The XRP Staking Scam Took $8.5M. Police Traced $19M in the Wallets.
Seoul police say a fake Flare staking site took 3.4 million XRP from 71 investors. The wallets behind it moved more than twice that sum.
Seoul police say a fake Flare staking site took 3.4 million XRP from 71 investors. The wallets behind it moved more than twice that sum.
Ostium's post-mortem confirms $23,752,746 gone from its liquidity vault in six minutes. The smart contracts worked exactly as written.
Zcash sealed the Orchard shielded pool after a four year counterfeiting bug. Only about 5% of 3.5M ZEC has crossed into Ironwood so far.
Over 34% of bitcoin has revealed its public key on chain. What quantum computers could reach, and the two BIPs written to close the gap.
DefiLlama data shows $17 billion stolen across 518 incidents in a decade, and more than half of the losses came from stolen keys or phished humans. The…
North Korea's TraderTraitor subgroup hit Drift on April 1 and KelpDAO on April 18. One attack used a fake quant firm. The other poisoned bridge infrastructure. Different tactics, same wallet.
A single exploit on April 19 triggered one of the fastest liquidity withdrawals the sector has ever seen, and the damage is still moving through the system.
The attacker moved nearly all stolen ETH into Bitcoin in roughly a day and a half, while Arbitrum scrambled to freeze a smaller portion of the funds on its own network.
The attacker funded the node through Monero and Hyperliquid weeks before the theft. Chainalysis mapped the entire trail. THORChain paused all trading.
A compromised private key let an attacker automate withdrawals from Polymarket's UMA CTF Adapter on Polygon. ZachXBT flagged it first. Losses passed $700,000 before the team responded. Polymarket says user funds are safe. The attacker has already split the proceeds across 15 wallets.
A researcher says over 40 DeFi platforms have employed DPRK state-linked developers. Their seven years of blockchain experience is, as she notes, not a lie. The Drift Protocol exploit was not a code bug. It was a six-month intelligence operation conducted by a North Korean state-affiliated group that attended conferences, deposited real capital, and waited.
StablR's EURR and USDR lost their pegs on Sunday after an attacker compromised a single private key in a 1-of-3 multisig, minted 8.35 million unbacked USDR and 4.5 million EURR, and dumped them for 1,115 ETH. The stablecoin issuer holds a Malta EMI license and operates under MiCA. Regulation did not stop a key management failure.
One of the world's largest Bitcoin ATM operators filed an SEC Form 8-K on April 8, 2026, disclosing that an unauthorized party accessed its corporate IT systems and drained 50.903 BTC from settlement accounts. Customer platforms and user data were not affected.
A criminal group is threatening to release videos of internal systems unless Kraken pays up. The exchange says no breach occurred and funds were never at risk. Kraken has identified and removed the insiders involved in both incidents, notified affected users and is cooperating with law enforcement.
North Korean group UNC4736 stole $270 million from Drift Protocol on April 1, converting part of it into USDC via Circle's own bridge. Circle's formal response clarifies when and why it can freeze assets — and calls for legislative action.
Investors allege Circle let $230 million in stolen USDC cross from Solana to Ethereum without intervention. The lawsuit lands as Tether steps in with a $127.5 million recovery package.