Russia-based Sality watched for copied bitcoin and Ethereum addresses and quietly replaced them with the attacker’s. CrowdStrike and law enforcement have now isolated more than 15,000 infected machines.
Authorities
A February report claimed that Tether had frozen about $4.2 billion worth of its USDt stablecoin allegedly connected to illicit activities since 2023.
The US Justice Department is seeking to recover about $327,829 worth of stablecoins allegedly connected to a money laundering scheme part of an online romance scam.
In a Monday notice, the US Attorney’s Office for Massachusetts said it had filed a civil forfeiture action to recover more than 327,829 of Tether’s USDt (USDT). According to authorities, the funds were tied to an alleged online romance fraud scheme perpetrated by an individual named “Linda Brown” which targeted a Massachusetts resident starting in 2024.
“Some of the victim’s funds were traced to multiple unhosted cryptocurrency wallets, which were seized in August 2025,” said the Justice Department. “The complaint alleges that all cryptocurrency associated with those wallets was property involved in money laundering.”
The notice of the romance scam came about three weeks after people in many countries celebrated Valentine’s Day. The US Attorney’s Office for the Northern District of Ohio issued a warning before the holiday about romance scams, informing people not to “send money, gift cards, or cryptocurrency to someone you have not met in person.”
Related: February crypto losses hit lowest level since March 2025, says PeckShield
Cointelegraph reached out to Tether for comment, but had not received a response at the time of publication.
Tether froze $4.2 billion tied to illicit activity in previous three years
On Friday, a spokesperson for the stablecoin issuer reportedly told Reuters that Tether had frozen about $4.2 billion worth of USDt connected to suspected criminal activity since 2023.
The company has the ability to freeze its stablecoin by blacklisting certain wallet addresses. For example, Tether reported in February that it had frozen about $544 million allegedly tied to unlawful betting platforms and money laundering at the request of Turkish authorities.
Magazine: Clarity Act risks repeat of Europe’s mistakes, crypto lawyer warns
Man tortured for 16 hours in botched crypto kidnap attempt, say French authorities – DL News
- Attackers severed man’s finger and cut his face, police say.
- Gang mistakenly thought victim’s son was a rich crypto trader.
- Crypto-related kidnap cases are on the rise in France, data shows.
French police have arrested three men in their twenties suspected of kidnapping and torturing a 74-year-old man in a bid to extort $3.5 million worth of crypto from his son.
Officers said the trio abducted the unnamed victim at dawn on January 25 from his home in Voiron, in the Isère department in the southeast of the country, the French media outlet Actu 17 reported.
However, the would-be kidnappers aborted their efforts after learning that the man’s son was not a crypto trader at all, but actually a web developer with no significant crypto funds.
“These are extremely violent acts that demonstrate a rather blatant level of amateurism on the part of the perpetrators,” a lawyer for the victim’s family told reporters.
Crypto-related kidnaps and other violent attacks are on the rise worldwide.
This is particularly the case in France, where 19 so-called wrench attacks have been reported, per Certik data.
Last year, French authorities rescued David Balland, the co-founder of crypto hardware firm Ledger, along with his wife, after they were kidnapped by criminals seeking a ransom.
A ‘living hell’
Officials told reporters the 74-year-old endured “nearly 16 hours of torture” at the gang’s hands.
Police said the trio found three 17-year-olds, who had rented a building on the victim’s property for the night, in an outbuilding.
The men reportedly tied these teenagers up and confiscated their mobile phones. The victim’s partner managed to hide in an attic room, where she remained undiscovered.
The victim was forced into a vehicle and driven to a back room of a bar in Valence, where the assailants reportedly filmed themselves torturing the man.
The gang then sent footage of the torture to his son via encrypted messages, demanding that he pay a ransom fee in an unnamed cryptocurrency.
When they eventually realised that the man’s son was not a “crypto millionaire” as they had incorrectly assumed, they decided to release their captive at 11 pm the same day, pushing him out of a car onto a roadside.
Officers said they questioned the bar’s manager and the vehicle owner, but released both without charge.
The victim has been discharged from hospital, the lawyer said, with “very deep scars, particularly on his face.”
The septuagenarian had “the mindset of a survivor,” the lawyer said. “The victim went through living hell and was confronted by determined individuals who were ready to stop at nothing.”
Tim Alper is a News Correspondent at DL News. Got a tip? Email him at tdalper@dlnews.com.

Back in 2020, about 120,000 Bitcoin, now worth around $15 billion, were mysteriously moved between wallets. Many believed it was a hack. But new reports say it wasn’t hacking at all.
According to crypto wallet firm OneKey, the problem came from a popular open-source Bitcoin tool called Libbitcoin Explorer (bx). This software was used to create wallets offline, but it contained a serious flaw: it didn’t generate private keys randomly enough.
Instead, the system used the computer’s clock as a seed to create wallet keys. That meant only a limited number of key combinations were possible. Anyone who knew roughly when a wallet was created could guess its private key, and take control of it.
Researchers found that over 220,000 Bitcoin addresses were affected. Shockingly, some people are still sending funds to these unsafe wallets today.
What’s most interesting is wallet addresses listed in the US government $14B (127K BTC) seizure previously were named in a Milky Sad report ~2 years ago for having vulnerable private keys and now the USG says they have custody of them. https://t.co/sHNwMXhLKH pic.twitter.com/icLWKU33kC
— ZachXBT (@zachxbt) October 14, 2025
The “Milk Sad” and LuBian Connection
This same weakness may explain earlier mysterious thefts, including the “Milk Sad” incident, where users lost their funds even though their computers weren’t connected to the internet.
The flaw also connects to another case involving LuBian, a major Bitcoin mining business. In 2020, LuBian lost 127,000 Bitcoin after attackers exploited a similar weak key system.
Now, U.S. authorities have confirmed that many of those coins were linked to Prince Group, a company accused of running online scams and forced-labor operations in Cambodia. The Department of Justice (DOJ) has seized those Bitcoin, making it one of the largest crypto confiscations ever.
NEW: Some of the 127,000 Bitcoin the U.S. government just seized from a Chinese scam were previously reported as having private key vulnerabilities
Now the U.S. government has them in custody
Is the U.S. government hacking Bitcoin wallets? 🤔
h/t @zachxbt pic.twitter.com/BY10yjUPmB
— Bitcoin Archive (@BTC_Archive) October 14, 2025
This discovery shows how a small coding mistake can expose billions of dollars. Weak random key generation doesn’t break Bitcoin itself , but it can break wallets built with poor code.
Experts now urge users to switch to hardware wallets or trusted apps that use true random number generators. It’s a strong reminder: in crypto, your security is only as strong as your code.




Disclaimer
The information provided by Altcoin Buzz is not financial advice. It is intended solely for educational, entertainment, and informational purposes. Any opinions or strategies shared are those of the writer/reviewers, and their risk tolerance may differ from yours. We are not liable for any losses you may incur from investments related to the information given. Bitcoin and other cryptocurrencies are high-risk assets; therefore, conduct thorough due diligence. Copyright Altcoin Buzz Pte Ltd.