News linked to both this project and an event.
Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.
the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)
leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)
Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.