Estimated $3.2 million lost after unauthenticated proof fields let old cross-shard receipts replay, crediting ONE without a source debit. Harmony confirmed an initial 4 billion ONE mint, its broader reconstruction reached 3.01 trillion. A rollback is planned and exchanges remain unnamed.
MÁS
$8.07 million lost from Coinsbuy across TRON and Ethereum in under an hour, then refilled ten drained wallets within half a day. One blog post since, no follow-up, Twitter account dormant since 2020. Nobody has said what actually failed.
MÁS
A firmware vulnerability silently routed Coldcard's hardware RNG for a guessable software fallback, letting attackers brute-force seeds offline. No phishing, no malware. $130 million reported stolen so far, at least 15 attackers, most funds still untouched, nobody caught.
MÁS
The numbers may differ, but the signal holds. The biggest crypto losses of H1 2026 passed every audit. The real attack surface was the keys, signers, and people around the code, not the code itself.
MÁS
A second exploit drained VerusCoin's Ethereum Bridge for $7.54 million, following a similar $11.6 million hack in May - same bridge, a different gap in the same broken trust boundary. This time there was no statement, no bounty, just silence.
MÁS
Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.
MÁS
AI keeps getting trusted before anyone checks if it should be. The bill is landing. Essays nobody can quote, wrongful arrests, insurance denials reversed 90% of the time, and data centers draining local water. The tool isn't the failure. Trusting it blind is.
MÁS
An attacker used a trusted price forwarder to feed the vault a fake $60K Bitcoin quote to drain $23.75 million from Ostium on Arbitrum, then collected the payout on trades that were never real.
MÁS
Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still moving in 2026.
MÁS
Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.
MÁS
$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.
MÁS
$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.
MÁS