Skip to main content
AVOID.NET
← Back to search
[TOPIC]

Malware

Investigations tagged with this subject. A topic describes what a page is about — an attack type, a jurisdiction, a regulator, a named actor — as distinct from the source that produced it.

3 investigations on this topic

avoid.net/nexera32/100[WARNING]

Nexera (formerly AllianceBlock) is a blockchain infrastructure protocol focused on compliant real-world asset tokenization, operating primarily on Ethereum. In August 2024, a threat actor later attributed to North Korea's Lazarus Group used social engineering and BeaverTail malware to steal smart contract management credentials, enabling unauthorized transfer of 47.24 million NXRA tokens valued at approximately $1.9 million. The team mitigated further losses by zeroing out and subsequently burning the 32.5 million tokens that remained in the attacker's wallet, limiting confirmed liquidated losses to roughly $449,000.

avoid.net/ton-blockchain44/100[WARNING]

TON (The Open Network) is a public layer-1 blockchain originally developed by Telegram and now deeply integrated with the Telegram messaging app under Pavel Durov's direction. It is a live, widely used network with legitimate exchanges, DeFi protocols, and hundreds of millions of Telegram Mini App users, but it has also become a recurring venue for phishing drainers, pyramid schemes, rug pulls, malware command-and-control infrastructure, and illicit Telegram-based marketplaces, in part because analytics and forensic tooling for TON lagged behind more established chains. Separately, Telegram co-founder Pavel Durov faces an unresolved criminal investigation in France opened in 2024 and, since July 2026, an in-absentia terrorism-related charge in Russia; neither has resulted in a conviction.

avoid.net/cardano72/100[CAUTIONARY]

Cardano (ADA) holders face a persistent and multi-vector threat landscape that includes deepfake giveaway scams impersonating founder Charles Hoskinson, social media account hijackings used to promote fraudulent tokens, phishing campaigns distributing credential-stealing malware disguised as wallet software, and NFT-based wallet drainers. The Cardano Foundation's own X account was compromised in December 2024, resulting in the promotion of a fake token and false regulatory claims. State-sponsored actors including the North Korean Lazarus Group have also targeted ADA holders through the Atomic Wallet supply chain attack.

avoid.net — verified advice for a post-truth world