Security news

Showing 251–300 of 341
Clear filters

August 3, 2026

Security

Hong Kong insurance agent loses HK$26 million in romance-linked crypto investment scam

Hong Kong agent loses HK$26 million in romance-linked crypto scam A Hong Kong insurance agent lost more than HK$26 million after scammers used an online romance over about six months to steer him into a fake crypto platform, police said. The victim handed over more than HK$4 million in cash and transferred nearly HK$22 million before suspecting fraud when the app showed 800% returns and blocked withdrawals. Between July 24 and July 30, police logged 25 similar reports with nearly HK$70 million in losses.

Security

Crypto Exploits Reached Record $1.1 Billion in First Half, Blockaid Says

Crypto exploits hit record $1.1B in H1, with North Korea-linked groups blamed for 55% Hackers stole a record $1.1 billion from crypto protocols in 212 onchain exploits in the first half of the year, Blockaid said, with North Korea-linked groups tied to $609 million, or 55% of losses. Ethereum and Solana saw the biggest network losses at about $332 million and $326 million, while operational security failures, including privileged key misuse, drove roughly $790 million in damages.

Security

South Korean Police Arrest Three in Alleged $9 Million Fake XRP Staking Fraud

South Korea arrests 3 in alleged fake XRP staking fraud South Korean police arrested three suspects linked to alleged fake XRP staking site Fxrpntwork.com, which reportedly took 3.4 million XRP, worth about $9 million, from 71 investors. Authorities said they also froze 17.3 billion won in digital assets on overseas exchanges. The case remains under investigation, and the arrests do not amount to convictions.

Security

xrpld 3.2.1 Stays Current as 3.3.0 Milestone Builds Broader XRPL Changes

xrpld 3.2.1 ships security fix as 3.3.0 queues broader XRPL changes xrpld 3.2.1 remains the latest XRP Ledger release as of Aug. 1, 2026, focusing on validator security by fixing manifest propagation issues and reducing risks from untrusted peer messages. The unreleased 3.3.0 milestone lists 122 items, including BatchV1_1 for grouped transactions with corrected inner-signature validation, while ConfidentialTransfer and Sponsored Fees remain in development and inactive.

August 2, 2026

Security

Ukraine Police Allege Fake Crypto Academy Defrauded Nearly 1,000 People of $1.1 Million

Ukraine police say fake crypto academy stole $1.1M from nearly 1,000 people Ukraine’s National Police said it dismantled a criminal group that posed as a crypto investing school and defrauded nearly 1,000 victims of more than $1.1 million. Investigators say people were persuaded to send money to controlled crypto wallets and a fake investment platform; suspects face up to 12 years in prison with confiscation of property.

August 1, 2026

Security

Blockaid Says Crypto Exploits Reached $1.1 Billion Across 212 Incidents in H1 2026

Blockaid: Crypto exploits hit record $1.1B in H1 2026 Hackers stole $1.1 billion across 212 crypto incidents in the first half of 2026, making it the most active six-month period on record, Blockaid said. KelpDAO’s $292 million loss and Drift’s $285 million exploit drove much of the damage, and Blockaid linked both, along with Humanity Protocol’s $32 million loss, to TraderTraitor, a North Korean subset of Lazarus, putting DPRK-linked thefts at $609 million, or 55% of the total.

Security

Hong Kong Reports HK$70 Million in One Week of Romance-Linked Crypto Investment Scams

Hong Kong logs HK$70M in romance-linked crypto investment scams in one week Hong Kong police recorded 25 investment fraud cases tied to online romantic relationships in the week ending July 30, with combined losses nearing HK$70 million ($9 million). The biggest case involved a 50-year-old insurance professional who reportedly lost about HK$26 million ($3.3 million) after an online partner posing as a car dealer steered her to a fake virtual asset platform that showed fabricated gains before blocking withdrawals.

Security

trade.xyz begins payouts after SK hynix price shock triggered Hyperliquid liquidations

trade.xyz starts refunds after SK Hynix perp crash on Hyperliquid trade.xyz said Aug. 1 it has begun reimbursing traders after an anomalous SK hynix pre-market print in South Korea pushed its Hyperliquid perpetual mark price down 18.7% on July 27, triggering roughly $60 million in long liquidations across about 960 accounts. Losses under $10,000 are being refunded automatically, while larger claims require an application; trade.xyz called the payouts a one-time discretionary decision.

July 31, 2026

Security

SecondFi Renews Bounty as It Pursues Recovery After 16.1M ADA Exploit

SecondFi renews bounty after 16.1M ADA exploit SecondFi has renewed its bounty offer to recover 16.1 million ADA stolen in a June exploit that affected 374 wallets. The team said the breach stemmed from a key-generation vulnerability and that it secured 129 million ADA during containment, but confirmed normal operations will not resume. Groom Lake researchers reportedly saw behavior resembling Lazarus Group techniques, though attribution remains unconfirmed.

Security

Swan Treasury loses about $625,000 after signer key leak on BNB Chain

Swan Treasury loses $625,000 after signer key compromise on BNB Chain Attackers used a leaked off-chain signer key to forge valid signatures and buy about 687,000 STY at roughly a 100x discount on BNB Chain, then sold the tokens for an estimated $625,000 profit, Defimon Alerts said. The firm said the exploit stemmed from the protocol’s compromised hardcoded signer key, not a flaw in its signature verification logic.

Security

AFX to release Aug. 3 user goodwill plan after $24.15M bridge exploit

AFX to unveil user recovery plan after $24.15M bridge exploit AFX said it has prepared a goodwill plan for users hit by last week’s $24.15 million bridge exploit and will release the proposal on Aug. 3. Its post-mortem blamed a supply-chain attack that began with social engineering against a developer and ended with validators co-signing a bridge transaction that drained about $24.15 million USDC; Arbitrum’s native bridge and network were not affected.

Security

Coinkite warns Coldcard Mk3 users after reports of 594 BTC moving from dormant wallets

Coinkite warns some Coldcard Mk3 wallets may be at risk Coinkite issued a security advisory for Coldcard Mk3 users after reports that about 594 BTC, worth roughly $38 million, moved from around 500 long-dormant single-signature wallets on July 30. The company said anyone who generated a seed on Mk3 firmware 4.0.1 through 5.0.3 may be affected, while Mk4, Q and Mk5 appear unaffected; it has not confirmed a root cause or a direct link to the transfers.

July 30, 2026

Security

South Korea Arrests Three Over Fake FXRP Platform That Took $8.6M in XRP

South Korea arrests suspects in fake FXRP scam targeting XRP holders South Korean authorities arrested three men over a fake FXRP investment platform that collected about 3.4 million XRP, worth roughly $8.6 million, from 71 victims before vanishing after just over a week. Police said the probe began after an overseas exchange flagged suspicious transactions, and investigators froze about $12.1 million on foreign exchanges within three days; two suspected organizers face aggravated fraud charges, while another suspect remains overseas under an international alert.

Security

Zcash Developers Say ZEC Supply Can Be Verified Locally Ahead of Ironwood

Zcash says ZEC supply can already be verified locally Zcash developers said users do not need to wait for the Ironwood migration from Orchard to confirm the coin’s supply, after questions over an Orchard vulnerability and possible hidden inflation. Co-founder Zooko said anyone running a fully synced node can verify the current supply of 16,848,458 ZEC locally, while Ironwood will cap Orchard withdrawals through a turnstile that records each withdrawal against prior deposits.

Security

Ostium says off-chain breach, not smart contract flaw, caused $23.75M USDC exploit

Ostium says July exploit came from off-chain breach, not smart contracts Ostium said its July exploit was caused by compromised off-chain infrastructure that let an attacker manipulate price reports and drain 23.75 million USDC from the OLP liquidity vault, not by a flaw in its smart contracts or governance multisigs. The team said a 100 USDC test trade generated about 897.8 USDC in fake profit before larger exploit cycles followed; trading resumed on July 23 after a migration to a new production environment.

July 29, 2026

Security

MCBS healthcare vendor breach may have exposed data of 1.26 million Americans

MCBS breach may have exposed data on 1.26 million Americans Medical Computer Business Services, a third-party vendor for hospitals and medical practices, said hackers accessed its network between Sept. 22 and Sept. 26, 2025, potentially compromising the personal and medical data of 1,261,464 people. The incident is listed by the U.S. Department of Health and Human Services as a hacking/IT breach, and MCBS says it notified affected individuals and is offering identity protection services.

Security

CFA Puts Estimated US Crypto Scam Losses at $80.7 Billion in 2025

CFA estimates US crypto scam losses hit $80.7B in 2025 The Consumer Federation of America said Americans lost an estimated $80.7 billion to crypto scams in 2025, versus $11.37 billion reported to the FBI, by applying a 7.1x multiplier based on a 2017 survey that found only 14% of fraud victims report cases to law enforcement. Crypto made up more than half of all scam and cybercrime losses, with investment fraud the biggest category at an estimated $61.4 billion.

Security

Blockaid says crypto losses hit $1.1B in H1 2026 as key compromises dominate

Blockaid: Crypto hacks hit $1.1B in H1 2026 as key compromises overtake code bugs Verified on-chain crypto security losses reached $1.1 billion across 212 incidents in H1 2026, Blockaid said in a July 28 report, with 74% of losses tied to compromised devices, private keys, signing systems and other off-chain infrastructure rather than smart-contract flaws. One DPRK-linked cluster accounted for about 55% of losses, while the incident count was 3.4x all of 2025.

July 28, 2026

Security

SparkKitty malware removed from App Store and Google Play after targeting wallet seed photos

SparkKitty malware found in App Store and Google Play apps Researchers say SparkKitty targeted crypto users on iOS and Android by abusing photo library access to scan images for 12-word and 24-word wallet recovery phrases with OCR, then sending the data to attacker-controlled servers. Apple and Google removed infected apps, including SOEX and other coin-related apps, after some drew thousands of downloads.

Security

Ukraine Police Say Fake Crypto Academy Defrauded 988 People of $1.11 Million

Ukraine police detain four in fake crypto academy fraud case Ukraine’s National Police said it dismantled a criminal group that allegedly posed as the “Ukrainian Financial Academy” and defrauded 988 people of about $1.11 million through controlled bank accounts, crypto wallets and a fake investment platform. Investigators detained four key suspects after searches in the Kharkiv and Dnipropetrovsk regions; they are in pretrial detention and face up to 12 years in prison with confiscation of property if convicted.

Security

CertiK says crypto wrench attacks rose 33% in H1 2026, with France at the center

Crypto wrench attacks jump 33% in H1 2026, with France the main hotspot CertiK recorded 52 wrench attacks in the first half of 2026, up 33.3% from a year earlier, while associated financial exposure surged to $124.18 million from about $10.5 million. France accounted for 33 of the 52 cases, which CertiK linked to the country’s visible crypto ecosystem and recent data breaches that may help criminals identify targets.

Security

Hong Kong sets 2030 quantum-security goal for banks as tokenization grows

HKMA sets 2030 quantum-security target for Hong Kong banks Hong Kong’s banking regulator has launched a quantum-risk framework and its first Quantum Preparedness Index as tokenized finance expands, with the sector scoring just 2.3 out of 10 and about half of surveyed institutions reporting no formal post-quantum plan. The HKMA wants full readiness by 2030, warning that tokenized deposits, digital assets and blockchain settlement rely on cryptography that could be broken by future quantum computers.

July 27, 2026

Security

Zcash’s Ironwood Upgrade to Lock Orchard Pool at Block 3,428,143

Zcash to lock Orchard pool in Ironwood upgrade on Tuesday Zcash’s Ironwood upgrade will lock the Orchard shielded pool at block 3,428,143 on Tuesday, preventing any new funds from entering a pool that holds 3.76 million ZEC, worth about $1.89 billion, or roughly 22% of supply. Holders’ coins remain safe and can only move out, as the change is designed to contain any undetected counterfeit ZEC after a May bug that could have allowed fake coin creation.

Security

SecondFi outlines ADA refund plan after 16.1 million token hack and shutdown

SecondFi to shut down after hack, launch ZK-based ADA refund tool SecondFi has published a recovery plan after hackers stole 16.1 million ADA from 374 wallets in June 2026 via an Android app vulnerability. The Cardano wallet said it is permanently ending normal operations and will focus on withdrawing remaining assets and compensating users, using what it calls Web3’s first zero-knowledge proof-based refund tool built with Input Output Group and the Cardano Foundation.

Security

SparkKitty malware found in App Store and Google Play apps targeting crypto users

SparkKitty malware found on Apple App Store and Google Play Check Point says the SparkKitty malware targeted crypto users through apps on Apple’s App Store, Google Play and third-party Android stores, using OCR to scan photos for wallet recovery phrases. It was embedded in the iOS app Bcoin and the Android app SOEX, which was downloaded more than 10,000 times before removal; stolen seed phrases, passwords and QR data were sent to hacker-controlled servers.

Security

BlueNoroff Uses Fake Video Meetings to Hunt Crypto Wallet Holders

BlueNoroff uses fake Zoom and Teams calls to target crypto wallet holders North Korean hacking group BlueNoroff is luring wealthy crypto users into fake Zoom and Microsoft Teams meetings, then checking their browsers for MetaMask and Solana wallets before selectively deploying malware, Cryptopoli reported. Victims are told their microphone is not working and prompted to install fake software, while hacked Telegram and LinkedIn accounts are also used as bait. Arctic Wolf estimated the campaign has hit more than 100 victims in over 20 countries.

Security

Triple-A says it can cover losses after treasury wallet breach and resumes normal operations

Triple-A confirms treasury wallet breach, says client funds were not affected Singapore-based payments firm Triple-A said unauthorized access to certain treasury wallets on July 25 led to the loss of company-owned digital assets, while client funds and payment operations were not affected. The company briefly put some services into maintenance mode for about three hours, said normal operations have resumed, and said the impact will be absorbed through treasury reserves; on-chain investigators had estimated the loss at about $11.8 million.

Security

Garden Finance takes app offline after Blockaid flags $450,000 HTLC exploit

Garden Finance takes app offline after $450,000 HTLC exploit alert Garden Finance temporarily took its app offline after Blockaid reported an ongoing exploit targeting the protocol’s hash time-locked contracts on Ethereum, Base, Arbitrum and BNB Smart Chain, with about $450,000 in USDT drained. Garden said it detected “unusual activity” and is conducting a full investigation, while Blockaid did not disclose the suspected vulnerability or whether user funds were affected.

July 26, 2026

Security

WEMIX suspends bridges and LP trading after $724,198 contract breach

WEMIX halts bridges and LP trading after stablecoin-linked contract exploit WEMIX suspended all WEMIX3.0-connected bridges, affected liquidity-pool trading and several services after an attacker took control of a contract linked to its WEMIX$ stablecoin and moved 724,198.27 USDC.e on Sunday at 9:17 UTC. WEMIX said the attacker minted about 5.23 million WEMIX$, swapped it into 30,736 WEMIX and USDC.e, then bridged funds to Ethereum and BNB Smart Chain; some exchange-linked addresses have already been frozen while the full impact remains under investigation.

Security

Zcash Eyes Key Resistance as Traders Watch Wedge Pattern Ahead of Ironwood Upgrade

Zcash set for Ironwood upgrade on July 28 after critical Orchard flaw Zcash is preparing the Ironwood network upgrade, or NU6.3, for July 28 at block 3,428,143 to retire the current Orchard shielded pool and launch a new pool with a corrected circuit after a critical vulnerability was found. The change is aimed at strengthening network security and helping determine whether the flaw was ever exploited.

Security

Coinbase launches Bitcoin consortium with $15M to prepare for future quantum risks

Coinbase forms Bitcoin quantum security consortium with $15M funding Coinbase unveiled a post-quantum security plan for Bitcoin and launched the Bitcoin Security Consortium with BlackRock, Fidelity Digital Assets, Block, Strategy, Anchorage Digital, ARK Invest, Blockstream and Galaxy, which committed $15 million over three years for developers and researchers. CEO Brian Armstrong said quantum computing is not an immediate threat, but Coinbase has already begun upgrading its custody and key management systems ahead of any migration.

Security

FBI alleges malware hidden in eight games led to theft from 80 crypto wallets

FBI says malware in eight video games stole at least $220,000 in crypto Federal investigators allege malware hidden in eight downloadable games infected about 8,000 devices, harvested credentials and led to at least $220,000 being taken from roughly 80 cryptocurrency wallets. Court filings say the campaign used Discord, Telegram, X and LinkedIn to target crypto holders, and the FBI is now seeking potential victims as the case against Wilkins moves forward.

July 25, 2026

Security

Across relayer loses less than $4M after fake Solana deposits trigger payouts

Across says a Risk Labs-operated relayer lost under $4 million in a July 17 Solana attack after an attacker forged 1,627 fake deposit events worth $41.7 million. The relayer paid out about $4.5 million across 581 requests before Solana operations were halted, while roughly $500,000 of the attacker’s funds remained trapped, cutting the net loss below $4 million. Across said user funds were unaffected and Solana transfers resumed via Circle’s CCTP.

Security

Optimism says critical pre-Lagoon refund bug was fixed before any production exploitation

Optimism discloses patched critical pre-Lagoon refund bug Optimism said a critical vulnerability in its pre-Lagoon SDM verify path could accept forged refund payloads without recomputation, creating a risk in refund verification. The issue was disclosed on the governance forum after being patched before the Lagoon upgrade reached any production chain, and Optimism says no funds were lost.

Security

Australian police say AI is fueling fake crypto investment scams as losses top $31.4 million

Australian police warn AI is powering fake crypto investment ecosystems The AFP-led JPC3 said transnational criminal networks are using AI to build end-to-end scam operations, including fake trading platforms, news articles, landing pages and chatbots, as losses from investment scams in Australia topped $31.4 million so far this year. The warning came as JPC3 expanded its national “Clickfit” campaign urging people to scrutinize online investment offers before sending money.

Security

OKX says crypto incidents jumped 50% in H1 2026 while disclosed losses fell to $956 million

OKX: Crypto security incidents rose 50% in H1 2026 as losses fell to $956M OKX’s H1 2026 Web3 security report, produced with SlowMist and OtterSec, logged 182 publicly disclosed incidents with $956 million in losses, up 50% in case count from H1 2025 but down about 60% in value. The report says attackers shifted from major smart contract exploits toward supply-chain breaches, social engineering, cloud key theft, single-point failures and AI-driven attacks, making users and AI agents the main targets.

July 24, 2026

Security

Kenya Freezes $888,030 in Cash and USDT in Expanding Alleged Laundering Probe

Kenya freezes $888,030 in cash and USDT in alleged laundering probe Kenya’s Assets Recovery Agency has frozen at least $888,030 in cash and USDT tied to two residents in an alleged money-laundering scheme that investigators say moved more than $2.32 million through shell firms, bank accounts, remittance services and crypto wallets. The ARA said the network used small transfers below reporting thresholds and multiple Binance accounts to obscure the funds’ origin; investigations are ongoing, and Kenya sent a mutual legal assistance request to the US in May 2026.

Security

Drift exploit wallet sends $44.4M in ETH to Tornado Cash after months of silence

Drift exploiter moves $44.4M in ETH into Tornado Cash after 3 months A wallet tied to the Drift Protocol exploit sent 23,095 ETH, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity, with researcher JL saying the attacker resumed 100 ETH batch deposits several times per minute. ZachXBT said he would not continue solo tracking work, citing the resources needed to monitor and freeze a nine-figure theft linked to North Korea.

Security

Three DeFi Security Breaches Drain $35.5 Million in Six Hours

Three DeFi hacks drain $35.5M in six hours Three security incidents hit AFX Trade, Verus Ethereum Bridge and B² Network on July 23, draining about $35.5 million in six hours. The biggest loss was AFX Trade at $24.15 million, followed by Verus Ethereum Bridge at $7.54 million and B² Network at $3.86 million. The attacks targeted bridge and supporting infrastructure, not Bitcoin, Ethereum or Arbitrum themselves, underscoring growing risks in cross-chain and off-chain systems.

Security

Robinhood confirms CEO Vlad Tenev’s X account was hacked in fake VLAD token scam

Robinhood confirms breach of CEO Vlad Tenev’s X account Hackers used Vlad Tenev’s compromised X account to promote a fake VLAD memecoin and post a fraudulent contract address, falsely claiming the token would be listed on Robinhood. The post was removed in under 20 minutes after drawing more than 175,000 views, and on-chain monitors estimated wallets tied to the scam extracted about 650 ETH, or roughly $1.2 million-$1.3 million.

July 23, 2026

Security

Bitcoin Security Consortium launches with $15 million from Coinbase, BlackRock, Strategy

Bitcoin Security Consortium launches with $15M backing from Coinbase, BlackRock, Strategy A group of major financial institutions and Bitcoin companies including Strategy, Coinbase, BlackRock, ARK Invest, Anchorage Digital, Block, Blockstream, Fidelity Digital Assets and Galaxy has launched the Bitcoin Security Consortium, committing $15 million over three years to support Bitcoin’s long-term security. The group will focus on research and development aimed at future quantum computing threats while funding independent developers and researchers.

Security

NIGHT Drops 45% After Wanchain Bridge Exploit Hits Midnight Treasury

Wanchain bridge exploit sends NIGHT down 45% NIGHT, the Midnight ecosystem’s native token, fell about 45% on Monday after an attacker exploited a flaw in Wanchain’s Cardano-to-BNB Chain bridge and drained roughly $10 million from the Cardano-side treasury. The bug in Wanchain’s TreasuryCheck validator let the attacker turn an approved transfer of about 3,110 NIGHT into more than 203 million NIGHT, which was then dumped on Cardano DEXs.

Security

AFX Trade loses about $24.15 million after bridge validator keys were compromised

AFX Trade drained for $24.15M after bridge validator key compromise AFX Trade, a USDC-settled perpetuals DEX on Arbitrum, lost about $24.15 million after an attacker used enough compromised hot-validator signatures to approve a bridge withdrawal. Blockaid said the on-chain logic worked as designed and Arbitrum said its native bridge was not affected; after a 200-second dispute period, the stolen USDC was moved to Ethereum and swapped for roughly 12,467 ETH.

Security

CertiK says crypto wrench attacks hit 52 in H1 as exposure reaches $124.1 million

CertiK: Crypto wrench attacks hit 52 in H1 2026, exposure jumps to $124.1M CertiK recorded 52 verified crypto wrench attacks worldwide in H1 2026, up 33.3% from a year earlier, while recorded financial exposure surged 1,079% to $124.1 million. Europe accounted for 39 cases, with France alone at 33, and home invasions became the leading attack method, rising to 20 incidents from one in H1 2025. This exposure figure includes stolen funds, ransom demands and frozen assets, not just confirmed losses.

July 22, 2026

Security

Zilliqa halts native ZIL transfers after Ledger signing flaw exposes private keys

Zilliqa freezes native ZIL transfers over Ledger key-exposure flaw Zilliqa halted native ZIL transactions on July 22 after confirming a Ledger app bug dating to 2019 that can let attackers reconstruct private keys from public on-chain signatures. The flaw affects only native, non-EVM ZIL transfers signed on Ledger devices; Zilliqa said about five affected signatures may be enough, warned users not to move funds, and said Ledger is preparing a patch.

Security

Ostium to Resume Trading on July 23 After $23.8M LP Vault Exploit

Ostium to reopen trading after $23.8M LP vault exploit Arbitrum perpetuals protocol Ostium said it will reopen trading Thursday, a week after a July 15 exploit drained nearly 23.8 million USDC from its liquidity provider vault. The protocol said trader collateral was unaffected because it sits in a separate contract, while open positions and pending orders will carry over and be repriced to the live market at reopening.

Security

CertiK says France led 52 crypto wrench attacks in first half of 2026

CertiK reports 52 crypto wrench attacks in H1 2026, led by France CertiK said confirmed physical attacks on crypto holders rose 33.3% year over year to 52 in H1 2026, with estimated financial exposure jumping to about $124.1 million from $10.5 million. Europe accounted for 39 cases and France for 33 alone, while crypto-related home invasions surged from one to 20; CertiK said the $124.1 million figure reflects exposure, not confirmed stolen funds.

Security

Upbit places Zilliqa on delisting watch after critical Ledger wallet key exposure

Upbit puts Zilliqa on delisting watch after Ledger app flaw Upbit has placed Zilliqa (ZIL) on delisting watch and frozen deposits and withdrawals for ZIL/KRW and ZIL/BTC after Zilliqa disclosed a critical Ledger wallet flaw that exposed private keys. Zilliqa said every version of its Ledger app since launch carried the bug, and accounts with about five or more native transactions should be considered compromised; the review runs until the week of August 17.

Security

SecondFi to wind down after $2.6 million ADA theft tied to wallet software flaw

SecondFi to shut down after $2.6M ADA hack hit 374 wallets SecondFi said it will wind down after attackers exploited a cryptographic flaw in its Cardano wallet software, stealing about 16.1 million ADA, or roughly $2.6 million, from 374 wallets. An independent probe pointed to a sophisticated external actor with indicators potentially linked to North Korea’s Lazarus Group, while recovery and wallet migration tools once expected within weeks are now targeted for August, with no reimbursement plan announced.

Security

42DAO Oracle Glitch Triggers 99.8% Balance Coin Crash and $912,000 Drain

42DAO oracle glitch triggers 99.8% BLC collapse and $912,000 drain Balance Coin (BLC) lost its dollar peg and crashed 99.8% to about $0.0013 after a seconds-long oracle failure on 42DAO let an attacker exploit two smart contracts and drain roughly $912,000 in a single transaction. Analysts said the pricing module accepted an abnormally low BTCB oracle price without filters, while the liquidation module acted on it instantly; the attacker then dumped newly minted BLC on PancakeSwap, wiping out liquidity and leaving the protocol with heavy bad debt.