attacker – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 16 Jun 2025 11:18:35 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 attacker – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 147,116 Americans Hit by Massive Data Breach – Firm Says Unknown Attacker May Have Exposed Names, Addresses, Social Security Numbers and More https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/ https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/#respond Mon, 16 Jun 2025 11:18:35 +0000 https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/

A major cybersecurity incident at a healthcare firm may have exposed the sensitive personal and health records of more than 100,000 Americans.

In a new filing with the Office of the Maine Attorney General, North Carolina-based optical care firm Asheville Eye Associates says it discovered a serious data breach affecting 147,116 people.

In a statement, the firm says that an unknown attacker breached its systems and siphoned patient data from its network, including names, addresses, Social Security numbers, medical treatment reports and health insurance records.

“On January 31, 2025, Asheville Eye Associates (AEA) notified individuals that it had detected and stopped a network security incident. An unauthorized party gained access to our network and acquired certain files from our systems. We quickly engaged third-party specialists to assist us with securing the network environment and investigating the incident.

Since that time, AEA has completed a comprehensive review and investigation of the potentially affected records and systems. Through that subsequent investigation, which concluded on April 14, 2025, we identified additional individuals whose personal information was contained in the affected records.”

Asheville Eye Associates is a firm specializing in ophthalmology services, offering cataract surgery, laser surgery for glaucoma and diabetes, LASIK and other procedures to treat ophthalmic disorders.

The firm says it abruptly sent letters of notification to impacted individuals to provide more information about the cybersecurity incident, while offering access to free credit monitoring services to people whose Social Security numbers were compromised.

For now, Asheville Eye Associates says it has not detected any instance of identity theft related to the data breach.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/feed/ 0 42332
Messaging App Used by Trump Admin Hacked – Attacker May Have Stolen Data From Hundreds of Government Employees: Report https://earlybirdsinvest.com/messaging-app-used-by-trump-admin-hacked-attacker-may-have-stolen-data-from-hundreds-of-government-employees-report/ https://earlybirdsinvest.com/messaging-app-used-by-trump-admin-hacked-attacker-may-have-stolen-data-from-hundreds-of-government-employees-report/#respond Thu, 08 May 2025 03:02:46 +0000 https://earlybirdsinvest.com/messaging-app-used-by-trump-admin-hacked-attacker-may-have-stolen-data-from-hundreds-of-government-employees-report/

The messaging app used by some members of the Trump administration and the US government has been hacked, according to a new report.

404 Media reports that a hacker stole customer data from TeleMessage, an Israeli software company that provides modified versions of messaging apps like Signal.

The US government reportedly uses modified apps to archive messages.

A Reuters photo last week revealed that Michael Waltz, the recently ousted national security adviser, was using TeleMessage to communicate with colleagues during a Trump administration cabinet meeting.

Trump said last week on Truth Social that he plans to nominate Waltz to serve as the US ambassador to the United Nations. The former national security adviser fell into hot water earlier this year for accidentally adding a journalist to a sensitive Signal chat about war plans between top Trump administration figures.

The identity of the hacker remains unknown, but 404 Media viewed the hacked material that was anonymously provided. The hacker also anonymously noted that the hack took 15-20 minutes and “wasn’t much effort at all.”

The hacker didn’t access Waltz’s messages specifically, but the thief did access data related to Customs and Border Protection (CBP) and the crypto exchange Coinbase, as well as other financial institutions. A screenshot shows that the hacker was able to access a TeleMessage panel that lists the names, phone numbers and email addresses of CPB employees.

The screenshot also shows an option to select 747 entries, suggesting that the attacker has access to the data of hundreds of US government employees.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/messaging-app-used-by-trump-admin-hacked-attacker-may-have-stolen-data-from-hundreds-of-government-employees-report/feed/ 0 34992
ZKsync Hit by Admin Hack, Attacker Mints 111 Million Extra Tokens https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/ https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/#respond Fri, 18 Apr 2025 04:16:36 +0000 https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/

A ZKsync admin account was compromised on April 15, which allowed an attacker to mint about $5 million worth of unclaimed ZK tokens.

The breach was confirmed through ZKsync’s official account on X, which stated that this was an isolated event and no user wallets were affected.

ZKsync is a tool built on Ethereum
ETH


$1,579.64

that helps speed up transactions by grouping them together and confirming them at once. The platform had been running an airdrop to give out 17.5% of its total ZK token supply to supporters of the project.

What Are Oracles in Crypto? (Beginner Friendly Animation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

According to an updated post on X, the attacker used access to three airdrop-related contracts and triggered a feature called “sweepUnclaimed()”. This function was meant to handle leftover tokens from the ongoing airdrop.

The attacker created 111 million extra ZK tokens, which increased the total supply by around 0.45%. Most of those tokens still remain in the attacker’s wallet.

ZKsync says its main contracts, including those controlling token rules and community governance, were not affected. The platform has also said that the exploited method cannot be used again.

To address the situation, ZKsync is working with a cybersecurity group called the Security Alliance (SEAL) to try to recover the stolen funds.

KiloEX, a decentralized exchange (DEX), recently paused all trading after a $7.5 million security breach. How did the attacker pull it off? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/zksync-hit-by-admin-hack-attacker-mints-111-million-extra-tokens/feed/ 0 31422
ZKsync Reveals Hack on Airdrop Tokens, Attacker Mints $5M Worth of Unclaimed ZK https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/ https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/#respond Thu, 17 Apr 2025 06:38:49 +0000 https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/

A security incident has shaken the ZKsync layer-2 network: on April 15, a compromised admin account led to the minting of roughly $5 million worth of unclaimed airdrop tokens. Although user funds remain untouched, the event highlights how leftover airdrop allocations can become a target for bad actors if not properly secured.

Unclaimed Airdrop Tokens Targeted

ZKsync originally airdropped 3.6 billion ZK tokens in June 2024 to reward early adopters of ZKsync Era and ZKsync Lite. Despite this extensive distribution, millions of tokens—amounting to nearly $5 million—remained unclaimed. These tokens resided in three smart contracts overseen by an admin account, which was compromised.

According to ZKsync’s statement, the attacker called a function named sweepUnclaimed() on the airdrop contract, thereby minting 111 million ZK tokens. This move effectively boosted the circulating supply by around 0.45% of a total fixed supply of 21 billion tokens.

The function existed to allow recovery of unclaimed tokens after the claim period but was gated behind admin-only access—an access point that was exploited once the admin key was compromised.

While $5 million is relatively modest compared to the broader crypto space, any unauthorized minting raises concerns about contract security and leftover token handling.

Scope of the Incident

ZKsync emphasizes that this hack was isolated to the airdrop contract and did not affect user wallets or the main ZK token contract. The governance framework and protocol itself remain intact, with no vulnerabilities reported beyond the compromised admin key. Additionally, ZKsync has assured the public that no further exploits are possible through the sweepUnclaimed() function, as the attacker has already taken all mintable tokens.

Still, the situation has reignited debate about contract design and admin key security. Best practices—such as using multisig wallets for critical admin functions, implementing time-locked operations, or designing contracts with immutable parameters—might have mitigated or prevented the breach.

Nevertheless, the incident sparked price volatility. At one point on April 15, ZK’s value had slid 16% to $0.040, though it later rebounded to around $0.047. Still, the token remains down approximately 7% over the past 24 hours, reflecting ongoing market wariness following the hack’s disclosure.

History of the Airdrop

ZKsync’s airdrop in 2024 was significant, allocating a considerable supply of tokens as a reward for ecosystem participants. Users who contributed to ZKsync Era and ZKsync Lite received varying amounts of ZK based on their activity, but a portion stayed unclaimed. These unclaimed tokens ended up centralized under three distribution contracts, ultimately making them a high-value prize for anyone who managed to breach the admin account’s security.

Response and Recovery Efforts

In a move to protect against further damage, ZKsync has enlisted the help of the Security Alliance (SEAL). The attacker’s wallet—containing most of the newly minted tokens—remains closely monitored, and ZKsync has publicly requested that the individual reach out to negotiate the return of funds. If that fails, the company could seek legal channels to address the theft.

ZKsync stresses that the rest of its architecture—including governance mechanisms, bridging components, and token supplies—remains secure. The protocol also claims that leftover vulnerabilities from the compromised admin key have been neutralized and that no additional user-facing security measures are needed at this time.

Looking Forward

While the hack did not involve user deposits or core protocol infrastructure, it raises questions about how leftover airdrop tokens are stored and secured. Distributing tokens to community members can be an effective way to reward early participation, but unclaimed portions may become a single point of failure if they are controlled by one privileged account.

ZKsync’s quick response and transparent communication have helped contain the issue. However, it remains to be seen whether the attacker will willingly return the stolen tokens. As the network continues to grow—it currently has $57.3 million in total value locked, according to DefiLlama—users and developers alike will watch closely to see what additional security measures ZKsync implements to prevent future admin key compromises.

]]>
https://earlybirdsinvest.com/zksync-reveals-hack-on-airdrop-tokens-attacker-mints-5m-worth-of-unclaimed-zk/feed/ 0 31258
Will double spending effectively burn attacker Bitcoin? https://earlybirdsinvest.com/will-double-spending-effectively-burn-attacker-bitcoin/ https://earlybirdsinvest.com/will-double-spending-effectively-burn-attacker-bitcoin/#respond Sun, 13 Apr 2025 04:18:10 +0000 https://earlybirdsinvest.com/will-double-spending-effectively-burn-attacker-bitcoin/

Some people express their view that the successful double spending attacks will invalidate Bitcoin as a technology and thus undermine the value of all Bitcoin (including attackers), making the attacks unwinnable.

That doesn’t seem reasonable to me. It doubles on other networks, and those networks continue to operate later. It certainly affects the value of Bitcoin, but it seems ridiculous that the new value will soon reach zero. Most people didn’t even catch up with the event for hours or days.

My opinion is that if my node detects large ReORG and double spending within that ReORG, it will not accept payments related to double spenders. No one accepted his bitcoin, as they know that if his identity is publicly known, they have a duty to be used in double terms. If his identity is not publicly known, his Bitcoin is still linked to attacks and no one should accept them for the same reasons.

Depending on how the attacker chose the transaction in the block, if the attacker simply does not include the transaction in the replacement block, then there could be something in 24,000 transactions in 6 blocks. It may be possible to find a single or a few transactions of high value that will be resolved differently, but it can be fuzzy and non-trivial to more people. I’m not sure this is a practical approach.

But on the other side of the coin…now I know the fact that all other bitcoins that are not associated with the attacker cannot be double-touched. Because, by definition, only one entity can have more than 50% of the hash power at a given time.

Assuming that the attacker only includes its own transactions, the sender of around 24,000 transactions is in a position to reissue its own transactions. It is not clear at all why someone attacks the blockchain and gives them more confidence to the actions of others.

Does this create a situation where the attacker effectively burns his coins while simultaneously increasing the reliability of all other coins?

No, not at all.

Or say something else: is it valid that there is no need to assume that 51% of attacks will undermine the value of the entire network?

No, all possibilities make the attacker immediately trade with Bitcoin if he was worried about an attack that would seriously affect the value of Bitcoin. They may not be able to exchange some of the coins involved in the attack, but they can shorten Bitcoin in future trades, or at least trade all other Bitcoin holdings. Attackers can even trade back with dips caused by the damage of attacks on Bitcoin’s value, and gain more value in recovery. I don’t think this argument will withstand scrutiny.

]]>
https://earlybirdsinvest.com/will-double-spending-effectively-burn-attacker-bitcoin/feed/ 0 30511