This week has seen significant developments in the realm of cybersecurity.
- An outdated random number generator led to a theft of $5.7 million in cryptocurrency.
- A new info-stealer for macOS has been siphoning off funds from crypto wallets.
- The creator of the Ransom Cartel ransomware was apprehended at the Belarus border.
- Hackers leaked data of over 100,000 police employees in the UK.
Outdated Random Number Generator Causes $5.7M Crypto Theft
A random number generator used for creating seed phrases has been linked to a series of attacks on cryptocurrency owners. Analysts from Coinspect reported on a new malicious campaign dubbed Ill Bloom.
The core issue was with the CryptoJS.lib.WordArray.random() function, which was written 12 years ago. When generating 128- and 256-bit seed phrases, it produced such weak entropy that the effective brute-force search space was reduced from cryptographically secure levels of 2^128 and 2^256 to negligible levels of 2^39 and 2^47. This vulnerability allowed attackers to crack victims' keys using standard hardware.
Hackers continuously generated potential password combinations, converted them into BIP39 addresses, and checked them against public blockchain data. The exploitation occurred in two waves:
- On May 27, attackers drained 431 accounts, totaling approximately $3.14 million.
- From May 30 to July 13, they stole an additional $2.55 million from 522 wallets.
According to analysts, the confirmed damage amounts to around $5.7 million, affecting Bitcoin, Ethereum (and EVM-compatible networks), Tron, Rootstock, and Polygon.
The vulnerable code was utilized by at least five crypto wallets:
- NanChat — fixed in version 1.3.0;
- Bitcoin Libre — corrected in version 4;
- Bexo Wallet — developers announced changes in version 20.1.0, but secure builds were not yet available in the App Store or Google Play at the time of publication;
- RRWallet and Milo — both projects have been shut down.
Coinspect cautioned that merely updating the vulnerable application will not secure the funds. The seed phrase originally created with the weak generator remains compromised, even if imported into a secure hardware wallet.
New Info-Stealer for macOS Draining Crypto Wallets
A newly discovered info-stealer for macOS employs an unconventional method to steal cryptocurrency: it spreads through emerging ClickFix attacks, stealing system passwords and Apple Keychain data. Researchers from Huntress identified the malware, which is written in Go.
The attack starts with an email: the victim clicks a link to a phishing page, where they are instructed to copy and execute a specific command in the terminal. The sequence of events is as follows:
- Downloader. The script collects basic system information and downloads a Mach-O file compiled for the victim's CPU architecture.
- Disguise. The malware creates a directory named trustd (mimicking a legitimate macOS process for certificate verification), copies its code there under the name com.apple.verified, and removes the extended attribute com.apple.quarantine to avoid antivirus alerts upon execution.
- Privilege escalation. Using the system utility osascript, the malware displays a fake system error window, prompting the user to enter their administrator password.
Once embedded in the system, the stealer analyzes password databases in browsers, cookie files, and Apple Keychain contents.
Its standout feature is a module for handling cryptocurrencies, enabling it to intercept and modify transactions in Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple networks just before they are signed.
Experts noted that this is the first instance of a crypto-drainer that leaves funds in the crypto wallet. The virus's code includes functions to calculate the total transaction amount and discreetly redirect only a specified percentage to the hacker's address. This method allows the attackers to exploit victims' accounts without raising immediate suspicion.
Huntress reported that this infrastructure is managed by the Russian company Aeza Group, which has previously faced sanctions from the US and UK for providing bulletproof hosting services to ransomware operators.
Ransom Cartel Creator Arrested at Belarus Border
The US Department of Justice sentenced 40-year-old Belarusian Maxim Silnikov for creating and managing the Ransom Cartel ransomware infrastructure.
Silnikov, known on Russian-speaking dark forums by aliases J.P. Morgan, xxx, and lansky, has been active in cybercrime since at least 2005. He launched the Ransom Cartel project in May 2021, following a classic CaaS model.
How the syndicate operated:
- Technical foundation. Ransom Cartel's code bore a strong resemblance to the popular ransomware REvil. Analysts speculated that Silnikov might have been a former core member of REvil who lacked full access to the original source code due to the absence of certain advanced obfuscation features in the new virus;
- Organizer role. Silnikov was responsible for recruiting partners, collaborating with initial access brokers, and managing the shadow website where participants coordinated attacks, negotiated with victims, and distributed ransoms, which were then laundered through cryptocurrency mixers.
According to investigators, from 2021 to 2023, Ransom Cartel attacked at least 18 companies worldwide, resulting in confirmed downtime losses exceeding $6.7 million, with ransom demands totaling at least $5.2 million.
Notable incidents include an August 2022 attack on a medical startup specializing in robotic surgery, which was paralyzed for two months. In spring 2023, hackers breached several law firms' infrastructure (two of which ultimately paid ransoms of $125,000 and $300,000 for data recovery).
Silnikov was arrested in Spain in July 2023 during an international operation. Although he managed to escape, authorities later apprehended him while attempting to cross the Belarus border. He agreed to extradition.
Silnikov was found guilty of conspiracy against the US, electronic communications fraud, and identity theft under aggravating circumstances. He faces a sentence of 16 years in prison.
Hackers Leak Data of Over 100,000 UK Police Employees
In the UK, a breach of the National Police Legal Database (PNLD) compromised contact details of more than 100,000 police officers and criminal justice system staff. The ExfilSquad ransomware group claimed responsibility for the attack.
PNLD is a key online resource utilized for over 30 years by 43 police forces in England and Wales, as well as the British Transport Police.
According to ExfilSquad, the attackers managed to exfiltrate 1.9 GB of information, comprising around 135,000 records. The database included:
- Full names, department names, and email addresses of 114,000 PNLD subscribers (officers, government partners);
- Contact information for 21,000 citizens using the public Ask the Police service.
The hackers published samples of the stolen database and demanded ransom from authorities to prevent the release of the remaining data.
PNLD representatives emphasized that the incident is under investigation and that the service does not store confidential information about crime victims, witnesses, or offenders. Additionally, there is no evidence of compromised passwords.
Russian Hackers Breach Hotel Wi-Fi to Spy on VIP Guests
Microsoft cybersecurity experts linked a large-scale campaign called CaptiveCrunch, targeting hotel guests and conference attendees, to the Russian hacktivist group Midnight Blizzard (APT29, Cozy Bear, Storm-2945).
The attacks aimed to compromise Microsoft 365 corporate accounts and spy on VIP guests. The campaign has been active at least since May 2026.
The attack vector and infection mechanics are as follows:
- Wi-Fi Breach. Hackers compromised the authentication equipment of hotel Wi-Fi networks and altered DNS settings.
- Traffic Redirection. When users attempted to access the internet, they were redirected either to fake Microsoft 365 Entra ID login pages or phishing sites using ClickFix tactics, where they were prompted to execute a command in the console under the guise of "updating the browser" or system. Attempts to infect Android devices with malicious APK files were also recorded.
During the campaign, hackers deployed two new viruses, whose code revealed traces of AI tools:
- CornFlake — a trojan written in Go. It features a complete set of espionage functions: keystroke interception, microphone and webcam recording, stealing Microsoft 365 session tokens, cookies, and passwords. It disguises itself as the Cloud Sync Service system service and distracts users with fake "Windows update" or "antivirus check" windows;
- ChocoShell — a PowerShell stealer that operates solely in memory. It aims to extract passwords, Azure AD tokens, and saved Wi-Fi data.
Management of infected devices and data collection were conducted through an unsecured web panel called FruitStone.
Traditional targets for spy hackers include diplomats, government officials, executives, and engineers from defense, energy, and major IT corporations, as well as scientists and employees of analytical centers.
Microsoft experts advised treating all public Wi-Fi networks in hotels and conference centers as compromised. They recommended using mobile internet or a reliable VPN for work and avoiding the installation of "updates" or utilities offered when connecting to guest networks.
Also on ForkLog:
- In 2026, losses from wrench attacks exceeded $30 million.
- An AI model from Meta hacked a third-party company during testing.
- A researcher found traces of North Korean hackers in 1,640 organizations.
- The Bitcoin Red Team identified thousands of issues in 390 Bitcoin projects.
- Scams involving fake MiCA licenses have increased in the EU.
- Ledger warned of AI risks amid the Coldcard breach.
- An AI agent from Anthropic created fake accounts to trick developers.
- Dragonfly estimated the prevention of Coldcard hacking at $2.
- Crypto wallet manufacturers cautioned against phishing attacks.
- Bitcoin service Boltz suspended swaps following a series of attacks.
- Kraken pointed out a gap in cryptocurrency wallet verification.
Weekend Reading Suggestions
On July 30, 2026, an unknown party drained nearly 1,200 addresses without touching a single Coldcard device. Neither advanced security features nor cryptographic marketing saved individuals who did everything right. We explore how this happened and why the incident impacts the Bitcoin industry more severely than any exchange hack.
