黑客 · 6470

TRM Labs: AI applications in crypto crime grew 40% in the past year

Comparative news, according to The Block, TRM Labs latest report shows that artificial intelligence applications in crypto crimes have increased 40% year-on-year over the past year, mainly driven by fraudulent activity. According to the report, crypto hackers are increasingly using artificial intelligence for vulnerability analysis, social engineering attacks, and infiltration. In the first half of 2026, there were 201 digital asset hacking attacks, a record high. Of these, about 75% of losses came from 4% of incidents, and North Korea-related activities caused about 600 million US dollars in losses, accounting for 61% of losses in the first half of the year. According to TRM Labs, artificial intelligence has not created new types of crime, but it has significantly lowered the threshold of crime and expanded the scale of attacks. This article is sponsored by GENG, Build Your Fortune on GENG (https://geng.one)

23h agoburnking
Black eats black? Fake DeFi actually snatched out North Korea's Lazarus real hacker

Black eats black? Fake DeFi actually snatched out North Korea's Lazarus real hacker

Source: Security Company ANY.RUN Compiled by: Daily Planet Daily Original title: Fishing Show of the Year, Fake DeFi Picks Out North Korea's Lazarus, Real Madrid Fans, Real Madrid Fans. With a mathematical background, they only use AI to write code. Core point of view: By setting up a fake DeFi company, the security agency successfully infiltrated the “Famous Chollima” hacker group under North Korea's Lazarus Group, revealed its complete process of using false identities, AI tools, and remote collaboration to infiltrate Western companies, and revealed its evolving toolset and infrastructure. Key element: The researchers disguised themselves as recruiters and recruited three North Korean agents within a few months to record their operation behavior, tool usage, and collaboration patterns in real time through the ANY.RUN sandbox environment. Agents used forged driver's licenses, stolen social security numbers, and mule accounts to complete the onboarding process. Some of these documents were processed by Google Gemini and had SynthID watermarks, revealing signs of forgery. Attackers rely on AI tools such as ChatGPT and Google Gemini to encode, translate, and modify files, and use AstrillVPN, remote desktop software, and dedicated servers to covertly access corporate environments. The three agents showed insufficient skills during development, frequently searched for basic issues, and exposed more proxy server and infrastructure information induced by selective network outages and captcha. The investigation found that Famous Chollima aims to lurk within the enterprise for a long time and legally obtain access to code, systems, and intellectual property rights, and is not limited to short-term attacks, and the threat persists significantly. Crypto friends who are often phished have probably heard of the North Korean hacker group Lazarus Group. Its well-known “campaigns” include, but are not limited to: Bybit ($1.5 billion) theft, Ronin Network/Axie Infinity Bridge attack ($6.2 billion), DMM Bitcoin/Ginco related attack ($308 million), Harmony Horizon Bridge attack ($100 million), and Atomic Wallet attacks ($100 million), etc. And the key to the success of these attacks is social engineering — hackers usually disguise themselves as normal job applicants, lurk at crypto companies for years, and wait for the right time. Recently, security agency ANY.RUN joined forces with BCA LTD (a company dedicated to threat intelligence and hunting) and NorthScan (a threat intelligence program to uncover the infiltration of North Korean IT workers) to effectively crack down on North Korean hacker agents. The researchers created a fake DeFi startup and successfully recruited “Famous Chollima” agents under North Korea's Lazarus Group who specialize in human infiltration, to gain an inside perspective on the actions of North Korea's IT workers. The ANY.RUN sandbox environment shows the agent's behavior patterns in real time, revealing their evolving toolsets, remote access workflows, AI tool usage, and supporting infrastructure. This survey went beyond the simple recruitment process and showed in depth how these agents collaborated, obtained, and used company resources after joining the company. The findings suggest that the North Korean IT worker program not only poses a recruitment risk; once agents sneak inside the organization, they can legally obtain access to code, systems, intellectual property, and critical business processes. The following is a report co-authored by the three parties, compiled by Daily Planet Daily. ——————Introduction In December of last year, we fully recorded the infiltration cycle of “Famous Chollima” for the first time. From recruiting collaborators to help them join Western companies, to falsifying documents, shipping laptops to intermediaries, and even using AI tools to assist and translate in real time during interviews, everything is under control. In that survey, we pretended to be a middleman willing to interview them and lend them a laptop in exchange for a percentage of their salary. The point is that those laptops are actually ANY.RUN sandbox environments that record every click and every step they take. This provided us with massive metrics, hours of computer operation videos, and face-to-face contact images, making an unprecedented survey and making headlines in many media. (“Famous Chollima...

1d agoOdaily星球日报#wallet security #hacks

US Department of Justice: Iran is accused of hacking the HBO website and stealing academic data

According to Decrypt, according to Decrypt, the US Department of Justice has filed a lawsuit against 17 hackers allegedly belonging to Iran's Mabna Research Institute, accusing them of participating in cyber attacks over several years, including hacking into the US cable network HBO in 2017, stealing data, and then demanding that the other party pay a ransom of about 6 million US dollars in Bitcoin. The prosecution alleges that the organization carried out hacking attacks on behalf of the Islamic Revolutionary Guard Corps of Iran and other Iranian government clients, targeting hundreds of universities, businesses, and government agencies around the world, stealing at least 31.5 terabytes of academic data and intellectual property rights. The organization also targeted over 100,000 professors' accounts around the world and hacked about 8,000 accounts at 144 American universities and 178 foreign universities. The US State Department offered a reward of up to $10 million to collect the whereabouts of 5 of these defendants. The US Treasury recently imposed sanctions on a number of Iranian crypto exchanges and frozen over $131 million in crypto assets linked to Iran's central bank and Revolutionary Guard Corps.

1d ago

On-Chain Detective Specter: 73 BTC worth $4.6 million originally came from the Whirlpool coin mixer

In comparison, according to on-chain detective Specter monitoring, the victim claimed to have transferred funds from Bitcoin to Ethereum due to a Coldcard hacker attack. However, on-chain data shows that 73 BTC (worth $4.6 million) originally came from the Whirlpool coin mixer two weeks ago, some of which were cross-chain to Ethereum, and then deposited through a phishing Tornado Cash interface. Two coin mixers were used in the relevant fund transfer process. The person was also spotted appearing in a Telegram group involving private key searches and brute-force cracking. On-chain detective Specter said the victim may have been a threatening actor, and her funds may have been stolen by another threatening actor.

1d ago

Industry leaders warn AI agents may turn billion-dollar crypto hacks into “change money”

Comparatively, at the 2026 Wyoming Blockchain Conference, Global Settlement Network CEO Ryan Kirkley warned that AI agents could allow hackers to hack Wi-Fi networks, passwords, and wallets on an unprecedented scale, dwarfing current billion-dollar cryptographic attacks. Kirkley said, “We thought these bridging attacks were serious; in fact, they were just change money.” Attacking one person with $20,000 in assets used to be too expensive, but now a single agent can attack everyone at the same time. Bill Laboon, vice president of technical operations at the Web3 Foundation, agreed, believing that the efficiency improvements brought about by decentralized systems are also beneficial to attackers. Midnight Foundation President Fahmi Syed emphasized that agents require clear parameter settings and should not be granted unlimited access to credit cards, social security information, and various accounts. Kirkley believes that setting proxy permissions is relatively easy to solve, and that the security of the underlying system is the greater concern. On the issue of trust, Laboon notes that big language models are still occasionally illusory, so they don't want to let agents manage individual pensions. Richard Incurred, founder of Silvermine Capital Advisors, believes proxy AI technology is growing faster than people can accept. Kirkley also mentioned the issue of supervisory liability, that is, when autonomous agents make mistakes or even break the law, accountability and fund recovery mechanisms have yet to be clarified.

2d ago#On-chain dynamics

Suspected 819 surge insider address summary: create a new address to increase 20,000 ETH

Comparing news, after 819 skyrocketed, several suspected insider addresses surfaced, as follows: The newly built address 0xedcdcaa1f18350c50c10bef860e64daa9785d05a took profit last night and then quadrupled ETH. The average entry price was 1,936 US dollars. As of press release, it held more than 20,000 ETH orders, and its cumulative surplus exceeded 6 million US dollars. Address 0xde8d9e530b0528ffa7b1190f862536c055dd9524 began opening ETH positions on the 17th. As of press release, it has accumulated 10,657 ETH (total value of US$20.7 million, average opening price of US$1,942), which has now been directly pledged. Additionally, a suspected hacker's address obtained 17,124 ETH through Tornado, which was sold at a high level 9 months ago, and invested 385.35 million DAI/USDS to buy 18,273 ETH last night, with an average price of $2,109.

2d ago

Spending 385.35 million DAI/USDS, a hacker bought 182.73 million ETH in 5 hours

In comparison, according to on-chain analyst Ember Monitoring, a hacker spent 385.35 million DAI/USDS in the past 5 hours to buy 182.73 million ETH, with a purchase price of $2,109. The above stablecoin comes from the 171.24 million ETH it received from Tornado Cash 9 months ago. The hacker then sold ETH at an average price of about $3308 and held it in exchange for DAI and USDS, and bought back ETH today during the ETH rally.

2d ago

KITE will migrate the new token contract 1:1, and the attackers' addresses are excluded

Comparing news, the KITE Foundation reported the progress of handling the token security incident. A new KITE ERC-20 contract has been deployed on the Ethereum main network. The total token supply remains unchanged. The old KITE will migrate to the new contract at a 1:1 ratio. It has been confirmed that addresses controlled by attackers will be eliminated and no new tokens will be obtained. The migration snapshot is based on the Ethereum mainnet block height of 25,692,498. Ordinary self-hosted wallet users will receive new tokens directly without exchange or authorization; exchange users will be migrated in coordination with the exchange and KITE team. The cross-chain channel will continue to be suspended until migration and verification are completed. Earlier, KITE discovered an abnormal transfer on August 6 and confirmed that it had been hacked. The team said that the incident did not cause loss of user or project assets, and the impact has now been controlled.

3d ago

$21 billion AI chip upstart Etched questioned: performance has not been verified by a third party so far

Comparing the news, AI News, Etched has caught the attention of the chip community after having just completed $700 million at a valuation of 21 billion US dollars. The Tiny Corp, an AI computing team founded by famous hacker George Hotz, the team behind tinygrad, an open source deep learning framework, publicly questioned Etched's technical propaganda: there are many photos of investors, orders, and hardware, but too little data to actually verify performance. One of Etched's core selling points is LVI, which allows the chip to run AI inference at lower voltages. Etched claims that this allows the trillion-parameter sparse MoE to reach over 80% of its theoretical peak computing power. Chip design practitioner Wesley Yue questioned that a high ratio does not mean absolute performance is strong. MFU (model computing power utilization) measures the ratio of actual computational power to the theoretical peak. If the chip itself has lower peak computing power, even if the utilization rate reaches 80%, it may not be able to outperform its rivals. Etched has yet to disclose full FLOPs, power consumption, and third-party benchmarks. The official website still only writes that early customer tests have reached the leading level, and that detailed performance data will be published later. However, there is currently no evidence that Etched was a fraud. The Wall Street Journal and Reuters have both confirmed that their chips have been shipped. Jane Street got its first complete rack last month, and deployment has already begun. The biggest question now is not whether there is a chip or not, but whether this chip has been advertised that well.

3d ago