
45 mentions across press, blogs, and newsletters
Mascots and brand characters are having a moment, with the latest entry coming from Apple in TikTok promos for its new MacBook Neo. ‘Lil Finder Guy’, as the internet calls him, peeked out with a super-cute design that’s caught the attention of Apple and brand character fans. In some ways, L
A new Glassworm-linked supply chain attack has briefly turned two popular React Native npm packages into delivery vehicles for Windows credential-stealing malware. On March 16, 2026, malicious versions of AstrOOnauta’s react-native-country-select@0.3.91 and react-native-international-phone-number
TRON has joined Mastercard’s Crypto Partner Program as the payments company expands coordination with blockchain, fintech, and banking participants working on digital asset payments. The move places TRON among more than 85 companies participating in a Mastercard-led initiative to link blockchain-bas
macOS infostealers like Atomic Stealer, Poseidon, and Cthulhu Stealer are surging as attackers target high-value Apple users. The long-held belief that Macs are immune to malware ha
Azury Infostealer Source Code Sold for $100 With Full Operator Panel, Crypto Wallet Theft, and Keylogging Capabilities
CoinGecko’s 2026 trading activity report shows onchain venues climbing into the industry’s top ranks, even as centralized exchanges continue to dominate overall spot and perpetuals volume.
The team urges users to avoid the site after hackers hijacked a team account and deployed a wallet drainer on the domain.
<img alt="Mastercard launches crypto partner program with a 'who's who' of industry" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDMvMDE5Y2RlNzctMDY3MC
The integration connects the widely used self-custody wallet with Uniswap’s routing infrastructure and liquidity pools.
The initiative brings together exchanges, fintech firms, and banks to explore cross-border payments, settlements, and enterprise use cases.
A fake CleanMyMac site tricks macOS users into installing SHub Stealer malware that steals credentials and crypto wallets. The post CleanMyMac Imposter Site Installs SHub Stealer on Ma
Even though South Korea is ending a nine-year ban on its listed companies that prevented them from investing in digital assets, stablecoins like USDC and USDT are expected to be excluded under the new regulations. Corporations have made several arguments for why they should be allowed to trade stab
Google Safe Browsing has missed
The country’s authorities aim to curb risky investments, limiting stablecoin use while setting clear rules for corporate digital asset trading.
Googl
Researchers uncovered Coruna, a sophisticated iOS exploit kit used to compromise thousands of iPhones and steal cryptocurrency data. The post Coruna iOS Exploit Kit Compromises Thousa
A powerful iPhone hacking toolkit capable of silently compromising devices has moved from a government-linked surveillance operation into espionage campaigns and criminal cryptocurrency theft networks, according to research from Google and mobile security firm iVerify. The toolkit, known as Coruna,
<img alt="Google warns of crypto scams using ‘new and powerful’ iPhone exploit kit" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMTIvMDE5YWU3NjItNmNlYi0
A previously undocumented set of 23 iOS exploits named "Coruna" has been deployed by multiple threat actors in targeted espionage campaigns and financially motivated attacks. [...]
Two of the biggest payment brands are working together to enable average consumers all over the world to purchase cryptocurrencies. On March 3, 2026, Visa and Bridge declared that their stablecoin card program would be accessible in over 100 countries by the end of the year. Bridge, a stablecoin inf
Security researchers from the Google Threat Intelligence Group (GTIG) have uncovered “Coruna,” a highly sophisticated iOS exploit kit responsible for compromising thousands of iPhones. Targeting iOS versions 13.0 through 17.2.1, the framework contains five complete exploit chains leve
A compromised Chrome extension with 7,000 users was updated to deploy malware, strip security headers, and steal cryptocurrency wallet seed phrases. The post Chrome Extension Hijacked to
<img alt="Visa and Stripe’s Bridge plan stablecoin card expansion to over 100 countries" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDMvMDE5Y2IzZDgtMG
Bridge has partnered with Lead Bank, a participant in Visa’s stablecoin settlement pilot, to help businesses and fintechs offer stablecoin-backed Visa cards.
Visa is expanding its partnership with Stripe-owned stablecoin infrastructure platform Bridge. The new collaboration will see the companies extend the global card issuance product they introduced last year, according to a Tuesday (March 3) press release emailed to PYMNTS. “Bridge enables busines
<img alt="Bitcoin company Fold pays off $66M debt, frees up BTC collateral" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDMvMDE5Y2FmODktMmI3ZC03ZDBlLTk
A trusted Chrome extension was hijacked to strip browser protections, deploy ClickFix malware, and steal cryptocurrency and user data. The post Chrome Extension Hijacked to Push ClickFix M
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users. [...]
Citrini warned everyone that these AI layoffs were coming, and it seems Jack Dorsey took their warning to heart and chose to act first.
Consensys made its cryptocurrency card, MetaMask Card, generally available in the United States, enabling users to pay with crypto anywhere Mastercard is accepted, online or in-store. The card is fully self-custodial, so users maintain control of their digital assets in their MetaMask wallet unt
The Mastercard-powered MetaMask debit card is now rolling out access to all users across the United States.
<img alt="Mastercard, MetaMask launch US crypto card, debuting in New York" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDIvMDE5Yzk5ZTUtYzE2YS03YzFkLTg
The card lets users spend digital assets directly from their self-custodial wallets at various merchants.
<img alt="Binance adds Ondo’s tokenized stocks in latest RWA push" class="type:primaryImage" src="https://images.cointelegraph.com/images/528_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDIvMDE5YzhmOTQtYmRkMS03ZDRhLTg5YjQtZmY3
ZeroDayRAT targets Android and iOS devices, combining real-time surveillance with direct financial theft within a single browser panel. The Malware-as-a-Service (MaaS) ecosystem is entering a new phase, blending mobile surveillance and financial crime into one seamless platform. Active promotions
The ETHDenver assistant is a live, conference-facing pilot, but CoinFello says the bigger goal is an agent that can trigger onchain actions via smart accounts and emerging agent standards.
Attackers used a fake PDF incident report hosted on AWS to scare victims into enabling 2FA, though a poorly crafted phishing campaign. Freelance security consultant Xavier Mertens reported a phishing campaign using a fake PDF security incident report hosted on AWS to scare victims into enabling 2FA.
On some Ethereum L2s, bots now burn over half the gas just searching for MEV, and they don’t pay proportionally for it. That’s a scaling and market-fairness problem rooted in market structure. The privacy conversation in crypto has finally escaped the “anonymous money” framing that do
North Korean hackers target users of top Ethereum wallet MetaMask&n
A newly surfaced mobile spyware platform called ZeroDayRAT is rapidly gaining traction across underground Telegram channels. ZeroDayRAT is designed to give attackers complete remote control over both Android and iOS devices, supporting versions from Android 5 through 16 and iOS up to version 26,
Researchers found malicious npm and PyPI packages tied to a fake recruitment campaign linked to North Korea’s Lazarus Group. ReversingLabs researcher uncovered new malicious packages on npm and PyPI connected to a fake job recruitment campaign attributed to the North Korea-linked Lazarus Group. The
A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. [...]
Lazarus Group’s latest software supply chain operation is using fake recruiter lures and popular open‑source ecosystems to deliver malware to cryptocurrency‑focused developers quietly. The campaign, dubbed graphalgo, abuses GitHub, npm, and PyPI to hide multi‑stage payloads behind seemingly legit
Less than a year after a global law enforcement takedown severely disrupted its operations, LummaStealer has not only survived, but it’s thriving again. Bitdefender researchers report a sharp resurgence in the infostealer’s activity, now fueled by a stealthy delivery chain centered on CastleLoade
Hyperliquid has bought an additional 5 million HYPE tokens worth $129.5 million at an average price of about $25.9.