EvilTokens phishing ring dismantled by Coinbase and Microsoft
On-chain forensics traced $1.1M in months, but the underlying device-code auth vulnerability that powered EvilTokens is already being groomed for Gmail and Okta.
Every Zipp story tagged #AISecurity, newest first.
On-chain forensics traced $1.1M in months, but the underlying device-code auth vulnerability that powered EvilTokens is already being groomed for Gmail and Okta.
The episode highlights the dual-use risk of frontier AI and raises pressure on labs to harden models against cyber abuse.
The Ethereum co-founder argues AI that can prove theorems can also formally verify software security, and that staying in crypto is itself a bet on defenders winning the AI arms race.
Buterin's counter to Liron Shapiro's 50% crash call isn't a quote, it's his balance sheet. With roughly nine-tenths of his wealth already in crypto, the Ethereum co-founder is effectively running the…
Vitalik's defense lands as AI-driven hash-attack scenarios move from white-paper speculation to broader investor concern, countering a thesis that calls for a 50%+ BTC drawdown.
Operators can't inspect the threat yet, so signed binaries carry the trust load. Cautious nodes going offline could thin Lightning routing capacity until CLN lifts the embargo.
The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.
The figures cannot be independently verified, but they are the first concrete metrics a major venue has put on a claim bitcoin developers have been making all month.
Security-driven wallet migrations can mimic selling pressure, making bearish on-chain readings a poor standalone signal while the AI findings await validation.
The founding argument is a Hugging Face breach in which closed AI tools reportedly blocked the forensic response; the alliance open-sources the stack defenders say they need to actually inspect…
The consortium signals that frontier-model providers, chip vendors, and cloud platforms now treat open-source AI security as a shared engineering problem worth coordinating on, not competing over.
The incident shows a capable model with guardrails off can chain unknown flaws, stolen credentials, and production-side weaknesses end-to-end, which is exactly the shape a serious crypto exploit…
The Foundation is publishing a security report that treats AI as an audit accelerant, not a replacement for formal verification and human reviewers.
The headline is the bug itself, but the takeaway from the Foundation's Protocol Security Team is bigger: AI-driven triage is now doing the work human reviewers used to absorb manually.
If basic smart contract reviews drop from weeks-long engagements to on-demand calls, the standard of care shifts too — and skipping one could read as negligence.
A single auditor report used to certify a DeFi protocol. As AI gets sharper at finding bugs, multi-agent systems that cross-check code are becoming the new floor — not a nice-to-have.
Buterin's pitch lands as the industry grapples with smart-contract exploit losses running into the billions — automated proof of correctness is the part AI may actually get right.