{
  "generatedAt": "2026-07-16T08:00:11.202Z",
  "windowHours": 72,
  "executiveSummary": "30 crypto-security item(s) in the window with ~$108.5M in reported losses The largest is \"Blockaid uncovers $18M exploit that forces Ostium trading halt\" (~$18.0M). Dominant vectors: oracle manipulation, phishing / wallet drainer, smart-contract bug, access-control flaw.",
  "trends": [
    "🧊 On-chain — Tether USDT freezes (7d): 18 addresses (2026-07-15). Source: Dune",
    "oracle manipulation activity observed (8 item(s))",
    "phishing / wallet drainer activity observed (2 item(s))",
    "smart-contract bug activity observed (2 item(s))"
  ],
  "briefingSpark": "Run `slither .` and `aderyn` on every PR. Free static analysis catches reentrancy, unchecked returns, and access-control gaps before an auditor (or attacker) does.",
  "items": [
    {
      "id": "https://thedefiant.io/news/defi/summerfi-to-wind-down-after-seven-years-citing-exploit",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "SummerFi to Wind Down After Seven Years, Citing Exploit",
      "summary": "Aave founder Stani Kulechov called the DeFi access point 'an OG' as its team said it would sunset the UI.",
      "url": "https://thedefiant.io/news/defi/summerfi-to-wind-down-after-seven-years-citing-exploit",
      "publishedAt": "2026-07-16T08:00:05.000Z",
      "category": "exploit",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "SummerFi",
        "Wind",
        "Down"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "SummerFi to Wind Down After Seven Years, Citing Exploit",
      "signature": "summerfi:summerfi-wind",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-16T08:00:05.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://thedefiant.io/news/cefi/etoro-strategic-stake-onchain-derivatives-extended-zengo",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up",
      "summary": "eToro has become a strategic investor in Extended, an onchain perpetual futures exchange, and said the round begins a partnership with Zengo, the self-custody wallet eToro acquired earlier this year. Neither company disclosed the investment size.",
      "url": "https://thedefiant.io/news/cefi/etoro-strategic-stake-onchain-derivatives-extended-zengo",
      "publishedAt": "2026-07-16T08:00:05.000Z",
      "category": "other",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Takes",
        "Strategic",
        "Stake"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up",
      "signature": "takes:etoro-takes",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-03T08:00:08.684Z",
      "timesSeen": 13
    },
    {
      "id": "https://crypto.news/california-duo-accused-of-laundering-crypto-from-fentanyl-and-meth-sales/",
      "source": "crypto.news",
      "sourceKind": "rss",
      "title": "California duo accused of laundering crypto from fentanyl and meth sales",
      "summary": "A California pair has been indicted on allegations of running a darknet drug operation that prosecutors say generated hundreds of thousands of dollars in cryptocurrency proceeds from fentanyl and methamphetamine sales. According to a Wednesday statement from the U.S. Department…",
      "url": "https://crypto.news/california-duo-accused-of-laundering-crypto-from-fentanyl-and-meth-sales/",
      "publishedAt": "2026-07-16T06:33:12.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "California"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "California duo accused of laundering crypto from fentanyl and meth sales",
      "signature": "california:california-duo",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-16T06:33:12.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.theblock.co/post/408560/california-duo-darknet-drug-crypto-money-laundering?utm_source=rss&utm_medium=rss",
      "source": "The Block",
      "sourceKind": "rss",
      "title": "California pair charged with laundering crypto proceeds from darknet fentanyl sales",
      "summary": "The pair allegedly shipped over 500 drug parcels over a seven-month period and laundered hundreds of thousands of dollars through crypto.",
      "url": "https://www.theblock.co/post/408560/california-duo-darknet-drug-crypto-money-laundering?utm_source=rss&utm_medium=rss",
      "publishedAt": "2026-07-16T02:23:34.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "California"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "California pair charged with laundering crypto proceeds from darknet fentanyl sales",
      "signature": "california:california-pair",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-16T02:23:34.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins/",
      "source": "Chainalysis",
      "sourceKind": "rss",
      "title": "OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins",
      "summary": "The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday updated its Central Bank of Iran designation to… The post OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins appeared first on Chainalysis.",
      "url": "https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins/",
      "publishedAt": "2026-07-15T22:37:36.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "OFAC",
        "Sanctions",
        "Iran"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins",
      "signature": "ofac:ofac:131m",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T22:37:36.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/",
      "source": "crypto.news",
      "sourceKind": "rss",
      "title": "Blockaid uncovers $18M exploit that forces Ostium trading halt",
      "summary": "Ostium has halted trading after an exploit tied to a compromised oracle signer key drained nearly $18 million USDC from its liquidity vault, according to blockchain security firm Blockaid. Blockaid reported that the attacker gained control of an oracle signer…",
      "url": "https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/",
      "publishedAt": "2026-07-15T20:32:40.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Blockaid",
        "Ostium"
      ],
      "amountUsd": 18000000,
      "amountSource": "heuristic",
      "oneLiner": "[~$18.0M · oracle manipulation] Blockaid uncovers $18M exploit that forces Ostium trading halt",
      "signature": "blockaid:18m:crypto-news",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T20:32:40.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://decrypt.co/373566/defi-exploit-ostium-oracle-hack",
      "source": "Decrypt",
      "sourceKind": "rss",
      "title": "Another DeFi Exploit: Perp DEX Ostium Loses $18 Million in Oracle Attack",
      "summary": "Hackers manipulated Ostium's price feed by compromising an oracle signer key, allowing them to drain roughly $18 million from the Arbitrum-based perpetuals exchange.",
      "url": "https://decrypt.co/373566/defi-exploit-ostium-oracle-hack",
      "publishedAt": "2026-07-15T17:01:25.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Another",
        "Exploit"
      ],
      "amountUsd": 18000000,
      "amountSource": "heuristic",
      "oneLiner": "[~$18.0M · oracle manipulation] Another DeFi Exploit: Perp DEX Ostium Loses $18 Million in Oracle Attack",
      "signature": "another:18m:decrypt",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T17:01:25.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://decrypt.co/373565/us-treasury-freezes-131-million-iran-crypto",
      "source": "Decrypt",
      "sourceKind": "rss",
      "title": "US Treasury Freezes $131 Million in Iran-Linked Crypto Wallets",
      "summary": "OFAC sanctioned addresses tied to Iran's central bank and armed forces, with Tether locking four Tron wallets as Washington's financial campaign against Tehran accelerates.",
      "url": "https://decrypt.co/373565/us-treasury-freezes-131-million-iran-crypto",
      "publishedAt": "2026-07-15T16:54:14.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "US",
        "Treasury",
        "Freezes"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "US Treasury Freezes $131 Million in Iran-Linked Crypto Wallets",
      "signature": "treasury:us-treasury",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-03T08:00:08.684Z",
      "timesSeen": 3
    },
    {
      "id": "https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault",
      "summary": "Blockaid says an attacker used a registered price-feed forwarder and future-dated oracle reports to book fake trading profits, in the latest exploit to target the automated infrastructure DeFi protocols lean on for pricing.",
      "url": "https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault",
      "publishedAt": "2026-07-15T16:12:18.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Ostium",
        "Halts",
        "Trading"
      ],
      "amountUsd": 18000000,
      "amountSource": "heuristic",
      "oneLiner": "[~$18.0M · oracle manipulation] Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault",
      "signature": "ostium:18m:the-defiant",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T16:12:18.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.theblock.co/post/408450/ostium-pauses-trading-after-apparent-18-million-vault-exploit?utm_source=rss&utm_medium=rss",
      "source": "The Block",
      "sourceKind": "rss",
      "title": "Ostium pauses trading after apparent $18 million vault exploit",
      "summary": "Onchain data shows the Ostium attacker dispersing the stolen funds across multiple wallets after converting USDC into ETH.",
      "url": "https://www.theblock.co/post/408450/ostium-pauses-trading-after-apparent-18-million-vault-exploit?utm_source=rss&utm_medium=rss",
      "publishedAt": "2026-07-15T15:47:52.000Z",
      "category": "exploit",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Ostium"
      ],
      "amountUsd": 18000000,
      "amountSource": "heuristic",
      "oneLiner": "[~$18.0M] Ostium pauses trading after apparent $18 million vault exploit",
      "signature": "ostium:18m:the-block",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T15:47:52.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi",
      "source": "CoinDesk",
      "sourceKind": "rss",
      "title": "Ostium suffers $18 million exploit as oracle attack wave continues to hit DeFi",
      "summary": "A hacker used Ostium's own price-reporting infrastructure against the protocol, submitting falsified future-dated oracle data to manufacture fake trading profits and trigger an $18 million payout.",
      "url": "https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi",
      "publishedAt": "2026-07-15T15:27:43.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Ostium"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "[oracle manipulation] Ostium suffers $18 million exploit as oracle attack wave continues to hit DeFi",
      "signature": "ostium:ostium-18",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T15:27:43.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://decrypt.co/373528/uk-fraud-review-calls-for-judge-training-on-crypto-laundering-ai-scams",
      "source": "Decrypt",
      "sourceKind": "rss",
      "title": "UK Fraud Review Calls for Judge Training on Crypto Laundering, AI Scams",
      "summary": "A government-backed review says magistrates and judges aren't ready for a coming surge in crypto money laundering and AI-enabled fraud cases.",
      "url": "https://decrypt.co/373528/uk-fraud-review-calls-for-judge-training-on-crypto-laundering-ai-scams",
      "publishedAt": "2026-07-15T12:15:31.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "UK",
        "Fraud",
        "Review"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "UK Fraud Review Calls for Judge Training on Crypto Laundering, AI Scams",
      "signature": "fraud:uk-fraud",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T12:15:31.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.coindesk.com/markets/2026/07/15/strategy-feels-very-secure-until-bitcoin-reaches-usd8-000-usd10-000-says-ceo",
      "source": "CoinDesk",
      "sourceKind": "rss",
      "title": "Strategy feels 'very secure' until bitcoin reaches $8,000-$10,000, says CEO",
      "summary": "Le highlighted increasing the U.S.-dollar reserve as an important lever in preferred stock STRC’s recovery back to around $90 having fallen below $75 last month.",
      "url": "https://www.coindesk.com/markets/2026/07/15/strategy-feels-very-secure-until-bitcoin-reaches-usd8-000-usd10-000-says-ceo",
      "publishedAt": "2026-07-15T12:00:33.000Z",
      "category": "other",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Strategy"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Strategy feels 'very secure' until bitcoin reaches $8,000-$10,000, says CEO",
      "signature": "strategy:strategy-feels",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T12:00:33.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog",
      "source": "CISA Cybersecurity Advisories",
      "sourceKind": "rss",
      "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
      "summary": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulner…",
      "url": "https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog",
      "publishedAt": "2026-07-15T12:00:00.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation",
        "access-control"
      ],
      "protocols": [
        "CISA",
        "Adds",
        "Two"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "[oracle manipulation] CISA Adds Two Known Exploited Vulnerabilities to Catalog",
      "signature": "cisa:cisa-adds",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T12:00:00.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://slowmist.medium.com/telegram-account-compromised-wallet-swapped-how-does-macos-malware-break-through-your-defenses-dad9bfed9c02?source=rss-4ceeedda40e8------2",
      "source": "SlowMist",
      "sourceKind": "rss",
      "title": "Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?",
      "summary": "Background Recently, the MistEye security monitoring system detected an information-stealing malware targeting macOS. The SlowMist security team immediately launched an investigation. Judging from its collection targets, this malware appears to conduct broad, indiscriminate data harvesting rather than focusing on a specific objective. Its targets include the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop local data, and the databases of more than a dozen cryptocurrency wallets. In our previous article, “ Analysis of a Google Sites Community Application Phishing Campaign and mac…",
      "url": "https://slowmist.medium.com/telegram-account-compromised-wallet-swapped-how-does-macos-malware-break-through-your-defenses-dad9bfed9c02?source=rss-4ceeedda40e8------2",
      "publishedAt": "2026-07-15T10:48:56.000Z",
      "category": "scam",
      "vectors": [
        "phishing-wallet-drainer"
      ],
      "protocols": [
        "Telegram",
        "Account",
        "Compromised"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "[phishing / wallet drainer] Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?",
      "signature": "telegram:telegram-account",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T10:48:56.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://crypto.news/scatman-spacex-account-hack-brand-token-crime/",
      "source": "crypto.news",
      "sourceKind": "rss",
      "title": "SCATMAN and the $135K hack: what the SpaceX account breach says about brand-token crime in 2026",
      "summary": "Hijacked SpaceX and Starlink X accounts pushed the SCATMAN memecoin for a $135K payday. Why credibility, not code, is crypto's cheapest attack surface.",
      "url": "https://crypto.news/scatman-spacex-account-hack-brand-token-crime/",
      "publishedAt": "2026-07-15T08:45:00.000Z",
      "category": "exploit",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "SCATMAN"
      ],
      "amountUsd": 135000,
      "amountSource": "heuristic",
      "oneLiner": "[~$135K] SCATMAN and the $135K hack: what the SpaceX account breach says about brand-token crime in 2026",
      "signature": "scatman:135k:crypto-news",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T08:45:00.000Z",
      "timesSeen": 1
    },
    {
      "id": "defillama:Ostium:2026-07-15T00:00:00.000Z",
      "source": "DeFiLlama Hacks DB",
      "sourceKind": "onchain-db",
      "title": "Ostium — exploit",
      "summary": "Technique: Protocol Logic / Price Oracle Manipulation. Chain: Arbitrum. Target: DeFi Protocol. Reported loss ~$18,000,000.",
      "url": "https://api.llama.fi/hacks",
      "publishedAt": "2026-07-15T00:00:00.000Z",
      "reportedAmountUsd": 18000000,
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Ostium"
      ],
      "amountUsd": 18000000,
      "amountSource": "structured",
      "oneLiner": "[$18.0M · oracle manipulation] Ostium — exploit",
      "signature": "ostium:18m:defillama-hacks-db",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "new",
      "firstSeen": "2026-07-15T00:00:00.000Z",
      "timesSeen": 1
    },
    {
      "id": "https://thedefiant.io/news/regulation/argentine-judge-orders-id-freeze-of-25-libra-linked-crypto-wallets",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "Argentine Judge Orders ID, Freeze of 25 LIBRA-Linked Crypto Wallets",
      "summary": "The order targets holders at Binance, Bybit, OKX and Bitfinex, but analyst Fernando Molina says no funds have actually been frozen yet.",
      "url": "https://thedefiant.io/news/regulation/argentine-judge-orders-id-freeze-of-25-libra-linked-crypto-wallets",
      "publishedAt": "2026-07-14T21:36:00.000Z",
      "category": "other",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Argentine",
        "Judge",
        "Orders"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Argentine Judge Orders ID, Freeze of 25 LIBRA-Linked Crypto Wallets",
      "signature": "argentine:argentine-judge",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-15T08:00:08.453Z",
      "timesSeen": 2
    },
    {
      "id": "https://thedefiant.io/news/hacks/prism-relaunches-on-new-contract-after-exploit-diverted-nearly-40-of-fees",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees",
      "summary": "A pseudonymous team is redeploying the Uniswap v4 token that pays fees to everyone who holds it, after a bad actor created 2,500 'phantom' fee positions. The original token has crashed more than 90% in a day.",
      "url": "https://thedefiant.io/news/hacks/prism-relaunches-on-new-contract-after-exploit-diverted-nearly-40-of-fees",
      "publishedAt": "2026-07-14T18:25:53.000Z",
      "category": "exploit",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Prism",
        "Relaunches",
        "New"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees",
      "signature": "prism:prism-relaunches",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-15T08:00:08.453Z",
      "timesSeen": 2
    },
    {
      "id": "rekt:bonzo-finance-rekt",
      "source": "rekt.news Leaderboard",
      "sourceKind": "onchain-db",
      "title": "Bonzo Finance - Rekt",
      "summary": "Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.",
      "url": "https://rekt.news/bonzo-finance-rekt/",
      "publishedAt": "2026-07-14T12:00:00.000Z",
      "reportedAmountUsd": 9050000,
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Bonzo Finance"
      ],
      "amountUsd": 9050000,
      "amountSource": "structured",
      "oneLiner": "[$9.1M · oracle manipulation] Bonzo Finance - Rekt",
      "signature": "bonzo:9m:rekt-news-leaderboar",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-15T08:00:08.453Z",
      "timesSeen": 2
    },
    {
      "id": "https://decrypt.co/373463/us-government-moves-288m-in-seized-crypto-to-coinbase-prime",
      "source": "Decrypt",
      "sourceKind": "rss",
      "title": "US Government Moves $288M in Seized Crypto to Coinbase Prime",
      "summary": "The seized coins landed at the government's custodian, which stops short of a sale but has revived questions about Trump's no-sell pledge.",
      "url": "https://decrypt.co/373463/us-government-moves-288m-in-seized-crypto-to-coinbase-prime",
      "publishedAt": "2026-07-14T11:08:43.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "US",
        "Government",
        "Moves"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "US Government Moves $288M in Seized Crypto to Coinbase Prime",
      "signature": "government:us-government",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-15T08:00:08.453Z",
      "timesSeen": 2
    },
    {
      "id": "https://slowmist.medium.com/threat-intelligence-injective-sdk-compromised-crypto-wallet-private-keys-stolen-0b8f06bf37ad?source=rss-4ceeedda40e8------2",
      "source": "SlowMist",
      "sourceKind": "rss",
      "title": "Threat Intelligence | Injective SDK Compromised, Crypto Wallet Private Keys Stolen",
      "summary": "Background This investigation began with what appeared to be a routine development workflow: a developer installs the official Injective SDK, generates a wallet, imports a mnemonic phrase, or passes an existing private key to an SDK interface. Everything appears normal during installation, and wallet operations may return the expected results. At the same time, however, an additional network request — one that is not part of the intended application logic — is silently sent in the background. Recently, security research firm Socket identified anomalous behavior in version 1.20.21 of the npm p…",
      "url": "https://slowmist.medium.com/threat-intelligence-injective-sdk-compromised-crypto-wallet-private-keys-stolen-0b8f06bf37ad?source=rss-4ceeedda40e8------2",
      "publishedAt": "2026-07-14T03:50:35.000Z",
      "category": "exploit",
      "vectors": [
        "private-key-compromise",
        "supply-chain"
      ],
      "protocols": [
        "Threat",
        "Intelligence"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "[private-key compromise] Threat Intelligence | Injective SDK Compromised, Crypto Wallet Private Keys Stolen",
      "signature": "threat:threat-intelligence",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "https://www.trmlabs.com/resources/blog/ofac-sanctions-firstvpn-and-ransomware-enablers-behind-attacks-on-americans",
      "source": "TRM Labs",
      "sourceKind": "rss",
      "title": "OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans | TRM Labs",
      "summary": "On July 13, 2026, OFAC sanctioned the FirstVPN Service (1VPNS), its administrator Dmytro Rashevskyi, and cryptor vendor Yevgeniy Silayev — targeting the anonymity and malware-obfuscation services ransomware groups rely on rather than a ransomware group itself, with TRM data showing operators paying the service directly on-chain.",
      "url": "https://www.trmlabs.com/resources/blog/ofac-sanctions-firstvpn-and-ransomware-enablers-behind-attacks-on-americans",
      "publishedAt": "2026-07-13T20:56:00.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "OFAC",
        "Sanctions",
        "FirstVPN"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans | TRM Labs",
      "signature": "ofac:ofac-sanctions",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-06-23T13:43:24.831Z",
      "timesSeen": 8
    },
    {
      "id": "https://thedefiant.io/news/hacks/bonzo-lend-loses-9m-on-hedera-in-supra-oracle-exploit",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit",
      "summary": "A single manipulated price feed let an attacker turn 250 SAUCE tokens worth a few dollars into $9.05 million in borrowed USDC and wrapped HBAR in eight seconds.",
      "url": "https://thedefiant.io/news/hacks/bonzo-lend-loses-9m-on-hedera-in-supra-oracle-exploit",
      "publishedAt": "2026-07-13T19:48:08.000Z",
      "category": "exploit",
      "vectors": [
        "oracle-manipulation"
      ],
      "protocols": [
        "Bonzo",
        "Lend",
        "Loses"
      ],
      "amountUsd": 9050000,
      "amountSource": "heuristic",
      "oneLiner": "[~$9.1M · oracle manipulation] Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit",
      "signature": "bonzo:9m:the-defiant",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "https://thedefiant.io/news/cefi/strategy-sells-467m-in-mstr-shares-bitcoin-stack-steady",
      "source": "The Defiant",
      "sourceKind": "rss",
      "title": "Strategy Sells $467M in MSTR Shares, Bitcoin Stack Steady",
      "summary": "The bitcoin treasury company's cash reserve climbed to $3 billion even as its 843,775 BTC holdings stayed frozen for a second straight week.",
      "url": "https://thedefiant.io/news/cefi/strategy-sells-467m-in-mstr-shares-bitcoin-stack-steady",
      "publishedAt": "2026-07-13T17:25:00.000Z",
      "category": "other",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Strategy",
        "Sells",
        "MSTR"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Strategy Sells $467M in MSTR Shares, Bitcoin Stack Steady",
      "signature": "strategy:strategy:467m",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "https://www.chainalysis.com/blog/chainalysis-daubert-standard-sterlingov/",
      "source": "Chainalysis",
      "sourceKind": "rss",
      "title": "Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard",
      "summary": "Blockchain tracing tools like Chainalysis Reactor help investigators untangle the financial networks behind illicit activity: fraud, theft, sanctions evasion, cybercrime,… The post Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard appeared first on Chainalysis.",
      "url": "https://www.chainalysis.com/blog/chainalysis-daubert-standard-sterlingov/",
      "publishedAt": "2026-07-13T13:56:28.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Courtroom"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard",
      "signature": "courtroom:courtroom-ready",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "slowmist:Lumi Finance:2026-07-13",
      "source": "SlowMist Hacked DB",
      "sourceKind": "onchain-db",
      "title": "Lumi Finance — exploit",
      "summary": "Attack method: Smart Contract Logic Vulnerability. Reported loss ~$270,000. The DeFi protocol Lumi Finance on Arbitrum suffered an exploit where attackers leveraged Sodium smart accounts that performed token approvals as a side effect during UserOp validation. This allowed a malicious Paymaster to gain allowances from multiple accounts and drain funds, resulting in approximately $270,000 in losses.",
      "url": "https://x.com/SlowMist_Team/status/2076669154036527314",
      "publishedAt": "2026-07-13T12:00:00.000Z",
      "reportedAmountUsd": 270000,
      "category": "exploit",
      "vectors": [
        "smart-contract-bug"
      ],
      "protocols": [
        "Lumi Finance"
      ],
      "amountUsd": 270000,
      "amountSource": "structured",
      "oneLiner": "[$270K · smart-contract bug] Lumi Finance — exploit",
      "signature": "lumi:270k:slowmist-hacked-db",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "slowmist:Chi Protocol:2026-07-13",
      "source": "SlowMist Hacked DB",
      "sourceKind": "onchain-db",
      "title": "Chi Protocol — exploit",
      "summary": "Attack method: Smart Contract Logic Vulnerability. Reported loss ~$8,500. Chi Protocol (a DeFi stablecoin protocol issuing $USC backed by LSTs/LRTs on Ethereum) was exploited due to a logic error in the ArbitrageV5 contract’s burn() function. The attacker used a flash loan to buy heavily depegged $USC cheaply on a thin Uniswap V2 pool and burned it to redeem full-value collateral (weETH/stETH/WETH) at the hardcoded $1 peg, without the burn function checking the actual peg (unlike the mint function). This resulted in approximately $8,500 loss, nearly draining the protocol’s reserves.",
      "url": "https://x.com/DefimonAlerts/status/2076887008773829119",
      "publishedAt": "2026-07-13T12:00:00.000Z",
      "reportedAmountUsd": 8500,
      "category": "exploit",
      "vectors": [
        "flash-loan",
        "smart-contract-bug"
      ],
      "protocols": [
        "Chi Protocol"
      ],
      "amountUsd": 8500,
      "amountSource": "structured",
      "oneLiner": "[$9K · flash-loan attack] Chi Protocol — exploit",
      "signature": "chi:9k:slowmist-hacked-db",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-15T08:00:08.453Z",
      "timesSeen": 2
    },
    {
      "id": "https://slowmist.medium.com/analysis-of-a-google-sites-community-application-phishing-campaign-and-macos-information-stealing-43ed1b04a1da?source=rss-4ceeedda40e8------2",
      "source": "SlowMist",
      "sourceKind": "rss",
      "title": "Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing…",
      "summary": "Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing Malware Abstract On July 8, 2026, Bruce Xu (@brucexu_eth) reported a phishing link disguised as a BuilDAO / Builder community application page. The attackers hosted the page on Google Sites, leveraging the trusted appearance of sites.google.com to lower users’ guard. The first part of the page mimicked a community application form, prompting users to provide information such as their location, identity, project links, and reasons for joining the community. Instead of proceeding to a legitimate re…",
      "url": "https://slowmist.medium.com/analysis-of-a-google-sites-community-application-phishing-campaign-and-macos-information-stealing-43ed1b04a1da?source=rss-4ceeedda40e8------2",
      "publishedAt": "2026-07-13T10:48:25.000Z",
      "category": "scam",
      "vectors": [
        "phishing-wallet-drainer"
      ],
      "protocols": [
        "Analysis",
        "Google",
        "Sites"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "[phishing / wallet drainer] Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing…",
      "signature": "analysis:analysis-google",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    },
    {
      "id": "https://decrypt.co/373374/chinese-prosecutors-float-treating-crypto-mixer-privacy-coin-use-as-sign-of-money-laundering",
      "source": "Decrypt",
      "sourceKind": "rss",
      "title": "Chinese Prosecutors Float Treating Crypto Mixer, Privacy Coin Use as Sign of Money Laundering",
      "summary": "An article in the top prosecutors' paper urges new blockchain evidence rules, presumptions of intent, and a state platform to sell seized coins.",
      "url": "https://decrypt.co/373374/chinese-prosecutors-float-treating-crypto-mixer-privacy-coin-use-as-sign-of-money-laundering",
      "publishedAt": "2026-07-13T10:43:13.000Z",
      "category": "enforcement",
      "vectors": [
        "unknown"
      ],
      "protocols": [
        "Chinese",
        "Prosecutors",
        "Float"
      ],
      "amountUsd": null,
      "amountSource": null,
      "oneLiner": "Chinese Prosecutors Float Treating Crypto Mixer, Privacy Coin Use as Sign of Money Laundering",
      "signature": "chinese:chinese-prosecutors",
      "confidence": 0.5,
      "classifiedBy": "rule",
      "recency": "developing",
      "firstSeen": "2026-07-14T08:00:49.967Z",
      "timesSeen": 3
    }
  ],
  "stats": {
    "totalItems": 30,
    "totalReportedLossUsd": 108513500,
    "topVectors": [
      {
        "vector": "oracle-manipulation",
        "count": 8
      },
      {
        "vector": "phishing-wallet-drainer",
        "count": 2
      },
      {
        "vector": "smart-contract-bug",
        "count": 2
      },
      {
        "vector": "access-control",
        "count": 1
      },
      {
        "vector": "private-key-compromise",
        "count": 1
      },
      {
        "vector": "supply-chain",
        "count": 1
      }
    ],
    "sourcesUsed": [
      "DeFiLlama Hacks DB",
      "SlowMist Hacked DB",
      "rekt.news Leaderboard",
      "BlockThreat",
      "Rekt News",
      "SlowMist",
      "Trail of Bits",
      "OpenZeppelin",
      "Zellic",
      "Chainalysis",
      "TRM Labs",
      "Elliptic",
      "CISA Cybersecurity Advisories",
      "SANS ISC",
      "Cointelegraph (Security)",
      "crypto.news",
      "The Defiant",
      "The Block",
      "CoinDesk",
      "Decrypt",
      "Protos",
      "Immunefi Audit Reports"
    ],
    "sourcesFailed": [
      {
        "source": "CertiK",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "ConsenSys Diligence",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "Cantina / Spearbit",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "pcaversaccio",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "Chainabuse",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "Arkham Intelligence",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@PeckShieldAlert",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@CertiKAlert",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@CyversAlerts",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@BlockSecTeam",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@AnciliaInc",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@Phalcon_xyz",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@zachxbt",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@SlowMist_Team",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@MistTrack_io",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@realScamSniffer",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@samczsun",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@tayvano_",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@spreekaway",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@_SEAL_Org",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@hypernative",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@HalbornSecurity",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@Beosin_com",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@GoPlusSecurity",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@Quantstamp",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@Chainalysis",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "@TrugardLabs",
        "error": "HTTP 402: {\"detail\":\"credits depleted\",\"status\":402,\"title\":\"Payment Required\",\"type\":\"https://api.x.com/2/problems/credits-depleted\"}"
      },
      {
        "source": "Immunefi",
        "error": "Invalid character in tag name\nLine: 1\nColumn: 49\nChar: @"
      }
    ],
    "sourceStats": [
      {
        "source": "CertiK",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "ConsenSys Diligence",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Cantina / Spearbit",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "pcaversaccio",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Chainabuse",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Arkham Intelligence",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@PeckShieldAlert",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@CertiKAlert",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@CyversAlerts",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@BlockSecTeam",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@AnciliaInc",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@Phalcon_xyz",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@zachxbt",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@SlowMist_Team",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@MistTrack_io",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@realScamSniffer",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@samczsun",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@tayvano_",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@spreekaway",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@_SEAL_Org",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@hypernative",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@HalbornSecurity",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@Beosin_com",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@GoPlusSecurity",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@Quantstamp",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@Chainalysis",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "@TrugardLabs",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "DeFiLlama Hacks DB",
        "raw": 586,
        "kept": 586,
        "windowed": 3,
        "final": 1
      },
      {
        "source": "SlowMist Hacked DB",
        "raw": 20,
        "kept": 20,
        "windowed": 2,
        "final": 2
      },
      {
        "source": "rekt.news Leaderboard",
        "raw": 308,
        "kept": 308,
        "windowed": 1,
        "final": 1
      },
      {
        "source": "BlockThreat",
        "raw": 15,
        "kept": 15,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Rekt News",
        "raw": 7,
        "kept": 7,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "SlowMist",
        "raw": 10,
        "kept": 8,
        "windowed": 3,
        "final": 3
      },
      {
        "source": "Trail of Bits",
        "raw": 20,
        "kept": 3,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "OpenZeppelin",
        "raw": 10,
        "kept": 7,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Zellic",
        "raw": 20,
        "kept": 9,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Chainalysis",
        "raw": 10,
        "kept": 4,
        "windowed": 2,
        "final": 2
      },
      {
        "source": "TRM Labs",
        "raw": 100,
        "kept": 38,
        "windowed": 1,
        "final": 1
      },
      {
        "source": "Elliptic",
        "raw": 10,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Immunefi",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "CISA Cybersecurity Advisories",
        "raw": 30,
        "kept": 3,
        "windowed": 1,
        "final": 1
      },
      {
        "source": "SANS ISC",
        "raw": 10,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Cointelegraph (Security)",
        "raw": 30,
        "kept": 14,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "crypto.news",
        "raw": 50,
        "kept": 3,
        "windowed": 3,
        "final": 3
      },
      {
        "source": "The Defiant",
        "raw": 100,
        "kept": 18,
        "windowed": 7,
        "final": 7
      },
      {
        "source": "The Block",
        "raw": 20,
        "kept": 2,
        "windowed": 2,
        "final": 2
      },
      {
        "source": "CoinDesk",
        "raw": 25,
        "kept": 2,
        "windowed": 2,
        "final": 2
      },
      {
        "source": "Decrypt",
        "raw": 56,
        "kept": 7,
        "windowed": 5,
        "final": 5
      },
      {
        "source": "Protos",
        "raw": 10,
        "kept": 0,
        "windowed": 0,
        "final": 0
      },
      {
        "source": "Immunefi Audit Reports",
        "raw": 0,
        "kept": 0,
        "windowed": 0,
        "final": 0
      }
    ]
  },
  "intel": {
    "newCount": 15,
    "developingCount": 15,
    "window7d": {
      "days": 7,
      "incidents": 92,
      "totalLossUsd": 1306873500,
      "vectorDistribution": [
        {
          "vector": "oracle-manipulation",
          "count": 11
        },
        {
          "vector": "phishing-wallet-drainer",
          "count": 5
        },
        {
          "vector": "smart-contract-bug",
          "count": 3
        },
        {
          "vector": "governance-attack",
          "count": 3
        },
        {
          "vector": "access-control",
          "count": 2
        },
        {
          "vector": "private-key-compromise",
          "count": 2
        },
        {
          "vector": "supply-chain",
          "count": 2
        },
        {
          "vector": "flash-loan",
          "count": 1
        }
      ]
    },
    "window30d": {
      "days": 30,
      "incidents": 449,
      "totalLossUsd": 5469554854.58,
      "vectorDistribution": [
        {
          "vector": "smart-contract-bug",
          "count": 44
        },
        {
          "vector": "phishing-wallet-drainer",
          "count": 21
        },
        {
          "vector": "social-engineering",
          "count": 18
        },
        {
          "vector": "private-key-compromise",
          "count": 16
        },
        {
          "vector": "oracle-manipulation",
          "count": 14
        },
        {
          "vector": "supply-chain",
          "count": 13
        },
        {
          "vector": "governance-attack",
          "count": 13
        },
        {
          "vector": "bridge-exploit",
          "count": 13
        },
        {
          "vector": "flash-loan",
          "count": 7
        },
        {
          "vector": "frontend-dns-hijack",
          "count": 5
        },
        {
          "vector": "access-control",
          "count": 4
        },
        {
          "vector": "rug-pull",
          "count": 3
        }
      ]
    },
    "weekOverWeek": {
      "prior7dLossUsd": 2965426000,
      "prior7dIncidents": 98,
      "lossDeltaPct": -56,
      "incidentDeltaPct": -6
    },
    "repeatVictims": [
      {
        "name": "bitcoin",
        "incidents": 20
      },
      {
        "name": "trump",
        "incidents": 10
      },
      {
        "name": "certik",
        "incidents": 10
      },
      {
        "name": "coinbase",
        "incidents": 9
      },
      {
        "name": "ethereum",
        "incidents": 8
      },
      {
        "name": "polymarket",
        "incidents": 8
      },
      {
        "name": "how",
        "incidents": 7
      },
      {
        "name": "xrp",
        "incidents": 7
      }
    ],
    "repeatActors": []
  }
}