We found cryptography bugs in the elliptic library using Wycheproof

Trail of Bits discovered and disclosed two vulnerabilities in the widely used elliptic JavaScript library that could allow signature forgery or prevent valid signature verification, with one vulnerability still unfixed after the 90-day disclosure window.

The Trail of Bits Blog
Krypto-Schwarzmarkt auf Telegram: Milliardenhandel verdrängt das Darknet

Krypto-Schwarzmarkt auf Telegram: Milliardenbetrug ersetzt das Darknet. Scammer, Geldwäsche und Menschenhandel im offenen Messenger.

TARNKAPPE.INFO

Moving Beyond the NPM elliptic Package

If you're in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node_modules. Art: CMYKat Why replace the elliptic package? Yesterday, the Trail of Bits blog published a post about finding cryptographic bugs in the elliptic library (a Javascript package on NPM) by using the Wycheproof.

http://soatok.blog/2025/11/19/moving-beyond-the-npm-elliptic-package/

#npm #crypto #cryptography #elliptic #security #infosec #cve #mitigation #appsec #javascript #js #npm #npmsecurity #npmpackages

Moving Beyond the NPM elliptic Package - Dhole Moments

If you’re in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node…

Dhole Moments
The Bridges to Fermat's Last Theorem - Numberphile

YouTube
📬 Telegram räumt auf: Zwei Mega-Märkte, 3.400 Accounts, 35 Milliarden Dollar weg
#DarkCommerce #Cybercrime #Elliptic #HuioneGuarantee #Telegram #TelegramMarktplätze #XinbiGuarantee https://sc.tarnkappe.info/8be08a
Telegram räumt auf: Zwei Mega-Märkte, 3.400 Accounts, 35 Milliarden Dollar weg

Telegram räumt auf – aber zu welchem Preis? Mit einem Schlag wurden zwei Mega-Schwarzmarkt-Netzwerke im Wert von 35 Mrd. USD gesperrt.

TARNKAPPE.INFO

i feel like there must be some linguistic reason these Chinese organized crime crypto money laundering companies always use the word "guarantee" in their names.

* Elliptic report: https://www.elliptic.co/blog/xinbi-guarantee
* Wired article: https://www.wired.com/story/xinbi-guarantee-crypto-scam-hub/

Also worth noting that Jacob Silverman and James Block (Dirty Bubble Media) were reporting on some of these Colorado based crypto scam companies a year and a half ago: https://www.thenation.com/article/economy/rocky-mountain-lie/

#Xinbi #XinbiGuarantee #crypto #crime #moneylaundering #corruption #colorado #NorthKorea #DPRK #pigbutchering #scams #fraud #Elliptic #triads #Zhongteng #ZhongtengAccounting #Telegram #China #LazarusGroup

Xinbi: The $8 Billion Colorado-Incorporated Marketplace for Pig-Butchering Scammers and North Korean Hackers

Xinbi Guarantee is a Chinese-language, Telegram-based marketplace for cyber fraudsters in Southeast Asia, dealing primarily in the USDT stablecoin. With $8.4 billion in transactions since 2022, it offers tools and services for scams, including money laundering, fake IDs, and stolen data. The platform is linked to North Korean hackers and operates through a Colorado-incorporated entity.

Today's light reading: https://eprint.iacr.org/2022/1325.pdf

Remarkably comprehensive survey of the subject matter (binary elliptic curves) and very clever construction. Useful in specific cases where differential addition isn't available. (And, having read the whole paper, useful when it is!)

#elliptic #cryptography #math

Alleged Co-Founder of Garantex Arrested in India - Authorities in India today arrested the alleged co-founder of Garantex, a cryptocu... https://krebsonsecurity.com/2025/03/alleged-co-founder-of-garantex-arrested-in-india/ #u.s.departmentofjustice #aleksandrmiraserda #u.s.secretservice #neer-do-wellnews #aleksejbesciokov #ransomware #elliptic #garantex
Alleged Co-Founder of Garantex Arrested in India – Krebs on Security

Alleged Co-Founder of Garantex Arrested in India

https://krebsonsecurity.com/2025/03/alleged-co-founder-of-garantex-arrested-in-india/

#U.S.DepartmentofJustice #AleksandrMiraSerda #Ne'er-Do-WellNews #U.S.SecretService #AleksejBesciokov #Ransomware #Elliptic #Garantex

Alleged Co-Founder of Garantex Arrested in India – Krebs on Security