BTC $64,421.24 +0.67%
ETH $1,877.49 +1.05%
BNB $569.37 +0.87%
XRP $1.09 +0.54%
SOL $74.70 +0.90%
TRX $0.3309 +0.07%
DOGE $0.0722 +3.94%
ADA $0.1648 +0.75%
BCH $209.19 -0.46%
LINK $8.39 +0.75%
HYPE $58.50 +1.86%
AAVE $92.32 +1.23%
SUI $0.7126 +0.41%
XLM $0.1771 -0.89%
ZEC $486.58 -0.02%
BTC $64,421.24 +0.67%
ETH $1,877.49 +1.05%
BNB $569.37 +0.87%
XRP $1.09 +0.54%
SOL $74.70 +0.90%
TRX $0.3309 +0.07%
DOGE $0.0722 +3.94%
ADA $0.1648 +0.75%
BCH $209.19 -0.46%
LINK $8.39 +0.75%
HYPE $58.50 +1.86%
AAVE $92.32 +1.23%
SUI $0.7126 +0.41%
XLM $0.1771 -0.89%
ZEC $486.58 -0.02%

gram

All
Article
Flash

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.

Ministry of Industry and Information Technology and three other departments: Strengthen the planning of internet technology innovation, promote the implementation of relevant national key research and development programs and major national science and technology projects

According to a report by Jinshi Data on July 13, the Ministry of Industry and Information Technology and three other departments issued guidance on promoting the high-quality development of internet infrastructure resources. It mentioned strengthening the planning of internet technology innovation, promoting the implementation of relevant national key research and development programs and major national science and technology projects, enhancing original technology innovation, and carrying out technical research on the integration of artificial intelligence, blockchain, distributed identifiers and internet infrastructure resources, breaking through key technologies such as network dynamic optimization, intelligent resource scheduling, and data security interaction. Strengthening the innovation of the IPv6 technology system to solve key issues such as protocol compatibility and high-performance transmission. Breaking through key technologies for satellite internet mega-constellation networking, rapid routing switching, and reliable anti-jamming transmission. Breaking through key technologies for the large-scale deployment and application of resource public key infrastructure.
app_icon
ChainCatcher Building the Web3 world with innovations.