Multi-Signature Wallet Drained via Sophisticated Phishing Approval Deception
Sophisticated phishing bypassed multi-sig security by disguising malicious approvals, leading to a $3M asset drain and highlighting advanced social engineering risks.
Walrus Seal Launches Decentralized Access Control Solution
Walrus's Seal introduces robust decentralized access control, addressing critical Web3 privacy gaps and enabling granular data monetization.
Multi-Sig Wallet Drained by Sophisticated Phishing Attack via Fake Contract
Attackers leverage fake Etherscan-verified contracts and disguised approvals to compromise multi-signature wallets, leading to direct asset exfiltration.
Walrus Launches Seal for Decentralized Web3 Access Control
Walrus introduces Seal, a decentralized access control primitive, enhancing data privacy and enabling granular content monetization across the Web3 application layer.
THORChain Founder’s Wallet Drained via Sophisticated Social Engineering Attack
A targeted social engineering exploit, leveraging compromised communication channels, bypassed traditional wallet security, highlighting critical human-factor vulnerabilities.
JavaScript Supply Chain Attack Threatens DeFi Wallet Transactions
A phishing-induced compromise of widely used JavaScript packages exposes a critical supply chain vulnerability, allowing attackers to hijack crypto transactions.
PlayDapp Suffers $290 Million Private Key Compromise, Token Minting Exploit
A compromised private key enabled unauthorized token minting, leading to a severe $290 million loss and critical supply inflation for PlayDapp.
Chrome V8 Engine Exploit Threatens Crypto Wallets and Sensitive Data
A critical "Type Confusion" vulnerability in the V8 engine allows remote code execution, enabling attackers to steal private keys and seed phrases via malicious websites.
NPM Supply Chain Compromise Redirects Crypto Transactions via Malicious Packages
A phishing-induced account takeover enabled malicious code injection into widely used NPM packages, silently rerouting cryptocurrency transactions at the browser level.
Safe Wallet User Drained by Malicious Request Finance Contract Impersonation
A sophisticated contract impersonation attack leveraged near-identical addresses to trick a Safe multi-sig wallet user into unknowingly approving a malicious batch transaction, resulting in a $3 million fund loss.
Web3 Ecosystem Endures Billions in Losses from Wallet Compromises and Phishing
The pervasive threat of compromised digital asset custody and social engineering tactics continues to erode capital across decentralized finance.
Threat Actors Drain User Wallets via Malicious Smart Contract Bots
Exploiting trust through social engineering and obfuscated code, adversaries trick users into deploying malicious smart contracts, enabling direct fund siphoning.
Cantina Enhances DeFi Security with Rapid Crowdsourced Competitions
Cantina’s crowdsourced security competitions accelerate vulnerability identification, fortifying DeFi protocols against emergent threats and enhancing ecosystem resilience.
Chrome V8 Engine Flaw Enables Crypto Wallet Drains
A critical type confusion vulnerability in Chrome's V8 engine permits arbitrary code execution, directly exposing user crypto assets to theft.
NPM Package Compromise Redirects Cryptocurrency Transactions via Phishing Attack
A supply chain compromise of critical npm packages, initiated by a phishing attack, injects malicious code to siphon browser-based cryptocurrency transactions.
Onyx Protocol Suffers $3.8 Million NFT Liquidation Contract Exploit
A critical flaw in the NFT liquidation contract allowed attackers to drain stablecoin reserves, compromising protocol integrity and asset peg.
Crypto Whale Loses $6.8 Million to Sophisticated Phishing Scam
A deceptive signature request vulnerability allowed an attacker to drain $6.8 million in digital assets, underscoring critical user-side security gaps.
New Gold Protocol Suffers $2 Million Flash Loan Price Manipulation
A single-source price oracle vulnerability enabled a flash loan attack, compromising $2 million and exposing critical DeFi risk.
OWASP Identifies Top 10 Smart Contract Vulnerabilities for 2025
The OWASP Smart Contract Top 10 for 2025 highlights persistent architectural flaws, posing systemic risk to decentralized finance protocols and user assets.
PlayDapp Suffers $290 Million Token Minting Exploit via Private Key Compromise
A compromised deployer private key enabled unauthorized token minting, creating a systemic risk of hyperinflation and devaluing existing assets.
GoPlus Suffers $169 Million Loss from Smart Contract and Insider Exploits
A confluence of smart contract vulnerabilities and insider access enabled the unauthorized manipulation of liquidity pools, leading to significant capital drain.
Chrome V8 Zero-Day Exploit Threatens Crypto Wallets
A critical type confusion vulnerability in Chrome's V8 engine enables remote code execution, posing a direct threat of crypto wallet compromise.
NPM Supply Chain Attack Compromises Crypto Wallets, DeFi Platforms
A supply chain compromise of critical NPM packages enables stealthy transaction hijacking, posing systemic risk to browser-based crypto operations.
JavaScript Supply Chain Attack Threatens DeFi Ecosystem
A compromised JavaScript package, widely integrated across DeFi, enables transaction hijacking, posing a systemic risk to user funds and operational integrity.
Browser Vulnerability Exposes Crypto Wallets to Private Key Theft
A critical V8 engine flaw permits arbitrary code execution, directly enabling private key exfiltration and severe digital asset compromise for browser users.
UXLINK Multi-Signature Wallet Compromised, $11.3 Million and Tokens Drained
A critical `delegateCall` vulnerability in UXLINK's multi-signature wallet allowed unauthorized administrative control, enabling asset exfiltration and illicit token minting.
UXLINK Exploiter Loses $48 Million to Sophisticated Phishing Attack
A malicious `increaseAllowance` signature allowed a phishing group to drain $48 million from a prior UXLINK exploiter, underscoring persistent social engineering risks.
Chrome V8 Engine Flaw Exposes Crypto Wallets to Private Key Theft
A critical Type Confusion vulnerability in Chromium's V8 JavaScript engine enables remote code execution, directly threatening digital asset private keys and facilitating wallet drains.
Chrome V8 Engine Vulnerability Exposes User Crypto Wallets to Theft
A critical Type Confusion bug in Chromium's V8 JavaScript engine allows malicious code execution, enabling private key theft and wallet drains.
