Security news

Showing 151–200 of 341
Clear filters

August 30, 2026

Security

Cronos Halts Network After Tectonic Breach Leaves Most Estimated $75M on Chain

Cronos halts blockchain after Tectonic exploit strands most of estimated $75M haul Cronos halted block production on Sunday after an attacker drained Tectonic, the network’s biggest lending protocol, in a breach researcher Weilin Li estimated at about $75 million. Li said roughly $6 million reached Ethereum while around $60 million remained stranded on Cronos after the freeze; Crypto.com CEO Kris Marszalek said the company’s app and exchange were not affected.

Security

Avici Users Lose $500,800 in Solana Card Exploit as AVICI Token Drops 49%

Avici card-funding exploit drains $500.8K from users, AVICI token tumbles A flaw in an outdated Rain contract led to a $1.1 million Solana exploit across multiple programs, including $500,800 taken from 1,685 Avici users. Avici said only card-funding contracts were affected, not its self-custodial wallets, and pledged full refunds; the breach sent AVICI down 49% from its 24-hour high to a record low of $0.217 before rebounding to $0.305.

August 29, 2026

Security

Polygon Reveals PoS Vulnerabilities Patched Through Austin and Kyoto Hard Forks

Polygon discloses patched PoS client vulnerabilities Polygon said it privately fixed several security flaws in its PoS network before disclosing them, using the Austin and Kyoto hard forks now active on mainnet. The issues affected Bor and Heimdall and included denial-of-service risks, validator resource exhaustion, and checkpoint processing flaws; Polygon said none were exploited on mainnet. Nodes on older versions have already fallen out of consensus and must upgrade to Bor v2.10.0 and Heimdall v0.11.0 to rejoin the canonical network.

Security

Core Lightning pushes node operators to install 26.06.7 after security review

Core Lightning issues emergency security update for node operators Core Lightning urged node operators to upgrade to version 26.06.7 after developers found several security vulnerabilities during a 10-day review that included AI-generated reports. The Aug. 28 release fixes verified issues, but technical details are under a two-week embargo, giving operators until mid-September to patch before the flaws are disclosed. Legacy versions 26.04 and older no longer receive security fixes.

Security

Fogo Foundation Reports 400 Million Token Theft as FOGO Falls About 20%

Fogo Foundation says attacker stole 400M FOGO tokens The Fogo Foundation said on Aug. 28 that an unidentified attacker compromised the organization and transferred out 400 million FOGO tokens, about 4% of the token’s 10 billion initial supply and more than 10% of circulating supply. FOGO fell about 20% to $0.00745 after the disclosure, while the foundation said the blockchain itself was not affected and it has asked exchanges, law enforcement and forensics firms to help trace and block the stolen funds.

Security

Ripple Maps Four-Stage Quantum Security Upgrade Path for XRP Ledger

Ripple lays out four-stage quantum security plan for XRP Ledger Ripple developers have outlined a four-stage plan to prepare the XRP Ledger for quantum-resistant cryptography as concerns grow over future threats to wallet and transaction security. The roadmap starts with identifying exposed parts of the network and testing replacement cryptography, then moves to running current and quantum-resistant security in parallel before broader migration, with an emergency path if quantum capabilities advance faster than expected.

August 28, 2026

Security

Avici attacker drains over $1 million from user accounts in live Solana exploit

Attacker drains over $1M from Solana neobank Avici An attacker drained more than $1.07 million from Avici customer accounts by bypassing the passkey-based authorization layer and adding a new admin to users’ collateral accounts before withdrawing funds, The Defiant reported. Avici acknowledged the incident at 18:42 UTC, nearly two hours after the first drain transaction, and said it is working with relevant partners, but has not said how many accounts were affected or whether users will be made whole.

Security

MANTRA post-mortem says Cosmos-EVM bug released 720.9 million tokens in August exploit

MANTRA says Aug. exploit released 720.9M tokens via Cosmos-EVM bug MANTRA Chain’s Aug. 28 post-mortem said an attacker exploited an unsigned-integer underflow bug in the shared cosmos/evm module, releasing about 720.9 million MANTRA worth roughly $3.6 million from a burn address and a legacy multisig on Aug. 20-21. MANTRA said no validator keys or multisigs were breached, no new tokens were minted, law enforcement is involved, and recovery updates are still pending.

Security

Core Lightning to Issue Embargoed v26.06.7 Security Release

Core Lightning plans embargoed v26.06.7 security release Christian Decker said Core Lightning will ship an embargoed v26.06.7 security release within about 24 hours, with binaries published immediately and source code withheld for 14 days to slow reverse-engineering. No vulnerability is known to be actively exploited. Operators who wait for source disclosure are advised to restart with the --offline flag, which keeps onchain enforcement while disabling peer connections.

Security

Kraken restores accounts after sanctioned crypto dust attack disrupted users

Kraken restores users after sanctioned crypto dust attack Kraken said some users were briefly locked out after receiving microtransactions tied to sanctioned funds between Aug. 17 and Aug. 24, in what it described as a dust attack meant to trigger account restrictions. The exchange restored access, froze the funds and is coordinating with authorities, while HTX said a review found no official accounts were behind the transfers and it is investigating whether the sending wallet was misidentified or used by a third party.

Security

Brazil advances crypto threat alert network for banks and exchanges

Brazil central bank advances crypto threat alert system for banks and exchanges Brazil’s central bank is moving to deploy a crypto threat alert system built with Hypernative to help banks and local exchanges detect, process and respond to cyberattacks that use crypto as an exit rail. ABToken executive director Regina Pedroso said integration should start within two weeks, with Foxbit and Mercado Bitcoin among the participants after tests with undisclosed firms.

Security

CCC exploit on BSC linked to sell() function abuse, with losses estimated at $117,000

CCC token hit by $117,000 exploit on BSC Blockchain security firm TenArmorAlert said CCC suffered an estimated $117,000 exploit on Aug. 28 after an attacker manipulated the token contract’s sell() function to burn tokens held by its liquidity pool pair, triggering abnormal price movement. The firm flagged an attack transaction starting with 0x89d805064, but had not disclosed the full attack sequence, recovery plan, or any compensation proposal at the time of the alert.

Security

The Sandbox Plans 1:1 Repayment After $700,000 SAND Bridge Exploit

The Sandbox to repay SAND holders 1:1 after $700,000 bridge exploit The Sandbox said it will reimburse eligible SAND holders on Base and BNB Chain with Ethereum-based SAND after an Aug. 21 exploit drained 14.744 million tokens, worth about $700,000, from an Ethereum vault. Claims are expected to open within two weeks and stay open for two weeks, with compensation funded from the treasury and no new tokens minted; two centralized exchanges holding more than 72% of eligible balances will pay affected customers directly.

Security

CoinGecko Report Says Audited Protocols Accounted for 88.44% of Crypto Hack Losses Since 2025

CoinGecko: audited protocols made up 88% of crypto hack losses since 2025 CoinGecko’s 2026 crypto security report found that protocols with independent audits accounted for 88.44% of the $3.63 billion stolen across 245 incidents tracked from January 2025 through July 2026. Auditors had cleared 147 of the breached platforms, while supply chain and infrastructure failures — not in-scope smart contract bugs — caused the biggest damage at more than $1.8 billion.

Security

Ledger disputes OneKey hack claim, says reproduced flaw had already been patched

Ledger says OneKey’s “hack” demo used an outdated Ethereum app Ledger pushed back on OneKey’s claim that it hacked a Ledger device, saying researchers reproduced a transaction-replacement flaw only on the old Ethereum app 1.22.1 and that the issue had already been patched in 1.22.2, with broader safeguards in Secure SDK 26.6.1. The flaw could let a compromised host show one transaction while getting another signed, but Ledger said it found no evidence of exploitation or losses and now recommends Ethereum app 1.22.3 or later.

August 27, 2026

Security

Tron Address Poisoning Scam Drains $9.4M From 15 Users in Four Weeks

Single Tron address poisoning scammer stole $9.4M from 15 victims in four weeks An address poisoning operator drained 15 Tron users of a combined $9.4 million over the past four weeks, on-chain investigator Specter said on August 27. The two biggest victims lost $2.5 million each, and the stolen funds were swapped into USDD and funneled to one consolidation wallet. MetaMask and Trust Wallet have added protections for this scam on EVM chains, but those features do not work on Tron.

Security

Coinspect Says Predictable Wallet Seed Phrases Enabled at Least $5.69M in Crypto Theft

Coinspect links wallet flaw to at least $5.69M in crypto theft Blockchain security firm Coinspect said a weakness in the CryptoJS library’s random number generator made seed phrases in at least five wallet apps predictable, exposing more than 2,000 recovery phrases across five blockchain networks. It tracked about $3.14 million stolen on May 27 and another $2.55 million drained between May 30 and July 13, with a further roughly $40,000 taken on July 20-21; the apps involved and full losses are still unconfirmed.

Security

Moonwell Restricts Base Borrowing After $8.7 Million Price Manipulation Exploit

Moonwell freezes borrowing after $8.7M Base exploit Moonwell cut borrow caps across all Base Core Markets to 1 wei after an attacker manipulated the price of thinly traded MAMO collateral and borrowed out real assets including cbBTC and USDC. Blockaid first estimated 50.6 cbBTC, worth more than $4 million, was drained from the mCBTC market, while PeckShield later put total losses at $8.7 million.

Security

FBI Seizes Domains Linked to QScan and QTRouter in U.S. Cyber Disruption

FBI seizes domains tied to alleged Chinese state-backed hacking tools U.S. authorities on Aug. 26 took offline QScan and QTRouter by seizing three domains hard-coded into the platforms, which the Justice Department said were used to target networks at NASA, the Federal Reserve, the Energy Department, HHS, NIH and the U.S. Senate. Court records attribute the tools to QTFY, a group allegedly linked to Nanjing Xinjiuwei Network Technology Company, and say the platforms helped find vulnerable devices and mask the origin of attacks.

Security

Core Lightning Urges Node Operators to Go Offline Before Emergency Security Update

Core Lightning urges node operators to shut down ahead of emergency fix Core Lightning maintainers said several vulnerabilities were found in Blockstream’s CLN implementation after AI-based CVE reports disclosed the issues, and urged node runners to take current versions offline and install an emergency update when signed binaries are released. The team said it aims to ship a fix within 48 hours and make full disclosure within two weeks, adding there were no reports of fund losses or active exploitation at the time.

August 26, 2026

Security

Kraken Restores Accounts After 12,000 Unsolicited Transfers Linked to HTX-Labeled Wallet

Kraken restores accounts hit by HTX-linked microtransfer reviews Kraken restored customer accounts it had temporarily restricted after nearly 12,000 unsolicited crypto transfers hit addresses linked to the exchange between Aug. 17 and 24. The disputed funds remain segregated due to their reported ties to sanctioned wallets; Arkham Intelligence labeled the sending wallet as connected to HTX, while HTX denied involvement and said it is investigating possible labeling errors or third-party actions.

August 25, 2026

Security

Cosmos Labs Urges Some EVM Chains to Halt After KiiChain, TAC and MANTRA Incidents

Cosmos Labs urges affected EVM chains to halt over security incident Cosmos Labs has told affected networks in contact with its team to suspend operations during an ongoing Cosmos EVM security incident, after KiiChain, TAC and MANTRA linked recent attacks to shared EVM infrastructure flaws. KiiChain said 148,326,583.15 KII was drained on Aug. 22 before it halted the chain, while TAC said an exploit moved 2,985,651,403 TAC; Cosmos Labs has not publicly confirmed whether all incidents came from one flaw.

Security

Kraken Says HTX-Linked Dust Transfers Temporarily Triggered Customer Account Locks

Kraken restores accounts after alleged HTX-linked dust attack Kraken said it briefly locked some customer accounts after wallets it identified as linked to HTX sent about 12,000 tiny transfers to Kraken-related addresses between Aug. 17 and Aug. 24. The exchange called it a dust attack aimed at tripping AML controls by placing U.K.- and EU-sanctioned funds into user accounts; access has since been restored, while the sanctioned funds remain frozen and Kraken says it is working with authorities.

Security

Socket ties 77 Firefox extension identities to crypto wallet theft campaign

Socket links 77 Firefox add-ons to crypto wallet theft campaign Security firm Socket says a campaign it calls the Offside Wallet Theft Factory used 77 Firefox extension identities, with 40 confirmed malicious, to impersonate OKX, Rabby Wallet, TronLink and other Web3 tools and steal recovery phrases or private keys. Some were modified Rabby builds that exfiltrated stored data, credentials and clipboard contents, while nine sports-score apps were later updated into wallet stealers to exploit existing installs.

Security

Chainalysis Operation Lighthouse Generated 14,300 CSAM Investigation Leads

Chainalysis-led CSAM crypto sweep identifies suspects in 125 countries Chainalysis said its multi-day Operation Lighthouse sprint with more than nine law enforcement agencies, 13 private-sector partners and non-profits generated 14,300 investigative leads, flagged 7,700+ suspect accounts, and identified CSAM-linked suspects in 125 countries. The operation reviewed 29,120 crypto addresses and digital identifiers tied to more than 100 suspected CSAM platforms and networks.

Security

Term Labs governance takeover drained $8.5M after attacker spent about $951

Term Labs governance takeover drains $8.5M from strategy vaults An attacker spent about $951 to buy a controlling stake in Term Labs’ governance token, passed malicious proposals on Aug. 23, 2026, and drained roughly $8.5 million from strategy vaults. The haul included 2,843 ETH and 1.68 million USDC, later swapped for about 1.6 million DAI. Term Labs shut all Meta Vault deposits and revoked DAO governance roles, while keeping withdrawals open.

Security

Cosmos Labs urges Cosmos EVM chains to halt after attacks hit multiple networks

Cosmos Labs urges Cosmos EVM chains to halt after attacks hit MANTRA, TAC and KiiChain Cosmos Labs told affected Cosmos EVM chains on Aug. 25 to coordinate validator halts as it responds to a security incident that has already hit MANTRA, TAC and KiiChain. KiiChain said 148.3 million KII were drained on Aug. 22 before validators stopped the network, while TAC said one account was drained and MANTRA said no user funds were affected. Cosmos Labs has not yet published the root cause or total losses and is preparing a patch and restart guidance.

August 24, 2026

Security

TAC Protocol Rebounds After Exploit, Says Shared Cosmos EVM Code Was at Fault

TAC says exploit came from shared Cosmos EVM code, not its own chain TAC Protocol said the August 22 exploit that forced validators to halt the chain was caused by a vulnerability in the shared Cosmos EVM precompile layer, not TAC’s own code. The attacker drained a single account before transactions were stopped at block 24,671,475, and TAC said only the native $TAC token was stolen. The token has since rebounded about 53% from its all-time low, but remains roughly 97% below its June 30 peak.

Security

Fake Google ad for Hyperliquid linked to Inferno drainer in $550,000 USDC theft

Hyperliquid user loses $550,000 USDC in phishing attack tied to Inferno drainer A Hyperliquid user lost about 550,019 USDC after clicking a Google sponsored ad that led to a fake version of the trading platform, while Salus linked the theft infrastructure to the Inferno drainer ecosystem. Salus said the phishing group bought the ad and spoofed the site, while the backend service handled the drain and automatically split proceeds, with one address receiving 80%.

Security

Sandbox bridge exploit minted 329 trillion fake SAND on Base, but losses stayed near $675,000

Sandbox exploit mints 329T fake SAND on Base, drains about $675,000 An attacker abused the approveAndCall function in The Sandbox’s SAND omnichain token on Base to seize LayerZero delegate permissions and mint 329.24 trillion unbacked SAND across 703 events on Aug. 21-22. Despite a nominal face value near $49 billion, the attacker extracted about 14.75 million SAND from the Ethereum OFT Adapter and converted it to roughly 80 ETH, or around $675,000, before Sandbox disabled bridging on Base and BNB Smart Chain.

Security

Besu Discloses Five Fixed Security Flaws After Releasing Urgent Node Update

Besu fixes five security flaws in Ethereum client update 26.7.1 Ethereum client Besu said five security vulnerabilities found by Certik were fixed in version 26.7.1, released July 27, with detailed advisories published on Aug. 14. Certik said the delayed disclosure was intentional: releasing the patch first gave node operators time to upgrade before attack details became public. The flaws could have let attackers exhaust node memory or threads, affecting availability and consensus processing.

Security

Term Finance Shuts Meta Vaults After Estimated $8.5 Million Governance Exploit

Term Finance closes Meta Vaults after $8.5M governance exploit Term Labs permanently closed its Term Meta Vaults after an attacker allegedly used majority control of a thinly held governance token to seize the strategy vaults and drain about $8.5 million, including 2,843 ETH and 1.68 million USDC swapped to DAI. The loss was roughly 68% of the vault product’s $12.45 million pre-attack holdings; deposits are now blocked, withdrawals remain open, and Term said its core borrowing and lending markets were unaffected.

Security

Estonia Revokes Zondacrypto License as Missing Executives and Frozen Funds Deepen Crisis

Estonia revokes Zondacrypto license as users stay locked out of funds Estonia’s Financial Intelligence Unit revoked BB Trade Estonia OÜ’s license on June 29, effectively shutting down Zondacrypto days before the EU’s July 1 MiCA deadline, while customers remained unable to access deposits and the platform had been offline since April. Recoveris said the exchange’s main Bitcoin hot wallet fell 99.7% to 0.086 BTC by April 1 and traced about $21 million sent to Kraken; Polish prosecutors have since folded the case into an organized-crime probe.

August 23, 2026

Security

Term Labs Says Governance Attack Drained About $8.5M From Term Finance Vaults

Term Labs says governance exploit drained $8.5M from Term Finance vaults Term Labs said a governance exploit hit several Term Finance vaults, with initial data showing the attacker used protocol rules rather than a code bug to withdraw about $8.5M in ETH and DAI. On-chain data cited in the report shows the attacker controlled four of the five drained vaults after converting share tokens into governance tokens, then used an Aug. 17 proposal and a six-day delay to change vault parameters and move the funds.

August 22, 2026

Security

MANTRA Chain Restarts Mainnet After 30-Hour Halt Triggered by Cosmos-EVM Flaw

MANTRA Chain restarts after 30-hour mainnet halt MANTRA Chain resumed block production around 5:30 a.m. UTC on Aug. 22 after deploying v8.4.0 to patch a Cosmos-EVM vulnerability that had halted mainnet transaction processing for about 30 hours. The team said two MANTRA-managed wallets were affected, but user balances were unchanged, no rollback was needed, and token holders did not need to take action.

Security

BounceBit to End Standalone Layer 1 and Move BB to BNB Chain After $3M Exploit

BounceBit to shut standalone Layer 1 after $3M BB token exploit BounceBit said it will wind down its standalone Evmos-based Layer 1 and migrate BB to BNB Chain after an attacker exploited an authorization flaw to move about 286.5 million BB tokens, worth roughly $3 million, across nine wallets. The team halted block production about 40 minutes after detecting the attack and said it will use a pre-attack snapshot to reverse unauthorized transfers and work with exchanges to restore customer balances.

Security

Two Binance Employees Detained at UAE Airports During Fraud Inquiry

UAE police briefly detained Binance staff in fraud probe Police in the United Arab Emirates stopped two Binance employees at airports and questioned a third in July as part of a fraud inquiry into funds moving through the exchange. All three were released, and Binance said the staff were asked for standard statements in routine inquiries tied to third-party fund flows, were not targets, and were promptly cleared.

August 21, 2026

Security

Coinkite Issues Coldcard Firmware Overhaul After Seed Flaw Linked to $100M in Bitcoin Theft

Coinkite pushes Coldcard security overhaul after seed flaw tied to $100M+ thefts Coinkite has released new firmware for Coldcard Mk4, Mk5 and Q wallets after a seed-generation flaw was linked to more than $100 million in stolen Bitcoin, and urged users to upgrade to 5.6.1 or 1.5.1Q. The update fixes issues in signing, USB data handling, firmware validation, Delta Mode and backups, and now requires users to add entropy when creating a seed with at least 65 key presses, 50 dice rolls or 128 coin flips. Users whose seeds were generated on affected versions between 2021 and July 2026 are being told to create a new seed on the updated firmware and move their BTC, while Coinkite said the thefts,

Security

India tells Google to shut down Firebase accounts linked to banking scam networks

India orders Google to remove Firebase accounts tied to banking scams India’s cybercrime agency I4C sent Google at least three notices in August seeking the shutdown of hundreds of Firebase accounts after tracing 57 Firebase-hosted websites and databases to fake banking apps and phishing operations. The notices said seven pages mimicked SBI, ICICI Bank and Axis Bank login screens, while other Firebase databases collected stolen card details, one-time passwords and malware data.

Security

BounceBit to retire its chain after $3.1 million BB token exploit

BounceBit to shut down chain after $3.1M BB token exploit BounceBit said it is sunsetting BounceBit Chain after hackers exploited an authorization flaw in an Evmos-based vesting and lockup module, moving 286 million BB tokens from nine wallets between Aug. 19 and 20. The firm said it cannot safely upgrade the discontinued Evmos infrastructure, so non-attacker balances will be reissued as BEP-20 BB on BNB Chain using a pre-exploit snapshot.

Security

Besu discloses five patched security flaws addressed in Ethereum client version 26.7.1

Besu details five patched security flaws in Ethereum client 26.7.1 Besu published advisories on Aug. 14 for five vulnerabilities privately reported by CertiK and fixed in version 26.7.1, released July 27. The flaws affected the Java-based Ethereum client’s peer-to-peer, RPC, WebSocket and consensus-facing interfaces and, in affected configurations, could exhaust memory or threads, disrupting node availability or consensus processing.

Security

USENIX Research Raises Phishing Concerns Around Ethereum’s EIP-7702 Delegation

USENIX research flags abuse risks in Ethereum’s EIP-7702 delegation Security research presented at the USENIX Security Symposium linked 63% of analyzed EIP-7702 authorization transactions to attacker-controlled contracts and identified more than $2.3 million in confirmed thefts from automated wallet-draining activity. The researchers did not describe a core Ethereum protocol bug; the risk is users being tricked into signing malicious wallet delegation authorizations.

Security

Check Point says 2,000 hacked WordPress sites were used to target crypto users

Check Point links StopAndProtect to 2,000 hacked WordPress sites Check Point Research said a group it calls StopAndProtect has turned nearly 2,000 poorly maintained WordPress sites into a malware network that steals crypto wallet seeds, passwords and files from Windows PCs via fake CAPTCHA pages. Logs from the attackers’ own exposed servers showed more than 6,000 unique IP infections by July 24, over 700 archives of stolen files and 20,000-plus victim screenshots.

Security

MANTRA Chain Pauses Network and Freezes Transactions After Unexplained Incident

MANTRA Chain halts network and freezes all transactions after incident MANTRA Chain has halted its network and frozen all transactions and endpoints after what the team called an incident affecting the chain. The disruption has hit deposits and withdrawals, and MANTRA asked exchanges and ecosystem partners to suspend trading in its native token while engineering and security teams investigate with external partners. No cause or recovery timeline has been disclosed.

August 20, 2026

Security

Fake AML screening sites use wallet approvals to steal crypto, researchers warn

Fake crypto AML checker sites trick users into wallet-draining approvals Malwarebytes says fraudulent anti-money laundering screening sites are impersonating services like AMLBot and prompting users to connect a wallet, sign a transaction, or pay a small “fee” to see a fake compliance result. Genuine wallet screening only requires a public address, not wallet connection or signing. Researchers found the same scam kit being rebranded under different names and logos.

Security

Check Point Links StopAndProtect Malware Campaign to Nearly 2,000 Hacked WordPress Sites

StopAndProtect hit 6,000+ IPs via hacked WordPress sites, Check Point says Check Point Research says the StopAndProtect operation used nearly 2,000 compromised WordPress sites to infect Windows users with fake CAPTCHA prompts that triggered PowerShell malware, stealing passwords, seed phrases and crypto wallet files, then spreading through networks and USB drives before locking screens or deploying ransomware. By July 24, researchers linked the campaign to more than 6,000 IPs and found 700+ archives of stolen data and 31,000+ victim screenshots exposed by the attackers’ own security mistakes.

Security

Rapid7 says crypto phishing campaign targeted 885,000 phone numbers across multiple markets

Rapid7 identifies crypto phishing campaign targeting 885,000 phone numbers Rapid7 said a phishing operation it calls Operation Asterix targeted about 885,000 phone numbers across several countries, using fake wallet-provider sites and support messages to steal crypto. The campaign matched 5,576 accounts to Binance users and impersonated Crypto.com, Ledger, Trezor, and Exodus; Rapid7 said about 13% of targeted accounts were hit and AI tools were a significant part of the operation.

Security

Binance Says It Helped Block $1.2 Million DAO Treasury Governance Attack

Binance says it helped stop $1.2M DAO treasury attack before execution Binance said on Aug. 18 that its monitoring team detected a malicious governance proposal targeting an unnamed DAO and, with less than 48 hours before execution, warned the project and coordinated with exchanges to close token deposits. The proposal was then voted down, blocking access to about $1.2 million in treasury tokens, while Binance did not name the project or token involved.

August 19, 2026

Security

Decred Issues Mandatory v2.1.6 Update to Fix Consensus, Mixing, and DoS Flaws

Decred releases mandatory v2.1.6 patch for consensus and mixing flaws Decred has issued a mandatory v2.1.6 update to fix a critical consensus vulnerability, a potential periodic deanonymization attack in its transaction mixing system, and several network DoS risks. The patch updates the mixclient protocol, changes how mixing sessions expire, and requires all users to upgrade to avoid running on a forked network; older dcrwallet clients will no longer mix with updated wallets.

Security

Maya Protocol pauses network after exploit drains an estimated $1.7 million

Maya Protocol halts network after exploit drains $1.7 million Maya Protocol paused its network after an attacker exploited six chained software bugs to steal about $1.7 million, including roughly 20 BTC and $300,000 in other assets, co-founder Aalux said. A preliminary analysis said a single 23-message transaction withdrew 48.87 million CACAO and helped crash the token 88.7% from about $0.115 to $0.013, while the team works on a fix to resume swaps.