The researcher said they examined the fake Ledger device’s firmware and found signs pointing to a Chinese semiconductor company named Espressif Systems. A Brazilian security researcher has warned others of the latest counterfeit Ledger device scam aimed at stealing users’ crypto. Posting as “Past_Computer2901” on the “ledgerwallet” Reddit channel on Thursday, the security researcher said they purchased what they thought was a legitimate Ledger device for personal use, but soon realized after it arrived that it was a sophisticated counterfeit aimed at stealing user funds. “This isn't meant to cause panic, but rather to serve as a serious warning — I’m honestly still a bit shaken by the sheer scale of this operation,” they said. Read more
The Ketman Project, funded by an Ethereum Foundation stipend, identified 100 North Korean IT workers and alerted about 53 projects employing DPRK operatives. The Ethereum Foundation said it funded a six-month project that exposed 100 North Korean operatives who had infiltrated Web3 companies under fake identities. The foundation on Thursday shared a recap of its ETH Rangers program, which was launched in late 2024 to provide "stipends for individuals doing public goods security work" within the ecosystem. One of the recipients used the capital to build the Ketman Project to focus on investigating “fake developers” embedded within crypto, particularly operatives from North Korea. Read more
Rhea Finance and the Russia-linked Grinex exchange were hacked for a combined $21 million over the past two days. At least 12 DeFi protocols and crypto businesses have been attacked in just over two weeks since the $280 million Drift Protocol exploit on April 1. Attacks aimed at crypto protocols or companies since the start of April include CoW Swap, Hyperbridge, Bybit, Dango, Silo Finance, BSC TMM, Aethir, MONA, Zerion and, most recently, Rhea Finance and the Grinex exchange. The Drift Protocol was hit with one of the largest exploits this year on April 1, losing around $280 million in a long-running social engineering attack suspected to involve North Korean-affiliated actors. Read more