Recent Cryptocurrency Cyber Attacks

Attacks on crypto exchanges, wallet providers, and web3 projects, where phishing pages and fake airdrops drain funds in minutes. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Fake Detective Tried to Steal Crypto Seed Phrase

Fake Detective Tried to Steal Crypto Seed Phrase

A scammer called Graham Cluley while spoofing the real Crime Stoppers phone number and posed as a police detective investigating cybercrime. The caller tried to build trust, claimed to have evidence tied to Cluley (including a passport scan), and steered the conversation toward his Trezor hardware…

August 6, 2026
Fake Job Interviews Used to Breach 1,600 Firms

Fake Job Interviews Used to Breach 1,600 Firms

A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions,…

August 6, 2026
Poipet Scam Ring Used ChatGPT for Romance & Fines

Poipet Scam Ring Used ChatGPT for Romance & Fines

OpenAI says it disrupted a Cambodia-based scam network operating from Poipet that used ChatGPT to scale romance, investment, gambling, and law-enforcement impersonation scams. The group used messaging apps to build trust, then pressured victims to pay deposits, activation fees, or fake fines,…

August 5, 2026
“I’m Allowed” Excuse Bypasses AI Safety Checks

“I’m Allowed” Excuse Bypasses AI Safety Checks

Cisco Talos reports that real threat actors are using AI coding assistants and chatbots to support scams and hacking workflows by bypassing safety guardrails with simple “authorized use” claims. The logs show attackers persuading models that activity is allowed (e.g., ownership/bug bounty/CTF…

August 5, 2026
Fake Sparrow Wallet App Stole $1.8M via App Store

Fake Sparrow Wallet App Stole $1.8M via App Store

A lawsuit alleges a counterfeit “Sparrow Wallet” app was allowed to remain in Apple’s App Store for months, leading investors to lose about $1.8M in Bitcoin. Victims reportedly entered their wallet “seed phrases” into the fake app, letting the scammer take over their funds. The case is a reminder…

August 4, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake IRS Letters Push Crypto Users to QR Scam

Fake IRS Letters Push Crypto Users to QR Scam

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call.…

August 4, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026
Fake China Police App Tied to Android RAT Ring

Fake China Police App Tied to Android RAT Ring

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal…

July 31, 2026
Lazarus-Linked Lures Hit Korea via Surveys & Sites

Lazarus-Linked Lures Hit Korea via Surveys & Sites

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South Korean organizations. The campaign used compromised legitimate websites (watering-hole attacks) and spearphishing emails, including messages…

July 30, 2026
AI Chatbots Outperform Humans in Romance Scams

AI Chatbots Outperform Humans in Romance Scams

Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long…

July 30, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake iPhone Wallet App Stole $1.8M in Bitcoin

Fake iPhone Wallet App Stole $1.8M in Bitcoin

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow Wallet. The victims trusted the app because it was available in the App Store, then entered their wallet “seed phrase” into the counterfeit…

July 30, 2026
Fake Job Interview Lure Targets Crypto Staff

Fake Job Interview Lure Targets Crypto Staff

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can…

July 30, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake “FBI Agents” Target Scam Victims in DMs

Fake “FBI Agents” Target Scam Victims in DMs

The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into…

July 21, 2026
Fake Web3 Job Interviews Push “ClickFix” Malware

Fake Web3 Job Interviews Push “ClickFix” Malware

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead…

July 21, 2026
Fake Dev Alias Got Into MetaMask Codebase

Fake Dev Alias Got Into MetaMask Codebase

A suspected North Korean IT worker allegedly got hired by Consensys (MetaMask’s parent) using an alias and contributed to MetaMask’s core wallet code for about a month. The person was later removed, and Consensys says an investigation found no stolen assets, no data theft, and no malicious code…

July 20, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo