← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,675
Relationships
18,058
Potential duplicates
0
Filter by kind
Entities
↯7324ee16
SecondFi detects the breach and activates emergency response protocols. Platform placed in maintenance mode.(2026-06-22:ctrl-wallet-security-exploit-and-forced-shutdown)event
↯00df96ce
First wave of coordinated attacks begins against SecondFi Cardano wallets, exploiting a cryptographic signing flaw to reconstruct private keys from public transaction data.(2026-06-21:ctrl-wallet-security-exploit-and-forced-shutdown)event
↯deb8c20a
EMURGO, commercial arm of Cardano, acquires Ctrl Wallet's technology infrastructure. The $CTRL token is explicitly excluded from the deal. EMURGO simultaneously rebrands Yoroi Wallet to SecondFi.(2026-04-29:ctrl-wallet-security-exploit-and-forced-shutdown)event
↯9fd76216
Ctrl Wallet initiates $XDEFI to $CTRL token migration at a 1:1 ratio, with the $XDEFI token scheduled to deprecate September 25, 2025.(2024-10-17:ctrl-wallet-security-exploit-and-forced-shutdown)event
↯fff0adbc
XDEFI Wallet publicly rebrands to Ctrl Wallet, announcing enhanced multichain features and new user onboarding focus.(2024-07-17:ctrl-wallet-security-exploit-and-forced-shutdown)event
↯64def702
XDEFI Wallet founded as a multi-chain self-custodial wallet.(2020-01-01:ctrl-wallet-security-exploit-and-forced-shutdown)event
□8f452fc0
Ctrl Wallet — Security Exploit and Forced Shutdownorganization
↯c8da4a91
As of this date, no law enforcement action, OFAC designation, or independent on-chain confirmation of Sector Drainer attributed thefts has been identified in publicly available sources.(2026-08-04:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
↯f72c14e2
Dark Web Informer article last modified, indicating continued monitoring or updates to the Sector Drainer report.(2026-03-21:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
↯2452dea0
Dark Web Informer publishes the first indexed public report on Sector Drainer, followed by a Brinztech breach alert the same day.(2026-03-18:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
↯704b2d29
Europol-led coalition dismantles Tycoon 2FA phishing-as-a-service platform, reflecting broader law enforcement pressure on the phishing-as-a-service and DaaS ecosystem during the same period Sector Drainer surfaced.(2026-03-04:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
↯e7459b81
SectorD registers on underground cybercrime forums (including crdworld.biz and carder.market) and posts the Sector Drainer DaaS advertisement listing a Phantom 0-day bypass, hidden drain, autowithdraw, and free hosting.(2026-03-01:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
↯321559cd
Sector Drainer operator (SectorD) claims the service began operating, though this assertion is unverified and comes exclusively from the operator's own advertising copy.(2024-01-01:sector-drainer-daas-wallet-drainer-with-phantom-0-day-bypass)event
□abc91a17
Sector Drainer — DaaS Wallet Drainer with Phantom 0-Day Bypassorganization
↯08a7e07f
Galaxy Research estimated potential losses could reach 2,055 BTC ($130 million) as a suspected fourth exploitation wave was under investigation. The Coldcard exploit and secondary phishing campaign together represented one of the largest self-custody security incidents in Bitcoin's history.(2026-08-04:coldcard-fake-hardware-audit-phishing-campaign)event
↯68ed8072
Proofpoint documented the fake hardware audit phishing campaign, reporting that attackers had launched spoofed Coinkite emails directing victims to a cloned Coldcard website where a 'Start Hardware Audit' button delivered a GitHub-hosted batch file installing ScreenConnect remote-access software. A live human chat operator was observed guiding victims through the process.(2026-08-03:coldcard-fake-hardware-audit-phishing-campaign)event
↯4dac37fa
Coinkite dispatched security advisory emails to all reachable customer addresses using its store and newsletter subscription systems, reaching addresses retained from purchases beginning in 2019. This prompted public criticism over data retention practices inconsistent with prior company statements.(2026-08-02:coldcard-fake-hardware-audit-phishing-campaign)event
↯9359d7bf
Galaxy Research tracked two additional waves of on-chain exploitation bringing total losses to 1,367 BTC (approximately $88.6 million) across 4,585 victim addresses, with at least 15 separate attackers identified.(2026-08-01:coldcard-fake-hardware-audit-phishing-campaign)event
↯8bfce694
Coinkite released emergency patched firmware (4.2.0+ for Mk3; 5.6.0+ for Mk4/Mk5; 1.5.0Q+ for Q) and advised all users on affected firmware versions to generate new seeds and migrate funds. Coinkite confirmed the vulnerability in a formal blog announcement.(2026-07-31:coldcard-fake-hardware-audit-phishing-campaign)event
↯b5d1de33
Block and independent researchers identified active exploitation of the Coldcard firmware RNG flaw. Coinkite published a preliminary vulnerability disclosure. An attacker drained 594 BTC ($38 million) from approximately 500 single-signature wallets in a 25-minute window.(2026-07-30:coldcard-fake-hardware-audit-phishing-campaign)event
↯731159bb
Coldcard firmware version 4.0.0 shipped with a coding error that routed seed generation to a deterministic software PRNG (Yasmarang) instead of the STM32 hardware RNG, reducing effective entropy to approximately 40 bits on Mk3 devices.(2021-03-01:coldcard-fake-hardware-audit-phishing-campaign)event
□d551fae0
Coldcard Fake Hardware Audit Phishing Campaignorganization
↯377d19e3
Bloomberg reports Yaroch turned himself in. Additional reporting confirms approximately $925,426 in total assets recovered. The adversarial nation is identified as Russia by NBC News sources. Yaroch is held in custody in Alexandria, Virginia.(2026-08-04:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯11c7bebc
Yaroch makes his first court appearance. U.S. Magistrate Judge Lindsey R. Vaala orders temporary detention. The FBI publicly confirms his termination. The case is widely reported across major news outlets including NBC News, CNN, Bloomberg, and CoinDesk.(2026-08-03:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯23d5e30f
Criminal complaint filed in the U.S. District Court for the Eastern District of Virginia (Case No. 602203), charging Yaroch with interstate transportation of stolen goods (18 U.S.C. § 2314) and receipt of stolen goods (18 U.S.C. § 2315).(2026-08-01:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯f2ae5fdd
Yaroch is arrested following execution of a search warrant. Investigators recover a Trezor hardware wallet, handwritten seed phrases, three passports, and an iPhone containing ChatGPT conversation logs and travel documents including a Portuguese power-of-attorney. A Kraken exchange account containing approximately $188,570 is identified.(2026-07-31:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯6dc1ad73
FBI interviews Yaroch at headquarters. His personal cryptocurrency wallet valued at approximately $1 million is identified. FBI agents collect property from his Ashburn, Virginia, residence. Yaroch subsequently withdraws his consent to a search of his cryptocurrency wallets.(2026-07-28:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯73aa6190
Yaroch moves approximately $1.02 million in cryptocurrency to Suilend, a decentralized lending protocol on the Sui blockchain, accessed via the Slush wallet application. He allegedly selects Suilend partly because he likes its water-droplet logo and intends to generate yield on idle assets.(2026-07-23:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯00947029
Yaroch queries ChatGPT about how someone with approximately $1 million could leave the United States and obtain residency or citizenship in an EU country. Follow-on queries include Turkish transit visa requirements and employment prospects in Greece.(2026-06-04:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯9ce425d4
Yaroch queries ChatGPT about how to invest approximately $1 million for maximum profit, per forensic analysis of his iPhone subsequently recovered by investigators.(2026-05-28:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯2fb94884
Yaroch transfers from the FBI Boston Field Office to the Counterintelligence and Espionage Division at FBI headquarters in Washington, D.C., while allegedly continuing to hold and manage the stolen cryptocurrency.(2025-02-01:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯8cd38f41
Alleged unauthorized transfers begin. Yaroch allegedly accesses FBI systems to extract seed phrases and private keys for cryptocurrency wallets tied to the active investigation, memorizes the credentials, and begins transferring funds to personal wallets. Approximately 10 to 12 transfers are alleged to have been made.(2024-12-01:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯eef54196
Yaroch is exposed to adversarial cryptocurrency wallet credentials in the course of his FBI duties at the Boston field office. He later alleges this is the point at which he became 'frustrated' the FBI would not act against the accounts.(2024-11-01:patrick-steven-yaroch-fbi-agent-crypto-theft)event
↯e9f8c1bb
Patrick Steven Yaroch joins FBI Boston Field Office and is assigned to a national security squad investigating cryptocurrency accounts linked to an adversarial foreign nation, later identified as Russia.(2017-01-01:patrick-steven-yaroch-fbi-agent-crypto-theft)event
□b16232d3
Patrick Steven Yaroch — FBI Agent Crypto Theftorganization
◎83a6bbec
◎c4a6261e
Data refreshes every 5 minutes · All metrics derived from Supabase