Bits of Gold Breach Hits 200,000 Users via Third-Party Vendor
Funds stayed safe, but national IDs and bank details now in circulation expose 200,000 customers to follow-on phishing, and the breach lands in a wave that already hit SafePal and Trezor.
Every Zipp story tagged #CryptoSecurity, newest first.
Funds stayed safe, but national IDs and bank details now in circulation expose 200,000 customers to follow-on phishing, and the breach lands in a wave that already hit SafePal and Trezor.
A data breach that exposes 250,000 users' personal data does not read like a financial loss; it reads like a personal-security event, and the regulatory exposure that follows is now structural, not…
The case puts identity checks at the center of crypto security, where fundraising, recruiting and partnerships can become attack surfaces.
The DPRK has spent years turning remote crypto hiring into a sanctions-evasion pipeline, and documenting how the bait works is one of the only public defences the rest of the industry has.
Rising bug-bounty activity has not eliminated exploit risk, while Immunefi says its audit competitions found more serious bugs per engagement than tier-1 audits.
AI-assisted financial lures raise the security risk for crypto firms, fintech providers and investors, making phishing resilience part of market infrastructure.
The warning shifts the custody debate from storage location to the controls protecting and using private keys.
The market backdrop remains cautious, with BTC dominance at 56.8%, an Altcoin Index score of 45/100 and Fear & Greed at 25, or Extreme Fear.
Galaxy Research has traced 1,596 BTC stolen across three confirmed attack waves, with a suspected fourth wave that would push total losses to roughly 2,000 BTC.
Krishna's timeline pulls commercial quantum computing inside the half-decade window, with Alphabet, IonQ and Rigetti in the race and crypto watching the long-term encryption threat.
DPRK alone siphoned nearly $600M. The headline number is bad, but the forward-looking warning on AI-driven exploits is the piece security teams and on-chain risk teams should be reading.
The founding argument is a Hugging Face breach in which closed AI tools reportedly blocked the forensic response; the alliance open-sources the stack defenders say they need to actually inspect…
Cross-platform spyware hiding in official app stores used OCR to lift wallet seed phrases straight out of users' camera rolls, with one Android app clearing 10K downloads before removal.
Criminals are targeting the people behind private keys, making personal safety and access controls central to crypto risk management.
The blast radius is upstream of any exploit: a compromised developer laptop at a subcontractor can inject tainted code into a wallet used by tens of millions before the next release ships.
The campaign abuses developer trust, posing as legitimate projects to slip infostealers past crypto investors who download what looks like routine open-source tooling.
Yi He's figure is a marketing line and an operations flex at once: roughly one in three attempted user-error transfers on the world's largest exchange now gets recovered instead of lost to the void.
Physical wrench attacks on crypto holders in Southeast Asia keep recurring, and each one reminds holders that on-chain security does nothing if the keys can be pried out of a person.
French Interior Minister Nuñez reported a sharp year-on-year jump from 45 cases in 2025, with around 200 arrests so far as emergency security measures for crypto figures begin to bite.
The Humanity Protocol exploit carried roughly $31M of that total, by itself accounting for over a third of June's on-chain theft across 40 incidents.