
Ravencoin Never Verified the Header Field That Just Broke Its Chain
Two mining pools now decide whether four days of transaction history survive, after the project team's request for a closer recovery point was refused.
Security threats, hacks, and cybersecurity in cryptocurrency.
24 articles

Two mining pools now decide whether four days of transaction history survive, after the project team's request for a closer recovery point was refused.
A 2021 firmware bug quietly gutted seed entropy on Mk3 devices, and an attacker who noticed swept the lot before dawn. Coinkite says Mk4, Q and Mk5 look safe on early analysis.
Three of six Gnosis Safe owner keys controlling the Hyperlane bridge ProxyAdmin sat on one machine. When the laptop was breached, the attacker drained 141 million H on Ethereum and minted 200 million more on BSC — and the H token fell 89 per cent.
THORChain confirmed on May 15 that one of its six Asgard vaults was compromised for roughly $10.7 million via a GG20 threshold-signature key-leak; on May 18, Blockaid flagged an $11.58 million drain on the Verus-Ethereum bridge caused by the same class of source-destination value-binding gap that broke Wormhole and Nomad in 2022.
Ethereum's co-founder published a long essay on Sunday arguing that machine-checkable mathematical proofs, generated and verified by AI, could become the foundational security layer for blockchains, cryptography and critical internet infrastructure — even as the same AI capabilities accelerate vulnerability discovery on the offence side.
A compromised admin key let an attacker mint 1,000 unbacked eBTC on Monad before Echo Protocol regained control and burnt the remaining 955 tokens. The nominal exposure was $76.7 million; the realised loss, laundered through Tornado Cash, came to about $821,700.
Binance launched Withdraw Protection on May 4, letting users freeze their account against on-chain withdrawals for up to seven days. A stricter lockdown mode disables early unlocking entirely. The feature exists because verified physical coercion attacks against crypto holders rose 75 per cent last year.
Blockchain intelligence firm TRM Labs reports that North Korean state-backed hackers stole approximately $577 million in 2026 — 76% of all crypto hack losses — across just two attacks: the Drift Protocol and Kelp DAO exploits.
Wasabi Protocol's deployer EOA held the only ADMIN_ROLE for the entire permission system, and an attacker drained roughly $4.55 million from perp vaults across four chains. The vulnerability was governance, not code.
Grinex, the sanctioned successor to Garantex, has suspended operations after attackers drained approximately $15 million from its systems. The exchange blamed 'foreign intelligence agencies' — a claim blockchain forensics firms have not corroborated.
Two incidents of internal staff accessing and leaking client data have armed a criminal group with KYC documentation and transaction records. Kraken says it will not pay and is working with law enforcement.
A week-long international enforcement campaign led by the US Secret Service and the UK's National Crime Agency traced $45 million in crypto fraud, froze $12 million, and disrupted over 120 scam domains.
The second-largest crypto exchange by volume says its internal controls caught a batch-transaction exploit modelled on the techniques that took down Mt. Gox, preventing what would have been one of the largest attempted thefts from a centralised venue.
America's largest bitcoin ATM operator revealed that attackers stole 50.9 BTC from its corporate settlement wallets in late March after compromising internal credentials, prompting an FBI investigation and a material event filing with the SEC.
Five days after North Korean hackers drained $270 million from Drift Protocol using social engineering and durable nonces, the Solana Foundation has unveiled STRIDE and the Solana Incident Response Network to overhaul ecosystem security.
Hackers compromise Curve's nameserver and redirect users to a cloned site, stealing $575K in approvals before the team regains control and directs users to curve.finance.
Badger DAO lost $120 million when attackers compromised its web interface, injecting malicious code that redirected user approvals to attacker-controlled addresses during fund transfers.
Upbit, a South Korean cryptocurrency exchange, lost approximately 342,000 ethereum worth $49 million in an abnormal transaction that transferred funds from the exchange's hot wallet to an unknown address on November 26.
Hackers stole approximately 7,000 bitcoin worth $40.7 million from Binance, the world's largest cryptocurrency exchange by trading volume, in a coordinated attack that exploited API keys and two-factor authentication codes.
QuadrigaCX discovered after its founder Gerald Cotten died that approximately $190 million in cryptocurrency held in cold storage wallets remained inaccessible because Cotten alone possessed the passwords and recovery keys required to unlock the encrypted systems.