Binance Square
#cryptohacks

cryptohacks

1.2M views
789 Discussing
tradekor
·
--
Article
The 2025 Crypto Theft Number Nobody Can Agree OnFour trackers, one year, and a $1.1 billion gap: nobody in crypto security agrees on how much was actually stolen in 2025. Start with the number that isn't in dispute. In February 2025, North Korea's Lazarus Group breached Bybit's cold wallet infrastructure and moved out roughly $1.5 billion in ETH — the largest crypto theft in history. The FBI's IC3 advisory confirms $1.5 billion as the official figure. Chainalysis, in its own year-end report, cites the same number for the same incident. On this one fact, every serious tracker lines up. Then the agreement stops. Ask "how much crypto was stolen across all of 2025" and you get four different answers from four trackers the industry treats as interchangeable: Chainalysis: $3.4 billion CertiK: $3.35 billion PeckShield: $4.04 billion SlowMist: $2.935 billion That's a spread of roughly $1.1 billion — about 37% of the smallest figure — between organizations whose entire job is counting this precisely. None of them has published a correction against the others. None has reconciled the gap. Press coverage, exchange risk disclosures, and even policy testimony cite whichever number happens to be on hand, as if $2.9 billion and $4 billion were the same fact stated two ways. They aren't. They're four different measurements of four different things, wearing the same headline. Why the numbers diverge The gap isn't sloppiness — it's scope, and each tracker draws the line somewhere different. Hacks versus scams. Chainalysis and CertiK lean toward counting technical exploits and breaches — code vulnerabilities, private key compromises, bridge attacks. PeckShield's wider $4.04 billion figure folds in a broader category that includes scams and rug pulls alongside hacks, which mechanically produces a bigger number without necessarily meaning more theft occurred by any narrower definition. CEX versus DeFi coverage. Some trackers weight centralized-exchange incidents (like Bybit) heavily because they're large, discrete, and easy to verify. Others build up their totals more from the long tail of smaller DeFi protocol exploits, which are numerous but individually harder to confirm and value precisely at the moment of the exploit. Gross loss versus net-of-recovered. A theft followed by a partial white-hat recovery, a negotiated return, or a law-enforcement clawback can get counted at the original gross figure by one tracker and at the net remaining loss by another. Same incident, two legitimate-looking numbers. Estimation methodology for the long tail. The handful of nine-figure incidents like Bybit are easy to nail down. The hundreds of smaller five- and six-figure DeFi exploits that make up the rest of the total are where trackers genuinely have to estimate, sample, and extrapolate — and small methodological choices compound across hundreds of incidents into a real aggregate difference. None of these choices is dishonest. Each is a defensible way to define "theft." The problem is that nobody discloses which definition they're using when the number gets forwarded, and by the time a figure reaches a press release or a Senate hearing, it's just "crypto theft in 2025: $X billion" — full stop, no methodology attached. Why it actually matters This isn't pedantry. These figures get used as inputs to real decisions. Institutional risk models cite whichever total makes crypto custody look safer or riskier depending on which side of a deal is doing the citing. Insurance underwriters pricing crypto-custody coverage need a real loss-rate denominator, and a 37% swing in the numerator changes the math on what a policy should cost. Regulatory testimony treats "crypto lost $X billion to theft this year" as a settled fact justifying a specific policy response, without anyone asking the questioner which tracker's methodology they're citing — or whether "worse than last year" and "better than last year" are both true depending on which one you pick. The framing effect is real too. A reporter or a policy staffer reaching for the biggest available number gets a "worst year on record" story; reaching for the smallest gets "crypto security is improving." Both headlines can run in the same week, sourced to different trackers, describing the same year. The falsifiable test Here's a way to watch whether this actually gets fixed rather than staying a permanent asterisk: has any tracker published a reconciliation methodology — a public breakdown of what they include and exclude, cross-walked against a competitor's figure, so a reader could convert between them? As of this writing, no. If one appears, that's a real sign the industry is treating this number as infrastructure rather than a headline generator. If the same four incompatible totals get recycled into next year's "state of crypto security" report with no cross-walk, that's the tell that nobody who cites these numbers actually needs them to be precise — just big. The Bybit number holds up because it's one incident, independently confirmed by a federal agency, with a clean chain of custody on the facts. The annual aggregate doesn't hold up the same way, because it was never one measurement to begin with — it's four different ones, laundered through a shared headline until they look like consensus. Which of these four numbers have you seen cited as "the" 2025 total — and did the source say which tracker it came from? Not financial advice. DYOR. $ETH #CryptoSecurity #DataIntegrity #Chainalysis #CryptoHacks

The 2025 Crypto Theft Number Nobody Can Agree On

Four trackers, one year, and a $1.1 billion gap: nobody in crypto security agrees on how much was actually stolen in 2025.
Start with the number that isn't in dispute. In February 2025, North Korea's Lazarus Group breached Bybit's cold wallet infrastructure and moved out roughly $1.5 billion in ETH — the largest crypto theft in history. The FBI's IC3 advisory confirms $1.5 billion as the official figure. Chainalysis, in its own year-end report, cites the same number for the same incident. On this one fact, every serious tracker lines up.
Then the agreement stops. Ask "how much crypto was stolen across all of 2025" and you get four different answers from four trackers the industry treats as interchangeable:
Chainalysis: $3.4 billion
CertiK: $3.35 billion
PeckShield: $4.04 billion
SlowMist: $2.935 billion
That's a spread of roughly $1.1 billion — about 37% of the smallest figure — between organizations whose entire job is counting this precisely. None of them has published a correction against the others. None has reconciled the gap. Press coverage, exchange risk disclosures, and even policy testimony cite whichever number happens to be on hand, as if $2.9 billion and $4 billion were the same fact stated two ways.
They aren't. They're four different measurements of four different things, wearing the same headline.
Why the numbers diverge
The gap isn't sloppiness — it's scope, and each tracker draws the line somewhere different.
Hacks versus scams. Chainalysis and CertiK lean toward counting technical exploits and breaches — code vulnerabilities, private key compromises, bridge attacks. PeckShield's wider $4.04 billion figure folds in a broader category that includes scams and rug pulls alongside hacks, which mechanically produces a bigger number without necessarily meaning more theft occurred by any narrower definition.
CEX versus DeFi coverage. Some trackers weight centralized-exchange incidents (like Bybit) heavily because they're large, discrete, and easy to verify. Others build up their totals more from the long tail of smaller DeFi protocol exploits, which are numerous but individually harder to confirm and value precisely at the moment of the exploit.
Gross loss versus net-of-recovered. A theft followed by a partial white-hat recovery, a negotiated return, or a law-enforcement clawback can get counted at the original gross figure by one tracker and at the net remaining loss by another. Same incident, two legitimate-looking numbers.
Estimation methodology for the long tail. The handful of nine-figure incidents like Bybit are easy to nail down. The hundreds of smaller five- and six-figure DeFi exploits that make up the rest of the total are where trackers genuinely have to estimate, sample, and extrapolate — and small methodological choices compound across hundreds of incidents into a real aggregate difference.
None of these choices is dishonest. Each is a defensible way to define "theft." The problem is that nobody discloses which definition they're using when the number gets forwarded, and by the time a figure reaches a press release or a Senate hearing, it's just "crypto theft in 2025: $X billion" — full stop, no methodology attached.
Why it actually matters
This isn't pedantry. These figures get used as inputs to real decisions.
Institutional risk models cite whichever total makes crypto custody look safer or riskier depending on which side of a deal is doing the citing. Insurance underwriters pricing crypto-custody coverage need a real loss-rate denominator, and a 37% swing in the numerator changes the math on what a policy should cost. Regulatory testimony treats "crypto lost $X billion to theft this year" as a settled fact justifying a specific policy response, without anyone asking the questioner which tracker's methodology they're citing — or whether "worse than last year" and "better than last year" are both true depending on which one you pick.
The framing effect is real too. A reporter or a policy staffer reaching for the biggest available number gets a "worst year on record" story; reaching for the smallest gets "crypto security is improving." Both headlines can run in the same week, sourced to different trackers, describing the same year.
The falsifiable test
Here's a way to watch whether this actually gets fixed rather than staying a permanent asterisk: has any tracker published a reconciliation methodology — a public breakdown of what they include and exclude, cross-walked against a competitor's figure, so a reader could convert between them? As of this writing, no. If one appears, that's a real sign the industry is treating this number as infrastructure rather than a headline generator. If the same four incompatible totals get recycled into next year's "state of crypto security" report with no cross-walk, that's the tell that nobody who cites these numbers actually needs them to be precise — just big.
The Bybit number holds up because it's one incident, independently confirmed by a federal agency, with a clean chain of custody on the facts. The annual aggregate doesn't hold up the same way, because it was never one measurement to begin with — it's four different ones, laundered through a shared headline until they look like consensus.
Which of these four numbers have you seen cited as "the" 2025 total — and did the source say which tracker it came from?
Not financial advice. DYOR.
$ETH #CryptoSecurity #DataIntegrity #Chainalysis #CryptoHacks
🚨 $11 BILLION WIPED OUT IN 6 MONTHS – THE BIGGEST HACK WAVE IN CRYPTO HISTORY 💥 Over 212 on-chain exploits this year alone, with North Korea-linked groups pocketing 55% of total losses. The real story isn't just the numbers – it's how they're executing these hits. 🔍 The top 4 attacks (KelpDAO, Drift Protocol, Resolv, CowSwap) accounted for 64% of all damage, and none were simple code bugs. Attackers compromised developer credentials, manipulated RPC infrastructure, and exploited single-point validator setups. Even LinkedIn recruitment scams are being weaponized to steal admin keys. 📊 Ethereum still leads in absolute losses ($332M), but Solana is now #2 – with 98% of its $326M coming from compromised private keys and signature infrastructure. Meanwhile, Arbitrum saw the first-ever exploit using EIP-7702 wallet delegation. The attack surface is expanding faster than most traders realize. 💬 If you're holding assets on any chain, what's your single biggest vulnerability right now? Is it the protocol, the bridge, or your own key management? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #CryptoHacks #ETH #SOL #DeFi #Security 🛡️ 🔍
🚨 $11 BILLION WIPED OUT IN 6 MONTHS – THE BIGGEST HACK WAVE IN CRYPTO HISTORY 💥

Over 212 on-chain exploits this year alone, with North Korea-linked groups pocketing 55% of total losses. The real story isn't just the numbers – it's how they're executing these hits.

🔍 The top 4 attacks (KelpDAO, Drift Protocol, Resolv, CowSwap) accounted for 64% of all damage, and none were simple code bugs. Attackers compromised developer credentials, manipulated RPC infrastructure, and exploited single-point validator setups. Even LinkedIn recruitment scams are being weaponized to steal admin keys.

📊 Ethereum still leads in absolute losses ($332M), but Solana is now #2 – with 98% of its $326M coming from compromised private keys and signature infrastructure. Meanwhile, Arbitrum saw the first-ever exploit using EIP-7702 wallet delegation. The attack surface is expanding faster than most traders realize.

💬 If you're holding assets on any chain, what's your single biggest vulnerability right now? Is it the protocol, the bridge, or your own key management? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #CryptoHacks #ETH #SOL #DeFi #Security

🛡️ 🔍
$1 Billion down the drain: Cryptocurrency hacks hit a record high in H1 2026, outpacing losses by a staggering 100% YoY. In the first half of 2026, the sector saw its worst start to a year since 2018, with total losses surpassing a breathtaking $1 Billion. Ethereum and Solana projects bore the brunt, losing $332 million and $326 million, respectively - a stark reminder that security still haunts even the biggest players in the crypto space #cryptoHacks, #decentralizedSecurity, #cryptocurrencyRegulations. Smart money is taking notice: on-chain transactions on Ethereum have plummeted as whales and institutions scramble to cover their losses. Expect a ripple effect across larger projects as investors reevaluate risk and seek safer havens #cryptoRiskOn. The forward signal is clear: if security continues to be a major concern, expect a flight to safety towards assets with robust infrastructure and a track record of strong security practices. Stay vigilant and watch for the first signs of mass capitulation #cryptoRiskOff. Will this record number of hacks be the wake-up call the crypto sector needs to prioritize security above profits?
$1 Billion down the drain: Cryptocurrency hacks hit a record high in H1 2026, outpacing losses by a staggering 100% YoY.

In the first half of 2026, the sector saw its worst start to a year since 2018, with total losses surpassing a breathtaking $1 Billion. Ethereum and Solana projects bore the brunt, losing $332 million and $326 million, respectively - a stark reminder that security still haunts even the biggest players in the crypto space #cryptoHacks, #decentralizedSecurity, #cryptocurrencyRegulations.

Smart money is taking notice: on-chain transactions on Ethereum have plummeted as whales and institutions scramble to cover their losses. Expect a ripple effect across larger projects as investors reevaluate risk and seek safer havens #cryptoRiskOn.

The forward signal is clear: if security continues to be a major concern, expect a flight to safety towards assets with robust infrastructure and a track record of strong security practices. Stay vigilant and watch for the first signs of mass capitulation #cryptoRiskOff.

Will this record number of hacks be the wake-up call the crypto sector needs to prioritize security above profits?
Verified
🚨 ХАКЕР ПОЛУЧИЛ АИРДРОП ВМЕСТО ДЕРЖАТЕЛЕЙ ТОКЕНА — КАК ТАКОЕ ВООБЩЕ ВОЗМОЖНО? Команда #Superfortune умудрилась отправить аирдроп… прямо в карман хакера. Нет, это не шутка. В ходе multisig-транзакции злоумышленник каким-то образом подменил адрес получателя. В итоге токены #GUA улетели на кошелёк хакера 0x70ae67…5c15 — вместо официального контракта аирдропа 0x70ae7d…5c15. Разница между адресами — всего несколько символов в середине. Именно этого и хватило. Что примечательно: сама команда исключает классическую схему address poisoning — ведь адрес хакера ни разу не взаимодействовал с инфраструктурой проекта до инцидента. Это значит, что вектор атаки был другим, и, скорее всего, более изощрённым — возможно, компрометация одного из подписантов или подмена на уровне интерфейса. Рынок отреагировал молниеносно: 📉 $GUA — минус 75% за 24 часа Очередное напоминание: даже multisig не панацея, если в цепочке подписей есть слабое звено. Всегда верифицируйте адреса побайтово, а не визуально. #cryptohacks #Airdrop #Web3Security #defi Если такой контент полезен — подпишись, здесь регулярно разбираю громкие инциденты и находки из мира крипты 🔔
🚨 ХАКЕР ПОЛУЧИЛ АИРДРОП ВМЕСТО ДЕРЖАТЕЛЕЙ ТОКЕНА — КАК ТАКОЕ ВООБЩЕ ВОЗМОЖНО?

Команда #Superfortune умудрилась отправить аирдроп… прямо в карман хакера. Нет, это не шутка.

В ходе multisig-транзакции злоумышленник каким-то образом подменил адрес получателя. В итоге токены #GUA улетели на кошелёк хакера 0x70ae67…5c15 — вместо официального контракта аирдропа 0x70ae7d…5c15. Разница между адресами — всего несколько символов в середине. Именно этого и хватило.

Что примечательно: сама команда исключает классическую схему address poisoning — ведь адрес хакера ни разу не взаимодействовал с инфраструктурой проекта до инцидента. Это значит, что вектор атаки был другим, и, скорее всего, более изощрённым — возможно, компрометация одного из подписантов или подмена на уровне интерфейса.

Рынок отреагировал молниеносно:
📉 $GUA — минус 75% за 24 часа

Очередное напоминание: даже multisig не панацея, если в цепочке подписей есть слабое звено. Всегда верифицируйте адреса побайтово, а не визуально.

#cryptohacks #Airdrop #Web3Security #defi

Если такой контент полезен — подпишись, здесь регулярно разбираю громкие инциденты и находки из мира крипты 🔔
$BTC AND $ETH TANKING AS HACKS HIT RECORD HIGH IN 2026 🔥 207 hacks in six months — that's the highest ever. North Korea-linked groups took 66% of the $972 million stolen, with two exploits alone draining $577 million from KelpDAO and Drift Protocol. Smart contracts aren't the only weak spot. Infrastructure failures caused 76% of losses despite only 15% of incidents. TVL in DeFi dropped from $115B to $70B in the same period. Bitcoin down 28%, ETH down 40%. That kind of pressure shakes out weak hands fast. Are you staying long or stepping aside? Not financial advice. Always manage your risk. #BTC #Ethereum #CryptoHacks #MarketCrash 🔥
$BTC AND $ETH TANKING AS HACKS HIT RECORD HIGH IN 2026 🔥

207 hacks in six months — that's the highest ever. North Korea-linked groups took 66% of the $972 million stolen, with two exploits alone draining $577 million from KelpDAO and Drift Protocol.

Smart contracts aren't the only weak spot. Infrastructure failures caused 76% of losses despite only 15% of incidents. TVL in DeFi dropped from $115B to $70B in the same period.

Bitcoin down 28%, ETH down 40%. That kind of pressure shakes out weak hands fast. Are you staying long or stepping aside?

Not financial advice. Always manage your risk.

#BTC #Ethereum #CryptoHacks #MarketCrash

🔥
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️ North Korean hackers just dropped some of the biggest exploits this year: Drift Protocol → $285M Kelp DAO → $292M Their Dirty Tactics: Fake job offers & deepfake calls 😈 Malware on dev laptops to steal keys Bridge exploits & fake collateral plays They plan attacks for months... super patient & dangerous. Stay Safe Kings: Hardware wallet only Never share seed/private keys Double-check every link & file Projects need better security ASAP! You teaming up against Lazarus or still clicking random links? 😂👇 #Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️
North Korean hackers just dropped some of the biggest exploits this year:
Drift Protocol → $285M
Kelp DAO → $292M
Their Dirty Tactics:
Fake job offers & deepfake calls 😈
Malware on dev laptops to steal keys
Bridge exploits & fake collateral plays
They plan attacks for months... super patient & dangerous.
Stay Safe Kings:
Hardware wallet only
Never share seed/private keys
Double-check every link & file
Projects need better security ASAP!
You teaming up against Lazarus or still clicking random links? 😂👇

#Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
·
--
Bullish
2026 年,DeFi 被盜金額已超過 7.5 億美元。我翻了一下受害者名單,裡面有幾個是被審計過的項目。很多人以為有審計報告就等於安全,但 2026 年的數據說的剛好相反:Kelp DAO 被盜 2.93 億美元,是今年最大單筆,它被駭的方式是橋接合約漏洞;Silo V2 被預言機操控,同樣發生在審計之後。 審計不是護身符,那審計的意義到底是什麼?🤔 【我查了 Genius Terminal 的四家審計機構】 Halborn、Cantina、HackenProof、Borg Research,這四家在業內各有側重。Halborn 做過 200+ 個區塊鏈項目,主力是智能合約和基礎設施漏洞;Cantina 以競賽式審計著稱,多位獨立研究員同時挑戰同一份代碼;HackenProof 專長是 bug bounty 管理和滲透測試;Borg Research 則偏向密碼學協議的底層驗證。 我覺得這個組合有意思的地方不是數量,而是覆蓋面。單一審計機構的視角有盲點,四家機構各從不同角度進入,理論上能縮小被忽略的攻擊面。 【審計的本質是什麼】 我個人認為,四家審計機構給的不是「不會被駭」的保證,而是一個信號:這個團隊願意花錢找外部人挑毛病,而且不只找一次。業內一份審計費用從 2.5 萬到 20 萬美元不等,而 DeFi 一次成功的攻擊損失從 500 萬到數億美元。這個比例算下來,多審一次的成本完全合理。 「安全審計的數量不代表安全,但它代表項目方對風險的態度。」 【對 $GENIUS 的意義】🔑 Ghost Orders 上鏈之後,Genius Terminal 的隱私交易功能才有辦法真實落地,用戶才有意願在平台上執行大額交易。大額交易量撐高平台 GMV,代幣持有者的 $USDC 推薦返還才有持續性的基礎。安全不是加分項,是整個飛輪的前提。 @GeniusOfficial $GENIUS #genius #defi #cryptohacks
2026 年,DeFi 被盜金額已超過 7.5 億美元。我翻了一下受害者名單,裡面有幾個是被審計過的項目。很多人以為有審計報告就等於安全,但 2026 年的數據說的剛好相反:Kelp DAO 被盜 2.93 億美元,是今年最大單筆,它被駭的方式是橋接合約漏洞;Silo V2 被預言機操控,同樣發生在審計之後。

審計不是護身符,那審計的意義到底是什麼?🤔

【我查了 Genius Terminal 的四家審計機構】
Halborn、Cantina、HackenProof、Borg Research,這四家在業內各有側重。Halborn 做過 200+ 個區塊鏈項目,主力是智能合約和基礎設施漏洞;Cantina 以競賽式審計著稱,多位獨立研究員同時挑戰同一份代碼;HackenProof 專長是 bug bounty 管理和滲透測試;Borg Research 則偏向密碼學協議的底層驗證。
我覺得這個組合有意思的地方不是數量,而是覆蓋面。單一審計機構的視角有盲點,四家機構各從不同角度進入,理論上能縮小被忽略的攻擊面。

【審計的本質是什麼】
我個人認為,四家審計機構給的不是「不會被駭」的保證,而是一個信號:這個團隊願意花錢找外部人挑毛病,而且不只找一次。業內一份審計費用從 2.5 萬到 20 萬美元不等,而 DeFi 一次成功的攻擊損失從 500 萬到數億美元。這個比例算下來,多審一次的成本完全合理。
「安全審計的數量不代表安全,但它代表項目方對風險的態度。」

【對 $GENIUS 的意義】🔑
Ghost Orders 上鏈之後,Genius Terminal 的隱私交易功能才有辦法真實落地,用戶才有意願在平台上執行大額交易。大額交易量撐高平台 GMV,代幣持有者的 $USDC 推薦返還才有持續性的基礎。安全不是加分項,是整個飛輪的前提。

@GeniusOfficial $GENIUS #genius #defi #cryptohacks
$ETH INCIDENT EXPOSES DEEP VULNERABILITY IN MEV BOTS 🚨 The recent hack of Jaredfromsubway.eth, a prominent MEV bot on the Ethereum network, has revealed a significant vulnerability in automated execution systems, resulting in a loss of over $7.5 million. This incident highlights the importance of robust security measures in the crypto space. The attack involved the deployment of 66 fake token contracts and liquidity pools, mimicking assets such as $WETH , $USDC , and $USDT , which enticed the bot to execute malicious transactions. This level of sophistication and deception is a wake-up call for the entire crypto community, are you increasing your security measures in response to this incident? Not financial advice. Manage your risk. #EthereumNews #MEVBotSecurity #CryptoHacks 💸
$ETH INCIDENT EXPOSES DEEP VULNERABILITY IN MEV BOTS 🚨

The recent hack of Jaredfromsubway.eth, a prominent MEV bot on the Ethereum network, has revealed a significant vulnerability in automated execution systems, resulting in a loss of over $7.5 million. This incident highlights the importance of robust security measures in the crypto space.

The attack involved the deployment of 66 fake token contracts and liquidity pools, mimicking assets such as $WETH , $USDC , and $USDT , which enticed the bot to execute malicious transactions. This level of sophistication and deception is a wake-up call for the entire crypto community, are you increasing your security measures in response to this incident?

Not financial advice. Manage your risk.

#EthereumNews #MEVBotSecurity #CryptoHacks
💸
EXPLOITED Gnosis Pay just dropped a bombshell revealing a software flaw dating back to October 2023 that enabled the $1.5 million exploit of its card safe infrastructure #GnosisPay #CryptoHacks #SecurityMatters. According to a postmortem, the vulnerability was discovered after the exploit occurred and thankfully all affected users have been fully reimbursed. This historic hack serves as a reminder that the crypto landscape is a cat-and-mouse game where security is paramount. The implications are clear: if you haven't tightened the screws on security measures yet, it's time to do so, not just for yourself, but for your fellow holders too. Will you adapt before it's too late?
EXPLOITED

Gnosis Pay just dropped a bombshell revealing a software flaw dating back to October 2023 that enabled the $1.5 million exploit of its card safe infrastructure #GnosisPay #CryptoHacks #SecurityMatters. According to a postmortem, the vulnerability was discovered after the exploit occurred and thankfully all affected users have been fully reimbursed. This historic hack serves as a reminder that the crypto landscape is a cat-and-mouse game where security is paramount. The implications are clear: if you haven't tightened the screws on security measures yet, it's time to do so, not just for yourself, but for your fellow holders too. Will you adapt before it's too late?
🔓 RAYDIUM ВЗЛОМАЛИ НА $1,34 МЛН — ЧЕРЕЗ КОНТРАКТЫ КОТОРЫМ УЖЕ 3 ГОДА Паниковать не нужно — но разобраться стоит. Взломали не саму биржу, а legacy AMM V3 — пять устаревших пулов ликвидности, которые задепрекейтили ещё в 2021 году после смерти #Serum. Никакого активного интерфейса, никаких текущих пользователей. Просто мёртвые контракты, которые забыли окончательно закрыть. Что утекло: — ~150 000 токенов #RAY — 5 600 #SOL — ~893 000 #USDC Как именно: Хакер создал фейковый LP mint и через него обошёл проверку безопасности при выводе. Уязвимость — не в свежем коде, а в логике трёхлетней давности, до которой ни у кого не доходили руки. Хорошая новость: #Raydium заявил, что покроет потери пострадавших из казны. Текущие пулы CLMM и новые версии AMM не затронуты — продолжают работать в штатном режиме. Это идеальная иллюстрация одной из главных проблем DeFi: новые контракты аудитят и патчат, старые — забывают. Команды уходят вперёд, Legacy висит в фоне годами. Хакеры не торопятся — они просто ждут, пока все забудут что там вообще что-то лежит. $1,34 млн за трёхлетнюю уязвимость — дорогое напоминание о цифровой гигиене. #raydium #solana #defi #cryptohacks Подпишись🤝
🔓 RAYDIUM ВЗЛОМАЛИ НА $1,34 МЛН — ЧЕРЕЗ КОНТРАКТЫ КОТОРЫМ УЖЕ 3 ГОДА

Паниковать не нужно — но разобраться стоит.

Взломали не саму биржу, а legacy AMM V3 — пять устаревших пулов ликвидности, которые задепрекейтили ещё в 2021 году после смерти #Serum. Никакого активного интерфейса, никаких текущих пользователей. Просто мёртвые контракты, которые забыли окончательно закрыть.

Что утекло:
— ~150 000 токенов #RAY
— 5 600 #SOL
— ~893 000 #USDC

Как именно:

Хакер создал фейковый LP mint и через него обошёл проверку безопасности при выводе. Уязвимость — не в свежем коде, а в логике трёхлетней давности, до которой ни у кого не доходили руки.

Хорошая новость:

#Raydium заявил, что покроет потери пострадавших из казны. Текущие пулы CLMM и новые версии AMM не затронуты — продолжают работать в штатном режиме.

Это идеальная иллюстрация одной из главных проблем DeFi: новые контракты аудитят и патчат, старые — забывают. Команды уходят вперёд, Legacy висит в фоне годами. Хакеры не торопятся — они просто ждут, пока все забудут что там вообще что-то лежит.

$1,34 млн за трёхлетнюю уязвимость — дорогое напоминание о цифровой гигиене.

#raydium #solana #defi #cryptohacks

Подпишись🤝
·
--
Bullish
🚨 **$H PUMPING 44%... BUT IS IT A MASSIVE BULL TRAP?!** 🚨 Everyone is celebrating because Humanity Protocol ($H) just pumped 44% after the team dropped their breach report and teased a compensation plan for the victims. But do NOT let this relief rally fool you—this is screaming danger! 🛑 Here is what the hype boys are ignoring: 1️⃣ **The Breach Was Brutal:** A single malware-infected developer laptop gave the attacker 7 private keys, allowing them to steal and maliciously mint a staggering **447 MILLION $H tokens**. 2️⃣ **THE HACKER STILL HAS CONTROL!** Yes, you read that right. The attacker still holds the ProxyAdmin keys on the BSC network. The protocol remains exposed! 🤯 3️⃣ **Massive Unlock Incoming:** As if the hack wasn't bad enough, a massive scheduled token unlock is hitting the market on **June 25**. Imagine that insane sell pressure crashing into an already fragile chart! 🩸 Smart money isn't buying this pump; they are using it as exit liquidity. This looks like the perfect setup for a brutal dump. Stay safe, protect your capital, and do not catch falling knives! 📉 Are you shorting $H or staying entirely away? Let me know! 👇🔥💸 #HumanityProtocol #CryptoNews #BinanceFutures #BearishSetup #CryptoHacks {future}(HUSDT)
🚨 **$H PUMPING 44%... BUT IS IT A MASSIVE BULL TRAP?!** 🚨
Everyone is celebrating because Humanity Protocol ($H ) just pumped 44% after the team dropped their breach report and teased a compensation plan for the victims. But do NOT let this relief rally fool you—this is screaming danger! 🛑
Here is what the hype boys are ignoring:
1️⃣ **The Breach Was Brutal:** A single malware-infected developer laptop gave the attacker 7 private keys, allowing them to steal and maliciously mint a staggering **447 MILLION $H tokens**.
2️⃣ **THE HACKER STILL HAS CONTROL!** Yes, you read that right. The attacker still holds the ProxyAdmin keys on the BSC network. The protocol remains exposed! 🤯
3️⃣ **Massive Unlock Incoming:** As if the hack wasn't bad enough, a massive scheduled token unlock is hitting the market on **June 25**. Imagine that insane sell pressure crashing into an already fragile chart! 🩸
Smart money isn't buying this pump; they are using it as exit liquidity. This looks like the perfect setup for a brutal dump. Stay safe, protect your capital, and do not catch falling knives! 📉
Are you shorting $H or staying entirely away? Let me know! 👇🔥💸
#HumanityProtocol #CryptoNews #BinanceFutures #BearishSetup #CryptoHacks
·
--
Bearish
Verified
Humanity Protocol disclosed a major security breach after an employee's laptop was compromised, allowing an attacker to obtain administrative keys controlling the project's bridge infrastructure on Ethereum and BNB Chain. According to the team, the attacker gained control of 3 of 6 Gnosis Safe owner keys used for the Ethereum bridge ProxyAdmin. This allowed them to transfer ownership of the bridge administration contract, deploy a malicious implementation, and move 141.2 million H tokens in a single transaction. Humanity Protocol said the attacker also compromised 3 of 5 Safe owner keys controlling the BNB Chain bridge. After taking over the bridge administration contract, the attacker deployed another malicious implementation containing an unlimited mint function. Using that contract, the attacker minted 200,000,005 H tokens in two transactions and transferred the newly created tokens to their own wallet. Blockchain investigator Specter initially reported that more than 17 wallets holding H tokens had been drained. As the hack progressed, the number of affected wallets grew into the hundreds. Specter later estimated losses had exceeded $30 million and reported that millions of dollars worth of stolen H tokens had already been sold for ETH. Humanity Protocol later estimated total losses at more than $36 million across Ethereum and BNB Chain. The project has halted deposits and withdrawals on affected bridges and says it is working with exchanges, security firms, and law enforcement to track funds and investigate the breach. #HumanityProtocol #Hack #cryptohacks #SecurityAlert
Humanity Protocol disclosed a major security breach after an employee's laptop was compromised, allowing an attacker to obtain administrative keys controlling the project's bridge infrastructure on Ethereum and BNB Chain.
According to the team, the attacker gained control of 3 of 6 Gnosis Safe owner keys used for the Ethereum bridge ProxyAdmin. This allowed them to transfer ownership of the bridge administration contract, deploy a malicious implementation, and move 141.2 million H tokens in a single transaction.
Humanity Protocol said the attacker also compromised 3 of 5 Safe owner keys controlling the BNB Chain bridge. After taking over the bridge administration contract, the attacker deployed another malicious implementation containing an unlimited mint function.
Using that contract, the attacker minted 200,000,005 H tokens in two transactions and transferred the newly created tokens to their own wallet.
Blockchain investigator Specter initially reported that more than 17 wallets holding H tokens had been drained. As the hack progressed, the number of affected wallets grew into the hundreds. Specter later estimated losses had exceeded $30 million and reported that millions of dollars worth of stolen H tokens had already been sold for ETH.
Humanity Protocol later estimated total losses at more than $36 million across Ethereum and BNB Chain.
The project has halted deposits and withdrawals on affected bridges and says it is working with exchanges, security firms, and law enforcement to track funds and investigate the breach.

#HumanityProtocol #Hack #cryptohacks #SecurityAlert
🚨 99.5% CRASH. 17 wallets. One perfectly timed hack. Read that again. Most people see a hack and think "bad luck." I see a question that nobody is asking loud enough. $H pumped to its all-time high. Momentum was peak. Retail was euphoric. The chart was vertical. Then, in that exact moment, 17 wallets — directly linked to the Humanity Protocol project — got "hacked." Every single H token inside them was dumped into the open market. No slow exit. No OTC deals. Just a full market obliteration. The price didn't just drop. It got divided by roughly 200 times overnight. 😶 Now, here's the uncomfortable part. Retail thinks: "Wow, security is terrible in crypto." Smart money thinks: "Who held those 17 wallets before the pump?" Because hacks don't schedule themselves at ATH. Hacks don't wait for maximum liquidity. Hacks don't coordinate 17 wallets in perfect sync with a retail euphoria event. But insiders do. --- The market teaches one lesson over and over: The loudest pump often attracts the quietest exit plan. --- Was this a security failure? Or was this an engineered liquidity event dressed up as a hack? --- I'm not giving an answer. I'm asking the question that the chart is already asking. 👇 Drop your honest take: Do you think $H was intentionally hacked... or intentionally "hacked"? $H {future}(HUSDT) #HUSDT #huminity #cryptohacks
🚨 99.5% CRASH.
17 wallets.
One perfectly timed hack.

Read that again.

Most people see a hack and think "bad luck."
I see a question that nobody is asking loud enough.

$H pumped to its all-time high.
Momentum was peak.
Retail was euphoric.
The chart was vertical.

Then, in that exact moment, 17 wallets — directly linked to the Humanity Protocol project — got "hacked."

Every single H token inside them was dumped into the open market.
No slow exit. No OTC deals. Just a full market obliteration.

The price didn't just drop.
It got divided by roughly 200 times overnight.

😶

Now, here's the uncomfortable part.

Retail thinks: "Wow, security is terrible in crypto."
Smart money thinks: "Who held those 17 wallets before the pump?"

Because hacks don't schedule themselves at ATH.
Hacks don't wait for maximum liquidity.
Hacks don't coordinate 17 wallets in perfect sync with a retail euphoria event.

But insiders do.

---

The market teaches one lesson over and over:
The loudest pump often attracts the quietest exit plan.

---

Was this a security failure?
Or was this an engineered liquidity event dressed up as a hack?

---

I'm not giving an answer.
I'm asking the question that the chart is already asking.

👇 Drop your honest take:
Do you think $H was intentionally hacked... or intentionally "hacked"?

$H
#HUSDT #huminity #cryptohacks
SlowMist has released its H1 2026 blockchain security report, documenting 182 publicly disclosed security incidents. Total losses reached USD 956 million, down significantly from more than USD 2.5 billion during the same period in 2025. While the value stolen declined, security incidents continued across the Web3 ecosystem. Ethereum recorded the highest number of incidents with 70, followed by BNB Chain with 27 and Base with 16. Private key compromise caused the largest financial losses, accounting for USD 688 million. Smart contract vulnerabilities remained the most common attack type with 76 recorded incidents. The report shows a difference between attack frequency and financial impact. Smart contract vulnerabilities appeared most often, while private key compromise resulted in the greatest losses. The findings reinforce the importance of improving blockchain security through stronger key management, infrastructure protection, and continued smart contract security practices. #cryptohacks #BlockchainSecurity #CryptoNews #CryptocurrencyNews
SlowMist has released its H1 2026 blockchain security report, documenting 182 publicly disclosed security incidents.

Total losses reached USD 956 million, down significantly from more than USD 2.5 billion during the same period in 2025. While the value stolen declined, security incidents continued across the Web3 ecosystem.

Ethereum recorded the highest number of incidents with 70, followed by BNB Chain with 27 and Base with 16. Private key compromise caused the largest financial losses, accounting for USD 688 million. Smart contract vulnerabilities remained the most common attack type with 76 recorded incidents.

The report shows a difference between attack frequency and financial impact. Smart contract vulnerabilities appeared most often, while private key compromise resulted in the greatest losses.

The findings reinforce the importance of improving blockchain security through stronger key management, infrastructure protection, and continued smart contract security practices.

#cryptohacks #BlockchainSecurity #CryptoNews #CryptocurrencyNews
$DEFI TVL SINKS 39% AS $BTC COLLATERAL DRAINS 🔥 Total value locked in DeFi has fallen every month this year, dropping from $115 billion to $70 billion — a 39% slide and the longest losing streak since 2022. Hacks have added to the pain, with 121 exploits stealing nearly $942 million through late June, and two breaches in April alone draining $293 million from KelpDAO. Aave deposits collapsed from $26.4 billion to $14.3 billion within days as trust evaporated. Capital is sitting in stablecoins, waiting for a catalyst. Are you allocating to DeFi at these levels or staying in cash? Not financial advice. Always manage your risk. #ETH #DeFi #TVLDecline #CryptoHacks 🔥
$DEFI TVL SINKS 39% AS $BTC COLLATERAL DRAINS 🔥

Total value locked in DeFi has fallen every month this year, dropping from $115 billion to $70 billion — a 39% slide and the longest losing streak since 2022. Hacks have added to the pain, with 121 exploits stealing nearly $942 million through late June, and two breaches in April alone draining $293 million from KelpDAO.

Aave deposits collapsed from $26.4 billion to $14.3 billion within days as trust evaporated. Capital is sitting in stablecoins, waiting for a catalyst.

Are you allocating to DeFi at these levels or staying in cash?

Not financial advice. Always manage your risk.

#ETH #DeFi #TVLDecline #CryptoHacks

🔥
$14.27 billion. That's how much crypto has lost to hacks and exploits since 2016, according to CoinGecko's latest data. The trend line tells its own story: • 2016: around $60M • 2021: $2.66B • 2022: $2.77B (still the worst year on record) • 2025: $2.55B • 2026 so far: $1.2B across 164 incidents, already more incidents than any full year before it Security tooling has genuinely improved over the years. Audits are standard now, bug bounties are common, monitoring is faster. But the losses haven't gone away, they've just changed shape. It's not always a shady protocol or an obvious rug pull. A lot of the damage comes from smart contract bugs, leaked private keys, phishing links, bridge exploits, or just someone getting socially engineered into signing the wrong thing. That's really the takeaway for anyone using this space day to day: 🔐 Don't assume a protocol is safe just because it's popular 🧪 Actually look into what you're interacting with before connecting your wallet 🚨 Slow down on approvals and signature requests, most people lose funds here without realizing what they signed 💰 Keep your hot wallet light. If you don't need it liquid right now, it shouldn't be sitting there Self-custody is the whole point of crypto, but it also means the security burden sits with you, not an exchange or a bank. Curious what people think: which is the bigger risk right now, smart contract bugs or human error? From the incident data, it's looking more and more like the human side. Source: CoinGecko #Crypto #CryptoSecurity #CryptoHacks #Web3 #Blockchain
$14.27 billion. That's how much crypto has lost to hacks and exploits since 2016, according to CoinGecko's latest data.
The trend line tells its own story:
• 2016: around $60M
• 2021: $2.66B
• 2022: $2.77B (still the worst year on record)
• 2025: $2.55B
• 2026 so far: $1.2B across 164 incidents, already more incidents than any full year before it
Security tooling has genuinely improved over the years. Audits are standard now, bug bounties are common, monitoring is faster. But the losses haven't gone away, they've just changed shape. It's not always a shady protocol or an obvious rug pull. A lot of the damage comes from smart contract bugs, leaked private keys, phishing links, bridge exploits, or just someone getting socially engineered into signing the wrong thing.
That's really the takeaway for anyone using this space day to day:
🔐 Don't assume a protocol is safe just because it's popular
🧪 Actually look into what you're interacting with before connecting your wallet
🚨 Slow down on approvals and signature requests, most people lose funds here without realizing what they signed
💰 Keep your hot wallet light. If you don't need it liquid right now, it shouldn't be sitting there
Self-custody is the whole point of crypto, but it also means the security burden sits with you, not an exchange or a bank.
Curious what people think: which is the bigger risk right now, smart contract bugs or human error? From the incident data, it's looking more and more like the human side.

Source: CoinGecko

#Crypto #CryptoSecurity #CryptoHacks #Web3 #Blockchain
💥 HARMONY PROTOCOL EXPLOITED: 4 BILLION $ONE PRINTED OUT OF THIN AIR 💥 The nightmare scenario just played out for Harmony Protocol ($ONE) in a massive on-chain exploit. 🚨 The Breakdown: The Glitch: Attacker exploited an empty-blocks vulnerability to bypass minting checks. The Damage: ~4 Billion $ONE minted instantly—inflating the supply by a staggering 26%. The Dump: Over 2.8 Billion tokens (~97%) were immediately funneled straight into exchanges to cash out. The Cover-up: A flaw in Harmony's totalSupply endpoint masked the inflation, blinding traders until the market crashed. 📉 Chart Impact: The immediate supply shock caused a brutal ~40% market capitulation. The attached Binance chart shows a horrific flush down to 0.000580, wiping out millions in market cap before catching a fragile, partial bounce up to 0.000777. 🛠️ What's Next? Harmony has paused its cross-chain bridge and deployed an emergency validator patch to stop further minting. However, with the vast majority of tokens already inside exchange deposit wallets, the team is actively discussing a hard blockchain rollback to erase the hacker's history. Can the ecosystem recover from back-to-back structural exploits, or is this the final nail in the coffin? 👇 #HarmonyONE #CryptoHacks #BinanceSquare #BlockchainSecurity #ONE
💥 HARMONY PROTOCOL EXPLOITED: 4 BILLION $ONE PRINTED OUT OF THIN AIR 💥

The nightmare scenario just played out for Harmony Protocol ($ONE) in a massive on-chain exploit.

🚨 The Breakdown:

The Glitch: Attacker exploited an empty-blocks vulnerability to bypass minting checks.

The Damage: ~4 Billion $ONE minted instantly—inflating the supply by a staggering 26%.

The Dump: Over 2.8 Billion tokens (~97%) were immediately funneled straight into exchanges to cash out.

The Cover-up: A flaw in Harmony's totalSupply endpoint masked the inflation, blinding traders until the market crashed.

📉 Chart Impact:
The immediate supply shock caused a brutal ~40% market capitulation. The attached Binance chart shows a horrific flush down to 0.000580, wiping out millions in market cap before catching a fragile, partial bounce up to 0.000777.

🛠️ What's Next?
Harmony has paused its cross-chain bridge and deployed an emergency validator patch to stop further minting. However, with the vast majority of tokens already inside exchange deposit wallets, the team is actively discussing a hard blockchain rollback to erase the hacker's history.

Can the ecosystem recover from back-to-back structural exploits, or is this the final nail in the coffin? 👇

#HarmonyONE #CryptoHacks #BinanceSquare #BlockchainSecurity #ONE
🚨 $BTC AND THE $10B HOLE HACKERS BURNED IN 12 YEARS 💣 📊 Sixteen figures of digital gold drained since 2012 — this isn't a market dip, it's a war on weak custody. Every major exploit rewires trust in the entire ecosystem, and $BTC catches the emotional shockwave first. 🦈 Hackers move like sharks, circling bridge contracts and hot wallets, waiting for one sloppy key to slip. The antidote was never panic — it's cold storage and ruthless operational hygiene. 💡 Hold your own keys and you starve the predators. Leave funds on exchanges and you're just renting exposure with extra steps. 🛡️ Someone is always testing your weakest link. 💬 Which wallet or bridge have you stopped trusting after the last attack? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #BTC #CryptoHacks #SelfCustody #Security #RiskManagement 🛡️ 💎
🚨 $BTC AND THE $10B HOLE HACKERS BURNED IN 12 YEARS 💣

📊 Sixteen figures of digital gold drained since 2012 — this isn't a market dip, it's a war on weak custody. Every major exploit rewires trust in the entire ecosystem, and $BTC catches the emotional shockwave first. 🦈 Hackers move like sharks, circling bridge contracts and hot wallets, waiting for one sloppy key to slip.

The antidote was never panic — it's cold storage and ruthless operational hygiene. 💡 Hold your own keys and you starve the predators. Leave funds on exchanges and you're just renting exposure with extra steps. 🛡️ Someone is always testing your weakest link.

💬 Which wallet or bridge have you stopped trusting after the last attack? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #BTC #CryptoHacks #SelfCustody #Security #RiskManagement

🛡️ 💎
🚨 $ETH HACK LOSSES SURPASS $1.1B IN H1 2026 – BIGGEST EVER! 💥 The on-chain security landscape just posted a brutal half-year record. Over $1.1B stolen across 212 incidents – with North Korean-linked actors responsible for 55% of the damage. 📊 This isn't just a tech problem; it's a liquidity confidence issue that directly impacts institutional capital flows into DeFi and smart contract platforms. Four mega-exploits accounted for 64% of total losses, including KelpDAO ($292M) and Drift Protocol ($285M). Fresh attack vectors like EIP-7702 delegation abuse signal that infrastructure sophistication is outpacing defense. 💡 If top-tier chains can't contain social engineering at the validator layer, the entire risk premium for holding tokens on those networks must be repriced. 💬 How do you assess the risk in your portfolio exposure to chains with high exploit history? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #ETH #CryptoHacks #Security #DeFi #OnChain 🛡️ 🚨
🚨 $ETH HACK LOSSES SURPASS $1.1B IN H1 2026 – BIGGEST EVER! 💥

The on-chain security landscape just posted a brutal half-year record. Over $1.1B stolen across 212 incidents – with North Korean-linked actors responsible for 55% of the damage. 📊 This isn't just a tech problem; it's a liquidity confidence issue that directly impacts institutional capital flows into DeFi and smart contract platforms.

Four mega-exploits accounted for 64% of total losses, including KelpDAO ($292M) and Drift Protocol ($285M). Fresh attack vectors like EIP-7702 delegation abuse signal that infrastructure sophistication is outpacing defense. 💡 If top-tier chains can't contain social engineering at the validator layer, the entire risk premium for holding tokens on those networks must be repriced. 💬 How do you assess the risk in your portfolio exposure to chains with high exploit history? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #ETH #CryptoHacks #Security #DeFi #OnChain

🛡️ 🚨
🚨 $ETH & $SOL UNDER SIEGE – $1B+ LOST TO HACKS IN RECORD FIRST HALF 💥 The half-year tally just crossed $1 billion in verified crypto losses, with North Korea-linked groups bagging nearly $600 million. That’s the highest incident count on record. 🔴 Social engineering and compromised multisigs are the new attack vectors, not just smart-contract flaws. Ethereum bled $332 million to large-scale exploits; Solana lost $326 million through signer infrastructure breaches. 📊 This isn’t just a security headline—it’s institutional friction that siphons liquidity and shakes confidence in settlement layers. Smart money is watching which chains respond with stronger forensic tools first. 💡 The second half carries fresh risk: AI-agent credential theft. If prompt injection or unauthorized signing goes mainstream, the attack surface expands exponentially. 💬 Are you factoring exploit probability into your capital allocation, or just chasing volume? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #ETH #Solana #CryptoHacks #Security #RiskManagement 🦈 ⚡
🚨 $ETH & $SOL UNDER SIEGE – $1B+ LOST TO HACKS IN RECORD FIRST HALF 💥

The half-year tally just crossed $1 billion in verified crypto losses, with North Korea-linked groups bagging nearly $600 million. That’s the highest incident count on record. 🔴 Social engineering and compromised multisigs are the new attack vectors, not just smart-contract flaws.

Ethereum bled $332 million to large-scale exploits; Solana lost $326 million through signer infrastructure breaches. 📊 This isn’t just a security headline—it’s institutional friction that siphons liquidity and shakes confidence in settlement layers. Smart money is watching which chains respond with stronger forensic tools first.

💡 The second half carries fresh risk: AI-agent credential theft. If prompt injection or unauthorized signing goes mainstream, the attack surface expands exponentially. 💬 Are you factoring exploit probability into your capital allocation, or just chasing volume? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #ETH #Solana #CryptoHacks #Security #RiskManagement

🦈 ⚡
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number