Hacker – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 19 Jul 2025 01:38:54 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Hacker – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hacker reconnaissance work continues on TeleMessage app vulnerability — Report https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/ https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/#respond Sat, 19 Jul 2025 01:38:53 +0000 https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/

Hackers are continuing to seek out opportunities to exploit the infamous CVE-2025-48927 vulnerability involved in TeleMessage, according to a new report from threat intelligence company GreyNoise.

GreyNoise’s tag, which monitors attempts to take advantage of the vulnerability, has detected 11 IP addresses that have attempted the exploit since April.

Other IP addresses may be performing reconnaissance work: A total of 2,009 IPs have searched for Spring Boot Actuator endpoints in the past 90 days, and 1,582 IPs have specifically targeted the /health endpoints, which commonly detect Spring Boot Actuator deployments.

The flaw allows hackers to extract data from vulnerable systems. The issue “stems from the platform’s continued use of a legacy confirmation in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication,” the research team told Cointelegraph.

TeleMessage is similar to the Signal App but allows for the archiving of chats for compliance purposes. Based in Israel, the company was acquired by US company Smarsh in 2024, before temporarily suspending services after a security breach in May that resulted in files being stolen from the app.

“TeleMessage has stated that the vulnerability has been patched on their end,” said Howdy Fisher, a member of the GreyNoise team. “However, patch timelines can vary depending on a variety of factors.”

Although security weaknesses in apps are more common than desired, the TeleMessage vulnerability could be significant for its users: government organizations and enterprises. Users of the app may include former US government officials like Mike Waltz, US Customs and Border Protection and crypto exchange Coinbase.

GreyNoise recommends users block malicious IPs and disable or restrict access to the /heapdump endpoint. In addition, limiting exposure to Actuator endpoints may be helpful, it said.

Related: Threat actors using ‘elaborate social engineering scheme’ to target crypto users — Report

Crypto theft rising in 2025; credentials on darknet go for thousands

Chainalysis’ latest crime report notes that over $2.17 billion has been stolen so far in 2025, a pace would take crypto-related thefts to new highs. Notable security attacks over the past months include physical “wrench attacks” on Bitcoin holders and high-profile incidents such as the February hack of crypto exchange Bybit.

Attempts to steal credentials often involve phishing attacks, malicious malware, and social engineering. 

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

]]>
https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/feed/ 0 48436
Crypto Hacker Who Drained $42,000,000 From GMX Goes White Hat, Returns Funds in Exchange for $5,000,000 Bounty https://earlybirdsinvest.com/crypto-hacker-who-drained-42000000-from-gmx-goes-white-hat-returns-funds-in-exchange-for-5000000-bounty/ https://earlybirdsinvest.com/crypto-hacker-who-drained-42000000-from-gmx-goes-white-hat-returns-funds-in-exchange-for-5000000-bounty/#respond Sun, 13 Jul 2025 00:30:02 +0000 https://earlybirdsinvest.com/crypto-hacker-who-drained-42000000-from-gmx-goes-white-hat-returns-funds-in-exchange-for-5000000-bounty/

A crypto hacker who stole tens of millions of dollars from the decentralized crypto perpetuals exchange GMX (GMX) is turning white hat by returning the stolen funds to collect a bounty.

In a new thread on the social media platform X, GMX says the hacker who stole $42 million worth of crypto assets earlier this week from its Arbitrum (ARB)-based liquidity pool is returning the funds and collecting a $5 million reward.

“A potential exploitable amount of $42 million belonging to GLP holders was secured. After payment of a $5 million bounty to the user, the remaining funds are now safely in the GMX Security Multisig.

Contributors are working on a proposed distribution plan for presentation to the GMX DAO (decentralized autonomous organization) and will share more information shortly.”

According to previous reports, the hacker struck on July 9th and transferred part of the funds to an unknown wallet. At the time, GMX said the exploit was limited to GMXV1 and that V2, its markets and liquidity pools, as well as the ecosystem’s native asset, were unaffected.

In its report on the incident, GMX says the exploit was a re-entrancy attack, or a type of hack that affects smart contracts by taking advantage of a vulnerability presented when a smart contract makes a call to another before updating itself, leaving open the possibility for an external malicious contract to enter in.

News of the returned fund sent GMX skyrocketing, as the digital asset is trading for $13.36 at time of writing, an 18.4% increase during the last 24 hours.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/crypto-hacker-who-drained-42000000-from-gmx-goes-white-hat-returns-funds-in-exchange-for-5000000-bounty/feed/ 0 47307
GMX Breach: Hacker Returns $20 Million, Keeps 10% as Reward https://earlybirdsinvest.com/gmx-breach-hacker-returns-20-million-keeps-10-as-reward/ https://earlybirdsinvest.com/gmx-breach-hacker-returns-20-million-keeps-10-as-reward/#respond Fri, 11 Jul 2025 21:27:38 +0000 https://earlybirdsinvest.com/gmx-breach-hacker-returns-20-million-keeps-10-as-reward/

A hacker who recently drained $40 million from GMX’s



$0

original trading platform, GMX V1, has begun returning the funds
, following an agreement with the GMX team.

The return process began after the hacker posted a message on the blockchain. The message was noticed by PeckShield, which confirmed that the hacker had accepted GMX’s offer of a reward for returning the money.

The hacker sent back around $9 million worth of Ethereum
ETH


$2,994.69

to an address that GMX had publicly shared.

What is Odysee & LBRY? Is Decentralized YouTube Possible? (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

PeckShield later confirmed two additional transactions, each involving the transfer of FRAX
FRAX


$0.9995

stablecoins, one for $5.49 million and the next for $5 million. In total, about $20 million has been returned.

Following the incident, GMX posted on X on July 10 to address the hacker directly. The team acknowledged the hacker’s skills and offered a $5 million “white hat” reward.

The team said they would help prove the source of the funds so they could be used without risk of being frozen or flagged.

The trading platform also noted that the hacker could retain 10% of the stolen amount, provided that 90% was returned to the addresses listed by GMX. However, GMX warned that if the funds were not returned within 48 hours, they would take legal action.

On July 10, Venn Network researchers stopped a security breach that could have stolen more than $10 million from decentralized finance (DeFi) projects. How? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/gmx-breach-hacker-returns-20-million-keeps-10-as-reward/feed/ 0 47094
Hacker Slips Malicious Code Into Ethereum Dev Tool ETHcode https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/ https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/#respond Fri, 11 Jul 2025 17:06:14 +0000 https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/

Cybersecurity researchers at ReversingLabs recently found that a hacker injected harmful code into ETHcode, a toolset for Ethereum
ETH


$2,962.49

developers.

ETHcode is a VS Code extension that helps developers build and test Ethereum-compatible smart contracts and apps.

The suspicious code was added on June 17 by a GitHub user named Airez299, who had no earlier contributions to the project.

What is Staking Crypto? (Rewards & Risks Explained SIMPLY)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The update included 43 separate changes and about 4,000 edited lines, which mainly described a new testing system and additional features. Inside this large batch, two lines of malicious code were hidden.

The update was reviewed by GitHub’s automated AI tool and also checked by 7finney, the team that manages ETHcode. Neither spotted the problem, and only small edits were requested before approval.

According to ReversingLabs, the harmful code was disguised in a way that made it hard to notice. The first line was placed in a file with a name almost identical to an existing one and written in a scrambled style to make it harder to read.

The second line was designed to activate the first. When triggered, it launched a PowerShell script that downloaded and ran a batch file from a public file-sharing site.

ReversingLabs noted that it was likely designed to steal cryptocurrency stored on the victim’s computer or interfere with Ethereum projects being developed using the tool.

Recently, Sentinel Labs discovered a hacking campaign linked to groups in North Korea that uses malware called NimDoor. How does the malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/feed/ 0 47061
GMX Hacker Returns Stolen $40 Million, Accepts $5M Bounty https://earlybirdsinvest.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/ https://earlybirdsinvest.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/#respond Fri, 11 Jul 2025 12:56:47 +0000 https://earlybirdsinvest.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/

Less than 48 hours after siphoning about $42 million in cryptocurrencies from the decentralized trading platform GMX, the hacker responsible for the attack has begun to return the stolen loot.

According to an update from the on-chain sleuth PeckShield, the GMX exploiter has returned at least $40.5 million in crypto assets, including ether (ETH) and Legacy Frax Dollar (FRAX).

Root Cause of the Exploit

Recall that the hacker exploited GMX’s smart contracts to steal the funds on July 9. A postmortem report from the firm confirmed that it was a re-entrancy attack. The exploiter took advantage of a smart contract function that could not prevent re-entrancy issues within the same smart contract.

This design flaw on GMX V1 enabled the criminal to place multiple calls within one function and caused the contract to calculate the wrong balance. They were able to artificially inflate the price of GLP, which is the liquidity provider token for GMX.

After the breach, they stole several assets, including Wrapped bitcoin (WBTC), FRAX, and DAI. They eventually bridged the funds from Arbitrum to Ethereum and converted all, except FRAX, to 11,700 ETH.

While the hacker made these moves, GMX dropped an on-chain message, offering a 10% white hat bounty in exchange for the stolen funds. The proposal would last for 48 hours, with a promise of no legal consequences.

Hacker Returns Stolen Funds

Earlier today, the hacker responded to GMX’s 10% bounty offering, with a message that read: “Ok, funds will be returned later.” They first returned $10.49 million FRAX to the GMX Security Committee Multisig address. The remaining $32 million, which were swapped for ETH earlier, have also been returned in batches.

Notably, the $32 million ETH was worth $35 million today following the spike in ether’s price. The hacker took the $3 million profit and returned the original amount. Therefore, they took a bounty of roughly $4.5 million and returned a total of $40.5 million.

Meanwhile, GMX has confirmed that the incident did not affect its V2 protocol, as the chain does not have the vulnerability that enabled the attack on V1. The team has lifted the minting caps it placed on liquidity tokens for GMX V2 on Arbitrum and Avalanche.

GMX, the native token of the GMX platform, has also recovered from a sudden dip caused by the incident. Data from CoinMarketCap shows the asset is up over 13% today.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/gmx-hacker-returns-stolen-40-million-accepts-5m-bounty/feed/ 0 47037
Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage https://earlybirdsinvest.com/alleged-chinese-hacker-tied-to-silk-typhoon-arrested-for-cyberespionage/ https://earlybirdsinvest.com/alleged-chinese-hacker-tied-to-silk-typhoon-arrested-for-cyberespionage/#respond Tue, 08 Jul 2025 02:18:44 +0000 https://earlybirdsinvest.com/alleged-chinese-hacker-tied-to-silk-typhoon-arrested-for-cyberespionage/

Cyber China

A Chinese national was arrested in Milan, Italy, last week for allegedly being linked to the state-sponsored Silk Typhoon hacking group, which responsible for cyberattacks against American organizations and government agencies.

According to Italian media ANSA, the 33-year-old man, Xu Zewei, was arrested at Milan’s Malpensa Airport on July 3rd after arriving on a flight from China. Italian police arrested the suspect on an international warrant from the U.S. government.

ANSA reports that Xu is accused of being linked to the Chinese state-sponsored Silk Typhoon hacking group, aka Hafnium, which has been responsible for a wide range of cyberespionage attacks against the U.S. and other countries.

In particular, Italian media reports that Xu is linked to the 2020 Silk Typhoon cyberattacks on infectious disease researchers and healthcare organizations, which aimed to steal data on anti-COVID vaccines.

“These actors have been observed attempting to identify and illicitly obtain valuable intellectual property (IP) and public health data related to vaccines, treatments, and testing from networks and personnel affiliated with COVID-19-related research,” read the joint advisory.

The hacking group has also been linked to more recent cyberespionage campaigns, including those on the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and the Committee on Foreign Investment.

In March, Microsoft reported that Silk Typhoon had begun targeting remote management tools and cloud services in supply chain attacks to gain access to downstream customers’ networks.

Xu is currently being held in Busto Arsizio prison with the U.S. seeking extradition to face trial in the States.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/alleged-chinese-hacker-tied-to-silk-typhoon-arrested-for-cyberespionage/feed/ 0 46386
CZ Warns of New Hacker Trend Targeting Crypto Data Platforms https://earlybirdsinvest.com/cz-warns-of-new-hacker-trend-targeting-crypto-data-platforms/ https://earlybirdsinvest.com/cz-warns-of-new-hacker-trend-targeting-crypto-data-platforms/#respond Tue, 24 Jun 2025 02:27:03 +0000 https://earlybirdsinvest.com/cz-warns-of-new-hacker-trend-targeting-crypto-data-platforms/

Binance’s former CEO, Changpeng Zhao (CZ), has warned about a new wave of cyberattacks targeting crypto data platforms.

This follows recent breaches at CoinMarketCap (CMC) and CoinTelegraph (CT) that exposed users to wallet-draining phishing schemes.

The CMC and CT Attacks

“Hackers are targeting information websites now. Be careful when authorizing wallet connect,” CZ said in a post on X. He pointed out that CMC was attacked just two days before CT was hit with a similar breach.

The trouble began on June 21 when CMC users started seeing a pop-up that said “Verify Wallet” and asked them to connect their crypto wallets. Members of the crypto community on X quickly flagged the notification as a phishing attempt designed to deceive victims into revealing private keys or sensitive information.

Shortly after the reports spread on social media, the platform acknowledged the malicious notification on its account. “We’ve identified and removed the malicious code from our site,” CoinMarketCap said in a Friday update. The team added that security investigations were underway and warned people not to connect their wallets.

CZ later shared that early checks showed 39 individuals were affected by the incident, with total losses of around $18,570. CMC also revealed plans to reimburse those affected by the hack.

On June 23, Cointelegraph’s website was also compromised in a front-end exploit. This time, users saw a pop-up promoting a fake token airdrop. The notification claimed people were eligible to get 50,000 “CTG” tokens, worth around $5,500 if they connected their wallets. The pop-up also falsely claimed that CertiK, a well-known security firm, had reviewed the smart contract.

The media outlet confirmed the issue on Sunday night and said it was working to fix it. “Do not click on these pop-ups, connect your wallets, or enter any personal information,” it warned on X.

Blockchain Security firm Scam Sniffer also found that the fake JavaScript code came from the company’s advertising system.

Hackers Are Shifting Tactics

In both cases, the bad actors were able to approve transactions and steal crypto once users connected their wallets. These incidents show a new trend where attackers are now using trusted news and data platforms to reach people instead of going after crypto exchanges directly.

Meanwhile, a recent study by TRM Labs showed that phishing schemes and malware-based infrastructure attacks made up 70% of the $2.2 billion stolen in crypto-related hacks in 2024.

Another report by Cybernews revealed a massive data breach that exposed over 16 billion login credentials, making it one of the largest stolen data collections ever found. Researchers believe this came from infostealer malware, credential stuffing, and past leaks that were repackaged.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/cz-warns-of-new-hacker-trend-targeting-crypto-data-platforms/feed/ 0 43765
Meta Pool Hacker Mints $27 Million in Tokens, Walks Away With Just $132,000 https://earlybirdsinvest.com/meta-pool-hacker-mints-27-million-in-tokens-walks-away-with-just-132000/ https://earlybirdsinvest.com/meta-pool-hacker-mints-27-million-in-tokens-walks-away-with-just-132000/#respond Mon, 23 Jun 2025 08:37:45 +0000 https://earlybirdsinvest.com/meta-pool-hacker-mints-27-million-in-tokens-walks-away-with-just-132000/

A recent exploit targeting Meta Pool resulted in the attacker walking away with just over $132,000 worth of Ethereum
ETH


$2,253.71

, despite mining nearly $27 million in tokens.

Meta Pool stated in a blog post published on June 17 that this was due to a combination of low trading activity in the token’s markets and a fast response from Meta Pool’s team, who paused the affected smart contract soon after identifying the issue.

The attacker exploited a flaw in Meta Pool’s “fast unstake functionality“, according to co-founder Claudio Cossio.

What is an NFT? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Normally, when someone unstakes their cryptocurrency, there is a delay before they can use it again. The fast version skips that waiting period under certain conditions. This shortcut allowed the attacker to issue 9,705 units of mpETH, the platform’s token used for staking.

According to Meta Pool, the exploit used the ERC4626 mint() function to create these tokens without proper permission. The attacker then tried to swap the fake mpETH for actual ETH across different pools on Ethereum and Optimism. They were able to get only 52.5 ETH, which was worth just over $132,000.

PeckShield confirmed that the contract had a major flaw, but the limited market depth of mpETH made it hard to profit from. Some of the swap pools targeted had very little liquidity, which kept the losses low.

Meta Pool’s team reassured users that all staked Ethereum remains safe. Those funds are handled by operators on the SSV Network, who continue to validate transactions and earn staking rewards.

On June 14, blockchain security firm SlowMist reported that a crypto holder lost nearly $6.9 million. How? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/meta-pool-hacker-mints-27-million-in-tokens-walks-away-with-just-132000/feed/ 0 43618
Lazarus hacker forgets VPN, gets exposed https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/ https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/#respond Mon, 02 Jun 2025 19:51:52 +0000 https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/

If you know anything about a crypto hack, you’ve probably heard of the Lazarus Group.

They’re pretty much the final boss of crypto cybercrime – a North Korean state-backed hacking group responsible for some of the biggest thefts in the industry, including the Bybit hack earlier this year.

They’ve always carried this boogeyman of blockchain, mysterious vibe. But a new BitMEX report pulled back the curtain a bit.

And turns out… they’re not as flawless as some might think.

Tea

Over time, Lazarus seems to have split into smaller teams, and not all of them are equally skilled. Some are pros. Others – not so much.

Case in point: a BitMEX employee got a message on LinkedIn about joining a crypto project.

If you’ve followed Lazarus’ past scams, you know this is something they’ve done before – so the employee flagged it to the security team.

They were sent a GitHub repo with a Next.js/React project that – surprise – contained malware.

The attacker wanted them to run the code locally, which would’ve let malicious scripts execute on the employee’s computer.

Now, here’s what BitMEX found in the code:

  • It used JavaScript’s eval() function, which takes a piece of text and treats it like code. So if it says “delete everything,” your computer will actually try to run that command – and that opens the door for attackers to sneak in harmful code;

  • The malware tried to connect to suspicious URLs to download even more code – the kind of infrastructure Lazarus has used before in past attacks;

  • It collected data like usernames, IP addresses, operating systems, and uploaded all of it to… wait for it… a public Supabase database 😀👍

Yes. Public.

This is like using Google Sheets to store stolen data… and then leaving the spreadsheet unlocked.

Think smart

The BitMEX team took a look and found nearly 900 logs from infected machines.

And in one of them, they caught a big oopsie: a hacker forgot to turn on their VPN and exposed their real location in Jiaxing, China.

Instead of treating this oopsie as a one-off discovery, BitMEX saw an opportunity here – they built a tool to keep checking the database.

This lets BitMEX:

  • Track new infections as they happen;

  • Figure out who’s being targeted – devs, exchange workers, or random users;

  • Watch for repeat mistakes by the hackers (like more IP leaks);

  • Potentially map out patterns – like locations, time zones, or organizational targets.

Lazarus is still dangerous – no doubt about it.

But the more we learn about their tricks (and their mistakes), the easier it becomes to protect people from falling for them.

]]>
https://earlybirdsinvest.com/lazarus-hacker-forgets-vpn-gets-exposed/feed/ 0 39759
Sui Community Launches Vote on Recovering $162,000,000 in Stolen Crypto From Hacker https://earlybirdsinvest.com/sui-community-launches-vote-on-recovering-162000000-in-stolen-crypto-from-hacker/ https://earlybirdsinvest.com/sui-community-launches-vote-on-recovering-162000000-in-stolen-crypto-from-hacker/#respond Fri, 30 May 2025 04:17:47 +0000 https://earlybirdsinvest.com/sui-community-launches-vote-on-recovering-162000000-in-stolen-crypto-from-hacker/

The Sui (SUI) community appears poised to greenlight a recovery plan to return $162 million worth of crypto stolen from the decentralized exchange Cetus Protocol last week.

Last week, a hacker hit Cetus with a sophisticated smart contract exploit targeting the decentralized exchange’s (DEX) concentrated liquidity market maker (CLMM) pools, purloining approximately $223 million worth of assets from the platform.

The DEX quickly froze $162 million worth of the stolen assets. Now, the Sui community is currently voting on a proposal that enables a special transaction to return those frozen assets from two attacker addresses back to Cetus.

If passed, the vote would approve a one-time authentication of two special transactions hard-coded with the two attacker addresses, stolen asset objects, and their destination.

The votes are weighted by validator stake, but the Sui Foundation’s stake is excluded to maintain neutrality. The vote passes if more than 50% of the total stake participates and there are more “yes” votes than “no” votes.

The voting period ends next week, but early passing could happen as early as Thursday if the remaining unvoted stake cannot change the outcome. That appears poised to happen, with 71% of the validators having already voted “yes” at time of writing, compared to 0.3% for “no,” 1.5% abstaining and 27.2% who had yet to vote.

Cetus also announced this week that it is in a position to fully cover the remaining losses via cash, token treasuries and a loan from the Sui Foundation, pending the vote’s passage.

“Because full recovery is dependent upon the results of the community vote, we humbly ask for the Sui community’s full support to recover the funds via the upcoming vote. We recognize that this is an extraordinary ask forced by our actions, however we think it is the right decision especially for those affected.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/sui-community-launches-vote-on-recovering-162000000-in-stolen-crypto-from-hacker/feed/ 0 39078