Fresh incidents, analyzed daily.
AI-assisted first pass, reviewed by us before it's published here.
Liquid Network sidechain exploit drains about 3,998 L-BTC
Liquid Network suffered a major sidechain exploit that minted and pegged out about 3,998 L-BTC, with losses estimated around $320 million. The incident forced a pause in peg operations and block production while the software was patched. Blockstream said the federation keys were not compromised.
ether.fi legacy AtomicQueue exploit drains 15.45 ETH
ether.fi says a legacy withdrawal queue was abused, draining about 15.45 ETH from 11 user wallets. The loss came from stale approvals tied to a deprecated helper contract, not from the core protocol. The company says affected users will be reimbursed.
Injective exploit drains $4.9M through market settlement logic
Injective reportedly lost about $4.9 million after an attacker abused market creation and settlement logic tied to a fake oracle and refund path. The chain later slowed severely and validators halted it after the exploit effectively collapsed under its own load. Ontology separately paused its mainnet as a precaution, saying user assets were not lost.
Aquifer Solana DEX drained via fake balance file abuse
Aquifer, a Solana trading venue, was drained of about $2.47 million in 212 transactions over 40 minutes. The attacker used a malicious program and fake token-account data that the venue accepted as real. Stolen assets were moved onward, including proceeds traced to Ethereum.
Tectonic loses $75M in price-manipulation attack on Cronos
Tectonic, the largest lending protocol on Cronos, was hit by a major price-manipulation attack valued at about $75 million. The attacker pushed a thinly traded token price sharply higher, borrowed against the inflated collateral, and forced Cronos to halt block production. About $6 million reportedly bridged to Ethereum before the chain rollback reversed the rest. TRM Labs says 2026 has already set a new high for price-manipulation exploits.
CCC token exploit drains $117,000 on Binance Smart Chain
A CCC token exploit on Binance Smart Chain drained an estimated $117,000 from a liquidity pool. Security alerts said the attack abused the token contract’s sell() logic to burn tokens held in the pool, distorting the token’s price. No recovery plan had been announced at the time of the alert.
The Sandbox pledges repayment after bridge exploit
The Sandbox said an Aug. 21 bridge exploit drained about $700,000 from an Ethereum vault tied to bridged SAND. The project said eligible users will be repaid 1:1 from treasury funds, and compromised bridge contracts will be retired. The incident affected bridged SAND on Base and BNB Chain, not Ethereum or Polygon.
Cosmos EVM accounting flaw exploited across six chains
A shared Cosmos EVM accounting bug was exploited across six networks, including MANTRA, TAC, and KiiChain. Public reports put the total theft near $6 million, with MANTRA accounting for the largest disclosed share at about $3.6 million. Cosmos Labs said it warned dozens of networks after the attacks began.
Moonwell loses $8.7M in Base oracle manipulation attack
Moonwell lost about $8.7 million on Aug. 27 after an attacker manipulated the price of the thinly traded MAMO token used as collateral on Base. The inflated price let the attacker borrow real assets including cbBTC, USDC, wstETH, and ETH. The incident left the protocol with bad debt and renewed concern about spot-price oracle risk.
CISA Flags Actively Exploited Metabase SQL Injection: BI Systems Targeted for Production DB Key Theft
CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog. The SQL injection bug in the Metabase BI platform allows attackers to compromise backend databases housing user mapping and API keys.
Microsoft Defender 'ShieldBreak' Zero-Day Patch Bypass Disclosed: Local SYSTEM Access Threatens Endpoint Wallets
A newly released exploit chain named 'ShieldBreak' completely bypasses Microsoft's initial patch for CVE-2026-50656 in Defender's Malware Protection Engine, granting standard users NT AUTHORITY\SYSTEM privileges.
Coinsbuy reportedly hit by $7.9 million theft
Coinsbuy reportedly suffered a $7.9 million crypto theft across Ethereum and Tron wallets. The platform paused deposits and withdrawals, then later said services resumed and customer funds were covered from reserves. The incident underscores exchange-wallet compromise risk.
Unlimited Technology Systems Breach Exposes 3.8M Records: Mass PII Exfiltration Fuels Targeted Crypto SIM-Swaps
A major data breach affecting 3.8 million individuals exposed personal, medical, and identity details. Cybercriminals are using massive PII datasets to coordinate targeted SIM swaps and social engineering against crypto investors.
Metabase CVSS 10.0 Zero-Day Exploited in the Wild: Database Key Theft Threatens Web3 Analytics & Treasury Stores
Attackers actively exploited an unpatched CVSS 10.0 zero-day in Metabase BI software (versions 1.58+), gaining root admin access to extract stored credentials for all connected production databases.
IBM Langflow AI Framework Hit by Remote Code Injection: AI Bots & Trading Pipelines Targeted
A critical code injection vulnerability in IBM Langflow (CVE-2026-9198) was added to CISA's KEV catalog after active exploitation was detected. Exploiting this AI workflow engine grants hackers arbitrary code execution on backend servers hosting trading bots and Web3 analytics tools.
Critical N-able N-central Zero-Day Exploited: MSP Platform Breach Threatens Downstream Web3 Infrastructure
A critical authentication bypass flaw in N-able’s N-central RMM platform is under active exploitation in the wild. Attackers gaining administrative control over MSP management servers can silently deploy keyloggers and drainers across thousands of managed enterprise endpoints.
CaptiveCrunch Campaign Hijacks Hotel Wi-Fi to Push RAT Malware Targeting Remote Web3 Executives
Threat actor Storm-2945 is using compromised hotel Wi-Fi networks to serve fake browser updates that install 'CornFlake' RAT malware, targeting remote crypto teams and conference travelers.
Cisco Secure FMC Zero-Day Exploited in the Wild: Enterprise Firewall Flaw Threatens Node Infrastructure
CISA added an actively exploited Cisco Secure Firewall Management Center flaw (CVE-2026-20316) to its KEV catalog. The bug allows unauthenticated static credential access to core perimeter firewalls.
Adform Supply Chain Attack: Hackers Poison Advertising Script to Swap Crypto Wallet Addresses
Attackers hijacked a core tracking script served by ad-tech giant Adform (reaching 14,000+ businesses), turning a trusted tracking pixel into a browser-based crypto address rewriter.
Coldcard Mk3 Seed Generation Flaw Exploited: $38M Drained in Automated 25-Minute Bitcoin Sweep
A critical firmware flaw in Coldcard Mk3 hardware wallets bypassed hardware randomness, creating predictable 24-word seed phrases. Attackers brute-forced the weakened entropy space to sweep 594 BTC across 500 wallets in under half an hour.
Origin Energy Breach: 900,000 Records Leaked; Why Reused Passwords Are the #1 Crypto Threat
Origin Energy confirmed a breach affecting 900,000 customers. With PII and account details exposed, the threat of credential stuffing against crypto exchange accounts is at an all-time high.
Seoul Police Bust Fake Flare Network Staking Ring: $8.5M in XRP Stolen via Hired Actors & Spoofed Domains
A sophisticated phishing ring hired actors to promote a fake Flare Network staking portal on YouTube, stealing $8.5M in XRP from 71 investors in just 8 days before police traced $18.8M across linked wallets.
AFX Trade Arbitrum Bridge Drained for $24.15M Following Multi-Sig Validator Key Compromise
Attackers compromised 5 out of 9 validator keys on AFX Trade's third-party Arbitrum bridge, reaching quorum to execute a fraudulent $24.15 million USDC withdrawal into Ethereum.
Undocumented Tenda Router Backdoor Exposed: Hardware Risks to Node Operators and RPC Endpoints
Security researchers uncovered an undocumented administrative backdoor (CVE-2026-11405) across multiple Tenda router models, allowing attackers to hijack network traffic and modify DNS settings.
Phishing signature drains $999,999 in USDT from Ethereum wallet
An Ethereum user reportedly lost $999,999 in USDT after signing a fraudulent approval. Attackers then used Multicall to move and split the funds quickly across a few transactions. The incident is another example of token-approval phishing at high value.
Aurum / NEYRO report alleges custodial drain hidden as “AI trading”
A forensic report alleges that Aurum’s NEYRO product did not perform real trading and instead routed deposits into a pool controlled by the operator. The report says user funds were then swept out and spread across many wallets. The claimed losses are in the tens of millions.
Gravity Bridge reportedly drained in suspected signing-key compromise
Gravity Bridge was reported to have lost about $5.4 million in what investigators suspect was a signing key compromise. Validators reportedly halted the bridge while the incident was investigated. The case highlights the danger of privileged key theft in cross-chain systems.
LayerZero-based cross-chain trick leads to Kelp DAO theft and Aave spillover
A cross-chain attack on Kelp DAO was reported to have released 116,500 rsETH to an attacker after a message was accepted as legitimate. The stolen assets were then used to borrow heavily across DeFi platforms, including Aave, contributing to a broader market panic and large withdrawals.
JFrog Artifactory Zero-Days Uncovered: How Package Registry Flaws Expose Web3 Build Pipelines
Critical privilege escalation zero-days in JFrog Artifactory allow unauthenticated attackers to breach package repositories, posing a severe threat of malicious dependency injection in Web3 CI/CD pipelines.
Garden Finance Exploit: Supply Chain Compromise Drains $450K USDT Across Multiple Chains
An off-chain solver database breach allowed hackers to inject fake transaction records into Garden Finance’s HTLC bridge, mistakenly releasing $450K USDT across Ethereum, Arbitrum, Base, and BNB Chain.