All Articles
31 articles
editorial-picksMAPO Bridge Exploit Mints 1 Quadrillion Tokens Through Solidity Encoding Flaw
A known Solidity encoding flaw in Butter Bridge V3.1 allowed an attacker to mint roughly 1 quadrillion MAPO tokens on May 20, collapsing the token's price and triggering an emergency bridge pause across Ethereum and BSC.
Web3 WatchGitHub Breach Hits Home for Crypto Devs as CZ Warns on API Keys
GitHub confirmed a poisoned VS Code extension breached an employee device and led to the theft of roughly 3,800 internal repositories. Binance founder Changpeng Zhao moved fast to warn crypto developers storing API keys in private repos.
Web3 WatchEcho Protocol Loses $816K After Admin Key Breach Unlocks Fake eBTC Mint
A compromised admin key on Echo Protocol's Monad deployment led to $816K in confirmed losses after an attacker minted 1,000 unbacked eBTC, borrowed against them on Curvance, and laundered the proceeds through Tornado Cash.
editorial-picksVerus Bridge Loses $11.5M Days After Its Own Critical Security Update
Seven days before the Verus-Ethereum Bridge lost $11.58 million in a single transaction, the project had shipped what it called a critical security update. The patch addressed a Bitcoin Core node vulnerability. The bridge was a different story.
Web3 WatchTHORChain's GG20 Hack Exposes a Cryptography Flaw That Could Hit Other Protocols
THORChain confirmed a $10.7M exploit tied to a flaw in GG20 threshold signature cryptography. The attacker rebuilt the vault's private key from the inside. Here's what that means for the rest of DeFi.
editorial-picksTHORChain Exploit Drains $10.8M Across Four Chains, Funds Still Moving
THORChain suffered a $10.8M multi-chain exploit on May 15, 2026. Trading was halted after node operator SamYap called for an emergency global pause. On-chain data shows stolen funds are still being laundered in real time.
Web3 WatchAurellion Labs Loses $455K USDC in Diamond Proxy Re-Init Attack
Aurellion Labs lost 455,003 USDC after an attacker exploited an unprotected initialize function in its Diamond proxy, seized ownership, and drained approved wallets.
Web3 WatchCoW DAO Taps Legal Reserve to Repay $1.2M DNS Phishing Victims
CoW DAO approved CIP-86 to repay $1.2M lost in the April 14 DNS hijack. Victims must file claims by May 14. Here's what you need to know.
Web3 WatchLayerZero Admits Comms Failure as Lazarus Attack Detail Stays Unanswered
LayerZero admits comms failure after Lazarus Group's $290M RPC attack. New OneSig multisig and DVN overhaul announced, but the RPC entry vector stays unexplained.
Showing 1–9 of 31 articles