The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Investment Banking/Venture
Breach intelligence, attack campaigns, and threat reports targeting the Investment Banking/Venture sector.
Explore Other Sectors
Investment Banking/Venture Threat Reports
Uranium Finance's 2021 Smart Contract Exploits: A DeFi Cautionary Tale
In April 2021, Uranium Finance, a decentralized exchange on Binance's BNB Chain, suffered two significant security breaches. On April 8, an attacker exploited a flaw in the smart contract's 'AmountWithBonus' variable, enabling unauthorized withdrawals totaling approximately $1.4 million. The attacker then coerced the platform into labeling a portion of the stolen funds as a 'bug bounty' in exchange for returning the remainder. On April 28, a separate vulnerability—a single-character coding error—was exploited, allowing the attacker to drain nearly $53.3 million from the platform's liquidity pools. This second attack forced Uranium Finance to cease operations, leaving users without recourse. These incidents underscore the critical importance of rigorous smart contract auditing and secure coding practices in the rapidly evolving DeFi sector. The substantial financial losses and operational disruptions highlight the vulnerabilities inherent in decentralized platforms and the necessity for continuous security assessments to protect user assets.
5 months ago
Kill Chain
Axios npm Package Compromise: A Wake-Up Call for Open-Source Security
In late March 2026, attackers compromised the npm account of a lead maintainer of the widely-used JavaScript library Axios, publishing malicious versions 1.14.1 and 0.30.4. These versions included a trojanized dependency, 'plain-crypto-js', which executed a cross-platform Remote Access Trojan (RAT) upon installation, affecting Windows, macOS, and Linux systems. The malicious packages were live for approximately three hours before removal, during which time they were potentially downloaded by numerous developers, given Axios's extensive use in the JavaScript ecosystem. ([securitylabs.datadoghq.com](https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The rapid deployment and widespread adoption of compromised packages highlight the need for enhanced security measures in package management and distribution processes to prevent similar future breaches.
5 months ago
Kill Chain
Torg Grabber: The Infostealer Targeting Cryptocurrency Wallets
In March 2026, cybersecurity researchers identified 'Torg Grabber,' a sophisticated infostealer malware targeting 728 cryptocurrency wallet browser extensions. The malware gains initial access through the 'ClickFix' technique, hijacking the clipboard to execute malicious PowerShell commands. Once inside, Torg Grabber exfiltrates sensitive data from 25 Chromium-based browsers and 8 Firefox variants, including credentials, cookies, and autofill data. It also targets 103 password managers and two-factor authentication tools, as well as 19 note-taking applications. The malware employs advanced evasion tactics, such as multi-layered obfuscation and reflective loading, to remain undetected. ([asec.ahnlab.com](https://asec.ahnlab.com/en/92902/?utm_source=openai)) The rapid development and deployment of Torg Grabber underscore a growing trend in the cyber threat landscape: the convergence of infostealers and ransomware. This evolution highlights the increasing sophistication of cybercriminals and the urgent need for organizations to enhance their security measures to protect sensitive data and digital assets. ([cyfirma.com](https://www.cyfirma.com/research/the-convergence-of-infostealers-and-ransomware-from-credential-harvesting-to-rapid-extortion-chains/?utm_source=openai))
6 months ago
Kill Chain
UniPass Wallet's 2023 Account Abstraction Vulnerability: A Critical Security Lesson
In October 2023, Fireblocks researchers identified a critical vulnerability in UniPass's ERC-4337 smart contract wallets, allowing attackers to take full control by replacing the trusted EntryPoint. This flaw exposed hundreds of wallets to potential fund drainage. The UniPass team promptly executed a white-hat operation to secure all affected wallets and implemented necessary fixes to prevent future exploits. This incident underscores the importance of rigorous security audits in the rapidly evolving landscape of smart contract wallets. As account abstraction gains traction, ensuring the integrity of foundational components like EntryPoint is paramount to safeguard user assets.
6 months ago
Kill Chain
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
In February 2026, the U.S. Department of Justice (DoJ) seized over $61 million in Tether (USDT) linked to 'pig butchering' cryptocurrency scams. These schemes involved fraudsters building trust with victims through fake romantic relationships, then persuading them to invest in fraudulent cryptocurrency platforms that displayed fabricated high returns. When victims attempted to withdraw funds, they were met with demands for additional fees, leading to further financial loss. The seized funds were traced to cryptocurrency addresses used to launder proceeds from these scams. ([justice.gov](https://www.justice.gov/usao-ednc/pr/us-attorneys-office-ednc-announces-seizure-61-million-dollars-worth-cryptocurrency?utm_source=openai)) This incident underscores the growing prevalence of sophisticated social engineering tactics in financial fraud, particularly within the cryptocurrency sector. It highlights the need for increased vigilance and regulatory measures to protect individuals from such deceptive practices.
6 months ago
Kill Chain
CEO Deepfake Scam 2019: A Wake-Up Call for Corporate Security
In March 2019, a UK-based energy firm's CEO was deceived by a deepfake audio impersonation of his German parent company's chief executive. The fraudster, using AI-generated voice technology, instructed the CEO to transfer €220,000 (approximately $243,000) to a Hungarian supplier's account. Believing the request was legitimate, the CEO complied. Subsequent attempts for additional transfers raised suspicions, leading to the discovery of the scam. The initial funds were moved from Hungary to Mexico and then dispersed to other locations, making recovery challenging. ([forbes.com](https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/?utm_source=openai)) This incident underscores the escalating threat of AI-driven deepfake technologies in corporate fraud. As these tools become more sophisticated and accessible, organizations face increased risks of impersonation attacks targeting financial transactions and sensitive information. The event highlights the urgent need for enhanced security measures and employee training to detect and prevent such advanced social engineering tactics.
7 months ago
Kill Chain
Abu Dhabi Finance Week 2026 Data Breach: A Cloud Misconfiguration Exposes VIP Passport Details
In early February 2026, Abu Dhabi Finance Week (ADFW) experienced a significant data breach due to a misconfigured cloud storage environment managed by a third-party vendor. This misconfiguration exposed scans of over 700 passports and identity cards belonging to high-profile attendees, including former British Prime Minister David Cameron and U.S. investor Anthony Scaramucci. The breach was discovered by cybersecurity researcher Roni Suchowski, who found that the sensitive documents were publicly accessible without password protection. Upon notification, ADFW promptly secured the environment and stated that access activity was limited to the researcher who identified the issue. The incident underscores the critical importance of securing cloud storage configurations to prevent unauthorized access to sensitive information. ([techradar.com](https://www.techradar.com/pro/security/abu-dhabi-finance-summit-exposes-personal-data-passport-info-of-hundreds-of-major-global-figures?utm_source=openai)) This breach highlights the ongoing risks associated with cloud misconfigurations, which continue to be a leading cause of data exposure. As organizations increasingly rely on cloud services, ensuring proper configuration and regular security audits is essential to protect sensitive data and maintain trust with stakeholders.
7 months ago
Kill Chain
Fake Gemini AI Chatbot Drives Google Coin Scam in 2026
In February 2026, cybercriminals launched a sophisticated scam involving a counterfeit AI chatbot impersonating Google's Gemini assistant to promote a fictitious cryptocurrency called 'Google Coin.' The fraudulent website, designed to mimic Google's branding, featured a chatbot that engaged users with convincing investment projections, claiming that a $395 investment could yield $2,755 upon listing. Victims were guided through a polished presale dashboard to make irreversible cryptocurrency payments, resulting in significant financial losses. ([malwarebytes.com](https://www.malwarebytes.com/blog/ai/2026/02/scammers-use-fake-gemini-ai-chatbot-to-sell-fake-google-coin?utm_source=openai)) This incident underscores the escalating use of AI-driven social engineering tactics in cybercrime. The ability of scammers to deploy AI chatbots that convincingly impersonate trusted brands highlights the urgent need for enhanced vigilance and verification mechanisms to protect consumers from such deceptive schemes.
7 months ago
Kill Chain
Operation DoppelBrand: Unveiling GS7's Credential Harvesting Tactics
Between December 2025 and January 2026, the GS7 cyberthreat group executed Operation DoppelBrand, a sophisticated phishing campaign targeting Fortune 500 companies, primarily in the financial sector. By creating near-identical replicas of corporate login portals, GS7 successfully harvested employee credentials, enabling unauthorized remote access to sensitive systems. The group registered over 150 malicious domains, utilizing services like NameCheap and Cloudflare to obscure their infrastructure, and exfiltrated stolen data via Telegram bots. This campaign underscores the evolving tactics of cybercriminals in credential harvesting and the critical need for robust cybersecurity measures. The incident highlights the increasing prevalence of brand impersonation in phishing attacks, emphasizing the necessity for organizations to implement advanced detection mechanisms and employee training to mitigate such threats.
7 months ago
Kill Chain
Bybit's 2025 Security Breach: A Deep Dive into the $1.4 Billion Ethereum Theft
In February 2025, Dubai-based cryptocurrency exchange Bybit suffered a significant security breach, resulting in the theft of approximately 401,000 Ethereum (ETH), valued at over $1.4 billion. The attackers exploited vulnerabilities in Bybit's multi-signature cold wallet system, facilitated by compromised infrastructure at Safe{Wallet}, a third-party provider. This incident stands as the largest cryptocurrency exchange hack to date. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Bybit?utm_source=openai)) The breach was attributed to the North Korean state-sponsored Lazarus Group, known for their sophisticated cyber operations targeting financial institutions. The stolen funds were laundered through various channels, including privacy-focused platforms, complicating recovery efforts. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Lazarus_Group?utm_source=openai))
7 months ago
Kill Chain
CIRO 2023 Data Breach Exposes Sensitive Data of 750,000 Canadian Investors
In late 2023, the Canadian Investment Regulatory Organization (CIRO) disclosed that a cyberattack compromised the personal and financial data of approximately 750,000 Canadian investors. The breach, involving unauthorized access to sensitive investor information, stemmed from an attack on a third-party IT provider responsible for maintaining the data. The breach's detection and subsequent investigation prompted CIRO to initiate notification procedures with impacted individuals and regulatory bodies. The incident highlighted critical weaknesses in third-party vendor security, raising concerns about the protection of confidential financial data within the regulated investment sector. This event is particularly relevant as it underscores a growing trend of attacks targeting regulatory and financial organizations via supply chain vectors. With increasing regulatory scrutiny and heightened risks from third-party service providers, organizations face renewed pressure to modernize data protection strategies and enforce robust vendor risk management frameworks.
8 months ago
Kill Chain
Malicious Chrome Extension Breach Drains MEXC Crypto Accounts via API Key Theft
In January 2026, cybersecurity researchers uncovered a malicious Chrome extension called "MEXC API Automator" targeting users of the MEXC cryptocurrency exchange. Deployed via the Chrome Web Store, the extension masqueraded as a legitimate trading tool to covertly generate new API keys on behalf of users, surreptitiously enabling withdrawal permissions. It then exfiltrated these sensitive credentials to a Telegram bot controlled by the attacker, granting potential full access to victims' MEXC accounts, including the ability to automate trades and drain balances. The campaign leveraged authenticated browser sessions, evading traditional credential protections, and tampered with the user interface to conceal its malicious activity. This incident highlights a sophisticated shift in attack vectors targeting API workflows and browser sessions, rather than direct password theft. It underscores urgent risks inherent in trusted browser extensions, particularly as infostealers increasingly exploit the digital supply chain and cryptographic asset platforms.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports