Ill Bloom Vulnerability Exposes Thousands of Crypto Wallets After $5M Theft
Security researchers have uncovered the Ill Bloom vulnerability, a flaw in wallet recovery phrase generation that has already led to at least $5 million in cryptocurrency theft. Here's what happened, which wallets may be affected, and how users can check whether they're at risk.
USB-Spreading Malware Poses New Threat to Crypto Wallet Users
Microsoft has disclosed a cryptocurrency-targeting malware campaign that spreads through USB drives and disguises itself as legitimate files. The threat can replace wallet addresses, steal sensitive crypto data, and maintain persistent access to infected Windows devices, raising fresh security concerns for digital asset holders.
TrapDoor Malware Targets Crypto Developers Through Fake Open-Source Packages
Socket Security researchers uncovered TrapDoor Malware, a supply-chain attack targeting crypto and AI developers through malicious open-source packages. The campaign affected npm, PyPI, and Crates.io ecosystems while attempting to steal credentials, wallet data, and developer access tokens.
Unauthorized eBTC Mint Pressures Echo Token and DeFi Markets
Echo Protocol paused cross-chain transactions after an attacker minted roughly 1,000 unauthorized eBTC on its Monad deployment. While the unauthorized supply was valued near $76.7 million, researchers said the realized extraction appeared far smaller. The incident has renewed scrutiny around DeFi bridge security and privileged access controls.
Lazarus Expands Attack Strategy With Mach-O Man macOS Malware
A new Lazarus-linked campaign is targeting crypto executives and fintech firms with macOS malware. The Mach-O Man toolkit uses fake meeting invites and social engineering to steal credentials and gain system access. The attack highlights growing risks tied to trusted communication channels.


















