Hackers Now Steal DeFi Keys Before Code Ships
A new malware campaign hits crypto developers upstream, lifting GitHub tokens, SSH keys, and wallets so attackers own the build before a protocol ever goes live.
A new malware campaign hits crypto developers upstream, lifting GitHub tokens, SSH keys, and wallets so attackers own the build before a protocol ever goes live.
Smart-contract exploits keep grabbing headlines, but the bulk of stolen funds trace back to compromised keys and operational gaps, a structural risk MPC and account abstraction are now trying to…
The builder cannot trace the perpetrator, and recovery work is still running through parallel approaches two weeks after the breach first surfaced.
The refund pledge buys goodwill, but a third-party vendor breach, repeated phishing incidents, and a federal marketing investigation now converge on the prediction market at the same time.
If hot-wallet reserves in ETH, USDT and SOL are running light, the withdrawal queue stops being an operations problem and starts being a solvency question for users still parked on the venue.
The injected code sat on the site frontend rather than in Polymarket's core contracts, but the read for prediction markets is harder: vendor risk now sits inside the user-trust boundary, not outside…
A 6-12 month migration window for roughly 1M BTC, then freeze the rest: a provocative governance proposal from one of crypto's loudest voices, and one with no obvious off-ramp.
Base is a Coinbase-incubated layer-2 with billions in TVL; sustained downtime on a venue that size tests the assumption that rollups inherit Ethereum's uptime guarantees.
The Coinbase-incubated layer-2 hit its second notable outage this year, freezing deposits and withdrawals and exposing the operational risk of a low-redundancy sequencer setup.
The flaw sat in SecondFi's address-generation layer, so moving a seed phrase to a new wallet offers zero protection, and SlowMist's wider loss estimate is the number every ADA holder is reading now.
The protocol itself was never breached. The real questions are how Emergo had the keys to seize 129M ADA mid-exploit, and whether the recovery optics for a founding entity are worth the trust cost.
Engineering milestones land alongside a 55% year-to-date slide in ADA and a $2.4M wallet exploit, exposing how far Cardano's technical roadmap has run ahead of the activity it was built to attract.
CryptoRank's monthly tracker now shows DeFi TVL below the $70B line for the first time since 2023, with 121 hacks and $942M in losses accelerating the year-long unwind across every major chain except…
The DOJ and White House are being told a single provision in the draft market-structure bill could strip investigators of the tools they currently rely on to trace and prosecute illicit crypto…
SlowMist's founder reads the on-chain fund flows and lands on a higher number than the project's own preliminary estimate, and a single bad wallet generator is what opened the door.
The move is broad-based: $2.24T market cap down across majors, Fear & Greed in extreme fear at 23, and Q2's $775M in stolen crypto is the second-cheapest quarter to attack on record.
The dollar loss was small, but the flaw class is the same one behind $340M in cross-chain bridge hacks already this year, and the root cause was a prover signing key left exposed on GitHub.
Bitcoin is flat to slightly red on the week, the Fear & Greed Index is pinned at 20, and a fresh wave of bridge and protocol exploits has pushed June's hack count above 20.
Microsoft's threat team linked the campaign to a hacking group it tracks as CryptoBandits, which uses poisoned USB sticks to seed malware that rewrites browser extensions for wallet theft.
The wind-down is the second protocol hit in the depegging of Main Street's msUSD, and it underlines how thin stablecoin liquidity can collapse into bank-run behavior in a weekend.