Security news

Showing 51–100 of 341
Clear filters

September 21, 2026

Security

Immunefi CEO says Liquid attackers lost white-hat standing by keeping 598.5 BTC

Immunefi CEO says Liquid attackers lost any white-hat claim Immunefi founder and CEO Mitchell Amador said the Liquid Network attackers gave up any white-hat status by keeping 598.5 BTC after returning 3,400 BTC from the roughly 4,000 BTC exploit. He said moving user funds without permission and then setting bounty terms ends coordinated disclosure, while Blockstream has rejected the group’s 10% bounty demand and called the remaining holdback theft.

Security

Z.ai open-sources ZCode after unauthorized repository uploads came to light

Z.ai open-sources ZCode after unauthorized file uploads exposed Z.ai has open-sourced its ZCode coding assistant after apologizing for a flaw that quietly sent developers’ local project files to Alibaba Cloud without permission. The issue, uncovered on Sept. 18 by blogger Ferstar, involved an encrypted 313 MB archive of a commercial project, including Git history; Z.ai says the uploads have stopped and any uploaded data was deleted and not used to train models.

Security

Kasplex Indexer Flaw Lets Attacker Drain ZEAL and NACHO Bridge Backing

Kasplex indexer flaw lets attacker drain ZEAL and NACHO bridge backing An attacker used five valid Kaspa transactions to trick the off-chain Kasplex KRC-20 indexer into crediting unsigned transfers, pulling 186.4 million ZEAL and 54.4 billion NACHO from a bridge custody wallet and dumping the minted L2 tokens into Zealous Swap pools. Kaspa’s base chain was not hacked, but affected pools lost 94% to 99.6% of their KAS-side value and Igra paused iKAS exits and Hyperlane transfers while operators prepare a patch and reindex.

Security

Upbit places MultiversX’s EGLD under review after mainnet exploit attempt

Upbit puts MultiversX’s EGLD under trading caution after mainnet exploit attempt Upbit placed EGLD/KRW, EGLD/BTC and EGLD/USDT under a trading caution designation on Sept. 21 after MultiversX confirmed an attempted VM-level atomicity exploit that caused invalid state changes and halted network progression. EGLD deposits and withdrawals remain suspended, and Upbit said it will review the token through Oct. 19-23 before deciding whether to lift the warning, extend it or end trading support.

Security

North Korean WaterPlum malware campaign hit 30,000 devices and stole $10.7 million

North Korean group WaterPlum hit 30,000 devices in fake crypto job scam North Korean cyber group WaterPlum, also known as Contagious Interview, posed as recruiters for crypto, AI and NFT firms and infected at least 30,000 devices across more than 100 countries, stealing at least $10.7 million, authorities said. Victims were told to run malware disguised as coding tests or video-call fixes, enabling theft from more than 7,000 crypto wallets between December 2025 and July 2026 and giving attackers access that could also compromise employers.

September 20, 2026

Security

Fetch.ai and NuNet incidents tied to compromised credentials cost about $2 million

Fetch.ai and NuNet linked to $2M exploit tied to compromised credentials Security firms linked a roughly $2 million exploit across Fetch.ai and NuNet to the same attacker wallet, with 8.7 million FET drained and 408.5 million NTX unauthorizedly minted. Fetch.ai said preliminary analysis points to compromised signing credentials; it later said no Fetch.ai contracts were at risk, while AGIX-to-FET conversions were paused as a precaution. The NTX mint sent the token down about 95% in 24 hours.

Security

French Family Bound in Home Invasion as Attackers Force €40,000 Crypto Transfer

Armed gang forces €40,000 crypto transfer in French home invasion Four masked men armed with a knife and an iron bar broke into a family home in Vendin-le-Vieil at 4 a.m., tied up the parents and two children with black tape, and forced the father to hand over account codes and login details, leading to a transfer of about €40,000 in cryptocurrency. Investigators said the attackers stayed on the phone with a remote coordinator throughout the raid, suggesting an organized operation.

Security

French Police Seek Four After Family Tied Up in Crypto-Linked Home Robbery

French police hunt four after crypto worker’s family tied up in home robbery Four suspects are being sought after a French crypto worker, his wife and their two children, aged 8 and 12, were restrained for more than three hours during a night-time home invasion in Vendin-le-Vieil. Investigators believe the attackers targeted the father over his work in cryptocurrency, forced him to hand over access codes and stole about €40,000 in crypto before fleeing; BFMTV reported he alerted emergency services around 8 a.m.

September 18, 2026

Security

Zimperium Report Says RatHat Android Malware Uses AI to Hijack Phones and Steal Logins

Zimperium details RatHat Android malware using AI to hijack phones Zimperium’s zLabs said a newly identified Android malware strain, RatHat, uses AI to control infected phones in real time, steal banking and crypto app logins, and intercept SMS one-time codes. The malware is spread via smishing and malvertising outside Google Play, abuses Accessibility permissions to enable Wireless Debugging and pair with the device’s own ADB service, and can monitor touch input to reconstruct PINs and passwords.

Security

IOG warns Cardano users to avoid YouTube channel after suspected takeover

IOG warns Cardano users off YouTube channel after suspected takeover Input Output Group told users on Sept. 18 not to interact with its YouTube channel after an apparent hijack aired a fake Charles Hoskinson giveaway livestream styled as a Project Catalyst event. IOG said users should not follow links, send crypto or share personal data until it confirms the channel is safe again; at the time of review, it had not explained the breach or confirmed recovery.

Security

Nostra Halts Starknet Money Market After Oracle Manipulation Attack

Nostra pauses Starknet money market after oracle manipulation exploit Starknet lending protocol Nostra halted lending, borrowing, withdrawals and liquidations on Thursday after a manipulated price oracle let one account borrow about $3.5 million against NSTR collateral. PeckShield said $1.92 million was bridged to Ethereum, while Nostra said final losses and potential recoveries are still unknown as it reconciles each asset and traces the funds.

Security

Chainalysis links North Korea and Iran to most of this year’s onchain malware surge

Chainalysis says North Korea and Iran drove most of a 420% jump in onchain malware State-linked hackers were behind about two-thirds of new cases where malware instructions or infrastructure data were stored on public blockchains, Chainalysis said. The firm linked previously unattributed activity across Tron, Aptos and BNB Smart Chain to UNC5342, a North Korea-linked group, warning that blockchain storage makes campaigns harder to disrupt because the data can stay accessible after takedowns.

September 17, 2026

Security

Revolut says no direct ransom demand followed breach affecting about 680 European clients

Revolut says it got no direct ransom demand after client data breach Revolut said it has not received any direct contact from hackers after a breach exposed data from about 680 European clients, pushing back on reports of a 6,000 XMR, roughly $3 million, ransom demand. The company said attackers used months of social engineering while posing as government authorities to obtain verification files, identity documents and transaction records; customer funds and internal systems were not affected.

Security

Chainalysis reports 420% jump in malware activity using blockchains as infrastructure

Chainalysis says state-linked hackers are increasingly using blockchains as malware infrastructure Malicious blockchain writes rose 420% over the past 12 months, with state-linked hackers making up roughly two-thirds of new activity each quarter, Chainalysis said. The firm said North Korea-linked operators used Tron, Aptos and BNB Chain to route infected devices to encrypted server details, while suspected Iran-linked actors hid command-and-control directions in Bitcoin transactions.

Security

Trader says fake Cloudflare check led to about $600,000 crypto loss

Trader cladzsol says fake Cloudflare check led to $600,000 loss Crypto trader cladzsol said he lost about $600,000 after malware infected his computer through a fake Cloudflare verification, though he said he managed to save roughly $400,000. Screenshots shared by Inside Calls show the site told him to press Win + R, paste a pre-copied command, and hit Enter — a ClickFix-style attack where the victim runs the malicious code themselves. Cladzsol later said the incident was not related to Arc.

Security

Hackers Claim Revolut Handed Over 680 Customer Files, Demand 6,000 XMR

Hackers demand 6,000 XMR over alleged Revolut customer data theft A group calling itself iamnotavillain told the Financial Times it is demanding 6,000 XMR, about $3 million, to keep files on roughly 680 Revolut customers off the market, after dropping an earlier bitcoin demand. The hackers claim Revolut handed over passports, selfies and transaction histories in response to fake law-enforcement requests sent through Italy’s PEC certified email system, rather than through a breach of its core systems; Revolut said customer funds and systems were unaffected and it had received no direct demand.

September 16, 2026

Security

Hackers Use HBO Max Reddit Account to Push 108 Malware Ads in Two-Day Campaign

Hackers hijack HBO Max Reddit account to run 108 malware ads Attackers used HBO Max’s verified Reddit account to push 108 malicious ads over about 48 hours, directing users to fake software downloads that told Mac users to paste commands into Terminal and Windows users into Run or PowerShell. Malwarebytes linked the campaign to “PasteSwitch,” an operation tied to info-stealing malware; Reddit paused the ads and opened an investigation, while victim numbers and any crypto losses remain unconfirmed.

Security

DCENT urges App Wallet users to move funds after abnormal transfers detected

DCENT urges App Wallet users to move funds after abnormal transfers detected South Korea-based IoTrust, the company behind DCENT, issued a critical notice after detecting abnormal transfers from its App Wallet on Sept. 16, urging users to move assets as soon as possible to a secure hardware wallet or another trusted address. The company said the issue appears limited to the App Wallet and is investigating the cause, scope, and any further steps for users.

Security

Core Lightning Urges Node Operators to Turn Off Experimental Features After New Alert

Core Lightning tells node operators to disable experimental features Core Lightning issued a September 15 alert telling node operators to immediately disable any experimental features or risk losing funds while the team investigates a newly found issue. The advisory applies to CLN software used on Bitcoin’s Lightning Network, not Bitcoin’s main network, and comes weeks after a separate late-August patch for another set of bugs.

Security

Elastic links KREMLIN malware campaign to Ethereum-based infrastructure updates

Elastic says the KREMLIN malware campaign infected at least 1,515 systems, with 98.75% of victims in Brazil, using malicious Chrome and Edge extensions plus Ethereum smart contracts to keep its infrastructure updated. The researchers said the operators used on-chain contracts as a “dead-drop” to change command servers and payload locations without updating the malware itself, while the browser component altered Chromium Secure Preferences to load extensions without user approval and steal credentials, cookies and session data.

Security

BitMart opens feedback portal but offers no withdrawal process or fund update

BitMart opens user portal that does not process withdrawals BitMart has launched a “User Engagement Portal” for affected customers a week after hiring Alvarez & Marsal, but the channel only collects questions and proposals and does not process withdrawals or change account balances. The exchange also gave no new details on reserves, recovery timelines or refunds, while reiterating plans to appoint an independent third party to oversee operations and hold assets during the review.

Security

MEXC says it intercepted 38.66 million USDT in July-August risk cases

MEXC says it intercepted 38.66 million USDT in July-August risk cases MEXC said in its July-August 2026 security report that it intercepted all 215 reports involving stolen or fraud-related funds flowing onto the platform, covering 38,655,490 USDT, with 42 cases involving judicial freezes. The exchange also said it restricted 20,752 risk-linked accounts, while its Futures Insurance Fund rose to 791.7 million USDT as of Sept. 1 and reserves for BTC, ETH, USDT and USDC remained above 100%.

Security

Symbiosis exploit let attacker mint 46.1 billion syBTC from a 330-satoshi deposit

Symbiosis bridge exploit minted 46.1B fake syBTC from 330 satoshis A Symbiosis attacker used two bugs on Sept. 11 to mint about 46.1 billion syBTC after depositing just 330 satoshis, sending 12 fraudulent transactions across BNB Chain, Ethereum and Rootstock in about four minutes. Symbiosis said one flaw checked the wrong transaction data and another treated negative fees as additions; the attacker sold 4.39 WBTC on Uniswap V4 for about $336,000, while the team said it recovered roughly 15 BTC by Sept. 12.

Security

JAN3 halts Indra forward swaps after denial-of-service attack during open beta

JAN3 pauses Indra forward swaps after DoS attack on beta launch day JAN3 temporarily disabled forward swaps on Indra after a denial-of-service attack hit the new Bitcoin swap service within hours of its September 15, 2026 open beta launch, CEO Samson Mow said. Swaps already in progress may be delayed. The incident affected JAN3’s provider-run infrastructure, with no indication of a failure in Bitcoin or the Lightning Network protocols.

September 15, 2026

Security

Authorized Multicall Helper Contract Blamed for $7.8M rsETH Theft From Safe Wallet

$7.8M rsETH theft traced to authorized helper contract, not Safe Security firms said the roughly 2,900 rsETH drained from a Gnosis Safe wallet on Ethereum Tuesday was stolen via a flawed authorization check in a helper Multicall contract the owner had approved, not a bug in Safe itself. SlowMist, BlockSec and AstraSec said an attacker exploited the contract, while the “yoink” bot front-ran the transaction by paying about $47,000 and captured the tokens; Kelp DAO later froze a receiving address for 24 hours.

Security

Trader Sends $2.15M in USDT After Scammers Hijack Partner’s Telegram Account

Scammers steal $2.15M USDT via hijacked Telegram account A crypto trader sent 2,151,772 USDT to scammers after a compromised Telegram account impersonated his business partner, on-chain investigator VAL said on X. The victim first made a $10 test transfer and got confirmation before sending the full amount. Tether later froze about $1 million six days after the theft, while investigators said the rest was traced through wallets linked to MaskEX.

September 14, 2026

Security

Reported Revolut Extortion Attempt Renews Focus on Risks Around Centralized KYC Data

Revolut extortion attempt reportedly exposed customer data Attackers who posed as a government agency to target Revolut customers have reportedly leaked sensitive data and demanded a ransom to stop more disclosures, International Cyber Digest reported. The outlet said the posted data included information tied to tennis player Alexander Shevchenko and Gamdom and Skinscom CEO Felix Römer, while Revolut said only “a limited number” of customers were affected.

Security

Swiss Bitcoin Pay Takes Servers Offline After Suspected Internal Breach

Swiss Bitcoin Pay takes servers offline after suspected internal breach Swiss Bitcoin Pay shut down its entire server infrastructure on Monday after concluding an intruder likely reached its internal systems. The company said the move was precautionary while it investigates, and warned that customer email addresses, Bitcoin addresses, IBANs, transaction histories and hashed passwords may have been exposed. It said no unauthorized Bitcoin movements were identified and customer funds are not at risk.

Security

HTX Reserve Wallet Moved 700 Million TRX Before June Disclosure, On-Chain Data Shows

HTX reserve wallets sent 700M TRX to Poloniex-linked and Binance addresses Protos traced 700 million TRX moved out of an HTX cold wallet in May, ahead of a June proof-of-reserves that showed HTX’s TRX holdings down by the same amount, about $238 million at current prices. Of that, 180 million TRX later reached an address voting for Poloniex’s Super Representative, while 100 million TRX was routed to a TRONScan-labeled Binance hot wallet.

Security

Hong Kong retiree loses over HK$13 million in fake crypto investment app fraud

Hong Kong man loses HK$13 million in fake crypto app scam A Hong Kong man in his 70s lost more than HK$13 million ($1.67 million) after a self-described crypto investment expert from Singapore contacted him on WhatsApp and steered him into a fake trading app. Police said the victim bought USDT and ETH and sent them to wallets specified by the scammer; the app showed fake profits until repeated withdrawal failures exposed the fraud.

Security

Cascade Closes After Five Years and Directs Users to Equilibria Claims Portal

Cascade shuts down brokerage, tells users to claim remaining funds Cascade, formerly Perennial, said it is shutting down after five years and urged users to withdraw or claim any remaining balances through Equilibria’s claim portal. The closure ends its 24/7 trading platform for crypto, commodities and tokenized assets, months after a July exploit drained about $1.3 million in USDC from its CLS vault and forced trading and withdrawal halts.

Security

Solana Mobile Disables Brevo Account After Email Provider Security Breach

Solana Mobile disables Brevo account after unauthorized access Solana Mobile said attackers gained unauthorized access to its Brevo marketing account during a breach at the email provider and may have exposed customer information. The company said it disabled the account, is reviewing what data was accessed with Brevo, and has no evidence emails were sent from its account so far. Brevo said attackers exploited a flaw in its SAML single sign-on system and accessed 138 customer accounts.

Security

Symbiosis recovers 15 BTC after bridge exploit as native Bitcoin route stays offline

Symbiosis recovers 15 BTC after bridge exploit, keeps native Bitcoin route paused Symbiosis said it recovered about 15 BTC after an attacker exploited its Bitcoin Bridge on Sept. 11, but its native BTC route remains suspended and affected liquidity providers are still waiting for a compensation plan. The team moved the recovered funds to a multisig wallet, resumed bitcoin swaps via Chainflip and THORChain, and is offering a 20% bounty for information that helps recover more assets.

September 13, 2026

Security

Solana Mobile Suspends Brevo Marketing Account After Unauthorized Access

Solana Mobile disables marketing email account after Brevo breach Solana Mobile said it found unauthorized access to its Brevo marketing email account and suspended it as Brevo investigates a wider breach tied to a SAML SSO vulnerability. Brevo said 138 customer accounts were affected overall: six were used to send phishing emails, 43 had contacts exported, and 93 showed no meaningful activity. Solana Mobile said it is still verifying the scope and knows of no emails sent from its account.

Security

Symbiosis Pauses BTC Bridge After Exploit Minted Billions in Unbacked syBTC

Symbiosis halts BTC bridge after syBTC mint exploit Symbiosis paused BTC routes after an attacker exploited its BTC Bridge at about 04:28 UTC on Sep. 11, minting roughly 2^62 raw syBTC — about 46.1 billion at face value — and cashing out around $336,000 in WBTC, Blockaid said. Symbiosis said other routes remain operational, it has recovered about 15 BTC to a team-controlled multisig, and is offering the attacker a 20% white-hat bounty until Sep. 13, 2026.

Security

Mexico Seizes 300 GPUs at Puebla Site in Probe of Suspected Illegal Crypto Mining

Mexican authorities seize 300 GPUs at suspected illegal Puebla crypto farm Mexican authorities seized about 300 GPUs from a suspected illicit crypto mining site in Puebla as they investigate possible electricity theft and money laundering. Officials said the remote property also contained 80 medium-voltage terminals, eight satellite antennas and a transformer, and described it as the fourth similar mining operation found near a hydroelectric dam in northern Puebla since early 2025.

Security

Chainflip says TRON USDT memo exploit caused $736,442 in unauthorized payouts

Chainflip pauses network after $736,442 TRON USDT exploit Chainflip halted operations after an attacker exploited how it processed TRON transaction memos, triggering six unauthorized USDT payouts totaling 736,442.17 USDT from the same deposits. The protocol said the issue was limited to TRON USDT, not TRON, the USDT contract or Tether reserves, and one pending 115,654.41 USDT swap remains in its vault unpaid. Chainflip says it has fixed the bug and plans user compensation, but the network will stay paused until Monday at the earliest.

September 12, 2026

Security

Revolut says fake government email led to disclosure of customer and Bitcoin records

Revolut discloses customer records after fake government email request Revolut said it handed over customer data to an unauthorized sender who used an official government agency’s email domain and passed authentication checks, leading the firm to treat the request as genuine. The disclosed records included names, dates of birth, addresses, ID documents, verification selfies, account statements, full transaction histories and Bitcoin wallet reference numbers, according to a customer notice shared by ZachXBT. ZachXBT said the incident appeared limited and may have targeted high-net-worth users.

Security

Symbiosis pauses BTC bridge after exploit creates unbacked syBTC on BNB Chain and Ethereum

Symbiosis halts BTC bridge after exploit mints unbacked syBTC Symbiosis shut down BTC routing on Sept. 11 after an attacker exploited its BridgeV2 contract to mint more than 2^62 syBTC on BNB Chain and Ethereum. The attacker converted only part of that balance into about 4.39 WBTC, or roughly $336,000, while other Symbiosis routes stayed live. The protocol said Bitcoin itself was not compromised.

September 11, 2026

Security

Osmosis says 40.65 BTC Nomic exploit went undetected for 74 days

Osmosis uncovers 40.65 BTC Nomic exploit after 74-day delay Osmosis said a Nomic exploit let an attacker double-spend nBTC and mint 40.650602 BTC on Osmosis with no BTC backing, but the issue went unnoticed for 74 days after the June 25 attack. The attacker cashed out about $1 million via 671 ETH sent to Tornado Cash, while 22.65 allBTC was frozen through an emergency upgrade. Osmosis now says allBTC was left 36% unbacked and has proposed using seized funds, halted USDC.noble redeployment, and Community Pool assets to cover the shortfall.

Security

Tether says DOJ acknowledged its role in freezing over $52 million tied to Xinbi Guarantee

DOJ freezes $52 million in crypto tied to Xinbi Guarantee Tether said it helped the U.S. Department of Justice freeze more than $52 million in digital assets in a crackdown on Xinbi Guarantee, a Chinese-language online marketplace that authorities say used Telegram to run fraud rings, money-laundering services and investment scams. The DOJ seized about $12 million from two wallets and moved to freeze 47 more tied to alleged laundering activity.

Security

Brevo SSO flaw exposed 138 accounts and enabled phishing through Trezor mailing systems

Brevo flaw let attacker access 138 accounts, hit Trezor mailing list Brevo said an authorization flaw in its login system let an attacker access 138 customer accounts by abusing single sign-on permissions, then send phishing emails through six accounts including those used by Trezor, BitBox and CoinTracking. Trezor said the fake email reached about 347,000 subscribers and drove roughly 2,500 clicks to a malicious link before the domain was taken down, and is treating the full newsletter list as potentially exposed.

September 10, 2026

Security

Liquid restarts block production after exploit-driven 3,996 BTC withdrawal

Liquid resumes block production after $320M withdrawal, keeps transactions frozen Liquid Network has restarted block production after functionary and bridge nodes received an emergency software update, but regular transactions and BTC peg-ins and peg-outs remain suspended while operators monitor the network. The halt followed a roughly 3,996 BTC withdrawal caused by an Elements proof-verification flaw; 3,400 BTC has since been returned, leaving about 598 BTC outside the federation wallet.

Security

Osmosis Plans Backstop After Nomic Bug Left Alloyed BTC 36% Underbacked

Osmosis moves to plug 36% backing gap in Alloyed BTC after Nomic bug A Nomic software flaw on June 25 minted 39.84 unbacked nBTC, leaving Osmosis’s Alloyed BTC 36% undercollateralized for 74 days before it was caught. Osmosis froze Nomic and Alloyed BTC deposits and withdrawals, locked 22.65 BTC tied to the incident, and now plans a governance proposal to seize those assets and use BTC accrued in the community pool to restore full backing.

Security

Trezor says compromised email provider was used to send fake wallet security alerts

Trezor warns of phishing emails sent via compromised provider Trezor said hackers exploited its third-party email provider on Sept. 9 to send fake “Critical Security Alert: STM32 Entropy Vulnerability” messages from what appeared to be legitimate Trezor infrastructure. The company said wallets were not affected, told users not to click the links, and said it had blocked the sending domain while investigating how the attackers used its email system.

Security

XRPL Replaces Permission Delegation V1.0 After Security Flaw Found in Testing

XRPL withdraws Permission Delegation V1.0 after high-severity bug XRPL pulled the original Permission Delegation amendment after bug bounty researcher Shotes found a flaw that could let a delegate delete and recreate an account while keeping irrevocable permissions, leaving the original account unable to revoke them. RippleX engineering head J. Ayo Akinyele said the hardened V1.1 has now cleared Cantina security review and QA, which logged 179 delegation tests and no critical internal bugs.

September 9, 2026

Security

US sanctions Xinbi as DOJ seizes crypto tied to alleged cybercrime marketplace

US sanctions Xinbi cybercrime marketplace, seizes $12M in crypto The US Treasury’s OFAC on Sept. 9 sanctioned Xinbi Guarantee, a Chinese-language marketplace that investigators say processed more than $24 billion for scam and money-laundering services, and flagged 52 wallet addresses that received over $8.4 billion in stablecoins. In a coordinated move, the DOJ seized about $12 million in crypto, restrained 47 more wallets, and linked Xinbi’s network to tens of millions in stolen funds moved by DPRK-linked actors.

Security

Alby Discloses Critical Flaw in Older Hub Versions Exposed to the Internet

Alby discloses critical flaw in older Alby Hub versions Alby said on Sept. 9 it confirmed a critical vulnerability in Alby Hub v1.7.0 to v1.18.5, affecting releases prior to August 2025 when the Hub was publicly accessible from the internet. The company said an attacker who could reach the management API might gain unauthorized access and send funds; v1.19.0 and newer are unaffected, and Alby says one user is known to have been impacted. For exposed users, Alby urged updating to v1.24.0, restricting public access, and changing the unlock password.

Security

Osmosis Freezes 22.65 BTC After Nomic Bug Put Alloyed BTC Reserves at Risk

Osmosis freezes Alloyed BTC after Nomic exploit Osmosis halted inbound and outbound transactions for Nomic and Alloyed BTC after a Nomic bug let an attacker double-spend nBTC and send false vouchers to the DEX, putting 39.84 nBTC — about 36% of Alloyed BTC reserves — at risk. Osmosis and IBC were not compromised, and an emergency upgrade with validators froze 22.65 BTC at the attacker’s address. The team plans governance votes to confiscate those assets and use community pool bitcoin to cover the remaining shortfall.

Security

Nebty Says DoppelCart Fake-Store Network Spans Nearly 119,000 .shop Domains

Nebty says DoppelCart runs 119,000 fake online shops German cybersecurity startup Nebty says it has uncovered DoppelCart, what it calls the largest known network of fake online stores, spanning about 119,000 domains, or 2.72% of all .shop domains in its September 2026 snapshot. Nebty says the sites impersonate 44,182 brands and send stolen checkout data, including card details, addresses and one-time bank confirmation codes, to attackers in real time over WebSockets.