Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets

"Coldcard" in boxy red typeColdcard logo (attribution)
Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.

An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.

Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".

42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft

Balance Coin, a small algorithmic stablecoin built on BNB Chain, lost its dollar peg and crashed to fractions of a cent after an attacker successfully exploited a flaw in its pricing logic. The attacker was able to trick the system into accepting an incorrectly low bitcoin price, which they then used to drain multiple vaults used by the project's lending protocol.

The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.

Wanchain bridge on Cardano exploited for more than $9 million

An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.

Allbridge exploited for $1.66 million

The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.

Across Protocol exploited for $3.35 million

The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.

Ostium loses at least $24 million to oracle exploit

Decentralized perpetual futures exchange Ostium was drained of at least $24 million after an attacker manipulated its oracle system — a system that pulls in off-chain price data. After the attacker apparently gained access to the private key used to sign oracle messages, they were able to submit future-dated oracle reports that tricked the system into thinking trades were profitable.

The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.

Bonzo Lend exploited for $9 million in oracle attack

The Hedera-based decentralized lending platform Bozno Lend was exploited for just over $9 million after an attacker took advantage of a flaw in the project's oracle system. The attacker was able to deposit tokens worth only a few dollars, then manipulate the project's oracle to reflect a dramatically higher price. They then borrowed $6.63 million in USDC and 34.5 million wrapped HBAR (~$2.4 million).

Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.

Summer Finance exploited for $6 million, shuts down

Summer Finance, a defi platform that provides "institutional defi vault infrastructure", was exploited for $6 million in an apparent flash loan attack. The attacker used a flash loan to deposit $64.8 million and then withdraw $70.9 million, taking advantage of a price manipulation bug that allowed them to withdraw more than they deposited.

Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."

Dutch Knaken crypto platform collapses with $8 million in customer funds missing

The Dutch cryptocurrency platform Knaken (not to be confused with the American Kraken platform) abruptly went offline in early June, leaving roughly 30,000 customers unable to access their funds. The company was unable to secure a license under the EU's MiCA regulations, which it said forced them to shut down. Though they claimed to be winding down the company in an orderly fashion, they reportedly stopped paying customer withdrawals, and asked customers to stop filing claims.

Dutch prosecutors asked courts to declare the platform bankrupt and install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers, who are missing around €7 million (~$8 million). The request was approved. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.

Polymarket customers lose $2.97 million, company blames third-party vendor

Polymarket customers have lost around $2.97 million to an attacker who then swapped stolen Polymarket USD (pUSD) to ETH.

Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.

Users of the SecondFi Cardano wallet lose $2.4 million in series of hacks

Users of the Cardano wallet SecondFi (formerly Yoroi) have lost a cumulative 16 million ADA (~$2.4 million) across three attacks targeting a vulnerability in the project's wallet generation code.

After the attacks commenced, SecondFi "rescued" another 129 million ADA (~$19.4 million) by moving the assets to a third party entity. They announced that an external accounting firm would verify the funds and process user claims.

About a month after the hack, SecondFi announced it would shut down operations.

Taiko bridge exploited

The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.

Highly active MEV bot known as jaredfromsubway.eth drained for $7.7 million

On blockchains like Ethereum, a strategy known as "MEV" (short for "maximal extractable value") allows intermediaries to profit from manipulating the structure of blocks added to the chain — often reordering or "sandwiching" transactions in ways that extract profits. Automated software known as MEV bots make a business out of this strategy, and one of the most active is a bot called jaredfromsubway.eth — likely so named after one-time Subway spokesman and convicted sex offender Jared Fogle because of its strategy of "sandwiching" transactions by placing trades on both sides, causing the original trader to pay more.

On June 20, an attacker used a series of contracts to cause the bot to grant token approvals that were later used to drain 4,427 ETH ($7.7 million). Some of the funds were then laundered through Tornado Cash.

Main Street USD (msUSD) loses its dollar peg

Main Street USD, also known as msUSD, lost its dollar peg and crashed to around $0.25. At points, the token dipped as low as around $0.06. The asset, issued by Main Street Finance, is supposed to be redeemable 1:1 with Circle's USDC stablecoin. It's used as part of a yield strategy that is marketed as "democratizing the options box spread strategy through a stablecoin". Prior to the depeg, there was about $80 million msUSD in circulation.

On June 20, the verification provider Accountable announced that they had "terminated its service agreement with MainStreet, effective immediately. MainStreet was unable to meet our verification standards." The sudden loss of confidence in the token caused the price to plummet as holders rushed to withdraw funds.

Main Street issued a statement, claiming that "Mainstreet remains fully backed" and that "this is an infrastructure and reporting issue, not a solvency issue." However, they noted that "while our portfolio remains fully backed, converting positions into immediate liquidity depends on prevailing market depth and market-maker appetite."

Aztec Connect hacked for a second time in less than a week

Three days after Aztec Labs' deprecated Aztec Connect blockchain bridge was exploited for $2.1 million, the project has been hacked again for the same amount. Aztec Labs confirmed the second exploit, again trying to emphasize that the code was deprecated four years ago.

The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.

Pudgy Penguins shuts down Pudgy Party NFT game after losing millions in less than ten months

A penguin with a nameplate reading "Pengu" stands facing the viewer in a snowy battle royale environment. A snowman behind holds a sign reading "JUMP" and another sign reads "Might as well JUMP"Pudgy Party screenshot (attribution)
The Pudgy Penguins NFT brand announced it would be shutting down its Pudgy Party NFT games less than ten months after its launch. The game was a mobile battle royale game, but built on crypto rails, with NFTs used for in-game items and characters that players could buy and sell. Pudgy Penguins seemed aware that the crypto aspect would be off-putting to many players, telling Decrypt in December 2025 that they were downplaying the crypto side of things "because the world is not ready for NFTs or crypto, or even blockchain en masse yet. But soon, very, very soon, we're going to use Pudgy Party as the glue between Web3 and Web2."

Although Pudgy Penguins CEO Lucas Netz boasted on Twitter in December about "1M+ downloads today. 10M+ downloads soon." he later admitted interest in the game had quickly died off. In a community call to announce the game's shutdown, Netz acknowledged that within months of the launch, there were only 200–300 active players. The project had lost the company millions of dollars, he confessed.

Deprecated project Aztec Connect exploited for $2.1 million

Aztec Connect, an abandoned defi privacy bridge from Aztec Labs, was drained of $2.1 million after an attacker exploited a bug in the project's smart contracts. Although the project was deprecated three years ago, funds remained in the legacy system. "Aztec Labs holds no admin keys or control over the system; it cannot be paused or upgraded by us," the project posted on social media.

The theft is only the latest in a string of attacks targeting vulnerable legacy smart contracts, many of which cannot be deleted, paused, or changed due to blockchains' immutable nature. Raydium and DxSale are two other platforms that have recently suffered losses due to old, insecure code.

Secret bridge exploited for $4.67 million a week before anyone notices

The bridge between the Cosmos-based Secret network and Axelar network was exploited via an infinite mint bug that went unnoticed for a week. An attacker exploited a smart contract in order to mint a large quantity of wrapped Axelar tokens on the Secret network, which they then redeeemed for around $4.67 million.

The exploit, which occurred on June 10, went unnoticed until June 17, when a transaction failed with a message suggesting that more tokens had been bridged out of the Secret network than had been bridged in.

Secret has warned, "If you hold Axelar-bridged saXXX tokens on Secret, please be aware their backing was affected and your funds may be lost."

Raydium users lose $1.34 million after legacy smart contract exploited

An attacker exploited a legacy smart contract that had been used by the Raydium Solana DEX before it was deprecated in 2021. Though the contract was unused, there were still funds in the liquidity pools affected by the vulnerable contract. Using fake LP tokens, the exploiter was able to trick an old smart contract with insufficient validation into allowing them to withdraw assets.

Raydium has said it will compensate users who lost funds in the exploit.

Humanity Protocol loses $36 million to employee laptop compromise

Humanity Protocol, a decentralized identity project that uses palm scans to try to prove that users are human, has suffered a $36 million loss after attackers compromised a laptop belonging to an employee. After the laptop was infected with malware, the malicious code gained root access, then stole seven private keys that were reportedly accidentally stored in a backup. Several of the keys were sufficient to satisfy multisignature requirements, which are intended to prevent private key leaks from allowing attackers to gain control over sensitive infrastructure like bridges. With multisignature wallets, keys are supposed to be stored separately across multiple individuals and devices; however, in this case, attackers only needed to compromise one laptop to gain control over multisig-protected contracts.

With the keys, the attacker stole more than 6 million of Humanity's H token, then used other keys to upgrade a bridge and drain 141 million more tokens. With the bridge access, they also minted 300 million new H tokens. The attacker then quickly swapped the ill-gotten tokens for ETH, causing the H price to plummet by 80–90%.

Humanity Protocol markets itself as a competitor to Sam Altman's World (formerly Worldcoin), a decentralized identity project that aims to use iris scans to prove that users are unique humans. Humanity raised $20 million in 2025 from Pantera Capital and Jump Crypto.

Thief steals remaining 7,200 unsold The Kiss NFTs in digital museum heist

A grid of pixels representing each of the 10,000 NFTs forming Klimt's The Kiss. About 75% of them, representing unsold NFTs, are missing.Missing pixels on the museum's map of The Kiss represent unsold, now stolen, NFTs (attribution)
Remember when Austria's otherwise respectable Belvedere Museum sold 10,000 NFTs representing postage-stamp sized sections of Gustav Klimt's The Kiss for like $2,000 a pop? No? Don't worry, I've got you.

Only about a quarter of them ever sold, leaving about 7,200 of them on the digital shelves. That is, until they were stolen (or, as the museum put it, "transferred from the wallet without authorization"). If valued at their sale price the stolen NFTs would be worth €13.32 million (US$15.3 million), though it's hard to argue the thief could've ever sold them for that amount given the museum had failed to do so for several years.

The stolen NFTs were soon made even less appealing to prospective buyers when the museum un-linked the image files from the digital assets, and OpenSea blocked them from trading.

Gravity Bridge drained of $5.4 million

Gravity Bridge, a bridge between the Cosmos and Ethereum blockchains, suffered $5.4 million in losses likely due compromised private keys. The developers of the protocol urged validators to halt while the theft was investigated, and the bridge was indeed halted shortly after. Two weeks after the hack, the Gravity Bridge interface remained unavailable.

DxSale exploited for $7.3 million

DxSale, a project that was popular in 2021 for launching new tokens and creating liquidity pools, suffered a $7.3 million exploit after ownership of a locker contract was transferred to a new address. Nine months later, the contract ownership was repeatedly moved between many new wallets — likely in an attempt to cover tracks — before $7.3 million was taken from old liquidity pools. The stolen assets were then swapped to BNB and routed through bridges and mixers to obscure the trail.

SquidRouterModule, unrelated to Squid Router, exploited for $3.2 million

A third-party Gnosis Safe smart contract called SquidRouterModule was exploited for $3.2 million. The smart contract included a set string that could be passed to identify a "safe" message; however, the string was visible in the public smart contract code and used by an attacker to impersonate Gnosis Safe users and then drain their wallets. 86 wallets had used the module, and lost a combined $3.2 million.

The name led to some confusion due to the similarly named Squid Router, which is not related. It's not clear if the users who installed the module were aware that the two projects were separate.

Polymarket loses $700,000 to private key compromise

Crypto sleuth zachxbt identified that "A Polymarket admin address appears to have been compromised on Polygon", writing that $520,000 had been drained as of the time of his post. The theft ultimately amounted to around $700,000, and Polymarket confirmed that a "wallet used for internal top-up operations" had been compromised. They did not provide further details as to how the compromise happened, though the company's VP of Engineering later said that the private key was six years old and that all private keys would be replaced with a managed key going forward.