Loading prices…
Category

Security

Crypto security — hacks, smart-contract exploits, scams, audits, and privacy news that protects user funds.

Crypto security covers the failures, attacks and deceptive practices that can put digital assets at risk: compromised exchange wallets, smart-contract exploits, governance attacks, flash-loan manipulation, phishing, scams and privacy breaches. The consequences often extend beyond the protocol first affected. Stolen USDC may be swapped for ETH, an exchange may suspend withdrawals after hot-wallet outflows, or a governance proposal may redirect a DAO treasury. For holders of BTC, ETH, SOL and stablecoins such as USDT and USDC, understanding the attack path is essential to judging whether an incident threatens one platform, connected protocols or the wider market.

Zipp tracks incidents from the first on-chain alert through confirmation, containment and recovery. Coverage examines transaction trails, attacker methods, disputed loss estimates, withdrawal status, token approvals, bridge and oracle dependencies, validator or admin-key controls, and any reimbursement or recovery plan. Recent reporting has followed the Ostium and Summer Finance exploits, the BONK DAO treasury attack, suspicious AscendEX hot-wallet movements and KelpDAO activity involving Chainlink CCIP. The desk also covers audits, disclosure practices and longer-term risks such as quantum computing, as well as sanctions enforcement, exchange exposure and blockchain tracing around Iran-linked CoinEx flows. We distinguish verified losses from funds merely moved or placed at risk, identify the evidence behind researchers’ claims, and monitor whether stolen assets are bridged, mixed, frozen or converted into assets including ETH. Privacy belongs to the same beat: readers need to know what transaction data is public, how analytics firms connect wallets, and where surveillance, compliance and user protection intersect.

Related tokens

Frequently asked questions

  1. What is the difference between a crypto hack and a smart-contract exploit?

    A hack is a broad term for unauthorized access or theft, including compromised keys, accounts and infrastructure. A smart-contract exploit specifically abuses faulty code, economic design or permissions in an on-chain application, sometimes without breaching its servers.

  2. How can I tell whether a reported crypto loss is confirmed?

    Check whether the figure is supported by identifiable on-chain transactions, a statement from the affected project and independent analysis. Large wallet movements are not automatically losses; funds may be relocated, quarantined or counted more than once.

  3. Why do attackers swap stolen USDC or USDT for ETH?

    Stablecoin issuers may be able to freeze tokens at specific addresses, while native assets such as ETH generally do not have an issuer-controlled freeze function. Swapping does not make funds untraceable, and exchanges, bridges or other services may still block them.

  4. Does a smart-contract audit mean a crypto protocol is safe?

    No. An audit reviews a defined codebase and scope at a particular stage, but it cannot guarantee that every bug, governance weakness, key-management failure or later upgrade is secure. Readers should check the audit scope, unresolved findings and whether deployed code matches the reviewed version.