BlockThreat - Week 33, 2025
BtcTurk | Coinbase | Kraken | Odin.Fun | Monero | DPRK IT Workers
Greetings!
BtcTurk has once again suffered a serious incident with this week’s hot wallet compromise resulting in the loss of $51.7M. This follows a $54M hack in June 2024 and an earlier 2018 incident where its user database was leaked on RaidForums. Two major $50M-plus losses in just over a year point to a troubling pattern and highlight a clear lack of fundamental security controls in their wallet infrastructure.
Speaking of unfortunate hacks, Coinbase inadvertently granted ERC-20 spending approval rights to 0x project’s permissionless Settler contract which is explicitly flagged in their documentation as off-limits. MEV bots immediately swooped in to drain some $550K in various tokens from their fee-collection wallet in mere hours. The news is concerning as Coinbase is about to open up DEX trading to millions of its retail customers.
A special thanks to this week’s sponsor Coinspect.

Coinspect’s Wallet Security Ranking is an objective, transparent, and regularly updated evaluation of leading cryptocurrency wallets. It focuses on critical security features like anti-phishing defenses, transaction clarity, and protection against blind signing, helping users choose wallets that prioritize their safety.
Link: https://www.coinspect.com/wallets/
Let’s dive into the news!
News
- Kraken suspends Monero deposits after 51% attack.
- Hashrate Heist or Hype? by Rekt explores Qubit’s attack on the Monero chain.
Crime
- A deep dive into DPRK IT worker operation after a compromise of one of their machines thread by ZachXBT. 30+ identities including Upwork and LinkedIn accounts, extensive used of Google tools, wallets, telegram channels and plenty of other indicators. A treasure trove of intelligence!
- Meet Gerardo Salgado aka Tammy Hans (the old one) a DPRK IT Worker who infected himself with Contagious Interview malware a thread by Narcass3.
- Someone just dropped almost 1.4k email address list used by North Korean IT workers by StyyK.
- Crypto crasher Do Kwon admits guilt over failed not-so-stablecoin that erased $41 billion.
- Former Pump.fun Employee Pleads Guilty, Awaits Sentencing for $2 Million Solana Theft.
- Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals. The target exchange, Grinex, is a rebrand of an earlier sanctioned Garantex exchange.
- XSS.IS Silenced! Inside the investigation that shut down one of cybercrime's most feared bazaars by Luca Stivali (Red Hot Cyber).
- U.S. seizes $2.8 million in crypto from Zeppelin ransomware operator.
- Italian Carabinieri Leverage Chainalysis to Dismantle Illicit Crypto Exchange. The report had an interesting note about Chainalysis writing custom bruteforcing scripts to help recover private keys from fragmented seed phrases.
- How Chainalysis Helped Uncover an NCA Officer’s Theft of Seized Bitcoin.
- Crypto Investors Accused of Kidnapping in Soho Townhouse. A bizarre kidnapping scheme fueled by crypto excess.
- Four people who ransomed Brazilian mother for Bitcoin arrested.
Phishing
- A detailed breakdown of a successful phishing attack using a malicious Cursor extension by zak.eth. Interestingly a similar Cursor extension bundled detailed notes on the malware campaign and expected revenues.
- $636k was lost to a poison address scam where a user sent 140 $ETH to a lookalike address a thread by Web3 Antivirus.
- North Korean Hackers Try to Get Hired at Binance Every Day—Here’s How They're Spotted.
Scams
Malware
Media
- bountyhunt3rz - Episode 23 - 0xjuann & 0xspearmint.
- Core Memory - How North Korea Infiltrated American Companies With Fake Tech Workers.
- 0xProfiles - Andy Li.
Research
- Crypto Asset Tracing Handbook by Slowmist.
- The Complete Guide to Securing Web3 Projects by Optimum.
- How to Hack a Web3 Wallet (Legally): A Full-Stack Pentesting Guide by 0xaudron (Valkyri).
- ScamDetect: Towards a Robust, Agnostic Framework to Uncover Threats in Smart Contracts.
- Beyond Zero Knowledge: How Fully Homomorphic Encryption Enables Private Shared State by Sam Wong (OpenZeppelin).
- Hunting Crits: Aragon's LockToVote Plugin • Ventral Digital by Patrick Drotleff (Ventral Digital).
- How AI-Powered Defense Stopped a $Millions Crypto Scam in Real-Time by Ninja_Dev.
- The Invariant Testing Bootcamp was added to the Recon Book.
- Top 15 Security Tips for BNB Chain Developers by Paul (Cantina).
- Safer Safe Explainer by DeFi Wonderland.
- How to Hack a Web3 Wallet (Legally): A Full-Stack Pentesting Guide by 0xaudron (Valkyri).
Tools
- Scrape Open Zeppelin Roles from any contract by Recon.
- Save 90% on Report Writing - Guaranteed or Your Money Back! Zero Cool is a new AI tool on the block for DeFi auditors.
- AWS Security Scanner by punishell. A tool to scan for AWS security misconfigurations using the AWS CLI and report issues by severity.
Hacks
Bebop
Date: August 12, 2025
Attack Vector: Function Parameter Validation
Impact: $20,000
Chain: Arbitrum
References:
https://x.com/SuplabsYi/status/1955230173365961128
https://x.com/SuplabsYi/status/1955601118891057517
https://docs.bebop.xyz/bebop/bebop-api-jam/jam-api-endpoints/manage-approvals
Exploit:
https://arbiscan.io/tx/0xe5f8fe69b38613a855dbcb499a2c4ecffe318c620a4c4117bd0e298213b7619d
Odin Fun
Date: August 12, 2025
Attack Vector: Price Oracle Manipulation
Impact: $7,000,000
Chain: ICP
References:
https://x.com/ethers_security/status/1955591670202003887
https://x.com/PeckShieldAlert/status/1955457951558406332
https://x.com/BobBodily/status/1955303509341114444
https://www.quillaudits.com/blog/hack-analysis/how-odinfun-lost-58-3BTC-to-worthless-liquidity
https://drive.google.com/file/d/1dA3G7bbWkIINqbHK25rZnxA0UYYDO5eI/view
https://rekt.news/odin-fun-rekt
Exploit:
https://odin.fun/user/urguz-m32zo-jlld6-pyy4l-z3c24-jv4pt-5fmll-gq2xd-6siiz-oxkao-xae?tab=activity
https://odin.fun/user/jeypm-z6t4p-uqshx-dtay4-qgw5d-ca7j5-alviu-fch2d-nmsnc-c4k3k-aae?tab=activity
YULIAI
Date: August 13, 2025
Attack Vector: Price Oracle Manipulation
Impact: $78,800
Chain: BSC
References:
https://x.com/TenArmorAlert/status/1955817707808432584
Exploit:
https://bscscan.com/tx/0xeab946cfea49b240284d3baef24a4071313d76c39de2ee9ab00d957896a6c1c4
Grizzifi
Date: August 13, 2025
Attack Vector: Reward Manipulation
Impact: $61,000
Chain: BSC
References:
https://x.com/TenArmorAlert/status/1955825401470578788
Exploit:
https://bscscan.com/tx/0xdb5296b19693c3c5032abe5c385a4f0cd14e863f3d44f018c1ed318fa20058f7
https://bscscan.com/tx/0xdb4f2c0d2ab8f029d9576dc96b0a9b547ef6c90e17a7a3146b27514dfeba6bba
Coinbase Exchange
Date: August 13, 2025
Attack Vector: Forgotten approval
Impact: $550,000
Chain: Ethereum
References:
https://x.com/TenArmorAlert/status/1955830852182794602
https://x.com/deeberiroz/status/1955718986894549344
https://cryptoslate.com/coinbase-loses-300k-to-rogue-mev-bots-after-token-swap-blunder/
https://rekt.news/drained-by-design
Exploit:
https://etherscan.io/tokentxns?a=0x382ffce2287252f930e1c8dc9328dac5bf282ba1
BtcTurk Exchange
Date: August 14, 2025
Attack Vector: Hot Wallet Compromise
Impact: $49,000,000
Chain: Bitcoin, Ethereum
References:
https://x.com/CyversAlerts/status/1955967877602803929
https://x.com/peckshield/status/1955969912477749674
https://x.com/PeckShieldAlert/status/1955984860889408006
https://x.com/BtcTurkKripto/status/1955981988747198513
https://x.com/CertiKAlert/status/1956287719505608920
https://rekt.news/btcturk-rekt
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident
Exploit:
https://etherscan.io/tokentxns?a=0xa041feb3a8297c5689fee180083164a061a17fd6
Size Credit
Date: August 15, 2025
Attack Vector: Function Parameter Validation
Impact: $20,000
Chain: Ethereum
References:
https://x.com/SuplabsYi/status/1956306748073230785
Exploit:
https://etherscan.io/tx/0xc7477d6a5c63b04d37a39038a28b4cbaa06beb167e390d55ad4a421dbe4067f8
Nevis Investment
Date: August 15, 2025
Attack Vector: Key/Signer Compromise
Impact: $3,000
Chain: BSC
References:
https://x.com/TikkalaResearch/status/1956417681030304217
Exploit:
https://bscscan.com/tx/0x9f269b571879cc0cec120eb40e8fdce44fafc585f4c4e64064af5d4ecc86ca7a
https://bscscan.com/tx/0x4bc9d41afba2a2a2aa7ce12dd5b4554250a8645fcc9704c22db19b15acc47ecf
D3X
Date: August 17, 2025
Attack Vector: Price Oracle Manipulation
Impact: $158,900
Chain: BSC
References:
https://x.com/TenArmorAlert/status/1957279788709671402
https://x.com/BlockSecTeam/status/1956661877473476962
https://x.com/SuplabsYi/status/1956695597546893598
Exploit:
https://bscscan.com/tx/0x26bcefc152d8cd49f4bb13a9f8a6846be887d7075bc81fa07aa8c0019bd6591f