Crypto Hacks and Security, Page 9

BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
On August 19, 2026, BaFin issued a warning about the NC Wallet app and two websites: on the regulator's findings, the unknown operators offer financial services there without authorisation. Because the wallet is custodial, it is the provider and not you who holds the key to your balance.
last month

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
last month

Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
Most emptied wallets were never hacked. Their owners confirmed it themselves, granting an approval that is unlimited and never expires. What sits behind "Approve" and a signature request, and how to get rid of old approvals.
last month

EU warning list for crypto providers: 167 entries, 165 of them from Italy, none from BaFin
ESMA maintains a Europe-wide register of non-compliant crypto providers. We counted it on August 16, 2026 and called up every web address stored in it. Three of 30 supervisory authorities supply any entries at all, and BaFin is not among them.
last month

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
last month

Two-Factor Authentication on a Crypto Exchange: Why SMS Is the Weakest Option
SMS codes are the most common form of two-factor authentication on crypto exchanges, and the weakest. The problem is not only SIM swapping, which the FBI has recorded falling for three years. It is real-time phishing, and against that neither SMS nor an authenticator app helps.
last month

BaFin Warnings 2026: 24 Crypto Platform Series With 639 Domains, and How to Check Your Provider
In 2026 BaFin is increasingly warning about entire series of near-identical crypto websites rather than about single providers. Our own count of the complete stock of warnings shows how large the phenomenon has become and which two register checks reliably vet a provider.
last month

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
last month

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
last month

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
last month