Security

Stay informed on cybersecurity and blockchain security news, including smart contract vulnerabilities, protocol exploits, phishing attacks, wallet security, data breaches, and emerging threats. Learn about security best practices, industry responses, and developments aimed at protecting users and digital assets.
صرف نمایاں
2 دن پہلے
Three blockchains halted in four days as emergency actions exposed limits of rollbacks and cross-chain recovery
Several blockchain networks recently faced price-manipulation attacks involving tokens such as TONIC, leading to emergency halts and, in one case, a chain rollback. TRM Labs estimated roughly $75 million was improperly borrowed, with about $6 million bridged to Ethereum and around $68.7 million reversed on Cronos. Bitquery reported net outflows of about $8.3 million on Ethereum and the discarding of 10,961 blocks, while project teams said they fully recovered 531,600 bnUSD and 1.366 million SODA and retrieved 82,430 USDC. Officials said user assets were not affected, but the incidents highlighted the limits of network halts once funds move across chains or into custodial venues.
ETH
ETH+5.00%
2 دن پہلے
8-30
Outdated Rain contract flaw drains $1.1 MILLION from Solana card programs; AVICI drops 49%
In August 2026, multiple Solana card programs were hit by a hack tied to a Rain contract vulnerability, with total losses of $1.1 million. Avici was the hardest hit, with 1,685 users losing $500,800. The attacker swapped the stolen stablecoins for SOL, bridged the funds to Ethereum, and routed them through Tornado Cash. Avici said self-custodial wallets were not affected and that all compromised card balances will be fully refunded.
SOL
SOL+3.56%
8-30
8-29
Raincards-linked neobank hack moves $1M USDC from Solana to Ethereum via deBridge, laundered through TornadoCash
Raincards infrastructure is suspected of being involved in an attack that drained funds from multiple neobanks and their users. The exploiter bridged $1M USDC from Solana to Ethereum via deBridge and laundered the funds using TornadoCash. Affected services include etherfi Cash, Avalanche Card and Solayer Pay, with users also reporting drained balances. The post said Circle had more than two hours to freeze the funds but did not act, and urged users to withdraw funds from impacted neobanks as soon as possible.
ETH
ETH+5.00%
8-29
8-29
Avici exploit attacker used $190 in bridged USDC to siphon about $670K, with 8,857 transactions since 16:49 UTC
Avici confirmed it was hit by an authorization-bypass exploit, with the attacker stealing about $670K. On-chain data show the attacker created a wallet at 13:40 UTC and bridged in $190 of USDC from Ethereum to cover gas. Draining began at 16:49 UTC and has continued, with 8,857 transactions executed by submitting a signature bundle, calling AddCollateralAdmin to gain admin privileges, and then withdrawing. The data indicate a verification flaw in which the second signature check pointed back to instruction 0, and the protocol’s upgrade key has not been used since March 2025.
ETH
ETH+5.00%
8-29
8-27
Cosmos Labs discloses ongoing security flaw in shared EVM module and urges affected networks to halt
Cosmos Labs has publicly disclosed an ongoing security vulnerability in its shared EVM module and formally advised related networks to pause operations to prevent potential risks from escalating. The flaw could affect EVM-compatibility components across the Cosmos ecosystem, with potential knock-on effects for associated assets including ATOM and VIRTUAL. Cosmos Labs has not yet detailed the scope of impact or provided a remediation timeline.
ATOM
ATOM+1.33%
8-27
8-26
Ledger fixes critical Ethereum app flaw in v1.22.2 affecting ETH transaction signing
A critical vulnerability has been found in the Ethereum app on Ledger hardware wallets that could let a malicious application change ETH transaction details during signing without the altered information appearing on the device screen. The issue affects users managing ETH and Ethereum-related assets on Ledger and could result in transfers being approved without their knowledge. Ledger said the flaw is fixed in Ethereum app v1.22.2 and urged users to update the app, Ledger Live and device firmware, and to avoid signing transactions until all updates are completed.
ETH
ETH+5.00%
8-26