# Cryptocurrency

Cryptocurrency is decentralized digital currency secured by cryptography and operating through distributed consensus and blockchain infrastructure.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## HBO Max's verified Reddit account hijacked to spread malware

DevFeed: [HBO Max's verified Reddit account hijacked to spread malware](<https://devfeed.tech/articles/hbo-max-s-verified-reddit-account-hijacked-to-spread-malware-26612.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware>)

Author: Pieter Arntz

Published: 2026-09-15T11:51:03Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pasteswitch](<https://devfeed.tech/tags/pasteswitch.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Cybercriminals hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads over about 48 hours. The ads promoted fake software and used ClickFix-style instructions to distribute infostealers and cryptocurrency clipboard hijackers to macOS and Windows users.

### Source excerpt

Cybercriminals used HBO Max's verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

## Search results are sending people to fake Bitrefill checkouts

DevFeed: [Search results are sending people to fake Bitrefill checkouts](<https://devfeed.tech/articles/search-results-are-sending-people-to-fake-bitrefill-checkouts-26613.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts>)

Author: Stefan Dasic

Published: 2026-09-15T08:40:22Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [payments](<https://devfeed.tech/tags/payments.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [qr-code](<https://devfeed.tech/tags/qr-code.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [search](<https://devfeed.tech/tags/search.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Fake Bitrefill checkout pages are appearing in search results and copying the company's branding and payment flow. They persuade victims to send cryptocurrency to scammer-controlled addresses, with no goods delivered and little chance of recovering the payment.

### Source excerpt

Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.

## Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms

DevFeed: [Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms](<https://devfeed.tech/articles/gitea-rce-flaw-now-under-active-exploitation-cisa-confirms-10721.md>)

Original publisher: [Read original article](<https://selfhostlab.io/gitea-rce-active-exploitation/>)

Author: Christian Rakoot

Published: 2026-08-29T06:33:49Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>)

Tags: [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [gitea-rce](<https://devfeed.tech/tags/gitea-rce.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-security-news](<https://devfeed.tech/tags/network-security-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

CISA confirmed that the critical Gitea vulnerability CVE-2026-60004 is being actively exploited and added it to the Known Exploited Vulnerabilities catalog. The article explains the exploit through Gitea's diffpatch API, which can enable arbitrary code execution, and describes a documented compromise of an outdated self-hosted instance that led to cryptocurrency mining inside a Docker container.

### Source excerpt

CISA has added CVE-2026-60004, the critical Gitea RCE flaw patched in version 1.27.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Help Net Security documented a real compromise: an outdated instance with open registration hit by an automated scanner, ending in a cryptocurrency-mining payload. Here is what changed and how to patch.

## Raspberry Pi Projects That Sound Great But Are Usually a Bad Idea

DevFeed: [Raspberry Pi Projects That Sound Great But Are Usually a Bad Idea](<https://devfeed.tech/articles/raspberry-pi-projects-that-sound-great-but-are-usually-a-bad-idea-10813.md>)

Original publisher: [Read original article](<https://raspberrytips.com/raspberry-pi-projects-bad-idea/>)

Author: Patrick Fromaget

Published: 2026-07-18T05:00:00Z

Content type: opinion

Language: en

Sources: [RaspberryTips](<https://devfeed.tech/sources/raspberrytips.md>)

Topics: [Hardware](<https://devfeed.tech/topics/hardware.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>), [servers](<https://devfeed.tech/topics/servers.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [experiment](<https://devfeed.tech/tags/experiment.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [inspiration](<https://devfeed.tech/tags/inspiration.md>), [linux](<https://devfeed.tech/tags/linux.md>), [projects](<https://devfeed.tech/tags/projects.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>)

### AI overview

The article argues that although Raspberry Pi computers can run many projects, some are poor choices for long-term reliance because they require more reliability and maintenance than a Pi setup can provide. It presents cryptocurrency mining and self-hosting an email server as examples: both can be useful learning exercises, but Raspberry Pi hardware is generally unsuitable for profitable mining or dependable email hosting.

### Source excerpt

After years of testing and writing tutorials on RaspberryTips, I can tell you one thing: you can make your Raspberry Pi do almost anything. However, just because it works doesn't mean it's a good idea. Let's talk about it. A Raspberry Pi can run many home projects, but some are poor choices for long-term use....

## AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)

DevFeed: [AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)](<https://devfeed.tech/articles/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions-pwn-request-july-2026-12890.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions>)

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [AsyncAPI Specification](<https://devfeed.tech/topics/asyncapi.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [asyncapi-supply-chain-attack](<https://devfeed.tech/tags/asyncapi-supply-chain-attack.md>), [chainguard-asyncapi](<https://devfeed.tech/tags/chainguard-asyncapi.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-actions-pwn-request](<https://devfeed.tech/tags/github-actions-pwn-request.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article analyzes a July 14, 2026 supply-chain compromise in which an attacker stole a privileged GitHub personal access token through a misconfigured GitHub Actions workflow and used it to publish five backdoored versions across four AsyncAPI npm packages. The malware activates when a library is loaded by a build or CI job and steals browser passwords, SSH keys, npm and GitHub tokens, cloud credentials, and cryptocurrency wallets while maintaining command-and-control access. It also explains why Chainguard customers were protected and recommends treating affected environments as compromised and rotating credentials.

### Source excerpt

A supply chain attack compromised AsyncAPI npm packages via GitHub Actions. See how Chainguard blocked the malicious releases by design.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## This month in security with Tony Anscombe - May 2026 edition

DevFeed: [This month in security with Tony Anscombe - May 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-may-2026-edition-8427.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-may-2026/>)

Author: Editor

Published: 2026-05-29T07:30:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Google](<https://devfeed.tech/topics/google.md>), [systems](<https://devfeed.tech/topics/systems.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [google](<https://devfeed.tech/tags/google.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A monthly cybersecurity roundup covering cyber-intrusions against Polish water treatment facilities, an AI-directed attack in Mexico that failed to move from IT to OT systems, an AI-developed zero-day exploit identified by Google, and cryptocurrency kiosk scams.

### Source excerpt

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit

## Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

DevFeed: [Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly](<https://devfeed.tech/articles/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly-6860.md>)

Original publisher: [Read original article](<https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/>)

Published: 2026-03-31T02:03:00Z

Content type: article

Language: en

Sources: [The latest research from Google](<https://devfeed.tech/sources/the-latest-research-from-google.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Post-quantum cryptography](<https://devfeed.tech/topics/post-quantum-cryptography.md>), [Quantum Computing](<https://devfeed.tech/topics/quantum-computing.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Zero-knowledge proof](<https://devfeed.tech/topics/zkp.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [algorithms-theory](<https://devfeed.tech/tags/algorithms-theory.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [coinbase](<https://devfeed.tech/tags/coinbase.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [google](<https://devfeed.tech/tags/google.md>), [government](<https://devfeed.tech/tags/government.md>), [migration](<https://devfeed.tech/tags/migration.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [quantum](<https://devfeed.tech/tags/quantum.md>), [quantum-computing](<https://devfeed.tech/tags/quantum-computing.md>), [research](<https://devfeed.tech/tags/research.md>), [security-privacy-and-abuse-prevention](<https://devfeed.tech/tags/security-privacy-and-abuse-prevention.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-knowledge](<https://devfeed.tech/tags/zero-knowledge.md>)

### AI overview

Google Research describes how future quantum computers could break the elliptic-curve cryptography protecting cryptocurrency with fewer resources than previously estimated. The article recommends transitioning blockchains to post-quantum cryptography and presents zero-knowledge proofs as a way to disclose vulnerabilities responsibly.

### Source excerpt

Algorithms & Theory

## SourceHut author describes the operational cost of aggressive LLM crawlers

DevFeed: [SourceHut author describes the operational cost of aggressive LLM crawlers](<https://devfeed.tech/articles/please-stop-externalizing-your-costs-directly-into-my-face-20810.md>)

Original publisher: [Read original article](<https://drewdevault.com/blog/Stop-externalizing-your-costs-on-me/>)

Author: March

Published: 2025-03-17T00:00:00Z

Content type: opinion

Language: en

Sources: [Drew DeVault](<https://devfeed.tech/sources/drew-devault.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Crawler](<https://devfeed.tech/topics/crawler.md>), [Git](<https://devfeed.tech/topics/git.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [git](<https://devfeed.tech/tags/git.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [llms](<https://devfeed.tech/tags/llms.md>), [robots](<https://devfeed.tech/tags/robots.md>)

### AI overview

A personal opinion post describes SourceHut's experience mitigating aggressive LLM crawlers that ignore robots.txt, crawl expensive Git endpoints, distribute requests across many IP addresses, and contribute to recurring outages. It also compares this burden with earlier CI cryptocurrency-mining abuse and Go module mirror traffic.

### Source excerpt

This blog post is expressing personal experiences and opinions and doesn't reflect any official policies of SourceHut. Over the past few months, instead of working on our priorities at SourceHut, I have spent anywhere from 20-100% of my time in any given week mitigating hyper-aggressive LLM crawlers at scale. This isn't the first time SourceHut has been at the wrong end of some malicious bullshit or paid someone else's externalized costs - every couple of years someone invents a new way of ruining my day. Four years ago, we decided to require payment to use our CI services because it was being abused to mine cryptocurrency. We alternated between periods of designing and deploying tools to curb this abuse and periods of near-complete outage when they adapted to our mitigations and saturated all of our compute with miners seeking a profit. It was bad enough having to beg my friends and family to avoid "investing" in the scam without having the scam break into my business and trash the place every day. Two years ago, we threatened to blacklist the Go module mirror because for some reason the Go team thinks that running terabytes of git clones all day, every day for every Go project on git.sr.ht is cheaper than maintaining any state or using webhooks or coordinating the work between instances or even just designing a module system that doesn't require Google to DoS git forges whose entire annual budgets are considerably smaller than a single Google engineer's salary. Now it's LLMs. If you think these crawlers respect robots.txt then you are several assumptions of good faith removed from reality. These bots crawl everything they can find, robots.txt be damned, including expensive endpoints like git blame, every page of every git log, and every commit in every repo, and they do so using random User-Agents that overlap with end-users and come from tens of thousands of IP addresses - mostly residential, in unrelated subnets, each one making no more than one HTTP request ove

## Ultralytics AI Pwn Request Supply Chain Attack

DevFeed: [Ultralytics AI Pwn Request Supply Chain Attack](<https://devfeed.tech/articles/ultralytics-ai-pwn-request-supply-chain-attack-8222.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/>)

Author: Stephen Thoemmes

Published: 2024-12-11T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Google](<https://devfeed.tech/topics/google.md>), [comfyui](<https://devfeed.tech/topics/comfyui.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [comfyui](<https://devfeed.tech/tags/comfyui.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [google](<https://devfeed.tech/tags/google.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [ultralytics](<https://devfeed.tech/tags/ultralytics.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article analyzes the two-phase Ultralytics supply chain attack in December 2024. Attackers published malicious PyPI versions containing cryptocurrency-mining malware, first through compromised GitHub Actions workflows and later by publishing directly to PyPI. The article presents the release timeline, detection signals such as unusual CPU usage and repository discrepancies, and guidance for detecting exposure and securing projects.

### Source excerpt

Discover the details of the Ultralytics AI supply chain attack, a sophisticated two-phase breach targeting PyPI releases and GitHub Actions with cryptocurrency mining malware. Learn how to detect exposure, secure your projects, and protect against future vulnerabilities using tools like Snyk.

## Lottie Player npm package compromised for crypto wallet theft

DevFeed: [Lottie Player npm package compromised for crypto wallet theft](<https://devfeed.tech/articles/lottie-player-npm-package-compromised-for-crypto-wallet-theft-8007.md>)

Original publisher: [Read original article](<https://snyk.io/blog/lottie-player-npm-package-compromised-crypto-wallet-theft/>)

Author: Liran Tal

Published: 2024-10-31T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The @lottiefiles/lottie-player npm package was compromised after an npm registry publishing token was exposed. Malicious code in versions 2.0.5, 2.0.6, and 2.0.7 attempted to prompt users to connect cryptocurrency wallets. Those versions were removed, and version 2.0.8 restored the safe project code. The article explains how to use Snyk Dependency Reports and the Snyk CLI to identify affected projects and vulnerable dependencies.

### Source excerpt

On October 31st, 2024, another package compromise and cryptocurrency hijack story unfolded for a popular npm package. Scan open source dependencies and container images in the CLI or your SCM with Snyk to determine if you're using one of the vulnerable versions of lottie-player, and potentially uncover any other security vulnerabilities you may have in your projects.

## Quick update: What's going on?

DevFeed: [Quick update: What's going on?](<https://devfeed.tech/articles/quick-update-what-s-going-on-34878.md>)

Original publisher: [Read original article](<https://pine64.org/2023/08/12/quick-update-whats-going-on/>)

Published: 2023-08-12T00:00:00Z

Content type: news

Language: en

Sources: [Community blog on PINE64](<https://devfeed.tech/sources/community-blog-on-pine64.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [coinbase](<https://devfeed.tech/topics/coinbase.md>), [FOSDEM](<https://devfeed.tech/topics/fosdem.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [coinbase](<https://devfeed.tech/tags/coinbase.md>), [community](<https://devfeed.tech/tags/community.md>), [community-update](<https://devfeed.tech/tags/community-update.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [linux](<https://devfeed.tech/tags/linux.md>), [payments](<https://devfeed.tech/tags/payments.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

PINE64 explains the pause in its community updates, announces that the Pine Store now accepts USD Coin payments through Coinbase, and invites the community to a meetup in Warsaw.

### Source excerpt

Welcome to our long-awaited community post, where we aim to address the most commonly asked question while also unveiling some more news. Let's get started! Why hasn't there been a community update for the past few months? Is PINE64 dead? As you may have noticed, there haven't been any community updates as of late, and we are sorry for the prolonged silence. This isn't because the community hasn't been busy, quite the opposite is true. Instead, the problem is that the usual community update authors are too busy with their daily jobs and other tasks around the community. Although thanks to some community members who have shown interest to participate, we are working on a new community update and we hope we will publish it soon! Pine Store now accepts payments in cryptocurrency. The community has consistently expressed interest in paying on the Pine Store with cryptocurrency, and despite several previous attempts to find a suitable crypto payment service, the process has proven challenging, leading to eventual failure. However, we are happy to announce that Pine Store now facilitates payments using USD Coin cryptocurrency via Coinbase! Talk to us at our upcoming community meetup in Warsaw! We always attempt to meet in person at least twice a year. For reasons that ought to be obvious to everyone, this wasn't possible these past few years, but now that travel is once again viable we're returning to a bi-annual meetup schedule. We always meet at FOSDEM in February followed by a meeting halfway through the calendar year. While FOSDEM primarily serves the function of interacting with the broader Linux community and members of other projects as well as product announcements, the second yearly meetup aims at evaluating the project's progress, identifying issues, and creating a roadmap for the coming months. This year we're holding the second meetup in Warsaw. TL, Ayufan, Lukasz, and I will be having lunch in Hala Gwardii on Sunday, August 20th at noon. The place offers a wi

## Update on beta testing payments in Signal

DevFeed: [Update on beta testing payments in Signal](<https://devfeed.tech/articles/update-on-beta-testing-payments-in-signal-1869.md>)

Original publisher: [Read original article](<https://signal.org/blog/update-on-beta-testing-payments/>)

Published: 2021-04-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [payments](<https://devfeed.tech/tags/payments.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [signal](<https://devfeed.tech/tags/signal.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>)

### AI overview

Signal discusses its beta-testing payments direction and the privacy problems of existing payment networks. Rather than building a cryptocurrency protocol itself, Signal proposes linked support for separately maintained non-custodial cryptocurrency wallets so users can access payments networks while keeping their data private.

### Source excerpt

As the world stands today, the future of transaction privacy does not look great. The existing landscape is dominated by traditional credit companies, who over the past decade have been steadily pushing their networks for increased access to user data. They (and their data customers) are on a track to getting SKU level data of every purchase everyone makes everywhere. There are other contenders, such as regional online payments networks (like Venmo in the US), but the data story there is similar. This is not a future we are particularly excited about. At Signal, we want to help build a different kind of tech - where software is built for you rather than for your data - so these are trends that we watch warily. Read more...

## Announcing World Trade Francs: The Official Ethereum Stablecoin

DevFeed: [Announcing World Trade Francs: The Official Ethereum Stablecoin](<https://devfeed.tech/articles/announcing-world-trade-francs-the-official-ethereum-stablecoin-16823.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2018/04/01/announcing-world-trade-francs-official-ethereum-stablecoin>)

Author: Vitalik Buterin

Published: 2018-04-01T15:35:26Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [blockchain-technology](<https://devfeed.tech/tags/blockchain-technology.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [governance](<https://devfeed.tech/tags/governance.md>), [network](<https://devfeed.tech/tags/network.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [token](<https://devfeed.tech/tags/token.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article announces World Trade Francs, described as a decentralized stablecoin built on Ethereum and next-generation blockchain technology. It also introduces WTF as a stable token and FTW as a corresponding volatile token within the proposed system.

### Source excerpt

We have long recognized that in order for cryptocurrency to reach mass adoption, a form of cryptocurrency that has higher price stability than existing cryptocurrencies like BTC and ETH would be needed so that people can use the currency to store funds and engage in commerce without worrying about their...

## On Inflation, Transaction Fees and Cryptocurrency Monetary Policy

DevFeed: [On Inflation, Transaction Fees and Cryptocurrency Monetary Policy](<https://devfeed.tech/articles/on-inflation-transaction-fees-and-cryptocurrency-monetary-policy-16777.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2016/07/27/inflation-transaction-fees-cryptocurrency-monetary-policy>)

Author: Vitalik Buterin

Published: 2016-07-27T17:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Security](<https://devfeed.tech/topics/security.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article examines how blockchains fund security through inflation or transaction fees. Using Bitcoin and Ethereum as examples, it discusses transaction-fee revenue, declining mining rewards, and the estimated cost of acquiring enough mining power to overwhelm the network.

### Source excerpt

The primary expense that must be paid by a blockchain is that of security. The blockchain must pay miners or validators to economically participate in its consensus protocol, whether proof of work or proof of stake, and this inevitably incurs some cost. There are two ways to pay for this...

## Ethereum Partners with R3CEV on Lizardcoin, Bringing Together the Best of Centralized Finance and Blockchain Technology

DevFeed: [Ethereum Partners with R3CEV on Lizardcoin, Bringing Together the Best of Centralized Finance and Blockchain Technology](<https://devfeed.tech/articles/ethereum-partners-with-r3cev-on-lizardcoin-bringing-together-the-best-of-centralized-finance-and-blockchain-technology-16754.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2016/04/01/ethereum-partners-with-r3cev-on-lizardcoin-bringing-together-the-best-of-centralized-finance-and-blockchain-technology>)

Author: Vitalik Buterin

Published: 2016-04-01T08:43:10Z

Content type: opinion

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [blockchain technology](<https://devfeed.tech/topics/blockchain-technology.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Finance](<https://devfeed.tech/topics/finance.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain-technology](<https://devfeed.tech/tags/blockchain-technology.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [finance](<https://devfeed.tech/tags/finance.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

The article describes an announced collaboration between the Ethereum Foundation and banking consortium R3CEV to create Lizardcoin, a blockchain-based cryptocurrency intended to combine centralized financial controls with blockchain technology. It outlines a capped and reducing supply, account holding fees, and multi-bank KYC requirements, while comparing the project with Bitcoin.

### Source excerpt

The Ethereum Foundation has announced that it will be working with the New York-based banking consortium R3CEV on creating a new blockchain-based cryptocurrency, Lizardcoin, which aims to showcase the benefits of blockchain technology as well as the consortium's ability to bring the technology to institutional clients and the regulation-loving masses...