The past week in the world of cybersecurity has been eventful. We witnessed several landmark events: from the sentencing of key figures in the notorious Scattered Spider group to the discovery of sophisticated malware targeting seed phrases from hardware wallets. Let's break down the key moments that everyone keeping a finger on the pulse of the crypto industry should know.
Scattered Spider Verdict: A Precedent or a Temporary Measure?
A British court sentenced two members of the hacker group Scattered Spider — Talha Jubaer (20 years old) and Owen Flowers (18 years old). They each received five and a half years in prison for hacking the IT infrastructure of Transport for London (TfL) in August 2024. This attack, which paralyzed transport for 8.4 million people and disabled 148 internal systems, caused £29 million in damages. Authorities estimated that a complete shutdown of the transport network could have cost the UK economy up to £56 billion.
Notably, this is not the group's only crime. The investigation established Jubaer's involvement in hacking at least 120 networks in the US, including critical infrastructure facilities. Over the year, from August 2024 to July 2025, he and his accomplices extorted over $115 million from victims worldwide. This verdict is an important signal, but it is just the tip of the iceberg. Scattered Spider remains one of the most serious cyber threats, and combating such groups requires global coordination.
New Attack Vector: macOS Malware and OkoBot Targeting Hardware Wallets
Particular attention was drawn to two new types of malware demonstrating the evolution of crypto asset theft methods. The first is an infostealer for macOS that not only steals Telegram sessions, bypassing 2FA, but also replaces legitimate applications for managing hardware wallets (Ledger Live and Trezor Suite) with phishing copies. Its goal is to trick the user into revealing their seed phrase. Dozens of wallets were affected, including Exodus, Atomic, Electrum, and full node clients.
The second, the OkoBot framework targeting Windows, uses the SeedHunter module. Its uniqueness lies in the fact that it doesn't just replace an application but injects malicious code directly into the processes of already installed Ledger Live and Trezor Suite. The module activates only when the user physically connects the hardware wallet to the PC, displaying a fake window for entering the seed phrase over the original interface. This is an extremely dangerous tactic, as the attack originates from within a trusted application, lulling the victim's vigilance.
Massive Network of Fake Repositories on GitHub
Experts discovered a network of 292 fake repositories on GitHub, disguised as popular antivirus software, utilities, and crypto services. Each repository led to a phishing landing page that dynamically adapted to the brand the victim was searching for. The downloaded ZIP archive contained a modified version of the BoryptGrab stealer, operating exclusively in RAM. It stole data from 19 browsers, 32 crypto wallets, as well as local Telegram and Steam sessions. A distinctive feature was bypassing Google Chrome's protection by directly injecting code into its process.
Privacy Issues with Browser Wallets
Researchers from KU Leuven audited 85 popular browser-based crypto wallets and identified systemic privacy issues. It turned out that the architecture of most of them allows third-party trackers to link user addresses and de-anonymize them. 36 out of 85 wallets revealed their presence to websites, and 17 allowed the provider's server to combine different addresses into a single profile. Most major players, including MetaMask and OKX, refused to acknowledge this as a vulnerability, citing "known nuances" or "low risk." This is an alarming signal for the entire Web3 ecosystem, where privacy should be a foundation.
Expert Opinion: This week clearly demonstrates a trend towards more sophisticated attacks: attackers are moving from mass phishing to targeted, technically complex operations aimed at the most valuable assets — seed phrases and authorized sessions. The attack on hardware wallets through the compromise of legitimate software is particularly dangerous, as it undermines the very concept of "cold storage." Users need to reconsider their security protocols: regularly check the list of connected sites, use isolated browser profiles, and most importantly, never enter a seed phrase into any application except during the initial setup of a new device.