|
🛡️ Crypto Security Briefing
Thu, 18 Jun 2026 20:27:31 GMT · last 72h
|
30 incidents |
$50.4M reported losses |
47 live sources |
|
|
Executive summary
HyperFund promoter Bitcoin Rodney admitted role in a $1.8B fraud, and an Aztec Network bridge exploit lost ~$2.3M. The total identified losses across reported incidents exceed $1.84B, but several items lack loss data. Dominant attack vectors include smart-contract bugs, private-key compromise, and phishing/supply-chain threats. A small number of source feeds failed, so the report may not capture all incidents.
- Smart-contract bugs remain the top technical vector for DeFi exploits.
- Private-key compromise on shared machines undermines multisig security.
- Phishing and supply-chain malware are infiltrating trusted software distribution channels.
- Emerging threats include quantum computing, AI agent payment risks, and metadata leaks.
|
|
Attack vectors
smart-contract bug · 6phishing / wallet drainer · 2supply-chain attack · 2private-key compromise · 2access-control flaw · 1bridge exploit · 1
|
|
Incidents & reports
|
Ex-Celsius CEO Mashinsky gets U.S. CFTC ban in final resolution with regulator
Alexander Mashinsky, the founder of failed crypto lender Celsius, had earlier been imprisoned for fraud and is now formally banned from CFTC registration.
CoinDesk · Thu, 18 Jun 2026 19:26:55 GMT
|
|
@HalbornSecurity · Thu, 18 Jun 2026 17:00:00 GMT
|
|
@HalbornSecurity · smart-contract bug · Thu, 18 Jun 2026 15:00:12 GMT
|
|
@spreekaway · Thu, 18 Jun 2026 14:22:19 GMT
|
|
@spreekaway · Thu, 18 Jun 2026 14:12:39 GMT
|
|
CertiK · Thu, 18 Jun 2026 12:20:00 GMT
|
|
Rockwell Automation FactoryTalk Historian Site Edition
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system. The following versions of Rockwell Automation FactoryTalk Historian Site Edition are affected: FactoryTalk Historian SE 11 (CVE-2025-13036) FactoryTalk Historian SE <=11.00 (CVE-2025-44019) FactoryTalk Historian SE <=11.00 (CVE-2025-36539) CVSS Vendor Equipment Vulnerabilities v3 7.7 Rockwell Automation Rockwell Automation FactoryTalk Historian Site Edition Concurrent Execution using Shared Resource with Improper S…
CISA Cybersecurity Advisories · access-control flaw, smart-contract bug · Thu, 18 Jun 2026 12:00:00 GMT
|
|
XRP tests key trendline support as bullish divergence fuels recovery hopes
XRP has dropped nearly 5% after a Fed-induced risk-off move swept across crypto markets, though traders remain focused on bullish chart signals and a major liquidity cluster near $1.30. The pullback began shortly after XRP (XRP) failed to break through…
crypto.news · Thu, 18 Jun 2026 11:46:04 GMT
|
|
Microsoft warns crypto clipper now acts like backdoor
Microsoft warns a crypto clipper campaign uses Tor, worm-like spread, and clipboard theft to replace wallet addresses and steal seed phrases.
crypto.news · phishing / wallet drainer, supply-chain attack · Thu, 18 Jun 2026 11:12:11 GMT
|
|
@Phalcon_xyz · smart-contract bug · Thu, 18 Jun 2026 09:25:06 GMT
|
|
pcaversaccio · Thu, 18 Jun 2026 09:19:39 GMT
|
|
~$2.3M · @Phalcon_xyz · bridge exploit, smart-contract bug · Thu, 18 Jun 2026 06:54:19 GMT
|
|
HyperFund promoter Bitcoin Rodney admits role in $1.8B crypto fraud
~$1.80B · A Florida man has pleaded guilty to operating an unlicensed money-transmitting business tied to HyperFund, a crypto investment scheme that U.S. authorities have described as a fraud that collected roughly $1.8 billion from investors. The U.S. Attorney’s Office for the…
crypto.news · Thu, 18 Jun 2026 06:50:11 GMT
|
|
Ark Invest buys $18.4M in Coinbase shares, trims Robinhood
Cathie Wood’s Ark Invest has purchased $18.4 million worth of Coinbase shares across three ETFs, even as the crypto exchange’s stock has fallen nearly 13% over the past month. According to Ark Invest’s Wednesday trading disclosure, the investment firm acquired…
crypto.news · Thu, 18 Jun 2026 06:31:53 GMT
|
|
Live markets: price action turns panicky in Saylor's STRC as bitcoin drops below $63,000
Total crypto market value has held steady near $2.26 trillion since Tuesday, with the recovery losing momentum after the Fed killed rate-cut hopes and spot ETFs swung back to outflows.
CoinDesk · Thu, 18 Jun 2026 06:02:19 GMT
|
|
@tayvano_ · Thu, 18 Jun 2026 01:43:02 GMT
|
|
@tayvano_ · Wed, 17 Jun 2026 22:15:14 GMT
|
|
@tayvano_ · Wed, 17 Jun 2026 19:59:00 GMT
|
|
@tayvano_ · Wed, 17 Jun 2026 19:10:10 GMT
|
|
pcaversaccio · Wed, 17 Jun 2026 19:07:31 GMT
|
|
Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening
Sanctions compliance in crypto isn’t just about knowing who’s on a list today. It’s about understanding the full arc of… The post Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening appeared first on Chainalysis.
Chainalysis · Wed, 17 Jun 2026 17:04:10 GMT
|
|
@HalbornSecurity · private-key compromise · Wed, 17 Jun 2026 17:00:01 GMT
|
|
~$5K · @PeckShieldAlert · private-key compromise · Wed, 17 Jun 2026 15:35:04 GMT
|
|
~$42.0M · @CertiKAlert · social engineering · Wed, 17 Jun 2026 14:11:17 GMT
|
|
Steam Workshop wallpapers found spreading crypto malware
Bad actors are using Steam Workshop's wallpaper application to sneak malware into users' computers and steal crypto wallet information. The post Steam Workshop wallpapers found spreading crypto malware appeared first on Protos.
Protos · supply-chain attack, phishing / wallet drainer · Wed, 17 Jun 2026 13:35:42 GMT
|
|
~$2.0M · @Beosin_com · smart-contract bug · Wed, 17 Jun 2026 07:12:27 GMT
|
|
~$6.0M · @Phalcon_xyz · Wed, 17 Jun 2026 05:45:32 GMT
|
|
@BlockSecTeam · Wed, 17 Jun 2026 03:35:35 GMT
|
|
~$111K · @SlowMist_Team · smart-contract bug · Wed, 17 Jun 2026 02:56:08 GMT
|
|
CertiK · Wed, 17 Jun 2026 02:46:27 GMT
|
|
|
Sources: CertiK, ConsenSys Diligence, Cantina / Spearbit, pcaversaccio, Chainabuse, Arkham Intelligence, @PeckShieldAlert, @CertiKAlert, @CyversAlerts, @BlockSecTeam, @AnciliaInc, @Phalcon_xyz, @zachxbt, @SlowMist_Team, @MistTrack_io, @realScamSniffer, @samczsun, @tayvano_, @spreekaway, @_SEAL_Org, @hypernative, @HalbornSecurity, @Beosin_com, @GoPlusSecurity, @Quantstamp, @Chainalysis, @TrugardLabs, DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, CoinDesk, Decrypt, Protos.
Sources unavailable: Week in Ethereum News (HTTP 403 (native fetch)); Immunefi (Invalid character in tag name
Line: 34
Column: 49
Char: @)
Generated by crypto-security-briefing · automated digest, verify before acting.
|
|