Over the past 72 hours, confirmed losses total at least ~$40.6M, led by a ~$18M token crash, a ~$7.5M MEV bot private-key compromise, and two smart-contract exploits ($4.7M and $1.1M). Dominant attack vectors are smart-contract bugs and private-key compromise, with social-engineering attacks (including an $8M kidnapping) remaining significant. Note: five key sources failed, so this may underrepresent actual activity.
✨MistTrack Quarterly Update: Risk Decay Model, Connection Path Analysis, and Developer Plan Risk scoring is only the starting point of AML analysis. The real challenge lies in understanding how risk propagates through complex fund flows, identifying exposure paths, and making
@MistTrack_io: ✨MistTrack Quarterly Update: Risk Decay Model, Connection Path Analysis, and Developer Plan
#PeckShieldAlert Specter has reported that #MEV bot #JaredFromSubway appears to have been drained of ~$7.5M in crypto, including 1,474.58 $WETH, 2.87M $USDC, & 2M $USDT. The attacker swapped the stolen funds for 4.4K ETH and has already deposited 1K ETH into #TornadoCash https://t.co/qY6IVDdnGJ [Loss ~$7,500,000]
@PeckShieldAlert: #PeckShieldAlert Specter has reported that #MEV bot #JaredFromSubway appears to have been drained of ~$7.5M in crypto,…
indeed, no one else does it like Main Street https://t.co/kMWamDladg
@spreekaway: indeed, no one else does it like Main Street https://t.co/kMWamDladg
#PeckShieldAlert ethereum:0x890a5122aa1da30fec4286de7904ff808f0bd74a has plummeted 70%. AlphaUSDC Delta V2 (Curator: #AlphaPING) holds a 30% exposure ($18M) to the msY/USDC market. The #Morpho msY/USDC market is 100% utilized. https://t.co/A2THMamJ9v https://t.co/4T4NbnnrgH [Loss ~$18,000,000; Protocols: Morpho]
@PeckShieldAlert: #PeckShieldAlert ethereum:0x890a5122aa1da30fec4286de7904ff808f0bd74a has plummeted 70%.
🚨GoPlus Security Alert: On June 19, @mySwapxyz (Starknet) was exploited. The attacker deployed a fake "EVIL" token contract (0x028c9a) and exploited a vulnerability in a project contract (0x01114c), draining approximately $305,000 from mySwap CL liquidity pools, including https://t.co/8sVDg98bmh https://t.co/yDms1GkODh [Loss ~$305,000; Protocols: Starknet]
@GoPlusSecurity: 🚨GoPlus Security Alert:
🚨 Security Alert: An attacker exploited an infinite mint vulnerability in a modified CW20-ICS20 token contract (secret1yxj...) on Secret Network, stealing approximately $4.67 million worth of assets from Axelar. Three transactions involving WETH, USDT, and WBTC were bridged https://t.co/sRNUL6IDNl https://t.co/6VKWR8wSZJ [Loss ~$4,670,000]
@GoPlusSecurity: 🚨 Security Alert:
#PeckShieldAlert An OLPC/LABUBU pool on PancakeSwap on #BNBChain has been exploited, resulting in a loss of ~$1.1M. The exploiter bridged the stolen funds to #Ethereum, deposited 633.4 $ETH into #TornadoCash, and sent 0.0221 $BNB and 0.0411 $ETH to a dead address. https://t.co/lCDWwThsjH [Loss ~$1,100,000; Protocols: PancakeSwap]
@PeckShieldAlert: #PeckShieldAlert An OLPC/LABUBU pool on PancakeSwap on #BNBChain has been exploited, resulting in a loss of ~$1.1M.
dude, so many people obsessing over fucking tx speed & scale are the same people who deposit into a cex, wait 30 mins for confirmations, and then wait another day or two to get money into their bank account. if fully shielded txs took 1-2 mins to be included, most users would
@pcaversaccio: dude, so many people obsessing over fucking tx speed & scale are the same people who deposit into a cex, wait 30 mi…
A short story about Indian scammers who called the cops on themselves: Earlier this week a follower DM'd me from his personal account complaining that 5.73 BTC ($475K) of his was 'unjustly' frozen at Changelly in Mar 2025. So I went and plotted the Bitcoin transaction in my https://t.co/gZxM4dRCW3 [Loss ~$475,000; 5.73 BTC]
@zachxbt: A short story about Indian scammers who called the cops on themselves:
"Auditing the code is necessary, but no longer sufficient." At Proof of Talk, CertiK CBO Jason Jiang discussed evolving attack vectors, institutional adoption, AI security, and why security must extend beyond smart contracts. Read the full interview👇 https://t.co/s1Vp2sVTZ7
@CertiK: "Auditing the code is necessary, but no longer sufficient."
#CertiKInsight 🚨 @msftsecurity warns about a new crypto clipper active since Feb 2026. The malware monitors the clipboard, steals seed phrases/private keys, captures screenshots, and swaps copied wallet addresses. Stay vigilant!👇 https://t.co/44h2CCoegk
@CertiKAlert: #CertiKInsight 🚨
#PeckShieldAlert The @Humanityprot exploiter-labeled address has bridged 130 $ETH ($220.6K) from #Ethereum to #BNBChain (381 $BNB) https://t.co/aqcbcQRWa5 [Loss ~$220,600]
@PeckShieldAlert: #PeckShieldAlert The @Humanityprot exploiter-labeled address has bridged 130 $ETH ($220.6K) from #Ethereum to #BNBChain…
Quantum computing is an approaching threat to blockchain security. 🔐 For most networks, the cryptographic foundations were never built to withstand it. @QRLedger has been building to address that problem ever since 2018. https://t.co/SshyHndbNW
@HalbornSecurity: Quantum computing is an approaching threat to blockchain security. 🔐
As social engineering attacks rise, OPSEC matters more than ever. Excited to have Roman, Incident Lead @Quantstamp, at @ETHCincoDeMayo sharing practical ways to lock down your devices, laptops, and accounts! https://t.co/uOPSlAMghj
@Quantstamp: As social engineering attacks rise, OPSEC matters more than ever.
Securing blockchain infrastructure for institutional adoption means auditing at every layer, not just the smart contracts. 🔐 Our engagement with @RaylsLabs covered smart contract auditing, L1 security assessment, architecture advisory, and cryptographic review. https://t.co/EtzY6neCp1
@HalbornSecurity: Securing blockchain infrastructure for institutional adoption means auditing at every layer, not just the smart contrac…
https://t.co/MzmtARehtY
@spreekaway: https://t.co/MzmtARehtY
That's right: ZERO. https://t.co/yex0V1k3wi
@spreekaway: That's right: ZERO. https://t.co/yex0V1k3wi
Sources unavailable: Rekt Newsletter (HTTP 403 (native fetch)); Week in Ethereum News (HTTP 403 (native fetch)); Immunefi (Feed not recognized as RSS 1 or 2.); CoinDesk (Crypto) (HTTP 404 (native fetch)); CoinDesk (Regulation) (HTTP 404 (native fetch))
Generated by crypto-security-briefing · automated digest, verify before acting.