Security

Stay informed on cybersecurity and blockchain security news, including smart contract vulnerabilities, protocol exploits, phishing attacks, wallet security, data breaches, and emerging threats. Learn about security best practices, industry responses, and developments aimed at protecting users and digital assets.
صرف نمایاں
7 گھنٹے پہلے
Harmony Protocol confirms unauthorized ONE minting, suspends bridge services after August 12 incident
Harmony Protocol said an unauthorized ONE minting incident occurred on August 12. Initial analysis put the minting at 4000000000 ONE, but a later on-chain reconstruction found about 3010000000000 ONE was issued to four attacker wallets through six forged crossshard transactions. The team said it has fixed the crossshard receipt verification flaw and a quorum verification bug for the prestaking committee, and deployed Mainnet v2026.1.1 at 06:30 (UTC+8) on August 12. It is preparing to roll back the network to block 92,730,034 and has suspended bridge services.
ONE
ONE-8.53%
7 گھنٹے پہلے
7 گھنٹے پہلے
Harmony says CrossShard receipt replay bug enabled unauthorized minting, including 400 million ONE
Harmony said a CrossShard Receipt Replay bug allowed valid receipts to be processed multiple times, minting new tokens without corresponding deductions. The network initially confirmed 400 million ONE in unauthorized minting, while forged crossshard issuance totaled about 3.01 trillion ONE, with the team still verifying the data, according to Foresight News. Harmony said an emergency patch activated on August 12 fixed the issue and crosschain services have been paused. The team is coordinating with validators and exchanges on a rollback targeting block 92,730,034, with Shard 0 paused to support the operation.
ONE
ONE-8.53%
7 گھنٹے پہلے
11 گھنٹے پہلے
Foundation pledges full reimbursement and to restore 1:1 backing for bridged XRP as bridge stays paused
The Foundation said it will make all affected users whole and fully replenish missing $XRP reserves to restore 1:1 backing for bridged XRP, with reserves verifiable onchain. It said the vulnerability has been identified and patched. The bridge remains paused pending an independent security review and will resume only after the review is successfully completed. The Foundation said it will publish a full technical report detailing the restoration mechanism and urged users to watch for scams and rely only on official channels for updates.
XRP
XRP-0.84%
11 گھنٹے پہلے
13 گھنٹے پہلے
DATA Foundation extends team and lead investor token lockups by 18 months, leaving Aug. 13 unlock date without replacement
DATA Foundation has kept team and lead investor tokens locked past Aug. 13, even though that date appeared in an earlier public supply schedule, and it has not published a new unlock date. The foundation said on June 25 it extended those lockups by an additional 18 months, but did not specify when the extension starts or how it is enforced. Early Backers and Core Contributors account for 41.6% of the project’s allocation buckets, with both set to unlock over 48 months. Separate coverage also flagged a potential wider unlock wave tied to returning VC funding and noted Pump Fun plans to unlock $127M of insider tokens on July 12, about double PUMP’s recent average daily volume.
PUMP
PUMP+2.12%
13 گھنٹے پہلے
20 گھنٹے پہلے
Harmony’s $ONE slides as much as 38% after exploit mints 4 billion unauthorized tokens
Harmony’s blockchain was attacked, with hackers exploiting a network flaw to mint 4 billion ONE tokens—about 26% of the circulating supply. About 2.8 billion tokens were quickly moved to centralized exchanges, fueling market panic. ONE fell as much as 38%, and blockchain analysis linked the incident to 10,288 transactions across 409 wallets. Within four hours, 53% of validators had applied a security update.
ONE
ONE-8.53%
20 گھنٹے پہلے
1 دن پہلے
Coldcard exploit highlights single-point-of-failure risk in private keys as losses reach $111 million
A vulnerability affecting certain Coldcard Bitcoin hardware wallets has intensified concerns about private-key security, with Blockaid CEO Ido BenNatan warning that private keys can become a single point of failure even when assets are kept offline. Galaxy Research has identified at least $111 million in confirmed thefts and estimated total losses could exceed $130 million. Blockaid data show nearly 75% of crypto funds lost to exploits in the first half of 2026 were linked to private-key compromises, while total hack losses in the period topped $1 billion amid record verified incidents. The episode underscores that offline storage alone may not prevent theft when seed generation, firmware, and cryptographic implementation are compromised.
BTC
BTC-1.51%
1 دن پہلے
1 دن پہلے
Sui plans NIST-standard quantum-safe accounts, targets mainnet rollout in 2026–2027
Sui plans to add an ML-DSA-65 signature option that follows NIST’s FIPS 204 standard as a native feature for regular accounts, while deploying SLH-DSA-SHA2-128s via Move smart contracts for high-value vaults. Quantum-safe vaults are expected to reach mainnet during 2026, with native ML-DSA-65 accounts targeted for testnet before the end of the year and mainnet account authentication in the first quarter of 2027. The network says it is preparing for a “harvest now, forge later” threat, in which attackers stockpile public-key data for future quantum attacks.
SUI
SUI-1.80%
1 دن پہلے
2 دن پہلے
Coreum bridge exploit drains 200,000 XRP in 97 minutes as memo-only checks bypass address validation
A logic flaw in Coreum’s cross-chain bridge led to an attack that stole about 200,000 XRP within 97 minutes. The bridge reportedly validated transaction memos but did not verify the actual destination addresses, allowing funds to be moved without accessing any private keys. XRPL itself was not affected, and the bridge has been halted while an official report remains pending.
XRP
XRP-0.84%
2 دن پہلے
8-11
Bitcoin network attack slows block production as developers prepare mitigations
Bitcoin is facing an attack that has significantly slowed block production, extending block times and constraining transaction throughput. Core developers have responded on an emergency basis and are preparing technical fixes and defensive measures to contain the impact. Attackers are also spreading misinformation, urging users to downgrade their Bitcoin node software or switch to clients with known security risks in an apparent effort to deepen disruption. The community is working to correct false claims and is urging users to rely on official channels for updates.
BTC
BTC-1.51%
8-11
8-11
North Korea-linked Kimsuky builds local AI setups to sharpen attacks on crypto and finance
North Korea-linked hacking group Kimsuky has been found setting up locally hosted large language model environments to incorporate AI into cyberattacks targeting the cryptocurrency and financial sectors. In the first half of 2026, North Korean hackers stole about $609 million—roughly 55% of the $1.1 billion lost across crypto hacks in the period—and Humanity Protocol lost $32 million. Blockchain investigator ZachXBT previously reported that North Korean IT workers earned more than $3.5 million in crypto by posing as developers, while leaked records showed the operation generated about $1 million a month.
HUMANITY
HUMANITY+21.36%
8-11