Founder of @SlowMist_Team // 分身一号/捉虫大师/救火运动员 // 🕖灾备频道 t.me/greyhatcos

HACKING
这行业割韭菜的行为越多,诈骗越多,跑路越多,黑客事件只会越多,一些有能力的黑客决不允许在“聪明”赚钱这块输过这般人。
506
22
602
241,066
Cos(余弦)😶‍🌫️ retweeted
针对Bitget被盗事件,又一次让我想起来我们开源的这份文档,cex可以参考。
来自 NexVault 的《Web3.0 加密货币交易所安全风险指南精编》总结了顶级交易平台可能面对的风险 —— 技术 + 管理 + 人为,全链防控一览。 📄 指南: github.com/nexvault/CEX-Secu… #CryptoSecurity #CexCrypto #Web3
4
22
9,355
Cos(余弦)😶‍🌫️ retweeted
Tether banned the wallet owned by the bitget exploiter etherscan.io/tx/0xdd30e4831e…
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
12
15
158
55,881
Cos(余弦)😶‍🌫️ retweeted
🚨 Unauthorized NFT transfers observed via Limit Break's Payment Processor on Ethereum and ApeChain. If you've approved Payment Processor on any chain, revoke it as a precaution. Cancelling listings doesn't remove the approval. V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 V3: 0x9a1d00000000fc540e2000560054812452eb5366 Per @0xQuit, NFTs in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 are held by a whitehat and expected to be returned.
1
6
27
5,848
Cos(余弦)😶‍🌫️ retweeted
最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。 其他几点都是说过的,我再强调一下: -我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。 -Bitget Wallet 为自托管钱包,运行于与 Bitget Exchange 完全分离且独立的基础设施之上,未受此次事件影响。 -Bitget Exchange 平台的充值交易奖励等功能都继续正常运行。在我们完成额外安全核查期间,提币功能暂时暂停;待我们确认可以安全恢复后,将尽快恢复提币。 -我们明白在此类事件发生时,用户希望尽快获得答复。我们将通过Bitget官方渠道及时发布最新进展。请关注我的和@bitget @xiejiayinBitget 的 X账号以及Bitget官方公告。
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
240
54
497
164,681
Cos(余弦)😶‍🌫️ retweeted
We’re working closely with @bitget on the ongoing investigation. For further details, please refer to Bitget’s official updates.
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
7
10
78
16,207
来自 @SpecterAnalyst 的链上分析关联出朝鲜黑客历史上的有关资金。另外,这次手法上确实和之前朝鲜黑客相关组织的手法类似,包括资金归集习惯… 更多信息见 Bitget 官方披露就好,我们在协同调查中。
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
11
15
90
47,103
补充下:链上部分我们有更直接的证据指向朝鲜黑客。
1
5
2,926
Cos(余弦)😶‍🌫️ retweeted
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
14
59
77,058
Cos(余弦)😶‍🌫️ retweeted
All hacker addresses have been tagged. We’re actively monitoring fund transfers and expanding our blacklist. We remain fully committed to combating illicit transactions.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
1
1
24
8,242
Cos(余弦)😶‍🌫️ retweeted
今天凌晨2:31 Bitget安全系统监测到部分热钱包出现异常转账。安全团队在第一时间启动应急响应机制。 一、已确认的情况: 1、初步评估涉及金额约3.516亿美金 2、冷钱包及平台绝大部分资产完整,未受影响 3、用户资金安全。本次损失金额完全在Bitget用户保护基金覆盖范围之内(保护基金当前规模逾4.64亿美元) 二、已采取的措施: 1、事件发生后数分钟内启动应急响应小组 异常转账地址已标记并上报 2、出于资金安全考虑,提币功能暂时关闭,待安全核查完成后有序恢复 3、已通知执法机构及链上安全机构介入调查 三、对您意味着什么: 1、您的账户余额准确,资产受到保护 2、充币和交易功能正常运行 3、提币暂时关闭,安全核查完成后将第一时间恢复 四、后续安排: 我们将以小时级别持续更新,请关注官方平台公告。我们将在24小时内发布完整事件报告,包括根本原因分析与整改措施。在调查结论明确前,我们不会对攻击方式进行任何猜测。 🙏Bitget 走过了多轮牛熊,我们不会回避本次事件——每一笔资金、每一个决策,我们都会向大家如实交代。后续进展将第一时间同步。安心!
479
111
1,008
992,469
Cos(余弦)😶‍🌫️ retweeted
🚨 SlowMist TI Alert 🚨 MemTensor's AI memory tooling has been compromised: MemoryOS (PyPI), the company's open-source long-term memory library for LLM and AI agents, and memtensor/memos-cloud-openclaw-plugin (npm), the official plugin connecting it to the OpenClaw agent runtime. Affected versions bundle cross-platform Go binaries that execute when the package is loaded or imported: MemoryOS==2.0.34 on PyPI, and plugin versions 0.1.21, 0.1.23 and 0.1.25 on npm. You are affected if the PyPI version has been imported in your environment, or if the npm plugin is installed and the OpenClaw gateway has been started. Potential attacker actions include harvesting npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, environment secrets, and other developer credentials, with data sent to infrastructure under skyleen[.]fr. The affected npm plugin may also expose user prompt content. Users should remove or downgrade affected packages to known-good versions (0.1.20 for npm and 2.0.33 for PyPI), terminate sckit processes, block associated infrastructure, review network activity, and rotate credentials accessible from affected environments. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. Reference: aikido.dev/blog/supplychain-… As always, stay vigilant! enterprise.misteye.io/threat…
9
8
23
8,795
Cos(余弦)😶‍🌫️ retweeted
🚨 Duelbits hot wallets on Ethereum, BSC and Tron saw ~$4.2M in outflows to newly created addresses, in a suspected private key compromise. Assets moved included 836 ETH, 1.62M USDT, 97K USDC, 209 BNB and 192K TRX. Most have since been swapped to ETH. Duelbits (EVM): 0x014435b1e39945cf4f5f0c3cbb5833195a95cc9b Duelbits (Tron): THqFmhAPcdHECH3wmrpZv4MWAB2v9TY1oN Hacker (EVM): 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76 Hacker (Tron): TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK
11
10
87
42,686
Cos(余弦)😶‍🌫️ retweeted
Thanks to @Cointelegraph for covering our investigation into the FomoPeek App Store poisoning and iOS kernel exploitation, conducted together with the @wallet security team. 🫡 We appreciate the opportunity to share our findings and help users better understand the risks and recommended response. 🌟 Read more 👉: cointelegraph.com/news/fomop…
7
4
22
7,780
是 FomoPeek…我们从来没说过是 FOMO 这个 App,我们发现是海外相关安全 KOL 及媒体自己搞错了,然后国内媒体参考了海外媒体的新闻源🫣…
卧槽 好嗨哟 到底是FOMO 还是FomoPeek ? @SlowMist_Team @evilcos 原文链接: theblockbeats.info/flash/368…
10
2
41
20,163
Cos(余弦)😶‍🌫️ retweeted
‼️ BREAKING: An app on Apple's official App Store was serving iPhone users malware designed to steal crypto wallet keys. SlowMist and OKX found FomoPeek versions 1.1 and 1.2, distributed Sept 9–17, hid a kernel exploit framework built to escape the iOS sandbox, decrypt the Keychain and pull data from 19 apps, including MetaMask, Trust Wallet and Apple Notes. SlowMist traced nearly 580,000 USDT to the attacker's main wallet.
45
199
1,524
183,426
Cos(余弦)😶‍🌫️ retweeted
我也收到了!非常感谢@evilcos @SlowMist_Team
收到了来自慢雾 @SlowMist_Team 的中秋礼盒~ 中秋快乐🥰
2
1
14
6,038
Cos(余弦)😶‍🌫️ retweeted
⚠️ Security Alert: FomoPeek v1.1-1.2 A joint investigation by our security team and @SlowMist_Team has found malicious code in FomoPeek App versions 1.1–1.2 that may expose private keys, seed phrases, credentials, and other sensitive data on iOS devices. If you've installed or used these versions: • Stop using FomoPeek immediately • Create a new wallet with new keys on a trusted device where FomoPeek was never installed • Transfer your assets to the new wallet as soon as possible • Update iOS to the latest available version • Check your accounts for suspicious activity If you detect unauthorized activity, contact the relevant platform's official support team and retain the affected device and evidence for investigation. Protect your keys. Stay vigilant.
29
28
116
48,600
Cos(余弦)😶‍🌫️ retweeted
据慢雾披露,发生一起针对 Web3 求职者的招聘投毒攻击。攻击者冒充 Web3 公司,以远程面试为由要求候选人在本地部署并运行名为 RoyalCity 的项目,运行或构建项目后可窃取浏览器凭证、钱包扩展数据和本地文件,监控剪贴板,并实现远程控制。慢雾称,该项目还在 errorHandler js 中植入服务端后门,可下载并执行远程代码;其攻击方式与此前 GitHub 招聘投毒事件高度相似。 wublock123.com/news/slowmist…
1
2
5
6,032
Cos(余弦)😶‍🌫️ retweeted
Replying to @SlowMist_Team
@SlowMist_Team confirmed that FomoPeek App versions 1.1–1.2 contained malicious code capable of stealing private keys and seed phrases from crypto wallet apps on the device. If you ever installed it on your iPhone, stop using the app and check whether you were affected.
🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the @okx, @OKXWallet_CN security team. Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that #FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore. Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection. 🧵👇
14
20
162
27,282
Cos(余弦)😶‍🌫️ retweeted
🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retrieves and executes remote code. This case closely resembles the recruitment-themed GitHub poisoning attack we previously analyzed, sharing the interview lure, execution through Tailwind, and highly similar payloads for data theft and remote access. Our previous analysis (slowmist.medium.com/threat-i…) provides more detail on this attack pattern. 🔍 IOCs Malicious IP: 144[.]172[.]107[.]50 Malicious domain: server-azure-tau[.]vercel[.]app URLs: hxxp://144[.]172[.]107[.]50:8085/upload hxxp://144[.]172[.]107[.]50:8086/upload ws://144[.]172[.]107[.]50:8087 hxxps://server-azure-tau[.]vercel[.]app/api/ipcheck-encrypted/604 Malicious dependency/repository reference: bitbucket:https://bitbucket[.]org/poc_review58/demoroyalcity Malicious files — SHA-256: tailwind.config.js 62a98662f2f84001edd71b68e8fa318140c750ba9af096f5e4c9a0bb5502eb6e errorHandler.js d6705f52757af8bc2708a39647fc8c34dc02ffab7838a1d9c10fd44cfe9a7081 ⚠️ Verify recruiters independently. Review unfamiliar projects before running them, and keep interview tasks isolated from your everyday development environment, wallets, and sensitive credentials. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. As always, stay vigilant! enterprise.misteye.io/threat… Thanks to @jhh_kh37332 for sharing the lead.
8
12
34
8,766