Short, tactical, daily. The weekly Issues are the verdict — these are the ticks in between.
-
Moonwell bled $8.7M to a MAMO oracle manipulation on Base, and Lightning node operators face an emergency patch cycle after AI-found bugs.
-
Active exploitation of a critical Gitea RCE (CVE-2026-60004) and a second unsafe-deserialization pair in Kaltura's mwEmbed threaten the self-hosted infrastructure crypto teams quietly run.
-
Galaxy pegs Coldcard hack at 1,789 BTC, and a max-severity Oracle WebLogic bug is under active exploitation.
-
Term Finance bled $8.5M when an attacker bought governance power and drained the Meta Vaults, a reminder that on-chain votes are an attack surface.
-
The Sandbox bridge got hit, minting unbacked SAND on Base and BSC while Korean exchanges slammed the doors.
-
A $3M BounceBit exploit kills a chain, MANTRA freezes after a Cosmos EVM fault, and Coldcard patches a $130M-class seed flaw.
-
MANTRA halts its chain after a Cosmos EVM exploit, and Coldcard tells users their existing seeds may already be compromised.
-
Two live wallet-drainer campaigns (40 malicious Firefox extensions and a Rapid7-tracked SMS phishing operation) are actively hunting seed phrases while everyone watches the short squeeze.
-
MAYAChain halted after six chained bugs let a 23-message transaction drain the pools, and 200K Bits of Gold customers had their data leaked.
-
BitBox and SafePal both cough up hardware wallet trouble on the same day, one firmware, one data leak.
-
SafePal wallet breach exposes 39,798 customers to physical and phishing risk while Harmony floats another chain rollback after the ONE exploit.
-
Two data leaks tie real names to real crypto stacks, and a fake DefiLlama app on Apple's own store was draining wallets.
-
A Privy security incident hits Kraken-linked wallets, Coldcard-related BTC thefts near $150M, and a French tax breach exposes 678,000 people as physical attacks climb.
-
Neutrl halts NUSD redemptions over an undisclosed reserve problem, and Tether's KPMG audit ships without the actual statements.
-
Harmony ONE cracks 40% on an alleged 4B-token mint, Trezor buyer data leaks via a shipping partner, and a SharePoint auth bypass is now under active exploitation.
-
Harmony's ONE minted into oblivion, Ravencoin faces a 51% reorg, and a small XRP bridge got fooled by fake deposits.
-
A Ravencoin block flaw, a drained BTCPay server, and a possibly insolvent BitMart converge on the same lesson: your funds are only as safe as the code and custodians holding them.
-
Coinsbuy loses $8M in a coordinated two-chain hit, and a malicious 'Solidity Pro' VS Code extension is draining dev wallets and keys.
-
Attackers are draining BTCPay Server Lightning nodes via remote access, and the Coldcard exploit is still pulling institutional money into ETFs.
-
BTCPay Server has a live, actively exploited flaw draining Lightning nodes, and a macOS ClickFix stealer is emptying crypto wallets.
-
The Coldcard exploit has moved from disclosure to on-chain reality, with 210,000 BTC fleeing old wallets and a French tax leak turning holder lists into physical threats.
-
A twelve-year-old weak RNG in CryptoJS drained $5.7M from five wallet apps, while the Coldcard thieves start washing 64 BTC and 200 ETH through mixers.
-
A Coldcard entropy flaw put roughly $120M and every seed generated on affected units in play, while a Gitea file-read bug and CISA's Langflow RCE round out a rough day for anyone running their own stack.
-
The Coldcard sweep is live, losses past $100M and climbing, and phishing operators are already surfing the panic with fake 'hardware audit' emails.
-
Coldcard hardware wallet drains near $114M and enter a suspected fourth sweep, five days in.
-
A 2021 Coldcard firmware bug crippled seed entropy, and someone spent it, sweeping ~1,082 BTC (~$70M, now near $89M) from 4,500 addresses in minutes.
-
Coldcard drain hits $70M via a supply-chain style exploit that never touched the devices, plus Metronome's $15.7M oracle-lag shortfall and the Adform clipboard-swap campaign.
-
A weak-RNG flaw in Coldcard Mk3 firmware drained 594 BTC ($38M) from ~500 addresses in a 25-minute sweep, and the vendor confirms it.
-
Ostium's $24M off-chain breach and a fake Flare staking site draining $8.5M in XRP prove the perimeter is you, not the contract.
-
Two live software supply-chain compromises plus an Apple-listed fake wallet that drained $1.8M, all pointing at the same failure mode: trusting the store.
-
A fake Sparrow Wallet on Apple's App Store drained $1.8M in BTC, while BitMart and BitMEX wind-downs leave user withdrawals in limbo.
-
SparkKitty photo-scraping malware and a fresh n8n sandbox escape land the same day Triple-A eats an $11.8M treasury breach, while BitMart withdrawals stall on the way out the door.
-
Two Ethereum bridges bled $31.7M in hours while a browser-built malware campaign impersonates Solana and TradingView to drain retail traders.
-
A North Korean phishing kit fingerprints your wallet before it drops malware, while Fastjson 1.x eats unauthenticated RCE with no patch in sight.
-
Odos is winding down with a hard July 30 withdrawal deadline, and a fresh batch of exploitable flaws (Redis RCE PoCs, NodeBB, ChatGPT AgentForger) landed the same day.
-
Two bridge exploits drained $35M across Bitcoin and Ethereum, with Verus hit through the same flaw class it ignored in May.
-
Zilliqa's Ledger app leaked private keys onchain since 2019, and a Wanchain bridge breach hit Cardano's Midnight token.
-
A hijacked npm package, live PAN-OS and ServiceNow exploitation, and WordPress wp2shell mean the machines your keys live on are the actual attack surface today.
-
Allbridge halts after a $1.65M flash loan exploit, and Zilliqa freezes ZIL exchange-wide over a compromised partner cold wallet.
-
Two live RCE flaws with public exploits and a stealer surge mean the threat this week is your machine, not your chart.
-
Two live supply-chain campaigns (ViteVenom npm, OtterCookie SVG fake-interview lures) are hunting crypto wallets on developer machines right now.
-
A macOS Telegram-session stealer targets crypto wallets while ClickFix ACR Stealer harvests browser tokens, both trading on human clicks rather than broken cryptography.
-
Ostium's oracle signer key got stolen and drained up to $18M, the second oracle/keeper exploit in a week after SummerFi.
-
Two live zero-days at SonicWall and a Cursor RCE that runs code the moment you open a repo, plus a poisoned @asyncapi npm chain.
-
Humanity Protocol loses $36M to social engineering as researchers show 85 wallet extensions leak your addresses.
-
CISA flags two 10.0-severity Joomla zero-days under active exploitation while three Microsoft 365 phishing kits surface, a bad week for anyone with credentials worth stealing.
-
A $9M oracle exploit gutted Hedera's Bonzo Lend while a poisoned jscrambler npm release quietly shipped an infostealer to every install.
-
Injective Labs' npm SDK was backdoored to steal wallet keys, Bonzo Lend lost $9M to a Supra oracle exploit on Hedera, and a Solana whale lost 181K SOL.
-
Two live wallet-drain stories today: the Coinspect 'Ill Bloom' weak-entropy seed flaw, actively swept, and a Ledger-disclosed laser attack on Tangem cards.
-
A $999,999 USDT approval-phishing drain and a Hong Kong regulatory mandate both point at the same weak spot: signature hygiene.
-
A signed-commit forgery in GitHub's 'Verified' badge and a batch of actively exploited max-severity flaws (ColdFusion, Langflow, UniFi) are the real hazards today; the market noise is just oil.
-
A governance attacker turned $4.4M into $21.2M by buying enough BONK to pass a malicious treasury proposal, while a trader ate a $2M same-block backrun on a route they never checked.
-
Summer.fi's Lazy Summer vaults drained for $6M via a flash loan redemption exploit, and a max-severity ColdFusion bug is under active attack.
-
A fake Maccy clipboard app ships PamStealer on macOS, and Moonbeam is forcing GLMR holders to bridge off Polkadot to Base by July 31.