The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Investment Banking/Venture
Breach intelligence, attack campaigns, and threat reports targeting the Investment Banking/Venture sector.
Explore Other Sectors
Investment Banking/Venture Threat Reports
North Korean Hackers Steal $351.6M from Bitget in Sophisticated Backend Compromise
On September 24, 2026, cryptocurrency exchange Bitget suffered a massive security breach resulting in the theft of $351.6 million from hot and warm wallets. Suspected North Korean threat actors compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. The attack affected multiple cryptocurrency assets including ETH, XRP, BNB, AVAX, USDT, and USDC across seven different blockchain networks. While customer account balances remained accurate and trading continued normally, withdrawals were temporarily suspended as a precautionary measure during the ongoing investigation. This incident highlights the continued escalation of North Korean state-sponsored cryptocurrency theft operations, representing one of the largest single exchange compromises in 2026. The sophisticated backend compromise demonstrates evolving attack techniques that bypass traditional security controls, emphasizing the urgent need for enhanced infrastructure protection and transaction authorization mechanisms in the rapidly growing digital asset sector.
5 hours ago
Kill Chain
RatHat Malware: The Dawn of AI-Powered Android Banking Trojans
RatHat is a sophisticated Android banking trojan discovered in September 2026 that represents a significant evolution in mobile malware capabilities. Developed by Chinese threat actors, the malware combines traditional Android Remote Access Trojan (RAT) functionality with artificial intelligence-powered interface automation. RatHat spreads through malvertising campaigns, SMS phishing, and fraudulent APK downloads outside Google Play Store. The malware exploits Android's Accessibility permissions to enable Developer Options and Wireless Debugging, establishing persistent shell-level access through dual Go-based agents that provide mutual restoration capabilities. What makes RatHat particularly dangerous is its AI-powered navigation system that serializes Android's Accessibility tree into XML and leverages external AI assistants to intelligently navigate device interfaces, making remote control operations more adaptive than traditional script-based automation. The malware targets banking and cryptocurrency applications with HTML overlays, intercepts SMS messages and notifications for OTP theft, and employs sophisticated anti-removal mechanisms including fake Google Play error messages. This incident highlights the emerging convergence of AI technology with cybercriminal operations, representing a new paradigm where malware can adapt and respond to user interface changes in real-time without requiring constant operator intervention or frequent code updates.
1 week ago
Kill Chain
Revolut's 2026 Social Engineering Breach: When Trust Becomes a Vulnerability
In September 2026, fintech giant Revolut disclosed a targeted social engineering attack where threat actors impersonated a government agency to fraudulently obtain sensitive customer data. The attackers used valid domain authentication credentials to request personally identifiable information via email, successfully deceiving Revolut into sharing financial records, passport copies, transaction histories, and account details of high-net-worth customers. The company immediately blocked the fraudulent address and notified relevant authorities upon discovering the deception, though the exact number of affected customers remains undisclosed. This incident highlights the growing sophistication of social engineering attacks targeting financial institutions and the critical need for enhanced verification protocols when handling government data requests, particularly as threat actors increasingly exploit trusted communication channels to bypass security controls.
1 week ago
Kill Chain
Trezor's Third-Party Email Provider Breach Exposes 347,000 Users to Cryptocurrency Phishing Campaign
In September 2026, cryptocurrency hardware wallet manufacturer Trezor disclosed a sophisticated phishing campaign targeting 347,000 users following a breach of their third-party email provider Brevo. Threat actors compromised Brevo's systems and sent convincing phishing emails claiming a critical hardware vulnerability in Trezor devices, tricking 2,500 users into clicking malicious links before the campaign was shut down within 20 minutes. This incident represents Trezor's third major security breach in recent years, following previous compromises of their support portal and shipping provider. This attack demonstrates the evolving sophistication of supply chain targeting, where attackers compromise trusted third-party service providers to reach high-value cryptocurrency users with credible social engineering tactics.
1 week ago
Kill Chain
Critical Alby Hub Vulnerability Exposed Bitcoin Wallets to Complete Takeover
In September 2026, Bitcoin wallet company Alby disclosed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5 that allowed attackers to completely take over internet-exposed Lightning wallets and drain funds. The flaw affected self-hosted Bitcoin wallets where owners had inadvertently exposed their Hub management interfaces to the public internet, often following Alby's own documentation that recommended such configurations. At least one user was confirmed affected, with the company providing limited details about the vulnerability mechanism pending responsible disclosure. The incident highlights the ongoing security challenges in cryptocurrency infrastructure, particularly as Bitcoin adoption accelerates and self-custody solutions become more mainstream. With ransomware groups increasingly targeting cryptocurrency platforms and the rise of state-sponsored attacks on financial infrastructure, vulnerabilities in wallet software present critical risks to both individual users and the broader digital asset ecosystem.
2 weeks ago
Kill Chain
Liquid Network Suffers $320M Bitcoin Theft Through Elements Software Vulnerability
In September 2026, unknown attackers claiming to be white hat hackers exploited a vulnerability in the Elements software powering Liquid Network's Bitcoin sidechain, withdrawing nearly 4,000 bitcoin worth approximately $320 million. The attackers used a bug in Elements to create unauthorized L-BTC tokens and then executed a peg-out transaction through SideSwap's authorization key, draining 95% of Liquid's bitcoin reserves. After communicating with Blockstream through encrypted messages embedded in Bitcoin transactions, the attackers returned 3,400 bitcoin but retained approximately 598.5 bitcoin worth $47 million. This incident highlights the growing sophistication of cryptocurrency protocol attacks and the blurred lines between legitimate security research and extortion in the DeFi ecosystem, particularly as Bitcoin layer-2 solutions become increasingly targeted by threat actors.
2 weeks ago
Kill Chain
Phantom Deal Campaign Exploits M&A Processes in Sophisticated Enterprise Fraud
The 'Phantom Deal' campaign represents a sophisticated evolution of advance fee scams targeting large enterprises through fake merger and acquisition proposals. Threat actors conducted extensive reconnaissance on companies like Gen (Norton/Avast parent company), impersonating executives via WhatsApp and creating fraudulent documentation from legitimate firms like PwC. The attackers attempted to trick employees into authorizing substantial financial transfers, with one attempt involving €626,735.45, by leveraging detailed corporate intelligence and social engineering tactics that exploited M&A processes and confidentiality requirements. This campaign highlights the growing sophistication of business email compromise attacks as threat actors increasingly target high-value corporate transactions. With M&A activity remaining robust and remote work normalizing digital-only communications, similar social engineering campaigns pose escalating risks to enterprise financial controls and decision-making processes.
3 weeks ago
Kill Chain
Cronos Blockchain Halts After $74M Tectonic Protocol Exploit
In August 2026, the Cronos blockchain network experienced a devastating $74 million exploit targeting the Tectonic DeFi lending protocol. Attackers artificially inflated the price of Tectonic's TONIC token by 100 times within 20 minutes, then used it as collateral to borrow legitimate assets. While the total exploit value reached $74 million, attackers only managed to extract approximately $6 million in Ethereum before Cronos validators executed an emergency consensus halt, freezing the blockchain to prevent further damage. The incident reduced Tectonic's total value locked from $122 million to under $3 million. This incident highlights the growing sophistication of DeFi price manipulation attacks and demonstrates how attackers are exploiting oracle vulnerabilities and lending protocol weaknesses to execute large-scale thefts. The rapid response by blockchain validators represents an evolution in DeFi incident response capabilities, though it raises questions about decentralization versus security trade-offs.
3 weeks ago
Kill Chain
Provenance Blockchain State Divergence: $500K DeFi Vulnerability Analysis
In March 2026, Trail of Bits discovered a critical vulnerability in Provenance Blockchain, a Cosmos SDK-based financial services platform, that allowed any user to grant themselves admin control over marker accounts without holding tokens. The bug affected 82 markers representing live financial assets worth approximately $500,000, including validator incentive funds and community grant programs. Exploitation required only two transactions: one to gain admin permissions through a flawed authorization check, and another to either mint new tokens or drain escrowed assets. This incident highlights the growing risks in blockchain application security as DeFi and tokenized assets become mainstream. State synchronization vulnerabilities in smart contract platforms represent a critical attack vector that can bypass traditional access controls.
1 month ago
Kill Chain
CopyCop's Disinformation Campaigns Against Armenia's Firebird AI Data Center in 2026
Between June 24 and July 13, 2026, the Russian influence network known as CopyCop (Storm-1516) orchestrated a series of disinformation campaigns targeting the Firebird AI data center in Hrazdan, Armenia. These campaigns disseminated false narratives, including fabricated earthquake threats, doubts about the facility's economic viability, and claims that the data center was a legitimate military target. The reach of these narratives expanded significantly, culminating in over 1.6 million combined views by the third instance, indicating a growing audience engagement as the campaign progressed. This incident underscores the increasing use of coordinated disinformation campaigns by state-affiliated actors to undermine strategic infrastructure projects. The targeting of a major AI initiative highlights the vulnerability of emerging technologies to such operations, emphasizing the need for robust information security measures and public awareness to counteract misinformation.
1 month ago
Kill Chain
Ukraine's Crackdown on 94 Fraudulent Call Centers in 2026
In August 2026, Ukrainian authorities conducted a large-scale operation resulting in the shutdown of 94 fraudulent call centers across the country. These centers engaged in various schemes, including posing as bank officials to extract sensitive financial information and luring victims into fake investment platforms. The coordinated effort involved 411 searches and led to the seizure of significant assets, including $2 million in cash, 64,000 euros, and 1 kilogram of gold. Additionally, 26 individuals were formally identified as suspects in connection with these fraudulent activities. This incident underscores a growing trend of sophisticated social engineering attacks targeting individuals and organizations. The scale and coordination of these fraudulent operations highlight the urgent need for enhanced cybersecurity measures and public awareness to combat such threats effectively.
1 month ago
Kill Chain
COLDCARD Phishing Attack Leads to Remote Access Installation
In August 2026, a sophisticated phishing campaign targeted COLDCARD hardware wallet users by impersonating official communications. Attackers sent emails claiming a security audit was necessary due to recent vulnerabilities, directing recipients to a fraudulent website to download a diagnostic tool. This tool installed ScreenConnect remote access software, granting attackers control over victims' computers, potentially leading to data theft or further malware deployment. This incident underscores the evolving nature of phishing attacks, which are becoming more targeted and convincing. The exploitation of recent security concerns to deceive users highlights the critical need for continuous vigilance and education on recognizing and avoiding such threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports