GhostAction Escalates: Credential-Stealing Workflow Now in Tens of Thousands of GitHub Repositories
Socket says more than 500 compromised GitHub accounts have committed a malicious workflow named security-audit.yml to tens of thousands of repositories since October 7. The new variant doesn't just take GitHub Actions secrets — it sweeps the full git history for AWS keys, AI service tokens and source-control credentials, including ones developers thought they had deleted.
What We Cover
One beat: the security of crypto.TrustGrade Cybersecurity Crypto News reports hacks and exploits, audit findings, enforcement and takedowns, phishing and malware operations, and incident analysis. Every story is verified against at least two independent sources or on-chain evidence before it runs — no price predictions, no token promotion, no noise. Trust data comes from TrustGrade, the trust layer for crypto.
Latest News
79thVault Drained of $12.5M in Suspected Operator Key Compromise on BNB Chain
A privileged wallet moved 2.01 million 79AU out of the project's PancakeSwap pool on October 7 and converted the proceeds into 16,249 BNB, roughly $12.5 million. CertiK, PeckShield and GoPlus tracked the funds; investigators say the pattern points to a compromised operator key or insider action — not a contract bug.
Sixteen Fake Firefox Wallet Extensions Stole Seed Phrases via Cloudflare Workers
Socket identified 16 malicious Firefox add-ons — four modified Rabby clones and twelve OKX-lookalike 'Portal WALLET' extensions — that harvested recovery phrases and private keys during wallet imports and transmitted them in plaintext to attacker-controlled Cloudflare Workers. Mozilla unpublished all 16 by October 5; anyone who typed a seed phrase into one should treat that wallet as compromised.
Security Digest — October 9, 2026: CFTC's $30M Fundsz Penalty, Set Protocol Rounding-Error Bug, 79AU Aftermath
Today's roundup: a federal court orders $30 million in penalties against two Fundsz promoters for a fake-algorithm investment scheme; Set Protocol reports a small exploit tied to a rounding error in actualizeFee(); the 79thVault drain stalls at a single consolidation address; and Abstract Chain sets a December 15 deadline for users to move their funds.
Leaked Chats Expose Silent Ransom Group's Crypto Wallets — and Chainalysis Confirms the Money Trail
A dump of nearly 5,700 internal messages allegedly from the Russia-linked Silent Ransom Group claims about $207 million in payments from 27 law firms and financial institutions in six months. Chainalysis has verified crypto addresses in the leak as genuinely tied to the group, including one wallet funded entirely by a single ransom payment exceeding $10 million.
Anthropic Opens Claude's Cyber Capabilities to Verified Defenders as AI Scanning Tally Passes 134,000 Findings
The expanded Cyber Verification Program merges Project Glasswing into three access tiers for verified security professionals, with fewer automated blocks on malware analysis and vulnerability testing — and new numbers on what AI-driven scanning has already found.
GhostAction Returns: 772 GitHub Repositories Hit in New Credential-Stealing Workflow Wave
GitGuardian documents a revived GitHub Actions supply-chain campaign that injected fake 'security check' workflows into 772 public repositories in a month — with only 16 percent of victims demonstrably cleaned up by October 5.
MALFEX: npm Wallet-Stealer Packages Racked Up 40,000 Downloads, Three Still Live Without Advisories
Checkmarx documents an npm supply-chain campaign delivering a RAT and a crypto-wallet stealer through eight malicious packages — three of which remained installable with no complete security advisory as of October 1.
Uranium Finance Exploiter Convicted as Jury Rejects 'Code Is Law' Defense in $53.3 Million DeFi Theft
A Manhattan federal jury found cybersecurity consultant Jonathan Spalletta guilty of computer fraud and money laundering over the 2021 Uranium Finance exploits, declining his argument that calling public smart contract functions is not a crime.
Crypto 'Godfather' Adam Iza Sentenced to 78 Months in $37 Million Meta Fraud Case
A federal judge in Los Angeles ordered the 26-year-old, already serving 15 years for an attempted Bitcoin robbery in Connecticut, to pay $23.4 million restitution for defrauding Meta of more than $37 million, evading taxes on the proceeds, and hiring off-duty LASD deputies to harass his rivals — a scheme that has now produced convictions against five former deputies.
Bitget Hack Laundering Generated $761,000 in Protocol Fees, On-Chain Analysis Finds
Independent researcher Andrey Sergeenkov traced $761,725 in fees collected by THORChain liquidity providers, MetaMask, Chainflip and CoW EthFlow while moving the $387.5 million stolen from Bitget — and followed $259,718 in THORChain affiliate fees to seven addresses with additional financial links to the laundering wallets, one trail ending at an OKX hot wallet.
FinCEN Withdraws Crypto Mixer Rule and Self-Hosted Wallet Proposal
The Treasury bureau formally pulled two proposals — the 2023 rule that would have treated crypto mixing as a primary money laundering concern and the 2020 'unhosted wallet' identity-verification rule — saying the mixer definition risked a chilling effect on legitimate activity and that neither rule was tailored to its purpose.
Flash Loan Attacks Drained $1.2 Billion From DeFi in Four Years, Peer-Reviewed Study Finds
A University of Winchester study published in the Journal of Financial Crime scanned 20.63 billion transactions across seven blockchains, counting 254 successful DeFi attacks and $6.568 billion in losses between February 2020 and July 2024 — including 72 flash loan incidents worth $1.211 billion that grew more sophisticated and harder to predict over time.
CertiK's Intel3D Report: Agentic AI Joins the Crypto Security Workforce, but Humans Keep the Accountability
A new CertiK report describes autonomous AI agents taking on smart contract analysis, live transaction monitoring and cross-chain fund tracing as attacks accelerate — while warning that agents with authority to act create their own attack surface, from prompt injection to confident wrong answers.
Citrix Patches NetScaler Zero-Day Exploited in Targeted Attacks — the Appliance Layer Bitget's Breach Exposed
Citrix released emergency fixes for CVE-2026-88779, a high-severity NetScaler ADC and Gateway flaw exploited as a zero-day against SAML-enabled deployments — including instances patched days earlier — weeks after Mandiant's Bitget report showed third-party security appliances as the entry path to a $387M theft.
X Money Bridge 'Revenue' Linked to USDG Wallet Draining via Permit Signatures, Salus Says
Security firm Salus reports that users of Revenue, an unofficial X Money-to-crypto bridge, were drained through permit signatures granting unlimited USDG spending approval, with stolen funds split 20/80 between two attacker addresses — a pattern resembling Inferno's drainer-as-a-service model, though no infrastructure link was established.
Undercover With the Launderers: ZachXBT Details Infiltration of Chinese Syndicate Suspected of Moving $1B+ for Lazarus
In an October 5 disclosure, blockchain investigator ZachXBT describes posing as a client of a Chinese organized crime network he alleges laundered more than $1 billion for North Korea's Lazarus Group, tracing a cluster of over $12 million in Bybit exploit funds and enabling a 442,000 USDT freeze by Tether.
Unidentified Base Vault Drained of $6M in wstETH After Multisig Whitelist Flip
An unnamed vault on Base lost 1,783 wstETH (about $6 million) after an attacker-controlled contract was removed from the vault's whitelist and re-enabled one minute later with valid multisig signatures — the fourth Aave-linked or Base incident in a week, according to Blockaid, PeckShield, CertiK and ExVul.
Bitget Trail Narrows: Chainalysis Attributes $387M Theft to North Korean Actors, BitOK Tracks 87.8 BTC
Chainalysis says the September 24 Bitget breach was DPRK-attributed, pushing North Korean-linked crypto theft past $1 billion in 2026, while a BitOK trace pins 87.82 BTC in ten unspent outputs and Mandiant's preliminary report describes a supply-chain path through third-party security appliances into Bitget's wallet job server.
Microsoft Confirms X Account Hijack Used to Push Fake Clippy Token
Unknown attackers compromised Microsoft's 13-million-follower X account to amplify a Clippy-impersonation account promoting a $Clippy token claimed to pair with $MSFT stock — a confirmed unauthorized-access incident that shows verified brand accounts remain prime pump-and-dump infrastructure.
NEAR Intents Closes $3.8M Exploit Probe After Funds Returned On-Chain With an Apology
NEAR Intents says the full $3.8 million taken in an October 1 exploit of its cross-chain system has been returned — confirmed by a BNB Chain transaction whose input data carried a message from the address labeled 'Near Intents Exploiter 1' — and the team has stopped its investigation, urging researchers to use bug bounties.