Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
Malone Lam's plea hearing approaches in the $240 million bitcoin social engineering theft; the case highlights surging crypto fraud and limited enforcement.
Malone Lam, accused of organizing a social engineering attack that stole over $240 million in bitcoin (4,100+ BTC) from a Washington, D.C. resident in August 2024, has a plea agreement hearing set. Callers impersonating Google and Gemini staff tricked the victim into revealing security codes. Lam and 17 co-defendants spent lavishly before FBI arrests; crypto investment fraud complaints to the FBI rose nearly 50% in 2025 while DOJ disbanded its crypto crimes unit.
HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
Hijacked HBO Max verified Reddit account ran 108 ClickFix malvertising ads delivering AMOS and Amatera stealers plus crypto clippers to macOS and Windows users.
Threat actors hijacked HBO Max's verified Reddit account (u/hbomax) to run 108 malicious ClickFix ads over 48 hours in a campaign tracked as PasteSwitch, researched by Hudson Rock and ADAMnetworks. macOS victims were served curl | zsh chains deploying MacSync and Atomic macOS Stealer (AMOS), which harvest browser credentials, Telegram data, Apple Notes, and macOS passwords, while fake Ledger, Trezor, and Exodus apps targeted BIP39 seed phrases. Windows users received an InstallFix chain using an MP3/HTA polyglot with mshta and PowerShell, scheduled-task persistence, AMSI disabling, and in-memory Amatera Stealer that hid C2 traffic (77.91.65.13:443) behind a facebook.com TLS SNI. AnimateClipper and ZigClipper components swapped copied crypto wallet addresses and used Binance Smart Chain contracts as mutable C2 dead drops; Reddit paused the ads and the initial access path remains undisclosed.
‘White hat’ hackers take $47 million bounty after $320 million crypto theft
Hackers withdrew $320 million in bitcoin from Liquid Network, negotiated on-chain, returned $266.5 million and kept a $47 million reward.
Purported white-hat hackers withdrew 4,000 BTC (about $320 million) from Liquid Network's own wallet, one of the largest cryptocurrency thefts of 2026. Over roughly 12 hours of public on-chain negotiation with operator Blockstream, the hackers returned $266.5 million in bitcoin and kept 598.5 BTC (about $47 million), claiming it as a reward for uncovering a bug. Blockstream deployed updated software and paused deposits and withdrawals while experts traced the flaw to the Elements sidechain framework. April thefts of $290 million from Kelp and $280 million from Drift, attributed to North Korean hackers, were previously 2026's largest.
We've got one word for it, and it's usually the wrong one
Cisco Talos's Threat Source newsletter critiques 'burnout' terminology, describing four occupational injuries, and flags a UAT-10820 WebDAV stealer campaign at a Ukrainian government organization.
Cisco Talos's Threat Source newsletter argues that 'burnout' is the wrong word for most cybersecurity occupational harm, distinguishing exhaustion, secondary traumatic stress, vicarious trauma, and moral injury based on clinical literature from trauma-exposed professions. The featured disclosure describes a complex WebDAV infection chain found at a Ukrainian government organization, attributed with moderate confidence to the Russian-tracked actor UAT-10820 and assessed as an opportunistic cryptocurrency and credential-stealing operation. The campaign delivers the Amatera stealer alongside ZigCryptoStealer and NetSupport Manager, abusing BNB Smart Chain bulletproof hosting, fake CAPTCHA prompts, a vulnerable driver to kill EDR, and rundll32.exe execution of disguised DLLs with ordinal calls. Weekly headlines also cover a Microsoft Defender 'ShieldCrash' zero-day exploit released after September 2026 Patch Tuesday, a North Korean Linux espionage toolkit backdooring HAProxy, and a multi-hop Google-domain redirect phishing campaign.
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Attackers compromised 120 Brevo email accounts and sent convincing phishing emails to Trezor, BitBox, and CoinTracking newsletter subscribers.
Trezor, BitBox, and CoinTracking confirmed that phishing emails were sent to newsletter subscribers after a compromise of their shared email provider, which CoinTracking identified as Brevo. Brevo said an attacker accessed 120 customer accounts and used them to send phishing emails from legitimate company domains, including fake security alerts like 'Critical Security Alert: STM32 Entropy Vulnerability' and 'Data Breach Notice: Please refresh API Keys.' Trezor had already suffered a separate breach exposing details of 81,000 customers, and CertiK reports physical wrench attacks on crypto holders rose 33 percent year-over-year with $124 million in losses in 2026.
Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.
Cisco Talos tracks a ClickFix-style campaign that tricks cryptocurrency traders into pasting JavaScript into Chrome's address bar or a Tampermonkey extension, promising fake bonuses on SwapZone and SimpleSwap. The loader pulls obfuscated JavaScript from cells in a public Google Sheet via the Visualization API, then behaves like a web skimmer, rewriting deposit addresses on screen, in web responses, and in the clipboard. Researchers counted 49 attacker-controlled Bitcoin addresses, with 24 receiving a combined 0.159 BTC, roughly $10,000, by early August 2026. A Tampermonkey variant re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts.
Party’s over for scammers who went on spending spree after $240M bitcoin theft
AP report on scammers' spending spree after a $240 million bitcoin social engineering theft, as ringleader Malone Lam nears a plea agreement.
DataBreaches.net syndicates AP reporting on the $240 million bitcoin theft from a Washington, D.C. resident via social engineering calls impersonating Google and Gemini. Alleged ringleader Malone Lam, 22, faces a plea hearing; the scam network spent stolen funds on cars, jets, and mansions before FBI arrests. Crypto investment fraud complaints to the FBI rose nearly 50% in 2025.