Harmony - Rekt


Estimated $3.2 million lost after unauthenticated proof fields let old cross-shard receipts replay, crediting ONE without a source debit. Harmony confirmed an initial 4 billion ONE mint, its broader reconstruction reached 3.01 trillion. A rollback is planned and exchanges remain unnamed.

DAHA FAZLA

Coinsbuy - Rekt


$8.07 million lost from Coinsbuy across TRON and Ethereum in under an hour, then refilled ten drained wallets within half a day. One blog post since, no follow-up, Twitter account dormant since 2020. Nobody has said what actually failed.

DAHA FAZLA

Cold Card - Rekt


A firmware vulnerability silently routed Coldcard's hardware RNG for a guessable software fallback, letting attackers brute-force seeds offline. No phishing, no malware. $130 million reported stolen so far, at least 15 attackers, most funds still untouched, nobody caught.

DAHA FAZLA

Wrong Attack Surface


The numbers may differ, but the signal holds. The biggest crypto losses of H1 2026 passed every audit. The real attack surface was the keys, signers, and people around the code, not the code itself.

DAHA FAZLA

AFX Trade - Rekt


Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.

DAHA FAZLA

BonkDAO - Rekt


$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.

DAHA FAZLA