Security
Security incidents, exploits, and risk mitigation updates.
Page 1 of 2. 28 published articles in this topic archive.
Reading exploit and incident reports
Security coverage should distinguish an initial allegation, confirmed affected systems, containment and recovery. An early loss estimate is not the same as a final accounting, and a protocol incident is not automatically a compromise of the underlying network. Follow the dates and the cited investigation as a story develops. General wallet-safety guidance can provide context, but it cannot verify a specific incident.
Questions to ask of each report
- Who confirmed the incident, and which contracts, chains or accounts are affected?
- Are losses gross or net of recoveries, and is the root cause established or still being investigated?
Primary documents and background
- Ethereum security and scam-prevention guidance
Project-maintained background on wallet security and common scams.
Coverage timeline
Sep 30, 2026–Oct 7, 2026 (UTC): 3 new articles and 0 older articles updated. These are counts of our coverage, not a measure of market activity. Dates below are publication dates.
- Chainalysis ties $387M Bitget theft to North Korea; XRP reaches Bitcoin as DPRK-linked thefts top $1B
- NEAR Intents pauses cross-chain swaps after $3.8M exploit, gives identified attacker 48 hours to return funds
- MetaMask Exits Lido Validators After Infrastructure Incident, Reports No Immediate Wallet Threat
- Bitget resumes Bitcoin withdrawals in phases after $388 million hack, with fund absorbing losses
- Bitget plans staged withdrawal restart after hack, updates losses to $388M and announces recovery bounty
All coverage
Chainalysis ties $387M Bitget theft to North Korea; XRP reaches Bitcoin as DPRK-linked thefts top $1B
Chainalysis said AI-assisted automation reduced a bridge-reconciliation task during its investigation of the $387 million Bitget theft from more than 20 hours of manual work to …
NEAR Intents pauses cross-chain swaps after $3.8M exploit, gives identified attacker 48 hours to return funds
NEAR Intents general manager Alex Shevchenko said the team had identified the person responsible for a roughly $3.8 million exploit and gave them 48 hours to return the funds [1…
MetaMask Exits Lido Validators After Infrastructure Incident, Reports No Immediate Wallet Threat
MetaMask is responding to a security incident affecting part of its infrastructure and says it has found no immediate threat to MetaMask wallets. As a precaution, it is exiting …
Bitget resumes Bitcoin withdrawals in phases after $388 million hack, with fund absorbing losses
Bitget resumed Bitcoin withdrawals four days after a reported $387.5 million hack, while the exchange restores withdrawals in phases [1] [2] [3]. CEO Gracy Chen said in a Septem…
Bitget plans staged withdrawal restart after hack, updates losses to $388M and announces recovery bounty
Bitget plans to restart withdrawals in stages on Sept. 28, beginning with Bitcoin, with Ether, USDT and other services scheduled to follow through Oct. 2. Other reporting also l…
Bitget raises Sept. 24 incident estimate to $387.5M, with withdrawal plan due Sept. 26
Bitget raised its estimate of assets transferred to attacker-controlled addresses in the Sept. 24 security incident to about $387.5 million, from $351.6 million. The exchange sa…
Bitget reports $351M breach; CEO cites DPRK-linked VPN IPs and says wallet keys were not obtained
Bitget detected unauthorized transfers from several wallets on Sept. 24. Reports put the losses at roughly $351 million to $352 million; CoinGape reported that XRP accounted for…
Reports flag suspected Bitget wallet compromise after over $170 million moves, some swapped to ETH
On-chain activity has raised suspicions of a security incident involving Bitget wallets, with reports saying more than $170 million in assets moved and other coverage putting th…
IOG warns users after its YouTube channel was hijacked to promote a fake Charles Hoskinson giveaway
Input Output Group (IOG) warned users to avoid its official YouTube channel after the channel was reportedly hijacked and used to air a fake Charles Hoskinson giveaway livestrea…
S&P Global to acquire OpenZeppelin to expand digital asset risk assessment into onchain technology
S&P Global has entered into an agreement to acquire OpenZeppelin, a smart contract security company, as part of an expansion of its digital asset risk assessment capabilities in…
Reports say Revolut hackers leaked customer KYC data and demanded ransom payments, including 10,000 BTC
Reports say hackers have released personal identification documents and verification selfies belonging to Revolut users and are using the data release as extortion to demand ran…
Trezor warns of phishing emails after breach of third-party email provider used to send alerts
Trezor warned users that hackers breached a third-party email provider and used Trezor’s legitimate email domain to send phishing messages, including an email with the subject “…
Cronos reports $9.19M still unrecovered after Tectonic exploit rollback reversed $111.2M
Cronos said $9.19 million remains unrecovered after an attacker borrowed $120.4 million from the Tectonic lending protocol, and validators later approved a rollback that reverse…
U.S. agents seize about $560,000 in cryptocurrency linked to Hamas and take over fundraising infrastructure
U.S. federal agents seized about $560,000 in cryptocurrency allegedly tied to Hamas’ military wing and took control of domains and servers used in the group’s fundraising and re…
Fake Claude Opus desktop app distributes RevStealer malware targeting 50+ crypto wallets on Windows
Security reporting says a fraudulent desktop application impersonating “Claude Opus 5 Free Desktop” is distributing the RevStealer malware on Windows systems [1]. The reports st…
More Markets reports Flow EVM lending reserve exploit draining about 15.5M WFLOW, ~$9.3M
More Markets experienced an exploit on Flow EVM that reportedly drained about 15.5 million WFLOW from the lending protocol, with Blockaid estimating the impact at roughly $9.3 m…
Cronos halts after Tectonic exploit, with attacker estimated to borrow about $75 million
The Cronos network halted after an exploit impacted the lending protocol Tectonic [1] [2]. Wu Blockchain reported that on-chain researcher Weilin Li estimated the attacker pumpe…
Bitfinex Securities raises $50 million for tokenized nickel trading backed by Alkemya assets
Bitfinex Securities said it raised $50 million in connection with a tokenized nickel trading offering, with reporting describing the security as being linked to a Luxembourg-bas…
BNB Chain activates Pasteur hard fork on mainnet to address bridge and validator security
BNB Chain activated the Pasteur hard fork on BSC mainnet on Aug. 25, with reporting describing the upgrade as targeting gaps in bridge and validator security and also including …
Monad proposes wallet upgrade to allow key replacement without changing addresses amid quantum risk
Monad, an Ethereum-compatible blockchain project, proposed a wallet upgrade intended to let users replace or retire the keys that control an account without changing the wallet …
Cosmos Labs advises Cosmos EVM chains to pause validators after incident impacting module users
Cosmos Labs said an ongoing security incident involving the Cosmos EVM module has affected users and has advised contacted Cosmos EVM-based chains to halt validator operations w…
Term Labs reports Aug. 23 governance exploit after attacker took control of strategy vaults, draining $8.5M
Multiple outlets reported that Term Labs suffered a governance exploit on Aug. 23, in which an attacker gained control of the protocol’s strategy vaults [1] [2]. Crypto.news and…
Maya Protocol pauses after a $1.7M cross-chain exploit drains BTC and CACAO
Maya Protocol suffered an estimated $1.7 million security breach, according to multiple reports on Aug. 19, 2026. Crypto.news said the cross-chain network halted operations afte…
Crypto wallet incidents: SafePal and Bits of Gold face data exposure while alleged AI theft hits Coldcard
SafePal said an authorization vulnerability in an order-tracking plugin exposed personal information for 39,798 customers, including names, contact details, delivery addresses, …