BTC $79,222.37 -0.72%
ETH $2,488.91 -0.05%
BNB $739.97 -1.29%
XRP $1.40 -1.04%
SOL $104.00 -1.36%
TRX $0.3345 -0.08%
DOGE $0.0902 +0.71%
ADA $0.2195 +0.14%
BCH $260.24 +1.59%
LINK $12.73 +3.08%
HYPE $85.48 -1.97%
AAVE $132.11 -0.55%
SUI $0.8271 +3.82%
XLM $0.1927 +4.96%
ZEC $1,155.53 -5.17%
BTC $79,222.37 -0.72%
ETH $2,488.91 -0.05%
BNB $739.97 -1.29%
XRP $1.40 -1.04%
SOL $104.00 -1.36%
TRX $0.3345 -0.08%
DOGE $0.0902 +0.71%
ADA $0.2195 +0.14%
BCH $260.24 +1.59%
LINK $12.73 +3.08%
HYPE $85.48 -1.97%
AAVE $132.11 -0.55%
SUI $0.8271 +3.82%
XLM $0.1927 +4.96%
ZEC $1,155.53 -5.17%

theft

All
Article
Flash

Malone Lam, the mastermind behind the theft of 240 million USD in BTC, will attend a plea agreement hearing this Tuesday

According to Apnews, a young cryptocurrency scam gang stole over 4,100 BTC in August 2024 through "social engineering" attacks, which was worth over $240 million at the time.After the theft, gang members quickly began extravagant spending, including purchasing sports cars, renting luxury homes, flying on private jets, and hiring security personnel. Among them, the alleged mastermind, a 22-year-old Singaporean named Malone Lam, reportedly spent over $569,000 in one night at a nightclub in Los Angeles.Investigations revealed that the suspects impersonated employees from Google and the cryptocurrency trading platform Gemini to trick victims into giving up their Google Drive access and security codes, allowing them to transfer the victims' bitcoins. They then moved the funds through multiple trading platforms and money laundering intermediaries. Their lavish lifestyle eventually drew the attention of law enforcement.One suspect was exposed when their IP address was revealed while hiding nearly $30 million in stolen cryptocurrency assets, leading police to trace it back to the luxury home they rented in California. Another suspect was found with $37 million worth of stolen cryptocurrency assets. Lam was accused of using the stolen funds to purchase a $2 million watch and over 30 vehicles including Porsches, Lamborghinis, and Ferraris.Currently, 18 defendants have been charged, and Lam is expected to attend a plea agreement hearing this Tuesday. The U.S. Department of Justice has already issued rulings against several accomplices, and related cases are still ongoing.

first_img Ukrainian police dismantle cryptocurrency scam, with monthly thefts reaching 1 million USD

The Ukrainian police and the Security Service of Ukraine (SBU) recently dismantled a scam network that used a fake investment platform to steal cryptocurrency. This network disguised itself as an investment platform website, luring users to connect their main cryptocurrency wallets and approve a small test transaction when withdrawing funds. Subsequently, it used a "wallet stealer" hidden within the website to automatically transfer user funds to wallets controlled by the operators, kicking victims off the platform. Investigators have currently confirmed 62 victims, with over 46 Ukrainian citizens involved, and the network could steal up to $1 million per month.The police stated that the false profits displayed on the platform are part of the scam, with operators manually creating transactions and adjusting user account balances to create the illusion of investment growth. In addition to cryptocurrency, the platform also collected victims' passport information, phone numbers, email addresses, login credentials, and photos during the registration and identity verification process. The main organizer of the network is a 25-year-old IT expert who recruited over 46 Ukrainian citizens and operated multiple offices in Kyiv and surrounding areas, with members responsible for building and maintaining fake websites, contacting potential victims, and providing security.Victims come from multiple countries, including Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, and Israel. The police traced the gang's server equipment located in the Netherlands and obtained a database stored there, which included a list of victims, cryptocurrency wallet addresses, suspected stolen amounts, internal communications, and platform operation information. The Ukrainian police and SBU subsequently executed 34 searches in Kyiv and surrounding areas, seizing over 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash, and 15 vehicles.

first_img The Fogo mainnet has been down for 46 hours due to the theft of 400 million FOGO, with no scheduled restart time

According to The Defiant, the Fogo mainnet has stopped producing blocks for about 46 hours since Saturday afternoon due to an attack on the Fogo Foundation, resulting in 4 million FOGO tokens (approximately 10.3% of the circulating supply) being transferred to the attacker's address. The foundation initially stated that the chain itself was unaffected, but 15 hours later, the network was actively paused, and plans were made to restrict the related addresses through an upgrade. Currently, the Fogo official explorer shows the last block as 718,525,971, and the RPC endpoint returns a 502 error, while the on-chain TVL tracked by DefiLlama has been frozen at $987,000 for three consecutive days.This downtime is attributed to Fogo's validator design: the chain is managed by a council of 7 voting validators, with the foundation staking evenly among 7 operators, allowing for coordination to pause and implement a client-level address blacklist within minutes. On the exchange side, both KuCoin and Gate have disabled FOGO deposits and withdrawals but retained trading, with a 24-hour spot trading volume of approximately $2.3 million. Meanwhile, a Twitter account impersonating the Fogo Foundation, @FcgoFNDN, posted a false compensation voting link, and Fogo officials reminded users to rely only on information from official channels.Fogo is the second network to actively pause over the weekend, following Cronos, which rolled back its state due to an attack on the Tectonic lending protocol. Fogo raised approximately $7 million by selling 2% of its supply through Binance before launching its mainnet in January, with a valuation of $350 million. The foundation has not yet disclosed details of the attack, compensation plans, or a restart timeline.

The cryptocurrency industry is once again debating "who should hold the private keys" due to the $130 million theft case involving the Coldcard wallet

A wallet security incident involving approximately $130 million in Bitcoin losses is reigniting discussions in the crypto industry about asset custody models: should Bitcoin holders rely on personal self-custody or turn to institutional custody? Hardware wallet manufacturer Coldcard had a vulnerability in its firmware in 2021 that led to some mnemonic phrases generated by the device being predictably risky. This vulnerability was discovered years later, and approximately 5,200 addresses and about 2,000 BTC have been stolen, with losses amounting to around $130 million.After the incident, some investors began to turn to Wall Street custody products. Data shows that the U.S. spot Bitcoin ETF saw a net inflow of about $626 million within days of the incident. Bloomberg ETF analyst Eric Balchunas stated that such security incidents could further drive funds into ETFs. However, the Bitcoin core community still insists on the self-custody concept. Casa co-founder Jameson Lopp stated that recent events should not undermine users' confidence in self-custody and pointed out that third-party custody also carries risks. Bitcoin Core early developer Peter Todd also believes that self-custody has a better long-term safety record than centralized institutions.Onramp co-founder Michael Tanguma believes that both options have flaws. He stated that concentrating a large amount of assets in a single institution creates a "honey pot," while hardware wallets face risks related to supply chains, firmware, and random number generation. Tanguma proposed a "multi-institution custody" solution, where multiple regulated institutions hold keys through a multi-signature mechanism, requiring multiple institutions to jointly sign any transaction to reduce single points of failure. However, this model has also sparked controversy. Critics argue that while multi-institution custody enhances security, it also introduces permissioned management, conflicting with the decentralized ideals originally pursued by Bitcoin. As Bitcoin gradually enters the fields of pensions, trusts, and institutional asset allocation, the industry is seeking new custody solutions suitable for long-term wealth management. The Coldcard vulnerability incident once again highlights that achieving a balance between security, decentralization, and usability remains a core challenge facing the Bitcoin ecosystem.
app_icon
ChainCatcher Building the Web3 world with innovations.