The week was rich in cybersecurity events directly affecting the crypto community. From sentencing hackers to detecting sophisticated malware targeting seed phrases, we break down the key trends and threats.
Scattered Spider Verdict: A Precedent for the Entire Industry
Key members of the notorious Scattered Spider group, 20-year-old Talha Jubair and 18-year-old Owen Flowers, received real prison sentences of five years and six months. Their attack on the IT infrastructure of Transport for London (TfL) in August 2024 led to the collapse of 148 internal systems and damages of £29 million. Had the hackers managed to paralyze the entire transport network, losses to the UK economy could have reached £56 billion. This is a serious signal for all cybercriminals: even youth and audacity will not save them from justice, especially when the safety of millions of citizens is at stake.
A New Wave of Threats for macOS: Session Theft and Wallet Spoofing
An infostealer for macOS, thoroughly analyzed by experts, demonstrates a comprehensive approach to stealing cryptocurrencies. The malware doesn't just steal passwords from keychains or cookie files. It intercepts authorized Telegram Desktop sessions, bypassing two-factor authentication, and, most dangerously, replaces legitimate applications for hardware wallets Ledger Live and Trezor Suite with their phishing copies. The goal is to extract the seed phrase. Dozens of wallets have been affected, including Exodus, Electrum, and full Bitcoin Core node clients. The only way to protect yourself is to urgently terminate all Telegram sessions and generate a new seed phrase on a clean device.
GitHub as a Breeding Ground for Infostealers: 300 Fake Repositories
A large-scale campaign to distribute a modified version of the BoryptGrab stealer affected GitHub. Hackers created 292 fake repositories, masquerading as popular antivirus and crypto services. Users were lured to phishing landing pages offering a ZIP archive download, the contents of which were updated every minute to evade signatures. The malware, operating exclusively in RAM, stole data from 19 browsers, 32 crypto wallets, and local messenger sessions. Its ability to bypass Google Chrome's protection by directly injecting code into the browser process poses a particular danger.
OkoBot and SeedHunter: Hunting Hardware Wallets
The OkoBot framework, targeting Windows, represents a new milestone in the evolution of malware. Its SeedHunter module doesn't just spoof an application; it injects malicious code directly into the processes of legitimate Ledger Live and Trezor Suite. It activates only when a hardware wallet is physically connected to the PC, after which it displays a fake window demanding the seed phrase. This is an extremely dangerous tactic, as the user sees the request from within the official program. The framework also includes keyloggers and hidden screen recording when password managers are opened.
Browser Wallets in the Crosshairs of Tracking: A Privacy Issue
A study of 85 popular browser-based crypto wallets revealed a systemic privacy issue. The architecture of most allows third-party trackers to link user addresses, monitor their movements, and de-anonymize their identity. 17 wallets transmitted data enabling different addresses to be combined into a single profile, while 36 disclosed their presence to websites. The response from developers, including MetaMask and Rabby, was mixed, ranging from refusing to acknowledge the problem to classifying the risks as low. This is a reminder that wallet security is not limited to protecting against theft of funds—the privacy of your transactions and identity is also at risk.
Expert Analysis
This week demonstrates a worrying trend: attackers are increasingly targeting not only software but also hardware wallets, using social engineering and spoofing legitimate software. The market urgently needs stricter security standards for browser extensions and desktop applications, and users need increased vigilance and regular checks of their active sessions.