Security news

Showing 1–50 of 341
Clear filters

October 9, 2026

Security

Brazil Police Recover More Than $1.7 Million From Self-Custody Crypto Wallets

Brazil seizes record $1.7M in crypto from self-custody wallets Santa Catarina’s Civil Police said Operation ClickFix recovered more than $1.7 million from self-custody crypto wallets, calling it the largest seizure of its kind by Brazilian law enforcement. The Sept. 10 operation targeted a phishing group that used social engineering and malware, and police said they found four seed phrases, identified the assets with Chainalysis tools, and transferred the funds in 13 transactions to the force’s institutional account on Foxbit.

Security

Ledger Halts CryptoBilis Wallet Sales as It Investigates Reported Customer Drains

Ledger tells CryptoBilis to halt wallet sales amid loss investigation Ledger has asked Southeast Asian reseller CryptoBilis to pause all Ledger sales and shipments while it investigates reports that buyers lost funds. The warning applies only to customers who bought from CryptoBilis in the past 90 days: Ledger told them not to set up the device, or if they already had, to move funds to a new device with a new seed phrase. The move came about an hour after analyst Specter put suspected losses above $86 million, a figure Ledger has not confirmed.

Security

Zcash targets January 2027 for post-quantum support for transparent payments

Zcash developers target Jan. 2027 for quantum-resistant transparent payments Zcash developers plan to add post-quantum signature opcodes in January 2027 to protect transparent transactions from future quantum attacks, with Zakura proposing hash-based signatures such as WOTS. The target is not a confirmed mainnet activation or migration deadline, but it matters because about 11.96 million ZEC, or 70.4% of supply, sits in transparent addresses where public keys can be exposed when coins are spent.

Security

London Man Gets 2.5 Years for SIM-Swap Scheme That Stole Nearly £200,000 in Crypto

London man jailed 2.5 years over £200,000 SIM-swap crypto theft Ajay Shinjin, 25, also known as AJ Marley Cruz, was sentenced at Inner London Crown Court after admitting his role in a November 2021 SIM-swap fraud that stole nearly £200,000 in cryptocurrency from BT customers. Police said he received more than £44,000 of the proceeds, with BT system data linking him to four devices used in the attacks.

Security

Pattaya Home Invasion Forced Expat to Transfer $820,000 in Crypto, Thai Police Say

Gunmen force Pattaya expat to transfer $820K in crypto Three armed men broke into a gated home in Nongprue at about 3:30 a.m. Tuesday, held a Chinese expat with Turkish citizenship at gunpoint, and forced him to transfer $820,000 in cryptocurrency, along with cash and three luxury watches, Thai local reports said. Police Region 2 said the crypto was sold immediately and investigators, working with the Immigration Bureau, are tracing the wallets and accounts involved to recover the funds.

October 8, 2026

Security

CrowdStrike says Korean bank breach suspect used Claude to ask where to sell stolen data

CrowdStrike: Korean bank breach suspect asked Claude where to sell stolen data CrowdStrike said session logs left in open directories on attacker-controlled servers show the suspect behind recent South Korean bank breaches asked Claude Code where Korean breach data is sold and how to find Telegram groups trading it. In its Oct. 7 report, CrowdStrike said the campaign used the Chinese-built ARTEX pentesting tool and assessed with moderate confidence the actor is a financially motivated Chinese speaker.

Security

French-U.S. Probe Shuts Nudeleaksteens, Seizes $783,000 in Crypto

French-US operation shuts down Nudeleaksteens, seizes $783,000 in crypto French and U.S. authorities shut down Nudeleaksteens, a platform that sold stolen intimate images of more than 17,000 women and underage girls, and seized over $783,000 (€700,000) in crypto including bitcoin, ether, litecoin and USDT. Two brothers, 21 and 25, were arrested in northern France as alleged site administrators; prosecutors said the network used crypto to reward users for doxxing victims and selling explicit “packs,” including child sexual abuse material.

Security

Dunamu warns social media scam targets Upbit accounts and even read-only API keys

Upbit operator Dunamu warns of scam targeting API keys Dunamu said it has found numerous social media posts trying to rent or buy Upbit accounts and even read-only API keys under the guise of checking market data. The company warned there is no need to share authenticated credentials for basic price data, urged users to delete exposed or unused keys immediately, and said accounts rented out or tied to suspicious activity will be suspended and may be referred to investigators.

October 7, 2026

Security

Jonathan Spalletta Convicted in Uranium Finance Theft Case Over $55 Million Exploit

Jonathan Spalletta convicted over $55M Uranium Finance exploits A Manhattan federal jury convicted cybersecurity consultant Jonathan Spalletta on computer fraud and money laundering charges tied to two April 2021 attacks on Uranium Finance that drained nearly $55 million and forced the platform to shut down. Prosecutors said authorities have seized about $31 million in crypto and collectibles linked to the thefts; sentencing is set for Feb. 16, and the money laundering count carries a maximum 20-year prison term.

Security

Ethereum Attacker Drains 200 ETH From Legacy MakerDAO Keeper Tied to 2020 Auctions

MakerDAO legacy contract drained for 200 ETH in Ethereum exploit An unknown attacker exploited a missing access-control check in a legacy MakerDAO auction keeper on Ethereum on Oct. 6, 2026, withdrawing 200 ETH worth about $543,000, CertiK said. The flaw let the attacker gain full control over the contract’s MakerDAO Vat account and settle four unfinished “Black Thursday” 2020 auctions. The stolen funds began moving to Tornado Cash within six minutes.

October 6, 2026

Security

Bitget Says Withdrawals Have Fully Reopened After $387.5 Million Hack

Bitget says withdrawals fully reopened after $387.5M hack Bitget CEO Gracy Chen said the exchange has fully resumed withdrawals after the Sept. 24 theft of about $387.5 million, which Chainalysis attributed to North Korean hackers. Chen said Bitget replenished its protection fund to above $300 million and has more than $1 billion in capital outside it, while investigators found no evidence of insider involvement so far and the exchange tightened approvals, reset credentials, and disabled the vulnerable third-party function.

Security

Immunefi says $6M Base vault hack revealed a bug disclosure blind spot

$6M Base vault exploit exposes bug disclosure gap, Immunefi says A still-unidentified Base vault lost about $6 million in wstETH after a malicious contract was added to its lending whitelist and withdrew assets without posting collateral, Immunefi security chief Gonçalo Magalhães said. He said roughly $31.7 million remained in the vault at the time of the briefing, while no operator had publicly claimed the vault or announced remediation more than 24 hours after the attack.

October 5, 2026

Security

Two crypto scams drained more than $472,000 through fake addresses and Permit2 abuse

Crypto users lose over $472,000 in address poisoning and Permit2 scams GoPlus Security said a user lost about $305,000 in DAI after copying a lookalike address from transaction history in an address poisoning attack, while Scam Sniffer reported a separate loss of $167,342 in LINK after a victim signed a phishing Permit2 approval on Ethereum. The cases highlight a simple risk: copied addresses and signed approvals can give attackers direct access to funds.

October 3, 2026

Security

September Crypto Hack Losses Reached $766.5M as Bitget and Liquid Drove Most of the Damage

September crypto hack losses hit $766.5M, led by Bitget and Liquid PeckShield counted 55 major crypto hacks in September with total losses of $766.49 million, up about 462% from August’s $136.3 million. Nearly all of that came from two breaches: Bitget lost about $387 million, while Liquid Network lost about $320 million, though $285 million was later returned. Excluding those two cases, the other 53 hacks totaled about $59 million.

Security

Microsoft X Account Breach Used to Promote Unauthorized Clippy-Themed Token

Microsoft’s X account hacked to promote fake Clippy token Hackers used Microsoft’s official X account to promote an unauthorized Clippy-themed token before the posts were removed about 30 minutes later. Microsoft confirmed the account was compromised, said it had secured access and was investigating, and denied any link between the token, Microsoft branding, or ownership rights in the company.

October 2, 2026

Security

Drift Opens DFX Claims With Initial Recovery Near 1 Cent Per Dollar Lost

Drift opens DFX claims at roughly 1 cent per dollar lost Drift Foundation, now called Velocity, has opened claims for victims of its April 1 exploit, but each DFX recovery token launched at about 0.0104 USDT, meaning roughly $1.04 back for every $100 lost. The rate is based on a 3.11 million USDT recovery pool against 299.5 million DFX, and can rise over time as Velocity revenue, pledged partner funds and any recovered assets are added; claims stay open until Jan. 1, 2028.

Security

FlashLoopAdapter flaw drains about $305,000 from two Safe wallets on Ethereum

FlashLoopAdapter exploit drains about $305,000 from two Safe wallets on Ethereum An access-control flaw in a custom FlashLoopAdapter built on top of Aave v3 let an attacker spoof Safe authentication and drain about $305,000 from two Safe wallets on Ethereum, SlowMist said. The attacker used a Morpho flash loan to repay roughly 1,335 WETH of Aave debt, then withdrew about 1,306 weETH plus 6.4 weETH, ending with around 114.1 ETH. Aave founder Stani Kulechov said the affected contract was a third-party adapter and had zero effect on Aave v3.

Security

Zano says attacker minted 36.9M unauthorized ZANO before month-long chain rollback

Zano rolls back blockchain after attacker minted 36.9M unauthorized ZANO Zano said an attacker exploited its Gateway Address bug on Aug. 29 and Sept. 25 to create 36.9 million ZANO and some fUSD, forcing the project to roll the chain back by about a month because the coins were indistinguishable from legitimate supply. The team said the exploit cost just 100 ZANO to set up, went unnoticed for nearly a month, and some of the minted coins entered the ecosystem. Zano said it will try to restore affected balances using its developer fund, team members’ personal funds and committed contributions, with recovery mainly handled through exchanges and payment services.

Security

Bitquery links TradeWiz drain wallet to earlier customer activity amid $459,000 loss

Bitquery links TradeWiz $459K drain to wallet used in 27 prior trades Bitquery said the wallet that collected about $459,000 drained from TradeWiz users had previously funded 27 trades through the same bot, creating a lead for investigators but not proving who controlled it or how keys were exposed. The firm estimated 20,933 wallets were affected; TradeWiz blamed private-key exposure tied to its SOL PVP export feature, paused EVM services, and said it had begun refunds.

Security

Core Lightning tells operators to upgrade after reports of attacks on older node versions

Core Lightning urges immediate upgrade for older node versions Core Lightning warned that attackers are targeting unpatched Bitcoin Lightning nodes and told operators running version 26.06.7 or earlier to upgrade immediately. The team did not disclose the specific vulnerabilities, but said version 26.06.8, released Sept. 22, includes fixes for responsibly reported flaws, including bugs that could crash sender nodes, exhaust REST interface memory, or trigger a channel-closing penalty that could cost users funds.

October 1, 2026

Security

Ostium Rebuilds Trading Stack With Gateway After $23.75 Million Vault Exploit

Ostium rolls out Gateway after $23.75M vault hack Ostium said Oct. 1 it is rebuilding its trading stack around Gateway, a new system promising sub-100 millisecond execution, unified margin and stronger infrastructure security, about three months after a $23.75 million theft from its OLP liquidity vault. Galaxy Research said the July attacker used a compromised oracle signer key and PriceUpKeep forwarder to push a false price report and repeatedly trade against it.

Security

MetaMask Exits Ethereum Validators After Infrastructure Breach Diverts 0.36 ETH

MetaMask starts validator exits after staking infrastructure compromise MetaMask began exiting Ethereum validators on Sept. 30 after a compromise apparently diverted about 0.36 ETH in block tips, while outside researchers estimated roughly 17,000 validators with about 523,000 ETH were pushed toward exit queues. MetaMask said wallets and customer funds show no signs of impact, but Lido expects the affected validators to finish exiting by Oct. 7 and says re-entry could take up to 45 days, leaving stake offline and not earning rewards.

Security

Drift opens DFX claims for April exploit victims with initial payouts around 1%

Drift opens DFX claims for April exploit victims Drift Foundation has opened DFX recovery claims and redemptions for wallets hit by its April 1 exploit, with about 3.11 million USDT currently in the pool. Eligible users receive 1 DFX per 1 USDT of verified losses, but the initial redemption rate is only about 0.0104 USDT per token, or roughly 1% of losses; redeemed DFX is burned. Claims close on Jan. 1, 2028.

Security

Zano details exploit that triggered 30-day rollback after $200M in illicit mints

Zano reveals bug behind 30-day chain rewind after $200M+ illicit mint Zano said a missing verification in its new Gateway Addresses let an attacker mint about 18.4 million ZANO in one transaction, repeat it, and do the same with fUSD, creating more than $200 million in illicit tokens. Because the first exploit went unnoticed for nearly a month and the coins blended into Zano’s privacy system, the project rolled the chain back to block 3,833,000 via Hard Fork 7 and disabled Gateway Addresses.

Security

NEAR Intents Exploit Drains About $3.8 Million, Service Pauses Across 11 Networks

NEAR Intents loses $3.8M in exploit, pauses deposits and withdrawals NEAR Intents said a bug in its Omni deposit and withdrawal infrastructure interaction with its smart contract led to about $3.8 million in losses, prompting a halt to deposits and withdrawals for about 12 more hours across 11 networks including BNB Chain, Polygon and Optimism. The team said it has patched the flaw, will fully reimburse affected users, and reported the incident to law enforcement.

Security

September Crypto Thefts Hit $766.49M as Bitget and Liquid Lead 2026 Losses

September sets 2026 crypto hack record at $766.5M Crypto hacks hit a 2026 monthly high in September, with $766.49 million stolen, up 462% from August, based on DeFi Llama data. The surge was driven mainly by the $387.5 million Bitget exploit and a $320 million Liquid Network hack, though about $285 million from Liquid was returned. CertiK counted 99 security incidents in the month, making September the peak of Q3.

Security

MetaMask Exits Lido Validators After Infrastructure Incident in Staking Unit

MetaMask exits Lido validators after infrastructure security incident MetaMask said it is responding to a security incident affecting part of its infrastructure and is proactively exiting Ethereum validators run by its non-custodial staking business, with no immediate threat identified to MetaMask wallets. In a Lido disclosure, MetaMask Staking said its final validators are expected to be exited by the end of October 7; no action is required from stETH holders, but rewards may be hit during the process.

Security

Bitget Restores Protection Fund Above $300 Million After Sept. 24 Breach

Bitget restores Protection Fund above $300M after $388M breach Bitget said it replenished its emergency Protection Fund to more than $300 million, five days ahead of its one-week deadline, after the Sept. 24 security incident that cost $388 million. The exchange said the fund covered the hit so user balances were unaffected, while withdrawals resumed from Sept. 28 and were set to be fully restored across all tokens, fiat, and P2P services by Oct. 2.

September 30, 2026

Security

SlowMist links Bitget hack to Aug. 31 zero-day in third-party security product

SlowMist says Bitget attackers exploited third-party security tools before theft SlowMist said it traced malicious activity tied to the Bitget hack back to Aug. 31, when attackers exploited a zero-day in a third-party security product and later moved through two security tools and a wallet host. Funds were stolen from Bitget hot wallets on Sept. 25 using a custom withdrawal tool that forged risk-control parameters and issued fraudulent withdrawal requests; Bitget CEO Gracy Chen said private keys and cold wallets were not compromised.

September 29, 2026

Security

Apple fixes CoreGraphics iPhone flaw as crypto security firms urge wallet users to update

Apple fixes exploited iPhone CoreGraphics flaw flagged in crypto security warning Apple released iOS 26.7.1 and iPadOS 26.7.1 to patch CVE-2026-86950, an out-of-bounds write in CoreGraphics that could allow arbitrary code execution via a malicious file. Apple said the bug may have been exploited against specific targets before iOS 27, while SlowMist separately urged crypto users to update affected devices over recent attacks aimed at sensitive wallet data; no public evidence links this CVE to wallet thefts.

Security

Liquid advances peg-out recovery with audit and key changes after September exploit

Liquid starts external audit as peg-out restart moves closer Liquid Network said an independent security audit of Elements v23.3.4 is now underway and the federation is replacing peg-out authorization key entries and securing related BTC receiving keys in cold storage, the latest steps toward restoring peg-outs after the Sept. 6 exploit. Withdrawals remain suspended with no restart date; the attack led to about 4,000 BTC leaving the federation reserve.

September 28, 2026

Security

Bitget Says $388 Million Hack Stemmed From Third-Party Product Vulnerabilities

Bitget says $388M hack came through third-party product vulnerability Bitget CEO Gracy Chen said the attacker behind last week’s $388 million theft exploited vulnerabilities in third-party products, stole internal credentials and sent fraudulent withdrawal commands that bypassed the exchange’s risk controls. Chen said no private keys or cold wallets were compromised, the incident has been contained, and withdrawals are resuming in phases from BTC on Monday to other tokens, fiat and P2P trades by Friday.

Security

D’CENT Wallet Hack Expands From XRP to Bitcoin, Ethereum, Tron and Stellar

D’CENT wallet hack spreads from XRP to Bitcoin and Ethereum Hackers have drained more than 12.4 million XRP from over 7,000 D’CENT wallets and also stole assets on Bitcoin, Ethereum, Tron and Stellar after compromising recovery phrases for the multi-chain wallet. IoTrust, D’CENT’s maker, said it has confirmed at least 110 abnormal transfer reports and is urging users who created wallets in its app to generate a new recovery phrase and move all assets immediately.

Security

MEXC Says $340K User Dispute Is Resolved After Alleged API-Based Account Theft

MEXC says $340K account theft dispute has been resolved MEXC said it has reached an agreement with user Shuang Fei over a reported theft of about $340,000 and considers the case “fully resolved,” without disclosing terms. The user had claimed 322,110 USDT and 9.13 million ONE were withdrawn on Sept. 27 after an attacker-created API allegedly remained usable following account recovery, despite MEXC documentation saying frozen accounts invalidate associated API keys.

Security

Bitget Restarts Bitcoin Withdrawals After $387.5 Million Security Breach

Bitget reopens BTC withdrawals after $387.5M hack Bitget resumed Bitcoin withdrawals at 08:00 UTC on Sept. 28, four days after suspending customer withdrawals following a hack that moved about $387.5 million to attacker-controlled addresses. The exchange said attackers exploited a third-party security product to obtain credentials and forge withdrawal commands, and that the vulnerability has been fixed with no further unauthorized transfers detected. ETH withdrawals are scheduled for Sept. 29 and USDT on Sept. 30, while Mandiant and SlowMist assist the investigation.

Security

Fake Giwa Layer-2 Chain Drains 766 ETH After Users Bridge Funds

Fake Giwa L2 scam drains 766 ETH from 1,335 users Threat actors launched a fake L2 chain impersonating Giwa and convinced users to bridge funds after DYORSWAP identified it as the project’s mainnet. About 766.25 ETH, worth more than $2 million, was drained from 1,335 addresses; Giwa later said it had not launched a mainnet, while DYORSWAP said it has begun reimbursing affected users and has already paid out more than 200 ETH from its own funds.

Security

Zano restarts chain at pre-Hard Fork 6 block after Gateway Addresses exploit

Zano rolls back blockchain by about a month after Gateway Addresses flaw Zano has restarted its blockchain at block 3,833,000, reversing roughly a month of history after a vulnerability tied to Gateway Addresses let unauthorized ZANO and Freedom Dollar enter circulation. The rollback wipes both the illicit tokens and legitimate transactions from that period, while payments already settled on other blockchains cannot be reversed; the team said nodes, miners, stakers, exchanges and other services must adopt the update and that a reimbursement and claims process is being prepared.

September 27, 2026

Security

Zano Restarts Blockchain Before Hard Fork 6, Erasing a Month of History After Inflation Bug

Zano restarts chain after inflation bug, erasing one month of history Zano said it has already restarted the blockchain from block height 3,833,000, just before Hard Fork 6, to contain an inflation bug tied to Gateway Addresses that enabled unauthorized issuance of ZANO and fUSD. The move wipes about a month of confirmed transactions; Zano said ordinary transaction privacy and wallet spend keys were not compromised, and Freedom Dollar said it absorbed several million dollars in losses from counterfeit fUSD.

Security

Japan arrests two suspects in 81 million yen fake police crypto fraud case

Japan arrests two over fake police crypto scam Japanese police arrested two suspects, aged 31 and 38, over a scheme that allegedly tricked a woman in her 40s into sending about 81 million yen ($515,000) in cryptocurrency after a caller posing as an Osaka Prefectural Police officer told her she had to “prove her innocence” in a supposed money-laundering case. Investigators say related cases tied to the suspects total about 240 million yen and believe the operation was run from Cambodia.

Security

Magic Eden warns legacy approvals left $5.7 million in NFTs exposed after contract exploit

Magic Eden warns legacy approvals exposed $5.7M in NFTs to exploit Magic Eden said old approvals from its now-closed EVM marketplace left more than $5.7 million worth of NFTs exposed to a vulnerability in Limit Break’s Payment Processor V2 after the contract was exploited this week. A whitehat operation rescued 23,155 NFTs, while Magic Eden said no active listings on its current products were affected and urged past EVM users to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base.

September 25, 2026

Security

Zano Prepares 24-Hour Rollback After Inflation Bug Linked to Gateway Addresses

Zano plans 24-hour blockchain rollback after inflation bug Privacy-focused blockchain Zano said an inflation bug tied to Gateway Addresses will force a rollback of roughly 24 hours of chain history, potentially wiping legitimate transactions along with unauthorized asset creation. The team told users on X and Telegram to stop activity involving ZANO and Confidential Assets and said it plans to reimburse losses, but it has not yet published the exploit details, rollback height, or the amount created.

Security

Three DeFi exploits hit Payy, Duelbits and Meter for over $11 million in one day

Three crypto exploits drain more than $11M in one day Payy Network, Duelbits and Meter were hit Thursday for a combined loss of more than $11 million. Payy said its Ethereum bridge was exploited for $1.8 million and paused all transactions, Duelbits’ co-founder confirmed an approximately $7 million hack and said the platform will stay offline during the investigation, while Meter said a block validation flaw let an attacker mint and dump $2.3 million in unbacked tokens.

Security

Cosmos Hub restart moves 1.23 million ATOM from Neutron exploiter wallet

Cosmos Hub validators seize 1.23M ATOM from Neutron exploiter wallet Cosmos Hub validators moved 1,227,121 ATOM, worth about $2.1 million, from the Neutron exploiter’s wallet when the network restarted Wednesday, executing the transfer at the state level without the owner’s signature after freezing the chain for nearly 25 hours. A 168,990 ATOM refund from a THORChain order escaped after the restart and was later bridged to Osmosis; the seized tokens now sit at cosmos1z8pq5c, an address with no known signer.

September 24, 2026

Security

DriveWealth Breach Exposed Historical Revolut Customer Data After Social Engineering Attack

DriveWealth breach exposed historical Revolut customer data DriveWealth, the US broker that previously handled Revolut’s US stock trading, said a social engineering attack on September 4-5 gave attackers unauthorized network access and exposed historical customer records from before Revolut changed its trading model. The data may include names, contact details, employment and biographical information, plus partial account numbers, while passwords, card and bank details, Revolut passcodes, and identity documents were not compromised.

Security

SlowMist Says FomoPeek iPhone App Carried Code to Target Wallet and Notes Data

FomoPeek iPhone app found with code to access wallet and Notes data SlowMist said official App Store releases of FomoPeek versions 1.1 and 1.2, marketed as a read-only crypto tracker, contained malicious modules that could be activated to target 19 wallet and note-taking apps. In a controlled test, the code collected and uploaded Apple Notes data, and a wallet linked to the attacker received 579,984.34 USDT across several networks, though investigators said that total is not a confirmed measure of funds stolen through the app.

September 23, 2026

Security

Attackers Drain About 11.7 Million XRP From 6,678 D’CENT App Wallets

$20M in XRP stolen from 6,678 D’CENT App Wallets Attackers drained about 11.7 million XRP from D’CENT App Wallet users in six waves between Sept. 15 and 20, with XRPL.to tracing the theft to valid signatures from already-compromised private keys rather than an XRP Ledger exploit. D’CENT confirmed abnormal transfers on Sept. 16, said hardware wallets were unaffected, and urged App Wallet users to move funds immediately.

Security

Cosmos Hub Restarts After Day-Long Halt Triggered by Neutron Governance Attack

Cosmos Hub resumes after 24-hour halt tied to Neutron governance attack Cosmos Hub validators restarted block production at 12:00 UTC Wednesday after halting the network for more than 24 hours in response to a governance attack on Neutron. The attack passed a malicious proposal that let the attacker drain $9.3 million from Astroport and Drop; Neutron was paused, while the Hub halt locked 1.2 million ATOM worth over $2.2 million in the attacker’s address for refund on restart.

Security

Binance to shift ZIL to Zilliqa EVM as legacy network is phased out

Binance to migrate ZIL to Zilliqa EVM after Ledger-linked security breach Binance will move ZIL on its platform from Zilliqa’s legacy mainnet to Zilliqa EVM at a 1:1 ratio, handling the migration for users as Zilliqa retires its old transaction system after a Ledger app flaw exposed 6,772 accounts. Zilliqa said at least 683.13 million ZIL was stolen, while ZIL trading on Binance will remain unaffected and future deposits and withdrawals will run on the EVM network.

Security

D'CENT investigates app wallet flaw after trackers link XRP losses to thousands of addresses

D'CENT probes app wallet transfers as trackers flag up to 9.3M XRP drained South Korean wallet maker D'CENT said it is investigating unauthorized transfers from its mobile App Wallet after on-chain trackers linked the incident to thousands of XRP Ledger addresses. The company said users may be affected if they used app versions earlier than 8.1.0, while XRPL.to tracked 2 million XRP leaving 1,552 wallets in two hours and XRPL Intel later estimated losses at 9.3 million XRP across 6,160 addresses, figures D'CENT has not confirmed.

September 22, 2026

Security

Dutch police arrest two in alleged fake EURC Rolex scam

Dutch police arrest two men over fake EURC Rolex purchases Dutch police arrested two men, 24 and 45, in an investigation into alleged crypto fraud after Marktplaats sellers reported handing over Rolex watches in exchange for counterfeit EURC tokens. Police said the fake tokens looked identical to genuine EURC at first glance; one suspect remains detained for 14 days, while investigators review seized data-storage devices for links to other cases.