined 846 crypto wallets sanctioned by the United States and Israel over links to Iran and found that 84% of them used USDT either entirely or almost entirely for transactions. The report said USDT has become an important payment tool for Iran to evade sanctions and support what it described as a "shadow banking system." It also criticized Tether for not freezing some sanctioned wallets quickly enough. The subcommittee has submitted the report to the U.S. Department of Justice and the Treasury Department. Tether did not respond to a request for comment from The Wall Street Journal, though it had previously cooperated with law enforcement to freeze some wallets tied to Iran.270
SlowMist2026-09-25 12:19:34SlowMist says no confirmed crypto theft tied to investigated iPhone Safari attackSlowMist said it has not independently confirmed any cryptocurrency theft caused by the specific iPhone Safari attack sample behind recent security warnings, even as reports urged users to update their devices and warned that malicious webpages could expose private keys and seed phrases. According to the blockchain security firm, the strongest technical evidence it has so far applies to iOS 18.4 through 18.6.2, while broader claims that the issue affects devices from iOS 13 to iOS 26.5 should still be treated as preliminary. SlowMist said it does not want to state that iOS 26.5 is affected without reproducible technical evidence. The company added that the Safari attack reuses methods from the previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components hidden in an App Store app. Its analysis found that the malicious sample was built to access Apple Keychain, retrieve and decrypt stored data, and read app files and shared app data that could include information from crypto wallet apps. Even so, SlowMist said the sample shows collection capability and intended targets, not proof of successful extraction from every targeted wallet. The firm still advised users to install the latest iOS security updates, avoid suspicious links, consider Lockdown Mode if they face higher risk, and move assets to a newly generated wallet on a clean device if they suspect their keys or seed phrases may have been exposed.310
North Korea2026-09-21 08:44:27FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlumThe FBI and Japan’s National Police Agency have publicly attributed a crypto-focused theft campaign to WaterPlum, a North Korean hacking group also known in the security industry as Contagious Interview. According to a warning document released last Friday and reporting by Forbes, the group posed as recruiters offering high-paying remote jobs, then tricked software developers and IT workers into running malware during coding tests or fake troubleshooting tasks. Authorities said the operation hit at least 30,000 devices across more than 100 countries and drained over 7,000 crypto wallets, with total proceeds reaching $10.7 million. The joint warning says the stolen funds and credentials ultimately flowed to Pyongyang. The malware packages used in the scheme included BeaverTail, InvisibleFerret, OtterCookie and a newer strain called StoatWaffle, which could launch after a target opened a blockchain-themed project folder in Visual Studio Code and clicked "Trust." Once active, the malware stole passwords, keystrokes, screenshots, wallet seed phrases and even passport photos. Authorities and security researchers said the campaign shows a shift in focus from major platforms to individual developers. The warning also documented AI face-swapping in interviews, fake job applications, and links to a laptop farm case in Japan.430
North Korea h2026-09-21 01:57:24North Korean hacking group WaterPlum posed as recruiters and stole $10.7 million in cryptoNorth Korean hacking group WaterPlum allegedly posed as recruiters for cryptocurrency, AI and NFT companies to distribute malware to software developers and IT workers. The malicious files were disguised as coding assignments or fixes for video meeting issues. According to the report, the campaign infected at least 30,000 devices across more than 100 countries. Cointelegraph said the group extracted funds or account credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The total amount stolen was at least $10.7 million. The case points to a broad social engineering operation aimed at people working in technical roles tied to the digital asset sector.460
WaterPlum2026-09-21 01:57:46North Korean group WaterPlum posed as recruiters to deliver malwareChainCatcher reported that the North Korean hacking group WaterPlum posed as recruiters from cryptocurrency, AI, and NFT companies and sent malware to software developers and IT workers. The malicious files were disguised as coding assignments or fixes for video meeting software. According to the report, the group infected at least 30,000 devices across more than 100 countries. It also extracted funds or account credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The total amount stolen was at least $10.7 million. The report points to a targeted social engineering campaign aimed at people working in technical roles, with the malware distributed under the cover of job-related communication and work tasks.480
Policy and Re2026-09-20 00:51:56Multinational warning says North Korea-linked hackers used fake crypto and AI job offers to target developersA joint warning cited by Forbes says a North Korea-linked hacking group known as WaterPlum, also called Contagious Interview, targeted IT developers worldwide through fake job offers between December 2025 and July 2026. The alert was issued by multiple agencies, including the U.S. Federal Bureau of Investigation and Japan’s National Police Agency. According to the warning, the attackers posed as companies in the AI, cryptocurrency, and NFT sectors. They approached job seekers on social media and recruitment platforms, then used supposed technical interviews or coding tests to persuade targets to download malicious files. Authorities said the campaign infected more than 30,000 devices across over 100 countries and regions. The warning also said data was stolen from more than 7,000 crypto wallets, and at least $10.71 million was traced to wallets controlled by the attackers. The case adds to a growing list of cyber operations tied to fake hiring processes aimed at developers and crypto users.320