← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,675
Relationships
18,058
Potential duplicates
0
Filter by kind
Entities
↯a23155fe
Allbridge Core Solana pool exploited for $1.65M via flash loan price manipulation of USDC/USDT pool ratio; protocol paused.(2026-07-20:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
↯ad2d24db
Across Protocol Solana relayer exploited for $3.35–$4.5M via forged deposit events using missing Anchor discriminator verification; 1,627 attacker wallets deployed; no user funds lost.(2026-07-17:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
↯61603c88
TeleSwap Bitcoin hot wallet begins showing suspicious outflows totaling over $735,000; transaction processing silently halts with no public disclosure.(2026-07-15:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
↯fdba480e
Funds recovered from Verus May 2026 hack redeposited into the Verus-Ethereum bridge — later drained again on July 23.(2026-07-08:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
↯b465a8a5
Taiko reopens its Ethereum L2 bridge after 10-day pause; all affected users reimbursed following independent security review.(2026-07-02:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
↯0342a0cf
Taiko bridge exploited for $1.7M via forged message proof enabled by leaked SGX signing key; block production halted.(2026-06-22:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
♦c07d4e27
H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Losttoken
↯8e1b6076
OFAC designates the Hossein Shamkhani oil smuggling and shipping network under Economic Fury.(2026-04-15:bitpin)event
↯59d01a20
Treasury Secretary Scott Bessent officially launches Operation Economic Fury as the financial component of the U.S. response to the Iran conflict.(2026-04-14:bitpin)event
↯753d8668
OFAC designates Babak Zanjani conglomerate including digital asset projects Zedcex and Zedxion — first major Economic Fury crypto action.(2026-01-30:bitpin)event
↯bf9bf9bb
OFAC designates Wallex (legal name: Khalgh Sarvat Sarzamin Parseh) to the SDN list under E.O. 13902, citing operation in the Iranian financial sector and facilitation of IRGC-linked transactions. Designated alongside Nobitex, Bitpin, and Ramzinex in the largest-ever U.S. enforcement action against Iran's digital asset sector.(2026-06-02:wallex)event
↯7903178a
U.S. Treasury launches Operation Economic Fury, targeting Iran's financial networks including cryptocurrency infrastructure.(2026-04-14:wallex)event
↯95aaa682
OFAC designates Zedcex and Zedxion, described by TRM Labs as IRGC-linked crypto infrastructure. Separate from the domestic exchange tier including Wallex.(2026-01-01:wallex)event
↯0cd9c5a0
Wallex website (wallex.ir) reported offline, approximately nine months before the formal OFAC designation.(2025-09-14:wallex)event
↯35315e36
Wallex.ir data breach confirmed, associated with RaidForums threat actor. Specific data categories and record count not fully disclosed in public sources.(2021-07-05:wallex)event
◎7668804f
nsfocusglobal.comdomain
◎bbd36b8e
sysdig.comdomain
↯59098ec7
CISA added CVE-2026-9198 to the KEV catalog with an August 7, 2026 remediation deadline for federal civilian agencies, representing the first AI agent platform CVE listed in the catalog.(2026-08-04:jadepuffer)event
↯b045831c
Sysdig disclosed the second JADEPUFFER campaign: the operator returned to the same Langflow instance and deployed ENCFORGE, a compiled Go ransomware built to encrypt AI model checkpoints, vector databases, and training datasets across approximately 180 file extensions.(2026-07-21:jadepuffer)event
↯86d7f412
IBM disclosed CVE-2026-9198, a new critical Langflow RCE vulnerability (CVSS 9.8) affecting versions 1.0.0 through 1.10.0, patched in v1.10.1.(2026-07-17:jadepuffer)event
↯2c55f795
Independent threat intelligence reports on JADEPUFFER published, noting the operator remained unattributed and the Bitcoin address was identified as a canonical documentation example.(2026-07-13:jadepuffer)event
↯66f26b35
CISA added Langflow as the first AI agent platform to its KEV catalog with a deadline for federal agencies to patch four CVEs.(2026-07-08:jadepuffer)event
↯a891f09f
Sysdig published public blog post disclosing JADEPUFFER, marking the first publicly documented agentic AI ransomware operation.(2026-07-03:jadepuffer)event
↯192ad8ca
Sysdig Threat Research Team disclosed the first JADEPUFFER campaign: a fully autonomous LLM agent exploited CVE-2025-3248 to access a Langflow instance, pivoted to Nacos via CVE-2021-29441, encrypted 1,342 configuration items, and deployed a ransom note containing Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy.(2026-07-02:jadepuffer)event
↯00df6bb5
CISA added CVE-2025-3248 (Langflow unauthenticated RCE, CVSS 9.8) to its Known Exploited Vulnerabilities catalog, noting prior exploitation by the Flodrix botnet.(2025-05-05:jadepuffer)event
↯d8f3eebc
CVE-2021-29441, a Nacos authentication bypass exploited in Phase 1 of JADEPUFFER, was publicly disclosed.(2021-03-01:jadepuffer)event
◇df08a2f4
3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLywallet
◎d197393a
zerohunt.aidomain
↯97fa3cc3
Jared Wray (jaredwray) confirms via X that his GitHub account was compromised; reports using OIDC with npm and one-time codes. States he regained account access at approximately 20:00 UTC and began full audit.(2026-08-04:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯339d45df
@antv ecosystem attack: 639 malicious versions across 323 packages published in under 30 minutes via stolen maintainer account. Socket detects most within 6.7 minutes.(2026-05-19:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯48d0625f
TeamPCP open-sources Shai-Hulud worm on GitHub under MIT License with message 'Shai-Hulud: Open Sourcing The Carnage,' announces $1,000 contest for largest supply chain attack using the code.(2026-05-12:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯5a84ba25
TanStack attack: TeamPCP compromises GitHub Actions pipeline, publishes 84 malicious versions across 42 @tanstack/* packages in approximately six minutes. CVE-2026-45321 (CVSS 9.6) assigned.(2026-05-11:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯484924db
Mini Shai-Hulud (fourth generation) begins operations, introducing SLSA provenance attestation forgery, OIDC token extraction from runner memory, and AI agent persistence hooks.(2026-04-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯5e30adf4
SANDWORM_MODE iteration of the worm introduced.(2026-03-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯55060d1a
SHA1-Hulud variant introduced with enhanced capabilities.(2025-11-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
↯f45fc90e
Original Shai-Hulud worm debuts, attributed to TeamPCP (UNC6780); marks start of systematic npm/PyPI supply chain campaign.(2025-09-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
□c2fee87c
ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)organization
↯7edb4a79
LayerZero publishes full incident report. Mandiant, CrowdStrike, and independent researchers are cited confirming attribution to TraderTraitor (UNC4899). Chainalysis updates its analysis with additional findings.(2026-05-18:layerzero)event
↯ed9f5b1b
Chainalysis publishes detailed on-chain analysis of the KelpDAO bridge exploit. OpenZeppelin publishes post-mortem confirming zero smart contract vulnerabilities; failure attributed entirely to off-chain infrastructure and configuration policy.(2026-04-23:layerzero)event
Data refreshes every 5 minutes · All metrics derived from Supabase