Liquid Bridge Loses 4,000 BTC as CTO Rejects Whitehat Claim
Ledger's CTO publicly disputes the framing, comparing the drain to the Ronin hack while exchanges freeze LBTC. Blockstream says the SideSwap key was used, not compromised.
Ledger's CTO publicly disputes the framing, comparing the drain to the Ronin hack while exchanges freeze LBTC. Blockstream says the SideSwap key was used, not compromised.
The closure marks a rare failure for a Tether-affiliated exchange, raising questions about custody oversight at regional venues operating under the stablecoin giant's backing.
Tether exclusively led Orionx's Series A in 2025; a $7M+ hole in customer BTC, ETH, XRP, and POL now puts the stablecoin issuer's due-diligence record back in the spotlight.
The case just shifted from a static forensic ledger to a live cross-chain trace: 20.5 BTC routed through 34 swaps while 1,402 BTC of identified loot still sits parked.
The precautionary halt widens the event from a DeFi protocol incident to a broader operational risk for Cronos users, lenders and ecosystem projects.
A researcher flagged the integer-underflow flaw on April 25 under Cosmos Labs' bounty program, but testers ruled live chains safe, a patch shipped silent, and within 20 hours of a public code change…
The pause breaks a project that, as recently as March, advertised 100% mainnet uptime on its own website, and the Foundation has yet to name the attack vector, the targeted addresses, or a restart…
Two MANTRA wallets were touched, but no addresses, hashes, or exploit path have been disclosed. Operators are now re-pulling a tag whose changes they cannot fully audit.
Behind the arrest sits a $94M customer-loss probe, roughly 4,500 inaccessible BTC, and a 2026-2028 Olympic sponsorship deal now sitting inside the Polish criminal file.
The 2014-era weakness is unusually hard to undo: a vulnerable phrase carries the flaw with it, and patching the app does not regenerate the secret. Migrate, do not update.
The portal lets users log balances and file claims but restores nothing: no withdrawals, no recovery guarantees, and no disclosed timetable for repayment.
The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.
The threat was contained with no user funds exploited, but deposits, withdrawals and MANTRA transactions remain frozen pending testing for a possible same-day restart.
Beyond the HBO breach, prosecutors allege that 8,000 professor accounts were compromised and attackers stole at least 31.5 TB of academic data and intellectual property.
The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.
The APR printed correctly until the moment a 20-bridge chain or a single-verifier oracle stopped behaving; April was the reminder that headline yield tells you the system worked, not whether it…
The Wyoming Stable Token Commission is the first US public entity to swap blockchain infrastructure on security grounds, joining a $15B migration wave triggered by the $292M Kelp DAO exploit.
The $100M in physical theft is the headline; the 40,000-record breach is the structural warning. Hardware-wallet security now means controlling what sits behind the device, not just the device itself.
Funds stayed safe, but national IDs and bank details now in circulation expose 200,000 customers to follow-on phishing, and the breach lands in a wave that already hit SafePal and Trezor.
The bug sat in open-source code for five years while a community built on 'don't trust, verify' outsourced its judgment to one vendor's reputation, Foundation CEO Zach Herbert argues.