TOPIC ARCHIVE

Web3

Selected Web3 developments from public primary sources.

P0
SlowMist Hacked

Coldcard hacked — $100.00M lost

Coldcard hardware wallets (by Coinkite) suffered from a firmware bug (since March 2021 on certain versions) that generated seeds with insufficient entropy (~40 bits on Mk3, ~72 bits on newer models vs. the intended 128 bits). Attackers off…

P0
SlowMist Hacked

AFX Bridge hacked — $24.15M lost

The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for…

P0
SlowMist Hacked

Ostium hacked — $18.00M lost

Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draini…

P0
SlowMist Hacked

Wanchain Cardano-BNB Chain Bridge hacked — $10.00M lost

Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspe…

P0
SlowMist Hacked

BonkDAO hacked — $20.00M lost

BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contr…

P0
SlowMist Hacked

Coldcard hacked — $70.20M lost

On July 30, 2026, between 01:10 and 01:51 UTC, a critical entropy vulnerability in Coldcard Mk3 hardware wallet firmware (versions 4.0.1–4.1.9) caused the device to use a weak software PRNG instead of the hardware true random number genera…

P0
SlowMist Hacked

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P1
SlowMist Hacked

Coinsbuy hacked — $7.90M lost

Wallets linked to Coinsbuy (a B2B crypto payment processor) were drained of more than $7.9 million across Ethereum and TRON around 13:00 UTC on August 9, 2026. The attacker laundered part of the funds into Monero (XMR) via exchanges, while…

P1
SlowMist Hacked

Bonzo Lend hacked — $9.05M lost

Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The bo…

P1
SlowMist Hacked

Lazy Summer Protocol hacked — $6.04M lost

Lazy Summer Protocol (under Summer.fi) USDC vaults were exploited due to NAV/share price calculation flaw. The attacker used flash loans and pre-accumulated overvalued Silo tokens to inflate vault NAV (~9.5%), redeeming at inflated price a…

P1
SlowMist Hacked

WEMIX hacked — $6.25M lost

The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before be…

P1
SlowMist Hacked

Verus Ethereum Bridge hacked — $7.54M lost

The Verus Ethereum Bridge was exploited again. The attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, draining approximately $7.54 million in assets (ETH, tBTC, USDC, etc.) from the bridge reserves.…

P1
Halborn Security Research

Explained: The Coldcard Hack (July 2026)

Starting on July 30, 2026, the wallets of users of the Coldcard hardware wallet began being drained. The attackers took advantage of a bug in the cold wallet’s key generation code, which allowed them to reconstruct private keys and steal a…

P1
SlowMist Hacked

Allbridge Core hacked — $1.65M lost

Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $…

P1
SlowMist Hacked

Crypto DAO hacked — $8.20M lost

Crypto DAO’s Pro token contract was exploited due to a missing access-control check; an attacker called a publicly accessible vault function and drained approximately $8.2 million in USDT.

P1
SlowMist Hacked

SecondFi hacked — $2.40M lost

SecondFi (formerly Yoroi) Cardano wallet suffered an exploit due to a vulnerability in its proprietary web wallet generation software, exposing private keys at the address level. Attackers drained ~16 million ADA ($2.4M) from 374 affected…

P1
BlockSec Security Insights

COLDCARD Incident: When a Wallet's "Random" Seed Wasn't Random

A silent build-and-integration bug in COLDCARD firmware routed Bitcoin seed generation onto a software RNG fallback, whose weak randomness left wallet seeds recoverable offline. Because the weakness is in the seed itself, a firmware update…

P1
BlockSec Security Insights

Newsletter - July 2026

July 2026's three largest DeFi incidents totaled approximately $67.9M in losses across Arbitrum and Solana. AFX Trade lost ~$24.15M after a supply chain attack compromised validator signing authority. Ostium's OLP vault was drained of ~$23…

P1
Rekt News

AFX Trade - Rekt

Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.

P1
Rekt News

Zunami Protocol - Case File

Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still movi…

P1
Halborn Security Research

Explained: The AFX Bridge Hack (July 2026)

In July 2026, AFX Trade, an Arbitrum-based decentralized perpetuals exchange, was the victim of a hack. Halborn explains what happened.

P1
Halborn Security Research

Explained: The Ostium Hack (July 2026)

In July 2026, Ostium, an Arbitrum-based perpetuals exchange, was the victim of a hack. Halborn explains what happened.