VPN

OpenAI
2026-08-25 18:59:35

OpenAI bans Russian influence accounts that used ChatGPT to produce pro-Kremlin content

OpenAI said it identified and banned a cluster of accounts tied to a covert Russian influence operation that used ChatGPT to generate social media posts. According to the company, the operation accessed the platform through Russian VPN services, promoted a fabricated entity called the "International Burke Institute," and produced German-language Telegram content critical of the European Union and the German government. OpenAI said the campaign has had limited reach so far, but warned that the infrastructure behind it could be scaled up in the future. The report was cited by Techub News, referencing The Decoder. The disclosure adds to OpenAI’s public reporting on how its tools are being used in coordinated influence efforts and how those campaigns attempt to distribute political messaging across online platforms.

20
OpenAI bans Russian influence accounts that used ChatGPT to produce pro-Kremlin content
Firefox
2026-08-25 14:17:21

Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases

Security firm Socket said it found a cluster of malicious cryptocurrency wallet extensions targeting Firefox users and tied them to an operation it calls "Offside Wallet Theft Factory." The company linked 77 extension identities to the campaign, with 40 confirmed as malicious, and said the activity ran for at least from March to August 2026. The extensions mainly impersonated well-known Web3 wallets including OKX, Rabby Wallet and TronLink, using highly convincing wallet interfaces to trick users into importing existing wallets and handing over seed phrases or private keys. Socket said roughly half of the malicious extensions directly prompted users to enter seed phrases. Another 13 were tampered Rabby builds that sent wallet account data to external servers when users saved account information, while five collected stored credentials and clipboard contents. Socket also found that at least nine of the malicious extensions had previously operated as sports score apps covering football, basketball and the NBA, building up users and reviews before later switching to wallet-stealing code through updates. It warned that anyone who entered a seed phrase or private key into the affected extensions should treat those credentials as permanently compromised and move funds to a brand-new wallet immediately.

00
Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases
Firefox exten
2026-08-25 14:18:31

Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious

Security firm Socket has linked 77 Firefox extensions to a malicious operation it calls the "Overstep wallet theft factory," according to a report cited by Decrypt. Of those, 40 have been confirmed as malicious. The extensions allegedly impersonated Web3 products including OKX, Rabby Wallet and TronLink, either by presenting fake wallet interfaces that pushed users to import existing wallets or by using modified versions of legitimate wallet code to steal seed phrases and private keys as they were entered. Mozilla signing records cited by Socket show the activity ran from March 9 to Aug. 3, and several of the extensions were still live when the report was published. Socket said about half of the extensions displayed realistic wallet interfaces designed to capture seed phrases or private keys. Another 13 were modified Rabby builds that functioned normally while sending stored account data to external servers, while five were built to collect saved credentials and clipboard contents. Socket also found 37 extensions posing as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually running a sports scores app that shared the same hardcoded credential. Nine confirmed malicious extensions were first published as football or basketball score apps before later updates swapped in wallet-stealing code. Socket said users who entered seed phrases or private keys into any of these extensions should treat them as permanently compromised and move funds to a new wallet immediately.

00
Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious
Firefox
2026-08-25 14:10:05

Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious

Socket’s threat research team said it linked 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 of them as malicious. According to the company, the extensions impersonated crypto wallet and Web3 brands including OKX, Rabby Wallet, and TronLink, with many designed to trick users into importing an existing wallet and entering a recovery phrase or private key. Mozilla signing records placed the campaign between March 9 and August 3, and Socket said several of the extensions were still live when it reported them. The researchers also found that 37 other extension identities were presented as unrelated utilities but actually displayed live sports scores. In nine confirmed cases, football, basketball, NBA, or American football score apps were later updated into wallet-stealing malware, allowing the operators to retain the install base and review history built by the original apps. Socket named the pattern the “Offside Wallet Theft Factory,” while saying it has not established that every extension was run by a single operator. The firm warned that users who entered a recovery phrase or private key into any of the affected extensions should treat those credentials as permanently compromised and move funds to a new wallet.

00
Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious
Keeta
2026-08-24 02:14:52

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days

Three separate crypto protocols were hit by attacks in less than a week, each exposing a different failure point in onchain security. On Aug. 20, payments-focused blockchain Keeta Network switched its mainnet to read-only mode after what it described as a security issue in a single component. The team later demanded that the attacker return the funds within 72 hours and said it had gathered evidence including IP data, VPN and VPS details, user-agent information, related email accounts, and service providers. On Aug. 22, The Sandbox suffered a cross-chain minting attack tied to its SAND bridge contract on Base. The attacker allegedly abused approveAndCall to seize LayerZero delegate authority, minting large amounts of SAND on Base and BNB Chain without Ethereum mainnet backing. While the notional over-minting figure reached about 14.9 billion SAND, the project and security reviews said the actual value drained from reserves and monetized was about $670,000. A day later, fixed-rate lending protocol Term Finance saw a governance proposal executed after sitting onchain for roughly six days with zero opposing votes. Assets moved out of the protocol included about 2,843 ETH and 1.68 million USDC, with reported losses around $8.5 million. Taken together, the three incidents point to a recurring question in crypto infrastructure: who can mint, who can change parameters, and who is watching governance before execution.

420
Three protocol attacks hit Keeta, The Sandbox and Term Finance within days
Keeta
2026-08-23 01:53:06

Keeta gives attacker 72 hours to return funds, says bug bounty is possible after full repayment

Keeta Network has issued a 72-hour ultimatum to the party behind a recent attack on its payment-focused blockchain, saying the attacker can avoid legal escalation only by returning all stolen funds in full. In a message addressed to the attacker, Keeta CEO Ty said the company’s investigation has made substantial progress and that it has collected evidence that could help identify those responsible. According to Ty, the material includes IP addresses tied to the attack, details on the VPN and VPS infrastructure used, user-agent and technical environment data linked to unauthorized requests, related email addresses, and information on software and infrastructure service providers. He said the evidence has been preserved and submitted to relevant parties. Keeta said repayment can be made in KTA, ETH, or USDC. If the full amount is returned within the deadline, the company said it is willing to offer a reward and resolve the matter without pursuing legal liability. If the funds are not returned on time, Keeta said it will retain all rights to seek legal action and pursue recovery of the assets.

170
Keeta gives attacker 72 hours to return funds, says bug bounty is possible after full repayment
Keeta
2026-08-23 01:52:57

Keeta tells attacker to return funds within 72 hours as probe identifies key evidence

Keeta Network said it has made material progress in its investigation into a recent attack on the payment blockchain, with CEO Ty stating that the team has gathered evidence that could identify the attacker. The preserved evidence has already been submitted to relevant parties and includes attack-linked IP addresses, details on VPN and VPS infrastructure, user-agent and technical environment data tied to unauthorized requests, related email addresses, and information on software and infrastructure providers allegedly used in the incident. Ty said the attacker has 72 hours to return all funds taken in the exploit, with repayment accepted in KTA, ETH, or USDC. If the full amount is returned, Keeta is willing to offer a reward and resolve the matter without pursuing legal action. If the deadline passes without repayment, the company said it will retain all rights to seek legal remedies and recover the funds. Ty also said the root cause of the incident has been confirmed and a patch is being tested. According to the statement, the issue is isolated to the affected component and does not affect Keeta’s anchor system or any externally connected systems. All KTA on Base were said to be unaffected, while the Keeta mainnet will remain in read-only mode until testing is complete and added safeguards are in place.

160
Keeta tells attacker to return funds within 72 hours as probe identifies key evidence
Keeta Network
2026-08-23 01:41:10

Keeta gives attacker 72 hours to return funds after security incident

Keeta Network has issued a public ultimatum following a recent attack, saying it has made substantial progress in its investigation and gathered evidence that could identify the party behind the incident. In a statement from CEO Ty, the payment-focused public blockchain said the material collected includes IP addresses tied to the attack, details on the VPN and VPS infrastructure used, user-agent and technical environment data from unauthorized requests, related email addresses, and information on the software and infrastructure service providers involved. Keeta said the evidence has been preserved and submitted to relevant parties. The project is demanding that the attacker return all funds obtained in the exploit within 72 hours, and said repayment can be made in KTA, ETH, or USDC. If the funds are fully returned, Keeta said it is willing to offer a reward for identifying the vulnerability and resolve the matter without pursuing legal action. If the deadline passes without full repayment, the company said it will retain all rights to seek legal accountability and recover the funds. Ty had previously said on Aug. 20 that the root cause of the incident had been identified, that the issue was limited to the affected component, and that neither the pegging system nor external connection systems were involved. He also said KTA on Base was unaffected, the mainnet would remain in read-only mode until patch testing is complete, and the team is evaluating a full compensation plan for affected users.

300
Keeta gives attacker 72 hours to return funds after security incident