AI-Generated Wallet Drainer Infiltrates Open-Source Ecosystem via Malicious NPM Package
An AI-crafted supply chain attack exploited developer trust in the NPM registry to deploy stealthy wallet-draining malware, compromising end-user funds.
Chromium V8 Zero-Day Flaw Enables Private Key Theft and Wallet Draining
A critical V8 engine zero-day (CVE-2025-10585) permitted remote code execution, exposing user private keys and draining hot wallets.
State-Sponsored APT Groups Use InvisibleFerret Backdoor to Steal Digital Assets
The InvisibleFerret backdoor, coupled with zero-day exploitation, bypasses endpoint security to exfiltrate wallet data, posing an extreme systemic risk.
Private Key Holders Targeted by Automated Malware and Physical Coercion
Automated CaaS malware now bypasses local security, weaponizing phishing and physical coercion to compromise private keys at scale.
Threat Actor LARVA-208 Targets Web3 Developers via Fake AI Platform Malware
Sophisticated spearphishing campaign delivers the Fickle infostealer via malicious 'audio driver' download, compromising developer credentials and project supply chains.
Chrome V8 Zero-Day Exploit Threatens Crypto Wallets
A critical type confusion vulnerability in Chrome's V8 engine enables remote code execution, posing a direct threat of crypto wallet compromise.
Chrome V8 Engine Exploit Threatens Crypto Wallets and Sensitive Data
A critical "Type Confusion" vulnerability in the V8 engine allows remote code execution, enabling attackers to steal private keys and seed phrases via malicious websites.
Chrome V8 Engine Vulnerability Exposes Crypto Wallets to Website Attacks
A critical "Type Confusion" bug in Chrome's V8 engine enables remote code execution, allowing attackers to drain crypto wallets via malicious websites.
