Market Prices

BTC Bitcoin
$63,744.7 -1.67%
ETH Ethereum
$1,911.14 -1.24%
SOL Solana
$73.87 -2.18%
BNB BNB Chain
$569.5 -0.90%
XRP XRP Ledger
$1.06 -3.01%
DOGE Dogecoin
$0.0707 -1.49%
ADA Cardano
$0.1586 +0.00%
AVAX Avalanche
$6.52 -0.76%
DOT Polkadot
$0.7593 -4.36%
LINK Chainlink
$8.34 -2.85%

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x830a...0c73
Arbitrage Bot
+$0.6M
85%
0xe0bf...4067
Market Maker
+$1.9M
72%
0xf95e...38f8
Arbitrage Bot
+$2.8M
75%

🧮 Tools

All →

The Trojan Horse Lives on GitHub: Kaspersky Flags New Crypto Malware Framework

Leotoshi
DAO

Trust is the oldest attack vector. Kaspersky just found a new one dressed as code—a malware framework that weaponizes GitHub repositories to target cryptocurrency investors. The method is not new, but the execution is refined. Social engineering meets trojanized applications. The code doesn't lie. Humans do.

Context: The Attack Surface Nobody Audits

We obsess over smart contract vulnerabilities. Reentrancy, oracle manipulation, flash loan attacks. But the most catastrophic losses still come from the simplest failure: a user executing a malicious binary. Kaspersky’s report details a framework that delivers trojanized applications through GitHub repos, exploiting the developer community’s implicit trust in open-source distribution. No multi-sig compromise. No governance exploit. Just a corrupted download link and an unwary user.

The framework is designed to steal credentials, clipboard data, and wallet files. It specifically targets crypto users—those who run node software, use desktop wallets, or manage private keys. Based on my experience auditing ICO contracts in 2017, I can tell you: the gap between protocol security and client-side security is where millions vanish.

Core: Code-Level Disassembly and Trade-Offs

Let’s examine the mechanics. The malware likely employs three classic techniques:

  1. Clipboard Hijacking: Monitors the clipboard for cryptocurrency addresses (regex patterns for Bitcoin, Ethereum, other chains). When detected, replaces the destination address with the attacker’s. The user copies an address, pastes what appears to be the same string—but funds go elsewhere. No smart contract needed.
  1. Keylogging + UI Manipulation: Records keystrokes to capture passwords, seed phrases, and 2FA codes. It can also inject overlays on wallet applications, tricking users into re-entering credentials. The trojanized application looks identical to the real thing, but each field shadows a memory dump.
  1. Direct Wallet File Exfiltration: Searches for common wallet data files (e.g., keystore, wallet.dat, metamask-*.json) and uploads them to a remote server. If the user’s wallet is encrypted, the keylogger provides the passphrase.

What makes this framework dangerous is its distribution channel. GitHub is the de facto source of truth for crypto open-source projects. Developers clone, build, and run code without verification. The attack exploits this workflow: a malicious fork of a popular library, a compromised maintainer account, or a fake project mimicking a legitimate one. The code passes initial inspection because only a small rogue file is added—logic obfuscated, masked as an update.

In my 2020 work on Compound’s interest rate models, I learned that fragility is structural. Here, the structural failure is the lack of code signing and hash verification in developer habits. We audit smart contracts but neglect the execution environment.

Contrarian: Security Blind Spots We Refuse to Address

The contrarian angle is uncomfortable: we are too reliant on trust in centralized distribution points. GitHub, npm, PyPI—these platforms are not secure supply chains. They are reputation-based reputation economies, and reputation can be bought, hacked, or faked.

The broader crypto ecosystem’s response to client-side attacks is reactive: install antivirus, use hardware wallets, check domain names. But hardware wallets only protect if the signing process itself is not compromised. A trojanized application can intercept the connection between wallet and dApp, signing malicious transactions without user awareness. The market is rational about protocol risk. It is blind to client risk.

After the 2022 bear market, I analyzed how 3AC-backed protocols failed. The cause was always improper risk parameterization—code assumptions that broke under stress. Similarly, this malware exploits an assumption: that the software we download is what it claims to be. We assume SHA-256 checksums are honored. We assume maintainers are honest. Audits are opinions, not guarantees. The code runs, and the code can betray.

Takeaway: Forecast and Actionable Signal

This attack vector will not disappear. It will evolve. Expect AI-generated fake repositories, automated supply chain attacks, and malware that adapts to user behavior. The only long-term mitigation is a shift in user behavior: treat every download as a potential threat until verified. Use deterministic builds, verify signatures, and keep private keys offline.

Kaspersky’s report is a reminder that the last mile of crypto security is not the blockchain—it’s the human running the code. The code doesn’t lie. But the humans who write it, and the platforms that distribute it, often do.

Fear & Greed

29

Fear

Market Sentiment

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,744.7
1
Ethereum ETH
$1,911.14
1
Solana SOL
$73.87
1
BNB Chain BNB
$569.5
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0707
1
Cardano ADA
$0.1586
1
Avalanche AVAX
$6.52
1
Polkadot DOT
$0.7593
1
Chainlink LINK
$8.34

🐋 Whale Tracker

🟢
0xcb42...ea1b
12h ago
In
47,212 BNB
🔴
0xe7b9...6ed5
12h ago
Out
32,637 BNB
🔵
0x153a...e848
2m ago
Stake
2,193,456 USDT