What we collected:
3,192 phishing domains
3,226 indicators published
74 wallets
Ledger was impersonated 277 times. Last week it was 29.
Sep 15, 2026 · 9:36 PM UTC
1
4
1,261
17 of 61 incidents this week involved compromised seed phrases or private keys. Root causes typically include: a compromised device, re-typing the seed into a fake wallet app, or exposing the seed to third-party storage.
The largest loss - $5.4M: a seed kept in cloud storage.
1
3
206
#DPRK intrusions this week:
Contagious Interview - $1.9M
IT worker hired onto the team - $500k
SINT-01 (Konni) - $480k
All three successful intrusions happened months before the theft occurred. DPRK actors persisted on developers' devices and infrastructure for an extended period. In the case of the DPRK IT worker, an insider leveraged his access to critical infrastructure and withdrew funds to his wallet..
#UNC1069 - a single incident with $0 loss
IOCs:
texmslives[.]com
tezmlives[.]com
tevmslives[.]com
microteamscall[.]com
usonliues[.]us
365lineup[.]com
1
1
8
2,395
This week's outlier involves fake wallet apps distributing Android APKs targeting Chinese users. In one case we tracked, the user lost ~$1M.
tronlinkwallet[.]cn
trustwallet-web3[.]cn
ledgerwallet-app[.]cn
imtoken-web3[.]cn
tokenpocket-web3[.]com[.]cn
binancewallet[.]com[.]cn
1
3
5
337
Misc fake meeting campaigns that could not be attributed.
gogglemeets[.]com
us04-web-zoom[.]us
workspace-zoommeeting[.]us
meetinglinvite[.]com
zoom[.]com[.]im
1
1
5
457
@SEAL_911 is free to anyone who needs it, and stays that way because people fund it. If this week's numbers are useful to you, fund the next one.
If you require a direct and more detailed data feed from @SEAL_Intel - talk to us.
securityalliance.org/donate
1
4
376



