@evilcos

Founder of @SlowMist_Team // 分身一号/捉虫大师/救火运动员 // 🕖灾备频道 https://nitter.cf/t.co/bMGdsBkYwM

HACKING
Joined November 2008
这行业割韭菜的行为越多,诈骗越多,跑路越多,黑客事件只会越多,一些有能力的黑客决不允许在“聪明”赚钱这块输过这般人。
506
22
5
604
243,637
Cos(余弦)😶‍🌫️ retweeted
Seeing a lot of chat about how the Bitget hack funds are being moved, so I wanted to share how it looks from our side at @chainflip. @MistTrack_io picked up that the exploiter tried to push funds through Chainflip and got rejected at the broker. Nothing was frozen. The deposit just got sent back to the refund address. That's how our screening works: every swap gets checked in real time, and if something is flagged, it doesn't go through and gets returned to the sender. I want to be honest, though; this is one example of the system doing its job. It doesn't mean we've stopped everything, and I'm not going to pretend we have. I think anyone that has claimed that is not reading the flows correctly. These funds are touching almost every major DEX. It's an ongoing battle, and it will continue to be so until everything has moved. What makes this one particularly hard is how the funds are moving. The hackers are routing through several hops first to obfuscate where the funds came from. By the time they come out the other side, they often don't get flagged as dirty along the way, even though they obviously are. Chainflip tends to sit at the end of that chain of steps as they are moving to Bitcoin, so for us it's the point where things really have to be tight. If we miss it, there often isn't another checkpoint after us. @evilcos made a point I completely agree with. The laundering is automated. Funds get split up and bridged across chains, and the second one rejects them; they move on to the next one. AML and KYT tools are still catching up to that speed. So for us it's about being fast and constantly adjusting as the methods change. This is where I have to signal out @SEAL_Org and @zeroshadow_io. The live tracking they do is honestly some of the most up-to-date I've seen in the data sources we use, and they put a lot of effort into getting protocols, exchanges, and issuers to work together and help where they can. We couldn't keep up without people like them. On the bigger debate, some have gone down the route of freezing funds; others don't screen at all. We've tried to land somewhere in between: we don't want stolen funds using Chainflip at all, but we also don't want to be taking custody and freezing. Someone put the argument against freezing well: "My cash dollar has literally no opinion if I hand it over to buy coffee or drugs; that's the whole point." Once a protocol starts making decisions about whose funds to hold, it's hard for it to be seen as neutral. I think there's something to that, and it's part of why refunding feels like the right approach for us. That said, I'm really not trying to call anyone out. Whatever approach someone takes, as long as there's a genuine effort to stop these flows, I respect it. We've been here before too. @Bybit_Official, @KelpDAO , and a bunch of other big incidents all taught everyone something, and each time the response has gotten a bit better. This one will be no different. If anyone wants to chat more about screening or how we handle this stuff, my DMs are open.
MistTrack: Bitget Exploiter Attempted to Route Stolen Funds via Chainflip but Broker Rejected According to on-chain monitoring by SlowMist's tracking arm MistTrack, the Bitget exploiter attempted to move stolen funds through the cross-chain liquidity protocol Chainflip, but the transaction was rejected at the broker interface ("deposit rejected by the broker"). The protocol did not freeze the capital but instead refunded the deposit directly back to the sender, effectively preventing the attacker from routing the exploit proceeds through the network.
3
5
2
16
2,440
一个残酷事实:我跟进跟踪了几小时,Chainflip 桥确实在很努力阻拦朝鲜黑客洗币,可惜的是 AML/KYT 落后黑客洗币速度。洗币团伙自动化大量打散资金,通过各类桥跨到不同链,如果被风控或者阻拦退回就会立即尝试下一条洗币路径,最终都将换成 BTC,然后在 BTC 上 CoinJoin 方式接着混淆洗币。 这是一个不断在演变的洗币工程。
The @bitget exploiter tried to move the stolen funds through @Chainflip. Chainflip’s response? “Deposit rejected by the broker.” 👋 No freeze, but no luck either — the funds were refunded. 👍 Nice try. 😶 We’ll continue tracking the movement of the stolen funds. 🔗 scan.chainflip.io/channels/1…
30
9
5
115
43,859
Cos(余弦)😶‍🌫️ retweeted
🚨 Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution. As we previously reported, this update is highly relevant to the iOS attack activity we have been tracking. Apple confirmed that the vulnerability may have been exploited in highly sophisticated attacks targeting specific individuals on iOS versions before iOS 27. For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data. 🔐 Please: • Update your iPhone, iPad, Mac and other Apple devices to the latest available security updates. • Avoid installing apps from unknown or untrusted sources. • Do not open suspicious links in Safari or in-app browsers. • Treat unexpected files, links and app installation prompts with caution. Stay alert and keep your devices updated. Apple Security Update: support.apple.com/en-us/1492…
2
10
7
28
10,877
Cos(余弦)😶‍🌫️ retweeted
The @bitget exploiter tried to move the stolen funds through @Chainflip. Chainflip’s response? “Deposit rejected by the broker.” 👋 No freeze, but no luck either — the funds were refunded. 👍 Nice try. 😶 We’ll continue tracking the movement of the stolen funds. 🔗 scan.chainflip.io/channels/1…
4
9
4
47
47,525
Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. support.apple.com/en-us/1492…
1
2,866
NEAR Intents 成功冻结住 Bitget 黑客洗币过程中的 $503k 资金👍协议有 AML/KYT 机制。
5
5
2
52
17,033
看来之前提醒是很对的,27 版本之前的 iOS 都被一些黑灰团伙漏洞利用,盗窃 iPhone 用户的加密钱包… ⚠️⚠️⚠️及时更新你的 iPhone/iPad/Mac 等到最新版本!谨慎安装不明 App!谨慎 Safari(及 App 内置浏览器)打开不明链接!
🧐🧐🧐 苹果发布重要更新,很可能是修复被用于窃取加密钱包的零日漏洞。 “苹果已知晓一份报告,该报告指出此问题可能已在针对特定目标个人的极其复杂的攻击中被利用,影响 iOS 27 之前的 iOS 版本。” cc @evilcos
5
7
7
102
53,835
Cos(余弦)😶‍🌫️ retweeted
🛡️ Powered by @SlowMist_Team! On-chain investigations done in a single step. Say goodbye to tedious manual checks and internal burnout! See how 0xDarren..._... (@0xDarrenG) uses the MistTrack Agent on Finch to handle on-chain risk control and fund tracking in just 10 seconds! Click the link to experience your exclusive on-chain security Agent 👇 finchtech.ai/market/chips/ag…
On chain investigation made simple by MistTrack Agent powered by @SlowMist_Team available now on @FinchTechCN Drop a wallet address or tx hash into MistTrack Agent and let it trace fund flows, map connections, and flag potential risks in seconds. finchtech.ai/market/chips/ag…
35
64
1
242
11,784
Cos(余弦)😶‍🌫️ retweeted
Bitget CEO Gracy Chen 在今日社区直播中表示,经完整溯源,本次安全事件系黑客利用第三方安全产品漏洞窃取内网权限凭证,并向钱包系统伪造提现命令,绕过风险校验执行异常转账;事件未涉及私钥泄露,冷钱包未受影响,具体技术细节将在后续安全报告中披露。Gracy 表示,核实后的损失处于保护基金覆盖范围内,Bitget 计划在一周内将保护基金重新补足至 3 亿美元基准线。目前 BTC 提现已恢复,ETH、USDT 等提现将按照此前公布的时间表陆续恢复。 wublock123.com/news/bitget-c…
4
2
8
8,919
早上和安全团队交流了下,顶流模型已经不用之前我们沉淀的那些安全 Skills 了...聪明到让我们省心😂
71
15
6
394
84,020
Cos(余弦)😶‍🌫️ retweeted
AGREE
Because multiple Asgardex contributors explicitly refused to return the ~$900K in fees you profited from the Bybit hack by DPRK. Multiple of those teams you mentioned decided to return fees. Choosing to keep Thorchain as decentralized as possible and not censoring activity at the protocol level is one thing. Profiting fees off the hack (knowingly) and then refusing to return those fees after is criminal.
2
1
1
19
11,313
1. Bitget 被盗是个传播广泛、公开、巨额且明确的黑客事件,而且很快就关联出朝鲜黑客资金痕迹 2. Circle/Tether 等都及时出手做了相关资金冻结,尤其 Circle 冻结了黑客持有的 USDC,实属难得,但感谢这次出手 3. THORChain 自己曾经被盗,出手干预自己的所谓“去中心化”平台速度也是很快的(如图,官方支持的大红按钮),但遇到行业大事件,忽视各方联系沟通,将自己媲美比特币、以太坊,说自己是去中心化,无权干涉…然后美滋滋地享受朝鲜黑客大额跨链贡献出的手续费… 4. 去中心化不是傻逼一样的口号,行业大事件下,分清楚哪个是真正要共同解决的问题才是关键 5. 真不要轻易把自己的“去中心化平台”去类比比特币/以太坊,真的很多很多不一样…不展开了…这种话题本就容易引起争论…
We are devasted to hear about the recent exploit and can imagine how difficult this must be for everyone involved. THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds? @star_okx @GracyBitget
55
40
21
352
247,924
Cos(余弦)😶‍🌫️ retweeted
I don’t think THORChain’s TSS + validator model represents true decentralization. The selected validators set collectively controls the underlying assets in the TSS vaults. Once the signing threshold is reached, those validators can move the funds. So from a custody perspective, THORChain is not comparable to Bitcoin or Ethereum base-layer consensus — it effectively acts as an intermediary between users and the native chains. TSS distributes control among multiple parties, but distributing an intermediary does not eliminate the intermediary.
We are devasted to hear about the recent exploit and can imagine how difficult this must be for everyone involved. THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds? @star_okx @GracyBitget
102
38
22
358
178,786
Cos(余弦)😶‍🌫️ retweeted
针对Bitget被盗事件,又一次让我想起来我们开源的这份文档,cex可以参考。
来自 NexVault 的《Web3.0 加密货币交易所安全风险指南精编》总结了顶级交易平台可能面对的风险 —— 技术 + 管理 + 人为,全链防控一览。 📄 指南: github.com/nexvault/CEX-Secu… #CryptoSecurity #CexCrypto #Web3
7
36
15,160
Cos(余弦)😶‍🌫️ retweeted
Tether banned the wallet owned by the bitget exploiter etherscan.io/tx/0xdd30e4831e…
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
15
19
4
179
62,117
Cos(余弦)😶‍🌫️ retweeted
🚨 Unauthorized NFT transfers observed via Limit Break's Payment Processor on Ethereum and ApeChain. If you've approved Payment Processor on any chain, revoke it as a precaution. Cancelling listings doesn't remove the approval. V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 V3: 0x9a1d00000000fc540e2000560054812452eb5366 Per @0xQuit, NFTs in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 are held by a whitehat and expected to be returned.
2
6
30
7,471
Cos(余弦)😶‍🌫️ retweeted
最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。 其他几点都是说过的,我再强调一下: -我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。 -Bitget Wallet 为自托管钱包,运行于与 Bitget Exchange 完全分离且独立的基础设施之上,未受此次事件影响。 -Bitget Exchange 平台的充值交易奖励等功能都继续正常运行。在我们完成额外安全核查期间,提币功能暂时暂停;待我们确认可以安全恢复后,将尽快恢复提币。 -我们明白在此类事件发生时,用户希望尽快获得答复。我们将通过Bitget官方渠道及时发布最新进展。请关注我的和@bitget @xiejiayinBitget 的 X账号以及Bitget官方公告。
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
335
56
27
517
183,694
Cos(余弦)😶‍🌫️ retweeted
We’re working closely with @bitget on the ongoing investigation. For further details, please refer to Bitget’s official updates.
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
10
10
85
21,535
来自 @SpecterAnalyst 的链上分析关联出朝鲜黑客历史上的有关资金。另外,这次手法上确实和之前朝鲜黑客相关组织的手法类似,包括资金归集习惯… 更多信息见 Bitget 官方披露就好,我们在协同调查中。
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
11
16
4
95
50,442
补充下:链上部分我们有更直接的证据指向朝鲜黑客。
1
6
3,796