AlphaFi, a yield aggregation protocol on the Sui blockchain, is shutting down operations following an oracle misconfiguration. The SUI Foundation is reportedly assisting with the wind-down process, with new deposits and loans disabled.
Cosmos Hub validators stopped block production for nearly 25 hours following a governance attack on Neutron that initially led to losses of approximately $9.5 million, moving 1.23 million ATOM from attacker wallets after restart.
The Ethereum Foundation's Protocol cluster published a roadmap setting December 2029 as a hard deadline for making Ethereum's base layer resistant to quantum computing attacks, covering consensus, execution, and networking layers.
Blockstream's Liquid Network disabled its bridge nodes after approximately 4,000 BTC ($320 million) were withdrawn from the federation wallet to a single address. The withdrawer left an on-chain message stating "we are whitehats."
Ontology's development team stopped the blockchain's mainnet block production on August 31 after flagging a potential security issue during routine checks. The network remained halted with no confirmed incident or restart timeline disclosed.
MANTRA Chain, a Layer 1 blockchain focused on real-world asset tokenization, halted network operations following an unspecified security incident. The native token dropped 18.5% to an all-time low before partially recovering.
A demonstrated consensus flaw let invalid blocks onto Ravencoin starting at block height 4,487,776 on August 7. Pools controlling majority hashpower are mining a replacement chain, putting deposits and withdrawals made since then at risk.
Zcash activated its Ironwood network upgrade at block height 3,428,143 on July 28, replacing the Orchard shielded pool with a new private pool. The upgrade prevents any potentially counterfeit coins from leaving the retired pool, which held about 3.66 million ZEC.
Blockchain firm Consensys disclosed that a North Korea-linked software developer gained access to its team and MetaMask wallet code before being identified and removed. The developer used a fake identity to infiltrate the company.
Ethereum-based rollup Taiko confirmed a compromise of its chain state verification mechanism, halting block production and urging users to withdraw funds. The exploit resulted in approximately $1.7 million in losses.
Syscoin halted its bridge after an attacker exploited a validation issue to mint approximately 5 billion unauthorized SYS tokens on the network's UTXO chain. The project is tracing the unauthorized tokens and investigating the breach.
Zcash developers executed a two-stage emergency fix after discovering a critical vulnerability in the Orchard shielded pool that could have enabled double-spending, temporarily suspending then restoring transactions through coordinated network upgrade.
Gravity Bridge, the cross-chain bridge connecting Ethereum and Cosmos, was exploited for approximately $5.4 million in digital assets including $4.3 million in USDC and 274 ETH, with investigators pointing to a compromised signing key rather than a smart contract vulnerability.
Hacking group TeamPCP claims to have breached GitHub's internal systems and stolen data from nearly 4,000 private repositories. Binance founder CZ and others urged crypto developers to rotate API keys immediately.
Blockchain security firm CertiK projects that 2026 will close with approximately 130 crypto wrench attacks (physical violence against digital asset holders), calling it a significantly underreported phenomenon with hundreds of millions in potential losses.
TRM Labs reports that North Korean state-backed hackers stole $577 million in two April exploits (including the $285 million Drift hack), representing 76% of all crypto losses in 2026. The regime has now stolen over $6 billion in cryptocurrency since 2017.
Anza and Jump Crypto's Firedancer introduced Falcon, a post-quantum signature solution for Solana. Falcon has the smallest signature among NIST standards, helping preserve Solana's high-throughput capabilities while addressing quantum computing threats.
Litecoin underwent a chain reorganization spanning more than three hours to undo its first major privacy-layer exploit, with attackers attempting double-spends against cross-chain swap protocols during the fork window.
Web3 hosting platform Vercel confirmed a security breach with attackers demanding $2 million ransom. Many crypto and Web3 projects deploy frontends on Vercel, raising concerns that secrets stored as environment variables may now be exposed.
Attackers drained approximately 116,500 rsETH (roughly $292-293 million) from Kelp DAO's LayerZero-powered bridge, causing emergency freezes across multiple DeFi protocols including Aave, SparkLend, Fluid, and Upshift. The exploit represents 2026's largest crypto hack to date and impacted at least nine protocols.
The Ketman Project, funded by an Ethereum Foundation stipend, identified approximately 100 North Korean IT workers who had infiltrated 53 different crypto projects over a six-month investigation period.
Wall Street broker Bernstein published research arguing that while quantum computing poses a real threat to Bitcoin, it represents a multi-year upgrade cycle rather than an existential crisis, with risks concentrated in older wallets and exposed keys.
On-chain investigator ZachXBT published 'Circle Files' alleging that Circle has inconsistently applied its freeze powers for USDC, with wallets blocked while stolen funds continued to move, raising questions about the stablecoin issuer's compliance enforcement.
Algorand jumped 50% after a Google Quantum AI research paper highlighted the blockchain as a live example of post-quantum cryptography implementation, while warning that quantum computers could threaten Bitcoin and Ethereum's current cryptographic security.
Google researchers published findings showing quantum computers may require 20x fewer qubits than previously estimated to break elliptic curve cryptography used by Bitcoin and Ethereum. The research suggests fault-tolerant quantum machines capable of threatening crypto security could arrive by 2029-2032, accelerating industry urgency around post-quantum upgrades.
Google publishes a call to action urging governments and industry to prepare for the end of current encryption standards, warning that a cryptographically relevant quantum computer is “not forever a decade away” and that the transition to post-quantum cryptography must begin now.