A Bitcoin Bridge Bug Sat Hidden for 74 Days, Then Froze 36% of a Major Cosmos Asset
A Bitcoin bridge bug minted 40 fake nBTC undetected for 74 days, leaving Osmosis's allBTC basket only 64% collateralized when the fraud surfaced.
Confirmed hacks, exploits, incident response, fund recovery, and postmortems.
97 articles
A Bitcoin bridge bug minted 40 fake nBTC undetected for 74 days, leaving Osmosis's allBTC basket only 64% collateralized when the fraud surfaced.
Three Bitcoin hacks in seven days each broke at a different layer, exposing why no single custody method protects you from every attack.
Symbiosis recovered $1.15M in Bitcoin after a bridge exploit, but the attacker minted 46 billion fake tokens and extracted only $336,000.
A Bitcoin bridge exploit drained $336,000 by minting unbacked synthetic BTC, part of $3.68 billion in total industry bridge losses exposing cross-chain.
Bitcoin bridges have lost over $3.68 billion to exploits, including two hacks in a week, while Bitcoin itself remains completely secure.
DeFi hacks hit $1.3 billion in 2026 despite safer code, as capital consolidation turned single exploits into ecosystem-wide crises.
Smart contract audits go stale the moment they're done; continuous post-deployment monitoring now checks your live code against new exploits every single.
A logic flaw, not a stolen key, let someone drain 95% of Liquid Network's Bitcoin reserves, exposing a critical gap in federation-based sidechain security.
A Liquid Network hacker kept $47M, roughly 15% of stolen Bitcoin, with no public bounty agreement, raising questions about white-hat hacking versus.
Harmony blockchain will shut down and migrate its ONE token to Ethereum, citing state-sponsored hackers and AI attacks it can no longer afford to fight.
A single crypto bridge hack on Liquid Network drove 99% of September's first week losses, totaling $322 million from one range-proof flaw.
Stolen private keys have overtaken smart contract bugs as the top DeFi threat, with $1.3 billion lost to exploits in 2026 so far.
Fake crypto wallet repair pages are draining funds by disguising token approvals as "fixes," and disconnecting the site won't cancel the permissions.
Smart contract bugs have cost billions because immutable blockchain code can never be patched, turning every vulnerability into a permanent, exploitable.
LayerZero admitted a design flaw let a single verifier enable a $292M hack, triggering $1.4B in assets to flee to Chainlink CCIP.
A $75 million DeFi lending exploit on Cronos shows how a token with just $11,000 in daily volume can be manipulated to drain an entire protocol.
A DeFi exploit initially reported as a $9.3 million loss yielded only $246,000 in real proceeds, revealing how token valuations distort crypto hack damage.
Three DeFi exploits drained nearly $10 million in 48 hours, proving even oracle-free protocols can fall to manipulation of internal lending logic.
A Trump Digital Gold memecoin surged to $60M then crashed 95% in hours, with insider wallets pocketing $312,000 in a suspected rug pull.
Audited crypto platforms lost $3.63 billion to hacks, exposing why security audits miss 89% of attack vectors used by criminals.
AI made crypto hacks double in 2026, yet total losses fell; more attacks, smaller targets, and the human layer is now the weakest link.
Term Finance lost $8.5M in a vault exploit, with 2,843 ETH and 1.68M USDC stolen; here is what affected users should do now.
Halborn found zero bugs behind a $292 million crypto hack; now the blockchain security firm is selling its breach autopsy expertise to Wall Street banks.
A Coldcard hardware wallet flaw drained $116 million from 5,200 users in July 2026, exposing seeds with just 40 bits of entropy instead of the promised.
Maya Protocol lost $1.7M to a crypto hack, the 16th exploit in August alone, exposing why cross-chain bridges remain DeFi's most vulnerable infrastructure.
Cross-chain bridges lost $328.6 million to hackers in 2026; here is how to verify, test, and choose safer bridges before your next transfer.
One crypto whale lost nearly $50 million across two phishing attacks three years apart, as wallet compromises now outpace smart contract bugs in crypto.
Ripple caught two XRP Ledger bugs that could drain accounts without private keys, exposing why crypto's audit-after-launch model fails.
A fake Google ad drained $550,000 in crypto from one trader, exposing how phishing attacks now exploit search results to bypass blockchain security.
Crypto post-mortems haven't stopped repeat exploits; the same bugs, from weak randomness to rounding errors, keep draining millions a decade later.
North Korea's Lazarus Group is embedding fake IT workers inside crypto companies for months, stealing source code and salaries without triggering any.
A caller named "Tiffany" allegedly stole $5 million in crypto using phone calls alone, proving social engineering beats code exploits every time.
BTCPay Server blocked Lightning Network remote access after attackers stole credentials and drained multiple nodes overnight, including Foundation's.
Bybit secured a U.S. court order to trace its $1.5 billion hack, but 90% of the stolen crypto is already untraceable after moving through thousands of.
A $4.4 million BONK governance attack drained $20 million from BonkDAO's treasury by exploiting a 1% quorum, with recovery nearly impossible since no.
Crypto hacks hit $247 million in July 2026, with a Coldcard hardware wallet exploit proving cold storage alone cannot protect your Bitcoin.
A $50 million smart contract exploit drained NFTs and crypto from Metaverse Tycoon, crashing its token 70% and exposing a critical blockchain gaming.
A five-year-old Coldcard firmware bug let attackers brute-force Bitcoin private keys remotely, stealing $116 million from over 5,200 wallets without.
The Verus Ethereum bridge was hacked twice in two months, losing $7.54 million, exposing how DeFi credential theft now rivals code exploits as a top.
Crypto hackers stole $97 million in July by targeting keys and governance systems, not code, leaving even fully audited protocols dangerously exposed.
Most crypto exchange hacks exploit humans, not code; leaked keys, social engineering, and unpatched systems cause far more losses than blockchain.
A fake job offer on Telegram let hackers steal $24.15 million from AFX Trade by compromising validators, not code; a user goodwill plan is due August 3.
Wanchain has given the NIGHT token hacker until August 6 to return 90% of stolen funds, offering a 10% bounty to avoid legal action.
Crypto hacks surged 50% in H1 2026, with the biggest losses bypassing audits entirely by targeting keys, signers, and cloud infrastructure instead of code.
North Korea's own elite crypto hackers turned against the regime, stealing state funds, exposing how $6 billion in cryptocurrency theft created an.
DeFi bridges lost $47 million in one week while their blockchains stayed safe, exposing a critical flaw in how crypto networks connect.
Justin Sun lost his entire $30 million World Liberty Financial investment to alleged fraud, proving even crypto billionaires can't escape the industry's.
Binance runs monthly phishing simulations on staff, with repeated failures risking termination, as social engineering now drives 65% of its security.
Attackers minted $5.23 million in unauthorized WEMIX$ stablecoin by hijacking its contract, crashing the token 99% and forcing WEMIX to halt all bridges.
Garden Finance and WEMIX lost a combined $6.7 million in crypto hacks hours apart, exposing how attackers now target infrastructure, not just code.