GM Security
Mon, 22 Jun 2026 11:53:32 GMT · last 72h
26 incidents
$791.6M reported losses
49 live sources
Executive summary

Q2 2026 is now the most-hacked quarter on record with 83 incidents and ~$755M in losses, led by bridge exploits. In the last 72 hours, total losses exceed $42M from at least 10 incidents, with smart-contract bugs, private-key compromises, and phishing wallet-drainers as the top vectors. The Axelar bridge infinite-mint exploit ($4.7M) and Taiko private-key attack ($1.7M) highlight critical infrastructure threats. A fentanyl-linked Chinese network used fake 'Zksync.jp' tokens for wallet-draining, blending geopolitical crime with crypto fraud. Note: one source (Immunefi) failed this run, so data may be incomplete.

Attack vectors
smart-contract bug · 6phishing / wallet drainer · 3social engineering · 3bridge exploit · 2private-key compromise · 2frontend / DNS hijack · 1
Incidents & reports
Sources: CertiK, ConsenSys Diligence, Cantina / Spearbit, pcaversaccio, Chainabuse, Arkham Intelligence, @PeckShieldAlert, @CertiKAlert, @CyversAlerts, @BlockSecTeam, @AnciliaInc, @Phalcon_xyz, @zachxbt, @SlowMist_Team, @MistTrack_io, @realScamSniffer, @samczsun, @tayvano_, @spreekaway, @_SEAL_Org, @hypernative, @HalbornSecurity, @Beosin_com, @GoPlusSecurity, @Quantstamp, @Chainalysis, @TrugardLabs, DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, The Block, CoinDesk, Decrypt, Protos, Immunefi Audit Reports.

Sources unavailable: Immunefi (Invalid character in tag name Line: 34 Column: 49 Char: @)

📸 Share image for socials — 1200×630
⬇ Download PNG GM Security daily crypto security briefing
Share
XLinkedInBlueskyFacebookThreadsRedditTelegramFarcasterEmail

Generated by GM Security · automated digest, verify before acting.