Blockchain & Cryptocurrency
,
Cryptocurrency Fraud
,
Fraud Management & Cybercrime
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence
Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero.
See Also: Revolutionizing Cross-Border Transactions with Permissioned DeFi
Harmony to Roll Back Blockchain After Massive Token Forgery
Harmony will roll back its blockchain after finding that attackers forged more than 3 trillion One tokens. Validators will restore both parts of Harmony’s network to a point before the unauthorized creation of tokens, meaning all transactions recorded afterwards will be discarded.
Harmony considered destroying the forged tokens, blocking affected wallets and moving One to a new token before deciding a rollback was the safest and fairest approach.
The project initially confirmed the exploit on Aug. 12 after a researcher found 4 billion newly created One tokens. A later investigation uncovered 3.01 trillion forged tokens across six transactions involving four attacker wallets. One wallet moved nearly 2.4 trillion One in under two minutes. Harmony said many forged tokens passed through trading platforms and blockchain bridges, making recovery difficult without affecting other users. The attack exploited a flaw that allowed the same valid transaction record to be processed repeatedly (see: Cryptohack Roundup: Harmony, BTCPay Exploits).
Delio CEO Gets 15-Year Prison Sentence
A South Korean court sentenced Delio CEO Jeong Sang-ho to 15 years in prison after finding him guilty of defrauding customers of about 70 billion won – $49 million – in digital assets, local media reported.
The Seoul Southern District Court convicted Jeong on most charges, including embezzlement and using false documents to register as a digital asset service provider. The court cleared him of the main charge alleging that he defrauded about 2,800 people of roughly 250 billion won. It ruled that evidence gathered during a server search and seizure was obtained illegally and could not support that charge.
Prosecutors requested a 20-year prison term. The court ordered Jeong detained because of concerns that he could flee. Delio had attracted customers by offering high returns on digital asset deposits. The company stopped withdrawals in June 2023 and declared bankruptcy in November 2024.
Alleged Crypto Ponzi Promoter Deported to the US
Fiji authorities extradited Edward Zimbardi to the United States after the accused Ponzi scammer spent more than a year on the run, said the Department of Justice. Zimbardi faces multiple wire fraud and money laundering charges related to “The Crypto Program,” which prosecutors said conned $165 million from victims.
Prosecutors allege he promoted investment packages that promised guaranteed monthly returns and directed thousands of investors to send cryptocurrency to wallets he controlled. Instead of buying the advertised packages, Zimbardi allegedly used more than $34 million for foreign currency bets and lost substantial sums.
The prosecutors also said he used money from new investors to pay earlier participants. He allegedly spent at least $10 million on personal expenses, including luxury vehicles and a house for his son. Zimbardi was indicted in July, and prosecutors plan to seek his continued detention.
SafePal Flaw Exposes Data Of Nearly 40,000 Customers
A flaw in SafePal’s order-tracking system exposed personal information belonging to about 39,800 customers, the crypto wallet provider said. The affected data included names, email addresses, phone numbers, shipping addresses and purchase details from orders placed between March 2025 and April 2026.
SafePal said the incident did not expose private keys, passwords, payment details or other information needed to access wallets and funds. But the company warned that scammers could use the leaked information to impersonate SafePal staff and trick customers into revealing wallet credentials.
Trezor Customer Data Exposed In ShipMonk Breach
Nearly 14,000 Trezor customers had personal information exposed after an unauthorized party accessed order data held by shipping provider ShipMonk.
The breach revealed names, email addresses, phone numbers and shipping addresses for 11,742 of the cold storage wallet provider’s customers. Another 1,947 customers had their names, cities and email addresses exposed. Those affected live across several countries, including the United States and the United Kingdom.
Trezor said its own systems were not breached and its hardware wallets are secure. The exposed information could make customers more vulnerable to phishing.
Attackers Exploit Mac Flaw to Mine Monero
Attackers exploited a flaw in Apple’s Screen Sharing feature to take control of Macs and install software that mines Monero. The Netherlands’ National Cyber Security Center reported attacks on several internet-connected Macs but did not identify those responsible.
Apple fixed the flaw through updates for supported macOS versions. The weakness allowed attackers on the network to access Screen Sharing without a valid password. Screen Sharing lets someone remotely view and control a Mac and is disabled by default.
Security firm Huntress said changing passwords would not stop the attack because the flaw bypassed the login process entirely. A researcher at the firm found tens of thousands of Macs that could potentially be vulnerable. U.S. authorities later raised the flaw’s severity rating to 9.8 out of 10.
Attackers installed Monero mining software because the digital currency can be mined using ordinary computers and offers transactions designed to hide identifying details.
Credit: Source link
