⬢ GM Security — 2026-06-18: $52.6M across 30 incidents
Daily crypto security briefing
2026-06-18 18:27 UTC · last 72h · 30 items · $52.6M reported losses · 47 sources
Last 24 hours
- [ADVISORY · NEW] @HalbornSecurity: Securing blockchain infrastructure for institutional adoption means auditing at every layer, not just the smart contrac… (@HalbornSecurity)
- [EXPLOIT · NEW] @Phalcon_xyz: .@aztecnetwork was attacked again. Like the Sunday, June 14, 2026 exploit, this attack appears related in nature, but t… — ~$2.2M (@Phalcon_xyz)
also: @MistTrack_io · @PeckShieldAlert
- [EXPLOIT · NEW] Aztec Connect - Rekt — $2.3M (rekt.news Leaderboard)
- [ADVISORY · NEW] Rockwell Automation FactoryTalk Historian Site Edition (CISA Cybersecurity Advisories)
- [NEWS · DEVELOPING · day 5] XRP tests key trendline support as bullish divergence fuels recovery hopes (crypto.news)
- [EXPLOIT · DEVELOPING · day 5] @Phalcon_xyz: Correct: this is not the same bug as the previous one, though both are circuit public input binding issues and the exec… (@Phalcon_xyz)
- [ADVISORY · DEVELOPING · day 5] Microsoft warns crypto clipper now acts like backdoor (crypto.news)
- [ENFORCEMENT · NEW] HyperFund promoter Bitcoin Rodney admits role in $1.8B crypto fraud — ~$1.80B (crypto.news)
also: Decrypt
- [NEWS · NEW] Ark Invest buys $18.4M in Coinbase shares, trims Robinhood (crypto.news)
- [NEWS · DEVELOPING · day 4] Live markets: price action turns panicky in Saylor's STRC as bitcoin drops below $63,000 (CoinDesk)
- [ADVISORY · NEW] @HalbornSecurity: Quantum computing is an approaching threat to blockchain security. 🔐 (@HalbornSecurity)
- [NEWS · DEVELOPING · day 3] @spreekaway: https://t.co/MzmtARehtY (@spreekaway)
- [ADVISORY · DEVELOPING · day 3] @spreekaway: That's right: ZERO. https://t.co/yex0V1k3wi (@spreekaway)
- [ADVISORY · DEVELOPING · day 2] @CertiK: Passkeys remove seed phrases, but not security risks. (CertiK)
- [NEWS · DEVELOPING · day 5] @pcaversaccio: ok guys, talk is cheap as you all know. let's move forward here; some very preliminary thoughts on how such a browser c… (pcaversaccio)
- [NEWS · DEVELOPING · day 5] @tayvano_: > beautiful simple clean (@tayvano_)
- [NEWS · DEVELOPING · day 6] @tayvano_: Boeing never told the USG that they cannot prevent their airplanes from falling out of the sky. (@tayvano_)
- [ADVISORY · DEVELOPING · day 6] @tayvano_: The Fed, Iran Trade, and Why BTC Looks Cheap Right Now https://t.co/sAVrcjp96K (@tayvano_)
- [NEWS · DEVELOPING · day 6] @tayvano_: unc1069 / sapphire sleet / whatever you want to call them (@tayvano_)
- [ADVISORY · DEVELOPING · day 5] @pcaversaccio: you can fully destroy perfect onchain privacy by leaking metadata (IP, user-agent, timezone, language settings, etc.).… (pcaversaccio)
Earlier · 24–72h
🧠 Deep reads
💡 Security thought-spark
Bridge inputs are untrusted inputs: validate source chain, sender, and nonce on every cross-chain message. Replays are how bridges get drained.
Full data: https://gmsecurity.net/briefing.json. Feedback or a source to add? [email protected]. George Donnelly offers Web3 development & security consulting.