Web3 Native Threat Intelligence.

Joined December 2022
16 Photos and videos
Earlier today, we flagged a VS Code extension (rphlmr.vscode-drizzle-orm) based on 21 critical YARA hits from vsix-audit. After manual inspection and deeper analysis, inspecting the .vsix, and reversing the WASM binaries, we’ve confirmed this is a False Positive.
1
238
- The SOL wallet identified was actually a character property table in the Oniguruma regex engine. - The "Dropper" patterns were standard Emscripten/LLHTTP boilerplate. - The "Stealer" hits were bundled dotenv and undici dependencies.
1
119
Takeaway: Automated scanners are essential for flagging capabilities, but manual verification is the only way to determine intent. We acted quickly in hopes of preventing harms, but in this case, we were mistaken. We've removed the post to avoid any confusion (sorry!).
1
100
BLOCKMAGE retweeted
7 Aug 2025
1/ I've been doing some research into how Unity Packages (similar to Node or Pip packages) could be weaponized for malware delivery Let me tell you, it doesn't exactly look good... 🧵
4
3
19
4,081
BLOCKMAGE retweeted
17 Apr 2025
Links: CVE-2025-31201: Apple CVE-2025-31200: Apple and Google Threat Analysis Group macOS Sequoia 15.4.1: support.apple.com/en-us/1224… iOS 18.4.1 and iPadOS 18.4.1: support.apple.com/en-us/1222… visionOS 2.4.1: support.apple.com/en-us/1224…
1
2
3
686
BLOCKMAGE retweeted
17 Apr 2025
No excuses. These are live use, not theoretical CVEs. Apple doesn’t push same-day cross-platform updates and delete vulnerable code unless the stakes are real. Stay sharp. Patch everything. Watch your traffic. 🧙‍♂️
1
1
3
345
BLOCKMAGE retweeted
17 Apr 2025
Two #CVE's, patched across every Apple platform, both marked as actively exploited in the wild: #Apple just released: - macOS 15.4.1, - iOS 18.4.1 - iPadOS 18.4.1 - tvOS 18.4.1 - visionOS 2.4.1 — and you should stop what you're doing and update now.
1
1
4
597
BLOCKMAGE retweeted
July 2023 #TornadoCash exit worth 1,400 ETH ($2.6M) Exit via 100 ETH Contract, swaps for USDC, heads out over the Synapse bridge, to Polygon 0xc09d3c2 and get gambled away at @Stake. I see this fairly often when analysing TC. Tool: @MetaSleuth
4
5
21
6,871
BLOCKMAGE retweeted
5 Nov 2023
Sadly received two messages about this from victims today. Seems another person lost funds in just past few min.
18
5
71
20,291
BLOCKMAGE retweeted
5 Nov 2023
Community Alert: There is currently a fake @Ledger Live app on the official @Microsoft App Store which was resulted in 16.8 BTC ($588K) stolen Scammer address bc1qg05gw43elzqxqnll8vs8x47ukkhudwyncxy64q
334
1,524
3,887
1,087,882
BLOCKMAGE retweeted
25 Oct 2023
1/ An investigation into the Canadian scammer known as Yahya for their involvement in 17 SIM swaps which resulted in more than $4.5M stolen.
291
839
3,794
824,341
BLOCKMAGE retweeted
19 Oct 2023
Replying to @PeckShieldAlert
This is another MakerDAO deposit. Now, I dont understand the exact mechanics of this, but after a bit of digging, funds seem to get withdrawn from Maker as USDC and deposited into Coinbase x.com/0xFantasy/status/16977…

2 Sep 2023
Replying to @MistTrack_io
seems that it was a deposit into maker. call trace and debank show it properly, but etherscan doesnt for some reason docs.makerdao.com/smart-cont…
3
2
6
2,268
BLOCKMAGE retweeted
3 Oct 2023
It's release time 🎃 - Responses can now be intercepted and modified - Delete requests from HTTP History - [Pro] Import/export your projects using our new "backups" page - [Pro] Add shell commands to your convert workflows with the new "Shell" node github.com/caido/caido/relea…
1
10
77
11,514
BLOCKMAGE retweeted
GM GMers! Tagging people who do great work in this space but I feel are not shown enough love! Go follow ⬇️ @CryptoaaService @WoAS_Necksus @0xFantasy @0xSaiyanElite @1c4m3by @Plumferno @BlockMageSec @boringsecurity @brookejlacey @ManicalEngineer Who did I miss? Tag them!
6
4
17
2,004
BLOCKMAGE retweeted
18 Aug 2023
@1c4m3by saved me the other day 🤝 appreciate your work ♥️
1
2
5
1,339
BLOCKMAGE retweeted
Introducing the Pocket Guardians They've already saved *hundreds* of you from dangerous websites Here's a quick intro ⬇️
24
52
178
16,930
BLOCKMAGE retweeted
3/ - @1c4m3by is a security researcher who's already blocked hundreds of scams - @OxSaiyanGod is a security researcher from @BlockMageSec - @plumferno works at @opensea's trust & safety team and founded @Server_Forge
5
3
33
4,429
BLOCKMAGE retweeted
18 Jul 2023
dprk once again rekting you via the platforms you use: github, slack, tg, npm. not checking email won't protect you anymore. 😭 admin keys and build/deploy systems gunna end up pwnd by this campaign. gl & rip.🪦 github.blog/2023-07-18-secur…
12
59
186
51,729
BLOCKMAGE retweeted
10 Jul 2023
Announcing The Arkham Airdrop: a distribution of rewards to our early users! Users can now convert their points exclusively on the Arkham Invite Dashboard. Beware of scammers: Only trust info from @arkhamintel verified on Twitter, only claim via Arkham, and double check URLs.
546
868
2,747
2,022,993
BLOCKMAGE retweeted
Yesterday, we received reports of people seeing unknown approval transactions in their transaction history. It turns out that this is a new scam where scammers use so-called gas tokens to steal money when victims revoke these "fake approvals".
175
1,922
3,597
1,486,021