Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.
Coinsbuy exploited for $8 milllion
Step App "move-to-earn" project shuts down
Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.
Proof of Attendance Protocol (POAP) shuts down
The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.
Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."
Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
Two arrested after Flare Network staking site scammed users out of 3.4 million XRP (~$8.5 million)
Two men were arrested on fraud charges, and Korean police are seeking a third. They reportedly advertised the scam project via YouTube and online articles.
- "12.3 Billion Won Crypto Scam Group Arrested", The Chosun
Triple-A hacked for $11.8 million
Triple-A did not say how much was taken or how the wallets were compromised, and said the impact was limited to "specific operational accounts" and able to be covered by treasury reserves. Blockchain analyst Specter estimated the loss at $11.8 million, stolen across the bitcoin and Tron networks.
Poolin bitcoin mining pool operator files for bankruptcy
The largest liability by far is the $163.7 million owed to roughly 11,700 people who had money in Poolin Wallet when the company froze withdrawals in September 2022, citing "some liquidity issues" during that year's crash. Instead of returning their bitcoin, Poolin handed them IOU tokens, which it never redeemed.
Poolin was founded in Beijing in 2017 and in better days accounted for almost a fifth of the bitcoin network's hashrate.
- Chapter 11 voluntary petition filed by Poolin Technology
- "Poolin, Once One of Bitcoin's Biggest Mining Pools, Files for Bankruptcy", Decrypt [archive]
42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft
The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.
Wanchain bridge on Cardano exploited for more than $9 million
Allbridge exploited for $1.66 million
Across Protocol exploited for $3.35 million
MVMT Labs files for bankruptcy
Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.
The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.
- Chapter 11 Voluntary Petition filed by MVMT Labs
- "Movement Labs files for Chapter 11 bankruptcy months after token scandal", CoinDesk
Ostium loses at least $24 million to oracle exploit
The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.
Bonzo Lend exploited for $9 million in oracle attack
Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.












![A circle overlaid with ][ symbols, followed by "Ostium" in orange capitals](https://primary-cdn.web3isgoinggreat.com/entryImages/logos/resized/ostium_300.webp)
