Independent RWA research desk · Status: operationalMethodology & corrections · Submit a story
BTC$86.1K+1.01% ETH$2.7K+0.62% DeFi TVL$97.1BMarket data DEX 24h$11.6BMarket data ETH gas0.36 gweiNetwork data 2026-09-23 07:49 UTC

DeFi Incident Tracker

Methodology →

Confirmed facts, reports under review and unresolved questions are kept separate. Records without verified sources are not presented as confirmed incidents.

Incident database

41 records match
EventDateChainTechniqueLossStatusConfidence
Whitehats move 52 bitcoin from the Coldcard hackAccording to Galaxy Digital, the good guys have moved 52 BTC to an address carrying an OP_RETURN message reading "claim:cryptorecoverytrust dot com."2026-09-22BitcoinSecurity incidentUnavailableConfirmed80%Open →
White hats outrun Coldcard hackers in 52-Bitcoin evacuationWhite hats secured about 40% of the Bitcoin moved in the Coldcard exploit’s second wave, transferring it to a Wyoming trust for victims.2026-09-22BitcoinExploitUnavailableUnder review55%Open →
Ledger CTOTL;DR: Charles Guillemet, Chief Technology Officer at Ledger, issued a public alert on September 21, 2026, regarding the DarkSword exploit chain targeting Safari. The threat chains six iOS security flaws that compromise the JavaScriptCore engine, bypass sandbox isolation, and exploit the system kernel. Google confirmed that the original vulnerabilities in the chain were patched starting ... Read more2026-09-21Not specifiedCredential compromiseUnavailableUnder review55%Open →
SlowMistSlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets. SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s…2026-09-21Not specifiedCredential compromiseUnavailableUnder review55%Open →
Pragma flags 6 price feeds as critical riskThe September 18 assessment exposes a gap between oracle valuations and the liquidity lenders need to sell collateral. The post Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit appeared first on CryptoSlate .2026-09-22Not specifiedExploit$3.5MUnder review55%Open →
SlowMistSlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets. SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s…2026-09-21Not specifiedCredential compromiseUnavailableUnder review55%Open →
Google Admits Gemini AIGoogle learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks.2026-09-21Not specifiedSecurity incidentUnavailableUnder review55%Open →
Why Balancer’s $1.4M hack recovery won’t pay LPsThe pending plan uses attack-time losses and pre-exploit pool balances, but no V1 claim window is open. The post Why Balancer’s $1.4M hack recovery won’t pay LPs anytime soon appeared first on CryptoSlate .2026-09-21Not specifiedExploit$1.4MUnder review55%Open →
Why Balancer’s $1.4M hack recovery won’t pay LPsThe pending plan uses attack-time losses and pre-exploit pool balances, but no V1 claim window is open. The post Why Balancer’s $1.4M hack recovery won’t pay LPs anytime soon appeared first on CryptoSlate .2026-09-21Not specifiedExploit$1.4MUnder review55%Open →
One wallet links $1.55 million FetchAI theft toFetch.ai says its own contracts were unaffected, while shared bridge routes leave an unresolved NTX supply question. The post One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint appeared first on CryptoSlate .2026-09-21Not specifiedSecurity incident$1.6MUnder review55%Open →
SecondFiSecondFi has warned holders of compromised wallets not to redeem upcoming NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address. According to SecondFi, some users affected by its June security incident…2026-09-21Not specifiedCredential compromiseUnavailableUnder review55%Open →
X sues Bitcoin account operators over alleged $278KX alleges six Bitcoin-focused accounts coordinated posts and engagement to inflate creator payouts, with claimed and projected losses of at least $378,000.2026-09-21BitcoinFraud or scam$278.0KConfirmed80%Open →
SecondFiSecondFi has warned holders of compromised wallets not to redeem upcoming NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address. According to SecondFi, some users affected by its June security incident…2026-09-21Not specifiedCredential compromiseUnavailableUnder review55%Open →
MultiversXMultiversX has come under formal trading review at Upbit after the South Korean exchange flagged EGLD on Sept. 21 following a mainnet security incident that forced the network to stop progressing. Upbit’s official notice designated EGLD/KRW, EGLD/BTC and EGLD/USDT as…2026-09-21Not specifiedExploitUnavailableUnder review55%Open →
Fetch.aiFetch.ai reports a security breach affecting SingularityNET contracts, revealing crucial operational updates. The post Fetch.ai Confirms SingularityNET Exploit appeared first on Coinfomania .2026-09-20Not specifiedExploitUnavailableUnder review55%Open →
Fetch.ai and NuNetThe same exploiter was linked to attacks involving Fetch.ai (FET) and NuNet (NTX), with roughly $2 million in assets involved. Security firms tied both events to the same wallet. NuNet’s token lost more than 70% of its value and touched an all-time low on September 20. How One Attacker Reached Two Protocols Blockaid said on The post Fetch.ai and NuNet Exploited for $2 Million by Same Attacker, NTX Hits All-Time Low appeared first on BeInCrypto .2026-09-20Not specifiedExploit$2.0MUnder review55%Open →
Blink Wallet pauses services after attacker drains custodialThe breach underscores the inherent risks of custodial crypto services, accelerating the shift towards self-custody amid regulatory pressures. The post Blink Wallet pauses services after attacker drains custodial accounts appeared first on Crypto Briefing .2026-09-19Not specifiedSecurity incidentUnavailableUnder review55%Open →
GoogleFour frontier AI labs have now confirmed that their models reached the open internet and then accessed the systems of real companies. Google joined that list on Friday, roughly four months after its own incidents happened. Gemini accessed three real companies during a May evaluation. Notably, the model stopped in all three cases. Google’s Gemini The post Google Confirms Gemini Hacked 3 Real Companies in May Safety Test appeared first on BeInCrypto .2026-09-19Not specifiedSecurity incidentUnavailableConfirmed80%Open →
Investigadores ganan $6,500 tras hackear OpenAI con ClaudeEl propio modelo de IA de un competidor terminó haciendo la mayor parte del trabajo en un ataque contra OpenAI. Los investigadores de Hacktron AI usaron Claude, de Anthropic, para escribir código de exploit funcional. Toda la intrusión tomó menos de 72 horas. OpenAI terminó pagando una recompensa de 6,500 dólares cuando el equipo demostró El post Investigadores ganan $6,500 tras hackear OpenAI con Claude de Anthropic fue visto por primera vez en BeInCrypto .2026-09-18Not specifiedExploit$6Confirmed80%Open →
7,000 Crypto Wallets Targeted as North Korean HackersTL;DR: Japan’s National Police Agency and the FBI confirmed the infection of over 30,000 devices and the theft of credentials from 7,000 wallets across more than 100 countries. Addresses controlled by the attackers received at least 1.7 billion yen (approximately $10.71 million) between December 2025 and July 2026. Law enforcement dismantled Japan’s first operational “laptop ... Read more2026-09-18Not specifiedCredential compromise$10.7MConfirmed80%Open →
North Korean hackers stole 7,000 crypto wallet records,North Korea linked hacking group WaterPlum has compromised more than 30,000 devices across over 100 countries and regions, stealing information from more than 7,000 cryptocurrency wallets while targeting developers through fake recruitment campaigns. Japan’s National Police Agency said on Sept.…2026-09-18Not specifiedCredential compromiseUnavailableUnder review55%Open →
Blockchain malware activity jumps 440% as AI lowersPublic chains preserve malware instructions beyond ordinary domain takedowns, shifting defense toward monitoring wallets, contracts and off-chain servers. The post Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers appeared first on CryptoSlate .2026-09-18Not specifiedMalwareUnavailableUnder review55%Open →
Ethereum Founder Vitalik Buterin Says AI Won’t DoomThe Ethereum co-founder said AI could help developers mathematically verify entire software systems, turning the same technology powering new attacks into a tool for defense.2026-09-17EthereumSecurity incidentUnavailableUnder review55%Open →
Cardano’s Splash fix patches the exploit, but leavesThe exploit drained 2.42 million ADA net, while OADA lacks protocol redemption and faces a thin-pool overhang. The post Cardano’s Splash fix patches the exploit, but leaves 2.4M ADA missing and holders trapped appeared first on CryptoSlate .2026-09-17Not specifiedExploitUnavailableUnder review55%Open →
Hacker turned 55 days of failed transactions into a $3 million master key thatLedger timestamps and SDK patches show why signed intent needed automatic checks before funds reached a bridge. The post Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets appeared first on CryptoSlate .2026-09-17Not specifiedSecurity incident$3.0MUnder review55%Open →
State hackers drive 420% surge in onchain malware,North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions.2026-09-17BitcoinMalwareUnavailableUnder review55%Open →
Chainflip to reset TRON USDT provider balances toProviders retain a separate on-chain record of what they are owed, but Chainflip has not disclosed repayment timing. The post Chainflip to reset TRON USDT provider balances to zero following $736,000 exploit appeared first on CryptoSlate .2026-09-17TronExploit$736Under review55%Open →
Revolut says no direct contact after $3 millionRevolut says it received no direct contact despite separate ransom demands for $3 million in Monero and 10,000 Bitcoin from competing breach claimants.2026-09-17BitcoinSecurity incident$3.0MConfirmed80%Open →
Chainflip to reset TRON USDT provider balances toProviders retain a separate on-chain record of what they are owed, but Chainflip has not disclosed repayment timing. The post Chainflip to reset TRON USDT provider balances to zero following $736,000 exploit appeared first on CryptoSlate .2026-09-17TronExploit$736Under review55%Open →
ERA Launches Software Wallet, Turning Its Hardware DeviceThe companion app connects to the ERA hardware wallet to add portfolio management, swaps, and dApp access across 14 networks — while private keys never leave the device. The release follows a full independent security audit by Cure53, and lands alongside a major update to ERA Lens, ERA’s on-device scam-warning system, plus new hardware-side capabilities The post ERA Launches Software Wallet, Turning Its Hardware Device Into a Full Self-Custody Ecosystem appeared first on BeInCrypto .2026-09-16Multi-chainCredential compromiseUnavailableUnder review55%Open →
OpenAI's Rogue AI Agents Were Probing Hugging FaceAn independent researcher found the agents hijacked Hugging Face accounts and mapped the platform's defenses as early as May 13—activity OpenAI's own incident report never fully described.2026-09-16Not specifiedSecurity incidentUnavailableUnder review55%Open →
Hackers Hijack HBO Max’s Reddit Account to SpreadAttackers ran 108 malicious ads through the streaming service’s verified account, directing users to fake software downloads.2026-09-16Not specifiedMalwareUnavailableConfirmed80%Open →
Celsius sues BitMEX for $495 million just 11Celsius Network’s bankruptcy estate has sued BitMEX over a 2020 liquidation cascade it says cost more than 6,360 Bitcoin. The complaint, filed Sept. 12 in the US Bankruptcy Court for the Southern District of New York, accuses entities behind the crypto derivatives exchange of fraud, market manipulation and wrongful liquidations during Bitcoin’s historic March 2020 […] The post Celsius sues BitMEX for $495 million just 11 days before exchange shutdown appeared first on CryptoSlate .2026-09-16BitcoinFraud or scam$495.0MUnder review55%Open →
VymopayMost people searching for a no-kyc crypto exchange alternative are not looking for less compliance, they are looking for less exposure. Less counterparty risk. Less reliance on a custodian that could be hacked, frozen, or insolvent when they need their…2026-09-16Not specifiedSecurity incidentUnavailableUnder review55%Open →
KREMLIN malware uses Ethereum to update attack serversKREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil.2026-09-16EthereumMalwareUnavailableUnder review55%Open →
Did crypto’s $20 Billion DeFi surge just getStablecoin growth stayed below 6% while ETH and SOL gained more than 32%, leaving the inflow picture unresolved. The post Did crypto’s $20 Billion DeFi surge just get stolen by price inflation? appeared first on CryptoSlate .2026-09-15Not specifiedSecurity incident$20.0BUnder review55%Open →
Balancer proposes shutdown and treasury distribution to BALBalancer's shutdown highlights governance challenges in DeFi, emphasizing the need for adaptive strategies amid financial instability and exploits. The post Balancer proposes shutdown and treasury distribution to BAL holders appeared first on Crypto Briefing .2026-09-14Not specifiedExploitUnavailableConfirmed80%Open →
MetaMask Adds New Wallet Protections Against Crypto ScamsMetaMask’s latest safeguards flag suspicious transfers and stop transactions that don’t match their previews.2026-09-14Not specifiedFraud or scamUnavailableUnder review55%Open →
AI Agents Just Slashed the Cost of aThe ECDSA.Fail challenge cut a resource benchmark for one component of a potential quantum attack by 86%.2026-09-10BitcoinSecurity incidentUnavailableUnder review55%Open →
Anthropic Discloses Fourth Claude Hacking Incident as DebateThe company now says attacks during security tests exposed model behavior failures, after initially emphasizing errors in its testing infrastructure.2026-09-10Not specifiedSecurity incidentUnavailableUnder review55%Open →
Trezor, BitBoxBitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.2026-09-10Multi-chainPhishingUnavailableUnder review55%Open →