Security news

Showing 51–100 of 170
Clear filters

August 12, 2026

Security

Boltz founders step down as unnamed Bitcoin group moves to take over suspended swap service

Boltz founders exit as veteran Bitcoiners take over suspended swap service Boltz said all original founders stepped down effective immediately and an unnamed group of “veteran Bitcoiners” will take over the suspended Bitcoin swap service, providing capital and engineering resources while vulnerabilities are fixed. Swaps remain offline after Aug. 3 attacks that Boltz said grew in frequency and sophistication and caused losses, though it added user funds were never at risk because the service is non-custodial.

Security

Malwarebytes Finds $500 Fake Tesla Token Presale Kit Built to Drain Crypto Wallets

Malwarebytes spots $500 kit for fake Tesla token presale scam Malwarebytes said a cybercrime forum seller known as xrep is offering a $500 “scam-in-a-box” that lets low-skill operators launch a fake $TSLA presale using Tesla branding and X account details. The kit includes phishing pages, a fake dashboard and a control panel that can collect 12-word recovery phrases, log usernames and locations, and prompt victims to send BTC, ETH, USDT or DOGE to attacker-controlled addresses.

Security

Ledger Executive Says Coldcard Breach Exposed Weak Randomness, Not Hardware Wallets

Ledger exec says Coldcard hack shows weak randomness, not hardware wallet risk Ledger’s Chief Human Agency Officer Ian Rogers told Bloomberg the $116 million Coldcard hack was caused by a 2021 firmware bug that sent seed generation through a software pseudorandom number generator instead of the hardware chip, leaving just 40 to 72 bits of entropy for attackers to brute-force. TRM Labs traced 1,082 BTC drained in the first 41-minute sweep on July 30; Rogers said AI is accelerating this kind of exploit and broader attacks on secrets and code.

Security

Ravencoin Hits Record Low as Consensus Flaw Forces Competing Chain Response

Ravencoin drops to record low after consensus exploit hits mainnet RVN fell as much as 22% to $0.002754 after a consensus vulnerability let vulnerable Ravencoin nodes accept invalid blocks from block 4,487,776. Mining pools 2Miners and RavenMiner are building a competing chain that would exclude blocks after 4,487,775, a move that could force a roughly three-day reorganization and reverse later transactions. Upbit and Bitget suspended RVN deposits and withdrawals, while Upbit kept trading open.

August 11, 2026

Security

Coreum Bridge Exploit Drains 199,916 XRP After Deposit Check Failure

Coreum bridge exploit drains 199,916 XRP in 97 minutes Coreum’s cross-chain bridge lost 199,916 XRP on Aug. 9 after an attacker exploited a deposit verification flaw to trigger withdrawals without making real deposits. XRPL.io shows the bridge sent 94 XRP payments approved by 17 of 28 relayer keys, with the funds moved to two newly created wallets, leaving the bridge with 493.5 XRP.

Security

Address Poisoning Scam Sends $100K in USDT to Lookalike Wallet

User loses $100K in USDT to address poisoning scam A crypto user sent about 100,000 USDT to a lookalike wallet address that an attacker had planted in the victim’s transaction history 66 days earlier, Cyvers Alerts said on Aug. 11. Cyvers said the attacker later swapped the stolen funds for about 52.8 ETH, in what it described as a social-engineering attack that relied on the victim selecting a forged address from history rather than a flaw in Tether, Ethereum, or the wallet software.

Security

Coldcard hack loss estimates range from 1,432 BTC floor to about 1,816 BTC

Coldcard hack loss estimate ranges from 1,432 BTC to about 1,816 BTC Investigators still have no definitive loss figure for the Coldcard hack, with estimates diverging because the theft hit self-custody wallets and relies on victim reports plus on-chain tracing. CryptoQuant has confirmed 1,432 BTC as a floor, while Galaxy Research puts its high-confidence minimum at 1,730 BTC and TRM Labs estimates about 1,816 BTC from more than 5,200 addresses, saying the total could keep rising as more victims come forward.

Security

Coreum XRPL Bridge Lost 199,916 XRP in Suspected Relayer Logic Exploit

Coreum XRPL bridge drained of nearly 200,000 XRP in relayer logic exploit On-chain analysis says 199,916.3 XRP was drained from Coreum’s XRPL bridge on Aug. 9 after relayers treated attacker self-payments with bridge memos as valid deposits and signed 94 withdrawals over 97 minutes. The evidence points to a destination-check flaw in relayer code, not stolen keys or an XRP Ledger failure; the bridge remains halted and Coreum had not published an official incident report by Aug. 11.

Security

BTCPay supporters offer up to 3 BTC bounty after Lightning wallet exploit

BTCPay backers offer up to 3 BTC bounty after Lightning wallet exploit BTCPay Server supporters pledged a bounty worth 10% of any recovered stolen funds, capped at 3 BTC, after a critical flaw in versions before 2.4.2 was actively exploited. BTCPay said attackers could steal LND admin macaroon credentials and take control of connected Lightning wallets, while onchain wallets were not affected, and urged users to upgrade to 2.4.2 or shut down servers and rotate credentials.

August 10, 2026

Security

Crypto Projects Lost About $110M in July as 2026 Hack Count Nears Record Pace

Immunefi says 2026 is on pace for a record year of major crypto hacks Crypto projects lost about $110 million to hacks in July, and Immunefi said 2026 could surpass 2024’s record for major incidents. The platform has logged 164 hacks through Aug. 3, including 67 losses above $1 million, and projects that figure could reach 114 by year-end versus the previous record of 72. Immunefi also said audit competitions found 6.2 serious flaws per engagement on average, compared with 1.5 in private tier-1 audits.

Security

Coinsbuy Wallets Reportedly Drained of $7.9 Million Across Ethereum and Tron

Coinsbuy reports $7.9M theft from Ethereum and Tron wallets Wallets linked to crypto payments platform Coinsbuy were reportedly drained of more than $7.9 million across Ethereum and Tron at around 13:00 UTC, in an incident first flagged by blockchain investigator Specter Analyst. Coinsbuy briefly paused deposits and withdrawals, then resumed services; the attacker was reportedly moving funds through exchanges into Monero, while ChangeNOW froze a six-figure amount tied to the theft.

August 9, 2026

Security

Crypto Thefts Reached $3.4 Billion in 2025 as Investigators Face a 45-Day Recovery Window

Crypto theft hit $3.4B in 2025, topped $1B again in H1 2026 Hackers stole about $3.4 billion in crypto in 2025 and another $1.1 billion across 212 incidents in the first half of 2026, with Lazarus-linked groups blamed for roughly 55% of this year’s losses. Investigators have about 45 days before laundering through DeFi, mixers, bridges and low-KYC venues makes recovery unlikely; less than 5% of the $1.5 billion Bybit hack was recovered.

Security

BTCPay blocks remote LND access on Docker after credential theft attacks

BTCPay restricts remote LND access after critical credential theft flaw BTCPay Server has temporarily blocked public remote connections to LND nodes on Docker deployments after attackers exploited a critical flaw to steal macaroon credentials and move funds. Version 2.4.2 installs LND 0.21.1 and auto-rotates credentials on standard setups, but operators using their own reverse proxy, Tor service or port forwarding must rotate them separately; Foundation and Citadel21 both reported drained Lightning nodes.

August 8, 2026

Security

BTCPay Server issues emergency fix for exploited 2FA bypass in merchant payment software

BTCPay Server ships emergency patch for exploited 2FA bypass bug BTCPay Server has released v2.4.2 after disclosing a critical vulnerability under active exploitation that let attackers bypass TOTP two-factor authentication via Greenfield API Basic Authentication. The flaw affected BTCPay’s application layer, not Bitcoin, and BTCPay urged operators to upgrade immediately, update NBXplorer to v2.6.10, and use scoped API keys instead of Basic Authentication.

August 7, 2026

Security

HTX Reserve Funds Were Moved to Poloniex-Labeled Wallets After Sanctions, Report Says

HTX reserves moved to Poloniex-labeled wallets after sanctions, report says After EU and UK sanctions on HTX, TRM Labs said the exchange began rapidly rotating on-chain addresses and shifted $1.3 billion in reserves into an undisclosed “ThirdParty” category in its proof-of-reserves. Protos traced 71,853.22 stETH, about $135 million, from HTX’s May 1 reserve address through several wallets on May 30 to addresses labeled on Etherscan as Poloniex, suggesting HTX funds were commingled with Poloniex reserves.

Security

Trezor Flags Sponsored Google Phishing Results After User Reports Major Loss

Trezor warns of phishing sites in sponsored Google results Trezor said on Aug. 7 it is seeing more phishing websites impersonating the company, including some appearing in sponsored Google search results, after X user David (@ReallyBadDay99) claimed he lost his “life savings” by clicking a top sponsored result for “Trezor wallet.” Trezor did not confirm the loss, but warned users never to enter a wallet backup on any website and to verify they are on its official site.

Security

BTCPay Server urges immediate update to v2.4.2 over actively exploited flaw

BTCPay Server urges emergency update to v2.4.2 over active exploit BTCPay Server told users to install version 2.4.2 immediately after finding a critical vulnerability that is already being actively exploited and could lead to stolen funds. The project said operators who cannot update right away should shut down their servers, but it has not disclosed which earlier versions are affected, how the attacks work, or whether losses have been confirmed.

Security

Coldcard Exploit Drives July Crypto Theft Losses to $247.4 Million

July crypto thefts hit $247.4M, second-worst month of 2026 Crypto thefts jumped to $247.4 million in July, more than triple June’s $75 million, making it the second-worst month of 2026 after April’s $644 million, DefiLlama data shows. The biggest hit was the Coldcard exploit, which stole at least $100 million in Bitcoin from 7,300 wallets across three confirmed attack waves, while Galaxy Digital said a suspected fourth wave could push losses to about $130 million.

Security

Researchers Link North Korean Recruitment Malware Campaign to 1,640 Organizations

North Korean hackers hit 1,640 organizations in 57 countries, researchers say Cybersecurity researchers say North Korean operators compromised 1,640 organizations across 57 countries via fake software developer recruitment campaigns, with crypto firms a consistent target. Kumio CTO Vangelis Stykas, who tracked the infrastructure for 22 months, said attackers used malware hidden in coding tests to steal admin access, cloud permissions and wallet credentials, often exploiting contractors with access to multiple companies.

Security

Sui Plans NIST-Approved Post-Quantum Signatures for Accounts and Smart Contract Vaults

Sui to add NIST-approved quantum-resistant signatures Sui said it will integrate two NIST-approved post-quantum signature schemes: ML-DSA-65 for standard accounts and SLH-DSA-SHA2-128s for high-value assets in smart contracts, aiming to reduce the risk that future quantum computers could break today’s on-chain cryptography. Users will be able to migrate with existing recovery phrases, and the feature won’t change consensus or require immediate app updates; vaults are due on mainnet this year, while ML-DSA-65 accounts are targeted for testnet by end-2026 and mainnet in Q1 2027.

August 6, 2026

Security

Chainalysis Says Violent Crypto Thefts Reached $30 Million in First Half of 2026

Chainalysis: violent crypto thefts hit $30M in H1 2026 Violent attacks on crypto holders stole an estimated $30 million in the first half of 2026 alone, putting the year on pace to top 2025’s record $58 million, Chainalysis said. France has driven much of the surge with 30 known incidents by midyear, and investigators linked the spike to a 2024 tax-data leak and a separate Waltio breach affecting about 50,000 users.

Security

Hong Kong police say Fun Coffee crypto scam reports hit 255 and losses reach HK$104 million

Hong Kong losses in alleged Fun Coffee crypto scam reach HK$104 million Hong Kong police said 255 reports have now been filed over the alleged Fun Coffee GCM crypto investment scam, with reported losses rising to about HK$104 million. Investigators say the platform promised 197% to 278% annual returns on USDT deposits before withdrawals stopped and the app went offline on July 20, 2026; six people have been arrested in Hong Kong and two more were detained in Macau as the probe widens.

Security

ZEUS Takes Lightning Infrastructure Offline After Security Incident

ZEUS halts Lightning wallet services after cyber incident ZEUS took its Lightning wallet infrastructure offline on Aug. 5 after a cybersecurity incident, saying the attack was contained and no customer funds were lost or at risk. The outage makes ZEUS the third major Lightning-related service to suspend key operations in about 72 hours after disruptions at Boltz and AQUA, raising concerns around infrastructure providers rather than the Lightning Network itself.

August 5, 2026

August 4, 2026

Security

Boltz Halts Bitcoin Swaps as AI-Assisted Attacks Outpace Security Fixes

Boltz suspends Bitcoin swaps after surge in AI-assisted attacks Boltz has disabled its non-custodial Bitcoin swap service until further notice, saying automated AI-assisted attacks are now finding and exploiting vulnerabilities faster than its team can patch them. The company said no user funds were at risk, cannot give an ETA for a return, and added that its API remains available for cooperative refunds while unilateral refunds still work independently of Boltz infrastructure.

Security

Ledger: Coldcard Exploit Shows Wallet Security Must Keep Up With AI-Era Threats

Ledger says Coldcard exploit highlights hardware RNG and AI risks in wallets Ledger CTO Charles Guillemet said the Coldcard exploit showed how hardware wallet security can fail when seed generation falls back to software randomness: the flaw made some private keys guessable and enabled theft. He said Ledger devices were unaffected because they use a certified hardware RNG in a Secure Element with no software fallback, and argued AI is speeding up vulnerability discovery, making independently certified randomness more critical.

Security

Hong Kong Police Report $9M in Romance Crypto Scams as Malaysia Event Loses Backing

Hong Kong police flag $9M in romance-linked crypto scams in one week Hong Kong police recorded 25 romance scam cases between July 24 and July 30 that cost victims a combined $9 million, including one insurance agent who lost $3.3 million after a fake online boyfriend pushed her into a fraudulent crypto app. The scams typically start on dating or messaging apps, show fake profits, and unravel when victims try to withdraw funds.

Security

Boltz suspends Bitcoin swaps as AI-assisted attacks outpace its security fixes

Boltz halts Bitcoin swap service over AI-assisted hacking attempts Boltz said it is disabling its non-custodial Bitcoin swap service until further notice after a steady rise in automated AI-assisted probing and several contained exploits this year. The team said attackers are now iterating faster than it can find and patch vulnerabilities, and recent security scans showed it could not “responsibly” restart swaps while multiple groups appear to be actively targeting its infrastructure. No user funds were at risk, and the API will stay live for refunds.

August 3, 2026

Security

Boltz Suspends Bitcoin, Lightning and Liquid Swaps After Citing AI-Assisted Attacks

Boltz suspends Bitcoin, Lightning and Liquid swaps after AI-assisted attacks Boltz shut down its non-custodial swap service on Monday until further notice, saying months of automated, AI-assisted probing and several exploits have outpaced the team’s ability to patch its infrastructure. The halt cuts off swap rails used by wallets including Bull Bitcoin and Aqua; Boltz said no user funds were ever at risk and losses were borne by the company, while its API remains online for cooperative refunds on in-flight swaps.

Security

Hong Kong insurance agent loses HK$26 million in romance-linked crypto investment scam

Hong Kong agent loses HK$26 million in romance-linked crypto scam A Hong Kong insurance agent lost more than HK$26 million after scammers used an online romance over about six months to steer him into a fake crypto platform, police said. The victim handed over more than HK$4 million in cash and transferred nearly HK$22 million before suspecting fraud when the app showed 800% returns and blocked withdrawals. Between July 24 and July 30, police logged 25 similar reports with nearly HK$70 million in losses.

Security

Crypto Exploits Reached Record $1.1 Billion in First Half, Blockaid Says

Crypto exploits hit record $1.1B in H1, with North Korea-linked groups blamed for 55% Hackers stole a record $1.1 billion from crypto protocols in 212 onchain exploits in the first half of the year, Blockaid said, with North Korea-linked groups tied to $609 million, or 55% of losses. Ethereum and Solana saw the biggest network losses at about $332 million and $326 million, while operational security failures, including privileged key misuse, drove roughly $790 million in damages.

Security

South Korean Police Arrest Three in Alleged $9 Million Fake XRP Staking Fraud

South Korea arrests 3 in alleged fake XRP staking fraud South Korean police arrested three suspects linked to alleged fake XRP staking site Fxrpntwork.com, which reportedly took 3.4 million XRP, worth about $9 million, from 71 investors. Authorities said they also froze 17.3 billion won in digital assets on overseas exchanges. The case remains under investigation, and the arrests do not amount to convictions.

Security

xrpld 3.2.1 Stays Current as 3.3.0 Milestone Builds Broader XRPL Changes

xrpld 3.2.1 ships security fix as 3.3.0 queues broader XRPL changes xrpld 3.2.1 remains the latest XRP Ledger release as of Aug. 1, 2026, focusing on validator security by fixing manifest propagation issues and reducing risks from untrusted peer messages. The unreleased 3.3.0 milestone lists 122 items, including BatchV1_1 for grouped transactions with corrected inner-signature validation, while ConfidentialTransfer and Sponsored Fees remain in development and inactive.

August 2, 2026

Security

Ukraine Police Allege Fake Crypto Academy Defrauded Nearly 1,000 People of $1.1 Million

Ukraine police say fake crypto academy stole $1.1M from nearly 1,000 people Ukraine’s National Police said it dismantled a criminal group that posed as a crypto investing school and defrauded nearly 1,000 victims of more than $1.1 million. Investigators say people were persuaded to send money to controlled crypto wallets and a fake investment platform; suspects face up to 12 years in prison with confiscation of property.

August 1, 2026

Security

Blockaid Says Crypto Exploits Reached $1.1 Billion Across 212 Incidents in H1 2026

Blockaid: Crypto exploits hit record $1.1B in H1 2026 Hackers stole $1.1 billion across 212 crypto incidents in the first half of 2026, making it the most active six-month period on record, Blockaid said. KelpDAO’s $292 million loss and Drift’s $285 million exploit drove much of the damage, and Blockaid linked both, along with Humanity Protocol’s $32 million loss, to TraderTraitor, a North Korean subset of Lazarus, putting DPRK-linked thefts at $609 million, or 55% of the total.

Security

Hong Kong Reports HK$70 Million in One Week of Romance-Linked Crypto Investment Scams

Hong Kong logs HK$70M in romance-linked crypto investment scams in one week Hong Kong police recorded 25 investment fraud cases tied to online romantic relationships in the week ending July 30, with combined losses nearing HK$70 million ($9 million). The biggest case involved a 50-year-old insurance professional who reportedly lost about HK$26 million ($3.3 million) after an online partner posing as a car dealer steered her to a fake virtual asset platform that showed fabricated gains before blocking withdrawals.

Security

trade.xyz begins payouts after SK hynix price shock triggered Hyperliquid liquidations

trade.xyz starts refunds after SK Hynix perp crash on Hyperliquid trade.xyz said Aug. 1 it has begun reimbursing traders after an anomalous SK hynix pre-market print in South Korea pushed its Hyperliquid perpetual mark price down 18.7% on July 27, triggering roughly $60 million in long liquidations across about 960 accounts. Losses under $10,000 are being refunded automatically, while larger claims require an application; trade.xyz called the payouts a one-time discretionary decision.

July 31, 2026

Security

SecondFi Renews Bounty as It Pursues Recovery After 16.1M ADA Exploit

SecondFi renews bounty after 16.1M ADA exploit SecondFi has renewed its bounty offer to recover 16.1 million ADA stolen in a June exploit that affected 374 wallets. The team said the breach stemmed from a key-generation vulnerability and that it secured 129 million ADA during containment, but confirmed normal operations will not resume. Groom Lake researchers reportedly saw behavior resembling Lazarus Group techniques, though attribution remains unconfirmed.

Security

Swan Treasury loses about $625,000 after signer key leak on BNB Chain

Swan Treasury loses $625,000 after signer key compromise on BNB Chain Attackers used a leaked off-chain signer key to forge valid signatures and buy about 687,000 STY at roughly a 100x discount on BNB Chain, then sold the tokens for an estimated $625,000 profit, Defimon Alerts said. The firm said the exploit stemmed from the protocol’s compromised hardcoded signer key, not a flaw in its signature verification logic.

Security

AFX to release Aug. 3 user goodwill plan after $24.15M bridge exploit

AFX to unveil user recovery plan after $24.15M bridge exploit AFX said it has prepared a goodwill plan for users hit by last week’s $24.15 million bridge exploit and will release the proposal on Aug. 3. Its post-mortem blamed a supply-chain attack that began with social engineering against a developer and ended with validators co-signing a bridge transaction that drained about $24.15 million USDC; Arbitrum’s native bridge and network were not affected.

Security

Coinkite warns Coldcard Mk3 users after reports of 594 BTC moving from dormant wallets

Coinkite warns some Coldcard Mk3 wallets may be at risk Coinkite issued a security advisory for Coldcard Mk3 users after reports that about 594 BTC, worth roughly $38 million, moved from around 500 long-dormant single-signature wallets on July 30. The company said anyone who generated a seed on Mk3 firmware 4.0.1 through 5.0.3 may be affected, while Mk4, Q and Mk5 appear unaffected; it has not confirmed a root cause or a direct link to the transfers.

July 30, 2026

Security

South Korea Arrests Three Over Fake FXRP Platform That Took $8.6M in XRP

South Korea arrests suspects in fake FXRP scam targeting XRP holders South Korean authorities arrested three men over a fake FXRP investment platform that collected about 3.4 million XRP, worth roughly $8.6 million, from 71 victims before vanishing after just over a week. Police said the probe began after an overseas exchange flagged suspicious transactions, and investigators froze about $12.1 million on foreign exchanges within three days; two suspected organizers face aggravated fraud charges, while another suspect remains overseas under an international alert.

Security

Zcash Developers Say ZEC Supply Can Be Verified Locally Ahead of Ironwood

Zcash says ZEC supply can already be verified locally Zcash developers said users do not need to wait for the Ironwood migration from Orchard to confirm the coin’s supply, after questions over an Orchard vulnerability and possible hidden inflation. Co-founder Zooko said anyone running a fully synced node can verify the current supply of 16,848,458 ZEC locally, while Ironwood will cap Orchard withdrawals through a turnstile that records each withdrawal against prior deposits.

Security

Ostium says off-chain breach, not smart contract flaw, caused $23.75M USDC exploit

Ostium says July exploit came from off-chain breach, not smart contracts Ostium said its July exploit was caused by compromised off-chain infrastructure that let an attacker manipulate price reports and drain 23.75 million USDC from the OLP liquidity vault, not by a flaw in its smart contracts or governance multisigs. The team said a 100 USDC test trade generated about 897.8 USDC in fake profit before larger exploit cycles followed; trading resumed on July 23 after a migration to a new production environment.

July 29, 2026

Security

MCBS healthcare vendor breach may have exposed data of 1.26 million Americans

MCBS breach may have exposed data on 1.26 million Americans Medical Computer Business Services, a third-party vendor for hospitals and medical practices, said hackers accessed its network between Sept. 22 and Sept. 26, 2025, potentially compromising the personal and medical data of 1,261,464 people. The incident is listed by the U.S. Department of Health and Human Services as a hacking/IT breach, and MCBS says it notified affected individuals and is offering identity protection services.

Security

CFA Puts Estimated US Crypto Scam Losses at $80.7 Billion in 2025

CFA estimates US crypto scam losses hit $80.7B in 2025 The Consumer Federation of America said Americans lost an estimated $80.7 billion to crypto scams in 2025, versus $11.37 billion reported to the FBI, by applying a 7.1x multiplier based on a 2017 survey that found only 14% of fraud victims report cases to law enforcement. Crypto made up more than half of all scam and cybercrime losses, with investment fraud the biggest category at an estimated $61.4 billion.

Security

Blockaid says crypto losses hit $1.1B in H1 2026 as key compromises dominate

Blockaid: Crypto hacks hit $1.1B in H1 2026 as key compromises overtake code bugs Verified on-chain crypto security losses reached $1.1 billion across 212 incidents in H1 2026, Blockaid said in a July 28 report, with 74% of losses tied to compromised devices, private keys, signing systems and other off-chain infrastructure rather than smart-contract flaws. One DPRK-linked cluster accounted for about 55% of losses, while the incident count was 3.4x all of 2025.

July 28, 2026

Security

SparkKitty malware removed from App Store and Google Play after targeting wallet seed photos

SparkKitty malware found in App Store and Google Play apps Researchers say SparkKitty targeted crypto users on iOS and Android by abusing photo library access to scan images for 12-word and 24-word wallet recovery phrases with OCR, then sending the data to attacker-controlled servers. Apple and Google removed infected apps, including SOEX and other coin-related apps, after some drew thousands of downloads.

Security

Ukraine Police Say Fake Crypto Academy Defrauded 988 People of $1.11 Million

Ukraine police detain four in fake crypto academy fraud case Ukraine’s National Police said it dismantled a criminal group that allegedly posed as the “Ukrainian Financial Academy” and defrauded 988 people of about $1.11 million through controlled bank accounts, crypto wallets and a fake investment platform. Investigators detained four key suspects after searches in the Kharkiv and Dnipropetrovsk regions; they are in pretrial detention and face up to 12 years in prison with confiscation of property if convicted.

Security

CertiK says crypto wrench attacks rose 33% in H1 2026, with France at the center

Crypto wrench attacks jump 33% in H1 2026, with France the main hotspot CertiK recorded 52 wrench attacks in the first half of 2026, up 33.3% from a year earlier, while associated financial exposure surged to $124.18 million from about $10.5 million. France accounted for 33 of the 52 cases, which CertiK linked to the country’s visible crypto ecosystem and recent data breaches that may help criminals identify targets.