Fake Google, Gemini Staff Tricked Victim in $245M BTC Heist
Security teams can dissect a high-impact social engineering attack where impersonators of Google and Gemini extracted Google Drive access and security codes to steal 4,100 bitcoin.
Cybersecurity entity
Ethereum is the most frequent co-covered peer, appearing in 4 of the 16 tracked stories. Across a 190-day span, the pace is roughly 0.6 stories per week. The busiest single day carried 2. Negative sentiment reaches 63% here, compared with 56% across the 796-story beat baseline for the same window.
Last mentioned: 1d ago
Entity pulse
Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 63 percentage points.
Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.
Ethereum is the most frequent co-covered peer, appearing in 4 of the 16 tracked stories. Across a 190-day span, the pace is roughly 0.6 stories per week. The busiest single day carried 2. Negative sentiment reaches 63% here, compared with 56% across the 796-story beat baseline for the same window. Source depth averages 3.1 original sources per story, versus 3 across the same-window beat baseline. Their average consequence score of 6.4 runs below the beat's 6.8 for that window. threat-intel accounts for 8 of the 16 tracked stories, while 2 other categories carry the remainder. We currently track 16 Cybersecurity stories that mention Bitcoin, published between March 6, 2026 and September 11, 2026.
Computed from the 16 stories linked to this entity, with beat comparisons drawn from all 796 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.
Coverage cohort
Other entities that clear the same relevance threshold in stories also covering Bitcoin. Shared-story counts are live from our verified record — not editorial picks.
Lam pleads guilty to racketeering conspiracy
Malone Lam pleaded guilty before Judge Colleen Kollar-Kotelly, becoming the 11th of 18 defendants to do so. Sentencing was not immediately scheduled; he faces a maximum of 20 years.
Public disclosure and advisory
Block’s Bitcoin Engineering and Security team releases a security advisory revealing the entropy-generating coding flaw in Coldcard. Coinkite issues a firmware update that fixes the vulnerability for new wallets but warns that existing wallets remain vulnerable.
Additional theft waves detected
Galaxy Research identifies two further suspicious transaction sequences, bringing total estimated losses to nearly $89 million.
Initial mass theft
Attackers drain over 1,000 BTC from 1,196 wallets in 41 minutes, initially valued at approximately $70 million.
Malicious code injected into Adform's trackpoint-async.js
Attackers modify the JavaScript file to swap cryptocurrency wallet addresses. The script is served from s2.adform[.]net to customer sites.
Adform detects and removes the malicious code
Adform identifies the compromise, deletes the poisoned file, and begins notifying affected clients.
Adform issues cache-clearing advisory
The company warns that the altered file may remain in browser caches and recommends users clear their cache to prevent continued execution.
Full ransom note revealed
Reporter Briana Whitney reads the entire initial ransom note on the Crime Junkie podcast, making its full text public for the first time.
Singapore Police Advisory Issued
Police warn public of multiple cryptocurrency scam variants exploiting World Cup 2026 excitement, including fake ticketing sites, fraudulent tokens, phishing, and malware.
Official Denial
CoinDCX issues a statement alleging an impersonation conspiracy and false charges.
FIR and Arrests
Mumbai police file an FIR and arrest co-founders Gupta and Khandelwal.
Exploit Detected
Hacker identifies and exploits a minting bug in Solv Protocol's smart contracts.
Asset Conversion
Attacker swaps minted tokens for Bitcoin-linked assets to secure value.
Bounty Offer
Solv Protocol publicly offers a 10% white-hat bounty for the return of the remaining 90% of funds.
Final ransom deadline
Threatened final deadline at 5 p.m. local time; if unpaid, the kidnappers claim Nancy Guthrie will be killed.
Initial ransom deadline passes
$4 million Bitcoin demand deadline expires; ransom increases to $6 million with a new deadline of February 9.
Nancy Guthrie disappears
Savannah Guthrie's mother goes missing from her home in Tucson, Arizona.
Monitoring Period Ends
CoinDCX concludes its tracking of the 1,212 specific clone domains.
Kevin Beaumont observes ongoing malicious activity
Beaumont reports seeing the wallet-swapping behavior via Adform over the past week, extending beyond the initial remediation.
$44M Cyberattack
CoinDCX suffers a major breach of an internal operational account.
Security teams can dissect a high-impact social engineering attack where impersonators of Google and Gemini extracted Google Drive access and security codes to steal 4,100 bitcoin.
For CISOs and security teams, the $320 million Liquid Network hack is a case study in systemic risk: the vulnerability was not the Bitcoin blockchain itself but the wrappers, bridges, and custody layers around it. Cross-chain infrastructure accounted for over 10% of attacks in 2026 versus just 3 in 2025.
Cybersecurity teams get a high-loss case study in how social engineering, not technical exploitation, enabled a network of young attackers to steal $245 million in Bitcoin from a D.C. resident. The guilty plea underscores the need for identity verification and transaction confirmation controls.
Attackers socially engineered a victim into surrendering bitcoin keys worth more than $240 million, then burned their anonymity on luxury purchases. The FBI arrest within a month shows how spend-out behavior, rather than blockchain laundering alone, can expose cybercriminals. Cybersecurity teams can extract lessons in identity obfuscation, transaction tracing, and social engineering defense.
A dollar-volume screen put Palo Alto Networks, CrowdStrike, and Fortinet atop the cybersecurity group on August 21 — a liquidity snapshot showing investor conviction concentrating in scaled, AI-native security platforms. The same day, PANW and CRWD both traded higher, with CRWD's gen-AI workload security noted as a key differentiator.
A predictable recovery phrase vulnerability in Coldcard hardware wallets enabled a highly automated attack, draining $89 million from 1,200+ addresses in under an hour. The flaw, disclosed by Block’s security team, highlights critical supply-chain risks in entropy generation for embedded devices.
The Coldcard vulnerability demonstrates how flawed random-number generation can compromise hardware wallets, a critical lesson for cryptographic security. Over 4,500 wallets lost $86M in Bitcoin as attackers reverse-engineered deterministic seed phrases. This ongoing breach forces a reevaluation of cold storage trust assumptions.
Source: The Business Times · Suvashree Ghosh
A web supply chain attack poisoned Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron addresses on any site using the script, evading all VirusTotal detections and highlighting gaps in browser-based threat detection.
The full $4 million Bitcoin ransom demand sent to Savannah Guthrie's family has been publicized. The note's tactics mirror ransomware groups, using cryptocurrency, deadlines, and escalation. FBI continues to investigate multiple notes, some considered potentially legitimate. The case illustrates the growing convergence of physical crime and cyber extortion methods.
Source: 1045snx.iheart.com · star1043.iheart.com
Sophisticated lookalike sites mimic legitimate crypto gift card platforms, using slight discounts and stolen codes to dupe users. Cybersecurity implications are severe as traditional detection methods struggle to identify these threats.
Cybersecurity professionals must note the sophisticated blend of phishing, malware delivery, and deepfake content in these scams. The Singapore police advisory details how attackers exploit World Cup hype to compromise cryptocurrency wallets and steal credentials.
A new wave of phishing websites is exploiting Grand Theft Auto VI hype by offering fake early access for cryptocurrency payments. These sites use social engineering and premium design to trick victims into sending $250 in Bitcoin, USDT, or Ethereum, with irreversible losses. Cybercriminals capitalize on the massive anticipation for the game, highlighting the need for user awareness and official channel verification.
The takedown of AudiA6 and Dark2Web reveals a sophisticated cybercrime ecosystem that processed $389 million in Bitcoin, leveraging layered transactions and a dedicated forum for customer acquisition. The operation underscores law enforcement's growing capability to trace and disrupt darknet infrastructure.
CoinDCX co-founders Sumit Gupta and Neeraj Khandelwal have been arrested in Mumbai following an FIR alleging cryptocurrency fraud of Rs 71 lakh. The exchange has vehemently denied the charges, claiming the arrests are the result of a sophisticated impersonation conspiracy involving over 1,200 fraudulent websites mimicking their platform to scam investors.
Solv Protocol has launched a 10% recovery bounty after a hacker exploited a smart contract vulnerability to drain approximately $2.7 million in assets. The attacker reportedly utilized a minting bug to generate unauthorized tokens before converting them into Bitcoin-pegged assets.
Source: uctoday.com · Cointelegraph
As quantum computing capabilities advance toward 'Q-Day,' the cryptographic foundations of the world's leading blockchain networks face an existential threat. This briefing evaluates the specific vulnerabilities of Bitcoin, Ethereum, and XRP and the architectural shifts required to maintain security in a post-quantum era.
Source: Coinpedia · Cryptonews.net
Bitcoin is linked from 16 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.
See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.