Antisemitic incidents ‘rise by a fifth’ amid US-Israel war with Iran
67 incidents. $763.97M gone. Q2 2026 Report is worth reading carefully.
Hacken's Security & Compliance Report breaks down what happened, what failed to prevent it, and what that means for the rest of the year:
Show more
Two incidents over the last 24 hours resulted in elevated errors or reduced availability on Claude for some users. Multiple separate network failures cut into our capacity to serve Claude, and some requests failed while we rerouted traffic.
Show more
As security incidents continue to increase across the crypto ecosystem, we’ve also seen a recent increase in malicious proposals targeting token-voting governance systems on Aragon. These proposals are designed to get control of enough tokens to drain liquidity pools.
This isn’t unique to Aragon, but it’s a good reminder to review your governance setup, monitor proposals closely, and make sure appropriate safeguards are in place.
Depending on your governance model, there are several ways to strengthen security:
• Extend voting durations and add timelock stages. Longer voting windows and a timelock before execution give token holders, contributors, and security teams more time to identify malicious proposals and coordinate a response. If your governance process allows early execution, consider using standard voting so proposals can never execute before the voting period ends.
• Restrict proposal creation. Limiting proposal creation to members of your governing bodies, or requiring a minimum token balance to create a proposal, can reduce spam and opportunistic attacks while preserving decentralized governance.
• Review quorum settings. Make sure treasury proposals require meaningful token holder participation before they can pass, and periodically review quorum thresholds as voter participation and governance activity evolve.
• Consider optimistic governance with a token holder veto. In this model, a trusted group such as a core team or multisig creates proposals, while token holders retain the ability to veto them during a protected objection window. This reduces voting overhead while preserving decentralized control, but it depends on token holders actively monitoring proposals and responding before the objection window closes.
Governance security is an ongoing process, and every project should regularly review its governance configuration as threats evolve.
We’ll continue building tools to make governance and execution more secure while helping projects strengthen their governance. If you’d like us to review your setup or discuss additional protections, our team is happy to help. Please reach out.
Show more
0 notable incidents across over 380,000 miles traveled by Robotaxi
⚠️Top 10 Security Incidents (January–June 2026)
1:KelpDAO, April 18, loss of approximately $292 million. The attacker exploited a verification flaw in the LayerZero-related cross-chain bridge validation flow, released a large amount of unbacked rsETH, and rapidly supplied it to protocols including Aave, Compound, Euler, and Fluid for borrowing and cashing out, ultimately evolving into a cross-protocol bad debt contagion event.
2:Drift Protocol, April 1, loss of approximately $285 million. The attacker obtained protocol administrative control by leveraging durable nonce, social engineering, and weaknesses in multisig governance, then introduced forged collateral assets and manipulated protocol parameters to drain a large amount of real assets from the protocol.
3:Step Finance, January 31, loss of approximately $40 million. The compromise of high-privilege devices and the treasury private key system resulted in significant asset losses. On February 24, the project announced it would cease operations.
4:Humanity Protocol, June 9, loss of approximately $31 million to $36 million. The root cause was improper management of private keys and multisig keys. After compromising critical devices, the attacker took over bridge administrative privileges and carried out fund transfers and abnormal minting across multiple chains.
5:Truebit, January 8, loss of approximately $26.6 million. The attacker exploited an integer overflow/pricing logic flaw in a legacy contract to mint a large amount of TRU at low cost and dump the tokens on the market, causing the token price to collapse rapidly.
6:Resolv Labs, March 22, loss of approximately $25 million. After obtaining high-privilege signing capabilities, the attacker exploited the lack of supply caps and ratio validation in the minting logic to mint approximately 80 million unbacked USR and cash them out.
7:SwapNet, January 25, loss of approximately $13.4 million. Its closed-source contract contained arbitrary-call / approval abuse risks. The attacker leveraged users' existing approved allowances to trigger malicious transferFrom calls and drained users' assets at scale.
8:Verus-Ethereum Bridge, May 18, loss of approximately $11.58 million. The cross-chain bridge failed to strictly verify whether the source-chain input amount matched the destination-chain release amount during the validation process. The attacker exploited this flaw to forge valid payloads and withdraw assets.
9:YieldBlox, February 22, loss of approximately $10.97 million. The attacker manipulated the price of USTRY in a low-liquidity market, causing the oracle to overestimate the collateral value, and then executed excessive borrowing from the Stellar lending pool.
10:THORChain, May 15, loss of approximately $10.7 million. A newly joined node operator exploited weaknesses in the GG20 threshold signature scheme, compromised a single vault, and withdrew assets across multiple chains, exposing the systemic risks of cross-chain signing infrastructure.
Show more
Bizarre NYC sewer spelunker incidents may have simple explanation: sources
We're detailing two new incidents that occurred during external cyber evaluations conducted by independent evaluation partners.
We outline what happened, how the activity was contained, and how we’re working with evaluators to strengthen our approach to third-party testing.
Show more
The Onchain Security Roundup tracked three incidents last week with $122M+ in reported losses
Coldcard / Coinkite: ~$114M. A five-year-old firmware defect in Coldcard hardware wallets routed seed generation through a weak software randomiser (instead of the hardware RNG), allowing an attacker to reconstruct victims' private keys entirely offline and sweep their bitcoin. There have been 3 confirmed waves of losses with a potential 4th one ongoing.
Coinkite published an advisory on July 30 and shipped emergency firmware on July 31, but installing it doesn't repair a previously generated seed.
CryptoDAO PRO (BNB Chain): ~$7.56M–$8.2M. The function that pays out PRO rewards was open for anyone to call, with no permission check and no limits. The attacker called it repeatedly, dumping 2.8M PRO into PancakeSwap and driving the price down 32%.
@HypernativeLabs identifies the fault with CryptoDAO's own distributor contract rather than PancakeSwap.
LULA (BNB Chain): ~$578.1K. LULA's token contract had a privileged function that could pull tokens out of its own PancakeSwap trading pool, skipping the usual transfer checks, and then tell the pool to treat the reduced balance as correct. The attacker staged helper contracts 12 days earlier, then used a $237M flash loan to load the pool with USDT, drained the LULA side until each remaining token looked enormously valuable, and sold a small amount back at the skewed rate.
Onchain risk expands beyond smart contracts to firmware and signer design around the protocol layer
Key generation, privileged token mechanics, and operational dependencies can all turn into loss vectors
Evaluating all of the different risks your capital is exposed to can be a difficult task, but Nexus Mutual is here to help
You’re Covered with Nexus Mutual
Show more
There have already been 2 KOL farming incidents in the ARC ecosystem
First, the OTC bridge, where people bought USDC at 60x the real price, then started vamping over 300K USDC after it got shilled by vamp KOLs
Second, trading through some unclear bridge mechanism into a USD platform, handled by one person, while ARC USDC is not even officially live yet
What comes next??? It is obvious that the people promoting this are cancer across multiple chains, They come in, take profit in one day, then leave everyone else stuck there holding losses
Why not just build for the ecosystem instead, and start trading when ARC officially launches its bridge and mainnet announcement?
You are not going to find the next $CASHCAT like this, $CASHCAT started in a fair way, without forcing too much hype
Excessive FOMO is never healthy for a chain ecosystem
Show more