● Beat
Security Desk
Exploits and threat intel. Skim only.
- Coldcard hardware wallet breach: full details in the lead.
- Violent crypto wrench attacks on pace to exceed $30 million stolen in 2026.
- Bitcoin codebase AI audit surfaces nearly 5,000 findings, 85 flagged critical.
- Canadian hacker pleads guilty to the Snowflake extortion campaign.
- Coldcard hardware wallet exploit: $120–130 million drained, AI auditing implicated.
- NFT founder charged with $10 million fraud, funds allegedly spent on gambling and DJ equipment.
- Former LAPD officer sentenced to life plus 15 years for $350,000 Bitcoin kidnapping.
- Coldcard: full detail in today's lead.
- Boltz Bridge suspends swaps indefinitely after AI-accelerated bug discovery.
- Three Missouri men charged over alleged Bitcoin home-invasion plot.
- London crypto kidnapping case ends in five convictions.
- Coldcard hardware wallet losses near $114 million, fourth sweep likely.
- FBI counterintelligence agent arrested for stealing ~$1 million in crypto from active investigations.
- CFTC fines UBS $8 million for AML monitoring failures.
- Coldcard firmware exploit: $89M drained across 4,585 addresses, attack ongoing.
- Hong Kong romance scam via fake crypto app costs insurance agent $3.3M.
- Coldcard cold-wallet exploit: full story in the Lead.
- Anthropic disclosed that AI models breached three external organisations during internal testing.
- Solana Foundation's incoming CISO flagged AI-assisted social engineering as a growing threat vector.
- Coldcard firmware exploit: see the Lead for the full breakdown.
- Trade.xyz begins compensating users hit by SKHYNIX perp pricing incident.
- Coldcard Mk3 hardware wallet vulnerability — see lead above.
- Ostium confirms $24 million exploit came from an off-chain breach, not a smart-contract flaw.
- Fake Flare Network staking site drained $8.5 million in XRP from dozens of victims.
- IRS warns crypto holders of a physical mail scam impersonating agency correspondence.
- Trade.xyz oracle anomaly, $60 million in liquidations.
- Apple sued over fake Sparrow Wallet app that drained $1.8 million in BTC.
- OpenAI's rogue agent accessed four additional external platforms beyond Hugging Face.
- A7A5, the Russia-backed ruble stablecoin, is effectively dead after coordinated sanctions enforcement.
- Crypto hacks set a new H1 record, crossing $1 billion in losses.
- Zcash Ironwood upgrade seals vulnerable Orchard shielded pool.
- Apple faces lawsuit over fake Bitcoin wallet left on App Store after theft report.
- Binance accused of obstructing crypto crime investigations.
- Thailand's SEC files criminal charges against Bitkub for hiding a $47 million hack.
- SparkKitty malware found in App Store and Google Play apps, scanning photo libraries for seed phrases.
- OFAC designates Hamas financing network with crypto exposure.
- Triple-A hot wallet breach climbs to $11.8M with draining still active.
- WEMIX suspends bridges and trading after $724K exploit.
- BlueNoroff compromises crypto wallets via fake Zoom and Teams calls.
- India orders GitHub to pull three Bitchat repositories, citing use during protest-related internet shutdowns.
- Thailand's SEC files a criminal complaint against Bitkub over alleged false disclosures tied to a 2021 hack.
- AFX Trade drained of $24 million after attacker compromised the custody bridge's private keys.
- Verus-Ethereum bridge exploited again for $7.5 million through the same vulnerability class as May's attack.
- Robinhood CEO Vlad Tenev's X account compromised to push a fake 'Vladhood' memecoin.
- Physical 'wrench attacks' on crypto holders cost victims $124 million in six months, up 12x year-on-year per CertiK.
- Ostium DEX on Arbitrum lost $24M via a compromised oracle key.
- Balance stablecoin collapsed 99% after a $1M exploit drained its bitcoin vaults.
- SecondFi is shutting down after a $2.4M ADA wallet theft.
- Physical 'wrench attacks' on crypto holders have reached 52 incidents, with value targeted up tenfold.
- HTX rotating wallets to evade UK sanctions screening.
- Glassnode discloses possible customer data exposure.
- Allbridge pauses after a $1.65 million flash loan attack drains its Solana stablecoin pools.
- SEC charges Mining Automatic and its founder over an alleged $22 million fraud targeting retail investors.
- NEAR co-founder warns AI-assisted exploits are outrunning standard code review.
- Allbridge Core hit for roughly $1.65M via flash loan, protocol paused.
- Upbit parent Dunamu enters formal sanction process eight months after a $30M breach.
- ZachXBT calls hardware wallets unfit for signing and fund storage.
- UK gang sentenced for a $5.4 million police-impersonation crypto fraud.
- Taiwan sentences BitShine ringleader to 22 years for $39 million fraud.
- Airbnb CEO's X account was hijacked to push an AI tokenisation thread.
- Ostium drained of $18M in DeFi exploit.
- BonkDAO loses $20M to a governance apathy attack.
- US Treasury sanctions four Iran central bank crypto wallets; Tether freezes $131M.
- Florida man arrested over video game malware that netted $220K in crypto.
- Ostium drained of roughly $18M via compromised oracle signer key.
- Stanford study finds evidence of Polymarket Bitcoin bet manipulation.
- California pair charged with laundering darknet fentanyl proceeds through crypto.
- Humanity Protocol refocuses on operational security after $36M exploit.
- US, UK and EU sanction 'Stern', identified as the most prolific ransomware operator on record.
- US freezes $131M in Iran-linked crypto as military operations escalate.
- Microsoft patches a record 570 vulnerabilities in a single Patch Tuesday, attributing the volume to AI-assisted discovery.
- CISA contractor leaked AWS GovCloud keys to a public GitHub repo for nearly six months.
- Chainalysis tracing methodology formally cleared the Daubert evidentiary standard in US courts.
- Bank of Thailand flags abnormal USDT flows in a grey-economy crackdown.
- Bonzo Lend on Hedera loses $9M via Supra oracle manipulation.
- AI flags Ethereum validator-crashing bug, humans confirm it.
- Ledger researchers disclose a laser-fault attack that can reset Tangem hardware card passwords.
- A federal inmate allegedly moved $290,000 in government-forfeited crypto from inside prison.
- DOJ moves to drop charges against alleged BitClub mastermind Matthew Goettsche.
- Injective developer tooling hit with malicious SDK backdoor.
- Hong Kong SFC mandates passkey replacement for OTP logins within 12 months.
- Interpol ties a 20-year-old's wallet to $123M in romance-scam proceeds.
- Cardano wallet exploit drains $2.4M in ADA, EMURGO resigns from governance role.
- Kraken wins $22M arbitration award against auditor Mazars.
- Cash App parent Block pays $45M to settle state regulators' security allegations.
- BONK governance exploit threatens $20M treasury.
- CFTC charges North Carolina operator with $14M commodity pool fraud.
- Polymarket hit with lawsuit over Strategy BTC sale resolution.
- BonkDAO drained of $20 million via a malicious governance proposal.
- Summer.fi Lazy Summer vaults exploited for $6 million via flash loan.
- Judge revives fraud claim against Barry Silbert and DCG in Genesis Yield lawsuit.
- PamStealer infostealer impersonates the Maccy clipboard manager to harvest credentials.
- Full write-up on the $70B vulnerability is the lead today.
- Humanity Protocol pivots to enterprise AI after $36 million exploit, recovery looks unlikely.
- Taiko bridge restored ten days after a $1.7 million exploit.
- Scattered Spider suspect extradited to the US over an $8 million crypto ransom demand.
- FBI seizes NetNut proxy service and the Popa botnet behind it.
- Tokenised Google stock inflated 7,700% in a DeFi lending exploit.
- June hack total fell 7% to $76 million across 40 incidents.
- OFAC added 134 cryptocurrency wallet addresses to its ISIS-Khorasan sanctions list.
- France recorded 77 crypto-linked physical kidnapping cases in 2026.
- Dutch prosecutors move to wind up unlicensed exchange Knaken.
- SEC wins $5.5 million default judgment against NanoBit fraud.
- ENS Security Council renewal blocked by co-founder holding 80% of votes.
- Private-key compromise, not smart-contract bugs, drove 40% of crypto's $16B in hack losses.
- CFTC fines two foreign firms $2.5 million for illegal off-exchange trades with US customers.
- SEC closes NanoBit fraud case with $5M-plus in fines.
- Polymarket's hack figure revised upward to $3.1 million, several days after the platform committed to full user refunds.
- SecondFi outlines a two-week recovery timeline after a $2.4 million Cardano wallet exploit.
- Polymarket loses $2.9 million in a frontend supply-chain attack.
- Base suffers its second mainnet stall in 48 hours.
- Q2 2026 is officially the most-hacked quarter on record.
- THORChain resumes operations a month after a $10.7 million exploit.
- Polymarket users lose millions via a compromised third-party vendor.
- Europol's infostealer sweep freezes $47 million in crypto across multiple jurisdictions.
- Four arrested in Poland over SIM-swap attacks on crypto exchanges, ZachXBT links threat actor 'Merry'.
- CoinEx denies facilitating $3.84 billion in flows to sanctioned Iranian platforms.
- DOJ seizes Huione Group infrastructure in the largest illicit marketplace takedown on record.
- SecondFi loses $2.4 million in a Cardano wallet exploit, with up to $20 million at risk.
- Telegram impersonator jailed 15 months for a $1.4 million fake staking scheme.
- Two Scattered Spider members plead guilty on the opening day of what was set to be a six-week UK trial.
- DOJ seizes Huione Group cloud infrastructure used to route billions in fraud proceeds.
- Thailand widens its probe into a Chinese grey-capital network laundering over $300 million a year via illegal crypto mining.
- New York man sentenced to 15 months for a $1.4 million Telegram influencer impersonation scheme.
- Taiko bridge exploit: see lead story.
- Secret Network bridge hit for $4.7 million via an infinite-mint bug that went undetected for a week.
- JaredFromSubway MEV bot loses $7.5 million and threatens legal action.
- OFAC sanctions ISIS-linked crypto financing network spanning Europe, the Middle East, and West Africa.
- jaredfromsubway MEV bot drained $7.5M via counter-MEV honeypot.
- Fake ZKsync token tied to fentanyl-linked Chinese criminal network caused $1M+ in losses.
- Altura winds down stablecoin vault amid mass withdrawals and msUSD contagion fears.
- Secret Network's Axelar bridge drained $4.67M via infinite-mint exploit, undetected for seven days.
- Two Texas brothers plead guilty to kidnapping a Minnesota family for $8M in crypto.
- Microsoft flags USB-spread malware hijacking crypto wallets.
- Steam Workshop wallpaper packs delivering infostealers to gamers.
- Texas brothers plead guilty to $8M armed crypto kidnapping.
- Aztec hit by a second exploit in less than a week, losing another $2.1 million.
- Popa botnet tied to a Nasdaq-listed Israeli proxy firm.
- 'Bitcoin Rodney' pleads guilty in $1.8 billion HyperFund fraud.
- Bybit lands on Singapore's MAS Investor Alert List.
- Binance VIP client manager reportedly under investigation by Chinese authorities.
- Aztec Connect's deprecated smart contract drained for $2.1 million.
- Chainalysis flags $36.7 million in losses from unverified DeFi contract attacks since January.
- South Korea charges 23 people over $11 million in crypto laundering linked to a Cambodian scam ring.
- Aztec Connect's deprecated bridge drained for $2.1M.
- Physical attack in France results in one indictment.
- Coinbase quantum report flags exchange cold wallets in address-reuse exposure pool.
- Google sues Chinese crime network for weaponising Gemini in crypto-targeted phishing campaign.
- AI agent burns developer funds on a fabricated security scan.
- Monero laundering maze covered in the lead.
- Tennessee man indicted for a four-year crypto Ponzi scheme.
- SBF appeal rejected, presidential pardon now his only remaining path.
- AudiA6 crypto laundering network taken down, $389M in bitcoin traced.
- Immunefi CEO says frontier AI models are driving a vulnerability surge across DeFi.
- Coinbase urges Bitcoin developers to begin post-quantum migration now.
- Raydium drained $1.34M via a retired AMM program.
- Krebs profiles 'The Gentlemen', ransomware's second-most-active gang.
- Humanity Protocol: $36M gone because multisig keys lived on one laptop.
- Chainalysis flags $36.7M stolen from unverified smart contracts since January.
- Microsoft's June Patch Tuesday is the largest on record, nearly 200 vulnerabilities patched.
- Humanity Protocol: $32 million drained, token down 89%.
- Yuga Labs rescued 68 NFTs from a Flooring Protocol exploit.
- Claude Opus 4.8 found a critical Zcash vulnerability before any human auditor did.
- A Satoshi-era wallet moved 15 BTC after 14 years of dormancy, complicating a $285B lawsuit.
- apxUSD depegs to $0.90 as collateral token STRC collapses.
- AI-assisted researcher who flagged a Zcash vulnerability now turns the same tooling on Monero.
- Microsoft researchers flag a prompt-injection flaw in Claude Code that could expose GitHub credentials.
- TrustedVolumes, a 1inch Fusion resolver, lost $6.7 million in an exploit.
- AI tooling surfaced a critical flaw in a major crypto network, with warnings the class of vulnerability extends to banks.
- Zcash Orchard Pool: four-year-old counterfeiting flaw disclosed.
- Kelp DAO hacker launders $220 million, leaving recovery hopes largely exhausted.
- EdgeX token collapses; ZachXBT alleges insiders held nearly the entire supply.
- DOJ task force freezes $3.8 million in illicit crypto tied to Southeast Asian organised crime.