‹ BackNewswallet security

wallet security

Scam Sniffer says Ethereum user lost about $167,000 in phishing attack
Revoke.cash urges users to review Auto-Revoking settings after Magic Eden security incident
MetaMask says infrastructure was affected in security incident, sees no direct threat to wallets
Crypto hardware wallets compared for 2026: Ledger, Trezor, QR devices and Bitcoin-only models
SlowMist
2026-09-30 04:58:55

SlowMist says earliest malicious activity in Bitget incident dates back to Aug. 31

SlowMist has released a preliminary investigation into the Bitget incident, saying the earliest malicious activity it has identified can be traced to Aug. 31. According to the report shared by SlowMist founder Cos on social media, the attacker is suspected of compromising two third-party security products and a wallet business host before using a customized withdrawal tool to move assets across multiple blockchains. The report says a node server tied to third-party security product A had a zero-day vulnerability on Aug. 31, when hidden scripts were run under a service process to read database passwords, environment variables, and connect to the database. Similar hidden-script activity was later found on two more nodes on Sept. 23 and Sept. 25. SlowMist also said the attacker likely entered the management platform of security product B in the early hours of Sept. 25 by abusing an internal employee account, then used task parameters and a web execution entry to write malicious files, alter server settings, and assemble malware. Host logs show the malicious program began running at 01:49 on Sept. 25. On-chain records show the first verified outbound transfer took place at 02:31, when the attacker address received 93 TRX and, 11 seconds later, 0.84 ETH. SlowMist said the investigation was still ongoing as of Sept. 29 and has not yet disclosed attribution, the final scale of losses, or the full scope of affected systems.

200
SlowMist says earliest malicious activity in Bitget incident dates back to Aug. 31
Mandiant says attackers entered Bitget wallet environment through third-party security devices
Project Eleven Buys Riva Labs to Add Post-Quantum Wallet and Signing Technology
crypto scams
2026-09-29 04:30:57

2026 crypto scam guide lists 12 common fraud schemes, from fake mainnets to account takeovers

TechFlowPost has published a 2026 crypto scam guide that groups common fraud tactics into five categories and 12 specific schemes, using the recent fake GIWA mainnet incident as a starting point. Written by Changan from the Biteye content team, the piece argues that the most dangerous part of crypto fraud is not only technical trickery, but the constant reshaping of familiar attack surfaces such as X posts, Telegram chats, Google search results, Discord verification flows, wallet history, mobile apps, and exchange recovery processes. The article details several patterns: fake project websites amplified by KOL reposts, fake recruiting and investment outreach that deliver malware through meeting plugins or coding tests, stolen influencer accounts used to launch tokens, Telegram impersonation and code theft, search-engine phishing pages, Discord wallet-drainer verification, fake airdrop emails, address poisoning, fake mainnets and fake bridges, malicious app updates, and exchange account resets backed by forged identity materials. It also cites examples including a fake Hyperliquid site that led to the theft of about 550,000 USDC and the fake GIWA mainnet, where 1,335 addresses sent roughly 767.65 ETH and about 766.25 ETH was drained. Its practical advice is consistent throughout: verify official channels, never share login codes or 2FA credentials, isolate devices from large holdings, review exchange permissions beyond just passwords, and treat every link, signature request, and software download with suspicion.

500
2026 crypto scam guide lists 12 common fraud schemes, from fake mainnets to account takeovers