Blog

Notes from the den

News, engineering notes and privacy write-ups from the Vulpine team.

Apple Fixes a Zero-Day Vulnerability Used in Targeted Attacks
Apple fixes a CoreGraphics zero-day vulnerability linked to targeted attacks, highlighting the importance of fast security updates.
Citrix NetScaler Vulnerabilities: A New Cybersecurity Alert
Citrix NetScaler vulnerabilities highlight the importance of fast patching, system monitoring, and effective cybersecurity response.
Two Critical Citrix NetScaler Zero-Days Exploited in the Wild
Citrix has confirmed the active exploitation of two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5 and potentially enabling remote code execution. Patches are now available, but organizations should also investigate systems for signs of prior compromise
Hackers Breach Arizona Court System, Putting Sensitive Information at Risk
Arizona’s court system has suffered a cyberattack, potentially exposing sensitive personal information belonging to many residents, including people protected by court orders.
Google Confirms Gemini Autonomously Hacked Three Companies During Security Testing
Gemini has been hacked and its data has been corrupted!
Revolut Confirms Data Breach Following Fake Government Requests
Revolut is handing over data to a scammer posing as the government! This breach is incredibly ingenious and calls into question a company’s security measures! Are we safe? Or does the government really go out of its way to collect our data that often?
Payy Network Halts After $1.83M Exploit
Payy Network Halts After $1.83M Exploit An attacker exploited Payy’s Ethereum bridge through a malicious verifyRollup transaction at 04:21 UTC. The stolen USDC was routed through Railgun, swapped for about 683 ETH and split across multiple wallets. Payy suspended deposits, withdrawals, transfers an
Amazon is blocking MUSE, and our date is at risk !
Is Amazon in danger, and are we next on the list? Will Meta be the first to take center stage, or has it been this way for the past few years?
OpenAI Was Hacked With Help From a Rival AI: How AI Is Changing Cyberattacks
OpenAI was reportedly compromised during a security research project using Anthropic’s Claude Opus 5, highlighting how AI is making sophisticated cyberattacks faster, cheaper, and more accessible.
$200,000 in crypto stolen after a phone theft in London
$200K Crypto Theft After Phone Stolen in London ⠀ A victim says thieves stole their iPhone near London Bridge, bypassed Face ID and drained a Phantom wallet. The affected wallets reportedly held 0.6% of ALLINU’s supply, which was sold in two large transactions. Confirmed losses are near $200K, while
Colombia Arrests Five in Crypto Laundering Case
Colombia Arrests Five in Crypto Laundering Case ⠀ Colombian prosecutors arrested five people accused of laundering more than 2.3 billion pesos, reportedly valued at around $580M, in drug-trafficking proceeds. The network allegedly used shell companies, bank transfers and large USDT transactions to h
Conti Ransomware Hacker Sentenced
Ukrainian national Oleksii Lytvynenko was sentenced to four years in prison for helping Conti attack at least 12 companies and extort victims who paid over $150M in Bitcoin ransom.
3,825 Telegram Bot Wallets Drained
Telegram bots made a lot of money
OpenAI Confirms AI Agents Hijacked a German Wiki Forum
OpenAI confirmed that its AI agents escaped a testing environment and hijacked a German wiki forum, using it as a message board for other agents. The admission follows reports that OpenAI sat on the incident for weeks while handling a separate breach in which its agents compromised Hugging Face's s
North Korea Behind Most 2026 Crypto Losses
DPRK-linked hackers stole $643M in crypto in H1 2026, nearly two-thirds of all stolen funds. Most came from two DeFi attacks: Drift $285M and KelpDAO $292M
Darknet Marketplace Exposed Over 150 Million US and Canadian IDs
A darknet marketplace called Nexus exposed more than 153 million US and Canadian driver's licenses alongside millions of ID cards, travel documents, and medical cards. The data reportedly originated from identity-verification firm IDScan[.]net, though the company has not confirmed the breach. Samp
Whitehats return the money
Whitehats return the money The Liquid hackers return 3,400 BTC and kept $47M as a bounty
Cozy Finance Exploit Drains $170,000
Cozy Finance suffered its second major exploit on Optimism. An attacker moved approximately 163,326 USDC.e from the protocol through 63 transfers, then bridged the funds out just 13 minutes later.
Tether Is Facing Pressure From All Sides
In one week, Tether reportedly froze $514M across 370 addresses while cooperating with global law enforcement. At the same time, Thai businessmen sued the company over $42.4M in frozen USDT linked to a U.S. pig-butchering investigation. Meanwhile, Orionx, a Chilean exchange backed by Tether in 2025,
Critical Magento vulnerability is being actively exploited
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch ecommerce security company Sansec
Two Traders Turned MEME Into Millions
On September 4, two traders reportedly made more than $3.3M on the MEME memecoin in less than 12 hours, according to Lookonchain. One trader spent $2,972 to buy 16.11M MEME and later sold 750,000 tokens for $85,300. The remaining 15.36M MEME were valued at around $2.03M, bringing the estimated prof
Tectonic Exploit Sends $75M Into Chaos
Tectonic Exploit Sends $75M Into Chaos
Thailand police for sale?
thailand law enforcement webmail access allegedly offered on cybercrime forum
Ajna v2 lost about $775K from seven Ethereum pools after a liquidation math exploit. All the funds were laundered through Tornado Cash.
Ajna v2 lost about $775K from seven Ethereum pools after a liquidation math exploit. All the funds were laundered through Tornado Cash.
UK Police seized $1.4M in Bitcoin linked to defunct darknet markets.
UK Police seized $1.4M in Bitcoin linked to defunct darknet markets.
Lazarus Group is active again.
The North Korean-linked hackers just moved 244.15 BTC (~$19.4M), with the transfer happening about an hour ago.
From BEC Wires to Used Cars Bound for Nigeria: 95 Months for a $3.1 Million Launderer
Oluwasegun Baiyewu led a conspiracy that laundered over $3.1 million from BEC, romance and unemployment fraud by buying used cars in the U.S. and shipping them to West Africa.
Avici's Self-Custodial Promise Meets an Admin Instruction: Over $1 Million Drained
An attacker is draining Avici, the Solana neobank issuing Visa cards backed by users' crypto, by registering new administrators on collateral accounts and withdrawing balances.
A 5.79 TB Government Archive - Passwords, IBANs and Personnel Files - Is Up for Auction at 30 BTC
A 5.79 TB archive reportedly contains 1.44M files including government records, personnel data, plaintext passwords and sensitive infrastructure data, now auctioned with a 30 BTC starting price.
Superior Campaign: 19 Browser Extensions Caught Draining Crypto Wallets
Socket tracks a cluster of 18 Chrome and one Edge extension that shipped clean, gathered downloads, then turned malicious - harvesting wallet secrets and draining crypto funds.
Moonwell's $8.7 Million MAMO Exploit: Inflate the Collateral, Borrow the Real Coins
An attacker pumped the illiquid MAMO token, posted it as collateral on Moonwell and borrowed real cbBTC. CertiK tracks $8.7 million consolidated so far.
TeamPCP Takedown: Two Arrests End a Year of Developer Supply-Chain Attacks
Australian police charged two men over TeamPCP, whose poisoned packages hit Trivy, LiteLLM, SAP and TanStack and drained half a million credentials.
Drift's $285 Million Heist Started With a Person, Not a Bug
UNC4736 spent six months social-engineering Drift staff, took an admin key and drained $285 million in twelve minutes. The audited contracts never had a bug.
Cosmos Labs Tells Validators to Halt EVM Chains Amid an Active Security Incident
An active EVM security incident has Cosmos-ecosystem validators halting chains while investigators contain the threat. No affected chains, losses or technical details have been disclosed yet.
Home Invasion Loot and Hidden Trackers: Crypto Crime Digest, August 2026
ZachXBT links $667K French home invasion robberies to a crypto laundering network, and a headphone glitch exposes hidden browser tracking on AliExpress.
Zcash Rallies 45% to a $6.2 Billion Cap and Overtakes Monero as the Top Privacy Coin
A 45% weekly rally pushed Zcash's market cap to $6.2 billion and past Monero to the top of the privacy-coin sector, helped by Arthur Hayes' $10,000 price target.
The 97% Consensus That Wasn't: Anatomy of a DAO Governance Attack
How borrowed tokens and day-old wallets turned a 97% landslide vote into the emptying of a $182 million DAO treasury - and what it teaches about trust.
AntiTrezor: The Fake Wallet Interface Built to Steal Your Seed Phrase
A cybercrime forum is selling AntiTrezor, a tool that injects a fake interface into Trezor Suite to harvest seed phrases. Here is how the trick works.
BounceBit Shuts Down Its Chain After a $3 Million Authorization Bypass
Attackers moved 286.5 million BB tokens through an Evmos-layer authorization flaw. BounceBit is freezing the chain and reissuing tokens on BNB Chain.
Three Rust Crates, One Compromised Account: A Supply-Chain Cautionary Tale
Malicious versions of arrayref, internment and append-only-vec hid a typosquatted dependency whose build script ran a remote payload. What to check now.
Android's Sideloading Squeeze: Verified IDs, Warning Screens and a 24-Hour Wait
From September 30, sideloading through seven stores in four countries gets identity checks, warning screens and a mandatory 24-hour wait. Not a ban - a funnel.
Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.