Blockchain & Cryptocurrency,
Cryptocurrency Fraud,
Fraud Management & Cybercrime
Also: ClickFix Attack Abuses Polygon Blockchain

Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, U.S. seizes Hamas-linked funds, ClickFix attack abuses Polygon blockchain, Bithumb wins lawsuit over bitcoin credit error, software flaw exposes six Cosmos networks, Cronos restarts after Tectonic attack, and Moonwell investigates $8.7 million exploit.
See Also: OnDemand | NSM-8 Deadline July 2022: Keys for Quantum-Resistant Algorithms Implementation
US Seizes Funds Linked to Hamas
The recent actions taken by the U.S. Department of Justice illustrate a concerted effort to disrupt terrorist financing operations. Over $560,000 in cryptocurrency, allegedly earmarked for Hamas, was seized along with multiple websites and communication systems purportedly utilized for fundraising and recruitment purposes. The United States has designated Hamas as a foreign terrorist organization, which adds a layer of urgency to these actions.
In an operation conducted throughout 2025, investigators traced and ultimately seized the funds via three warrants. These funds were reportedly intended to support the Al Qassam Brigades, the military wing of Hamas. In a significant move, the FBI also seized internet domains and servers tied to the group’s main website, which allowed investigators to intercept cryptocurrency contributions that were intended for Hamas.
The fundraising strategy employed by Hamas reportedly directed supporters from an encrypted chat group to a website that frequently changed cryptocurrency addresses, making it difficult for authorities to track donations. As part of the investigation, the FBI gathered information concerning thousands of individuals who contacted Hamas for donation purposes. This information is anticipated to play a crucial role in future investigations aimed at curbing terrorism financing.
ClickFix Attack Abuses Polygon Blockchain
In another development, cybersecurity experts uncovered a ClickFix campaign that has compromised at least 31 organizations, using the Polygon blockchain to cloak malicious activities. Research by GuidePoint Security revealed that affected entities included websites across e-commerce, professional services, and retail logistics sectors.
The attackers compromise business websites to insert harmful code displaying a fraudulent human verification prompt. Victims are misled into using Windows shortcuts to paste commands, unwittingly starting the installation of malware that remains active even after a computer is restarted. This malware regularly communicates with systems controlled by the attackers.
Using a technique known as EtherHiding, the attackers store ever-changing server information on the blockchain, enabling them to swiftly redirect infected computers to new control servers as defenders manage to block previous ones.
Bithumb Wins Lawsuit Over Bitcoin Credit Error
A landmark ruling by a South Korean court has ordered a Bithumb user to return earnings from a botched transaction where the exchange mistakenly credited the user with bitcoin. According to local media, the Seoul Central District Court ruled in favor of Bithumb in one of four lawsuits concerning such gains, which involved approximately 194 million won (about $140,000).
This incident followed a significant error during a promotional giveaway in February, when Bithumb inadvertently credited hundreds of users with bitcoin instead of Korean won due to an employee misclassifying the reward unit. The cumulative error led to the allocation of 620,000 bitcoin, valued at around $43 billion at the time, which triggered a plunge in bitcoin’s price on Bithumb and incited scrutiny from regulatory authorities regarding the exchange’s risk controls and internal safeguards.
Software Flaw Exposes 6 Cosmos Networks
From August 20 to August 25, attackers exploited a software vulnerability to siphon funds from six networks within the Cosmos blockchain ecosystem. Cosmos Labs confirmed that the flaw impacted Cosmos EVM, software meant to facilitate Ethereum-based applications. This vulnerability allowed unauthorized users to falsely inflate their account balances, tricking the networks into accepting these misleading values as genuine.
An initial report concerning the flaw was made to Cosmos Labs in April, which first assessed that operational networks were not at risk. However, as the security situation evolved, it became apparent that the flaw posed a broader threat, prompting the release of a fix in August.
While some of the stolen tokens were exchanged for assets worth around $5.7 million, affected networks included Mantra, Tac, and KiiChain. Many accounts utilized by the attackers at various exchanges have since been frozen.
Cronos Restarts After Tectonic Attack
Cronos has resumed its operations following an attack on the Tectonic lending platform, where attackers managed to borrow approximately $74 million by manipulating the reported value of Tectonic’s TONIC token within a mere 20-minute time frame. Security firm PeckShield reported that during the incident, the attacker successfully moved around $6 million worth of Ethereum, while a majority of the borrowed funds remained stranded on the Cronos network.
In response to this breach, Cronos temporarily halted all transactions but was able to restore the network to a state prior to the incident quickly.
Tectonic advised its users to refrain from utilizing the platform while the investigation into the breach was ongoing, underlining the risks now associated with digital asset ecosystems.
Moonwell Investigates $8.7M Exploit
Moonwell is currently probing an attack that may have led to the loss of around $8.7 million from one of its lending services. Both PeckShield and CertiK have corroborated these estimations regarding the financial damage incurred. The assailant artificially inflated the value of mamo, a digital asset utilized on the Moonwell platform, allowing them to borrow more valuable assets and withdraw significant funds.
In a precautionary measure, Moonwell has temporarily restricted new borrowing in affected markets while simultaneously limiting deposits involving mamo, as the investigation unfolds.

