Researchers discovered 474 leaked GitHub App private keys still active, including one committed to the CDC's official repository in April 2025 that provided write access to CDC systems for 17 months. The compromised key granted potential code execution capabilities in the CDC's Azure environment and was revoked on September 18.
Rita Crypto Tips discusses distributed key generation (DKG) as a security approach that eliminates single points of failure in cryptocurrency systems. DKG allows multiple participants to collectively control a private key without any one party holding the full secret, reducing risks from compromised devices, insider threats, and key leaks. The post highlights Rialo's implementation combining DKG with threshold cryptography for applications like multisig wallets, institutional custody, validators, and bridges.
Security researchers discovered that FomoPeek versions 1.1–1.2, distributed through Apple's App Store, contained an iOS kernel-exploit framework capable of escaping the sandbox, decrypting Keychain data, and stealing cryptocurrency private keys and seed phrases. Nearly $580,000 in USDT was traced to a primary attack address, highlighting the vulnerability of storing complete cryptographic authority on a single compromised device.
On September 20, 2026, attackers exploited smart contracts for Fetch.ai and NuNet after compromising private keys used by both projects. The attacker drained approximately 8.7 million ethereum tokens worth $2M and illegally minted over 408 million NTX tokens by leveraging missing security controls in the conversion contracts.
SlowMist reported a ~$2M loss from Fetch.ai due to a compromised private key used to authorize a TokenConversionManagerV3 contract. The attacker exploited missing security checks in the conversionIn() function to drain the bridge's entire FET balance in a single transaction.
A major iOS security incident involving the FomoPeek app exposed cryptocurrency wallet private keys through malicious code identified by SlowMist and OKX researchers. The app versions 1.1 and 1.2 contained an iOS kernel exploitation framework capable of escaping sandbox protections and accessing Keychain data, leading to multiple reported crypto thefts. Binance Wallet advised affected users to immediately delete the app, update iOS, and transfer assets to new wallets.
SlowMist and OKX security teams discovered that FomoPeek App versions 1.1–1.2 contain malicious code including an iOS kernel exploitation framework capable of escaping sandboxes and accessing private keys and sensitive data. The affected iOS versions range from 12.0–18.7 and 26.0–26.1, with users advised to check accounts, create new wallets, and stop using the app immediately.
Revolut confirmed a data breach involving stolen customer information after attackers exploited fraudulent requests from a spoofed government email account. Threat actors demanding $3 million in XMR have publicly announced the extortion, though Revolut denies receiving direct contact; the post discusses how Internet Computer's threshold cryptography and canister-based authorization could prevent similar attacks through distributed key management and policy-enforced workflows.
A social media post discusses security tips for protecting AI agents from being hacked, addressing concerns about private key compromise.