Microsoft's official X account was compromised for approximately 30 minutes on October 2, 2026, and used to promote a fraudulent $Clippy token. Microsoft regained control, removed the posts, and is investigating the incident.
MemTensor's AI memory tooling, including the MemoryOS library (PyPI) and the memtensor/memos-cloud-openclaw-plugin (npm), has been compromised. This affects their open-source long-term memory library for LLM and AI agents and its official plugin for the OpenClaw agent.
Malicious versions of the iOS app FomoPeek, distributed via the Apple App Store, have been linked to approximately $580,000 in crypto theft. SlowMist reported that these versions exploited iOS kernel vulnerabilities to access sensitive data from other applications.
Security researchers and Ledger's CTO have warned of a zero-day exploit in Safari targeting iPhones running iOS 13 through 26.5. The exploit, delivered via malicious webpages, can escalate to kernel-level access to steal private keys and seed phrases from crypto wallets stored on the device.
Curaçao's gambling regulator, the CGA, announced on September 17 that its online gaming portal was hacked. The extent of the breach is still under investigation, but users speculate that sensitive data of crypto casino operators, potentially including personal information and KYC details, may have been compromised and could be leaked.
A supply chain attack has been identified where a malicious PHP package, visanduma/nova-two-factor, injects code into Laravel Nova extensions. This code queries Ethereum transactions to find C2 server IP addresses and then downloads a cross-platform credential stealer targeting browser accounts, crypto wallets, and developer credentials. There is currently no evidence of successful theft.
Crypto technology provider Haruko suffered a cyberattack that exposed read-only exchange API details and trading data for 15 clients. Some smaller hedge funds with weaker security controls may have lost a small amount of funds. Haruko has fixed the vulnerability and refreshed its server-side secrets.
Long's custodial bridge was affected by a supply chain attack where a third-party RPC fed fabricated withdrawal events, leading to the release of approximately $118,000 worth of WETH. The team halted the keeper, rebuilt verification, and refilled the vault, with no user funds lost.
Peru's Ministry of Economy and Finance confirmed its official X account was compromised by crypto scammers promoting a fake token called $HYLO. The ministry clarified the posts were unauthorized, deleted the fraudulent messages, and regained control of the account.
Swiss Bitcoin Pay, a non-custodial Bitcoin payment processor, shut down its servers due to a suspected data breach. The company stated that no customer funds or private keys are at risk, and minor security updates have been applied.
Revolut experienced a data breach where a sophisticated phishing attack, impersonating a government agency, bypassed email security protocols (SPF, DKIM, DMARC) and tricked the company into handing over sensitive customer data, including identity documents and Bitcoin transaction histories. No customer funds were stolen, and Revolut has notified law enforcement and regulators.
Trezor's third-party email provider has been breached, leading to potential phishing attacks. Users are advised to avoid clicking links in suspicious emails.
Trezor announced that an additional 67,000 US users were impacted by a data breach at its shipping provider, ShipMonk. This incident could lead to increased risks of phishing and social engineering attacks against affected customers.
SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page. The decoy page loads JavaScript that screens for iPhones, potentially leading to asset theft from the DarkSword wallet.