Bitget Wallet reassures users that their self-custodial assets remain secure following a security incident at Bitget Exchange, emphasizing the wallet operates independently. A separate post highlights that wallet security alone is insufficient; users must also practice good security habits like protecting seed phrases, verifying websites, and avoiding phishing attacks.
A user discusses crypto wallet privacy and phishing vulnerabilities on public blockchains, highlighting how address reuse and hex-string copying enable attacks. They describe Americanfort_io's three-layer privacy solution: FortressName for readable identities, Send-to-Name for one-time addresses, and SafeSend for selective transaction disclosure, while acknowledging the product remains in beta development.
A crypto Twitter user recommends six browser extensions that enhance X functionality for cryptocurrency traders and enthusiasts, including tools for wallet tracking, reputation checking, scam detection, and trading intelligence. The extensions help users identify phishing attempts, view linked wallets, and monitor account activity before engaging with potentially risky interactions.
A cryptocurrency privacy service called FortressName allows users to register a single name to receive funds across multiple blockchains while mapping each payment to a fresh stealth address, reducing exposure to phishing and wallet history tracking. The service provider Americanfort_io is promoting the platform at cryptocurrency conferences in Seoul and Singapore in October 2026.
Bitget exchange suffered a $351.6M hack on September 24, 2026, with unauthorized transfers from hot and warm wallets. The exchange claims its Protection Fund covers the loss, though withdrawals remain frozen while the incident is investigated. The post also discusses address poisoning risks in crypto transactions and mentions Americanfort_io's alternative security approach using unique stealth addresses.
RemControl, a new Android banking malware-as-a-service platform, targets users in Europe and Canada through malvertising campaigns impersonating the TVTap IPTV app. The malware uses over 30 phishing overlays to steal banking credentials and can perform remote actions including screenshot capture and keystroke logging. It evades detection by blocking Google Play Protect and uses Telegram channels to dynamically rotate its command-and-control infrastructure.
Two X users discuss AmericanFortress, a privacy infrastructure platform that replaces complex crypto wallet addresses with human-readable @names while generating unique stealth addresses for each transaction to reduce phishing risk and enhance on-chain privacy.
A social media post highlights security and privacy issues in cryptocurrency transactions, including address poisoning and phishing attacks, and promotes Americanfort_io as a wallet solution that uses stealth addresses and FortressNames to enable private transactions without exposing balances or transaction history.
The placeholder domain third-party.com, widely used in developer documentation as an example hostname, is now serving ClickFix attacks that impersonate Cloudflare verification pages to trick Windows users into executing malicious PowerShell commands. Unlike IANA-reserved documentation domains, third-party.com is a normally registered domain whose owner can control its content, creating a security vulnerability for developers who copy example code literally.
Dutch intelligence services AIVD and MIVD, along with five other organizations, warn that AI is making cyberattacks faster and easier by automating attacks and lowering barriers for malicious actors. They urge businesses and institutions to strengthen cybersecurity measures, keep systems updated, monitor networks, and invest in employee awareness and training.
Nano Labs founder Jack Kong's X account was hacked and used to post phishing links impersonating a new crypto project. Users are warned not to connect wallets or sign transactions from the compromised account without official verification.
Passkeys are digital keys that replace passwords, using your device's biometric or PIN verification to securely sign in without transmitting passwords. Each service gets a unique passkey based on public key cryptography, protecting against password reuse, theft, and phishing attacks.
AmericanFortress promotes Send-to-Name technology that generates unique stealth addresses for transactions to prevent address poisoning and phishing attacks while maintaining privacy between sender and recipient.
Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.
Anthropic faces mounting CVEs with limited attacker response, while the tech industry navigates AI model releases, security vulnerabilities in enterprise software, and evolving cybersecurity threats including ransomware and phishing campaigns.
A social media post discusses Tangem's cryptocurrency hardware wallet ecosystem, explaining self-custody concepts and how Tangem's products—wallet cards, rings, apps, and payment solutions—integrate security with practical everyday usage for crypto users.
Microsoft disrupted EvilTokens, an AI-powered subscription scam platform that compromised 12,000 accounts across 10,000 organizations globally. The platform, introduced via Telegram in February, charged $1,500 upfront plus $500 monthly, using an AI chatbot to analyze victim inboxes and recommend fraud strategies. Microsoft seized 50 websites and 150 domains, and UK police arrested two suspects.
A user warned about receiving a suspicious unsolicited crypto interview pitch on X from an account that requested credentials through a Google Sites link with an Apps Script login flow, exhibiting multiple phishing indicators.
A crypto user lost $20,000 from their MetaMask wallet after being socially engineered by scammers posing as NPR's "The Indicator" podcast. The attackers gained credentials through a fake interview, compromised multiple accounts, and drained the wallet containing funds from a newly launched $JERRY token on Robinhood Chain.
Microsoft is retiring SMS and voice as first-factor authentication methods for Entra ID starting February 2027, requiring administrators to migrate users to phishing-resistant alternatives like passkeys, FIDO2 security keys, or QR code authentication. The company has already ended SMS sign-in for free tenants and is rolling out passkeys as the default authentication method. Organizations must complete migration before the deadline to avoid sign-in disruptions.