BTC $81,251.09 +6.41%
ETH $2,619.04 +7.36%
BNB $763.87 +3.89%
XRP $1.41 +8.93%
SOL $113.29 +11.99%
TRX $0.3383 +1.09%
DOGE $0.0878 +7.89%
ADA $0.2277 +12.29%
BCH $256.87 +9.50%
LINK $12.35 +8.46%
HYPE $93.11 +8.54%
AAVE $143.09 +12.02%
SUI $0.8259 +11.57%
XLM $0.1953 +7.08%
ZEC $1,575.16 +8.44%
AAPL $335.06 -0.47%
AMZN $254.23 +1.54%
GOOGL $350.75 +1.07%
MSFT $494.29 -0.61%
META $668.92 -1.96%
NVDA $222.45 +1.45%
TSLA $364.35 -0.34%
SNDK $1,790.10 +11.30%
INTC $109.09 -0.05%
SPCX $152.52 -1.29%
MU $1,017.19 +4.04%
AMD $557.33 +2.81%
BTC $81,251.09 +6.41%
ETH $2,619.04 +7.36%
BNB $763.87 +3.89%
XRP $1.41 +8.93%
SOL $113.29 +11.99%
TRX $0.3383 +1.09%
DOGE $0.0878 +7.89%
ADA $0.2277 +12.29%
BCH $256.87 +9.50%
LINK $12.35 +8.46%
HYPE $93.11 +8.54%
AAVE $143.09 +12.02%
SUI $0.8259 +11.57%
XLM $0.1953 +7.08%
ZEC $1,575.16 +8.44%
AAPL $335.06 -0.47%
AMZN $254.23 +1.54%
GOOGL $350.75 +1.07%
MSFT $494.29 -0.61%
META $668.92 -1.96%
NVDA $222.45 +1.45%
TSLA $364.35 -0.34%
SNDK $1,790.10 +11.30%
INTC $109.09 -0.05%
SPCX $152.52 -1.29%
MU $1,017.19 +4.04%
AMD $557.33 +2.81%

into

All
Article
Flash

first_img Fake AI trading robot tutorial deceives 224 victims into deploying malicious contracts

On September 14, blockchain intelligence company TRM Labs released a report revealing that fake YouTube tutorials lured 224 victims into deploying and funding malicious smart contracts under the guise of building AI-based crypto arbitrage bots, resulting in the theft of 274.6 ETH. TRM identified a total of 234 contracts deployed by the victims, with funds ultimately flowing into six collection addresses controlled by the operators. The stolen ETH was worth approximately $517,000 at the time of the transfer, with a median loss of 1 ETH per incident.Unlike common wallet theft attacks, this scam did not involve phishing links, spoofed domains, or malicious authorization prompts. Victims chose the tutorials themselves, copied the code, deployed the contracts, and funded them from their own wallets, with each step authorized by the victims themselves. As a result, wallet security warnings and phishing blacklists could not be triggered. TRM discovered nine nearly identical YouTube tutorials disguised as different creators, using AI-generated virtual hosts and voiceovers, promising to build fully automated crypto trading bots with Claude, and guiding victims to a compiler website controlled by the operators, some of which mimicked the commonly used Remix development environment.In one variant analyzed by TRM, a backend script would discard the source code pasted by the victims and retrieve another contract from the operator's server, with the clean code displayed on the screen never being on-chain. The replaced contract accepted deposits and transferred any balance over 0.05 ETH to the operators when the victims pressed Start or Withdraw, with no arbitrage logic or AI functionality included in the contract.

first_img The EU Cyber Resilience Act comes into effect, requiring cryptocurrency wallet providers to report vulnerabilities within 24 hours

According to Cointelegraph, the European Union's Cyber Resilience Act (CRA) officially came into effect on September 11, requiring cryptocurrency hardware and software wallet providers to submit early warning reports within 24 hours upon discovering actively exploited vulnerabilities or serious security flaws, and to submit complete notifications within 72 hours. Manufacturers must also submit final reports within 14 days after taking corrective or mitigating measures, while serious incidents must be reported within one month.The European Commission stated that the new reporting requirements aim to better protect consumers and businesses from cyber threats, applicable to all "products with digital elements" sold in the EU market, and are built upon the EU's broader cybersecurity strategy. According to the penalty provisions of the final draft, companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing incorrect, incomplete, or misleading information may also incur fines of up to €5 million.Before the implementation of this measure, several hardware wallet manufacturers recently disclosed incidents of user data breaches. On September 4, Trezor revealed that a data breach involving its logistics provider ShipMonk affected approximately 67,000 U.S. customers, exceeding the initial estimate of 14,000; this week, Trezor and BitBox also warned users to be cautious of phishing emails disguised as urgent security notifications. In June, the Layer-1 blockchain network Zilliqa warned of vulnerabilities in its Ledger application, where attackers could exploit publicly available on-chain data to recover user private keys.

The U.S. CFTC has added 3 new insider trading investigations into Polymarket: involving Biden's pardons, the Iran war, and Google

The U.S. Commodity Futures Trading Commission (CFTC) has previously secretly approved at least three insider trading investigations related to Polymarket trading, involving contracts related to Biden's pardons, the Iran war, and Google-related events. The relevant investigation documents were obtained by WIRED through the Freedom of Information Act.Among them, CFTC Chairman Michael Selig approved an investigation into contracts related to Biden's pardons in May, after a trader had profited over $300,000 in the relevant market; in the same month, the CFTC also approved an investigation into Iran war contracts, after a group of suspicious accounts was reported to have profited $2.4 million with a win rate of about 98%. In July, the CFTC further initiated an investigation into Google-related Polymarket contracts, focusing on individuals who may have traded using non-public information regarding Google's 2025 search rankings. The Southern District Attorney's Office in New York is also conducting a parallel investigation.It is currently unclear whether the aforementioned accounts are connected to previously investigated individuals. Polymarket stated that the company would refer the relevant matters to law enforcement and cooperate with the investigation. As the prediction market rapidly expands, U.S. regulators are clearly intensifying their scrutiny of insider trading and market manipulation.
app_icon
ChainCatcher Building the Web3 world with innovations.