
AI-generated summary
Sality has been around since 2003 and used a clipjacking technique to steal cryptocurrencies by replacing addresses copied to the clipboard. It operated peer-to-peer without a central server, which made it difficult to eradicate.
An address almost identical to yours, except for one character. Since Wednesday, this sleight of hand no longer works. A botnet that has been trapping crypto users for eight years has just been dismantled by CrowdStrike and the American justice system. Her name, Sality. His age, 23, eight of which he spent hijacking Bitcoin and Ethereum addresses copied to his victims' clipboards. A method of disconcerting simplicity, which alone explains its longevity.
Sality trapped Bitcoin with a simple copy and paste
The process is called clipjacking, and its code name among the Sality operators was EggJagger. Its principle can be summed up in three words: monitor the clipboard of the infected machine, spot anything that looks like a Bitcoin or Ethereum address, then discreetly replace it with that of the attacker, without any window or alert betraying the substitution.
Nobody types a crypto address by hand, everyone copies and pastes it. It is precisely this habit that the malware has been exploiting for eight years. CrowdStrike puts the confirmed loot at at least 12.1 million rubles, around $150,000, from this payload alone. The unspent assets linked to Sality's portfolios had peaked much higher, around 147 million rubles at the start of 2025, a jackpot that no one ever came to claim.
A network without a leader, difficult to decapitate
Sality had been around since 2003, long before Bitcoin existed, and had survived several waves of cleanup without ever really disappearing.
Its secret weapon, no central server to enter. The infected machines communicated directly with each other, peer-to-peer, and the malware spread on its own by attaching itself to executable files exchanged on network shares and USB keys. No commander to arrest, no headquarters to search, not even an accommodation bill to bring up.
To overcome this, CrowdStrike and the authorities had to poison the network and redirect traffic to sinkholes. The operation, launched on August 31 and formally announced on September 1, mobilized the DOJ, the FBI, the American Defense Criminal Investigative Service, as well as police in Bulgaria, Hungary and Romania. It made it possible to isolate more than 15,000 infected machines spread across four countries.

Since September 1, the US Department of Commerce, via the BEA, has been disseminating real GDP and the PCE index on ten public blockchains simultaneously, including Ethereum, Arbitrum and Base, using Chainlink infrastructure.

Astra, OpenAI's next model, is rated "critical" on the internal cyber risk scale after discovering and exploiting two zero-day flaws, bypassing hardened systems and showing unprecedented offensive capacity, despite reinforced safeguards which still let 8.5% of malicious requests through.

A study from ARK Invest and Glassnode evaluates the decentralization of Bitcoin, Ethereum and Solana based on auditability, security, governance and ownership distribution. Bitcoin comes out on top for overall decentralization, followed by Ethereum and then Solana, although no network dominates across all dimensions. The report highlights disparities in material cost, validation concentration and geographic distribution.

AI agents generate millions of micro-transactions via stablecoins, primarily on the Base network. With an average of 30 cents per transaction, this model supplants bank cards for digital services, according to data from Coinbase and Gartner.

A hacker stole $234,000 by exploiting a rounding flaw in the joinswapPoolAmountOut function of the Balancer V1 protocol, an immutable version of the code written in 2020 and never updated. The attack used flash loans to reduce WBTC reserves to zero, allowing a deposit of one satoshi to receive a disproportionate reward. Balancer Labs is gone, but V1 code remains active and exposed in many DeFi forks.

Thousands of US X Money users received unsolicited password reset emails after the service opened to all Premium and Premium+ subscribers. X confirms an ongoing investigation with no evidence of compromise, attributing the incident to a flaw allowing reset requests with only the public username.