Individual Crypto Investor Drained $11 Million via Physical Coercion Attack
The most critical vulnerability remains the human element, which physical "wrench attacks" exploit to bypass all digital security controls.
Aerodrome Velodrome Users Drained by Centralized DNS Hijacking Attack
A centralized DNS registrar compromise allowed a front-end hijack, tricking users into signing malicious token approvals and draining wallets.
Centralized Exchange Hot Wallets Drained by Private Key Compromise
A critical lapse in operational security exposed hot wallet private keys, enabling a multi-chain drain of $48M across seven networks.
Pre-Launch Wallet Compromise Forces $22.1 Million Token Burn and Re-Allocation
A pre-TGE wallet compromise, likely via social engineering, forced an immediate $22.1M token burn, exposing the critical risk of centralized key management.
Malicious Chrome Extension Steals Seed Phrases via Covert Sui Transactions
A high-ranking malicious wallet extension weaponized the Sui blockchain to covertly exfiltrate user mnemonics, bypassing traditional network monitoring.
UXLINK Multi-Signature Wallet Compromised via Delegate Call Vulnerability
A critical delegate call flaw in UXLINK's multi-sig wallet granted unauthorized administrative control, enabling significant asset exfiltration.
Tangem Hardware Wallets Vulnerable to PIN Brute Force “Tearing Attack”
A physical side-channel vulnerability in Tangem cards enables rapid PIN brute-forcing, directly exposing user assets to theft if physical access is gained.
User Funds Drained by Malicious Uniswap Permit2 Signature
A deceptive Permit2 transaction approval allowed an attacker to siphon $118,000 in user assets, highlighting critical signature verification risks.
Ethereum Wallets Compromised by EIP-7702 Delegator Contract Exploits
EIP-7702's delegator function enables sophisticated phishing, allowing attackers to bypass critical on-chain checks and drain user funds.
