The week was packed with events in the cybersecurity sphere. I analyzed several major incidents that affected both ordinary crypto asset holders and infrastructure projects. Below are the key threats that require immediate attention.

Massive phishing operation "Asterix"

Attackers compromised a database containing approximately 885,000 phone numbers of crypto investors worldwide. The attack scheme is classic vishing: victims received calls allegedly from support services or emails on behalf of well-known platforms, including Crypto.com. The ultimate goal is to trick the user into visiting a fake website or installing a fake app imitating Ledger, Trezor, or Exodus to steal the seed phrase.

What is particularly alarming is the automation of the process. Hackers used scripts to mass-verify numbers against the databases of the largest exchanges. The effectiveness turned out to be frighteningly high: in the German sample alone, the match rate was 13.6% (43,066 real investors). More than 5,500 confirmed Binance accounts were queued for attack. The largest fragment of stolen data is 316,002 numbers of German citizens. The lists also include residents of the US, UK, Hong Kong, and Ledger clients.

Fake AML services — a new trap for wallets

Scammers are actively copying the design of legitimate platforms like AMLBot, creating fake "checkers." The scheme is simple: the site requests a wallet connection for "scanning," imitates analysis, and gives a false "Clean" result. The catch is in signing a transaction disguised as a fee payment, which transfers control over funds to a malicious smart contract. This once again confirms: trusting third-party verification services without thorough vetting is a deadly risk.

Supply chain attack on the Rust ecosystem

The compromise of a developer account for the popular package arrayref (over 245 million downloads) led to the infection of code that executed during compilation. The malicious dependency proc-macro1 was disguised as a legitimate one, and a fake build.rs downloaded a loader to steal passwords from browsers and collect system information. Experts link the infrastructure of this campaign to the North Korean group Sapphire Sleet. This is a serious wake-up call for everyone using open-source code in blockchain tools, especially for Ethereum and Solana.

Hack of 14,500 Dahua cameras

The CameraSwarm operation was uncovered thanks to a mistake by hackers who left their server unprotected. Three attack vectors: brute-forcing passwords on port 37777, exploiting 2021 vulnerabilities (p2pwn), and intercepting control via serial numbers. I strongly recommend camera owners check for a hidden p2pwn account and disable P2P if it is not in use.

Manic trojan: a mesh network for data theft

A new Android trojan attacks more than 169 apps, including banking and cryptocurrency ones. Manic intercepts keystrokes, classifies seed phrases, and 2FA codes. Its unique feature is transmitting data through neighboring infected devices via Wi-Fi Direct or Bluetooth, creating a mesh network to bypass blocks. This is an evolution of malware that the market is not yet ready for.

My comment: This week demonstrates the consolidation of hacker efforts around the crypto industry. Attacks are becoming increasingly targeted and technological, using AI and sophisticated methods to bypass defenses. Investors critically need to switch to hardware wallets with verified firmware, and developers need to thoroughly audit dependencies. Vigilance is the only effective defense in conditions where even basic libraries are being hacked.