GM Security
Fri, 26 Jun 2026 13:10:26 GMT Β· last 72h
30 incidents
$50.0M reported losses
49 live sources
Executive summary

Over the last 72 hours, the most material incidents include a ~$860M RWA protocol access-control exploit, a ~$47M global infostealer/phishing takedown, and a ~$47M flash-loan event, with total reported losses exceeding $954M. Dominant attack vectors are smart-contract bugs, supply-chain compromises, and social-engineering/phishing. Multiple high-profile supply-chain attacks and a governance-attack on Tornado Cash also emerged, while a Base chain halt and several private-key-compromise incidents underscore persistent infrastructure risk.

Attack vectors
smart-contract bug Β· 4supply-chain attack Β· 3social engineering Β· 2private-key compromise Β· 2frontend / DNS hijack Β· 1oracle manipulation Β· 1
Incidents & reports
Sources: CertiK, ConsenSys Diligence, Cantina / Spearbit, pcaversaccio, Chainabuse, Arkham Intelligence, @PeckShieldAlert, @CertiKAlert, @CyversAlerts, @BlockSecTeam, @AnciliaInc, @Phalcon_xyz, @zachxbt, @SlowMist_Team, @MistTrack_io, @realScamSniffer, @samczsun, @tayvano_, @spreekaway, @_SEAL_Org, @hypernative, @HalbornSecurity, @Beosin_com, @GoPlusSecurity, @Quantstamp, @Chainalysis, @TrugardLabs, DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, The Block, CoinDesk, Decrypt, Protos, Immunefi Audit Reports.

Sources unavailable: Immunefi (Invalid character in tag name Line: 34 Column: 49 Char: @)

πŸ“Έ Share image for socials β€” 1200Γ—630
⬇ Download PNG GM Security daily crypto security briefing
Share
XLinkedInBlueskyFacebookThreadsRedditTelegramFarcasterEmail

Generated by GM Security Β· automated digest, verify before acting.