
Following the Kelp DAO bridge exploit, approximately $15 billion in assets have migrated from LayerZero to Chainlink CCIP, including institutions like BitGo, Kraken, and Mantle. The article analyzes LayerZero's single-validator configuration vulnerability versus Chainlink's multi-node security model, notes the significant drop in LayerZero's ZRO token market cap, and discusses the winner-take-all trend in cross-chain infrastructure.
2 години тому

Australia's corporate regulator, ASIC, has shut down 3,106 cryptocurrency investment scams in the 2026 fiscal year, a nearly 30% increase year-on-year, as online scams overall surged 182% to over 19,400. Scammers are using generative AI, deepfake videos, fake news articles, and celebrity endorsements to make fraudulent platforms appear legitimate. ASIC also removed 7,051 fake investment platforms and 5,476 phishing links. The regulator urges investors to independently verify license information before transferring funds.
4 години тому

Cross-chain protocol Maya Protocol suspended operations after attackers exploited six software vulnerabilities to steal approximately $1.7 million in Bitcoin and other assets. By forging liquidity pool balances, the attackers took control of pools and drained large amounts of CACAO tokens, causing CACAO's price to plummet nearly 89%. The team has released a post-mortem report and published the attacker's address, hoping to recover funds as a bug bounty. The incident exposed shortcomings in the protocol's code auditing, and the team stated it will adopt a more adversarial review approach.
17 години тому

Decred has released a mandatory software patch, v2.1.6, to fix a critical consensus vulnerability, a potential periodic mixing deanonymization attack, and multiple network denial-of-service risks. The patch includes 23 commits across 20 files, adding 795 lines and removing 392. The project urges all users to upgrade promptly to avoid running on different chains due to a network fork. The update affects both dcrd and dcrwallet, and specifically reminds holders, voting service providers, miners, and exchanges to update.
2026-08-19

On August 18, Binance announced that its security team successfully thwarted a malicious governance proposal targeting an unnamed decentralized autonomous organization (DAO), which could have stolen approximately $1.2 million in treasury tokens. Binance detected the threat less than 48 hours before the proposal's execution and immediately contacted the project team, while also coordinating with other centralized exchanges to suspend deposits of the affected token. The project team voted against the proposal before execution, and Binance stated that no funds were lost. Binance did not disclose the project's name, proposal ID, or on-chain transaction records, but noted that the attacker exploited a vulnerability in the project's governance mechanism where the threshold for creating proposals was too low.
2026-08-19

Bybit intercepted over $700 million in potential user losses during the first half of 2026 through real-time blockchain monitoring and AI-assisted threat detection. The exchange processed more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users and identifying approximately $212 million in fraud-related funds. After suffering a $1.46 billion hack in February 2025, Bybit strengthened its security architecture, now monitoring all business-related on-chain activity and handling 10 token project security incidents without platform losses. Additionally, Bybit has filed legal actions against North Korea and the Lazarus Group.
2026-08-19

Maya Protocol paused its network after an attacker exploited six related software vulnerabilities to steal approximately $1.7 million in Bitcoin and other crypto assets. The attack was carried out in a single transaction containing 23 messages, with about $1.36 million moved to external blockchains and $291,000 remaining in attacker-controlled positions. The CACAO token plunged 88.7% during the incident. The team has begun fixes to resume trading, with initial analysis pointing to flaws in transaction accounts, outbound transaction handling, and liquidity pool calculations.
2026-08-19

Swiss hardware Bitcoin wallet maker BitBox discovered two critical vulnerabilities and a bootloader issue in its firmware through an internal AI audit, prompting the release of the Dixence security update. Exploiting these flaws would require a successful phishing attack and user interaction with a compromised device. BitBox stated that no user funds were stolen and seed phrases were never at risk. The company disclosed the issues voluntarily, with no evidence of exploitation. This incident serves as a reminder that hardware wallets are not infallible, and users should promptly update firmware to mitigate risks.
2026-08-18

BitBox has released firmware updates to fix two critical vulnerabilities that could allow malicious firmware installation or lock bitcoins to unintended addresses. The first flaw affects unconfigured BitBox02 and BitBox02 Nova Multi versions, potentially enabling arbitrary code execution; the second affects the Silent Payments implementation. BitBox stated that no exploits have been detected and no user funds have been reported lost. This follows a previous Coldcard firmware vulnerability that led to the theft of over $112 million in bitcoins.
2026-08-18

In August 2026, SafePal, Trezor, and Bits of Gold disclosed data breaches within four days, exposing the names, phone numbers, addresses, and purchase histories of approximately 253,000 customers. The Trezor and Bits of Gold breaches stemmed from the same vulnerability, CVE-2026-72898, a critical SQL injection flaw in Metabase. This data was used to target cryptocurrency holders in physical attacks (wrench attacks), which surged 33% in the first half of 2026, causing $124.1 million in financial losses. The article analyzes the common technical root cause and highlights the structural inadequacies of hardware wallet manufacturers and brokers in addressing such threats.
2026-08-18