A Coldcard Wave 3 operator moved about 20.5 BTC into Ether through THORChain, the first spend from the original addresses across three attack waves.
Zilliqa's post-mortem confirmed 683.13 million ZIL was stolen through a flaw in its legacy Ledger app, exposing 6,772 accounts and freezing legacy transactions.
Term Labs permanently closed its Meta Vaults after an $8.5 million governance exploit, while withdrawals remain open and the core Term lending markets remain under review.
The Sandbox halted Base and BNB Smart Chain bridging after an exploit minted unbacked SAND. On-chain reports put the observed reserve loss near $675,000.
SafePal says an order-tracking flaw exposed data from 39,798 hardware-wallet buyers and is reviewing claims that the dataset is being offered for sale.
TRM Labs traced roughly 1,816 Bitcoin, worth about $116 million at its August 5 snapshot, from more than 5,200 addresses in four Coldcard-related attack waves.
Harmony confirmed an exploit involving the unauthorized minting of 4 billion ONE tokens as the token fell sharply and the team weighed a patch, exchange freezes and a potential rollback.
A volunteer Bitcoin Red Team says its AI-assisted review scanned 150 repositories and made more than a dozen vulnerability disclosures, without naming affected projects or reporting new thefts.
Galaxy Research's August 4 update put confirmed Coldcard-related thefts at 1,596 BTC from about 7,300 addresses, while a separate suspected fourth wave could lift the estimate further.
Ledger researchers said a $250,000 laboratory laser attack can reset a Tangem card password and steal associated funds, while Tangem says the physical attack is not scalable.
Safe said its smart accounts handled nearly 130 million transactions and $39.35 billion in Q2 transfers, while 54.8 million SAFE tokens were staked in its Safenet beta.
Triple-A says customer funds are safe as PeckShield tracks a reported $9.7 million multi-chain wallet drain consolidated into 5,227 ETH.
Trust Wallet has rolled out an in-app AI feature that can read portfolio data, flag token risks and prepare crypto transactions, while requiring users to approve every onchain action.
CertiK recorded 52 verified physical crypto coercion attacks in the first half of 2026, with $124.1 million in exposure and France accounting for 33 cases.
Zcash is shifting node operators away from zcashd and toward Zebra before the July 28 Ironwood upgrade, while Zebra 6.1.0 fixes four node-security issues.
Revolut X now lets customers use AI assistants including Claude and Gemini to analyze markets, set alerts and prepare crypto orders, with final approval still required.
Stellar activated Protocol 27, called Zipper, adding smart-account delegation and stronger replay protection as XLM trading volume surged but the token remained below 20 cents.
XRP Ledger v3.2.0 has reached about 89% adoption on the default validator list, but its fixCleanup3_2_0 amendment still needs a separate on-chain vote.
Zcash patched a critical Orchard shielded-pool bug through an emergency soft fork and NU6.2 upgrade as ZEC sold off and traders questioned supply-audit assurances.
Joe Grand's new wallet-hacking video confirms a $2.24 million KeepKey recovery, teases an older Trezor case he says is worth more than $60 million, and sets up a public-relations problem for Trezor.