62 hack event(s)
Description of the event: Security firm Coinspect disclosed that RRWallet (RenrenBit’s wallet) generated vulnerable seed phrases due to a weak RNG in the CryptoJS library (Ill Bloom vulnerability, CVE-2026-71851), making private keys predictable and leading to theft. One user lost approximately $2 million.
Amount of loss: $ 2,000,000 Attack method: Supply Chain Attack
Description of the event: ZEUS (Bitcoin Lightning Network wallet and LSP provider) infrastructure suffered a cybersecurity incident/attack within the last few hours; the attack was mitigated. Services were temporarily taken offline for a full systems audit out of caution; no customer funds were lost or at risk, and closed LSP channels will be replaced upon restoration. The incident appears limited to ZEUS infrastructure, with no evidence of a Lightning node software vulnerability.
Amount of loss: 0 Attack method: Infrastructure Compromise
Description of the event: Coldcard hardware wallets (by Coinkite) suffered from a firmware bug (since March 2021 on certain versions) that generated seeds with insufficient entropy (~40 bits on Mk3, ~72 bits on newer models vs. the intended 128 bits). Attackers offline brute-forced predictable private keys and drained numerous single-signature Bitcoin addresses across multiple waves without ever accessing the devices, with cumulative losses exceeding $100 million and the incident ongoing.
Amount of loss: $ 100000000 Attack method: Firmware Vulnerability
Description of the event: SecondFi (formerly Yoroi) Cardano wallet suffered an exploit due to a vulnerability in its proprietary web wallet generation software, exposing private keys at the address level. Attackers drained ~16 million ADA ($2.4M) from 374 affected wallets across three attacks. The project secured ~129 million ADA (~$19.4M) through emergency rescue; affected users must wait for official recovery and are advised to use hardware wallets for migration.
Amount of loss: $ 2,400,000 Attack method: Predictable Private Key Exploit
Description of the event: A third-party Gnosis Safe module named SquidRouterModule was exploited, draining approximately $3-3.2 million from 86 Gnosis Safe wallets on Ethereum and Base within about 2 hours. The module has no affiliation with the official Squid Router protocol—confusion arose solely due to the contract name on Basescan. Victims had previously added this faulty third-party module as a trusted Safe Module, granting it permission to spend any tokens without signatures. The attacker exploited weak authentication (accepting a publicly visible constant string as "message security" proof) to execute arbitrary calldata, forcing fake Uniswap V3 swaps (real tokens for worthless 'u' token in attacker-controlled pools) and draining funds, which were consolidated into ~3.07M DAI. Squid confirmed its core router and user funds/integrations remain fully secure.
Amount of loss: $ 3,200,000 Attack method: Smart Contract Vulnerability
Description of the event: An employee device at Zerion was compromised through an AI-driven social engineering attack, allegedly linked to a DPRK-associated advanced persistent threat (APT) group. The attacker successfully obtained the employee’s logged-in sessions, account credentials, and private keys to company hot wallets used for internal testing and operations, and subsequently transferred approximately $100,000 from multiple internal hot wallets. No user funds were affected in this incident, and Zerion’s products, mobile applications, and backend infrastructure were not compromised. The attack was limited to an employee device and internal company hot wallet systems. Following the incident, the team proactively took down the web application and carried out full credential rotation, device security reviews, and infrastructure hardening measures to prevent further risk exposure.
Amount of loss: $ 100,000 Attack method: AI-enabled Social Engineering Attack
Description of the event: According to ZachXBT, the Trust Wallet Discord vanity URL (discord[.]gg/trustwallet) has been hijacked and currently directs users to a phishing server. Users are advised to avoid using links from official channels—including the official website, Telegram, and blogs—to join the Discord at this time.
Amount of loss: 0 Attack method: Supply Chain Attack
Description of the event: the Holdstation team confirmed that its DeFAI Smart Wallet product suffered a supply chain attack targeting the application distribution infrastructure. This resulted in unauthorized transactions in some user wallets, with a confirmed loss of approximately $462,000 USDT. Smart contracts were not directly exploited. The team committed to 100% compensation for affected users and is reinforcing security measures.
Amount of loss: $ 462,000 Attack method: Supply Chain Attack
Description of the event: Trust Wallet has issued an official notice confirming that version 2.68 of its browser extension contains a security vulnerability, and advised all users running version 2.68 to immediately disable it and upgrade to version 2.69. According to SlowMist’s analysis, this backdoor incident originated from a malicious modification of Trust Wallet’s internal codebase (analytics service logic), rather than the introduction of a compromised third-party package (e.g., a malicious npm package). The attacker directly tampered with the application’s own code, using the legitimate PostHog library to redirect analytics data to a malicious server. As of December 31, the incident has been confirmed to affect 2,520 wallet addresses, with a total loss of approximately USD 8.5 million. Preliminary investigation indicates that this attack is related to the Sha1-Hulud industry-level supply chain incident that occurred in November. Trust Wallet has now rolled back the extension to the secure version 2.69 and initiated a compensation process for affected users.
Amount of loss: $ 8,500,000 Attack method: Malicious Code Injection Attack
Description of the event: The official X account of the hardware wallet Keystone is suspected to have been hacked. Users are advised to remain vigilant and be cautious of potential risks.
Amount of loss: - Attack method: Account Compromise
Description of the event: According to monitoring by Scam Sniffer, the X account of Ordinals Wallet was hacked, and a phishing link was posted. Upon review, the related post has already been deleted.
Amount of loss: - Attack method: Account Compromise
Description of the event: According to a message posted by Wasabi Wallet on Twitter, users have reported that a coordinator named WasabiCoordinator is gradually stealing user funds through a complex attack. Wasabi Wallet advises all users connected to this coordinator to immediately stop CoinJoin operations and announces that a new version will be released soon to prevent such attacks. Subsequently, Wasabi Wallet tweeted that there were three types of attacks in this incident: attacks on free coordinators, supply chain (GitHub) compromise, user-targeted attacks.
Amount of loss: - Attack method: Security Vulnerability
Description of the event: On July 2, 2024, the decentralized AI project Bittensor was attacked, resulting in some Bittensor wallet users being compromised. The hackers stole approximately 32,000 TAO tokens, valued at around $8 million. On-chain investigator ZachXBT suggested that the attack may have been due to a private key leak. However, Bittensor later clarified that the affected users were actually compromised because a malicious Bittensor package had been uploaded to the Python PyPi package manager.
Amount of loss: $ 8,000,000 Attack method: Security Vulnerability
Description of the event: On the X platform, on-chain investigator ZachXBT reported that the X account of hardware wallet provider Trezor was hacked.
Amount of loss: - Attack method: Account Compromise
Description of the event: The user-friendly crypto wallet designed for DeFi and NFTs, Phantom, reported a DDoS attack on its platform. Someone attempted to overload its systems, causing potential temporary interruptions in some services. User assets are secure.
Amount of loss: - Attack method: DDoS Attack
Description of the event: Trezor, the manufacturer of encrypted hardware wallets, has announced that it is currently investigating a security incident that occurred on January 17, 2024. Unauthorized access was detected to the third-party support portal used by Trezor. No damage has been inflicted on customers' digital assets. Internal audits indicate that the exposure might be limited to information of customers who have interacted with Trezor Support since December 2021, encompassing only email and names/nicknames.
Amount of loss: - Attack method: Third-party Vulnerability
Description of the event: Wizz Wallet, the wallet of the Atomicals protocol, posted on Twitter that builders within the Atomicals ecosystem, including the Wizz team, have experienced DDoS attacks.
Amount of loss: - Attack method: DDoS Attack
Description of the event: Recently, Telcoin Wallet was subjected to a targeted attack, and Telcoin tweeted that it is aware of the situation with the Telcoin app. Use of the app has been temporarily frozen while the issue is investigated and an update will be provided as soon as possible.
Amount of loss: $ 1,240,000 Attack method: Unknown
Description of the event: UniSat Wallet's official tweet is suspected to have been hacked.It posted a promotional tweet for a program with closed comments and a suspected malicious link.
Amount of loss: - Attack method: Account Compromise
Description of the event: On October 6th, MCT issued an announcement stating that in the past two days, some users had reported cases of their MCT wallets being compromised. After investigation today, it was discovered that due to the DNS domain hijacking, under certain specific conditions, private keys could potentially be uploaded to a fraudulent domain. MCT advises users who have entered their private keys into MCT since September 15, 2023, to transfer their wallet balances as a precautionary measure as soon as possible.
Amount of loss: - Attack method: Domain Hijacking