Topic
security
42 stories
Bitget says ~$352M stolen in suspected North Korean hack; withdrawals paused
Bitget CEO Gracy Chen says North Korea's Lazarus Group likely stole roughly $352 million from the exchange's hot and warm wallets, with withdrawals paused and most losses covered by a protection fund.
Bitget says $352M drained from hot wallets, pauses withdrawals
Bitget CEO Gracy Chen said roughly $352 million was drained from the exchange's hot and warm wallets on September 24, and paused withdrawals while insisting cold wallets and user funds are safe.
CertiK Pins ~$2B of 2025 Crypto Theft on North Korea, or About 60% of All Losses
Blockchain security firm CertiK says North Korea–linked hackers stole about $2.06 billion in crypto in 2025 — roughly 60% of all theft losses — and $6.75 billion across 263 incidents since 2016.
Symbiosis recovers ~15 BTC after Bitcoin bridge exploit, dangles 20% bounty at attacker
Symbiosis says it recovered about 15 BTC after a Sept. 11 exploit of its Bitcoin Bridge minted roughly 46.1 billion unbacked syBTC, though security firms peg the attacker's actual take at about $336,000.
Revolut says attacker used a real government email domain to pry customer KYC and Bitcoin transaction data loose
Revolut says an attacker used a legitimate government agency email domain to submit fraudulent data requests, exposing affected customers' KYC documents and full transaction histories, including Bitcoin activity.
Blockstream refuses to pay ransom over $47M Liquid bitcoin hack: 'It is theft'
Blockstream has rejected a ransom demand tied to a hack of its Liquid network that took roughly $47 million in bitcoin, saying it will treat the loss as theft rather than pay for the coins' return.
Researchers cut a key quantum-attack benchmark for Bitcoin and Ethereum in half — with caveats attached
A crowdsourced challenge run through Eigen Labs' ECDSA.Fail cut the estimated quantum resources for a core step of a Bitcoin and Ethereum attack to roughly 1.5 billion, more than half below Google's March benchmark, though the two counts aren't strictly comparable.
Cronos Rolled Back Two Hours of Transactions to Undo a $111M DeFi Exploit
Cronos reversed a roughly $111 million DeFi exploit by rolling back about two hours of on-chain transactions, according to Decrypt — a move that overrode the ledger's normal immutability.
Coldcard-Linked Hacker Moves $7.7M in Bitcoin, About Half of a Third Tranche
A hacker shifted about $7.7 million in bitcoin — reportedly nearly half of a third batch of coins tied to a Coldcard-linked theft — while BTC traded near $79,400, per Decrypt.
Coldcard thief moves nearly half of 'Wave 3' bitcoin as total losses near 1,806 BTC
Galaxy Research says the attacker behind the Coldcard hardware-wallet thefts has moved 45% of the bitcoin taken in the "Wave 3" round, with total losses now put at roughly 1,806 BTC (~$143.9 million).
Trezor's ShipMonk breach balloons: 67,000 more customers exposed, records that should have been deleted
Trezor now says roughly 67,000 more U.S. customers had personal data exposed in a breach at its former shipping partner ShipMonk, far more than the ~14,000 it disclosed in August.
Ledger and OneKey trade claims over an Ethereum app bug that was already patched
Rival hardware wallet maker OneKey says it reproduced a transaction-replacement exploit against Ledger's Ethereum app version 1.22.1; Ledger says the flaw was patched weeks earlier and no user was affected.
StarkWare says it pushed through a quantum-resistant Bitcoin transaction — by going around the network
StarkWare says it executed the first Bitcoin transaction hardened against quantum attack, using brute-forced signatures that a MARA mining pool had to accept directly because ordinary nodes would reject it.
FOMO denies its iOS update drained user wallets; the accuser has a history
Crypto trading app FOMO's co-founder denies an X account's claim that an iOS update drained $6 million in user funds, as Protos finds the cited 662 SOL transfer is real but unexplained.
Maya Protocol Halts Network After Six-Bug Exploit Drains $1.4M in Bitcoin
Maya Protocol halted its network on Wednesday after attackers chained six separate bugs to take roughly $1.4 million in Bitcoin, per a Decrypt report; the team has not published its own accounting.
Crypto-stealing malware is riding pirated copies of 'The Odyssey,' Decrypt reports
Decrypt says illegal downloads of "The Odyssey" are bundled with wallet-draining software, but no malware family, indicator or loss figure has been published alongside the claim.
Israeli broker Bits of Gold says vendor breach exposed data on 200,000 customers
Bits of Gold says a hacker reached a third-party analytics vendor and took names, national ID numbers and bank details for roughly 200,000 customers — about 80% of its user base — with no funds or keys touched.
SafePal says 39,798 customers' names and addresses were exposed by an order-tracking flaw
Hardware wallet maker SafePal says an authorization flaw in an order-tracking plug-in exposed names, addresses and contact details for 39,798 customers who ordered between March 2025 and April 2026.
Trezor customer data exposed through a shipping partner, Decrypt reports — scope still undisclosed
Decrypt reported on August 13 that Trezor customer data was exposed via a third-party shipping provider, with the partner's identity, the affected record count and the data fields all still undisclosed.
Trezor customer addresses exposed in breach at shipping contractor ShipMonk
Trezor says a breach at logistics contractor ShipMonk exposed names and contact details of roughly 13,700 customers, including home addresses and phone numbers for 11,742 of them.
Harmony confirms unauthorized mint of 4 billion ONE, says it is weighing a rollback
Harmony says an attacker minted 4 billion ONE tokens without authorization; on-chain researcher Juiceberg estimates about 97% has already reached exchanges, and the token fell roughly a third on Wednesday.
Harmony says attacker minted ~4 billion ONE; token drops 26% as team weighs a rollback
Harmony's ONE fell about 26% on Wednesday after an apparent exploit minted roughly 4 billion tokens, and the team said it is pursuing exchange freezes, a patch and a possible chain rollback.
Coldcard seed bug drives a spike in new Bitcoin addresses as users flee 2021-era wallets
Coinkite users have lost at least 1,816 BTC — roughly $116 million — in four theft waves since July 30, traced to a 2021 firmware bug that generated wallet seeds with a weak software random number generator.
Immunefi puts July crypto hack losses at $110 million — and uses the occasion to market its audit competitions
Immunefi says crypto lost about $110 million to hacks in July and paid researchers $2.32 million, in a statement that also markets its own audit-competition product against rival auditors.
BTCPay Server warns of critical flaw under active exploitation; patch details not yet public
BTCPay Server has warned that a critical flaw in the self-hosted Bitcoin payment processor is under active exploitation, though no CVE number or patched release has surfaced in public reporting yet.
BTCPay Server tells users to patch or power down, citing an actively exploited critical bug
BTCPay Server told users on Aug. 7 to upgrade to version 2.4.2 or shut down their servers, saying a critical flaw is already being exploited and funds may be at risk.
Ethereum Foundation funds a front-end integrity tool built for journalists, aimed at wallets
The Ethereum Foundation's Trillion Dollar Security initiative is funding Freedom of the Press Foundation to build a WEBCAT front-end verification library for crypto wallets, though the announcement names no grant amount, timeline or committed integrators.
Coldcard's seed flaw is still live, and an exchange is already selling the moral
Coinkite says the entropy flaw behind up to $114 million in stolen bitcoin is still live and requires manual migration, while OKX claims the theft is driving record deposits to exchanges.
Fourth Coldcard sweep is running live, with estimated losses near $114 million
Galaxy's Alex Thorn says a fourth wave of sweeps against Coldcard-generated bitcoin addresses began Monday, putting estimated losses since July 30 near 1,816 BTC, or roughly $114 million.
Coldcard wallet drain reaches $88 million, per Decrypt — with the mechanism still unspecified
Decrypt reports that losses from an exploit hitting Coldcard bitcoin wallets have reached $88 million and are still climbing, with the attack vector and vendor response not yet specified.
CZ warns Bitcoin holders after reported $70 million Coldcard exploit
Decrypt reported on August 1 that Binance founder Changpeng Zhao warned Bitcoin holders after a roughly $70 million exploit involving Coldcard hardware wallets, with the attack path still unspecified.
Coldcard key flaw: third sweep takes 208 BTC, running total hits 1,367
A third sweep of wallets seeded by a flawed March 2021 Coldcard firmware build drained 208 bitcoin from 1,912 addresses, pushing the running total to 1,367 BTC.
Galaxy puts the Coldcard drain at 1,082 BTC across 1,196 wallets — roughly double the first count
Galaxy Research says an attacker swept 1,082.65 BTC from 1,196 Coldcard wallets in 41 minutes on July 30 by reconstructing weakly generated seeds offline, without touching a single device.
Crypto 'wrench attacks' hit 52 in first half of 2026, with money targeted up more than tenfold
CertiK recorded 52 crypto "wrench attacks" — physical assaults and extortion targeting holders — in the first half of 2026, with total money demanded or stolen jumping more than tenfold to $124 million, most of it concentrated in France.
Trezor executive concedes hardware wallets are "clunky" but rejects ZachXBT's "complete garbage" verdict
On-chain investigator ZachXBT called all hardware wallets "complete garbage" for high-stakes use; Trezor's commercial chief conceded the tools are "clunky" but rejected the blanket verdict, while Tornado Cash's Roman Storm sided partly with ZachXBT.
Ethereum Foundation: AI agents found real protocol bugs, but the triage is where the work is
Ethereum Foundation's Protocol Security team says coordinated AI agents found real bugs in protocol code, including a disclosed libp2p flaw, but that verifying the findings — not generating them — is now the hard part.
BitGo says it will ship quantum-risk tools for institutional Bitcoin wallets 'in coming weeks'
BitGo said Thursday it will roll out tools in the coming weeks to help institutions measure and cut Bitcoin wallets' exposure to a future quantum-computing attack, built on its existing multi-signature setup.
Bitcoin Core ships a test build to fix the privacy feature that leaked privacy
Bitcoin Core has published v31.1rc1 for testing, a minor release whose headline fix closes a privacy bug in the new private-broadcast feature that could leak a sender's IP address to a peer.
Bitcoin Core discloses a high-severity node-crash bug, CVE-2024-52911, fixed in version 29.0
Bitcoin Core disclosed CVE-2024-52911, a high-severity use-after-free bug that let a miner crash nodes running versions from 0.14.0 up to 29.0 by broadcasting a specially crafted invalid block.
Bitcoin Core discloses five patched vulnerabilities, including a high-severity remote-crash bug that lingered for eight years
Bitcoin Core disclosed five node vulnerabilities patched in earlier releases, led by a high-severity use-after-free crash bug that went unnoticed for roughly eight years.
Ethereum Foundation launches "Clear Signing" standard to kill blind transaction approvals
The Ethereum Foundation released ERC-7730, an open "Clear Signing" standard that gives wallet users human-readable descriptions of transactions to eliminate blind signing approvals.
Crypto theft dipped to $76M in June, with Humanity Protocol's $31M–$36M hack the largest single loss
Blockchain security firm PeckShield tallied about $76 million stolen across 40 crypto incidents in June, a 7% dip from May, led by Humanity Protocol's private-key breach.