Back to Blog

Web3 Security

10 articles on this topic.

Web3 & Smart Contract Security27 September 2026

Magic Eden's Retired Payment Processor Bled $1.8M via Zombie Approvals

A bug in a payment processor Magic Eden stopped using in 2024 let attackers drain NFTs and wETH from old wallet approvals — even after the marketplace itself was shut down.

web3-securitynft-securitytoken-approvals
4 min readRead
Web3 & DeFi Security1 September 2026

Cronos Halts Its Entire Chain to Reverse a $75M Tectonic Exploit

An attacker pumped Tectonic's governance token 100x in 20 minutes to borrow against phantom collateral. Cronos validators froze the whole chain and rolled it back to claw the funds back — trading decentralization for recovery.

defiweb3-securitysmart-contracts
4 min readRead
Web3 & Smart Contract Security30 August 2026

Rain Contract Bug Drains $1.1M From 'Self-Custodial' Crypto Cards

An outdated Solana smart contract at payments processor Rain let an attacker seize admin control of card-collateral accounts, draining funds from Avici and Tria customers who believed their crypto stayed under their own control.

web3-securitysmart-contractssolana
4 min readRead
Web3 & Smart Contract Security29 August 2026

BounceBit's $3M Authorization Bug Forces It to Kill Its Own Layer 1

An unverified-account flaw in BounceBit's Evmos-based chain let an attacker drain 286.5 million BB from nine wallets — and because the underlying chain client is itself discontinued, BounceBit is retiring the L1 rather than patching it.

web3-securitysmart-contract-securityblockchain
4 min readRead
Web3 & Smart Contract Security28 August 2026

Cosmos EVM Bug Drains Three Chains After Early Public Disclosure

A shared underflow in the Cosmos EVM module let an attacker drain KiiChain, TAC, and Nesa Chain within days of Cosmos Labs publishing the fix — before telling the chains that ran the vulnerable code.

cosmosvulnerability-disclosureweb3-security
4 min readRead
DeFi & Smart Contract Security26 August 2026

Term Finance's $8.5M Governance Takeover: When a Timelock Doesn't Trigger

An attacker bought up Term Finance's thinly-held governance token and voted itself control of the protocol's vaults, draining roughly 68% of assets — with the on-paper timelock and veto safeguards never firing.

defi-securitygovernance-attacksmart-contracts
4 min readRead
Web3 Security12 August 2026

Fake Flare Network Staking Site Drains $8.5M in XRP, Two Arrested

A cloned staking site, a fabricated Wikipedia entry, and a paid actor were enough to convince 71 investors to hand over 3.4 million XRP — a reminder that brand impersonation, not smart-contract exploits, remains crypto's most reliable attack surface.

web3-securitycrypto-scamsbrand-impersonation
4 min readRead
Web3 & Exchange Security10 August 2026

Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem

An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.

web3-securityexchange-securitycross-chain
4 min readRead
Hardware Wallet Security2 August 2026

Coldcard's 2021 Firmware Bug Drains $89M in Bitcoin — A Five-Year Blind Spot

A silent 2021 configuration error swapped Coldcard's hardware RNG for a predictable software fallback, and five years later attackers used it to drain more than $89 million in Bitcoin.

bitcoinhardware-walletsrng
4 min readRead
Web3 Security29 June 2026

Taiko Bridge Drained $1.7M After SGX Signing Key Exposed on GitHub

An attacker leveraged a publicly committed SGX enclave key to forge withdrawal proofs on Taiko's Ethereum L2 bridge, draining $1.7 million before block production was halted on 22 June 2026.

bridge-exploitethereum-l2sgx
4 min readRead