Web3 Users Targeted by Evolving Social Engineering Malware Campaign
The attack leverages sophisticated social engineering to trick high-value users into installing a malicious binary, fundamentally bypassing smart contract security.
Malicious Chrome Extension Skims Solana User Swaps via Hidden Transaction Instruction
Browser extension supply chain risk is high; hidden transaction instructions execute perpetual, low-volume asset skimming from user trades.
Balancer Users Drained via DNS Provider Social Engineering Attack
A third-party DNS provider compromise redirected users to a malicious front-end, enabling unauthorized token approvals and asset draining.
Centralized Exchange Hot Wallet Drained by Compromised Administrative Credential
The compromise of a single administrative credential on a hot wallet system presents an existential operational risk, bypassing cold storage security models.
Website Supply Chain Attack Drains User Wallets via Malicious Script
Third-party resource compromise injected a malicious JavaScript drainer, weaponizing a trusted front-end to steal user token approvals.
AI-Generated Wallet Drainer Infiltrates Open-Source Ecosystem via Malicious NPM Package
An AI-crafted supply chain attack exploited developer trust in the NPM registry to deploy stealthy wallet-draining malware, compromising end-user funds.
Seedify Fund Bridge Key Compromised Minting Unauthorized Tokens across Multiple Chains
Bridge contract private key compromise allowed unauthorized token minting, leading to immediate liquidity pool drain across five chains.
Web3 Users Compromised by AI-Aided Phishing Network Stealing Seed Phrases
The FreeDrain campaign leverages AI-generated content and search engine spamdexing to steal mnemonic phrases, bypassing traditional security controls at scale.
Centralized Exchange Private Key Compromise Drains $1.5 Billion in Assets
The compromise of a single, critical private key in an exchange's cold storage infrastructure resulted in a systemic, nine-figure asset drain.
