Hackers Now Steal DeFi Keys Before Code Ships
A new malware campaign hits crypto developers upstream, lifting GitHub tokens, SSH keys, and wallets so attackers own the build before a protocol ever goes live.
99 stories mentioning it. Newest first.
A new malware campaign hits crypto developers upstream, lifting GitHub tokens, SSH keys, and wallets so attackers own the build before a protocol ever goes live.
Most crypto phishing attacks don't hack code, they trick you into signing a transaction. Here is the full kill chain, from the fake link to the drained wallet.
Michael Coates, ex-Twitter and Mozilla security lead, says attackers are moving off smart contracts and onto people, with full spoofed voice calls as the near-term threat.
Smart-contract exploits keep grabbing headlines, but the bulk of stolen funds trace back to compromised keys and operational gaps, a structural risk MPC and account abstraction are now trying to…
Most stolen crypto starts with a sloppy wallet setup. Here is the step-by-step method that closes the five holes phishers actually use.
From Mt. Gox to FTX, Ronin to Bybit, the largest crypto hacks have shaped how the industry thinks about custody, code, and trust. Here is the story of each one and the lesson it left behind.
A 594 BTC hardware-wallet drain, three Fed hawks, and an ETF rebound driven almost entirely by BlackRock. The bid is thinner than the tape suggests.
Bridges remain the single largest hack surface in crypto. A 7-point checklist covering audits, finality, TVL, and exit windows helps separate safe bridges from the next exploit.
A SIM-swap lets an attacker hijack your phone number, beat SMS 2FA, and drain your exchange account. Here is how the attack works and how to lock it down in an afternoon.
A 2023 Ledger library breach drained wallets via a single malicious update. Here is how supply chain attacks actually compromise crypto wallets, and why they are so hard to defend against.
Four hack reports, ETF outflows, and a treasury dump crowd around BTC, while one Trump-era verdict quietly carries the day's only bullish narrative.
A clipboard hijacker silently rewrites a copied wallet address in milliseconds. Copying BTC or ETH to a scammer has cost users millions. Here is how it works and the one defense that actually holds.
Bridges hold billions in locked tokens, run on upgrade-resistant code, and guard them with validator sets smaller than the chains they connect — a perfect target.
A single malicious extension update can drain your wallet. Here is how dependency-confusion, typosquatting, and rogue updates actually unfold, and the defensive habits that blunt them.
Most lost crypto starts with one copied address. A 30-second checklist of full-string checks, hardware confirmation, and a tiny test send can stop address-poisoning and clipboard malware in their tracks.
Smart accounts shift crypto attack surfaces; they don't shrink them. Here is how ERC-4337 changes real risk for ETH users and developers.
Address poisoning sends a $0 dust transfer from a look-alike address, then waits for you to copy-paste it. Billions of transactions later, users keep losing millions.
Crypto is unforgiving. A single mistake can wipe out years of savings. This 15-item checklist covers the practices that quietly separate people who keep their crypto from people who do not.
A meme-coin governance heist drains $20M the same hour Washington declares it is taking over crypto. The crowd is split, and that split is the signal.
Wallet drainer kits turned crypto phishing into a $500M+ service industry. Here is how drainer-as-a-service works, who runs it, and why it keeps growing.