1D ago
4 sources
Hackers withdrew about 4,000 BTC from the wallet that backs Liquid Network, a Bitcoin sidechain used by exchanges and other financial institutions. Liquid said the attackers used SideSwap through its Peg-out Authorization Key system, but said no SideSwap key or other PAK appeared to be compromised. Liquid disabled bridge nodes and asked exchanges to halt L-BTC deposits and withdrawals while it investigates the vulnerability and patches nodes.
— This is a major live crypto security incident affecting a network used to move Bitcoin-backed assets, with immediate risk to exchanges and users handling L-BTC. Anyone operating Liquid infrastructure or supporting Liquid assets should follow vendor guidance, pause affected activity where advised, and wait for confirmed remediation before resuming transfers.
Sources: Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys, Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC, Hackers Return $263 Million Stolen From Liquid Network (+1 more)
1M ago
3 sources
A flaw in COLDCARD hardware wallet firmware likely let attackers steal about $88.6 million in Bitcoin from thousands of wallets. Researchers say an integration error caused affected devices to use a deterministic software random number generator instead of the STM32 hardware random number generator when creating wallet seeds, making seeds guessable offline. Coinkite says affected versions include Mk2 and Mk3 firmware 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0 or 6.6.0X, and Q devices before 1.5.0Q or 6.6.0QX; patching does not fix already generated seeds.
— This is both a vulnerability and an active theft event affecting cryptocurrency holders, and updating alone is not enough if a seed was created on a vulnerable version. Affected users should install fixed firmware, generate a new seed, and move funds after testing the new wallet.
Sources: COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft, Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen, COLDCARD security audit phishing attack installs remote access tool
2M ago
2 sources
A malicious version of Injective Labs' JavaScript SDK was published to npm after attackers compromised a contributor account, putting developers and downstream crypto apps at risk of wallet theft. The poisoned release was @injectivelabs/sdk-ts version 1.20.21, and 17 related packages were pinned to it. The malware triggered when wallet-generation or wallet-import functions were used, then exfiltrated mnemonic seed phrases and private keys via HTTP requests disguised as legitimate traffic. Injective later published clean version 1.20.23.
— Developers who installed or used the affected package may have exposed wallet secrets that let attackers drain funds, so this is urgent for cryptocurrency projects and users tied to those wallets. Affected teams should audit dependencies, rotate environment secrets, and move funds to new wallets if any seed phrase or private key may have been handled by the malicious version.
Sources: Injective SDK on npm infected with cryptocurrency wallet stealer, Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
2M ago
1 sources
The JaredFromSubway Ethereum trading bot lost about $15 million after an attacker tricked it into approving malicious contracts and then drained its funds. According to Blockaid and JaredFromSubway, the attacker created fake MEV (maximal extractable value) opportunities using bogus pools and tokens so the bot would grant ERC-20 spending approvals to attacker-controlled helper contracts; the attacker later used those lingering approvals and the transferFrom function to withdraw WETH, USDC, and USDT.
— This is a major crypto theft that shows how automated on-chain trading systems can be manipulated even without directly breaking a blockchain. Crypto firms, bot operators, and smart-contract developers should review approval logic, route validation, and allowance revocation controls immediately.
Sources: JaredFromSubway MEV bot hacked in $15 million crypto theft