Crypto Hacks and Security, Page 6

Moonwell Exploit on Base: How a MAMO Oracle Manipulation Drained $8.7 Million From the Lending Market
An attacker drove the price of the thinly traded MAMO token fortyfold and borrowed $11.03 million against it from the Moonwell lending protocol on Base. Around $9.13 million remains open and falls on depositors who never touched MAMO.
29 days ago

Core Lightning Security Vulnerability: What Node Operators Must Do Now
Core Lightning has reported several confirmed security vulnerabilities and shipped an emergency update as version 26.06.7. If you run your own Lightning node, update now or restart it with the --offline switch.
29 days ago

Cosmos EVM Vulnerability: $5.72 Million From Six Blockchains and Why Three Chains Had to Halt
A flaw in the shared Cosmos EVM module was exploited on six blockchains between August 20 and 25, 2026, and roughly $5.72 million was turned into money. What the post-mortem of August 28 says and what you can check as a holder now.
29 days ago

Ajna Exploit: $775,400 Drained and No Pause Button in the DeFi Lending Protocol
Between August 28 and 29, 2026 roughly $775,400 drained out of seven Ethereum pools of the lending protocol Ajna v2. Because the contract is immutable and has no governance, there is no pause button: users have to withdraw themselves.
29 days ago

Dust Attack on Kraken: Why 12,000 Tiny Deposits Froze Customer Accounts
Between August 17 and 24, Kraken received almost 12,000 tiny amounts from wallets that analytics services attribute to the sanctioned exchange HTX. The automated sanctions screening then froze the accounts of customers who had nothing to do with it.
last month

BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
BaFin has been warning since August 24, 2026 about a crypto website that, according to the regulator's findings, misuses the identity of a real German company. Why the commercial register and the imprint are worthless as proof, and how to check a provider yourself in a few minutes.
last month

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
last month

Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.
last month

Term Finance Governance Exploit: Why Audited Code Does Not Protect Your DeFi Deposits
Around $8.5 million flowed out of the Ethereum lending protocol Term Finance on August 23, 2026, after an attacker bought a voting majority over the deposit pools. The code itself stayed intact: here is how to judge how easily a DeFi pool can be opened by a vote.
last month

SAND Bridge Exploit at The Sandbox: Why Not to Trade SAND on Base and BNB Chain Now
An attack on The Sandbox's cross-chain bridge created unbacked SAND tokens on Base and BNB Smart Chain on August 22, 2026. Bridging is halted; holdings on Ethereum and Polygon are unaffected, according to the studio.
last month