Crypto Investors Face Global Physical Coercion Attacks to Steal Private Keys
The human layer is the new attack surface; physical coercion exploits social engineering to bypass all digital security controls.
Web3 Users Compromised by AI-Aided Phishing Network Stealing Seed Phrases
The FreeDrain campaign leverages AI-generated content and search engine spamdexing to steal mnemonic phrases, bypassing traditional security controls at scale.
Web3 Users Compromised by New Eleven Drainer Phishing-as-a-Service
Eleven Drainer is the latest DaaS threat, leveraging social engineering to trick users into signing malicious token approvals, bypassing smart contract security.
Centralized Exchange Users Targeted by AI Deepfake Voice Phishing Attacks
AI-driven voice cloning is weaponizing social engineering, establishing a high-trust, high-urgency vector for critical credential theft.
New Phishing-as-a-Service Group Targets Web3 Wallet Token Approvals
The emergence of Eleven Drainer professionalizes social engineering, weaponizing malicious `permit` and `approve` calls to systematically sweep user-approved assets.
Mobile Malware Uses OCR to Steal Wallet Seed Phrases from Screenshots
The SparkCat and SpyAgent malware strains weaponize Optical Character Recognition to exploit the human layer, reading and exfiltrating private keys stored as device images.
Telegram Social Engineering Scam Drains User Funds with False Recovery Promises
This loss recovery scheme weaponizes emotional vulnerability and social proof to funnel non-reversible USDT into international scam wallets.
Exchange Private Key Compromised via Partner Social Engineering Attack
Off-chain social engineering against third-party vendors remains a critical attack vector, bypassing hardened on-chain controls.
Brazilian Crypto Investors Targeted by WhatsApp Social Engineering Malware
The Eternidade Stealer, a sophisticated banking trojan, weaponizes WhatsApp social engineering to steal user private keys and financial credentials.
