Incident AnalysisThe actors who withdrew ~4,000 BTC from the Liquid Federation wallet have told Blockstream, via Bitcoin transactions, to fix the Elements bug and update every node before funds are returned — and reportedly sent encrypted technical details. Nothing about their identity or intentions is confirmed.
Sep 7, 2026·3 min read
Incident AnalysisA self-trading scheme on an illiquid, dormant perpetual market generated fake profits on one account, bankrupted a burner account, and withdrew $287K — with the loss socialized across the platform. Deposits, withdrawals, and trading are paused while the team coordinates tracing and freezes.
Sep 7, 2026·2 min read
HacksOn-chain monitors flagged a coordinated drain of more than 600 wallets believed linked to Bitcoin mining platform GoMining, with roughly $2.8 million swapped and bridged across chains before consolidating into about 1,147 ETH. GoMining has not confirmed the incident, and Bitget has suspended GOMINING deposits and withdrawals.
Sep 6, 2026·3 min read
Incident AnalysisCertiK, TRM Labs, and Forbes converge on roughly $1.3 billion in hack losses through the first half of 2026, with compromised private keys overtaking smart-contract bugs as the leading attack vector for the first time on record. The year's biggest thefts — Drift's $285M and KelpDAO's $290M — passed their audits before losing everything to a single compromised key.
Sep 6, 2026·5 min read
SecurityThe Swiss Bitcoin broker's completed forensic investigation found two exposed data groups: bank transaction lists covering 5,120 customers and correspondence with partner banks affecting 291 more, some including identity documents and source-of-funds records. Customer funds and private keys were never at risk, the noncustodial firm says.
Sep 6, 2026·3 min read
Security DigestThe day's smaller security stories in brief: on-chain tracking reportedly shows the Kelp DAO exploiter moving $175 million in ETH after Arbitrum's freeze, Binance warns of a surge in text-message phishing, the Trezor breach settles at roughly 80,700 exposed customers with no overlap accounting, Notional Finance's root cause is confirmed as an integer overflow, and the Tectonic attacker bridges stolen ETH to Tornado Cash.
Sep 6, 2026·3 min read
Incident AnalysisThe Sui lending protocol is shutting down after an attacker removed about $91,000 from three vaults during a suspected compromise of Switchboard's Move-based oracle infrastructure — an incident that also halted four networks and impaired Virtue's VUSD stablecoin.
Sep 5, 2026·2 min read
Security DigestThe day's smaller security stories in brief: the G7's cybersecurity working group warns organizations to start migrating to post-quantum cryptography now, Google patches an actively exploited Chrome V8 zero-day, attackers exploited a critical Citrix NetScaler auth bypass, and Coder's registry infrastructure was compromised to push malicious Terraform modules.
Sep 5, 2026·2 min read
SecurityA New York lawsuit claims Tether froze $42.4 million in USDT on an informal Homeland Security request months before any warrant existed, in a $61 million alleged pig-butchering seizure. The plaintiffs deny any involvement — and the case tests how much freeze power a stablecoin issuer really has.
Sep 5, 2026·2 min read
SecurityTrezor says a shipping-provider breach it disclosed in August affects another 67,000 US customers whose order records were kept despite written deletion assurances. The exposed data maps confirmed hardware-wallet owners to home addresses, setting up targeted phishing and physical-security risks.
Sep 5, 2026·2 min read
Incident AnalysisInjective went roughly four hours without a block during an emergency patch after researchers estimated $4.9 million was bridged out in a binary-options market exploit. The foundation says the chain was upgraded, not halted; researchers disagree about where the vulnerability sat.
Sep 4, 2026·2 min read
HacksBlockchain investigators report roughly $1.7 million in DAI and USDC left an escrow contract linked to Notional Finance and were swapped for 689.2 ETH before entering Tornado Cash. The protocol has not confirmed the incident.
Sep 4, 2026·2 min read
SecurityThe frontier model scores 100% on ExploitBench, but the version reaching customers is restricted to secure code review and patching and refuses proof-of-concept exploit requests. OpenAI paired the launch with a $1 billion defender-access program.
Sep 4, 2026·2 min read
Security DigestThe day's smaller security stories in brief: Wave 3 Coldcard theft funds move through THORChain into Ethereum, Blockaid details how an outdated Rain card contract drained about $1.1 million across crypto neobanks, the DOJ and CrowdStrike isolate a long-running crypto-stealing botnet, and the FBI seizes $560,000 tied to an alleged Hamas fundraising operation.
Sep 4, 2026·3 min read
SecurityUkraine's National Police and Security Service say they shut down a network of fake investment platforms that drained crypto wallets belonging to 62 identified victims in more than 20 countries, using a wallet drainer activated through a fake test transaction.
Sep 4, 2026·2 min read
HacksThe Solana AMM set a September 3, 14:00 UTC deadline for the attacker to return at least 80% of the stolen funds in exchange for a 20% bounty and no civil claims. Public reporting points to compromised credentials, not a contract bug.
Sep 3, 2026·2 min read
Incident AnalysisThe official account confirms six exploited networks, roughly $5.7 million realized by attackers, frozen exchange accounts — and a bounty triage decision that routed a fund-draining bug down the public patch path.
Sep 3, 2026·4 min read
SecurityIn the same week, OpenAI classified its first model at the Critical tier for cybersecurity capability and Anthropic published a post-incident review of Claude models reaching real systems during evaluations. Both disclosures describe the new baseline defenders operate against.
Sep 3, 2026·4 min read
Security DigestThe day's smaller security stories in brief: a $234K rounding exploit against legacy Balancer V1 pools and an advisory to withdraw, Fogo's mainnet returns with 237M tokens burned after a supply attack, and the fallout from France's confirmed 678,000-record tax data breach continues to hang over crypto holders.
Sep 3, 2026·3 min read
SecurityArkham-traced wallets tagged to the OFAC-sanctioned North Korean collective cycled $30 million in Bitcoin through the perps DEX, converted to ETH and SOL, and bridged out to Tron, Solana and Ethereum before reaching centralized exchanges.
Sep 2, 2026·2 min read
SecurityBor and Heimdall client vulnerabilities — including a crafted-transaction resource exhaustion vector — were patched through hard forks deployed privately before public disclosure. No exploitation was observed on mainnet.
Sep 2, 2026·2 min read
Security DigestThe day's smaller security stories in brief: South Korea charges four in a first-of-its-kind case of crypto flowing out of a UN-designated terror group, Galaxy Research tallies Coldcard hack losses with 87% of funds unmoved, and a Chainalysis-led operation flags thousands of accounts in a child abuse investigation.
Sep 2, 2026·2 min read
SecurityICE awarded TRM Labs a $94.6 million forensic software contract without competition after a six-day market research window. Chainalysis has filed a sealed bid protest, and the case is testing how the government buys blockchain surveillance tooling.
Sep 1, 2026·4 min read
HacksA suspected pump-and-borrow attack against lending protocol Tectonic drained an estimated $74–75 million before Cronos halted the chain. The network has since restarted, but the cause and final loss figure remain unconfirmed by both projects.
Sep 1, 2026·3 min read
Incident AnalysisMantra's postmortem confirms an unsigned-integer underflow in Cosmos EVM's balance-accounting layer drained 720.9 million MANTRA from two protocol wallets. The fix had been merged upstream three months earlier — and shipped as a release one day before the attack.
Sep 1, 2026·3 min read
HacksAn attacker used an Ankr liquid staking token and Aave-style E-mode borrowing to drain roughly 15.5 million WFLOW from a More Markets lending reserve on Flow EVM, according to Blockaid's on-chain analysis.
Sep 1, 2026·2 min read
HacksFive compromised validator signatures cleared the two-thirds threshold, allowing the withdrawal of the protocol's entire USDC reserve through a mechanism that operated exactly as designed.
Aug 31, 2026·2 min read
HacksA build error swapped hardware randomness for predictable software entropy, making thousands of Coldcard wallet seeds reproducible from guessable device states. Estimated losses exceed $130 million.
Aug 31, 2026·4 min read
HacksAn attacker used a trusted price forwarder to feed a fake $60,000 Bitcoin quote, draining the perpetuals exchange's vault in five minutes through trades that were never real.
Aug 31, 2026·3 min read
HacksAn attacker acquired 90.7% of voting power with just 0.5 ETH, bypassing timelock protections to drain 2,843 WETH and 1.68 million USDC from vaults.
Aug 31, 2026·3 min read