Sitemap

Holidays, FOMO, ATHs, Scammers, Hacks, Tools & Insights Designed to Keep You Safe — “Crypto Security Truths”: Issue 23

16 min readDec 9, 2024

--

Weekly Review of Top Cybersecurity Incidents, Topics, Tools and Issues in Web3, Crypto, and Blockchain Ecosystems

We have been capturing as much as we run across every week to find you clear examples of what not to do in the Cryptoverse in terms of risk, safety and security. We have captured a long list of topics this week in the following headings: Hacked, Malware, Phishing, Scammers, Crime, On-Chain, Tools, & Research, so buckle up and learn how to protect yourself better in Crypto.

Press enter or click to view image in full size

Our top thought leaders capture their own perspective for each category as an Analyst Notes.

29 Nov 24–6 Dec 24

Don’t forget you can vote up to 50-times a day for your favorite articles. We accept more than 1-vote.

Introduction

The crypto and Web3 landscape is both a goldmine of opportunity and a minefield of threats. This week’s highlights unpack the rise of meme coin trading strategies, revealing how savvy traders are using tools like Toxi Solana Bot and gmgn.ai to track smart wallets and capitalize on cultural trends. Yet, these gains come with risks, as scammers exploit platforms like PumpFun to execute rug pulls and malicious actors steal millions through phishing scams. Meanwhile, leaders like Beau are driving efforts to fortify NFT communities and make scams harder to execute, proving that resilience and education are as vital as tools and tactics. If you’re navigating this space, knowing how to balance ambition with caution has never been more important.

Hacked

Crypto Exchange XT.com Hit by $1.7M Hack

Dubai-based crypto exchange XT.com has suspended withdrawals following a hack involving $1.7 million in stolen funds. The attacker reportedly drained $1 million USDT in 12 currencies, converting it to 461.58 ETH. XT reassures users that its reserves exceed user assets by 1.5x and claims no harm to customer funds. While the exchange investigates the breach, it plans to introduce a “Merkle Tree Asset Proof System” to enhance transparency and security. [ Protos on X and Protos Blog ]

$200K Vulnerability Exploited in Syntax Bonding Curve Contracts

Syntax faced a $200,000 loss after a vulnerability in its bonding curve contracts was exploited. In response, Syntax has paused platform operations and initiated a collaboration with security experts to resolve the issue. Access to the platform remains restricted as the team works to ensure the safety of users’ funds. [ Spectral_Labs on X ]

Clipper DEX Exploited for $450K on Optimism and Base

Clipper DEX experienced a $450,000 exploit affecting its pools on Optimism and Base, amounting to 6% of its total value locked (TVL). The exploit, targeting a specific swap feature, was contained to these chains. Clipper has paused trading and deposits platform-wide while enabling users to withdraw assets securely. Investigations are ongoing, with fund recovery efforts underway. [ Clipper_DEX on X ]

Telecom Hack Hits U.S. Giants: AT&T, Verizon Breached

Chinese hackers infiltrated major U.S. telecom providers, accessing live calls, records, and critical systems. The U.S. government recommends using encrypted apps like Signal or WhatsApp, but officials admit that resolving the breach will take time. This incident highlights a severe vulnerability in national telecom infrastructure. [ MarioNawfal on X ]

Phishing Alert: BasedBrett Compromised

Twitter user BasedBrett’s account was compromised, leading to phishing tweets flagged by Scam Sniffer. The anti-scam group identified the malicious site hours before and warns users to remain vigilant against similar attacks. [ Scam Sniffer on X ]

Compromised Wallets: A Lingering Threat

A user shared a story of being drained again from a wallet compromised three years ago, demonstrating how once private keys or seed phrases are exposed, attackers can monitor and exploit them indefinitely. This serves as a reminder that compromised wallets remain unsafe even years after the initial breach. [ CryptoShields on X ]

Analyst Takeaway: These incidents underline a recurring theme in crypto security — complex vulnerabilities exploited through advanced strategies. XT.com’s hack reflects the growing risk even for exchanges with robust reserves. Meanwhile, Syntax and Clipper DEX highlight the danger of untested smart contract mechanisms, while the telecom breach emphasizes vulnerabilities in traditional infrastructure intersecting with Web3. These breaches reinforce the need for layered defenses, such as real-time monitoring and transparent audit trails, paired with rapid incident response strategies.

Malware

Solana Supply Chain Attack

A phishing campaign targeting the Solana ecosystem resulted in a supply chain attack compromising the popular @solana/web3.js library. Hackers published malicious versions (1.95.6 and 1.95.7) designed to steal private keys from developers and dapps handling them directly, resulting in six-figure losses. Solana has since unpublished the malicious packages, urging developers to upgrade to 1.95.8 and rotate compromised keys. The attack highlights the risks of software supply chains, especially in handling sensitive materials like private keys. [ Anza_xyz, CyberStrategy1, 0xngmi, on X ]

Meeten Malware Campaign

A new campaign called “Meeten” is targeting Web3 professionals through fake video conferencing apps. Hackers impersonate trusted contacts to distribute malware-laden links that drain crypto wallets, steal browser data, and compromise system credentials. Using advanced techniques, the malware (Realst) affects both macOS and Windows systems, exploiting wallet credentials and browser vulnerabilities. Vigilance, verified links, and security solutions like Warden are crucial for staying protected. [ Warden_Secure on X and Cyber Strategy Insittute Medium Blog ]

Analyst Takeaway: The Solana supply chain attack and Meeten campaign are stark reminders of the evolving threat landscape targeting both individual users and developers. The exploitation of software dependencies like @solana/web3.js showcases the critical need for rigorous code review and dependency management. Similarly, Meeten illustrates how tailored malware campaigns exploit trust to infiltrate systems. The solution? Hardened supply chains, strict access controls, and user education on phishing tactics.

Phishing

WallStreetBets Account Phishing Attack

A phishing campaign originating from the compromised WallStreetBets X account resulted in $2.2M in losses. Attackers exploited XSS vulnerabilities in phishing sites and used expired dapp domains to bypass blacklists. Solana users are advised to scrutinize unexpected pop-ups and simulate connections cautiously to avoid falling victim to these sophisticated tactics. [ Scam Sniffer on X ]

Press enter or click to view image in full size

Pudgy Penguins Phishing Surge

Phishing attacks targeting the Pudgy Penguins NFT community surged following the $PENGU airdrop, with numerous phishing sites created in a single day. The influx highlights the need for tools like PocketUniverse to mitigate risks as hackers exploit hype-driven events in the NFT space. [ 1c4m3by on X ]

Cardano Foundation X Account Hack

The Cardano Foundation’s official X account (@Cardano_CF) was compromised, posting suspicious messages with comments disabled. Users are warned to avoid engaging with the account until the issue is resolved, as hackers often employ social engineering tactics targeting major crypto organizations. [ NFT-dreww on X ]

Press enter or click to view image in full size

Phishing Ads on Google

Phishing ads impersonating GMGN appeared on Google, tricking users into connecting wallets and signing malicious transactions. Scam Sniffer urges users to skip Google Ads results, bookmark trusted sites, and exercise caution before signing any transactions. [ Scam Sniffer on X ]

Bitcoin Phishing Loss

A victim lost 2.77 BTC (~$284K) after falling for a phishing signature disguised as an “Increase Approval” prompt shortly after withdrawing funds from MEXC. The incident underscores the importance of pausing and scrutinizing transactions to prevent devastating losses. [ Scam Sniffer on X ]

Analyst Takeaway: Phishing attacks are becoming increasingly sophisticated, leveraging everything from compromised social media accounts to malicious Google Ads. The WallStreetBets case reveals how attackers exploit platform vulnerabilities, while Pudgy Penguins and Cardano Foundation attacks highlight the risks of hype and centralized control. Users must adopt a ‘trust but verify’ mindset, and organizations should invest in proactive monitoring, secure social media protocols, and community education.

Scammers

Frustration with Complex Airdrop Processes

A crypto user shared their frustration with the overly complicated process of claiming an HL airdrop, which involved multiple steps such as downloading a mobile app, importing wallets, and linking them across platforms, only to find their efforts unrewarded. Despite heavy trading activity during 2021, the user noted a significant drop in 2024 and criticized the zero-value outcome, highlighting inefficiencies in user experience for crypto incentives. [ lazyvillager1 on X ]

Insider Manipulation in $SHIRO’s Launch

Bubblemaps uncovered suspicious insider trading during $SHIRO’s launch, revealing that nearly 90% of the token supply was acquired by insiders within seconds before the official announcement. Promoted as a fair launch, $SHIRO quickly reached a $1 billion market cap but faced scrutiny after evidence showed insiders dispersed holdings across 500+ wallets. This investigation highlights the recurring issue of manipulated “fair” launches in the crypto space, eroding trust among investors. [ Bubble Maps on X ]

Parallel Finance’s Collapse and Deception

Parallel Finance, once a promising DeFi project backed by elite VCs, unraveled due to mismanagement and deliberate obfuscation. The protocol secretly minted tokens, manipulated collateral ratios, and abandoned its chain, leaving users with significant losses. A self-proclaimed white-hat hacker seized control, exposing the team’s dubious practices and accelerating its demise. This saga underscores the importance of transparency in DeFi and the dangers of relying on glossy PR over actual accountability. [ RektHQ on X and blog ]

Warnings Against the GingerX Solana Scam

Crypto Rug Muncher issued a stark warning against GingerX Solana, an upcoming project labeled as a scam. The project is allegedly promoted by a dubious agency, Lykkel LLC, known for suspicious activities and protected social media posts. This serves as a reminder to avoid gold-checked endorsements without proper scrutiny and to remain vigilant against potential fraud in the crypto landscape. [ CryptoRugMunch on X ]

Scammers Exploiting Social Media Personas

BeauSecurity cautioned users against falling for elaborate scams involving dormant wallets and fake OnlyFans personas. This highlights a broader trend of scammers exploiting social media and creating false identities to deceive crypto enthusiasts. The message emphasizes the need for users to verify identities and interactions carefully before engaging in crypto transactions or communications. [ beausecurity on X ]

The Rise and Fall of a TikTok Scam Artist

Pablo’s investigation exposed TJR, a TikTok personality selling a $999 “Mastermind” trading course that claims to provide insider strategies and memecoin tips. However, reviews suggest the course recycles free online material, exploiting followers’ trust for profit. This case illustrates the dangers of social media influencers leveraging fame for monetary gain while providing little value to their audience. [ pasha_insights on X ]

Apple Dog ($DOGA): Bundling Scam Alert

Crypto Rug Muncher flagged $DOGA as a potential bundled scam after uncovering evidence of hundreds of fresh wallets containing only $DOGA. These wallets were supplied by larger wallets within the project, suggesting a high likelihood of a rug pull. The recommendation’s clear: avoid this project to protect your assets. [ CryptoRugMunch on X ]

Gold-Checked Scam: Vow Solana

Vow Solana, a project promoted by Espy Marketing, was identified as another scam leveraging X’s gold check verification to appear legitimate. Crypto Rug Muncher criticized the platform for enabling scams and called for action from Elon Musk and X support to curb fraudulent use of verified accounts. [ CryptoRugMunch on X ]

Scam Prevention Win on $FATHER

Using GMGN’s platform, Crypto Rug Muncher highlighted a victory in identifying scam, dump, and transfer wallets in the $FATHER project. These flagged wallets were part of a suspected rug pull operation. The analyst encouraged users to use GMGN for scam detection and always verify project legitimacy before trading. [ CryptoRugMunch on X ]

Insider-Controlled Rug Pull in $JUSTICE

$JUSTICE ($PNUT) was exposed as a supply-controlled scam, with insiders reportedly holding 58% of the token’s supply, according to the Devsnightmare bot. Crypto Rug Muncher sarcastically remarked that the project’s “justice” seemed to be aimed at exploiting the crypto community. [ CryptoRugMunch on X ]

Analyst Takeaway: The patterns are clear: scammers exploit insider control, social engineering, and fake personas to prey on victims’ trust and hype. From $HAWK & $SHIRO’s insider launch manipulation to GingerX Solana’s deceptive marketing, transparency remains a persistent issue in crypto. The rise of influencer-led scams like TJR’s trading course and insider-controlled rug pulls like $JUSTICE shows the urgent need for tools like GMGN to flag irregularities and community efforts to expose fraud.

Crime

Cryptojacking Scheme Using Amazon & Microsoft Infrastructure

Charles O. Parks III, aka “CP3O,” pleaded guilty to a cryptojacking operation that exploited cloud service providers like Amazon and Microsoft. By creating fraudulent accounts under aliases, Parks accessed massive computing power, mining over $970,000 in cryptocurrency while leaving behind an unpaid $3.5 million bill. His sophisticated scheme involved laundering the illicit gains through crypto exchanges, NFT marketplaces, and luxury purchases. This case highlights the vulnerabilities of cloud billing systems and underscores the importance of securing access to computing resources to prevent fraud. [ Warden_Secure on X and Cyber Strategy Institute Medium blog ]

Analyst Takeaway: Parks’ cryptojacking scheme exploiting cloud infrastructure underscores systemic weaknesses in cloud billing and access management. The sophisticated laundering of illicit gains through exchanges, NFTs, and luxury goods further reveals vulnerabilities in crypto traceability. This case highlights the importance of stronger KYC processes, real-time anomaly detection, and collaboration between cloud providers and blockchain platforms to mitigate financial crime. But it also shows crime doesn’t pay for several reasons, because he used the wrong infrastructure to mine Crypto, he lost $2.5M+ compared to what he actually mined and his bills.

Tools

AI-Powered On-Chain Agent Economies

The rise of AI-driven projects like Spectral, Zerebro, and Virtual Protocol is reshaping the blockchain landscape. These platforms enable the creation of autonomous agents that generate art, analyze data, and interact with users in real time. With varying functionalities — such as Zerebro’s AI rapper and Virtual Protocol’s co-ownership model — they present innovative use cases for integrating AI into Web3 ecosystems, with substantial market capitalizations signaling strong investor interest. [ 0x_gremlin on X ]

Cod3x’s Cloud-Based AI Agent Security

Cod3x introduces a revolutionary security model for AI agents by eliminating private key knowledge, relying instead on cloud-based hardware wallets and authenticated transactions. This approach safeguards user assets while enabling creators to retain control. Discussions about integrating Cod3x with platforms like Virtual Protocol suggest a potential synergy that could redefine trading and operational workflows for blockchain-based AI systems. [ Cod3xOrg on X ]

Big Tony: AI Trading Bot Evolution

Big Tony, an AI trading bot powered by Cod3x, is gaining traction in crypto markets. Utilizing real-time data analysis and an evolving personality, it demonstrates profitable strategies and decision-making capabilities. Speculation about integrating Cod3x with Virtual Protocol hints at a future where trading bots are more autonomous, efficient, and adaptable, further optimizing trading workflows. [ Timmy_Turnes on X ]

Toxi Solana Bot: Automated Copy Trading

Toxi Solana Bot offers a streamlined way to monitor and replicate wallet trades on the Solana network. Users can select manual or automated modes, adjust risk settings, and copy trades based on market capitalization preferences. With features like real-time alerts and customizable trade amounts, the bot empowers both novice and experienced traders to capitalize on high-potential opportunities efficiently. [ 0x_Discover on X ]

Analyst Takeaway: AI-powered tools like Cod3x, Big Tony, and Toxi Solana Bot are revolutionizing blockchain efficiency while presenting new risks. Cod3x’s cloud-based security model is a promising step in safeguarding AI agent autonomy, while Toxi’s copy trading simplifies access for retail users. However, their adoption must be coupled with robust security standards to ensure user trust as we push the boundaries of Web3 innovation.

Research

Essential Incident Response (IR) Tips for Web3 Founders

Web3 founders must proactively prepare for breaches by setting up offline communication channels, delegating authority during founder or developer unavailability, and securing incident response (IR) partnerships. Saving IR contacts outside corporate systems, such as on personal phones, and crafting legal and PR strategies in advance are critical to mitigating technical and reputational damage during a crisis. Preparation beyond firewalls ensures readiness for the chaos of an exploit. [ CyberStrategy1 on X ]

Avoiding Rug Pull Scams

The rise of meme coins has attracted scammers exploiting platforms like PumpFun, creating tokens with deceptive activity patterns and fraudulent advertising. To avoid these scams, traders should analyze token activity, check wallet distributions, and scrutinize advertising sources. Tools like Bubble Maps and gmgn.ai offer insights, while careful due diligence is vital before investing in rapidly growing tokens. [ PenguinWeb3 on X ]

Token Sniping Strategies for High Gains

Finding and investing in high-potential tokens requires strategic tools and careful analysis. Platforms like gmgn.ai and bots such as Toxi Solana Bot help traders identify promising tokens and execute fast snipes. Proper token analysis, including checking contract quality, social media engagement, and liquidity status, is key. Narratives and cultural trends, especially in meme coins, play a significant role in identifying profitable opportunities. [ Dionysus on X ]

Tracking Smart Money for Meme Coin Success

To profit from meme coins, traders should monitor “smart wallets” with high monthly PnL and track their movements using tools like Toxi Solana Bot and DexScreener. Effective strategies include creating categorized watchlists, analyzing liquidity and trading volumes, and leveraging multichart views for technical analysis. These steps empower traders to make informed decisions while navigating the volatile crypto market. [ 0xFrogify on X ]

Building Safer Web3 Communities

Beau, a prominent Web3 security advocate, highlights his efforts to prevent scams and improve community safety, focusing on making projects like Pudgy Penguins resilient against scammers. His commitment to sharing practical security tips has garnered appreciation from users aiming to navigate Web3 with greater vigilance. [ beausecurity on X ]

Smart Wallet Strategies for Memecoin Trading

Danny Crypton shares a systematic approach to profiting from memecoins, emphasizing the importance of tracking smart wallets with high monthly profits. Key steps include using tools like Toxi Solana Bot for copy trading, conducting basic token analysis (e.g., liquidity lock and active volume), and organizing tokens into watchlists for efficient monitoring. For advanced traders, DexScreener offers multi-chart tracking and portfolio insights, helping users identify promising opportunities and manage risks effectively. [ Danny_Crypton on X ]

Will Tracking Binance Insider Wallets Allow You to Front Run Future Listings?

DeFiTracer unveils wallets with substantial profits from insider memecoin trades, spotlighting tokens like $ACT and $PNUT. By analyzing patterns and insider behaviors, he identifies potential Binance listings, including $BULLY, $BERT, and $MICHI. DeFiTracer also hosts giveaways and premium calls via Telegram, fostering engagement while encouraging diversification and informed decision-making. [ DeFiTracer on X ]

SOL Traders and Winning Strategies — 2K Wallets Reviewed to Find 8 Insiders

Anatoli Kopadze showcases high-performing Solana traders with remarkable win rates and profits from tokens like $PILLZUMI and $Fartcoin. He recommends tools like GMGN’s website and Telegram bot for analyzing tokens and executing trades, helping traders refine their strategies for maximum returns. [ AnatoliKopadze on X ]

November’s Web3 Phishing Losses and Defense Tips

Scam Sniffer reports $9.38M stolen and over 9,200 victims in November phishing scams, with malicious signatures emerging as the primary attack vector. Despite a decline in monetary losses, the threat evolves with new players like Angel Drainer replacing Inferno Drainer. Scam Sniffer advises users to scrutinize signature requests, adopt anti-scam wallets, and install security extensions to prevent empty wallets. [ Scam Sniffer on X ]

Analyst Takeaway: Web3 founders must learn from recent incidents by integrating Incident Response (IR) readiness into their operations. Preparing offline communication channels, clear delegation of authority, and external IR contacts are non-negotiable. Coupled with enhanced legal and PR strategies, these steps ensure organizations can weather breaches with minimal damage to reputation and user trust. Prevention remains the best strategy, but preparation bridges the gap when prevention fails. The evolving Web3 and crypto landscape presents both significant opportunities and risks, requiring traders, developers, and community leaders to adopt smarter and safer strategies. From avoiding rug pull scams by scrutinizing token activity and leveraging tools like Bubble Maps, to tracking “smart wallets” and utilizing advanced bots for profitable token sniping, success lies in combining vigilance with actionable insights. However, the rise of phishing scams, insider trading patterns, and deceptive advertising highlights the constant need for education, robust tools, and community collaboration. Leaders like Beau in NFT communities and platforms like Scam Sniffer are working to fortify defenses, demonstrating that collective efforts can make scams harder to execute. Ultimately, staying secure means combining strategic analysis, community support, and the right tools to navigate the volatile Web3 market with confidence.

Conclusion

This week’s takeaways reveal a crypto market where opportunity and danger exist in equal measure. From traders deploying sniper bots to profit off meme coins like $Fartcoin, to insights into insider wallet movements predicting potential Binance listings, the tools and strategies for success are growing more advanced. Yet, with $9.38M lost to phishing in November alone and rug pulls exploiting deceptive token activity, the risks are just as sophisticated. The key is a multi-pronged approach: use tools like Bubble Maps and Toxi Solana Bot to make informed trades, educate yourself on emerging threats, and engage with leaders working to safeguard communities like Pudgy Penguins. Success in this space isn’t just about making the right moves — it’s about being prepared to defend against the wrong ones.

Thanks for getting this far in our article. Don’t forget that you can vote up to 50-times a day for your favorite articles on Medium. We accept more than 1-vote, as it helps us spread the Cybersecurity insights into Crypto. The more people that see this information, the more people we can help. We should share information about criminals and scammers to help protect each other, just like we pick up stray trash and put it in the trash can.

Further Resources about Cyber Strategy Institute:

If interested in other analysis, checkout our other Medium articles, our Indpeth Analysis Articles and for more of a daily understanding of the Cryptoverse follow our Twitter account. Relying on a dying Cybersecurity model is not a foundation for success; that is what Warden changes for the good!

Warden

It is designed leveraging a Zero Trust model, stopping all known bad and unknown malicious threats. This starts by defending at the kernel level, so that any software does not know it’s been placed into a sandbox. We call this the “Inception Protection” model, which will not allow any program to impact your systems. No other system can do this on the market today. Protect your digital life, your families or your organization today with Warden!

If you want a 50% Discount on your purchase, then sign up for our newsletter, and we will send you the code for your support. Just reply to your first email saying you would like a discount.

Cyber Strategy Institute

Medium: https://cyberstrategy1.medium.com/

Twitter: https://twitter.com/CyberStrategy1

X: https://x.com/Warden_Secure

Website: https://cyberstrategyinstitute.com

Protect Yourself, Family or Business Today with Warden!

https://cyberstrategyinstitute.com/personal-protection-warden

--

--

Cyber Strategy Institute
Cyber Strategy Institute

Written by Cyber Strategy Institute

Crypto Security Truths - Scam Hunter, ZeroTrust Endpoint Defense & writing about all things Crypto Security. Stay up-to-date on latest Threats by following us!