Security

Stay informed on cybersecurity and blockchain security news, including smart contract vulnerabilities, protocol exploits, phishing attacks, wallet security, data breaches, and emerging threats. Learn about security best practices, industry responses, and developments aimed at protecting users and digital assets.
Featured only
1d ago
Post claims Base users were rugged again within 24 hours as traders pile into a viral TikTok animal token on Solana
A post alleged that a Base-chain project executed another rug pull in under 24 hours, wiping users’ assets. It also said traders are rotating into a Solana-based token themed on an animal that went viral on TikTok. The post framed the episode as a repeat security failure that undermines trust in Base as Ethereum’s Layer 2 infrastructure. It added that the shift toward high-risk meme tokens on Solana could amplify short-term volatility and liquidation risk, with knock-on effects for Base-native assets and Solana on-chain liquidity.
Selected
SOL
SOL+1.91%
1d ago
7-17
SlowMist flags new macOS malware that can steal Telegram sessions, passwords and crypto
Security firm SlowMist said it has identified a new macOS malware targeting Apple Mac users that can steal Telegram login sessions, encrypted local wallet databases, and passwords stored in Apple Keychain, browsers and Notes. The attackers can use the stolen data to access chats and unlock wallets offline. The malware can also display fake hardware wallet apps, including Ledger and Trezor, to trick users into entering recovery phrases.
BTC
BTC+1.23%
7-17
7-16
GoPlusSecurity launches DeepScan AI Auditor on TermiX as verified provider on BNB Chain
GoPlusSecurity’s DeepScan AI auditing service has gone live on TermiX as a Verified Provider and is now available on BNB Chain. The tool scans any token contract to flag vulnerabilities, scam patterns, and hidden risks, returning a report within minutes. Payments settle via an on-chain USDC escrow release mechanism, with funds paid out immediately once the audit result is verified. The rollout is positioned as trust infrastructure for smart-contract deployment on BNB Chain, targeting DeFi and agent-economy use cases that rely on fast, credible token launches.
BNB
BNB+0.59%
7-16
7-9
GOAT Network says its Bitcoin zkRollup keeps proving in-house to reduce operational risk
GOAT Network says it is the only Bitcoin zkRollup that does not outsource its proof system. The project argues that keeping proving guarantees in-house reduces operational risk and helps protect the foundation of the network’s security model. The statement focuses on the independence of proof generation within a zkRollup architecture, positioning its security assumptions as different from other Bitcoin L2 approaches. The post provides no details on mainnet status, TVL, transaction volume, partnerships, third-party audits, or any disclosed vulnerabilities.
GOAT
GOAT+2.12%
7-9
7-8
Gate user account reportedly accessed via old Mac web device and legacy passkey, with 746,475 HSK and 100,000–1,700,000 USDT said stolen
A Gate exchange user account was reportedly accessed from the owner’s old Mac web device using a legacy passkey, with the platform said to have retained complete records of the login. The incident is described as involving the theft of about 100,000–1,700,000 USDT (U) and 746,475 HSK, with HSK presented as the primary stolen asset. The key dispute centers on how liveness facial verification was passed, prompting calls for Gate to release the verification video for independent review amid speculation about possible AI spoofing. There is said to be no evidence the case was staged, but the failure of security controls is treated as a confirmed outcome in the discussion.
7-8
7-7
Two Solana validator operators linked to private inclusion lanes for MEV bot MRiYA4oN3158fCV8evhuCofrDzbHyYvYnGZUDJvoCsa
Two Solana validator operators were identified as running private inclusion lanes for a major on-chain MEV bot, MRiYA4oN3158fCV8evhuCofrDzbHyYvYnGZUDJvoCsa. The bot paid zero priority fee yet achieved an 84% success rate on Helius leaders and 80% on Kiln. With the same bot and the same transactions, success across every other validator was 25%. The behavior was described as not attributable to SWQoS or luck.
SOL
SOL+1.91%
7-7
7-6
Coinspect flags “Ill Bloom” weak-randomness flaw putting thousands of wallets at risk, with over $5M drained since May 27
Security research firm Coinspect has identified a cross-chain randomness-generation flaw dubbed “Ill Bloom” that affects thousands of wallets on networks including Bitcoin, Ethereum and Solana. The weakness stems from poor randomness, allowing attackers to derive private keys and steal funds, according to Coinspect. Losses have exceeded $5 million since May 27. The incident has undermined confidence in on-chain asset custody and impacts public blockchains and ecosystem tokens that rely on ECDSA or similar signature mechanisms.
M
M+2.23%
7-6
7-6
Developer wallet tied to Polymarket user routed ~9.7 ETH to Bybit after deploying Base tokens $BRIAN and $JESSE
The article says the Base token $JESSE was deployed and fully controlled by the same developer wallet linked to a Polymarket account and the $BRIAN project. It alleges the wallet repeatedly claimed creator fees and sold each claim within a minute. About ~9.7 ETH (about $12,000) was routed through a fresh burner wallet into Bybit within two hours. The author adds they joined without auditing the contract mechanics and later concluded the project carried a centralized single-point risk with no multisig or governance constraints.
7-6