@evaderscom

.com drains, rugs, compromised accounts. onchain when it matters. no hopium. all news: @evaders on tg

onchain
Joined September 2026
Same Fetch exploiter just hit @SingularityNET. Unauthorized mint: 260M AGIX + 53.838M WMTx on Ethereum. Exploiter bag now ~$16.77M (198.3M AGIX ~$14.42M, 649 ETH ~$1.67M, 33.538M WMTx ~$627k). Ignore "AGIX bridge / recovery" DMs. official only.
5
4
130
~$1.53M FET out of Fetch.ai's converter in one call. Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%. TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof. Ignore "migration / conversion" DMs. Official only.
20
first FET. then NTX. then AGIX and WMTx. the authorizer key is finishing the set.
47
what to do: - revoke unknown AGIX / WMTx spender approvals if you used the SingularityNET bridge - no "urgent AGIX migration / bridge recovery" DMs - wait for @SingularityNET / World Mobile official only - prior FET/NTX thread still stands: nitter.cf/evaderscom/status/2101…
~$1.53M FET out of Fetch.ai's converter in one call. Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%. TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof. Ignore "migration / conversion" DMs. Official only.
75
What we can hard-state so far: - unauthorized mint on Ethereum (protocol inventory / bridge path), not a mass seed-steal campaign - AGIX: 260M minted; exploiter still holds ~198.3M (~$14.42M) - WMTx: 53.838M minted; holds ~33.538M (~$627k) - same bag also shows ~649 ETH (~$1.67M), including prior Fetch haul PeckShield has not named the exact function yet. Same actor as TokenConversionManagerV3 FET/NTX.
45
PeckShield (~11:21 Warsaw): same wallet cluster that drained the Fetch converter and minted NTX now unauthorized-minted AGIX and WMTx via SingularityNET infra on Ethereum. PANews: World Mobile Chain previously confirmed the SingularityNET cross-chain bridge on the WMTx mint path.
6
108
~$1.53M FET out of Fetch.ai's converter in one call. Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%. TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof. Ignore "migration / conversion" DMs. Official only.
1
1
3
265
conversionOut remembered the limits. conversionIn forgot them. the key did not.
1
4
#PeckShieldAlert The same exploiter has exploited both @Fetch_ai & @nunet_global, totaling ~$2M in crypto losses: 8.7M ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 ($1.53M) drained &408.5M NTX ($462.73K) minted NuNet's $NTX has dropped ~65%. The exploiter has swapped the stolen funds for 546.36 $ETH (~$1.44M) so far.
6
🚨 FomoPeek App v1.1–1.2: malicious iOS code stealing wallet keys. SlowMist + OKX: kernel exploit framework escapes sandbox, reads Keychain (seeds / private keys). attack loop still live on infected installs. If you ever installed 1.1–1.2: rotate on a clean device. don't reinstall.
5
6
231
sources: SlowMist TI (Sep 19): nitter.cf/SlowMist_Team/status/2…
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
10
the "alpha app" came with an 8-method jailbreak for your Keychain.
19
what to do: - check wallets for weird outs - on a device that NEVER had FomoPeek: new seed, new keys - move funds there now - update iOS to latest - uninstall. do not reinstall any version (1.3 removed the exploit binary but past 1.1–1.2 installs may already be burned) - if funds moved: contact the exchange/wallet support with the device kept as evidence. ignore "recovery" DMs
112
one module is an iOS kernel exploit framework with 8 attack methods. picks the right one for device + iOS version. affected: iOS 12.0–18.7 and iOS 26.0–26.1. on success: sandbox escape → decrypt Keychain → read other apps' files. seeds, keys, logins, chat history, files. also talks to hidden C2 servers and takes remote commands. SlowMist saw plaintext traffic: attack function ON, runs on a timer. older iOS = higher risk.
23
multiple wallets already drained after private-key exposure. victims had FomoPeek 1.1–1.2 on the same phone as their wallets. joint SlowMist / OKX analysis: app ships two modules that have nothing to do with its stated features.
5
63
🚨 WaterPlum: ~$10.7M crypto out via fake job interviews. FBI + Japan + Australia + Germany: North Korea-linked Contagious Interview posed as AI/crypto recruiters. Coding tests → malware. 30k+ devices, 7k+ wallets. Dec 2025–Jul 2026 haul to DPRK. Don't run recruiter "interview" code on your machine.
2
3
136
the take-home assignment went home with the keys.
1
73