Binance Square
#cryptohacks

cryptohacks

1.2M views
792 Discussing
Crypto With Faisal
·
--
#sandboxsandsuspectedinfinitemintflawonbase ​🚨 CRITICAL SMART CONTRACT FLAW ON BASE! 🚨 ​A massive infinite mint exploit just hit the market. Over 500 MILLION SAND tokens were printed out of thin air due to a severe smart contract loophole on the Base network. ​Market conditions are tough enough without dealing with broken code flooding the supply! ​Immediate Action Plan for Traders: ​🛑 Step Away from SAND: Do not try to catch this falling knife. Buying the dip right now is incredibly risky. ​🛡️ Review Your Exposure: Double-check your portfolio's exposure to other assets on the Base network just to be safe. ​📢 Await Official Updates: Keep an eye out for a formal announcement and post-mortem from The Sandbox team. ​Developers need to prioritize auditing their code so we can trade in peace. Stay safe out there! ​⚠️ Disclaimer: Always do your own research. This is not financial advice. ​ #cryptohacks #SmartContractExploit CLICK below 👇 TO TRADE $SOL $TRB $DASH {future}(DASHUSDT) {future}(SOLUSDT) {future}(TRBUSDT)
#sandboxsandsuspectedinfinitemintflawonbase
​🚨 CRITICAL SMART CONTRACT FLAW ON BASE! 🚨

​A massive infinite mint exploit just hit the market. Over 500 MILLION SAND tokens were printed out of thin air due to a severe smart contract loophole on the Base network.

​Market conditions are tough enough without dealing with broken code flooding the supply!

​Immediate Action Plan for Traders:

​🛑 Step Away from SAND: Do not try to catch this falling knife. Buying the dip right now is incredibly risky.

​🛡️ Review Your Exposure: Double-check your portfolio's exposure to other assets on the Base network just to be safe.

​📢 Await Official Updates: Keep an eye out for a formal announcement and post-mortem from The Sandbox team.

​Developers need to prioritize auditing their code so we can trade in peace. Stay safe out there!

​⚠️ Disclaimer: Always do your own research. This is not financial advice.

#cryptohacks #SmartContractExploit
CLICK below 👇 TO TRADE

$SOL $TRB $DASH
#sandboxsandsuspectedinfinitemintflawonbase Can someone check the developers?! 🤦‍♂️ Seriously, being a trader is already hard enough with the usual market crashes, but now we have to deal with endless mint exploits? More than 500M SAND were printed as if from nothing on the Base network due to a vulnerability in a smart contract. Total nightmare! What should traders do now? 🛑 Avoid grabbing a falling knife—don’t try to buy SAND for now. 🚨 Monitor the situation for an official response from The Sandbox team. 🛡️ Make sure to re-check whether any of your assets on the Base network were exposed. We’re just trying to trade safely—please fix the code next time! ⚠️ This is not financial advice! Stay safe and trade on a secure platform. Update, please #cryptohacks #SmartContractExploit #sand $BTC {future}(BTCUSDT)
#sandboxsandsuspectedinfinitemintflawonbase
Can someone check the developers?! 🤦‍♂️ Seriously, being a trader is already hard enough with the usual market crashes, but now we have to deal with endless mint exploits? More than 500M SAND were printed as if from nothing on the Base network due to a vulnerability in a smart contract. Total nightmare!
What should traders do now?
🛑 Avoid grabbing a falling knife—don’t try to buy SAND for now.
🚨 Monitor the situation for an official response from The Sandbox team.
🛡️ Make sure to re-check whether any of your assets on the Base network were exposed.
We’re just trying to trade safely—please fix the code next time!
⚠️ This is not financial advice!
Stay safe and trade on a secure platform.

Update, please

#cryptohacks #SmartContractExploit #sand
$BTC
Article
The 2025 Crypto Theft Number Nobody Can Agree OnFour trackers, one year, and a $1.1 billion gap: nobody in crypto security agrees on how much was actually stolen in 2025. Start with the number that isn't in dispute. In February 2025, North Korea's Lazarus Group breached Bybit's cold wallet infrastructure and moved out roughly $1.5 billion in ETH — the largest crypto theft in history. The FBI's IC3 advisory confirms $1.5 billion as the official figure. Chainalysis, in its own year-end report, cites the same number for the same incident. On this one fact, every serious tracker lines up. Then the agreement stops. Ask "how much crypto was stolen across all of 2025" and you get four different answers from four trackers the industry treats as interchangeable: Chainalysis: $3.4 billion CertiK: $3.35 billion PeckShield: $4.04 billion SlowMist: $2.935 billion That's a spread of roughly $1.1 billion — about 37% of the smallest figure — between organizations whose entire job is counting this precisely. None of them has published a correction against the others. None has reconciled the gap. Press coverage, exchange risk disclosures, and even policy testimony cite whichever number happens to be on hand, as if $2.9 billion and $4 billion were the same fact stated two ways. They aren't. They're four different measurements of four different things, wearing the same headline. Why the numbers diverge The gap isn't sloppiness — it's scope, and each tracker draws the line somewhere different. Hacks versus scams. Chainalysis and CertiK lean toward counting technical exploits and breaches — code vulnerabilities, private key compromises, bridge attacks. PeckShield's wider $4.04 billion figure folds in a broader category that includes scams and rug pulls alongside hacks, which mechanically produces a bigger number without necessarily meaning more theft occurred by any narrower definition. CEX versus DeFi coverage. Some trackers weight centralized-exchange incidents (like Bybit) heavily because they're large, discrete, and easy to verify. Others build up their totals more from the long tail of smaller DeFi protocol exploits, which are numerous but individually harder to confirm and value precisely at the moment of the exploit. Gross loss versus net-of-recovered. A theft followed by a partial white-hat recovery, a negotiated return, or a law-enforcement clawback can get counted at the original gross figure by one tracker and at the net remaining loss by another. Same incident, two legitimate-looking numbers. Estimation methodology for the long tail. The handful of nine-figure incidents like Bybit are easy to nail down. The hundreds of smaller five- and six-figure DeFi exploits that make up the rest of the total are where trackers genuinely have to estimate, sample, and extrapolate — and small methodological choices compound across hundreds of incidents into a real aggregate difference. None of these choices is dishonest. Each is a defensible way to define "theft." The problem is that nobody discloses which definition they're using when the number gets forwarded, and by the time a figure reaches a press release or a Senate hearing, it's just "crypto theft in 2025: $X billion" — full stop, no methodology attached. Why it actually matters This isn't pedantry. These figures get used as inputs to real decisions. Institutional risk models cite whichever total makes crypto custody look safer or riskier depending on which side of a deal is doing the citing. Insurance underwriters pricing crypto-custody coverage need a real loss-rate denominator, and a 37% swing in the numerator changes the math on what a policy should cost. Regulatory testimony treats "crypto lost $X billion to theft this year" as a settled fact justifying a specific policy response, without anyone asking the questioner which tracker's methodology they're citing — or whether "worse than last year" and "better than last year" are both true depending on which one you pick. The framing effect is real too. A reporter or a policy staffer reaching for the biggest available number gets a "worst year on record" story; reaching for the smallest gets "crypto security is improving." Both headlines can run in the same week, sourced to different trackers, describing the same year. The falsifiable test Here's a way to watch whether this actually gets fixed rather than staying a permanent asterisk: has any tracker published a reconciliation methodology — a public breakdown of what they include and exclude, cross-walked against a competitor's figure, so a reader could convert between them? As of this writing, no. If one appears, that's a real sign the industry is treating this number as infrastructure rather than a headline generator. If the same four incompatible totals get recycled into next year's "state of crypto security" report with no cross-walk, that's the tell that nobody who cites these numbers actually needs them to be precise — just big. The Bybit number holds up because it's one incident, independently confirmed by a federal agency, with a clean chain of custody on the facts. The annual aggregate doesn't hold up the same way, because it was never one measurement to begin with — it's four different ones, laundered through a shared headline until they look like consensus. Which of these four numbers have you seen cited as "the" 2025 total — and did the source say which tracker it came from? Not financial advice. DYOR. $ETH #CryptoSecurity #DataIntegrity #Chainalysis #CryptoHacks

The 2025 Crypto Theft Number Nobody Can Agree On

Four trackers, one year, and a $1.1 billion gap: nobody in crypto security agrees on how much was actually stolen in 2025.
Start with the number that isn't in dispute. In February 2025, North Korea's Lazarus Group breached Bybit's cold wallet infrastructure and moved out roughly $1.5 billion in ETH — the largest crypto theft in history. The FBI's IC3 advisory confirms $1.5 billion as the official figure. Chainalysis, in its own year-end report, cites the same number for the same incident. On this one fact, every serious tracker lines up.
Then the agreement stops. Ask "how much crypto was stolen across all of 2025" and you get four different answers from four trackers the industry treats as interchangeable:
Chainalysis: $3.4 billion
CertiK: $3.35 billion
PeckShield: $4.04 billion
SlowMist: $2.935 billion
That's a spread of roughly $1.1 billion — about 37% of the smallest figure — between organizations whose entire job is counting this precisely. None of them has published a correction against the others. None has reconciled the gap. Press coverage, exchange risk disclosures, and even policy testimony cite whichever number happens to be on hand, as if $2.9 billion and $4 billion were the same fact stated two ways.
They aren't. They're four different measurements of four different things, wearing the same headline.
Why the numbers diverge
The gap isn't sloppiness — it's scope, and each tracker draws the line somewhere different.
Hacks versus scams. Chainalysis and CertiK lean toward counting technical exploits and breaches — code vulnerabilities, private key compromises, bridge attacks. PeckShield's wider $4.04 billion figure folds in a broader category that includes scams and rug pulls alongside hacks, which mechanically produces a bigger number without necessarily meaning more theft occurred by any narrower definition.
CEX versus DeFi coverage. Some trackers weight centralized-exchange incidents (like Bybit) heavily because they're large, discrete, and easy to verify. Others build up their totals more from the long tail of smaller DeFi protocol exploits, which are numerous but individually harder to confirm and value precisely at the moment of the exploit.
Gross loss versus net-of-recovered. A theft followed by a partial white-hat recovery, a negotiated return, or a law-enforcement clawback can get counted at the original gross figure by one tracker and at the net remaining loss by another. Same incident, two legitimate-looking numbers.
Estimation methodology for the long tail. The handful of nine-figure incidents like Bybit are easy to nail down. The hundreds of smaller five- and six-figure DeFi exploits that make up the rest of the total are where trackers genuinely have to estimate, sample, and extrapolate — and small methodological choices compound across hundreds of incidents into a real aggregate difference.
None of these choices is dishonest. Each is a defensible way to define "theft." The problem is that nobody discloses which definition they're using when the number gets forwarded, and by the time a figure reaches a press release or a Senate hearing, it's just "crypto theft in 2025: $X billion" — full stop, no methodology attached.
Why it actually matters
This isn't pedantry. These figures get used as inputs to real decisions.
Institutional risk models cite whichever total makes crypto custody look safer or riskier depending on which side of a deal is doing the citing. Insurance underwriters pricing crypto-custody coverage need a real loss-rate denominator, and a 37% swing in the numerator changes the math on what a policy should cost. Regulatory testimony treats "crypto lost $X billion to theft this year" as a settled fact justifying a specific policy response, without anyone asking the questioner which tracker's methodology they're citing — or whether "worse than last year" and "better than last year" are both true depending on which one you pick.
The framing effect is real too. A reporter or a policy staffer reaching for the biggest available number gets a "worst year on record" story; reaching for the smallest gets "crypto security is improving." Both headlines can run in the same week, sourced to different trackers, describing the same year.
The falsifiable test
Here's a way to watch whether this actually gets fixed rather than staying a permanent asterisk: has any tracker published a reconciliation methodology — a public breakdown of what they include and exclude, cross-walked against a competitor's figure, so a reader could convert between them? As of this writing, no. If one appears, that's a real sign the industry is treating this number as infrastructure rather than a headline generator. If the same four incompatible totals get recycled into next year's "state of crypto security" report with no cross-walk, that's the tell that nobody who cites these numbers actually needs them to be precise — just big.
The Bybit number holds up because it's one incident, independently confirmed by a federal agency, with a clean chain of custody on the facts. The annual aggregate doesn't hold up the same way, because it was never one measurement to begin with — it's four different ones, laundered through a shared headline until they look like consensus.
Which of these four numbers have you seen cited as "the" 2025 total — and did the source say which tracker it came from?
Not financial advice. DYOR.
$ETH #CryptoSecurity #DataIntegrity #Chainalysis #CryptoHacks
🚨 $11 BILLION WIPED OUT IN 6 MONTHS – THE BIGGEST HACK WAVE IN CRYPTO HISTORY 💥 Over 212 on-chain exploits this year alone, with North Korea-linked groups pocketing 55% of total losses. The real story isn't just the numbers – it's how they're executing these hits. 🔍 The top 4 attacks (KelpDAO, Drift Protocol, Resolv, CowSwap) accounted for 64% of all damage, and none were simple code bugs. Attackers compromised developer credentials, manipulated RPC infrastructure, and exploited single-point validator setups. Even LinkedIn recruitment scams are being weaponized to steal admin keys. 📊 Ethereum still leads in absolute losses ($332M), but Solana is now #2 – with 98% of its $326M coming from compromised private keys and signature infrastructure. Meanwhile, Arbitrum saw the first-ever exploit using EIP-7702 wallet delegation. The attack surface is expanding faster than most traders realize. 💬 If you're holding assets on any chain, what's your single biggest vulnerability right now? Is it the protocol, the bridge, or your own key management? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #CryptoHacks #ETH #SOL #DeFi #Security 🛡️ 🔍
🚨 $11 BILLION WIPED OUT IN 6 MONTHS – THE BIGGEST HACK WAVE IN CRYPTO HISTORY 💥

Over 212 on-chain exploits this year alone, with North Korea-linked groups pocketing 55% of total losses. The real story isn't just the numbers – it's how they're executing these hits.

🔍 The top 4 attacks (KelpDAO, Drift Protocol, Resolv, CowSwap) accounted for 64% of all damage, and none were simple code bugs. Attackers compromised developer credentials, manipulated RPC infrastructure, and exploited single-point validator setups. Even LinkedIn recruitment scams are being weaponized to steal admin keys.

📊 Ethereum still leads in absolute losses ($332M), but Solana is now #2 – with 98% of its $326M coming from compromised private keys and signature infrastructure. Meanwhile, Arbitrum saw the first-ever exploit using EIP-7702 wallet delegation. The attack surface is expanding faster than most traders realize.

💬 If you're holding assets on any chain, what's your single biggest vulnerability right now? Is it the protocol, the bridge, or your own key management? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #CryptoHacks #ETH #SOL #DeFi #Security

🛡️ 🔍
·
--
$1 Billion down the drain: Cryptocurrency hacks hit a record high in H1 2026, outpacing losses by a staggering 100% YoY. In the first half of 2026, the sector saw its worst start to a year since 2018, with total losses surpassing a breathtaking $1 Billion. Ethereum and Solana projects bore the brunt, losing $332 million and $326 million, respectively - a stark reminder that security still haunts even the biggest players in the crypto space #cryptoHacks, #decentralizedSecurity, #cryptocurrencyRegulations. Smart money is taking notice: on-chain transactions on Ethereum have plummeted as whales and institutions scramble to cover their losses. Expect a ripple effect across larger projects as investors reevaluate risk and seek safer havens #cryptoRiskOn. The forward signal is clear: if security continues to be a major concern, expect a flight to safety towards assets with robust infrastructure and a track record of strong security practices. Stay vigilant and watch for the first signs of mass capitulation #cryptoRiskOff. Will this record number of hacks be the wake-up call the crypto sector needs to prioritize security above profits?
$1 Billion down the drain: Cryptocurrency hacks hit a record high in H1 2026, outpacing losses by a staggering 100% YoY.

In the first half of 2026, the sector saw its worst start to a year since 2018, with total losses surpassing a breathtaking $1 Billion. Ethereum and Solana projects bore the brunt, losing $332 million and $326 million, respectively - a stark reminder that security still haunts even the biggest players in the crypto space #cryptoHacks, #decentralizedSecurity, #cryptocurrencyRegulations.

Smart money is taking notice: on-chain transactions on Ethereum have plummeted as whales and institutions scramble to cover their losses. Expect a ripple effect across larger projects as investors reevaluate risk and seek safer havens #cryptoRiskOn.

The forward signal is clear: if security continues to be a major concern, expect a flight to safety towards assets with robust infrastructure and a track record of strong security practices. Stay vigilant and watch for the first signs of mass capitulation #cryptoRiskOff.

Will this record number of hacks be the wake-up call the crypto sector needs to prioritize security above profits?
$BTC AND $ETH TANKING AS HACKS HIT RECORD HIGH IN 2026 🔥 207 hacks in six months — that's the highest ever. North Korea-linked groups took 66% of the $972 million stolen, with two exploits alone draining $577 million from KelpDAO and Drift Protocol. Smart contracts aren't the only weak spot. Infrastructure failures caused 76% of losses despite only 15% of incidents. TVL in DeFi dropped from $115B to $70B in the same period. Bitcoin down 28%, ETH down 40%. That kind of pressure shakes out weak hands fast. Are you staying long or stepping aside? Not financial advice. Always manage your risk. #BTC #Ethereum #CryptoHacks #MarketCrash 🔥
$BTC AND $ETH TANKING AS HACKS HIT RECORD HIGH IN 2026 🔥

207 hacks in six months — that's the highest ever. North Korea-linked groups took 66% of the $972 million stolen, with two exploits alone draining $577 million from KelpDAO and Drift Protocol.

Smart contracts aren't the only weak spot. Infrastructure failures caused 76% of losses despite only 15% of incidents. TVL in DeFi dropped from $115B to $70B in the same period.

Bitcoin down 28%, ETH down 40%. That kind of pressure shakes out weak hands fast. Are you staying long or stepping aside?

Not financial advice. Always manage your risk.

#BTC #Ethereum #CryptoHacks #MarketCrash

🔥
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️ North Korean hackers just dropped some of the biggest exploits this year: Drift Protocol → $285M Kelp DAO → $292M Their Dirty Tactics: Fake job offers & deepfake calls 😈 Malware on dev laptops to steal keys Bridge exploits & fake collateral plays They plan attacks for months... super patient & dangerous. Stay Safe Kings: Hardware wallet only Never share seed/private keys Double-check every link & file Projects need better security ASAP! You teaming up against Lazarus or still clicking random links? 😂👇 #Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
💥 Lazarus Group is Cooking Crypto in 2026 ⚠️
North Korean hackers just dropped some of the biggest exploits this year:
Drift Protocol → $285M
Kelp DAO → $292M
Their Dirty Tactics:
Fake job offers & deepfake calls 😈
Malware on dev laptops to steal keys
Bridge exploits & fake collateral plays
They plan attacks for months... super patient & dangerous.
Stay Safe Kings:
Hardware wallet only
Never share seed/private keys
Double-check every link & file
Projects need better security ASAP!
You teaming up against Lazarus or still clicking random links? 😂👇

#Lazarus #cryptohacks #CryptoSecurity #BinanceSquare
Verified
🚨 HACKER GOT AIRDROP INSTEAD OF TOKEN HOLDERS — HOW IS THIS EVEN POSSIBLE? The #Superfortune team somehow sent an airdrop… straight into the hacker's pocket. No joke. During a multisig transaction, the attacker somehow swapped the recipient address. As a result, the #GUA tokens flew to the hacker's wallet 0x70ae67…5c15 — instead of the official airdrop contract 0x70ae7d…5c15. The difference between the addresses is just a few characters in the middle. That was all it took. Interestingly, the team rules out the classic address poisoning scheme — since the hacker's address had never interacted with the project's infrastructure before the incident. This suggests that the attack vector was different, and likely more sophisticated — possibly the compromise of one of the signers or a swap at the interface level. The market reacted instantly: 📉 $GUA — down 75% in 24 hours Another reminder: even multisig isn't a cure-all if there's a weak link in the signature chain. Always verify addresses byte by byte, not just visually. #cryptohacks #Airdrop #Web3Security #defi If you find this content useful — subscribe, I regularly break down high-profile incidents and discoveries from the crypto world 🔔
🚨 HACKER GOT AIRDROP INSTEAD OF TOKEN HOLDERS — HOW IS THIS EVEN POSSIBLE?

The #Superfortune team somehow sent an airdrop… straight into the hacker's pocket. No joke.

During a multisig transaction, the attacker somehow swapped the recipient address. As a result, the #GUA tokens flew to the hacker's wallet 0x70ae67…5c15 — instead of the official airdrop contract 0x70ae7d…5c15. The difference between the addresses is just a few characters in the middle. That was all it took.

Interestingly, the team rules out the classic address poisoning scheme — since the hacker's address had never interacted with the project's infrastructure before the incident. This suggests that the attack vector was different, and likely more sophisticated — possibly the compromise of one of the signers or a swap at the interface level.

The market reacted instantly:
📉 $GUA — down 75% in 24 hours

Another reminder: even multisig isn't a cure-all if there's a weak link in the signature chain. Always verify addresses byte by byte, not just visually.

#cryptohacks #Airdrop #Web3Security #defi

If you find this content useful — subscribe, I regularly break down high-profile incidents and discoveries from the crypto world 🔔
·
--
Bullish
In 2026, the amount stolen in DeFi exceeded $750 million. I checked the list of victims, and several were audited projects. Many people think that having an audit report means safety, but the data from 2026 says the opposite: Kelp DAO was hacked for $293 million, making it the largest single incident this year, and it was exploited through a bridge contract vulnerability; Silo V2 was manipulated by an oracle, also after an audit. An audit isn't a safety net, so what’s the real meaning of an audit? 🤔 【I checked four auditing firms on Genius Terminal】 Halborn, Cantina, HackenProof, and Borg Research, each with their own focus in the industry. Halborn has audited over 200 blockchain projects, primarily focusing on smart contracts and infrastructure vulnerabilities; Cantina is known for competitive audits, where multiple independent researchers challenge the same code simultaneously; HackenProof specializes in bug bounty management and penetration testing; Borg Research leans towards the foundational verification of cryptographic protocols. I think the interesting part of this combination isn’t the number, but the coverage. A single auditing firm’s perspective has blind spots, while the four firms approach it from different angles, theoretically reducing overlooked attack surfaces. 【What’s the essence of an audit】 Personally, I believe the four auditing firms don’t provide a guarantee of "won’t be hacked," but rather a signal: this team is willing to spend money to have outsiders point out issues, and not just once. Industry audit fees range from $25,000 to $200,000, while a successful attack in DeFi can result in losses from $5 million to hundreds of millions. When you calculate this ratio, the cost of auditing multiple times is entirely reasonable. "The quantity of security audits doesn’t represent safety, but it does reflect the project team’s attitude towards risk." 【The significance of $GENIUS 】🔑 After Ghost Orders go on-chain, Genius Terminal’s privacy trading feature can truly take off, allowing users to execute large trades on the platform. High trading volumes support the platform's GMV, and the token holders’ $USDC recommended returns have a sustainable foundation. Security isn’t just a bonus; it’s the premise of the whole flywheel. @GeniusOfficial $GENIUS #genius #defi #cryptohacks
In 2026, the amount stolen in DeFi exceeded $750 million. I checked the list of victims, and several were audited projects. Many people think that having an audit report means safety, but the data from 2026 says the opposite: Kelp DAO was hacked for $293 million, making it the largest single incident this year, and it was exploited through a bridge contract vulnerability; Silo V2 was manipulated by an oracle, also after an audit.

An audit isn't a safety net, so what’s the real meaning of an audit? 🤔

【I checked four auditing firms on Genius Terminal】
Halborn, Cantina, HackenProof, and Borg Research, each with their own focus in the industry. Halborn has audited over 200 blockchain projects, primarily focusing on smart contracts and infrastructure vulnerabilities; Cantina is known for competitive audits, where multiple independent researchers challenge the same code simultaneously; HackenProof specializes in bug bounty management and penetration testing; Borg Research leans towards the foundational verification of cryptographic protocols.
I think the interesting part of this combination isn’t the number, but the coverage. A single auditing firm’s perspective has blind spots, while the four firms approach it from different angles, theoretically reducing overlooked attack surfaces.

【What’s the essence of an audit】
Personally, I believe the four auditing firms don’t provide a guarantee of "won’t be hacked," but rather a signal: this team is willing to spend money to have outsiders point out issues, and not just once. Industry audit fees range from $25,000 to $200,000, while a successful attack in DeFi can result in losses from $5 million to hundreds of millions. When you calculate this ratio, the cost of auditing multiple times is entirely reasonable.
"The quantity of security audits doesn’t represent safety, but it does reflect the project team’s attitude towards risk."

【The significance of $GENIUS 】🔑
After Ghost Orders go on-chain, Genius Terminal’s privacy trading feature can truly take off, allowing users to execute large trades on the platform. High trading volumes support the platform's GMV, and the token holders’ $USDC recommended returns have a sustainable foundation. Security isn’t just a bonus; it’s the premise of the whole flywheel.

@GeniusOfficial $GENIUS #genius #defi #cryptohacks
$ETH INCIDENT EXPOSES DEEP VULNERABILITY IN MEV BOTS 🚨 The recent hack of Jaredfromsubway.eth, a prominent MEV bot on the Ethereum network, has revealed a significant vulnerability in automated execution systems, resulting in a loss of over $7.5 million. This incident highlights the importance of robust security measures in the crypto space. The attack involved the deployment of 66 fake token contracts and liquidity pools, mimicking assets such as $WETH , $USDC , and $USDT , which enticed the bot to execute malicious transactions. This level of sophistication and deception is a wake-up call for the entire crypto community, are you increasing your security measures in response to this incident? Not financial advice. Manage your risk. #EthereumNews #MEVBotSecurity #CryptoHacks 💸
$ETH INCIDENT EXPOSES DEEP VULNERABILITY IN MEV BOTS 🚨

The recent hack of Jaredfromsubway.eth, a prominent MEV bot on the Ethereum network, has revealed a significant vulnerability in automated execution systems, resulting in a loss of over $7.5 million. This incident highlights the importance of robust security measures in the crypto space.

The attack involved the deployment of 66 fake token contracts and liquidity pools, mimicking assets such as $WETH , $USDC , and $USDT , which enticed the bot to execute malicious transactions. This level of sophistication and deception is a wake-up call for the entire crypto community, are you increasing your security measures in response to this incident?

Not financial advice. Manage your risk.

#EthereumNews #MEVBotSecurity #CryptoHacks
💸
·
--
EXPLOITED Gnosis Pay just dropped a bombshell revealing a software flaw dating back to October 2023 that enabled the $1.5 million exploit of its card safe infrastructure #GnosisPay #CryptoHacks #SecurityMatters. According to a postmortem, the vulnerability was discovered after the exploit occurred and thankfully all affected users have been fully reimbursed. This historic hack serves as a reminder that the crypto landscape is a cat-and-mouse game where security is paramount. The implications are clear: if you haven't tightened the screws on security measures yet, it's time to do so, not just for yourself, but for your fellow holders too. Will you adapt before it's too late?
EXPLOITED

Gnosis Pay just dropped a bombshell revealing a software flaw dating back to October 2023 that enabled the $1.5 million exploit of its card safe infrastructure #GnosisPay #CryptoHacks #SecurityMatters. According to a postmortem, the vulnerability was discovered after the exploit occurred and thankfully all affected users have been fully reimbursed. This historic hack serves as a reminder that the crypto landscape is a cat-and-mouse game where security is paramount. The implications are clear: if you haven't tightened the screws on security measures yet, it's time to do so, not just for yourself, but for your fellow holders too. Will you adapt before it's too late?
🔓 RAYDIUM HACKED FOR $1.34 MILLION — THROUGH CONTRACTS THAT HAVE BEEN AROUND FOR 3 YEARS No need to panic — but it’s worth understanding. It wasn’t the exchange itself that got hacked, but the legacy AMM V3 — five outdated liquidity pools that were deprecated back in 2021 after the demise of #Serum. No active interface, no current users. Just dead contracts that were completely forgotten. What leaked: — ~150,000 #RAY tokens — 5,600 #SOL — ~893,000 #USDC How it happened: The hacker created a fake LP mint and bypassed the security checks during the withdrawal. The vulnerability isn’t in fresh code, but in the logic from three years ago that nobody got around to fixing. The good news: #Raydium stated that they will cover the losses of the affected users from their treasury. Current CLMM pools and new versions of the AMM are unaffected — continuing to operate as usual. This is a perfect illustration of one of the main problems in DeFi: new contracts get audited and patched, while old ones are forgotten. Teams move ahead, Legacy hangs in the background for years. Hackers aren’t in a rush — they just wait until everyone forgets there’s anything there at all. $1.34 million for a three-year vulnerability — a costly reminder about digital hygiene. #raydium #solana #defi #cryptohacks Subscribe🤝
🔓 RAYDIUM HACKED FOR $1.34 MILLION — THROUGH CONTRACTS THAT HAVE BEEN AROUND FOR 3 YEARS

No need to panic — but it’s worth understanding.

It wasn’t the exchange itself that got hacked, but the legacy AMM V3 — five outdated liquidity pools that were deprecated back in 2021 after the demise of #Serum. No active interface, no current users. Just dead contracts that were completely forgotten.

What leaked:
— ~150,000 #RAY tokens
— 5,600 #SOL
— ~893,000 #USDC

How it happened:

The hacker created a fake LP mint and bypassed the security checks during the withdrawal. The vulnerability isn’t in fresh code, but in the logic from three years ago that nobody got around to fixing.

The good news:

#Raydium stated that they will cover the losses of the affected users from their treasury. Current CLMM pools and new versions of the AMM are unaffected — continuing to operate as usual.

This is a perfect illustration of one of the main problems in DeFi: new contracts get audited and patched, while old ones are forgotten. Teams move ahead, Legacy hangs in the background for years. Hackers aren’t in a rush — they just wait until everyone forgets there’s anything there at all.

$1.34 million for a three-year vulnerability — a costly reminder about digital hygiene.

#raydium #solana #defi #cryptohacks

Subscribe🤝
·
--
Bullish
🚨 **$H PUMPING 44%... BUT IS IT A MASSIVE BULL TRAP?!** 🚨 Everyone is celebrating because Humanity Protocol ($H) just pumped 44% after the team dropped their breach report and teased a compensation plan for the victims. But do NOT let this relief rally fool you—this is screaming danger! 🛑 Here is what the hype boys are ignoring: 1️⃣ **The Breach Was Brutal:** A single malware-infected developer laptop gave the attacker 7 private keys, allowing them to steal and maliciously mint a staggering **447 MILLION $H tokens**. 2️⃣ **THE HACKER STILL HAS CONTROL!** Yes, you read that right. The attacker still holds the ProxyAdmin keys on the BSC network. The protocol remains exposed! 🤯 3️⃣ **Massive Unlock Incoming:** As if the hack wasn't bad enough, a massive scheduled token unlock is hitting the market on **June 25**. Imagine that insane sell pressure crashing into an already fragile chart! 🩸 Smart money isn't buying this pump; they are using it as exit liquidity. This looks like the perfect setup for a brutal dump. Stay safe, protect your capital, and do not catch falling knives! 📉 Are you shorting $H or staying entirely away? Let me know! 👇🔥💸 #HumanityProtocol #CryptoNews #BinanceFutures #BearishSetup #CryptoHacks {future}(HUSDT)
🚨 **$H PUMPING 44%... BUT IS IT A MASSIVE BULL TRAP?!** 🚨
Everyone is celebrating because Humanity Protocol ($H ) just pumped 44% after the team dropped their breach report and teased a compensation plan for the victims. But do NOT let this relief rally fool you—this is screaming danger! 🛑
Here is what the hype boys are ignoring:
1️⃣ **The Breach Was Brutal:** A single malware-infected developer laptop gave the attacker 7 private keys, allowing them to steal and maliciously mint a staggering **447 MILLION $H tokens**.
2️⃣ **THE HACKER STILL HAS CONTROL!** Yes, you read that right. The attacker still holds the ProxyAdmin keys on the BSC network. The protocol remains exposed! 🤯
3️⃣ **Massive Unlock Incoming:** As if the hack wasn't bad enough, a massive scheduled token unlock is hitting the market on **June 25**. Imagine that insane sell pressure crashing into an already fragile chart! 🩸
Smart money isn't buying this pump; they are using it as exit liquidity. This looks like the perfect setup for a brutal dump. Stay safe, protect your capital, and do not catch falling knives! 📉
Are you shorting $H or staying entirely away? Let me know! 👇🔥💸
#HumanityProtocol #CryptoNews #BinanceFutures #BearishSetup #CryptoHacks
·
--
Bearish
Verified
Humanity Protocol disclosed a major security breach after an employee's laptop was compromised, allowing an attacker to obtain administrative keys controlling the project's bridge infrastructure on Ethereum and BNB Chain. According to the team, the attacker gained control of 3 of 6 Gnosis Safe owner keys used for the Ethereum bridge ProxyAdmin. This allowed them to transfer ownership of the bridge administration contract, deploy a malicious implementation, and move 141.2 million H tokens in a single transaction. Humanity Protocol said the attacker also compromised 3 of 5 Safe owner keys controlling the BNB Chain bridge. After taking over the bridge administration contract, the attacker deployed another malicious implementation containing an unlimited mint function. Using that contract, the attacker minted 200,000,005 H tokens in two transactions and transferred the newly created tokens to their own wallet. Blockchain investigator Specter initially reported that more than 17 wallets holding H tokens had been drained. As the hack progressed, the number of affected wallets grew into the hundreds. Specter later estimated losses had exceeded $30 million and reported that millions of dollars worth of stolen H tokens had already been sold for ETH. Humanity Protocol later estimated total losses at more than $36 million across Ethereum and BNB Chain. The project has halted deposits and withdrawals on affected bridges and says it is working with exchanges, security firms, and law enforcement to track funds and investigate the breach. #HumanityProtocol #Hack #cryptohacks #SecurityAlert
Humanity Protocol disclosed a major security breach after an employee's laptop was compromised, allowing an attacker to obtain administrative keys controlling the project's bridge infrastructure on Ethereum and BNB Chain.
According to the team, the attacker gained control of 3 of 6 Gnosis Safe owner keys used for the Ethereum bridge ProxyAdmin. This allowed them to transfer ownership of the bridge administration contract, deploy a malicious implementation, and move 141.2 million H tokens in a single transaction.
Humanity Protocol said the attacker also compromised 3 of 5 Safe owner keys controlling the BNB Chain bridge. After taking over the bridge administration contract, the attacker deployed another malicious implementation containing an unlimited mint function.
Using that contract, the attacker minted 200,000,005 H tokens in two transactions and transferred the newly created tokens to their own wallet.
Blockchain investigator Specter initially reported that more than 17 wallets holding H tokens had been drained. As the hack progressed, the number of affected wallets grew into the hundreds. Specter later estimated losses had exceeded $30 million and reported that millions of dollars worth of stolen H tokens had already been sold for ETH.
Humanity Protocol later estimated total losses at more than $36 million across Ethereum and BNB Chain.
The project has halted deposits and withdrawals on affected bridges and says it is working with exchanges, security firms, and law enforcement to track funds and investigate the breach.

#HumanityProtocol #Hack #cryptohacks #SecurityAlert
🚨 99.5% CRASH. 17 wallets. One perfectly timed hack. Read that again. Most people see a hack and think "bad luck." I see a question that nobody is asking loud enough. $H pumped to its all-time high. Momentum was peak. Retail was euphoric. The chart was vertical. Then, in that exact moment, 17 wallets — directly linked to the Humanity Protocol project — got "hacked." Every single H token inside them was dumped into the open market. No slow exit. No OTC deals. Just a full market obliteration. The price didn't just drop. It got divided by roughly 200 times overnight. 😶 Now, here's the uncomfortable part. Retail thinks: "Wow, security is terrible in crypto." Smart money thinks: "Who held those 17 wallets before the pump?" Because hacks don't schedule themselves at ATH. Hacks don't wait for maximum liquidity. Hacks don't coordinate 17 wallets in perfect sync with a retail euphoria event. But insiders do. --- The market teaches one lesson over and over: The loudest pump often attracts the quietest exit plan. --- Was this a security failure? Or was this an engineered liquidity event dressed up as a hack? --- I'm not giving an answer. I'm asking the question that the chart is already asking. 👇 Drop your honest take: Do you think $H was intentionally hacked... or intentionally "hacked"? $H {future}(HUSDT) #HUSDT #huminity #cryptohacks
🚨 99.5% CRASH.
17 wallets.
One perfectly timed hack.

Read that again.

Most people see a hack and think "bad luck."
I see a question that nobody is asking loud enough.

$H pumped to its all-time high.
Momentum was peak.
Retail was euphoric.
The chart was vertical.

Then, in that exact moment, 17 wallets — directly linked to the Humanity Protocol project — got "hacked."

Every single H token inside them was dumped into the open market.
No slow exit. No OTC deals. Just a full market obliteration.

The price didn't just drop.
It got divided by roughly 200 times overnight.

😶

Now, here's the uncomfortable part.

Retail thinks: "Wow, security is terrible in crypto."
Smart money thinks: "Who held those 17 wallets before the pump?"

Because hacks don't schedule themselves at ATH.
Hacks don't wait for maximum liquidity.
Hacks don't coordinate 17 wallets in perfect sync with a retail euphoria event.

But insiders do.

---

The market teaches one lesson over and over:
The loudest pump often attracts the quietest exit plan.

---

Was this a security failure?
Or was this an engineered liquidity event dressed up as a hack?

---

I'm not giving an answer.
I'm asking the question that the chart is already asking.

👇 Drop your honest take:
Do you think $H was intentionally hacked... or intentionally "hacked"?

$H
#HUSDT #huminity #cryptohacks
SlowMist has released its H1 2026 blockchain security report, documenting 182 publicly disclosed security incidents. Total losses reached USD 956 million, down significantly from more than USD 2.5 billion during the same period in 2025. While the value stolen declined, security incidents continued across the Web3 ecosystem. Ethereum recorded the highest number of incidents with 70, followed by BNB Chain with 27 and Base with 16. Private key compromise caused the largest financial losses, accounting for USD 688 million. Smart contract vulnerabilities remained the most common attack type with 76 recorded incidents. The report shows a difference between attack frequency and financial impact. Smart contract vulnerabilities appeared most often, while private key compromise resulted in the greatest losses. The findings reinforce the importance of improving blockchain security through stronger key management, infrastructure protection, and continued smart contract security practices. #cryptohacks #BlockchainSecurity #CryptoNews #CryptocurrencyNews
SlowMist has released its H1 2026 blockchain security report, documenting 182 publicly disclosed security incidents.

Total losses reached USD 956 million, down significantly from more than USD 2.5 billion during the same period in 2025. While the value stolen declined, security incidents continued across the Web3 ecosystem.

Ethereum recorded the highest number of incidents with 70, followed by BNB Chain with 27 and Base with 16. Private key compromise caused the largest financial losses, accounting for USD 688 million. Smart contract vulnerabilities remained the most common attack type with 76 recorded incidents.

The report shows a difference between attack frequency and financial impact. Smart contract vulnerabilities appeared most often, while private key compromise resulted in the greatest losses.

The findings reinforce the importance of improving blockchain security through stronger key management, infrastructure protection, and continued smart contract security practices.

#cryptohacks #BlockchainSecurity #CryptoNews #CryptocurrencyNews
$DEFI TVL SINKS 39% AS $BTC COLLATERAL DRAINS 🔥 Total value locked in DeFi has fallen every month this year, dropping from $115 billion to $70 billion — a 39% slide and the longest losing streak since 2022. Hacks have added to the pain, with 121 exploits stealing nearly $942 million through late June, and two breaches in April alone draining $293 million from KelpDAO. Aave deposits collapsed from $26.4 billion to $14.3 billion within days as trust evaporated. Capital is sitting in stablecoins, waiting for a catalyst. Are you allocating to DeFi at these levels or staying in cash? Not financial advice. Always manage your risk. #ETH #DeFi #TVLDecline #CryptoHacks 🔥
$DEFI TVL SINKS 39% AS $BTC COLLATERAL DRAINS 🔥

Total value locked in DeFi has fallen every month this year, dropping from $115 billion to $70 billion — a 39% slide and the longest losing streak since 2022. Hacks have added to the pain, with 121 exploits stealing nearly $942 million through late June, and two breaches in April alone draining $293 million from KelpDAO.

Aave deposits collapsed from $26.4 billion to $14.3 billion within days as trust evaporated. Capital is sitting in stablecoins, waiting for a catalyst.

Are you allocating to DeFi at these levels or staying in cash?

Not financial advice. Always manage your risk.

#ETH #DeFi #TVLDecline #CryptoHacks

🔥
·
--
Bullish
#sandboxsandsuspectedinfinitemintflawonbase Can someone please check on the devs?! 🤦‍♂️ Seriously, being a trader is hard enough with regular market dumps, but now we have to deal with infinite mint exploits? Over 500M SAND got printed out of thin air on Base because of a smart contract loophole. Total nightmare! What should traders do now? 🛑 Avoid catching a falling knife—do not attempt to buy SAND right now. 🚨 Monitor the situation for an official response from The Sandbox team. 🛡️ Double-check your exposure to any Base network assets. We are just trying to trade in peace, please secure the code next time! ⚠️ This is not financial advice! Stay safe and trade on a secure platform. Create a new account using my link: [https://www.binance.com/register?ref=VINHTOCDO](https://www.binance.com/register?ref=VINHTOCDO) or code VINHTOCDO! #cryptohacks #SmartContractExploit #SAND #VINHTOCDO $BTC {future}(BTCUSDT) $ETH {future}(ETHUSDT) $BNB {future}(BNBUSDT)
#sandboxsandsuspectedinfinitemintflawonbase
Can someone please check on the devs?! 🤦‍♂️ Seriously, being a trader is hard enough with regular market dumps, but now we have to deal with infinite mint exploits? Over 500M SAND got printed out of thin air on Base because of a smart contract loophole. Total nightmare!
What should traders do now?
🛑 Avoid catching a falling knife—do not attempt to buy SAND right now.
🚨 Monitor the situation for an official response from The Sandbox team.
🛡️ Double-check your exposure to any Base network assets.
We are just trying to trade in peace, please secure the code next time!
⚠️ This is not financial advice!
Stay safe and trade on a secure platform. Create a new account using my link: https://www.binance.com/register?ref=VINHTOCDO or code VINHTOCDO!
#cryptohacks #SmartContractExploit #SAND #VINHTOCDO
$BTC
$ETH
$BNB
$14.27 billion. That's how much crypto has lost to hacks and exploits since 2016, according to CoinGecko's latest data. The trend line tells its own story: • 2016: around $60M • 2021: $2.66B • 2022: $2.77B (still the worst year on record) • 2025: $2.55B • 2026 so far: $1.2B across 164 incidents, already more incidents than any full year before it Security tooling has genuinely improved over the years. Audits are standard now, bug bounties are common, monitoring is faster. But the losses haven't gone away, they've just changed shape. It's not always a shady protocol or an obvious rug pull. A lot of the damage comes from smart contract bugs, leaked private keys, phishing links, bridge exploits, or just someone getting socially engineered into signing the wrong thing. That's really the takeaway for anyone using this space day to day: 🔐 Don't assume a protocol is safe just because it's popular 🧪 Actually look into what you're interacting with before connecting your wallet 🚨 Slow down on approvals and signature requests, most people lose funds here without realizing what they signed 💰 Keep your hot wallet light. If you don't need it liquid right now, it shouldn't be sitting there Self-custody is the whole point of crypto, but it also means the security burden sits with you, not an exchange or a bank. Curious what people think: which is the bigger risk right now, smart contract bugs or human error? From the incident data, it's looking more and more like the human side. Source: CoinGecko #Crypto #CryptoSecurity #CryptoHacks #Web3 #Blockchain
$14.27 billion. That's how much crypto has lost to hacks and exploits since 2016, according to CoinGecko's latest data.
The trend line tells its own story:
• 2016: around $60M
• 2021: $2.66B
• 2022: $2.77B (still the worst year on record)
• 2025: $2.55B
• 2026 so far: $1.2B across 164 incidents, already more incidents than any full year before it
Security tooling has genuinely improved over the years. Audits are standard now, bug bounties are common, monitoring is faster. But the losses haven't gone away, they've just changed shape. It's not always a shady protocol or an obvious rug pull. A lot of the damage comes from smart contract bugs, leaked private keys, phishing links, bridge exploits, or just someone getting socially engineered into signing the wrong thing.
That's really the takeaway for anyone using this space day to day:
🔐 Don't assume a protocol is safe just because it's popular
🧪 Actually look into what you're interacting with before connecting your wallet
🚨 Slow down on approvals and signature requests, most people lose funds here without realizing what they signed
💰 Keep your hot wallet light. If you don't need it liquid right now, it shouldn't be sitting there
Self-custody is the whole point of crypto, but it also means the security burden sits with you, not an exchange or a bank.
Curious what people think: which is the bigger risk right now, smart contract bugs or human error? From the incident data, it's looking more and more like the human side.

Source: CoinGecko

#Crypto #CryptoSecurity #CryptoHacks #Web3 #Blockchain
💥 HARMONY PROTOCOL EXPLOITED: 4 BILLION $ONE PRINTED OUT OF THIN AIR 💥 The nightmare scenario just played out for Harmony Protocol ($ONE) in a massive on-chain exploit. 🚨 The Breakdown: The Glitch: Attacker exploited an empty-blocks vulnerability to bypass minting checks. The Damage: ~4 Billion $ONE minted instantly—inflating the supply by a staggering 26%. The Dump: Over 2.8 Billion tokens (~97%) were immediately funneled straight into exchanges to cash out. The Cover-up: A flaw in Harmony's totalSupply endpoint masked the inflation, blinding traders until the market crashed. 📉 Chart Impact: The immediate supply shock caused a brutal ~40% market capitulation. The attached Binance chart shows a horrific flush down to 0.000580, wiping out millions in market cap before catching a fragile, partial bounce up to 0.000777. 🛠️ What's Next? Harmony has paused its cross-chain bridge and deployed an emergency validator patch to stop further minting. However, with the vast majority of tokens already inside exchange deposit wallets, the team is actively discussing a hard blockchain rollback to erase the hacker's history. Can the ecosystem recover from back-to-back structural exploits, or is this the final nail in the coffin? 👇 #HarmonyONE #CryptoHacks #BinanceSquare #BlockchainSecurity #ONE
💥 HARMONY PROTOCOL EXPLOITED: 4 BILLION $ONE PRINTED OUT OF THIN AIR 💥

The nightmare scenario just played out for Harmony Protocol ($ONE) in a massive on-chain exploit.

🚨 The Breakdown:

The Glitch: Attacker exploited an empty-blocks vulnerability to bypass minting checks.

The Damage: ~4 Billion $ONE minted instantly—inflating the supply by a staggering 26%.

The Dump: Over 2.8 Billion tokens (~97%) were immediately funneled straight into exchanges to cash out.

The Cover-up: A flaw in Harmony's totalSupply endpoint masked the inflation, blinding traders until the market crashed.

📉 Chart Impact:
The immediate supply shock caused a brutal ~40% market capitulation. The attached Binance chart shows a horrific flush down to 0.000580, wiping out millions in market cap before catching a fragile, partial bounce up to 0.000777.

🛠️ What's Next?
Harmony has paused its cross-chain bridge and deployed an emergency validator patch to stop further minting. However, with the vast majority of tokens already inside exchange deposit wallets, the team is actively discussing a hard blockchain rollback to erase the hacker's history.

Can the ecosystem recover from back-to-back structural exploits, or is this the final nail in the coffin? 👇

#HarmonyONE #CryptoHacks #BinanceSquare #BlockchainSecurity #ONE
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number