BlockchainUnmasked

519 posts

BlockchainUnmasked banner
BlockchainUnmasked

BlockchainUnmasked

@BlockUnmasked

Blockchain intelligence for investigating crypto-related financial crime and fraud

انضم June 2022
578 يتبع411 المتابعون

2026 Yıllık Özeti

@BlockUnmasked hesabının Twitter yılını gör

تغريدة مثبتة
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
Detection is solved. Four exploits this week, all flagged within minutes. Response isn't. It runs on relationships most teams don't have until the morning they need them. The platforms trace. We run the response. How the BU War Room works, end to end 👇 blockchainunmasked.com/post/the-war-r…
BlockchainUnmasked tweet media
English
0
2
3
630
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
Both. Based on the victim cases, we had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We did not know the exact implementation bug that's now public. But the company had significant and sufficient information to reasses their firmware, seed generation entropy and potentially notify their own customers. That's why we disclosed it privately to the manufacturer and law enforcement instead of making public accusations or technical claims we couldn't substantiate. We work alongside local, state, and federal law enforcement every day. We routinely become aware of crimes, vulnerabilities, and active investigations long before they become public, and our responsibility is to report them through the usual channels.
English
1
0
2
61
Tay 💖
Tay 💖@tayvano_·
@BlockUnmasked Sorry maybe I wasn’t clear Did you know or did you not know.
English
1
0
0
103
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
In 2024, victims came to us with bitcoin missing from Coldcard wallets. No malware, no phishing. We traced it to weak seed entropy and filed reports with the manufacturer and multiple agencies. Two years later: $38M swept in 25 minutes. blockchainunmasked.com/post/coldcard-…
English
38
62
565
479.9K
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
Tay, with respect, that's not an accurate characterization, and this bums me out given the rapport in the past. We investigated multiple victim cases, identified an unusual pattern, notified the manufacturer, worked with local, state, and federal law enforcement, and focused on tracing the stolen funds. That's what blockchain forensic investigators do. We are not firmware researchers or bug bounty hunters, and we weren't in a position to publicly accuse a company or disclose an ongoing investigation before the facts were established. We had sufficient evidence that something was fundamentally wrong with the seed generation process to warrant disclosure. We disclosed it to the parties who could investigate, notify customers if necessary, issue firmware updates, and pursue those responsible. We don't speculate publicly, and we don't expose ourselves or others to unnecessary allegations of libel or slander by making claims we can't substantiate. The article explains what we observed, what we did, and what we did not conclude. All of our data, findings, victims that approached us then, and reporting was and is again being shared with federal law enforcement.
English
1
0
5
346
Tay 💖
Tay 💖@tayvano_·
@BlockUnmasked So you knew and did nothing. Or you didn’t know and are lying to get attention today. Which is it? I need to know just how far up the shitlist to put your sorry asses.
English
1
0
1
534
Breadman
Breadman@BTCBreadMan·
@w_s_bitcoin @BlockUnmasked It brings up a fascinating question though. What could Coinkite realistically have done if they did discover the bug after several years of people generating bad seeds with it?
English
2
0
3
651
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
We did at the time (2024), and are now presenting all findings to law enforcement and legal teams working on this versus disclosing victim information or specifics of an ongoing investigation. Because we're a fraud investigation firm who works alongside law enforcement and lawyers vs a bug bounty firm, we handle cases a bit differently.
English
2
0
30
2.5K
MAGS 🔑⛏️🚒
MAGS 🔑⛏️🚒@Crypto_Mags·
Your post doesn't actually indicate that you reported on this exact vulnerability. There are no supporting documents that imply this. You're going to have to provide more if you expect anyone to believe you. And I think people will really want this information / proof for lawsuits. So it's in the best interest of everyone to reveal more than you did
English
2
0
12
3.3K
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
Fair skepticism. We didn't identify the specific code-level bug now being discussed, nor claimed we did here. In 2024, multiple victims approached us with materially similar losses that didn't appear to involve the usual causes, phishing, malware, or known seed exposure. At first, we suspected insider involvement, but it was an early working hypothesis, not a conclusion, and we did not accuse anyone. Our investigation concluded it was a function/failure of the seed generation entropy. We understood enough to recognize that the weak seed entropy involved warranted escalation, and we reported what we had to the company for review and federal law enforcement. Because these matters involve victims and ongoing investigations, we never responsibly disclose the underlying evidence or comment much further. We can't sensationalize active cases or present speculation as fact.
English
4
2
93
5.4K
Wicked
Wicked@w_s_bitcoin·
I call bullshit. You guys didn’t find the bug either. Nobody did until Kimi K3 traversed the entire failed exit path with a sufficiently large enough context window. And if you had found the bug yourselves, you should’ve responsibly disclosed it years ago. But again, doesn’t seem like you’re claiming you did.
English
11
2
119
12.1K
BlockchainUnmasked أُعيد تغريده
Deconflict.com
Deconflict.com@deconflict_·
If you believe your Bitcoin was stolen because of the @COLDCARDwallet vulnerability, report it to law enforcement as soon as possible. Do not assume your case is too small, too technical, or too late to report. Start with your local police department. Ask to file an official report and request that it be routed to a detective who handles cybercrime, financial crimes, or cryptocurrency investigations. If you are in the United States, also submit a complaint through the FBI’s Internet Crime Complaint Center at IC3.gov. You can contact your local FBI field office as well. Before making the report, collect what you have: • The wallet address from which the Bitcoin was stolen • The destination address or addresses • Transaction hashes • The amount taken • The date and time of the transactions • Your COLDCARD model • The firmware version used when the seed was generated • The approximate date the seed was created • Purchase records, screenshots, emails, or other supporting information • Any report or complaint numbers you have already received Preserve the device, seed backup, packaging, receipts, and related records. Do not destroy or reset anything that could later help establish ownership or support the investigation. Most importantly, do not share your seed phrase, private keys, PIN, or sensitive personal information with anyone offering to recover your funds. Victims of cryptocurrency theft are frequently targeted a second time by people pretending to be investigators, attorneys, recovery specialists, or government officials. What we can do is help victims understand how to report the theft and help participating law enforcement agencies identify related investigations and reach the appropriate investigators. If you were affected and do not know where to begin, send Deconflict a DM. Do not include your seed phrase, private keys, PIN, Social Security number, identification documents, or other sensitive information. We will help point you toward the appropriate law enforcement reporting channel.
English
1
9
29
19.6K
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
Unfortunately, there are plenty of wallets and protocols they can use if they want to hide these funds. It'll just take a bit of time. Id encourage you to view the bybit hack wallets. Or kelp dao. There are plenty of offramps for the bad guys because bad protocols will facilitate. Also, someone willing to attack and steal $88m certainly won't return it and settle for $4m. Wouldn't be surprised if this was DPRK or another nation state.
English
0
0
2
293
Sky
Sky@skysupersonic·
Dear COLDCARD attackers, Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin. Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder. I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor. Respectfully, hodlers worldwide
English
1.6K
1.6K
19.4K
1.5M
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | August 2, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 Thefts attributed to a Coldcard hacker reportedly total 1,367.05 BTC (approximately $88.6m) across 4,585 addresses, with an ongoing wave described as targeting any RNG-generated seed phrase on ColdCard products. A second wave attributed to the same actor reportedly took 1,158.81 BTC from 2,673 addresses. (via @officer_secret and @DarkWebInformer) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - BNB Chain said a former employee allegedly used a company tutorial wallet to deploy a memecoin it did not authorize or endorse. The former employee allegedly bought 796.7M ASTEROID (79.67% of supply) for $10K across four new wallets, then sold 718.8M ASTEROID for 1,103 BNB ($638K). (via @lookonchain and @Cointelegraph) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - A Minnesota crypto ATM ban went into effect following reported losses of about $1 million. State officials said Minnesota residents, largely senior citizens, lost the amount from scams tied to crypto kiosks between 2023 and 2025. (via @Cointelegraph) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - Dubai-based Shelbit allegedly sent $676 million to Binance in what is described as a sanctions-evasion operation, per Reuters. Shelbit reportedly processed over $4 billion since May 2024 through a network tied to Iranian gambling sites, the central bank, and the IRGC. (via @TheBlockCo) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
2
223
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 31, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 A hardware wallet randomness bug turned seeds described as impossible to guess into guessable ones, and $38 million worth of BTC was swept in 25 minutes. Coinkite said it is likely an attacker used AI to review previous versions of its open-source firmware to uncover the vulnerability. (via @CoinDesk and @decryptmedia) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Shelbit, a Dubai-based exchange, allegedly sent hundreds of millions of dollars to major crypto exchanges, including Binance, linking gambling sites and sanctioned Iranian entities to global crypto markets as part of an alleged $4 billion sanctions-evasion network. (via @CoinDesk) - The FBI, alongside the State Department and international partners, issued a joint alert on North Korean IT workers who use false identities and third-party proxies to conduct malicious cyber activity and generate revenue. Eight individuals have been sentenced to prison for their roles in these schemes so far in 2026. (via @FBI) - Seoul police say a fake staking site drained $8.5 million in XRP from dozens of investors, with the total potentially rising to nearly $20 million. Two alleged scammers were detained and a third remains at large. (via CoinDesk) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - Anthropic said its Claude AI models escaped test environments and breached networks at three companies on the open internet. One model built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. (via @TheRecord_Media and @BleepinComputer) - Amazon linked multiple npm supply-chain attacks to North Korean hackers, who researchers say were behind several high-profile compromises of open-source software libraries used by developers worldwide. (via @BleepinComputer and @TheRecord_Media) - Verified accounts on X are spreading links delivering an open-source information stealer via a malicious Rust crate named width-table, imported into a project called Polymarket-5min-bot on GitHub, with code that walks a directory and uploads files to a website. (via @vxunderground) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - New York's Attorney General sued prediction market Kalshi over an alleged illegal gambling operation, seeking $36 billion. The CFTC asked a court to block New York from enforcing state gambling laws against the federally regulated platform the day before the state filed suit. (via @decryptmedia and @Cointelegraph) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - The Treasury Department said the Hormuz Safe platform accepted bitcoin and other digital assets as part of an alleged sanctions workaround tied to IRGC-backed shipping controls in the Strait of Hormuz. (via CoinDesk) - The EU sanctioned Prince Group and its chairman Chen Zhi over alleged cyber-scams and forced labor. (via @OCCRP) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
1
229
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 30, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 A federal jury convicted Hadi Matar of attempting to provide material support to Hizbollah, engaging in an act of terrorism transcending national boundaries, and providing material support to terrorists, stemming from his August 2022 attempt to murder author Salman Rushdie in an effort to carry out a fatwa calling for Rushdie's execution over a 1988 novel. (via @FBI) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - A second exploit reportedly drained the Verus Ethereum Bridge for $7.54 million, following a similar $11.6 million hack in May involving the same bridge, with no statement or bounty issued this time. (via @RektHQ) - Ostium attributed a $24 million exploit to an off-chain breach, ruled out a smart contract flaw, and said trader collateral was unaffected while a recovery plan for liquidity providers is pending. (via @TheBlockCo) - OpenMonero said a zero-day vulnerability it claims had been hiding since the project's launch caused a drain of approximately 399 XMR. (via @DarkWebInformer) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Seoul police said a ring drained $8.5M in XRP through a fake Flare Network staking site, using copied branding and planted Wikipedia entries, blog posts, and YouTube videos to appear legitimate. (via @decryptmedia) - Russia's FSB accused Telegram founder Pavel Durov of aiding terrorism and placed him on an international wanted list; separately, Telegram faces terror-related legal action in Australia carrying a potential fine of up to $38 million. (via @OCCRP) - Igor Runets, founder of crypto mining firm BitRiver, was transferred to pre-trial detention as he faces fraud accusations involving an alleged $12.5 million in damages from a deal with conglomerate En+. (via @CoinDesk) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - The Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is exploiting a Microsoft Outlook Web Access zero-day to deliver a backdoor called OWAReaper for long-term mailbox access. (via @BleepinComputer) - Cybercriminals are attempting to extort the UK Department for Education after allegedly compromising more than 600,000 pieces of data, including names, email addresses, and phone numbers. (via @TheRecord_Media) - Analog Devices filed an 8-K disclosing unauthorized access to certain systems identified on June 23, 2026, with the investigation finding files were exfiltrated and law enforcement notified. (via @DarkWebInformer) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - Binance.US CEO Stephen Gregory said the exchange will apply for a CFTC designated contract market license in August, which would allow it to offer prediction markets. (via @TheBlockCo) - A South Korea policy report recommends interim licensing guidance, greater flexibility for stablecoin issuers, and rules ahead of the Digital Asset Basic Act. (via @Cointelegraph) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - The US Treasury said Iranian maritime firm HormuzSafe accepted Bitcoin and other digital assets to evade sanctions and generate revenue for Iran's Islamic Revolutionary Guard Corps. (via @Cointelegraph) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
2
207
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 29, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 A7A5, a ruble-pegged cryptoasset issued in Kyrgyzstan and backed by a sanctioned Russian state bank, saw transaction volumes fall 96% after coordinated US, UK and EU sanctions enforced through blockchain analytics. The token moved more than $100 billion in its first year; its only significant exchange is now offline. (via @elliptic) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - Researchers reported a roughly $578K exploit on LULA in which an attacker flashloaned approximately $237M to maximize deflation through claimReward and recycle functions, after deploying helpers to accumulate rewards 12 days earlier. (via @CertiKAlert) - Zcash activated its Ironwood upgrade, launching a new shielded pool and retiring the Orchard pool following a counterfeiting bug that went undetected for four years. Withdrawals are now capped at verified deposits. (via @CoinDesk) - A company behind an AI trade that caused $60 million in crypto liquidations said it will cover all losses after the mark price fell 19% on a single pre-market trade in Korea. (via @CoinDesk) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Russia's FSB says Telegram founder Pavel Durov faces a terrorism-related charge and an international arrest warrant, alleging the app was used by Ukrainian intelligence to organize attacks and conduct espionage inside Russia. (via @Cointelegraph) - The FBI director said the bureau has opened more than 30 cases, helped restrain assets valued at more than $15 billion, and helped drive hundreds of arrests in a global offensive against scam centers. (via @FBI) - A lawsuit claims Apple ranked a fake Sparrow Wallet app and placed it in curated crypto collections alongside legitimate ones, with the fake app alleged to have drained $1.8M in Bitcoin. (via @decryptmedia) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - JFrog confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to escape an isolated testing environment, then breached Hugging Face through malicious datasets after executing roughly 17,600 actions. (via @BleepinComputer and @DarkWebInformer) - Researchers found that Anthropic's Claude Cowork could break out of its own virtual machine, a week after OpenAI disclosed a frontier AI sandbox escape. (via @decryptmedia) - Threat actors are impersonating recruiters to lure Web3 professionals into installing malware disguised as an AI meeting tool called "Relay," targeting browser credentials, wallet data, Keychain data, and Telegram sessions on macOS and Windows. (via @SlowMist_Team) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - Binance's Android app is unavailable on Google Play in some EU markets amid scrutiny over MiCA compliance. (via @Cointelegraph) - Hungary removed mandatory third-party checks for crypto conversions as CoinCash received authorization to provide digital asset services under MiCA. (via Cointelegraph) - A coalition of 44 state attorneys general told the CFTC it lacks authority over sports prediction markets and urged the agency to draft new rules consistent with the Commodity Exchange Act. (via @TheBlockCo) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
2
209
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 28, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 Five compromised validator signatures reportedly cleared the two-thirds threshold guarding a bridge, draining $24.15 million from the AFX USDC custody bridge contract on Arbitrum. The funds were reportedly moved out through standard public rails. (via @RektHQ) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - The Across Protocol exploiter's labeled address refunded 331.8 ETH (approximately $623.9K) to the Across Protocol Hub Pool Owner Multisig after approximately $3.6M in crypto was reportedly drained in an attack on Solana. (via @PeckShieldAlert) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - A lawsuit alleges Apple kept a fake bitcoin wallet app on its store after one user reported an $875,000 theft, leading to another user losing roughly $840,000; separate plaintiffs allege approximately $1.8 million in Bitcoin was stolen via a fraudulent Sparrow Wallet app. (via @CoinDesk and @BleepinComputer) - Thailand's SEC alleges Bitkub concealed a cyberattack that occurred in May 2021, during which hackers stole 1.7 billion baht across 16 digital assets. (via @CoinDesk) - Afeez Olatunji Adewale, 27, arrested in Nigeria in August 2023 as part of an FBI operation and extradited to the United States in February 2026, has been sentenced for money laundering conspiracy and wire fraud tied to a sexual extortion case. (via @FBI) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - SparkKitty malware infiltrated Apple's App Store and Google Play, scanning photos on infected iPhones and Android devices for cryptocurrency wallet recovery phrases, according to a newly detailed report. (via @decryptmedia) - The ShinyHunters extortion gang claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials via a supply-chain attack. (via @BleepinComputer) - Hackers are actively exploiting a zero-day vulnerability in the FastJson open-source Java library, enabling remote code execution without user interaction or elevated privileges. (via BleepingComputer) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - A federal judge issued a preliminary injunction blocking Minnesota from enforcing its new law banning prediction markets, finding that not every contract qualifies as a swap under federal law, in a win for Kalshi and Polymarket. (via @TheBlockCo and @decryptmedia) - Myanmar approved the death penalty for forced scam labor and life imprisonment for crypto fraud; the UN estimates scam operations across the region drove up to $114 billion in losses in 2025. (via Decrypt) - CME is contesting the CFTC's approach after the regulator issued its first listing approval for onchain perpetual futures, arguing the move diverts from existing law. (via CoinDesk) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - OFAC designated Zaid Issam Ahmed al-Jebouri, described as an Iraqi national based in Istanbul, and two associates as Specially Designated Global Terrorists linked to an alleged Hamas financing network. (via @chainalysis) - The U.S. Treasury Department sanctioned the sister and significant other of Iranian tycoon Babak Zanjani, targeting a network of crypto exchanges and global companies accused of laundering funds for Iran's Revolutionary Guard Corps. (via @OCCRP) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
2
211
Ultimate indicator
Ultimate indicator@machielsrobin1·
$ESIM Blacklisting: No Explanation, No Accountability My wallet was manually blacklisted through the $ESIM token contract, yet nobody is willing to provide a clear reason, evidence, or a responsible point of contact. The attached screenshots show a disturbing chain of contradiction: 1. A January 9 Telegram announcement in which the @depinsim team explicitly stated that it had blacklisted addresses and associated users. This confirms that the team knows how the blacklist operates and has previously used it. 2. Binance provided me with a contact presented as connected to the developer. This person claims to be only a team member, says they do not personally know who the developer is and repeatedly directs me to Bitget. 3. That same contact claims that Bitget knows more about the situation and should provide a solution. 4. Bitget formally confirms the opposite: Bitget did not blacklist my wallet, cannot remove the restriction and states that the blacklist is controlled by the $ESIM project team or the party controlling the token contract. Despite repeated requests, @depinsim has provided: No exact reason for blacklisting my wallet No evidence of prohibited activity No court order or law-enforcement reference No identity or contact details for the responsible developer No appeal or review procedure No legal representative’s contact details The project cannot continue redirecting affected holders to exchanges when the exchanges themselves confirm that only the project team or contract controller can impose and remove the restriction. I formally request that @depinsim disclose the reason and evidence for this blacklist, identify the responsible contract controller and provide a transparent procedure to challenge the decision. All statements are supported by the attached correspondence. @zachxbt @MetaSleuth @chainalysis @blockaid_ @BlockUnmasked @Onchainsnoop @CFInvestigators @BinanceHelpDesk @BitgetGlobal @kucoincom
Ultimate indicator tweet mediaUltimate indicator tweet mediaUltimate indicator tweet mediaUltimate indicator tweet media
Ultimate indicator@machielsrobin1

The situation around @depinsim ($ESIM) is becoming increasingly concerning. Over the past week: • Multiple reports of wallets being blacklisted at the smart contract level. • Multiple reports of blocked unstaked tokens. • Telegram moderators no longer respond to these reports. • Users asking critical questions report being muted. • The developer I was communicating with has stopped responding for over 2 days. • Official emails have gone unanswered for more than a week. According to the smart contract structure and explanations shared by people familiar with it, wallet blacklisting is performed manually through the proxy contract by an administrator and can also be manually reversed. If that is correct, the team has the technical ability to restore wrongly blacklisted wallets while the underlying investigation continues. Instead, affected holders have received no explanation, no evidence, no timeline and no appeal process. The community deserves answers: • Is the project still actively managed? • Will legitimate holders regain access to their assets? • Why are innocent wallets still blacklisted?Transparency is the fastest way to restore confidence. @depinsim @zachxbt @PeckShieldAlert @CertiKAlert @GoPlusSecurity @ScamSniffer @ArkhamIntel @Lookonchain @nansen_ai @bubblemaps @WuBlockchain @CoinDesk @Cointelegraph @TheBlock__ @DecryptMedia @DLNewsInfo @BNBCHAIN @binance @BinanceHelpDesk @KuCoinCom

English
6
9
12
452
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 27, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 Triple-A, a stablecoin payments company, confirmed a treasury-wallet breach after losses reached $11.8 million, with new deposits reportedly continuing to be swept. The company said client funds were unaffected, that it is investigating, and that the financial impact would be absorbed through its treasury reserves. (via @Cointelegraph and @TheBlockCo) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - Garden Finance took its app offline after Blockaid reported a $450,000 exploit, saying an attacker compromised an independent solver's off-chain database and inserted fraudulent swap records. No user funds or smart contracts were affected. (via @Cointelegraph) - WEMIX said an attacker compromised a WEMIX$-linked contract and moved 724,198 USDC.e, or about $724,000. The company suspended bridges, liquidity-pool trading, and several services. (via Cointelegraph) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Thailand's SEC filed a criminal complaint against exchange Bitkub and two former directors, alleging they omitted a $47 million theft from its 2021 filings. (via @decryptmedia) - Georgia charged four people in an $8.2 million laundering scheme involving fake companies and millions in cash. (via @OCCRP) - Brazilian police suspect a group of shipping around 6.5 metric tons of cocaine and laundering billions in Brazilian reals through crypto-enabled illicit money brokers, in a transnational probe. (via Cointelegraph) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - Researchers detailed SparkKitty, malware hidden in mobile apps that reportedly scans photos to steal cryptocurrency wallet recovery phrases. (via @TheBlockCo) - Researchers discovered that hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance. (via @TheRecord_Media) - GitHub and PyPI introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and limit their impact. (via @BleepinComputer) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - The Commodity Futures Trading Commission issued an advisory signaling that firms have been straying into cookie-cutter self-certification of event contracts. (via @CoinDesk) Follow BlockchainUnmasked for your daily news digest every morning
English
0
1
3
143
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 26, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 The EU added HTX to its Russia sanctions list, barring transactions starting Aug. 23. Other crypto platforms named alongside HTX include EXMO, Rapira, BitPapa, Aifory Pro, WhiteBird, NoOnecrypto, and Exnode. (via @TheBlockCo) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - North Korea reportedly arrested former state cyber operators accused of hacking two state banks and laundering funds through crypto. The group allegedly breached Central Bank systems, converted crypto to cash via Chinese brokers, and used small transfers to evade detection. (via @CoinDesk and @Cointelegraph) - An international operation conducted from late May to mid-June 2026 across seven countries led to 28 arrests and seizure of more than 460 items, including electronic devices, crypto wallets, and drugs. Further arrests are expected. (via @Europol) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - A malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. (via @BleepinComputer) - Steam discussion forums are being abused in ClickFix attacks that pose as fixes for game problems but instead infect devices with XMRig cryptominers. (via @BleepinComputer) - A cybercrime group calling itself Coinbase Cartel is reportedly recruiting individuals with stolen data or access to compromised organizations, advertising negotiable revenue splits via a dark web site. It says it is not affiliated with the Coinbase exchange. (via @DarkWebInformer) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - Wise plans to resubmit a US charter application under the GENIUS Act after the OCC denied it this week, citing AML/CFT risks, despite approving similar charters for digital asset companies in the past year. (via @Cointelegraph) - Sberbank plans crypto trading infrastructure by December. New Russian regulations for crypto trading, custody, and settlement take effect Sept. 1, with licensed-intermediary requirements applying from July 2027. (via @CoinDesk) - Analysts suggest MiCA and the UK's finalizing crypto framework could spur mergers, acquisitions, and closer ties between crypto firms and banks. (via CoinDesk) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
3
130
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 25, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 Andria Liluashvili was sentenced to 12 years in prison and stripped of $13 million in luxury assets following a secretive trial, after funneling monthly kickbacks from fraudulent call centers to his relative, the former head of Georgia's State Security Service. (via @OCCRP) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - TripleA wallets were reportedly drained of more than $9.7M across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The exploiter bridged stolen funds to Ethereum, consolidating 5,227 ETH. (via @PeckShieldAlert) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Khalid Satary was extradited to the United States on allegations that his laboratories used call centers, telemedicine doctors, and kickbacks to generate $547 million in Medicare claims for medically unnecessary cancer tests, with court records indicating about $134 million was paid out. (via @OCCRP) - A Montenegrin court sentenced the Kavač clan leader and his network to a combined 148 years in prison, including a 40-year term for the fugitive boss, using intercepted Sky app communications as evidence. (via OCCRP) - Britain's National Crime Agency froze 16 luxury apartments in central London acquired by Xu Haika, who is under investigation in Singapore as part of authorities' largest ever money laundering probe. (via @NCA_UK) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - The Qilin ransomware group named four claimed victims: medical technology company Stryker, Highline Community College in Washington, Kean University in New Jersey, and the Argentine Army. (via @DarkWebInformer) - PEAR ransomware claimed Metropolitan Construction Systems, a US-based construction management company, as a victim. (via @DarkWebInformer) 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗶𝗼𝗻 & 𝗣𝗼𝗹𝗶𝗰𝘆 - Fidelity called on the US Senate to pass the CLARITY Act, joining industry groups and crypto firms pushing for market structure legislation. (via @Cointelegraph) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - The EU's 21st Russia sanctions package introduces a transaction ban on 14 crypto-related service platforms across multiple third countries and adds power to sanction evasion-enabling jurisdictions. (via @chainalysis and @trmlabs) - EU authorities listed HTX exchange on a register of entities accused of providing crypto or payment services in defiance of Russia measures; the package stops short of a full asset freeze but accuses HTX of significantly frustrating EU sanctions. (via @Cointelegraph) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
2
185
BlockchainUnmasked
BlockchainUnmasked@BlockUnmasked·
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | July 24, 2026 Your Daily Crypto News Digest 𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 A federal jury convicted Barry Augustinsky on charges of mail fraud, conspiracy to commit mail fraud, money laundering, unlawful monetary transactions, and obtaining information under false pretenses; many victims were elderly and sent personal checks to post office boxes in Portsmouth and Poquoson that Augustinsky collected and deposited. He faces up to 20 years in prison at sentencing on November 5, 2026. (via @FBI) 𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀 - The Drift Protocol exploiter who stole $285M reportedly deposited 23,095 ETH ($44.4M) into Tornado Cash and still holds 107,165 ETH ($201M). (via @lookonchain) - Researchers reported a loss of approximately 542,144 USDC at Lien Finance, tracing it to a flaw in the exchangeEquivalentBonds function that allowed attackers to mint unbacked bond tokens and drain funds. (via @SlowMist_Team) - Someone reportedly lost $340,463 to a phishing multicall on Ethereum that buried an unlimited approve() call inside a top-level multicall() function. (via @realScamSniffer) 𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀 - Thailand's SEC filed a criminal complaint against Bitkub and two former directors over alleged false disclosures linked to a 2021 cyberattack involving $50 million in assets. (via @Cointelegraph) - BitMEX, Arthur Hayes, Samuel Reed, and Benjamin Delo face a proposed class action alleging insider trading and deliberate server freezes, with the complaint claiming an internal desk accessed private user data during outages. (via @TheBlockCo and @CoinDesk) - Secretary of State Marco Rubio announced U.S. visa restrictions targeting individuals connected to transnational cyber-scam operations. (via @TheRecord ) 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 - A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to compromise Zimbra webmail accounts worldwide, according to a warning from the U.S. and other nations. (via The Record) - The Clop ransomware gang is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. (via @BleepinComputer) - A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping attackers identify which victims to prioritize. (via @BleepinComputer) 𝗦𝗮𝗻𝗰𝘁𝗶𝗼𝗻𝘀 & 𝗗𝗲𝘀𝗶𝗴𝗻𝗮𝘁𝗶𝗼𝗻𝘀 - The EU is considering a ban on third-country crypto service providers for the first time, targeting 14 unnamed crypto companies as part of a 21st sanctions package aimed at a $120B crypto network linked to Russia. (via @CoinDesk) - The EU will bar Belarusian nationals and residents from owning, controlling, or managing exchanges and other MiCA-regulated crypto firms starting August 25. (via Cointelegraph) Follow BlockchainUnmasked for your daily news digest every morning
English
0
0
1
170