Security news

Showing 151–170 of 170
Clear filters

July 15, 2026

Security

Ostium loses up to $18 million in oracle signer exploit on Arbitrum

Ostium loses nearly $18M in oracle key exploit on Arbitrum Attackers drained nearly $18 million USDC from Ostium after compromising an oracle signer private key, letting them bypass verification checks and submit favorable future prices. Blockaid flagged the incident on July 15, 2026, saying the attacker used a registered PriceUpKeep forwarder and authorized oracle reports to run about 20 looped trades, extracting roughly 32%-35% of the protocol’s ~$34 million TVL.

Security

Hijacked SpaceX and Starlink X accounts used to promote SCATMAN token in brief scam

SpaceX and Starlink X accounts hijacked to pump SCATMAN memecoin Verified X accounts for SpaceX and Starlink were briefly hijacked on July 12 and used to repost promotions for the SCATMAN memecoin, helping drive a 575% surge in the first 20 minutes before the posts were removed. The attacker reportedly minted 10 trillion tokens and sold them across two wallets for about 73.7 ETH, or roughly $135,000, turning the brands’ credibility into a short-lived exit liquidity event for buyers.

July 14, 2026

Security

Gwalior accountant alleges Rs 21 crore loss in six-month fake crypto trading fraud

Gwalior CA alleges Rs 21 crore crypto scam tied to fake Bitcoin, USDT trades A 70-year-old chartered accountant in Gwalior told police he lost more than Rs 21 crore over six months in an alleged crypto investment fraud that began with a WhatsApp approach and a fake Bitcoin-USDT trading platform. Investigators said an initial Rs 1.88 lakh payout was used to build trust before the victim was asked for more money, including Rs 10.84 crore in “tax” and 2 lakh USDT as risk margin; police have frozen about Rs 2 crore after tracing funds through 570 mule accounts.

Security

Prism Deploys New Ethereum Contract After Exploit Diverted Nearly 40% of Trading Fees

Prism relaunches on new Ethereum contract after fee-draining exploit Prism is abandoning its original PRISM token and deploying a new Ethereum contract after disclosing that an attacker spent most of July siphoning off just under 40% of trading fees. The exploit used helper contracts to create 2,500 extra fee-earning positions beyond the token’s 5,000 cap, and the old token fell about 91% in 24 hours. It is still unclear how holders will migrate to the new contract.

Security

Humanity Protocol Rebuilds Security After $36 Million Token Theft

Humanity Protocol revamps security after $36M token hack Humanity Protocol said it is rebuilding its operational security framework from the ground up after an employee laptop was compromised last month, leading to the theft of $36 million in H tokens. Quantstamp said the attack may have involved a North Korea-linked group using phishing and malware to gain remote access to an admin hot wallet and multisig keys, underscoring the growing crypto threat from employee-targeted social engineering.

Security

BonkDAO Treasury Drained After Attacker Buys Majority in BIP #76 Vote

BonkDAO treasury drained after attacker bought vote majority An attacker spent about $4.4 million buying BONK, pushed through BonkDAO proposal BIP #76, and transferred roughly $20 million in BONK from the DAO treasury on July 6. The vote passed with 882.38 billion BONK in favor against an 879.95 billion quorum, with just seven wallets participating, and executed automatically via Realms with no timelock or veto. BonkDAO said no smart contract, key, or user wallet was compromised. Exchanges began responding, with Upbit suspending BONK deposits and withdrawals as investigators traced the funds.

Security

Interpol says Thai suspect’s wallet moved $122 million in alleged romance scam proceeds

Interpol links $122M crypto wallet to romance scam suspect in Thailand Interpol said a 20-year-old suspect arrested in Thailand controlled a crypto wallet that processed more than $122 million in alleged romance scam proceeds over 10 months, with funds often routed through cross-chain swaps to hide the trail. The wallet was uncovered during Operation First Light 2026, a January-April sweep across 97 countries that led to 5,811 arrests, $293 million intercepted, and more than 142,000 victims identified.

July 13, 2026

Security

Bonzo Lend Loses About $9.05M After Hedera Oracle Verification Flaw

Bonzo Lend loses $9.05M in oracle exploit on Hedera Bonzo Lend was drained of about $9.05 million on July 11 after an attacker exploited a verification flaw in Supra’s Hedera oracle contract, using 250 SAUCE worth only a few dollars as collateral to inflate its price and borrow 6.63 million USDC and 34.52 million wrapped HBAR. A second wallet borrowed about $1 million more before claiming to be a white hat and offering to return the funds; the protocol remains paused.

Security

BlueMove says overflow bug led to $500K SUI drain, amid insider speculation

BlueMove offers bounty after $500K SUI drain from locked pools BlueMove says an attacker exploited a long-standing arithmetic overflow bug in its legacy AMM contract to drain liquidity from 389 pools, taking about 700,000 SUI, or roughly $500,000. The DEX offered the exploiter a 30% white hat bounty to return the funds, said it will compensate affected users if no deal is reached within 48 hours, and added that the project will shut down going forward.

Security

OKX to Halt Solana USDC Deposits and Withdrawals on July 14 for Wallet Maintenance

OKX to pause Solana USDC deposits and withdrawals on July 14 OKX said it will suspend USDC deposits and withdrawals on the Solana network from July 14 at 14:30 UTC+8 for wallet maintenance, while trading will remain available. The exchange gave no end time and said services will resume after the work is completed, potentially without a separate announcement. Users were told not to send Solana-based USDC during the pause because transfers could risk lost funds.

Security

Ethereum Foundation says AI agents found and helped disclose bug in libp2p code

Ethereum Foundation says AI agent fleet found protocol bug in libp2p The Ethereum Foundation’s Protocol Security team said it is using coordinated AI agents to test critical protocol code and has already found real vulnerabilities, including a remotely triggerable panic in the libp2p gossipsub library used for Ethereum’s peer-to-peer communications. The issue has been fixed and publicly disclosed as CVE-2026-34219, while the team said the main challenge is triaging AI findings to separate real bugs from false positives.

Security

Gwalior accountant loses ₹21.06 crore in alleged fake crypto trading scam

Gwalior CA loses ₹21.06 crore in fake crypto trading scam A 70-year-old chartered accountant in Gwalior, Ashok Vijayvargiya, lost ₹21.06 crore ($2.2 million) after fraudsters befriended him on social media and lured him onto a fake crypto trading platform with fabricated early gains. Madhya Pradesh’s State Cyber Cell has filed a case and is tracing 20 bank accounts, three WhatsApp numbers, and the scam portal’s URL to try to freeze linked funds.

July 12, 2026

Security

Crypto hacks reached 207 cases in H1 2026 as losses stayed under $1 billion

Immunefi logs record 207 crypto hacks in H1 2026, losses at $972M Immunefi said 207 successful crypto attacks were recorded in H1 2026, the highest six-month total on record, but losses were about $972 million, less than half of H1 2025 and still below $1 billion. The data points to more frequent but less destructive hacks, with the median loss per incident falling from $6 million in 2022 to $1.5 million in 2025; smart contract exploits made up 125 of the 207 attacks.

Security

Singapore police and seven crypto platforms block over $4.2 million in potential scam losses

Singapore police and crypto exchanges stop $4.2M in potential scam losses The Singapore Police Force said a six-week operation with Coinbase, Coinhako, Gemini, Independent Reserve, OKX, StraitsX and Upbit identified more than 145 potential scam victims before they sent funds, preventing over $4.2 million in possible losses. Investigators used blockchain tools from Chainalysis and TRM Labs, then intervened by phone and in person with customer information provided by the exchanges.

July 11, 2026

Security

HKICL warns of fake FPS websites using cash rewards to harvest user and bank data

HKICL warns of fake FPS websites stealing user data Hong Kong Interbank Clearing Limited said it found multiple counterfeit websites posing as official FPS service providers and offering fake “Buyer Online Security Protection” to collect Hong Kong ID numbers, ID card photos, phone numbers, bank details and account names. The sites also promise cash rewards and route users into virtual wallet deposits or withdrawals; HKICL said they have no connection to its services and urged suspected victims to report cases to police.

Security

Bonzo Lend Pauses After $9 Million Borrowing Attack Linked to Hedera Oracle

Bonzo Lend loses about $9M in Hedera oracle exploit Bonzo Finance said an attacker borrowed roughly $9 million from its Bonzo Lend pool on Hedera on July 11 after manipulating a third-party SAUCE price oracle, while the protocol’s own contracts were not breached. The attacker used 250 SAUCE worth only a few dollars as collateral, inflated the oracle price by about 12 orders of magnitude, then borrowed about 6.6 million USDC and 34.5 million WHBAR; Bonzo Lend and its points program have been paused.

Security

Injective says no funds were at risk after backdoored npm packages exposed wallet secrets

Injective says no funds were compromised in npm supply-chain attack Attackers slipped wallet-key-stealing code into version 1.20.21 of Injective’s @injectivelabs/sdk-ts and 17 linked official npm packages, exposing any private keys or seed phrases processed during a brief release window. Injective said the issue was fixed within an hour and “no funds were ever at risk,” while security firms urged developers to upgrade to 1.20.23 and rotate any secrets touched by the compromised packages.

Security

Florida man says Wells Fargo impersonation scam drained $251,300 in life savings

Florida man loses $251,300 in Wells Fargo impersonation scam Randall Kahn of Florida lost his entire life savings after a caller posing as a Wells Fargo fraud representative convinced him to withdraw cash from nine branches over seven days and hand it to a rideshare driver, NBC 6 South Florida reported. Kahn said the caller cited supposed irregular account activity and provided what appeared to be legitimate employee and incident numbers; Wells Fargo later denied reimbursement, saying proper policies were followed in authorizing the transactions.

Security

Ledger discloses Tangem card flaw that allows password reset via laser attack

Ledger researchers reveal unpatchable Tangem card flaw Ledger’s Donjon team disclosed a hardware attack that can reset a Tangem wallet card’s password by hitting its secure element with a nanosecond laser pulse, bypassing a firmware recovery check. The attack was demonstrated on three cards and reported to Tangem on Feb. 10, but it requires physical possession, invasive prep, specialist skills and roughly $250,000 in lab equipment. Because cards already in circulation can’t receive firmware updates, the issue is unpatchable on existing devices.

Security

SecondFi breach may have exposed over 129 million ADA, researchers say

SecondFi hack losses may top 129M ADA, far above initial estimate SecondFi, the EMURGO-backed Cardano web wallet, initially said a flaw in its wallet-generation software led to the theft of about 16 million ADA, but SlowMist founder Yu Xian now says wallets tied to the attacker handled more than 129 million ADA plus other tokens, suggesting losses above $20 million. Blink Labs told users to treat SecondFi-created wallets as compromised and move assets to new wallets, while SecondFi asked users not to restore seed phrases elsewhere pending its review.