Fresh incidents, analyzed daily.
AI-assisted first pass, reviewed by us before it's published here.
WEMIX Smart Contract Hacked: $6.25M in Stablecoins Illegally Minted After Owner Key Compromise
Attackers compromised the owner/admin credentials for WEMIX$ stablecoin smart contracts, fraudulently minting 5.22M unbacked tokens before swapping and bridging out $6.25 million.
Russian APT Campaign Targeting Zimbra Mail Servers: A Blueprint for Targeted Web3 Phishing
International intelligence confirms an APT campaign targeting Zimbra webmail servers. Compromised internal communications directly enable high-precision social engineering against protocol admins and multisig keyholders.
Critical Check Point Firewall Zero-Day Hit by Active Exploitation: A Direct Threat to Validator Integrity
A CVSS 9.1 authentication bypass in Check Point SmartConsole allows attackers to modify firewall policies, potentially exposing isolated crypto bridge validators to direct intrusion.
Active $9.7M Exploit Hits Crypto Payment Processor Triple-A
Crypto payment processor Triple-A is facing an ongoing hot wallet breach, with over $9.7M routed to a single attacker address—and deposits are still live. Read our breakdown of the attack and crucial security hardening practices every crypto business must implement to prevent key compromises.
Ostium drained of $23.75M in oracle signer key compromise
Ostium confirmed a loss of 23,752,746 USDC from its OLP vault after an attacker obtained an oracle signer private key. The protocol paused trading and later reopened after hardening measures. The funds were converted into ETH and routed through Tornado Cash.
Verus Ethereum Bridge hit again in $7.54M exploit
The Verus Ethereum Bridge suffered another exploit, this time draining about $7.54 million from the same bridge contract hit earlier in the year. Security researchers said the attack used the bridge’s import path to trigger payouts that were not properly backed on the source side. The incident added to a series of bridge losses this month.
AFX Trade loses $24.15M after bridge validator keys are compromised
AFX Trade was drained of about $24.15 million in USDC after an attacker compromised the signing keys used by its bridge validators. The withdrawal was accepted by the protocol because enough validator signatures were present. The stolen funds were then moved to Ethereum and swapped for ETH.