Security
Security incidents, exploits, and risk mitigation updates.
Page 1 of 1. 16 published articles in this topic archive.
Reading exploit and incident reports
Security coverage should distinguish an initial allegation, confirmed affected systems, containment and recovery. An early loss estimate is not the same as a final accounting, and a protocol incident is not automatically a compromise of the underlying network. Follow the dates and the cited investigation as a story develops. General wallet-safety guidance can provide context, but it cannot verify a specific incident.
Questions to ask of each report
- Who confirmed the incident, and which contracts, chains or accounts are affected?
- Are losses gross or net of recoveries, and is the root cause established or still being investigated?
Primary documents and background
- Ethereum security and scam-prevention guidance
Project-maintained background on wallet security and common scams.
Coverage timeline
Sep 1, 2026–Sep 8, 2026 (UTC): 3 new articles and 0 older articles updated. These are counts of our coverage, not a measure of market activity. Dates below are publication dates.
- Cronos reports $9.19M still unrecovered after Tectonic exploit rollback reversed $111.2M
- U.S. agents seize about $560,000 in cryptocurrency linked to Hamas and take over fundraising infrastructure
- Fake Claude Opus desktop app distributes RevStealer malware targeting 50+ crypto wallets on Windows
- More Markets reports Flow EVM lending reserve exploit draining about 15.5M WFLOW, ~$9.3M
- Cronos halts after Tectonic exploit, with attacker estimated to borrow about $75 million
All coverage
Cronos reports $9.19M still unrecovered after Tectonic exploit rollback reversed $111.2M
Cronos said $9.19 million remains unrecovered after an attacker borrowed $120.4 million from the Tectonic lending protocol, and validators later approved a rollback that reverse…
U.S. agents seize about $560,000 in cryptocurrency linked to Hamas and take over fundraising infrastructure
U.S. federal agents seized about $560,000 in cryptocurrency allegedly tied to Hamas’ military wing and took control of domains and servers used in the group’s fundraising and re…
Fake Claude Opus desktop app distributes RevStealer malware targeting 50+ crypto wallets on Windows
Security reporting says a fraudulent desktop application impersonating “Claude Opus 5 Free Desktop” is distributing the RevStealer malware on Windows systems [1]. The reports st…
More Markets reports Flow EVM lending reserve exploit draining about 15.5M WFLOW, ~$9.3M
More Markets experienced an exploit on Flow EVM that reportedly drained about 15.5 million WFLOW from the lending protocol, with Blockaid estimating the impact at roughly $9.3 m…
Cronos halts after Tectonic exploit, with attacker estimated to borrow about $75 million
The Cronos network halted after an exploit impacted the lending protocol Tectonic [1] [2]. Wu Blockchain reported that on-chain researcher Weilin Li estimated the attacker pumpe…
Bitfinex Securities raises $50 million for tokenized nickel trading backed by Alkemya assets
Bitfinex Securities said it raised $50 million in connection with a tokenized nickel trading offering, with reporting describing the security as being linked to a Luxembourg-bas…
BNB Chain activates Pasteur hard fork on mainnet to address bridge and validator security
BNB Chain activated the Pasteur hard fork on BSC mainnet on Aug. 25, with reporting describing the upgrade as targeting gaps in bridge and validator security and also including …
Monad proposes wallet upgrade to allow key replacement without changing addresses amid quantum risk
Monad, an Ethereum-compatible blockchain project, proposed a wallet upgrade intended to let users replace or retire the keys that control an account without changing the wallet …
Cosmos Labs advises Cosmos EVM chains to pause validators after incident impacting module users
Cosmos Labs said an ongoing security incident involving the Cosmos EVM module has affected users and has advised contacted Cosmos EVM-based chains to halt validator operations w…
Term Labs reports Aug. 23 governance exploit after attacker took control of strategy vaults, draining $8.5M
Multiple outlets reported that Term Labs suffered a governance exploit on Aug. 23, in which an attacker gained control of the protocol’s strategy vaults [1] [2]. Crypto.news and…
Maya Protocol pauses after a $1.7M cross-chain exploit drains BTC and CACAO
Maya Protocol suffered an estimated $1.7 million security breach, according to multiple reports on Aug. 19, 2026. Crypto.news said the cross-chain network halted operations afte…
Crypto wallet incidents: SafePal and Bits of Gold face data exposure while alleged AI theft hits Coldcard
SafePal said an authorization vulnerability in an order-tracking plugin exposed personal information for 39,798 customers, including names, contact details, delivery addresses, …
SafePal Says Order-Tracking Plugin Flaw Exposed Data for Nearly 40,000 Customers
Crypto wallet provider SafePal disclosed a data breach that exposed order information for nearly 40,000 customers, according to reporting published on Aug. 16, 2026. The company…
Trezor says ShipMonk breach exposed shipping data for 13,689 customers
Hardware wallet maker Trezor said a data breach at its shipping provider, ShipMonk, exposed sensitive order information for thousands of customers. Trezor reported that ShipMonk…
Harmony investigates reported 4B ONE unauthorized mint as ONE crashes and rollback considered
Harmony is investigating a reported unauthorized mint of ONE tokens, with multiple outlets citing an alleged 4 billion ONE minted after suspected exploit activity. CoinDesk repo…
Bybit Sues North Korea in U.S. Court, Freezes Lazarus-Stolen Crypto and Seeks Recovery
Bybit has filed a civil lawsuit in U.S. federal court targeting North Korea’s Reconnaissance General Bureau and the Lazarus Group over a reported $1.5 billion crypto theft linke…