BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%
BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%

slowmist

All
Article
Flash

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code, which may lead to the leakage of private keys and mnemonic phrases

SlowMist released a security warning stating that it has recently received multiple reports of FomoPeek users' assets being stolen. After a joint investigation with the OKX security team, it was found that some affected users had previously installed or used FomoPeek versions 1.1 to 1.2, which contained malicious code. SlowMist stated that there are modules in FomoPeek unrelated to normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting eight different attack methods that can automatically select the exploitation method based on device model and iOS version. Affected systems include iOS 12 to 18.7 and iOS 26 to 26.1. If the exploitation is successful, the application may break through the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files. In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist indicated that its analysis of captured plaintext traffic shows that the related attack functions are currently enabled and will run automatically on a regular basis. SlowMist recommends that users who have installed or used FomoPeek versions 1.1 to 1.2 immediately check for any anomalies in their assets, generate new private keys and mnemonic phrases on trusted devices that have never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and not continuing to use or reinstall FomoPeek.

OKX, in collaboration with Elliptic, SlowMist, and OttoSec, released the Web3 Security and Risk Control Report for the first half of 2026

According to official news, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "Web3 Security and Risk Control Report for the First Half of 2026." The report points out that the focus of Web3 attacks is gradually shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, the OKX risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million transactions related to hacking and theft, about 1.48 million transactions related to phishing, and around 990,000 transactions related to fraud. The OKX Web3 on-chain intelligence label library currently has over 1 billion labels, covering more than 420 chains, and has integrated capabilities such as address screening, transaction monitoring, and sanction address control into infrastructures like DEX and Exchange OS.In addition, in terms of user protection, OKX has intercepted over 7 million visits to risky websites, completed over 200,000 device risk assessments, identified over 60,000 high-risk apps, and intercepted or alerted on over 4 million high-risk signature operations. The report also introduces the "risk control pre-positioning" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.
app_icon
ChainCatcher Building the Web3 world with innovations.