Drain – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 08 Sep 2025 09:38:07 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Drain – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers Drain WLFI Tokens Using Ethereum’s EIP-7702 Feature https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/ https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/#respond Mon, 08 Sep 2025 09:38:07 +0000 https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/

A security flaw is being used by attackers to steal WLFI tokens from Ethereum
ETH


$4,269.41

wallets.

According to a September 1 post on X by SlowMist’s Yu Xian, criminals are taking advantage of a new Ethereum feature, EIP-7702, to pull funds from user wallets once they have been compromised.

Ethereum’s May upgrade introduced EIP-7702, which allows regular wallets to behave like smart contract wallets for a short time.

Sidechains in Crypto Explained EASILY (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Xian explained that attackers first gain control of a victim’s private key. After that, they set up a delegate contract on the wallet address. This contract gives the attacker the ability to approve and process transactions.

Once the wallet receives a deposit, such as WLFI tokens, it is only a matter of seconds before the funds are withdrawn to the attacker’s own wallet.

In one example reported on August 31, an X user claimed their friend’s WLFI tokens were stolen after they sent ETH into the wallet. Xian confirmed that this looked like the “Classic EIP-7702 phishing exploit”.

Xian also explained that even when users try to transfer remaining tokens from the compromised wallet, the gas fees can be rerouted to the attacker.

To reduce the damage, Xian recommended canceling or overwriting the delegate contract associated with EIP-7702. He also advised moving any remaining tokens to a secure wallet as soon as possible.

Recently, Anthropic warned that its chatbot, Claude, is being misused by bad actors to support online criminal activity. How? Read the full story.


]]>
https://earlybirdsinvest.com/hackers-drain-wlfi-tokens-using-ethereums-eip-7702-feature/feed/ 0 57363
Crypto Funds Just Lost $1.43B in the Biggest Drain Since March https://earlybirdsinvest.com/crypto-funds-just-lost-1-43b-in-the-biggest-drain-since-march/ https://earlybirdsinvest.com/crypto-funds-just-lost-1-43b-in-the-biggest-drain-since-march/#respond Mon, 25 Aug 2025 18:52:50 +0000 https://earlybirdsinvest.com/crypto-funds-just-lost-1-43b-in-the-biggest-drain-since-march/

Digital asset investment products faced their largest weekly outflows since March as $1.43 billion exited the market. Despite this, trading volumes in exchange-traded products (ETPs) surged to $38 billion, around 50% above the yearly average, which reflected “increasingly polarised” investor sentiment over US monetary policy.

Early in the week, fears of a hawkish Federal Reserve outlook triggered $2 billion in outflows. Despite this, sentiment rebounded after Jerome Powell’s Jackson Hole speech, which investors viewed as more dovish than anticipated. This eventually led to $594 million in inflows.

Ethereum Outperforms Bitcoin

In the latest edition of “Digital Asset Fund Flows Weekly Report,” CoinShares revealed that investor behavior showed a clearer tilt toward Ethereum compared to Bitcoin during the recent market turbulence. Ethereum staged a strong recovery mid-week and restricted outflows to $440 million, far below Bitcoin’s $1 billion decline.

On a month-to-date basis, Ethereum recorded inflows of $2.5 billion, while Bitcoin remains in negative territory with $1 billion in net outflows. Year-to-date, Ethereum inflows represent 26% of total assets under management, compared with Bitcoin’s 11%.

Investor activity favored several altcoins this past week, with XRP leading at $25 million in inflows. Solana and Cronos also gained $12 million and $4.4 million in inflows, respectively. Next up was Cardano with $2.9 million, followed by Chainlink with $2.1 million. Litecoin also attracted a minor inflow of $0.3 million over the past week.

Sui and Ton, on the other hand, suffered the most with outflows of $12.9 million and $1.5 million, respectively. Multi-asset products also witnessed $0.6 million in outflows.

Regional Divergence

Regionally, the United States experienced the largest outflows, with $1.31 billion over the past week, while Sweden and Switzerland recorded $135 billion and $11.8 billion in withdrawals, respectively. Several other countries, however, saw modest inflows.

Germany, for one, led with $18.4 million in inflows, followed by Canada with $3.7 million and Australia with $3.5 million. Hong Kong contributed $2.6 million, while Brazil also attracted $1 million in inflows during the same period.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/crypto-funds-just-lost-1-43b-in-the-biggest-drain-since-march/feed/ 0 55083
Scammers Drain $27,000 From Bank of America Customer After Duping Victim With Apple Wallet Trick: Report https://earlybirdsinvest.com/scammers-drain-27000-from-bank-of-america-customer-after-duping-victim-with-apple-wallet-trick-report/ https://earlybirdsinvest.com/scammers-drain-27000-from-bank-of-america-customer-after-duping-victim-with-apple-wallet-trick-report/#respond Tue, 29 Jul 2025 17:20:29 +0000 https://earlybirdsinvest.com/scammers-drain-27000-from-bank-of-america-customer-after-duping-victim-with-apple-wallet-trick-report/

A scammer reportedly drained $27,000 in life savings from a man in Arizona by pretending to be his bank representative.

An Arizona resident who wants to only be identified as Dave tells the website Moneywise.com that he received a normal-looking fraud alert from Bank of America, which questioned whether he had authorized a $399 purchase at the electronics store Best Buy.

Dave responded, saying “no,” and then reportedly received a follow-up text from the scammer with a number to call. Someone claiming to be a Bank of America (BofA) representative then told Dave over the phone that his account had been compromised and that he was being targeted by a rogue BofA employee.

The con artist told Dave to withdraw his whole bank account to protect it, and then the scammer instructed him to “secure” the cash using Apple Wallet.

Dave was then walked through creating a scannable card on his phone that was linked to the scammer’s account. The Arizona man then deposited the cash in a bank drive-through, unwittingly transferring the money to a scammer.

“This is my life savings, and I don’t have any assurances, but they sounded so real.”

Peoria Police Department Detective Michael Finney worked with Dave and froze the linked accounts, managing to recover roughly 90% of his funds in five months.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/scammers-drain-27000-from-bank-of-america-customer-after-duping-victim-with-apple-wallet-trick-report/feed/ 0 50347
Scammers Pose as Tech Firms to Drain Crypto Wallets, Darktrace Warns https://earlybirdsinvest.com/scammers-pose-as-tech-firms-to-drain-crypto-wallets-darktrace-warns/ https://earlybirdsinvest.com/scammers-pose-as-tech-firms-to-drain-crypto-wallets-darktrace-warns/#respond Sat, 12 Jul 2025 19:14:21 +0000 https://earlybirdsinvest.com/scammers-pose-as-tech-firms-to-drain-crypto-wallets-darktrace-warns/

Darktrace, a cybersecurity firm, has warned that online scammers are using fake startups to steal cryptocurrency from unsuspecting users.

According to the findings shared on July 10, the attackers use methods similar to those seen in “Traffer Group” campaigns, which are known for stealing account details and other sensitive data through malicious software.

This scam works by creating fake companies that claim to work in areas like artificial intelligence (AI), gaming, Web3, and social media. These fake start-ups use hacked X accounts to contact people and also publish posts on Medium and GitHub to make their projects look real.

What is Impermanent Loss in Crypto? (Explained With Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Darktrace explained in the report that victims are usually approached through private messages on X, Telegram, or Discord. The cybersecurity firm noted:

A fake employee of the company will contact a victim asking to test out their software in exchange for a cryptocurrency payment.

The attackers then send a link to download the malicious software. When victims install it, a Cloudflare security screen appears, while the program secretly begins collecting data from the computer.

As part of this process, the malware steals the victim’s cryptocurrency wallet credentials. Both Windows and Mac users have been affected, the report stated.

On July 8, BitMEX



$51.24K

Research reported that a Bitcoin
BTC


$117,573.51

wallet linked to the Mt. Gox hack has become the target of a new scam. How? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/scammers-pose-as-tech-firms-to-drain-crypto-wallets-darktrace-warns/feed/ 0 47259
Scammers Drain $70,000 From Bank Accounts in Scheme Targeting JPMorgan Chase, Bank of America, Citibank and Capital One Customers: Report https://earlybirdsinvest.com/scammers-drain-70000-from-bank-accounts-in-scheme-targeting-jpmorgan-chase-bank-of-america-citibank-and-capital-one-customers-report/ https://earlybirdsinvest.com/scammers-drain-70000-from-bank-accounts-in-scheme-targeting-jpmorgan-chase-bank-of-america-citibank-and-capital-one-customers-report/#respond Sat, 05 Jul 2025 22:29:03 +0000 https://earlybirdsinvest.com/scammers-drain-70000-from-bank-accounts-in-scheme-targeting-jpmorgan-chase-bank-of-america-citibank-and-capital-one-customers-report/

An ATM scheme has reportedly drained tens of thousands of dollars from elderly customers of the biggest banks in the United States.

New York City police are warning senior citizens to be on the lookout for a trio of scammers at ATMs after a crime spree that occurred between May and June, reports The New York Post.

Authorities warn that the group – made up of two men and a woman – act as good Samaritans by offering to help the elderly use the ATM or strike up a conversation with them as a distraction to try and steal their bank cards.

Police say that on May 14th, the trio stole $20,000 from the bank account of a 90-year-old woman and drained $3,000 from the account of an 83-year-old woman in two separate incidents that occurred just one hour apart.

On June 2nd, one of the thieves started up a conversation with a 71-year-old man while withdrawing cash at a Chase Bank ATM. While the victim was distracted, the scammer stole the man’s bank card and linked up with another man at a different Chase Bank ATM location, where they tried to take out $5,500.

The 71-year-old says the scammers charged $6,000 to his account in just one hour.

The thieves struck again on June 19th when they targeted an 86-year-old woman and stole about $24,000 from her account.

According to the police, the trio is responsible for stealing at least $70,000 from elderly victims.

Authorities say that a total of nine incidents of thieves using the same scheme against seniors at Chase Bank, Bank of America, Capital One and Citibank locations in New York were reported between May 8th and June 26th.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
]]>
https://earlybirdsinvest.com/scammers-drain-70000-from-bank-accounts-in-scheme-targeting-jpmorgan-chase-bank-of-america-citibank-and-capital-one-customers-report/feed/ 0 45986
Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections https://earlybirdsinvest.com/pepe-meme-creators-nft-projects-hit-for-1-million-as-contract-hijackers-drain-collections/ https://earlybirdsinvest.com/pepe-meme-creators-nft-projects-hit-for-1-million-as-contract-hijackers-drain-collections/#respond Sat, 28 Jun 2025 23:47:26 +0000 https://earlybirdsinvest.com/pepe-meme-creators-nft-projects-hit-for-1-million-as-contract-hijackers-drain-collections/

Projects tied to Pepe meme creator Matt Furie and the NFT studio ChainSaw lost roughly $1 million to contract takeover exploits last week, according to on-chain investigator ZachXBT.

On June 27, ZachXBT reported transaction records showing that the attacker seized control of the “Replicandy” contract at 4:25 a.m. UTC on June 18 by transferring ownership to the externally owned address 0x9Fca. 

Two hours later, the new owner withdrew mint proceeds and, at 5:11 a.m. the next day, reopened the mint, issued fresh NFTs, and dumped them into open bids, pushing the floor price to zero.

On June 23, the same address took over three additional ChainSaw contracts: Peplicator, Hedz, and Zogz. The bad actor then repeated the mint-and-dump cycle. 

ZachXBT estimated the combined theft at more than $310,000 and linked the funds to three collector addresses: 0xf6a9, 0x7e58, and 0x58f4. He traced a 2.05 ETH payment from 0x9Fca to an exchange deposit that converted to 5,007.91 USDT and was then moved to MEXC. 

He subsequently mapped many smaller monthly deposits from unrelated projects into the same exchange wallet.

Two GitHub accounts, “devmad119” and “sujitb2114,” list wallets that intersect the stolen fund trail. 

Both accounts share indicators that ZachXBT associated with North Korean IT workers, including Korean language system settings, Astral VPN sessions, and Asia-Russia time zones, despite résumés that claim US residency.

Favrr exploit follows the same payroll path

A second incident surfaced on June 25, when the freelance services token project Favrr lost more than $680,000 following its listing on a DEX. On-chain analysis linked the exploit to the consolidation wallet 0x477, which received recurring payments from Favrr payroll addresses 0x1708 and 0x6412. 

Gate.io deposit address 0xab7 received part of the stolen Favrr tokens, and was previously funded by the suspected developer behind “sujitb2114”.

Favrr announced that it would refund all initial decentralized offering participants, cancel its MEXC listing, and initiate a thorough audit of its codebase. The project added that it will publish a new launch timeline “in the coming weeks” and advised users to avoid trading impostor tokens in the interim.

ZachXBT reported that Favrr’s chief technology officer, listed as Alex Hong, deleted his LinkedIn profile after the exploit. Attempts to verify his work history with previous employers were unsuccessful.

The investigator plans to release aggregate data on payroll flows to wallets tied to the same North Korean cluster, contending that basic due diligence checks would have flagged the hires.

The stolen funds from the ChainSaw collections remain idle, while most Favrr proceeds have already passed through Gate.io and several nested services. 

ZachXBT said he has not reached the teams because their direct message channels are closed, and official Telegram or Discord rooms do not provide contact options.

The incidents bring renewed attention to the risks of “shadow hiring” in crypto projects that outsource development through gig-work platforms. 

Investigators continue to follow the on-chain trails, and affected communities await formal statements from Furie, ChainSaw, and Favrr.

Mentioned in this article
]]>
https://earlybirdsinvest.com/pepe-meme-creators-nft-projects-hit-for-1-million-as-contract-hijackers-drain-collections/feed/ 0 44694
16 Billion Exposed Passwords Give Hackers Blueprint to Drain Wallets – Crypto Security Alert https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/ https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/#respond Thu, 19 Jun 2025 21:43:02 +0000 https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/

Journalist

Hassan Shittu

Journalist

Hassan Shittu

About Author

Hassan, a Cryptonews.com journalist with 6+ years of experience in Web3 journalism, brings deep knowledge across Crypto, Web3 Gaming, NFTs, and Play-to-Earn sectors. His work has appeared in…

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

A recent data breach has exposed over 16 billion login credentials from online platforms, including Apple, Google, Facebook, Telegram, and GitHub.

The Cybernews research team, which uncovered the leak, described it as one of the largest credential dumps ever recorded, with serious implications for online users, crypto security, and digital asset management.

16B Login Records Leaked in Alarming Wave of Fresh Malware-Based Breaches

According to researchers, the breach is not a single incident but a combination of datasets collected from infostealer malware, credential stuffing attacks, and previously unreported leaks.

Some of these datasets contained up to 3.5 billion entries on their own, with the average dataset holding around 550 million records. The researchers have been tracking the data since early 2024, uncovering at least 30 exposed sets, many of them never publicly disclosed before.

“This is not just a leak—it’s a blueprint for mass exploitation,” the Cybernews team stated.

“With over 16 billion login records exposed, cybercriminals now have unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing,” they added.

The structure and recency of the data make the breach especially dangerous. Unlike older, recycled leaks, much of this data was harvested recently by modern info-stealing malware, posing an urgent crypto security threat to users.

The data typically includes login details organized by URL, along with associated usernames, passwords, cookies, and even tokens.

Some datasets point to specific services, such as Telegram, which was linked to a 60 million record dump.

Another, allegedly tied to the Russian Federation, held more than 455 million records. A number of entries also appear related to cloud services, government portals, and business accounts.

Most of the data was found in unsecured Elasticsearch databases and object storage instances. Though these were exposed for only a short period, it was long enough for researchers to copy the contents.

The origin of the datasets remains unclear, but experts believe that at least some were compiled by criminal actors.

Massive Credential Leaks cRaise Alarm for Crypto Users Amid Dark Web Sales

At this scale, credential leaks are a direct threat to crypto security. Attackers can deploy phishing scams, ransomware, business email compromise tactics, and unauthorized access to crypto wallets and trading platforms.

Users without multi-factor authentication (MFA) are especially vulnerable.

“The inclusion of both old and recent infostealer logs—often with tokens, cookies, and metadata—makes this data particularly dangerous for organizations lacking multi-factor authentication or credential hygiene practices,” researchers added.

While the full number of people affected is impossible to determine due to overlapping records, the scale means even a small success rate could translate into millions of compromised accounts.

Crypto users, in particular, are advised to act quickly. Since wallet services and exchanges often rely on credentials linked to mainstream email providers or cloud services, any breach could lead directly to asset theft.

Cybernews stressed the importance of basic cyber hygiene. Users should change passwords immediately, turn on MFA wherever possible, and scan their devices for malware.

“There’s little impact users can have on the existence of these leaks,” the research team noted, “but staying proactive with your own security remains the best defense.”

At the time of reporting, no single actor has claimed responsibility for the leaked databases.

But with new datasets emerging every few weeks, researchers say this reflects a growing trend of sophisticated infostealer operations that threaten the entire crypto security ecosystem.

For now, the leak stands as a stark reminder of how exposed digital life can be and how quickly stolen credentials can turn into real-world consequences.

This reminder can be corroborated with the recent incident of threat actors on the dark web allegedly selling personal data from users of major crypto exchanges Gemini and Binance, according to a March 27 report by cyber threat tracker Dark Web Informer.

A threat actor known as “AKM69” is claiming to offer 100,000 Gemini records, including names, emails, phone numbers, and location data, mostly from the U.S., U.K., and Singapore.

Another seller, “kiki88888,” listed 132,000 alleged Binance user records, though the source appears to be infostealer malware, not an exchange breach.

Though there’s no confirmed breach of the exchanges themselves, the incident shows the evolving threat to crypto security, with stolen credentials often repurposed for phishing, fraud, and wallet recovery scams.


]]>
https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/feed/ 0 42989
HashEx Security Alert – A Single Signature Could Drain Your Wallet https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/ https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/#respond Sat, 05 Apr 2025 05:35:14 +0000 https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/
HodlX Guest Post  Submit Your Post

 

Zero days without incidents in the DeFi space. This time the vulnerability was discovered in a widely used ‘elliptic library.’

What makes matters worse its exploitation could lead to hackers taking control of users’ private keys and draining wallets.

All through a simple fraudulent message signed by a user. Is this a critical issue?

The first thing to consider is the fact that libraries like elliptic provide developers with ready-made code components.

This means that instead of writing the code from scratch and checking it as they go, developers just borrow the elements they need.

While it’s considered to be a safer practice, since the libraries are continuously used and tested, this also increases the risks if one vulnerability gets through.

Elliptic library is used extensively across the JavaScript ecosystem. It powers cryptographic functions in many well-known blockchain projects, web applications and security systems.

According to NPM statistics, the package containing the error is downloaded approximately 12–13 million times weekly, with over 3,000 projects directly listing it as a dependency.

This broad usage implies that the vulnerability potentially affects a vast number of applications especially cryptocurrency wallets, blockchain nodes and electronic signature systems as well as any service relying on ECDSA signatures through elliptic, especially when handling externally provided input.

This vulnerability allows remote attackers to fully compromise sensitive data without proper authorization.

That’s why the issue received an extremely high severity rating approximately nine out of 10 on the CVSS scale.

It’s important to point out that exploiting this vulnerability requires a very specific sequence of actions and the victim must sign arbitrary data provided by the attacker.

That means that some projects may remain safe, for example, if an application only signs predetermined internal messages.

Still, many users don’t pay as much attention when signing messages via crypto wallets as they do when signing a transaction.

Whenever a Web 3.0 site asks users to sign terms of service, users often neglect to read them.

Similarly, users might quickly sign a message for an airdrop without fully understanding the implications.

Technical details

The problem comes from not handling errors properly during the creation of ECDSA (Elliptic Curve Digital Signature Algorithm) signatures.

ECDSA is commonly used to confirm that messages, like blockchain transactions, are genuine.

To create a signature, you need a secret key only the owner knows it and a unique random number called a ‘nonce.’

If the same nonce is used more than once for different messages, someone could figure out the secret key using math.

Normally, attackers can’t figure out the private key from one or two signatures because each one uses a unique random number (nonce).

But the elliptic library has a flaw – if it gets an odd type of input (like a special string instead of the expected format), it could create two signatures with the same nonce for different messages.

This mistake could reveal the private key, which should never happen in proper ECDSA use.

To exploit this vulnerability, an attacker needs two things.

  • A valid message and its signature from the user for instance, from any previous interactions
  • The user to sign a second message explicitly created to exploit the vulnerability

With these two signatures, the attacker can compute the user’s private key, gaining full access to funds and actions associated with it. Detailed information is available in the GitHub Security Advisory.

Exploitation scenarios

Attackers may exploit this vulnerability through various methods, including the following.

  • Phishing attacks that direct users to fake websites and request message signatures
  • Malicious DApps (decentralized applications) disguised as harmless services, such as signing terms of use or participating in airdrops
  • Social engineering convincing users to sign seemingly harmless messages
  • Compromising servers’ private keys that sign messages from users

A particularly concerning aspect is users’ generally lax attitude toward signing messages compared to transactions.

Crypto projects frequently ask users to sign terms of service or airdrop participation messages, potentially making exploitation easier.

So, think about it would you sign a message to claim free tokens? What if that signature could cost you your entire crypto balance?

Recommendations

Users must promptly update all applications and wallets that utilize the elliptic library for signatures to the latest secure version.

Exercise caution when signing messages, particularly from unfamiliar or suspicious sources.

Developers of wallets and applications should verify their elliptic library version.

If any users could be affected by the vulnerable version, developers must inform them about the urgent need for updating.


Gleb Zykov is the co-founder and CTO of HashEx Blockchain Security. He has more than 14 years of experience in the IT industry and over eight years in internet security, as well as a strong technical background in blockchain technology (Bitcoin, Ethereum and EVM-based blockchains).

 

Check Latest Headlines on HodlX

Follow Us on Twitter Facebook Telegram

Check out the Latest Industry Announcements
 

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any loses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: DALLE3

]]>
https://earlybirdsinvest.com/hashex-security-alert-a-single-signature-could-drain-your-wallet/feed/ 0 29094
Hackers Drain Bank Accounts in New Global Attack on Apple and Google Android Devices: Report https://earlybirdsinvest.com/hackers-drain-bank-accounts-in-new-global-attack-on-apple-and-google-android-devices-report/ https://earlybirdsinvest.com/hackers-drain-bank-accounts-in-new-global-attack-on-apple-and-google-android-devices-report/#respond Thu, 20 Feb 2025 23:59:58 +0000 https://earlybirdsinvest.com/hackers-drain-bank-accounts-in-new-global-attack-on-apple-and-google-android-devices-report/

Hackers are reportedly draining bank accounts and stealing smartphone users’ credentials using a new and highly effective technique.

Cybersecurity researchers say criminals are now sending text messages that appear to be from banks and delivery services – with malicious PDF files attached, reports Samsung Magazine.

The PDFs either contain links that exploit security flaws and install malware or links that send users directly to fake bank websites, enticing people users to enter their login details.

Victims across the US, Germany, and the UK have already suffered financial losses after opening the fraudulent PDFs.

Researchers say people tend to trust PDFs more than links, and the method increases the chances of users falling for the scam.

Although SMS phishing and email-based PDF attacks have existed for years, the tactic of sending malicious PDFs directly via SMS texts is a new twist.

To stay safe, security experts recommend both Apple and Android users avoid opening PDFs from unknown senders, verify messages with official sources, keep smartphones updated and use antivirus software to prevent malware infections.

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Follow us on X, Facebook and Telegram

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/hackers-drain-bank-accounts-in-new-global-attack-on-apple-and-google-android-devices-report/feed/ 0 20806
Microsoft Warns: XCSSET Malware Can Drain Crypto Wallets on Apple Devices https://earlybirdsinvest.com/microsoft-warns-xcsset-malware-can-drain-crypto-wallets-on-apple-devices/ https://earlybirdsinvest.com/microsoft-warns-xcsset-malware-can-drain-crypto-wallets-on-apple-devices/#respond Thu, 20 Feb 2025 06:56:51 +0000 https://earlybirdsinvest.com/microsoft-warns-xcsset-malware-can-drain-crypto-wallets-on-apple-devices/

Microsoft Threat Intelligence has identified an updated version of XCSSET malware that can steal cryptocurrency from macOS devices.

Originally discovered in 2020, XCSSET was known for capturing screenshots, tracking user activity, and extracting data from Telegram.

According to a February 17 post on X, the latest version expands its reach by accessing information stored in Apple’s Notes app. It also uses techniques to hide from detection, which makes it harder to remove.

What is a Liquidity Pool in Crypto? (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Once installed, the malware reloads every time a user opens Launchpad, ensuring it remains active on the device. Since it also has the ability to encrypt files, there is concern it could be used in ransomware attacks.

Microsoft reports that this variant has been seen in only a small number of cases. However, they shared details to help organizations improve security and prevent potential damage.

XCSSET has primarily been found in projects created with Xcode, Apple’s development software. It spreads if developers download infected files. Previous versions could modify what users see in their web browsers, which could allow hackers to replace cryptocurrency wallet addresses and divert funds.

Microsoft notes that its Defender for Endpoint software on Mac can detect the malware. They advise users to carefully review any Xcode projects they download or clone and to only install software from official sources.

Recently, the cybersecurity firm Check Point raised concerns about macOS malware called Banshee. How serious could the malware be? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/microsoft-warns-xcsset-malware-can-drain-crypto-wallets-on-apple-devices/feed/ 0 20662