⬢ GM Security — 2026-06-18: $58.9M across 30 incidents
Daily crypto security briefing
2026-06-18 14:32 UTC · last 72h · 30 items · $58.9M reported losses · 53 sources
Last 24 hours
- [ADVISORY] XRP tests key trendline support as bullish divergence fuels recovery hopes (crypto.news)
- [EXPLOIT] @Phalcon_xyz: Correct: this is not the same bug as the previous one, though both are circuit public input binding issues and the exec… (@Phalcon_xyz)
- [ADVISORY] Microsoft warns crypto clipper now acts like backdoor (crypto.news)
- [ENFORCEMENT] HyperFund promoter Bitcoin Rodney admits role in $1.8B crypto fraud — $1.80B (crypto.news)
also: Decrypt
- [NEWS] Ark Invest buys $18.4M in Coinbase shares, trims Robinhood (crypto.news)
- [ADVISORY] Live markets: DXY Index breaks higher as bitcoin tries to weather stronger dollar (CoinDesk)
- [EXPLOIT] @PeckShieldAlert: #PeckShieldAlert The @UXLINKofficial exploiter-labeled address has swapped ~14.6M $DAI for 8,298.6 $ETH. — $14.6M (@PeckShieldAlert)
- [EXPLOIT] @HalbornSecurity: Multisig doesn't protect you if your keys share the same machine. 🔑 (Halborn)
- [NEWS] @immunefi: Everyone keeps telling you crypto is dead. No money left. No opportunity. — $500K (@Immunefi)
- [NEWS] @spreekaway: https://t.co/MzmtARehtY (@spreekaway)
- [NEWS] @spreekaway: That's right: ZERO. https://t.co/yex0V1k3wi (@spreekaway)
- [NEWS] @immunefi: It’s a good day to find a crit https://t.co/1XIzuycxCL (@Immunefi)
- [NEWS] @pcaversaccio: ok guys, talk is cheap as you all know. let's move forward here; some very preliminary thoughts on how such a browser c… (pcaversaccio)
- [NEWS] @tayvano_: > beautiful simple clean (@tayvano_)
- [NEWS] @tayvano_: Boeing never told the USG that they cannot prevent their airplanes from falling out of the sky. (@tayvano_)
- [NEWS] @tayvano_: The Fed, Iran Trade, and Why BTC Looks Cheap Right Now https://t.co/sAVrcjp96K (@tayvano_)
- [NEWS] @tayvano_: unc1069 / sapphire sleet / whatever you want to call them (@tayvano_)
- [ADVISORY] @pcaversaccio: you can fully destroy perfect onchain privacy by leaking metadata (IP, user-agent, timezone, language settings, etc.).… (pcaversaccio)
- [NEWS] @immunefi: SR Summer is just getting started https://t.co/pTrDs8Z1QI (@Immunefi)
- [NEWS] @immunefi: Finding security signal in web3 has been too slow for the people who need it most. (@Immunefi)
Earlier · 24–72h
🧠 Deep reads
💡 Security thought-spark
Bridge inputs are untrusted inputs: validate source chain, sender, and nonce on every cross-chain message. Replays are how bridges get drained.
Full data: https://gmsecurity.net/briefing.json. Feedback or a source to add? [email protected]. George Donnelly offers Web3 development & security consulting.