GM Security
Sun, 21 Jun 2026 12:50:35 GMT · last 72h
27 incidents
$14.6M reported losses
49 live sources
Executive summary

Over the last 72 hours, at least ~$40.6M in losses were reported, led by a ~$18M token crash and a ~$7.5M MEV bot drain via private key compromise and phishing. Dominant vectors include private-key-compromise, social-engineering, and smart-contract bugs; social attacks (kidnapping, Indian scammers) accounted for ~$16.5M. Supply-chain malware targeting Steam users and a bridge exploit also emerged. Note: 5 sources failed, so this summary may underrepresent true activity.

Attack vectors
social engineering · 5smart-contract bug · 4private-key compromise · 3supply-chain attack · 2phishing / wallet drainer · 1bridge exploit · 1
Incidents & reports
Sources: CertiK, ConsenSys Diligence, Cantina / Spearbit, pcaversaccio, Chainabuse, Arkham Intelligence, @PeckShieldAlert, @CertiKAlert, @CyversAlerts, @BlockSecTeam, @AnciliaInc, @Phalcon_xyz, @zachxbt, @SlowMist_Team, @MistTrack_io, @realScamSniffer, @samczsun, @tayvano_, @spreekaway, @_SEAL_Org, @hypernative, @HalbornSecurity, @Beosin_com, @GoPlusSecurity, @Quantstamp, @Chainalysis, @TrugardLabs, DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, The Block, CoinDesk, Decrypt, Protos, Immunefi Audit Reports.

Sources unavailable: Rekt Newsletter (HTTP 403 (native fetch)); Week in Ethereum News (HTTP 403 (native fetch)); Immunefi (Invalid character in tag name Line: 34 Column: 49 Char: @); CoinDesk (Crypto) (HTTP 404 (native fetch)); CoinDesk (Regulation) (HTTP 404 (native fetch))

📸 Share image for socials — 1200×630
⬇ Download PNG GM Security daily crypto security briefing
Share
XLinkedInBlueskyFacebookThreadsRedditTelegramFarcasterEmail

Generated by crypto-security-briefing · automated digest, verify before acting.