FreshRSS

πŸ”’
❌ About FreshRSS
There are new articles available, click to refresh the page.
☐ β˜† βœ‡ Web3 is going just great

Blockstream pauses Liquid Network after attackers claiming to be whitehats take 4,000 BTC (~$320 million)

By: Molly White β€”
A navy blue circle with a turquoise wave inside it

An unauthorized withdrawal of 3,998.5 BTC (~$320 million) from the Liquid Network, a bitcoin sidechain, prompted a network halt. By disabling nodes that bridge between Liquid and the bitcoin mainchain, attackers are limited in their ability to cash out via bridge. Blockstream, the developers of Liquid Network, also said they had contacted exchanges to ask them to pause LBTC deposits and withdrawals, cutting off another avenue.

The unauthorized transaction included a message reading "we are whitehats. contact us on chain", suggesting the possibility that the withdrawal was in fact well-intentioned security researchers aiming to "rescue" funds after discovering they were vulnerable and then return them to a secure wallet. However, as of the afternoon on September 6, Blockstream had only said that they were "working on contacting" the "purported white-hat hackers".

☐ β˜† βœ‡ Web3 is going just great

More Markets exploited for $9.3 million

By: Molly White β€”
An orange jellyfish symbol, followed by "More" in black capitals

Defi lending project More Markets lost $9.3 million after an attacker was able to trick the lending protocol logic and empty the project's reserve. The attack was noticed by blockchain security researchers at Blockaid; More Labs later announced they were investigating. Oddly, while acknowledging that funds had been stolen, they wrote, "Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused." They claimed that only 5% of the assets were bridged out of the Flow blockchain, though did not explain how they planned to prevent the attacker from moving more tokens or collapsing the token price entirely.

☐ β˜† βœ‡ Web3 is going just great

Crypto.com-affiliated Cronos blockchain halted after Tectonic theft

By: Molly White β€”
"cronos" in black lowercase

The ostensibly decentralized Cronos blockchain was halted after a price manipulation attack allowed an attacker to borrow more than $75 million against nearly worthless collateral from the Tectonic lending platform. The attacker pumped the price of the thinly traded TONIC token, the native token of Tectonic, then borrowed against it. The attacker cashed out approximately $6 million by bridging it to Ethereum before the Cronos chain was halted, limiting their profits. The blockchain was offline for almost 24 hours, during which time it was rolled back to a block prior to the hack β€” essentially undoing all the transactions that occurred after that block.

Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain β€” though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.

☐ β˜† βœ‡ Web3 is going just great

Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks

By: Molly White β€”
"rain" in stylized pink letters

A vulnerability in a smart contract belonging to Rain, a crypto payments infrastructure provider, resulted in $1.1 million in losses to various firms. Customers of the Avici cryptocurrency neobank, which offers a Visa credit card through which customers can spend crypto, suffered roughly $500,000 in losses. Customers of another neobank, Tria, lost more than $430,000.

The losses are somewhat unusual because the neobanks describe themselves as self-custodial, which normally means that customers have total control over their crypto assets rather than storing them on a third-party platform. Normally, self-custody is more resilient to exploits like this, given that assets remain in user wallets. However, because these neobanks require customers to load funds they want to be able to spend into a third-party contract, they were vulnerable to the theft.

☐ β˜† βœ‡ Web3 is going just great

$1.76 million stolen from MAYAChain in attack exploiting six bugs

By: Molly White β€”
A wavy blue-green M shape followed by "Maya" in white

The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.

☐ β˜† βœ‡ Web3 is going just great

KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure

By: Molly White β€”
An illustration of an atom, followed by "Cosmos" in black capitals, with a slash through the O

Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."

KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.

☐ β˜† βœ‡ Web3 is going just great

BounceBit exploited for $3 million, announces shutdown and migration

By: Molly White β€”
An X symbol with dots above and below, followed by BounceBit in black

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

☐ β˜† βœ‡ Web3 is going just great

Moonwell loses $8.7 million to fourth exploit in less than a year

By: Molly White β€”
Two grey crescents facing each other on a blue background

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

☐ β˜† βœ‡ Web3 is going just great

Term Finance loses $8.5 million to governance attack

By: Molly White β€”
A blue square with a T cut out, followed by "Term" in blue caps

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token β€” which was not widely held β€” and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

☐ β˜† βœ‡ Web3 is going just great

Ravencoin rolls back blockchain after exploit

By: Molly White β€”
A blue, yellow, and orange raven formed out of triangles, followed by "Ravencoin" in navy capitals

Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.

Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.

☐ β˜† βœ‡ Web3 is going just great

Harmony token plunges 40% after unauthorized mint

By: Molly White β€”
A rounded H formed out of a swirly white line, followed by the text "Harmony" in white

An attacker was able to exploit the Harmony blockchain to mint 4 billion of the network's $ONE token. The massive increase in token supply caused the token price to plunge 40%.

Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback β€” that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.

This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North Korean hacking groups.

☐ β˜† βœ‡ Web3 is going just great

Triple-A hacked for $11.8 million

By: Molly White β€”
"Triple-A." in black, with the dot over the i, the hyphen, and the period in orange to pink gradient

Singapore-based stablecoin payments company Triple-A confirmed that an attacker stole $11.8 million in company funds from its treasury wallets. The company briefly took some services offline while they investigated the hack.

Triple-A did not say how much was taken or how the wallets were compromised, and said the impact was limited to "specific operational accounts" and able to be covered by treasury reserves. Blockchain analyst Specter estimated the loss at $11.8 million, stolen across the bitcoin and Tron networks.

☐ β˜† βœ‡ Web3 is going just great

Two arrested after Flare Network staking site scammed users out of 3.4 million XRP (~$8.5 million)

By: Molly White β€”

South Korean police say scammers running a fake staking website under the name of the real Flare Network took 3.4 million XRP (~$8.5 million) from 71 investors. It's possible the scammers stole closer to $19 million. Victims were promised guaranteed returns of 1.5% to 1.8% a month; the site was only live for about a week in October 2025 before the operators disappeared with the deposits.

Two men were arrested on fraud charges, and Korean police are seeking a third. They reportedly advertised the scam project via YouTube and online articles.

☐ β˜† βœ‡ Web3 is going just great

Poolin bitcoin mining pool operator files for bankruptcy

By: Molly White β€”
Two overlapping squares, one navy and one turquoise. The text "Poolin", with "Pool" in black and "in" in turquoise.

Poolin Technology, once among the largest bitcoin mining pools in the world, has filed for bankruptcy, listing more than $100 million in debts against less than $10 million in assets.

The largest liability by far is the $163.7 million owed to roughly 11,700 people who had money in Poolin Wallet when the company froze withdrawals in September 2022, citing "some liquidity issues" during that year's crash. Instead of returning their bitcoin, Poolin handed them IOU tokens, which it never redeemed.

Poolin was founded in Beijing in 2017 and in better days accounted for almost a fifth of the bitcoin network's hashrate.

☐ β˜† βœ‡ Web3 is going just great

MVMT Labs files for bankruptcy

By: Molly White β€”
Three overlapping polygons, followed by "Movement" in black

MVMT Labs, the company behind the Movement blockchain, has filed for bankruptcy, reporting assets of between $100,001 and $500,000 against liabilities of between $1 million and $10 million. The largest unsecured claim, at more than $1.6 million, belongs to co-founder Rushi Manche β€” whom the company fired in May 2025 after an investigation into the MOVE token launch.

Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.

The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.

☐ β˜† βœ‡ Web3 is going just great

Proof of Attendance Protocol (POAP) shuts down

By: Molly White β€”
"POAP" in purple text, with a diamond-shaped O, inside a circular medal-with-ribbon shape with wavy edges

Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.

The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.

Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."

☐ β˜† βœ‡ Web3 is going just great

Step App "move-to-earn" project shuts down

By: Molly White β€”
"Step App" in black italic caps with a sneaker between the words

Step App, one of the last surviving "move-to-earn" projects from the 2022 crypto fitness fad, announced it will shut down all services on August 21. The project advertised itself as a "fitness app that pays you", and was essentially a step counter that paid crypto rewards. Users had to first buy the Step App's FITFI token to purchase an NFT representing sneakers, then were rewarded with the project's KCAL tokens for each minute they spent moving β€” although the number of minutes that would generate rewards were capped, often at just a few minutes, and required more NFTs to increase.

Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 β€” far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.

☐ β˜† βœ‡ Web3 is going just great

Coinsbuy exploited for $8 milllion

By: Molly White β€”
"Coinsbuy", with a dot above and below the i

The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.

Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.

☐ β˜† βœ‡ Web3 is going just great

Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets

By: Molly White β€”
"Coldcard" in boxy red type

Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.

An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.

Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".

☐ β˜† βœ‡ Web3 is going just great

Wanchain bridge on Cardano exploited for more than $9 million

By: Molly White β€”
A hexagon shape with a ^ in the middle, followed by "wanchain"

An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.

☐ β˜† βœ‡ Web3 is going just great

42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft

By: Molly White β€”
A black sphere shape with "42" on it in white, surrounded by green orbits

Balance Coin, a small algorithmic stablecoin built on BNB Chain, lost its dollar peg and crashed to fractions of a cent after an attacker successfully exploited a flaw in its pricing logic. The attacker was able to trick the system into accepting an incorrectly low bitcoin price, which they then used to drain multiple vaults used by the project's lending protocol.

The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.

☐ β˜† βœ‡ Web3 is going just great

Across Protocol exploited for $3.35 million

By: Molly White β€”
Four cyan lines in an X shape, followed by "Across" in cyan capitals

The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.

☐ β˜† βœ‡ Web3 is going just great

Allbridge exploited for $1.66 million

By: Molly White β€”
A rounded bq image, with () on either side, followed by "Allbridge" in black

The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.

☐ β˜† βœ‡ Web3 is going just great

Summer Finance exploited for $6 million, shuts down

By: Molly White β€”
"summer.fi" in lowercase pink to purple gradient

Summer Finance, a defi platform that provides "institutional defi vault infrastructure", was exploited for $6 million in an apparent flash loan attack. The attacker used a flash loan to deposit $64.8 million and then withdraw $70.9 million, taking advantage of a price manipulation bug that allowed them to withdraw more than they deposited.

Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."

☐ β˜† βœ‡ Web3 is going just great

Bonzo Lend exploited for $9 million in oracle attack

By: Molly White β€”
"Bonzo" in rounded black lowercase

The Hedera-based decentralized lending platform Bozno Lend was exploited for just over $9 million after an attacker took advantage of a flaw in the project's oracle system. The attacker was able to deposit tokens worth only a few dollars, then manipulate the project's oracle to reflect a dramatically higher price. They then borrowed $6.63 million in USDC and 34.5 million wrapped HBAR (~$2.4 million).

Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.

☐ β˜† βœ‡ Web3 is going just great

Ostium loses at least $24 million to oracle exploit

By: Molly White β€”
A circle overlaid with ][ symbols, followed by "Ostium" in orange capitals

Decentralized perpetual futures exchange Ostium was drained of at least $24 million after an attacker manipulated its oracle system β€” a system that pulls in off-chain price data. After the attacker apparently gained access to the private key used to sign oracle messages, they were able to submit future-dated oracle reports that tricked the system into thinking trades were profitable.

The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.

☐ β˜† βœ‡ Web3 is going just great

Dutch Knaken crypto platform collapses with $8 million in customer funds missing

By: Molly White β€”
"Knaken" in black capitals, with the A surrounded by a blue hexagon

The Dutch cryptocurrency platform Knaken (not to be confused with the American Kraken platform) abruptly went offline in early June, leaving roughly 30,000 customers unable to access their funds. The company was unable to secure a license under the EU's MiCA regulations, which it said forced them to shut down. Though they claimed to be winding down the company in an orderly fashion, they reportedly stopped paying customer withdrawals, and asked customers to stop filing claims.

Dutch prosecutors asked courts to declare the platform bankrupt and install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers, who are missing around €7 million (~$8 million). The request was approved. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.

☐ β˜† βœ‡ Web3 is going just great

Polymarket customers lose $2.97 million, company blames third-party vendor

By: Molly White β€”
A parallelogram created from three triangles, followed by Polymarket in black

Polymarket customers have lost around $2.97 million to an attacker who then swapped stolen Polymarket USD (pUSD) to ETH.

Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.

☐ β˜† βœ‡ Web3 is going just great

Users of the SecondFi Cardano wallet lose $2.4 million in series of hacks

By: Molly White β€”
Two overlapping semi-transparent turquoise and blue rounded parallelograms, followed by "SecondFi" in white

Users of the Cardano wallet SecondFi (formerly Yoroi) have lost a cumulative 16 million ADA (~$2.4 million) across three attacks targeting a vulnerability in the project's wallet generation code.

After the attacks commenced, SecondFi "rescued" another 129 million ADA (~$19.4 million) by moving the assets to a third party entity. They announced that an external accounting firm would verify the funds and process user claims.

About a month after the hack, SecondFi announced it would shut down operations.

☐ β˜† βœ‡ Web3 is going just great

Highly active MEV bot known as jaredfromsubway.eth drained for $7.7 million

By: Molly White β€”

On blockchains like Ethereum, a strategy known as "MEV" (short for "maximal extractable value") allows intermediaries to profit from manipulating the structure of blocks added to the chain β€” often reordering or "sandwiching" transactions in ways that extract profits. Automated software known as MEV bots make a business out of this strategy, and one of the most active is a bot called jaredfromsubway.eth β€” likely so named after one-time Subway spokesman and convicted sex offender Jared Fogle because of its strategy of "sandwiching" transactions by placing trades on both sides, causing the original trader to pay more.

On June 20, an attacker used a series of contracts to cause the bot to grant token approvals that were later used to drain 4,427 ETH ($7.7 million). Some of the funds were then laundered through Tornado Cash.

☐ β˜† βœ‡ Web3 is going just great

Secret bridge exploited for $4.67 million a week before anyone notices

By: Molly White β€”
An S formed from two interlocking diamond shapes, followed by "Secret" in black

The bridge between the Cosmos-based Secret network and Axelar network was exploited via an infinite mint bug that went unnoticed for a week. An attacker exploited a smart contract in order to mint a large quantity of wrapped Axelar tokens on the Secret network, which they then redeeemed for around $4.67 million.

The exploit, which occurred on June 10, went unnoticed until June 17, when a transaction failed with a message suggesting that more tokens had been bridged out of the Secret network than had been bridged in.

Secret has warned, "If you hold Axelar-bridged saXXX tokens on Secret, please be aware their backing was affected and your funds may be lost."

☐ β˜† βœ‡ Web3 is going just great

Main Street USD (msUSD) loses its dollar peg

By: Molly White β€”
"Main Street" in black text, with the two E's in "street" represented by stacks of horizontal lines

Main Street USD, also known as msUSD, lost its dollar peg and crashed to around $0.25. At points, the token dipped as low as around $0.06. The asset, issued by Main Street Finance, is supposed to be redeemable 1:1 with Circle's USDC stablecoin. It's used as part of a yield strategy that is marketed as "democratizing the options box spread strategy through a stablecoin". Prior to the depeg, there was about $80 million msUSD in circulation.

On June 20, the verification provider Accountable announced that they had "terminated its service agreement with MainStreet, effective immediately. MainStreet was unable to meet our verification standards." The sudden loss of confidence in the token caused the price to plummet as holders rushed to withdraw funds.

Main Street issued a statement, claiming that "Mainstreet remains fully backed" and that "this is an infrastructure and reporting issue, not a solvency issue." However, they noted that "while our portfolio remains fully backed, converting positions into immediate liquidity depends on prevailing market depth and market-maker appetite."

☐ β˜† βœ‡ Web3 is going just great

Taiko bridge exploited

By: Molly White β€”
A pink three-pointed Celtic knot shape, followed by "Taiko"

The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.

☐ β˜† βœ‡ Web3 is going just great

Thief steals remaining 7,200 unsold The Kiss NFTs in digital museum heist

By: Molly White β€”
A grid of pixels representing each of the 10,000 NFTs forming Klimt's The Kiss. About 75% of them, representing unsold NFTs, are missing.

Remember when Austria's otherwise respectable Belvedere Museum sold 10,000 NFTs representing postage-stamp sized sections of Gustav Klimt's The Kiss for like $2,000 a pop? No? Don't worry, I've got you.

Only about a quarter of them ever sold, leaving about 7,200 of them on the digital shelves. That is, until they were stolen (or, as the museum put it, "transferred from the wallet without authorization"). If valued at their sale price the stolen NFTs would be worth €13.32 million (US$15.3 million), though it's hard to argue the thief could've ever sold them for that amount given the museum had failed to do so for several years.

The stolen NFTs were soon made even less appealing to prospective buyers when the museum un-linked the image files from the digital assets, and OpenSea blocked them from trading.

☐ β˜† βœ‡ Web3 is going just great

RetoSwap users lose $2.7 million to Haveno vulnerability

By: Molly White β€”
An R made from semi-circle shapes followed by "Retoswap"

The RetoSwap decentralized exchange for trading the Monero privacycoin was exploited after an attacker exploited a vulnerability in the Haveno Monero exchange protocol used by the project. Users lost an estimated $2.7 million when their transactions were routed to the attacker's wallet.

Because Monero is a privacycoin, a type of cryptocurrency that obscures transaction details including sender and receiver wallets, it is not feasible to trace the stolen assets.

☐ β˜† βœ‡ Web3 is going just great

Aztec Connect hacked for a second time in less than a week

By: Molly White β€”
"Aztec" in a variety of capital letter fonts

Three days after Aztec Labs' deprecated Aztec Connect blockchain bridge was exploited for $2.1 million, the project has been hacked again for the same amount. Aztec Labs confirmed the second exploit, again trying to emphasize that the code was deprecated four years ago.

The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.

☐ β˜† βœ‡ Web3 is going just great

Pudgy Penguins shuts down Pudgy Party NFT game after losing millions in less than ten months

By: Molly White β€”
A penguin with a nameplate reading "Pengu" stands facing the viewer in a snowy battle royale environment. A snowman behind holds a sign reading "JUMP" and another sign reads "Might as well JUMP"

The Pudgy Penguins NFT brand announced it would be shutting down its Pudgy Party NFT games less than ten months after its launch. The game was a mobile battle royale game, but built on crypto rails, with NFTs used for in-game items and characters that players could buy and sell. Pudgy Penguins seemed aware that the crypto aspect would be off-putting to many players, telling Decrypt in December 2025 that they were downplaying the crypto side of things "because the world is not ready for NFTs or crypto, or even blockchain en masse yet. But soon, very, very soon, we're going to use Pudgy Party as the glue between Web3 and Web2."

Although Pudgy Penguins CEO Lucas Netz boasted on Twitter in December about "1M+ downloads today. 10M+ downloads soon." he later admitted interest in the game had quickly died off. In a community call to announce the game's shutdown, Netz acknowledged that within months of the launch, there were only 200–300 active players. The project had lost the company millions of dollars, he confessed.

☐ β˜† βœ‡ Web3 is going just great

Polymarket loses $700,000 to private key compromise

By: Molly White β€”
A parallelogram created from three triangles, followed by Polymarket in black

Crypto sleuth zachxbt identified that "A Polymarket admin address appears to have been compromised on Polygon", writing that $520,000 had been drained as of the time of his post. The theft ultimately amounted to around $700,000, and Polymarket confirmed that a "wallet used for internal top-up operations" had been compromised. They did not provide further details as to how the compromise happened, though the company's VP of Engineering later said that the private key was six years old and that all private keys would be replaced with a managed key going forward.

☐ β˜† βœ‡ Web3 is going just great

Gravity Bridge drained of $5.4 million

By: Molly White β€”
Blue lines showing a circular portion of a plane bending around a sphere, followed by "Gravity Bridge" in grey caps

Gravity Bridge, a bridge between the Cosmos and Ethereum blockchains, suffered $5.4 million in losses likely due compromised private keys. The developers of the protocol urged validators to halt while the theft was investigated, and the bridge was indeed halted shortly after. Two weeks after the hack, the Gravity Bridge interface remained unavailable.

☐ β˜† βœ‡ Web3 is going just great

SquidRouterModule, unrelated to Squid Router, exploited for $3.2 million

By: Molly White β€”

A third-party Gnosis Safe smart contract called SquidRouterModule was exploited for $3.2 million. The smart contract included a set string that could be passed to identify a "safe" message; however, the string was visible in the public smart contract code and used by an attacker to impersonate Gnosis Safe users and then drain their wallets. 86 wallets had used the module, and lost a combined $3.2 million.

The name led to some confusion due to the similarly named Squid Router, which is not related. It's not clear if the users who installed the module were aware that the two projects were separate.

☐ β˜† βœ‡ Web3 is going just great

Humanity Protocol loses $36 million to employee laptop compromise

By: Molly White β€”
A five-pointed shape followed by "humanity" in black

Humanity Protocol, a decentralized identity project that uses palm scans to try to prove that users are human, has suffered a $36 million loss after attackers compromised a laptop belonging to an employee. After the laptop was infected with malware, the malicious code gained root access, then stole seven private keys that were reportedly accidentally stored in a backup. Several of the keys were sufficient to satisfy multisignature requirements, which are intended to prevent private key leaks from allowing attackers to gain control over sensitive infrastructure like bridges. With multisignature wallets, keys are supposed to be stored separately across multiple individuals and devices; however, in this case, attackers only needed to compromise one laptop to gain control over multisig-protected contracts.

With the keys, the attacker stole more than 6 million of Humanity's H token, then used other keys to upgrade a bridge and drain 141 million more tokens. With the bridge access, they also minted 300 million new H tokens. The attacker then quickly swapped the ill-gotten tokens for ETH, causing the H price to plummet by 80–90%.

Humanity Protocol markets itself as a competitor to Sam Altman's World (formerly Worldcoin), a decentralized identity project that aims to use iris scans to prove that users are unique humans. Humanity raised $20 million in 2025 from Pantera Capital and Jump Crypto.

☐ β˜† βœ‡ Web3 is going just great

Deprecated project Aztec Connect exploited for $2.1 million

By: Molly White β€”
"Aztec" in a variety of capital letter fonts

Aztec Connect, an abandoned defi privacy bridge from Aztec Labs, was drained of $2.1 million after an attacker exploited a bug in the project's smart contracts. Although the project was deprecated three years ago, funds remained in the legacy system. "Aztec Labs holds no admin keys or control over the system; it cannot be paused or upgraded by us," the project posted on social media.

The theft is only the latest in a string of attacks targeting vulnerable legacy smart contracts, many of which cannot be deleted, paused, or changed due to blockchains' immutable nature. Raydium and DxSale are two other platforms that have recently suffered losses due to old, insecure code.

☐ β˜† βœ‡ Web3 is going just great

Raydium users lose $1.34 million after legacy smart contract exploited

By: Molly White β€”
A blue, purple, and turquoise hexagon with an "R&" in the middle, followed by white capitals spelling "Raydium"

An attacker exploited a legacy smart contract that had been used by the Raydium Solana DEX before it was deprecated in 2021. Though the contract was unused, there were still funds in the liquidity pools affected by the vulnerable contract. Using fake LP tokens, the exploiter was able to trick an old smart contract with insufficient validation into allowing them to withdraw assets.

Raydium has said it will compensate users who lost funds in the exploit.

☐ β˜† βœ‡ Web3 is going just great

DxSale exploited for $7.3 million

By: Molly White β€”
A black rounded square with two white carets pointing inwards

DxSale, a project that was popular in 2021 for launching new tokens and creating liquidity pools, suffered a $7.3 million exploit after ownership of a locker contract was transferred to a new address. Nine months later, the contract ownership was repeatedly moved between many new wallets β€” likely in an attempt to cover tracks β€” before $7.3 million was taken from old liquidity pools. The stolen assets were then swapped to BNB and routed through bridges and mixers to obscure the trail.

☐ β˜† βœ‡ Web3 is going just great

Largest North American bitcoin ATM operator, Bitcoin Depot, files for bankruptcy

By: Molly White β€”
A yellow and black Bitcoin ATM with "Bitcoin sold here" printed on the side

Bitcoin Depot has filed for Chapter 11 bankruptcy. The company operates a fleet of kiosks at retail locations that allow customers to purchase bitcoin with cash. Bitcoin Depot announced in a press release that its 9,700 kiosks – primarily located at gas stations and convenience stores – had already been taken offline.

The company's bankruptcy filing reports between $10 million and $50 million in both assets and liabilities. In a recent financial disclosure, the company had reported a 49% year-over-year reduction in revenue and a net loss of $9.5 million for the year. The company had also suffered a $3.67 million hack in April.

Bitcoin Depot has blamed a challenging state-level regulatory environment for its bankruptcy, pointing to a series of regulatory restrictions and outright bans on crypto ATMs, which are a major conduit for crypto scams. An FBI report on Internet crime in 2024 showed 11,000 reports of fraud involving crypto ATMs – a 99% increase from the prior year. Almost $250 million was reported lost due to such scams, with a majority of it coming from victims over 60 years old. Several states have responded by introducing laws imposing strict compliance requirements or transaction limits on ATM operators, and Indiana and Tennessee have both recently banned the kiosks entirely. Additionally, the company is defending against lawsuits from both Massachusetts and Iowa, which argue that the company uses a misleading pricing structure, knowingly enables crypto scames, and maintains a predatory refund policy.

☐ β˜† βœ‡ Web3 is going just great

Verus bridge hacked for $11.6 million

By: Molly White β€”
A blue circle with a white V followed by "verus" in blue lowercase

An attacker stole $11.6 million in various crypto assets from the Verus–Ethereum bridge, which allows users to use tokens from the Verus network on the Ethereum chain and vice versa. The attacker then swapped the tokens for ETH, limiting the ability for issuers of more centralized tokens to freeze the stolen assets.

Verus halted the entire Verus network after the exploit was detected in hopes of limiting further damage.

The exploiter later accepted a bounty offer by Verus, returning 4,052 ETH (~$8.5 million) while keeping the remaining ~25% as a "bounty".

☐ β˜† βœ‡ Web3 is going just great

THORchain exploited for $10.8 million

By: Molly White β€”
A blue and green lightning bolt followed by β€œThorchain”

The THORchain cross-chain liquidity protocol was exploited for around $10.8 million across several blockchains: Bitcoin, Ethereum, BNB Chain, and Base. The protocol paused trading after observing the suspicious transactions. News of the hack caused the protocol's RUNE token to drop in price by more than 10%.

☐ β˜† βœ‡ Web3 is going just great

Transit Finance hacked for $1.88 million

By: Molly White β€”
A blue circle with a white T made out of three polygons, followed by "Transit" in blue text

Transit Finance was exploited for $1.88 million after an attacker exploited a "legacy contract" on the TRON blockchain that the project said was deprecated in 2022. "Historical vulnerabilities within it" were exploited, the project explained, allowing the attacker to steal $1.88 million.

Transit was previously exploited in 2022 for $21 million, although around 70% of the stolen assets were later returned.

☐ β˜† βœ‡ Web3 is going just great

TAC bridge exploited for $2.8 million

By: Molly White β€”
A purple circle with two triangles resembling a lightning bolt, followed by "TAC" in purple

The TAC bridge, which bridges assets from the Ethereum blockchain to the Telegram-linked TON chain, was exploited for $2.8 million. The project paused the bridge and announced they were investigating.

The project has announced they intend to "restor[e] bridge liquidity through a legally structured sale of Foundation's TAC token treasury reserves."

❌