← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,675
Relationships
18,058
Potential duplicates
0
Filter by kind
Entities
↯0372d63c
OWASP releases 2026 LLM Top 10. Prompt injection retains the number-one position for the third consecutive year. Excessive agency rises to third place. For the first time, rankings incorporate real-world incident data from 6,639 documented incidents.(2026-08-06:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯69472b97
Blockaid publishes H1 2026 security report documenting 212 on-chain exploits totaling $1.1 billion — a record — and identifying AI agent prompt injection as an emerging and growing attack sub-category. Blockaid projects AI agent deployments growing 10x annually and forecasts multiple additional AI agent incidents in H2 2026.(2026-07-29:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯3b7c9670
Ledger announces Agent Stack, a hardware-enforced human-in-the-loop signing architecture for AI crypto agents, directly referencing the prompt injection threat class as motivation.(2026-07-16:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯ecbe2e31
TechTimes covers active campaign in which hidden webpage instructions are confirmed to be causing AI agents to pay hackers in live deployments, corroborating Zscaler findings.(2026-07-09:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯9a57e355
SecurityWeek reports Zscaler's discovery of two active indirect prompt injection campaigns using SEO poisoning and hidden HTML to make AI agents transfer cryptocurrency to attacker-controlled wallets. Testing confirms four of 26 LLMs execute unauthorized payments after reading a malicious webpage.(2026-07-06:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯e94ef94c
OWASP publishes findings that prompt injection drives most agentic AI security failures in production. Help Net Security reports prompt injection attacks surged 340% in 2026.(2026-06-11:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯a73d9834
Bankr/Grok prompt injection attack on Base chain. Attacker airdrops a 'Bankr Club Membership' NFT to Grok's wallet to escalate permissions, then posts a Morse-code-encoded transfer instruction on X. Grok decodes the message; Bankr executes the transfer. Approximately 3 billion DRB tokens ($155,000-$175,000) are drained. Around 80% recovered after community doxxing.(2026-05-04:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯f01816b7
OpenClaw AI agent 'Lobstar Wilde' transfers 52.43 million LOBSTAR tokens (valued at approximately $250,000) to an unintended address due to a quantity-parsing error. Tokens liquidated within 15 minutes for approximately $40,000. Malicious actors subsequently replicate the parsing logic to exploit other OpenClaw-based agents.(2026-02-01:ai-agent-prompt-injection-crypto-attack-class-2026)event
↯4d742cbc
Step Finance suffers $40 million treasury breach on Solana. Attacker compromises executive devices and exploits overpermissioned AI trading agents to move approximately 261,000 SOL without human authorization. Only $4.7 million recovered. Platform subsequently shuts down.(2026-01-31:ai-agent-prompt-injection-crypto-attack-class-2026)event
□b7a69503
AI Agent Prompt Injection Crypto Attack Class (2026)organization
↯9d251757
The U.S. Attorney's Office for the Southern District of New York unseals a federal indictment charging Taj Tarsha with one count of securities fraud and one count of wire fraud. The case is assigned to U.S. District Judge Lewis A. Kaplan. Each count carries a maximum of 20 years' imprisonment.(2026-08-05:taj-tarsha-few-and-far-limited)event
↯d3128f32
Taj Tarsha is arrested.(2026-06-06:taj-tarsha-few-and-far-limited)event
↯1c1ff255
FAR token launches on NEAR Protocol mainnet. The token quickly loses virtually all value and ceases active trading.(2024-03-08:taj-tarsha-few-and-far-limited)event
↯3c438337
Tarsha allegedly pays Co-Founder-1 and the operations director company funds to regain control of the multi-signature wallet. He then allegedly makes false statements to investors claiming diverted transactions had benefited the business.(2023-07-01:taj-tarsha-few-and-far-limited)event
↯5dfd409e
An internal audit of Few and Far's finances exposes alleged misappropriation of investor funds by Tarsha. Team members take steps to remove Tarsha from the company's multi-signature wallet.(2023-06-01:taj-tarsha-few-and-far-limited)event
↯28fa7f77
Tech Funding News reports Few and Far has raised $10.5 million with Pantera Capital as lead investor.(2023-03-03:taj-tarsha-few-and-far-limited)event
↯315a31ab
Taj Tarsha and Karisa Winett (VP of Operations) appear in a sponsored CoinDesk TV segment on 'NEAR TO IMPOSSIBLE,' promoting Few and Far's goal to onboard the next billion users to Web3.(2023-01-18:taj-tarsha-few-and-far-limited)event
↯3a4fed9f
Few and Far incorporated; company is based in the British Virgin Islands and begins operations building on NEAR Protocol.(2022-03-01:taj-tarsha-few-and-far-limited)event
↯8e994e5a
Taj Tarsha begins soliciting investors in Few and Far via SAFT agreements, selling rights to future FAR tokens. Fundraising targets the NEAR Protocol NFT marketplace opportunity.(2022-02-01:taj-tarsha-few-and-far-limited)event
↯f20080ea
On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.(2026-08-05:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯04af068e
CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.(2026-08-04:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯bacc4cd6
Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.(2026-08-03:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯35b37ffb
Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.(2026-08-02:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯dd9abbcf
Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.(2026-08-01:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯b7799289
Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.(2026-07-31:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
↯13d7d3be
Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.(2021-03-01:coldcard-coinkite-august-2026-multi-actor-attacker-cluster)event
♦bb8fdcf5
Coldcard / Coinkite — August 2026 Multi-Actor Attacker Clustertoken
◎96a459fd
cpapracticeadvisor.comdomain
◎dff8cb9e
journalofaccountancy.comdomain
↯0fa0a73d
Help Net Security and Bitdefender publish technical analyses of the phishing infrastructure, confirming the Hong Kong registrar, Romanian hosting, and multi-stage vishing component.(2026-08-04:irs-fake-digital-asset-compliance-portal-physical-mail-phishing)event
↯7a02ee62
Journal of Accountancy and CPA Practice Advisor publish detailed analyses of the scam, including victim guidance and confirmation that no arrests have been made.(2026-08-03:irs-fake-digital-asset-compliance-portal-physical-mail-phishing)event
↯d031226e
Additional mainstream crypto and financial media outlets including Northeast Times and Crypto Times report on the IRS warning. @IRSnews posts an alert on X.(2026-07-31:irs-fake-digital-asset-compliance-portal-physical-mail-phishing)event
↯cfa4f19a
IRS Criminal Investigation issues a public fraud alert confirming that the 'Digital Asset Compliance Portal' does not exist and that the agency did not send the letters. IRS-CI Chief Jarod Koopman characterizes it as a 'professionalized international scam operation.' Bloomberg reports on the campaign.(2026-07-30:irs-fake-digital-asset-compliance-portal-physical-mail-phishing)event
↯6e2479bb
Coinbase and DarkTower jointly issue a consumer alert identifying the fraudulent 'Digital Asset Compliance Portal' campaign, flagging the domain infrastructure and attack mechanics.(2026-07-28:irs-fake-digital-asset-compliance-portal-physical-mail-phishing)event
□03d3beba
IRS Fake Digital Asset Compliance Portal — Physical Mail Phishingorganization
↯1b633a94
Civil lawsuit filed by Timothy A. Kinnetz Revocable Trust in U.S. District Court for the District of South Dakota (Case No. 4:25-cv-04134) against Benaiah entities, Benjamin Paul Wiener, Joshua DeWitt, and Christopher Charles Hmielewski.(2025-07-18:benjamin-paul-wiener-benaiah-capital)event
↯b4d699c5
Benaiah entities collapse following FBI and IRS raids on Wiener's residence and the fund's Sioux Falls office.(2025-06-01:benjamin-paul-wiener-benaiah-capital)event
↯9191b448
Kinnetz's Kraken account is liquidated to $599.30 without investor authorization.(2025-03-01:benjamin-paul-wiener-benaiah-capital)event
↯f9e188b0
Timothy A. Kinnetz Revocable Trust invests $4 million with Benaiah entities — $1 million to Benaiah Digital, $3 million to a Kraken account managed by Benaiah Capital.(2021-12-01:benjamin-paul-wiener-benaiah-capital)event
↯c1edc2a3
A US court order bars Arbitrum from releasing the $71 million frozen after the KelpDAO hack, with lawyers for 2015 DPRK kidnapping victims claiming the funds as North Korean state assets under a pre-existing federal judgment.(2026-08-01:dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign)event
↯5ff7b6ac
A wallet linked to the Drift exploit transfers approximately 23,095 ETH ($44.4 million) to Tornado Cash — the first major laundering movement since the April 1 attack. PeckShield flags the transactions.(2026-07-24:dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign)event
↯9140e176
Arbitrum DAO votes to implement a protocol-level lock on KelpDAO exploit-linked assets.(2026-05-12:dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign)event
↯992d09fa
KelpDAO publicly states that LayerZero approved the 1-of-1 DVN setup it later blamed for the $292 million exploit.(2026-05-05:dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign)event
↯ab9e88ff
KelpDAO and Aave request Arbitrum to release the $71 million in frozen ETH for recovery and bad debt resolution purposes.(2026-04-27:dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign)event
Data refreshes every 5 minutes · All metrics derived from Supabase