Crypto Hacks Surged to $763M in Q2 2026 as Operational Failures Spike
Crypto hacks stole $763,971,791 across 67 incidents in Q2 2026, with accessibility weaknesses the single biggest point of failure. According to a recent report by blockchain security and compliance firm Hacken, Q2 saw crypto hacks rise by 58.3% from Q1’s $482.7 million and netted the highest losses since Q2 2025. While smart contract bugs accounted for most incidents, their cumulative loss only mounted to just 11% of all losses. Operational and infrastructural failures, including compromised keys and signers, took the bigger pie at 88.3% of all losses. As for the perpetrators, 75.5% of the funds drained were attributed to Democratic People’s Republic of Korea (DPRK) actors. Note that Consensys, the company behind Ethereum’s wallet MetaMask, recently acknowledged hiring a software developer linked to North Korea. Realizing this a month later, the individual was fired and his system access revoked. The firm reported the incident to law enforcement while reassuring users that no funds were lost, no data was leaked, and no malicious code was deployed. The report also documents that Q2 witnessed the first case of AI malicious prompt injection causing an exfiltration of $174,000. Here, the firm notes that failure comes from “inadequate review, missing variants and weak testing.” In the European Union, the grace period for crypto players to pursue a full license expired on July 1. By this time, only about 215 Crypto-Asset Service Providers (CASPs) had acquired Markets in Crypto-Assets Regulation (MiCA) authorization despite 1,200 expressing interest. Binance, MEXC and HTX (formerly Huobi) are among the most prominent exchanges that were forced to shut down under this rule. Additionally, Circle’s USDC is so far the only MiCA-compliant stablecoin out of the top 10 in terms of market cap. Nonetheless, Hacken notes that the most trusted counterparties in the future will be the ones that prove safety first, regardless of their existence period, their audits, and total value locked. #TerraLabs #YiHeBinance #receita_federal #EconomicAlert
Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart
At least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and reported by security firms BlockAid and Peckshield. The run of attacks share a common thread. None broke the underlying cryptography — each was either a logic flaw, where the code ran as written but the rules still let money out, or a compromised key that handed an attacker control it should never have had. The most damning was blockchain network Verus. Blockaid detected an exploit on the Verus-Ethereum bridge early Thursday that drained about $7.54 million in ether, tokenized bitcoin and a spread of stablecoins. The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. CoinDesk reported that earlier incident, an $11.5 million loss, in May. A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain. The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing. The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was draineagain two weeks later. The cost of that trust is visible in the protocol's wn numbers. Verus held close to $100 millnvalue locked at the start of 2025, accordingo DefiLlama. #quickfarm #GamingCoins #kriptohaber24 #ZAIBOTIO #NOTCOİN
Glassnode flags possible data exposure, warns customers of phishing risk
Glassnode, a prominent crypto market data and analytics provider, has notified customers of an ongoing security incident that may have resulted in the exposure of certain user information, including email addresses. The company said it is actively investigating the incident and has yet to determine the full extent of any affected data. Glassnode urged users to remain alert for phishing attempts and fraudulent communications impersonating the company. It advised customers to trust only emails sent from its official domain, noting that it does not operate a customer support phone line, and said it will provide further updates if additional action is required. Concerns about a potential Glassnode data breach first surfaced in a Reddit post, where a user warned that Glassnode’s email list may have been leaked or hacked after receiving a phishing email at an address created exclusively for the blockchain analytics platform. The user said the targeted nature of the message indicated that customer email data may have been exposed. #GamingCoins #YapayzekaAI #Robertkiyosaki
Balance Coin crashes 99% after reported $915K exploit
Balance Coin, an algorithmic stablecoin designed to maintain a peg to the US dollar, has fallen more than 99% following a reported exploit. The stablecoin, the native algorithmic stablecoin of Balance Protocol, is currently trading at $0.001358, down from $0.9954, according to CoinMarketCap. Blockchain security firm PeckShield on Wednesday said the depeg followed a $915,000 exploit of decentralized autonomous organization 42DAO, which governs the Balance Protocol and its BLC token. TenArmor said it had detected a suspicious attack involving GemJoin and 42DAO on the BNB Chain. #pepepumping #HotTrends #Yazdan #xmucanX #Dogecoin
SecondFi to wind down after $2.6M ADA theft linked to wallet flaw
Cardano-based wallet SecondFi is preparing to shut down after a security breach exposed issues around wallet security and left hundreds of users awaiting recovery options. SecondFi said it will wind down SecondFi and Yoroi wallet services after attackers stole about 16.1 million ADA, worth roughly $2.6 million, due to a cryptographic flaw in its wallet software, according to an update published on Wednesday. The platform said an independent investigation by blockchain intelligence provider Groom Lake identified a sophisticated external actor behind the attack and found indicators potentially linked to North Korea’s Lazarus Group, although no attribution has been confirmed. It added that the breach affected 374 wallets. The update came nearly a month after SecondFi first disclosed the exploit in late June, with affected users still waiting for recovery tools and migration options that the company says are now targeted for release in August. SecondFi’s latest update has drawn frustration from some users who say they are still waiting for a clear path to recover or migrate their assets after the exploit. Earlier guidance from the platform advised affected users not to restore recovery phrases into new Cardano wallets, saying that moving funds elsewhere “does not mitigate the risk” while SecondFi investigated the incident. On June 27, SecondFi said it had identified a recovery path and expected to begin the process within about two weeks after completing testing and security reviews. Nearly a month later, the company said the recovery tool is still under development and is now expected to launch in August. But many of us were told our funds could be recovered within two weeks. Now we’re being asked to wait even longer,” one user wrote in response to SecondFi’s Wednesday update. Cointelegraph contacted SecondFi for details on potential reimbursement plans but did not receive a response by publication time. EMURGO also did not respond to earlier requests for comment. #Kriptocutrader #jasmyustd #PEPEATH #ZeusInCrypto
U.S. DOJ Moves to Seize $25 Million in Cryptocurrency Linked to International Fraud Ring
The U.S. Department of Justice has initiated forfeiture proceedings to seize more than $25 million in cryptocurrency tied to an international fraud investigation, according to a report by The Block. The action marks the latest effort by federal authorities to recover digital assets linked to cross-border financial crimes. Prosecutors are pursuing a formal forfeiture action to transfer the seized cryptocurrency to the state, the DOJ confirmed. The assets were secured during a broader investigation into an international fraud scheme, though officials have not disclosed specific details about the alleged perpetrators or the nature of the fraudulent activity. The case underscores the growing role of cryptocurrency in illicit financial networks and the government’s increasing capacity to trace and recover digital funds. This case highlights the dual nature of cryptocurrency: while it enables financial innovation, it also presents new avenues for fraud. For legitimate investors and businesses, the DOJ’s actions signal a maturing regulatory environment that prioritizes consumer protection and asset recovery. However, the seizure also raises questions about due process for asset owners and the challenges of proving ownership in decentralized systems. The outcome of this forfeiture could set a precedent for how U.S. authorities handle similar cases involving digital assets. #CrudeOilFuturesRiseOver4% #SuperMicroRisesNearly20% #SenateReleasesUpdatedCLARITYActText #GoogleDocsMagic #xmucan
Layer-1 blockchain network Zilliqa warned that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys using publicly available onchain data. The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key,” Zilliqa said in a Wednesday X post. Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and are advised to await further guidance before taking any action. The warning comes after Zilliqa on Monday asked exchanges to temporarily pause Zilliqa ($ZIL) deposits and withdrawals after identifying a security vulnerability that resulted in the theft of an undisclosed amount of $ZIL from a cold wallet. Zilliqa said it will publish a corrected version of the app in coordination with Ledger. It said that users transacting $ZIL through EVM-compatible tooling were not affected. The $ZIL token fell 1.5% in the past 24 hours and 17% over the past week, to trade above $0.0024 at publication, according to CoinMarketCap. #quickfarm #EconomicAlert #Robertkiyosaki #tobechukwu #Launchpool
Altcoin Investors Beware! Security Crisis Deepens: Two Major Exchanges Added Them to Their Warning L
Zilliqa ($ZIL), one of the popular altcoins of the 2021 bull season, announced that it is facing a significant security crisis due to a critical vulnerability discovered in its Ledger hardware wallet application. Zilliqa, in a statement made from the X account, stated that the attack stemmed from a security vulnerability in the Ledger application. At this point, Zilliqa states that a critical vulnerability in the Ledger application makes the private keys used for $ZIL transactions vulnerable to recovery attacks. The team stated that the problem affects all versions released from 2019 to 2026, and that active exploitation was observed on July 19th. Following this active vulnerability, the team stated that $ZIL transactions were suspended, but EVM transactions were not affected by this security flaw. Following these developments, South Korea-based cryptocurrency exchanges Upbit and Bithumb classified $ZIL as a “warning asset” in their trading markets. Exchanges have announced that they are suspending deposits and withdrawals for $ZIL, citing user security concerns. Upbit and Bithumb made similar statements, warning that trading support for $ZIL could be completely terminated if the security issue is not resolved within a reasonable timeframe or if adequate measures to protect investors are not taken. This development has led to a review of security measures within the Zilliqa ecosystem, and users who conduct $ZIL transactions via Ledger are advised to change their addresses and discontinue using their compromised wallets. As you may recall, Zilliqa previously announced that $ZIL held in a cold wallet had been stolen in a security incident at one of its partner exchanges. #ONDO #LISTAAirdrop #FlokiCoin #ZE_TRAD🐂 #YiHeBinance
AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call
AI shopping agent developer ORO has confirmed a significant security breach, losing approximately $630,000 worth of ALPHA tokens in an attack attributed to a North Korean state-backed hacking group. The incident, detailed in ORO’s internal incident report and first reported by Protos, highlights the increasingly sophisticated social engineering tactics used by cybercriminals to target cryptocurrency projects. According to ORO’s findings, the attack began when an employee received a message on Telegram from an acquaintance met at a previous offline conference. The hacker, impersonating a trusted contact, convinced the employee to join a video call. During this call, malware was deployed onto the employee’s device, granting the attackers access to internal systems and ultimately the company’s ALPHA token reserves. ORO stated that the method aligns with known patterns of the Lazarus Group, a notorious North Korean hacking collective responsible for numerous high-profile crypto thefts. The use of social engineering—building trust through fake identities and leveraging real-world connections—marks a dangerous evolution in crypto-related cybercrime. This incident serves as a stark reminder that even early-stage AI projects with valuable token treasuries are prime targets. The attack exploited human trust rather than technical vulnerabilities, underscoring that security awareness training is as critical as software safeguards. For the broader crypto ecosystem, it reinforces the need for robust multi-signature wallets, hardware security modules, and strict verification protocols for any communication involving fund transfers. ORO has since engaged with blockchain security firms and law enforcement to trace the stolen funds, though recovering tokens from state-sponsored actors is notoriously difficult. The company is also reviewing its internal security policies and employee communication guidelines.The attackers used a social engineering tactic: they contacted an ORO employee on Telegram, impersonating a known acquaintance, and convinced the employee to join a video call that installed malware on the employee’s device, allowing theft of ALPHA tokens. ORO attributes the attack to a North Korean state-backed hacking group, likely the Lazarus Group, which has a long history of targeting cryptocurrency exchanges and projects. Projects should implement strict verification for any communication involving fund transfers, use multi-signature wallets, provide regular security awareness training, and avoid relying solely on messaging apps for sensitive operational conversations. #BitcoinDominanceRisesTo59% #SenateReleasesUpdatedCLARITYActText #DellRises11%MarketCapNears$290B #HongKongStorageStocksStrengthen #Nasdaq100RisesOnChipRebound
80% of Malicious Code Passed AI Review in CI/CD Pipeline Security Test
When an AI agent says it has reviewed the code, that might mean almost nothing. A new research paper by Yohann Sidot, published on arXiv, lays out a sobering finding: in a sophisticated multi-agent system built specifically to enforce CI/CD pipeline security, a single cleverly worded external request was enough to push malicious code all the way to deployment — bypassing every automated check in its path. The research examined a pipeline composed of five distinct production LLMs sourced from three different providers. The architecture followed a realistic CI/CD flow: triage, developer, security scan, review, and approve/deploy. The whole system ran in shadow mode behind an LLM firewall, designed to simulate a genuinely hardened agentic environment. The entry agent performed well on one narrow metric. Across 40 attempts, it never leaked its system prompt — a result suggesting that surface-level prompt confidentiality can hold. But that turned out to be the least interesting finding of the study. All data in this research was entirely synthetic. The attack simulations used a mocked exfiltration sink, and no real external URLs were contacted at any point. This is methodologically sound for a controlled study, but it also means the prevalence of these specific attack patterns in live production pipelines remains an open question. The gap between a clean experimental setup and the messier reality of deployed systems is real. Production pipelines differ in architecture, LLM configuration, organizational policy layers, and human-in-the-loop intervention points. What the paper establishes is a proof-of-concept vulnerability class — not a confirmed attack in the wild. Still, the core insight holds regardless of deployment context: if AI agents can be made to defer to fabricated authority signals, and if the code they approve is clean enough to evade pattern-based detection, then the verification layer of an agentic CI/CD pipeline is only as strong as the agents’ capacity to reason about intent — and that capacity, the paper shows, is neither guaranteed nor easy to operationalize at scale. Only LLM reasoning about the intent of the code — rather than its syntax or pattern-based properties — provided any partial defense. All other controls, including distributed verification and prompt secrecy, were insufficient on their own. #GoogleDocsMagic #Robert #LISTAAirdrop #Kriptocutrader
ロシアの国家ドゥーマは、暗号資産市場のためのルールを定める法案を承認した。同法案は、国内における暗号資産の取引のための条件や、越境貿易の条件を設定している。 議会は、デジタル通貨とデジタル権利に関する『Digital Currency and Digital Rights』という題名の法案第1194918-8号を、火曜日に行われた第2読会および第3読会で可決した。法案に関する最終採決を議員らが予定していたことから、公式な議会記録によれば、その事前の見通しどおりだった。 本法は、暗号資産市場の参加者(暗号資産取引所、ブローカー、資産運用会社、カストディアンを含む)に対する規制された枠組みを作り、同分野で事業を行う企業に求められる要件を定めている。