Security – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 15 Sep 2025 23:23:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Security – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Cupcakes turn your spare phone into free air-gap cold storage https://earlybirdsinvest.com/cupcakes-turn-your-spare-phone-into-free-air-gap-cold-storage/ https://earlybirdsinvest.com/cupcakes-turn-your-spare-phone-into-free-air-gap-cold-storage/#respond Mon, 15 Sep 2025 23:23:36 +0000 https://earlybirdsinvest.com/cupcakes-turn-your-spare-phone-into-free-air-gap-cold-storage/

Cake Wallet launches Cupcake, a free open source app that turns your spare smartphone or tablet into an air-gap cold storage device, offering hardware-level cryptographic security without shipping, cost or personal data collection.

Cupcakes store private keys offline while pairing with cake wallets in modes with views. Users create transactions in the online app, forward them to Cupcake for offline signatures via QR codes, and broadcast and return the signed transaction. Cake wallets place cupcakes as an alternative to traditional hardware wallets, recommending enhanced devices and airplane modes, citing faster access, plausible negativity, no transport or geographical restrictions, and reducing the risk of supply chains. Cupcake currently supports Bitcoin and Monero, touted as suitable for retail users and privacy advocates, and is aimed at those who want immediate banking cold storage without purchasing dedicated hardware.

]]> https://earlybirdsinvest.com/cupcakes-turn-your-spare-phone-into-free-air-gap-cold-storage/feed/ 0 58635 Researchers release undetectable malware and release crypto browser wallets https://earlybirdsinvest.com/researchers-release-undetectable-malware-and-release-crypto-browser-wallets/ https://earlybirdsinvest.com/researchers-release-undetectable-malware-and-release-crypto-browser-wallets/#respond Mon, 15 Sep 2025 18:12:56 +0000 https://earlybirdsinvest.com/researchers-release-undetectable-malware-and-release-crypto-browser-wallets/

A new malware strain was discovered Thursday that could steal data beyond antivirus checks from crypto wallets on Windows, Linux and MacOS systems.

Called ModStealer, the package was delivered through fake job recruiter ads targeted at developers, remaining undetected by the major antivirus engines for almost a month upon disclosure.

The disclosure was made by security company Mosyle, according to the first one Report from 9to5mac. Decryption I reached out to Mosil to learn more.

According to Mosyle, distribution via fake job recruiter ads was an intentional tactic. This is because it is designed to contact developers who are likely already installed a Node.js environment.

ModStealer “will avoid detection by mainstream anti-virus solutions and pose great risks to the broader digital asset ecosystem,” said ShānZhang, chief information security officer at blockchain security firm SlowMist. Decryption. “Unlike traditional steelers, ModStealer stands out for its multi-platform support and stealth “zero-detect” execution chain. ”

When executed, the malware scans browser-based Crypto wallet extensions, system credentials, and digital certificates.

“Exclude data to a remote C2 server,” Zhang explained. A C2, or “Command and Control” server, is a centralized system used by cybercriminals to manage and control compromised devices in a network, and acts as an operational hub for malware and cyberattacks.

On Apple hardware running MACO, malware is automatically configured via a “persistent method” and runs automatically every time the computer starts by impersonating itself as a background helper program.

The setup continues to run quietly without the user noticing. Indications of infection include a secret file called “.sysupdater.dat” for each disclosure and a connection to a suspicious server.

“Although it is common on its own, these persistent methods and strong obfuscation make ModStealer resilient against signature-based security tools,” says Zhang.

The discovery of ModStaler comes just after the relevant warning from ledger CTO Charles Guillemet. Disclosure On Tuesday, the attackers attempted to compromise NPM developer accounts and spread malicious code that could quietly replace crypto wallet addresses during transactions, putting funds at risk across multiple blockchains.

The attack was detected early and failed, but Guillemet later noted that the compromised package was obsessed with Ethereum, Solana and other chains.

“If your funds are sitting in a wallet or exchange of software, you’re one code execution from losing everything.” Gillemet Tweet Hours after his first warning.

When asked about the possible impact of the new malware, Zhang warned that ModStealer would raise “a direct threat to crypto users and platforms.”

For end users, “private keys, seed phrases, and exchange API keys can compromise and lead to direct losses of assets,” Zhang said, adding that “large theft of browser extension wallet data can cause large chain exploits, eroding and amplifying supply chain risks.”

]]> https://earlybirdsinvest.com/researchers-release-undetectable-malware-and-release-crypto-browser-wallets/feed/ 0 58599 Radiant Capital Hacker Washs $26.7 million ETH https://earlybirdsinvest.com/radiant-capital-hacker-washs-26-7-million-eth/ https://earlybirdsinvest.com/radiant-capital-hacker-washs-26-7-million-eth/#respond Mon, 15 Sep 2025 13:01:15 +0000 https://earlybirdsinvest.com/radiant-capital-hacker-washs-26-7-million-eth/

The world of decentralized finance (DEFI) is once again tackling important security cases. The news recently broke the infamous Radiant Capital Hacker I washed quite a bit. The incident highlights an ongoing vulnerability within the crypto ecosystem.

Specifically, hackers have driven a staggering 5,933 ETH, worth around $26.7 million, through privacy mixer Tornado Cash. This move, reported by Embercn, is a significant development after the first exploit.

How did the Radiant Capital Hacker perform the laundry?

The laundry process involves the use of Tornado Cash, a decentralized protocol designed to obscure the origins of cryptocurrency trading. for Radiant Capital HackerThis tool has proven effective in making it difficult to follow the stolen funds.

Here is a breakdown of the important facts:

  • Laundry: 5,933 ETH, worth $26.7 million.
  • method: We used Tornado Cash, a well-known crypto mixer.
  • Current holdings: Despite the laundry, hackers still manage around $104 million in various cryptocurrencies.

This event is not an isolated incident, but a continuation of a previously targeted exploit on radiocapital. Hackers systematically moved funds to avoid detection, pose a major challenge to tracing efforts.

What is the impact on Defi Security and Trust?

This latest move Radiant Capital Hacker Send strict reminders about the persistent security risks of your Defi space. When such large sums are stolen and washed, they inevitably invade users’ trust in decentralized protocols.

This case raises several important questions:

  • How can the Defi protocol enhance security measures to prevent future exploits?
  • What role does Tornado cash play in enabling illegal activities?
  • How can the Crypto community work together with such sophisticated attacks?

Furthermore, the ability to Radiant Capital Hacker Moving such a substantial amounts underscores the need for continued vigilance and improved audit practices within the Defi Ecosystem. Protocols must prioritize robust security frameworks.

Addressing the broader challenges of cryptographic exploits

Radioactive capital exploits are not unique. The crypto industry has witnessed numerous hacks and thefts. However, each incident provides valuable lessons. Projects need to invest heavily in security audits, bug bounty programs and real-time monitoring, and need to quickly detect and respond to threats.

It is paramount for users to understand the risks associated with DEFI. Always conduct a thorough investigation before interacting with the protocol and consider the security track record of the platform you are using.

In conclusion, a $26.7 million laundry was successful. Radiant Capital Hacker Through Tornado Cash, it will be a major blow to the project and the broader Defi community. It highlights the critical needs of enhanced security measures and collective efforts to protect digital assets. The ongoing challenge of tracking these funds will undoubtedly shape future debates about regulatory oversight and technological advances in crypto security.

Frequently asked questions (FAQ)

Q1: What is radioactive capital?

Radiant Capital is a distributed financing and borrowing protocol built on the Arbitrum blockchain, aimed at providing cross-chain liquidity to its users.

Q2: How much money did Radiant Capital Hacker wash?

Hackers washed 5,933 ETH. This was worth around $26.7 million at the time of transaction through Trnado’s cash.

Q3: What is Tornado Cash and why is it debatable?

Tornado Cash is a decentralized privacy solution that mixes various cryptocurrency transactions to obscure their origins and makes it difficult to track funds. That’s controversial as hackers and illegal actors are frequently used to wash stolen funds while meeting legal privacy needs.

Q4: Do hackers still have stolen funds?

Yes, even after washing $26.7 million, the hackers reportedly hold about $104 million in other cryptocurrencies.

Q5: What does it mean to users of Radiant Capital?

The immediate effect of laundry on user funds depends on the specific nature of the original exploit, but such events generally lead to reduced trust and potential volatility of the protocol’s native token. Users must maintain notifications via official radiocapital channels.

If you find this article insightful, consider sharing it with your network to spread awareness about key security issues in the crypto space. Your vigilance will help strengthen our collective defense against illegal activities.

For more information on the latest crypto market trends, see our article on radioactive capital and Defi security measures, major developments that will shape future audits.

Disclaimer: The information provided is not trading advice, bitcoinworld.co.in is not responsible for any investments made based on the information provided on this page. We strongly recommend independent research and consultation with qualified experts before making an investment decision.

]]> https://earlybirdsinvest.com/radiant-capital-hacker-washs-26-7-million-eth/feed/ 0 58566 Was NPM exploited? https://earlybirdsinvest.com/was-npm-exploited/ https://earlybirdsinvest.com/was-npm-exploited/#respond Mon, 15 Sep 2025 07:49:34 +0000 https://earlybirdsinvest.com/was-npm-exploited/

Recent NPM supply chain attacks have sparked a brief panic in the crypto community and increased fear of widespread fund theft. Some dismissed exploitation as a minor, but security experts emphasized it as a wake-up call to developers.

“Nothing Burger” with wake-up call

The first report of a massive JavaScript Node Package Manager (NPM) supply chain attack caused a short but intense period of panic within the crypto community. For hours, the destiny seized the warning and speculated about the widespread theft of the user fund. At the time, Ledger CTO Charles Guillemet advised software wallet users to stop on-chain transactions and hardware wallet users and recheck all transactions.

However, over time, the magnitude of the attacks became more clear. It has become clear that malicious code is highly targeted and the number of affected applications is limited. Notable projects like Uniswap, Metamask, Okx Wallet and Aave are all released statements that confirm that they are not affected.

The widespread lack of damage quickly turned the initial panic into a debate. Some Crypto users have begun to question the severity of the original warning. Some now see it as a vigilante, and even see indirect attacks on software wallets. This perspective, while highlighting authentic vulnerabilities, suggests, may be exaggerated to promote the use of hardware wallets.

While some have branded the damage from the perspective of stolen cryptographic elements as a misuse of “Nothingburger,” some blockchain security experts argue that the incident should serve as a wake-up call for all software developers. These experts agree that the incident examines the security model of hardware wallets, but also warn users of such wallets could lose funds for similar attacks under certain circumstances.

Cartesi co-founder Augusto Teixeira showed this point, saying, “Even hardware wallet users can be affected by such attacks. For example, they use hardware wallets with the help of meta masks without checking the data on the device’s screen.

According to Teixeira, hardware wallets don’t have any important features, such as address books and integration with JSON ABI. This allows users to better understand what they are signing from the device’s screen.

Industry-wide impact and best practices

NPM Incidents raise questions about the security practices used by developers, package managers, and organizations. Some people in the Crypto industry believe that best practices (such as peer reviews, unable to allow developers to push code into production without approval) can minimize the probability of such an attack. Additionally, they argue that developers should update their systems and avoid reusing passwords.

Shahaf Bar-Geffen, co-founder and CEO of COTI, believes package managers like NPM should make the sign-in process even more difficult to become an attacker. He argues that “critical package security frameworks,” potentially overseen by organizations like the OpenJS Foundation, can “require annual third-party audits of packages that exceed the fast download thresholds” “2FA, Scoped API tokens), reproducible builds, and packages that exceed the fast download threshold.” Bar-Geffen believes this layered validation model will help encourage best practices while protecting critical infrastructure.

Cartesi’s solutions architect Carlo Fragni encourages researchers to continue to focus on the channels they use to avoid having to resort to one person (which could benefit) to expose malicious activities. He also advocates that “analyze dependencies and perform due diligence on all dependencies whenever they are updated to a new version.”

]]> https://earlybirdsinvest.com/was-npm-exploited/feed/ 0 58530 Thorchain Security Breach leads to a loss of $1.2 million https://earlybirdsinvest.com/thorchain-security-breach-leads-to-a-loss-of-1-2-million/ https://earlybirdsinvest.com/thorchain-security-breach-leads-to-a-loss-of-1-2-million/#respond Mon, 15 Sep 2025 02:38:00 +0000 https://earlybirdsinvest.com/thorchain-security-breach-leads-to-a-loss-of-1-2-million/

Thorchain experienced a security breach this week, resulting in an estimated loss of around $1.2 million. The numbers themselves are smaller than some of the larger hacks we’ve seen in recent years, but the fact that it happened again on the same protocol tells us. Thorchain has established itself as a major player in distributed cross-chain swap. It allows people to travel between Bitcoin, Ethereum, Binance chains and other networks without using central exchange. The core idea is obviously strong, but it targets the system.

Ongoing exploits raise concerns about the stability of the protocol

The latest incidents add to the long history. Thorchain has handled multiple exploits since 2021, including a series of attacks that have released around $13 million in weeks. The network was also announced earlier this year, revealing a $93 million shortfall and hundreds of millions of debt. To sum up, this pattern questions whether infrastructure is strong enough to handle both legitimate demand and constant pressure from attackers.

Cross-chain swaps pose structural security risks

Part of the problem is how cross-chain swapping works. The system acts like a bridge between different blockchains, and its bridges often turn into the weakest point. Once attackers find flaws, they can drain the funds quickly. It takes place long before the defense catches up. A million losses are important to the community, and they repeatedly take cases and take away trust.

Thorchain Security Breach and Hacked Funds Wash

What makes things even more complicated is Torcaine’s role in handling hacked funds from other attacks. Earlier this year, roughly $1.2 billion flowed through Torcaine from Bibit’s exploit. Hackers were able to convert stolen Ethereum to Bitcoin, and used the cross-chain feature to blur the trail. Thorchain’s daily trading volume jumped from around $80 million to nearly $600 million during that episode. Obviously, the same tool that allows for decentralized swap gives criminals a way to wash stolen assets.

Wide trends in cross-chain bridge attacks since 2021

Cross-chain bridges have been attacked over and over again. Poly Network lost more than $600 million, Wormhole Bridge was released at $326 million, and North Korea-linked Ronin Network Hack has well over 500 million. Some estimates have lost over $4 billion in cross-chain attacks between 2021 and 2024, with the average size of these thefts many times larger than other defi exploits.

Vulnerable confidence in Thorchain security and Defi

The industry continues to experiment with corrections. Zero knowledge proof, multi-party computing wallets, and AI-driven monitoring are deployed to reduce single points of failure. Audit and bug bounty programs are standard. Still, attackers continue to move faster than defenders.

For users and investors, all security breaches leave the same question. Can decentralized finances build trustworthy foundations or can they continue to set up vulnerabilities? Thorchain has gone through another $1 million loss, which may seem modest compared to the $1 billion hack, but the message is the same. Defi is still dangerous, especially when cross-chain tools are involved.

]]> https://earlybirdsinvest.com/thorchain-security-breach-leads-to-a-loss-of-1-2-million/feed/ 0 58485 $3.047 million USDC released in fake request finance contract attack https://earlybirdsinvest.com/3-047-million-usdc-released-in-fake-request-finance-contract-attack/ https://earlybirdsinvest.com/3-047-million-usdc-released-in-fake-request-finance-contract-attack/#respond Sun, 14 Sep 2025 21:26:58 +0000 https://earlybirdsinvest.com/3-047-million-usdc-released-in-fake-request-finance-contract-attack/

A recent phishing attack has lost $3.047 billion in USDC. Exploits targeted secure multi-signature wallets. While using fake request finance agreements. Investigators say the attackers carefully planned the scheme. They did it in a way that seemed almost permitted. The victims used two secure, secure multi-signature wallets. According to Scam Sniffer, the transaction appeared to be being processed through the Request Finance app interface. However, what was hidden inside the batch request was the approval of the malicious contract.

The fake contract address was roughly the same as the legitimate contract address. There are only subtle differences in the intermediate characters. Both started and ended with the same character. It makes it difficult to notice at a glance. To improve reliability, the attackers have identified a malicious contract with Etherscan. This extra step made it seem authentic to anyone who casually reviews it. If approval is granted. The attacker quickly ran out of $3.047 billion in USDC. The stolen funds were then exchanged for ETH. They then quickly moved to tornado cash, making it difficult to track.

Carefully planned timeline

The attack timeline shows clear preparation. Thirteen days before the theft, the attacker deployed a fake request financial agreement. They performed multiple “batch payment” transactions to make the contract look active and reliable. By the time the victim has a conversation with it. The contract appeared to have a normal usage history. When the victim used the Request Finance app, the attacker slipped the hidden approval into a batch transaction. Once the transaction is signed, the exploit is complete.

Response from Request Finance

Request Finance has confirmed the incident and issued a statement warning users. The company confirmed that the malicious actors deployed the look of a batch payment agreement. According to the statement, only one customer was affected. The vulnerability has since been fixed. However, the exact method used to inject malicious approval remains unknown. Analysts believe that possible attack vectors can contain vulnerabilities in the app itself. There are also frontends or DNS hijacks that modify malware or browser extension transactions or have been compromised. You cannot exclude other forms of code injection.

Security concerns have been highlighted

This case illustrates the growth trend of fraud in the crypto industry. Attackers no longer rely on basic phishing links or obvious tricks. Instead, they deploy verified contracts, mimic real services, and hide malicious actions within complex transactions. Batch transactions designed to simplify payments can also create opportunities for attackers. This is to group multiple actions together. It becomes difficult for users to see all approvals or forwarding. This ambiguity allows attackers to slip malformed operations. Without being noticed until it’s too late.

Community Lessons

Experts emphasize the need for extreme attention when using multisends. Alternatively, use the batch payment feature. All contract approvals must review letters by letter to avoid confusion with similarly visible addresses. As seen in this case, even the details that are often overlooked can cause significant losses. Security companies also recommend that users minimize the use of browser extensions. You can also check which apps are connected to your wallet.

Update your software, use your hardware wallet for approval, and maintain cross-check contract addresses through trusted sources. These can reduce the risk of such exploits. This incident is a reminder to enhance user protection for the platform. Enhanced warnings, auto-flagrating contracts like visuals, and improved transaction visibility can help prevent similar attacks.

Costly reminders

The $3.047 million loss is a reminder of the high interests of a diversified financial. Secure and request financing remains a popular tool. Attackers are increasingly exploiting complexity. For users, attention is the only real defense. In this case, the attackers relied on sensitiveness, preparation, and persuasive fakes. Unfortunately, it was enough to trick a multi-signature setup and provide access. This case shows that in cryptography, all approvals are important for each click.

]]> https://earlybirdsinvest.com/3-047-million-usdc-released-in-fake-request-finance-contract-attack/feed/ 0 58449 AI Giants faces FTC inquiries regarding chatbot safety and child protection https://earlybirdsinvest.com/ai-giants-faces-ftc-inquiries-regarding-chatbot-safety-and-child-protection/ https://earlybirdsinvest.com/ai-giants-faces-ftc-inquiries-regarding-chatbot-safety-and-child-protection/#respond Sun, 14 Sep 2025 16:13:41 +0000 https://earlybirdsinvest.com/ai-giants-faces-ftc-inquiries-regarding-chatbot-safety-and-child-protection/

The Federal Trade Commission issued a mandatory order to seven major technology companies on Thursday, requesting more information on how artificial intelligence chatbots protect children and teenagers from potential harm.

The research targets Openai, Alphabet, Alphabet, Meta, Xai, Snap, Character Technologies and Instagram, so within 45 days you should disclose how to monetize user engagement, develop AI characters, and protect minors from dangerous content.

The FTC will begin enquiries to AI chatbots that act as companions. Agency Issue 6 (b) Order from 7 companies that run AI chatbots for consumers: https://t.co/pcvqfzhbxl

– FTC (@FTC) September 11, 2025

A recent study by advocacy groups documented harmful interactions with 669 children in just 50 hours of testing, including sexual live streaming with users ages 12 to 15, drug use, and bots suggesting romantic relationships.

“Protecting children online is a top priority for the Trump Vance FTC and encourages innovation in key sectors of our economy,” FTC Chairman Andrew Ferguson said in a statement.

This filing requires that companies provide monthly user engagement, revenue, and safety data split by age groups (under 13), teens (13-17), minors (under 18), young adults (18-24), and users over 25 years old.

The FTC says the information will help the committee investigate. “Companies that provide fellow AI monetize user engagement, impose and enforce age-based restrictions, process user input, generate output, and measure, test and monitor negative impacts before and after deployment.

Construction of AI Guardrails

“It’s a positive step, but the problem is bigger than putting up a guardrail,” said Taranjeet Singh, head of AI at SearchUnify. Decryption.

The first approach is to build guardrails at the prompt or post-generation stage “to ensure that nothing is provided for the child with anything inappropriate.”

“The second method is to deal with it with LLM training. If the model matches the values ​​during data curation, it is more likely to avoid harmful conversations,” Singh added.

He noted that being educated as a major case in which AI can “improve learning and reduce costs” can “play a bigger role in society.”

Safety concerns regarding AI interactions with users have been highlighted by several cases, including an illegal death lawsuit against Chargether after 14-year-old Sewell Setzer III committed suicide in February 2024 following an obsessive relationship with AI BOT.

Following the lawsuit, there is notice of Charition.AI “improve detection, response and intervention related to user input that violates our terms and community guidelines” and extension of time, a company spokesperson said. Decryption at that time.

Last month, the National Association of Attorney Generals sent a letter to 13 AI companies demanding stronger child protection.

The group warned that “exposing a child to sexual content cannot be defended,” and that “when it was done by a human, it is illegal, or even for criminals, it is illegal.”

Decryption We will contact all seven companies named in our FTC order for additional comments and update this story if we respond.

]]> https://earlybirdsinvest.com/ai-giants-faces-ftc-inquiries-regarding-chatbot-safety-and-child-protection/feed/ 0 58417 The new ModStealer malware targets crypto wallets across the operating system https://earlybirdsinvest.com/the-new-modstealer-malware-targets-crypto-wallets-across-the-operating-system/ https://earlybirdsinvest.com/the-new-modstealer-malware-targets-crypto-wallets-across-the-operating-system/#respond Sun, 14 Sep 2025 11:02:37 +0000 https://earlybirdsinvest.com/the-new-modstealer-malware-targets-crypto-wallets-across-the-operating-system/

A newly discovered malware called ModStealer targets crypto users across MacOS, Windows and Linux systems, poses the risk of accessing wallets and credentials.

Apple-focused security company Mosyle said it has been completely undetected by major antivirus engines for almost a month since it was uploaded to Virustotal, an online platform that detects malware and analyzes files that detect malicious content.

Mosyle said ModStealer is designed to extract data using preloaded code that steals private keys, certificates, credentials and browser-based wallet extensions. Security researchers have discovered a variety of wallet targeting logic, including extensions to Safari and Chromium-based browsers.

The security company said malware will persist on MacOS by abuse the system to register as a background agent. The team said that although the servers are hosted in Finland, they believe the infrastructure will be routed through Germany to hide the operator’s origins.

Security companies warn of fake job ads

Malware is reportedly distributed through fake job recruitment ads, a tactic that is increasingly used to target web3 developers and builders.

When a user installs a malicious package, ModStealer will be embedded in the system and run in the background. Capture data from the clipboard, take a screenshot, and execute a remote command.

Stephen Ajayi, Dapp and technical leads at AI audit blockchain security company Hacken told Cointelegraph that malicious recruitment campaigns are becoming increasingly common using fraudulent “test tasks” as a malware delivery mechanism. He warned developers to take additional precautions when asked to download files or complete a full evaluation.

“Developers need to verify the legitimacy of recruiters and related domains,” Ajayi told Cointelegraph. “Sharing assignments through a public repository and requesting tasks to be opened only in disposable virtual machines that do not have a wallet, SSH key, or password manager.”

Emphasizing the importance of compartmentalizing sensitive assets, Ajayi advised the team to maintain a strict separation between the development environment and wallet storage.

“A clear separation between the development environment ‘development box’ and the wallet environment ‘wallet box’ is essential,” he told Cointelegraph.

Related: Failed NPM Exploit Highlights Posing Threat to Crypto Security: exec

Hacken Security Lead shares practical steps with users

Ajayi also highlighted the importance of basic wallet hygiene and endpoint stiffening to protect against threats like ModStealer.

“I use a hardware wallet and always check the transaction address on the device display, and at least the first and last six letters before accepting,” he told Cointelegraph.

Ajayi advised users to maintain a dedicated lockdown browser profile or separate device dedicated to wallet activity, interacting with only trusted wallet extensions.

For account protection, he recommended offline storage for seed phrases, multifactor authentication, and FIDO2 passkeys where possible.

https://www.youtube.com/watch?v=pf_ibefihvc

magazine: Thailand’s “Big Secret” Crypto Hack, RWA Token for Chinese Developers: Asia Express

]]> https://earlybirdsinvest.com/the-new-modstealer-malware-targets-crypto-wallets-across-the-operating-system/feed/ 0 58384 New insights highlight Defi’s urgent security measures https://earlybirdsinvest.com/new-insights-highlight-defis-urgent-security-measures/ https://earlybirdsinvest.com/new-insights-highlight-defis-urgent-security-measures/#respond Sun, 14 Sep 2025 05:51:24 +0000 https://earlybirdsinvest.com/new-insights-highlight-defis-urgent-security-measures/

The rapid growth of cross-chain transfers in decentralized finance (DEFI) has launched new opportunities for users, but has also introduced unprecedented risks. According to recent security analysis, flash loan attacks have become a major threat to bridge protocols, with billions of dollars being lost due to exploits within minutes of execution.

Platforms such as Jumper replacement While positioning itself as a safer alternative for cross-chain operations, experts emphasize that the broader ecosystem still faces fundamental vulnerabilities that require urgent solutions.

Flashloans allows attackers to borrow huge amounts of money instantly, exploit the weaknesses of the protocol and repay the loans in one blockchain transaction. If the attack fails, the transaction returns and there is no risk of an attacker.

“Flash loans have transformed the weaknesses of any minor protocol into a valuable opportunity for attackers. “Cross-chain bridges are particularly vulnerable due to the complex processes involved in locking, casting and verifying assets across multiple blockchains.”

Recent incidents highlight the scope of the issue.

  • Euler Finance (March 2023) – The attacker used flash loans to operate the internal accounting system, causing great losses.
  • Wormhole Bridge (February 2022) – Fault in signature verification allows for the creation of wrapped tokens without comparable collateral.
  • Ronin Bridge (March 2022) – Secret keys compromise exposed balloters and allow attackers to steal hundreds of millions of assets.
  • Re-attack – Take advantage of contracts that allow multiple calls before updating your balance.
  • Oracle Operation – Distorts price supply using Flashloan-funded transactions.
  • Abuse of governance – Temporarily borrow a governance token and pass on a malicious proposal.

Industry leaders recommend multi-layered defense strategies, including:

  • Governance delay – A waiting period will be implemented before the proposal becomes effective.
  • Multi-signature scheme – Distribute signing authority across organizations and jurisdictions.
  • Rate Limiting and Ceiling – Preventing large withdrawals or rapid debt accumulation.
  • Real-time monitoring – Detect suspicious transactions, rapid governance shifts, or abnormal liquidity movements.

“Security can no longer be an afterthought,” he added (spokesman). “The protocol must combine distributed verification with robust emergency response capabilities to prevent catastrophic violations.”

Encouraging developments are emerging, such as proof-based bridges of zero knowledge, final improvements to Layer 2, and insurance protocols that provide partial coverage of bridge-related losses. However, experts warn that attackers are targeting governance systems and adapting as quickly as they are leveraging miners’ extractable value (MEV) opportunities.

Regulatory frameworks are beginning to take shape, but standards vary by jurisdiction. Until more comprehensive protections are in place, users are encouraged to choose a platform with proven security records and robust protection mechanisms.

The organization is a leader in blockchain security research and infrastructure, dedicated to advancing the secure and scalable solutions of the Defi Ecosystem. By developing cutting-edge protocols and promoting best practices, the company will enable users and institutions to safely participate in the future of multi-chain financials.

]]> https://earlybirdsinvest.com/new-insights-highlight-defis-urgent-security-measures/feed/ 0 58348 DOJ is about to seize $500,000 in USDT from Ilandrone Supplier’s private wallet https://earlybirdsinvest.com/doj-is-about-to-seize-500000-in-usdt-from-ilandrone-suppliers-private-wallet/ https://earlybirdsinvest.com/doj-is-about-to-seize-500000-in-usdt-from-ilandrone-suppliers-private-wallet/#respond Sun, 14 Sep 2025 00:40:12 +0000 https://earlybirdsinvest.com/doj-is-about-to-seize-500000-in-usdt-from-ilandrone-suppliers-private-wallet/

The U.S. Attorney’s Office in Massachusetts has filed civil forfeiture measures to recover approximately $584,741 in tether (USDT) stablecoins From the Iranian people who provided technology to the Iranian army.

Tokens are said to be stored in non-bearing cryptocurrencies walletauthorities did not give any further details.

Mohammad Abedini, 39, is the founder and managing director of San’at Danesh Rahpooyan Aflak Co. (SDRA), an Iranian company that provides the technology used in drones to the country’s military.

SDRA is widely used in Iran’s drone strikes and provides navigation equipment to companies producing Shahed drones by Russia in the war in Ukraine, and by several Middle Eastern military groups.

In January 2024, three US service members were killed at a military base in northern Jordan. The DOJ said subsequent analysis revealed that Iranian Shahed UAVs were the source of the attack using SDRA’s Sepehr navigation system.

Abedini has been accused of providing material support to foreign terrorist organizations, resulting in death, and is conspiring to procure sensitive US technology used in military drones. He was detained by Italian authorities in December 2024, but was released in January 2025. According to the DOJ, he is believed to be in Iran at the moment.

According to a request from non-profit Iran Watch from 2016 to 2024, Abedini and his business partners allegedly smuggled US-original electronics and technical data from American manufacturers and re-exported them from Switzerland to Iran. The device is so small that it may have been reportedly carried in a suitcase. These allegations have not been proven yet.

Can the government grab a code from a private wallet?

Grab a crypto from a private wallet is not easy. Unlike centralization exchange Like Coinbase or Binancethere are no intermediaries that the government forces. The owner’s owner controls his keys. But the US government was able to do that before.

In 2022, DOJ seized 94,000 BTC (worth around $3.6 billion at the time) from Ilya Lichtenstein and Heather Morgan, who ran a record-breaking Bitfinex hack.

Investigators tracked down the stolen items, according to the announcement. Bitcoin I finally found the couple’s private key after accessing an online cloud storage account through multiple mixers.

In another example, like Silk Road founder Ross Ulbricht, federal agents performed digital forensics on confiscated laptops to obtain their private keys.

]]> https://earlybirdsinvest.com/doj-is-about-to-seize-500000-in-usdt-from-ilandrone-suppliers-private-wallet/feed/ 0 58308