‹ BackNewsseed phrase

seed phrase

THORSwap says hijacked third-party support widget led to about $58,000 in losses
SlowMist warns DarkSword iOS exploit is now being used in real attacks
SafePal
2026-09-18 03:45:29

SafePal outlines how crypto users can spot and avoid social engineering scams

SafePal has published a security guide warning crypto users that many losses begin not with a technical exploit, but with a scammer persuading the victim to hand over control. The guide says social engineering attacks often rely on impersonation, urgency, fake websites, malicious software, long-term trust building, and even offline delivery tactics rather than direct wallet or system compromise. According to the guide, common setups include fake customer support messages on Telegram, Discord, X, WeChat, or by phone; phishing links distributed through email, text messages, search ads, QR codes, and direct messages; and pressure tactics built around claims that assets are being stolen or accounts are about to be frozen. SafePal also warns about scams tied to airdrops, NFT rewards, high-yield investment offers, recovery services, and unsolicited hardware devices sent through offline channels. The company breaks these attacks into three stages: building credibility, creating a reason that demands action, and then pushing the victim to visit a site, scan a QR code, download software, connect a wallet, sign a transaction, share a screen, reveal credentials, or transfer funds. SafePal says users should never share seed phrases, private keys, PINs, or wallet passwords, should not verify a sender through links or numbers provided by that sender, and should avoid approving signatures or permissions they do not understand. If a seed phrase or private key has already been exposed, the guide says the wallet should be treated as compromised and assets should be moved to a newly created wallet on a trusted device.

490
SafePal outlines how crypto users can spot and avoid social engineering scams
wallet recove
2026-09-04 09:22:17

Wallet recovery expert unlocked a supposed $1 billion ETH wallet and found about $10

A 2021 case involving a client calling himself Rusty has become a sharp example of the limits and risks of crypto wallet recovery. Rusty told wallet recovery specialist Chris Brooks that he and two others had won a lawsuit and gained access to 5,000 BTC, then worth about $53 million, along with $1 billion in ETH. Brooks and his father flew overnight to Georgia and spent a full day working on the wallets in a back office at a shopping mall. They ultimately found only about $10. The case sits at the center of a broader point made by recovery professionals: people often believe they have lost access to large crypto holdings, but in many situations the money was never in the wallet they are trying to open, or the issue stems from missing information rather than missing onchain funds. The report examines what can and cannot be recovered across mnemonic phrases, passwords, passphrases, and hardware wallets. Industry figures cited in the piece, including Bruno Krauss of ReWallet, Bitcoin educator Bennet, and Trezor analyst Lucien Bourdon, say some wallets can be recovered when users retain partial information or when software, password generation, or hardware defects create an opening. But if a truly random seed phrase is completely lost, there is usually no practical path back. They also warn that handing wallet backups to a recovery service creates a separate security problem, since anyone with the necessary seed data may be able to control the funds.

890
Wallet recovery expert unlocked a supposed $1 billion ETH wallet and found about $10
Researchers Uncover 19 Malicious Chrome and Edge Extensions That Steal Crypto Wallet Keys
Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases
Firefox exten
2026-08-25 14:18:31

Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious

Security firm Socket has linked 77 Firefox extensions to a malicious operation it calls the "Overstep wallet theft factory," according to a report cited by Decrypt. Of those, 40 have been confirmed as malicious. The extensions allegedly impersonated Web3 products including OKX, Rabby Wallet and TronLink, either by presenting fake wallet interfaces that pushed users to import existing wallets or by using modified versions of legitimate wallet code to steal seed phrases and private keys as they were entered. Mozilla signing records cited by Socket show the activity ran from March 9 to Aug. 3, and several of the extensions were still live when the report was published. Socket said about half of the extensions displayed realistic wallet interfaces designed to capture seed phrases or private keys. Another 13 were modified Rabby builds that functioned normally while sending stored account data to external servers, while five were built to collect saved credentials and clipboard contents. Socket also found 37 extensions posing as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually running a sports scores app that shared the same hardcoded credential. Nine confirmed malicious extensions were first published as football or basketball score apps before later updates swapped in wallet-stealing code. Socket said users who entered seed phrases or private keys into any of these extensions should treat them as permanently compromised and move funds to a new wallet immediately.

1050
Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious
SafePal says it is selecting anti-phishing firms and independent security auditors after order system data leak