Greetings!
Just three exploits this week, totaling around $70M in losses—most of it from a single victim of private key theft, UPCX. Interestingly, the project reported that all stolen funds were back under their control just a few days later.
We’re wrapping up a brutal Q1, marked by record-breaking hacks, sophisticated North Korean campaigns targeting the entire ecosystem, hundreds of millions lost to phishing, and plenty of other nastiness. Hang in there, folks. The fight is worth it.
Before we dive into the news, a special thank you to this week’s sponsor—Recon.
Get a Recon Invariant Audit: a powerful testing suite plus world-class auditors to catch what others miss. Open-source, no vendor lock-in, and proven to find severe bugs. Before spending millions on audits, invest in tests that evolve over time that catch bugs and keep them from coming back.
See our portfolio: https://getrecon.xyz/#services.
Enjoy reading BlockThreat? Consider sponsoring the next edition or becoming a paid subscriber to unlock the premium section with detailed information on hacks, vulnerability, indicators, special reports, and searchable newsletter archives.
Let’s dive into the news!
News
Someone stole the stolen money from ZKLend while the attacker tried to launder funds on a Tornado Cash phishing site. However, this may be a case of misdirection where the thief and the victim are the same person.
Coinbase-backed web3 security shop Harpie announces immediate shutdown due to financial difficulties.
eXch announces a merger, leaving Belize. Delists USDT and USDC.
Sigma Prime patches critical security bug in Electra consensus nodes.
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain.
Mozilla Patches Critical Firefox Bug Similar to Chrome's Recent Zero-Day Vulnerability.
Q1 2025 Hack3d Report by CertiK.
Crime
Demystifying the North Korean Threat by samczsun (SEAL).
North Korea tech workers found among staff at UK blockchain projects.
A Thriller Gone Real: Alleged Scammer Kidnapped by Fake Police, Loses $50 Million.
FBI Albuquerque, federal prosecutors seize cryptocurrency allegedly meant for Hamas.
Iran Officials Allegedly Steal $21 Million in Crypto While 'Investigating' Corruption.
UK Police Recover $671,000 in Stolen Crypto Under Proceeds of Crime Act.
First Digital to 'Pursue Legal Action' Over Justin Sun Allegations as FDUSD Drops.
Policy
Phishing
One Time Pwnage: SEAL Releases Advisory On SLOVENLY COMET. SMS-based authentication is bad enough, but when an SMS gateway gets hacked that’s taking things to the next level.
Coinbase user reportedly scammed of $34 million in Bitcoin according to ZachXBT.
Bitcoin ‘address poisoning’ attacks on the rise, warns Casa CSO Jameson Lopp.
Reports of a targeted X hijacking campaign by Guillermo Rauch.
Reports of a new Cloudflare human verification scam which drops malware on unsuspecting users.
North Korean hackers adopt ClickFix attacks to target crypto firms.
The Impersonator by Rekt. An analysis of the NickLFranklin personae working on behalf of the DPRK regime.
A Sneaky Phish Just Grabbed my Mailchimp Mailing List by Troy Hunt.
Scams
A survey of Bitboy scams by ZachXBT.
Cronos blockchain to reissue 70 billion burned tokens from 2021 as controversial vote gets approved.
SEC Closes Investigation Into Haliey Welch Over Alleged HAWK Memecoin Rug Pull: Report.
Malware
Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads by Kirill Boychenko (Socket).
Hackers Preloading Counterfeit Android Phones With Crypto-Stealing Malware: Kaspersky.
Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign.
Outlaw Group Uses SSH Brute-Force to Deploy Cryptojacking Malware on Linux Servers.
Multiple crypto packages hijacked, turned into info-stealers by Ax Sharma (Sonatype).
Contests
BuidlGuidl CTF - Challenge #4.
Media
Bountyhunt3rz - Episode 9 - jack sanford.
Immunefi - The Magnus Show Ep. 2 on AIXBT bot hack, LLMs and security with Mitchell Amador and Yikesawjeez.
Security Weekly - Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323 with Keith Hoodlet.
Research
Total NEAR Shutdown by neumo and 100proof.
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum.
LookAhead: Preventing DeFi Attacks via Unveiling Adversarial Contracts.
The Three Prompts of Spec Thinking: Yet Another Lens for Smart Contract Auditing by Dravee.
The Unavoidable Extinction of Public Audits by Carlos Alegre (SigmaPrime).
How to Multisig - Best practices on how to implement secure standard operation procedures for multisigs by Fredrik Svantes.
How to deploy (Gnosis) Safe Multisig locally using anvil by bugbountydegen.
Exchange Rate Manipulation in ERC4626 Vaults by Alberto Cuesta Canada, Dariusz Glowinski (Euler Finance).
A simple L2 security and finalization roadmap by Vitalik Buterin.
The Case for EOF by Kamil Śliwak (Solidity Team).
Tools
Aderyn VS Code Extension by Cyfrin Audits.
Safe Utils by OpenZeppelin.
Snubb - multichain token approval scanner in your terminal by jonjon.
esprl - private EVM blockchain explorer by Paul Mullr.
Enjoy reading BlockThreat? Consider sponsoring the next edition or becoming a paid subscriber to unlock the premium section with detailed information on hacks, vulnerability, indicators, special reports, and searchable newsletter archives.