Security news

Showing 101–150 of 341
Clear filters

September 9, 2026

Security

Tether Freezes $39.3 Million in USDT Across Tron Wallets Linked to Xinbi Guarantee

Tether freezes $39.3M USDT tied to Xinbi Guarantee on Tron Tether has frozen about $39.3 million in USDT across 10 Tron addresses linked to Xinbi Guarantee, a Chinese-language guarantee marketplace that TRM Labs has tied to scam operations, money laundering networks and cybercrime groups. MistTrack said the wallets were unevenly funded, with the largest holding about 10.78 million USDT, in what it described as another potential crackdown on illicit Telegram-based escrow platforms.

September 8, 2026

Security

Schwartz Says XRPL Hub Has Recovered After July Manifest-Flood Attack

Schwartz says XRPL hub recovered after July manifest-flood attack David “JoelKatz” Schwartz said his XRP Ledger hub has been “rock solid” for the past two weeks after issues triggered by the July 30 manifest-flood attack, with current peer connections at 406 versus a 401.12 average since Aug. 25. The attack disrupted XRPL peer connectivity by flooding nodes with fake or unverified validator manifests, but Schwartz said the ledger stayed online without halting or forking as validators kept consensus running and developers deployed emergency fixes.

Security

Cronos Rolled Back Nearly Two Hours of Blocks After $111.2 Million Tectonic Exploit

Cronos rolls back blockchain to reverse $111.2M from Tectonic exploit Cronos said validators erased 10,961 blocks — 1 hour 54 minutes of history — after the Aug. 30 Tectonic exploit, reversing about $111.2 million in borrowing activity and wiping out legitimate transactions in the same window. The network said the move protected roughly 92% of funds still onchain, but $9.19 million had already left Cronos before the halt and remains unrecovered.

Security

Harmony to Wind Down After 3 Trillion ONE Exploit and Shift Balances to Ethereum

Harmony to shut down and migrate to Ethereum after 3T ONE mint exploit Harmony said it is winding down and moving to Ethereum, citing threats from state actors and AI agents after an Aug. 11 exploit led to the unauthorized minting of 3 trillion ONE. User balances will be migrated via a snapshot and airdropped to the same wallet addresses on Ethereum, but tokens locked in smart contracts will not transfer and must be withdrawn within three days.

Security

Police in Lutsk shut alleged crypto investment scam call center

Police shut down alleged $500,000-a-month crypto scam call center in Lutsk Ukrainian police said they dismantled a call center in Lutsk that posed as investment firms offering crypto, securities and FX products to citizens of Ukraine and the EU, with about 60 operators allegedly involved and the organizer believed to have made up to $500,000 a month. During searches, officers seized about $30,000, 468 phones, 214 SIM cards and more than 1,000 pieces of computer equipment.

Security

Galaxy Research Says Coldcard Attacker Moved 97 BTC From Third Theft Wave

Coldcard exploit hacker moves 97 BTC through THORChain and CoinJoin The attacker behind the third wave of Coldcard thefts has moved 97.09 BTC, about $7.8 million, or 45% of the stolen funds from that batch, Galaxy Research said. The firm said the laundering used THORChain swaps and CoinJoin, while about 82% of the broader stolen assets still remain at the original recipient addresses. Galaxy estimates the 2021 firmware flaw has now been tied to 1,806 BTC in losses, worth about $143.9 million.

September 7, 2026

Security

Liquid Network Recovers 3,400 BTC After 4,000 BTC Bridge Withdrawal

Liquid recovers 3,400 BTC after disputed 4,000 BTC withdrawal Liquid Network has recovered 3,400 BTC worth about $268.2 million from self-described white-hat hackers after a 4,000 BTC withdrawal, with on-chain data showing about 598.5 BTC, or roughly $47 million, still in the actors’ address. Blockstream said its bridge nodes were patched before the repayment, but Liquid has not said when bridge and L-BTC services will resume.

Security

Orionx Freezes Withdrawals and Begins Wind-Down After Alleged $7M Asset Transfers

Orionx halts withdrawals and starts wind-down after $7M asset discrepancy Chilean crypto exchange Orionx has suspended customer withdrawals and begun a definitive wind-down after saying a forensic audit found more than $7 million in custodied assets had been moved to wallets outside its control. The company filed a criminal complaint on Sept. 2 against former executives Roberto Zibert and Joaquín Díaz, while Chile’s CMF said it does not oversee the closure or have authority to order customer funds returned because Orionx is not registered or authorized.

Security

Winona County Reports Second Ransomware Attack After Paying $128,539 in January Case

Minnesota’s Winona County hit by second ransomware attack after payoff Winona County, Minnesota said it was hit by a second ransomware attack in April, months after paying about $128,539 to resolve a January 2026 breach. The county said different cybercriminals were behind the later attack; the first incident exposed personal, medical, law enforcement and financial data, while emergency services stayed online in both cases. The April attack is still under review, and the county is working with the FBI.

Security

Bluechip Upgrades Tether as Hacken Warns Two Keys Could Control $91.3B in USDT

Bluechip lifts Tether to C as Hacken flags two-key control over half of USDT Bluechip raised Tether’s corporate grade to C from D after a KPMG US financial audit, but its new review with Hacken gave USDT just 3.3/10 on cybersecurity. Hacken said about $91.3 billion of USDT on Tron, roughly half the supply, is controlled by a contract that could be seized with two signing keys, with no built-in delay or reversal; it found no evidence any key has been compromised or that any incident occurred.

Security

Galaxy says third-wave Coldcard exploiter moved 45% of stolen Bitcoin

Galaxy: Third-wave Coldcard exploiter moved 45% of stolen BTC The attacker behind the third wave of the Coldcard wallet hack has moved about 45% of its Bitcoin haul, sending funds through THORChain into Ethereum and into CoinJoin transactions, Galaxy Research said in a Monday update. Galaxy added the exploiter set up 293 two-of-two multisig vaults and has now drained the 11 largest vaults; across all Coldcard attack waves, 82% of the stolen BTC remains in original attacker-controlled addresses and 18% has moved in apparent laundering.

Security

XRP Healthcare Says 4,011 Wallets Were Drained in $452,000 XRPH Wallet Breach

XRP Healthcare says wallet breach hit 4,011 accounts XRP Healthcare said unauthorized transactions that began Sept. 3 drained about $452,000 in XRP and related assets from 4,011 XRPH Wallet accounts. The project said it traced the stolen funds to one Ethereum wallet and contacted exchanges to try to freeze them, while independent researchers alleged the wallet’s staking function may have exposed users’ seed phrases — a finding the company had not confirmed at publication.

Security

Rocket Halts Trading After $287,000 Loss From Dormant Perp Market Manipulation

Rocket suspends trading after $287,000 perp market manipulation attack Rocket paused deposits, withdrawals and trading after an attacker manipulated a dormant perpetual market on Sept. 5, using inflated orders and self-trades to create artificial profits and withdraw about $287,000 through the platform’s Bridge. The project said it is working with security firms, law enforcement, exchanges, bridges and stablecoin issuers to trace and freeze the funds, and is preparing a recovery plan that will prioritize smaller affected accounts.

Security

Malicious Packagist Themes Linked to iPhone Safari Exploit Chain Targeting Wallet Data

Socket links malicious Packagist themes to iPhone exploit chain targeting wallet data Socket said 13 malicious OphimCMS and KKPhim themes on Packagist were used to infect websites with JavaScript that checked iOS versions and served Safari exploits for iOS 18.4-18.6.x, potentially reaching protected data including Keychain records and wallet material. Apple has patched the chain in later iOS releases, making updates the main defense for affected iPhone users.

September 6, 2026

Security

Berlin Rejects 30 BTC Ransom as Rhysida Publishes 5.7 TB of Stolen Data

Berlin refuses 30 BTC ransom as Rhysida leaks 5.7 TB of stolen data Berlin’s state government refused to pay a 30 BTC ransom, about €2 million, and the Rhysida ransomware group responded by publishing 5.7 terabytes of stolen data on the dark web after the Sept. 4 deadline expired. Officials warned residents’ personal data may be in the leak, while a crisis unit, police, and Germany’s federal cybersecurity agency review the files and investigate the attack.

Security

Ukraine Breaks Up Fake Crypto Investment Network Targeting Users in Over 20 Countries

Ukraine dismantles fake crypto investment ring targeting 20+ countries Ukrainian investigators uncovered a network of fake investment platforms that targeted crypto users in more than 20 countries, identifying 62 victims so far and saying more than 46 Ukrainians took part. Police said the group used wallet-draining software hidden behind small “test” transactions and faked account gains to win trust. After tracing servers to the Netherlands, authorities carried out 34 searches in Kyiv and the surrounding region, seizing over 100 computers, 100 phones, 79 SIM cards, cash and 15 vehicles.

Security

Mexican Authorities Probe Killing of Musician Jonathan Meléndez in Suspected Bitcoin Attack

Mexican musician Jonathan Meléndez killed in suspected $1.5M bitcoin wrench attack Mexican authorities are investigating the Sept. 1 killing of Camilo Séptimo member Jonathan Meléndez, his four-month-pregnant wife, their three-year-old daughter and their housemaid at the family’s apartment in Atizapán after suspects allegedly targeted a hardware wallet holding about $1.5 million in BTC. Two suspects were detained within 12 hours, including an associate of Meléndez who allegedly knew about the crypto holdings.

Security

Orionx Winds Down After Audit Finds More Than $7 Million Missing From Custodied Assets

Orionx halts withdrawals after audit finds $7 million asset gap Chilean crypto exchange Orionx said it is winding down and has suspended customer withdrawals after a forensic audit found more than $7 million in transactions that moved custodied assets to external wallets. The company accused founding partners Joaquín Díaz and Roberto Zibert, along with former employees, of involvement and filed criminal complaints, warning users there is no guarantee they will recover 100% of their funds.

September 5, 2026

Security

Trezor Expands ShipMonk Breach Notice to 67,000 U.S. Customers

Trezor expands ShipMonk breach notice to 67,000 US customers Trezor said former shipping partner ShipMonk told it on Sept. 2 that order records from November 2019 through August 2021 had remained in ShipMonk’s systems and were caught in the same breach first disclosed in August. The exposed data covers about 67,000 US customers and includes names, emails, phone numbers, shipping addresses, and order numbers; Trezor said its own systems and hardware wallets were not compromised, but warned of higher phishing and physical security risks.

Security

Google Fixes Actively Exploited Chrome V8 Flaw in Latest Browser Update

Google patches actively exploited Chrome V8 flaw Google has released a Chrome security update to fix CVE-2026-85046, a high-severity type-confusion bug in the V8 JavaScript and WebAssembly engine that it says attackers were already exploiting. The patch is included in Chrome 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with rollout continuing over the coming days and weeks, while Google withholds technical details until more users and affected third-party projects are patched.

Security

Vesu says faulty Pragma feed caused $3 million in abnormal Starknet liquidations

Vesu says faulty Pragma feed triggered $3M in abnormal liquidations on Starknet Starknet lending protocol Vesu said an incorrect upstream Pragma price feed made 47 borrowing positions across several pools appear liquidatable between 04:08 and 04:10 UTC on Sept. 4, leading automated liquidators to remove about $3 million in collateral. Vesu said its contracts behaved as designed, Pragma has deployed a fix, affected pools were paused by curators, and recovery talks are under way with Pragma, StarkWare, the Starknet Foundation, and pool curators.

Security

August Crypto Hacks Rise to 50 as Losses Drop to $136.3 Million

August crypto hacks jump 67% as losses fall to $136.3M The crypto sector recorded 50 major hacks in August 2026, up 67% from July, while total losses fell 49.5% to $136.3 million, Peckshield said. A $74 million exploit of decentralized lending protocol Tectonicfi made up more than half of the month’s losses, but most of the funds were trapped after the Cronos network paused its chain. Peckshield said many DeFi breaches still stem from compromised privileged keys.

September 4, 2026

Security

Balancer Sets Sept. 8 Deadline for Wallet Linked to Aug. 31 Exploit

Balancer sets Sept. 8 deadline for wallet tied to Aug. 31 exploit Balancer has told the operator of a wallet linked to its Aug. 31 Balancer V1 exploit to return the stolen funds by Sept. 8 or face escalation. In an on-chain notice posted Sept. 3, the protocol offered a bounty for funds sent back to the Balancer DAO multisig and asked for a Blockscan response by 21:00 UTC. Balancer said non-cooperation could trigger technical, on-chain and legal action.

Security

Trezor says ShipMonk breach exposed 67,000 more U.S. customer records

Trezor says ShipMonk breach exposed data of 67,000 more U.S. customers Trezor said Friday that a breach at shipping provider ShipMonk exposed another 67,000 U.S. customers, lifting the total affected to about 80,700 from 13,689 disclosed in August. The newly identified records include names, emails, phone numbers, home addresses and order numbers for orders placed between November 2019 and August 2021, despite Trezor saying its contracts required deletion after 90 days and that it had received written confirmation the data had been erased.

Security

Notional Finance Legacy Escrow Drained for About $1.73 Million in Overflow Exploit

Notional Finance legacy escrow hit by $1.73M exploit An attacker drained about $1.73 million from Notional Finance’s legacy escrow contract early Friday by exploiting an unsafe uint128 downcast that made a fabricated -2^128 liability register as zero, letting the account appear debt-free. Etherscan shows 69,257 DAI and 1,658,524 USDC were withdrawn, swapped into about 689 ETH and later routed through Tornado Cash; Notional had not issued a public statement at publication.

Security

User Reportedly Loses $2.1M in FXRP After ChatGPT Surfaced Phishing Swap Link

User reportedly loses $2.1M in FXRP after phishing link from ChatGPT A crypto user known as Alex said he lost about 1.9 million FXRP, worth roughly $2.1 million, after ChatGPT allegedly pointed him to a phishing site for swapping sFLR to WFLR. After connecting his wallet, he approved an unlimited transaction, letting the attacker drain the funds within seconds; blockchain investigator VAL said later tests in several languages no longer returned the malicious link.

Security

Tectonic exploit-linked wallet sends 2,658.9 ETH into Tornado Cash

Tectonic hacker-linked wallet sends $6.65M in ETH to Tornado Cash A wallet tied to the Tectonic exploit deposited about 2,658.9 ETH, worth $6.65 million, into Tornado Cash on Sept. 3 UTC, PeckShield said. The funds appear to be the Ethereum portion Cronos could not recover when validators rolled back the chain after the Aug. 30 hack, which reversed most of the attacker’s balances still on Cronos but not assets already moved to Ethereum.

September 3, 2026

Security

Pocket Bitcoin Says Data Breach Exposed Personal Data of More Than 5,400 Users

Pocket Bitcoin says data breach exposed information on 5,400+ users Swiss-based Bitcoin trading service Pocket Bitcoin said a hacker copied personal data from more than 5,400 users after gaining access on Aug. 16. Exposed information included email addresses, customer inquiry records and bank transfer-related details, while some users also had ID documents, residential addresses, proof-of-funds materials and Bitcoin addresses disclosed. The company said it blocked the access, fixed the flaw and reported the incident to Switzerland’s federal data protection authority; it added that no Bitcoin or private keys were compromised.

Security

DOJ investigates coordinated password-reset attack targeting X users

DOJ opens probe into mass password-reset attack on X Attorney General Todd Blanche said the Justice Department is pursuing the criminals behind a coordinated password-reset attack that hit “hundreds of thousands of X users” on Sept. 2. X said it stopped the attack before any accounts were compromised, after users reported waves of reset emails sent from info@x.com with valid six-digit codes. X engineer Mridul Singhai said the company found no sign of a breach.

Security

Term Labs says all fixed-rate positions were recovered after August governance exploit

Term Labs recovers final fixed-rate position after August governance exploit Term Labs said it has recovered all fixed-rate loan positions tied to vaults hit in its August governance exploit, with the last position moved at 14:52 UTC on Aug. 25. The protocol said the attack was limited to liquid ETH and USDC held in Term vault strategies, while V1 and V2 contracts and direct borrowing and lending markets were not compromised. Meta Vaults and affected strategies remain shut down, new deposits are permanently disabled, and withdrawals stay open.

Security

Fake Claude desktop app on GitHub linked to malware targeting crypto wallets

Fake Claude desktop app on GitHub used to target crypto wallets Cybersecurity researchers at Morphisec said attackers are distributing a fake “Claude Opus 5 Free Desktop” app on GitHub that installs a Windows infostealer aimed at crypto wallets, browser data, password managers and VPN configs. The malware targets wallets including Atomic, Ledger Wallet, Trezor Suite, Electrum, Wasabi and Sparrow, and could help compromise funds if users rely on weak passphrases or stolen credentials.

Security

Full Sail to Wind Down on Sui After $91,000 Oracle Exploit

Full Sail to shut down on Sui after $91,000 oracle exploit Full Sail said it is winding down on Sui after an Aug. 29 attack drained about $91,000 from three vaults by exploiting Switchboard production code for oracle price signers. The team said this was not an admin key compromise, paused deposits and withdrawals, and plans to use all remaining protocol-owned liquidity while absorbing the shortfall so affected depositors are compensated first.

Security

Rain Solana card contract exploit drained about $1.1 million across multiple programs

Rain contract flaw let attacker drain about $1.1M from Solana card programs An outdated Rain Solana card contract was exploited on Aug. 28, allowing unauthorized withdrawals from collateral accounts used by multiple stablecoin card programs, Blockaid said. Avici reported $500,859 stolen from 1,685 users and Tria said $431,945 was drained from 636 customers, with total losses estimated at about $1.1 million. Rain said all programs using the vulnerable contract version have since been upgraded.

September 2, 2026

Security

US and European authorities disrupt Sality botnet linked to crypto clipboard theft

US, European agencies disrupt Sality botnet tied to crypto clipboard theft The US Justice Department said it disrupted the Sality botnet in an operation with Bulgarian, Hungarian and Romanian authorities, plus CrowdStrike and the Shadowserver Foundation. CrowdStrike said operators used the EggJagger clipjacking tool to steal at least 12.1 million rubles, or about $150,000, in crypto over the past eight years by swapping wallet addresses copied by victims. The action cut the attackers off from roughly 15,000 infected computers, CrowdStrike said.

Security

DOJ and CrowdStrike Disrupt Sality Botnet After Years of Crypto Theft

DOJ and CrowdStrike disrupt Sality botnet, isolating 15,000 infected machines The U.S. Justice Department and CrowdStrike dismantled parts of Sality, a peer-to-peer botnet active since 2003, by seizing linked domains in the U.S. and taking down infrastructure in Bulgaria, Hungary, and Romania. The operation redirected more than 15,000 infected devices to CrowdStrike-controlled sinkholes, cutting them off from operators that used the EggJagger malware to replace copied crypto wallet addresses and divert payments; CrowdStrike estimates at least $150,000 was stolen.

Security

YAM Finance Faces Governance Takeover Attempt With $337,000 Potentially Exposed

YAM Finance faces governance takeover attempt An attacker amassed about 504,000 self-delegated YAM, or 3.3% of supply, and used it to submit proposal #45, which would make an attacker-controlled address the pending admin of YAM’s Timelock. Defimon said that could hand over control of protocol contracts and the DAO treasury, putting about $337,000 at risk, and urged holders to vote against the proposal before block 25,897,343.

Security

Armed Home Invasion in Alès Adds to France’s Rising Number of Crypto Extortion Cases

Armed intruders in Alès hold couple for 2 hours in crypto extortion attempt Two masked gunmen tied up a couple at their home in Alès, southern France, and threatened them for more than two hours while demanding cryptocurrency transfers, local media reported. The attackers fled before police arrived after neighbors heard screams and called officers; the couple’s young child was inside the house. DCOS investigators in Nîmes have taken over the case, and no arrests were initially reported.

Security

Fogo Restarts Mainnet After Recovering and Removing 237 Million Stolen FOGO

Fogo restarts mainnet after recovering 237M stolen FOGO Fogo has resumed mainnet operations after recovering and permanently removing 237 million of the 400 million FOGO stolen in the Aug. 28 compromise involving the Fogo Foundation. The Layer 1 had halted on Aug. 29 to stop movement of the tokens; 163 million FOGO remains unrecovered, and the project said recovery efforts with centralized exchanges and law enforcement are ongoing while its investigation continues.

Security

Core DAO Plans Emergency Hard Fork After Validator Reward Issue

Core DAO coordinates emergency hard fork over excess validator rewards Core DAO said Sept. 1 it has contained an issue that let a small group of validators obtain CORE rewards above the blockchain’s intended issuance, and is now coordinating a forward-only emergency hard fork to deploy a permanent fix. The project said confirmed transactions will not be rolled back and user assets are safe, but several exchanges have restricted or halted CORE deposits, withdrawals, or transfers while the incident is investigated.

September 1, 2026

Security

TRM Labs Counts 32 Crypto Price-Manipulation Exploits in 2026 as Lending Risks Grow

TRM Labs says price manipulation attacks hit 32 cases in 2026 so far TRM Labs said it has recorded 32 price-manipulation exploits so far in 2026, already far above 12 cases last year, as attackers pump illiquid tokens, use the inflated assets as collateral, and leave lending protocols with bad debt. The trend is hitting a growing crypto-backed lending market: Tectonic recently lost more than $70 million after TONIC was inflated 100x in about 20 minutes, though a Cronos rollback cut the attacker’s haul to about $6 million.

Security

Belgian Police Target Crypto Wallets in Cross-Border Piracy Investigation

Belgian police target crypto wallets in offshore piracy probe Belgian federal police have targeted crypto wallets allegedly linked to designated offshore piracy platforms in a cross-border enforcement action, the government said. The move was framed as a specific criminal investigation into piracy-linked wallets, not a broader crackdown on crypto wallets or self-custody.

Security

Fake Claude Desktop App on Windows Used to Spread RevStealer Crypto-Theft Malware

Fake Claude desktop app spreads RevStealer on Windows Cybersecurity firm Morphisec said a trojanized “Claude Opus 5 Free Desktop” app is distributing RevStealer malware on Windows, targeting data from more than 50 crypto wallets, 12 password managers and web browsers. The fake Electron app uses Anthropic branding, decrypts and runs a hidden payload, exfiltrates stolen data in encrypted records, then deletes itself; stolen session cookies may let attackers access accounts even with MFA.

Security

Unsolicited password reset emails hit thousands of X users, including crypto accounts

Thousands of X users hit by unsolicited password reset emails Thousands of X users, including prominent crypto accounts and at least four CoinDesk staffers, received waves of password reset emails Tuesday, with some users reporting up to 10 messages in a few hours. There is no confirmed evidence that X was breached or that attackers obtained users’ email addresses, since anyone can trigger a reset request using a public username.

Security

August Logged 50 Major Crypto Hacks, a 2026 High, as Losses Fell to $136.3 Million

August sets 2026 crypto hack record as losses fall to $136.3M Crypto saw 50 major hacks in August, the highest monthly count of 2026, while total losses fell 49.5% from July to $136.3 million, PeckShield said Tuesday. The biggest breach hit Cronos-based lending protocol Tectonic for about $74 million, though only around $6 million reached Ethereum before validators froze the network; Cronos later restored the chain state and resumed block production.

Security

Cronos Resumes After Emergency Halt and Rollback Tied to Tectonic Exploit

Cronos restarts after Tectonic exploit rollback Cronos has resumed block production after validators halted the network during an exploit targeting Tectonic and rolled the chain back to before the attack. The restart began from block 90,896,189 on Aug. 30 at 23:49:01 UTC, with node operators told to use Cronos v1.7.8 and the latest Aug. 31 mainnet snapshot. Cronos said the chain is fully back online, though bridges, RPC providers, explorers and some protocols may restore service more slowly.

August 31, 2026

Security

Australia charges two men in alleged TeamPCP software supply-chain hacking case

Australia charges two men over alleged TeamPCP supply-chain attacks Australian authorities charged two Western Australian men on Aug. 26 after an AFP-FBI probe into the alleged TeamPCP cybercrime syndicate, accusing the group of compromising more than 1,000 organizations, stealing over 500,000 credentials and taking at least 300GB of data via malicious code inserted into open-source software components. Police say the men also received cryptocurrency, with the value still under investigation.

Security

CoinGecko: Crypto Platforms Lost $3.63 Billion in 245 Incidents From 2025 to July 2026

CoinGecko: Audited crypto platforms made up 88% of losses in 2025-2026 hacks CoinGecko said crypto platforms lost $3.63 billion across 245 incidents between January 2025 and July 2026, with the 10 biggest attacks making up more than 72.5% of the total. Of those incidents, 147 hit previously audited protocols, which accounted for 88.44% of all funds stolen, underscoring that audits did not prevent the biggest losses.

Security

Ontology Suspends Mainnet Block Production During Security Review

Ontology pauses mainnet block production over security concern Ontology has temporarily halted mainnet block production after core developers flagged a potential security issue during a routine check, suspending on-chain transactions while validators conduct an emergency review. The team said there is currently no indication of any loss or compromise of user assets, and the chain will stay paused until the assessment is complete and any required upgrades are finished.

Security

More Markets hit by $9.3 million WFLOW exploit on Flow EVM

More Markets exploit on Flow EVM drains $9.3M in WFLOW More Markets was exploited on Flow EVM on Aug. 31, with about 15.5 million WFLOW drained from its mFlowWFLOW lending reserve, a loss Blockaid estimated at roughly $9.3 million. Blockaid said the attacker used an Ankr bonded liquid staking token together with More Markets’ E Mode mechanism, and traced a cluster of transactions moving the funds after the attack. There is no indication Flow itself was compromised.

Security

Cronos Stops Chain After Tectonic Exploit Estimated at About $75 Million

Cronos halts blockchain after Tectonic exploit estimated at $75M Cronos halted its blockchain Sunday after an exploit hit decentralized lending protocol Tectonic, with researcher Weilin Li estimating roughly $75 million was affected. Li said the attacker pumped TONIC’s price about 100-fold in 20 minutes, borrowed other assets, and bridged around $6 million to Ethereum before the halt, leaving most funds on Cronos. Crypto.com CEO Kris Marszalek said the company’s app and exchange were unaffected and operating normally.