A recent security breach has been identified, exploiting two primary vectors. Attackers used a malicious TestFlight app disguised as a wallet product to compromise user systems. Additionally, a known vulnerability in VSCode/Cursor, which allows arbitrary code execution when a file is opened, was leveraged. This vulnerability has been flagged by the security community since late 2025, highlighting ongoing risks in software security.