Register and share your invite link to earn from video plays and referrals.

GoPlus Security 🚦
@GoPlusSecurity
Protect Your Every Transaction. User App: 🛡️ Dev Integration: Security Intelligence & SafeToken Protocol 🛡️
1.1K Following    436.8K Followers
🚨 GoPlus Security Alert: @TectonicFi just got hit with a price-manipulation + over-borrow attack on @CronosNetwork. ~$75M gone. ~$6M already bridged to Ethereum and swapped into ~2,600 ETH. Cronos is halted so the rest can’t keep moving. tectonic:native is getting wrecked. Playbook: thin-liq tectonic:native. Loop collateral and borrows, pump the mark in minutes, then size up. At a ~20% collateral factor, that bag printed ~$375M in collateral value and ~$75M in borrow power. Then they vacuumed USDT and other assets. Attacker: 0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652 Attack contracts: 0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3 0x2dc6a36f4e5eeefe112c01569de96dea496bb618 Cronos aggregation wallets: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc ETH profit wallet: Example attack txs:
Show more
🚨 GoPlus Security Alert: A fraud ring seized realtrumpcoins[.]com and the @realtrumpcoins1 account, then maliciously launched $GOLD(EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS). They pumped mcap to $60M, dumped, and rugged — profit $8.2M+. Dev seed money traces to #KuCoin#. 15 operator wallets were seeded from #Binance#. Same crew also deployed $PLATINUM, a malicious token that can drain any holder’s balance. On-chain trail: Token mint: EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS Dev wallet: 3pQA1ZCaAuFgVJPmkxUGhBaDQjRpt88CXaXmoVy3fRsr Operator wallet: 3odTMNgv5ViWXYoiZCwXuMbk8FTdJkpwvEHJfosuATos Dev funder (KuCoin-linked hot wallet): BmFdpraQhkiDQE6SnfG5omcA1VwzqfXrwtNYBwWTymy6 Dev funding tx: Funder of the 15 insider wallets (Binance-linked hot wallet): 5tzFkiKscXHK5ZXCGbXZxdw7gTjjD1mBwuoFbhUvuAi9 Insider funding tx example: Malicious routing contract: FLASHX8DrLbgeR8FcfNV1F5krxYcYMUdBkrP1EPBtxB9 (all 15 insider wallets traded through it) They also deployed another malicious meme — Trump Digital Platinum ($PLATINUM): AuzcYsvKsYs1DFkQVzpm6tLzWb2fFSfZGxLHyubWY4jM Do not buy. The contract can sweep any holder’s full balance at will. Token security check 👉
Show more
⚠️ Exploit Breakdown: Aug 28: the card-balance collateral program behind #Solana# crypto neobank @avici took a sustained hit. Avici says 1,685 users were affected, ~$500K drained. Full refunds promised. Attacker abused a signature-verification / auth-logic bug in Rain’s legacy Solana card contract, then ran the same 3-step loop across a pile of user collateral accounts: (1) Submit a crafted signature bundle — SubmitSignatures (2) Register themselves as admin — AddCollateralAdmin (3) Pull the collateral — WithdrawCollateralAsset Stolen USDC/USDT was periodically swapped to SOL and moved out. One tx: Root cause is not a stolen upgrade key, and not a Solana L1 bug. The program mis-parsed / mis-bound the Ed25519 verify result, so the attacker’s own signature could pass as a legit admin authorization. Attacker: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Hit program: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a Example attack tx:
Show more
UPDATE: All affected card balances will be refunded in full Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed. Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control. When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected. Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected. Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances. Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely. Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.
Show more
⚠️Oracle Manipulation Analysis: Aug 27: @MoonwellDeFi ’s $MAMO collateral oracle got manipulated. ~$8M drained. Attacker extracted real liquidity from the $mcbBTC market. Root cause: thin-liq $MAMO was listed as Moonwell collateral. Attacker pumped the oracle print from ~$0.0105 to ~$0.088 — about 8x — so the mMAMO position’s book value went wildly oversized. Then they looped borrows of real cbBTC out of Moonwell’s cbBTC Core Market (mcbBTC). Attacker: 0x719eae70d4A83f35bF82A2740699F5db84BE919D Attack contract: 0xAbDA3Cfe3ce2668b7829AAccBE594Abb326BCe4F Hit contracts: 0xF877ACaFA28c19b96727966690b2f44d35aD5976 (mcbBTC) 0xEdc817A28E8B93B03976FBd4a3dDBc9f7D176c22 (mUSDC) 0x627Fe393Bc6EdDA28e99AE648fD6fF362514304b (mwstETH) Example attack txs:
Show more
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged. We will share another update as soon as we have more information.
Show more
🚨 GoPlus Security Alert: Aug 25: @realio_network’s realio[.]fund got hit. Attackers seized the platform’s signing stack and swept treasury + custodial wallets across 5 chains. 127.9M $RIO gone ($6.2M). Attacker has cashed out ~$317K so far. Root cause: platform signing keys were taken over. realio[.]fund ran one hot signer for treasury, reserves, and user custody sub-accounts. Once that capability was in hostile hands, they could sign transfers straight out on Ethereum, BNB Chain, Algorand, Stellar, and Realio’s native chain. No user approval. No rekey. No contract bug. A multi-chain RWA issuer put user funds and treasury signing on the same webapp surface. Economically, that keyset is just a cluster of hot wallets.
Show more
Last night, the webapp fell victim to an attack. Access to the platform has been halted, and no more funds are moving in or out of user wallets. This report, created by an independent community member, provides a detailed summary of the event: The team is working on a recovery plan and verification of the incident details. Please do not purchase $RIO on Algorand or Stellar; the bridges to these chains will remain closed indefinitely. Freehold and Districts are not impacted by this. Please do not use the webapp anymore; Freehold is the only wallet we are actively maintaining going forward. We have identified deposits by the attacker into both @MEXC and @kucoincom and are in contact with them. The market impact on $RIO was limited, and the attacker was not able to sell much before everything was frozen. We believe CEXs can safely begin enabling deposits/withdrawals on BNB Chain again. We will work with law enforcement to identify the attacker.
Show more
🚨 GoPlus Security Alert Aug 21, 23:42 UTC — attackers hijacked the delegate permissions on @TheSandboxGame’s SAND OFT (LayerZero Omnichain Fungible Token) contract on Base. They forged cross-chain messages and started infinitely minting unbacked $SAND. The exploit ran for hours. Trillions of tokens got printed. Liquidity + reserve limits kept the damage to ~$670k. Attacker-linked wallets: 0x67624bfadee937c9281b4f98ce18af1bee01257e 0x07bc449e85d9b66899425df8c8ab49cfb44a5f1e 0xAbE09907D2038181FC5Fb0ff0c961C147CdA4D22 0x638Ccb18370eE228378a565c1d4D0F9620d7F296 0x53eda2e80E46B804C5a47260cE04642e82d004cA 0xac76b04397c9296dfc00e25c96d8e51b4edfaf29 Compromised contract: 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF Example attack tx: 🛡️ GoPlus Security Notes 1️⃣ Projects: Strip or hard-disable any generic approveAndCall / paidCall style arbitrary-call functions on OFTs. At minimum, block calls to LayerZero Endpoint, MessageLib, and other privileged contracts. Set the delegate to a multisig + Timelock. Actively monitor DelegateChanged, ConfigSet, PeerSet events. Audits must specifically test the cross-contract combo risk: “ERC20 extension functions × Endpoint relying on msg.sender auth.” Auditing them in isolation isn’t enough. 2️⃣Users: Do not trade $SAND on Base or BSC — both chains’ liquidity is already polluted. If you provided SAND liquidity on Base/BSC, sit tight for the official snapshot + compensation plan. Watch for fake support / phishing links in replies and socials. Stay sharp.
Show more
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply. SAND tokens on Ethereum and Polygon are NOT affected. No user wallets were compromised, and no action is required from holders and liquidity pool (LP) providers on those networks. The SAND locked on Ethereum, which backs all bridged SAND, is fully intact. An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed. ⚠️ Do not buy, sell, or trade SAND on Base or BSC. Liquidity on those networks is compromised. We are taking a pre-incident snapshot and preparing a compensation plan for the qualified users of the impacted LPs. Affected users can reach out to official support via contact@sandbox.game. We continue to monitor the situation and are actively investigating its scope, and we will share a full incident report and detailed technical post-mortem soon. We apologize for the inconvenience this has caused and deeply appreciate the continued patience and support of The Sandbox community. ⚠️ Reminder: Our team will NEVER DM you first. Please beware of scam links in the replies.
Show more
🚨 GoPlus Security Alert: Bull run’s back, volume’s pumping — and so are the hackers & scammers. Multiple “wrong transfer” disasters in the last 24h alone. 1️⃣ Case-sensitivity fat-finger on Solana A user manually typed a Solana address and mixed up uppercase & lowercase characters (TU → tu, k → K). Since Solana addresses are case-sensitive, ~430K $CATE went straight into an unowned blackhole. Gone forever. Correct: Bzj4TU2MdQ3gkkgm5t93ruzFEzLk7qRsuYJCq4jvMDeF Wrong: Bzj4tu2MdQ3gkkgm5t93ruzFEzLK7qRsuYJCq4jvMDeF 2️⃣ Classic address-poisoning attack A victim copied a lookalike address from their own tx history (matching prefix & suffix) and lost ~$2M. Victim: 0x7Ba7f4773fa7890BaD57879F0a1Faa0eDffB3520 Correct: 0xF0e67A1896E814E30c011e36174de28CAA9Ab1aF Poisoned: 0xF0e6A49668dE1195B931A3717c9cc36fc19721aF Attack Tx: 🛡️ GoPlus Reminder: On-chain transfers have no undo button. Build better habits or get rekt: 1. Never type addresses by hand. Never copy from tx history — that’s exactly how address poisoning works. 2. Verify character by character. Don’t just glance at the start & end — the middle is where the trap usually sits. 3. Turn on “hide zero-balance / dust transactions” in your wallet settings. This blocks dust-poisoning attempts cold. 4. Moving big bags? Send a tiny test first. Wait for confirmation, then send the rest. One extra step, massive extra safety.
Show more
I have just made the biggest mistake of my life I sent 429710 cate (my life savings) to what i believed was my new wallet address on fomo Being an idiot i typed it out very carefully or so i thought to my new sol address Bzj4TU2MdQ3gkkgm5t93ruzFEzLk7qRsuYJCq4jvMDeF Unfortunately for me i sent it to Bzj4tu2MdQ3gkkgm5t93ruzFEzLK7qRsuYJCq4jvMDeF and not Bzj4TU2MdQ3gkkgm5t93ruzFEzLk7qRsuYJCq4jvMDeF (I capitalized the TU cause im braindead)
Show more
All 18 skills in the Skill Hub on @binance #AgentOS# have been fully listed by @SafuSkill. → None of the 18 skills were found to have high-risk issues. → Average security score: 97.4/100, with 15 skills at a perfect 100 Skills that could use further security hardening: → #p2p#: one high-severity data upload request pattern → #binance-wallet-tracker#: three low-severity Unicode confusable characters → #fiat#: one info-level advisory Always run a security check before installing a skill: Is the source official? Does it contain malicious behavior? What high-privilege actions does it perform? Go Agentic. Stay Safu!
Show more
Meet Agent OS - a new way to build, deploy and use AI agents on Binance. Bring Binance market intelligence, payment, on-chain, data and trading capabilities directly into your AI workflow. Build. Analyze. Trade. With AI. 🫡 Experience it ↠
Show more
⚠️ SafePal’s order-tracking plugin just got cooked — order data for ~39.8k users (names, addresses, phones & emails) got leaked. Wallets + seed phrases are still safe fr, but this is pure fuel for precision phishing. Scammers are already loading up. Real talk: SafePal will NEVER ask for your seed phrase or private keys. Don’t scan random QRs or leak any verification info!
Show more
Dear community, While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers. The issue has been fixed with additional security measures introduced. The incident impacts approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. Exposed information includes name, email address, shipping address, phone number, and purchase details. All affected customers have been notified individually by email. We have also published this webpage for customers to verify if they are affected using order ID number and shipping country. For a complete disclosure of the incident and the actions we’ve taken, along with FAQs and guidance, please refer to our blog: This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers. Never share your seed phrase, private key, or password with anyone, and stay vigilant against phishing or impersonation attempts. We are extremely sorry to the community and those who are affected. Updates will be posted on our blog as we continue to work through things.
Show more
😱A BTC holder just dodged a #Coldcard# MK4 theft, moved his stack to a CEX… and got completely wiped in under 12 hours. $750k in #BTC# gone. Reason? Google account owned + Google Authenticator cloud sync left on. This is NOT a one-off. Most Google compromises aren’t brute force — they’re phishing + credential stuffing. The usual plays: 1. Fake Google login pages tricking you into handing over the password 2. Malicious browser extensions / cracked software silently yoinking cookies & creds 3. Weak password reuse → massive credential stuffing 4. Recovery email or phone number taken over → instant password reset. 🛡️GoPlus security playbook so you don’t get rekt: 1️⃣Google account → hardware key or Passkey on. Regularly audit devices, third-party access & recovery options. Password alone is a single point of failure. 2️⃣Cloud backup → keep Google Authenticator cloud sync OFF by default. Store recovery keys offline. Never let email + password + 2FA share the same trust chain. 3️⃣Exchange accounts → dedicated email only. Enable withdrawal address whitelist + cooldown period. Kill API withdrawal perms. Watch for abnormal logins like a hawk.
Show more
A very close friend of mine, coldcard MK4 User, after 6 years of suggesting Bitcoin to him, finally allocated and went pretty hard in 2025. 3/4 of a million dollars Moved ALL to a very well known and solid Australian exchange Less then 12 hours later, it was withdrawn ALL gone
Show more
⚠️Trezor Data Leak Alert: Fake #Trezor# devices, social eng, package swaps, wrench attacks & home invasions — risk is UP❗️ @Trezor confirmed a data leak at their shipping provider ShipMonk. 11,742 customers → full name, address, phone & email exposed. Another 1,947 → partial data. Only recent orders (May 10 – Aug 8 2026) in 🇺🇸 🇬🇧 🇸🇪 🇨🇴 🇧🇷 🇮🇹 🇵🇹. 🛡 Stay safe: 1. Don’t click any suspicious links. Extra eyes on anything claiming to be from help@trezor.io — verify the real official source. 2. Watch for intercepted packages swapped with malicious hardware wallets + address-based physical threats. 3. When your device arrives: check anti-tamper seals, packaging, firmware origin & init process. Never use a pre-loaded seed. 4. OPSEC 101: Don't flex your bags online. Don't leave your identity permanently mapped to your shipping address.
Show more
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026. The data exposed: - Full names - Shipping addresses - Phone numbers - Email addresses The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy). All affected customers have been contacted separately by email. Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts. NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels. We are deeply sorry to the community and those affected. We are investigating this situation and will post updates on our blog:
Show more
🚨GoPlus Security Alert: A user just got drained for ~$550K USDC after signing a malicious #ncreaseAllowance# transaction. Victim: 0xa707d3D5d174f59d2C2b81491BDc5650E55F065B Phishing addresses: 0x9bcD8076840378a6eDFfc97ed824621C48D9104a 0x525dD9C729323FD842FCFeBd63659A4EE56444E1 0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566 0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1 0x98b2761559A348968C994D9856dCfc96B6f13C55 🛡 Stay safe—follow GoPlus’ four anti-phishing rules: 🚫 Don’t click unknown links 🚫 Don’t install unverified software 🚫 Don’t sign transactions you don’t fully understand 🚫 Don’t send funds to unverified addresses Install the GoPlus Security extension to block phishing links, risky signatures, malicious approvals, and suspicious transactions in real time 👇
Show more
Excited to join forces with AvengerDAO! 🤝 Together, we’re making top-tier security tools & services accessible for every @BNBCHAIN builder. #StaySafu# | Security First 🫡
Every builder should have a clear path to strong security. AvengerDAO now brings 11 security firms, an official BNB Chain standard, and bug bounty support for builders, from development through launch and beyond. The goal is to raise the baseline for every project launching on BNB Chain 🧵👇
Show more
🚨 GoPlus Security Alert: A user lost approximately $100K USDT in an address poisoning attack. The victim received more than 400 poisoning transactions after their previous transfer 69 days ago. 🔍How address poisoning works: Attackers send small transactions from malicious addresses designed to resemble a victim’s intended recipient—often matching the first and last few characters—then wait for a copy-paste mistake. These attacks are now fully automated, from identifying targets and generating lookalike addresses to deploying spoof tokens, sending dust transactions, and laundering stolen funds through mixers. Victim: 0x9B4Ded0ab7754428F7eC0f63a42bAe70D2f51D83 Intended recipient: 0xae7C0ffAB6e77BE2D7d7880a4Ce433F59A4e2c85 ↕️ Poisoning address: 0xAe7c08afAD91db18666EEAC055D7562c9f4e2c85 ☠️ The poisoned address closely mirrors the intended recipient at both ends. 🛡️ Security Reminders: • Never copy a recipient address from your transaction history. • Verify the entire address—not just the first and last few characters. • Always send a small test transaction before transferring a large amount.
Show more
🚨GoPlus Security Alert: Harmony $ONE has suffered an exploit. The attacker illicitly minted approximately 4B $ONE, with more than 2.8B tokens rapidly transferred to exchanges and sold, sending $ONE down over 35% within minutes. The Harmony team is urgently working to patch the vulnerability and has asked exchanges to immediately freeze the following attacker-linked addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn 0xe7427699427821230177dd13f460d6ce43014510 one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5 one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7 0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy 0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba
Show more
We are asking all exchanges to block and freeze funds that traces back to these 4 wallet addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn 0xe7427699427821230177dd13f460d6ce43014510 one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5 one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7 0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy 0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba
Show more
🚨 GoPlus Security Alert: B2B crypto payment processor @coinsbuycom had associated wallets drained on Ethereum + TRON for ~$7.9M. Attacker then laundered via Monero/XMR, routing through CEXs including ChangeNOW / FixedFloat / BingX. 1. Coinsbuy’s X has been dormant since 2020, but their developer docs keep getting updates: 2. Attack pattern fits hot-wallet private key or admin privilege compromise. In the 2026-07-10 release notes they just fixed: “Fixed transportation transfers being confirmed without verifying the collected amount against the deposits actually received on the node — a mismatch now raises an incident instead of silently overstating the Locked in node balance and causing false insufficient funds errors later.” Doesn’t directly prove the root cause of this drain, but shows how complex their transfer / node / fund-consolidation logic is — high-risk surfaces on both ops and accounting layers. 3. Attacker addresses: 0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3 0x66790b54B891e2ebdef58a15B969Ff6fb4374b17 TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR h/t: @SpecterAnalyst ’s Telegram channel
Show more
🚨GoPlus Community Alert Microsoft Threat Intelligence has identified malicious websites abusing BNB Chain RPC gateways to fetch live malicious instructions from on-chain smart contracts, then using fake CAPTCHA / “browser repair” prompts to socially engineer users into running them. These ClickFix / TerminalFix campaigns are hitting thousands of enterprise and consumer devices worldwide every day. Attack chain: 1. Attackers compromise legitimate sites and inject JS that displays fake CAPTCHA or “fix your browser” screens. 2. The page doesn’t hardcode the payload — it queries a BNB Chain RPC endpoint and dynamically pulls the next-stage commands from a smart contract. 3. Users are instructed to open Win+R / Terminal / PowerShell and paste a “verification” or “repair” command — which actually executes the freshly fetched on-chain payload. 4. Successful execution frequently leads to Lumma and other info-stealers, destructive malware, or full remote-access tools. Immediate advice: 1️⃣Any page that tells you to press Win+R, open Terminal/PowerShell/cmd, and paste something is malicious. Close it immediately. 2️⃣Never trust “CAPTCHA failed — run this command to fix”, “browser error — execute this script”, or “support needs you to paste a command in the terminal”. 3️⃣Don’t copy, don’t paste, don’t run. Close the tab and clear recent downloads if needed. 4️⃣If you already ran the command: disconnect from the network right away and change critical passwords (email, SSO, company IM, browser sync, VPN, password manager) from a clean device.
Show more
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
Show more
👀Thieves eating thieves? Just stole $500k USDC… MEV bot snatched $320k of it for only $0.03! A #Base# user got phished and lost ~$500k USDC. The attacker immediately tried to swap the loot into WETH — but forgot to set any slippage protection. The trade got routed straight into a low-liquidity #Uniswap# V4 WETH/USDC pool (PoolId:0x1d8c55f347727c0fb4f5e1b65cdb93639e0c7102580a7d345e1144cd5a718f54). Result: $500k USDC → only 67.9 WETH (~$129k). ~$370k vanished to extreme slippage… and an MEV bot scooped most of it (~$320k). 😂The wild part? The bot only needed $0.03 in capital for the arb, but paid a juicy 3.5 ETH in gas. The victim already sent on-chain messages to both the attacker and the MEV address, offering a 10% bounty for the return of the funds. Victim: 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c Attacker: 0x920d3b63541eAFe13E05dc4f3453904102c39708 MEV bot: 0x0000208D547A446BA9059CbB2CfcfbAEAd7d3fA3 Attack tx:
Show more
🚨 BREAKING: South Korea’s top exchange #Upbit# announced it will delist $BONK on Sept 7. The exchange cited unresolved security incidents and major disclosure shortfalls as the primary reasons.
🧵1/2 🚨GoPlus Security Alert: #BONK# Suffers Governance Attack, Resulting in a $20M Loss Bonk (@bonk_inu) was hit by a malicious governance proposal attack. A total of 4.426T $BONK held in the BonkDAO wallet was transferred to a malicious address (9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ). The malicious proposal remained live for 6 full days without any effective intervention, ultimately resulting in a total loss of approximately $20 million. Attack proposal details:
Show more
GoPlus Security is proud to support Robinhood Chain by @RobinhoodCrypto . As a Web3 security infrastructure provider, GoPlus brings its token and transaction risk detection capabilities to the Robinhood Chain ecosystem. GoPlus token and transaction risk detection for Robinhood Chain assets are now available across @GeckoTerminal , @DEXToolsApp , @dexscreener , @CoinMarketCap , @BinanceWallet , @wallet , @BitgetWallet , @TokenPocket_TP , @Debot_Official , and @UseUniversalX . To support builders and developers in the Robinhood Chain ecosystem, simply sign up on our platform to get your API key and access complimentary API quota for our services. Get started:
Show more