Issue #004 · Week of July 26, 2026
This Week’s Verdict
The malware this week did not arrive as a file; it arrived as instructions and let your browser do the assembly. Meanwhile the CeFi graveyard added another headstone, DPRK ran both sides of the crime (stealing funds, then arresting the launderers), and the market spent its energy debating quantum roadmaps instead of reading the withdrawal queues. As always, by the time the token cratered 59%, the exit was already priced in.
The Breaches
The headline number belongs to two Ethereum bridges that lost a combined $31.7 million within hours of each other, with a third protocol halting staking as the contagion spread. Bridges remain the softest target in the stack, and nothing about that has changed in three years.
Elsewhere, crypto payments firm Triple-A was drained for $9.7 million in a wallet compromise. And the slow-motion breach nobody labels a breach continued: BitMart announced it will wind down after nine years, its BMX token cratering roughly 59% in 24 hours while users reported withdrawal delays. The global CEO says he learned of the closure when it went public and was told his employment was ending on July 24. When the people running the exchange find out from the press, the depositors were never going to be first in line.
BitMEX joined the wind-down list with its own legal tail: Arthur Hayes, Samuel Reed, and Benjamin Delo face a proposed class action alleging an “Insider Trading Desk” and deliberate server freezes tied to 623 BTC in liquidation claims. Old allegations, new courtroom, same collateral.
Vulnerabilities Worth Your Attention
- SourTrade malvertising (detailed by Confiant on July 23): fake TradingView, Solana, and Luno pages ship malware in pieces and have the victim’s browser assemble the final Windows executable in memory using the legitimate Bun runtime. No single malicious payload sits at a fixed URL to block, which is the entire point.
- Fastjson 1.x (CVE-2026-16723, CVSS 9.0): unauthenticated RCE in Alibaba’s Java JSON library, actively exploited in Spring Boot apps, with no patch available. If you run this, you are already exposed.
- GitLab RCE PoC: working exploit published July 24 for a flaw GitLab patched on June 10. Any authenticated user who can push to a project owns unpatched self-managed 18.11.3 servers. Six weeks was your grace period.
- Certighost: a low-privileged Active Directory user obtains a Domain Controller certificate, then pulls the krbtgt secret via DCSync. Full domain compromise from a nobody account.
- AgentForger (Zenity Labs): a single phishing link could build and deploy a rogue autonomous agent inside a victim’s org via ChatGPT Workspace Agents. Patched by OpenAI on June 8, but a preview of where the next class of breaches lives.
- Supply-chain defenses, finally: GitHub and PyPI added a time-based cooldown to Dependabot to blunt the window when a freshly published malicious package gets auto-pulled. A structural fix, not a signature. Rare and welcome.
Threat Actors & Campaigns
North Korea worked both ends of the table. BlueNoroff was found running an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains, profiling victims’ crypto wallets before delivering malware in ClickFix-style social engineering. At the same time, Daily NK reports the DPRK arrested former state cyber operators accused of hacking two of its own state banks and laundering the proceeds through crypto. The regime tolerates crimes committed for the state, not against it.
Golden Chickens resurfaced with four new malware families (TinyEgg, ChonkyChicken and a modular variant, plus a browser credential stealer), proving that public disclosure inconveniences these operations without ending them.
On the AI-abuse front, a threat actor pointed the open-source Hermes AI agent in unattended “YOLO” mode at Thailand’s Ministry of Finance, letting it hunt for root and traverse the network autonomously. This is the automation of post-exploitation, and it is no longer theoretical.
And a reminder that social engineering, not clever cryptography, is the primary attack surface: Binance now red-teams its own staff monthly against exactly this. They are not being paranoid.
The Bigger Picture
The board is tilting toward real-world assets. On Hyperliquid, tokenized RWAs (stocks, commodities, indices) became the largest trading category for the first time, more than half of weekly volume, prompting ARK to declare a regime change. CoinDesk noted the institutional influx has quietly killed the memecoin craze. In Brazil, farmers tokenized dairy cows to collateralize loans on B3, ten cows backing a $19,600 credit, which is either the future of RWA lending or the most literal bull market on record.
On the regulatory front, the CLARITY Act is on the ropes: Galaxy cut its passage odds to 30% as Senate Majority Leader John Thune signaled it likely misses the August recess, with Democrats rejecting the GOP ethics language. The EU dropped its 21st Russia sanctions package, targeting a claimed $120B crypto network and adding HTX, EXMO, Rapira, and others to a transaction ban starting August 23, while Chainalysis flagged the new third-country ban mechanism. Meanwhile the OCC denied Wise’s national trust charter over AML/CFT concerns, an unusual rejection amid a wave of approvals; Wise plans to refile under the GENIUS Act.
The infrastructure keeps quietly rotting and rebuilding at the edges: Poolin, once Bitcoin’s biggest mining pool, filed for bankruptcy, still owing 11,700 users. Odos and Dango are shutting down. And Samsung Wallet will add stablecoin support including Circle’s USDC, which puts stablecoins on hundreds of millions of phones with no timeline attached. That last one, if it ships, matters more than any price chart this week.
Resources
- https://www.reddit.com/r/CryptoCurrency/comments/1v6940c/two_ethereum_bridges_lose_317m_within_hours_as/
- https://www.reddit.com/r/CryptoCurrency/comments/1v6aplc/crypto_payments_firm_triplea_hit_by_97_million/
- https://thedefiant.io/converge/cefi/bitmart-to-wind-down-exchange-end-trading-by-aug-26
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
- North Korea Slips Into Consensys While macOS Malware Reads Your Telegram
- Issue #002 — Week of July 12, 2026
- Token Approvals and the Infinite Allowance
More: Issues · Field Notes · RTFM
New Issue every week. Follow @ItsAlreadyPrice or subscribe via RSS so the next exploit does not surprise you.