⤷ Title: Fake Jobs, Real Theft: “Contagious Interview” Malware Drains Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BeaverTail #Contagious Interview #Cryptocurrency Theft #Invisible Ferret #malware #MetaMask Security #North Korean hackers #Python Malware #social engineering #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BeaverTail #Contagious Interview #Cryptocurrency Theft #Invisible Ferret #malware #MetaMask Security #North Korean hackers #Python Malware #social engineering #Web3 security
Daily CyberSecurity
Fake Jobs, Real Theft: "Contagious Interview" Malware Drains Crypto Wallets
North Korean hackers target IT pros with "Contagious Interview" malware. Fake job offers install trojanized MetaMask extensions to steal crypto.
⤷ Title: The Solidity delete Trap: How a Simple Keyword Can Wipe Out a Protocol's Revenue
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:00:16 GMT
════════════════════════
⌗ Tags: #solidity #bug_bounty #web3_security #smart_contracts #cybersecurity
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:00:16 GMT
════════════════════════
⌗ Tags: #solidity #bug_bounty #web3_security #smart_contracts #cybersecurity
Medium
The Solidity delete Trap: How a Simple Keyword Can Wipe Out a Protocol's Revenue
Exploring a real-world smart contract vulnerability where state machine mismanagement and a 12-week timelock collided to create a complete…
⤷ Title: Breaking Immutability: How I Bypassed a Core Security Invariant in a Major DeFi Protocol
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 11:42:05 GMT
════════════════════════
⌗ Tags: #web3_security #solidity #bug_bounty #defi #smart_contracts
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 11:42:05 GMT
════════════════════════
⌗ Tags: #web3_security #solidity #bug_bounty #defi #smart_contracts
Medium
Breaking Immutability: How I Bypassed a Core Security Invariant in a Major DeFi Protocol
In the world of smart contract security, immutability is a sacred concept. When a protocol’s documentation explicitly states that a core…
⤷ Title: Critical Web3 Vulnerability: Full Account Takeover via Arbitrary Internal Self-Calls in Smart…
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Sat, 28 Feb 2026 19:04:04 GMT
════════════════════════
⌗ Tags: #web3_security #smart_contracts #solidity #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Sat, 28 Feb 2026 19:04:04 GMT
════════════════════════
⌗ Tags: #web3_security #smart_contracts #solidity #bug_bounty #cybersecurity
Medium
Critical Web3 Vulnerability: Full Account Takeover via Arbitrary Internal Self-Calls in Smart Wallets
How a missing target validation led to a complete compromise of a modular smart contract wallet.
⤷ Title: ClickFix Alert: Fake Venture Capitalists Target Web3 Pros with “Terminal” Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:29:06 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #cyber_espionage #infosec #LinkedIn Scams #malware #Moonlock Lab #North Korean hackers #social engineering #UNC1069 #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:29:06 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #cyber_espionage #infosec #LinkedIn Scams #malware #Moonlock Lab #North Korean hackers #social engineering #UNC1069 #Web3 security
Daily CyberSecurity
ClickFix Alert: Fake Venture Capitalists Target Web3 Pros with "Terminal" Phishing
Moonlock Lab uncovers a North Korean-aligned malware campaign targeting Web3 pros. Attackers use fake VC profiles and ClickFix CAPTCHAs to deploy malware.
⤷ Title: Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
Daily CyberSecurity
Malicious "Hex Visualizer" Chrome Extension Targeting imToken Users
Socket researchers uncover "ImToken Chromophore," a malicious Chrome extension using fake branding and homoglyphs to steal crypto wallet seed phrases.
⤷ Title: The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
Daily CyberSecurity
The 'Contagious Interview' Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
A fake LinkedIn recruiter and a poisoned GitHub repo: See how a CEO uncovered the North Korean "Contagious Interview" malware targeting Web3 developers.
⤷ Title: How I Found a $1,000 Signature Replay Vulnerability in a Blockchain Bridge SDK
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 18:22:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #web3_security #defi_security #ethical_hacking #blockchain
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 18:22:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #web3_security #defi_security #ethical_hacking #blockchain
Medium
How I Found a $1,000 Signature Replay Vulnerability in a Blockchain Bridge SDK
A Step-by-Step Journey from Code Review to Bounty
⤷ Title: How I Found a $1,000 Signature Replay Vulnerability in a Blockchain Bridge SDK
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 05:08:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web3_security #defi_security #ethical_hacking #blockchain
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 05:08:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web3_security #defi_security #ethical_hacking #blockchain
Medium
How I Found a $1,000 Signature Replay Vulnerability in a Blockchain Bridge SDK
A Step-by-Step Journey from Code Review to Bounty
⤷ Title: LLM Injection + Unlimited Approval + RCE: The Coinbase AgentKit Attack Chain
════════════════════════
𐀪 Author: xxmrlnxx
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 07:05:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #prompt_injection_attack #web3_security #cybersecurity #ai_security
════════════════════════
𐀪 Author: xxmrlnxx
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 07:05:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #prompt_injection_attack #web3_security #cybersecurity #ai_security
Medium
LLM Injection + Unlimited Approval + RCE: The Coinbase AgentKit Attack Chain
A prompt injection that crosses three trust boundaries — and why Coinbase called it Medium