← All Articles
Security Hub

Security Hub

Self-custody architecture, MPC wallets, smart contract security, and fraud protection.

113 articles
ZachXBT Ties $475K in Frozen Bitcoin to an Elder-Fraud Mule

ZachXBT Ties $475K in Frozen Bitcoin to an Elder-Fraud Mule

On-chain investigator ZachXBT traced $475K in frozen bitcoin to social engineering scams on elderly Americans after a suspected money mule asked him for help.

Jun 19, 2026Read Analysis →
Texas Brothers Plead Guilty to $8M Armed Crypto Kidnapping

Texas Brothers Plead Guilty to $8M Armed Crypto Kidnapping

Isiah and Raymond Garcia admitted to holding a Minnesota family at gunpoint for eight hours and forcing an $8M crypto transfer. The case shows how self-custody shifts risk to the holder.

Jun 19, 2026Read Analysis →
G7 Renews Push on North Korean Crypto Theft as Losses Top $2B

G7 Renews Push on North Korean Crypto Theft as Losses Top $2B

G7 leaders issued a fresh joint call to counter state-sponsored crypto theft, citing a Chainalysis figure of more than $2 billion stolen by DPRK-linked hackers.

Jun 18, 2026Read Analysis →
CFTC Closes Its Celsius Case With a Permanent Ban on Mashinsky

CFTC Closes Its Celsius Case With a Permanent Ban on Mashinsky

The CFTC entered a consent order on June 18, 2026 resolving its fraud case against Celsius founder Alexander Mashinsky, with permanent trading and registration bans.

Jun 18, 2026Read Analysis →
France Moves to Retire Non-Quantum Encryption as Bitcoin Risk Looms

France Moves to Retire Non-Quantum Encryption as Bitcoin Risk Looms

France is pushing to phase out classical encryption in favor of post-quantum schemes, reviving questions about how exposed Bitcoin's signatures really are.

Jun 18, 2026Read Analysis →
'Bitcoin Rodney' Pleads Guilty in $1.8B HyperFund Ponzi

'Bitcoin Rodney' Pleads Guilty in $1.8B HyperFund Ponzi

Rodney Burton, the promoter known as 'Bitcoin Rodney,' pleaded guilty over the $1.8B HyperFund Ponzi. He faces up to 5 years and is sentenced July 23.

Jun 17, 2026Read Analysis →
Zcash Says Counterfeit ZEC Was Likely Never Minted, but Can't Prove It

Zcash Says Counterfeit ZEC Was Likely Never Minted, but Can't Prove It

Zooko Wilcox says prior exploitation of the Orchard counterfeiting bug looks unlikely, but cryptography alone cannot confirm no fake ZEC was ever minted.

Jun 15, 2026Read Analysis →
North Korea Tied to $32M Humanity Protocol Hack via Fake Bithumb Email

North Korea Tied to $32M Humanity Protocol Hack via Fake Bithumb Email

A Quantstamp investigation links the $32M Humanity Protocol hack to North Korean actors who used a fake Bithumb email to get in, per a June 14 report.

Jun 14, 2026Read Analysis →
Q2 2026 Is Crypto's Most-Hacked Quarter on Record, DefiLlama Says

Q2 2026 Is Crypto's Most-Hacked Quarter on Record, DefiLlama Says

DefiLlama data shows Q2 2026 has logged roughly 70 hacks, about double the previous quarterly record, even as the dollar losses stay front-loaded in April.

Jun 12, 2026Read Analysis →
Raydium Loses $1.34M to a Retired Pool, Treasury Covers It

Raydium Loses $1.34M to a Retired Pool, Treasury Covers It

Raydium says an attacker drained $1.34M from five deprecated AMM V3 pools via an LP mint flaw. Active funds were untouched and the treasury will reimburse.

Jun 11, 2026Read Analysis →
Polychain-Backed Bitcoin L2 Botanix to Shut Down by July 9

Polychain-Backed Bitcoin L2 Botanix to Shut Down by July 9

Botanix, a venture-funded Bitcoin Layer 2 that raised $11.5M, is winding down. Users must withdraw assets by July 9 or the validator Federation sweeps the rest.

Jun 10, 2026Read Analysis →
Humanity's $36M Exploit Traced to a Multisig on One Laptop

Humanity's $36M Exploit Traced to a Multisig on One Laptop

A CoinDesk post-mortem says the Humanity Protocol drain happened because its multisig signing keys all lived on a single compromised laptop. The lesson for self-custody.

Jun 9, 2026Read Analysis →
Yuga Labs Rescues 68 NFTs Including 29 Bored Apes From a Flooring Exploit

Yuga Labs Rescues 68 NFTs Including 29 Bored Apes From a Flooring Exploit

Yuga Labs says it pulled 68 NFTs, among them 29 Bored Apes and 2 CryptoPunks, out of a Flooring Protocol exploit. The rescue underlines pooled-custody risk in DeFi.

Jun 9, 2026Read Analysis →
Humanity Protocol Wallets Drained for $19M, H Token Falls 80%

Humanity Protocol Wallets Drained for $19M, H Token Falls 80%

Wallets linked to Humanity Protocol were drained for more than $19 million and the H token fell over 80%, per WuBlockchain. Here is what is known so far.

Jun 9, 2026Read Analysis →
Zcash Plans an Ironwood Pool to Restore Supply Proof After Orchard Flaw

Zcash Plans an Ironwood Pool to Restore Supply Proof After Orchard Flaw

Zcash developers propose Ironwood, a new shielded pool with a turnstile checkpoint, to restore supply verification after a bug in Orchard could have minted fake ZEC.

Jun 8, 2026Read Analysis →
AI Now Finds Crypto Bugs Humans Missed for Years, and Auditors Aren't Ready

AI Now Finds Crypto Bugs Humans Missed for Years, and Auditors Aren't Ready

A four-year-old Zcash flaw surfaced with help from Claude Opus 4.8. Security researchers say AI-found bugs change who hunts vulnerabilities, and how fast.

Jun 7, 2026Read Analysis →
AI Found a Zcash Bug That Could Have Printed Counterfeit ZEC

AI Found a Zcash Bug That Could Have Printed Counterfeit ZEC

A soundness bug in Zcash's Orchard shielded pool could have minted undetectable counterfeit ZEC. A researcher found it with an AI model, and validators patched it in five days.

Jun 5, 2026Read Analysis →
Trezor Discloses Laser Fault Attack on Safe 7 Chip, Says Funds Safe

Trezor Discloses Laser Fault Attack on Safe 7 Chip, Says Funds Safe

Trezor disclosed a laser fault injection flaw in the Safe 7's TROPIC01 secure element, found by Ledger's Donjon team. Trezor says keys are not stored on the chip.

Jun 3, 2026Read Analysis →
EDGE Token Crashes 70% as ZachXBT Demands edgeX Name Its Market Makers

EDGE Token Crashes 70% as ZachXBT Demands edgeX Name Its Market Makers

edgeX's EDGE token fell as much as 70% on June 1-2, triggering $2.81M in liquidations. ZachXBT says insiders controlled a low float and wants counterparties named.

Jun 2, 2026Read Analysis →
Kelp DAO Hacker Launders $220M in Six Weeks, Closing Recovery Window

Kelp DAO Hacker Launders $220M in Six Weeks, Closing Recovery Window

The Kelp DAO exploiter has laundered nearly all of the unfrozen $220M from April's $293M rsETH drain, leaving only the $71M frozen by Arbitrum recoverable.

Jun 2, 2026Read Analysis →
Radiant Capital to Wind Down After Failing to Recover From $50M Exploit

Radiant Capital to Wind Down After Failing to Recover From $50M Exploit

Radiant Capital is winding down operations after a $50M cross-chain exploit it never recovered from. Here is what the shutdown means for DeFi lending risk.

Jun 1, 2026Read Analysis →
Developer Frees 1,003 ETH Locked in a 2016 ICO Contract for Nine Years

Developer Frees 1,003 ETH Locked in a 2016 ICO Contract for Nine Years

A developer known as Florent recovered 1,003 ETH worth about $2M that had been stuck in a 2016 ICO smart contract for nine years. Here is what it means for on-chain funds.

Jun 1, 2026Read Analysis →
Gravity Bridge Drained of $5.4M in Suspected Signing-Key Compromise

Gravity Bridge Drained of $5.4M in Suspected Signing-Key Compromise

Gravity Bridge lost about $5.4M on May 30 in a suspected signing-key compromise. Stolen USDC, ETH, and USDT moved through Binance and ChangeNow.

May 31, 2026Read Analysis →
DxSale Drained of $7.3M as Backdoor Hits 2021-Era BNB Lockers

DxSale Drained of $7.3M as Backdoor Hits 2021-Era BNB Lockers

An attacker drained $7.3M in BNB from more than 1,400 DxSale liquidity lockers dating to 2021, using a privileged fee reset and a backdated lock expiry.

May 30, 2026Read Analysis →
Circle Blacklist Freezes $12.6M of Zama Confidential USDC, ZachXBT Says

Circle Blacklist Freezes $12.6M of Zama Confidential USDC, ZachXBT Says

On-chain investigator ZachXBT reports $12.6M of Zama cUSDC frozen after a Circle blacklisting, extending the USDC freeze debate to confidential wrapped tokens.

May 30, 2026Read Analysis →
SquidRouter Module Drains $3M From Safe Wallets on Ethereum and Base

SquidRouter Module Drains $3M From Safe Wallets on Ethereum and Base

A third-party SquidRouterModule attached to Safe smart wallets was exploited on Ethereum and Base, draining roughly $3M and exposing module-level risk.

May 26, 2026Read Analysis →
TrapDoor Malware Hits Crypto Devs With 34 Poisoned Packages

TrapDoor Malware Hits Crypto Devs With 34 Poisoned Packages

A supply chain campaign called TrapDoor has shipped 34 malicious packages targeting crypto and AI developers, draining wallets, SSH keys, and API tokens.

May 25, 2026Read Analysis →
StablR EURR and USDR Contracts Exploited for $10M, ZachXBT Reports

StablR EURR and USDR Contracts Exploited for $10M, ZachXBT Reports

On-chain investigator ZachXBT flagged a roughly $10M exploit affecting smart contracts tied to StablR's EURR and USDR stablecoins, Cointelegraph reports.

May 24, 2026Read Analysis →
THORChain Recovery Plan Rules Out New RUNE Minting After May 15 Exploit

THORChain Recovery Plan Rules Out New RUNE Minting After May 15 Exploit

THORChain proposed a recovery plan after the May 15 exploit, ruling out fresh RUNE issuance to repay affected users and forcing losses through protocol revenue instead.

May 22, 2026Read Analysis →
Glassnode: 10% of Bitcoin Supply Is 'Structurally Unsafe' From Quantum

Glassnode: 10% of Bitcoin Supply Is 'Structurally Unsafe' From Quantum

Glassnode warns nearly 10% of BTC supply sits in quantum-vulnerable addresses, with Franklin Templeton, WisdomTree, and Robinhood ETF holdings 100% exposed.

May 21, 2026Read Analysis →
GitHub Probes Unauthorized Access to Internal Repos, CZ Urges API Key Rotation

GitHub Probes Unauthorized Access to Internal Repos, CZ Urges API Key Rotation

GitHub is investigating unauthorized access to its internal repositories. CZ told developers to rotate API keys in code, including private repos.

May 20, 2026Read Analysis →
Echo Protocol Reclaims Admin Key, Burns 955 eBTC Held by Attacker

Echo Protocol Reclaims Admin Key, Burns 955 eBTC Held by Attacker

Echo Protocol says it has regained control of the compromised admin key and burned the attacker's remaining 955 eBTC after a major cross-chain exploit.

May 19, 2026Read Analysis →
Jameson Lopp Urges Zero Trust as Google-Based Phishing Bypasses Filters

Jameson Lopp Urges Zero Trust as Google-Based Phishing Bypasses Filters

Casa CTO Jameson Lopp tells crypto holders to treat every inbound message as hostile after a phishing scheme abused Google infrastructure to slip past filters.

May 18, 2026Read Analysis →
Verus-Ethereum Bridge Drained for $11.4M in Suspected Exploit

Verus-Ethereum Bridge Drained for $11.4M in Suspected Exploit

PeckShield flagged a Verus-Ethereum bridge exploit on May 18, 2026, with attackers funneling roughly $11.4M through Tornado Cash.

May 18, 2026Read Analysis →
THORChain Halts Chain After Suspected Multichain Exploit

THORChain Halts Chain After Suspected Multichain Exploit

THORChain triggered an emergency halt on May 15 after a suspected multichain exploit, putting the cross-chain swap protocol's recovery and trust on trial.

May 16, 2026Read Analysis →
Fireblocks CEO: Bitcoin Quantum Upgrade Is a Coordination Problem

Fireblocks CEO: Bitcoin Quantum Upgrade Is a Coordination Problem

Fireblocks CEO Michael Shaulov says migrating Bitcoin to post-quantum signatures is mostly a coordination issue. The cryptographic algorithms already exist.

May 14, 2026Read Analysis →
Kelp DAO and Aave Burn Exploiter Tokens, Refill 117K rsETH

Kelp DAO and Aave Burn Exploiter Tokens, Refill 117K rsETH

Kelp DAO and Aave finished recovery steps for the rsETH exploit, burning the attacker's tokens and committing to refill 117,132 rsETH over two weeks.

May 13, 2026Read Analysis →
North Korea Stole $2.1B in Crypto in 2025, 60% of All Losses: CertiK

North Korea Stole $2.1B in Crypto in 2025, 60% of All Losses: CertiK

CertiK attributes 60% of 2025 crypto theft to North Korean state-sponsored groups, with $2.1B stolen across Bybit, DMM, and DeFi targets.

May 12, 2026Read Analysis →
Physical 'Wrench Attacks' Cost Crypto Holders Over $100M Since January

Physical 'Wrench Attacks' Cost Crypto Holders Over $100M Since January

Physical extortion of crypto holders has produced more than $100M in losses in the first four months of 2026, per CryptoSlate. Here is what is driving it.

May 11, 2026Read Analysis →
April 2026 Crypto Exploits Top $635M Across 28 Incidents, Worst Month of Year

April 2026 Crypto Exploits Top $635M Across 28 Incidents, Worst Month of Year

April 2026 saw over $635M stolen across 28 crypto exploits, the worst month of the year so far. Here is what drove the spike and what users can do.

May 9, 2026Read Analysis →
GothFerrari Gets 78 Months in Prison for $250M Crypto Theft Ring

GothFerrari Gets 78 Months in Prison for $250M Crypto Theft Ring

A member of the social engineering crew known as GothFerrari was sentenced to 78 months in US federal prison for helping steal roughly $250M in crypto.

May 7, 2026Read Analysis →
Aave to Overhaul Collateral and Listing Standards After KelpDAO Exploit

Aave to Overhaul Collateral and Listing Standards After KelpDAO Exploit

Aave moves to tighten collateral and listing standards across its markets after the KelpDAO rsETH exploit forced emergency liquidations and risk freezes.

May 7, 2026Read Analysis →
Drift Outlines Recovery Plan for Users After $295M DPRK-Linked Exploit

Drift Outlines Recovery Plan for Users After $295M DPRK-Linked Exploit

Solana perpetuals exchange Drift published a recovery plan for users after a $295M exploit that on-chain investigators have linked to North Korean actors.

May 5, 2026Read Analysis →
Binance Rolls Out Withdraw Protection Feature for User Accounts

Binance Rolls Out Withdraw Protection Feature for User Accounts

Binance launches Withdraw Protection, a new account safeguard that adds friction to suspicious withdrawals and gives users a window to reverse risky transfers.

May 4, 2026Read Analysis →
ZachXBT Accuses Tokenlon of Routing Illicit Funds Through Its Aggregator

ZachXBT Accuses Tokenlon of Routing Illicit Funds Through Its Aggregator

On-chain sleuth ZachXBT alleges DEX aggregator Tokenlon processed funds tied to illicit activity, reigniting debate over compliance gaps in DeFi routing layers.

May 4, 2026Read Analysis →
Bitcoin Devs Call Paul Sztorc's eCash Fork a Hazardous Airdrop

Bitcoin Devs Call Paul Sztorc's eCash Fork a Hazardous Airdrop

Bitcoin developers are publicly warning holders against Paul Sztorc's eCash fork, calling its claim mechanics hazardous for everyday BTC users.

May 2, 2026Read Analysis →
Cointelegraph Warns Linux 'Copy Fail' Bug Puts Crypto Wallets at Risk

Cointelegraph Warns Linux 'Copy Fail' Bug Puts Crypto Wallets at Risk

Cointelegraph reports a Linux 'Copy Fail' bug, citing Xint Code, that lets attackers tamper with copy operations. Crypto users on Linux face heightened clipboard risks.

May 2, 2026Read Analysis →
Paradigm Proposes PACTs to Shield Dormant Bitcoin From Quantum Risk

Paradigm Proposes PACTs to Shield Dormant Bitcoin From Quantum Risk

Paradigm researcher Dan Robinson proposed PACTs, a scheme that lets dormant Bitcoin holders prove ownership before quantum computers can crack exposed keys.

May 1, 2026Read Analysis →
Hundreds of Dormant Ethereum Wallets Drained Into Same Tagged Addresses

Hundreds of Dormant Ethereum Wallets Drained Into Same Tagged Addresses

Hundreds of long-dormant Ethereum wallets were swept into the same tagged addresses, with the cause possibly tracing back years, per CryptoSlate.

May 1, 2026Read Analysis →
Wasabi Protocol Loses $5M After Attacker Seizes Deployer Key

Wasabi Protocol Loses $5M After Attacker Seizes Deployer Key

Wasabi Protocol lost roughly $5 million after an attacker took control of the deployer admin key and drained contracts across three chains.

Apr 30, 2026Read Analysis →
Cursor AI Agent Wipes PocketOS Production Data in One Railway Call

Cursor AI Agent Wipes PocketOS Production Data in One Railway Call

PocketOS founder Jeremy Crane says a Cursor agent running Claude Opus erased production data and backups via one Railway API call. Crypto agent risk in focus.

Apr 29, 2026Read Analysis →
Google Finds Live Prompt-Injection Payloads Hunting AI Agents and PayPal

Google Finds Live Prompt-Injection Payloads Hunting AI Agents and PayPal

Google scanned billions of pages and found real payloads built to hijack AI agents into draining PayPal balances and leaking enterprise data.

Apr 27, 2026Read Analysis →
Litecoin Confirms Zero-Day Bug Triggered 13-Block Reorg

Litecoin Confirms Zero-Day Bug Triggered 13-Block Reorg

Litecoin developers say a zero-day vulnerability caused a 13-block chain reorganization on April 25. The network has been patched and is stable again.

Apr 25, 2026Read Analysis →
Only 1.7M Satoshi-Era Coins at Quantum Risk, James Check Argues

Only 1.7M Satoshi-Era Coins at Quantum Risk, James Check Argues

Glassnode analyst James Check says Bitcoin's quantum risk is concentrated in 1.716M old P2PK coins, not the full 19M supply, narrowing the panic window.

Apr 25, 2026Read Analysis →
France Charges 88 in Crypto Kidnapping Surge, Le Monde Reports

France Charges 88 in Crypto Kidnapping Surge, Le Monde Reports

France's national anti-organized-crime branch has charged 88 people across a wave of crypto-related kidnappings, Le Monde reported on April 25, 2026.

Apr 25, 2026Read Analysis →
KelpDAO Hacker Swaps 75,700 ETH Into Bitcoin Worth $175M

KelpDAO Hacker Swaps 75,700 ETH Into Bitcoin Worth $175M

The KelpDAO exploiter converted nearly all 75,700 ETH, roughly $175M, into BTC over 36 hours, locking in gains and complicating recovery.

Apr 23, 2026Read Analysis →
Bybit Flags macOS Malware Campaign Aimed at Claude Code Searchers

Bybit Flags macOS Malware Campaign Aimed at Claude Code Searchers

Bybit's security team disclosed a macOS malware campaign that preys on users searching for Claude Code, exploiting AI tool demand to deliver payloads.

Apr 22, 2026Read Analysis →
Volo Protocol Confirms $3.5M Exploit on Its Sui Vaults

Volo Protocol Confirms $3.5M Exploit on Its Sui Vaults

Sui-based Volo Protocol has confirmed a $3.5M exploit of its vaults, with roughly $500K frozen so far. What's on the table and what isn't.

Apr 22, 2026Read Analysis →
Unauthorized Users Accessed Anthropic's Cyberattack-Capable Mythos AI

Unauthorized Users Accessed Anthropic's Cyberattack-Capable Mythos AI

Bloomberg reports a small group of unauthorized users accessed Anthropic's new Mythos AI, a model the company says is powerful enough to enable cyberattacks.

Apr 22, 2026Read Analysis →
KelpDAO Exploiter Launders $80M in ETH Through Thorchain

KelpDAO Exploiter Launders $80M in ETH Through Thorchain

The attacker behind the $292M KelpDAO drain has routed roughly $80M in ETH through Thorchain swaps, complicating recovery efforts for rsETH depositors.

Apr 22, 2026Read Analysis →
Ripple Sets 2028 Deadline to Quantum-Proof the XRP Ledger

Ripple Sets 2028 Deadline to Quantum-Proof the XRP Ledger

Ripple gave itself a 2028 deadline to swap out the XRP Ledger's cryptography before quantum machines can break it, calling the threat 'credible.'

Apr 20, 2026Read Analysis →
Aave Says rsETH Is Fully Backed, but Keeps V3 and V4 Markets Frozen

Aave Says rsETH Is Fully Backed, but Keeps V3 and V4 Markets Frozen

Aave confirmed the rsETH sitting in its V3 and V4 markets on Ethereum is fully backed, but the markets stay frozen while KelpDAO bridge risk is reviewed.

Apr 20, 2026Read Analysis →
Vercel Traces Its Breach to an AI Tool's Google OAuth

Vercel Traces Its Breach to an AI Tool's Google OAuth

Vercel says a third-party AI tool's compromised Google Workspace OAuth was the entry point for its breach, a supply chain risk crypto devs should map out.

Apr 20, 2026Read Analysis →
BitMEX's Quantum Canary Says Don't Freeze Bitcoin Until Quantum Is Real

BitMEX's Quantum Canary Says Don't Freeze Bitcoin Until Quantum Is Real

BitMEX Research published a Bitcoin canary fund proposal on April 16, 2026 as an alternative to BIP-361's mandatory five-year quantum migration deadline.

Apr 19, 2026Read Analysis →
KelpDAO Bridge Drained for $292M, Making It 2026's Biggest DeFi Hack

KelpDAO Bridge Drained for $292M, Making It 2026's Biggest DeFi Hack

An attacker drained 116,500 rsETH, about $292M, from KelpDAO's LayerZero bridge on April 18, 2026. Aave, SparkLend, and Fluid froze affected markets.

Apr 19, 2026Read Analysis →
Vitalik Warns of DNS Registrar Attack on Ethereum Gateway eth.limo

Vitalik Warns of DNS Registrar Attack on Ethereum Gateway eth.limo

Vitalik Buterin has flagged a DNS registrar attack on eth.limo, the ENS gateway service, and is warning users to stay cautious during the team's response.

Apr 18, 2026Read Analysis →
Zerion Takes Down Its Web App After Detecting Abnormal Activity

Zerion Takes Down Its Web App After Detecting Abnormal Activity

Zerion proactively shut down app.zerion.io and Blockaid blocked the site. Mobile apps and browser extension are unaffected. User funds remain safe.

Apr 11, 2026Read Analysis →
Operation Atlantic Froze 12 Million Dollars in Crypto Stolen Through Approval Phishing

Operation Atlantic Froze 12 Million Dollars in Crypto Stolen Through Approval Phishing

US Secret Service, UK NCA, and Canadian police traced $45M in crypto fraud across 30 countries, freezing $12M and contacting 3,000 victims directly.

Apr 10, 2026Read Analysis →
Solana Foundation Launches STRIDE and SIRN to Harden DeFi Security After Drift

Solana Foundation Launches STRIDE and SIRN to Harden DeFi Security After Drift

The Solana Foundation rolls out two security programs, STRIDE for formal verification and SIRN for 24/7 threat monitoring, six days after the $280M Drift exploit.

Apr 7, 2026Read Analysis →
Ledger CTO Says AI Is Driving the Cost of Crypto Attacks Toward Zero

Ledger CTO Says AI Is Driving the Cost of Crypto Attacks Toward Zero

Ledger CTO Charles Guillemet warns that AI is making crypto exploits faster, cheaper, and harder to stop, with $1.4 billion already lost this year.

Apr 5, 2026Read Analysis →
Do Crypto Debit Cards With No KYC Really Exist?

Do Crypto Debit Cards With No KYC Really Exist?

Most no-KYC crypto card claims turn out to mean low limits, delayed verification, or temporary access. Here is what regulation, enforcement, and market history actually say.

Apr 1, 2026Read Analysis →
Google Pulls Its Post-Quantum Deadline Forward to 2029, and Crypto Has Three Years to Catch Up

Google Pulls Its Post-Quantum Deadline Forward to 2029, and Crypto Has Three Years to Catch Up

Google accelerated its post-quantum cryptography migration from 2035 to 2029, putting pressure on Bitcoin and Ethereum developers racing to replace ECDSA.

Mar 26, 2026Read Analysis →
Google Finds iOS Malware That Hunts for Coinbase, MetaMask, and 11 Other Crypto Apps

Google Finds iOS Malware That Hunts for Coinbase, MetaMask, and 11 Other Crypto Apps

The DarkSword exploit chain uses six iOS vulnerabilities to deploy Ghostblade, a data stealer targeting 13 crypto exchange and wallet apps on unpatched iPhones.

Mar 20, 2026Read Analysis →
Bitrefill Was Hacked by Lazarus Group, and 18,500 Customer Records Were Exposed

Bitrefill Was Hacked by Lazarus Group, and 18,500 Customer Records Were Exposed

Bitrefill reveals a March 1 cyberattack linked to North Korea

Mar 18, 2026Read Analysis →
The US, UK, and Canada Just Launched a Joint Operation to Stop Crypto Approval Phishing in Real Time

The US, UK, and Canada Just Launched a Joint Operation to Stop Crypto Approval Phishing in Real Time

Operation Atlantic brings the Secret Service, NCA, and Ontario police together to disrupt approval phishing scams that stole $17 billion in crypto last year.

Mar 17, 2026Read Analysis →
Venus Protocol Loses 3.7 Million Dollars After an Attacker Spent Nine Months Cornering One Token

Venus Protocol Loses 3.7 Million Dollars After an Attacker Spent Nine Months Cornering One Token

An attacker accumulated 84% of Thena's THE supply cap on Venus Protocol, manipulated the price, and borrowed $3.7M in CAKE, BTC, and BNB before anyone noticed.

Mar 15, 2026Read Analysis →
Crypto Losses Dropped 87% in February, but Hackers Stopped Attacking Code and Started Attacking You

Crypto Losses Dropped 87% in February, but Hackers Stopped Attacking Code and Started Attacking You

February 2026 crypto losses fell to $26-49M from $385M in January. The catch: social engineering now causes more damage than smart contract exploits.

Mar 14, 2026Read Analysis →
Hackers Hijacked the BONK.fun Domain and Planted a Wallet Drainer on Solana Biggest Meme Launchpad

Hackers Hijacked the BONK.fun Domain and Planted a Wallet Drainer on Solana Biggest Meme Launchpad

BONK.fun team confirms hackers took over a team account and embedded a crypto drainer on the Solana token launchpad domain, tricking users with a fake TOS prompt.

Mar 12, 2026Read Analysis →
Ledger Donjon Found a MediaTek Flaw That Lets Attackers Steal Seed Phrases From Android Phones in 45 Seconds

Ledger Donjon Found a MediaTek Flaw That Lets Attackers Steal Seed Phrases From Android Phones in 45 Seconds

A secure boot chain vulnerability in MediaTek processors allowed USB-based seed extraction from Trust Wallet, Phantom, and four other wallets. Patched January 2026.

Mar 12, 2026Read Analysis →
Are Crypto Cards Safe? What Happens When Your Card Issuer Fails

Are Crypto Cards Safe? What Happens When Your Card Issuer Fails

What protects your money on a crypto card? E-money segregation, Visa/MC chargebacks, custody models, and lessons from three real card program collapses.

Mar 9, 2026Read Analysis →
A Coinbase-Backed Startup Just Built a Quantum-Proof Wallet Prototype Because Current Exchange Architecture Will Break

A Coinbase-Backed Startup Just Built a Quantum-Proof Wallet Prototype Because Current Exchange Architecture Will Break

Project Eleven releases a post-quantum wallet prototype that restores key derivation for exchanges, solving a critical BIP32 vulnerability before NIST deadlines hit.

Mar 9, 2026Read Analysis →
Google Uncovers Coruna, a Spy-Grade iOS Exploit Kit That Steals Crypto Wallets From Older iPhones

Google Uncovers Coruna, a Spy-Grade iOS Exploit Kit That Steals Crypto Wallets From Older iPhones

Google's threat team found a 23-exploit iPhone kit called Coruna that steals seed phrases from MetaMask, Bitget Wallet, and Exodus. Here is what you need to know.

Mar 5, 2026Read Analysis →
An AI Bug Hunter Caught a Critical XRP Ledger Flaw That Could Have Drained $80 Billion, and No Human Spotted It First

An AI Bug Hunter Caught a Critical XRP Ledger Flaw That Could Have Drained $80 Billion, and No Human Spotted It First

Cantina's AI tool Apex flagged a signature bypass in the XRPL Batch amendment that would have let attackers drain wallets without private keys.

Feb 27, 2026Read Analysis →
IoTeX Bridge Drained for $8.8 Million After a Private Key Compromise, and the Attacker Is Already Routing Funds Through THORChain to Bitcoin

IoTeX Bridge Drained for $8.8 Million After a Private Key Compromise, and the Attacker Is Already Routing Funds Through THORChain to Bitcoin

A private key exploit gave an attacker control of IoTeX bridge contracts, draining $8.8M in tokens. Funds are being laundered through THORChain to Bitcoin.

Feb 21, 2026Read Analysis →
Uniswap Founder Hayden Adams Says the Ad Economy Needs to Go After a Fake Google Ad Drains a Trader's Entire Net Worth

Uniswap Founder Hayden Adams Says the Ad Economy Needs to Go After a Fake Google Ad Drains a Trader's Entire Net Worth

A fraudulent Google ad mimicking Uniswap drained a trader's mid-six-figure portfolio using the AngelFerno wallet drainer as phishing scams hit $370M in January.

Feb 21, 2026Read Analysis →
Specialized AI Detects 92 Percent of Real-World DeFi Exploits While Generic Models Catch Just a Third

Specialized AI Detects 92 Percent of Real-World DeFi Exploits While Generic Models Catch Just a Third

Cecuro's AI security agent detected 92% of exploited DeFi contracts worth $228M, while a GPT-5.1 baseline caught only 34%. The benchmark is now open source.

Feb 20, 2026Read Analysis →
A Single Misconfigured Oracle Valued cbETH at $1.12 Instead of $2,200, Draining $1.78 Million From Moonwell in Four Minutes

A Single Misconfigured Oracle Valued cbETH at $1.12 Instead of $2,200, Draining $1.78 Million From Moonwell in Four Minutes

Moonwell lost $1.78M in bad debt after a Chainlink OEV oracle wrapper misconfigured cbETH pricing at $1.12, with auditors linking the bug to AI-generated code.

Feb 18, 2026Read Analysis →
Scammers Are Mailing Fake Trezor and Ledger Letters With QR Codes Designed to Drain Your Wallet

Scammers Are Mailing Fake Trezor and Ledger Letters With QR Codes Designed to Drain Your Wallet

Physical phishing letters impersonating Trezor and Ledger use QR codes to steal recovery phrases. Here is how the attack works and how to protect yourself.

Feb 16, 2026Read Analysis →
The Mixin Network Hacker Resurfaces With $117M in ETH After Two Years of Silence, Routing the First $4M Through Tornado Cash

The Mixin Network Hacker Resurfaces With $117M in ETH After Two Years of Silence, Routing the First $4M Through Tornado Cash

A wallet tied to the $200M Mixin Network hack has begun liquidating 59,854 ETH through Tornado Cash after more than two years of dormancy.

Feb 13, 2026Read Analysis →
Ledger Draws a Line in the Sand on AI Agent Security: Propose, Don't Sign

Ledger Draws a Line in the Sand on AI Agent Security: Propose, Don't Sign

Ledger argues AI agents should never hold private keys, pushing a 'propose, humans sign' model that challenges Coinbase's agentic wallet approach.

Feb 12, 2026Read Analysis →
Bitget and BlockSec Release the UEX Security Standard, Setting a New Benchmark for Asset Protection Across Crypto and TradFi

Bitget and BlockSec Release the UEX Security Standard, Setting a New Benchmark for Asset Protection Across Crypto and TradFi

Bitget partners with BlockSec to publish the UEX Security Standard, a system-level security framework for exchanges bridging crypto and traditional markets.

Feb 9, 2026Read Analysis →
Binance's Human Firewall Prevented $6.69 Billion in Scam Losses in 2025, Protecting 5.4 Million Users

Binance's Human Firewall Prevented $6.69 Billion in Scam Losses in 2025, Protecting 5.4 Million Users

Binance's 9-level anti-scam system combined AI monitoring with human wake-up calls to prevent $6.69B in fraud losses and shield 5.4M users in 2025.

Feb 8, 2026Read Analysis →
KuCoin Pushes Passkeys as Crypto Exchanges Race to Kill the Password

KuCoin Pushes Passkeys as Crypto Exchanges Race to Kill the Password

KuCoin now supports full passwordless login via passkeys. Here is how the FIDO2 standard is reshaping crypto exchange security and why it matters for your funds.

Feb 8, 2026Read Analysis →
OKX Wallet Has Blocked 8.53 Million Malicious Domains and Recovered $896 Million in Assets Since Launch

OKX Wallet Has Blocked 8.53 Million Malicious Domains and Recovered $896 Million in Assets Since Launch

OKX reveals wallet security stats: 8.53M malicious domains blocked, 23M+ risky tokens flagged, and nearly $900M in user assets recovered since launch.

Feb 8, 2026Read Analysis →
Binance Recovers $12.8 Million in Stolen Funds in 2025 as Anti-Scam Machine Scales Up

Binance Recovers $12.8 Million in Stolen Funds in 2025 as Anti-Scam Machine Scales Up

Binance recovered $12.8M in stolen crypto in 2025, up 41% from 2024. Here is how their AI-powered anti-scam system protects users.

Feb 7, 2026Read Analysis →
Binance Warns of Lookalike Wallet Address Scams: How to Detect and Prevent Them

Binance Warns of Lookalike Wallet Address Scams: How to Detect and Prevent Them

Binance issues a detailed warning on lookalike wallet address scams that trick users into sending funds to fraudulent addresses. Detection tips inside.

Feb 6, 2026Read Analysis →
Binance Pushes ED25519 as the Gold Standard for API Security and Deprecates HMAC Keys

Binance Pushes ED25519 as the Gold Standard for API Security and Deprecates HMAC Keys

Binance recommends ED25519 signatures for API security, deprecating HMAC. Here's what the upgrade means for traders, bots, and card-linked accounts.

Feb 6, 2026Read Analysis →
COCA Wallet Migrates to Privy: Seedless Authentication Comes to MPC Wallets

COCA Wallet Migrates to Privy: Seedless Authentication Comes to MPC Wallets

COCA Wallet integrates Privy for seedless login. No more seed phrases, familiar auth methods, and full self-custody preserved.

Feb 5, 2026Read Analysis →
Lombard Finance Integrates Chainlink Proof of Reserve to Bring Transparency to $1.1B BTCFi Protocol

Lombard Finance Integrates Chainlink Proof of Reserve to Bring Transparency to $1.1B BTCFi Protocol

Lombard Finance adds Chainlink Proof of Reserve, CCIP, and Price Feeds to verify LBTC collateralization across 15 chains in real-time.

Feb 5, 2026Read Analysis →
Binance Launches Security Center: Automatic Risk Scanning for Web3 Wallet Users

Binance Launches Security Center: Automatic Risk Scanning for Web3 Wallet Users

Binance introduces Security Center, an automatic risk scanner for its Web3 Wallet. We analyze what it checks, how it protects funds, and what it means for users.

Feb 3, 2026Read Analysis →
Jupiter ASR Claim Security: Why You Should Never Import Your Seed Phrase

Jupiter ASR Claim Security: Why You Should Never Import Your Seed Phrase

Jupiter has faced security concerns over its ASR claim flow. Learn why seed phrase imports are dangerous for card-linked wallets and what the new direct claim flow means.

Feb 1, 2026Read Analysis →
ether.fi x MEXC Co-Branded Card: The Accountability Stack and User Protections

ether.fi x MEXC Co-Branded Card: The Accountability Stack and User Protections

A definitive guide to the ether.fi x MEXC co-branded card. Analyze the 15% dining boost, the issuer accountability stack, and dispute protection frameworks.

Feb 1, 2026Read Analysis →
RedotPay Adds Apple Pay and Google Pay: Tap-to-Pay Goes Mainstream

RedotPay Adds Apple Pay and Google Pay: Tap-to-Pay Goes Mainstream

RedotPay now supports Apple Pay and Google Pay. Here is what mobile wallet integration changes for security, daily usability, and cardholder behavior.

Jan 31, 2026Read Analysis →
Binance MPC Wallets: A New Standard for Card-Linked Custody?

Binance MPC Wallets: A New Standard for Card-Linked Custody?

Binance has launched MPC wallet integration for its ecosystem. Analyze how Multi-Party Computation changes security for crypto cardholders and reduces single-point-of-failure risk.

Jan 31, 2026Read Analysis →
The 'Convincing Marshall' Scam: Why Crypto Cardholders are Targets

The 'Convincing Marshall' Scam: Why Crypto Cardholders are Targets

A deep dive into high-pressure social engineering scams targeting cardholders. Learn how scammers use 'official' authority to bypass security and what you can do to protect your wallet.

Jan 30, 2026Read Analysis →
The 2026 Crypto Card Custody Bible: From Seed Phrases to BaaS Risk

The 2026 Crypto Card Custody Bible: From Seed Phrases to BaaS Risk

A 2000-word deep dive into the technical and legal layers of crypto card custody. Learn about MPC, Account Abstraction (ERC-4337), and how to audit your issuer's solvency risk.

Jan 29, 2026Read Analysis →
The CLARITY Act vs. Stablecoin Rewards: Why Coinbase is Fighting Back

The CLARITY Act vs. Stablecoin Rewards: Why Coinbase is Fighting Back

The US CLARITY Act could effectively ban stablecoin rewards. Learn why Coinbase withdrew support, the impact on cardholders, and the $243M revenue stake.

Jan 28, 2026Read Analysis →
What DeFi Security Platforms Actually Do, and Why Audits Are No Longer Enough

What DeFi Security Platforms Actually Do, and Why Audits Are No Longer Enough

DeFi security no longer stops at audits. Here is what modern security platforms actually do, from monitoring and alerting to oracle, permissions, and incident-response controls.

Jan 28, 2026Read Analysis →
Self-Custody Crypto Cards: What Changes When You Hold Your Own Keys

Self-Custody Crypto Cards: What Changes When You Hold Your Own Keys

Self-custody vs custodial crypto cards: security architecture, gas fees, recovery mechanisms, real breach case studies, and a cost-benefit analysis of 7 cards with actual numbers.

Jan 23, 2026Read Analysis →
Smart Contract Fraud Protection: Can Code Stop Card Theft?

Smart Contract Fraud Protection: Can Code Stop Card Theft?

How smart contracts protect your crypto card from fraud. Learn about on-chain spending limits, guardians, and the future of decentralized card security.

Jan 22, 2026Read Analysis →
Self-Sovereign Identity: The Future of Crypto Card KYC

Self-Sovereign Identity: The Future of Crypto Card KYC

The end of 'sending your passport' is here. Learn how ZK-KYC and Self-Sovereign Identity (SSI) are making crypto cards private and secure.

Jan 22, 2026Read Analysis →
The Regulatory Landscape of 2026: MiCA 2.0 and Your Crypto Card

The Regulatory Landscape of 2026: MiCA 2.0 and Your Crypto Card

How does MiCA 2.0 impact your crypto card choice? Learn about the new EU regulations and how they affect card privacy, limits, and availability.

Jan 22, 2026Read Analysis →
MPC Security for Crypto Cards: How Key Splitting Protects Your Funds

MPC Security for Crypto Cards: How Key Splitting Protects Your Funds

How Multi-Party Computation (MPC) protects crypto cards: threshold signatures, key share architecture, vs. multisig comparison, real security incidents, and implementation across 12 major cards.

Jan 21, 2026Read Analysis →

Category Stats

Total Articles113
Latest UpdateJun 19, 2026