MEV bot intercepts $7.8M in rsETH after Safe module exploit
A flawed authorized helper module let an attacker extract about 2,900 rsETH before an MEV bot copied the transaction and took the funds.
Crypto security incidents, investigations, wallet risks and recovery updates, distinguishing confirmed findings from allegations.
A flawed authorized helper module let an attacker extract about 2,900 rsETH before an MEV bot copied the transaction and took the funds.
Symbiosis says it recovered about 15 BTC after an unauthorized syBTC mint, while its native Bitcoin bridge and compensation plan remain unresolved.
Blockstream says it will not pay a 10% bounty demanded for Bitcoin still held after the Liquid Network exploit and will pursue recovery with investigators.
A cross-organization SSO authorization flaw let an attacker use legitimate email infrastructure to target Trezor subscribers with a fake wallet warning.
New reporting separates funds transferred off Cronos from roughly $111.2 million reversed after the August 30 Tectonic lending exploit.
Jaredfromsubway.eth, one of Ethereum’s most active sandwich attack bots, was drained for more than $7.5 million.
A New York judge has delayed a decision on Aave’s request to unfreeze $71 million in ETH linked to the Kelp DAO exploit. The court wants more legal clarification before moving forward with the case. Meanwhile, recovery efforts for affected rsETH users continue across the DeFi ecosystem.
CoinDCX is investing $11 million to combat crypto fraud after its founders were cleared in an impersonation-related case. The exchange plans to address phishing and fake websites through a new Digital Suraksha Network. The move highlights rising concerns around user safety as India’s crypto market continues to grow.
Solv Protocol lost about $2.7 million after a smart contract exploit allowed an attacker to mint tokens and swap them for Bitcoin-pegged assets. The platform has offered a 10% bounty to recover the funds and says affected users will be reimbursed. Security firms are now investigating the breach.
Uniswap’s founder is warning users after a victim lost a six-figure portfolio to a fake search ad posing as the protocol. Sponsored phishing links remain a major threat as crypto scam losses climb again. Users connecting wallets through search results face heightened risk.
Figure Technology confirmed a data breach after a social-engineering attack, with hackers publishing customer data online. While crypto phishing losses have declined overall, sensitive personal data remains a prime target. The incident lands as Figure expands its public-market presence and tokenized equity ambitions.
Matcha Meta users were urged to revoke approvals after a SwapNet contract exploit drained up to $16.8 million on Base, with security firms tracing the attack to a smart-contract flaw that allowed approved funds to be transferred, highlighting ongoing DeFi risks that are increasingly being exposed with the help of AI tools.
Ilya Lichtenstein, who carried out the 2016 Bitfinex Bitcoin hack, has been released early under the First Step Act after serving just over a year of a five-year sentence. His release comes as Donald Trump signals renewed scrutiny of crypto-related prosecutions, reopening debate around punishment, reform, and accountability in the crypto era.
A trader claims to have earned $1 million by exploiting abnormal trading behavior in a low-liquidity BNB Chain memecoin on Binance. While the exchange denies any security breach, the incident highlights how unusual order flow and memecoin-driven volatility continue to create sharp — and risky — trading opportunities.
Trust Wallet will reimburse about $7M lost in a Christmas Day browser extension exploit that was quietly prepared weeks in advance. Investigators say the attack may point to insider access, raising fresh concerns around wallet software security and update controls.
A crypto user lost nearly $50M in USDT after copying a poisoned wallet address from transaction history. The incident highlights how address spoofing scams exploit habit and speed, not technical flaws.
Former Mt. Gox CEO Mark Karpelès used Claude AI to audit the exchange’s 2011 code, revealing severe security flaws that contributed to its early hacks. While AI could have flagged vulnerabilities, human oversight failures were central to the collapse — a lesson that still echoes in today’s crypto landscape.
Unity Technologies has fixed a major Android security flaw that could have exposed crypto users through Unity-built apps. While no exploits were detected, both Unity and Microsoft urged developers to rebuild their games with the updated engine to ensure user safety.