A clear guide to how cryptocurrency works, with the security lessons hidden inside blockchains, wallets, private keys, custody, and transaction signing.
A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.
An FBI arrest tied to alleged Steam-distributed malware shows how attackers can turn familiar gaming trust into a path toward crypto theft, even without a breach of the platform itself.
A macOS infostealer is drawing attention for leaning on social engineering and process disruption rather than a flashy exploit chain.
A campaign tied to trojanized collaboration software shows how attackers can turn ordinary installer habits into a credential-theft and wallet-theft pipeline.
A cross-border police action against an alleged investment scam network shows how modern crypto fraud depends on persuasion, speed, and payment flows more than on malware.
A recovery-phrase generation flaw known as Ill Bloom shows how weak randomness at wallet creation can leave cryptocurrency funds vulnerable long after the original setup.
A compromised AWS-hosted AI gateway tied to Amazon Bedrock shows how generative AI middleware can become valuable enough to hijack for cryptocurrency mining.
A disguised browser add-on linked to a crypto clipper campaign shows how transaction tampering can happen inside the browser, not on the blockchain.
Researchers flagged a browser-extension campaign that impersonates a familiar note-taking tool and aims to swap cryptocurrency wallet addresses at transaction time.
A critical weakness in remote-support software shows how one privileged login path can become a launch point for malware, secret theft, and broader endpoint risk.
Ukraine’s asset recovery agency moved more than $8.3 million in cryptocurrency into an official wallet, showing how custody, legality, and blockchain controls collide once criminal proceeds become public funds.
The malware campaign tied to Rokarolla shows how mobile fraud tooling can survive pressure on one control channel by pairing impersonation sites with backup command infrastructure and permission abuse.
A new phase of disruption against infrastructure linked to SocGholish, Amadey, and StealC shows how loaders and stealers help turn one intrusion into many crimes.
A surge of scam websites is using the promise of “VIP” access to Grand Theft Auto 6 to pressure hopeful players into sending cryptocurrency and, in some cases, hundreds of dollars.
A polished impersonation scam is using the pull of Grand Theft Auto VI to push victims toward cryptocurrency payments for access that never arrives.
A new Windows malware family is reported to spread through USB devices and use Tor, while altering wallet addresses to steal cryptocurrency.
A deceptive trust layer is being abused to make a crypto clipper look safer than it is, turning stars, reviews, and clipboard swaps into a quiet route to theft.
A malicious dependency found in more than 140 Mastra packages shows how a software supply-chain incident can move from build tools to browser-facing cryptocurrency surfaces.
A newly spotted lightweight backdoor combines removable-media spread with cryptocurrency theft, showing how compact malware can still punch through modern defenses.