36% of Osmosis Alloyed BTC Lost Its Bitcoin Backing to Nomic
A double-spend on the Nomic bridge left 36% of Osmosis Alloyed BTC with no bitcoin behind it. Validators froze 22.65 BTC, and a real gap remains.
A double-spend on the Nomic bridge left 36% of Osmosis Alloyed BTC with no bitcoin behind it. Validators froze 22.65 BTC, and a real gap remains.
Trezor's hardware held, but a breached email vendor blasted a fake STM32 security alert to users on September 9, the second vendor data leak in a month.
Smart contract exploits were 60% of 2026 crypto hacks but just 17% of the losses. Keys, custody and signing systems took 76% of the stolen value.
The Liquid Network hack drained about 4,000 bitcoin, yet no keys were stolen. A patch meant to fix a 2019 flaw let the attacker mint unbacked coins.
Price-manipulation exploits hit a record 32 in DeFi lending in 2026. The Tectonic case shows why the attack is cheap, repeatable and tough to audit away.
Harmony will shut its Layer 1 on September 10 and migrate ONE to Ethereum, saying it can no longer defend the chain against state actors and AI agents.
Liquid Network lost 3,996 BTC, near 320 million dollars, to an Elements rangeproof bug on September 6. No key was stolen, and 197 BTC now back the peg.
A crypto oracle is how a blockchain reads a price it cannot see itself. Learn what oracles do, why attackers target them, and who runs the feeds today.
An attacker drained about $75 million from Tectonic on Cronos by inflating a token that barely traded. Price manipulation is now one in eight crypto hacks.
The biggest crypto hacks of 2026 skipped the code and stole the keys. Losses fell below 2025, yet one state-linked crew still took nearly half the total.
The SEC's first transfer agent overhaul since the 1980s runs 421 pages and adds blockchain reporting, yet only two onchain firms have registered so far.
Injective lost $4.9M on August 31 to a market-ID collision in binary-options settlement, then framed the near four-hour block halt as a routine upgrade.
Coinsbuy says it replenished wallets after an $8 million hack across Ethereum and Tron. On-chain data shows the refund covered only about half.
Two XRPL amendments were pulled after critical flaws. Both return in xrpld 3.3.0 next week, with three new ones and an 80% validator vote.
Minnesota's crypto kiosk ban and its bank custody law took effect on the same August 1 date, and the two statutes point in opposite directions.
A Coldcard firmware flaw drained 594 BTC. Block puts the seed search space at 32 bits, Coinkite at 72. Here is how to check your own device.
Crypto cybersecurity is no longer a side topic. It sits at the center of the biggest stories in the industry, from $285M smart contract exploits to state-sponsored DeFi infiltration traced back to North Korean operatives embedded in protocols since 2020. The threat surface keeps widening. Phishing campaigns target wallet owners with increasingly convincing fakes, exploit teams hunt zero-day vulnerabilities in audited contracts, social engineering attacks compromise key personnel at major protocols, and laundering routes flow through cross-chain bridges, mixers, and OTC desks faster than law enforcement can trace them. The defenders are evolving too. Audit firms add formal verification, protocols ship circuit breakers, stablecoin issuers debate when and how to freeze stolen funds, and chains like Arbitrum experiment with reaching directly into hacker wallets. Each case sets a precedent. Coinliva tracks the actual incidents and the response that follows: the post-mortems, the on-chain forensics from Chainalysis, TRM Labs, and Elliptic, the recovery efforts coordinated across protocols, the legal actions like the class action against Circle over Drift, and the security firms doing the analysis nobody else publishes. Real numbers, named protocols, traced wallets. Where crypto security actually stands, not where the marketing claims it does.