Lookonchain APP

App Store

BNB (BNB) — Onchain News & Whale Tracking

Real-time BNB whale movements, exchange flows and onchain findings tracked by Lookonchain. 593 updates and counting.

2026.08.07 10:56

Microsoft: Discovers new attack campaign hiding malicious code via BNB Chain smart contracts, affecting thousands of devices globally.

Microsoft’s Threat Intelligence Team has released a report disclosing a set of compromised websites that use ClickFix and TerminalFix to launch social engineering attacks, combined with EtherHiding technology, to access smart contracts via the BNB Smart Chain RPC gateway for retrieving subsequent malicious commands. Since the malicious content is stored in on-chain smart contracts, only the wallet owner that deployed the contract can modify it, making it hard to eliminate through traditional takedown or blocking measures. Attackers forge CAPTCHA verification pages to trick users into opening Windows’ Run window, Terminal, or PowerShell, then pasting and executing malicious commands. The attack workflow extensively leverages system tools including conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and Living-off-the-Land (LotL) attacks. Microsoft points out that ClickFix and TerminalFix have emerged as high-frequency initial intrusion vectors, impacting thousands of enterprise and personal devices worldwide daily. Multiple threat actors use these tactics to spread malware such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, which can further lead to credential theft, lateral movement, and ransomware attacks. The tech giant advises users against following prompts from CAPTCHAs, web error pages, emails, or ads to paste and execute any commands in Windows Run, Terminal, PowerShell, or Command Prompt.

2026.07.09 23:36

Security Warning: Abnormal on-chain fund flows detected for the CodexField project on BNB Chain.

On-chain investigator Specter has issued a community security alert, warning of potential fund misappropriation risks associated with the CodexField project on BNB Chain. On-chain tracking shows the project has amassed over $85 million in funds. Specter detected abnormal on-chain fund flows yesterday: a wallet bridged 17.3 million USDT from TRON to Ethereum, then swapped the tokens for DAI via Bitget Swap on Polygon. So far, $6.5 million has been transferred out, while the remaining $10.8 million is still in transit. The funds were originally bridged from Ethereum to TRON roughly six months ago, and the source wallet is linked to CodexField’s deposit contract. Below are key addresses for users to verify on their own: EVM: 0xBc606358910b3720d136F0d4Ce12b759C270747a TRON: TQNTEYadFVVQeobBtctSjurJ5RpfBsTmqh, TAzpg8L1WkkzCxxZk8TYnvaRYahehh52MK Related deposit contract: 0x9E6A75b546B65E7B9D34E2c9aB8Fe224B9aA52AA Additional red flags: The project requires a minimum $100 deposit for participation. Blockchain security tool Blocksec MetaSuites initially labeled the deposit contract as "Fake CodexField", but Specter’s follow-up investigation found the contract is actually operated by the CodexField team itself. The project uses multiple domains and subdomains to collect user deposits, and the team previously shared these domains via official channels. Its fund flow pattern is unusual, deviating from standard fund management practices: the project bridges funds across multiple blockchains, routes them through intermediate wallets, and ultimately sends assets to centralized exchanges. Specter noted that based on on-chain activity, the project warrants high vigilance. It advises all users interacting with CodexField to exercise extreme caution until the team provides a transparent explanation of its fund movements.

Page 1 / 12 Next →

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano