Harmony weighs full rollback as $ONE mint floods exchanges
A successful rollback on a major chain would reset a question most networks never had to answer: who eats the loss when the bridge mints in error?
Crypto security covers the failures, attacks and deceptive practices that can put digital assets at risk: compromised exchange wallets, smart-contract exploits, governance attacks, flash-loan manipulation, phishing, scams and privacy breaches. The consequences often extend beyond the protocol first affected. Stolen USDC may be swapped for ETH, an exchange may suspend withdrawals after hot-wallet outflows, or a governance proposal may redirect a DAO treasury. For holders of BTC, ETH, SOL and stablecoins such as USDT and USDC, understanding the attack path is essential to judging whether an incident threatens one platform, connected protocols or the wider market.
Zipp tracks incidents from the first on-chain alert through confirmation, containment and recovery. Coverage examines transaction trails, attacker methods, disputed loss estimates, withdrawal status, token approvals, bridge and oracle dependencies, validator or admin-key controls, and any reimbursement or recovery plan. Recent reporting has followed the Ostium and Summer Finance exploits, the BONK DAO treasury attack, suspicious AscendEX hot-wallet movements and KelpDAO activity involving Chainlink CCIP. The desk also covers audits, disclosure practices and longer-term risks such as quantum computing, as well as sanctions enforcement, exchange exposure and blockchain tracing around Iran-linked CoinEx flows. We distinguish verified losses from funds merely moved or placed at risk, identify the evidence behind researchers’ claims, and monitor whether stolen assets are bridged, mixed, frozen or converted into assets including ETH. Privacy belongs to the same beat: readers need to know what transaction data is public, how analytics firms connect wallets, and where surveillance, compliance and user protection intersect.
A successful rollback on a major chain would reset a question most networks never had to answer: who eats the loss when the bridge mints in error?
The DPRK has spent years turning remote crypto hiring into a sanctions-evasion pipeline, and documenting how the bait works is one of the only public defences the rest of the industry has.
Over 1,600 victims handed $397M to a fund that promised crypto liquidity pool returns; the CFTC and SEC filed charges the same day, with Delgado already facing federal wire fraud counts.
Fear & Greed at 27 and BTC dominance at 56.4% frame a cautious market, while bridge security and SEC scrutiny add separate risks.
The 4B figure is ~27x larger than Harmony's 2023 staking bug and lands on the base layer rather than a bridge, with the rollback trade-off now the structural question for the next base-layer…
The scale of the allegation puts investor protection and compliance risk at the center of the market impact, while the claims remain unproven in court.
The rollback puts every RVN payment since Aug. 7 at risk of reversal, with two mining pools now choosing which version of recent history the rest of the network has to accept.
Traders sat in "Fear" ahead of a CPI print that could reset rate-cut expectations, while an $8M exchange hack and MicroStrategy's BTC sales added fresh jitters.
The $190K cap is the headline, but the real story is LND as a single-vendor credential risk now that attackers have demonstrated a working drain against the dominant Lightning node stack.
Fraud losses, state bans, KYC rules and high fees are pushing the US Bitcoin ATM sector toward a broader business-model rethink.
The bounty is set at 10% of recovered funds, capped at 3 BTC, while the flaw puts connected wallets and LND nodes at risk.
The updated roadmap signals a structural shift: Ethereum is hardening its foundations against quantum threats while pushing native rollups and leaner protocol design as the next scalability layer.
The shift broadens Ethereum's development agenda beyond upgrade sequencing, with privacy and resilience against quantum threats now treated as core protocol concerns.
Rising bug-bounty activity has not eliminated exploit risk, while Immunefi says its audit competitions found more serious bugs per engagement than tier-1 audits.
With the access method unresolved and roughly $972M already stolen across the sector by late July, the incident sharpens focus on exchange withdrawal controls.
AI-assisted financial lures raise the security risk for crypto firms, fintech providers and investors, making phishing resilience part of market infrastructure.
The episode turns a planned L2 shutdown into a test of bridge reliability and user exit procedures across DeFi.
The giants (BUIDL, USYC, iBENJI) sit below 1% utilization. Smaller credit and reinsurance tokens hit 55-98%. That gap is the bull case for the next leg of tokenization.
The $1.1B in H1 exploits and the 70-90% altcoin collapse broke the token-treasury funding model. Survivors like Hyperliquid, Aave and Ether.fi charge fees in stablecoins or cash while peers funded…
The figures put custody choices at the center of Bitcoin's adoption story, while sustained activity will determine how durable the signal is.
A hack is a broad term for unauthorized access or theft, including compromised keys, accounts and infrastructure. A smart-contract exploit specifically abuses faulty code, economic design or permissions in an on-chain application, sometimes without breaching its servers.
Check whether the figure is supported by identifiable on-chain transactions, a statement from the affected project and independent analysis. Large wallet movements are not automatically losses; funds may be relocated, quarantined or counted more than once.
Stablecoin issuers may be able to freeze tokens at specific addresses, while native assets such as ETH generally do not have an issuer-controlled freeze function. Swapping does not make funds untraceable, and exchanges, bridges or other services may still block them.
No. An audit reviews a defined codebase and scope at a particular stage, but it cannot guarantee that every bug, governance weakness, key-management failure or later upgrade is secure. Readers should check the audit scope, unresolved findings and whether deployed code matches the reviewed version.