Security audits ‘not enough’ as losses reach $1.5B in 2023, security professional says

As companies continue to fall for hacks and exploits, professionals working in the cybersecurity space chipped in on what can be improved in terms of crypto security for digital asset companies and the broader crypto industry. Before September, almost $1 billion had already been lost ...

Aerodrome and Velodrome DeFi platforms experience front-end hacks

The decentralized finance (DeFi) platforms Aerodrome and Velodrome reported compromises to their front ends on Nov. 28. The two platforms posted announcements on X (formerly Twitter) stating their front ends were compromised and asked users not to interact with the platforms while inv ...

KyberSwap DEX hacker sends an on-chain message: Be nice, or else

The exploiter behind the $46 million crypto theft against KyberSwap has demanded its execs and tokenholders ease up on the hostilities, threatening to push out negotiations until everyone is “more civil.”In an on-chain message addressed to KyberSwap executives, tokenholders and ...

Inferno Drainer says it’s shutting down after helping steal $70M in crypto

Inferno Drainer, one of the most popular crypto wallet-draining kits for hire says it is shutting down for good after helping phishing scammers steal nearly $70 million worth of crypto this year. In a Nov. 26 Telegram post, the team behind Inferno Drainer said it was “time for us to move o ...

Indexed Finance thwarts hijackers, set to compensate 2021 hack victims

Indexed Finance, an Ethereum-based project that suffered a $16 million hack in 2021, has successfully thwarted two hijacking attempts. The project’s decentralized autonomous organization (DAO) control will be returned to its founders, aiming to allocate the remaining treasury to victims of ...

Blast network hits $400M TVL, rebuts claim that it’s too centralized

Web3 protocol Blast network has gained over $400 million in total value locked (TVL) in the four days since it was launched, according to data from blockchain analytics platform DeBank. But in a Nov. 23 social media thread, Polygon Labs developer relations engineer Jarrod Watts claimed that the n ...

KyberSwap attacker used ‘infinite money glitch,’ Australia’s tax agency won’t clarify DeFi rules: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The attacker who stole $46 million from the KyberSwap protocol has used a complex strategy described by ...

KyberSwap hacker offers $4.6M bounty for return of $46M loot

The decentralized exchange KyberSwap has offered a 10% bounty reward to the hacker who stole $46 million on Nov. 22 and left a note of negotiation. The exchange wants 90% of the loot returned by 6 am UTC on Nov. 25.On Nov. 23, KyberSwap alerted users that its liquidity solution, KyberSwap ...

KyberSwap attacker used ‘infinite money glitch’ to drain funds: DeFi expert

The attacker who drained $46 million from KyberSwap relied on a “complex and carefully engineered smart contract exploit” to carry out the attack, according to a social media thread by Ambient exchange founder Doug Colkitt. Colkitt labeled the exploit an “infinite mo ...

HECO Chain bridge compromised, over $86.6M sent to suspicious addresses

Data shared by blockchain security platform PeckShield shows that more than $86.6 million in digital assets were transferred from the HECO Chain bridge to suspicious addresses. The security firm suggests that the bridge is compromised and an exploit is ongoing. In response to the inci ...

dYdX founder blames V3 central components for ‘targeted attack,’ involves FBI

Decentralized finance (DeFi) protocol dYdX founder Antonio Juliano took to X (formerly Twitter) to share some of the findings of the investigation into the loss of $9 million in insurance funds, in what many suspected was an exit scam that took place on Nov. 17.Juliano noted that the actua ...

Poloniex says hacker’s identity is confirmed, offers last bounty at $10M

Crypto exchange Poloniex recently posted a message to the hacker responsible for stealing over $100 million in digital assets from one of its wallets saying that they’ve identified the person and are giving the perpetrators a chance to return the assets in exchange for a $10 million bounty.  ...

Kronos Research halts trading amid $25M API key hack investigation

A hacker walked away with $25 million from quantitative trading firm Kronos Research after accessing its compromised API keys.On Nov. 19, Kronos Research revealed that an unauthorized entity accessed some of its API keys. Subsequently, the firm stopped its trading services on the plat ...

Atomic Wallet asks to toss suit over $100M hack saying it has ‘no US ties’

The company behind Atomic Wallet has asked a United States court to dismiss a class action suit seeking damages from a $100 million hack arguing the claims should’ve been filed in Estonia where it's based.In a Nov. 16 dismissal motion in a Colorado District Court the Estonian firm argued i ...

Poloniex crypto exchange resumes withdrawals after $100M hack

Justin Sun’s cryptocurrency exchange Poloniex is preparing to resume operations after suffering a major hack in mid-November, according to an official company announcement posted on Nov. 15In the statement, the company said that the platform has “mostly completed” the restoration ...

Cybersecurity team claims up to $2.1B in crypto stored in old wallets are at risk

While the crypto community is still weathering the effects of the recent $100-million Poloniex hack, another cybersecurity threat that could affect billions worth of crypto assets has been discovered by a team of blockchain security experts. On Nov. 14, cybersecurity company Unciphere ...

Mango Markets’ exploiter to face trial in April, and Coinflux shuts multichain: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The exploiter behind the $116-million theft of assets from Mango Markets will face trial in April next ...

Crypto exchange CoinSpot reportedly suffers $2M hot wallet hack

Australian crypto exchange CoinSpot has reportedly been hacked for $2.4 million in a “probable private key compromise” over at least one of its hot wallets.According to a Nov. 8 post to his Telegram channel, blockchain sleuth ZachXBT highlighted two transactions entering the alleged hacker ...

Monero’s community wallet loses all funds after attack

A recent attack compromised Monero’s community crowdfunding wallet, wiping out its entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.The incident took place on Sept. 1 but was only disclosed on GitHub on Nov. 2 by Monero’s developer Luigi. According to him, the source of the b ...

Fraud trial of Mango Markets exploiter behind alleged $116M theft pushed to April

Lawyers representing the $116 million Mango Markets exploiter have convinced a judge to postpone the fraud trial until April 8, 2023.Avraham Eisenberg’s fraud trial was set to commence on Dec. 4 but several circumstances impacted his trial preparations, according to his lawyers, who ...

SafeMoon addresses recent exploits amid SEC charges

Decentralized finance project SafeMoon, which was charged by the United States Securities and Exchange Commission (SEC) for security rules violations and fraud, has said that it is closely examining recent developments and will work to resolve the situation promptly.According to a statemen ...

Apple MacOS malware targets crypto community and engineers

A new malware discovered on Apple’s macOS — tied to the North Korean hacking group Lazarus — has reportedly targeted blockchain engineers of a cryptocurrency exchange platform.The macOS malware “KandyKorn” is a stealthy backdoor capable of data retrieval, dire ...

SafeMoon hacker’s use of centralized exchanges could help law enforcement: Match System

SafeMoon, a decentralized finance project exploited in March, resulting in a net loss of $8.9 million in BNB, has been charged by the United States Securities and Exchange Commission and its key executives for security rules violations and frauds. The funds associated with the exploit have ...

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

Lazarus Group used a new form of malware in an attempt to compromise a crypto exchange, according to an October 31 report from Elastic Security Labs. Elastic has named the new malware “KANDYKORN” and the loader program that loads it into memory “SUGARLOAD,” as the loader file has a novel “ ...

Onyx Protocol exploiter begins siphoning $2.1M loot on Tornado Cash

Decentralized peer-to-peer lending protocol Onyx Protocol lost roughly $2.1 million in an exploit of a market with no liquidity that was deployed on Oct. 27. The Onyx Protocol hacker exploited a known bug, a rounding issue behind the popular CompoundV2 fork, explained blockchain inves ...

Crypto horrors: Tales of lost Bitcoin wallets

In the shadowy corners of the digital world, where the glow of computer screens illuminates faces with eerie light, there exist tales of lost fortunes. These tales act as a terrifying reminder of the unpredictable nature and volatility present in the cryptocurrency markets and the need to adopt s ...

Unibot contract $560K exploit crashes token price by more than 40%

A new contract deployed on Oct. 29 by Unibot, a popular Telegram bot used to snipe trades on the decentralized exchange Uniswap, was reportedly exploited to hack roughly $560,000 in various memcoins from users.On Oct. 31, blockchain security firm Scopescan alerted Unibot users about an ong ...

3 unique ways hackers are stealing your crypto: Bitrace Report

To track down and counter the sudden disappearance of tokens from crypto wallets requires investors to know the various ways bad actors use to steal cryptocurrencies successfully. Blockchain investigator Bitrace has identified three effective ways hackers gain access to crypto in ...

Crypto thief steals $4.4M in a day as toll rises from LastPass breach

At least 25 people have reportedly seen $4.4 million in crypto drained from across 80 wallets due to a 2022 data breach that impacted password storage software LastPass.In an Oct. 27 X (Twitter) post, pseudonymous on-chain researcher ZachXBT said they and MetaMask developer Taylor Monahan ...

85% of crypto rug pulls in Q3 didn’t report audits: Hacken

Cryptocurrency rug pulls are not too difficult to be spotted by investors as the majority of such scams usually share distinct and visible features, according to a new report.Blockchain security auditor Hacken on Oct. 25 released its latest security insights report, aiming to spot the tren ...

EtherHiding: Why hackers may prefer Binance’s BNB Smart Chain

Despite the name “EtherHiding,” the new attack vector that hides malicious code in blockchain smart contracts doesn’t have much to do with Ethereum at all, cybersecurity analysts have revealed.As reported by Cointelegraph on Oct. 16, EtherHiding has been discovered as a new way for ba ...

Atomic Wallet freezes $2M in ‘suspicious deposits’ on exchanges

Hacked cryptocurrency wallet Atomic Wallet has frozen $2 million in “suspicious deposits” in a joint effort with major crypto exchanges.Announcing the news to Cointelegraph on Oct. 19, Atomic Wallet said that blockchain intelligence firms Chainalysis and Crystal have assisted the wallet fi ...

Platypus Finance recovers 90% of assets lost in exploit

Decentralized finance (DeFi) protocol Platypus Finance said it had recovered 90% of assets that were stolen in a security breach last week.According to the October 17 announcement, developers said the protocol's net loss was limited to "18,000 Avalanche," worth $167,400 at the time of publ ...

Fantom Foundation hacked for an estimated $6.7M: Report

Fantom Foundation, developers of the Fantom network, have reportedly been hacked for over $6.7 million worth of cryptocurrency. Blockchain data shows that an address labeled “Fake_Phishing188024” was sent over 2,000 Convex (CVX) tokens and other cryptocurrencies from a kno ...

EtherHiding: Hackers create novel way to hide malicious code in blockchains

Cybercriminals have discovered a new way to spread malware to unsuspecting users, this time, by manipulating BNB Smart Chain (BSC) smart contracts to hide malware and disseminate malicious code.A breakdown of the technique known as ‘EtherHiding’ — was shared by security r ...

Individual Linked to Cryptocurrency Money Laundering Operation Selling Stolen Tokens at Discounted Rates

Blockchain analysis experts have uncovered an individual allegedly linked to a cryptocurrency money laundering operation selling stolen tokens from recent high-profile exchange hacks at discounted rates. These investigations led to an individual who is reportedly selling stolen cryptocurrency tokens ...

Crypto-Related Exploits Reach All-Time High in September 2023, With $329.8 Million Stolen

In September 2023, crypto-related exploits reached an unfortunate peak, making it the worst month of the year so far in terms of cryptocurrency theft, with a staggering $329.8 million in digital assets stolen. Blockchain security firm CertiK reported on October 2 that the most significant contrib ...

Balancer Website Compromised in DNS Attack, $238,000 Stolen

The Balancer team has stated that a social engineering attack on its domain registrar, EuroDNS, was responsible for the compromise of its website's frontend on September 19. This incident resulted in an estimated $238,000 in cryptocurrency being stolen. Balancer DAO actively addressed the DNS att ...

CoinEx Prepares to Resume Deposit and Withdrawal Services After $70 Million Hack

Cryptocurrency exchange CoinEx is preparing to reopen deposit and withdrawal services more than a week after experiencing a $70 million hack due to compromised hot wallet private keys. CoinEx previously communicated its intention to develop and implement a new wallet system to support the 211 blo ...

CoinEx Cryptocurrency Exchange Hit by $70 Million Hack – Investigation Points to North Korean Hackers

Hong Kong's cryptocurrency exchange, CoinEx, recently disclosed a security breach resulting in hackers making off with more than $70 million in tokens. CoinEx has been actively investigating the incident and is working on deploying a new wallet system to restore both user access and platform functio ...

Security platforms warn about hidden phishing and wallet drainer links

With millions of dollars worth of assets being lost to phishing attacks after signing malicious permissions, the threat of losing crypto assets from questionable links is very real. When these are paired with platforms allowing hidden links, users are subjected to a different kind of risk.  ...

Stake hack of $41M was performed by North Korean group: FBI

The $41 million hack of crypto gambling site Stake was carried out by the North Korean Lazarus Group, the Federal Bureau of Investigation (FBI) stated in an announcement on Sept. 7. This group has stolen more than $200 million of crypto in 2023, the announcement stated. ...

Crypto gambling site Stake sees $16M withdrawals in possible hack

Crypto gambling site Stake has experienced $16 million in withdrawals on Sept. 4 in what security platform Cyvers Alerts is calling “suspicious transactions.” The withdrawing account has been labeled “Stake.com Hacker” by Etherscan, implying that the drained funds may be t ...

South Korea plans to submit bill to freeze North’s crypto assets: Report

The government of South Korea is reportedly planning to submit a bill that will track and freeze North Korean crypto and virtual assets that are used to fund its capital Pyongyang's illicit weapons program. According to a report by local media outlet JoongAng Daily, multiple anonymous ...

Exploits, hacks and scams stole almost $1B in 2023: Report

Malicious actors targeting the crypto space have taken more than $45 million in digital assets from their victims in the month of August alone and a total of $997 million year-to-date (YTD), according to a report shared by the blockchain security firm CertiK. Within the report, CertiK ...

FTX Temporarily Suspends Accounts Following Kroll Cybersecurity Breach

Following the recent Kroll cybersecurity breach, FTX Derivatives Exchange, a financially distressed cryptocurrency trading company, has opted to temporarily suspend accounts of impacted users accessing its claims portal. FTX's decision which was posted on X (formerly known as Twitter) was underta ...

WinRAR Zero-Day Vulnerability Exploited to Compromise Crypto and Stock Trading Accounts

The developers behind file compression software WinRAR have patched a zero-day vulnerability that allowed hackers to install malware onto unsuspecting victims' computers, enabling them to hack into their crypto and stock trading accounts. On Aug. 23, Singapore-based cybersecurity firm Group-IB re ...

Weekend Wrap: Uniswap dev sacked for alleged rug, Steadefi hacker goes mixing and more

Uniswap dev loses job, was it worth it? A Uniswap developer known as “AzFlin” has been sacked by the founder of Uniswap Labs, Hayden Adams, for allegedly creating a memecoin and rug pulling it a few hours later for 14 wrapped-Ether (wETH), worth $25,800. It is understood ...

Zunami Protocol confirms stablecoin pools attacked, $2.1M loss estimated

Decentralized finance protocol Zunami Protocol has advised users not to buy any of its Zunami Ether (zETH) or Zunami USD (UZD) stablecoins, after encountering an attack on its "zStables" pools on Curve Finance. On Aug. 13,  Zunami confirmed on X (Twitter) that its stablecoin pool ...

Curve Finance vows to reimburse users after $62M hack

Decentralized finance (DeFi) platform Curve Finance has officially stated its intention to reimburse users impacted by the recent hack resulting in $62 million of losses. According to an X (formerly Twitter) post from its official account, ongoing investigations are yielding prog ...

DeFi tries to recover from Curve hack, but exploits continue: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The DeFi ecosystem is yet to recover from the crisis brought on by the Curve Finance hack, and even tho ...

Victim of 90 ETH exploit set to claw funds back after hacker was blacklisted

With the help of police and cyber authorities, a victim of a hack worth 90 Ether (ETH) has gotten the attacker’s Tether (USDT) address blacklisted. As a result, they may be able to get most of their funds back. [2023/08/11 17:30] ...

Aave’s Earning Farm protocol targeted by reentrancy attack — PeckShield

Blockchain security firm PeckShield revealed fresh vulnerabilities targeting decentralized finance (DeFi) projects on Aug. 9. According to the firm, Aave’s Earning Farm has been compromised by a reentrancy attack, resulting in the theft of at least $287,000 worth of Ether (ETH). ...

Blockchain Capital’s X account hacked to promote token claim scam

The X (Twitter) account of crypto-focused venture capital firm Blockchain Capital was seemingly taken over by scammers attempting to lure users with the promise of a token claim.On Aug. 9, Blockchain Capital’s account made multiple posts promising a giveaway of “BCAP” tokens and directed u ...

Cypher Protocol freezes smart contract after an estimated $1M exploit

Solana-based decentralized futures exchange Cypher Protocol halted its smart contract after an estimated $1 million exploit.On Aug. 7, Cypher alerted its 13,500 followers on X (formerly known as Twitter) that it had experienced a security incident and had therefore frozen its smart contrac ...

CoinsPaid claims North Korean hacking group used fake job interview to steal $37M

Estonia-based cryptocurrency payments firm CoinsPaid suspects North Korean hackers with the Lazarus Group gained access to its systems through fake recruiters targeting employees.In an Aug. 7 blog post, CoinsPaid said an exploit which allowed hackers to steal more than $37 million on July ...

Curve Finance opens bounty after exploiter’s return deadline expires

Decentralized finance (DeFi) protocol Curve Finance is extending a bug bounty offer to anyone who is able to identify the exploiter responsible for draining over $61 million from its pools on July 30. Curve and other protocols affected by the attack offered a 10% bug bounty to the hac ...

Alchemix reports return of all stolen funds from Curve pools

Lending platform Alchemix has announced the return of all stolen funds by the Curve finance hacker. The attack took place on July 30 and resulted in over $61 million in cryptocurrencies drained, including $13.6 million from Alchemix’s alETH-ETH pool. Along with Alchemix, JPEGd&r ...

JPEG’d confirms return of 5,495 ETH from Curve hacker

Nonfungible token finance (NFT-Fi) protocol JPEG’d has confirmed that 5,495 Ether (ETH), worth roughly $10 million at current prices, has been returned by the Curve Finance hacker. In exchange for returning the funds that were stolen on July 30, the hacker received a 610.6 ETH ($1.1 ...

Curve-Vyper exploit: The whole story so far

The decentralized finance (DeFi) ecosystem has experienced a challenging week after a seismic security incident led to over $61 million being stolen from Curve Finance’s pools, leaving several protocols facing broader contagion risks.This attack exposed vulnerabilities across DeFi pr ...

CRV exposure risk throws a curveball at the DeFi ecosystem: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The $47 million Curve Finance exploit on July 30 had a domino effect on the DeFi ecosystem, mainly due ...

Curve hacker behind $61M heist begins returning funds

The attacker behind the $61 million July 30 Curve Finance attack has returned 4,820.55 Alchemix ETH (alETH), worth approximately $8,889,118, to the Alchemix Finance team and 1 ETH, approximately $1,844, to the Curve Finance team. The Alchemix Finance protocol alETH-ETH pool on Curve is one of the ...

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

Decentralized finance (DeFi) platforms Curve, Metronome and Alchemix have jointly announced an initiative to recover stolen funds from the recent exploits of Curve’s pools.According to on-chain data, the protocols are offering a 10% bounty of the stolen funds as a reward, urging thos ...

Curve’s crvUSD depegs as market reacts to shock events

Curve Finance’s native stablecoin, crvUSD, briefly depegged on Aug. 3, reacting to an uncertain environment surrounding the protocol after its recent exploit. In the course of the day, the stablecoin fell by as much as 0.35% before regaining its peg to the United States dollar.Curve& ...

Individual charged with money laundering admits to hacking Bitfinex in 2016: Report

One-half of the couple alleged to have laundered billions of dollars worth of cryptocurrency has reportedly admitted he was behind the 2016 Bitfinex hack.According to an Aug. 3 CNBC report, Ilya Lichtenstein told a U.S. court he was the individual behind an exploit of cryptocurrency exchan ...

Curve emergency DAO terminates rewards for hack-related pools

The Curve Finance lending protocol has terminated governance token rewards for select liquidity pools affected by the July 30 Curve exploit and July 6 Multichain exploit, according to an Aug. 2 social media post from a member of the protocol’s governing body. The ending of rewar ...

Binance’s CZ warns crypto community about emerging scam

Binance CEO Changpeng 'CZ' Zhao warned his followers on X about a tricky and increasingly popular scam targeting the crypto community, in which fake wallet addresses are used to defraud users during transactions.The scheme generates addresses with the same starting and ending characters as ...

Base’s largest DEX LeetSwap halts trading amid exploit concerns

Decentralized exchange LeetSwap, which operates on Coinbase’s Base network has announced a pause on trading, citing concerns of a potential exploit.LeetSwap tweeted on Aug. 1 that it noticed some of its liquidity pools may have been compromised and temporarily stopped trading to inve ...

BNB Smart Chain hit with copycat Vyper attack, $73K exploited

The BNB Smart Chain (BSC) has reportedly suffered copycat attacks due to a vulnerability in the Vyper programming language, following a similar vein to the exploit on the decentralized finance (DeFi) protocol Curve Finance.Amid the exploits carried out on Ethereum, Blockchain security firm ...

Vyper vulnerability exposes DeFi ecosystem to stress tests

Decentralized finance (DeFi) protocols are undergoing a stress test following a critical vulnerability was found on versions of Vyper programming language, resulting in the theft of millions of dollars worth of cryptocurrencies on July 30.A number of pools using Vyper 0.2.15, 0.2.16 and 0. ...

Curve Finance pools exploited in over $24M due to reentrancy vulnerability

Several stable pools on Curve Finance using Vyper were exploited on July 30, with losses reaching $24 million at the time of writing. According to Vyper, its 0.2.15, 0.2.16 and 0.3.0 versions are vulnerable to malfunctioning reentrancy locks. "The investigation is ongoing but any proj ...

Another week of DeFi hacks, but ZK-proof development heats up: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The past week in DeFi was dominated by exploits and hacks, with three DeFi platforms losing nearly $39 ...

Pro-XRP lawyer Jeremy Hogan’s scam tweet bonanza finally falls silent

The recent flood of scam tweets on pro-XRP lawyer Jeremy Hogan’s hacked account has finally dried up after nearly four days.Since July 24, the XRP community has been diligently warning others and tagging Twitter’s support after they noticed Hogan’s account tweeting malici ...

Redditor’s hacked Bitcoin is a lesson on the hidden dangers of paper wallets

A Reddit user has become the latest example of why crypto users should be more careful when using wallet generators — after the user lost a few thousand dollars worth of Bitcoin (BTC) from their "secure" paper wallet.On July 24, a Redditor by the name /jdmcnair posted on th ...

Crypto payment gateway CoinsPaid suspects Lazarus Group in $37M hack

Cryptocurrency payments platform CoinsPaid has pointed the finger at North Korean state-backed Lazarus Group as being behind the hacking of its internal systems, which allowed them to steal $37.3 million on July 22.“We suspect Lazarus Group, one of the most powerful hacker organisati ...

Connext, Alchemix launch cross-chain token standard to reduce bridge exploit losses

The Connext cross-chain bridging protocol has announced a new token standard to reduce losses from bridge hacks. According to a July 24 announcement, the new “xERC-20” standard allows token issuers to maintain a list of official bridges and control how many tokens can be minted by eac ...

Alphapo hot wallets hacked for over $31 million

Crypto payment platform Alphapo had at least $31 million drained from its hot wallets on Ether (ETH), TRON (TRX), and Bitcoin (BTC), security experts reported on July 22. Since the number of Bitcoins stolen is uncertain, the figures may be even higher. According to on-chain sleuth Zac ...

‘Multichain was a big blow’, says Andre Cronje as Fantom TVL slumps

Fantom's co-founder Andre Cronje classified Multichain's debacle as a "big blow" to the smart contract platform, which saw a sharp decline in activity in the past weeks as a result of Multichain's problems. According to data from DefiLlama, Fantom's total value locked (TVL) dropped fr ...

Crypto lender Geist Finance shuts down permanently over Multichain hack

Lending protocol Geist Finance is shutting down permanently due to losses from the Multichain exploit, according to a July 14 social media post from the app’s development team. Geist contracts were paused on July 6, then resumed in “withdraw and repay only” mode on July 9. The l ...

USB keystroke injectors still a threat to crypto users

The Diabolic Drive’s name sounds as ominous as its potential payload. The recently developed USB wireless keystroke injection tool is intended to stress test networks, but could it potentially be used as a means to steal cryptocurrency from unwitting users?The new gadget is set to be ...

Crypto scams are down 77% — but this exploit is making a huge comeback

Cryptocurrency scams have fallen a massive 77% from $3.3 billion to $1.1 billion over the first six months of 2023, according to a recent report by blockchain intelligence firm Chainalysis.The catch, though, is that ransom attacks are back in trend, with perpetrators pocketing 62.4% more r ...

New York prosecutor charges hacker over $9M exploit of Solana-based exchange

A former security engineer for an international technology firm has been arrested and charged for allegedly using a smart contract bug to steal $9 million in cryptocurrency from a Solana-based decentralized crypto exchange.On June 11, the United States Attorney for the Southern District of ...

Bug bounties can help secure blockchain networks, but have mixed results

Bug bounties are programs organizations offer to incentivize security researchers or ethical or white hat hackers to find and report vulnerabilities in their software, websites or systems. Bug bounties aim to improve overall security by identifying and fixing potential weaknesses before malicious ...

Multichain’s ‘mysterious withdrawals’ have whiffs of a ‘rug pull’ — Chainalysis

The multi-million dollar exploit of cross-chain bridge protocol Multichain could have been an internal rug pull, according to blockchain security and analytics firm Chainalysis.“On July 6, 2023, cross-chain bridge protocol Multichain experienced unusually large, unauthorized withdraw ...

Pink, Pussy, Venom, Inferno — Drainers coming for a crypto wallet near you

Four major crypto drainers have emerged to fill the vacuum left by the notorious wallet sweeper Monkey Drainer, with thousands of victims targeted and millions in crypto stolen already this year. The crypto drainers — called Pink Drainer, Inferno Drainer, Pussy Drainer, and Venom Dra ...

Multichain attack triggers Twitter phishing scheme for FTM distribution

Hackers continue their relentless attacks, displaying no signs of slowing down. Shortly after the Multichain hack, scammers started spreading a phishing link on Twitter.The fraudulent distribution of Fantom (FTM) to users — falsely linked to the Multichain attack — is rapidly s ...

Circle, Tether freezes over $65M in assets transferred from Multichain

Stablecoin issuers Circle and Tether have frozen over $65 million in assets tied to the suspected exploit of cross-chain router protocol Multichain. The move follows unexplained large outflows from the Multichain MPC bridge on July 6. According to the knowledge graph protocol 0xScope, ...

Over $765K worth of NFTs stolen after SIM swap attack on Gutter Cat Gang

More than $765,000 worth of nonfungible tokens has been stolen as part of a reported SIM swap attack on the Gutter Cat Gang NFT project.The security breach was highlighted by several NFT community members at around 8 pm UTC on July 7, with Gutter Cat Gang co-founder @GutterMitch tweeting o ...

DeFi ‘circuit breaker’ could slash hack losses by 70%: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.Amid the growing number of hacks in the DeFi ecosystem, a smart contract developer has made a new Ether ...

Multichain MPC bridge sees $100M+ outflows, sparking fears of exploit

Abnormally large outflows from the Multichain MPC bridge platform are sparking fears of a multi-million dollar exploit.On July 6, observers noticed that approximately $102 million worth of crypto has been withdrawn from Multichain’s Fantom bridge on the Ethereum side, as well as $666 ...

Darknet bad actors work together to steal your crypto, here’s how — Binance CSO

Lurking in the shadiest corners of the dark web is a “well-established” ecosystem of hackers that target cryptocurrency users with poor “security hygiene,” according to Binance’s chief security officer.Speaking to Cointelegraph, Binance CSO Jimmy Su said in re ...

Poly Network urges users to withdraw after exploit affects 57 crypto assets

Further details are coming to light following a July 2 attack on cross-chain bridge platform Poly Network, which has resulted in a hacker being able to issue billions of tokens out of thin air for profit.In a July 2 Twitter post, Poly Network confirmed it became the latest DeFi exploit vic ...

$656M lost from crypto hacks, scams and rug pulls in H1 2023: Report

According to a June 30 report by Web3 security firm Beosin, the total value of cryptocurrencies lost in scams, hacks and rug pulls amounted to $656 million during the first half of 2023. This includes the loss of $471.43 million in 108 protocol attacks, $108 million in various phishing scams and ...

Over $204M lost to DeFi hacks and scams in Q2: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The second quarter of 2023 saw over $208 million exploited and hacked from DeFi protocols, and with jus ...

$794K SIM swap hacker PlugwalkJoe sentenced to five years in prison

British Hacker Joseph O’Connor, also known online as PlugwalkJoe, has been sentenced to five years in U.S. prison for his role in stealing $794,000 worth of cryptocurrency via a SIM swap attack on a crypto exchange executive back in April 2019. O’Connor was initially arrested i ...

100K ChatGPT logins have been leaked on dark web, cybersecurity firm warns

Over the past year, more than 100,000 login credentials to the popular artificial intelligence chatbot ChatGPT have been leaked and traded on the dark web, according to a Singaporean cybersecurity firm.A June 20 blog post by Group-IB revealed just over 101,000 compromised logins for OpenAI ...

Atomic Wallet gives major update on hack but questions remain unanswered

Atomic Wallet users have been left wanting more answers, despite the decentralized wallet provider finally releasing a full “event statement” about the June exploit — which some estimate has run up to $100 million in losses.In a June 20, blog post — the first m ...

Curve pool imbalance triggers USDT depeg concerns: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.On June 15, an imbalance in Curve Finance’s 3pool led to a Tether (USDT) depeg scare as the stablecoin’ ...

Hashflow assures users will be made ‘whole’ following $600K exploit

Crypto trading platform Hashflow has assured affected users will be “made whole” following an exploit that saw at least $600,000 in digital assets removed from the platform.On June 14, blockchain security firm Peckshield reported an ongoing issue with the Hashflow trading platf ...

Institutional crypto broker FPG halts withdrawals after $20M cyberattack

Cryptocurrency brokerage firm Floating Point Group (FPG) has confirmed it has halted trading, withdrawals and deposits on its platform after falling victim to a cyberattack on June 11. FPG estimates the attack resulted in a total loss of between $15 million and $20 million.According to a J ...

North Korean hackers swipe over $100M from Atomic Wallet users

Atomic Wallet, a noncustodial decentralized wallet, has been hit by a staggering exploit, leading to users reporting losses of their entire cryptocurrency portfolios. This unforeseen breach has sent shockwaves through the crypto community, as Atomic Wallet’s fundamental premise relies on us ...

Atomic Wallet hackers turn to OFAC-sanctioned Garantex: Elliptic

Illicit funds gained from the $35 million Atomic Wallet hack are on the move again, with sanctioned Russian-based crypto exchange Garantex reportedly becoming the latest to come in contact with the hacked crypto. On June 13, blockchain security and compliance firm Elliptic updated the ...

Scammers steal nearly $1M after hijacking 8+ prominent crypto twitter accounts

Over the past few weeks, a group of scammers has hijacked more than eight Twitter accounts belonging to prominent figures in the crypto space to promote phishing scams. The group has stolen almost $1 million worth of crypto so far, according to blockchain sleuth ZachXBT. In a June 9 Twitte ...

US Justice Department charges two men in Mt. Gox hack

The United States Justice Department has unsealed charges against two men it says are responsible for the $400 million hack of former Bitcoin exchange Mt. Gox. According to the announcement, 43-year-old Alexey Bilyuchenko and 29-year-old Aleksandr Verner allegedly conspired to launder 647,00 ...

Atomic Wallet hacker sends crypto to mixer used by Lazarus Group: Elliptic

Illicit funds gained from the $35 million Atomic Wallet hack have been moving to a crypto mixer known to be favored by North Korea’s most notorious cyber-hacking group.On June 5, blockchain compliance analytics firm Elliptic reported that its Investigations Team has traced funds from ...

Atomic Wallet says hack affected 1% of active users, but investors claim otherwise

A hack that drained $35 million from Atomic Wallet users since June 2 impacted less than 1% of its monthly active users, according to the company. In the aftermath of the attack, Atomic Wallet — along with individual blockchain investigators — have amped up efforts to track and revert ...

Atomic Wallet hack losses top $35M, on-chain sleuth reports

At least $35 million worth of crypto assets have been stolen from Atomic Wallet users since June 2, according to an analysis from on-chain sleuth ZachXBT. The five largest losses account for $17 million.According to Atomic Wallet on Twitter, the cause of the attack is being investigated. R ...

Atomic Wallet exploited, users report loss of entire portfolios

Atomic Wallet has been apparently exploited, with users on Twitter reporting complete losses of their crypto portfolios. Atomic is a noncustodial-decentralized wallet, meaning users are responsible for assets stored in the application. "We have received reports of wallets being compro ...

Tornado Cash Cryptocurrency Mixer Faces Serious Attack, Tokens Withdrawn

Cryptocurrency mixer Tornado Cash suffered a serious attack - an unknown person gained full control over the protocol and has already started withdrawing TORN tokens. An analyst at investment firm Paradigm, using the Twitter pseudonym samczsun, reported that on May 20, so ...

North Korean Hackers Steal $721 Million in Cryptocurrency, Targeting Japan and Vietnam

North Korean-linked hacker groups stole $721 million in cryptocurrency from Japanese entrepreneurs between 2017 and Jan. 1, 2023, according to an Elliptic study published by Nikkei. The amount represents 30% of total losses from DPRK hack ...

Ukrainian Cyber Police Shut Down Nine Services Used by Hackers to Exchange Crypto Ransom

The National Police of Ukraine's Cyber Police Division has announced the shutdown of nine services that were being used by hackers to exchange virtual assets obtained as ransom payments. The operation, which was conducted in collaboration with the Main Police Investigation Department and the Pros ...

The Pokémon Company seeks Director of Corporate Development with NFT and Meta Universe expertise

The Pokémon Company needs a director of corporate development with NFT and meta universe skills Japanese company that owns the rights to the Pokémon brand, The Pokémon Company, is looking for a top manager with expertise in non-interchangeable tokens (NFT) and the meta universe. These are the ...

Hackers Return $7.2 Million Stolen from Safemoon’s Decentralized Cryptocurrency Exchange

The decentralized cryptocurrency exchange Safemoon was the target of hackers who managed to steal $9 million worth of crypto assets from the protocol's liquidity pool at the end of March. However, the good news is that the attackers returned $7.2 million in two separate transactions in the early ...

Cyber Attacks Continue to Plague the Cryptocurrency Industry

PeckShield, a cybersecurity agency, has reported that hackers have breached the DeFi Yearn.Finance protocol and made off with $11 million worth of cryptocurrency assets. Reports earlier indicated that the Aave V1 protocol had been hacked, but Aave developers clarified that the protocol was not co ...

General Bytes Announces Refund Plan for Victims of Crypto ATM Hack

General Bytes, a manufacturer of crypto ATMs, has recently announced that they are prepared to reimburse users who were affected by the recent security breach. This breach occurred when hackers were able to gain access to customers' hot wallets by downloading malicious Java applications onto cryp ...

Scammers Impersonate Ripple CEO Brad Garlinghouse to Promote Fake Cryptocurrency Giveaway on Twitter

The official account of a well-known Indian news channel, News 24, with a substantial following of 1.3 million on Twitter, was hacked by unknown individuals who posted a fraudulent message about distributing 100,000,000 XRP coins. According to the fake tweet posted by the hackers, Ripple CEO Brad ...