Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,536
Relationships
17,946
Potential duplicates
0

Entities

Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.(2026-07-31:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
cc64569c
Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.(2026-07-30:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
09343553
CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.(2024-11-04:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
0b43e2b5
Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)organization
654e1b7a
Crypto Times reports that over 100 crypto projects shut down in H1 2026, citing RootData data, listing Leap Wallet among the closures and attributing the broader wave to financial exhaustion rather than fraud.(2026-08-04:leap-wallet)event
3e2331d6
All Leap Wallet products permanently cease operation. The leapwallet.io domain displays a farewell page. Users who have not exported recovery phrases by this date must retain their seed phrase to recover funds via a compatible wallet.(2026-05-28:leap-wallet)event
0e4c824e
Leap Wallet announces permanent shutdown of all products effective May 28, 2026. Affected products include the browser extension, iOS and Android apps, Compass Wallet, Swapfast, the Leap Cosmos Hub validator, and Leap Cosmos Snaps. No specific reason disclosed.(2026-04-03:leap-wallet)event
4cce4e26
Leap begins building on the Cosmos interchain. Within approximately one year, the team reports over 300,000 users across its product suite.(2022-07-01:leap-wallet)event
23bea4dc
Terra blockchain collapses. Terraform Labs — an investor in Leap — fails. Leap begins pivoting to the broader Cosmos ecosystem.(2022-05-01:leap-wallet)event
67ecb25f
Leap announces $3.2 million private token sale co-led by CoinFund and Pantera Capital, with participation from Arrington Capital, Accel, and Terraform Labs. Implied valuation approximately $40 million.(2022-04-05:leap-wallet)event
687f522d
Leap Wallet founded by Sanjeev Rao in Vancouver, British Columbia, with a $50,000 grant from Terraform Labs. Initial product is a Terra ecosystem browser extension.(2021-11-01:leap-wallet)event
37b32f26
Leap Walletorganization
fcbd3ee5
The Hacker News publishes comprehensive coverage citing Sonatype and OpenSourceMalware research, describing 1,033 total packages, crypto drain capabilities, Aeza Group infrastructure link, and connection to Moika campaign.(2026-08-10:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
07302fd3
SC Media and other outlets publish coverage. OpenSourceMalware co-founder Jenn Gile reports total confirmed WEL1DROPPER packages at 1,033.(2026-08-08:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
f4cbb8ed
Sonatype Research Labs publishes campaign tracking under the name 'Flooding Dropper' (sonatype-2026-005660), identifying 846 malicious npm components. Campaign velocity reportedly slowed after discovery week.(2026-08-07:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
5e3300d2
OpenSourceMalware publishes analysis of the AI slopsquatting campaign, documenting 700+ malicious npm packages published in approximately 48 hours and naming the campaign 'WEL1DROPPER'.(2026-08-06:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
5161d8a1
OpenSourceMalware researchers identify bigops-backend as the first documented WEL1DROPPER package, triggering a cross-platform native binary payload on Windows, Linux, and macOS.(2026-08-05:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
071b6040
Moika Wave 3: Fourth account emcd-vue publishes packages impersonating EMCD cryptocurrency exchange with advanced obfuscation.(2026-06-01:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
6bedb4be
Moika Wave 2: Third account t-in-one adds 12 packages, including impersonation of Sberbank's payment widget. Microsoft Security Blog separately documents 33 malicious npm packages abusing dependency confusion.(2026-05-29:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
d8527b17
Moika Wave 1: npm accounts mr.4nd3r50n and pik-libs publish 164 malicious packages targeting cloud platform and financial services internal scopes within 25 minutes.(2026-05-27:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
26228231
Moika dependency confusion campaign begins: over 250 malicious npm packages published, exfiltrating process.env contents and delivering OS-specific second-stage payloads. Assessed by OpenSourceMalware as a predecessor to WEL1DROPPER.(2026-04-01:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
4aed43cd
WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)organization
3b14d02f
French Finance Ministry confirms the June 2026 DGFiP breach affecting 678,437 taxpayers. Multiple outlets including The Block, Decrypt, and Bitcoin Magazine publish warnings to crypto holders about the compounded physical attack risk.(2026-08-14:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
4fcd67cc
Threat actor ZeroBytes publicly claims responsibility for the DGFiP breach on breach forums, stating data from more than 600,000 individuals was obtained.(2026-08-12:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
7634bed2
CryptoTimes and other outlets report Chainalysis data confirming France as the global wrench attack hotspot in H1 2026, with over USD 30 million stolen.(2026-08-06:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
829f3c40
CertiK Intel3D H1 2026 Wrench Attacks Report formally published via GlobeNewswire press release.(2026-07-25:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
9198d588
CertiK publishes its H1 2026 Wrench Attacks Report, recording 52 verified global incidents (33 in France), USD 124.1 million in estimated financial exposure, and a 33% year-over-year surge.(2026-07-22:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
82963edf
French Interior Minister Laurent Nuñez publicly discloses that authorities have logged more than 70 crypto-related violent incidents. DGFiP cuts off attacker's access around this period.(2026-06-30:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
edc7fb5c
Unauthorized intrusion into DGFiP systems occurs. Attacker allegedly gains access using stolen or misused credentials of a legitimate user, connects to the internal VPN, and uses an internal search tool to extract taxpayer records.(2026-06-26:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
b1e93452
CoinDesk publishes investigation into the rise of wrench attacks, documenting France's emergence as global epicenter and quoting TRM Labs on the strategic shift from technical to physical targeting.(2026-04-19:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
b1709b8c
Forbes publishes investigation into France's crypto kidnapping crisis, noting a pattern of 'zero convictions' as a contributing factor in the escalating attack rate.(2026-02-14:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
9afe5015
Ghalia C., the Bobigny tax office employee, is reported to have lost a bail appeal and remains in custody, facing charges of complicity in violence and criminal conspiracy. Case reported by Gizmodo.(2026-01-10:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
4af3349f
Stolen Waltio database — containing data on approximately 50,000 users of the French crypto tax platform — appeared for sale on BreachForums. The breach had not yet been detected by Waltio.(2025-12-24:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
5733d346
Ledger co-founder David Balland kidnapped in France. One of his fingers was reportedly severed before police rescued him, in a case that drew international attention to France's crypto violence problem.(2025-01-01:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
ab2a4978
Three armed men assaulted a La Santé prison guard in his Montreuil home. French investigators later allege that Ghalia C., a Bobigny tax office employee, provided the attackers with the victim's address using unauthorized access to Mira, the tax administration's internal software.(2024-09-01:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
1b88b907
France DGFIP Tax Data Breach — Crypto Wrench Attack Enablement (August 2026)protocol
c70d7203
Huntress published full technical analysis of the Go-based macOS infostealer, documenting the DRAIN function, Aeza Group C2 infrastructure, IOCs, and remediation steps. AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.(2026-08-06:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
5139148c
Microsoft Security Blog published an analysis documenting that a macOS ClickFix campaign had evolved to include new obfuscation techniques, providing broader context for the threat landscape one day before the Huntress publication.(2026-08-05:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
554a2485
Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.(2026-06-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
e7d65cfc
AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.(2026-03-10:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
c536ad4d
Approximate date of initial infection: A macOS endpoint monitored by Huntress MDR was compromised via a ClickFix social engineering attack, installing the Go-based infostealer. The infection remained undetected for approximately three months.(2026-03-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
df9db0eb
Data refreshes every 5 minutes · All metrics derived from Supabase