Skip to main content
Sign in

Avoid your next
big mistake

Crowdsourced due diligence for crypto

Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis

Browse investigationsSubmit evidenceHow it works

Featured Investigations

197·
sort:
avoid.net/zetachain62/100[CAUTIONARY]

ZetaChain is a Layer-1 blockchain founded in 2021 that enables omnichain smart contracts and native cross-chain interoperability across Bitcoin, Ethereum, and other networks without bridges. The protocol launched its mainnet beta in January 2024, raised $27 million in a Series A in August 2023, and achieved EU MiCAR compliance and DFSA recognition. In April 2026, it suffered a $333,868 exploit of its GatewayEVM smart contract targeting internal team wallets; no user funds were lost, though the team acknowledged it had previously overlooked a bug bounty report flagging the same vulnerability.

avoid.net/dutch-crypto-investment-fraud-ring-20260/100[CRITICAL]

A large-scale international investment fraud network, dismantled by Dutch and Belgian police in July 2026, operated approximately 20 call centers staffed by over 700 people who posed as financial advisers and used fake cryptocurrency trading platforms to steal an estimated €100 million per month from victims worldwide. The alleged mastermind — Ehud Tenenbaum, a 46-year-old dual Israeli-Polish national known in cybercrime circles as 'The Analyzer' for his late-1990s hacking of U.S. government systems — was arrested in Poland in May 2026 and extradited to the Netherlands. Tens of thousands of victims across multiple countries are estimated, with Dutch victims alone reporting nearly €25 million in losses.

avoid.net/fluid-instadapp52/100[CAUTIONARY]

Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.

avoid.net/bonk-fun52/100[CAUTIONARY]

BONK.fun (also marketed as LetsBONK.fun) is a no-code meme coin launchpad on the Solana blockchain, launched in April 2025 as a joint initiative between the BONK community and Raydium protocol. The platform rapidly captured majority market share from Pump.fun by mid-2025 before losing significant ground later that year, and suffered a domain-level security breach in March 2026 caused by a social engineering attack on its domain service provider — an incident attributed to the third-party infrastructure provider, not the platform's own code or contracts. The platform is operationally linked to Bonk, Inc. (Nasdaq: BNKK), a publicly traded company that holds a revenue sharing interest in the platform.

avoid.net/sturdy-v162/100[CAUTIONARY]

Sturdy Finance V1 was a DeFi lending protocol that allowed users to earn yield on deposits while borrowers accessed interest-free loans backed by staked collateral. On June 12, 2023, an attacker exploited a read-only reentrancy vulnerability in the protocol's price oracle integration — a third-party flaw originating in Balancer — and drained approximately 442 ETH (roughly $800,000). Sturdy V1 paused markets immediately, reopened its stablecoin market within days, and later formally sunset V1 in favor of Sturdy V2, which launched in early 2024 with a redesigned, modular architecture and three additional audits.

avoid.net/magpie-protocol62/100[CAUTIONARY]

Magpie Protocol is a cross-chain DEX aggregator and liquidity aggregation platform founded in Dubai in 2022, backed by Jump Crypto and others in a $3 million seed round. In April 2024 the protocol suffered a smart contract exploit in which approximately $129,000 was drained from 221 user wallets due to an unchecked calldata vulnerability; the team fully reimbursed all affected users within two weeks. The project subsequently rebranded to Fly in Q1 2025 and launched the FLY governance token on the Sonic blockchain in June 2025, reporting over $6.3 billion in cumulative trading volume and 260,000 unique on-chain users as of that date.

avoid.net/thetanuts-finance62/100[CAUTIONARY]

Thetanuts Finance is a multi-chain DeFi options protocol launched in August 2021, offering structured products (options vaults) across Ethereum, BNB Chain, Arbitrum, Polygon, and other networks. The protocol has raised $35 million across two funding rounds and has undergone seven smart-contract audits, but suffered a $2.1 million exploit in June 2026 targeting a deprecated legacy vault, with approximately $2 million subsequently recovered through whitehat efforts. TVL has declined substantially from a 2022 peak of roughly $50 million to under $1 million as of mid-2026.

avoid.net/triple-a-payments62/100[CAUTIONARY]

Triple-A (Triple-A Technologies Pte Ltd) is a Singapore-headquartered crypto payment gateway founded in 2017 by Eric Barbier, licensed by the Monetary Authority of Singapore as a Major Payment Institution and holding additional regulatory authorizations in the EU, US, and Canada. In July 2026, the company's own treasury hot wallets were drained of approximately $11.8 million across six blockchain networks in a security breach; Triple-A stated that customer funds were held separately in trust and were not affected. The incident raises operational security questions, but represents a suffered attack on company treasury rather than fraud perpetrated by the company.

avoid.net/manta-network52/100[CAUTIONARY]

Manta Network is a modular zero-knowledge blockchain platform consisting of Manta Pacific (an Ethereum L2) and Manta Atlantic (a Polkadot parachain being deprecated as of August 2026). The project launched its MANTA token in January 2024, an event marred by a large-scale DDoS attack on its RPC infrastructure and concurrent allegations — sourced from on-chain data and social media, not regulatory or court filings — that a Korean business development representative dumped 2 million ecosystem tokens at launch. No formal criminal charges or regulatory actions against Manta Network or its founders have been identified as of mid-2026.

avoid.net/peopledao48/100[WARNING]

PeopleDAO is a community-governed decentralized autonomous organization that emerged from ConstitutionDAO in late 2021, adopting the PEOPLE token as its governance instrument and operating as a meta-DAO incubator for social-good subDAOs. In March 2023, the organization suffered a significant treasury exploit in which an attacker stole 76.5 ETH (approximately $120,000) by exploiting a publicly shared Google Sheets payroll form with edit access — a failure of basic operational security controls. The stolen funds were moved to centralized exchanges and no recovery has been confirmed; the incident drew engagement from on-chain investigator ZachXBT and blockchain security firm SlowMist.

avoid.net/bit-com56/100[CAUTIONARY]

Bit.com was a cryptocurrency derivatives and spot exchange launched in August 2020 by Matrixport, a Singapore-based digital asset firm founded by Bitmain co-founder Jihan Wu. On December 27, 2025, the exchange announced a phased wind-down under the label 'business restructuring,' with spot trading ceasing January 31, 2026, a backup withdrawal-only station active through March 31, 2026, and post-deadline asset recovery requiring individual customer-service requests. No regulatory action, security breach, or insolvency has been publicly reported as the cause; the shutdown appears consistent with a broader strategic consolidation by Matrixport, which rebranded as 'BIT' on March 20, 2026.

avoid.net/thalaswap62/100[CAUTIONARY]

ThalaSwap is the decentralized exchange component of Thala Labs, an Aptos-based DeFi protocol offering an AMM, the Move Dollar (MOD) overcollateralized stablecoin, liquid staking, and a launchpad. On November 15, 2024, an input-validation bug introduced in a two-line patch to the v1 farming contract allowed an attacker to drain $25.5 million in liquidity pool tokens; funds were fully recovered within hours after SEAL 911 identified the exploiter via on-chain evidence and the attacker returned assets in exchange for a $300,000 bounty.

avoid.net/austrian-albanian-crypto-investment-fraud-ring-europol-april-20262/100[CRITICAL]

A criminal network operating out of Tirana, Albania, allegedly defrauded victims across Europe and worldwide of at least EUR 50 million through fake cryptocurrency investment platforms and follow-on fund-recovery scams. Austrian and Albanian authorities, supported by Europol and Eurojust, raided three call centers and nine residences on April 17, 2026, arresting ten suspects. No convictions have been recorded as of the investigation date; the arrests and seizures represent the law-enforcement action stage.

avoid.net/b-network-bsquared-bitcoin-layer-2-staking-contract-exploit30/100[WARNING]

On July 22, 2026, B² Network — a Bitcoin Layer-2 ZK rollup protocol — suffered a security incident in which an attacker allegedly exploited unauthorized access to the B2 token staking contract's upgrade authority and drained approximately 8.59 million B2 tokens valued at roughly $3.86 million. The stolen tokens were converted to BNB, bridged to Ethereum, and reportedly laundered through NEAR Intents and HOT Protocol toward Zcash. The team suspended staking, committed to full user compensation, and reportedly offered the attacker legal immunity in exchange for a partial refund. As of August 2026, no funds have been publicly confirmed as recovered.

avoid.net/crypto-whale-repeat-phishing-25-6m-drain-august-20260/100[CRITICAL]

On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in WBTC, cbBTC, aWBTC, DAI, ETH, LDO, USDS, and CRV to a phishing attack that induced the victim to authorize malicious token-approval transactions. The same wallet had previously lost $24.2 million in a nearly identical phishing scheme in September 2023, of which approximately 90% was returned; no funds from the 2026 attack had been recovered as of mid-August 2026. The combined gross exposure across both incidents is approximately $49.8 million, making this one of the most consequential repeat-targeting cases in Ethereum's history.

avoid.net/robinhood-chain-scam-ecosystem12/100[CRITICAL]

Robinhood Chain, an Arbitrum-based Ethereum Layer 2 launched by Robinhood Markets on July 1, 2026, experienced a rapid influx of fraudulent tokens within days of its permissionless mainnet going live, including honeypot contracts, vanishing-token scams, wallet-drainer schemes, and memecoin rug pulls. On July 23, 2026, the verified X account of Robinhood CEO Vlad Tenev was compromised and used to promote a fake memecoin called 'Vladhood' (VLAD), which generated approximately $22 million in trading volume before the post was removed. This page covers the scam ecosystem that emerged on Robinhood Chain and is distinct from Robinhood Markets, Inc. and its legitimate crypto brokerage operations.

avoid.net/bits-of-gold52/100[CAUTIONARY]

Bits of Gold is Israel's largest regulated cryptocurrency broker, founded in 2013 and licensed by the Israeli Capital Market, Insurance and Savings Authority since 2022. On August 16-17, 2026, the company disclosed that a third-party analytics vendor breach exposed personal data on approximately 200,000 customers — including national ID numbers, bank account details, and public wallet addresses — stemming from CVE-2026-72898, an actively exploited zero-day in self-hosted Metabase software. Customer crypto funds and private keys were not compromised, and the company has engaged a cybersecurity incident-response firm while notifying Israeli regulators.

avoid.net/zapper52/100[CAUTIONARY]

Zapper was a DeFi portfolio tracking and interaction platform founded in 2019 that reached 2 million monthly active users and raised approximately $16.5 million from investors including Mark Cuban and Framework Ventures. The platform announced it would permanently shut down all services on August 3, 2026, following a sustained decline in market demand and a damaging April 2025 domain hijacking incident in which attackers socially engineered Zapper's domain registrar to redirect users to a phishing page. The shutdown creates immediate user-protection concerns: lingering wallet permissions granted to Zapper's contracts should be revoked, and the closure creates conditions favorable for scammers to launch fake 'Zapper migration' or 'fund recovery' phishing campaigns targeting former users.

avoid.net/triple-a-treasury-hack-july-202628/100[WARNING]

Triple-A, a Singapore-based crypto payment platform holding a Major Payment Institution license from the Monetary Authority of Singapore (MAS), suffered an unauthorized access event beginning approximately July 24, 2026, in which approximately $11.8 million in company treasury assets was drained across seven blockchain networks over roughly 31 hours. The attacker consolidated stolen funds as approximately 5,287 ETH at a single Ethereum address. Triple-A stated that client funds were entirely segregated and unaffected, and that the company remained solvent and able to meet all liabilities.

avoid.net/letsbonk-fun32/100[WARNING]

LetsBonk.fun, later rebranded as Bonk.fun, is a Solana-based memecoin launchpad launched on April 25, 2025 by the BONK community in partnership with Raydium Protocol. The platform rose to capture over 78% of Solana launchpad market share at its mid-2025 peak before experiencing steep decline, and suffered a domain hijack and wallet-drainer attack in March 2026. The platform's permissionless token creation model, built-in multi-wallet bundler tooling, and community reports alleging the platform hosted 'KOL-backed bundled scams' present elevated risk for retail investors.

avoid.net/solana-blinks-durable-nonce-drainer-kits-20260/100[CRITICAL]

A family of increasingly sophisticated wallet-drainer toolkits targeting the Solana ecosystem that weaponize legitimate Solana protocol features — Blinks (blockchain action links), durable nonces, and the system 'assign' instruction — to bypass the transaction-simulation safety layer that most Solana wallets rely on as their primary defense. Documented in detail by security researchers from February 2024 onward and materially escalated in late 2025 and early 2026, these kits are distributed as scam-as-a-service products supporting 90+ wallet types; losses attributable to Solana phishing reached approximately $90 million in H1 2025 alone, before the simulation-bypass generation was widely deployed. A state-level durable-nonce attack on Drift Protocol (April 2026) demonstrated that the same primitive can scale to $285 million in a single operation.

avoid.net/orca80/100[VERIFIED]

Orca is a concentrated-liquidity automated market maker (AMM) and decentralized exchange built on the Solana blockchain, launched in February 2021 by co-founders Grace "Ori" Kwan and Yutaro Mori. Its core product, Whirlpools, is an open-source CLMM protocol with six independent security audits, a verifiable on-chain build, and no confirmed exploits since inception. The protocol operates via a DAO governed by the ORCA token and has expanded to Eclipse mainnet; the primary documented risk factors are residual upgrade-authority centralization, the legacy Three Arrows Capital investor relationship (now defunct), and a 2023 decision to geo-block U.S. users from the web interface without a public regulatory explanation.

avoid.net/blockfi38/100[WARNING]

BlockFi was a cryptocurrency lending platform founded in 2017 by Zac Prince and Flori Marquez, once valued at $3 billion. The company faced a $100 million SEC and state regulator settlement in February 2022 for offering unregistered securities, then collapsed in November 2022 following the implosion of FTX, which had extended BlockFi a $400 million credit facility. After filing Chapter 11 bankruptcy, BlockFi achieved a notable outcome: all creditors received 100% recovery of allowed claims, funded largely by a $874.5 million settlement with FTX/Alameda Research.

avoid.net/three-arrows-capital2/100[CRITICAL]

Three Arrows Capital (3AC) was a Singapore-based cryptocurrency hedge fund founded in 2012 by Su Zhu and Kyle Davies that, at its peak in early 2022, managed an estimated $10 billion in assets. Severe losses from the Terra/LUNA ecosystem collapse in May 2022 triggered cascading margin calls and a liquidity crisis that led to court-ordered liquidation in the British Virgin Islands on June 27, 2022, leaving more than $3.5 billion in creditor claims. The founders subsequently faced arrest warrants, prison sentences for non-cooperation with liquidators, a nine-year regulatory ban by Singapore's Monetary Authority, and fines from Dubai's virtual asset regulator over a failed post-collapse exchange venture.

avoid.net/dodo-amm62/100[CAUTIONARY]

DODO is a decentralized exchange (DEX) and on-chain liquidity protocol launched in August 2020, built around a proprietary Proactive Market Maker (PMM) algorithm that sources external oracle prices to concentrate liquidity and reduce slippage. On March 8, 2021, attackers exploited a reinitialization vulnerability in the V2 Crowdpool smart contracts, draining approximately $3.8 million from four pools; roughly $3.1 million was subsequently returned by white-hat and front-running bots, with an estimated $700,000 remaining unrecovered from the original attacker. No regulatory actions by the SEC, CFTC, or other agencies have been reported against the project or its founders as of August 2026.

avoid.net/woofi58/100[CAUTIONARY]

WooFi (WOOFi Swap) is the decentralized exchange component of WOO Network, a crypto liquidity ecosystem incubated by Kronos Research and launched in 2019. On March 5, 2024, WooFi's synthetic proactive market making (sPMM) algorithm on Arbitrum was exploited via flash loan oracle manipulation, resulting in approximately $8.75 million in losses — one of the largest DeFi exploits of early 2024. The team responded by pausing contracts within 13 minutes, commissioning post-exploit audits by Sherlock and Zellic, and pledging to redeploy after fixes; funds were never recovered.

avoid.net/bond-protocol58/100[CAUTIONARY]

Bond Protocol is a permissionless bonds-as-a-service platform for DeFi, spun out of OlympusDAO's Olympus Pro product via a governance vote in mid-2022. In October 2022 — just weeks after its public launch — the protocol's Fixed-Expiry Teller smart contract was exploited for approximately $300,000 in OHM tokens due to a missing input validation vulnerability that had evaded three prior independent audits. The attacker ultimately returned all funds, the team underwent re-auditing with Zellic and Sherlock, and the protocol raised $2.5M in seed funding, though its TVL has since declined to minimal levels.

avoid.net/dexodus-finance55/100[CAUTIONARY]

Dexodus Finance is an oracle-based perpetual derivatives DEX operating on Coinbase's Base L2 network, founded in 2023 and headquartered in Barcelona, Spain. On May 26, 2025, the protocol suffered a signature replay attack that drained approximately $291,000–$300,000 from its liquidity pool due to the absence of nonce tracking and timestamp validation in its Chainlink oracle price-report verification logic. The team claims to have achieved 100% fund recovery within 24 hours, deprecated Perps V1, and launched a redesigned Perps V2 system; however, the protocol's current TVL remains modest at approximately $1.28M and independent verification of the full recovery narrative is limited.

avoid.net/lcx62/100[CAUTIONARY]

LCX (Liechtenstein Cryptoassets Exchange) is a regulated crypto exchange and tokenization platform headquartered in Vaduz, Liechtenstein, holding eight registrations under the Liechtenstein Financial Market Authority (FMA) pursuant to the Token and Trusted Technology Service Provider Act (TVTG). In January 2022 the exchange suffered a hot wallet compromise in which approximately $7.94 million in crypto assets were stolen, with stolen funds rapidly laundered through Tornado Cash; LCX subsequently used its own funds to compensate affected users and cooperated with international law enforcement to freeze an alleged 60% of stolen assets. The exchange is flagged by ZachXBT and carries a below-average trust score primarily due to the 2022 hack, ongoing user complaints about withdrawal delays and account freezes, and the broader security posture concerns that led to the compromise.

avoid.net/dtrinity-dlend56/100[CAUTIONARY]

dTRINITY is a DeFi protocol self-described as the world's first subsidized stablecoin system, with dLEND serving as its Aave v3-forked lending market deployed across Fraxtal, Ethereum, and Katana. On March 17, 2026, the dLEND Ethereum deployment was exploited via an empty-market liquidityIndex inflation attack, resulting in approximately $257,000 in bad debt drained from the dUSD lending pool. The protocol paused operations and pledged to cover losses with internal funds, though the incident raised questions about audit coverage and the adequacy of pre-deployment testing on the Ethereum instance.

avoid.net/dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign0/100[CRITICAL]

In April 2026, North Korea-linked threat actors attributed to the Lazarus Group and its subunits executed two separate, high-value cryptocurrency exploits within 18 days — draining approximately $285 million from Drift Protocol on April 1 and approximately $292 million from KelpDAO on April 18. Combined, the two attacks account for an estimated $577–635 million in losses, comprising 76% of all documented cryptocurrency hack value through April 2026 and representing the largest coordinated DPRK crypto theft campaign on record.

avoid.net/lcx-exchange52/100[CAUTIONARY]

LCX Exchange (Liechtenstein Cryptoassets Exchange) is a regulated crypto trading platform incorporated in Liechtenstein and registered with the country's Financial Market Authority (FMA). On January 8, 2022, the exchange suffered a hot wallet compromise resulting in the theft of approximately $6.8–7.94 million in various cryptocurrencies; LCX subsequently covered all user losses from company funds and cooperated with multi-jurisdictional law enforcement, ultimately freezing approximately 60% of stolen assets. As of 2024–2025, LCX remains operational, holds multiple licenses under the Liechtenstein Blockchain Act (TVTG), and has filed a pre-application for a pan-European MiCA license.

avoid.net/atomic-wallet-hack10/100[CRITICAL]

In June 2023, Atomic Wallet — an Estonian non-custodial cryptocurrency wallet with approximately five million users — suffered a major security breach in which attackers drained funds from an estimated 5,500 user wallets. Blockchain analytics firms Elliptic and on-chain investigators attributed the attack to North Korea's Lazarus Group with high confidence, and the FBI later confirmed this attribution. The total loss figure is disputed, with Elliptic placing it above $100 million and independent researcher Taylor Monahan estimating a minimum of $115 million; the underlying attack vector was never publicly confirmed by Atomic Wallet.

avoid.net/playdapp22/100[CRITICAL]

PlayDapp is a South Korean blockchain gaming platform and NFT marketplace founded in 2017 and operating on Ethereum and Polygon. In February 2024, an attacker who had obtained PlayDapp's contract deployer private key via a phishing email added themselves as an authorized minter and minted 1.79 billion PLA tokens across two events, representing a nominal loss of approximately $290 million. The platform subsequently suspended the PLA smart contract and executed a 1:1 migration to a new token (PDA) to remediate the illegitimate token supply.

avoid.net/trifleck2/100[CRITICAL]

Trifleck is a shell company with no verifiable business registration used as a front in an active LinkedIn-based malware campaign targeting crypto and Web3 developers, first publicly disclosed in May 2026. The campaign delivers a malicious 'pre-interview code review' ZIP file containing infostealers after recruiters posing as Trifleck employees contact developers with frontend job offers. The attack pattern, infrastructure, and malware families are consistent with tactics attributed by Microsoft, Mandiant, Palo Alto Unit 42, and the FBI to DPRK-aligned threat actors operating under the cluster known as Contagious Interview.

avoid.net/sweat-economy-sweat-protocol58/100[CAUTIONARY]

Sweat Economy is a move-to-earn protocol on NEAR Protocol that rewards users with SWEAT tokens for physical activity, built on top of the Sweatcoin app which has over 120 million registered users. On April 29, 2026, the SWEAT token contract on NEAR was exploited via a Rust smart contract vulnerability, allowing an attacker to drain approximately 13.71 billion SWEAT tokens — roughly 65% of total supply — valued at approximately $3.5 million, within 30 seconds. The Sweat Foundation coordinated with MEXC exchange and Rhea Finance to freeze attacker funds and ultimately restored all external user balances, with a patched contract subsequently deployed.

avoid.net/clober-liquidity-vault58/100[CAUTIONARY]

Clober is a fully on-chain order book DEX (Decentralized Exchange) for EVM networks, built on the proprietary LOBSTER algorithm, which launched on February 14, 2023. Its Liquidity Vault product, a hybrid order-book/AMM product launched on Coinbase's Base network in December 2024, was exploited for approximately 133.7 ETH (~$501,000) within days of launch due to a reentrancy vulnerability introduced in post-audit code changes. The attacker ultimately moved the stolen funds through Tornado Cash after on-chain bounty negotiations failed.

avoid.net/unibot58/100[CAUTIONARY]

Unibot is a Telegram-based trading bot launched in May 2023 that enabled users to execute Uniswap trades directly within Telegram. On October 31, 2023, a newly deployed router contract containing a call injection vulnerability was exploited, draining approximately $560,000–$640,000 in user funds that were subsequently laundered through Tornado Cash; the team ultimately reimbursed affected users at a reported cost of $1.78 million. A second crisis followed in March 2024 when the Ethereum and Solana development teams publicly split amid mutual accusations of unauthorized deployments and revenue misappropriation, causing the token to shed an additional 40% of its value and reducing the project to a fraction of its former user base.

avoid.net/astroport55/100[CAUTIONARY]

Astroport is an automated market maker (AMM) DEX originally launched on the Terra blockchain in December 2021, developed by a joint venture of Delphi Labs, Terraform Labs, We3, and Attic Lab. The protocol suffered catastrophic TVL loss during the May 2022 Terra/Luna ecosystem collapse and was subsequently rebuilt as a multi-chain AMM spanning Neutron, Sei, Injective, and Terra 2.0. In July 2024, Astroport was directly exploited via a reentrancy vulnerability in IBC hooks on the Terra chain, resulting in approximately $6.4 million in losses.

avoid.net/leap-wallet62/100[CAUTIONARY]

Leap Wallet was a non-custodial multi-chain crypto wallet founded in 2021 and backed by $3.2 million from Pantera Capital and CoinFund. Originally built for the Terra ecosystem, it pivoted to Cosmos after Terra's 2022 collapse and grew to support 100+ chains. On April 3, 2026, the team announced permanent cessation of all products effective May 28, 2026, without disclosing a specific reason, creating an eight-week compressed migration window that raised user security concerns.

avoid.net/edward-zimbardi-the-crypto-program2/100[CRITICAL]

Edward Zimbardi, 59, of Flowery Branch, Georgia, is accused of operating 'The Crypto Program,' an alleged cryptocurrency Ponzi scheme that prosecutors allege collected more than $165 million from at least 6,000 investors worldwide between June 2022 and August 2023 by promising guaranteed 25% monthly returns on fake advertising packages. Zimbardi was indicted on 25 federal counts on July 8, 2026, by a grand jury in the Northern District of Georgia, deported from Fiji on August 14, 2026, and appeared before a federal magistrate in Los Angeles on August 17, 2026. All charges are allegations; no conviction has been entered.

avoid.net/changenow42/100[WARNING]

ChangeNOW is a non-custodial, KYC-optional instant cryptocurrency swap service founded in 2017 and operated by CHN Group LLC, incorporated in Saint Vincent and the Grenadines. The platform supports swaps across more than 1,000 crypto assets without mandatory account registration, a design that has made it a recurrent node in post-exploit fund flows. In 2026 alone, stolen funds from two confirmed major hacks — the Gravity Bridge $5.4 million exploit (May 2026) and the Coinsbuy $7.9 million theft (August 2026) — were reportedly routed through ChangeNOW, though no regulatory enforcement action has been taken against the company as of August 2026.

avoid.net/bitmart-exchange-insolvency-claims-and-frozen-withdrawals-august-202612/100[CRITICAL]

BitMart, a cryptocurrency exchange operating since 2017, announced an orderly wind-down on July 26, 2026, with all trading to cease by August 26, 2026, and full platform closure by January 31, 2027. Following the announcement, multiple users and at least one market-making firm reported being unable to withdraw assets, on-chain data recorded anomalously low withdrawal activity, and an open letter signed by users and employees gave founder Sheldon Xia until August 19 to disclose financial reserves and a repayment plan. Insolvency has been alleged but not independently confirmed; no regulatory body has filed charges or made a formal finding as of August 17, 2026.

avoid.net/shuffle-shuffle-com38/100[WARNING]

Shuffle (shuffle.com) is a crypto casino and sportsbook launched in February 2023, operated by Natural Nine B.V. under a Curacao Gaming Control Board license, and founded by Noah Dummett alongside co-founders Darcy Spangler and Harley Fresh. In October 2025, Shuffle confirmed a major data breach through third-party CRM provider Fast Track that exposed personal data and KYC documents for the majority of its users. In August 2026, blockchain investigator ZachXBT alleged that stolen victim funds were wagered on Shuffle in real time while the alleged thief was on the phone with the victim; Shuffle confirmed it would lock the associated account after reviewing submitted evidence.

avoid.net/doj-pig-butchering-civil-forfeiture-dc-district-july-202610/100[CRITICAL]

On July 21, 2026, the U.S. Attorney's Office for the District of Columbia and the U.S. Secret Service Washington Field Office filed five civil forfeiture complaints in federal court seeking to recover more than $25 million in USDT traced to pig butchering fraud schemes operated from Southeast Asia. The filings, which proceed against the cryptocurrency assets themselves and name no individual defendants, targeted funds linked to romance scams, approval phishing, and fake investment platforms that defrauded more than 470 identified victims across the United States and Canada. The action is part of the broader DC Scam Center Strike Force, launched in November 2025, which had restrained or seized more than $832 million in cryptocurrency from Chinese transnational criminal organizations by June 2026.

avoid.net/christopher-delgado-goliath-ventures-inc2/100[CRITICAL]

Christopher Alexander Delgado (age 34, Apopka, Florida) was the President and CEO of Goliath Ventures Inc. (formerly Gen-Z Venture Firm), a Florida-based cryptocurrency investment firm that operated as a Ponzi scheme from at least January 2023 through January 2026. Delgado pleaded guilty on June 30, 2026, in the U.S. District Court for the Middle District of Florida to conspiracy to commit wire fraud, wire fraud, and money laundering in connection with a scheme that raised at least $397 million (per CFTC) to $425 million (per SEC) from over 1,300 to 1,611 investors. On August 11, 2026, both the CFTC and SEC filed separate civil enforcement actions against Delgado and Goliath Ventures; Goliath Ventures ceased operations in February 2026 and filed for bankruptcy in March 2026.

avoid.net/indonesia-pig-butchering-syndicate-live-model-operation-2025-20262/100[CRITICAL]

An international online fraud syndicate operating out of Sukoharjo and Surakarta in Central Java, Indonesia from approximately July 2025 to May 2026, allegedly defrauding at least 133 U.S. victims of approximately US$2.33 million through romance manipulation and fake cryptocurrency investment platforms, a scheme known as 'pig butchering.' Indonesian police arrested 39 suspects in May 2026 and have engaged the FBI given the predominance of American victims. Charges are pending; no convictions have been entered as of the date of this investigation.

avoid.net/crypto-com-phishing-campaign-email-domain-abuse-august-20263/100[CRITICAL]

An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.

avoid.net/france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-20268/100[CRITICAL]

In late June 2026, an unauthorized intrusion into France's General Directorate of Public Finances (DGFiP) exposed the personal and financial data of an estimated 678,437 taxpayers, including names, addresses, income figures, withholding rates, and tax identifiers. The breach was publicly claimed on August 12, 2026 by a threat actor using the pseudonym ZeroBytes, and confirmed by French authorities on August 14, 2026. The incident directly amplifies an established pattern of violent physical coercion — so-called wrench attacks — against crypto holders in France, which CertiK and Chainalysis both identified as the global epicenter of such attacks in H1 2026.

avoid.net/vanta-stealer-python-infostealer-targeting-crypto-wallets2/100[CRITICAL]

Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.

avoid.net/star-credit-holdings-misam-m-abidi2/100[CRITICAL]

Star Credit Holdings was a Tennessee-based cryptocurrency investment firm operated by Misam M. Abidi (age 47, of Nolensville, Tennessee) from approximately 2020 to 2024. On June 12, 2026, a federal grand jury in the Western District of Tennessee returned an 11-count indictment against Abidi, alleging he ran a classic Ponzi scheme that diverted over $1.9 million in investor funds to himself and family members. Abidi had previously faced state-level regulatory action in May 2024 over a broader alleged fraud involving Star Credit Holdings, a related cryptocurrency token (NUME/NumisMe), and co-defendants Ali Raza Galani and Anisha Abidi, with total alleged investor losses across 17 states exceeding $6.3 million.

avoid.net/misam-m-abidi2/100[CRITICAL]

Misam M. Abidi, 47, of Nolensville, Tennessee, is an independent candidate for Tennessee Governor who was indicted on June 12, 2026 by a federal grand jury in the Western District of Tennessee on 11 counts including wire fraud, money laundering, unlicensed money transmission, and aiding in false tax return preparation. Federal prosecutors allege Abidi operated Star Credit Holdings as a cryptocurrency Ponzi scheme between 2020 and 2024, diverting over $1.9 million of investor funds to himself and family members. Abidi and his associates also face a separate 2024 Tennessee state civil enforcement action involving an alleged $6.3 million fraud spanning 17 states, connected to the STAR Investment Club and the NUME cryptocurrency token issued through NumisMe LLC.

avoid.net/allo-protocol68/100[CAUTIONARY]

Allo Protocol is an open-source, EVM-compatible smart contract framework for on-chain capital allocation, developed by Gitcoin and launched on Ethereum mainnet in November 2023. It served as the underlying infrastructure for Gitcoin Grants Stack from 2023 through May 2025, when Gitcoin's software division (Grants Lab) was shut down due to financial constraints, placing Allo in maintenance mode. No fraud allegations, regulatory actions, or security exploits have been publicly documented against the protocol itself.

avoid.net/ramzinex2/100[CRITICAL]

Ramzinex (formally Ramzineh Electronic Commerce Innovation Company) is a Tehran-based cryptocurrency exchange founded in 2018 that served over one million Iranian users across more than 200 trading pairs. On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control designated Ramzinex on its Specially Designated Nationals list under Executive Order 13902 and Iran-related sanctions authorities, alleging the exchange processed transactions linked to the Islamic Revolutionary Guard Corps and a government-backed Iranian financial institution. The designation carries secondary sanctions exposure, meaning non-U.S. financial institutions that conduct significant transactions with Ramzinex after June 2, 2026, risk correspondent account restrictions and further OFAC action.

avoid.net/allbridge-core-second-flash-loan-exploit-july-202620/100[CRITICAL]

On July 19–20, 2026, Allbridge Core, a cross-chain stablecoin bridge protocol, suffered a $1.65–1.66 million flash-loan exploit targeting its Solana USDC/USDT liquidity pools — the second structurally similar attack on the protocol since April 2023. An attacker borrowed $1.12 million USDC from Kamino Finance, manipulated the pool's internal stablecoin ratio through rapid swaps, extracted liquidity at distorted rates, then bridged the proceeds to Ethereum before the protocol was paused. The incident raised serious questions about the completeness of post-2023 remediation, specifically the failure to apply the protocol's own 'single-pool per blockchain' fix to its Solana deployment.

avoid.net/node-gyp-npm-supply-chain-compromise-june-20260/100[CRITICAL]

In June 2026, a self-propagating npm supply chain worm designated 'Miasma' exploited a novel install-time execution technique called 'Phantom Gyp' — abusing binding.gyp configuration files to trigger malicious code during npm install. The campaign spread across 57 packages and 286+ malicious versions, harvesting developer and CI/CD credentials from npm, GitHub, AWS, GCP, Azure, HashiCorp Vault, and Kubernetes, and then self-propagating by republishing poisoned releases using stolen publishing tokens. The attack poses a direct threat to crypto developers whose CI/CD pipelines manage private keys, wallet seed phrases, and signing infrastructure.

avoid.net/phantom-gyp-npm-supply-chain-attack-june-20260/100[CRITICAL]

On June 3, 2026, attackers deployed a self-replicating worm across 57 npm packages in 286 malicious versions within under two hours, using a novel technique dubbed 'Phantom Gyp' that abused binding.gyp build configuration files to execute malicious code during npm install while bypassing all mainstream lifecycle-script security scanners. The campaign — classified as the latest wave of the Miasma/Shai-Hulud worm family — targeted CI/CD credential stores across AWS, GCP, Azure, GitHub, Kubernetes, and developer password managers, and included novel persistence mechanisms that injected backdoors into AI coding assistant configurations. The highest-profile victim was @vapi-ai/server-sdk (408,000+ monthly downloads), though Vapi confirmed the four compromised versions received zero downloads before removal.

avoid.net/summer-finance-summer-fi28/100[WARNING]

Summer Finance, operating as Summer.fi, was a DeFi yield-optimization protocol that spun out of the Maker Foundation in 2021 and rebranded from Oasis.app in June 2023. On July 6, 2026, its Lazy Summer Protocol was exploited for approximately $6.04 million through a share-price manipulation attack that leveraged stale-valued tokens left over from the November 2025 collapse of Stream Finance. Following the exploit, the company announced it would cease operations, with the Summer.fi application shutting down on August 31, 2026, and governance of remaining vault infrastructure transitioning to the Lazy Summer DAO.

avoid.net/coinkite-coldcard18/100[CRITICAL]

Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.

avoid.net/oraichain-evm-cross-chain-unauthorized-minting-exploit-august-202628/100[WARNING]

On August 9, 2026, Oraichain — an AI-focused Layer 1 blockchain — suffered a supply-integrity exploit in which a vulnerability in its EVM cross-chain transfer path enabled the unauthorized minting of ORAI tokens. The team halted the entire network at 04:00 UTC, restricted all bridges and cross-chain routes, and coordinated with centralized exchanges including MEXC to freeze fund movements. As of mid-August 2026, the exploit path had been addressed, the network had been restored, and the team was preparing to burn the unauthorized minted balances to reconcile canonical ORAI supply.

avoid.net/crypto-whale-repeat-phishing-drain-august-202610/100[CRITICAL]

On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.

avoid.net/jewelbug-apt2/100[CRITICAL]

Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.

avoid.net/wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-20262/100[CRITICAL]

WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660), which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026. Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework. Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation, link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host), and report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor; the two campaigns share the npm supply-chain vector but have distinct infrastructure and attribution.

avoid.net/ravedao2/100[CRITICAL]

RaveDAO is a Web3 entertainment protocol that markets itself as a community bridging electronic dance music culture with blockchain-based ticketing, governance, and event access. Its native token, RAVE, launched on Binance Alpha in December 2025 and experienced a ~10,800% price surge in April 2026 before collapsing approximately 95% within 48 hours amid substantial on-chain evidence of insider supply control and an alleged coordinated 'bait and liquidate' short-squeeze scheme. Binance, Bitget, and Gate.io opened formal investigations; on-chain investigator ZachXBT publicly accused the project's affiliated insiders of engineering the rally and named RAVE as part of a broader pattern of Bitget-enabled market-maker fraud.

avoid.net/heisenberg-guru-hsbg4/100[CRITICAL]

Heisenberg Guru (HSBG) is a Hong Kong-based cryptocurrency market maker alleged by on-chain investigator ZachXBT to have orchestrated coordinated supply-control manipulation schemes across at least six tokens — RIVER, RAVE, SIREN, MYX, SKYAI, and LAB — primarily through Bitget, with Binance and Gate.io as secondary venues. On May 19, 2026, ZachXBT posted a $10,000 personal bounty for insider evidence identifying the firm's operators, naming 'Sion' and 'Chao' as core team members. As of May 31, 2026, HSBG has not publicly responded to the allegations, no regulatory action has been confirmed, and the bounty remains open.

avoid.net/rossen-iossifov-rg-coins2/100[CRITICAL]

Rossen G. Iossifov, a 53-year-old Bulgarian national, owned and operated RG Coins, a cryptocurrency exchange in Sofia, Bulgaria that served as the primary off-ramp for the Alexandria (Romania) Online Auction Fraud Network, laundering nearly $5 million in crypto proceeds defrauded from approximately 900 American victims. Convicted in 2020 and sentenced in January 2021 to 121 months in federal prison, Iossifov was charged again in July 2026 with allegedly conspiring from his prison cell to steal and launder $290,000 in cryptocurrency that had already been ordered forfeited to the United States government following his prior conviction.

avoid.net/probit-global23/100[CRITICAL]

ProBit Global was a South Korea-founded centralized cryptocurrency exchange that operated from 2018 until it permanently terminated all services by April 1, 2026. The shutdown followed an inability or unwillingness to obtain MiCA licensing for EU/EEA users and a stated broader regulatory and restructuring rationale for global operations. The wind-down included a controversial abandoned-funds clause under which assets not withdrawn by April 1, 2026 were deemed permanently lost, as well as a monthly administrative fee of up to 10% of balances during the grace period, raising significant consumer-protection concerns.

avoid.net/alephium34/100[WARNING]

Alephium is a Swiss-founded Proof-of-Work Layer-1 blockchain launched November 8, 2021, featuring sharded smart contracts and the Proof-of-Less-Work consensus mechanism. On May 29-30, 2026, its TokenBridge was exploited for approximately $815,000 in approximately seven minutes via an off-chain backend vulnerability that allowed forged guardian messages to authorize unauthorized transfers and the minting of 13.76 million unbacked wrapped ALPH tokens. The team took the bridge offline, burned the unauthorized tokens, and committed to full user compensation.

avoid.net/helium58/100[CAUTIONARY]

Helium is a decentralized physical infrastructure network (DePIN) founded in 2013 by Amir Haleem, Shawn Fanning, and Sean Carey, operated by Nova Labs, Inc. The network incentivizes individuals to deploy wireless hotspots for IoT (LoRaWAN) and mobile coverage using its HNT token, which migrated to the Solana blockchain in April 2023. The project has a documented history of misrepresenting partner relationships to investors, resulting in a $200,000 SEC civil settlement in April 2025, but has demonstrated meaningful real-world usage growth through verified carrier data-offload partnerships with AT&T, T-Mobile, and Telefonica.

avoid.net/eclipse32/100[WARNING]

Eclipse is a Layer 2 blockchain on Ethereum that uses the Solana Virtual Machine (SVM) for execution, Celestia for data availability, and Ethereum for settlement. Developed by Eclipse Labs and launched on mainnet in November 2024, the project has experienced significant turbulence including the removal of its founder over sexual misconduct allegations, a heavily criticized token airdrop, a 95% TVL collapse, and a 65% workforce reduction in August 2025. As of early 2026, the project publicly admitted it had 'no users' and pivoted to building consumer applications in-house.

avoid.net/george-santos-cftc-prediction-market-manipulation8/100[CRITICAL]

Former U.S. Congressman George Anthony Devolder Santos was found by the Commodity Futures Trading Commission to have manipulated event contracts on the prediction market platform Kalshi by trading on his own attendance at the 2026 State of the Union address while making misleading public statements on social media to move contract prices in his favor. On July 31, 2026, Santos settled the action — without admitting or denying the findings — agreeing to disgorge $17,569.98 in profits, pay a $17,500 civil monetary penalty, and accept a three-year ban from all CFTC-registered entities. The case is described by multiple outlets as the first federal sanction imposed for political prediction market manipulation, though it follows separate earlier CFTC enforcement activity targeting insider trading in event contracts.

avoid.net/axiom-dex-insider-trading-broox-bauer14/100[CRITICAL]

In February 2026, blockchain investigator ZachXBT published findings alleging that Broox Bauer, a senior business development employee at Axiom Exchange — a Solana-based trading platform backed by Y Combinator — exploited internal dashboard access controls to retrieve private user wallet data and coordinate front-running trades over approximately ten months. The alleged scheme involved compiling key opinion leader (KOL) wallet addresses into shared Google Sheets to position ahead of anticipated price moves, with alleged profits cited at over $400,000. Axiom stated it was shocked, revoked access, and pledged an internal investigation; no independent forensic audit or formal regulatory action had been publicly announced as of June 2026.

avoid.net/axiom-dex28/100[WARNING]

Axiom is a Solana-based crypto trading platform founded in 2024 by Henry Zhang ('Mist') and Preston Ellis ('Cal'), which completed Y Combinator's Winter 2025 batch and generated over $390 million in cumulative revenue. In February 2026, blockchain investigator ZachXBT published a documented investigation revealing that a senior business development employee, Broox Bauer, along with colleagues, systematically abused internal dashboard tools with insufficient access controls to access private user wallet data and conduct insider trading for over 10 months beginning in early 2025. Axiom confirmed the breach, removed access to the implicated tools, and pledged an internal investigation, but no formal legal charges had been publicly filed as of the date of reporting.

avoid.net/broox-bauer-axiom-insider-trading-ring6/100[CRITICAL]

Broox Bauer, a senior business development employee at Axiom Exchange, was publicly identified in February 2026 by on-chain investigator ZachXBT as the alleged orchestrator of an insider trading scheme running from early 2025. Bauer allegedly abused internal access to Axiom's customer support dashboard to extract private wallet data belonging to users and key opinion leaders, sharing that data with a small group to front-run trades. Axiom, a Y Combinator-backed Solana trading terminal that generated over $390 million in cumulative revenue, acknowledged the misconduct, terminated access to the relevant tools, and stated it would investigate and hold the responsible parties accountable.

avoid.net/axiom-trading38/100[WARNING]

Axiom Trading (axiom.trade) is a Y Combinator Winter 2025-backed Solana trading terminal that generated over $390 million in revenue since its January 2025 launch. In February 2026, blockchain investigator ZachXBT published a report alleging that senior business development employee Broox Bauer and associates systematically abused internal customer support tools to access private user wallet data and front-run customer trades for more than ten months, with alleged profits exceeding $400,000. Axiom removed access to the implicated tools and stated it was investigating, but no public disclosure of disciplinary or legal outcomes had been made as of June 2026.

avoid.net/gemini58/100[CAUTIONARY]

Gemini is a New York-based cryptocurrency exchange and custodian bank founded in 2015 by Cameron and Tyler Winklevoss, regulated under a NYDFS Limited Purpose Trust Charter. The exchange gained significant notoriety following the collapse of its Gemini Earn lending program in late 2022, which left approximately 340,000 users with roughly $900 million in frozen assets; subsequent SEC and NYDFS enforcement actions were resolved by early 2024 and 2026 respectively with full customer restitution. Gemini went public on the Nasdaq in September 2025 under the ticker GEMI, but its stock has since declined more than 80% amid deepening losses, executive departures, mass layoffs, and a contested post-IPO strategic pivot to prediction markets.

avoid.net/bitmex56/100[CAUTIONARY]

BitMEX (Bitcoin Mercantile Exchange) is a cryptocurrency derivatives exchange founded in 2014 by Arthur Hayes, Ben Delo, and Samuel Reed that pioneered the perpetual swap contract and at its peak was one of the largest crypto derivatives platforms in the world. In October 2020, the CFTC and DOJ charged the exchange and its co-founders with operating an unregistered trading platform and willfully failing to implement anti-money laundering and know-your-customer programs in violation of the Bank Secrecy Act. All three co-founders subsequently pleaded guilty, the exchange paid a $100 million civil settlement, and in March 2025 the founders and the corporate entity received presidential pardons from Donald Trump.

avoid.net/liquid-global10/100[CRITICAL]

Liquid Global (operating under its parent entity Quoine Pte. Ltd.) was a Japanese-headquartered cryptocurrency exchange founded in 2014 and rebranded from QUOINE to Liquid in 2018. In August 2021, the exchange suffered one of the largest exchange hacks of that year — approximately $97 million in Bitcoin, Ethereum, XRP, TRON, and other tokens stolen — with the attack subsequently attributed by Chainalysis to actors working on behalf of the DPRK, consistent with Lazarus Group tradecraft. FTX provided a $120 million emergency loan days after the breach, then acquired Liquid outright in April 2022; when FTX itself filed for Chapter 11 bankruptcy in November 2022, Liquid halted all withdrawals and customer funds were caught in the subsequent restructuring proceedings.

avoid.net/blockchain-capital68/100[CAUTIONARY]

BCAP is the world's first tokenized venture capital fund interest, issued in April 2017 as a Regulation D security token. It represents a non-voting economic interest in Blockchain Capital's Fund III. The firm manages $2B+ AUM with portfolio companies including Coinbase, Kraken, and Circle. Key risks include a $6.3M SIM-swap attack on co-founder Bart Stephens, Brock Pierce founding controversy, Epstein/Coinbase periphery connections, and effectively zero secondary market liquidity despite the token wrapper. No SEC enforcement actions exist.

avoid.net/fbi-fake-token-tron-impersonation-wallet-freeze-extortion-scam-march-20262/100[CRITICAL]

In March 2026, an unidentified threat actor deployed fraudulent TRC-20 tokens on the Tron network branded as FBI assets and airdropped them to at least 728 wallets, including high-net-worth addresses holding seven-figure USDT balances. The tokens carried messages falsely claiming recipient wallets were frozen for anti-money laundering violations and directed holders to an external phishing site demanding identity and credential submission. The FBI's New York Field Office issued an official warning on March 19, 2026, confirming it does not distribute tokens or request blockchain-based identity verification of any kind.

avoid.net/clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-20260/100[CRITICAL]

A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.

avoid.net/ai-powered-crypto-phishing-infrastructure-20262/100[CRITICAL]

A broad, industrialized criminal ecosystem has emerged in 2025–2026 in which threat actors use generative AI tools — including large language models, deepfake video engines, and voice-cloning services — to produce and operate crypto phishing infrastructure at unprecedented scale. Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods. Law enforcement agencies across the US, UK, and Canada have begun coordinated enforcement actions, but the pace of tool proliferation continues to outpace disruption.

avoid.net/malone-lam-crypto-syndicate0/100[CRITICAL]

The Malone Lam Crypto Syndicate, also known as the Social Engineering Enterprise (SEE), is an alleged multi-state criminal organization that stole approximately $263 million in cryptocurrency between October 2023 and May 2025 through social engineering, residential home invasions, and hardware wallet theft. Led by Singaporean national Malone Lam (alias 'Anne Hathaway', 'Greavys'), the enterprise comprised at least 14 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars. The DOJ charged the organization under the RICO statute — one of the most aggressive crypto theft prosecutions ever filed — and as of June 2026, nine co-defendants have pleaded guilty and been sentenced to 70–78 months, while Lam and co-lead Jeandiel Serrano remain in pre-trial proceedings.

avoid.net/requests-secure-v20/100[CRITICAL]

requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.

avoid.net/debank-auction2/100[CRITICAL]

debank[.]auction is a malicious domain impersonating DeBank (debank.com), a legitimate decentralized finance portfolio tracker founded in 2018. Documented by Zscaler ThreatLabz in July 2026, the site combines typosquatting with indirect prompt injection (IPI) — embedding hidden instructions in its HTML to manipulate AI agents into misclassifying the fraudulent domain as the authoritative DeBank platform. The campaign represents an active, real-world exploitation of autonomous AI agents rather than solely targeting human users.

avoid.net/vy-pham4/100[CRITICAL]

Vy Pham is a California-based cryptocurrency promoter charged in October 2024 by both the U.S. Department of Justice (DOJ) and the U.S. Securities and Exchange Commission (SEC) in connection with alleged market manipulation of two meme tokens: Saitama Inu and Robo Inu Finance. Pham agreed to plead guilty to conspiracy to commit market manipulation, conspiracy to commit wire fraud, and operating an unlicensed money transmitting business. The charges are part of a coordinated federal enforcement action, Operation Token Mirrors, which targeted 18 individuals and entities for widespread fraud in cryptocurrency markets.

avoid.net/rainberry-inc25/100[CRITICAL]

Rainberry Inc, formerly BitTorrent Inc and the developer of the BitTorrent protocol and BitTorrent Token (BTT), agreed in March 2026 to pay a $10 million civil penalty to settle SEC allegations that it facilitated wash trading to artificially inflate trading volume for the TRX cryptocurrency in 2018–2019. The settlement, filed as a proposed final judgment in U.S. District Court for the Southern District of New York, did not require any admission of wrongdoing. All remaining claims against Rainberry, Justin Sun (Tron founder and controlling owner), Tron Foundation, and BitTorrent Foundation were dismissed with prejudice.

avoid.net/mev-bot-scam-youtube-ai-trading-bot-campaign-20262/100[CRITICAL]

An ongoing campaign, active since at least mid-2022 and continuing through 2025, uses AI-generated YouTube videos to promote malicious Solidity smart contracts disguised as Maximal Extractable Value (MEV) arbitrage trading bots. According to SentinelOne Labs (SentinelLABS), one attacker wallet alone collected approximately 244.9 ETH (roughly $902,000 USD) from victims, with total documented losses across the broader campaign exceeding $1 million. Victims are deceived into deploying backdoored contracts via Remix IDE and depositing ETH, which is then routed directly to attacker-controlled wallets through obfuscated code.

avoid.net/ravencoin-consensus-vulnerability-exploit-august-202610/100[CRITICAL]

On August 7, 2026, an attacker exploited a critical consensus vulnerability in the Ravencoin (RVN) network by manipulating the nHeight field in KAWPOW block headers to bypass proof-of-work verification. Invalid blocks were accepted by vulnerable nodes beginning at block height 4,487,776, prompting exchanges Upbit, Bitget, and Bitvavo to suspend RVN deposits and withdrawals and causing RVN to fall approximately 19% to around $0.00288. An emergency patch (v4.6.1.1-hf1) was released on August 10, 2026 by mining pool 2Miners rather than Ravencoin's core development team, marking at least the third significant consensus-level failure in the network's history.

avoid.net/htx-fca-uk-enforcement-illegal-crypto-promotions-202618/100[CRITICAL]

The UK Financial Conduct Authority commenced High Court proceedings on 21 October 2025 against Huobi Global S.A. (the Panamanian entity behind the HTX exchange, formerly Huobi) and multiple categories of 'persons unknown', alleging repeated breach of Section 21 of the Financial Services and Markets Act 2000 by promoting cryptoasset services to UK consumers without authorisation. This is the FCA's first enforcement action against an offshore crypto exchange for illegal financial promotions. As of August 2026, proceedings are stayed while settlement talks continue; no court ruling on the merits has been issued.

avoid.net/bitradex4/100[CRITICAL]

BitradeX (operating primarily at bitradex.ai and previously bitradex.com) is an alleged MLM-structured cryptocurrency trading platform that markets AI-powered trading bots promising annualised returns of 109.5%–182.5%. Launched in early 2025 and promoted via French footballer Olivier Giroud as global brand ambassador from June 2025, the platform has received formal investor warnings from three regulators — Thailand's SEC (February 2026), Securities Commission Malaysia (March 2026), and the Alberta Securities Commission (April 2026) — each citing lack of registration or authorisation. BehindMLM and other analyst sources characterise the scheme as a Ponzi and pyramid hybrid with no retail product, Chinese-origin ownership obscured behind a UK-registered shell, and a pattern of withdrawal blocks consistent with schemes in terminal decline. As of August 2026, the platform reportedly ceased withdrawals and deployed an exit-scam narrative.

avoid.net/coreum-xrpl-bridge-exploit-august-202612/100[CRITICAL]

On August 9, 2026, an attacker exploited a deposit-verification flaw in the cross-chain bridge connecting the XRP Ledger to the Coreum blockchain (operated by tx, formerly Coreum and Sologenic), draining 199,916.3 XRP — approximately $200,000 and 99.7% of the bridge's total reserve — across 94 multisig transactions over 97 minutes. The bridge was halted by tx as of August 11, 2026; bridged XRP on the tx chain is not fully backed as of the most recent reporting, and no compensation plan had been announced as of August 13, 2026.

avoid.net/unidentified-crypto-whale-25-6m-repeated-phishing-drain0/100[CRITICAL]

On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.

avoid.net/shipmonk28/100[WARNING]

ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.

avoid.net/ascendex5/100[CRITICAL]

AscendEX (formerly BitMax), a centralized cryptocurrency exchange founded in 2018, ceased all normal operations on July 1, 2026, after a capital restructuring deal with The Royal Investment Bank of Kelantan Inc. (RIBK) collapsed. The exchange froze automated withdrawals on July 6, 2026, disclosed it may be insolvent, and explicitly stated it could not guarantee full recovery of customer funds. The closure compounded a prior $77.7 million hot-wallet breach suffered in December 2021.

avoid.net/mica-non-compliant-exchange-risk-cluster-post-july-1-20268/100[CRITICAL]

From July 1, 2026, the EU's Markets in Crypto-Assets Regulation (MiCA) entered full enforcement, requiring all crypto-asset service providers (CASPs) serving EU residents to hold a valid authorisation from an EU national competent authority. Approximately 80% of previously operating exchanges failed to obtain authorisation by the deadline, creating a systemic consumer-protection risk cluster in which EU retail users holding assets on unlicensed platforms face potential account restrictions, withdrawal freezes, and — in at least one documented case (AscendEX) — possible permanent loss of funds due to exchange insolvency. ESMA maintains a formal register of both authorised CASPs and flagged non-compliant entities, but coverage of the latter is acknowledged to be incomplete.

avoid.net/ascendex-insolvency-and-withdrawal-freeze-july-20262/100[CRITICAL]

AscendEX (formerly BitMax), a Singapore-headquartered centralized crypto exchange founded in 2018, ceased all operations on July 1, 2026, citing a failure to obtain EU MiCA authorization and the collapse of a strategic liquidity transaction. On-chain data showed exchange reserves dropped by more than $240 million on June 20, 2026; by July 8 only approximately $13.45 million remained on-chain, over $12 million of which consisted of the exchange's own illiquid ASD and UNITE tokens. As of the investigation date, automated withdrawals have been frozen since July 6, 2026, replaced with a manual review process offering no guaranteed timeline or recovery amounts, and the exchange's own legal notice warned that formal insolvency proceedings could follow.

avoid.net/ascendex-bitmax12/100[CRITICAL]

AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.

avoid.net/chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-20260/100[CRITICAL]

ChainDrop is a self-propagating npm supply chain worm discovered on August 4, 2026, representing the latest wave of the Mini Shai-Hulud malware family attributed to the threat group TeamPCP. By compromising the GitHub account of open-source maintainer Jared Wray (jaredwray), attackers injected a two-stage credential-harvesting payload into the widely used keyv and cacheable package ecosystems, which then self-propagated to over 440 additional npm packages representing approximately 2 billion combined monthly downloads. A distinguishing technical characteristic is the worm's use of an Ethereum smart contract for dynamic command-and-control infrastructure, a technique known as EtherHiding, which explicitly targets crypto and Web3 developer tooling alongside cloud and CI/CD credentials.

avoid.net/tanstack-npm-supply-chain-attack-mini-shai-hulud-teampcp0/100[CRITICAL]

On May 11, 2026, threat actor group TeamPCP executed a sophisticated supply chain attack against the TanStack npm ecosystem, compromising 42 packages across 84 malicious versions collectively downloaded millions of times per week. The attack, branded internally as the 'Mini Shai-Hulud' worm, chained three GitHub Actions vulnerabilities to extract an OIDC token from runner memory and autonomously publish credential-stealing payloads that spread to over 170 additional npm and PyPI packages including Mistral AI, UiPath, and OpenSearch. The campaign is the fourth documented wave from TeamPCP, a group active since at least late 2024, and represents the first recorded npm worm to produce validly-attested malicious packages under SLSA Build Level 3 provenance.

avoid.net/miasma-redhat-npm-supply-chain-attack2/100[CRITICAL]

Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.

avoid.net/shai-hulud-teampcp-supply-chain-attack0/100[CRITICAL]

Shai-Hulud is a self-replicating supply chain worm attributed to the financially motivated threat group TeamPCP (also tracked as DeadCatx3, PCPcat, ShellForce, CipherForce, and UNC6780 by Google's Threat Intelligence Group). Active since September 2025, the campaign has compromised hundreds of npm and PyPI packages by harvesting CI/CD credentials through malicious preinstall lifecycle hooks, directly enabling the Trust Wallet Chrome extension hack of December 2025 in which approximately $8.5 million was stolen from 2,520 wallets. As of June 2026, the campaign remains active through copycat variants following TeamPCP's public open-sourcing of the worm's source code on May 12–13, 2026.

avoid.net/rushi-manche12/100[CRITICAL]

Rushikesh 'Rushi' Manche is the co-founder and former CEO of Movement Labs (MVMT Labs, Inc.), a blockchain infrastructure startup that raised at a $3 billion valuation and launched the MOVE token in December 2024. He was suspended on May 2, 2025 and terminated on May 7, 2025 following a third-party investigation by Groom Lake that, according to Movement Labs, linked him to a controversial market-making arrangement with intermediary Rentech and Chinese firm Web3Port that allegedly enabled a coordinated dump of approximately 66 million MOVE tokens within 24 hours of launch, causing an estimated $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the MOVE token launch is confirmed; as of the date of this page no charges, indictment, or criminal finding against Manche has been publicly reported. MVMT Labs filed for Chapter 11 bankruptcy on July 15, 2026, listing Manche as its largest unsecured creditor with a $1.6 million claim while he simultaneously retains a 34.25% equity stake in the company.

avoid.net/movement-labs8/100[CRITICAL]

Movement Labs, the original development company behind the Movement blockchain and MOVE token, filed for Chapter 11 bankruptcy on July 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware. The filing followed a prolonged crisis triggered by a December 2024 market-making arrangement in which 66 million MOVE tokens — approximately 5% of total supply — were sold into the market one day after the token's exchange debut, creating roughly $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the token launch is ongoing as of mid-2026, and MOVE has lost over 94% of its peak value.

avoid.net/storj-labs28/100[WARNING]

Storj Labs, the company behind the decentralized cloud storage protocol and STORJ token, filed for voluntary Chapter 11 bankruptcy protection on July 26, 2026 in the U.S. Bankruptcy Court for the Northern District of West Virginia (case 5:26-bk-00512). The company attributes the filing to legacy financial obligations predating its current operating strategy, not to operational failure, and states that its decentralized storage network and customer services remain uninterrupted. STORJ token holders face significant uncertainty: the company has proposed an equity conversion mechanism, but terms remain undisclosed, court approval is required, and token holders rank behind all creditors under standard bankruptcy law.

avoid.net/novatech-ltd-cynthia-petion-650m-crypto-mlm-fraud2/100[CRITICAL]

NovaTech Ltd. (also marketed as NovaTech FX), incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion, is alleged by U.S. and Canadian regulators to have operated a fraudulent multi-level marketing and crypto investment scheme from June 2019 through May 2023 that raised more than $650 million from over 200,000 investors worldwide. The SEC filed a civil complaint on August 12, 2024, alleging the scheme functioned as a Ponzi, with new investor funds used to pay earlier participants rather than traded as claimed. Regulatory bodies in three jurisdictions — the U.S. SEC, Ontario's Capital Markets Tribunal, and the Maryland Securities Commissioner — have each taken enforcement action; as of the investigation date, the SEC civil litigation remains ongoing and no criminal convictions have been entered.

avoid.net/263m-rico-social-engineering-crypto-theft-gang-dc-2024-2026-prosecutions0/100[CRITICAL]

The Social Engineering Enterprise (SEE) is a multi-state organized crime network that prosecutors allege stole over $263 million in cryptocurrency from multiple victims between October 2023 and May 2025, including over 4,100 Bitcoin from a single Washington, D.C. resident on August 18, 2024 — described by federal prosecutors as one of the largest single-victim cryptocurrency thefts in U.S. history. Formed through online gaming platform connections and prosecuted under the federal RICO statute in the U.S. District Court for the District of Columbia, the enterprise had 17 individuals charged as of late 2025, with 9 guilty pleas entered and at least two sentencings completed as of mid-2026.

avoid.net/hong-kong-insurance-agent-romance-scam-fake-crypto-app-3-3m-july-20260/100[CRITICAL]

In late July 2026, Hong Kong police reported that a woman in her fifties working in insurance lost more than HK$26 million (approximately US$3.3 million) to a pig-butchering romance scheme involving a fraudulent cryptocurrency investment application that displayed fabricated returns exceeding 800%. The case was the largest among 25 romance-linked investment fraud cases recorded by Hong Kong police in the week of July 24–30, 2026, which collectively resulted in losses of nearly HK$70 million (approximately US$8.9 million). No specific perpetrators have been publicly named or charged as of the reporting date.

avoid.net/lido-finance70/100[CAUTIONARY]

Lido Finance is the largest Ethereum liquid-staking protocol, launched in December 2020, enabling users to stake ETH and receive the liquid derivative token stETH without meeting the standard 32 ETH validator minimum. Governed by the Lido DAO via the LDO token, the protocol held approximately 24% of all staked ETH and roughly $19 billion in TVL as of early 2026. Lido carries no fraud or exit-scam history, but poses well-documented systemic centralization risk to Ethereum consensus, governance-concentration concerns among LDO token holders, and faces an active US federal securities lawsuit alleging that LDO is an unregistered security.

avoid.net/kamino-finance74/100[CAUTIONARY]

Kamino Finance is a Solana-based DeFi protocol that combines automated concentrated-liquidity vaults, a lending and borrowing market (K-Lend), and leveraged yield strategies. Launched in August 2022 as a spin-off from Hubble Protocol, it has grown to become the largest DeFi protocol by total value locked on Solana, with multi-billion-dollar deposits as of 2026. The protocol has maintained a zero-bad-debt record since launch, completed more than ten independent security audits, and operates a $1.5 million bug bounty program, though centralization risks around upgrade authority keys and token distribution remain publicly documented concerns.

avoid.net/nicolo-nourafchan-robert-yadgarov-sec-doj-insider-trading-ring2/100[CRITICAL]

On May 6, 2026, the SEC and DOJ charged 30 individuals — with the SEC filing civil charges against 21 of them — in connection with an alleged decade-long insider trading scheme orchestrated by M&A attorney Nicolo Nourafchan and his partner Robert Yadgarov. Nourafchan allegedly misappropriated material nonpublic information from confidential client files at multiple elite BigLaw firms including Sidley Austin, Latham & Watkins, Cleary Gottlieb, and Goodwin Procter, then distributed tips through a tiered network of middlemen and traders in exchange for cash kickbacks. The alleged scheme spanned roughly 30 M&A transactions, generated tens of millions of dollars in illicit profits, and involved fugitives in Russia and Israel as well as international regulatory cooperation across five foreign jurisdictions.

avoid.net/bandcampro-ai-assisted-fraud-campaign2/100[CRITICAL]

Between September 2025 and May 2026, a solo Russian-speaking threat actor operating under the handle 'bandcampro' conducted a sustained AI-assisted fraud and credential-theft campaign targeting MAGA and QAnon communities to steal cryptocurrency. The actor deployed a jailbroken Google Gemini CLI — with safety guardrails persistently disabled via a GEMINI.md context injection file — as the operational backbone of an automated social engineering, influence operation, and hacking pipeline. The campaign is documented in a May 2026 Trend Micro research report titled 'Inside the 5-Year Influence and Fraud Patriot Bait Campaign.'

avoid.net/injective-protocol55/100[CAUTIONARY]

Injective Protocol is a Layer 1 blockchain built on the Cosmos SDK, designed for decentralized finance applications including derivatives, perpetuals, and spot trading via a fully on-chain order book. Founded in 2018 by Eric Chen and Albert Chon and backed by Binance Labs, Pantera Capital, and Mark Cuban, it launched its canonical mainnet in November 2021 and has grown to a top-tier DeFi chain. No regulatory enforcement actions have been identified against Injective; however, concerns exist around a 2025-2026 bug bounty dispute involving an alleged $500 million critical vulnerability, validator stake concentration, and third-party scams impersonating the protocol.

avoid.net/chainlink67/100[CAUTIONARY]

Chainlink is a decentralized blockchain oracle network founded in 2017 by Sergey Nazarov and Steve Ellis, with Cornell University professor Ari Juels co-authoring the whitepaper. The protocol provides smart contracts with tamper-resistant access to off-chain data and computation, holding an estimated 69–70% share of the oracle market and enabling over $26 trillion in cumulative transaction value as of 2025. No regulatory actions have been filed against Chainlink or its parent entity, Chainlink Labs; the primary documented concerns center on token-supply centralization and a 2020 campaign by an anonymous entity publishing unverified fraud allegations that were subsequently discredited.

avoid.net/ethereum64/100[CAUTIONARY]

Ethereum (ETH) is the second-largest cryptocurrency by market capitalization (~$278 billion as of May 2026) and the leading smart-contract platform, hosting the majority of decentralized finance (DeFi) and NFT activity. The protocol has a documented history of governance controversy stemming from the 2016 DAO hack hard fork, ongoing centralization concerns around liquid staking and MEV infrastructure, and persistent smart-contract and phishing-based fraud targeting end users, though Ethereum itself has not been the subject of any regulatory enforcement action and its spot ETFs have received SEC approval.

avoid.net/nexo34/100[WARNING]

Nexo is a crypto lending and yield platform founded in 2018 by Antoni Trenchev and Kosta Kantchev, incorporated in the Cayman Islands, that grew to over $11 billion in assets under management. The company paid a $45 million settlement to the SEC and a multistate coalition of regulators in January 2023 over the unregistered offer and sale of its Earn Interest Product, and exited the US market in late 2022. A Bulgarian criminal investigation launched simultaneously was closed in December 2023 for lack of evidence, after which Nexo filed a $3 billion ICSID arbitration claim against Bulgaria; Nexo formally reentered the US market in February 2026 in partnership with Bakkt.

avoid.net/voyager-digital0/100[CRITICAL]

Voyager Digital was a US-based cryptocurrency brokerage and lending platform founded in 2018 that grew to 3.5 million users and $5.9 billion in assets before filing for Chapter 11 bankruptcy on July 5, 2022, following a $650 million loan default by Three Arrows Capital. The company's collapse resulted in customers losing access to funds, multiple federal regulatory actions against the firm and its CEO Stephen Ehrlich, and the failure of two successive acquisition deals by FTX and Binance.US. After a court-approved liquidation plan in May 2023, creditors received partial distributions estimated at approximately 70% of claims across multiple tranches through 2024.

avoid.net/duelbits32/100[WARNING]

DuelBits is a Curacao-licensed crypto casino and sportsbook operated by Liquid Entertainment N.V., launched in 2020. The platform suffered a confirmed $4.6 million private key compromise on February 13, 2024, affecting wallets on both the Ethereum and BNB Chain networks. DuelBits has also been flagged in broader contexts related to unlicensed gambling promotion, Twitch's 2022 ban on unlicensed gambling streams, and mixed user reports of withdrawal delays and account-closure disputes.

avoid.net/july-2026-bridge-hack-wave-three-protocols-35-6m-one-day0/100[CRITICAL]

On July 22–23, 2026, three separate cross-chain bridge protocols — AFX Trade, B-Squared Network, and Verus — were exploited within approximately six hours of each other for a combined loss of roughly $35.6 million. The incidents contributed to a July 2026 monthly total of approximately $97 million in crypto security losses and are part of a record-setting H1 2026 in which total hack losses surpassed $1 billion across the industry. No single threat actor has been publicly attributed to all three attacks, though the clustering prompted security firm Blockaid to label the period 'Hackers Day.'

avoid.net/levana-perps32/100[WARNING]

Levana Perps is a decentralized perpetual-swap protocol originally deployed on Osmosis (Cosmos ecosystem) and later expanded to Sei and Injective. In December 2023, the protocol suffered a confirmed oracle-manipulation exploit spanning 13 days that drained approximately $1.14 million (roughly 10% of liquidity provider funds). The protocol subsequently underwent a strategic rebrand and token migration into the Rujira (RUJI) ecosystem in 2025, effectively sunsetting the standalone LVN token.

avoid.net/2026-violent-crypto-wrench-attack-wave-h1-chainalysis-report0/100[CRITICAL]

In H1 2026, physical coercion attacks ('wrench attacks') targeting cryptocurrency holders reached record levels, with Chainalysis documenting 46 incidents and over $30 million in confirmed losses, while CertiK's parallel Intel3D report verified 52 incidents and $124 million in total financial exposure. France emerged as the global epicenter, accounting for 33 of 52 verified incidents, largely attributed to a 2024 theft of tax records by a French government official and a separate breach of crypto tax platform Waltio affecting 50,000 users. The attack wave is on pace to surpass every prior full-year record and represents a structural shift in crypto crime toward physical coercion that bypasses on-chain security entirely.

avoid.net/gotbit-vortex-antier-contrarian-doj-crypto-market-maker-manipulation-ring2/100[CRITICAL]

Four cryptocurrency market-making firms — Gotbit Consulting, Vortex, Antier Solutions, and Contrarian — were the subjects of coordinated DOJ criminal indictments filed between October 2024 and September 2025 and publicly announced on March 30, 2026. Ten foreign nationals were charged across three separate federal indictments in the Northern District of California and the District of Massachusetts for conducting wash trading and pump-and-dump schemes affecting over 60 cryptocurrency tokens, resulting in the seizure of more than $25 million in digital assets. Gotbit founder Aleksei Andriunin pleaded guilty and was sentenced to eight months in federal prison in June 2025, and Gotbit was ordered to forfeit approximately $23 million in cryptocurrency and cease operations.

avoid.net/ravencoin-rvn22/100[CRITICAL]

In August 2026, Ravencoin's mainnet suffered a critical consensus vulnerability in its KAWPOW proof-of-work algorithm that allowed attackers to produce invalid blocks at a fraction of normal mining cost, beginning at block height 4,487,776 on August 7, 2026. Majority mining pools took unilateral control of the recovery process, issuing a patch without the core development team and threatening a deep three-day blockchain reorganization that would reverse all transactions since block 4,487,775. The incident — the network's third known consensus or supply failure — triggered an approximately 19-20% price crash, exchange-wide suspension of RVN transfers, and raised acute governance concerns about the project's effectively inactive development team.

avoid.net/harmony-protocol-one-token-unauthorized-mint-exploit-august-20268/100[CRITICAL]

On August 12, 2026, Harmony Protocol confirmed an exploit in which approximately 4 billion ONE tokens were minted without authorization through a flaw in cross-shard receipt verification, representing roughly 26% of the token's prior circulating supply. An estimated 2.8 billion of the minted tokens (approximately 97% of the illicit supply) were transferred to centralized exchanges before Harmony could coordinate a freeze response; the token price fell between 30% and 40% to a record low of approximately $0.0005735. Harmony released emergency validator patch v2026.1.1 and paused its Horizon bridge while evaluating a potential blockchain rollback, but the root cause and confirmed token totals had not been officially disclosed as of the date of this report.

avoid.net/catfi-memecoin-catfi2/100[CRITICAL]

CATFI was a Solana-based memecoin launched via Pump.fun whose operators, led by a suspect identified only as Park (alias 'Eth Father'), orchestrated a coordinated pump-and-dump that caused approximately 900 million won (~$600,000) in investor losses across 256 victims in early 2025. South Korean authorities arrested five individuals in May 2026, resulting in South Korea's first criminal prosecution for a decentralized-exchange rug pull under the Virtual Asset User Protection Act, and the ringleader was sentenced to four years in prison by the Seoul Southern District Court on July 23, 2026.

avoid.net/cream-finance12/100[CRITICAL]

C.R.E.A.M. Finance is a decentralized lending protocol that launched on Ethereum in August 2020, originally forked from Compound Finance. The protocol suffered three major exploits across 2021, losing approximately $186 million in total user funds, and has been effectively dormant since early 2022 with minimal development activity and a TVL that collapsed from over $2 billion to under $3 million.

avoid.net/cream-lending10/100[CRITICAL]

C.R.E.A.M. Finance (Crypto Rules Everything Around Me) is a decentralized lending and borrowing protocol launched in August 2020, forked from Compound Finance. The protocol suffered three major exploits in 2021 totaling approximately $185 million in losses, making it one of the most frequently and severely hacked DeFi protocols in history. On-chain investigator ZachXBT flagged the protocol and its founders, and the CREAM token has collapsed more than 99% from its all-time high.

avoid.net/stablr-multisig-exploit-and-eurr-usdr-depeg28/100[WARNING]

StablR is a Malta-licensed, MiCA-compliant stablecoin issuer backed by Tether that issues EURR (euro-pegged) and USDR (dollar-pegged) tokens on Ethereum and Solana. On May 24, 2026, an attacker compromised one signer in the platform's 1-of-3 minting multisig, replaced the remaining legitimate owners with malicious addresses, and minted approximately $13.5 million in unbacked tokens, realizing roughly $2.8 million (1,115 ETH) in net proceeds by dumping on decentralized exchanges. Both stablecoins lost significant peg value within hours; as of late July 2026, minting and redemption remain suspended and the reserve deficit had not been publicly resolved.

avoid.net/cosmos-atom54/100[CAUTIONARY]

Cosmos is a Layer 1 blockchain protocol and interoperability hub founded by Jae Kwon and Ethan Buchman, with its mainnet launching in March 2019. The project pioneered the Inter-Blockchain Communication (IBC) protocol, enabling sovereign blockchains to transfer assets and data across networks. While the protocol has broad institutional adoption and a large ecosystem, it has faced material governance controversies, a serious security incident involving alleged North Korean developer contributions to its Liquid Staking Module, leadership fragmentation, and persistent concerns over the Interchain Foundation's financial transparency.

avoid.net/blockstream-jade-fake-firmware-phishing-campaign-august-20265/100[CRITICAL]

A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.

avoid.net/coinsbuy38/100[WARNING]

Coinsbuy (coinsbuy.com) is a B2B cryptocurrency payments platform and exchange incorporated in Saint Vincent and the Grenadines, with reported operational presence in Panama. On August 9, 2026, wallets linked to the platform were drained of approximately $7.9–8.07 million across Ethereum and TRON networks in a coordinated cross-chain attack. The company stated that all affected client funds were covered from its own reserves, though the attack vector remained publicly unconfirmed as of mid-August 2026.

avoid.net/blockfills-reliz-technology-group12/100[CRITICAL]

BlockFills, a Chicago-based institutional crypto trading and liquidity provider operating under parent entity Reliz Technology Group Holdings Inc., filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of Delaware on March 15, 2026, listing up to $500 million in liabilities against $50–100 million in assets. The filing followed the suspension of client deposits and withdrawals in February 2026, a lawsuit by creditor Dominion Capital alleging that client funds were commingled with company accounts, and a federal court order freezing approximately 70.6 BTC. A plan of reorganization was confirmed on July 13, 2026, with Keyrock completing the acquisition of BlockFills' trading and brokerage assets for $3.25 million.

avoid.net/titan8/100[CRITICAL]

TITAN (IRON Titanium Token) was the governance and collateral token of Iron Finance, a partially-collateralized algorithmic stablecoin protocol deployed on Polygon in May 2021. On June 16–17, 2021, the protocol suffered a catastrophic collapse — described by the Iron Finance team as 'the world's first large-scale crypto bank run' — during which TITAN's price fell from an all-time high of approximately $65 to effectively zero within hours, wiping out an estimated $2 billion in total value locked. The collapse was attributed by the Iron Finance team and independent analysts, including the U.S. Federal Reserve, to a fundamental design flaw in the protocol's stabilization mechanism rather than intentional fraud, though allegations of a rug pull circulated widely in the immediate aftermath.

avoid.net/trump-memecoin-august-2026-sec-investigation-request14/100[CRITICAL]

The $TRUMP (Official Trump) memecoin launched on the Solana blockchain on January 17, 2025, two days before Donald Trump's presidential inauguration, and rapidly surged to a peak of approximately $75 before declining more than 98% to around $1.51 as of August 2026. Trump-affiliated entities — CIC Digital LLC and Fight Fight Fight LLC — retained 80% of the 1 billion token supply and have collectively earned an estimated $636 million in royalties, while approximately 988,905 retail investors accumulated losses exceeding $3.81 billion. On August 4, 2026, Senators Elizabeth Warren and Richard Blumenthal formally demanded that SEC Chairman Paul Atkins open an investigation into the token's alleged fraudulent enrichment schemes, though the SEC's own February 2025 guidance classifying memecoins as non-securities limits its enforcement authority.

avoid.net/oramama-x-war-panic-scam-network2/100[CRITICAL]

The ORAMAMA X War-Panic Scam Network is a coordinated cluster of more than 10 accounts on X (formerly Twitter) that used AI-generated geopolitical fear content — including fabricated claims about the US-Iran conflict — to accumulate large audiences before executing a confirmed pump-and-dump of the Solana meme token $ORAMAMA on February 22, 2026. On-chain investigator ZachXBT exposed the network in March 2026, documenting six-figure profits and warning that the scalable playbook posed nation-state-level disinformation risks.

avoid.net/libra-diem30/100[WARNING]

Libra was a proposed global cryptocurrency announced by Facebook (now Meta) on June 18, 2019, initially designed as a multi-currency-backed stablecoin governed by an independent consortium called the Libra Association. The project faced immediate and sustained opposition from U.S. and international regulators, lost the majority of its founding payment-industry partners within months of announcement, underwent significant structural changes and a rebrand to Diem in December 2020, and ultimately shut down in January 2022 when the Diem Association sold its intellectual property and technology assets to Silvergate Capital Corporation for approximately $182 million. The acquired assets were subsequently written down to near zero when Silvergate itself collapsed in March 2023.

avoid.net/fun-coffee-gcm-project2/100[CRITICAL]

Fun Coffee, also marketed as the GCM Project, was a purported Vietnam-based coffee technology investment scheme that operated a cryptocurrency deposit and multi-level-commission structure promising annual returns of 197% to 278%. The scheme entered the Hong Kong market in late 2025, was placed on the Hong Kong Securities and Futures Commission's suspicious investment product alert list on July 13, 2026, and collapsed on approximately July 20, 2026, when its mobile app, withdrawals, and customer support went offline simultaneously. A joint Hong Kong–Macau police operation in August 2026 resulted in eight arrests; a ninth arrest followed in Singapore. Confirmed police-reported losses stand at approximately HK$104 million (US$13.3 million) across more than 255 complaints as of early August 2026, while investors in a roughly 4,000-member chat group allege combined losses exceeding HK$1 billion (US$127 million).

avoid.net/bitrefill52/100[CAUTIONARY]

Bitrefill is a Stockholm-headquartered crypto e-commerce platform founded in 2014 that allows users to purchase gift cards, eSIMs, and phone top-ups with Bitcoin and other cryptocurrencies. On March 1, 2026, the company suffered a confirmed cyberattack in which attackers compromised an employee laptop, escalated access to production infrastructure and hot wallets, drained an undisclosed amount of cryptocurrency, and exfiltrated approximately 18,500 purchase records. Bitrefill publicly attributed the attack to North Korea's Lazarus Group (Bluenoroff subgroup) based on malware signatures, on-chain tracing, and reuse of IP and email addresses consistent with prior DPRK-linked operations.

avoid.net/eu-mica-post-deadline-regulator-impersonation-scam-cluster0/100[CRITICAL]

Following the expiration of the EU Markets in Crypto-Assets (MiCA) transitional period on July 1, 2026, a cluster of fraud operations emerged targeting crypto users displaced by the mass exit of more than 1,700 unlicensed exchanges from the European market. Fraudsters impersonate officials from ESMA, France's AMF, the Dutch AFM, and other national regulators, directing victims to transfer assets to criminal-controlled fake websites under the guise of regulatory compliance. Multiple EU financial watchdogs publicly warned of the scam wave in early August 2026, characterizing the transition window as unusually favorable for fraudsters.

avoid.net/coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-202618/100[CRITICAL]

A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.

avoid.net/pump-fun-solana-labs-jito-labs-rico-mev-class-action-sdny-202628/100[WARNING]

Aguilar v. Baton Corporation Ltd. (Case No. 1:25-cv-00880-CM) is a federal class action lawsuit filed in the U.S. District Court for the Southern District of New York against Pump.fun operator Baton Corporation Ltd., Solana Labs, the Solana Foundation, and their named executives, alleging a coordinated RICO racketeering enterprise centered on the Pump.fun memecoin launchpad. A second amended consolidated complaint was filed January 7, 2026, supported by over 5,000 alleged internal chat logs, and seeks between $4 billion and $5.5 billion in compensatory damages — potentially tripled under RICO. Jito Labs, initially named as a co-defendant for alleged MEV-enabling conduct, obtained a voluntary dismissal of claims against it in September 2025 without any settlement payment.

avoid.net/ashcrypto-roya-token-pump-and-dump18/100[CRITICAL]

Ashcrypto (X: @Ashcryptoreal) is a crypto influencer with over 2.1 million followers on X who was alleged by on-chain investigator ZachXBT in May 2026 to have executed a pump-and-dump scheme involving ROYA, the native token of Royale Finance. According to ZachXBT's published evidence, Ashcrypto publicly promoted ROYA while privately messaging premium-channel followers that his team was 'holding 100%' and buying more, while simultaneously selling. Ashcrypto did not respond to requests for comment and had not publicly addressed the allegations as of the time of reporting.

avoid.net/tiffany-milanovich2/100[CRITICAL]

Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.

avoid.net/irs-digital-asset-compliance-portal-phishing-campaign-20260/100[CRITICAL]

Beginning in late July 2026, an organized criminal operation mailed counterfeit IRS letters to US cryptocurrency holders directing them via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest credentials and drain digital asset accounts. IRS Criminal Investigation confirmed the campaign on July 30, 2026, stating no such portal exists; infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior phishing history.

avoid.net/apple-app-store-systematic-fake-crypto-wallet-cluster-26-apps-april-20262/100[CRITICAL]

Beginning in at least fall 2025 and publicly disclosed in April 2026, a coordinated cluster of 26 fraudulent iOS applications impersonating major cryptocurrency wallets was discovered on Apple's App Store by Kaspersky researchers. The campaign, dubbed FakeWallet and attributed with moderate confidence to the SparkKitty threat actor group, targeted seed phrase theft primarily from Chinese iOS users. The broader pattern of fake wallet apps on Apple's platforms in 2026 resulted in documented losses exceeding $11 million across multiple distinct incidents and triggered civil litigation against Apple.

avoid.net/fx-winning-david-merino-quintana1/100[CRITICAL]

FX Winning (also styled FXWinning) was a fraudulent cryptocurrency and foreign exchange investment platform allegedly masterminded by Spanish national David Merino Quintana, a businessman from Gran Canaria, Spain. Spanish authorities, coordinating with Europol, the US Drug Enforcement Administration, and investigators in Mexico and Colombia, allege the platform operated as a Ponzi scheme from approximately 2020 to 2023, collecting funds from up to 15,000 victims across more than 30 countries, with Spanish investigators estimating losses of at least €460 million and total funds collected potentially reaching €46 billion. Merino was arrested in Dubai on June 1, 2026, following an international arrest warrant issued by Spain's Audiencia Nacional, and extradition proceedings to Spain are pending.

avoid.net/fake-sparrow-wallet-apple-app-store0/100[CRITICAL]

A fraudulent iOS application impersonating Sparrow Wallet — a legitimate Bitcoin wallet that has no official iOS release — passed Apple's App Store review process and operated on the platform between at least May and August 2025, draining a combined $1.84 million in Bitcoin from three victims by capturing their seed phrases. Three plaintiffs filed a federal lawsuit against Apple on July 24, 2026 in the Northern District of California, case 5:26-cv-07713, alleging negligence, fraudulent misrepresentation, and strict products liability; the actual perpetrators behind the fraudulent app remain unidentified.

avoid.net/cryptomus-xeltox-enterprises-ltd2/100[CRITICAL]

Cryptomus is a cryptocurrency payment processor and exchange operated by Xeltox Enterprises Ltd., a company incorporated in British Columbia, Canada. In October 2025, Canada's financial intelligence unit FINTRAC imposed a record C$176.96 million (approximately US$126 million) administrative penalty against Xeltox for 2,593 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, citing failures to report transactions linked to child sexual abuse material, ransomware payments, fraud, and Iran sanctions evasion. Blockchain intelligence firm TRM Labs further assessed with high confidence that Cryptomus launched a successor platform, Heleket, shortly after implementing mandatory KYC controls, allegedly to continue facilitating illicit activity under a separate brand.

avoid.net/blazar-token-john-a-desalvo2/100[CRITICAL]

Blazar Token was a fraudulent cryptocurrency created by former New Jersey State Corrections Lieutenant John A. DeSalvo, who marketed it to law enforcement personnel and first responders as a 'crypto pension' supplement beginning in November 2021. DeSalvo raised at least $623,888 from approximately 222 investors through materially false representations, then misappropriated the funds and executed a rug-pull in May 2022 by selling over 41 billion of his own tokens, collapsing the price. He pleaded guilty to federal securities fraud charges in March 2024, and the SEC reached a civil settlement in August 2026 ordering disgorgement of $681,105.

avoid.net/btcpay-server-lightning-lnd-macaroon-exploit-august-202662/100[CAUTIONARY]

In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.

avoid.net/fifa-world-cup-2026-crypto-phishing-and-typosquatting-infrastructure2/100[CRITICAL]

A coordinated, multi-actor scam infrastructure emerged around the 2026 FIFA World Cup (hosted across Canada, Mexico, and the United States, June 11 to July 19, 2026), comprising more than 13,000 to 19,000 registered World Cup-themed domains of which approximately 8.8% have been flagged as malicious or suspicious. The infrastructure combines typosquatted FIFA domains, AI-generated fake ticketing portals, cryptocurrency wallet drainers, seed-phrase phishing kits, and Android banking trojans, with at least one threat actor cluster — designated GHOST STADIUM — attributed to Chinese-speaking operators. The FBI issued a formal public service announcement on May 27, 2026, warning consumers and reporting at least 36 confirmed fraudulent domains spoofing official FIFA web properties.

avoid.net/secondfi-cardano-wallet13/100[CRITICAL]

SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026. Between June 21 and 23, 2026, attackers exploited a deterministic nonce-derivation flaw in the platform's wallet generation software, draining approximately 16 million ADA (~$2.4 million) from 374 user wallets. Up to 129 million ADA across 3,072 wallets was placed at risk, with blockchain security firm SlowMist estimating total exposure could exceed $20 million; EMURGO has committed to full user reimbursement through an independently secured restoration fund, though no timeline or audit has been published.

avoid.net/taiko-ethereum-l2-bridge10/100[CRITICAL]

On June 22, 2026, Taiko — an Ethereum-equivalent layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million from its L1 Bridge and ERC-20 vault by using an RSA-3072 Intel SGX signing key that had been committed in plaintext to the public taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and execute fraudulent withdrawal transactions on Ethereum with no corresponding deposits on Taiko's chain. Taiko halted block production network-wide, froze affected contracts, and urged all users to exit every bridge on the network within approximately eight minutes of the attack being detected by Blockaid's monitoring system.

avoid.net/dean-daghita-cmdss-command-services-and-support4/100[CRITICAL]

Command Services and Support, Inc. (CMDSS) is a Haymarket, Virginia-based Service-Disabled Veteran-Owned Small Business led by president and CEO Dean Daghita that received a U.S. Marshals Service contract in October 2024 to manage and dispose of Class 2-4 seized cryptocurrency. In January 2026, blockchain investigator ZachXBT publicly alleged that Daghita's son, John Daghita (alias 'Lick'), had stolen over $46 million in digital assets from government-controlled USMS wallets by abusing insider access obtained through his father's company. John Daghita was arrested in Saint Martin on March 4, 2026, and was subsequently indicted on 15 federal counts; Dean Daghita himself had not been charged as of August 2026, though CMDSS's online presence was taken offline following the revelations and the company faces significant scrutiny over contract award process and oversight failures.

avoid.net/emerson-sousa-pires2/100[CRITICAL]

Emerson Sousa Pires is a Brazilian national and co-founder of MCC International Corp. (doing business as Mining Capital Coin), who faces a $46.2 million SEC default judgment entered August 26, 2025, alongside co-founder Luiz Carlos Capuci Jr. for operating an alleged crypto mining Ponzi scheme that defrauded approximately 65,535 investors. Pires is separately charged criminally and faces additional civil enforcement by the CFTC arising from a second fraudulent cryptocurrency investment platform, EmpiresX, through which he allegedly defrauded over 12,500 additional investors. He has reportedly fled to Brazil, where Brazilian law prohibits extradition of citizens, though Brazilian federal authorities conducted arrests in connection with parallel domestic proceedings in September 2023.

avoid.net/luiz-carlos-capuci-jr2/100[CRITICAL]

Luiz Carlos Capuci Jr. is the co-founder and CEO of MCC International Corp. (doing business as Mining Capital Coin) and the operator of CPTLCoin Corp. and Bitchain Exchanges. He is the subject of a DOJ criminal indictment unsealed in May 2022 for allegedly orchestrating a $62 million global cryptocurrency investment fraud affecting more than 65,000 investors, and faces up to 45 years in prison on three conspiracy counts. In August 2025, a U.S. federal court entered a $46 million default judgment against him and co-defendant Emerson Sousa Pires in the parallel SEC civil case.

avoid.net/wanchain-cardano-bridge-night-token-exploit-july-20268/100[CRITICAL]

On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.

avoid.net/taiko-ethereum-l2-bridge-exploit7/100[CRITICAL]

On June 22, 2026, an attacker drained approximately $1.7 million from the Taiko Ethereum layer-2 bridge and ERC-20 vault by exploiting a leaked Intel SGX RSA-3072 signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and submit withdrawal requests on Ethereum with no matching deposits on Taiko, causing the bridge contracts to release funds against fraudulent proofs. Taiko halted block production and froze bridge withdrawals within approximately eight minutes of the attack being detected by Blockaid's monitoring system.

avoid.net/huobi-htx7/100[CRITICAL]

HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.

avoid.net/pump-fun-solana-memecoin-launchpad-ecosystem-fraud4/100[CRITICAL]

Pump.fun is a Solana-based memecoin launchpad operated by Baton Corporation Limited that launched in January 2024 and rapidly became the dominant token creation platform on Solana, generating over $1 billion in fees by April 2025. The platform is the subject of multiple federal class action lawsuits alleging it facilitated unregistered securities sales, insider front-running via MEV infrastructure, and systemic pump-and-dump fraud affecting retail traders. Third-party analysis of over 7 million tokens launched on the platform between January 2024 and March 2025 found that 98.6% exhibited fraudulent characteristics including pump-and-dump patterns and rug pulls.

avoid.net/rugproof-solana-launchpad0/100[CRITICAL]

Rugproof is an anonymous Solana-based token launchpad that markets itself as protecting investors from rug pulls through anti-dump mechanics, bonding curve mechanics, and SOL refund guarantees. On July 28–29, 2025, blockchain analytics firm Bubblemaps published on-chain findings alleging that the project's creator distributed SOL to 162 coordinated wallets that collectively acquired 50% of the RUGPROOF token supply at launch, a pattern Bubblemaps characterized as consistent with rug-pull bundling schemes. The project's team identity, tokenomics documentation, and smart contract audits remain undisclosed as of the date of reporting.

avoid.net/verus-ethereum-bridge-second-exploit-july-20260/100[CRITICAL]

On July 23, 2026, the Verus-Ethereum Bridge suffered a second major security exploit in 66 days, with an attacker draining approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. The attack exploited the same contract, entry path, and vulnerability class as a May 18, 2026 incident that had drained $11.58 million — raising critical concerns that the underlying flaw was never properly remediated before recovered funds were redeposited into the bridge on July 8, 2026. Combined losses from both exploits total approximately $19.1 million, with the July attacker subsequently laundering stolen assets through Tornado Cash.

avoid.net/91m-bitcoin-social-engineering-theft-hardware-wallet-impersonation-august-20260/100[CRITICAL]

On August 19, 2025, a single victim lost 783 BTC (approximately $91 million at the time) after attackers impersonated customer support representatives for both a hardware wallet manufacturer and a cryptocurrency exchange. The stolen funds were routed through Wasabi Wallet's CoinJoin mixing service to obstruct traceability. Blockchain investigator ZachXBT publicly disclosed the theft on August 21, 2025, noting it occurred exactly one year after the $243 million Genesis creditor social engineering theft of August 19, 2024. This incident and its successor threats constitute a documented category-level attack pattern targeting high-net-worth Bitcoin holders through trusted-service impersonation, particularly dangerous in the August 2026 environment following the Coldcard firmware exploit and associated phishing surge.

avoid.net/clickfix-bnb-chain-etherhiding-malware-campaign0/100[CRITICAL]

An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.

avoid.net/mcc-international-corp-cptlcoin-corp-bitchain-exchanges2/100[CRITICAL]

MCC International Corp. (doing business as Mining Capital Coin), CPTLCoin Corp., and Bitchain Exchanges were collectively operated as a multi-level marketing cryptocurrency fraud scheme that defrauded 65,535 investors worldwide of an alleged $62 million between at least January 2018 and 2022. The SEC filed charges in April 2022 and secured a combined $46 million default judgment in August 2025; co-founders Luiz Carlos Capuci Jr. and Emerson Sousa Pires fled to Brazil and were arrested there by Brazilian Federal Police in September 2023 under a separate domestic money-laundering investigation.

avoid.net/siavash-kayvanpour-ofac-designated-shelbit-founder2/100[CRITICAL]

Siavash Kayvanpour is an Iranian expatriate and founder of Shelbit, an unlicensed cryptocurrency exchange that U.S. Treasury's OFAC personally designated on August 7, 2026 under Executive Order 13224 for materially supporting Iran's Islamic Revolutionary Guard Corps (IRGC). Blockchain investigators traced over USD 6.3 billion in flows through the Shelbit network between May 2024 and March 2026, linking the exchange to IRGC-affiliated wallets, Iran's central bank, and one of the world's largest illegal online gambling operations. Kayvanpour holds citizenships in Iran, Dominica, and Afghanistan, complicating international enforcement of the designation.

avoid.net/supra-oracle-bonzo-lend-attack-vector22/100[CRITICAL]

On July 11, 2026, Hedera's largest lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a signature verification flaw in Supra's on-chain oracle verifier contract. The vulnerable code had been live for at least two years and was deployed to 11 other chains — all of which received a security patch in the days before the Hedera attack — while the Hedera instance remained unpatched. Supra, founded in 2020 and backed by Coinbase Ventures and other institutional investors, is a cross-chain oracle and infrastructure network whose verifier flaw carries systemic risk to any dependent protocol.

avoid.net/summer-finance-summer-fi-lazy-summer-protocol-flash-loan-exploit-and-shutdown18/100[CRITICAL]

On July 6, 2026, an attacker used a $65.4 million Morpho flash loan to exploit a stale-asset share-price manipulation vulnerability in Summer.fi's Lazy Summer Protocol, extracting approximately $6.04 million in DAI from two Ethereum USDC vaults. The stolen funds were subsequently laundered through Tornado Cash. On July 15, 2026, Summer.fi Labs announced it had no viable path forward and would cease operations by August 31, 2026, with governance of the Lazy Summer Protocol transferring entirely to the Lazy Summer DAO.

avoid.net/hypervault-finance0/100[CRITICAL]

Hypervault Finance was a yield-aggregating DeFi vault protocol built on the HyperEVM layer of the Hyperliquid blockchain that executed a confirmed exit scam on or around September 25–26, 2025, draining approximately $3.6–4.64 million from roughly 1,100 depositors. Operators bridged funds to Ethereum via deBridge, converted assets to ETH, and routed approximately 752 ETH into Tornado Cash to obscure the trail before deleting all web properties, social media accounts, and GitHub repositories. The project had falsely claimed ongoing security audits by Spearbit, Pashov Group, and Code4rena — none of which were conducted — and attracted deposits with promises of 76–95% annualized yields on stablecoins and HYPE liquidity tokens.

avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-202638/100[WARNING]

On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.

avoid.net/lazarus-group-mach-o-man-macos-campaign-20260/100[CRITICAL]

The Lazarus Group Mach-O Man campaign is a state-sponsored macOS malware operation publicly disclosed in April 2026, attributed to North Korea's Reconnaissance General Bureau via the Chollima operational unit. The campaign delivers a modular, Go-compiled malware kit through ClickFix social engineering — fake video-conference invitations distributed over Telegram — targeting cryptocurrency developers, fintech executives, and high-value enterprise users running Apple hardware. Researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform identified four distinct attack stages culminating in macOS Keychain theft, browser credential harvesting, and exfiltration via the Telegram Bot API.

avoid.net/ai-agent-prompt-injection-crypto-attack-class-20260/100[CRITICAL]

Prompt injection attacks against autonomous AI crypto trading agents constitute a documented and accelerating threat class in 2026, responsible for over $45 million in aggregate losses across multiple confirmed incidents. Attackers embed hidden instructions in airdropped NFT metadata, web page content, and encoded social media posts to cause AI agents with wallet signing authority to execute unauthorized fund transfers — no smart contract vulnerability required. Security firm Blockaid, OWASP, and researchers at Zscaler have each independently confirmed prompt injection as a live, reproducible attack vector against production AI agent deployments.

avoid.net/dprk-crypto-theft-h1-2026-trm-labs-blockaid-report0/100[CRITICAL]

North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm. Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds. Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.

avoid.net/q2-2026-record-crypto-hack-wave0/100[CRITICAL]

The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.

avoid.net/q2-2026-defi-record-hack-wave0/100[CRITICAL]

Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.

avoid.net/humanity-protocol-h-token-hack18/100[CRITICAL]

On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.

avoid.net/0xdf8c3a7ffbdc144f462687120e4ae4c4e5e55abe50/100[WARNING]

0xdF8C3A7FFbdC144f462687120E4AE4C4e5E55abE is an Ethereum externally owned account (EOA) with no recorded on-chain transaction history, zero ETH balance, and no token holdings as of August 2026. No verifiable associations with scams, fraud, sanctions, regulatory actions, or illicit activity were found across any checked source; however, the absence of on-chain history and public intelligence makes a definitive trust assessment impossible.

avoid.net/noones-exchange34/100[WARNING]

NoOnes is a peer-to-peer cryptocurrency marketplace launched in 2023 by Ray Youssef, co-founder of the now-defunct Paxful exchange. The platform operates across 190+ countries, reports 2.5 million users, and is headquartered in Dubai. It carries significant reputational and structural risk owing to a confirmed $7.9 million hot-wallet exploit in January 2025, the founder's DOJ indictment on AML charges stemming from Paxful, and Youssef's subsequent forced departure from the CEO role in February 2026 under undisclosed legal circumstances.

avoid.net/keyv-cacheable-npm-supply-chain-attack-teampcp-mini-shai-hulud-august-20260/100[CRITICAL]

On August 4, 2026, the GitHub account of Jared Wray (jaredwray), maintainer of the keyv and cacheable npm package ecosystems, was compromised, enabling attackers to inject the Mini Shai-Hulud credential-stealing worm into at least 11 core packages representing over two billion combined monthly downloads. A self-propagating worm mechanism subsequently expanded the blast radius to more than 400 additional npm packages across 2,234 poisoned versions. The attack is attributed to the TeamPCP threat group and represents one of the largest npm supply chain compromises on record by download volume.

avoid.net/bonzo-finance28/100[WARNING]

Bonzo Finance is an open-source, non-custodial lending and borrowing protocol deployed on the Hedera network, developed by Bonzo Finance Labs and launched on mainnet on October 28, 2024. On July 11, 2026, an attacker exploited a BLS signature verification flaw in a Supra oracle contract to artificially inflate the price of the SAUCE token by approximately 12 orders of magnitude, draining approximately $9.05 million in USDC and wrapped HBAR from Bonzo Lend. The incident caused Bonzo Lend's total value locked to collapse 77% and Hedera's overall DeFi TVL to drop nearly 40% within 24 hours; Bonzo Lend and Bonzo Points were subsequently paused, with the Hedera Foundation committing backing for full user position recovery.

avoid.net/neyro-token-aurum-foundation-exit-scam-rebrand2/100[CRITICAL]

Aurum Foundation was an MLM crypto Ponzi scheme launched from Dubai in mid-2024 that marketed an alleged AI trading bot promising approximately 30% monthly returns. In June 2026, facing regulatory action from at least ten jurisdictions, operators rebranded to 'Neyro' and introduced a NEYRO token before executing a classic exit-scam on July 30, 2026, draining investor wallets and issuing a fabricated 'we got hacked' notice to conceal operator flight.

avoid.net/zhuoying-chen-haojie-zhang-43m-pig-butchering-laundering-network2/100[CRITICAL]

Zhuoying Chen (aka 'Jolene,' 27, Brooklyn, NY) and Haojie Zhang (aka 'Kevin,' 38, Queens, NY) were charged by federal prosecutors on July 16, 2026 with conspiracy to commit money laundering in connection with laundering at least $43 million in proceeds from pig-butchering investment fraud schemes between 2020 and 2022. The pair allegedly managed a domestic infrastructure layer of a China-linked criminal network, recruiting over a dozen money mules across Brooklyn and Queens who opened 140 bank accounts under approximately 45 shell companies, then converted the layered funds to cryptocurrency for transfer to China-based co-conspirators. Both defendants face up to 20 years in prison.

avoid.net/travis-ford-wolf-capital-crypto-ponzi2/100[CRITICAL]

Travis Ford, 36, of Glenpool, Oklahoma, was the co-founder, CEO, and head trader of Wolf Capital Crypto Trading LLC. He was sentenced on November 14, 2025, to 60 months in federal prison after pleading guilty in January 2025 to one count of conspiracy to commit wire fraud for operating a $9.4 million Ponzi scheme that defrauded approximately 2,800 investors. The CFTC filed a parallel civil enforcement action in December 2025 alleging broader fraud spanning October 2022 through December 2024 and involving more than $10 million from over 3,000 participants.

avoid.net/mica-post-deadline-crypto-firm-impersonation-scam-cluster-august-20260/100[CRITICAL]

Following the July 1, 2026 expiry of MiCA transitional arrangements, which forced over 1,700 unlicensed crypto firms to cease EU operations, financial regulators including ESMA, France's AMF, the Dutch AFM, and Belgium's FSMA identified a coordinated surge in impersonation fraud targeting displaced retail investors. Fraudsters have misused ESMA's official name, logo, and branding — including fabricated MiCA authorization documents and spoofed regulator communications — to deceive users seeking compliant alternatives into transferring assets to fraudulent wallets. This scam cluster is confirmed by formal regulatory advisories published August 6, 2026 and represents a distinct pattern exploiting genuine regulatory transition confusion.

avoid.net/holoworld-ai-ava-token-insider-bundling-scheme14/100[CRITICAL]

Holoworld AI, a Solana-based AI avatar platform developed by Hologram Labs and backed by Polychain Capital's $6.5 million seed round, launched its AVA token on November 13, 2024, via Pump.fun. On-chain analytics firm Bubblemaps identified 23 wallets allegedly linked to the token deployer that accumulated approximately 40% of AVA's total supply at launch through coordinated automated sniping. AVA subsequently crashed more than 96% from its January 2025 all-time high of $0.33, erasing nearly $290 million in fully diluted valuation and causing substantial losses for retail holders.

avoid.net/benjamin-paul-wiener-benaiah-capital2/100[CRITICAL]

Benjamin Paul Wiener, a 43-year-old Sioux Falls, South Dakota resident, was indicted in June 2026 on 29 federal counts including wire fraud, money laundering, bank fraud, and aggravated identity theft. Prosecutors allege he operated a Ponzi-style cryptocurrency investment scheme through at least eight entities under the 'Benaiah' brand, raising approximately $25.1 million from dozens of investors primarily in South Dakota and Minnesota, resulting in estimated losses of approximately $20 million. Wiener pleaded not guilty on July 10, 2026, and trial is scheduled for September 15, 2026; all allegations remain unproven in court.

avoid.net/jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys0/100[CRITICAL]

JADEPUFFER is a threat actor and ransomware campaign documented by Sysdig's Threat Research Team in July 2026, assessed as the first confirmed end-to-end autonomous ransomware operation directed by a large language model (LLM) rather than a human operator at each step. The attack exploited CVE-2025-3248, a critical unauthenticated remote code execution flaw in the Langflow AI workflow platform, and the LLM agent autonomously conducted reconnaissance, swept for cryptocurrency wallet private keys and seed phrases alongside other credentials, moved laterally, encrypted a production database, and delivered a ransom demand — all without human direction of individual steps. A follow-on variant named ENCFORGE, attributed to the same operator, subsequently targeted AI model weights and training datasets on Langflow-exposed hosts, and approximately 1,050 Langflow instances remained publicly reachable at time of Sysdig's disclosure.

avoid.net/aurum-foundation2/100[CRITICAL]

Aurum Foundation is a Dubai-based MLM crypto Ponzi scheme that launched in mid-2024, promising monthly returns of 9.48% to 15.01% through an alleged AI trading bot called EX-AI, with no on-chain evidence of genuine trading activity. The scheme attracted regulatory fraud warnings from at least ten jurisdictions across Europe, Asia, Africa, and Oceania before collapsing on July 30, 2026, with operators issuing a 'we got hacked' announcement widely characterized as a classic exit-scam cover story. On-chain analysis identified approximately $31.7 million transiting through core wallets over a 17-day window, consistent with redistribution to early investors rather than external trading profits.

avoid.net/blazestake73/100[CAUTIONARY]

BlazeStake, operated by the pseudonymous SolBlaze team, is a non-custodial Solana liquid staking protocol that issues bSOL against SOL delegated across 200+ validators. It runs on Solana Labs' audited stake-pool program, discloses eight third-party audits of that shared program, and is described by its own documentation as governed by an ecosystem multisig overseen by the Solana Foundation, though the composition of that multisig and specifics of admin-key controls are not publicly itemized in available sources. No hacks, exploits, or regulatory actions against BlazeStake specifically have been found. The most material adverse event on record remains the April 2024 public dispute with MarginFi over reward-token distribution, which was reportedly resolved; a March 2026 joint SEC/CFTC statement classifying liquid staking as generally non-securities activity reduces regulatory tail risk for the category as a whole.

avoid.net/bitpin2/100[CRITICAL]

Bitpin (legal name: Sana Ayman Mubadala) is an Iranian cryptocurrency exchange established in 2020 and headquartered in the Anzali Free Zone, Gilan province, Iran. On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Bitpin under Executive Orders 13224 and 13902 as part of the broader Economic Fury campaign, citing alleged processing of millions of dollars in IRGC-linked transactions and alleged investor connections to U.S. sanctions evasion. Bitpin handled approximately 10 percent of Iran's digital asset inflows in 2025, representing an estimated USD 821 million in volume.

avoid.net/huang-xingshan2/100[CRITICAL]

Huang Xingshan (also known as Ah Zhe and Huang Xing Saan) is a Chinese national charged by the U.S. Department of Justice on April 23, 2026, with wire fraud conspiracy for co-managing Shunda Park, an industrial-scale pig-butchering cryptocurrency fraud compound in Karen State, Myanmar. Prosecutors allege he served as a high-level manager and enforcer who personally participated in the physical punishment of trafficked workers. He was arrested by Thai authorities in early 2026 on immigration charges and remains in Thai custody while the U.S. pursues extradition.

avoid.net/zero-network-zerion-l238/100[WARNING]

Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.

avoid.net/mastra-ai-npm-supply-chain-attack-june-20260/100[CRITICAL]

On June 17, 2026, attackers hijacked a dormant npm contributor account ('ehindero') to inject a malicious dependency ('easy-day-js') into 140+ packages across the @mastra npm scope, affecting an estimated 1.1 million+ weekly downloads. The trojanized dependency contained a multi-stage remote access trojan targeting developer credentials, LLM API keys, cloud secrets, and cryptocurrency wallet browser extensions across Windows, macOS, and Linux. Mastra and npm responded within hours by revoking the compromised account, unpublishing malicious versions, and forward-rolling clean releases.

avoid.net/jiang-wen-jie2/100[CRITICAL]

Jiang Wen Jie (also known as Jiang Nan) is a Chinese national charged by the U.S. Department of Justice on April 23, 2026, with wire fraud conspiracy for his alleged role as a team leader at Shunda Park, a pig-butchering scam compound that operated in Min Let Pan, Myanmar, from at least January to November 2025. Under Jiang's alleged supervision, trafficked workers were coerced into defrauding American victims through fake cryptocurrency investment platforms, with at least one victim losing over $3 million to a single scammer under his command. Jiang was arrested by Thai authorities in early 2026 on immigration charges while allegedly attempting to return to Myanmar after relocating to Cambodia following the Karen National Liberation Army's seizure of Shunda Park, and he remains in Thai custody as the DOJ pursues extradition.

avoid.net/coinrail12/100[CRITICAL]

Coinrail was a small South Korean cryptocurrency exchange that suffered a major security breach on June 10, 2018, resulting in the theft of approximately $40 million worth of ERC-20 tokens including NPXS (Pundi X), ATX (Aston X), DENT, and others. The incident triggered a broader cryptocurrency market sell-off, contributing to a loss of over $40 billion in total crypto market capitalization. Following the hack, Coinrail suspended trading operations and cooperated with South Korean law enforcement; the exchange subsequently transitioned to an offline platform and never fully resumed normal operations.

avoid.net/marinade-finance79/100[VERIFIED]

Marinade Finance is a non-custodial liquid staking protocol on Solana, launched on mainnet August 2, 2021. It operates two primary products — mSOL (liquid staking) and Marinade Native (non-liquid delegation) — and as of mid-2025 held approximately 10–11 million SOL in total staked value, making it one of Solana's largest staking providers. The protocol is governed by MNDE token holders via an on-chain DAO and has compiled a clean auditing track record with no confirmed exploits as of the investigation date.

avoid.net/cryptojs-ill-bloom-weak-rng-multi-wallet-drain-cve-2026-718514/100[CRITICAL]

CVE-2026-71851, designated 'Ill Bloom' by Coinspect, is a critical (CVSS 9.0) cryptographic vulnerability in the crypto-js npm library affecting versions 3.1.2-4 through 3.3.x, in which the library's CryptoJS.lib.WordArray.random() function used a Math.random()-seeded Multiply-With-Carry algorithm rather than a cryptographically secure PRNG, collapsing intended 128-bit entropy to approximately 2^39 bits. Active exploitation was identified from May 27, 2026, with measured losses of at least $5.69 million across at least 2,114 vulnerable wallet addresses tied to five named applications: RRWallet, Milo (both discontinued), Bexo Wallet, NanChat, and Bitcoin Libre. Public CVE disclosure occurred on August 5–7, 2026, following a staged disclosure process by Coinspect.

ZachXBT Intelligence · Backfilled

3
avoid.net/trezor57/100[CAUTIONARY]

Trezor is a legitimate Prague-based hardware wallet manufacturer (SatoshiLabs) and one of the oldest in the industry, but it has accumulated a significant threat ecosystem around its brand. A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps. Trezor hardware devices have also been subject to disclosed physical attack vectors, including an alleged unpatchable flaw in the STM32 microcontroller used in the Trezor T model.

avoid.net/coinspaid62/100[CAUTIONARY]

CoinsPaid (operating legal entity Dream Finance OÜ, headquartered in Tallinn, Estonia) is a business-to-business crypto payment processing platform founded in 2014 by Max Krupyshev and Pavel Kashuba. The company suffered two confirmed external cyberattacks — a $37.3 million theft in July 2023 and a $7.5 million breach in January 2024 — both attributed to third-party attackers with the first definitively linked to North Korea's Lazarus Group by blockchain analysts and the FBI; client funds were reported unaffected in both incidents. The company is currently navigating significant regulatory uncertainty under the EU's MiCA framework after losing its legacy Estonian FIU licence and suspending operations through its Lithuanian entity, while its CASP application in Estonia remains pending as of mid-2026.

avoid.net/ninamo71/100[CAUTIONARY]

Ninamo is a purported crypto entity whose name was submitted for investigation on AVOID.NET. Exhaustive searches across regulatory databases, blockchain explorers, crypto news outlets, scam trackers, social media platforms, domain registries, and the Wayback Machine returned no verifiable information about any crypto project, exchange, token, or DeFi protocol operating under the name Ninamo. No wallet addresses, enforcement actions, community reports, or archived web presence could be located.

200 entities tracked · record updated 2026-08
Page transparency log
Last updated fingerprint: CmrCks…Vo71