@evaderscomi
iAccount based inMontenegro!
About this account
- Account based in
- Montenegro
- Connected via
- Web
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
.com drains, rugs, compromised accounts. onchain when it matters. no hopium. all news: @evaders on tg
onchain
Joined September 2026
- Tweets3K
- Following8
- Followers137
- Likes10
Same Fetch exploiter just hit @SingularityNET.
Unauthorized mint: 260M AGIX + 53.838M WMTx on Ethereum.
Exploiter bag now ~$16.77M (198.3M AGIX ~$14.42M, 649 ETH ~$1.67M, 33.538M WMTx ~$627k).
Ignore "AGIX bridge / recovery" DMs. official only.
sources:
PeckShield: nitter.cf/PeckShieldAlert/status…
Lookonchain: lookonchain.com/feeds/73309
prior Fetch+NuNet: nitter.cf/evaderscom/status/2101…
~$1.53M FET out of Fetch.ai's converter in one call.
Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%.
TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof.
Ignore "migration / conversion" DMs. Official only.
what to do:
- revoke unknown AGIX / WMTx spender approvals if you used the SingularityNET bridge
- no "urgent AGIX migration / bridge recovery" DMs
- wait for @SingularityNET / World Mobile official only
- prior FET/NTX thread still stands: nitter.cf/evaderscom/status/2101…
~$1.53M FET out of Fetch.ai's converter in one call.
Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%.
TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof.
Ignore "migration / conversion" DMs. Official only.
What we can hard-state so far:
- unauthorized mint on Ethereum (protocol inventory / bridge path), not a mass seed-steal campaign
- AGIX: 260M minted; exploiter still holds ~198.3M (~$14.42M)
- WMTx: 53.838M minted; holds ~33.538M (~$627k)
- same bag also shows ~649 ETH (~$1.67M), including prior Fetch haul
PeckShield has not named the exact function yet. Same actor as TokenConversionManagerV3 FET/NTX.
PeckShield (~11:21 Warsaw): same wallet cluster that drained the Fetch converter and minted NTX now unauthorized-minted AGIX and WMTx via SingularityNET infra on Ethereum.
PANews: World Mobile Chain previously confirmed the SingularityNET cross-chain bridge on the WMTx mint path.
~$1.53M FET out of Fetch.ai's converter in one call.
Same exploiter minted ~408.5M NTX (~$463k). Total ~$2M. NTX −65%.
TokenConversionManagerV3 conversionIn(): one leaked authorizer EOA signature. No limits. No burn proof.
Ignore "migration / conversion" DMs. Official only.
sources:
SlowMist: nitter.cf/SlowMist_Team/status/2…
PeckShield: nitter.cf/PeckShieldAlert/status…
Tx: etherscan.io/tx/0xfe12c63b32…
#PeckShieldAlert The same exploiter has exploited both @Fetch_ai & @nunet_global, totaling ~$2M in crypto losses: 8.7M ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 ($1.53M) drained &408.5M NTX ($462.73K) minted
NuNet's $NTX has dropped ~65%. The exploiter has swapped the stolen funds for 546.36 $ETH (~$1.44M) so far.
🚨 FomoPeek App v1.1–1.2: malicious iOS code stealing wallet keys.
SlowMist + OKX: kernel exploit framework escapes sandbox, reads Keychain (seeds / private keys). attack loop still live on infected installs.
If you ever installed 1.1–1.2: rotate on a clean device. don't reinstall.
sources:
SlowMist TI (Sep 19): nitter.cf/SlowMist_Team/status/2…
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨
We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2.
A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️
Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version.
‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️
If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device.
🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed.
The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands.
Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk.
If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately:
1️⃣ Check your accounts and assets for any unusual activity.
2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase.
3️⃣ Move your assets to the new account as soon as possible.
4️⃣ Update your device to the latest available iOS version.
5️⃣ Do not continue using or reinstalling FomoPeek.
6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
what to do:
- check wallets for weird outs
- on a device that NEVER had FomoPeek: new seed, new keys
- move funds there now
- update iOS to latest
- uninstall. do not reinstall any version (1.3 removed the exploit binary but past 1.1–1.2 installs may already be burned)
- if funds moved: contact the exchange/wallet support with the device kept as evidence. ignore "recovery" DMs
one module is an iOS kernel exploit framework with 8 attack methods. picks the right one for device + iOS version.
affected: iOS 12.0–18.7 and iOS 26.0–26.1.
on success: sandbox escape → decrypt Keychain → read other apps' files. seeds, keys, logins, chat history, files.
also talks to hidden C2 servers and takes remote commands. SlowMist saw plaintext traffic: attack function ON, runs on a timer. older iOS = higher risk.
multiple wallets already drained after private-key exposure. victims had FomoPeek 1.1–1.2 on the same phone as their wallets.
joint SlowMist / OKX analysis: app ships two modules that have nothing to do with its stated features.
🚨 WaterPlum: ~$10.7M crypto out via fake job interviews.
FBI + Japan + Australia + Germany: North Korea-linked Contagious Interview posed as AI/crypto recruiters. Coding tests → malware. 30k+ devices, 7k+ wallets. Dec 2025–Jul 2026 haul to DPRK.
Don't run recruiter "interview" code on your machine.
sources:
IC3 CSA (Sep 18): ic3.gov/CSA/2026/260918.pdf
CyberScoop: cyberscoop.com/north-korea-w…