Security

Stay informed on cybersecurity and blockchain security news, including smart contract vulnerabilities, protocol exploits, phishing attacks, wallet security, data breaches, and emerging threats. Learn about security best practices, industry responses, and developments aimed at protecting users and digital assets.
Featured only
1d ago
Outdated Rain contract flaw drains $1.1 MILLION from Solana card programs; AVICI drops 49%
In August 2026, multiple Solana card programs were hit by a hack tied to a Rain contract vulnerability, with total losses of $1.1 million. Avici was the hardest hit, with 1,685 users losing $500,800. The attacker swapped the stolen stablecoins for SOL, bridged the funds to Ethereum, and routed them through Tornado Cash. Avici said self-custodial wallets were not affected and that all compromised card balances will be fully refunded.
SOL
SOL-2.31%
1d ago
2d ago
Raincards-linked neobank hack moves $1M USDC from Solana to Ethereum via deBridge, laundered through TornadoCash
Raincards infrastructure is suspected of being involved in an attack that drained funds from multiple neobanks and their users. The exploiter bridged $1M USDC from Solana to Ethereum via deBridge and laundered the funds using TornadoCash. Affected services include etherfi Cash, Avalanche Card and Solayer Pay, with users also reporting drained balances. The post said Circle had more than two hours to freeze the funds but did not act, and urged users to withdraw funds from impacted neobanks as soon as possible.
ETH
ETH-0.87%
2d ago
2d ago
Avici exploit attacker used $190 in bridged USDC to siphon about $670K, with 8,857 transactions since 16:49 UTC
Avici confirmed it was hit by an authorization-bypass exploit, with the attacker stealing about $670K. On-chain data show the attacker created a wallet at 13:40 UTC and bridged in $190 of USDC from Ethereum to cover gas. Draining began at 16:49 UTC and has continued, with 8,857 transactions executed by submitting a signature bundle, calling AddCollateralAdmin to gain admin privileges, and then withdrawing. The data indicate a verification flaw in which the second signature check pointed back to instruction 0, and the protocol’s upgrade key has not been used since March 2025.
ETH
ETH-0.87%
2d ago
8-27
Cosmos Labs discloses ongoing security flaw in shared EVM module and urges affected networks to halt
Cosmos Labs has publicly disclosed an ongoing security vulnerability in its shared EVM module and formally advised related networks to pause operations to prevent potential risks from escalating. The flaw could affect EVM-compatibility components across the Cosmos ecosystem, with potential knock-on effects for associated assets including ATOM and VIRTUAL. Cosmos Labs has not yet detailed the scope of impact or provided a remediation timeline.
ATOM
ATOM-0.47%
8-27
8-26
Ledger fixes critical Ethereum app flaw in v1.22.2 affecting ETH transaction signing
A critical vulnerability has been found in the Ethereum app on Ledger hardware wallets that could let a malicious application change ETH transaction details during signing without the altered information appearing on the device screen. The issue affects users managing ETH and Ethereum-related assets on Ledger and could result in transfers being approved without their knowledge. Ledger said the flaw is fixed in Ethereum app v1.22.2 and urged users to update the app, Ledger Live and device firmware, and to avoid signing transactions until all updates are completed.
ETH
ETH-0.87%
8-26
8-25
The Sandbox says SAND bridge exploit drained 14,742,341.84 tokens from Ethereum vault
The Sandbox has released findings on a recent SAND bridge security incident. It said an attacker exploited a configuration function in the SAND token contract on Base and BNB Chain, where the contract also served as the LayerZero bridge integration, and set themselves as the sole verifier for incoming bridge messages. The attacker then stole about 14.74 million SAND from the Ethereum vault backing the bridge, roughly 0.5% of the fixed 3 billion maximum supply, while the team said it quickly contained the exploit and completed on-chain forensics.
SAND
SAND-4.59%
8-25
8-25
The Sandbox discloses security incident affecting its cross-chain bridge infrastructure
Metaverse project The Sandbox said its cross-chain bridge infrastructure was hit by a security incident. The issue could affect the transfer of assets between different blockchain networks, though the scope of any impact and potential losses have not been disclosed. The incident has raised concerns about the platform’s infrastructure security and could weigh on SAND and other ecosystem assets in the near term.
SAND
SAND-4.59%
8-25