
Phishing through email, newsletters and security alerts
Open the official app yourself or type the official domain into your browser manually. Go there directly. Do not let the email decide where you land.
MASTR · 2024–2026
From the first contact to the permission, key or device an attacker wants.
Many attacks begin outside the blockchain. A convincing interview invitation, a password-reset email or a compromised public account can move a person from a familiar service to an attacker-controlled workflow. The BlockLayerPod and BeaconLayerPod article follows that progression through the accounts, invitations and installation requests reported to MASTR. Read it alongside the account-compromise and reply-bot records to see how reputation is reused as bait.
Other failures occur in software people already trust. Browser extensions, dependencies, release pipelines and embedded signing systems can change the risk without changing the logo on screen. The Trust Wallet, Coldcard and agentic-finance publications examine different parts of that problem. A wallet connection, token approval, leaked session and exposed seed are different events; their consequences and the response they require should not be conflated.
The privacy series adds the information layer. Public transfers, exchange records, infrastructure logs and reused identities can connect activities that a user believed were separate. Its three original posts are presented together. Historical warnings describe the situation then; check the relevant product’s current guidance before acting on an old software version or incident report.
53 · Publicaciones seleccionadas · 1/3

Open the official app yourself or type the official domain into your browser manually. Go there directly. Do not let the email decide where you land.

What’s happening is simple: someone, (in this case most likely bots), triggers a password reset request through X’s public reset form. For that, the public username is enough. X then sends the reset email itself to the address linked to the…
If onchain evidence clearly documents a scam, theft or other crime, CEXs should be legally required to hand over the relevant KYC and transaction data to law enforcement when a valid legal request exists.
I’ll focus more heavily on bug bounties again. Unless this space decides that this public work, which depends entirely on support, matters enough to keep alive.
I’m being paid to perform full security assessments on 2 of them, while I gave another 5 only a rough 30-minute pass. Even at that depth, some of the vulnerabilities and basic security failures I found are frankly alarming.
Everyone forgets that those who became rich here, or have simply been around long enough to understand this market, took risks when everyone else had already declared it dead and buried.

Its Ministry of Digital Affairs said the operation came from overseas and combined manual hacking with AI agents such as OpenClaw.

Some of you have probably noticed this already: under certain accounts, almost every crypto-related tweet gets one of these bot replies within seconds.
A small reward and a large permission: AI-wallet access. Dated original source, with context and links.

1/2 This is my (crazy!) list of high-profile X accounts that were compromised and then used to promote memecoins, fraudulent tokens or related crypto scams.
Learn how scams work and study their methods, so you can move through life armed with knowledge instead of blind trust!
The FBI has arrested 21-year-old Zyaire Wilkins over an alleged operation that distributed malware through video games.

Calling every hardware wallet “garbage” because Ledger Live has poor UX confuses the frontend with the security boundary.

They are organised, patient, funded, technically serious and fully aware that crypto still runs on weak humans, lazy security, rushed integrations and teams that spend more on marketing than on infrastructure hardening.

Here is a summary of what appears to have happened with #BonkDAO. So you can verify it yourself, here is everything I found:

SecondFi is the rebranded Yoroi wallet, originally developed by Emurgo, one of Cardano’s founding entities alongside IOG and the Cardano Foundation.

A detailed investigation of interview invitations, impersonated podcasts and the attempt to compromise creators’ devices.
These systems are moving into the layers where modern society actually runs: code, cloud, identity, payment rails, financial markets, logistics, media, operating systems, cyber operations, hardware design and the information feeds through…

AI will multiply the scale, speed and precision of attacks, but the ugly truth is that many of these incidents are not some mysterious act of cyber warfare.
Private/ personal thoughts I would not want stored, processed, analysed, profiled, misunderstood, leaked, subpoenaed, monetised or used to build a better psychological map of me.

A "short" scientific breakdown of AI finance, agentic wallets and the problems nobody wants to think about yet, for those who occasionally still enjoy reading something longer: 👇
They want people to trust X with payments and cards even though the platform can barely stay functional 48h.
Sensitive information and AI services: MASTR’s privacy stance. Dated original source, with context and links.

A severe technical malfunction on the derivatives exchange Paradex caused the Bitcoin price to briefly display at 0 US dollars, triggering mass liquidations across the platform.