Cold Card - Rekt


A firmware vulnerability silently routed Coldcard's hardware RNG for a guessable software fallback, letting attackers brute-force seeds offline. No phishing, no malware. $130 million reported stolen so far, at least 15 attackers, most funds still untouched, nobody caught.

DAHA FAZLA

Wrong Attack Surface


The numbers may differ, but the signal holds. The biggest crypto losses of H1 2026 passed every audit. The real attack surface was the keys, signers, and people around the code, not the code itself.

DAHA FAZLA

AFX Trade - Rekt


Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.

DAHA FAZLA

BonkDAO - Rekt


$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.

DAHA FAZLA

Digging for Gold


Multi-strategy yield protocol Altura, raised $39 million for a gold-backed strategy, moved funds through Tron, relied on a verifier tied to the COO's own project, ran a dashboard that admitted it verified nothing, closed the vault, and left depositors waiting.

DAHA FAZLA

SecondFi - Rekt


A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already there.

DAHA FAZLA