Binance Square
#hackeralert

hackeralert

1.7M views
936 Discussing
Ghost Writer
·
--
Bearish
Verified
🚨BREAKING: Claude Opus 4.8 just exposed a critical $ZEC bug! A flaw that could mint infinite counterfeit Zcash. > Sat in the Orchard pool since May 2022. > Undetected for 3 years. > Found May 29 in an audit. > Patched June 1-3 via emergency hard fork. A researcher used Opus 4.8 to build a working exploit. Unlimited fake ZEC in a test environment. The patch isn't the scary part. The privacy is. The same tech that hides balances means: • No way to scan the chain for abuse. • No way to prove it wasn't exploited. • Team confirms supply "intact." • Team admits they can't cryptographically prove it. ZEC dropped 30% in a day. Same class of bug hit Zcash in 2019. Also undetected for years. Privacy coins hide everything. Including whether they're already broken. {spot}(ZECUSDT) {future}(ZECUSDT) #ZECFallsBelow$515Down16Pct #ZcashBug25PercentDrop #zec #HackerAlert
🚨BREAKING: Claude Opus 4.8 just exposed a critical $ZEC bug!

A flaw that could mint infinite counterfeit Zcash.

> Sat in the Orchard pool since May 2022.
> Undetected for 3 years.
> Found May 29 in an audit.
> Patched June 1-3 via emergency hard fork.

A researcher used Opus 4.8 to build a working exploit.
Unlimited fake ZEC in a test environment.

The patch isn't the scary part.
The privacy is.

The same tech that hides balances means:

• No way to scan the chain for abuse.
• No way to prove it wasn't exploited.
• Team confirms supply "intact."
• Team admits they can't cryptographically prove it.

ZEC dropped 30% in a day.

Same class of bug hit Zcash in 2019.
Also undetected for years.

Privacy coins hide everything.
Including whether they're already broken.
#ZECFallsBelow$515Down16Pct #ZcashBug25PercentDrop #zec #HackerAlert
Verified
Panic in the privacy bunker AI detects a massive counterfeiting flaw in #zcash and triggers a $120M collapse The privacy cryptocurrency market is facing critical hours after it was revealed that Zcash #zec operated for four years with a mathematical vulnerability that allowed for the unlimited and undetectable printing of coins. Although the flaw has already been fixed, the technical, reputational, and market impact has been massive. 1. The trigger: The ghost of undetectable counterfeiting The flaw: A vulnerability in the scalar multiplication mechanism of the Orchard privacy circuit (active since May 2022) allowed an attacker to spend the same protected coin multiple times without leaving a trace, breaking the technical supply limit. The privacy dilemma: Due to Zcash's own anonymity architecture, it is cryptographically impossible to verify if anyone exploited this flaw before its fix. This uncertainty led to the complete exit of high-profile figures from the ecosystem, like Arthur Hayes. 2. The AI factor: Claude Opus 4.8 as the ultimate auditor The vulnerability was not found by humans, but by an audit framework assisted by the new AI model Claude Opus 4.8, operated by researcher Taylor Hornby on May 29. The process was an extreme speed success: after the AI discovery, the tech team took just a few hours to create a proof of concept and only a few days to deploy an emergency patch via a soft fork on June 1 and the final update NU6.2 on June 2. 3. Massacre in the markets and record liquidations ZEC suffered a vertical drop of up to 60%, falling from $630 on Thursday to a low of approximately $250 on Friday. There were $120.23 million in forced liquidations within 24 hours ($73M in long positions and $46M in shorts). The volume of Zcash position destruction was rated by CoinGlass as 3.80 times more extreme than its weekly average. #CryptoNews #HackerAlert $ZEC {spot}(ZECUSDT)
Panic in the privacy bunker
AI detects a massive counterfeiting flaw in #zcash and triggers a $120M collapse

The privacy cryptocurrency market is facing critical hours after it was revealed that Zcash #zec operated for four years with a mathematical vulnerability that allowed for the unlimited and undetectable printing of coins. Although the flaw has already been fixed, the technical, reputational, and market impact has been massive.

1. The trigger: The ghost of undetectable counterfeiting
The flaw: A vulnerability in the scalar multiplication mechanism of the Orchard privacy circuit (active since May 2022) allowed an attacker to spend the same protected coin multiple times without leaving a trace, breaking the technical supply limit.
The privacy dilemma: Due to Zcash's own anonymity architecture, it is cryptographically impossible to verify if anyone exploited this flaw before its fix. This uncertainty led to the complete exit of high-profile figures from the ecosystem, like Arthur Hayes.

2. The AI factor: Claude Opus 4.8 as the ultimate auditor
The vulnerability was not found by humans, but by an audit framework assisted by the new AI model Claude Opus 4.8, operated by researcher Taylor Hornby on May 29.
The process was an extreme speed success: after the AI discovery, the tech team took just a few hours to create a proof of concept and only a few days to deploy an emergency patch via a soft fork on June 1 and the final update NU6.2 on June 2.

3. Massacre in the markets and record liquidations
ZEC suffered a vertical drop of up to 60%, falling from $630 on Thursday to a low of approximately $250 on Friday.
There were $120.23 million in forced liquidations within 24 hours ($73M in long positions and $46M in shorts). The volume of Zcash position destruction was rated by CoinGlass as 3.80 times more extreme than its weekly average.
#CryptoNews #HackerAlert
$ZEC
Verified
Hackers exploited Specter on BNB Chain and stole $2.5 million. Attackers minted 99 million TSR tokens, dumped them on the market, and caused the token price to crash by approximately 99%. Part of the stolen funds has already been bridged to Ethereum and laundered through Tornado Cash. #scamriskwarning #ScamWarning #HackerAlert
Hackers exploited Specter on BNB Chain and stole $2.5 million.

Attackers minted 99 million TSR tokens, dumped them on the market, and caused the token price to crash by approximately 99%.

Part of the stolen funds has already been bridged to Ethereum and laundered through Tornado Cash.

#scamriskwarning #ScamWarning #HackerAlert
·
--
⚠️ StablR Exploit: EURR & USDR Still Not Fully Pegged! #warning! #HackerAlert On May 24, 2026, Malta-based stablecoin issuer StablR suffered a serious exploit. What happened: An attacker compromised a 1-of-3 minting multisig (one private key was enough). They took full control, added their address, removed the legitimate signers, and minted unbacked tokens: 8.35M USDR 4.5M EURR Total face value: ~$10.4–13.5M The attacker dumped most of it on DEXes and extracted ~1,115 $ETH (~$2.8–3.15M). The sudden flood of fake supply triggered a sharp depeg: EURR dropped over 20% (down to ~$0.85–0.93) USDR crashed as low as $0.40 As of today (May 25), both stablecoins have still not fully restored their $1 peg. Important clarification: This was not a smart contract code bug. It was a classic key management & governance failure. The real reserves were never stolen — the damage came from uncontrolled minting of unbacked tokens. StablR confirmed the incident and, with help from Blockaid and on-chain investigator ZachXBT, has already frozen part of the stolen funds. Key takeaway: Even “MiCA-compliant” and regulated stablecoin issuers can be brought down by weak operational security. Stay safe out there.
⚠️ StablR Exploit: EURR & USDR Still Not Fully Pegged!

#warning! #HackerAlert

On May 24, 2026, Malta-based stablecoin issuer StablR suffered a serious exploit.

What happened:
An attacker compromised a 1-of-3 minting multisig (one private key was enough). They took full control, added their address, removed the legitimate signers, and minted unbacked tokens:
8.35M USDR
4.5M EURR
Total face value: ~$10.4–13.5M

The attacker dumped most of it on DEXes and extracted ~1,115 $ETH (~$2.8–3.15M). The sudden flood of fake supply triggered a sharp depeg:
EURR dropped over 20% (down to ~$0.85–0.93)
USDR crashed as low as $0.40

As of today (May 25), both stablecoins have still not fully restored their $1 peg.

Important clarification:
This was not a smart contract code bug. It was a classic key management & governance failure. The real reserves were never stolen — the damage came from uncontrolled minting of unbacked tokens.
StablR confirmed the incident and, with help from Blockaid and on-chain investigator ZachXBT, has already frozen part of the stolen funds.

Key takeaway:
Even “MiCA-compliant” and regulated stablecoin issuers can be brought down by weak operational security.

Stay safe out there.
"I do it for the ego before the money"... Behind their screens, some of the most wanted hackers in France… are sometimes barely 15 years old 💻 The most concerning thing according to several cybersecurity experts is that this new generation doesn't always have exceptional technical skills. Yet, the damage is enormous: massive data theft, paralyzed institutions, and millions in euros lost... Among them, a 21-year-old hacker nicknamed "Hex Dex", suspected of having retrieved data from several sports federations… but also "Breach3d", a mere 15-year-old involved in the hack of the ANTS.... #HackerAlert
"I do it for the ego before the money"...

Behind their screens, some of the most wanted hackers in France… are sometimes barely 15 years old 💻

The most concerning thing according to several cybersecurity experts is that this new generation doesn't always have exceptional technical skills.
Yet, the damage is enormous: massive data theft, paralyzed institutions, and millions in euros lost...

Among them, a 21-year-old hacker nicknamed "Hex Dex", suspected of having retrieved data from several sports federations… but also "Breach3d", a mere 15-year-old involved in the hack of the ANTS....
#HackerAlert
Verified
💵 The biggest threats to cryptocurrencies in April weren't the bugs in smart contracts. It was North Korean operatives posing as a quantum fund (Drift) and DDoS-ing bridge nodes to mint fake messages (Kelp DAO). Audits won't catch this. #Korea #CoreaDelNorte #HackerAlert #CRİPTO #Hack $DRIFT $AAVE
💵 The biggest threats to cryptocurrencies in April weren't the bugs in smart contracts. It was North Korean operatives posing as a quantum fund (Drift) and DDoS-ing bridge nodes to mint fake messages (Kelp DAO). Audits won't catch this.

#Korea #CoreaDelNorte #HackerAlert #CRİPTO #Hack $DRIFT $AAVE
Verified
POLYMARKET TAKES A MEGA HIT! OVER $600,000 STOLEN IN MINUTES. #Polymarket 😱💸 The prediction platform confirmed the breach. Are your funds safe? Read before you bet. 🔥 What went down: An attacker compromised an admin wallet on Polygon and drained over **$600,000** in crypto. Researcher ZachXBT raised the alarm, and Arkham bumped the initial figure from $520k to over $600k. ⚠️ Risk for users? Polymarket assures that user funds and smart contracts are secure. The hack was due to a leaked private key used for internal payments (rewards), not a failure in the core infrastructure. ❓ What they’re not explaining: How was the key leaked? Will there be more vulnerabilities? The investigation is still open. 📉 Panic or FUD? This blow exposes the risks even in decentralized platforms. If you're trading on Polymarket, stay alert for updates. 👉 Do you think this will affect trust in prediction markets? Comment below! 💬 Have you experienced something similar? Share your story. 🔁 RT and like so no one sleeps on their funds in exchanges! #Polymarket #HackerAlert #criptonews #Polygon
POLYMARKET TAKES A MEGA HIT! OVER $600,000 STOLEN IN MINUTES. #Polymarket 😱💸

The prediction platform confirmed the breach. Are your funds safe? Read before you bet.

🔥 What went down:
An attacker compromised an admin wallet on Polygon and drained over **$600,000** in crypto. Researcher ZachXBT raised the alarm, and Arkham bumped the initial figure from $520k to over $600k.

⚠️ Risk for users?
Polymarket assures that user funds and smart contracts are secure. The hack was due to a leaked private key used for internal payments (rewards), not a failure in the core infrastructure.

❓ What they’re not explaining:
How was the key leaked? Will there be more vulnerabilities? The investigation is still open.

📉 Panic or FUD?
This blow exposes the risks even in decentralized platforms. If you're trading on Polymarket, stay alert for updates.

👉 Do you think this will affect trust in prediction markets? Comment below!
💬 Have you experienced something similar? Share your story.

🔁 RT and like so no one sleeps on their funds in exchanges!

#Polymarket #HackerAlert #criptonews #Polygon
·
--
Bearish
MAP Protocol ($MAPO) Hacked - Token Crashes 99.99% The Butter Network cross-chain bridge was exploited yesterday, and the damage is brutal. ▪️ What Happened: Attacker exploited a hash collision bug in Butter Bridge V3.1's OmniServiceProxy contract on both Ethereum and BNB Chain. ▪️ The Mint: A jaw-dropping 1 Quadrillion $MAPO tokens minted out of thin air. That is 4.8 Million times the legitimate supply of 208 Million. ▪️ The Drain: Attacker dumped 1 Billion tokens on Uniswap, walking away with 52 ETH (~$180K). ▪️ Price Action: MAPO crashed from $0.00305 to $0.000000143 in a matter of hours. ▪️ Ongoing Risk: Hacker still holds 999.99 Billion MAPO. More dumps possible. Team Response: → MAP Protocol paused mainnet → Butter Network paused ButterSwap → New contract address and asset snapshot incoming → Attacker-held tokens will be invalidated Action For Holders: Do not trade #MAPO on Uniswap. Wait for the official snapshot announcement. This is the 18th DeFi protocol exploited this month. Bridge security is once again in the spotlight. Stay sharp. Verify before you ape. NFA & DYOR ALWAYS #Hack #HackerAlert #CryptoPatel
MAP Protocol ($MAPO) Hacked - Token Crashes 99.99%

The Butter Network cross-chain bridge was exploited yesterday, and the damage is brutal.

▪️ What Happened: Attacker exploited a hash collision bug in Butter Bridge V3.1's OmniServiceProxy contract on both Ethereum and BNB Chain.
▪️ The Mint: A jaw-dropping 1 Quadrillion $MAPO tokens minted out of thin air. That is 4.8 Million times the legitimate supply of 208 Million.
▪️ The Drain: Attacker dumped 1 Billion tokens on Uniswap, walking away with 52 ETH (~$180K).
▪️ Price Action: MAPO crashed from $0.00305 to $0.000000143 in a matter of hours.
▪️ Ongoing Risk: Hacker still holds 999.99 Billion MAPO. More dumps possible.

Team Response:
→ MAP Protocol paused mainnet
→ Butter Network paused ButterSwap
→ New contract address and asset snapshot incoming
→ Attacker-held tokens will be invalidated

Action For Holders: Do not trade #MAPO on Uniswap. Wait for the official snapshot announcement.
This is the 18th DeFi protocol exploited this month. Bridge security is once again in the spotlight.

Stay sharp. Verify before you ape.
NFA & DYOR ALWAYS

#Hack #HackerAlert #CryptoPatel
Verified
🥷 The hacker from the Huminity Protocol has minted 200 million H and has already sold 100 million of the previously minted H for 774 $BNB . 🥷 Keep in mind that the Humanity hacker has minted another 100 million $H on BSC. By selling H, the hacker has already netted 18 510 $ETH (30.83 million dollars) and 1 548 BNB (924,000 dollars). The hacker still holds 111.36 million $H (14 million dollars) ready to be dumped. However, on-chain liquidity is nearly depleted. 🇺🇸📊 #BTC #ETH According to SoSoValue data, on June 8 (Eastern Time), U.S. spot Bitcoin ETFs recorded a total net outflow of 91.37 million dollars. Meanwhile, U.S. spot Ethereum ETFs recorded a total net inflow of 82.37 million dollars. #etf 💸 A whale ("0x97f") closed its long position on $HYPE with a loss of 3.22 million dollars. Next, it sold 165,391 HYPE, raking in a profit of 1.978 million dollars in the spot market. Later, the whale opened a short position of 15,000 $SP500 with 50x leverage, valued at 111.38 million dollars, with a liquidation price of 8295.66 dollars. <a>...</a> 🕵️ According to IC3 researchers, cryptocurrencies have "limited utility" when addressing trust and payment issues in the AI space. 📊 #RWA The market cap of tokenized stocks has reached 5.5 billion dollars thanks to the SpaceX IPO and the expansion of stock trading. #humanity #HackerAlert #etf #ballenas
🥷 The hacker from the Huminity Protocol has minted 200 million H and has already sold 100 million of the previously minted H for 774 $BNB .

🥷 Keep in mind that the Humanity hacker has minted another 100 million $H on BSC.

By selling H, the hacker has already netted 18 510 $ETH (30.83 million dollars) and 1 548 BNB (924,000 dollars).

The hacker still holds 111.36 million $H (14 million dollars) ready to be dumped.

However, on-chain liquidity is nearly depleted.

🇺🇸📊 #BTC #ETH According to SoSoValue data, on June 8 (Eastern Time), U.S. spot Bitcoin ETFs recorded a total net outflow of 91.37 million dollars. Meanwhile, U.S. spot Ethereum ETFs recorded a total net inflow of 82.37 million dollars. #etf

💸 A whale ("0x97f") closed its long position on $HYPE with a loss of 3.22 million dollars.

Next, it sold 165,391 HYPE, raking in a profit of 1.978 million dollars in the spot market.

Later, the whale opened a short position of 15,000 $SP500 with 50x leverage, valued at 111.38 million dollars, with a liquidation price of 8295.66 dollars. <a>...</a>

🕵️ According to IC3 researchers, cryptocurrencies have "limited utility" when addressing trust and payment issues in the AI space.

📊 #RWA The market cap of tokenized stocks has reached 5.5 billion dollars thanks to the SpaceX IPO and the expansion of stock trading.

#humanity #HackerAlert #etf #ballenas
chejo222:
me gustaría empezar a investigar de esa manera donde está esta clase de información
🕵️‍♂️ A newly created wallet received 25 000 $ETH (42.03 million dollars) from Kr@k3n, likely tied to Bitmine. 🐳 #AAVE The "whale" keeps feeding $USDC and $USDT into Aave V3 to short ETH. Total: 132.16 million dollars in $USDC and $USDT contributed, with 35,001 ETH borrowed, deposited on Binance, and sold. Address: 0x1be45fef92c4e2538fecd150757ed62b7b3757d7 🥷 The hacker from Pando Rings sold the 6,240 $ETH they bought during the dip three days ago for 10.29 million $DAI, raking in over $290,000 in profit. 🥷 According to Specter Analyst, the Humanity protocol has suffered a cyber attack valued at over 31 million dollars. The fund drain is still ongoing, and the hacker is swapping $H for ETH. #HackerAlert #ballenas #Inversiones #billetera HumanityProtocolWalletsHackedOver$19M#analysis
🕵️‍♂️ A newly created wallet received 25 000 $ETH (42.03 million dollars) from Kr@k3n, likely tied to Bitmine.

🐳 #AAVE The "whale" keeps feeding $USDC and $USDT into Aave V3 to short ETH.

Total: 132.16 million dollars in $USDC and $USDT contributed, with 35,001 ETH borrowed, deposited on Binance, and sold.

Address: 0x1be45fef92c4e2538fecd150757ed62b7b3757d7

🥷 The hacker from Pando Rings sold the 6,240 $ETH they bought during the dip three days ago for 10.29 million $DAI, raking in over $290,000 in profit.

🥷 According to Specter Analyst, the Humanity protocol has suffered a cyber attack valued at over 31 million dollars.

The fund drain is still ongoing, and the hacker is swapping $H for ETH.

#HackerAlert #ballenas #Inversiones #billetera HumanityProtocolWalletsHackedOver$19M#analysis
‼️Latin America is experiencing one of the biggest "data leak" waves in user history, according to security firm VECERT Analyzer. With high adoption of digital assets in the region, the risk of phishing and theft is rising. 🚨 Strategy transferred 411 bitcoin to Coinbase Prime. Bettors on Polymarket are giving it a 91% chance that the company will dump BTC before the end of 2026. 📈 Starting today, CME Group enables 24/7 trading for bitcoin futures and options. This eliminates the classic weekend "gap". The move responds to high institutional interest. 📉 JPMorgan states that the strong outflows from bitcoin and gold ETFs reflect a cooling off of the bet against monetary depreciation, driven by expectations of a possible agreement between the U.S. and Iran. 📉 Standard Chartered holds one of the most bullish forecasts for Ethereum: projecting that ETH could hit $40,000 by the end of 2030. 🚨 The crypto ecosystem isn't slowing down. Stay updated with the most significant news from the last 24 hours. Less noise. More context. More clarity.⚡ 📩 ⚠️ Nearly USD 500,000 was drained from about 297 wallets across Ethereum, Polygon, BNB Chain, Base, Arbitrum, among other networks. The on-chain investigator known as Mr Wildcat suspects a massive leak of private keys from a provider. #HackerAlert #ballenas #Latinoamérica #etf #criptonews $BTC $BNB $ETH {spot}(POLUSDT) {spot}(ARBUSDT)
‼️Latin America is experiencing one of the biggest "data leak" waves in user history, according to security firm VECERT Analyzer. With high adoption of digital assets in the region, the risk of phishing and theft is rising.

🚨 Strategy transferred 411 bitcoin to Coinbase Prime. Bettors on Polymarket are giving it a 91% chance that the company will dump BTC before the end of 2026.

📈 Starting today, CME Group enables 24/7 trading for bitcoin futures and options. This eliminates the classic weekend "gap". The move responds to high institutional interest.

📉 JPMorgan states that the strong outflows from bitcoin and gold ETFs reflect a cooling off of the bet against monetary depreciation, driven by expectations of a possible agreement between the U.S. and Iran.

📉 Standard Chartered holds one of the most bullish forecasts for Ethereum: projecting that ETH could hit $40,000 by the end of 2030.

🚨 The crypto ecosystem isn't slowing down.

Stay updated with the most significant news from the last 24 hours.

Less noise. More context. More clarity.⚡

📩 ⚠️ Nearly USD 500,000 was drained from about 297 wallets across Ethereum, Polygon, BNB Chain, Base, Arbitrum, among other networks. The on-chain investigator known as Mr Wildcat suspects a massive leak of private keys from a provider.

#HackerAlert #ballenas #Latinoamérica #etf #criptonews $BTC $BNB $ETH
🚨 Tether froze 72 million USDT on the Tron network, apparently linked to an alleged exploit of 120 million dollars. 📈 Part of these funds were used to buy Monero (XMR), causing a spike in that cryptocurrency's price to nearly 440 dollars. 🚔 International police dismantled AudiA6, a network accused of laundering over 336 million euros in cryptocurrencies for cyber extortion gangs. The operation in Georgia resulted in two arrests. 🔹 The SpaceX pre-IPO raised 500 million dollars on Binance. 🔹 Large dormant Cardano wallets have been reactivated. An analytics firm commented that "something changed beneath the surface." 📉 Nakamoto Inc. sold 600 BTC to settle a debt of 45 million dollars. The company now holds 4,467 BTC in its treasury. 📈 With its IPO, SpaceX became the eighth publicly traded company with the most Bitcoin. The company founded by Elon Musk owns 18,712 BTC. #SpaceXSharesOpen29PercentAboveIPOPrice #BTC #USDT #ballenas #HackerAlert $BTC $XMR $SPCXB
🚨 Tether froze 72 million USDT on the Tron network, apparently linked to an alleged exploit of 120 million dollars.

📈 Part of these funds were used to buy Monero (XMR), causing a spike in that cryptocurrency's price to nearly 440 dollars.

🚔 International police dismantled AudiA6, a network accused of laundering over 336 million euros in cryptocurrencies for cyber extortion gangs. The operation in Georgia resulted in two arrests.

🔹 The SpaceX pre-IPO raised 500 million dollars on Binance.

🔹 Large dormant Cardano wallets have been reactivated. An analytics firm commented that "something changed beneath the surface."

📉 Nakamoto Inc. sold 600 BTC to settle a debt of 45 million dollars. The company now holds 4,467 BTC in its treasury.

📈 With its IPO, SpaceX became the eighth publicly traded company with the most Bitcoin. The company founded by Elon Musk owns 18,712 BTC.

#SpaceXSharesOpen29PercentAboveIPOPrice #BTC #USDT #ballenas #HackerAlert $BTC $XMR $SPCXB
Article
New Mac Malware Targets Crypto Users. Reaper Bypasses Apple Protections and Steals Wallet DataMac users are facing a new cybersecurity threat. Security researchers have identified a malware strain called Reaper that specifically targets cryptocurrency holders and is capable of bypassing some of macOS’s built-in security protections. The malware is being distributed through fake download pages that imitate popular applications. Once a victim executes the malicious script, Reaper begins collecting credentials, cryptocurrency wallet data, and sensitive documents stored on the device. Attackers Have Found a New Way Around macOS Security Until recently, cybercriminals commonly relied on social engineering techniques that tricked users into manually running malicious commands in Terminal. Apple has gradually closed many of those attack vectors through security updates. However, the creators of Reaper have found a new approach. Instead of abusing Terminal, the malware leverages Script Editor, a built-in macOS application that comes preinstalled on every Mac. Since most users rarely interact with it, few recognize the potential security risks it can pose. Malicious websites can automatically launch Script Editor and display what appears to be a harmless script. In reality, the dangerous code is hidden among ASCII art, whitespace, and other elements that make it difficult for ordinary users to detect. A single click on the Run button can be enough to give attackers access to the system. Fake Websites Are Designed to Look Legitimate The campaign relies on deceptive domains that closely resemble well-known companies and software platforms. Security researchers have discovered websites using typo-squatting techniques, making them appear trustworthy at first glance. Once the script is launched, victims are often presented with a fake Apple security update prompt requesting their Mac password. This is the moment when attackers gain access to more sensitive areas of the system. Interestingly, the malware first checks the device’s keyboard layout. If it detects a Russian-language configuration, the attack terminates immediately. This behavior is commonly observed in malware campaigns and may offer clues about the origin of the operators behind the attack. Crypto Wallets and Password Managers Are Primary Targets The malware's primary objective is to compromise cryptocurrency-related applications. Reaper specifically targets popular wallets such as Ledger Live, Trezor Suite, and Exodus. According to researchers, it can manipulate internal wallet files and intercept future transactions. Beyond crypto wallets, the malware also focuses heavily on web browsers. It attempts to extract stored credentials from Chrome, Firefox, and Microsoft Edge while also harvesting data from browser extensions such as MetaMask and password managers like 1Password. Cryptocurrency assets are not the only target. Reaper Also Steals Sensitive Documents Security analysis shows that the malware actively scans both Desktop and Documents folders for valuable files. Among the targeted file types are: Microsoft Word documents (.docx)PDF files (.pdf)Excel spreadsheets (.xlsx)Wallet backup files (.wallet)Private key and backup files (.keys) The collected files are compressed into archives and transmitted to remote command-and-control servers operated by the attackers. In some cases, Reaper also installs a hidden backdoor that allows long-term access to the device even after a system reboot. The Third Similar Campaign in Just Weeks According to cybersecurity experts, Reaper is not an isolated incident. It represents the third major campaign in roughly two months that has adopted a similar AppleScript-based attack technique combined with social engineering tactics. Researchers have also linked the activity to broader campaigns involving fake troubleshooting guides and fraudulent technical support content published across various web platforms. Those campaigns have been associated with other well-known malware families designed to steal cryptocurrency assets and sensitive personal information. How Can Users Protect Themselves? Security professionals recommend extreme caution when downloading software from unofficial sources. Users should always verify website addresses before downloading applications and be highly suspicious of unexpected prompts requesting system passwords. Particular attention should be paid to any website that asks users to open Script Editor or execute an unfamiliar script. These tactics are becoming one of the primary delivery mechanisms for Reaper, a malware family that is increasingly targeting cryptocurrency investors using Apple devices. #Apple , #CyberSecurity , #CryptoNews , #HackerAlert , #StaySafe Stay one step ahead – follow our profile and stay informed about everything important in the world of cryptocurrencies. Disclaimer: The information and opinions presented in this article are for informational and educational purposes only and should not be considered financial or investment advice. Nothing on this page constitutes a recommendation to buy or sell any assets. Cryptocurrency investments are inherently risky and may result in financial loss. Always do your own research before making any investment decisions.

New Mac Malware Targets Crypto Users. Reaper Bypasses Apple Protections and Steals Wallet Data

Mac users are facing a new cybersecurity threat. Security researchers have identified a malware strain called Reaper that specifically targets cryptocurrency holders and is capable of bypassing some of macOS’s built-in security protections.
The malware is being distributed through fake download pages that imitate popular applications. Once a victim executes the malicious script, Reaper begins collecting credentials, cryptocurrency wallet data, and sensitive documents stored on the device.
Attackers Have Found a New Way Around macOS Security
Until recently, cybercriminals commonly relied on social engineering techniques that tricked users into manually running malicious commands in Terminal.
Apple has gradually closed many of those attack vectors through security updates. However, the creators of Reaper have found a new approach.
Instead of abusing Terminal, the malware leverages Script Editor, a built-in macOS application that comes preinstalled on every Mac. Since most users rarely interact with it, few recognize the potential security risks it can pose.
Malicious websites can automatically launch Script Editor and display what appears to be a harmless script. In reality, the dangerous code is hidden among ASCII art, whitespace, and other elements that make it difficult for ordinary users to detect.
A single click on the Run button can be enough to give attackers access to the system.
Fake Websites Are Designed to Look Legitimate
The campaign relies on deceptive domains that closely resemble well-known companies and software platforms.
Security researchers have discovered websites using typo-squatting techniques, making them appear trustworthy at first glance.
Once the script is launched, victims are often presented with a fake Apple security update prompt requesting their Mac password.
This is the moment when attackers gain access to more sensitive areas of the system.
Interestingly, the malware first checks the device’s keyboard layout. If it detects a Russian-language configuration, the attack terminates immediately. This behavior is commonly observed in malware campaigns and may offer clues about the origin of the operators behind the attack.
Crypto Wallets and Password Managers Are Primary Targets
The malware's primary objective is to compromise cryptocurrency-related applications.
Reaper specifically targets popular wallets such as Ledger Live, Trezor Suite, and Exodus. According to researchers, it can manipulate internal wallet files and intercept future transactions.
Beyond crypto wallets, the malware also focuses heavily on web browsers.
It attempts to extract stored credentials from Chrome, Firefox, and Microsoft Edge while also harvesting data from browser extensions such as MetaMask and password managers like 1Password.
Cryptocurrency assets are not the only target.
Reaper Also Steals Sensitive Documents
Security analysis shows that the malware actively scans both Desktop and Documents folders for valuable files.
Among the targeted file types are:
Microsoft Word documents (.docx)PDF files (.pdf)Excel spreadsheets (.xlsx)Wallet backup files (.wallet)Private key and backup files (.keys)
The collected files are compressed into archives and transmitted to remote command-and-control servers operated by the attackers.
In some cases, Reaper also installs a hidden backdoor that allows long-term access to the device even after a system reboot.
The Third Similar Campaign in Just Weeks
According to cybersecurity experts, Reaper is not an isolated incident.
It represents the third major campaign in roughly two months that has adopted a similar AppleScript-based attack technique combined with social engineering tactics.
Researchers have also linked the activity to broader campaigns involving fake troubleshooting guides and fraudulent technical support content published across various web platforms. Those campaigns have been associated with other well-known malware families designed to steal cryptocurrency assets and sensitive personal information.
How Can Users Protect Themselves?
Security professionals recommend extreme caution when downloading software from unofficial sources.
Users should always verify website addresses before downloading applications and be highly suspicious of unexpected prompts requesting system passwords.
Particular attention should be paid to any website that asks users to open Script Editor or execute an unfamiliar script.
These tactics are becoming one of the primary delivery mechanisms for Reaper, a malware family that is increasingly targeting cryptocurrency investors using Apple devices.
#Apple , #CyberSecurity , #CryptoNews , #HackerAlert , #StaySafe
Stay one step ahead – follow our profile and stay informed about everything important in the world of cryptocurrencies.
Disclaimer:
The information and opinions presented in this article are for informational and educational purposes only and should not be considered financial or investment advice. Nothing on this page constitutes a recommendation to buy or sell any assets. Cryptocurrency investments are inherently risky and may result in financial loss. Always do your own research before making any investment decisions.
💸 While $ZEC and $HYPE keep tanking, the whale Loracle seems to be in serious trouble. Their long position on $ZEC (10x) has lost over $3.2 million, and their long position on $HYPE (2x) has lost $1.567 million. They're also holding long positions in $NEAR , $TON , $ASTER , and $XMR, with a total loss of $6.65 million. 🥷 #ZEC According to market data from Binance, ZEC is trading at $272.79, down 48.4% in the last 24 hours. CoinGlass data shows that ZEC liquidations totaled $81.91 million over the last 24 hours, including about $70.55 million in long liquidations and $11.36 million in shorts. Previously, co-founder of B1tM3X Arthur Hayes mentioned on X that he had sold all his ZEC position due to the Orchard Pool exploit. #hack 🗣 Jim Cramer says, "stop losing money and go to bed." 📉 Crypto trading activity continues to weaken, with spot trading volume dropping to its lowest monthly level since October 2023. As activity slows down, liquidity remains concentrated in a small group of exchanges. Gate is among the deepest places in both spot and perpetual futures markets, reinforcing its position as a major hub for large-scale execution. Institutional liquidity continues to consolidate around a handful of dominant exchanges. link 🐳 #AAVE After being inactive for 3 years, a whale with 38,554 $ETH ($64.28 million): - Supplied 20,000 $ETH ($33.28M) to Aave V3 - Borrowed $30M $USDT - Bought 17,826 $ETH at $1,683 (loop loan) - Now holds 56,380 $ETH ($94.04 million) The whale is likely to scoop up more ETH. #HackerAlert #ballenas #Twitter #crypto
💸 While $ZEC and $HYPE keep tanking, the whale Loracle seems to be in serious trouble. Their long position on $ZEC (10x) has lost over $3.2 million, and their long position on $HYPE (2x) has lost $1.567 million. They're also holding long positions in $NEAR , $TON , $ASTER , and $XMR, with a total loss of $6.65 million.

🥷 #ZEC According to market data from Binance, ZEC is trading at $272.79, down 48.4% in the last 24 hours.

CoinGlass data shows that ZEC liquidations totaled $81.91 million over the last 24 hours, including about $70.55 million in long liquidations and $11.36 million in shorts.

Previously, co-founder of B1tM3X Arthur Hayes mentioned on X that he had sold all his ZEC position due to the Orchard Pool exploit. #hack

🗣 Jim Cramer says, "stop losing money and go to bed."

📉 Crypto trading activity continues to weaken, with spot trading volume dropping to its lowest monthly level since October 2023.

As activity slows down, liquidity remains concentrated in a small group of exchanges. Gate is among the deepest places in both spot and perpetual futures markets, reinforcing its position as a major hub for large-scale execution.

Institutional liquidity continues to consolidate around a handful of dominant exchanges. link

🐳 #AAVE After being inactive for 3 years, a whale with 38,554 $ETH ($64.28 million):

- Supplied 20,000 $ETH ($33.28M) to Aave V3
- Borrowed $30M $USDT
- Bought 17,826 $ETH at $1,683 (loop loan)
- Now holds 56,380 $ETH ($94.04 million)

The whale is likely to scoop up more ETH.

#HackerAlert #ballenas #Twitter #crypto
🗣 #BTC The CEO of Franklin Templeton, Jenny Johnson, once called Bitcoin "the biggest distraction" from blockchain. Now she acknowledges its value in high-inflation economies. #macro 🇺🇸🧑‍💻 #MGUSD #XLM MoneyGram is launching MGUSD, a US dollar stablecoin based on Stellar. #stablecoin 🕵️‍♂️ 1,445.97 #BTC ($100,815,307) aggregated inflows on Binance. 🗣 The future is interoperability between stablecoins, tokenized bank deposits, CBDCs, and fiat, says Ken Moore, CIO of Mastercard, at Proof of Talk 2026. 💸 Pension-usdt.eth is truly a legendary trader! Two months ago, they got caught in their short positions on #BTC and #ETH, with unrealized losses over 20 million dollars. Five days ago, their short position at $ETH finally turned profitable, and they closed with a gain of 1.13 million dollars. Now, their short position of 1,400 $BTC (97.15 million $) is also back in the green. 🐳 A whale closed their long position on HYPE with a profit of 2.28 million dollars and has now switched to a short position on HYPE (5x) valued at 13.6 million dollars. They also sold 40,000 $HYPE for 2.85 million dollars and still hold 150,000 HYPE (~10.75 million dollars), with a cash profit of 6.4 million dollars. 🥷 PeckShieldAlert: 99 million #TSR have been minted and sold (-99%). The hacker has already redeemed #TSR for about 2.5 million USDT. #ballenas #HackerAlert #Inversiones #financial #crypto
🗣 #BTC The CEO of Franklin Templeton, Jenny Johnson, once called Bitcoin "the biggest distraction" from blockchain. Now she acknowledges its value in high-inflation economies. #macro

🇺🇸🧑‍💻 #MGUSD #XLM MoneyGram is launching MGUSD, a US dollar stablecoin based on Stellar. #stablecoin

🕵️‍♂️ 1,445.97 #BTC ($100,815,307)
aggregated inflows on Binance.

🗣 The future is interoperability between stablecoins, tokenized bank deposits, CBDCs, and fiat, says Ken Moore, CIO of Mastercard, at Proof of Talk 2026.

💸 Pension-usdt.eth is truly a legendary trader!

Two months ago, they got caught in their short positions on #BTC and #ETH, with unrealized losses over 20 million dollars.

Five days ago, their short position at $ETH finally turned profitable, and they closed with a gain of 1.13 million dollars.

Now, their short position of 1,400 $BTC (97.15 million $) is also back in the green.

🐳 A whale closed their long position on HYPE with a profit of 2.28 million dollars and has now switched to a short position on HYPE (5x) valued at 13.6 million dollars.

They also sold 40,000 $HYPE for 2.85 million dollars and still hold 150,000 HYPE (~10.75 million dollars), with a cash profit of 6.4 million dollars.

🥷 PeckShieldAlert: 99 million #TSR have been minted and sold (-99%).

The hacker has already redeemed #TSR for about 2.5 million USDT.

#ballenas #HackerAlert #Inversiones #financial #crypto
🐳 Blackrock deposited 929 $BTC (67.5 million dollars) and 36.449 $ETH (72.23 million dollars) in Coinbase and is likely to deposit more. 🐳 The high supply from long-term holders masks a bigger issue. The buyers who fueled this cycle are no longer accumulating. Whale balances are decreasing and dolphin growth continues to slide. Dive into the details. link 🥷 #BTC #ETH #SOL According to CertiK, losses from hacks on crypto platforms in May dropped to 68.3 million dollars, which is nearly 90% less than the 650 million lost in April. link 💸 A trader shorted 9 $btc for $981K 75 days ago and opened a long position in $FARTCOIN . Today, the position has been completely liquidated, resulting in a loss of $896K, leaving only $84.6K. #blackRock #ballenas #crypto #HackerAlert #Liquidations
🐳 Blackrock deposited 929 $BTC (67.5 million dollars) and 36.449 $ETH (72.23 million dollars) in Coinbase and is likely to deposit more.

🐳 The high supply from long-term holders masks a bigger issue.

The buyers who fueled this cycle are no longer accumulating.

Whale balances are decreasing and dolphin growth continues to slide.

Dive into the details. link

🥷 #BTC #ETH #SOL According to CertiK, losses from hacks on crypto platforms in May dropped to 68.3 million dollars, which is nearly 90% less than the 650 million lost in April. link

💸 A trader shorted 9 $btc for $981K 75 days ago and opened a long position in $FARTCOIN . Today, the position has been completely liquidated, resulting in a loss of $896K, leaving only $84.6K.

#blackRock #ballenas #crypto #HackerAlert #Liquidations
🚨 ON-CHAIN ALERT: $5.4M GRAVITY BRIDGE EXPLOIT 🚨 On-chain data shows the attacker drained roughly $5.4M from Gravity Bridge and has already started laundering funds through multiple transactions. 🔍 Key Findings: • A large portion of stolen assets was bridged and swapped. • The attacker still controls over $4.2M in ETH. • Funds remain traceable on-chain, making every move worth monitoring. This isn't over yet. The hacker is still sitting on millions in ETH, and the next wallet movements could reveal where the funds are headed next. Stay alert. Smart money watches the wallets before the headlines. #GUSDT #Onchain #CryptoAlert #HackerAlert #DeFiSecurity $G
🚨 ON-CHAIN ALERT: $5.4M GRAVITY BRIDGE EXPLOIT 🚨

On-chain data shows the attacker drained roughly $5.4M from Gravity Bridge and has already started laundering funds through multiple transactions.

🔍 Key Findings:

• A large portion of stolen assets was bridged and swapped.

• The attacker still controls over $4.2M in ETH.

• Funds remain traceable on-chain, making every move worth monitoring.

This isn't over yet.

The hacker is still sitting on millions in ETH, and the next wallet movements could reveal where the funds are headed next.

Stay alert. Smart money watches the wallets before the headlines.

#GUSDT #Onchain #CryptoAlert #HackerAlert #DeFiSecurity $G
🥷 Gravity Bridge got hacked for about 5.4 million bucks. The stolen assets got flipped for #ETH. Right now, the attacker still holds around 2,102 ETH (4.1 million dollars). 💼 Circle froze a contract from the Zama protocol, locking up 12.6 million in user funds. According to ZachXBT, this has raised questions about their ability to freeze on-chain assets. #Zama #Circle #ETH #HackerAlert #Inversiones $ZAMA $ETH
🥷 Gravity Bridge got hacked for about 5.4 million bucks. The stolen assets got flipped for #ETH.

Right now, the attacker still holds around 2,102 ETH (4.1 million dollars).

💼 Circle froze a contract from the Zama protocol, locking up 12.6 million in user funds. According to ZachXBT, this has raised questions about their ability to freeze on-chain assets.

#Zama #Circle #ETH #HackerAlert #Inversiones $ZAMA $ETH
🏢 The DTCC, the main market infrastructure in the U.S., announced it will enable asset tokenization on the Stellar network by 2027. This news pumped the price of the crypto XLM by 11%. ⛔️After the wave of hacks in April and May, "I now consider all DeFi to be unsafe. I've been privately advising friends and family to exit all positions in DeFi," stated Manual Aráoz, creator of OpenZeppelin. #DTCC #stellar #defi #OpenZeppelin #HackerAlert $XLM
🏢 The DTCC, the main market infrastructure in the U.S., announced it will enable asset tokenization on the Stellar network by 2027. This news pumped the price of the crypto XLM by 11%.

⛔️After the wave of hacks in April and May, "I now consider all DeFi to be unsafe. I've been privately advising friends and family to exit all positions in DeFi," stated Manual Aráoz, creator of OpenZeppelin.

#DTCC #stellar #defi #OpenZeppelin #HackerAlert $XLM
😱 A $3 million exploit cleaned out 86 wallets in under two hours on Ethereum and Base without stealing any private keys. The attacker exploited a vulnerability in an external module of Squid Router, according to Blockaid. 🎯 Hyperliquid dives into the prediction market game. The HIP-4 upgrade allows the creation of markets on real-world events directly within the Hyperliquid infrastructure, eliminating the need for external oracles to resolve outcomes. #Hyperliquid #hype #HackerAlert #ETH #Base $ETH $HYPE
😱 A $3 million exploit cleaned out 86 wallets in under two hours on Ethereum and Base without stealing any private keys. The attacker exploited a vulnerability in an external module of Squid Router, according to Blockaid.

🎯 Hyperliquid dives into the prediction market game. The HIP-4 upgrade allows the creation of markets on real-world events directly within the Hyperliquid infrastructure, eliminating the need for external oracles to resolve outcomes.

#Hyperliquid #hype #HackerAlert #ETH #Base $ETH $HYPE
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number