Tag: SlowMist

  • Altcoin Refuses to Freeze Assets Stolen from Bitget

    Altcoin Refuses to Freeze Assets Stolen from Bitget

    Key Highlights:

    • Attackers from the Bitget security incident are moving stolen funds across chains using THORChain, according to SlowMist’s MistTrack platform.
    • Bitget CEO Gracy Chen formally requested THORChain reject transactions from identified attacker addresses, arguing decentralization should not shield illicit fund flows.
    • THORChain responded that its permissionless design mirrors Bitcoin and Ethereum, questioning how much responsibility base-layer chains bear for processing known stolen assets.

    Bitget Hackers Leverage THORChain for Cross-Chain Laundering, On-Chain Data Shows

    Blockchain security firm SlowMist has confirmed that addresses linked to the recent Bitget security breach are actively utilizing THORChain to bridge and exchange stolen assets across multiple networks. The firm’s on-chain tracking platform, MistTrack, reported that the attackers have initiated cross-chain transactions through the decentralized liquidity protocol, a pattern that mirrors the movement of roughly $1.2 billion in funds stolen during the Bybit exploit earlier this year. MistTrack emphasized that the attacker addresses have been publicly identified and are under active surveillance by industry participants.

    Debate Intensifies Over Decentralized Protocol Accountability

    The development has reignited a contentious industry debate regarding the obligations of decentralized protocols when processing proceeds from known hacks. MistTrack argued that the principle of decentralization should not serve as an automatic justification for facilitating the movement of demonstrably stolen funds. The platform called for an industry-wide discussion on the responsibility protocols like THORChain should bear in such scenarios, suggesting that technical neutrality cannot fully absolve infrastructure providers of ethical or reputational considerations when handling illicit flows at scale.

    Bitget CEO Demands Protocol-Level Intervention

    Following MistTrack’s disclosure, Bitget CEO Gracy Chen issued a formal appeal to THORChain, urging the protocol to reject transactions originating from the flagged addresses. Chen stated that the addresses associated with the attackers had been publicly shared and were still being actively monitored. She contended that while decentralization is a foundational design principle, it should not be seen as “a shield to facilitate the movement of stolen funds with known origins.” Her statement underscores a growing expectation among centralized exchanges that decentralized infrastructure should implement screening or blocking mechanisms for sanctioned or hack-linked addresses.

    THORChain Defends Permissionless Architecture

    THORChain responded to the criticism by reaffirming its commitment to a decentralized and permissionless operational model, drawing a direct parallel to base-layer networks such as Bitcoin, Ethereum, and BNB Chain. While expressing regret over the Bitget attack, the team posed a rhetorical challenge: “How much responsibility should Bitcoin, Ethereum, and $BNB Chain bear when processing known stolen funds?” The response frames the issue as a systemic characteristic of censorship-resistant networks rather than a protocol-specific failing, resisting calls for transaction-level filtering.

    Why This Matters

    The clash between Bitget and THORChain highlights a deepening fault line in the crypto ecosystem: the tension between the ethos of permissionless, censorship-resistant infrastructure and the practical demands of asset recovery and regulatory compliance. As cross-chain bridges become critical arteries for liquidity—and for laundering—pressure is mounting on decentralized protocols to adopt some form of on-chain screening without compromising their core architecture. The outcome of this debate could shape future standards for bridge governance, influence how regulators treat decentralized protocols, and determine whether “code is law” remains an absolute defense when stolen funds traverse public rails.

    Frequently Asked Questions

    What is THORChain and why are hackers using it?

    THORChain is a decentralized cross-chain liquidity protocol that enables native asset swaps between blockchains without wrapped tokens. Its permissionless design allows anyone to move funds across chains—including Bitcoin, Ethereum, and BNB Chain—without KYC or centralized approval, making it attractive for laundering stolen assets.

    Can THORChain technically block the hacker addresses?

    THORChain’s architecture is designed to be censorship-resistant; validators process transactions based on consensus rules, not identity. Implementing an address blocklist would require a governance vote and protocol upgrade, which contradicts its permissionless ethos and could set a precedent for future interventions.

    Has this happened before with other major hacks?

    Yes. SlowMist’s MistTrack previously documented that a significant portion of the approximately $1.2 billion stolen in the Bybit attack was also routed through THORChain, indicating a recurring pattern of high-profile exploit proceeds flowing through the same cross-chain infrastructure.

  • Cryptocurrency App Secretly Steals Assets — Delete Immediately

    Cryptocurrency App Secretly Steals Assets — Delete Immediately

    Key Highlights

    • Blockchain security firm SlowMist, in collaboration with the OKX security team, discovered malicious code in FomoPeek versions 1.1 and 1.2 designed to steal private keys, seed phrases, and Keychain data from iOS devices.
    • The malware includes an exploit framework targeting iOS kernel vulnerabilities across versions 12.0 through 18.7 and 26.0–26.1, capable of bypassing sandbox protections and automatically selecting from eight attack methods based on device model.
    • SlowMist urges all affected users to immediately migrate assets to a new wallet generated on a clean device, update iOS to the latest version, and permanently cease using FomoPeek.

    SlowMist Uncovers Supply-Chain Attack in FomoPeek iOS App

    Blockchain security company SlowMist has issued a critical alert revealing that versions 1.1 and 1.2 of the FomoPeek application contain malicious code engineered to exfiltrate users’ private keys, seed phrases, login credentials, and other sensitive data stored in the iOS Keychain. The discovery followed reports from multiple FomoPeek users who experienced unexplained asset theft, prompting a joint forensic investigation by SlowMist and the OKX security team.

    Exploit Framework Targets Broad iOS Version Range

    According to SlowMist’s technical analysis, the compromised application bundles an exploit framework wholly unrelated to FomoPeek’s stated functionality. This framework specifically targets kernel vulnerabilities in Apple’s iOS operating system, supporting eight distinct attack vectors. The malware automatically fingerprints the victim’s device model and iOS version to select the appropriate exploit, enabling it to bypass the iOS sandbox and decrypt Keychain contents.

    The affected iOS versions span a remarkably wide range: iOS 12.0 through 18.7, as well as the newly released iOS 26.0 and 26.1. This coverage suggests the attackers maintained and updated their exploit chain over an extended period, potentially impacting millions of devices that have not applied the very latest security patches.

    Active Command-and-Control Infrastructure

    SlowMist researchers further determined that FomoPeek communicates with hidden command-and-control (C2) servers not associated with any legitimate public service. Analysis of intercepted unencrypted network traffic indicates the attack functions remain active and execute automatically at regular intervals, meaning the threat is ongoing and not merely a dormant payload.

    Why This Matters

    This incident represents a sophisticated supply-chain compromise targeting cryptocurrency users through a seemingly legitimate application. The breadth of iOS versions exploited underscores the persistent value of kernel-level vulnerabilities to threat actors and the difficulty of defending against zero-day or n-day exploits once they are weaponized in widely distributed software. For the crypto ecosystem, the case highlights the critical importance of verifying application integrity, using hardware wallets for significant holdings, and maintaining rigorous device hygiene. The collaboration between SlowMist and OKX also demonstrates the growing role of exchange security teams in threat intelligence sharing and incident response.

    Frequently Asked Questions

    Which FomoPeek versions are confirmed compromised?

    Only versions 1.1 and 1.2 have been identified as containing the malicious exploit framework and data-exfiltration code.

    What should I do if I installed FomoPeek 1.1 or 1.2?

    Immediately check your wallet for unauthorized transactions. Using a trusted device on which FomoPeek was never installed, generate a new private key and mnemonic phrase, then transfer all assets to the new wallet. Update your iPhone or iPad to the latest iOS version, delete FomoPeek, and do not reinstall it.

    Does updating iOS alone fix the problem?

    Updating iOS patches the kernel vulnerabilities used by the exploit, preventing future Keychain decryption. However, if your private keys or seed phrases were already stolen, the attacker retains control of the associated wallets. You must rotate credentials on a clean device as described above.

  • SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Hiding StealC Info-Stealer

    SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Hiding StealC Info-Stealer

    A malware campaign disguised as downloadable model weights for Alibaba’s Qwen 3.8 27B AI model has targeted GitHub users who run open-source artificial intelligence models locally. SlowMist’s security team reported the threat on August 28, warning that the malicious files can steal credentials and other sensitive data.

    Fake Qwen AI model hosted on GitHub

    The fraudulent GitHub repository was designed to look like an official download page for Qwen, promising users a fully offline AI model that would keep their data private. However, the repository’s file size revealed the deception.

    The ZIP archive was just 487 KB, or less than half a megabyte. A genuine AI model with 27 billion parameters typically requires more than 16 GB of storage.

    Named uncensored_qwen_v2.6.zip, the malicious archive was created on August 20, 2026. Four days later, the attackers modified the repository’s README file so that every download link led directly to the harmful ZIP file.

    Alibaba’s legitimate Qwen project was not affected by the incident.

    StealC malware targets passwords and crypto wallets

    The archive contained three files: a command file, an executable program and a script disguised as a certificate. The executable was a renamed version of a LuaJIT interpreter, a tool commonly used by game engines. While the interpreter itself is not inherently dangerous, the fake certificate script uses it to deliver StealC malware.

    Once active, StealC collects the infected computer’s system name, username, machine ID and Windows version. It also captures a screenshot and sends the stolen information to an attacker-controlled server.

    The malware can additionally target browser login credentials, cookies, browsing history, email passwords and cryptocurrency wallet data.

    The attackers added a fallback mechanism that retrieves a backup server address from a smart contract on the Polygon blockchain. If the primary server is taken offline, the attackers can change the malware’s server location without updating the code on infected computers.

    Growing number of malicious AI repositories

    SlowMist identified at least 23 other GitHub repositories and 29 similar ZIP files that used the same Lua-based delivery chain.

    Island.io separately discovered and reported a campaign called FakeGit, which has been active since March 2025. The campaign has reportedly created around 7,600 malicious GitHub repositories and generated more than 14 million download events.

    About 800 of those repositories specifically impersonate AI-related tools. They use a technique called AgentBaiting, which can even persuade AI assistants to recommend the malicious projects.

    Cryptopolitan reported in January that Alibaba’s genuine models had surpassed 700 million downloads on Hugging Face, more than any other open-source AI system.

    In late June, at least 292 GitHub repositories copying well-known brands were flagged. Those repositories distributed BoryptGrab, a malware strain capable of stealing data from 32 cryptocurrency wallets and 19 web browsers.

    Separately, security firm InfoStealers described another automated campaign called Megalodon, which created more than 5,000 fake repositories in only six hours.

    How attackers make fake GitHub projects look legitimate

    Cybercriminals are increasingly copying legitimate projects, creating convincing README pages and using stolen developer identities to make malicious repositories appear authentic. They also list the fake projects in public AI directories such as LobeHub and Glama, increasing their visibility and credibility.

    Cryptopolitan previously reported a similar tactic in which the StopAndProtect operation turned nearly 2,000 compromised WordPress websites into traps for cryptocurrency users.

    Island.io said the malicious repositories are designed to exploit the growing demand for AI capabilities.