The address labeled Bofur Capital lost $2M due to an address poisoning attack after withdrawing from Compound. A phisher sent a small USDC transaction to spoof the address, and the victim mistakenly copied the wrong address, leading to the drain. The stolen funds were swapped to 2M DAI.
Coinkite advised Coldcard users to generate new seed phrases, warning that existing vulnerable seeds remain unsafe despite a firmware update aimed at strengthening seed generation.
Cybersecurity firm Rapid7 has identified a phishing campaign targeting 885,000 phone numbers, aiming to steal cryptocurrency by redirecting users to fake wallet websites.
A suspicious outflow of $1.284 million USDC was detected on August 11th from a vultisig-related address. Approximately $1.092 million USDC was swapped for ETH and deposited into Tornado Cash.
BitBox has patched severe wallet flaws recommending users update to firmware version 9.26.5. The company has received no reports of exploitation or fund losses.
Boltz, a Bitcoin swap service, remains offline after its founders exited and an unnamed group agreed to take over. The service is being fixed for vulnerabilities that caused losses to the company.
SafePal reported a breach exposing the personal data of 39,798 buyers, including names, phone numbers, and shipping addresses, due to a flaw in an order-tracking plug-in. The stolen data is being advertised for sale.
Trezor reported that data from 14,000 users, including names, phone numbers, and shipping addresses, was exposed through a shipping provider flaw over 14 months. The company warns of potential phishing risks.
Coinsbuy lost $8.07 million across TRON and Ethereum within an hour. The project's Twitter account has been dormant since 2020, and the cause of the failure has not been disclosed.