attack – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 10 Sep 2025 22:23:28 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 attack – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 DDoS defender targeted in 1.5 Bpps denial-of-service attack https://earlybirdsinvest.com/ddos-defender-targeted-in-1-5-bpps-denial-of-service-attack/ https://earlybirdsinvest.com/ddos-defender-targeted-in-1-5-bpps-denial-of-service-attack/#respond Wed, 10 Sep 2025 22:23:27 +0000 https://earlybirdsinvest.com/ddos-defender-targeted-in-1-5-bpps-denial-of-service-attack/

DDoS defender targeted in 1.5 Bpps denial-of-service attack

A DDoS mitigation service provider in Europe was targeted in a massive distributed denial-of-service attack that reached 1.5 billion packets per second.

The attack originated from thousands of IoTs and MikroTik routers, and it was mitigated by FastNetMon, a company that offers protection against service disruptions.

“The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed,” FastNetMon says in a press release.

“The malicious traffic was primarily a UDP flood launched from compromised customer-premises equipment (CPE), including IoT devices and routers, across more than 11,000 unique networks worldwide,” the company explains.

The record-breaking DDoS attack
The record-breaking DDoS attack
Source: FastNetMon

FastNetMon did not name the targeted customer, but describes it as a DDoS scrubbing provider. These services specialize in filtering out malicious traffic during DDoS attacks through packet inspection, rate limiting, CAPTCHA, and anomaly detection.

The attack was detected in real-time, and mitigation action was taken using the customer’s DDoS scrubbing facility. The measures included deploying access control lists (ACLs) on edge routers known for amplification capabilities.

News of the attack comes just days after internet infrastructure giant Cloudflare announced that it blocked the largest recorded volumetric DDoS attack in history, which peaked at 11.5 terabits per second (Tbps) and 5.1 billion packets per second (Bpps).

In both attacks, the goal was to exhaust processing abilities on the receiving end and cause service outages.

FastNetMon’s founder, Pavel Odintsov, commented that the trend of these massive attacks has become very dangerous, and intervention at the internet service provider (ISP) level is required to stop this mass-scale weaponization of compromised consumer hardware.

“What makes this case remarkable is the sheer number of distributed sources and the abuse of everyday networking devices. Without proactive ISP-level filtering, compromised consumer hardware can be weaponised at a massive scale” – FastNetMon

“The industry must act to implement detection logic at the ISP level to stop outgoing attacks before they scale,” says Odintsov.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/ddos-defender-targeted-in-1-5-bpps-denial-of-service-attack/feed/ 0 57786
Ripple CTO Praises XRP Wallet for Swift Reaction to Supply Chain Attack https://earlybirdsinvest.com/ripple-cto-praises-xrp-wallet-for-swift-reaction-to-supply-chain-attack/ https://earlybirdsinvest.com/ripple-cto-praises-xrp-wallet-for-swift-reaction-to-supply-chain-attack/#respond Mon, 08 Sep 2025 22:44:57 +0000 https://earlybirdsinvest.com/ripple-cto-praises-xrp-wallet-for-swift-reaction-to-supply-chain-attack/

David Schwartz, chief technology officer at Ripple, has praised Xaman, a popular XRP wallet, for swiftly reacting to a large-scale supply chain attack on the Node Package Manager (NPM) ecosystem. 

A reputable developer’s NPM account was recently compromised, and widely JavaScript packages ended up being infected with malicious code. 

The malware specifically targets cryptocurrency wallets such as MetaMask in order to redirect the funds of uninitiated crypto users to the attackers by secretly swapping addresses. 

You Might Also Like

Title news

As reported by U.Today, Ledger CTO Charles Guillemet has urged crypto users who do not have hardware wallets with clear signing to temporarily stop conducting on-chain transactions. 

Xaman’s reaction 

The team behind the Xaman wallet immediately conducted an audit, which showed that it was safe for users. 

XRPL Labs co-founder Wietse Wind Supply has noted that chain attacks are becoming “more and more common.”

]]>
https://earlybirdsinvest.com/ripple-cto-praises-xrp-wallet-for-swift-reaction-to-supply-chain-attack/feed/ 0 57457
Largest supply chain attack in history targets crypto users through compromised JavaScript packages https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/ https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/#respond Mon, 08 Sep 2025 19:17:57 +0000 https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/

A new cyberattack is silently targeting crypto from users during transactions amid an incident that security researchers describe as the largest supply chain attack in history.

BleepingComputer reported that hackers compromised NPM package maintainer accounts through phishing emails and injected malware that steals crypto.

The attack targeted JavaScript developers with fraudulent emails appearing to originate from “[email protected],” an impersonated domain mimicking the legitimate NPM registry.

The phishing messages warned maintainers that their accounts would be locked on Sept. 10, unless they updated their two-factor authentication credentials through a malicious link.

Attackers successfully compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries include fundamental development tools such as “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting virtually the entire JavaScript ecosystem.

Targeting crypto

The malicious code operates as a browser-based interceptor, monitoring network traffic for crypto transactions across Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash networks.

When users initiate crypto transfers, the malware silently replaces destination wallet addresses with attacker-controlled accounts before transaction signing.

Aikido Security researcher Charlie Eriksen explained:

“What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Ledger CTO Charles Guillemet warned crypto users about the ongoing threat, noting the JavaScript ecosystem may be compromised given the massive download figures.

Hardware wallet users retain protection if they verify transaction details before signing, while software wallet users face a higher risk. Guillemet advised:

“If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.”

He also noted uncertainty about whether attackers can directly extract seed phrases from software wallets.

Sophisticated targeting

The attack represents a sophisticated supply chain targeting where criminals compromise trusted development infrastructure to reach end users.

By infiltrating packages downloaded billions of times weekly, attackers gained unprecedented access to cryptocurrency applications and wallet interfaces.

BleepingComputer identified the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows similar JavaScript library compromises throughout 2025, including the July attack on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten popular NPM libraries.

Mentioned in this article
]]>
https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/feed/ 0 57436
Cloudflare hit by data breach in Salesloft Drift supply chain attack https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/ https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/#respond Tue, 02 Sep 2025 21:07:53 +0000 https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/

Cloudflare

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week.

The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens.

Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens.

“Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer’s configuration and could contain sensitive information like access tokens,” Cloudflare said.

“Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel.”

The company’s investigation found that the threat actors stole only the text contained within the Salesforce case objects (including customer support tickets and their associated data, but no attachments) between August 12 and August 17, after an initial reconnaissance stage on August 9.

These exfiltrated case objects contained only text-based data, including:

  • The subject line of the Salesforce case
  • The body of the case (which may include keys, secrets, etc., if provided by the customer to Cloudflare)
  • Customer contact information (for example, company name, requester’s email address and phone number, company domain name, and company country)

“We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” Cloudflare added.

“Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

Wave of Salesforce data breaches

Since the start of the year, the ShinyHunters extortion group has been targeting Salesforce customers in data theft attacks, using voice phishing (vishing) to trick employees into linking malicious OAuth apps with their company’s Salesforce instances. This tactic enabled the attackers to steal databases, which were later used to extort victims.

Since Google first wrote about these attacks in June, numerous data breaches have been linked to ShinyHunters’ social engineering tactics, including those targeting Google itself, Cisco, Qantas, Allianz Life, Farmers Insurance, Workday, Adidas, as well as LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

While some security researchers have told BleepingComputer that the Salesloft supply chain attacks involve the same threat actors, Google has found no conclusive evidence linking them.

Palo Alto Networks also confirmed over the weekend that the threat actors behind the Salesloft Drift breaches stole some support data submitted by customers, including contact info and text comments.

The Palo Alto Networks incident was also limited to its Salesforce CRM and, as the company told BleepingComputer, it did not affect any of its products, systems, or services.

The cybersecurity company observed the attackers searching for secrets, including AWS access keys (AKIA), VPN and SSO login strings, Snowflake tokens, as well as generic keywords such as “secret,” “password,” or “key,” which could be used to breach more cloud platforms to steal data in other extortion attacks.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/feed/ 0 56444
Farmers Insurance data breach impacts 1.1M people after Salesforce attack https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/ https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/#respond Mon, 25 Aug 2025 19:29:05 +0000 https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/

Farmers Insurance sign

U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with BleepingComputer learning that the data was stolen in the widespread Salesforce attacks.

Farmers Insurance is a U.S.-based insurer that provides auto, home, life, and business insurance products. It operates through a network of agents and subsidiaries, serving more than 10 million households nationwide.

The company disclosed the data breach in an advisory on its website, saying that its database at a third-party vendor was breached on May 29, 2025.

“On May 30, 2025, one of Farmers’ third-party vendors alerted Farmers to suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing Farmers customer information (the “Incident”),” reads the data breach notification on its website.

“The third-party vendor had monitoring tools in place, which allowed the vendor to quickly detect the activity and take appropriate containment measures, including blocking the unauthorized actor. After learning of the activity, Farmers immediately launched a comprehensive investigation to determine the nature and scope of the Incident and notified appropriate law enforcement authorities.”

The company says that its investigation determined that customers’ names, addresses, dates of birth, driver’s license numbers, and/or last four digits of Social Security numbers were stolen during the breach.

Farmers began sending data breach notifications to impacted individuals on August 22, with a sample notification [1, 2] shared with the Maine Attorney General’s Office, stating that a combined total of 1,111,386 customers were impacted.

While Farmers did not disclose the name of the third-party vendor, BleepingComputer has learned that the data was stolen in the widespread Salesforce data theft attacks that have impacted numerous organizations this year.

BleepingComputer contacted Farmers with additional questions about the breach and will update the story if we receive a response.

The Salesforce data theft attacks

Since the beginning of the year, threat actors classified as ‘UNC6040’ or ‘UNC6240’ have been conducting social engineering attacks on Salesforce customers.

During these attacks, threat actors conduct voice phishing (vishing) to trick employees into linking a malicious OAuth app with their company’s Salesforce instances.

Once linked, the threat actors used the connection to download and steal the databases, which were then used to extort the company through email.

The extortion demands come from the ShinyHunters cybercrime group, who told BleepingComputer that the attacks involve multiple overlapping threat groups, with each group handling specific tasks to breach Salesforce instances and steal data.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

Other companies impacted in these attacks include Google, Cisco, Workday, Adidas, Qantas, Allianz Life, and the LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

 

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/feed/ 0 55095
Bitcoiner loses $91M in social engineering attack: ZachXBT https://earlybirdsinvest.com/bitcoiner-loses-91m-in-social-engineering-attack-zachxbt/ https://earlybirdsinvest.com/bitcoiner-loses-91m-in-social-engineering-attack-zachxbt/#respond Fri, 22 Aug 2025 01:33:53 +0000 https://earlybirdsinvest.com/bitcoiner-loses-91m-in-social-engineering-attack-zachxbt/

A Bitcoiner lost $91 million in a single transaction to a social engineering attack on Tuesday, with funds then sent to a privacy-focused Bitcoin wallet, according to blockchain investigator ZachXBT.

The victim was deceived by impostors posing as crypto exchange and hardware wallet support, losing 783 Bitcoin (BTC) in a single transaction, ZachXBT said in an X post on Thursday.

Blockchain data shows the theft occurred on Tuesday at 11:06 am UTC, and the exploiter started laundering the stolen funds a day later through the Bitcoin privacy-focused Wasabi Wallet to conceal the trail of the stolen funds, ZachXBT said. 

Social engineering attacks involve attackers tricking people into revealing sensitive information, such as their private keys or passwords, allowing attackers to steal the funds. These exploits have been rampant in crypto, targeting everyone from sophisticated crypto investors to the elderly. 

Asked how one can avoid being socially engineered, ZachXBT said to assume every call or email received is a “scam by default.”

Source: ZachXBT

ZachXBT rules out North Korea hackers

While ZachXBT didn’t name any suspects, he ruled out the notorious North Korean state-backed Lazarus Group as a potential culprit.

The attacker received the funds at a clean Bitcoin wallet address — ‘bc1qyxyk’ — before using Wasabi Wallet’s privacy features to try to conceal them.

ZachXBT added that, coincidentally, the attack occurred exactly one year after the $243 million Genesis creditor theft.

Scammers impersonating hardware crypto wallet providers

Scammers have frequently impersonated crypto hardware wallet providers such as Ledger and Trezor using sophisticated methods.

In late April, scammers impersonating Ledger sent out letters posing as the company, asking users for secret recovery phrases to crypto wallets in an attempt to take control of the device. 

They claimed a “critical security update” needed to be performed on their devices and that failure to comply may “result in restricted access to your wallet and funds.”

Related: Small setups, big wins: Is solo Bitcoin mining making a comeback?

In the same month, an elderly US citizen lost over $330 million worth of Bitcoin to a social engineering attack, sending shockwaves through the industry.

Crypto theft is still a multibillion-dollar industry

More than $2.1 billion was stolen from crypto-related attacks across the first five months of 2025, with the bulk of losses coming from wallet compromises and phishing attacks, blockchain security firm CertiK said in June.

The largest incident by far was the $1.4 billion exploit of crypto exchange Bybit in February, highlighting that even large, extensively audited crypto platforms remain at risk.

Magazine: Bitcoin’s long-term security budget problem: Impending crisis or FUD?

]]> https://earlybirdsinvest.com/bitcoiner-loses-91m-in-social-engineering-attack-zachxbt/feed/ 0 54462 Kraken suspends Monero deposits after 51% attack https://earlybirdsinvest.com/kraken-suspends-monero-deposits-after-51-attack/ https://earlybirdsinvest.com/kraken-suspends-monero-deposits-after-51-attack/#respond Sat, 16 Aug 2025 21:23:50 +0000 https://earlybirdsinvest.com/kraken-suspends-monero-deposits-after-51-attack/

Crypto exchange Kraken has announced the suspension of Monero (XMR) deposits following a confirmed 51% attack on the network on August 12. The attack was linked to the Qubic mining pool, which managed to control over half of Monero’s hashrate, peaking at 2.6GH/s.

This dominance allowed Qubic to conduct a six-block deep reorganization of Monero’s blockchain, effectively rewriting history and orphaning around 60 blocks. The attack exposes the vulnerability of mid-tier Proof-of-work networks like Monero to majority control maneuvers.

Kraken follows ‘security precaution’ with Monero

Monero is a privacy-focused coin designed to provide secure, anonymous, and untraceable transactions. Unlike transparent blockchains such as Bitcoin and Ethereum, Monero conceals the sender, receiver, and amount for every transaction, and is popular among users who value financial privacy and freedom.

Launched in April 2014, Monero has suffered previous security incidents, including a flooding attack in March 2024 that congested the network. However, the recent 51% attack is the first major breach of Monero’s consensus protocol, heightening community concern about mining concentration and network resilience. Kraken posted:

“As a security precaution, we have paused Monero (XMR) deposits after detecting that a single mining pool has gained more than 50% of the network’s total hashing power. This concentration of mining power poses a potential risk to network integrity.

We are actively monitoring the situation and will resume deposits once we determine it is safe to do so. Trading and withdrawals for XMR remain fully operational.”

Lack of official communications makes Monero look ‘weak’

Monero’s price has fallen by as much as 14%, with the episode reigniting concerns about the centralization of mining in privacy-centric cryptocurrencies and the market impact of such attacks.

While security analysts are still debating the degree to which the reorganization constituted a full 51% attack (some argue it was a stress test on Monero’s decentralization rather than a purely malicious assault), a lack of official communications are conspicuous by their absence, as privacy-centric Unstoppable Wallet posted:

“To be honest, we kind of deserve this…

Zero unified pushback, no official statements, outdated website, passive devs.

Meanwhile Qubic, despite not actually hitting 51%, are winning the info war simply by being loud.

Monero community looks weak.

It’s both pathetic.”

As exchanges like Kraken take protective action, the broader crypto community will need to reconsider the resilience strategies for networks with smaller mining populations, as regulators highlight the added risk of privacy coins in centralized trading environments.

Monero Market Data

At the time of press 9:20 pm UTC on Aug. 16, 2025, Monero is ranked #29 by market cap and the price is up 7.92% over the past 24 hours. Monero has a market capitalization of $4.73 billion with a 24-hour trading volume of $67.26 million. Learn more about Monero ›

Crypto Market Summary

At the time of press 9:20 pm UTC on Aug. 16, 2025, the total crypto market is valued at at $3.98 trillion with a 24-hour volume of $129.45 billion. Bitcoin dominance is currently at 58.92%. Learn more about the crypto market ›

Mentioned in this article
]]>
https://earlybirdsinvest.com/kraken-suspends-monero-deposits-after-51-attack/feed/ 0 53556
Colt Telecom attack claimed by WarLock ransomware, data up for sale https://earlybirdsinvest.com/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/ https://earlybirdsinvest.com/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/#respond Sat, 16 Aug 2025 10:05:05 +0000 https://earlybirdsinvest.com/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/

Colt Telecom attack claimed by WarLock ransomware, data up for sale

UK-based telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company’s operations, including hosting and porting services, Colt Online, and Voice API platforms.

The British telecommunications and network services provider disclosed that the attack started on August 12 and the disruption continues as its IT staff works around the clock to mitigate its effects.

Founded in 1992 as City of London Telecommunications (COLT) and acquired by Fidelity Investments in 2015, Colt is a major telecommunications service provider operating in 30 countries across Europe, Asia, and North America. The company employs 75,000 km of fiber networks linking 900 data centers.

Services still offline

Initially, the company announced a “technical issue” without confirming a cyber incident. However, the nature of the event was communicated in subsequent status updates.

The attack forced the firm to take specific systems offline as a protective measure, which affected the operations of support services, including Colt Online and the Voice API platform.

Customer communication through online portals is currently unavailable, and clients are advised to contact Colt by email or phone and expect slower-than-usual responses.

The company underlined that the impacted systems are support services, not the core customer network infrastructure.

As of today, there is no estimation for restoring affected systems and operations.

Colt says it has notified the authorities about the incident without providing any details about the perpetrators or the type of attack.

WarLock claims the attack

A threat actor using the alias ‘cnkjasdfgd’ and claiming to be a member of the WarLock ransomware gang claimed the attack and offered to sell for $200,000 a batch of one million documents allegedly stolen from Colt.

Several data samples have also been published to prove the validity of the files. According to the threat actor, the stolen files include financial, employee, customer, and executive data, internal emails, and software development information.

Threat actor's post on a hacker forum
Threat actor’s post on a hacker forum
Source: KELA

Although the telecommunications company did not disclose the cause of the breach, security researcher Kevin Beaumont says that the hacker likely managed to gain initial access by exploiting a remote code execution vulnerability in Microsoft SharePoint tracked as CVE-2025-53770.

The security issue has been exploited as a zero-day since at least July 18 and is considered critical in severity. Microsoft addressed it in a security update on July 21.

According to Beaumont, the hackers stole a few hundred gigabytes of files with customer data and documentation.

BleepingComputer has contacted Colt to ask for verification of these allegations, and a spokesperson sent us the below comment:

“We’re aware of claims regarding the cyber incident. We are currently investigating these claims.”

“Our technical team is focused on restoring the internal systems impacted by the cyber incident and is working closely with third-party cyber experts. We are grateful for our customers’ understanding as we work towards a resolution to fix the impacted internal systems.” – Colt spokesperson

Update 8/15 – Added comment from Colt

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/feed/ 0 53475
Qubic Claims Majority Control of Monero Hashrate, Raising 51% Attack Fears https://earlybirdsinvest.com/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears/ https://earlybirdsinvest.com/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears/#respond Tue, 12 Aug 2025 12:49:13 +0000 https://earlybirdsinvest.com/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears/

Qubic, a project led by former IOTA co-founder Sergey Ivancheglo, says it has secured more than 51% of Monero’s global hashrate, a milestone that, if true, gives it the ability to reorganize blocks, censor transactions, and attempt double-spends on the privacy-focused blockchain.

Ivancheglo framed the move as a stress test to help the Monero community prepare for future network threats, but the announcement has triggered sharp debate among developers and security experts.

jwp-player-placeholder

A 51% attack occurs when a single entity or coordinated group controls a majority of a proof-of-work network’s hashrate. Ethereum Classic suffered multiple reorganizations in 2020, resulting in millions of dollars in losses, while Bitcoin Gold faced similar assaults in 2018 and 2020.

Smaller networks like Verge have also been targeted, demonstrating how concentrated hashing power can destabilize and entire cryptocurrency network.

Monero, which uses the CPU-friendly RandomX algorithm, has long prided itself on resisting ASIC centralization. Qubic’s “useful proof-of-work” (uPoW) model repurposes Monero mining rewards by converting XMR into USDT, then using the proceeds to buy and burn QUBIC tokens, a deflationary mechanism that doubles as a liquidity sink for its own ecosystem.

From mid-May to late July, Qubic’s share of the network jumped from less than 2% to over 25%, at times topping pool rankings.

Ledger CTO Charles Guillemet warned on X that Monero “appears to be in the midst of a successful 51% attack,” citing signs of a major chain reorganization, with several other industry experts like SlowMist founder Yu Xian expressing their doubt over Qubic’s economics.

Whether the events mark a hostile takeover or simply a stress test, XMR has responded negatively, dropping by 6.65% in the past 24 hours to compound a 16% decline over the past week.

Read more: How $330M BTC Hacker May Have Doubled Down on Monero Derivatives

]]>
https://earlybirdsinvest.com/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears/feed/ 0 52827
Monero price dips as Qubic likely succeeds in 51% attack https://earlybirdsinvest.com/monero-price-dips-as-qubic-likely-succeeds-in-51-attack/ https://earlybirdsinvest.com/monero-price-dips-as-qubic-likely-succeeds-in-51-attack/#respond Tue, 12 Aug 2025 12:41:13 +0000 https://earlybirdsinvest.com/monero-price-dips-as-qubic-likely-succeeds-in-51-attack/

The privacy-focused cryptocurrency Monero has suffered a major disruption, with 60 mined blocks discarded from its blockchain in the past 24 hours amid an ongoing attempted 51% attack by the Qubic network.

The Monero Consensus Status dashboard shows Monero saw 60 orphaned blocks (valid blocks that were rejected) in the last 720 blocks. The disruption comes amid an ongoing economic attack by the Qubic network, incentivizing selfish mining.

Qubic miners redirect their computing power to mine Monero (XMR) and sell the proceeds to buy and burn Qubic tokens, while being paid in QUBIC. Qubic miners reportedly earn more than Monero miners under this setup.

The attack has sparked fears of a possible “51% attack” — a rare and serious event that can let attackers rewrite transactions or block them entirely.

An orphaned block is a valid block excluded from the main chain because another competing block at the same height was accepted first. In selfish mining, a miner with significant hashrate withholds blocks and publishes them strategically to overtake the public chain, causing honest miners’ work to be discarded.

As of the time of writing, Monero’s price stands at over $247, down over 8.6% from the price of over $276 reported 24 hours ago.

Hackers, Monero, Hacks
Monero’s 24-hour price chart. Source: CoinMarketCap

Qubic attack disrupts Monero network

Qubic’s Monero mining pool openly engages in selfish mining, with Qubic founder Sergey Ivancheglo admitting it in an X post. Ivancheglo claimed in a Tuesday X post that “Qubic has achieved 51% over Monero” and the team is “waiting for independent confirmations.”

Related: 51% attack on Ethereum more difficult than on Bitcoin — Justin Drake

A 51% attack occurs when a single entity — in this case, the Qubic mining pool — controls over half of a blockchain network’s mining power or stake, allowing them to manipulate transactions. Zhong Chenming, the co-founder of crypto cybersecurity firm SlowMist, said in a Tuesday X post that “this time the 51% attack on Monero seems to have succeeded.” He added:

“The cost was also high, and it’s unclear what the economic benefits of doing this are in the end… In theory, the Qubic mining pool can now rewrite the blockchain, achieve double-spending, and censor any transactions.”

Source: Zhong Chenming

Not everyone is convinced

Doubts remain around whether a successful 51% attack occurred. Engaging in selfish mining with control over a high percentage of the hashrate that is short of the majority can occasionally lead to orphaned blocks.

Monero’s total hashrate evaluation by CoinWarz results in a 5 GH/s estimation. Unverified data provided by Qubic claims a peak hashrate of 3.01 GH/s, which is more than sufficient, and a current hashrate of 2.08 GH/s, insufficient for a 51% attack.

The Monero Consensus Status also indicates that the number of blocks mined by unknown mining pools and solo miners — the category which includes Qubic — reached nearly 30% on Aug. 11. This could signal Qubic controlling most of the hashrate for a brief period, or controlling a significant portion but still a minority of the hashrate.

SeraiDEX’s lead developer, Luke Parker, raised an issue with reports that a 51% attack took place in a separate X post. He noted that a six-block-deep network reorganization with block orphaning “does not mean a ‘51% attack’ was successful.”

“It does mean an adversary with a high amount of hash got lucky,” he added.

Related: Coin Metrics research shows BTC and ETH are immune to 51% attacks

Hack war escalates between networks

Qubic and Monero are locked in an ongoing hack war, trading countermeasures. Ivancheglo previously wrote on X that Monero broke Qubic’s selfish mining system, prompting his fix. Before that, Ivancheglo accused a developer of Monero mining software XMRig, Sergei Chernykh, of denial-of-service (DDoS) attackg Qubic’s pool, leading to hashrate losses — a claim Chernykh disputes.

The attack first started in late July when the community noticed what it described as an “economic attack.” The operation uses economic incentives — paying Qubic miners more than Monero miners — in an attempt to take control over most of Monero’s hashrate and consequently the network.

Niko Demchuk, head of legal at onchain forensics firm AMLBot, told Cointelegraph that Qubic’s attack on Monero could be deemed “computer sabotage” or “unauthorized access” under Belarusian and European Union laws. However, no statute explicitly mentions 51% attacks. Demchuk said Belarus’ cybercrime rules could apply if blockchain manipulation disrupts protected systems.

Magazine: Bitcoin vs. the quantum computer threat: Timeline and solutions (2025–2035)

]]> https://earlybirdsinvest.com/monero-price-dips-as-qubic-likely-succeeds-in-51-attack/feed/ 0 52824