Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,675
Relationships
18,058
Potential duplicates
0

Entities

Allbridge Core Solana pool exploited for $1.65M via flash loan price manipulation of USDC/USDT pool ratio; protocol paused.(2026-07-20:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
a23155fe
Across Protocol Solana relayer exploited for $3.35–$4.5M via forged deposit events using missing Anchor discriminator verification; 1,627 attacker wallets deployed; no user funds lost.(2026-07-17:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
ad2d24db
TeleSwap Bitcoin hot wallet begins showing suspicious outflows totaling over $735,000; transaction processing silently halts with no public disclosure.(2026-07-15:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
61603c88
Funds recovered from Verus May 2026 hack redeposited into the Verus-Ethereum bridge — later drained again on July 23.(2026-07-08:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
fdba480e
Taiko reopens its Ethereum L2 bridge after 10-day pause; all affected users reimbursed following independent security review.(2026-07-02:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
b465a8a5
Taiko bridge exploited for $1.7M via forged message proof enabled by leaked SGX signing key; block production halted.(2026-06-22:h2-2026-july-bridge-hack-wave-seven-attacks-m-lost)event
0342a0cf
H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Losttoken
c07d4e27
ideaagency.netdomain
26a5795e
OFAC designates the Hossein Shamkhani oil smuggling and shipping network under Economic Fury.(2026-04-15:bitpin)event
8e1b6076
Treasury Secretary Scott Bessent officially launches Operation Economic Fury as the financial component of the U.S. response to the Iran conflict.(2026-04-14:bitpin)event
59d01a20
OFAC designates Babak Zanjani conglomerate including digital asset projects Zedcex and Zedxion — first major Economic Fury crypto action.(2026-01-30:bitpin)event
753d8668
cryptoarbitragetracker.comdomain
76223233
blockspot.iodomain
da87c3d3
breachsense.comdomain
c680b635
iranwatch.orgdomain
6944c22e
OFAC designates Wallex (legal name: Khalgh Sarvat Sarzamin Parseh) to the SDN list under E.O. 13902, citing operation in the Iranian financial sector and facilitation of IRGC-linked transactions. Designated alongside Nobitex, Bitpin, and Ramzinex in the largest-ever U.S. enforcement action against Iran's digital asset sector.(2026-06-02:wallex)event
bf9bf9bb
U.S. Treasury launches Operation Economic Fury, targeting Iran's financial networks including cryptocurrency infrastructure.(2026-04-14:wallex)event
7903178a
OFAC designates Zedcex and Zedxion, described by TRM Labs as IRGC-linked crypto infrastructure. Separate from the domestic exchange tier including Wallex.(2026-01-01:wallex)event
95aaa682
Wallex website (wallex.ir) reported offline, approximately nine months before the formal OFAC designation.(2025-09-14:wallex)event
0cd9c5a0
Wallex.ir data breach confirmed, associated with RaidForums threat actor. Specific data categories and record count not fully disclosed in public sources.(2021-07-05:wallex)event
35315e36
krypt3ia.wordpress.comdomain
bfd5ed22
hard2bit.comdomain
241be841
mishcon.comdomain
0d02af59
CISA added CVE-2026-9198 to the KEV catalog with an August 7, 2026 remediation deadline for federal civilian agencies, representing the first AI agent platform CVE listed in the catalog.(2026-08-04:jadepuffer)event
59098ec7
Sysdig disclosed the second JADEPUFFER campaign: the operator returned to the same Langflow instance and deployed ENCFORGE, a compiled Go ransomware built to encrypt AI model checkpoints, vector databases, and training datasets across approximately 180 file extensions.(2026-07-21:jadepuffer)event
b045831c
IBM disclosed CVE-2026-9198, a new critical Langflow RCE vulnerability (CVSS 9.8) affecting versions 1.0.0 through 1.10.0, patched in v1.10.1.(2026-07-17:jadepuffer)event
86d7f412
Independent threat intelligence reports on JADEPUFFER published, noting the operator remained unattributed and the Bitcoin address was identified as a canonical documentation example.(2026-07-13:jadepuffer)event
2c55f795
CISA added Langflow as the first AI agent platform to its KEV catalog with a deadline for federal agencies to patch four CVEs.(2026-07-08:jadepuffer)event
66f26b35
Sysdig published public blog post disclosing JADEPUFFER, marking the first publicly documented agentic AI ransomware operation.(2026-07-03:jadepuffer)event
a891f09f
Sysdig Threat Research Team disclosed the first JADEPUFFER campaign: a fully autonomous LLM agent exploited CVE-2025-3248 to access a Langflow instance, pivoted to Nacos via CVE-2021-29441, encrypted 1,342 configuration items, and deployed a ransom note containing Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy.(2026-07-02:jadepuffer)event
192ad8ca
CISA added CVE-2025-3248 (Langflow unauthenticated RCE, CVSS 9.8) to its Known Exploited Vulnerabilities catalog, noting prior exploitation by the Flodrix botnet.(2025-05-05:jadepuffer)event
00df6bb5
CVE-2021-29441, a Nacos authentication bypass exploited in Phase 1 of JADEPUFFER, was publicly disclosed.(2021-03-01:jadepuffer)event
d8f3eebc
JADEPUFFERorganization
8bc074d5
Jared Wray (jaredwray) confirms via X that his GitHub account was compromised; reports using OIDC with npm and one-time codes. States he regained account access at approximately 20:00 UTC and began full audit.(2026-08-04:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
97fa3cc3
@antv ecosystem attack: 639 malicious versions across 323 packages published in under 30 minutes via stolen maintainer account. Socket detects most within 6.7 minutes.(2026-05-19:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
339d45df
TeamPCP open-sources Shai-Hulud worm on GitHub under MIT License with message 'Shai-Hulud: Open Sourcing The Carnage,' announces $1,000 contest for largest supply chain attack using the code.(2026-05-12:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
48d0625f
TanStack attack: TeamPCP compromises GitHub Actions pipeline, publishes 84 malicious versions across 42 @tanstack/* packages in approximately six minutes. CVE-2026-45321 (CVSS 9.6) assigned.(2026-05-11:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
5a84ba25
Mini Shai-Hulud (fourth generation) begins operations, introducing SLSA provenance attestation forgery, OIDC token extraction from runner memory, and AI agent persistence hooks.(2026-04-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
484924db
SANDWORM_MODE iteration of the worm introduced.(2026-03-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
5e30adf4
SHA1-Hulud variant introduced with enhanced capabilities.(2025-11-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
55060d1a
Original Shai-Hulud worm debuts, attributed to TeamPCP (UNC6780); marks start of systematic npm/PyPI supply chain campaign.(2025-09-01:chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026)event
f45fc90e
ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)organization
c2fee87c
LayerZero publishes full incident report. Mandiant, CrowdStrike, and independent researchers are cited confirming attribution to TraderTraitor (UNC4899). Chainalysis updates its analysis with additional findings.(2026-05-18:layerzero)event
7edb4a79
Chainalysis publishes detailed on-chain analysis of the KelpDAO bridge exploit. OpenZeppelin publishes post-mortem confirming zero smart contract vulnerabilities; failure attributed entirely to off-chain infrastructure and configuration policy.(2026-04-23:layerzero)event
ed9f5b1b
Data refreshes every 5 minutes · All metrics derived from Supabase