Crypto Hacks and Security, Page 7

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.
last month

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
last month

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
last month

Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
On August 18, 2026 an attacker drew roughly $1.65 million out of MAYAChain's liquidity pools through six chained faults, and the team then halted the chain globally. Anyone who swapped or provided liquidity there can check in a few minutes whether their own money is stuck in the halted system.
last month

BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
On August 19, 2026, BaFin issued a warning about the NC Wallet app and two websites: on the regulator's findings, the unknown operators offer financial services there without authorisation. Because the wallet is custodial, it is the provider and not you who holds the key to your balance.
last month

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
last month

Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
Most emptied wallets were never hacked. Their owners confirmed it themselves, granting an approval that is unlimited and never expires. What sits behind "Approve" and a signature request, and how to get rid of old approvals.
last month

EU warning list for crypto providers: 167 entries, 165 of them from Italy, none from BaFin
ESMA maintains a Europe-wide register of non-compliant crypto providers. We counted it on August 16, 2026 and called up every web address stored in it. Three of 30 supervisory authorities supply any entries at all, and BaFin is not among them.
last month

