Web3 Antivirus: Single Signature Drains 316K USDC
The drainer did not exploit a contract bug — it exploited user signing habits. The reminder list is unsexy, which is exactly why it keeps working.
The drainer did not exploit a contract bug — it exploited user signing habits. The reminder list is unsexy, which is exactly why it keeps working.
A wallet linked to Chun Wang, known on X as @satofishi, withdrew an additional 15,740 ETH worth approximately $26.4…
The U.S. Department of Justice has charged two individuals in connection with a $389 million cryptocurrency laundering…
The funds came from a legacy AMM V3 program Raydium phased out in 2021 — no current UI users were exposed, but the exploit shows aged on-chain program surfaces remain a live attack surface.
The vulnerability sat in a deprecated pool program, not the live mainnet — but the attack shows how legacy Solana AMM code keeps paying out years after the protocol moved on.
Raydium, one of Solana's largest decentralized exchanges, confirmed a $1.34 million exploit targeting a retired…
A four-year dormant bug in Zcash's shielded-pool cryptography — discovered by AI, not a human auditor — reminds the market that 'private by design' is a promise, not a guarantee.
Not a smart-contract bug — a single developer laptop compromised by malware exposed the admin hot wallet plus six Safe owner keys across Ethereum and BSC, draining over $31M.
Botanix, a Bitcoin Layer 2 network, is winding down operations and has issued an urgent call for users to withdraw…
A US criminal case built around a Bitcoin-funded Lamborghini has put physical attacks on crypto holders back in the courtroom, as cumulative losses from wrench attacks top $100M this year.
BTC is off nearly 3% from Monday's high even as Nasdaq 100 futures extend gains — a fresh $36M Humanity Protocol exploit is doing the narrative work for the 'no second best' crowd.
The breach wasn't a novel attack — it was a textbook custody failure on a project backed by Pantera and Jump Crypto, and the recovered token price is still a third of pre-breach levels.
The team says no contract or product security issue has been found, but a 60% flash move on a Binance Labs-backed token raises harder questions about who was selling and why.
The biggest story isn't the 80% drawdown — it's the pattern: stolen keys, not flawed code, drove most of 2026's largest crypto losses, and H just became the freshest data point.
More than 17 wallets linked to the project have been siphoned in an active exploit, with on-chain monitors flagging losses above $31M as the H token collapses on thin liquidity.
The attacker is swapping stolen $H straight into $ETH in real time — a textbook exit-liquidity drain that turns a smart-contract bug into an instant market crash for everyone holding the token.
The exploit traced through 17 wallets hit the H token harder than the dollar loss — and a founder-confirmed private-key compromise means the attack vector was a single point of failure, not a…
The complaint isn't the sanctions themselves — it's that compliance tooling can't tell pre-sanction HTX wallets from post-sanction ones, tainting legitimate address clusters and degrading the risk…
Orchard's privacy shield means a counterfeiting flaw cannot be ruled out retroactively, and the market is treating that uncertainty as if it had already happened.
Iran has announced the full closure of the Bab al-Mandab Strait following Israeli military strikes, a move with…