Security

Stay informed on cybersecurity and blockchain security news, including smart contract vulnerabilities, protocol exploits, phishing attacks, wallet security, data breaches, and emerging threats. Learn about security best practices, industry responses, and developments aimed at protecting users and digital assets.
Featured only
1d ago
Bitcoin restaking platform BounceBit to phase out its L1 blockchain after exploit
Bitcoin restaking platform BounceBit said it will gradually wind down its proprietary L1 blockchain after a recent exploit. The platform’s core business centers on BTC restaking, and it said the security incident has led to the decision to end operations of the underlying public chain. The team has not disclosed details of the attack or the size of the losses, but the shutdown decision has delivered a major hit to the project’s fundamentals.
BTC
BTC+1.31%
1d ago
8-21
Maya Protocol halts operations after multi-bug exploit drains CACAO tokens and cross-chain assets
Maya Protocol has suspended all operations following a multi-vulnerability attack. The attacker exploited multiple security flaws to steal the platform’s native CACAO token and a large amount of cross-chain assets, with the specific loss amount not disclosed. As a decentralized cross-chain liquidity protocol, the incident damaged its core assets and liquidity across related pools, raising concerns about the security of cross-chain infrastructure.
BTC
BTC+1.31%
8-21
8-19
Aave TVL remains 43% lower after April 18 KelpDAO hack
Aave’s total value locked (TVL) remains down 43% since the April 18 KelpDAO hack, and is 67% below its 52-week high. Hackers deposited stolen rsETH into Aave and borrowed real ETH against it, leaving Aave and Compound with an estimated $246 million in combined bad debt. Aave’s TVL fell from $26.4 billion before the attack to $14.9 billion, tightening lending capacity and increasing volatility pressure. The AAVE token fell about 20% the day after the incident and now trades near $89, still below pre-hack levels.
AAVE
AAVE+7.92%
8-19
8-18
Bits of Gold probes breach potentially exposing data of up to 250,000 customers as Paz pauses Bitcoin buys
Israel’s largest regulated cryptocurrency broker, Bits of Gold, said a breach in a supporting data analysis system may have exposed personal information for up to 250,000 users. The potentially affected data includes names, national identity numbers, contact details, IP addresses, bank-account details and public crypto wallet addresses, while customer funds and digital assets were not compromised. Paz temporarily halted Bitcoin purchases via its Yellow convenience store app after the disclosure. Bits of Gold said the incident occurred several days earlier and it has opened an investigation.
BTC
BTC+1.31%
8-18
8-16
Stale oracle parameters trigger DeFi losses without hacks in Aave and Moonwell incidents
On March 10, 2026, Aave misconfigured its CAPO risk oracle, capping the onchain wstETH exchange rate about 2.85% below market and triggering roughly 10,938 wstETH liquidations. Liquidation volume totaled about $26–27 million, with liquidators capturing around 499–512 ETH in value. On February 15, 2026, Moonwell misconfigured a Chainlink OEV wrapper after a governance change, reporting cbETH at about $1.12 instead of roughly $2,200 and enabling the seizure of 1,096.317 cbETH. The incident left the protocol with about $1.78 million in bad debt.
ETH
ETH+2.18%
8-16
8-15
XRP Ledger–tx bridge bug lets attacker mint bridged XRP from phantom deposits, draining about 200,000 in 94 payments
A bridge connecting the XRP Ledger to the tx chain was exploited through a flaw in its deposit-detection logic. The attacker crafted transactions with no real deposits, minted bridged XRP on the tx chain, then swapped it back into real XRP. About 200,000 XRP was transferred out across 94 payments, each correctly signed by 17 of 28 relayers. Ripple’s ledger was not compromised, but txEcosystem said bridged XRP on its chain is no longer fully backed.
XRP
XRP+0.06%
8-15
8-14
Harmony Protocol confirms unauthorized ONE minting, suspends bridge services after August 12 incident
Harmony Protocol said an unauthorized ONE minting incident occurred on August 12. Initial analysis put the minting at 4000000000 ONE, but a later on-chain reconstruction found about 3010000000000 ONE was issued to four attacker wallets through six forged crossshard transactions. The team said it has fixed the crossshard receipt verification flaw and a quorum verification bug for the prestaking committee, and deployed Mainnet v2026.1.1 at 06:30 (UTC+8) on August 12. It is preparing to roll back the network to block 92,730,034 and has suspended bridge services.
ONE
ONE+0.13%
8-14
8-14
Harmony says CrossShard receipt replay bug enabled unauthorized minting, including 400 million ONE
Harmony said a CrossShard Receipt Replay bug allowed valid receipts to be processed multiple times, minting new tokens without corresponding deductions. The network initially confirmed 400 million ONE in unauthorized minting, while forged crossshard issuance totaled about 3.01 trillion ONE, with the team still verifying the data, according to Foresight News. Harmony said an emergency patch activated on August 12 fixed the issue and crosschain services have been paused. The team is coordinating with validators and exchanges on a rollback targeting block 92,730,034, with Shard 0 paused to support the operation.
ONE
ONE+0.13%
8-14
8-14
Foundation pledges full reimbursement and to restore 1:1 backing for bridged XRP as bridge stays paused
The Foundation said it will make all affected users whole and fully replenish missing $XRP reserves to restore 1:1 backing for bridged XRP, with reserves verifiable onchain. It said the vulnerability has been identified and patched. The bridge remains paused pending an independent security review and will resume only after the review is successfully completed. The Foundation said it will publish a full technical report detailing the restoration mechanism and urged users to watch for scams and rely only on official channels for updates.
XRP
XRP+0.06%
8-14
8-14
DATA Foundation extends team and lead investor token lockups by 18 months, leaving Aug. 13 unlock date without replacement
DATA Foundation has kept team and lead investor tokens locked past Aug. 13, even though that date appeared in an earlier public supply schedule, and it has not published a new unlock date. The foundation said on June 25 it extended those lockups by an additional 18 months, but did not specify when the extension starts or how it is enforced. Early Backers and Core Contributors account for 41.6% of the project’s allocation buckets, with both set to unlock over 48 months. Separate coverage also flagged a potential wider unlock wave tied to returning VC funding and noted Pump Fun plans to unlock $127M of insider tokens on July 12, about double PUMP’s recent average daily volume.
PUMP
PUMP-3.86%
8-14