Crypto Hacks and Security, Page 7

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.
last month

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
last month

Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
On August 30, 2026, the validators of the Cronos chain halted block production after an attacker had emptied the lending market Tectonic via an inflated TONIC price. What is established, why the damage figures diverge, and what you can check if your balance sits on a haltable chain.
last month

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
last month

Moonwell Exploit on Base: How a MAMO Oracle Manipulation Drained $8.7 Million From the Lending Market
An attacker drove the price of the thinly traded MAMO token fortyfold and borrowed $11.03 million against it from the Moonwell lending protocol on Base. Around $9.13 million remains open and falls on depositors who never touched MAMO.
last month

Core Lightning Security Vulnerability: What Node Operators Must Do Now
Core Lightning has reported several confirmed security vulnerabilities and shipped an emergency update as version 26.06.7. If you run your own Lightning node, update now or restart it with the --offline switch.
last month

Cosmos EVM Vulnerability: $5.72 Million From Six Blockchains and Why Three Chains Had to Halt
A flaw in the shared Cosmos EVM module was exploited on six blockchains between August 20 and 25, 2026, and roughly $5.72 million was turned into money. What the post-mortem of August 28 says and what you can check as a holder now.
last month

Ajna Exploit: $775,400 Drained and No Pause Button in the DeFi Lending Protocol
Between August 28 and 29, 2026 roughly $775,400 drained out of seven Ethereum pools of the lending protocol Ajna v2. Because the contract is immutable and has no governance, there is no pause button: users have to withdraw themselves.
last month

Dust Attack on Kraken: Why 12,000 Tiny Deposits Froze Customer Accounts
Between August 17 and 24, Kraken received almost 12,000 tiny amounts from wallets that analytics services attribute to the sanctioned exchange HTX. The automated sanctions screening then froze the accounts of customers who had nothing to do with it.
last month

BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
BaFin has been warning since August 24, 2026 about a crypto website that, according to the regulator's findings, misuses the identity of a real German company. Why the commercial register and the imprint are worthless as proof, and how to check a provider yourself in a few minutes.
last month