Posts of CRYPTO ROAST

newest first

#1981Text

🔤 UPD: The $352M Bitget Hack Started Almost a Month Earlier 🟠Remember the $351.6M Bitget hack? SlowMist’s investigation suggests the actual operation didn’t begin on September 24. The first traces of malicious activity reportedly appeared as early as August 31. 🟠According to SlowMist, the attacker exploited a zero-day vulnerability in a third-party security service, gaining access to its database. Malicious activity was later identified on two additional nodes — suggesting the attackers were already establishing their foothold weeks before the money moved. 🟠Then on September 25, the attacker reportedly compromised another third-party security service using an employee account and began uploading malicious files. The attackers had also prepared a tool specifically designed for Bitget’s internal systems. 🟠That tool could allegedly forge risk-control parameters, automatically generate withdrawal requests and execute them. Once the theft began, assets were withdrawn across multiple blockchains for almost three hours. 🟠SlowMist is still investigating exactly how the attackers moved between the compromised systems. But the timeline makes one thing clear: this wasn’t a quick wallet exploit. It appears to have been a multi-stage operation prepared weeks in advance. 🟠Meanwhile, Bitget is gradually restoring withdrawals. USDT withdrawals are now available on Ethereum, BSC, Solana and Tron, while BTC and ETH withdrawals had already been reopened. 👉 The $352M disappeared in hours. The attack behind it may have been running for almost a month.

Open in Telegram
Views1,589−66%vs avg
Forwards4
Reactions61
Comments—
#1980Text

🔤 UPD: $50M From the Bitget Hack Hit NEAR Intents 🟠Remember the $351.6M Bitget hack? Some of the stolen crypto is now testing an uncomfortable question for DeFi: what exactly does “permissionless” mean when a protocol can still freeze your funds? 🟠More than $50M linked to the Bitget hack was reportedly routed toward NEAR Intents. Its SHIELD system blocked most of those attempts during the quote stage, while another $503K was frozen during execution. Around $166K still made it through. 🟠And that triggered a debate. NEAR Intents describes itself as permissionless, but its architecture allows specific governance addresses to block accounts and even pause swaps and withdrawals entirely. 🟠NEAR Intents responded with a simple argument: “permissionless does not mean neutral.” In other words, anyone may be able to access the protocol — but that doesn’t necessarily mean the protocol has to process every transaction. 🟠Compare that with THORChain, which reportedly refused to selectively block hacker-linked funds after the same Bitget incident, pointing specifically to its permissionless architecture. 🟠Important distinction: NEAR Intents is a separate protocol built on top of NEAR. These controls exist at the Intents layer and do not mean the NEAR blockchain itself can selectively freeze funds. 👉 The Bitget hack is turning into more than a $352M security incident. Now it’s exposing where different DeFi protocols draw the line between permissionless infrastructure and intervention.

Open in Telegram
Views263−94%vs avg
Forwards0
Reactions6
Comments—
#1979Text
Views1,029−78%vs avg
Forwards0
Reactions—
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h147
11 h1,029
  1. After 1 hour147
  2. Total to date1,029
#1978Text
Views2,451−48%vs avg
Forwards2
Reactions5
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h0
1 h363
16 h1,475
37 h2,451
  1. After 1 hour363
  2. After 24 hours1,475
  3. Total to date2,451
#1977Text
Views3,207−32%vs avg
Forwards1
Reactions7
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h0
1 h275
5 h683
22 h1,699
40 h2,614
61 h3,207
  1. After 1 hour275
  2. After 6 hours683
  3. After 24 hours1,699
  4. Total to date3,207
#1976Text
Views3,294−30%vs avg
Forwards2
Reactions4
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h123
9 h991
21 h1,647
35 h2,063
51 h2,704
68 h3,294
  1. After 1 hour123
  2. After 24 hours1,647
  3. Total to date3,294
#1975Text
Views3,169−33%vs avg
Forwards0
Reactions102
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h0
32 h1,926
42 h2,493
55 h2,864
68 h3,169
  1. After 24 hours1,926
  2. Total to date3,169
#1974Text
Views3,086−35%vs avg
Forwards1
Reactions104
Comments—
Views growthHide views growth

Views growth

Hours after publication

Show as table
Hours after publicationViews
0 h0
53 h2,689
64 h3,086
  1. Total to date3,086
#1973Text
Views3,064−35%vs avg
Forwards0
Reactions153
Comments—
#1972Text
Views3,631−23%vs avg
Forwards0
Reactions179
Comments—
#1971Text
Views4,985+5%vs avg
Forwards0
Reactions273
Comments—
#1970Text
Views5,123+8%vs avg
Forwards2
Reactions264
Comments—
#1969Text
Views4,902+4%vs avg
Forwards0
Reactions268
Comments—
#1968Text
Views5,375+14%vs avg
Forwards1
Reactions310
Comments—
#1967Textedited
Views5,468+16%vs avg
Forwards0
Reactions288
Comments—
#1966Text
Views5,587+18%vs avg
Forwards1
Reactions273
Comments—
#1965Text
Views6,856+45%vs avg
Forwards1
Reactions352
Comments—
#1964Text

🔤 UPD: Trezor’s Official Domain Is Now Sending Phishing Emails 🟠Remember the Trezor data leak that exposed personal information belonging to tens of thousands of hardware wallet customers? Now there’s another problem — attackers reportedly compromised Trezor’s official domain and used it to distribute phishing emails. 🟠According to Trezor, the attackers gained access through a third-party email provider and started sending fake warnings about a supposed “critical vulnerability.” 🟠This makes the attack especially dangerous. These aren’t random emails from an obviously fake Trezor address — the messages were reportedly being sent through official Trezor infrastructure, giving victims another reason to trust them. 🟠Combine that with previously leaked customer information — names, emails, phone numbers, shipping addresses and order history — and attackers potentially have everything needed for extremely convincing targeted phishing campaigns. 🟠Trezor says it has disabled the affected domain and is investigating the compromise. Users should avoid clicking links in suspicious Trezor emails and access services directly instead. 🔓 First they got the customer list. Now they got the trusted sender. That’s how phishing becomes dangerously convincing.

Open in Telegram
Views6,801+44%vs avg
Forwards1
Reactions333
Comments—
#1963Text
Views6,098+29%vs avg
Forwards1
Reactions345
Comments—
#1962Text
Views7,164+51%vs avg
Forwards1
Reactions421
Comments—
#1961Text
Views7,288+54%vs avg
Forwards1
Reactions404
Comments—
#1960Text

🔤 UPD: Trezor Data Leak Is Much Bigger Than We Thought 🟠Remember the ShipMonk breach that exposed the personal information of roughly 14,000 Trezor customers? Turns out that was only part of the story. 🟠Trezor now says data belonging to another 67,000 U.S. customers was also exposed. The leaked records reportedly include names, emails, phone numbers, shipping addresses, and order numbers from purchases made between 2019 and 2021. 🟠The ugly part is that this data apparently shouldn’t have existed anymore. Trezor says logistics partner ShipMonk repeatedly provided written confirmation that the old customer data had been deleted — yet it remained stored in its systems. 🟠No private keys or seed phrases were compromised, so this isn’t a hardware-wallet hack. But combining a person’s name, phone number, home address, and proof that they purchased a hardware wallet creates an extremely valuable targeting database. 🟠Trezor is warning users about increased risks of targeted phishing, scam calls, impersonation attacks, and even physical security threats. A scammer doesn’t have to guess whether you own crypto anymore — the leaked order history already tells them. 🟠This is why privacy matters just as much as wallet security. Your seed can remain perfectly safe while leaked personal data gives attackers everything they need to start working on you instead. 👉 They didn’t steal the keys. They leaked a map of who might be holding them.

Open in Telegram
Views7,828+65%vs avg
Forwards1
Reactions415
Comments—
#1959Text

🔤 UPD: $115M COLDCARD Hacker Starts Moving the Bitcoin 🟠Remember the COLDCARD seed-generation flaw that allowed attackers to reconstruct weak private keys and drain thousands of wallets? The stolen funds are finally starting to move. 🟠According to Galaxy Digital’s Alex Thorn, the third-wave attacker moved stolen $BTC on-chain for the first time, swapping part of it into $ETH through THORChain — likely the beginning of the laundering and cash-out phase. 🟠The scale is now estimated at 1,789.28 BTC worth roughly $114.7M, stolen from 8,865 addresses across the full series of attacks. Until now, funds from all three waves had reportedly remained sitting in the attackers’ original wallets. 🟠The hacker is apparently having some trouble. Several THORChain swaps were reportedly refunded, but attempts to move the Bitcoin continue. Around 90% of the third-wave funds still haven’t moved. 🟠Thorn says the BTC routed through THORChain has already been traced to new Ethereum addresses, with the information shared with authorities and crypto companies. Moving across chains may complicate tracking — but it also creates an entirely new trail for investigators to follow. 🟠The exploit phase is basically over. Now comes the harder part for the attacker: turning $115M of publicly traceable stolen Bitcoin into spendable money without touching infrastructure willing to freeze it. 👉 Stealing crypto is one problem. Laundering nine figures on a public blockchain is another.

Open in Telegram
Views7,047+49%vs avg
Forwards2
Reactions396
Comments—
#1958Text
Views6,285+33%vs avg
Forwards1
Reactions413
Comments—
#1957Text
Views6,731+42%vs avg
Forwards2
Reactions381
Comments—
#1956Text
Views7,061+49%vs avg
Forwards2
Reactions382
Comments—