River Financial Inc. has sued Blockstream Services Canada ULC for breach of contract, seeking roughly $6.7 million that River alleges has remained unpaid under an agreement terminating the companies' commercial relationship. River filed the complaint in the Northern District of California on September 11. The case names Blockstream Services Canada ULC, not Blockstream Corp, as the sole defendant and requests a jury trial. The disputed amount consists of approximately $3.55 million in prepaid refunds and a separate $3.15 million early…
Lazarus Group
Bitget Confirms $351.6M Wallet Breach and Suspends Withdrawals
Bitget has confirmed approximately $351.6 million in unauthorized transfers from portions of its wallet infrastructure after detecting abnormal activity at 18:31 UTC on September 24. The exchange said the $351.6 million incident was contained to parts of its hot and warm wallet layers under a three-tier custody system. Its cold wallets were not affected. Bitget activated its emergency response process within minutes, identified and flagged addresses connected to the transfers and notified law-enforcement agencies and onchain security firms. Withdrawals Paused…
3 days ago
Lazarus-Linked Wallets Move $30M Through Hyperliquid as U.S. Entry Talks Advance
Wallets linked to North Korea’s Lazarus Group moved more than $30 million through Hyperliquid over the past three weeks, with activity continuing through August 31 as the onchain derivatives platform moves closer to a potential regulated U.S. entry. More than $30 million passed through the identified wallet cluster using Hyperliquid’s HyperUnit infrastructure. The addresses had previously been connected to Lazarus by ZachXBT in 2024 through activity involving about $61 million in stolen funds. Bitcoin Moves Into ETH and SOL Before…
4 weeks ago
North Korea-Linked BlueNoroff Uses Fake Zoom Calls To Profile Crypto Wallets
North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to identify cryptocurrency wallets before choosing which victims receive malware. JUMPSEC recovered the source code behind an active phishing kit after its operators left JavaScript source maps exposed on live infrastructure. The files revealed an operator-controlled system combining hijacked Telegram accounts, fake meeting pages, wallet reconnaissance and malware delivery. The campaign begins when a compromised Telegram account belonging to a genuine industry contact sends a meeting invitation.…
2 months ago
Humanity And KelpDAO Exploit Funds Comingle As ZachXBT Flags Possible Attacker Overlap
Funds from the Humanity Protocol and KelpDAO exploits have commingled onchain, creating new evidence that may point to overlap between the attackers behind the two incidents. Onchain investigator ZachXBT flagged the fund commingling and linked it to a Bitcoin transaction that joined value connected to both exploit paths. The movement does not by itself prove that the same attacker carried out both breaches, but it creates a stronger shared-infrastructure signal than the earlier Humanity Protocol evidence alone. The new link…
3 months ago
UXLINK Exploiter Sends 3,700 ETH Through Tornado Cash
Wallets tied to the UXLINK exploit have transferred 3,700 ETH into Tornado Cash, moving another large portion of the stolen funds beyond the attacker’s publicly visible wallet cluster. The latest onchain movement marks a shift from asset management into direct obfuscation. The deposits do not erase the transaction history, but they break the simple link between the exploit wallets and the addresses that eventually receive the funds, narrowing the options available to exchanges, investigators and the project. The Ethereum was…
3 months ago
North Korea-Linked Hackers Drove 76% Of 2026 Crypto Hack Losses
Two Attacks Changed The 2026 Hack Table North Korea-linked hackers have accounted for 76% of all crypto hack losses in 2026 through April, according to new research from TRM Labs. The figure is not the result of dozens of smaller attacks. It comes from two huge incidents that overwhelmed the rest of the year’s exploit data. TRM placed the combined stolen value at about $577 million, split between the Drift Protocol exploit on April 1 and the KelpDAO bridge exploit…
5 months ago



