Disclaimer: SpendNode is for informational purposes only and is not a financial advisor. Some links on this site are affiliate links - we may earn a commission at no extra cost to you. This does not affect our data or rankings. Affiliate DisclosureView Policy
← All Articles
Security Hub

Security Hub

Self-custody architecture, MPC wallets, smart contract security, and fraud protection.

41 articles
Google Finds iOS Malware That Hunts for Coinbase, MetaMask, and 11 Other Crypto Apps

Google Finds iOS Malware That Hunts for Coinbase, MetaMask, and 11 Other Crypto Apps

The DarkSword exploit chain uses six iOS vulnerabilities to deploy Ghostblade, a data stealer targeting 13 crypto exchange and wallet apps on unpatched iPhones.

Mar 20, 2026Read Analysis →
Bitrefill Was Hacked by Lazarus Group, and 18,500 Customer Records Were Exposed

Bitrefill Was Hacked by Lazarus Group, and 18,500 Customer Records Were Exposed

Bitrefill reveals a March 1 cyberattack linked to North Korea

Mar 18, 2026Read Analysis →
The US, UK, and Canada Just Launched a Joint Operation to Stop Crypto Approval Phishing in Real Time

The US, UK, and Canada Just Launched a Joint Operation to Stop Crypto Approval Phishing in Real Time

Operation Atlantic brings the Secret Service, NCA, and Ontario police together to disrupt approval phishing scams that stole $17 billion in crypto last year.

Mar 17, 2026Read Analysis →
Venus Protocol Loses 3.7 Million Dollars After an Attacker Spent Nine Months Cornering One Token

Venus Protocol Loses 3.7 Million Dollars After an Attacker Spent Nine Months Cornering One Token

An attacker accumulated 84% of Thena's THE supply cap on Venus Protocol, manipulated the price, and borrowed $3.7M in CAKE, BTC, and BNB before anyone noticed.

Mar 15, 2026Read Analysis →
Crypto Losses Dropped 87% in February, but Hackers Stopped Attacking Code and Started Attacking You

Crypto Losses Dropped 87% in February, but Hackers Stopped Attacking Code and Started Attacking You

February 2026 crypto losses fell to $26-49M from $385M in January. The catch: social engineering now causes more damage than smart contract exploits.

Mar 14, 2026Read Analysis →
Hackers Hijacked the BONK.fun Domain and Planted a Wallet Drainer on Solana Biggest Meme Launchpad

Hackers Hijacked the BONK.fun Domain and Planted a Wallet Drainer on Solana Biggest Meme Launchpad

BONK.fun team confirms hackers took over a team account and embedded a crypto drainer on the Solana token launchpad domain, tricking users with a fake TOS prompt.

Mar 12, 2026Read Analysis →
Ledger Donjon Found a MediaTek Flaw That Lets Attackers Steal Seed Phrases From Android Phones in 45 Seconds

Ledger Donjon Found a MediaTek Flaw That Lets Attackers Steal Seed Phrases From Android Phones in 45 Seconds

A secure boot chain vulnerability in MediaTek processors allowed USB-based seed extraction from Trust Wallet, Phantom, and four other wallets. Patched January 2026.

Mar 12, 2026Read Analysis →
Are Crypto Cards Safe? What Happens When Your Card Issuer Fails

Are Crypto Cards Safe? What Happens When Your Card Issuer Fails

What protects your money on a crypto card? E-money segregation, Visa/MC chargebacks, custody models, and lessons from three real card program collapses.

Mar 9, 2026Read Analysis →
A Coinbase-Backed Startup Just Built a Quantum-Proof Wallet Prototype Because Current Exchange Architecture Will Break

A Coinbase-Backed Startup Just Built a Quantum-Proof Wallet Prototype Because Current Exchange Architecture Will Break

Project Eleven releases a post-quantum wallet prototype that restores key derivation for exchanges, solving a critical BIP32 vulnerability before NIST deadlines hit.

Mar 9, 2026Read Analysis →
Google Uncovers Coruna, a Spy-Grade iOS Exploit Kit That Steals Crypto Wallets From Older iPhones

Google Uncovers Coruna, a Spy-Grade iOS Exploit Kit That Steals Crypto Wallets From Older iPhones

Google's threat team found a 23-exploit iPhone kit called Coruna that steals seed phrases from MetaMask, Bitget Wallet, and Exodus. Here is what you need to know.

Mar 5, 2026Read Analysis →
An AI Bug Hunter Caught a Critical XRP Ledger Flaw That Could Have Drained $80 Billion, and No Human Spotted It First

An AI Bug Hunter Caught a Critical XRP Ledger Flaw That Could Have Drained $80 Billion, and No Human Spotted It First

Cantina's AI tool Apex flagged a signature bypass in the XRPL Batch amendment that would have let attackers drain wallets without private keys.

Feb 27, 2026Read Analysis →
IoTeX Bridge Drained for $8.8 Million After a Private Key Compromise, and the Attacker Is Already Routing Funds Through THORChain to Bitcoin

IoTeX Bridge Drained for $8.8 Million After a Private Key Compromise, and the Attacker Is Already Routing Funds Through THORChain to Bitcoin

A private key exploit gave an attacker control of IoTeX bridge contracts, draining $8.8M in tokens. Funds are being laundered through THORChain to Bitcoin.

Feb 21, 2026Read Analysis →
Uniswap Founder Hayden Adams Says the Ad Economy Needs to Go After a Fake Google Ad Drains a Trader's Entire Net Worth

Uniswap Founder Hayden Adams Says the Ad Economy Needs to Go After a Fake Google Ad Drains a Trader's Entire Net Worth

A fraudulent Google ad mimicking Uniswap drained a trader's mid-six-figure portfolio using the AngelFerno wallet drainer as phishing scams hit $370M in January.

Feb 21, 2026Read Analysis →
Specialized AI Detects 92 Percent of Real-World DeFi Exploits While Generic Models Catch Just a Third

Specialized AI Detects 92 Percent of Real-World DeFi Exploits While Generic Models Catch Just a Third

Cecuro's AI security agent detected 92% of exploited DeFi contracts worth $228M, while a GPT-5.1 baseline caught only 34%. The benchmark is now open source.

Feb 20, 2026Read Analysis →
A Single Misconfigured Oracle Valued cbETH at $1.12 Instead of $2,200, Draining $1.78 Million From Moonwell in Four Minutes

A Single Misconfigured Oracle Valued cbETH at $1.12 Instead of $2,200, Draining $1.78 Million From Moonwell in Four Minutes

Moonwell lost $1.78M in bad debt after a Chainlink OEV oracle wrapper misconfigured cbETH pricing at $1.12, with auditors linking the bug to AI-generated code.

Feb 18, 2026Read Analysis →
Scammers Are Mailing Fake Trezor and Ledger Letters With QR Codes Designed to Drain Your Wallet

Scammers Are Mailing Fake Trezor and Ledger Letters With QR Codes Designed to Drain Your Wallet

Physical phishing letters impersonating Trezor and Ledger use QR codes to steal recovery phrases. Here is how the attack works and how to protect yourself.

Feb 16, 2026Read Analysis →
The Mixin Network Hacker Resurfaces With $117M in ETH After Two Years of Silence, Routing the First $4M Through Tornado Cash

The Mixin Network Hacker Resurfaces With $117M in ETH After Two Years of Silence, Routing the First $4M Through Tornado Cash

A wallet tied to the $200M Mixin Network hack has begun liquidating 59,854 ETH through Tornado Cash after more than two years of dormancy.

Feb 13, 2026Read Analysis →
Ledger Draws a Line in the Sand on AI Agent Security: Propose, Don't Sign

Ledger Draws a Line in the Sand on AI Agent Security: Propose, Don't Sign

Ledger argues AI agents should never hold private keys, pushing a 'propose, humans sign' model that challenges Coinbase's agentic wallet approach.

Feb 12, 2026Read Analysis →
Bitget and BlockSec Release the UEX Security Standard, Setting a New Benchmark for Asset Protection Across Crypto and TradFi

Bitget and BlockSec Release the UEX Security Standard, Setting a New Benchmark for Asset Protection Across Crypto and TradFi

Bitget partners with BlockSec to publish the UEX Security Standard, a system-level security framework for exchanges bridging crypto and traditional markets.

Feb 9, 2026Read Analysis →
Binance's Human Firewall Prevented $6.69 Billion in Scam Losses in 2025, Protecting 5.4 Million Users

Binance's Human Firewall Prevented $6.69 Billion in Scam Losses in 2025, Protecting 5.4 Million Users

Binance's 9-level anti-scam system combined AI monitoring with human wake-up calls to prevent $6.69B in fraud losses and shield 5.4M users in 2025.

Feb 8, 2026Read Analysis →
KuCoin Pushes Passkeys as Crypto Exchanges Race to Kill the Password

KuCoin Pushes Passkeys as Crypto Exchanges Race to Kill the Password

KuCoin now supports full passwordless login via passkeys. Here is how the FIDO2 standard is reshaping crypto exchange security and why it matters for your funds.

Feb 8, 2026Read Analysis →
OKX Wallet Has Blocked 8.53 Million Malicious Domains and Recovered $896 Million in Assets Since Launch

OKX Wallet Has Blocked 8.53 Million Malicious Domains and Recovered $896 Million in Assets Since Launch

OKX reveals wallet security stats: 8.53M malicious domains blocked, 23M+ risky tokens flagged, and nearly $900M in user assets recovered since launch.

Feb 8, 2026Read Analysis →
Binance Recovers $12.8 Million in Stolen Funds in 2025 as Anti-Scam Machine Scales Up

Binance Recovers $12.8 Million in Stolen Funds in 2025 as Anti-Scam Machine Scales Up

Binance recovered $12.8M in stolen crypto in 2025, up 41% from 2024. Here is how their AI-powered anti-scam system protects users.

Feb 7, 2026Read Analysis →
Binance Warns of Lookalike Wallet Address Scams: How to Detect and Prevent Them

Binance Warns of Lookalike Wallet Address Scams: How to Detect and Prevent Them

Binance issues a detailed warning on lookalike wallet address scams that trick users into sending funds to fraudulent addresses. Detection tips inside.

Feb 6, 2026Read Analysis →
Binance Pushes ED25519 as the Gold Standard for API Security and Deprecates HMAC Keys

Binance Pushes ED25519 as the Gold Standard for API Security and Deprecates HMAC Keys

Binance recommends ED25519 signatures for API security, deprecating HMAC. Here's what the upgrade means for traders, bots, and card-linked accounts.

Feb 6, 2026Read Analysis →
COCA Wallet Migrates to Privy: Seedless Authentication Comes to MPC Wallets

COCA Wallet Migrates to Privy: Seedless Authentication Comes to MPC Wallets

COCA Wallet integrates Privy for seedless login. No more seed phrases, familiar auth methods, and full self-custody preserved.

Feb 5, 2026Read Analysis →
Lombard Finance Integrates Chainlink Proof of Reserve to Bring Transparency to $1.1B BTCFi Protocol

Lombard Finance Integrates Chainlink Proof of Reserve to Bring Transparency to $1.1B BTCFi Protocol

Lombard Finance adds Chainlink Proof of Reserve, CCIP, and Price Feeds to verify LBTC collateralization across 15 chains in real-time.

Feb 5, 2026Read Analysis →
Binance Launches Security Center: Automatic Risk Scanning for Web3 Wallet Users

Binance Launches Security Center: Automatic Risk Scanning for Web3 Wallet Users

Binance introduces Security Center, an automatic risk scanner for its Web3 Wallet. We analyze what it checks, how it protects funds, and what it means for users.

Feb 3, 2026Read Analysis →
Jupiter ASR Claim Security: Why You Should Never Import Your Seed Phrase

Jupiter ASR Claim Security: Why You Should Never Import Your Seed Phrase

Jupiter has faced security concerns over its ASR claim flow. Learn why seed phrase imports are dangerous for card-linked wallets and what the new direct claim flow means.

Feb 1, 2026Read Analysis →
ether.fi x MEXC Co-Branded Card: The Accountability Stack and User Protections

ether.fi x MEXC Co-Branded Card: The Accountability Stack and User Protections

A definitive guide to the ether.fi x MEXC co-branded card. Analyze the 15% dining boost, the issuer accountability stack, and dispute protection frameworks.

Feb 1, 2026Read Analysis →
Binance MPC Wallets: A New Standard for Card-Linked Custody?

Binance MPC Wallets: A New Standard for Card-Linked Custody?

Binance has launched MPC wallet integration for its ecosystem. Analyze how Multi-Party Computation changes security for crypto cardholders and reduces single-point-of-failure risk.

Jan 31, 2026Read Analysis →
RedotPay Adds Apple Pay and Google Pay: Tap-to-Pay Goes Mainstream

RedotPay Adds Apple Pay and Google Pay: Tap-to-Pay Goes Mainstream

RedotPay now supports Apple Pay and Google Pay. Here is what mobile wallet integration changes for security, daily usability, and cardholder behavior.

Jan 31, 2026Read Analysis →
The 'Convincing Marshall' Scam: Why Crypto Cardholders are Targets

The 'Convincing Marshall' Scam: Why Crypto Cardholders are Targets

A deep dive into high-pressure social engineering scams targeting cardholders. Learn how scammers use 'official' authority to bypass security and what you can do to protect your wallet.

Jan 30, 2026Read Analysis →
The 2026 Crypto Card Custody Bible: From Seed Phrases to BaaS Risk

The 2026 Crypto Card Custody Bible: From Seed Phrases to BaaS Risk

A 2000-word deep dive into the technical and legal layers of crypto card custody. Learn about MPC, Account Abstraction (ERC-4337), and how to audit your issuer's solvency risk.

Jan 29, 2026Read Analysis →
The CLARITY Act vs. Stablecoin Rewards: Why Coinbase is Fighting Back

The CLARITY Act vs. Stablecoin Rewards: Why Coinbase is Fighting Back

The US CLARITY Act could effectively ban stablecoin rewards. Learn why Coinbase withdrew support, the impact on cardholders, and the $243M revenue stake.

Jan 28, 2026Read Analysis →
Why Blockchain Security Platforms Are Becoming Core Infrastructure in DeFi

Why Blockchain Security Platforms Are Becoming Core Infrastructure in DeFi

DeFi security is shifting from basic audits to real-time threat monitoring and cross-chain attack detection. Learn how this protects your crypto card assets.

Jan 28, 2026Read Analysis →
Self-Custody Crypto Cards: Complete Guide to Non-Custodial Spending (2026)

Self-Custody Crypto Cards: Complete Guide to Non-Custodial Spending (2026)

Deep-dive into self-custody vs custodial models: security architecture comparison (MPC vs multi-sig), product analysis of 5 cards, recovery mechanisms, gas fees, and real-world breach case studies.

Jan 23, 2026Read Analysis →
Self-Sovereign Identity: The Future of Crypto Card KYC

Self-Sovereign Identity: The Future of Crypto Card KYC

The end of 'sending your passport' is here. Learn how ZK-KYC and Self-Sovereign Identity (SSI) are making crypto cards private and secure.

Jan 22, 2026Read Analysis →
The Regulatory Landscape of 2026: MiCA 2.0 and Your Crypto Card

The Regulatory Landscape of 2026: MiCA 2.0 and Your Crypto Card

How does MiCA 2.0 impact your crypto card choice? Learn about the new EU regulations and how they affect card privacy, limits, and availability.

Jan 22, 2026Read Analysis →
Smart Contract Fraud Protection: Can Code Stop Card Theft?

Smart Contract Fraud Protection: Can Code Stop Card Theft?

How smart contracts protect your crypto card from fraud. Learn about on-chain spending limits, guardians, and the future of decentralized card security.

Jan 22, 2026Read Analysis →
MPC Security for Crypto Cards: Complete 2026 Technical Guide

MPC Security for Crypto Cards: Complete 2026 Technical Guide

How Multi-Party Computation (MPC) protects crypto cards: threshold signatures, key share architecture, vs. multisig comparison, real security incidents, and implementation across 12 major cards.

Jan 21, 2026Read Analysis →

Category Stats

Total Articles41
Latest UpdateMar 20, 2026