In May, one of StablR's three signing keys was compromised, allowing an attacker to mint tokens directly into their wallet. This incident occurred despite StablR being a licensed and compliant stablecoin issuer, with no custody breach or stolen funds involved.
Governance takeovers have recently drained $22 million through bought and borrowed votes. Blockaid's Cosigner aims to mitigate this by adding an independent signer to multisig and MPC setups to validate transactions.
A user is questioning BitMart's liquidity and transparency regarding fund returns, stating that the exchange's actions have caused people to lose access to funds.
Malicious activity has been identified in Solidity Pro, a VSCode extension targeting Solidity/Web3 developers. Historical versions under two publisher identities, helper-beeps and another, are affected.
The Sandbox experienced a security breach where 500 million SAND tokens were minted on the Base network, potentially undermining tokenomics and risking market instability.
FlashstakeV2 mispriced its reward pool, allowing for instant upfront reward extraction of approximately 0.4285 ETH. The incident occurred in August 2026.
The address labeled Bofur Capital lost $2M due to an address poisoning attack after withdrawing from Compound. A phisher sent a small USDC transaction to spoof the address, and the victim mistakenly copied the wrong address, leading to the drain. The stolen funds were swapped to 2M DAI.
BounceBit will shut down its L1 chain and migrate to BNB Chain following an exploit that resulted in the loss of 286.5 million BB tokens. The migration emphasizes the need for robust blockchain infrastructure security.
A Rust supply chain attack has exposed components of the Solana ecosystem, creating potential for remote code execution and highlighting the need for enhanced security measures.
Coinkite advised Coldcard users to generate new seed phrases, warning that existing vulnerable seeds remain unsafe despite a firmware update aimed at strengthening seed generation.
Cybersecurity firm Rapid7 has identified a phishing campaign targeting 885,000 phone numbers, aiming to steal cryptocurrency by redirecting users to fake wallet websites.
A victim address has been drained of approximately $25 million in assets for the second time since 2023. The stolen assets were swapped for DAI and are now held at a specific address.
A suspicious outflow of $1.284 million USDC was detected on August 11th from a vultisig-related address. Approximately $1.092 million USDC was swapped for ETH and deposited into Tornado Cash.
Unknown victims were drained of $25.6 million in crypto, including aWBTC, DAI, WBTC, and ETH. The hacker swapped the stolen funds and holds them across four addresses.
BitBox has patched severe wallet flaws recommending users update to firmware version 9.26.5. The company has received no reports of exploitation or fund losses.
Boltz, a Bitcoin swap service, remains offline after its founders exited and an unnamed group agreed to take over. The service is being fixed for vulnerabilities that caused losses to the company.
SafePal reported a breach exposing the personal data of 39,798 buyers, including names, phone numbers, and shipping addresses, due to a flaw in an order-tracking plug-in. The stolen data is being advertised for sale.
Trezor reported that data from 14,000 users, including names, phone numbers, and shipping addresses, was exposed through a shipping provider flaw over 14 months. The company warns of potential phishing risks.
DefiLlama's founder delayed the mobile app launch due to phishing apps on the Apple Store that were documented to drain funds from crypto wallets. Apple removed one fake app.
A firmware vulnerability in Coldcard allowed attackers to brute-force seeds offline, resulting in an estimated $130 million stolen from at least 15 attackers. Most funds remain untouched.
Coinsbuy lost $8.07 million across TRON and Ethereum within an hour. The project's Twitter account has been dormant since 2020, and the cause of the failure has not been disclosed.
An attacker exploited the Harmony blockchain to mint 4 billion ONE tokens, causing the token price to plunge 40%. Harmony paused its token bridge, asked exchanges to freeze funds, and is considering a rollback.
Ravencoin experienced an exploit allowing attackers to mine invalid blocks, leading to a controversial rollback of four days of blockchain history. Several exchanges have halted withdrawals and deposits.
In week 33 of 2026, $3.3 million was stolen across four incidents, including a consensus failure on Harmony and Ravencoin, and multiple PII leaks affecting crypto users.
Maya Protocol experienced a withdrawal logic flaw resulting in a loss of approximately $1.7 million. The team has paused global operations to address the issues and is seeking fund recovery.