DeTracker Security Feed

What happens when a fully-licensed, fully-compliant stablecoin issuer still gets hit? In May, one of StablR's three signing keys was compromised, and the attacker minted tokens directly into their own wallet, with no custody breach and no stolen funds involved. Hypernative's https://t.co/lFaqmeMEWR

In May, one of StablR's three signing keys was compromised, allowing an attacker to mint tokens directly into their wallet. This incident occurred despite StablR being a licensed and compliant stablecoin issuer, with no custody breach or stolen funds involved.

#StablR

Governance takeovers recently drained $22M via bought and borrowed votes. Blockaid's Cosigner adds an independent signer to multisig and MPC setups, validating what each transaction actually does so a malicious proposal fails to execute. Read more: https://t.co/Y49D6QXm1x https://t.co/OKddITdyTz

Governance takeovers have recently drained $22 million through bought and borrowed votes. Blockaid's Cosigner aims to mitigate this by adding an independent signer to multisig and MPC setups to validate transactions.

🚨 Beware of Solidity Pro: A Targeted Poisoning Attack on #Web3 Developers SlowMist Security Team has identified malicious activity in Solidity Pro, a #VSCode extension targeting #Solidity/Web3 developers. Historical versions under two publisher identities, helper-beeps and https://t.co/4TLBvoRylX

Malicious activity has been identified in Solidity Pro, a VSCode extension targeting Solidity/Web3 developers. Historical versions under two publisher identities, helper-beeps and another, are affected.

#PeckShieldAlert The address labeled Bofur Capital got hit for $2M via address poisoning after withdrawing from #Compound. Phisher sent a 0.0002 USDC dust tx to spoof the address, and the victim copy-pasted the wrong one -$2M drained. Funds have since been swapped to 2M $DAI, https://t.co/gowY3GJnoD

The address labeled Bofur Capital lost $2M due to an address poisoning attack after withdrawing from Compound. A phisher sent a small USDC transaction to spoof the address, and the victim mistakenly copied the wrong address, leading to the drain. The stolen funds were swapped to 2M DAI.

#Compound #DAI #USDC

#CertiKInsight 🚨 Victim address 0x13e382dfe53207E9ce2eeEab330F69da2794179E has been drained of ~$25M in assets, a second time since 2023. Much of the assets have been swapped for DAI and are now at https://t.co/P6HWOk9AjL. Stay Vigilant! https://t.co/gh0ddR0rbC https://t.co/QkNN7cMHgq

A victim address has been drained of approximately $25 million in assets for the second time since 2023. The stolen assets were swapped for DAI and are now held at a specific address.

#DAI

#CertiKInsight 🚨 We detected Tornado Cash deposits that trace to a suspicious outflow of $1.284M USDC on Aug 11th from @vultisig related address: https://t.co/JM3NEGhvXO ~$1.092M USDC was swapped into 575.4 ETH, then deposited into Tornado Cash from two EOAs. Stay Vigilant! https://t.co/o66Os85Vm0

A suspicious outflow of $1.284 million USDC was detected on August 11th from a vultisig-related address. Approximately $1.092 million USDC was swapped for ETH and deposited into Tornado Cash.

#CASH #USDC

#PeckShieldAlert Specter has reported that unknown victims were drained of $25.6M in crypto, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M). The hacker has swapped the stolen funds for 20M $DAI and 3K $ETH ($5.64M) and now holds them across 4 addresses. https://t.co/GcmqDA91MW

Unknown victims were drained of $25.6 million in crypto, including aWBTC, DAI, WBTC, and ETH. The hacker swapped the stolen funds and holds them across four addresses.

#DAI

critical key_compromise

Cold Card - Rekt

A firmware vulnerability in Coldcard allowed attackers to brute-force seeds offline, resulting in an estimated $130 million stolen from at least 15 attackers. Most funds remain untouched.

#ColdCard

Coinsbuy - Rekt

Coinsbuy lost $8.07 million across TRON and Ethereum within an hour. The project's Twitter account has been dormant since 2020, and the cause of the failure has not been disclosed.

#Coinsbuy

BlockThreat - Week 33, 2026

In week 33 of 2026, $3.3 million was stolen across four incidents, including a consensus failure on Harmony and Ravencoin, and multiple PII leaks affecting crypto users.