Issue #003 · Week of July 19, 2026
This Week’s Verdict
The threat this week did not knock on the door, it filled out an onboarding form. Consensys paid a North Korean developer to work on MetaMask, which is either a hiring failure or a preview of every remote-first company’s next incident report. The exploits that mattered were quiet, the supply chain was busy, and Bitcoin obligingly sold off into a Fed meeting nobody expects to be dovish.
The Breaches
The headline number this week is a recovery, not a loss. The attacker behind the May 7 TrustedVolumes exploit (an RFQ market maker used by 1inch Fusion, drained of roughly $5.87M to $6.7M in WETH, USDT, WBTC, and USDC via a bug in its custom RFQ swap proxy) sent back 1,122.12 ETH, about $2.07M, on July 17. This is the same operator responsible for the March 2025 1inch Fusion V1 exploit. Partial restitution from a repeat offender is not redemption, it is inventory management.
Elsewhere, Dunamu, operator of Upbit, drew a sanctions process from South Korean regulators over a roughly $36M hack, a case complicated by the fact that the Virtual Asset User Protection Act contains no explicit penalty provisions for system breaches. Regulators want to punish something the law forgot to define. A fake exchange also drained over $240K from hundreds of retail victims, the kind of loss that never trends but always recurs.
Vulnerabilities Worth Your Attention
- wp2shell (WordPress Core): Two flaws, now with CVE IDs and a public proof-of-concept, let an anonymous HTTP request run code on a bare install with zero plugins. Every 6.9 and 7.0 site was in range. Patch is not optional.
- HollowByte (OpenSSL): An 11-byte TLS request makes an unpatched server reserve up to 131 KB for a message that never arrives. On glibc systems, that memory is gone until restart. The fix shipped in June with no CVE and no changelog entry, which is its own kind of vulnerability.
- LegacyHive (Windows): A researcher published a zero-day granting admin privilege escalation on fully patched systems. No vendor fix at disclosure.
- SonicWall SMA 1000: Volexity attributes pre-disclosure zero-day exploitation of the VPN appliances to UTA0533, with root access obtained since June 22. Edge devices remain the softest perimeter you own.
- 7-Zip RCE: Version 26.02 patches remote code execution via a crafted archive. The oldest attack vector still works because someone always opens the file.
Threat Actors & Campaigns
The DPRK headline is Consensys unknowingly outsourcing developer work on MetaMask to a North Korean operative introduced via a “reputable third-party service provider.” The vetting chain broke exactly where it always does, at the trusted intermediary. In parallel, North Korean actors tied to the Contagious Interview campaign are hiding four-stage OTTERCOOKIE-aligned payloads (a browser-credential and crypto-wallet stealer, plus a file stealer) inside SVG flag images delivered through fake coding tests. The lure is a job, the payoff is your seed phrase.
Supply-chain crews stayed busy. Checkmarx flagged seven malicious Vite npm packages (ViteVenom, an expansion of ChainVeil) using blockchain-based C2 spanning Tron and other chains. SlowMist documented macOS malware that hijacks Telegram sessions and decrypts crypto wallets or phishes recovery phrases via fake apps, while Kaspersky identified a separate framework targeting investors through trojanized GitHub apps. Microsoft meanwhile warns of surging ACR Stealer activity using ClickFix lures to lift browser tokens and Microsoft 365 files. Also billed this week: the Scattered Spider-linked pair sentenced in the UK over a $115M ransom scheme.
The Bigger Picture
Regulators missed their own deadline: US agencies blew past the GENIUS Act one-year mark, issuing 10 proposed rules instead of final ones, with the Jan. 18, 2027 effective date unmoved and the implementation window now compressed. Add USDT facing a two-year countdown on US platforms and OKX Europe offering voluntary USDT-to-USDC conversion under MiCA, and Tether’s regulatory runway keeps shortening. France, for its part, ordered ISPs to geoblock Polymarket on gambling grounds, timed to the World Cup third-place match.
Markets did what macro told them. Bitcoin slid toward $63,000, with the Coinbase premium negative for a record 60 straight days and roughly two-thirds of exchange inflows coming from long-term holders selling at a loss. The proximate trigger was an AI-driven chip rout after Moonshot’s Kimi K3 beat Western frontier models on key benchmarks, dragging risk assets down together. Meanwhile the money kept coming from Wall Street’s side: Citadel Securities put $400M into Crypto.com at a $20B valuation, and ZachXBT picked a fight with Trezor over hardware wallet safety. On the debate about who moves markets, note DOJ is reportedly dropping charges against an alleged $722M Ponzi operator, which tells you more about enforcement priorities than any rule ever will.
Resources
- https://www.reddit.com/r/CryptoCurrency/comments/1uzlx2j/the_attacker_behind_the_may_58m_trustedvolumes/
- https://www.reddit.com/r/CryptoCurrency/comments/1v0gvt1/a_fake_crypto_exchange_has_drained_240k_from/
- https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
- https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
- https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/
- https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
- https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
- https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
More: Issues · Field Notes · RTFM
New Issue every week. Follow @ItsAlreadyPrice or subscribe via RSS so the next exploit does not surprise you.