SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool. SlowMist traced the earliest logged malicious activity linked to Bitget’s $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product. Attackers stole the funds from Bitget’s hot wallets on Sept. 24 (UTC), transferring assets to addresses they controlled across several blockchains. SlowMist’s investigation identified malicious activity involving two third-party security products and a wallet application host. According to a SlowMist progress report, the attacker used a hidden script to access the database of what SlowMist called “Product A,” after retrieving its password from an environment variable. Similar activity was later detected on two other nodes on Sept. 23 and Sept. 25. The dates and times in the report are in UTC+8. Read more
The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified. An iPhone Safari attack behind recent security warnings hasn’t yet been linked to a confirmed cryptocurrency theft in SlowMist’s investigation. Multiple reports surfaced this week urging iPhone users to update their devices immediately and warning that malicious Safari pages could expose crypto private keys and seed phrases, with some citing a range from iOS 13 through iOS 26.5. SlowMist told Cointelegraph that it has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed, while its strongest technical evidence covers iOS 18.4 through 18.6.2. Read more
SlowMist said malicious FomoPeek versions distributed through Apple’s App Store used iOS kernel exploits to escape the sandbox and access sensitive data from other apps. A malicious iOS app distributed through Apple’s App Store has been linked to nearly $580,000 in stolen crypto after researchers found it contained multiple kernel exploits capable of escaping Apple’s sandbox and accessing sensitive wallet data. According to an investigation published by blockchain security firm SlowMist, the app, called FomoPeek, introduced two malicious modules that could exploit iOS vulnerabilities, gain elevated privileges and access Keychain data and files belonging to other apps. SlowMist said the affected versions were released on Sept. 9 and Sept. 12, while version 1.3, released Sept. 17, removed the malicious components. Read more
A macOS malware steals credentials to hijack Telegram sessions, decrypt cryptocurrency wallets or trick users into entering their wallet recovery phrases through fake applications. A macOS information-stealing malware can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist. The malware harvests data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with more than a dozen cryptocurrency wallets. After collecting passwords and authenticated sessions, the malware copies users’ authenticated Telegram Desktop session data, wallet databases and browser wallet extension data. Read more
SlowMist introduced a layered security framework for Web3 AI agents as autonomous tools handle more onchain actions and digital assets. Cybersecurity company SlowMist has introduced a five-layer security framework for AI and Web3 agents, pitching it as a way to reduce the growing risks that come with autonomous systems handling onchain actions and digital assets. In a Wednesday blog post, the company said the framework centers on a user’s AI agents and combines governance controls through its AI Development Security Solution, or ADSS, with execution-layer tools including OpenClaw, MistEye Skill, MistTrack Skill and MistAgent. The company said the system is designed to create a closed-loop process of checks before execution, constraints during execution and review afterward. SlowMist’s so-called “digital fortress” aims to defend against risks including prompt injection, supply chain poisoning attacks, data leaks and asset loss due to unauthorized operations or AI agent behavior exploits. It also seeks to reduc...
SlowMist flagged 472 AI skills containing malicious code, as plugins and extensions increasingly become a target for hackers seeking access to the devices of cryptocurrency investors. A plugin hub associated with the open-source artificial intelligence agent project OpenClaw has become a target for supply chain poisoning attacks, according to a new report from cybersecurity firm SlowMist. In a report released on Monday, SlowMist said attackers have been uploading malicious “skills” to OpenClaw’s plugin hub, known as ClawHub, exploiting what it described as weak or nonexistent review mechanisms. The activity allows harmful code to spread to users who install the plugins, potentially without realizing the risk. SlowMist said its Web3-focused threat intelligence solution, MistEye, issued high-severity alerts related to 472 malicious skills on the platform. Read more
Attackers have hijacked trusted Snap Store publishers via expired domains, allowing malicious wallet updates to reach long-time Linux users. Blockchain security company SlowMist flagged a new Linux-based attack vector that exploits trusted applications distributed through the Snap Store to steal users’ crypto recovery seed phrases. In a post on X, SlowMist’s chief information security officer, 23pds, said attackers are abusing expired domains to hijack long-standing Snap Store publisher accounts and distribute malicious updates through official channels. The compromised applications reportedly impersonate popular crypto wallets, including Exodus, Ledger Live and Trust Wallet, using interfaces that closely resemble legitimate software. Read more