Switchboard's oracle service for Solana ended support on September 25, giving applications only six days' warning to migrate their price feed infrastructure. The tight deadline has raised questions about which Solana applications still rely on Switchboard's data.
A vulnerability in Limit Break's Payment Processor V2 left NFTs listed on Magic Eden's now-closed EVM marketplace between February and October 2024 exposed to potential theft. Whitehat researchers rescued 23,155 NFTs worth more than $5.7 million before malicious actors could exploit the flaw.
XRP Ledger's Batch V1.1 upgrade has maintained support from 30 of 35 tracked validators and is approaching activation on September 29. The feature allows up to eight transactions to be grouped together to succeed or fail as a unit, with Ripple reporting that asset managers and commercial projects are already preparing to use it following extensive security reviews.
Security researchers have uncovered a Brazilian banking malware operation deploying KREMLIN toolkit, which uses Ethereum smart contracts to update its attack infrastructure and hijacks Chrome and Edge browsers to steal credentials and session tokens. More than 1,500 infections have been traced.
Ethereum co-founder Vitalik Buterin published an updated Ethereum Improvement Proposal (EIP) 8141 on Sunday, proposing changes to how wallets sign transactions, batch operations, and handle payments ahead of the Hegotá upgrade.
DeFi protocol Notional Finance suffered a $1.7 million exploit on September 4, with an attacker draining approximately $69,000 in DAI and $1.66 million in USDC from a legacy escrow contract through an integer overflow bug. The stolen funds were reportedly moved to Tornado Cash.
Hyperliquid is testing HIP-3, an upgrade that introduces optional permissioned markets using on-chain allowlists controlled by independent deployers. The venue-scoped controls allow operators to restrict trading access to their own markets without affecting existing permissionless markets.
Ten AI coding agents competed in Austin Griffith's security challenge at Devcon, attempting 12 Solidity challenges originally designed for human developers. Only OpenAI's Codex completed all challenges, while DeepSeek, an open-weight Chinese model, came closest among cheaper alternatives.
A bridge configuration flaw on Base and BNB Smart Chain allowed attackers to hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain approximately $675,000 from the Ethereum vault.
A security vulnerability in an outdated Rain card smart contract led to approximately $1.1 million being drained from Solana-based platforms on August 28, with Avici suffering $500,800 in losses affecting 1,685 users. The exploit caused Avici's token to crash 49%.
TRON founder Justin Sun secured a procedural victory after a California federal judge rejected World Liberty Financial's attempt to move their multi-hundred-million-dollar dispute into private arbitration. Sun alleges the Trump-backed crypto venture's smart contract contains a hidden backdoor to freeze or burn token holdings.
Layer 1 blockchain platform Harmony confirmed it was exploited through unauthorized minting of 4 billion ONE tokens, causing the cryptocurrency to plunge approximately 40%. The exploit was first reported by social media users before the company's official confirmation.
Prediction market platform Polymarket is replacing single-price snapshots with time-weighted average prices (TWAP) for settling short-duration crypto markets after traders exploited brief price manipulation windows to drain funds. The platform is offering $1M in rewards as part of the upgrade.
Cybersecurity researchers have identified sophisticated evolution in ClickFix malware operations, including attackers using BNB Chain smart contracts to deliver attack instructions, browser fingerprinting to hide macOS malware lures, and a self-propagating npm worm called ChainDrop that infected over 400 packages downloaded hundreds of millions of times weekly.
Michael Coates, newly appointed Chief Information Security Officer at the Solana Foundation, warned that AI-driven social engineering attacks, deepfakes, and credential theft have become the cryptocurrency industry's primary security threats, replacing traditional smart contract vulnerabilities as the main concern.
Blockchain asset management protocol Swan Treasury suffered an estimated $625,000 loss when attackers exploited a leaked off-chain signer key to purchase STY tokens at a steep discount and sell them for profit.
The cryptocurrency industry has experienced $972 million in security breaches during 2026, with the majority of stolen funds traced to compromised private keys, signature exploits, and governance vulnerabilities rather than smart contract flaws.
The cryptocurrency industry has experienced $972 million in security breaches during 2026, with the majority of stolen funds traced to compromised private keys, signature exploits, and governance vulnerabilities rather than smart contract flaws.
Sablier Labs announced it is halting development of its Ethereum token-streaming protocol and entering maintenance mode until 2028, though smart contracts used by 345,000+ addresses will continue operating.