# 🛡️ GM Security — 2026-07-16

**30 incidents** · **$108.5M reported losses** · last 72h · 22 live sources

## Executive summary

30 crypto-security item(s) in the window with ~$108.5M in reported losses The largest is "Blockaid uncovers $18M exploit that forces Ostium trading halt" (~$18.0M). Dominant vectors: oracle manipulation, phishing / wallet drainer, smart-contract bug, access-control flaw.

**Trends to watch**

- 🧊 On-chain — Tether USDT freezes (7d): 18 addresses (2026-07-15). Source: Dune
- oracle manipulation activity observed (8 item(s))
- phishing / wallet drainer activity observed (2 item(s))
- smart-contract bug activity observed (2 item(s))

## 📊 Trend tracker

- 15 new today · 15 developing
- 7-day: 92 incidents, $1.31B stolen (-56% vs prior week)
- 30-day: 449 incidents, $5.47B stolen
- 7-day vectors: oracle manipulation (11), phishing / wallet drainer (5), smart-contract bug (3)
- Repeat targets (30d): bitcoin (20), trump (10), certik (10), coinbase (9), ethereum (8)

**Attack vectors:** oracle manipulation (8) · phishing / wallet drainer (2) · smart-contract bug (2) · access-control flaw (1) · private-key compromise (1) · supply-chain attack (1)

## Incidents & reports

### [SummerFi to Wind Down After Seven Years, Citing Exploit](https://thedefiant.io/news/defi/summerfi-to-wind-down-after-seven-years-citing-exploit)
**NEW** · _The Defiant_

Aave founder Stani Kulechov called the DeFi access point 'an OG' as its team said it would sunset the UI.

### [eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up](https://thedefiant.io/news/cefi/etoro-strategic-stake-onchain-derivatives-extended-zengo)
**DEVELOPING · day 13** · _The Defiant_

eToro has become a strategic investor in Extended, an onchain perpetual futures exchange, and said the round begins a partnership with Zengo, the self-custody wallet eToro acquired earlier this year. Neither company disclosed the investment size.

### [California duo accused of laundering crypto from fentanyl and meth sales](https://crypto.news/california-duo-accused-of-laundering-crypto-from-fentanyl-and-meth-sales/)
**NEW** · _crypto.news_

A California pair has been indicted on allegations of running a darknet drug operation that prosecutors say generated hundreds of thousands of dollars in cryptocurrency proceeds from fentanyl and methamphetamine sales. According to a Wednesday statement from the U.S. Department…

### [California pair charged with laundering crypto proceeds from darknet fentanyl sales](https://www.theblock.co/post/408560/california-duo-darknet-drug-crypto-money-laundering?utm_source=rss&utm_medium=rss)
**NEW** · _The Block_

The pair allegedly shipped over 500 drug parcels over a seven-month period and laundered hundreds of thousands of dollars through crypto.

### [OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins](https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins/)
**NEW** · _Chainalysis_

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday updated its Central Bank of Iran designation to… The post OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins appeared first on Chainalysis.

### [Blockaid uncovers $18M exploit that forces Ostium trading halt](https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/)
**NEW** · `~$18.0M` · oracle manipulation · _crypto.news_

Ostium has halted trading after an exploit tied to a compromised oracle signer key drained nearly $18 million USDC from its liquidity vault, according to blockchain security firm Blockaid. Blockaid reported that the attacker gained control of an oracle signer…

### [Another DeFi Exploit: Perp DEX Ostium Loses $18 Million in Oracle Attack](https://decrypt.co/373566/defi-exploit-ostium-oracle-hack)
**NEW** · `~$18.0M` · oracle manipulation · _Decrypt_

Hackers manipulated Ostium's price feed by compromising an oracle signer key, allowing them to drain roughly $18 million from the Arbitrum-based perpetuals exchange.

### [US Treasury Freezes $131 Million in Iran-Linked Crypto Wallets](https://decrypt.co/373565/us-treasury-freezes-131-million-iran-crypto)
**DEVELOPING · day 3** · _Decrypt_

OFAC sanctioned addresses tied to Iran's central bank and armed forces, with Tether locking four Tron wallets as Washington's financial campaign against Tehran accelerates.

### [Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault](https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault)
**NEW** · `~$18.0M` · oracle manipulation · _The Defiant_

Blockaid says an attacker used a registered price-feed forwarder and future-dated oracle reports to book fake trading profits, in the latest exploit to target the automated infrastructure DeFi protocols lean on for pricing.

### [Ostium pauses trading after apparent $18 million vault exploit](https://www.theblock.co/post/408450/ostium-pauses-trading-after-apparent-18-million-vault-exploit?utm_source=rss&utm_medium=rss)
**NEW** · `~$18.0M` · _The Block_

Onchain data shows the Ostium attacker dispersing the stolen funds across multiple wallets after converting USDC into ETH.

### [Ostium suffers $18 million exploit as oracle attack wave continues to hit DeFi](https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi)
**NEW** · oracle manipulation · _CoinDesk_

A hacker used Ostium's own price-reporting infrastructure against the protocol, submitting falsified future-dated oracle data to manufacture fake trading profits and trigger an $18 million payout.

### [UK Fraud Review Calls for Judge Training on Crypto Laundering, AI Scams](https://decrypt.co/373528/uk-fraud-review-calls-for-judge-training-on-crypto-laundering-ai-scams)
**NEW** · _Decrypt_

A government-backed review says magistrates and judges aren't ready for a coming surge in crypto money laundering and AI-enabled fraud cases.

### [Strategy feels 'very secure' until bitcoin reaches $8,000-$10,000, says CEO](https://www.coindesk.com/markets/2026/07/15/strategy-feels-very-secure-until-bitcoin-reaches-usd8-000-usd10-000-says-ceo)
**NEW** · _CoinDesk_

Le highlighted increasing the U.S.-dollar reserve as an important lever in preferred stock STRC’s recovery back to around $90 having fallen below $75 last month.

### [CISA Adds Two Known Exploited Vulnerabilities to Catalog](https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog)
**NEW** · oracle manipulation, access-control flaw · _CISA Cybersecurity Advisories_

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulner…

### [Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?](https://slowmist.medium.com/telegram-account-compromised-wallet-swapped-how-does-macos-malware-break-through-your-defenses-dad9bfed9c02?source=rss-4ceeedda40e8------2)
**NEW** · phishing / wallet drainer · _SlowMist_

Background Recently, the MistEye security monitoring system detected an information-stealing malware targeting macOS. The SlowMist security team immediately launched an investigation. Judging from its collection targets, this malware appears to conduct broad, indiscriminate data harvesting rather than focusing on a specific objective. Its targets include the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop local data, and the databases of more than a dozen cryptocurrency wallets. In our previous article, “ Analysis of a Google Sites Community Application Phishing Campaign and mac…

### [SCATMAN and the $135K hack: what the SpaceX account breach says about brand-token crime in 2026](https://crypto.news/scatman-spacex-account-hack-brand-token-crime/)
**NEW** · `~$135K` · _crypto.news_

Hijacked SpaceX and Starlink X accounts pushed the SCATMAN memecoin for a $135K payday. Why credibility, not code, is crypto's cheapest attack surface.

### [Ostium — exploit](https://api.llama.fi/hacks)
**NEW** · `$18.0M` · oracle manipulation · _DeFiLlama Hacks DB_

Technique: Protocol Logic / Price Oracle Manipulation. Chain: Arbitrum. Target: DeFi Protocol. Reported loss ~$18,000,000.

### [Argentine Judge Orders ID, Freeze of 25 LIBRA-Linked Crypto Wallets](https://thedefiant.io/news/regulation/argentine-judge-orders-id-freeze-of-25-libra-linked-crypto-wallets)
**DEVELOPING · day 2** · _The Defiant_

The order targets holders at Binance, Bybit, OKX and Bitfinex, but analyst Fernando Molina says no funds have actually been frozen yet.

### [Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees](https://thedefiant.io/news/hacks/prism-relaunches-on-new-contract-after-exploit-diverted-nearly-40-of-fees)
**DEVELOPING · day 2** · _The Defiant_

A pseudonymous team is redeploying the Uniswap v4 token that pays fees to everyone who holds it, after a bad actor created 2,500 'phantom' fee positions. The original token has crashed more than 90% in a day.

### [Bonzo Finance - Rekt](https://rekt.news/bonzo-finance-rekt/)
**DEVELOPING · day 2** · `$9.1M` · oracle manipulation · _rekt.news Leaderboard_

Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.

### [US Government Moves $288M in Seized Crypto to Coinbase Prime](https://decrypt.co/373463/us-government-moves-288m-in-seized-crypto-to-coinbase-prime)
**DEVELOPING · day 2** · _Decrypt_

The seized coins landed at the government's custodian, which stops short of a sale but has revived questions about Trump's no-sell pledge.

### [Threat Intelligence | Injective SDK Compromised, Crypto Wallet Private Keys Stolen](https://slowmist.medium.com/threat-intelligence-injective-sdk-compromised-crypto-wallet-private-keys-stolen-0b8f06bf37ad?source=rss-4ceeedda40e8------2)
**DEVELOPING · day 3** · private-key compromise, supply-chain attack · _SlowMist_

Background This investigation began with what appeared to be a routine development workflow: a developer installs the official Injective SDK, generates a wallet, imports a mnemonic phrase, or passes an existing private key to an SDK interface. Everything appears normal during installation, and wallet operations may return the expected results. At the same time, however, an additional network request — one that is not part of the intended application logic — is silently sent in the background. Recently, security research firm Socket identified anomalous behavior in version 1.20.21 of the npm p…

### [OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans | TRM Labs](https://www.trmlabs.com/resources/blog/ofac-sanctions-firstvpn-and-ransomware-enablers-behind-attacks-on-americans)
**DEVELOPING · day 8** · _TRM Labs_

On July 13, 2026, OFAC sanctioned the FirstVPN Service (1VPNS), its administrator Dmytro Rashevskyi, and cryptor vendor Yevgeniy Silayev — targeting the anonymity and malware-obfuscation services ransomware groups rely on rather than a ransomware group itself, with TRM data showing operators paying the service directly on-chain.

### [Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit](https://thedefiant.io/news/hacks/bonzo-lend-loses-9m-on-hedera-in-supra-oracle-exploit)
**DEVELOPING · day 3** · `~$9.1M` · oracle manipulation · _The Defiant_

A single manipulated price feed let an attacker turn 250 SAUCE tokens worth a few dollars into $9.05 million in borrowed USDC and wrapped HBAR in eight seconds.

### [Strategy Sells $467M in MSTR Shares, Bitcoin Stack Steady](https://thedefiant.io/news/cefi/strategy-sells-467m-in-mstr-shares-bitcoin-stack-steady)
**DEVELOPING · day 3** · _The Defiant_

The bitcoin treasury company's cash reserve climbed to $3 billion even as its 843,775 BTC holdings stayed frozen for a second straight week.

### [Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard](https://www.chainalysis.com/blog/chainalysis-daubert-standard-sterlingov/)
**DEVELOPING · day 3** · _Chainalysis_

Blockchain tracing tools like Chainalysis Reactor help investigators untangle the financial networks behind illicit activity: fraud, theft, sanctions evasion, cybercrime,… The post Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard appeared first on Chainalysis.

### [Lumi Finance — exploit](https://x.com/SlowMist_Team/status/2076669154036527314)
**DEVELOPING · day 3** · `$270K` · smart-contract bug · _SlowMist Hacked DB_

Attack method: Smart Contract Logic Vulnerability. Reported loss ~$270,000. The DeFi protocol Lumi Finance on Arbitrum suffered an exploit where attackers leveraged Sodium smart accounts that performed token approvals as a side effect during UserOp validation. This allowed a malicious Paymaster to gain allowances from multiple accounts and drain funds, resulting in approximately $270,000 in losses.

### [Chi Protocol — exploit](https://x.com/DefimonAlerts/status/2076887008773829119)
**DEVELOPING · day 2** · `$9K` · flash-loan attack, smart-contract bug · _SlowMist Hacked DB_

Attack method: Smart Contract Logic Vulnerability. Reported loss ~$8,500. Chi Protocol (a DeFi stablecoin protocol issuing $USC backed by LSTs/LRTs on Ethereum) was exploited due to a logic error in the ArbitrageV5 contract’s burn() function. The attacker used a flash loan to buy heavily depegged $USC cheaply on a thin Uniswap V2 pool and burned it to redeem full-value collateral (weETH/stETH/WETH) at the hardcoded $1 peg, without the burn function checking the actual peg (unlike the mint function). This resulted in approximately $8,500 loss, nearly draining the protocol’s reserves.

### [Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing…](https://slowmist.medium.com/analysis-of-a-google-sites-community-application-phishing-campaign-and-macos-information-stealing-43ed1b04a1da?source=rss-4ceeedda40e8------2)
**DEVELOPING · day 3** · phishing / wallet drainer · _SlowMist_

Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing Malware Abstract On July 8, 2026, Bruce Xu (@brucexu_eth) reported a phishing link disguised as a BuilDAO / Builder community application page. The attackers hosted the page on Google Sites, leveraging the trusted appearance of sites.google.com to lower users’ guard. The first part of the page mimicked a community application form, prompting users to provide information such as their location, identity, project links, and reasons for joining the community. Instead of proceeding to a legitimate re…

### [Chinese Prosecutors Float Treating Crypto Mixer, Privacy Coin Use as Sign of Money Laundering](https://decrypt.co/373374/chinese-prosecutors-float-treating-crypto-mixer-privacy-coin-use-as-sign-of-money-laundering)
**DEVELOPING · day 3** · _Decrypt_

An article in the top prosecutors' paper urges new blockchain evidence rules, presumptions of intent, and a state platform to sell seized coins.

---

_Sources: DeFiLlama Hacks DB, SlowMist Hacked DB, rekt.news Leaderboard, BlockThreat, Rekt News, SlowMist, Trail of Bits, OpenZeppelin, Zellic, Chainalysis, TRM Labs, Elliptic, CISA Cybersecurity Advisories, SANS ISC, Cointelegraph (Security), crypto.news, The Defiant, The Block, CoinDesk, Decrypt, Protos, Immunefi Audit Reports. Automated digest — verify before acting._

_Sources unavailable: CertiK (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); ConsenSys Diligence (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); Cantina / Spearbit (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); pcaversaccio (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); Chainabuse (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); Arkham Intelligence (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @PeckShieldAlert (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @CertiKAlert (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @CyversAlerts (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @BlockSecTeam (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @AnciliaInc (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @Phalcon_xyz (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @zachxbt (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @SlowMist_Team (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @MistTrack_io (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @realScamSniffer (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @samczsun (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @tayvano_ (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @spreekaway (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @_SEAL_Org (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @hypernative (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @HalbornSecurity (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @Beosin_com (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @GoPlusSecurity (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @Quantstamp (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @Chainalysis (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); @TrugardLabs (HTTP 402: {"detail":"credits depleted","status":402,"title":"Payment Required","type":"https://api.x.com/2/problems/credits-depleted"}); Immunefi (Invalid character in tag name
Line: 1
Column: 49
Char: @)._