Crypto Hacks and Security
This page collects every CryptoTicker.io report on attacks and fraud in the crypto market: hacked exchanges, exploits in DeFi protocols and bridges, stolen NFTs, wallet drainers, phishing, abused token approvals and rug pulls. The newest cases are at the top.
A hack is rarely over after one day. Funds get moved, exchanges freeze accounts, projects announce reimbursements. We therefore keep ongoing cases up to date with dated updates, the latest one always at the top of the article.
How to protect yourself
- Revoke approvals. Most wallet drainers and many protocol exploits reach your funds through approvals you once granted to a contract. Check them regularly, for example with revoke.cash or in the approvals section of your block explorer, and revoke what you no longer need.
- A hardware wallet protects your key, not your approvals. It stops anyone from stealing your private key. It does not stop an approval you signed yourself if the contract behind it is exploited later. Only sign what you can read and understand on the device.
- Check your exchange balance. After an exchange hack, what matters is whether the exchange covers customer losses and whether withdrawals work. Keep only what you need for trading on an exchange and look for a MiCA licence.
- Never enter your seed phrase. No support agent, airdrop page or wallet update will ask for it. Links from direct messages and sponsored search results are a common way onto phishing sites.
All reports
Ongoing cases are kept up to date with dated updates.

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
yesterday

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
yesterday

Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.
2 days ago

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
2 days ago

BaFin Warning: What Happens When You Enter Your Data on an AI Crypto Platform
On September 23, 2026 BaFin warned about 39 near-identical websites presenting themselves as AI-powered crypto trading platforms. On its findings these pages take no money but pass the data left in their contact form on to unauthorized trading platforms.
2 days ago

Fetch.ai Bridge Exploit: What FET, AGIX and NTX Holders Must Check Now
A single call drained the FET liquidity of the SingularityNET bridge on September 19, and hundreds of millions of unbacked tokens were minted afterwards. What is affected, what Fetch.ai has halted, and what to check in your wallet, at your exchange and on tax.
4 days ago

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
7 days ago

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
8 days ago

Crypto investment fraud: when the tax office taxes phantom gains and what to check now
Between September 11 and 16, 2026, BaFin published thirteen consumer notices, seven of them on crypto-assets. Anyone who has paid into such a platform risks not only the loss but, in some circumstances, a tax demand on gains that never existed.
8 days ago
