Tagged: exploit

Harmony Devs Confirm Major Exploit Involving Unauthorized Creation of ONE Crypto Tokens

Developers behind the Harmony blockchain protocol have officially acknowledged a significant security breach that allowed the unauthorized generation of a large volume of additional ONE tokens, the network’s native digital asset. The confirmation comes after on-chain observers first highlighted unusual activity involving the sudden appearance… Read More

BTCPay Server Community Pledges Recovery Reward of Up to 3 Bitcoin (BTC) After Critical Vulnerability Was Exploited

Following a significant security breach affecting the open-source Bitcoin payment platform, members of the BTCPay Server community have stepped forward with a substantial incentive aimed at reclaiming lost assets. Supporters of the project have pledged a recovery bounty structured as 10 percent of any funds… Read More

Coinsbuy Crypto Wallets Hit by Cross-Chain Drain on Ethereum and TRON, Losses Near $8 Million

A significant security incident has struck Coinsbuy, a B2B cryptocurrency payment processing platform serving enterprises, merchants, and exchanges. On-chain investigators reported that wallets linked to the service were drained of approximately $7.9 million in assets spanning the Ethereum and TRON networks. #PeckShieldAlert Specter has reported… Read More

Microsoft Identifies Malware Threat Using BNB Chain Smart Contracts to Hide Attack Commands

Microsoft Threat Intelligence has identified a widespread malware campaign that stores and retrieves attack instructions via smart contracts on the BNB Chain. The operation affects thousands of Windows systems daily, spanning both corporate networks and individual users. Researchers describe the approach as EtherHiding, in which… Read More

Ethereum Cross-Chain Bridge of Verus Protocol Exploited, $7.44 Million Drained via Notarization Mismatch

Blockchain security firm CertiK has noted that on July 23, 2026, an attacker successfully targeted the Ethereum cross-chain bridge of the Verus Protocol, extracting roughly $7.44 million in assets that included ETH, tBTC, various stablecoins, and MKR. The exploit hinged on a fundamental difference in… Read More

DeFI Exploits : Crypto Hacker Spends $4M to Drain $20M from BonkDAO’s Treasury, No Smart Contract Failed

Immunefi indicated that a recent incident involving BonkDAO highlights a troubling shift in how digital assets are being compromised. An individual invested approximately $4 million to acquire sufficient voting power, enabling the passage of a malicious governance proposal during a period of limited participant engagement…. Read More

Triple-A Crypto Hot Wallet Losses Surge as New Deposits Continue to be Drained

On-chain investigator Specter has reported that losses tied to compromised hot wallets associated with Singapore payments firm Triple-A have risen further, reaching an estimated $11.8 million. This marks an increase from the more than $9.3 million initially identified late Friday. Specter first publicly highlighted the… Read More

AFX Trade Suffers Bridge Exploit on Arbitrum, Draining Over $24 Million in Stablecoin USDC 

In a recent setback for DeFi ecosystem participants active on Arbitrum, the perpetuals trading platform AFX Trade experienced a substantial security breach targeting one of its proprietary bridges. Blockchain security firm Blockaid first identified the incident around 21:30 UTC on July 22, 2026, reporting that… Read More

South Korean Financial Regulator Advances Sanction Proceedings Against Dunamu, Upbit’s Parent Company, Months After Major Security Incident

South Korea’s Financial Supervisory Service (FSS) has formally launched the sanction process against Dunamu, the operator of Upbit, the nation’s largest cryptocurrency exchange by trading volume. The regulator recently delivered an inspection report to the company regarding last year’s significant hacking event, marking the first… Read More

Zilliqa Blockchain Dev Team Alerts Ecosystem to Security Breach at Exchange Partner’s Offline, Cold Storage Wallet

On July 20, 2026, the Zilliqa blockchain team disclosed a notable security event affecting one of its centralized exchange collaborators. Tokens of the project’s native cryptocurrency, ZIL, were taken from an offline cold wallet managed by the partner. The project has launched a thorough probe… Read More

Ostium, an Arbitrum based Perpetual DEX, Hit by Major Vault Exploit Involving Oracle Manipulation

Decentralized perpetuals trading platform Ostium, focused on real-world assets on the Arbitrum network, has suffered a substantial security incident resulting in the loss of approximately $18 million from its liquidity vault. The attack, which occurred on July 15, 2026, prompted the immediate halt of all… Read More

Bonzo Lend, Hedera’s DeFi Lending Platform, Suffers $9 Million Loss from Oracle Manipulation

Bonzo Lend—a DeFi lending protocol—experienced a major security incident resulting in approximately $9.05 million in losses. The exploit, which occurred on July 11, 2026, stemmed from a vulnerability in a third-party oracle service rather than any flaw in Bonzo’s own smart contracts. The incident began… Read More

Mercuryo Executive Says BONK Exploit Means Industry Needs to Rethink Security

BonkDAO, the manager of BONK memecoin ecosystem, have reported that approximately $20 million in value was drained from the network as a user gained sufficient token voting power to drive a transfer of funds to accounts they controlled. The exploit heightens concerns that smaller coins… Read More

BONK Memecoin and Solana Ecosystem’s BonkDAO Suffers Significant Treasury Drain in Governance Attack

BonkDAO—the entity managing aspects of the BONK memecoin ecosystem on Solana—has confirmed the loss of roughly $20 million worth of BONK tokens from its treasury. The incident stemmed from a malicious governance proposal that successfully authorized the transfer of funds to an attacker-controlled wallet. According… Read More

DeFi Hack : Summer Finance Hit by Suspected Flash Loan Exploit, Losing Appr $6M in DAI

Summer Finance—a yield aggregation and automated vault management platform formerly known as Oasis.app—has fallen victim to an exploit that drained roughly $6 million in DAI tokens. The incident, which surfaced on July 6, 2026, on the Ethereum blockchain, has prompted security researchers and on-chain analysts… Read More

Chainalysis Shares Insights on $7.5 Million Reverse Honeypot Exploit Against Ethereum’s Top Sandwich Bot

Blockchain analytics firm Chainalysis has published an in-depth examination of a sophisticated exploit that drained at least $7.5 million from JaredfromSubway.eth, widely regarded as Ethereum’s most active sandwich-attack operator. According to insights from Chainalysis, the incident unfolded over June 20–21, 2026, when an unknown attacker… Read More

SecondFi Outlines Recovery Plan After $2.4 Million Cardano Wallet Breach

SecondFi, the Cardano-based self-custody wallet platform formerly known as Yoroi and developed by Emurgo, has detailed a structured path to restore funds to users impacted by a security incident that occurred in late June 2026. The company confirmed it will work toward returning affected assets… Read More

Cardano (ADA) Project SecondFi Hit by Major Exploit with Losses Potentially Exceeding $20M

In yet another rather concerning development for the already struggling Cardano (ADA) ecosystem, the DeFi project SecondFi has been the victim of a significant exploit. The security breach was traced back to a vulnerability in the project’s proprietary wallet generation software, which permitted unauthorized access… Read More

Axelar Discloses $4.7 Million Loss in Secret Network Bridge Exploit

Blockchain interoperability platform Axelar has confirmed a security breach that resulted in the theft of approximately $4.7 million in bridged assets connected to the Secret Network. The incident, disclosed on June 19, 2026, involved tokens transferred via the Cosmos Inter-Blockchain Communication (IBC) protocol and was… Read More

Zcash (ZEC) Ecosystem Approves Ironwood Upgrade Consensus Rules, Aims for Late July Activation

Privacy focused Zcash (ZEC) developers have finalized precise modifications to the consensus rules for the upcoming Ironwood network upgrade. The decision addresses a serious flaw recently uncovered in the Orchard shielded transaction pool, which had raised alarms about the privacy-centric cryptocurrency’s vulnerability to potentially unlimited… Read More

Send this to a friend