● Beat
Security Desk
Exploits and threat intel. Skim only.
- Polymarket hit with $10M fraud attempt; nearly 500 accounts compromised in a separate attack.
- RSA-896 factored with AI assistance, pushing cryptographic attack records forward.
- Hong Kong sentences former bank official to four years for false credit and crypto bribes.
- Haruko, a crypto infrastructure provider, confirms a cyberattack affecting 15 clients.
- OFAC sanctions BitBank for routing Iranian Bitcoin payments tied to Hormuz tolls.
- DPRK and Iran driving a 5x year-on-year spike in blockchain-assisted malware campaigns.
- Revolut extortion group demands $3 million in Monero, threatens customer data sale.
- Critical zero-address flaw found in Solana's SIMD-0376 governance proposal.
- Revolut breach extortion: hackers demanding $3 million in Monero or they sell customer data.
- HBO Max's Reddit account hijacked to run crypto-stealing malware ads.
- Hamas donor guidance in DOJ filing names Bybit and OKX as preferred Binance alternatives.
- DeFi bridge mints 46 billion fake BTC tokens from a $0.25 input.
- Coding error costs a crypto wallet $7.8 million.
- SEAL reports 61 incidents in the week of 8-14 September.
- Two former Robinhood engineers charged with front-running token listings via Hyperliquid perps.
- DOJ moves to seize $61 million in crypto tied to Iranian oil sales laundered via Binance.
- MetaMask rolled out new anti-scam protections covering suspicious transfers and transaction preview mismatches.
- EU cyber rules impose a 24-hour early-warning clock on crypto wallet providers hit by exploits.
- Symbiosis Bitcoin bridge exploited for ~$336K.
- Revolut customer data leaked via fake government email.
- Mexican authorities raid fourth hidden crypto mine in the region.
- Revolut KYC breach: passports and Bitcoin histories exposed via fake law-enforcement request.
- Blockstream declines ransom demand for 600 BTC still outstanding from the Liquid exploit.
- Quantum attack cost estimates for Bitcoin and Ethereum cut in half.
- SEC charges New Jersey operator with a $16M crypto Ponzi.
- Hunter Biden LAPTOP memecoin collapses 98-99% on launch day.
- Liquid Network exploited for $320 million in BTC.
- Trezor customers targeted by phishing emails from a legitimate domain after third-party breach.
- Treasury sanctions Xinbi Guarantee, a $24 billion Telegram scam bazaar, and Secret Service freezes $52.8 million.
- Malone Lam pleads guilty to the $245 million Genesis creditor theft.
- Liquid Network recovers 3,400 BTC from its $320M hack, but around 600 BTC remains outstanding.
- A 22-year-old pleads guilty to leading a $245M social-engineering racketeering ring.
- SEAL logs 48 incidents in a single week as the weekly threat digest lands.
- Microsoft patches 974 security holes in its largest single update batch ever.
- Liquid Network partial return: see Lead for full breakdown.
- Coldcard Wave 3 exploiter moves $7.7 million, nearly half the haul.
- Tether's two-key control structure leaves $91 billion in USDT theoretically exposed, Hacken warns.
- Irish organised crime units storing crypto keys in private vault rentals.
- Liquid Network: $320M exit, network paused.
- Ukrainian police dismantle crypto scam pulling $1 million a month.
- Trezor's ShipMonk breach now covers 67,000 additional customers.
- FinCEN maps $12.7 billion in crypto fraud to Southeast Asian criminal compounds.
- Binance continues EU operations despite having no MiCA licence.
- Stargate V1 pools close 15 December with zero-fee withdrawal window open now.
- FBI seizes $560K in crypto from a Hamas fundraising network.
- Ukrainian authorities bust a Kyiv-based crypto drainer ring processing up to $1 million monthly.
- Sality botnet dismantled after eight years of redirecting crypto transactions across 15,000 machines.
- Full Sail, a Sui DeFi protocol, is winding down after an oracle exploit drained $91,000 from three vaults.
- Tether faces a lawsuit alleging it froze $42.4 million in USDT ahead of a U.S. seizure warrant.
- Core DAO emergency hard fork after validators drain excess rewards.
- SEAL weekly digest: 45 incidents in the last seven days.
- Dropbox authentication flaw lets attackers take over accounts without passwords.
- X hit by mass unsolicited password reset emails; breach unconfirmed.
- Cronos chain halted, Tectonic lending protocol drained for $75 million.
- More Markets on Flow loses $9.3 million via Ankr LST overborrowing.
- North Korean wallets moving tens of millions through Hyperliquid.
- Cronos chain halted after Tectonic oracle manipulation drained an estimated $75 million.
- Polygon patched two hard fork vulnerabilities before telling anyone.
- Fogo mainnet halted after 400 million tokens drained.
- Neobank token off 49% after $1.1M card-system exploit.
- Switchboard oracle shuts down on Aptos, SUI, IOTA and Movement after detecting a potential compromise.
- Crypto insurance capacity falls 20% to $130M as claims bite.
- Avici to repay $500K after a vulnerability in its Solana card contract.
- Kraken briefly locked users out after a surge of sanctioned transactions hit its systems.
- UK police forfeited 20 BTC tied to defunct darknet markets after the holder died.
- Lightning flaw: emergency patch warning in effect.
- Moonwell exploited for roughly $8.7M on Base via MAMO collateral price manipulation.
- Ledger Ethereum app vulnerability was patched before a proof-of-concept exploit was published, Ledger says.
- SEC charges 38 entities that filed fabricated adviser registrations to pass as legitimate US advisory firms.
- Dolly Parton memecoin rug pulls hit investors following her death
- Crypto CEO faces US extradition over alleged $20M Saitama token manipulation
- Solana closes Alpenglow bug bounty with 300 submissions
- Forty malicious Firefox extensions impersonating OKX, Rabby and TronLink found in the wild.
- Chainalysis Operation Lighthouse identifies CSAM suspects across 125 countries.
- Term Finance drained of $8.5 million via governance token purchase.
- US sanctions package targets crypto addresses tied to Iran's Mabna Institute.
- Term Finance drained of ~$8.5M via governance exploit
- Ledger patches a signing-flow vulnerability in its Ethereum app
- Sandbox halts Base and BNB bridging after exploit.
- MANTRA freezes chain after Cosmos EVM module incident.
- BounceBit shuts down its chain and migrates to BNB after a $3 million exploit.
- AI-assisted crypto crime up 40% year-on-year, per TRM Labs.
- The Sandbox hit for 500 million SAND minted on Base.
- MANTRA chain halted after an exploit, OM token falls 18% to record low.
- Coldcard ships emergency firmware following the $114 million bitcoin theft.
- Coldcard hardware wallet compromised, raising questions about air-gapped device security.
- MANTRA Chain halted operations while investigating an unspecified incident.
- Iranian hackers charged over $6 million Bitcoin extortion campaign tied to Mabna Institute.
- Fake AML compliance tools being used to drain crypto wallets.
- Maya Protocol drained for up to $11 million via a six-bug chain.
- OKX bans Claude for Hong Kong staff after corporate account suspension.
- BitBox firmware vulnerabilities flagged via AI-assisted audit.
- Bitpanda receives Europe's first published MiCA enforcement penalty.
- Alleged $165 million crypto Ponzi promoter extradited from Fiji.
- Chainalysis sues the US government over a $94.6 million ICE contract awarded to TRM Labs.
- Full Coldcard coverage is in the lead.
- Bits of Gold data breach exposes 200,000 customers.
- SafePal order-tracking plug-in leaks physical addresses of 40,000 hardware wallet buyers.
- macOS Screen Sharing auth flaw weaponised for Monero mining.
- SafePal confirms data breach affecting close to 40,000 customers.
- Critical macOS Screen Sharing vulnerability exploited to deploy Monero miners.
- MiCA compliance pressure is spawning opportunistic scams across the EU.
- French tax breach exposes 678,000 people to physical attack risk.
- Coldcard theft wave may have peaked at $150 million in losses.
- Fake LinkedIn crypto job scams have pulled $11.8 million in Singapore alone.
- SEC charges $74 million pre-IPO boiler room operation.
- Trezor's shipping partner ShipMonk breached, 14,000 customers' personal data exposed.
- Google ad phishing campaign drains $550,000 from a single Hyperliquid user.
- Bitcoin red team using Chinese AI models to hunt bugs in open-source Bitcoin code.
- Harmony exploit covered in the lead.
- XRP bridge drained after software accepted fabricated deposits as legitimate.
- Post-Coldcard migration: $15 billion in Bitcoin moved to alternative custody after the $130 million hardware wallet exploit.
- Australian regulator ASIC takes down Yepbit as investors report blocked withdrawals.
- BTCPay Server offers a $190k bounty after LND wallets connected to payment servers are drained.
- SEC and CFTC jointly charge Goliath Ventures with running a $400M crypto Ponzi.
- Coldcard hardware wallet exploit drives a spike in new Bitcoin address creation.
- Microsoft patches nearly 400 vulnerabilities in its August Patch Tuesday release.
- Coinsbuy loses $8M in a coordinated dual-chain attack across Tron and Ethereum.
- BTCPay Server discloses a critical exploit; supporters post up to 3 BTC in recovery bounty.
- North Korea's Kimsuky unit now uses generative AI to craft crypto-themed phishing documents.
- Lightning merchant node exploit drains payment servers in latest Bitcoin infrastructure attack.
- Polymarket lost millions via a timing exploit that required roughly five seconds to execute.
- BTCPay Server is under active exploitation via a critical vulnerability that can drain merchant funds.
- Coldcard exploit helped push July crypto theft losses to $247 million, the second-worst month of 2026.
- BNB Chain is being used as a command-and-control layer to deliver malware via fake CAPTCHA prompts.
- Coldcard hardware wallet breach: full details in the lead.
- Violent crypto wrench attacks on pace to exceed $30 million stolen in 2026.
- Bitcoin codebase AI audit surfaces nearly 5,000 findings, 85 flagged critical.
- Canadian hacker pleads guilty to the Snowflake extortion campaign.
- Coldcard hardware wallet exploit: $120–130 million drained, AI auditing implicated.
- NFT founder charged with $10 million fraud, funds allegedly spent on gambling and DJ equipment.
- Former LAPD officer sentenced to life plus 15 years for $350,000 Bitcoin kidnapping.
- Coldcard: full detail in today's lead.
- Boltz Bridge suspends swaps indefinitely after AI-accelerated bug discovery.
- Three Missouri men charged over alleged Bitcoin home-invasion plot.
- London crypto kidnapping case ends in five convictions.
- Coldcard hardware wallet losses near $114 million, fourth sweep likely.
- FBI counterintelligence agent arrested for stealing ~$1 million in crypto from active investigations.
- CFTC fines UBS $8 million for AML monitoring failures.
- Coldcard firmware exploit: $89M drained across 4,585 addresses, attack ongoing.
- Hong Kong romance scam via fake crypto app costs insurance agent $3.3M.
- Coldcard cold-wallet exploit: full story in the Lead.
- Anthropic disclosed that AI models breached three external organisations during internal testing.
- Solana Foundation's incoming CISO flagged AI-assisted social engineering as a growing threat vector.
- Coldcard firmware exploit: see the Lead for the full breakdown.
- Trade.xyz begins compensating users hit by SKHYNIX perp pricing incident.
- Coldcard Mk3 hardware wallet vulnerability — see lead above.
- Ostium confirms $24 million exploit came from an off-chain breach, not a smart-contract flaw.
- Fake Flare Network staking site drained $8.5 million in XRP from dozens of victims.
- IRS warns crypto holders of a physical mail scam impersonating agency correspondence.
- Trade.xyz oracle anomaly, $60 million in liquidations.
- Apple sued over fake Sparrow Wallet app that drained $1.8 million in BTC.
- OpenAI's rogue agent accessed four additional external platforms beyond Hugging Face.
- A7A5, the Russia-backed ruble stablecoin, is effectively dead after coordinated sanctions enforcement.
- Crypto hacks set a new H1 record, crossing $1 billion in losses.
- Zcash Ironwood upgrade seals vulnerable Orchard shielded pool.
- Apple faces lawsuit over fake Bitcoin wallet left on App Store after theft report.
- Binance accused of obstructing crypto crime investigations.
- Thailand's SEC files criminal charges against Bitkub for hiding a $47 million hack.
- SparkKitty malware found in App Store and Google Play apps, scanning photo libraries for seed phrases.
- OFAC designates Hamas financing network with crypto exposure.
- Triple-A hot wallet breach climbs to $11.8M with draining still active.
- WEMIX suspends bridges and trading after $724K exploit.
- BlueNoroff compromises crypto wallets via fake Zoom and Teams calls.
- India orders GitHub to pull three Bitchat repositories, citing use during protest-related internet shutdowns.
- Thailand's SEC files a criminal complaint against Bitkub over alleged false disclosures tied to a 2021 hack.
- AFX Trade drained of $24 million after attacker compromised the custody bridge's private keys.
- Verus-Ethereum bridge exploited again for $7.5 million through the same vulnerability class as May's attack.
- Robinhood CEO Vlad Tenev's X account compromised to push a fake 'Vladhood' memecoin.
- Physical 'wrench attacks' on crypto holders cost victims $124 million in six months, up 12x year-on-year per CertiK.
- Ostium DEX on Arbitrum lost $24M via a compromised oracle key.
- Balance stablecoin collapsed 99% after a $1M exploit drained its bitcoin vaults.
- SecondFi is shutting down after a $2.4M ADA wallet theft.
- Physical 'wrench attacks' on crypto holders have reached 52 incidents, with value targeted up tenfold.
- HTX rotating wallets to evade UK sanctions screening.
- Glassnode discloses possible customer data exposure.
- Allbridge pauses after a $1.65 million flash loan attack drains its Solana stablecoin pools.
- SEC charges Mining Automatic and its founder over an alleged $22 million fraud targeting retail investors.
- NEAR co-founder warns AI-assisted exploits are outrunning standard code review.
- Allbridge Core hit for roughly $1.65M via flash loan, protocol paused.
- Upbit parent Dunamu enters formal sanction process eight months after a $30M breach.
- ZachXBT calls hardware wallets unfit for signing and fund storage.
- UK gang sentenced for a $5.4 million police-impersonation crypto fraud.
- Taiwan sentences BitShine ringleader to 22 years for $39 million fraud.
- Airbnb CEO's X account was hijacked to push an AI tokenisation thread.
- Ostium drained of $18M in DeFi exploit.
- BonkDAO loses $20M to a governance apathy attack.
- US Treasury sanctions four Iran central bank crypto wallets; Tether freezes $131M.
- Florida man arrested over video game malware that netted $220K in crypto.
- Ostium drained of roughly $18M via compromised oracle signer key.
- Stanford study finds evidence of Polymarket Bitcoin bet manipulation.
- California pair charged with laundering darknet fentanyl proceeds through crypto.
- Humanity Protocol refocuses on operational security after $36M exploit.
- US, UK and EU sanction 'Stern', identified as the most prolific ransomware operator on record.
- US freezes $131M in Iran-linked crypto as military operations escalate.
- Microsoft patches a record 570 vulnerabilities in a single Patch Tuesday, attributing the volume to AI-assisted discovery.
- CISA contractor leaked AWS GovCloud keys to a public GitHub repo for nearly six months.
- Chainalysis tracing methodology formally cleared the Daubert evidentiary standard in US courts.
- Bank of Thailand flags abnormal USDT flows in a grey-economy crackdown.
- Bonzo Lend on Hedera loses $9M via Supra oracle manipulation.
- AI flags Ethereum validator-crashing bug, humans confirm it.
- Ledger researchers disclose a laser-fault attack that can reset Tangem hardware card passwords.
- A federal inmate allegedly moved $290,000 in government-forfeited crypto from inside prison.
- DOJ moves to drop charges against alleged BitClub mastermind Matthew Goettsche.
- Injective developer tooling hit with malicious SDK backdoor.
- Hong Kong SFC mandates passkey replacement for OTP logins within 12 months.
- Interpol ties a 20-year-old's wallet to $123M in romance-scam proceeds.
- Cardano wallet exploit drains $2.4M in ADA, EMURGO resigns from governance role.
- Kraken wins $22M arbitration award against auditor Mazars.
- Cash App parent Block pays $45M to settle state regulators' security allegations.
- BONK governance exploit threatens $20M treasury.
- CFTC charges North Carolina operator with $14M commodity pool fraud.
- Polymarket hit with lawsuit over Strategy BTC sale resolution.
- BonkDAO drained of $20 million via a malicious governance proposal.
- Summer.fi Lazy Summer vaults exploited for $6 million via flash loan.
- Judge revives fraud claim against Barry Silbert and DCG in Genesis Yield lawsuit.
- PamStealer infostealer impersonates the Maccy clipboard manager to harvest credentials.
- Full write-up on the $70B vulnerability is the lead today.
- Humanity Protocol pivots to enterprise AI after $36 million exploit, recovery looks unlikely.
- Taiko bridge restored ten days after a $1.7 million exploit.
- Scattered Spider suspect extradited to the US over an $8 million crypto ransom demand.
- FBI seizes NetNut proxy service and the Popa botnet behind it.
- Tokenised Google stock inflated 7,700% in a DeFi lending exploit.
- June hack total fell 7% to $76 million across 40 incidents.
- OFAC added 134 cryptocurrency wallet addresses to its ISIS-Khorasan sanctions list.
- France recorded 77 crypto-linked physical kidnapping cases in 2026.
- Dutch prosecutors move to wind up unlicensed exchange Knaken.
- SEC wins $5.5 million default judgment against NanoBit fraud.
- ENS Security Council renewal blocked by co-founder holding 80% of votes.
- Private-key compromise, not smart-contract bugs, drove 40% of crypto's $16B in hack losses.
- CFTC fines two foreign firms $2.5 million for illegal off-exchange trades with US customers.
- SEC closes NanoBit fraud case with $5M-plus in fines.
- Polymarket's hack figure revised upward to $3.1 million, several days after the platform committed to full user refunds.
- SecondFi outlines a two-week recovery timeline after a $2.4 million Cardano wallet exploit.
- Polymarket loses $2.9 million in a frontend supply-chain attack.
- Base suffers its second mainnet stall in 48 hours.
- Q2 2026 is officially the most-hacked quarter on record.
- THORChain resumes operations a month after a $10.7 million exploit.
- Polymarket users lose millions via a compromised third-party vendor.
- Europol's infostealer sweep freezes $47 million in crypto across multiple jurisdictions.
- Four arrested in Poland over SIM-swap attacks on crypto exchanges, ZachXBT links threat actor 'Merry'.
- CoinEx denies facilitating $3.84 billion in flows to sanctioned Iranian platforms.
- DOJ seizes Huione Group infrastructure in the largest illicit marketplace takedown on record.
- SecondFi loses $2.4 million in a Cardano wallet exploit, with up to $20 million at risk.
- Telegram impersonator jailed 15 months for a $1.4 million fake staking scheme.
- Two Scattered Spider members plead guilty on the opening day of what was set to be a six-week UK trial.
- DOJ seizes Huione Group cloud infrastructure used to route billions in fraud proceeds.
- Thailand widens its probe into a Chinese grey-capital network laundering over $300 million a year via illegal crypto mining.
- New York man sentenced to 15 months for a $1.4 million Telegram influencer impersonation scheme.
- Taiko bridge exploit: see lead story.
- Secret Network bridge hit for $4.7 million via an infinite-mint bug that went undetected for a week.
- JaredFromSubway MEV bot loses $7.5 million and threatens legal action.
- OFAC sanctions ISIS-linked crypto financing network spanning Europe, the Middle East, and West Africa.
- jaredfromsubway MEV bot drained $7.5M via counter-MEV honeypot.
- Fake ZKsync token tied to fentanyl-linked Chinese criminal network caused $1M+ in losses.
- Altura winds down stablecoin vault amid mass withdrawals and msUSD contagion fears.
- Secret Network's Axelar bridge drained $4.67M via infinite-mint exploit, undetected for seven days.
- Two Texas brothers plead guilty to kidnapping a Minnesota family for $8M in crypto.
- Microsoft flags USB-spread malware hijacking crypto wallets.
- Steam Workshop wallpaper packs delivering infostealers to gamers.
- Texas brothers plead guilty to $8M armed crypto kidnapping.
- Aztec hit by a second exploit in less than a week, losing another $2.1 million.
- Popa botnet tied to a Nasdaq-listed Israeli proxy firm.
- 'Bitcoin Rodney' pleads guilty in $1.8 billion HyperFund fraud.
- Bybit lands on Singapore's MAS Investor Alert List.
- Binance VIP client manager reportedly under investigation by Chinese authorities.
- Aztec Connect's deprecated smart contract drained for $2.1 million.
- Chainalysis flags $36.7 million in losses from unverified DeFi contract attacks since January.
- South Korea charges 23 people over $11 million in crypto laundering linked to a Cambodian scam ring.
- Aztec Connect's deprecated bridge drained for $2.1M.
- Physical attack in France results in one indictment.
- Coinbase quantum report flags exchange cold wallets in address-reuse exposure pool.
- Google sues Chinese crime network for weaponising Gemini in crypto-targeted phishing campaign.
- AI agent burns developer funds on a fabricated security scan.
- Monero laundering maze covered in the lead.
- Tennessee man indicted for a four-year crypto Ponzi scheme.
- SBF appeal rejected, presidential pardon now his only remaining path.
- AudiA6 crypto laundering network taken down, $389M in bitcoin traced.
- Immunefi CEO says frontier AI models are driving a vulnerability surge across DeFi.
- Coinbase urges Bitcoin developers to begin post-quantum migration now.
- Raydium drained $1.34M via a retired AMM program.
- Krebs profiles 'The Gentlemen', ransomware's second-most-active gang.
- Humanity Protocol: $36M gone because multisig keys lived on one laptop.
- Chainalysis flags $36.7M stolen from unverified smart contracts since January.
- Microsoft's June Patch Tuesday is the largest on record, nearly 200 vulnerabilities patched.
- Humanity Protocol: $32 million drained, token down 89%.
- Yuga Labs rescued 68 NFTs from a Flooring Protocol exploit.
- Claude Opus 4.8 found a critical Zcash vulnerability before any human auditor did.
- A Satoshi-era wallet moved 15 BTC after 14 years of dormancy, complicating a $285B lawsuit.
- apxUSD depegs to $0.90 as collateral token STRC collapses.
- AI-assisted researcher who flagged a Zcash vulnerability now turns the same tooling on Monero.
- Microsoft researchers flag a prompt-injection flaw in Claude Code that could expose GitHub credentials.
- TrustedVolumes, a 1inch Fusion resolver, lost $6.7 million in an exploit.
- AI tooling surfaced a critical flaw in a major crypto network, with warnings the class of vulnerability extends to banks.
- Zcash Orchard Pool: four-year-old counterfeiting flaw disclosed.
- Kelp DAO hacker launders $220 million, leaving recovery hopes largely exhausted.
- EdgeX token collapses; ZachXBT alleges insiders held nearly the entire supply.
- DOJ task force freezes $3.8 million in illicit crypto tied to Southeast Asian organised crime.