Don Jes

191 posts

Don Jes

Don Jes

@DonJes666

Katılım Kasım 2024
135 Takip Edilen29 Takipçiler
Unstoppable | Private Wallet
Unstoppable | Private Wallet@unstoppablebyhs·
18,500 People Thought Buying Gift Cards Made Them Anonymous On March 1, Bitrefill (a major gift card provider) was hacked by North Korea's Lazarus Group. 18,500 user purchase records exposed: - what they bought, - when and with what crypto. - email addresses - IP addresses - in some cases, names were leaked as well It may look like gift cards give you some anonymity but in reality you're just passing your data from one provider to another.
Bitrefill@bitrefill

March 1st incident report On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation - including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) - we find many similarities between this attack and past cyberattacks by the DPRK Lazarus / Bluenoroff group against other companies in the crypto industries. The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated. That credential provided access to a snapshot containing production secrets. From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets. We first detected the incident after noticing suspicious purchasing patterns with certain suppliers. We realized that our gift card stock and supply lines were being exploited. At the same time we found some of our hot wallets being drained and funds transferred to attacker-controlled wallets. The moment we identified the breach, we took all of our systems offline as part of our containment response. Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial. Since the incident, our team has been working closely with top industry security researchers, incident response specialists, on-chain analysts and law enforcement to understand what happened and how we can prevent it from happening again. A sincere thank you to @zeroshadow_io, @SEAL_Org, @RecoverisTeam and @fearsoff for their rapid response and support throughout this ordeal. What about your data Based on our investigation and our logs we don’t have reason to think that customer data was the target of this breach. There is no evidence that they extracted our entire database, only that the attackers ran a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory. Bitrefill was designed to store very little personal data. We are a store, not a crypto service provider. We don’t require mandatory KYC. When a customer chooses to verify their account - e.g. to access higher purchasing tiers or certain products - that data is kept exclusively with our external KYC provider, with no backups in our system. Still, based on database logs, we know that a subset of purchase records was accessed and we want to be transparent about that. Around 18,500 purchase records were accessed by the attackers. Those records contained limited customer information, such as email addresses, crypto payment address, and metadata including IP address. For approximately 1,000 purchases, specific products required customers to provide a name. That information is encrypted in our database. However, since the attackers may have gotten access to the encryption keys, we are treating this data as potentially accessed. Customers in this category have already been notified directly by email. At this time, based on the information currently available, we do not believe customers need to take specific action. As a precaution, we recommend remaining cautious of any unexpected communications related to Bitrefill or crypto. If this assessment changes, we will of course immediately inform those affected. What we are doing We have already significantly improved our cybersecurity practices, but vow to continue to draw learnings from this experience to make sure user and company balances and data remain maximally safe. Specifically we’re: -Continuing thorough cybersecurity reviews and pentests with multiple external experts and implementing recommendations; -Further tightening internal access controls; -Further improving logging and monitoring for faster detection and more effective response; and -Continuing to refine and test our incident response procedures and automated shutdown procedures. The bottom line Getting hit by a sophisticated attack sucks (a lot). We’ve been in business for over 10 years and it’s the first time we’ve been hit this hard. But we survived. Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital. Almost everything is back to normal: payments, stock, accounts. Sales volumes are also back to normal, and we are eternally thankful to our customers for your continued confidence in us. We will continue to do our best to continue deserving your trust. Thank you!

English
14
17
103
12.9K
Don Jes
Don Jes@DonJes666·
@unstoppablebyhs @unusual_whales Stop commenting and check your support emails. Been trying to get in contact all day. Why hasn’t my transaction arrived when it says completed?!!
English
1
0
0
37
unusual_whales
unusual_whales@unusual_whales·
Meta is offering top executives stock options for the first time since its 2012 IPO, per Bloomberg
English
113
41
1.1K
202.1K
Don Jes
Don Jes@DonJes666·
@vikrantnyc @cakewallet Hi VIK. Do you have any contact with Unstoppable Wallet. I made a swap with them. It says completed but has nothing yet arrived! Any help would be greatly appreciated. Was XMR-USDT
English
11
0
5
79
Don Jes
Don Jes@DonJes666·
@unstoppablebyhs PLEASE CHECK YOUR DMS. SWAP SAYS COMPLETED NOTHING ARRIVED. IS THIS A SCAM ?
English
1
0
1
68
Don Jes
Don Jes@DonJes666·
@unstoppablebyhs Hi my swap says completed but nothing has arrived. How do I solve this ?
English
8
0
2
84
Ran Neuner
Ran Neuner@cryptomanran·
WE FINALLY KNOW WHY THE MARKET CRASHED ON 10 OCTOBER AND WHY IT JUST CANT BOUNCE! We never really understood why the big crypto crash started on October 10th and why we couldn't even get a single meaningful bounce! Today the answer seem simple! Let me break it down. 1. DAT's like MSTR, BMNR and others have been one of 2 big buyers that powered this cycle. 2. The DAT game is simple, you need to be the biggest so that you get into the big indices and when you do, passive index trackers are forced to buy large amounts of your stock. As they do you get bigger and get added to more indices, and so the cycle perpetuates. 3. On EXACTLY 10th October, MSCI , the world's 2nd biggest Index company published the below. They are questioning whether companies that hold crypto assets as their core business, should be considered as "companies" or "funds". 4. If they are "funds" they are not included in passive indexing. why, because this creates a circular loop. The fund buys assets , gets bigger and then is included in more indices and buys more assets. 5. The expected ruling will be announced on 15 January 2026 and if this does pass, the companies like MSTR will be automatically removed from all indices. 6. If this happens it would mean that all the pension funds, normal funds and all other passive index holders would dump their MSTR automatically. 7. It would also mean that going forward they would never be included and as such , one of the big reasons why they actually exist would disappear. 8 . Since DATs have been powering this cycle and have been most the buying pressure, the smart money saw this immediately after the 10TH of October announcement and positioned accordingly. 9. The 10TH of October wasn't a coincidence after all - It was smart money seeing a big risk to crypto and the current market structure. 10. The market will probably continue to dum until around the end of December and if the announcement is negative, we will get a huge dump in preparation for the removal from the indices. 11. On the other hand , if it is positive , the bull market is back!! I broke this down on a 10 minute video this morning and I will leave a link in the next tweet! If you enjoyed this analysis, please retweet and follow this account!
Ran Neuner tweet media
English
1K
2K
10.7K
2.3M
Mr Horrible
Mr Horrible@RickSky1967·
@TateTheTalisman @pepemoonboy An idiot that does not know how to properly invest money and will be flat broke within 10 years Depreciating liabilities are not investments The smartest car purchase you made was your Lada
English
1
0
1
72
PepeMoonBoy
PepeMoonBoy@pepemoonboy·
BMW’s are athletic rich Mercedes are swaggy rich Porsche’s are country club rich Maserati’s are fake rich Ferrari’s are entrepreneur rich Lamborghini’s are 25 year old streamer rich Bentley’s are old money rich Rolls Royce’s are trust fund baby rich Bugatti’s are pro athlete rich
English
764
477
9.7K
1.2M
Don Jes
Don Jes@DonJes666·
@trwapp_ Talking waffle driving in dubai on weekends is less traffic
English
0
0
0
33
Prime Tate
Prime Tate@primetateHQ·
Andrew Tate’s brutal rant on why weekends are for poor people:
English
21
38
312
12.6K
Andrew Tate
Andrew Tate@Cobratate·
@RAILGUN_Project The only real privacy solution. Anyone whos been through the shit I have, will already be using it.
English
57
30
718
67.6K
RAILGUN - Private Ethereum DeFi
RAILGUN - Private Ethereum DeFi@RAILGUN_Project·
Even if you hold stablecoins or tokens on a public ledger, you as a RAILGUN user, do not have to give up your own personal data. RAILGUN makes most ERC-20s shieldable, a power up that's particularly effective when the rest of the ledger is public.
English
18
21
340
63K
mrpatrickschmitt
mrpatrickschmitt@mr_pschmitt·
Being in this market since 2018 I have seen so many Meta`s, Narratives, Tech and memes so I think the Privacy Token meta is here to stay and we might even see $ZEC and $DASH in the Top 10 soon. My Price Prediction for my Top 4: $ZEC $3,000 - $5,000 $DASH $1,500 - $2,500 $ZEN $200 - 4600 $ZERA $1 - $3 Just my thoughts and ofc no guarantee but imo very conservative compared to predictions from the big players.
English
104
65
502
157.8K
Don Jes
Don Jes@DonJes666·
@asherdipps Just get apple care and order a new one
English
0
0
0
129
Asher
Asher@asherdipps·
lol screw aluminum
Asher tweet mediaAsher tweet media
English
308
100
4.4K
1.2M
Connor Humm
Connor Humm@TikiTakaConnor·
🎥 Ethan Nwaneri’s goal against Brighton for Arsenal - That Merino back heel was special. 🤩
English
4
140
2.7K
70.6K
Don Jes
Don Jes@DonJes666·
@SoftFuder By the end of the day. What’s that really mean though ?
English
0
0
0
10
顺丰 🛡️
顺丰 🛡️@SoftFuder·
$ZEC will flip $XMR by end of the week
English
1
0
1
190
Don Jes retweetledi
Iggy
Iggy@iggymaz·
@CFC_Janty Top 4 is not for everyone
Iggy tweet media
English
24
27
978
20.8K
Don Jes
Don Jes@DonJes666·
@xTKcrypto XMR been banned for years doesn’t bother us
English
1
0
16
401
TK🫧
TK🫧@xTKcrypto·
EU 🇪🇺 set to ban privacy coins including $XMR, $ZEC, and $DASH by 2026 as part of tightening crypto regulations. Anonymous transactions under scrutiny as regulators crack down on potential money laundering vectors. Significant implications for privacy-focused cryptocurrencies ahead. #Crypto #Regulation #Europe
TK🫧 tweet media
English
74
31
151
40.1K