This Web3 security protocol recovered $800K in user funds after Vulcan Forged exploit

As Web3 gets bigger, it struggles to keep up with the malicious actors targeting users’ funds across different blockchains and networks. This security protocol takes a preventive approach against hacks and exploits, freezing assets before they get stolen.Web3 benefits from being a d ...

Poloniex prepares to resume withdrawals after $100M hack

Cryptocurrency exchange Poloniex is preparing to resume withdrawals and deposits after suffering a $100 million hack on Nov. 10.Poloniex took to X (formerly Twitter) on Nov. 29 to announce that it will be gradually resuming deposit and withdrawal services on Nov. 30 at 02:00 am UTC. ...

Security audits ‘not enough’ as losses reach $1.5B in 2023, security professional says

As companies continue to fall for hacks and exploits, professionals working in the cybersecurity space chipped in on what can be improved in terms of crypto security for digital asset companies and the broader crypto industry. Before September, almost $1 billion had already been lost ...

Aerodrome and Velodrome DeFi platforms experience front-end hacks

The decentralized finance (DeFi) platforms Aerodrome and Velodrome reported compromises to their front ends on Nov. 28. The two platforms posted announcements on X (formerly Twitter) stating their front ends were compromised and asked users not to interact with the platforms while inv ...

KyberSwap DEX hacker sends an on-chain message: Be nice, or else

The exploiter behind the $46 million crypto theft against KyberSwap has demanded its execs and tokenholders ease up on the hostilities, threatening to push out negotiations until everyone is “more civil.”In an on-chain message addressed to KyberSwap executives, tokenholders and ...

Crypto exchange HTX reinstates Bitcoin services after $30M hack

Bitcoin (BTC) deposits and withdrawals have returned to the Justin Sun-linked crypto exchange HTX, formerly Huobi, after it suffered a $30 million exploit on Nov. 22.In a Nov. 26 blog post, HTX said deposit and withdrawal functionality is back for multiple currencies, including BTC, Ether ...

Indexed Finance thwarts hijackers, set to compensate 2021 hack victims

Indexed Finance, an Ethereum-based project that suffered a $16 million hack in 2021, has successfully thwarted two hijacking attempts. The project’s decentralized autonomous organization (DAO) control will be returned to its founders, aiming to allocate the remaining treasury to victims of ...

Blast network hits $400M TVL, rebuts claim that it’s too centralized

Web3 protocol Blast network has gained over $400 million in total value locked (TVL) in the four days since it was launched, according to data from blockchain analytics platform DeBank. But in a Nov. 23 social media thread, Polygon Labs developer relations engineer Jarrod Watts claimed that the n ...

KyberSwap attacker used ‘infinite money glitch,’ Australia’s tax agency won’t clarify DeFi rules: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The attacker who stole $46 million from the KyberSwap protocol has used a complex strategy described by ...

KyberSwap hacker offers $4.6M bounty for return of $46M loot

The decentralized exchange KyberSwap has offered a 10% bounty reward to the hacker who stole $46 million on Nov. 22 and left a note of negotiation. The exchange wants 90% of the loot returned by 6 am UTC on Nov. 25.On Nov. 23, KyberSwap alerted users that its liquidity solution, KyberSwap ...

KyberSwap attacker used ‘infinite money glitch’ to drain funds: DeFi expert

The attacker who drained $46 million from KyberSwap relied on a “complex and carefully engineered smart contract exploit” to carry out the attack, according to a social media thread by Ambient exchange founder Doug Colkitt. Colkitt labeled the exploit an “infinite mo ...

HTX to restore services ‘within 24 hours’ after $13.6M hack

Crypto exchange HTX, formerly Huobi Global, will resume deposits and withdrawals within 24 hours after suffering a $13.6 million exploit on Nov. 22.According to its official announcement, the exchange promised to "fully compensate for the losses caused by this attack and 100% guarantee the ...

Justin Sun-related crypto platforms hacked 4 times in 2 months

Tron founder Justin Sun's crypto businesses have come under repeated attack from hackers over the past two months, with at least four hacks of the largest exploits targeting platforms related to the crypto entrepreneur.Sun’s HTX crypto exchange has been hacked at least twice since the plat ...

KyberSwap DEX exploited for $46 million, TVL tanks 68%

Around $46 million in various crypto assets has seemingly been drained from the decentralized KyberSwap exchange in the latest decentralized finance exploit.On Nov. 23, the Kyber Network team alerted its users stating in an X (Twitter) post that KyberSwap Elastic “has experienced a s ...

HTX exchange loses $13.6M in hot wallet hack: Report

HTX, formerly Huobi Global, suffered an estimated loss of $13.6 million as part of the $86.6 million HECO Chain bridge exploit on Nov. 22. According to a report by blockchain security firm Cyvers, the losses stem from three compromised hot wallets with users and exchang ...

HECO Chain bridge compromised, over $86.6M sent to suspicious addresses

Data shared by blockchain security platform PeckShield shows that more than $86.6 million in digital assets were transferred from the HECO Chain bridge to suspicious addresses. The security firm suggests that the bridge is compromised and an exploit is ongoing. In response to the inci ...

Mt. Gox creditors offered fresh hope with new ‘commencement of repayment’ email

Creditors of Mt. Gox, a now-defunct Bitcoin (BTC) exchange that lost 850,000 BTC to a hack in 2014, have reportedly received a new email hinting at soon-to-come repayments.Nobuaki Kobayashi, the trustee overseeing the Mt. Gox Bitcoin exchange’s estate, on Nov. 21 started sending out emails ...

Fantom Foundation awards $1.7M bounty for preventing $170M drain

The Fantom Foundation, a nonprofit organization developing the Fantom blockchain platform, has eliminated a significant vulnerability after a $550,000 hack in October.On Oct. 17, the Fantom Foundation suffered a hot wallet hack, with an unknown attacker draining 1% of Fantom Foundation’s f ...

dYdX founder blames V3 central components for ‘targeted attack,’ involves FBI

Decentralized finance (DeFi) protocol dYdX founder Antonio Juliano took to X (formerly Twitter) to share some of the findings of the investigation into the loss of $9 million in insurance funds, in what many suspected was an exit scam that took place on Nov. 17.Juliano noted that the actua ...

Poloniex says hacker’s identity is confirmed, offers last bounty at $10M

Crypto exchange Poloniex recently posted a message to the hacker responsible for stealing over $100 million in digital assets from one of its wallets saying that they’ve identified the person and are giving the perpetrators a chance to return the assets in exchange for a $10 million bounty.  ...

Bridges have big problems — How can cross-chain swaps be quicker and safer?

A big problem when transferring assets from one blockchain to another concerns bridges. Between 2020 and 2022, data from Token Terminal revealed that more than $2.5 billion had been stolen by hackers — all because of vulnerabilities within bridge infrastructure.In some cases, inadeq ...

Kronos Research halts trading amid $25M API key hack investigation

A hacker walked away with $25 million from quantitative trading firm Kronos Research after accessing its compromised API keys.On Nov. 19, Kronos Research revealed that an unauthorized entity accessed some of its API keys. Subsequently, the firm stopped its trading services on the plat ...

Atomic Wallet asks to toss suit over $100M hack saying it has ‘no US ties’

The company behind Atomic Wallet has asked a United States court to dismiss a class action suit seeking damages from a $100 million hack arguing the claims should’ve been filed in Estonia where it's based.In a Nov. 16 dismissal motion in a Colorado District Court the Estonian firm argued i ...

Poloniex crypto exchange resumes withdrawals after $100M hack

Justin Sun’s cryptocurrency exchange Poloniex is preparing to resume operations after suffering a major hack in mid-November, according to an official company announcement posted on Nov. 15In the statement, the company said that the platform has “mostly completed” the restoration ...

OpenSea NFT users report massive email phishing campaign

Users of the major nonfungible token (NFT) marketplace OpenSea have said they are being targeted with a new email phishing attack, and have received emails containing malicious links from attackers posing as the marketplace itself.According to social media reports, OpenSea users and develo ...

Cybersecurity team claims up to $2.1B in crypto stored in old wallets are at risk

While the crypto community is still weathering the effects of the recent $100-million Poloniex hack, another cybersecurity threat that could affect billions worth of crypto assets has been discovered by a team of blockchain security experts. On Nov. 14, cybersecurity company Unciphere ...

Hackers claim to have stolen user data from defunct crypto ATM firm Coin Cloud

An anonymous group of hackers claims to have stolen personal information for about 300,000 customers of the Bitcoin (BTC) ATM company called Coin Cloud, the pseudonymous cybersecurity account Vx-underground posted on X (formerly Twitter). ...

Mango Markets’ exploiter to face trial in April, and Coinflux shuts multichain: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The exploiter behind the $116-million theft of assets from Mango Markets will face trial in April next ...

Crypto exchange CoinSpot reportedly suffers $2M hot wallet hack

Australian crypto exchange CoinSpot has reportedly been hacked for $2.4 million in a “probable private key compromise” over at least one of its hot wallets.According to a Nov. 8 post to his Telegram channel, blockchain sleuth ZachXBT highlighted two transactions entering the alleged hacker ...

Monero’s community wallet loses all funds after attack

A recent attack compromised Monero’s community crowdfunding wallet, wiping out its entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.The incident took place on Sept. 1 but was only disclosed on GitHub on Nov. 2 by Monero’s developer Luigi. According to him, the source of the b ...

Fraud trial of Mango Markets exploiter behind alleged $116M theft pushed to April

Lawyers representing the $116 million Mango Markets exploiter have convinced a judge to postpone the fraud trial until April 8, 2023.Avraham Eisenberg’s fraud trial was set to commence on Dec. 4 but several circumstances impacted his trial preparations, according to his lawyers, who ...

Multichain inside job? And SOL surges 80% in a month: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.A trader managed to exploit the brief opening of the Multichain cross-chain bridge, which was frozen si ...

SafeMoon addresses recent exploits amid SEC charges

Decentralized finance project SafeMoon, which was charged by the United States Securities and Exchange Commission (SEC) for security rules violations and fraud, has said that it is closely examining recent developments and will work to resolve the situation promptly.According to a statemen ...

Apple MacOS malware targets crypto community and engineers

A new malware discovered on Apple’s macOS — tied to the North Korean hacking group Lazarus — has reportedly targeted blockchain engineers of a cryptocurrency exchange platform.The macOS malware “KandyKorn” is a stealthy backdoor capable of data retrieval, dire ...

SafeMoon hacker’s use of centralized exchanges could help law enforcement: Match System

SafeMoon, a decentralized finance project exploited in March, resulting in a net loss of $8.9 million in BNB, has been charged by the United States Securities and Exchange Commission and its key executives for security rules violations and frauds. The funds associated with the exploit have ...

Breaking: Some Multichain transactions are confirmed as queue unwinds

Hacked cross-chain protocol Multichain has confirmed some transactions, and its backlog of queued transactions has declined to only a single transaction, according to data from Multichain's explorer tool. Blockchain data confirms that some of the transactions have been confirmed on the destinatio ...

Lazarus used ‘KANDYKORN’ malware in attempt to compromise exchange —Elastic

Lazarus Group used a new form of malware in an attempt to compromise a crypto exchange, according to an October 31 report from Elastic Security Labs. Elastic has named the new malware “KANDYKORN” and the loader program that loads it into memory “SUGARLOAD,” as the loader file has a novel “ ...

Onyx Protocol exploiter begins siphoning $2.1M loot on Tornado Cash

Decentralized peer-to-peer lending protocol Onyx Protocol lost roughly $2.1 million in an exploit of a market with no liquidity that was deployed on Oct. 27. The Onyx Protocol hacker exploited a known bug, a rounding issue behind the popular CompoundV2 fork, explained blockchain inves ...

October sees a comparative lull in crypto crime with losses of $32.2M: CertiK

Web3 theft hit a low point for the year so far in October, CertiK reported. Losses to hacks, exploits and scams confirmed by the blockchain security firm amounted to $32.2 million for the month across 38 incidents, with no single incident leading to a loss of over $7 million.Compared to th ...

Unibot contract $560K exploit crashes token price by more than 40%

A new contract deployed on Oct. 29 by Unibot, a popular Telegram bot used to snipe trades on the decentralized exchange Uniswap, was reportedly exploited to hack roughly $560,000 in various memcoins from users.On Oct. 31, blockchain security firm Scopescan alerted Unibot users about an ong ...

3 unique ways hackers are stealing your crypto: Bitrace Report

To track down and counter the sudden disappearance of tokens from crypto wallets requires investors to know the various ways bad actors use to steal cryptocurrencies successfully. Blockchain investigator Bitrace has identified three effective ways hackers gain access to crypto in ...

Crypto thief steals $4.4M in a day as toll rises from LastPass breach

At least 25 people have reportedly seen $4.4 million in crypto drained from across 80 wallets due to a 2022 data breach that impacted password storage software LastPass.In an Oct. 27 X (Twitter) post, pseudonymous on-chain researcher ZachXBT said they and MetaMask developer Taylor Monahan ...

Audits and rug-pulled projects, a $650B token burn, and major DeFi protocol quits UK: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The past week in DeFi was filled with bullish resurgences for many projects, but it was the Uniswap fou ...

Scammers create Blockworks clone site to drain crypto wallets

Phishing scammers have cloned the websites of crypto media outlet Blockworks and Ethereum blockchain scanner Etherscan to trick unsuspecting readers into connecting their wallets to a crypto drainer.A fake Blockworks site displays a fake “BREAKING” news report of a supposed mul ...

Telegram trading bot Maestro refunds users 610 ETH after router exploit

Maestrobots, a group of cryptocurrency bots on the Telegram messenger, is refunding users in the aftermath of a 280 Ether (ETH) attack.The Maestro team refunded the users affected by the Maestro Router 2 contract, the platform announced on X (formerly Twitter) on Oct. 25. According to the ...

85% of crypto rug pulls in Q3 didn’t report audits: Hacken

Cryptocurrency rug pulls are not too difficult to be spotted by investors as the majority of such scams usually share distinct and visible features, according to a new report.Blockchain security auditor Hacken on Oct. 25 released its latest security insights report, aiming to spot the tren ...

Singapore court authorizes freeze order attached to wallets as soulbound NFT

The Singapore High Court has allowed financial investigation firm Intelligent Sanctuary (iSanctuary) to attach nonfungible tokens (NFTs) containing a legal document to cold wallets associated with a hack, according to United Kingdom-based iSanctuary and local press accounts.A court-issued ...

Busy week for Uniswap, and Platypus recovers 90% of hacked funds: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The past week in DeFi was dominated by developments in the popular decentralized exchange platform Unis ...

Atomic Wallet freezes $2M in ‘suspicious deposits’ on exchanges

Hacked cryptocurrency wallet Atomic Wallet has frozen $2 million in “suspicious deposits” in a joint effort with major crypto exchanges.Announcing the news to Cointelegraph on Oct. 19, Atomic Wallet said that blockchain intelligence firms Chainalysis and Crystal have assisted the wallet fi ...

Platypus Finance recovers 90% of assets lost in exploit

Decentralized finance (DeFi) protocol Platypus Finance said it had recovered 90% of assets that were stolen in a security breach last week.According to the October 17 announcement, developers said the protocol's net loss was limited to "18,000 Avalanche," worth $167,400 at the time of publ ...

Fantom Foundation hacked for an estimated $6.7M: Report

Fantom Foundation, developers of the Fantom network, have reportedly been hacked for over $6.7 million worth of cryptocurrency. Blockchain data shows that an address labeled “Fake_Phishing188024” was sent over 2,000 Convex (CVX) tokens and other cryptocurrencies from a kno ...

Individual Linked to Cryptocurrency Money Laundering Operation Selling Stolen Tokens at Discounted Rates

Blockchain analysis experts have uncovered an individual allegedly linked to a cryptocurrency money laundering operation selling stolen tokens from recent high-profile exchange hacks at discounted rates. These investigations led to an individual who is reportedly selling stolen cryptocurrency tokens ...

Crypto-Related Exploits Reach All-Time High in September 2023, With $329.8 Million Stolen

In September 2023, crypto-related exploits reached an unfortunate peak, making it the worst month of the year so far in terms of cryptocurrency theft, with a staggering $329.8 million in digital assets stolen. Blockchain security firm CertiK reported on October 2 that the most significant contrib ...

Balancer Website Compromised in DNS Attack, $238,000 Stolen

The Balancer team has stated that a social engineering attack on its domain registrar, EuroDNS, was responsible for the compromise of its website's frontend on September 19. This incident resulted in an estimated $238,000 in cryptocurrency being stolen. Balancer DAO actively addressed the DNS att ...

CoinEx Prepares to Resume Deposit and Withdrawal Services After $70 Million Hack

Cryptocurrency exchange CoinEx is preparing to reopen deposit and withdrawal services more than a week after experiencing a $70 million hack due to compromised hot wallet private keys. CoinEx previously communicated its intention to develop and implement a new wallet system to support the 211 blo ...

CoinEx Cryptocurrency Exchange Hit by $70 Million Hack – Investigation Points to North Korean Hackers

Hong Kong's cryptocurrency exchange, CoinEx, recently disclosed a security breach resulting in hackers making off with more than $70 million in tokens. CoinEx has been actively investigating the incident and is working on deploying a new wallet system to restore both user access and platform functio ...

Security platforms warn about hidden phishing and wallet drainer links

With millions of dollars worth of assets being lost to phishing attacks after signing malicious permissions, the threat of losing crypto assets from questionable links is very real. When these are paired with platforms allowing hidden links, users are subjected to a different kind of risk.  ...

Stake hack of $41M was performed by North Korean group: FBI

The $41 million hack of crypto gambling site Stake was carried out by the North Korean Lazarus Group, the Federal Bureau of Investigation (FBI) stated in an announcement on Sept. 7. This group has stolen more than $200 million of crypto in 2023, the announcement stated. ...

Crypto whale loses $24M in staked Ethereum to phishing attack

A cryptocurrency whale has fallen victim to a massive phishing attack, losing millions of dollars in staked Ethereum on the liquid staking provider Rocket Pool.A large cryptocurrency investor lost the entire address balance of Lido Staked ETH (stETH) and Rocket Pool ETH (rETH) due to a phi ...

Crypto is in ‘arms race’ against AI-powered scams: Quantstamp co-founder

With the field of artificial intelligence evolving at near breakneck speed, scammers now have access to tools that can help them execute highly sophisticated attacks en masse, warns the co-founder of Web3 security firm Quantstamp.Speaking to Cointelegraph at Korea Blockchain Week, Quantsta ...

Crypto casino Stake reopens withdrawals just 5 hours after $41M hack

Crypto betting platform Stake has reopened deposits and withdrawals and resumed services for users only five hours after the platform was hacked to the tune of $41.3 million, blockchain security firms estimate.Stake confirmed that all services resumed at 9:28pm UTC time on Sept. 4 — ...

Crypto gambling site Stake sees $16M withdrawals in possible hack

Crypto gambling site Stake has experienced $16 million in withdrawals on Sept. 4 in what security platform Cyvers Alerts is calling “suspicious transactions.” The withdrawing account has been labeled “Stake.com Hacker” by Etherscan, implying that the drained funds may be t ...

South Korea plans to submit bill to freeze North’s crypto assets: Report

The government of South Korea is reportedly planning to submit a bill that will track and freeze North Korean crypto and virtual assets that are used to fund its capital Pyongyang's illicit weapons program. According to a report by local media outlet JoongAng Daily, multiple anonymous ...

Exploits, hacks and scams stole almost $1B in 2023: Report

Malicious actors targeting the crypto space have taken more than $45 million in digital assets from their victims in the month of August alone and a total of $997 million year-to-date (YTD), according to a report shared by the blockchain security firm CertiK. Within the report, CertiK ...

$16M in crypto lost to hacks in August — Report

A total of $15.8 million in cryptocurrencies were lost to hacks or exploits in the month of August.According to an Aug. 31 report by blockchain security firm Immunfi, a combined $23.4 million in crypto was lost to a combination of hacks and fraud, a significant decrease compared to the $32 ...

No, Bitcoin withdraws from exchanges is not inherently bullish for crypto

Crypto analysts on X (the social media platform formerly known as Twitter) and YouTube interviews have been abuzz with talk about the trend of Bitcoin leaving centralized exchanges.On Aug. 29, the quantity of Bitcoin (BTC) held within exchanges saw a decline, reaching its lowest point sinc ...

Base project RocketSwap shares emergency plan following $865K exploit

Base project RocketSwap Labs has outlined its emergency program to bounce back from a brute force hack that swiped $865,000 or 471 Ether (ETH) from the protocol on Aug. 14.The team explained on Aug. 15 that they plan on redeploying a new farm contract and open-source it on-chain, reli ...

Weekend Wrap: Uniswap dev sacked for alleged rug, Steadefi hacker goes mixing and more

Uniswap dev loses job, was it worth it? A Uniswap developer known as “AzFlin” has been sacked by the founder of Uniswap Labs, Hayden Adams, for allegedly creating a memecoin and rug pulling it a few hours later for 14 wrapped-Ether (wETH), worth $25,800. It is understood ...

Zunami Protocol confirms stablecoin pools attacked, $2.1M loss estimated

Decentralized finance protocol Zunami Protocol has advised users not to buy any of its Zunami Ether (zETH) or Zunami USD (UZD) stablecoins, after encountering an attack on its "zStables" pools on Curve Finance. On Aug. 13,  Zunami confirmed on X (Twitter) that its stablecoin pool ...

DeFi tries to recover from Curve hack, but exploits continue: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The DeFi ecosystem is yet to recover from the crisis brought on by the Curve Finance hack, and even tho ...

Victim of 90 ETH exploit set to claw funds back after hacker was blacklisted

With the help of police and cyber authorities, a victim of a hack worth 90 Ether (ETH) has gotten the attacker’s Tether (USDT) address blacklisted. As a result, they may be able to get most of their funds back. [2023/08/11 17:30] ...

Only 6 out of 45 crypto wallet brands have undergone penetration testing: Report

A July report from cybersecurity certification platform CER found that only six of 45 cryptocurrency wallet brands, or 13.3%, have undergone penetration testing to find security vulnerabilities. Of these, only half have performed tests on the latest versions of their products.The three bra ...

Aave’s Earning Farm protocol targeted by reentrancy attack — PeckShield

Blockchain security firm PeckShield revealed fresh vulnerabilities targeting decentralized finance (DeFi) projects on Aug. 9. According to the firm, Aave’s Earning Farm has been compromised by a reentrancy attack, resulting in the theft of at least $287,000 worth of Ether (ETH). ...

Blockchain Capital’s X account hacked to promote token claim scam

The X (Twitter) account of crypto-focused venture capital firm Blockchain Capital was seemingly taken over by scammers attempting to lure users with the promise of a token claim.On Aug. 9, Blockchain Capital’s account made multiple posts promising a giveaway of “BCAP” tokens and directed u ...

Cypher Protocol freezes smart contract after an estimated $1M exploit

Solana-based decentralized futures exchange Cypher Protocol halted its smart contract after an estimated $1 million exploit.On Aug. 7, Cypher alerted its 13,500 followers on X (formerly known as Twitter) that it had experienced a security incident and had therefore frozen its smart contrac ...

CoinsPaid claims North Korean hacking group used fake job interview to steal $37M

Estonia-based cryptocurrency payments firm CoinsPaid suspects North Korean hackers with the Lazarus Group gained access to its systems through fake recruiters targeting employees.In an Aug. 7 blog post, CoinsPaid said an exploit which allowed hackers to steal more than $37 million on July ...

Nifty News: Trader nabs 800 ETH by baiting a bot, NFT thefts slow and more

NFT trader's $1.5M bot chess moveYouTuber and nonfungible token (NFT) trader Hanwe Chang said he scored 800 Ether (ETH), around $1.5 million, by tricking a rival trader’s bot into buying his own inflated NFTs.In an Aug. 5 X (Twitter) post, Chang said he noticed a bot was ...

Curve Finance opens bounty after exploiter’s return deadline expires

Decentralized finance (DeFi) protocol Curve Finance is extending a bug bounty offer to anyone who is able to identify the exploiter responsible for draining over $61 million from its pools on July 30. Curve and other protocols affected by the attack offered a 10% bug bounty to the hac ...

Alchemix reports return of all stolen funds from Curve pools

Lending platform Alchemix has announced the return of all stolen funds by the Curve finance hacker. The attack took place on July 30 and resulted in over $61 million in cryptocurrencies drained, including $13.6 million from Alchemix’s alETH-ETH pool. Along with Alchemix, JPEGd&r ...

JPEG’d confirms return of 5,495 ETH from Curve hacker

Nonfungible token finance (NFT-Fi) protocol JPEG’d has confirmed that 5,495 Ether (ETH), worth roughly $10 million at current prices, has been returned by the Curve Finance hacker. In exchange for returning the funds that were stolen on July 30, the hacker received a 610.6 ETH ($1.1 ...

Curve-Vyper exploit: The whole story so far

The decentralized finance (DeFi) ecosystem has experienced a challenging week after a seismic security incident led to over $61 million being stolen from Curve Finance’s pools, leaving several protocols facing broader contagion risks.This attack exposed vulnerabilities across DeFi pr ...

CRV exposure risk throws a curveball at the DeFi ecosystem: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The $47 million Curve Finance exploit on July 30 had a domino effect on the DeFi ecosystem, mainly due ...

Curve, Metronome and Alchemix offering 10% bug bounty on Vyper hack

Decentralized finance (DeFi) platforms Curve, Metronome and Alchemix have jointly announced an initiative to recover stolen funds from the recent exploits of Curve’s pools.According to on-chain data, the protocols are offering a 10% bounty of the stolen funds as a reward, urging thos ...

Curve emergency DAO terminates rewards for hack-related pools

The Curve Finance lending protocol has terminated governance token rewards for select liquidity pools affected by the July 30 Curve exploit and July 6 Multichain exploit, according to an Aug. 2 social media post from a member of the protocol’s governing body. The ending of rewar ...

Binance’s CZ warns crypto community about emerging scam

Binance CEO Changpeng 'CZ' Zhao warned his followers on X about a tricky and increasingly popular scam targeting the crypto community, in which fake wallet addresses are used to defraud users during transactions.The scheme generates addresses with the same starting and ending characters as ...

Base’s largest DEX LeetSwap halts trading amid exploit concerns

Decentralized exchange LeetSwap, which operates on Coinbase’s Base network has announced a pause on trading, citing concerns of a potential exploit.LeetSwap tweeted on Aug. 1 that it noticed some of its liquidity pools may have been compromised and temporarily stopped trading to inve ...

Crypto market loses $486M in July, most since 2022: Report

The cryptocurrency market is having its worst month of 2023, according to a report from Web3 outlet De.Fi shared with Cointelegraph. Losses for July totaled $486 million, more than six times the total from 2022:Cryptocurrency losses comparing July 2022 and July 2023. Source: De.FiTh ...

Ethereum logs $1M MEV block reward amid Curve Finance exploit

The recent Curve Finance exploit has reportedly led to one of the largest ever maximal extractable value (MEV) reward blocks of 584.05 Ether (ETH). On July 31, Ethereum core developer “eric.eth” reported that “today has produced some of the largest MEV reward blocks ...

BNB Smart Chain hit with copycat Vyper attack, $73K exploited

The BNB Smart Chain (BSC) has reportedly suffered copycat attacks due to a vulnerability in the Vyper programming language, following a similar vein to the exploit on the decentralized finance (DeFi) protocol Curve Finance.Amid the exploits carried out on Ethereum, Blockchain security firm ...

Vyper vulnerability exposes DeFi ecosystem to stress tests

Decentralized finance (DeFi) protocols are undergoing a stress test following a critical vulnerability was found on versions of Vyper programming language, resulting in the theft of millions of dollars worth of cryptocurrencies on July 30.A number of pools using Vyper 0.2.15, 0.2.16 and 0. ...

Curve Finance pools exploited in over $24M due to reentrancy vulnerability

Several stable pools on Curve Finance using Vyper were exploited on July 30, with losses reaching $24 million at the time of writing. According to Vyper, its 0.2.15, 0.2.16 and 0.3.0 versions are vulnerable to malfunctioning reentrancy locks. "The investigation is ongoing but any proj ...

Another week of DeFi hacks, but ZK-proof development heats up: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The past week in DeFi was dominated by exploits and hacks, with three DeFi platforms losing nearly $39 ...

Pro-XRP lawyer Jeremy Hogan’s scam tweet bonanza finally falls silent

The recent flood of scam tweets on pro-XRP lawyer Jeremy Hogan’s hacked account has finally dried up after nearly four days.Since July 24, the XRP community has been diligently warning others and tagging Twitter’s support after they noticed Hogan’s account tweeting malici ...

Redditor’s hacked Bitcoin is a lesson on the hidden dangers of paper wallets

A Reddit user has become the latest example of why crypto users should be more careful when using wallet generators — after the user lost a few thousand dollars worth of Bitcoin (BTC) from their "secure" paper wallet.On July 24, a Redditor by the name /jdmcnair posted on th ...

Crypto payment gateway CoinsPaid suspects Lazarus Group in $37M hack

Cryptocurrency payments platform CoinsPaid has pointed the finger at North Korean state-backed Lazarus Group as being behind the hacking of its internal systems, which allowed them to steal $37.3 million on July 22.“We suspect Lazarus Group, one of the most powerful hacker organisati ...

Era Lend on zkSync exploited for $3.4M in reentrancy attack

Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process ...

Connext, Alchemix launch cross-chain token standard to reduce bridge exploit losses

The Connext cross-chain bridging protocol has announced a new token standard to reduce losses from bridge hacks. According to a July 24 announcement, the new “xERC-20” standard allows token issuers to maintain a list of official bridges and control how many tokens can be minted by eac ...

Alphapo hot wallets hacked for over $31 million

Crypto payment platform Alphapo had at least $31 million drained from its hot wallets on Ether (ETH), TRON (TRX), and Bitcoin (BTC), security experts reported on July 22. Since the number of Bitcoins stolen is uncertain, the figures may be even higher. According to on-chain sleuth Zac ...

How easy is a SIM swap hack and how does one guard against it?

Despite the rise of cybersecurity infrastructure, the online identity still faces many risks, including those related to the hacks of one’s phone numbers.In early July, LayerZero CEO Bryan Pellegrino became one of the latest victims of a SIM swap attack, which allowed hackers to brie ...

‘Multichain was a big blow’, says Andre Cronje as Fantom TVL slumps

Fantom's co-founder Andre Cronje classified Multichain's debacle as a "big blow" to the smart contract platform, which saw a sharp decline in activity in the past weeks as a result of Multichain's problems. According to data from DefiLlama, Fantom's total value locked (TVL) dropped fr ...

Crypto lender Geist Finance shuts down permanently over Multichain hack

Lending protocol Geist Finance is shutting down permanently due to losses from the Multichain exploit, according to a July 14 social media post from the app’s development team. Geist contracts were paused on July 6, then resumed in “withdraw and repay only” mode on July 9. The l ...

USB keystroke injectors still a threat to crypto users

The Diabolic Drive’s name sounds as ominous as its potential payload. The recently developed USB wireless keystroke injection tool is intended to stress test networks, but could it potentially be used as a means to steal cryptocurrency from unwitting users?The new gadget is set to be ...

Crypto scams are down 77% — but this exploit is making a huge comeback

Cryptocurrency scams have fallen a massive 77% from $3.3 billion to $1.1 billion over the first six months of 2023, according to a recent report by blockchain intelligence firm Chainalysis.The catch, though, is that ransom attacks are back in trend, with perpetrators pocketing 62.4% more r ...

New York prosecutor charges hacker over $9M exploit of Solana-based exchange

A former security engineer for an international technology firm has been arrested and charged for allegedly using a smart contract bug to steal $9 million in cryptocurrency from a Solana-based decentralized crypto exchange.On June 11, the United States Attorney for the Southern District of ...

Bug bounties can help secure blockchain networks, but have mixed results

Bug bounties are programs organizations offer to incentivize security researchers or ethical or white hat hackers to find and report vulnerabilities in their software, websites or systems. Bug bounties aim to improve overall security by identifying and fixing potential weaknesses before malicious ...

Multichain’s ‘mysterious withdrawals’ have whiffs of a ‘rug pull’ — Chainalysis

The multi-million dollar exploit of cross-chain bridge protocol Multichain could have been an internal rug pull, according to blockchain security and analytics firm Chainalysis.“On July 6, 2023, cross-chain bridge protocol Multichain experienced unusually large, unauthorized withdraw ...

Pink, Pussy, Venom, Inferno — Drainers coming for a crypto wallet near you

Four major crypto drainers have emerged to fill the vacuum left by the notorious wallet sweeper Monkey Drainer, with thousands of victims targeted and millions in crypto stolen already this year. The crypto drainers — called Pink Drainer, Inferno Drainer, Pussy Drainer, and Venom Dra ...

Gaming gear maker Razer hacked, user data, encryption keys for sale online: Report

A post appeared on a hackers’ forum on July 8 offering information allegedly hacked from gaming hardware maker Razer. “I have stolen the source code, encryption keys, database, backend access logins etc,” the hacker declared. The Straits Times said it saw a sample of ...

Multichain attack triggers Twitter phishing scheme for FTM distribution

Hackers continue their relentless attacks, displaying no signs of slowing down. Shortly after the Multichain hack, scammers started spreading a phishing link on Twitter.The fraudulent distribution of Fantom (FTM) to users — falsely linked to the Multichain attack — is rapidly s ...

Circle, Tether freezes over $65M in assets transferred from Multichain

Stablecoin issuers Circle and Tether have frozen over $65 million in assets tied to the suspected exploit of cross-chain router protocol Multichain. The move follows unexplained large outflows from the Multichain MPC bridge on July 6. According to the knowledge graph protocol 0xScope, ...

Over $765K worth of NFTs stolen after SIM swap attack on Gutter Cat Gang

More than $765,000 worth of nonfungible tokens has been stolen as part of a reported SIM swap attack on the Gutter Cat Gang NFT project.The security breach was highlighted by several NFT community members at around 8 pm UTC on July 7, with Gutter Cat Gang co-founder @GutterMitch tweeting o ...

DeFi ‘circuit breaker’ could slash hack losses by 70%: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.Amid the growing number of hacks in the DeFi ecosystem, a smart contract developer has made a new Ether ...

$30B stolen from crypto ecosystem since 2012: Report

From 2012 to the present, over $30 billion in crypto has been hacked in 1,101 documented incidents, a July 7 report from SlowMist has revealed.According to the blockchain security firm, the top five most common hacks are smart contract vulnerabilities, rug pulls, flash loan attacks, scams ...

Multichain MPC bridge sees $100M+ outflows, sparking fears of exploit

Abnormally large outflows from the Multichain MPC bridge platform are sparking fears of a multi-million dollar exploit.On July 6, observers noticed that approximately $102 million worth of crypto has been withdrawn from Multichain’s Fantom bridge on the Ethereum side, as well as $666 ...

US Homeland Security returns $314K from 2016 Bitfinex hack

Via a July 6 announcement, cryptocurrency exchange Bitfinex says it has received $312,219.71 in cash and 6.917 in Bitcoin Cash (BCH) from the United States Department of Homeland Security. The seizure was conducted in cooperation with U.S. Customs and Border Protection. According to Bitfinex staf ...

Darknet bad actors work together to steal your crypto, here’s how — Binance CSO

Lurking in the shadiest corners of the dark web is a “well-established” ecosystem of hackers that target cryptocurrency users with poor “security hygiene,” according to Binance’s chief security officer.Speaking to Cointelegraph, Binance CSO Jimmy Su said in re ...

Chibi Finance $1M alleged rug pull: How it happened

On June 26, decentralized finance (DeFi) aggregator Chibi Finance was exploited by its own deployer account, and $1 million worth of cryptocurrency was drained from its contracts in an apparent rug pull or exit scam. The protocol’s official user interface disappeared, producing a 404 error, and a ...

Poly Network urges users to withdraw after exploit affects 57 crypto assets

Further details are coming to light following a July 2 attack on cross-chain bridge platform Poly Network, which has resulted in a hacker being able to issue billions of tokens out of thin air for profit.In a July 2 Twitter post, Poly Network confirmed it became the latest DeFi exploit vic ...

Over $204M lost to DeFi hacks and scams in Q2: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.The second quarter of 2023 saw over $208 million exploited and hacked from DeFi protocols, and with jus ...

Yield Protocol declares full recovery from Euler hack, awaits user token exchange

Yield Protocol announced on June 27 that it had fully recovered from the Euler flash loan attack. Liquidity providers can now update their strategy tokens, the protocol said on Twitter. That was the last step to protocol restoration after “a long journey.”Yield Protocol was one ...

Over $204M was lost in Q2 DeFi hacks and scams: Report

Over $204 million was lost in decentralized finance (DeFi) hacks and scams in the second quarter of 2023, according to a June 27 report from Web3 portfolio app De.Fi. The report, titled “Q2 De.Fi Rekt Report,” was partially based on data from De.Fi’s “Rekt Database.” Over $208.5 million wa ...

$794K SIM swap hacker PlugwalkJoe sentenced to five years in prison

British Hacker Joseph O’Connor, also known online as PlugwalkJoe, has been sentenced to five years in U.S. prison for his role in stealing $794,000 worth of cryptocurrency via a SIM swap attack on a crypto exchange executive back in April 2019. O’Connor was initially arrested i ...

100K ChatGPT logins have been leaked on dark web, cybersecurity firm warns

Over the past year, more than 100,000 login credentials to the popular artificial intelligence chatbot ChatGPT have been leaked and traded on the dark web, according to a Singaporean cybersecurity firm.A June 20 blog post by Group-IB revealed just over 101,000 compromised logins for OpenAI ...

Atomic Wallet gives major update on hack but questions remain unanswered

Atomic Wallet users have been left wanting more answers, despite the decentralized wallet provider finally releasing a full “event statement” about the June exploit — which some estimate has run up to $100 million in losses.In a June 20, blog post — the first m ...

CZ, Powell and more rally to fund legal fees for on-chain sleuth ZachXBT, surpassing $1M

Blockchain investigator ZachXBT has received over $1 million in donations in slightly more 24 hours from the crypto community to pay for his legal fees in a defamation lawsuit.ZachXBT, known for his investigative work in the blockchain and cryptocurrency industry, has become embroiled in a ...

On-chain sleuth ZachXBT sued for libel after claiming plaintiff drained funds from project

Blockchain investigator ZachXBT has been sued for libel by one of the people he accused of fraud, according to a June 16 social media post. According to the post, Jeffrey Huang, known as “MachiBigBrother” on Twitter, has accused ZachXBT of damaging his reputation through false allegat ...

Curve pool imbalance triggers USDT depeg concerns: Finance Redefined

Welcome to Finance Redefined, your weekly dose of essential decentralized finance (DeFi) insights — a newsletter crafted to bring you the most significant developments from the past week.On June 15, an imbalance in Curve Finance’s 3pool led to a Tether (USDT) depeg scare as the stablecoin’ ...

Institutional crypto broker FPG halts withdrawals after $20M cyberattack

Cryptocurrency brokerage firm Floating Point Group (FPG) has confirmed it has halted trading, withdrawals and deposits on its platform after falling victim to a cyberattack on June 11. FPG estimates the attack resulted in a total loss of between $15 million and $20 million.According to a J ...

North Korean hackers swipe over $100M from Atomic Wallet users

Atomic Wallet, a noncustodial decentralized wallet, has been hit by a staggering exploit, leading to users reporting losses of their entire cryptocurrency portfolios. This unforeseen breach has sent shockwaves through the crypto community, as Atomic Wallet’s fundamental premise relies on us ...

Atomic Wallet hackers turn to OFAC-sanctioned Garantex: Elliptic

Illicit funds gained from the $35 million Atomic Wallet hack are on the move again, with sanctioned Russian-based crypto exchange Garantex reportedly becoming the latest to come in contact with the hacked crypto. On June 13, blockchain security and compliance firm Elliptic updated the ...

Scammers steal nearly $1M after hijacking 8+ prominent crypto twitter accounts

Over the past few weeks, a group of scammers has hijacked more than eight Twitter accounts belonging to prominent figures in the crypto space to promote phishing scams. The group has stolen almost $1 million worth of crypto so far, according to blockchain sleuth ZachXBT. In a June 9 Twitte ...

US Justice Department charges two men in Mt. Gox hack

The United States Justice Department has unsealed charges against two men it says are responsible for the $400 million hack of former Bitcoin exchange Mt. Gox. According to the announcement, 43-year-old Alexey Bilyuchenko and 29-year-old Aleksandr Verner allegedly conspired to launder 647,00 ...

Atomic Wallet hacker sends crypto to mixer used by Lazarus Group: Elliptic

Illicit funds gained from the $35 million Atomic Wallet hack have been moving to a crypto mixer known to be favored by North Korea’s most notorious cyber-hacking group.On June 5, blockchain compliance analytics firm Elliptic reported that its Investigations Team has traced funds from ...

Atomic Wallet says hack affected 1% of active users, but investors claim otherwise

A hack that drained $35 million from Atomic Wallet users since June 2 impacted less than 1% of its monthly active users, according to the company. In the aftermath of the attack, Atomic Wallet — along with individual blockchain investigators — have amped up efforts to track and revert ...

Atomic Wallet hack losses top $35M, on-chain sleuth reports

At least $35 million worth of crypto assets have been stolen from Atomic Wallet users since June 2, according to an analysis from on-chain sleuth ZachXBT. The five largest losses account for $17 million.According to Atomic Wallet on Twitter, the cause of the attack is being investigated. R ...

Atomic Wallet exploited, users report loss of entire portfolios

Atomic Wallet has been apparently exploited, with users on Twitter reporting complete losses of their crypto portfolios. Atomic is a noncustodial-decentralized wallet, meaning users are responsible for assets stored in the application. "We have received reports of wallets being compro ...

Cryptocurrency Hacks in February 2023

Cybersecurity experts from PeckShield have reported that a whopping $35.5 million worth of cryptocurrencies were stolen in February. The largest number of successful hacks, a total of 141, occurred on February 11th. As per the analysis, the biggest amount that hackers could steal from one project ...