🛡️ Crypto Security Briefing
Fri, 19 Jun 2026 13:47:41 GMT · last 72h
30
incidents
$45.0M
reported losses
47
live sources
Executive summary

Total known losses across items exceed $1.84B, led by the $1.8B HyperFund fraud plea and a $42M social-engineering loss. Dominant vectors are social-engineering, private-key compromise, and smart-contract bugs, with notable bridge exploits and supply-chain malware incidents. Item volume may be reduced due to two data-source failures.

  • Social-engineering and private-key theft remain the most costly vectors.
  • Auditing alone is insufficient; layered security across infrastructure is critical.
  • Bridge exploits and zk-circuit bugs demand focused defensive review.
  • Supply-chain malware via USB and Steam wallpapers broadens attack surface.
Attack vectors
smart-contract bug · 5social engineering · 4private-key compromise · 3supply-chain attack · 2bridge exploit · 2access-control flaw · 1
Incidents & reports
@GoPlusSecurity · social engineering · Fri, 19 Jun 2026 13:00:15 GMT
~$475K · @zachxbt · social engineering · Fri, 19 Jun 2026 11:52:19 GMT
CertiK · Fri, 19 Jun 2026 11:31:01 GMT
Microsoft found malware that hijacks crypto wallets and spreads through USB sticks
The software intercepts shortcut files and directs them to install a worm that harvests private keys from the Windows clipboard and inserts its own destination wallet addresses when it detects a transfer.
CoinDesk · private-key compromise, supply-chain attack · Fri, 19 Jun 2026 08:48:14 GMT
North Korea’s crypto hack spree draws fresh G7 warning
G7 leaders urged joint action on North Korea crypto theft as reports tie DPRK hackers to $2.02B stolen in 2025 and missile funding.
crypto.news · social engineering · Fri, 19 Jun 2026 08:35:35 GMT
~$221K · @PeckShieldAlert · bridge exploit · Fri, 19 Jun 2026 03:46:00 GMT
Ireland flags crypto as major threat in anti-money laundering push
Ireland has identified crypto assets as a “very significant” money laundering and terrorism financing risk and has committed to introducing industry standards governing crypto-related sources of funds by the second half of 2027. According to Ireland’s Department of Finance, the…
crypto.news · Thu, 18 Jun 2026 23:35:09 GMT
Ex-Celsius CEO Mashinsky gets U.S. CFTC ban in final resolution with regulator
Alexander Mashinsky, the founder of failed crypto lender Celsius, had earlier been imprisoned for fraud and is now formally banned from CFTC registration.
CoinDesk · Thu, 18 Jun 2026 19:26:55 GMT
@HalbornSecurity · Thu, 18 Jun 2026 17:00:00 GMT
@HalbornSecurity · smart-contract bug · Thu, 18 Jun 2026 15:00:12 GMT
@spreekaway · Thu, 18 Jun 2026 14:22:19 GMT
@spreekaway · Thu, 18 Jun 2026 14:12:39 GMT
CertiK · Thu, 18 Jun 2026 12:20:00 GMT
Rockwell Automation FactoryTalk Historian Site Edition
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system. The following versions of Rockwell Automation FactoryTalk Historian Site Edition are affected: FactoryTalk Historian SE 11 (CVE-2025-13036) FactoryTalk Historian SE <=11.00 (CVE-2025-44019) FactoryTalk Historian SE <=11.00 (CVE-2025-36539) CVSS Vendor Equipment Vulnerabilities v3 7.7 Rockwell Automation Rockwell Automation FactoryTalk Historian Site Edition Concurrent Execution using Shared Resource with Improper S…
CISA Cybersecurity Advisories · access-control flaw, smart-contract bug · Thu, 18 Jun 2026 12:00:00 GMT
@Phalcon_xyz · smart-contract bug · Thu, 18 Jun 2026 09:25:06 GMT
pcaversaccio · Thu, 18 Jun 2026 09:19:39 GMT
~$2.3M · @Phalcon_xyz · bridge exploit, smart-contract bug · Thu, 18 Jun 2026 06:54:19 GMT
Live markets: price action turns panicky in Saylor's STRC as bitcoin drops below $63,000
Total crypto market value has held steady near $2.26 trillion since Tuesday, with the recovery losing momentum after the Fed killed rate-cut hopes and spot ETFs swung back to outflows.
CoinDesk · Thu, 18 Jun 2026 06:02:19 GMT
@tayvano_ · Thu, 18 Jun 2026 01:43:02 GMT
@tayvano_ · Wed, 17 Jun 2026 22:15:14 GMT
@tayvano_ · Wed, 17 Jun 2026 19:59:00 GMT
@tayvano_ · Wed, 17 Jun 2026 19:10:10 GMT
pcaversaccio · Wed, 17 Jun 2026 19:07:31 GMT
Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening
Sanctions compliance in crypto isn’t just about knowing who’s on a list today. It’s about understanding the full arc of… The post Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening appeared first on Chainalysis.
Chainalysis · Wed, 17 Jun 2026 17:04:10 GMT
@HalbornSecurity · private-key compromise · Wed, 17 Jun 2026 17:00:01 GMT
Florida Man 'Bitcoin Rodney' Pleads Guilty Over $1.8 Billion HyperFund Crypto Fraud
~$1.80B · A Miami-based man who went by the name “Bitcoin Rodney” pleaded guilty for his role in what prosecutors said was a massive global fraud.
Decrypt · Wed, 17 Jun 2026 15:37:41 GMT
~$5K · @PeckShieldAlert · private-key compromise · Wed, 17 Jun 2026 15:35:04 GMT
~$42.0M · @CertiKAlert · social engineering · Wed, 17 Jun 2026 14:11:17 GMT
Steam Workshop wallpapers found spreading crypto malware
Bad actors are using Steam Workshop's wallpaper application to sneak malware into users' computers and steal crypto wallet information. The post Steam Workshop wallpapers found spreading crypto malware appeared first on Protos.
Protos · supply-chain attack, phishing / wallet drainer · Wed, 17 Jun 2026 13:35:42 GMT
~$2.0M · @Beosin_com · smart-contract bug · Wed, 17 Jun 2026 07:12:27 GMT
Sources: CertiK, ConsenSys Diligence, Cantina / Spearbit, pcaversaccio, Chainabuse, Arkham Intelligence, @PeckShieldAlert, @CertiKAlert, @CyversAlerts, @BlockSecTeam, @AnciliaInc, @Phalcon_xyz, @zachxbt, @SlowMist_Team, @MistTrack_io, @realScamSniffer, @samczsun, @tayvano_, @spreekaway, @_SEAL_Org, @hypernative, @HalbornSecurity, @Beosin_com, @GoPlusSecurity, @Quantstamp, @Chainalysis, @TrugardLabs, DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, CoinDesk, Decrypt, Protos.
Sources unavailable: Week in Ethereum News (HTTP 403 (native fetch)); Immunefi (Feed not recognized as RSS 1 or 2.)
Generated by crypto-security-briefing · automated digest, verify before acting.