Security news

Showing 301–341 of 341
Clear filters

July 21, 2026

Security

NIGHT Drops After $13.2M Wanchain Bridge Exploit Hits Midnight Token Route

Wanchain bridge exploit drains $13.2M in NIGHT, token drops about 30% A Wanchain bridge exploit drained 515 million NIGHT tokens worth about $13.2 million, triggering a roughly 30% drop in Midnight’s token as the affected route was paused. The issue was tied to a signature reuse flaw in cross-chain bridge infrastructure, while Cardano’s base layer and Midnight validator infrastructure were not compromised.

Security

Ostium plans trading restart after $23.75M Arbitrum liquidity vault exploit

Ostium targets trading restart this week after $23.75M vault exploit Ostium said it plans to resume trading this week, about five days after an attacker drained 23,752,746 USDC from its liquidity pool on Arbitrum. The exchange said it will give at least 24 hours’ notice and is running final checks with auditors and outside cybersecurity experts; when trading reopens, frozen positions will resume at the prevailing market price. Trader margin was not taken, but liquidity providers absorbed the loss and Ostium has not yet detailed compensation.

Security

Allbridge Core says Solana pool exploit drained about $1.66 million

Allbridge Core exploit drains $1.66M from Solana liquidity pools Allbridge said a hacker used a flash loan to exploit swap logic in its Solana liquidity pools, draining about $1.66 million after skewing USDT pricing with five same-asset swaps and then trading 4,000 USDT for 2.24 million USDC. The bridge has resumed routes that do not rely on liquidity pools, plans to stop pool-based swaps, and said no user wallets, private keys or non-pool routes were affected.

Security

FBI arrests Florida man over malware hidden in Steam game updates

FBI arrests Florida man over malware hidden in eight Steam games Federal prosecutors say 21-year-old Zyaire Wilkins of North Lauderdale, Florida, paid for infostealer malware that was later pushed through updates to eight Steam games, infecting about 8,000 computers and stealing crypto over roughly two years. Investigators traced about $382,000 in crypto flows and more than 150 Bitrefill gift cards, many used for Uber Eats orders; Wilkins faces a charge that carries up to 10 years in prison.

Security

New Zealand police warn of crypto scam using fake detectives and spoofed calls

New Zealand warns of police impersonation scam targeting crypto wallets New Zealand police say scammers posing as detectives and crypto company staff have stolen millions from wallet holders in recent weeks. Detective Inspector Stuart Mills said callers claim a victim’s personal details were found on someone recently arrested, then a fake company representative pushes for passwords or seed phrases, sometimes via a spoofed app site. Police said real officers will never ask for wallet details, PINs or seed phrases.

July 20, 2026

Security

Zilliqa reports ZIL theft from exchange partner cold wallet as transfers are halted

ZIL transfers paused after exchange partner cold wallet theft Zilliqa said Monday that an unspecified amount of ZIL was stolen from the cold wallet of one of its exchange partners, prompting a call to temporarily pause deposits and withdrawals to stop the funds being moved through centralized platforms. Coinone and KuCoin halted ZIL transfers, while the token fell to an all-time low of $0.002441 as Zilliqa said its investigation is ongoing.

Security

Allbridge Core halts bridge after reported $1.65 million exploit on Solana

Allbridge Core pauses protocol after $1.65M Solana exploit Allbridge Core said it paused the protocol after a security incident that reportedly drained $1.65 million from its Solana deployment on Sunday. Onchain Lens said the attacker used a $1.12 million USDC flash loan from Kamino and rapid USDC/USDT swaps to distort the stablecoin pool’s exchange rate, then withdrew liquidity at manipulated rates, bridged the funds to Ethereum and moved them into privacy pools.

July 19, 2026

Security

Consensys says North Korea-linked contractor briefly accessed MetaMask systems

Consensys says it cut off North Korea-linked MetaMask contractor Consensys said it identified and removed a North Korea-linked developer who had worked on MetaMask code and had internal access for about a month in spring 2026. The consultant, described by Drop Site as using the alias Tyler Knapp and GitHub account imyugioh, worked on components including crypto-to-fiat modules; Consensys said its investigation found no data theft, malicious code, or impact on users, and that law enforcement was notified.

July 18, 2026

Security

Kaspersky says OkoBot crypto malware campaign has hit users in more than 25 countries

Kaspersky flags OkoBot malware campaign targeting crypto users in 25+ countries Kaspersky says the newly identified OkoBot framework has been active for more than a year, using over 20 modules to steal seed phrases, wallet credentials and browser data through ClickFix lures and fake GitHub downloads. One module, SeedHunter, replaces Ledger and Trezor recovery screens with phishing pages; researchers say hundreds of users have been targeted, with the most victims reported in Brazil, Vietnam, Canada, Mexico and Türkiye.

Security

Group-IB says RedHook Android malware uses Wireless Debugging to steal banking data

Group-IB warns RedHook malware is hijacking Android via Wireless Debugging Group-IB says a new RedHook variant is infecting Android devices by abusing Wireless Debugging to gain shell-level access, letting attackers steal passwords, stream screens, capture lock-screen codes and show fake banking prompts. Victims in Vietnam and Indonesia are being lured via calls and messages posing as banks or government agencies to fake Google Play pages serving malicious apps from GitHub and Amazon cloud servers.

Security

SlowMist says macOS malware can hijack Telegram sessions and swap wallet apps

SlowMist details macOS malware that hijacks Telegram sessions and swaps wallet apps SlowMist says a newly analyzed macOS malware sample can steal Telegram’s local “tdata” session files, letting attackers open an already authorized account on another Mac without a phone code or two-step verification. The malware, linked to a fake BuilDAO app campaign reported July 8, also copies data from at least 16 desktop wallets and can replace Ledger Live, Ledger Wallet, and Trezor Suite with phishing lookalikes that ask for recovery phrases, PINs, or passphrases.

Security

Trusted Volumes attacker returns 1,122 ETH after $5.9 million May exploit

Trusted Volumes attacker returns 1,122 ETH after May exploit A wallet tied to the May 7 Trusted Volumes hack sent 1,122 ETH back to the protocol’s inventory, partially recovering funds from an exploit that drained about $5.9 million via a signature-check bypass in its RFQ swap proxy. On-chain data indicates the attacker kept roughly $2 million in ETH, in what appears to be a bounty-style settlement rather than a full return.

Security

Consensys pauses releases after North Korea-linked consultant accessed MetaMask systems

Consensys pauses releases after North Korea-linked contractor accessed systems Consensys temporarily halted product releases after a consultant using the alias “Tyler Knapp” gained access to its systems for about a month and worked on core MetaMask code, including parts tied to third-party fiat onramps. The company said an internal investigation found no stolen assets, exposed data, malicious code, or user harm, and it is now reviewing contractor screening and third-party hiring controls.

July 17, 2026

Security

Protocol exploit losses reach $57M in July as attack methods broaden

July DeFi exploits hit $57M as attacks spread beyond Ethereum Protocol exploits caused $57 million in crypto losses so far in July after more than $75 million was stolen in June, with recent attacks increasingly tied to smart contract logic flaws, oracle manipulation, front-end bugs and governance abuse. DeFi Llama data cited in the report shows Solana lost over $21 million in July, Arbitrum over $18 million, Base more than $14 million and Ethereum about $7 million.

Security

SlowMist says macOS malware can hijack Telegram sessions and target crypto wallets

macOS malware can hijack Telegram Desktop and target crypto wallets SlowMist warned that a macOS info-stealer can copy authenticated Telegram Desktop session data and wallet files, letting attackers access Telegram without a phone code or two-step verification and try to decrypt stolen wallet databases offline. The malware also replaces Ledger and Trezor apps with fake versions to steal recovery phrases, and targets wallets including Exodus, Atomic, Electrum, Wasabi, Monero, and full-node clients like Bitcoin Core.

July 16, 2026

Security

Kaspersky says OkoBot malware is actively targeting crypto wallet users in 25 countries

Kaspersky warns OkoBot malware is actively targeting crypto wallet users Kaspersky’s GReAT team said OkoBot has entered an active phase, putting hundreds of users in 25 countries at risk by hijacking official Ledger Live, Ledger Wallet and Trezor Suite apps with fake verification windows to steal funds. The campaign is reportedly targeting IT specialists and developers via infected GitHub tools, and Kaspersky warned its 20-plus-module framework could spread further beyond current hotspots including Brazil, Vietnam, Canada, Mexico and Turkey.

Security

Dutch and Belgian police break up cross-border crypto fraud network

Dutch and Belgian police dismantle €100M-a-month crypto scam network Police in the Netherlands and Belgium said they broke up an international crypto investment fraud ring that had operated since at least 2021 and at its peak siphoned off more than €100 million a month. Investigators said the group ran about 20 call centers with 700+ staff posing as financial advisers; six suspects were detained in Poland, Belgium, Greece and Cyprus, and Dutch media linked a key organizer to Ehud (Udi) Tenenbaum, though police have not officially confirmed the identity.

Security

Florida Man Charged in Alleged Malware Game Scheme That Stole $220,000 in Crypto

Florida man charged over malware game scheme that stole $220,000 in crypto U.S. authorities charged 21-year-old North Lauderdale resident Zyaire Dontaevious Zamarion Wilkins with conspiracy to obtain information by computer for private financial gain after he allegedly helped launch eight malware-laced games, including BlockBlasters, Dashverse, Lunara and PirateFi. The FBI says the campaign infected about 8,000 devices, accessed 80 crypto wallets and drained at least $220,000; Wilkins faces up to 10 years in prison if convicted.

Security

Summer.fi to Wind Down After $6.04 Million Exploit Hit Lazy Summer Protocol

Summer.fi to shut down after $6.04M Lazy Summer exploit Summer.fi said it will wind down after a July 6 exploit drained $6.04 million from its Lazy Summer Protocol, wiping out capital the team said it needed to rebuild. The attacker manipulated share prices in two Ethereum USDC vaults, with about 5.64 million USDC lost from LazyVault_LowerRisk_USDC and 0.40 million USDC from LazyVault_HigherRisk_USDC; the app will stay live until Aug. 31 while the Lazy Summer DAO works to restore withdrawals and redemptions.

July 15, 2026

Security

OFAC Adds Four Iran Central Bank Crypto Wallets as Tether Freezes $131 Million

OFAC adds four Iran central bank crypto wallets to sanctions list The U.S. Treasury’s OFAC on Tuesday added four cryptocurrency addresses to its Central Bank of Iran designation, and Tether immediately froze $131 million in stablecoins held there. Chainalysis said the wallets had received $165 million in stablecoins in total; with this action, Tether has now frozen nearly $475 million tied to OFAC-identified Central Bank of Iran addresses.

Security

Ostium pauses trading after oracle key exploit drains up to $18 million in USDC

Ostium halts trading after oracle key exploit drains up to $18M USDC Ostium paused trading after an attacker used a compromised oracle signer key to drain between $11.86 million and $18 million USDC from its liquidity vault, Blockaid said. The attacker allegedly submitted future-dated price reports and ran about 20 trading loops via a registered PriceUpKeep forwarder, extracting up to 28% of the protocol’s $63 million TVL without taking real market risk.

Security

Ostium loses up to $18 million in oracle signer exploit on Arbitrum

Ostium loses nearly $18M in oracle key exploit on Arbitrum Attackers drained nearly $18 million USDC from Ostium after compromising an oracle signer private key, letting them bypass verification checks and submit favorable future prices. Blockaid flagged the incident on July 15, 2026, saying the attacker used a registered PriceUpKeep forwarder and authorized oracle reports to run about 20 looped trades, extracting roughly 32%-35% of the protocol’s ~$34 million TVL.

Security

Hijacked SpaceX and Starlink X accounts used to promote SCATMAN token in brief scam

SpaceX and Starlink X accounts hijacked to pump SCATMAN memecoin Verified X accounts for SpaceX and Starlink were briefly hijacked on July 12 and used to repost promotions for the SCATMAN memecoin, helping drive a 575% surge in the first 20 minutes before the posts were removed. The attacker reportedly minted 10 trillion tokens and sold them across two wallets for about 73.7 ETH, or roughly $135,000, turning the brands’ credibility into a short-lived exit liquidity event for buyers.

July 14, 2026

Security

Gwalior accountant alleges Rs 21 crore loss in six-month fake crypto trading fraud

Gwalior CA alleges Rs 21 crore crypto scam tied to fake Bitcoin, USDT trades A 70-year-old chartered accountant in Gwalior told police he lost more than Rs 21 crore over six months in an alleged crypto investment fraud that began with a WhatsApp approach and a fake Bitcoin-USDT trading platform. Investigators said an initial Rs 1.88 lakh payout was used to build trust before the victim was asked for more money, including Rs 10.84 crore in “tax” and 2 lakh USDT as risk margin; police have frozen about Rs 2 crore after tracing funds through 570 mule accounts.

Security

Prism Deploys New Ethereum Contract After Exploit Diverted Nearly 40% of Trading Fees

Prism relaunches on new Ethereum contract after fee-draining exploit Prism is abandoning its original PRISM token and deploying a new Ethereum contract after disclosing that an attacker spent most of July siphoning off just under 40% of trading fees. The exploit used helper contracts to create 2,500 extra fee-earning positions beyond the token’s 5,000 cap, and the old token fell about 91% in 24 hours. It is still unclear how holders will migrate to the new contract.

Security

Humanity Protocol Rebuilds Security After $36 Million Token Theft

Humanity Protocol revamps security after $36M token hack Humanity Protocol said it is rebuilding its operational security framework from the ground up after an employee laptop was compromised last month, leading to the theft of $36 million in H tokens. Quantstamp said the attack may have involved a North Korea-linked group using phishing and malware to gain remote access to an admin hot wallet and multisig keys, underscoring the growing crypto threat from employee-targeted social engineering.

Security

BonkDAO Treasury Drained After Attacker Buys Majority in BIP #76 Vote

BonkDAO treasury drained after attacker bought vote majority An attacker spent about $4.4 million buying BONK, pushed through BonkDAO proposal BIP #76, and transferred roughly $20 million in BONK from the DAO treasury on July 6. The vote passed with 882.38 billion BONK in favor against an 879.95 billion quorum, with just seven wallets participating, and executed automatically via Realms with no timelock or veto. BonkDAO said no smart contract, key, or user wallet was compromised. Exchanges began responding, with Upbit suspending BONK deposits and withdrawals as investigators traced the funds.

Security

Interpol says Thai suspect’s wallet moved $122 million in alleged romance scam proceeds

Interpol links $122M crypto wallet to romance scam suspect in Thailand Interpol said a 20-year-old suspect arrested in Thailand controlled a crypto wallet that processed more than $122 million in alleged romance scam proceeds over 10 months, with funds often routed through cross-chain swaps to hide the trail. The wallet was uncovered during Operation First Light 2026, a January-April sweep across 97 countries that led to 5,811 arrests, $293 million intercepted, and more than 142,000 victims identified.

July 13, 2026

Security

Bonzo Lend Loses About $9.05M After Hedera Oracle Verification Flaw

Bonzo Lend loses $9.05M in oracle exploit on Hedera Bonzo Lend was drained of about $9.05 million on July 11 after an attacker exploited a verification flaw in Supra’s Hedera oracle contract, using 250 SAUCE worth only a few dollars as collateral to inflate its price and borrow 6.63 million USDC and 34.52 million wrapped HBAR. A second wallet borrowed about $1 million more before claiming to be a white hat and offering to return the funds; the protocol remains paused.

Security

BlueMove says overflow bug led to $500K SUI drain, amid insider speculation

BlueMove offers bounty after $500K SUI drain from locked pools BlueMove says an attacker exploited a long-standing arithmetic overflow bug in its legacy AMM contract to drain liquidity from 389 pools, taking about 700,000 SUI, or roughly $500,000. The DEX offered the exploiter a 30% white hat bounty to return the funds, said it will compensate affected users if no deal is reached within 48 hours, and added that the project will shut down going forward.

Security

OKX to Halt Solana USDC Deposits and Withdrawals on July 14 for Wallet Maintenance

OKX to pause Solana USDC deposits and withdrawals on July 14 OKX said it will suspend USDC deposits and withdrawals on the Solana network from July 14 at 14:30 UTC+8 for wallet maintenance, while trading will remain available. The exchange gave no end time and said services will resume after the work is completed, potentially without a separate announcement. Users were told not to send Solana-based USDC during the pause because transfers could risk lost funds.

Security

Ethereum Foundation says AI agents found and helped disclose bug in libp2p code

Ethereum Foundation says AI agent fleet found protocol bug in libp2p The Ethereum Foundation’s Protocol Security team said it is using coordinated AI agents to test critical protocol code and has already found real vulnerabilities, including a remotely triggerable panic in the libp2p gossipsub library used for Ethereum’s peer-to-peer communications. The issue has been fixed and publicly disclosed as CVE-2026-34219, while the team said the main challenge is triaging AI findings to separate real bugs from false positives.

Security

Gwalior accountant loses ₹21.06 crore in alleged fake crypto trading scam

Gwalior CA loses ₹21.06 crore in fake crypto trading scam A 70-year-old chartered accountant in Gwalior, Ashok Vijayvargiya, lost ₹21.06 crore ($2.2 million) after fraudsters befriended him on social media and lured him onto a fake crypto trading platform with fabricated early gains. Madhya Pradesh’s State Cyber Cell has filed a case and is tracing 20 bank accounts, three WhatsApp numbers, and the scam portal’s URL to try to freeze linked funds.

July 12, 2026

Security

Crypto hacks reached 207 cases in H1 2026 as losses stayed under $1 billion

Immunefi logs record 207 crypto hacks in H1 2026, losses at $972M Immunefi said 207 successful crypto attacks were recorded in H1 2026, the highest six-month total on record, but losses were about $972 million, less than half of H1 2025 and still below $1 billion. The data points to more frequent but less destructive hacks, with the median loss per incident falling from $6 million in 2022 to $1.5 million in 2025; smart contract exploits made up 125 of the 207 attacks.

Security

Singapore police and seven crypto platforms block over $4.2 million in potential scam losses

Singapore police and crypto exchanges stop $4.2M in potential scam losses The Singapore Police Force said a six-week operation with Coinbase, Coinhako, Gemini, Independent Reserve, OKX, StraitsX and Upbit identified more than 145 potential scam victims before they sent funds, preventing over $4.2 million in possible losses. Investigators used blockchain tools from Chainalysis and TRM Labs, then intervened by phone and in person with customer information provided by the exchanges.

July 11, 2026

Security

HKICL warns of fake FPS websites using cash rewards to harvest user and bank data

HKICL warns of fake FPS websites stealing user data Hong Kong Interbank Clearing Limited said it found multiple counterfeit websites posing as official FPS service providers and offering fake “Buyer Online Security Protection” to collect Hong Kong ID numbers, ID card photos, phone numbers, bank details and account names. The sites also promise cash rewards and route users into virtual wallet deposits or withdrawals; HKICL said they have no connection to its services and urged suspected victims to report cases to police.

Security

Bonzo Lend Pauses After $9 Million Borrowing Attack Linked to Hedera Oracle

Bonzo Lend loses about $9M in Hedera oracle exploit Bonzo Finance said an attacker borrowed roughly $9 million from its Bonzo Lend pool on Hedera on July 11 after manipulating a third-party SAUCE price oracle, while the protocol’s own contracts were not breached. The attacker used 250 SAUCE worth only a few dollars as collateral, inflated the oracle price by about 12 orders of magnitude, then borrowed about 6.6 million USDC and 34.5 million WHBAR; Bonzo Lend and its points program have been paused.

Security

Injective says no funds were at risk after backdoored npm packages exposed wallet secrets

Injective says no funds were compromised in npm supply-chain attack Attackers slipped wallet-key-stealing code into version 1.20.21 of Injective’s @injectivelabs/sdk-ts and 17 linked official npm packages, exposing any private keys or seed phrases processed during a brief release window. Injective said the issue was fixed within an hour and “no funds were ever at risk,” while security firms urged developers to upgrade to 1.20.23 and rotate any secrets touched by the compromised packages.

Security

Florida man says Wells Fargo impersonation scam drained $251,300 in life savings

Florida man loses $251,300 in Wells Fargo impersonation scam Randall Kahn of Florida lost his entire life savings after a caller posing as a Wells Fargo fraud representative convinced him to withdraw cash from nine branches over seven days and hand it to a rideshare driver, NBC 6 South Florida reported. Kahn said the caller cited supposed irregular account activity and provided what appeared to be legitimate employee and incident numbers; Wells Fargo later denied reimbursement, saying proper policies were followed in authorizing the transactions.

Security

Ledger discloses Tangem card flaw that allows password reset via laser attack

Ledger researchers reveal unpatchable Tangem card flaw Ledger’s Donjon team disclosed a hardware attack that can reset a Tangem wallet card’s password by hitting its secure element with a nanosecond laser pulse, bypassing a firmware recovery check. The attack was demonstrated on three cards and reported to Tangem on Feb. 10, but it requires physical possession, invasive prep, specialist skills and roughly $250,000 in lab equipment. Because cards already in circulation can’t receive firmware updates, the issue is unpatchable on existing devices.

Security

SecondFi breach may have exposed over 129 million ADA, researchers say

SecondFi hack losses may top 129M ADA, far above initial estimate SecondFi, the EMURGO-backed Cardano web wallet, initially said a flaw in its wallet-generation software led to the theft of about 16 million ADA, but SlowMist founder Yu Xian now says wallets tied to the attacker handled more than 129 million ADA plus other tokens, suggesting losses above $20 million. Blink Labs told users to treat SecondFi-created wallets as compromised and move assets to new wallets, while SecondFi asked users not to restore seed phrases elsewhere pending its review.