Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
Zeus Network is a Solana-based protocol (token ticker ZEUS, mint ZEUS1aR7aX8DFFJf5QjWj2ftDDdNTroMNGo8YoQm3Gq) that markets itself as a permissionless Bitcoin-to-Solana bridge, minting a 1:1 Bitcoin-pegged asset called zBTC via its APOLLO application and Zeus Program Library (ZPL). The project raised roughly $8 million from named venture funds and angel investors, including Solana co-founder Anatoly Yakovenko, and its ZEUS token has fallen approximately 99.7% from its April 2024 all-time high, trading at fractions of a cent as of July 2026. A set of specific abandonment allegations attributed to a social-media watchdog account (deleted Discord, an unconfirmed Astarter "acquisition," an unreachable team, disabled comments) could not be independently corroborated from verifiable sources at the time of this review; on the contrary, available evidence points to an active, if commercially struggling, project rather than a confirmed rug pull or exit scam.
avoid.net/janus-henderson-anemoy-aaa-clo-fund-jaaa→72/100[CAUTIONARY]The Janus Henderson Anemoy AAA CLO Fund (JAAA) is a tokenized real-world asset fund providing on-chain exposure to AAA-rated tranches of Collateralized Loan Obligations (CLOs), actively managed by Janus Henderson Investors U.S. LLC as sub-advisor and issued by Anemoy Capital SPC Limited, a British Virgin Islands regulated professional fund. Launched in June 2025 with a $1 billion seed allocation from the Sky/MakerDAO ecosystem via the Grove DeFi protocol, the tokenized fund had approximately $686 million in assets under management as of June 2026. The fund is restricted to non-US qualified institutional investors who pass KYC/AML onboarding via the Centrifuge platform, and carries inherent risks from CLO market credit spreads, smart contract infrastructure, cross-jurisdictional regulatory uncertainty, and stablecoin dependency.
avoid.net/invesco-short-duration-us-government-securities-fund-ustb→78/100[VERIFIED]USTB is a tokenized short-duration U.S. Treasury fund originally launched by Superstate in February 2024 and transitioned to Invesco Advisers, Inc. as investment manager in mid-2026. As of July 2026, the fund holds approximately $682 million in AUM, is deployed on Ethereum, Solana, and Plume, and is restricted to accredited investors and qualified purchasers. It operates as a private Section 3(c)(7) fund under a Regulation D Rule 506(c) exemption and has no record of regulatory enforcement actions, fraud allegations, or security incidents.
avoid.net/spiko-amundi-overnight-swap-fund-eur→78/100[VERIFIED]The Spiko Amundi Overnight Swap Fund EUR (ticker: eurSAFO) is a tokenized UCITS money market fund launched in March 2026, co-developed by French fintech Spiko and Amundi, Europe's largest asset manager with approximately €2.4 trillion under management. The EUR share class is regulated by France's Autorité des Marchés Financiers (AMF) and operates as a sub-fund of SPIKO SICAV, using fully collateralized total return swaps with Tier 1 bank counterparties to deliver yields above overnight benchmarks. As of mid-2026, eurSAFO had approximately $830 million in total asset value across five blockchain networks, ranking among the largest tokenized RWA funds globally.
avoid.net/janus-henderson-anemoy-treasury-fund-jtrsy→82/100[VERIFIED]The Janus Henderson Anemoy Treasury Fund (JTRSY) is a tokenized British Virgin Islands professional fund that invests exclusively in short-term U.S. Treasury Bills with maturities under six months, issued on-chain via the Centrifuge protocol. The fund is regulated by the BVI Financial Services Commission, managed by Anemoy Asset Management with Janus Henderson Investors as sub-investment manager, and has received top-tier credit ratings including AA+f/S1+ from S&P Global Ratings as of March 2025. Access is restricted to non-U.S. professional investors and qualified crypto institutions, with subscriptions and redemptions settled in USDC.
avoid.net/usdgo→74/100[CAUTIONARY]USDGO is a USD-pegged enterprise stablecoin launched in February 2026, issued by Anchorage Digital Bank N.A. (the first federally chartered crypto bank in the United States) and branded and distributed by Hong Kong-listed OSL Group. As of July 2026 its circulating supply surpassed $1 billion, placing it among the top six regulated stablecoins globally. No fraud allegations, regulatory actions, or enforcement proceedings have been identified against the issuer or distributor in connection with USDGO.
avoid.net/spiko-eu-t-bills-money-market-fund→78/100[VERIFIED]Spiko EU T-Bills Money Market Fund (ticker: EUTBL) is a tokenized money market fund structured as a UCITS sub-fund of the Spiko SICAV, investing exclusively in short-term Eurozone sovereign Treasury Bills. It is regulated by the French Autorité des marchés financiers (AMF), managed by Twenty First Capital, and custodied by CACEIS Bank (a Credit Agricole subsidiary). As of July 2026 it ranks approximately #64 by market capitalization on CoinGecko with over $1 billion in assets under management, making it one of the largest tokenized real-world asset (RWA) products in Europe. No fraud, hack, or regulatory enforcement actions have been identified against Spiko or the fund.
avoid.net/usx→62/100[CAUTIONARY]USX is a Solana-native synthetic stablecoin issued by Solstice Finance, a DeFi protocol incubated by Deus X Capital, a $1 billion institutional digital-asset investment firm. Launched on September 30, 2025 with $160 million in TVL, USX is backed 1:1 by a diversified reserve of USDC, USDT, tokenized Treasuries, and delta-neutral hedged positions, with reserves attested in real time via Chainlink and Accountable. In December 2025, USX briefly depegged to $0.10 on secondary Solana DEX markets due to a liquidity crunch; the issuer attributed the event to secondary-market illiquidity rather than collateral failure, and USX subsequently restabilized near $1.00.
avoid.net/ylds→68/100[CAUTIONARY]YLDS is a yield-bearing, SEC-registered debt security issued as a tokenized face-amount certificate by Figure Certificate Company (FCC), a wholly owned subsidiary of Figure Technology Solutions, Inc. (Nasdaq: FIGR). It is the first interest-bearing transferable stablecoin to be registered under the U.S. Investment Company Act of 1940, and as of mid-2026 has approximately $540 million in circulation across Provenance Blockchain, Solana, Stellar, and Sui. While the product carries legitimate regulatory backing, parent company Figure Technology Solutions faces outstanding short-seller allegations regarding blockchain misrepresentation, lending quality, and a significant 2026 data breach affecting nearly one million customers.
avoid.net/audiera-beat→32/100[WARNING]Audiera is a BNB Chain-based Web3 gaming and music platform that markets itself as the blockchain evolution of the Audition rhythm game franchise, issuing the BEAT token at TGE in November 2025. The project has attracted significant speculative trading volume, reaching a market cap briefly exceeding $2 billion in June 2026 before collapsing approximately 88% within days, raising pump-and-dump concerns among analysts. Key risk factors include anonymous or undisclosed founding team, unverified IP licensing claims relating to the original Audition game IP owned by T3 Entertainment, concentrated token distribution, and derivative-driven price action disconnected from measurable user adoption.
avoid.net/adi→52/100[CAUTIONARY]ADI is the native utility token of ADI Chain, an Ethereum-compatible Layer 2 blockchain developed by Abu Dhabi-based ADI Foundation, a unit of Sirius International Holding — the digital arm of International Holding Company (IHC), a $240 billion UAE conglomerate chaired by Sheikh Tahnoon bin Zayed Al Nahyan, brother of the UAE president. Mainnet launched December 9, 2025, with the token listing simultaneously on Kraken, KuCoin, and Crypto.com; as of July 2026 it ranked approximately #69–#74 by market cap with a valuation near $840 million. The project carries meaningful institutional backing and regulatory legitimacy through a UAE Central Bank-approved dirham stablecoin and MoUs with BlackRock, Mastercard, and Franklin Templeton, but is offset by governance opacity in its parent conglomerate, an associated prediction-market subsidiary whose CEO has documented ties to the Qatargate corruption scandal, a principal executive who settled insider-trading charges with India's SEBI in 2025, and undisclosed investors in a July 2026 $50 million fundraise.
avoid.net/united-stables-u→48/100[WARNING]United Stables is a USD-pegged stablecoin issued by United Stables Limited (registered in the British Virgin Islands), operating under the ticker symbol U. Launched in December 2025 on BNB Chain and Ethereum, it reached approximately $1 billion in circulating supply by mid-2026, ranking among the top-100 cryptocurrencies by market cap. The issuer explicitly states it holds no regulatory licenses under MiCA, Hong Kong stablecoin law, or the US GENIUS Act, and the public leadership profile is extremely limited, with the CEO identified only as 'Athena Y.'
avoid.net/bfusd→52/100[CAUTIONARY]BFUSD is a reward-bearing margin asset launched by Binance Futures in November 2024, designed exclusively for use as collateral in USDT-M Futures trading. It is not a blockchain token, cannot be withdrawn from Binance, and generates yield through delta-neutral funding-fee strategies and ETH staking. While Binance maintains a reserve fund and transparency dashboard, the product carries significant concentrated counterparty risk tied to Binance's centralized custody model and its operator's prior criminal guilty plea on AML charges in 2023.
avoid.net/pax-gold-paxg→72/100[CAUTIONARY]PAX Gold (PAXG) is a regulated, gold-backed ERC-20 token issued by Paxos Trust Company, launched in September 2019, where each token represents one fine troy ounce of physical gold stored in Brink's vaults in London. Paxos holds a national trust charter from the U.S. Office of the Comptroller of the Currency (OCC) as of December 2025, and publishes monthly third-party attestation reports via KPMG. The issuing entity, Paxos Trust Company, entered a $48.5 million settlement with the New York Department of Financial Services (NYDFS) in August 2025 over anti-money laundering failures tied to its prior BUSD stablecoin business, which does not directly implicate PAXG but reflects compliance weaknesses at the parent firm.
avoid.net/ondo-us-dollar-yield-usdy→72/100[CAUTIONARY]Ondo US Dollar Yield (USDY) is a tokenized yield-bearing note issued by Ondo USDY LLC, a Delaware bankruptcy-remote special purpose vehicle affiliated with Ondo Finance, and backed by short-duration U.S. Treasuries, iShares Short Treasury Bond ETF shares, and bank demand deposits. The token is offered exclusively to non-U.S. persons under a Regulation S exemption, accrues yield through a rising token price or daily rebasing, and had grown to approximately $740 million in supply across ten blockchains as of early 2026. A two-year SEC investigation into Ondo Finance was closed without charges in December 2025, though ongoing risks include centralized price-setting infrastructure, limited FDIC deposit coverage on a portion of reserves, and access and composability constraints imposed by the token's on-chain allowlist system.
avoid.net/tether-gold-xaut→44/100[WARNING]Tether Gold (XAUT) is a commodity-backed digital token issued by TG Commodities, S.A. de C.V., a subsidiary of Tether Holdings, where each token represents one troy fine ounce of physical gold stored in LBMA-certified Swiss vaults. The product ranks among the top tokenized gold assets by market capitalization, with approximately 375,000 troy ounces of gold backing circulation as of mid-2025. Its parent company, Tether Limited, has settled enforcement actions with the CFTC and the New York Attorney General over misrepresentation of its USDT stablecoin reserves, and remained under an active DOJ probe as of late 2024 into alleged sanctions and anti-money laundering violations.
avoid.net/falcon-usd-usdf→42/100[WARNING]Falcon USD (USDf) is a synthetic overcollateralized dollar token issued by Falcon Finance, a protocol incubated and backed by DWF Labs, launched publicly on April 30, 2025. As of mid-2026, USDf holds a market capitalization of approximately $1.4 billion, ranking it among the top synthetic stablecoins. The protocol has attracted significant scrutiny due to its parent firm DWF Labs facing alleged market manipulation and wash trading charges, a notable depeg event in July 2025, opaque off-chain reserve management, and concerns raised by independent DeFi risk researchers over collateral quality and centralized control.
avoid.net/ripple-usd-rlusd→74/100[CAUTIONARY]Ripple USD (RLUSD) is a U.S. dollar-pegged stablecoin issued by Standard Custody & Trust Company, LLC, a wholly owned subsidiary of Ripple Labs, under a limited-purpose trust company charter granted by the New York Department of Financial Services (NYDFS). It launched on December 17, 2024, following formal regulatory approval, and had grown to approximately $1.5 billion in circulating supply as of July 2026. RLUSD carries standard centralization and counterparty risks inherent to issuer-controlled fiat-backed stablecoins, including administrative freeze and blacklist capabilities, but is backed by monthly Deloitte attestations, BNY Mellon custody of reserves, and a clear regulatory framework.
avoid.net/blackrock-usd-institutional-digital-liquidity-fund→82/100[VERIFIED]BUIDL is a tokenized U.S. dollar money market fund managed by BlackRock and issued on public blockchains through tokenization platform and transfer agent Securitize. Launched on Ethereum in March 2024, it holds cash, U.S. Treasury bills, and repurchase agreements, is custodied by Bank of New York Mellon, and is offered as a private placement restricted to accredited/qualified institutional investors rather than as a retail SEC-registered security. It has grown into the largest tokenized U.S. Treasury fund by assets under management, but access, redemption, and transfer are gated by centralized whitelisting and freeze controls typical of permissioned real-world-asset (RWA) tokens.
avoid.net/paypal-usd→68/100[CAUTIONARY]PayPal USD (PYUSD) is a US dollar-pegged stablecoin issued by Paxos Trust Company, a New York-chartered limited purpose trust company regulated by the NYDFS, and marketed by PayPal. Reserves are attested monthly by an independent accounting firm and are held in cash and short-term US Treasuries, with redemption rights subject to Paxos and PayPal compliance review. PYUSD carries the same centralization risks common to bank-issued stablecoins (issuer freeze and address-wipe functions) and its issuer, Paxos, has a prior NYDFS enforcement history tied to its Binance-branded BUSD stablecoin, though PYUSD itself has not been the subject of a depeg event, and a 2023 SEC subpoena into PYUSD was closed in February 2025 without enforcement action.
avoid.net/global-dollar→68/100[CAUTIONARY]Global Dollar (USDG) is a fiat-backed stablecoin issued by Paxos Digital Singapore Pte. Ltd. and regulated by the Monetary Authority of Singapore, launched in November 2024 to anchor the Global Dollar Network (GDN), a consortium of exchanges and fintechs including Robinhood, Kraken, Galaxy Digital, Anchorage Digital, Bullish, Nuvei, and Visa. USDG differentiates itself from USDT and USDC by sharing reserve yield with network partners rather than retaining it at the issuer, and publishes monthly third-party reserve attestations. The stablecoin itself has no confirmed depeg incidents or direct regulatory enforcement action to date, but its issuer, Paxos, has a documented history of AML/KYC compliance failures tied to the BUSD stablecoin, and USDG's yield-distribution model sits in a regulatory gray area under the GENIUS Act's interest-payment prohibitions that lawmakers and banking groups are actively seeking to close.
avoid.net/lighter→62/100[CAUTIONARY]Lighter is a venture-backed, zero-fee perpetual futures decentralized exchange built as a custom zero-knowledge rollup on Ethereum, founded by former Citadel engineer Vladimir Novakovski. It has raised roughly $89 million from high-profile investors including Founders Fund, Ribbit Capital, Haun Ventures, Craft Ventures, Dragonfly and Robinhood Markets, reaching a $1.5 billion valuation, and briefly ranked among the top perpetuals DEXs by volume. The platform has drawn scrutiny over post-token-launch withdrawal delays, a front-end chart-manipulation controversy following a bot-driven price spike, heavy team/investor token allocation, and a sharp decline in trading volume and user activity after its December 2025 airdrop.
avoid.net/gho→61/100[CAUTIONARY]GHO is a decentralized, crypto-collateralized stablecoin native to the Aave protocol, launched in July 2023 and minted through governance-approved 'Facilitators.' The token suffered a prolonged sub-$1 depeg for roughly seven months after launch and a sharper flash depeg during the July 2023 Curve Finance exploit, before stabilizing near $1.00 in 2024–2026 following the introduction of a Peg Stability Module-style mechanism. As of mid-2026, GHO's peg is largely stable and its supply has grown to roughly $500–650 million, but the protocol carries residual risks tied to collateral concentration, stablecoin-backed peg defenses, and recent turmoil in Aave DAO governance following the exit of the Aave Chan Initiative, a delegate that had driven much of GHO's growth.
avoid.net/usds→63/100[CAUTIONARY]USDS is the primary stablecoin of Sky (formerly MakerDAO), launched in September 2024 as the successor to DAI within Sky's product line, with holders able to convert 1:1 between the two tokens. USDS is over-collateralized by a mix of crypto assets, USDC held via peg stability modules, and tokenized real-world assets including U.S. Treasuries, but it has drawn recurring criticism over a wallet-freezing capability, a custody arrangement for hundreds of millions of dollars in reserves that relied on a single externally-owned wallet, and rising governance complexity under Sky's 'Endgame' restructuring. No confirmed hack or sustained depeg of USDS itself has been documented as of this writing, though it inherits pass-through depeg risk from its USDC backing.
avoid.net/binancelife→28/100[WARNING]BinanceLife (币安人生, ticker 币安人生/BINANCELIFE) is a Chinese-language meme token launched on the BNB Smart Chain via the Four.meme launchpad on October 4, 2025. It has no affiliation with the Binance exchange, Binance founder Changpeng Zhao (CZ), or CZ's memoir of the same Chinese title, despite its name and branding closely evoking Binance. The token operated for months with no official website, no verified team, and heavily concentrated token holdings, yet was nonetheless listed on Binance Alpha and later Binance's spot market, raising concerns about the risk of retail investors mistaking it for an official Binance-affiliated asset.
avoid.net/usdd→28/100[WARNING]USDD is a stablecoin issued by the TRON DAO Reserve, launched in May 2022 and marketed as an over-collateralized, algorithmically-assisted alternative to Terra's failed UST. USDD de-pegged from its $1.00 target within weeks of launch and again during the November 2022 FTX collapse, and has since faced sustained criticism over opaque, shifting reserve composition, a defunct governance structure, and the concentration of control and collateral around TRON founder Justin Sun and his exchange HTX. Independent stablecoin rating firm Bluechip assigned USDD the lowest grade ('F') among stablecoins it assessed, citing commingled reserves and an absence of functioning decentralized governance.
avoid.net/usd1→38/100[WARNING]USD1 is a U.S. dollar-pegged stablecoin launched in March 2025 by World Liberty Financial (WLFI), a DeFi project with direct financial ties to the Trump family. Reserves are custodied by BitGo Trust Company and attested to monthly by Crowe LLP, but the coin has drawn scrutiny for delayed attestation reports, heavy offshore concentration, an unresolved conflict-of-interest controversy tied to a $2 billion MGX-Binance transaction, a June 2026 exchange delisting following an address freeze, and open questions about whether its issuance structure complies with the GENIUS Act. As of July 2026 it ranks among the largest stablecoins by market capitalization, though its governance is entangled with the political and business interests of a sitting U.S. president's family.
avoid.net/world-liberty-financial-wlfi→22/100[CRITICAL]World Liberty Financial (WLFI) is a DeFi protocol and stablecoin issuer co-founded in 2024 by members of the Trump family and the Witkoff family, along with crypto entrepreneurs Chase Herro and Zachary Folkman. The project has raised approximately $550 million through governance token sales and issued the USD1 stablecoin, which reached roughly $4.6 billion in circulating supply by mid-2026. The project has attracted sustained congressional scrutiny, multiple Senate-requested federal probes, a high-profile lawsuit from one of its largest investors, allegations of token sales to sanctioned entities, and documented conflicts of interest tied to the sitting U.S. president's direct financial stake in the venture.
avoid.net/teleswap→32/100[WARNING]TeleSwap (formerly TeleportDAO) is a cross-chain bridge protocol that lets users move Bitcoin and Runes to EVM chains, TON, and Solana using light-client and "Locker"/"Teleporter" custodian architecture, funded by a $2.5M 2023 seed round and a 2024 public token sale. On July 15, 2026, on-chain investigator ZachXBT and the SlowMist Hacked incident database reported suspicious outflows of roughly $735,000 from TeleSwap's Bitcoin hot wallet followed by laundering through Tornado Cash; as of this writing TeleSwap has not issued a public confirmation, technical postmortem, or the underlying transaction details, which is itself a notable transparency concern. Overall reporting quality on the incident is thin — it traces back mainly to one investigator's claim and aggregator write-ups rather than a project statement, a named security-firm root-cause report, or Tier-1 news coverage, so key facts (attack vector, exact amount, affected users) remain unverified.
avoid.net/barnbridge→12/100[CRITICAL]BarnBridge was an Ethereum-based DeFi protocol, structured as a DAO, best known for its SMART Yield product, which tranched variable-rate yield from lending markets like Compound and Aave into fixed and variable risk classes. The protocol halted operations in mid-2023 after founders disclosed an SEC investigation, and BarnBridge DAO and its two founders settled with the SEC in December 2023 for $1.7 million over unregistered offer and sale of crypto asset securities and unregistered investment company violations. On July 15, 2026, despite being effectively defunct, BarnBridge's SMART Yield governance and legacy token approvals were exploited in a governance-takeover attack that drained approximately $776,000 in USDC from roughly 50 wallets; the attacker reportedly spent only about $600 to acquire enough BOND voting power to pass a malicious upgrade proposal through an inactive DAO. The scout flag characterizing this as a governance-attack incident is substantiated: the event is corroborated across multiple independent crypto-news outlets and an on-chain security firm, though as of this writing it lacks coverage from top-tier wire/legal press specific to the 2026 incident itself (the 2023 SEC action is Tier 1 sourced).
avoid.net/zilliqa→61/100[CAUTIONARY]Zilliqa is a Singapore-founded, sharded layer-1 blockchain launched in 2017 out of National University of Singapore research, with a track record of independent smart-contract audits and no history of SEC or DOJ enforcement action against the project itself. Its trust profile is weighed down by two distinct security incidents: a February 2025 exploit of Zilliqa's own X-Bridge token-manager contracts (protocol-level fault, roughly $42,000 realized loss) and a July 2026 theft of ZIL tokens from an exchange partner's cold wallet, which Zilliqa's own preliminary findings attribute to a technical flaw in legacy ZIL1 wallet transaction-signing rather than to the exchange's custody practices — a claim that as of this writing is corroborated by only one secondary source and remains unconfirmed by Zilliqa's promised full post-mortem.
avoid.net/bonkdao→30/100[WARNING]BonkDAO is the decentralized governance body overseeing the community treasury of BONK, a Solana-based dog-themed memecoin launched in December 2022. On July 6, 2026, BonkDAO's treasury was drained of approximately $20 million in BONK tokens after an attacker accumulated enough BONK on the open market (roughly $4-4.4 million worth) to win a governance vote (Realms proposal BIP #76) and authorize the transfer of about 4.426 trillion BONK to a wallet under their control. This was a governance/voting-power exploit rather than a smart-contract hack, and it was widely reported by mainstream and crypto-native outlets, giving the core facts high confidence; the identity of the attacker, ultimate fund recovery, and any compensation for the DAO remain unresolved as of the most recent reporting.
avoid.net/ledger-live→58/100[CAUTIONARY]Ledger Live is the official companion application published by Ledger SAS for managing Ledger hardware wallets. The genuine application itself has no documented vulnerabilities that have led to direct fund loss, but the "Ledger Live" name and branding have been repeatedly and successfully counterfeited on major app marketplaces (Apple App Store, Microsoft Store, Google Play, Chrome Web Store), resulting in tens of millions of dollars in alleged theft from users who mistook fake listings for the real app. Separately, a genuine Ledger-published software component in the same ecosystem (the Ledger Connect Kit library) was compromised in a December 2023 supply-chain attack that briefly redirected funds from users of dApps integrating with Ledger hardware wallets.
avoid.net/gmgn-ai→58/100[CAUTIONARY]GMGN.ai is a Singapore-based, primarily Chinese-run multi-chain memecoin trading terminal and Telegram trading bot, launched in mid-2023, focused on Solana, Ethereum, Base, and BNB Chain token discovery, smart-money wallet tracking, and copy trading. The platform states it is non-custodial and cannot move user wallet balances itself, but it carries a poor Trustpilot rating driven by complaints about copy-trading losses and unclear fees, and it has been the target of extensive phishing and impersonation campaigns — including fake mobile apps and cloned websites — that have drained victims' wallets. No confirmed breach of GMGN's own infrastructure or misappropriation of user funds by the company has been documented in available sources.
avoid.net/cavepay→18/100[CRITICAL]Cavepay (marketed at the domain cavepay.app and via a Telegram channel) presented itself as a multi-cryptocurrency wallet service. Independent, credible reporting on the project is essentially nonexistent: no Tier 1 or Tier 2 news coverage, regulatory action, or court records were found. The only substantive third-party assessment located is an automated scam-detection aggregator that flags the site for phishing and gives it the lowest possible trust rating, and the domain no longer resolves. Given the near-total absence of verifiable information, this page should be treated as low confidence — it documents red flags and an information vacuum rather than a confirmed fraud finding or a confirmed clean bill of health.
avoid.net/peter-stokes-scattered-spider→3/100[CRITICAL]Peter Stokes, 19, a dual U.S.-Estonian national, was arrested in Finland in April 2026 on an Interpol Red Notice and extradited to the United States on July 1, 2026 to face federal charges in the Northern District of Illinois for alleged membership in the Scattered Spider cybercrime collective. Prosecutors allege Stokes participated in a May 2025 social-engineering breach of an unnamed luxury jewelry retailer in which attackers reset an employee's two-factor authentication credentials via the company help desk, stole data, and demanded roughly $8 million in cryptocurrency. All allegations against Stokes are pending trial and unproven in court; Scattered Spider as a network has been linked by U.S. authorities to more than 100 corporate intrusions and over $100 million in crypto-denominated ransom and extortion payments.
avoid.net/knaken→4/100[CRITICAL]Knaken (Knaken Cryptohandel B.V.), a Rotterdam-based Dutch cryptocurrency exchange founded in 2017, was declared bankrupt by a Rotterdam court on July 16, 2026 after roughly €7 million in customer funds could not be accounted for. The platform, which had roughly 30,000 customers, went offline in early June 2026 after failing to obtain the license required under the EU's Markets in Crypto-Assets (MiCA) regulation, and is now the subject of a Dutch Public Prosecution Service (OM) criminal investigation into the missing funds.
avoid.net/benjamin-paul-wiener→8/100[CRITICAL]Benjamin Paul Wiener is a 43-year-old Sioux Falls, South Dakota resident and founder of the Benaiah group of investment entities who was indicted by a federal grand jury in June 2026 on 29 counts including wire fraud, bank fraud, money laundering, and aggravated identity theft, in connection with an alleged Ponzi-style scheme that solicited roughly $20-25 million from investors in cash and cryptocurrency. Wiener pleaded not guilty at his arraignment on July 10, 2026, and is scheduled for trial on September 15, 2026; the case is a pending criminal matter and Wiener is presumed innocent unless and until convicted. A separate, earlier-filed civil lawsuit and court-ordered asset freeze/receivership against Wiener's Benaiah entities alleges similar conduct and predates the criminal indictment.
avoid.net/summer-fi-lazy-summer-protocol→22/100[CRITICAL]Summer.fi, a DeFi yield-optimization platform formerly known as Oasis.app that spun out of the Maker Foundation in 2021, operated the DAO-governed Lazy Summer Protocol until a July 6, 2026 exploit drained roughly $6.04 million from two of its USDC vaults via a flash-loan-funded share-price manipulation of the Fleet Commander accounting contract. Summer.fi's own post-mortem attributes the loss to an operational oversight — an old, capped strategy that was never fully removed from vault net-asset-value calculations — rather than a smart-contract bug or compromised keys. The Summer.fi Labs company announced on July 15, 2026 that it would wind down and shut off its app by August 31, 2026, leaving user compensation and the fate of roughly $4 million in illiquid affected-vault holdings to a future Lazy Summer DAO governance vote.
avoid.net/injective-npm-sdk-supply-chain-attack→62/100[CAUTIONARY]On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.
avoid.net/wanchain→32/100[WARNING]Wanchain is a blockchain interoperability project founded in 2017 by Jack Lu that operates cross-chain bridges connecting networks such as Ethereum, BNB Chain, and Cardano. On July 21, 2026, Wanchain's Cardano-to-BNB Chain bridge was exploited for approximately $10 million (515.2 million NIGHT tokens) due to a signature-reuse flaw in its TreasuryCheck validator, one of the larger cross-chain bridge exploits of 2026. The incident caused a 30-40% intraday crash in the price of NIGHT (the token of the Cardano-affiliated Midnight blockchain) and prompted Wanchain to take its bridge offline while the Midnight Foundation publicly distanced its core network from the breach.
avoid.net/ostium→32/100[WARNING]Ostium is an Arbitrum-based decentralized perpetuals exchange, founded by Harvard alumni Kaledora Kiernan-Linn and Marco Antonio Ribeiro, that offers leveraged exposure to real-world assets such as commodities, FX, and indices. On July 15, 2026, the protocol lost an estimated $18-24 million after an attacker compromised an oracle signer's private key and pushed forged, future-dated BTC/USD price reports through a component (PriceUpKeep) that Ostium's own bug bounty program had explicitly excluded from scrutiny. Ostium halted trading within roughly an hour of detection, but as of the most recent reporting the protocol had not published a final loss figure, root-cause postmortem, or reimbursement plan for affected liquidity providers.
avoid.net/philippines-sec-multi-exchange-unlicensed-operations-enforcement→20/100[CRITICAL]In August 2025, the Philippine Securities and Exchange Commission (SEC) issued public advisories naming ten major global cryptocurrency exchanges — OKX, Bybit, KuCoin, Kraken, MEXC, Bitget, Phemex, CoinEx, BitMart, and Poloniex — as operating without mandatory Crypto Asset Service Provider (CASP) registration, and directed the National Telecommunications Commission (NTC) to instruct ISPs PLDT and Smart Communications to block access to these platforms. The action follows the July 5, 2025 effectivity of SEC Memorandum Circulars No. 4 and No. 5 (Series of 2025) which established the CASP regulatory framework. Filipino users of these platforms face inability to access funds through local ISPs, no legal recourse in Philippine courts, and exposure to fraud without regulatory protection.
avoid.net/north-korea-lazarus-group-h1-2026-systematic-crypto-theft-campaign→0/100[CRITICAL]North Korea-linked threat actors, operating under cluster names including Lazarus Group and TraderTraitor (UNC4736), are alleged to have stolen approximately $643 million in cryptocurrency during the first half of 2026 — representing roughly 66% of the $972 million stolen across 207 documented incidents globally in that period, according to blockchain intelligence firm TRM Labs. Two anchor attacks, the $285 million Drift Protocol exploit on April 1 and the $292 million KelpDAO bridge exploit on April 18, together accounted for approximately 59% of all H1 2026 crypto hack losses. Cumulative DPRK-attributed crypto theft since 2017 has now exceeded $6 billion across an estimated 270+ incidents, according to multiple blockchain intelligence firms.
avoid.net/trump-memecoin-presidential-conflict-of-interest-and-retail-losses→8/100[CRITICAL]The $TRUMP token is a Solana-based memecoin launched on January 17, 2025 — three days before President Donald Trump's inauguration — by two Trump-affiliated entities, CIC Digital LLC and Fight Fight Fight LLC, which collectively retained 80% of the 1-billion-token supply under a multi-year vesting schedule. Trump's June 2026 Office of Government Ethics financial disclosure reported $635 million in royalties from the token, funneled through a licensing agreement with an entity called 'Celebration Coins' for which no public digital footprint could be found. As the token collapsed more than 97% from its January 2025 peak of approximately $74, on-chain analysis by Chainalysis attributed losses of over $700 million to retail buyers across more than 764,000 wallets, while legal experts, Senate investigators, and ethics watchdogs raised alarms that the token's anonymous purchase mechanism created an untraceable channel for gifts and influence payments to a sitting president.
avoid.net/blockfills-reliz-technology-group-holdings→4/100[CRITICAL]BlockFills, a Chicago-based institutional crypto trading and lending firm operating through parent entity Reliz Technology Group Holdings, Inc., filed Chapter 11 bankruptcy on March 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware, reporting $50–100M in assets against $100–500M in liabilities. A central allegation — confirmed by debtors' own counsel at the first-day hearing — is that client funds were never segregated but were commingled with company funds on a single balance sheet, producing an estimated $77M deficit that renders clients unsecured creditors. In June 2026, Brussels-based market maker Keyrock agreed to acquire substantially all BlockFills assets for $3.25M, a figure that represents a fraction of total liabilities and raises serious doubts about meaningful client recovery.
avoid.net/mica-eu-mass-non-compliance-83-unlicensed-platform-risk→18/100[CRITICAL]The European Union's Markets in Crypto-Assets Regulation (MiCA) transitional grace period expired on July 1, 2026. Of approximately 1,200+ crypto firms that previously operated under national VASP registrations, only roughly 210–244 obtained full Crypto Asset Service Provider (CASP) authorization — a conversion rate of approximately 17–20%, leaving an estimated 83% operating in breach of EU law. ESMA confirmed on April 17, 2026 that no extensions would be granted and that unlicensed firms must cease EU services immediately; affected major exchanges include Binance (withdrew Greek application June 24, 2026), MEXC, Bitget, CoinEx, and others serving millions of European users.
avoid.net/wasabi-protocol→18/100[CRITICAL]Wasabi Protocol is a decentralized perpetual futures trading platform backed by Electric Capital, offering leveraged trading on long-tail assets including memecoins and NFTs across Ethereum, Base, Berachain, and Blast. On April 30, 2026, the protocol suffered an estimated $5–5.9 million exploit after an attacker compromised the sole deployer wallet (wasabideployer.eth), which held unchecked ADMIN_ROLE permissions across all upgradeable vault contracts with no multisig or timelock protections. The attacker drained all pool balances within approximately three minutes via UUPS proxy upgrades, subsequently routing the majority of funds through Tornado Cash.
avoid.net/trenton-johnston-crypto-social-engineering-theft-ring→2/100[CRITICAL]Trenton Richard David Johnston, a 20-year-old Canadian national, pleaded guilty on June 10, 2026 in U.S. District Court (Southern District of Florida) to conspiracy to commit money laundering in connection with a social engineering scheme that caused losses exceeding $13 million in cryptocurrency. Johnston operated as part of a broader theft ring — connected to 'The Com' hacker network — alongside co-conspirators including Miami resident Brandon Michael Tardibone and an uncharged individual identified by blockchain investigator ZachXBT as Dritan Kapllani Jr., who is alleged to be linked to approximately $19 million in total social engineering thefts. The scheme involved impersonating support representatives from Google, Trezor, and other crypto companies to trick victims into surrendering access to their digital wallets.
avoid.net/doj-global-pig-butchering-takedown-ko-thet-sanduo-giant-company→0/100[CRITICAL]In April and May 2026, the U.S. Department of Justice's Scam Center Strike Force, in coordination with the FBI, Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police, announced charges against six individuals operating three named cryptocurrency investment fraud organizations — Ko Thet Company, Sanduo Group, and Giant Company — as part of a coordinated global takedown that resulted in at least 276 arrests, dismantlement of nine scam centers, and restraint of over $701 million in cryptocurrency linked to money laundering. The operations are part of a broader law enforcement campaign against Southeast Asian pig-butchering fraud compounds that have been estimated to defraud Americans of billions of dollars annually, and are intertwined with human trafficking and forced labor.
avoid.net/polygon-zkevm→38/100[WARNING]Polygon zkEVM was a zero-knowledge rollup network launched in March 2023 by Polygon Labs, built upon the 2021 acquisition of Hermez Network for approximately $250 million in MATIC tokens. Despite early promise — including Vitalik Buterin processing the first transaction — the chain never achieved meaningful adoption, reportedly failed to implement the cost-reducing EIP-4844 blobs upgrade, and was shut down on July 1, 2026. Assets locked in DeFi smart contracts at the time of shutdown cannot be auto-migrated and may be permanently inaccessible.
avoid.net/zero-network-zerion-l2→38/100[WARNING]Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.
avoid.net/wojtek-kulisz-merry-sim-swap-crypto-theft-ring→2/100[CRITICAL]Wojtek Kulisz, known online as 'Merry', is a Polish national alleged by blockchain investigator ZachXBT to be among four individuals arrested in Poland on June 25, 2026, as part of a joint CBZC-FBI-HSI operation targeting an organized SIM swap crypto theft ring. The group is accused of breaching telecommunications infrastructure, hijacking victims' phone numbers, and draining cryptocurrency exchange accounts, with prosecutors estimating laundered funds in excess of tens of millions of Polish zlotys (approximately $5–$15 million USD). Polish authorities placed all four suspects in pretrial detention facing charges of participation in an organized criminal group, unauthorized computer system access, and money laundering, each carrying a maximum sentence of 25 years.
avoid.net/aztec-connect-deprecated-bridge-double-exploit-june-2026→20/100[CRITICAL]In June 2026, two separate deprecated Aztec infrastructure contracts on Ethereum were exploited within one week, draining a combined total of approximately $4.25 million. The first exploit, on June 14, targeted the legacy Aztec Connect rollup contract via a proof verification mismatch; a follow-on second attack on June 15 drained residual funds. A third, separate exploit on June 17-18 hit the deprecated Aztec Private Rollup Bridge's escapeHatch function. Aztec Labs stated it had renounced all admin keys over the affected contracts in April 2024 and that the incidents had no connection to the current Aztec Network or AZTEC ERC-20 token.
avoid.net/jonathan-spalletta-uranium-finance-exploiter→2/100[CRITICAL]Jonathan Spalletta, age 36, of Rockville, Maryland, was indicted by the U.S. Attorney's Office for the Southern District of New York on March 31, 2026 for allegedly executing two separate smart contract exploits against Uranium Finance in April 2021, draining a combined approximately $54.7 million across 26 BSC liquidity pools. He is charged with one count of computer fraud and one count of money laundering, carrying a combined maximum sentence of 30 years. Federal prosecutors allege Spalletta laundered proceeds through Tornado Cash, converted funds into rare collectibles, and negotiated a fraudulent bug bounty following the first exploit to conceal his involvement.
avoid.net/fake-trezor-support-social-engineering-282m-heist→0/100[CRITICAL]On January 10, 2026, an unidentified victim lost approximately $282 million in Bitcoin and Litecoin after an attacker impersonating Trezor 'Value Wallet' customer support convinced the victim to disclose their 24-word seed phrase, granting the attacker complete wallet access. This is the largest individual social engineering crypto theft ever recorded, surpassing the previous record of $243 million set in August 2024. Stolen funds were laundered through ThorChain, multiple instant exchanges, and converted predominantly into Monero, causing XMR to surge up to 80% in the days following the incident; no suspect has been publicly identified and full recovery is considered extremely unlikely.
avoid.net/paxful-ray-youssef→4/100[CRITICAL]Paxful Holdings Inc., once one of the world's largest peer-to-peer Bitcoin trading platforms, pleaded guilty in December 2025 to three federal criminal counts including conspiracy to violate the Travel Act by facilitating illegal prostitution, operating an unlicensed money transmitting business, and violating Bank Secrecy Act AML requirements. Co-founder and former CEO Ray Youssef was separately indicted by the DOJ in February 2026 on related charges and was deported from Mexico to Los Angeles for arraignment. The company shut down operations in November 2025, having admitted to knowingly processing funds linked to fraud, sex trafficking, child sexual abuse material distribution, and transactions with North Korean and Iranian state-sponsored actors.
avoid.net/nanobit-fake-crypto-platform-sec-pig-butchering-judgment→0/100[CRITICAL]NanoBit Limited was a fraudulent cryptocurrency trading platform operated from approximately September 2023 to June 2024 that defrauded at least 18 investors of nearly $1 million via a 'pig butchering' scheme conducted through WhatsApp groups. The U.S. Securities and Exchange Commission filed charges in September 2024 against four corporate entities and three individuals, and on June 16, 2026, the U.S. District Court for the Eastern District of New York entered a $5,518,902 default judgment — one of the SEC's first securities-fraud judgments against a fake-platform pig butchering operation — though recovery is considered essentially impossible as more than $2 million was wired to bank accounts in Hong Kong.
avoid.net/edel-finance→28/100[WARNING]Edel Finance is a decentralized lending protocol for tokenized equities, built as an Aave v3 fork on the Base/EVM network with an institutional Canton Network component, that launched mainnet on March 25, 2026. On July 1, 2026, the protocol suffered a flash-loan oracle manipulation exploit that drained approximately $403,000 from its xStock lending reserves, with stolen funds routed immediately to Tornado Cash. The protocol had also faced prior controversy in November 2025 over alleged insider acquisition of more than 30% of the EDEL token supply, contradicting stated tokenomics.
avoid.net/little-boy-plus-bsc-defi-logic-exploit→10/100[CRITICAL]Little Boy Plus (LBP) is a DeFi mining protocol on BNB Smart Chain that marketed itself as fully decentralized with no team, no pre-mine, and no admin keys, built around a fixed 21 million LBP token supply. On June 17–18, 2026, an attacker exploited a logic flaw in the protocol's LBPHashrate contract to artificially mint reward tokens and drain approximately $377,642 USDT (roughly 610.6 BNB) from the LBP/USDT PancakeSwap liquidity pair. No post-incident statement or recovery effort was announced by the project as of publication.
avoid.net/binance-mica-greece-application-withdrawal→32/100[WARNING]Binance, the world's largest cryptocurrency exchange by trading volume, withdrew its Markets in Crypto-Assets (MiCA) license application from Greece's Hellenic Capital Market Commission on June 24, 2026, days before the EU's July 1, 2026 compliance deadline, after reports indicated the regulator was preparing to reject the bid. The withdrawal triggered a suspension of services across all 27 EU member states effective July 1, 2026, affecting users in France, Italy, Poland, Spain, and other countries. Binance stated it intends to pursue MiCA authorization through another EU member state, with France cited as the most likely destination, though the exchange already faces an active judicial probe there over alleged money laundering and tax fraud.
avoid.net/mexc-exchange→32/100[WARNING]MEXC Exchange is a global cryptocurrency trading platform founded in 2018 and currently headquartered in the Seychelles. The exchange has accumulated regulatory warnings from multiple jurisdictions including Germany (BaFin), the Netherlands (AFM), Japan (FSA), Hong Kong (SFC), Estonia (FIU), and the Seychelles (FSA), primarily for operating without required authorizations. As of July 1, 2026, MEXC does not hold a MiCA Crypto-Asset Service Provider (CASP) license and formally exited the EU market, instructing EU users to withdraw funds before the deadline.
avoid.net/rowan-energy-david-duckworth-five-year-green-crypto-fraud→2/100[CRITICAL]Rowan Energy was a UK-based company founded by David Duckworth that marketed a blockchain-powered green energy rewards platform, selling SmartMiner hardware devices and the RWN token under the premise of tokenized renewable energy certificates. In April 2025, a white-hat researcher discovered a hidden token minting function and a suppressed token supply nearly double the publicly stated figure; Duckworth denied the allegations for 69 days before the company quietly shut down its blockchain on June 24–25, 2025, causing a greater than 99.9% collapse in RWN token value and leaving investors with no refund or recourse.
avoid.net/jaredfromsubway-eth-mev-bot-counter-honeypot-exploit→10/100[CRITICAL]JaredFromSubway.eth is a pseudonymously operated Ethereum MEV (Maximal Extractable Value) sandwich-attack bot that rose to infamy in 2023 and became responsible for an estimated 70% of all sandwich attacks on the Ethereum network between November 2024 and October 2025. On June 20, 2026, an unknown attacker reversed the bot's predatory logic against it, deploying 66 fake token contracts and fake liquidity pools to manipulate the bot into granting persistent token spending approvals, then sweeping approximately $7.5 million in WETH, USDC, and USDT in a single coordinated drain transaction. The stolen funds were subsequently routed through Tornado Cash, and the bot's operator — who offered a 50% white-hat bounty — has alleged they will pursue legal and law-enforcement remedies.
avoid.net/humanity-protocol-staged-hack-allegation-zachxbt→18/100[CRITICAL]Humanity Protocol is a Hong Kong-based proof-of-personhood blockchain project that raised $50 million at a $1.1 billion valuation before suffering a $32-36 million private key compromise on June 8-9, 2026. On-chain investigator ZachXBT publicly alleged the incident appeared 'possibly staged' as a coordinated exit, citing pre-hack token manipulation and suspicious market-maker activity; ZachXBT subsequently updated his assessment to separate the private key compromise from the alleged price manipulation, concluding both events likely occurred but may have been independent. The project's H token fell as much as 90% from its all-time high, wiping over $1 billion in market capitalization, and the BNB Chain token contract remained under attacker control as of mid-June 2026.
avoid.net/satori-finance→48/100[WARNING]Satori Finance was a decentralized perpetual futures exchange that raised $10 million in May 2022 from Polychain Capital, Coinbase Ventures, and Jump Crypto, and processed a reported $134 billion in cumulative trading volume before announcing its shutdown on June 16, 2026. The platform cited prolonged unfavorable market conditions and insufficient revenue as the reason for closure, giving users a 30-day window to withdraw funds before a hard deadline of July 16, 2026 at 23:59 UTC. No hacks, exploits, or fraud allegations have been substantiated; the shutdown appears to be an orderly wind-down of a VC-backed DeFi project that failed commercially.
avoid.net/leva-heal-limited-fake-ledger-live-app-apple-app-store→2/100[CRITICAL]Leva Heal Limited is a UK-registered company (Companies House number 12178110) whose Apple developer account was used to publish a fraudulent application impersonating Ledger Live on the macOS App Store between April 7 and April 13, 2026. The app harvested users' 24-word seed phrases, resulting in the theft of approximately $9.5 million in cryptocurrency from at least 50 victims. Apple removed the app and terminated the associated developer account on or around April 13-14, 2026, after community reports surfaced through on-chain investigator ZachXBT.
avoid.net/clawd-token-fake-clawdbot-ai-scam→2/100[CRITICAL]The $CLAWD token is a fraudulent Solana memecoin launched in January 2026 by unidentified actors who exploited a roughly 10-second window during the ClawdBot-to-Moltbot brand rename to seize the project's X handle and GitHub organization. Presenting the token as an official launch by the viral open-source AI project, the scammers drove the market cap to approximately $16 million before founder Peter Steinberger publicly denied any involvement and the token collapsed by roughly 90%. No attacker has been publicly identified and investor losses are considered unrecoverable.
avoid.net/stakedao→38/100[WARNING]StakeDAO is a DeFi protocol launched in January 2021 that provides liquid locking, yield strategies, and governance aggregation built primarily around Curve Finance's ecosystem on Ethereum and Arbitrum. On May 27, 2026, the protocol suffered a significant exploit when an attacker compromised its deployer private key and used it to reconfigure a LayerZero v2 OFT bridge peer, enabling the minting of approximately 5.44 trillion vsdCRV tokens on Arbitrum and the extraction of roughly $91,000 in ETH. The incident did not involve a smart contract vulnerability but exposed a critical operational security failure: the deployer key was a single point of failure with no multisig protection, no timelock, and was allegedly operated as a hot key inside automated infrastructure.
avoid.net/meteora-m3m3-token→18/100[CRITICAL]Meteora is a Solana-based decentralized exchange and liquidity protocol that, as of mid-2026, holds over $800 million in total value locked and accounts for approximately 26% of Solana DEX activity. The protocol and its co-founder Benjamin Chow are named defendants in two parallel federal class action lawsuits filed in the Southern District of New York, alleging a coordinated pump-and-dump scheme during the December 2024 launch of the M3M3 memecoin and a subsequent LIBRA token scheme in February 2025, with combined alleged investor losses exceeding $69 million. The M3M3 token has fallen more than 98% from its all-time high, and the amended complaint filed July 2025 broadens the alleged fraud enterprise to at least 15 token launches.
avoid.net/axiom-solana-dex→32/100[WARNING]Axiom is a Y Combinator-backed (Winter 2025 cohort) browser-based trading terminal for Solana, founded by Henry Zhang ('Mist') and Preston Ellis ('Cal'), that aggregates decentralized exchange liquidity and offers sub-400-millisecond execution for memecoin and perpetual futures trading. In February 2026, blockchain investigator ZachXBT published evidence that senior employees, primarily business development lead Broox Bauer, used internal admin dashboards to surveil private user wallet data and allegedly front-run profitable traders for more than ten months, netting an alleged $400,000 in illicit gains. Axiom acknowledged the misconduct, revoked tool access, and pledged an internal investigation, but as of late June 2026 no criminal charges have been filed, no formal user remediation program has been announced, and the platform continues to operate.
avoid.net/secret-network-axelar-bridge-exploit-june-2026→8/100[CRITICAL]On June 10, 2026, an attacker exploited a missing channel-origin validation in a customized CW20-ICS20 smart contract on Secret Network to mint approximately $4.67 million in unbacked Axelar-wrapped tokens (saTokens) and redeem them for real escrowed assets. The exploit went undetected for seven days due in part to Secret Network's privacy-by-default architecture, which encrypts account balances and masked the missing collateral until a failed cross-chain transfer on June 17 exposed the shortfall. Blockchain security firm Common Prefix traced the vulnerability to the contract's initial deployment in early 2023; a March 5, 2026 contract migration added new functionality but carried the unpatched validation flaw forward without a new security audit.
avoid.net/ko-thet-company-sanduo-group-giant-company-pig-butchering-network→0/100[CRITICAL]Ko Thet Company, Sanduo Group, and Giant Company are three alleged organized criminal enterprises that operated pig-butchering cryptocurrency fraud networks out of Southeast Asia, primarily targeting Americans. A coordinated international law enforcement operation announced April 29, 2026 resulted in at least 276 arrests across Dubai and Thailand, the shutdown of nine scam centers, the seizure of $701 million in cryptocurrency, and federal indictments unsealed in the Southern District of California against four named defendants and two fugitive co-conspirators. The FBI's companion initiative, Operation Level Up, identified approximately 9,000 victims and estimated $562 million in losses prevented.
avoid.net/courier-based-pig-butchering-scam-network-fbi-warning-june-2026→0/100[CRITICAL]In June 2026, the FBI's Internet Crime Complaint Center issued a formal public service announcement warning that cryptocurrency investment fraud operators — commonly operating 'pig butchering' schemes from forced-labor compounds in Southeast Asia — have adopted a physical courier variant to collect cash directly from victims when banks block electronic transfers. This hybrid approach uses in-person couriers authenticated via dollar bill serial numbers or pre-arranged passwords to collect cash from victims at their homes or public locations. Pig butchering scams caused Americans $11.37 billion in losses in 2025 alone, with the courier variant representing an escalation designed to circumvent traditional financial institution fraud controls.
avoid.net/loopring-dex-shutdown-june-2026→38/100[WARNING]Loopring, Ethereum's first zero-knowledge rollup decentralized exchange, permanently ceased all trading and relayer operations on June 28, 2026, citing lack of meaningful user adoption, architectural obsolescence relative to modern zkEVM competitors, and a cascade of major exchange delistings of its LRC token. The shutdown is notable for disabling the protocol's hallmark trustless self-custody exit mechanism in favor of a team-controlled batch distribution, raising concerns among DeFi researchers about the integrity of the protocol's security guarantees at the moment they matter most.
avoid.net/zcash-orchard-pool-counterfeiting-vulnerability→52/100[CAUTIONARY]A critical soundness vulnerability in Zcash's Orchard shielded pool was discovered on May 29, 2026 by security engineer Taylor Hornby using Anthropic's Opus 4.8 AI model. The flaw, present since the Orchard pool's activation in May 2022, could have allowed a malicious prover to generate unlimited counterfeit ZEC undetectably within the shielded pool. An emergency soft fork and subsequent NU6.2 hard fork patched the vulnerability by June 3, 2026, prior to public disclosure on June 5, 2026, after which ZEC declined approximately 38% in 24 hours.
avoid.net/shibarium-bridge→32/100[WARNING]The Shibarium Bridge is the Ethereum-to-Shibarium cross-chain bridge operated by the Shiba Inu ecosystem team, enabling transfer of SHIB, BONE, LEASH, and other tokens between Ethereum mainnet and the Shibarium Layer 2 network. The bridge suffered two major incidents: a chaotic launch in August 2023 that left approximately $1.7 million in ETH temporarily inaccessible, and a far more serious exploit in September 2025 in which attackers compromised 10 of 12 validator signing keys to drain approximately $3–4.1 million in assets. The bridge was partially restored in October 2025 following a security overhaul, but hack victims faced ongoing repayment delays and independent analysts raised persistent concerns about centralization and governance design.
avoid.net/june-2026-cross-chain-bridge-exploit-127m-three-protocols→10/100[CRITICAL]An alleged coordinated cross-chain bridge exploit on June 14, 2026 is described as draining $127 million from three DeFi protocols — identified only as BridgeLink, CrossFlow, and Relay Protocol — across Ethereum, Arbitrum, and Polygon in under 12 minutes. This specific incident, including the protocol names, the $127M figure, and the 03:42 UTC timestamp, cannot be independently verified through any Tier 1 or Tier 2 source as of June 30, 2026; the sole primary source is a blog post by Nadcab Labs, an Indian blockchain development services company with a commercial interest in publishing DeFi security content. While a severe pattern of verified cross-chain bridge exploits across 2026 provides real context, the specific claims in this investigation request should be treated as unverified until corroborated by credible on-chain analysis or major news coverage.
avoid.net/step-finance→22/100[CRITICAL]Step Finance was a Solana-based DeFi portfolio tracker and analytics dashboard founded in 2021, often described as the 'front page of Solana,' with approximately 300,000–350,000 monthly active users at its peak. On January 31, 2026, attackers compromised devices belonging to members of the executive team, gaining access to treasury and fee wallets and draining an estimated $27–40 million in digital assets. Unable to secure refinancing or an acquisition, the team announced a permanent shutdown on February 23, 2026, alongside affiliated projects SolanaFloor and Remora Markets.
avoid.net/q2-2026-bridge-exploit-wave→0/100[CRITICAL]The second quarter of 2026 (April–June) saw a record-breaking wave of cross-chain bridge exploits, with at least six distinct incidents draining approximately $340 million from bridge protocols alone, out of $755 million stolen across 83 crypto hacks industry-wide. The largest single events — the Drift Protocol ($285M) and KelpDAO LayerZero bridge ($292M) exploits — were attributed with medium confidence to North Korea's Lazarus Group / TraderTraitor subunit. Attack vectors ranged from social engineering of governance signers and RPC infrastructure poisoning, to smart contract proof-validation gaps and private key leakage.
avoid.net/huobi-htx→14/100[CRITICAL]HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.
avoid.net/a7a5-stablecoin-old-vector→0/100[CRITICAL]A7A5 is a Russian ruble-backed stablecoin issued by Old Vector LLC, a Kyrgyzstan-registered company incorporated in December 2024, operating on the Ethereum and TRON blockchains. It was created by A7 LLC, a Moscow-based cross-border payment firm 51%-owned by sanctioned Moldovan oligarch Ilan Shor and 49%-owned by Promsvyazbank, a sanctioned Russian state-owned bank. By mid-2026, A7A5 had processed over $110 billion in cumulative on-chain transactions, making it the subject of sanctions designations by the United States, European Union, United Kingdom, Canada, Switzerland, Ukraine, and other jurisdictions for its role in enabling Russian sanctions evasion and providing a settlement layer for entities seeking to bypass Western financial restrictions.
avoid.net/john-daghita→2/100[CRITICAL]John Daghita, a 22-year-old operating online under the alias 'Lick', is alleged to have stolen approximately $46 million in cryptocurrency from wallets controlled by the U.S. Marshals Service (USMS) by leveraging privileged access derived from his father's federal contracting firm, Command Services & Support (CMDSS). Daghita was arrested on Saint Martin in March 2026 following a joint FBI and French Gendarmerie operation triggered in part by blockchain investigator ZachXBT's public exposure of his wallet activity during a Telegram 'band-for-band' exchange. As of May 2026, a French appellate court approved extradition and Daghita consented to transfer to the United States to face federal charges.
avoid.net/thorchain-gg20-mpc-vault-exploit-may-2026→38/100[WARNING]On May 15, 2026, THORChain suffered a targeted cryptographic exploit in which a malicious node operator reconstructed a full private key from a single Asgard vault by exploiting incremental key material leakage in the GG20 Threshold Signature Scheme, draining approximately $10.7 to $11 million across nine blockchain networks. The protocol executed an automated and community-coordinated emergency halt, published a formal exploit report on May 21, 2026, and resumed trading on June 23, 2026, after a 39-day shutdown and an 11-stage security overhaul. The incident is the third major security breach in THORChain's history and exposed systemic risks in GG20-based MPC implementations.
avoid.net/q2-2026-record-crypto-hack-wave→0/100[CRITICAL]The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.
avoid.net/andean-medjedovic-kyberswap-indexed-finance-attacker→0/100[CRITICAL]Andean Medjedovic is a 22-year-old Canadian national indicted by the U.S. Department of Justice (Eastern District of New York) on February 3, 2025, for allegedly stealing approximately $65 million from two decentralized finance protocols — Indexed Finance ($16.5 million in October 2021) and KyberSwap ($48.4 million in November 2023) — through flash-loan manipulation and deceptive smart contract trading. He has been a fugitive since December 2021, was arrested in Belgrade, Serbia in August 2024 but released after extradition was denied, and was believed to be at large in Bosnia as of January 2025. A Washington D.C. lobbying firm filed documents in February 2026 seeking a U.S. presidential pardon on his behalf.
avoid.net/star-credit-holdings-misam-m-abidi→2/100[CRITICAL]Star Credit Holdings was a Tennessee-based cryptocurrency investment firm operated by Misam M. Abidi (age 47, of Nolensville, Tennessee) from approximately 2020 to 2024. On June 12, 2026, a federal grand jury in the Western District of Tennessee returned an 11-count indictment against Abidi, alleging he ran a classic Ponzi scheme that diverted over $1.9 million in investor funds to himself and family members. Abidi had previously faced state-level regulatory action in May 2024 over a broader alleged fraud involving Star Credit Holdings, a related cryptocurrency token (NUME/NumisMe), and co-defendants Ali Raza Galani and Anisha Abidi, with total alleged investor losses across 17 states exceeding $6.3 million.
avoid.net/axiom-dex-insider-trading-broox-bauer→14/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that Broox Bauer, a senior business development employee at Axiom Exchange — a Solana-based trading platform backed by Y Combinator — exploited internal dashboard access controls to retrieve private user wallet data and coordinate front-running trades over approximately ten months. The alleged scheme involved compiling key opinion leader (KOL) wallet addresses into shared Google Sheets to position ahead of anticipated price moves, with alleged profits cited at over $400,000. Axiom stated it was shocked, revoked access, and pledged an internal investigation; no independent forensic audit or formal regulatory action had been publicly announced as of June 2026.
avoid.net/zcash-orchard-pool-counterfeiting-vulnerability-2026→28/100[WARNING]On June 5, 2026, Shielded Labs publicly disclosed a critical soundness flaw in the zero-knowledge proof circuit of Zcash's Orchard shielded pool that had existed undetected since the pool's activation in May 2022. The vulnerability, found by security engineer Taylor Hornby using Anthropic's Claude Opus 4.8 AI model, could have allowed unlimited undetectable counterfeit ZEC minting with no on-chain signature; an emergency hard fork patched the circuit by June 3, 2026. Because Orchard's privacy design conceals transaction history, no cryptographic method exists to determine whether the flaw was exploited during the four years it was present, leaving the supply integrity of shielded ZEC permanently unverifiable for that period.
avoid.net/taiko-l2-bridge-exploit-june-2026→22/100[CRITICAL]On June 21–22, 2026, Taiko — an Ethereum-equivalent Layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million (roughly 870 ETH and 1.99 million TAIKO tokens) by forging cross-chain withdrawal proofs using an SGX enclave signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The team halted block production, froze bridge and ERC20Vault contracts, and pledged full 1:1 recollateralization before reopening. The incident is part of a broader 2026 pattern of bridge exploits totaling over $340 million across 14+ incidents.
avoid.net/abracadabra-money-mim-depeg-june-2026→12/100[CRITICAL]Abracadabra Money's Magic Internet Money (MIM) stablecoin experienced a severe depeg event in June 2026, falling from its $1 target to approximately $0.43–$0.50, a collapse of over 50%. The crisis built over ten days beginning June 15, 2026, and was accompanied by $994 million in cross-market liquidations and a broader crypto market downturn. Emergency measures launched June 25 — including sharply raised Cauldron interest rates and suspended Curve bribes — represent the protocol's fourth major stability incident since 2024.
avoid.net/humanity-protocol-june-2026-hack→18/100[CRITICAL]On June 8–9, 2026, Humanity Protocol — a palm-biometric decentralized identity project backed by Pantera Capital and Jump Crypto at a $1.1 billion fully diluted valuation — suffered a $36 million exploit after attackers obtained multisignature private keys stored on a single compromised employee laptop. Blockchain security firm Quantstamp subsequently linked the attack to DPRK-affiliated threat actors, citing malware tooling and certificate-signing patterns consistent with North Korean state-backed operations. The H token collapsed approximately 80–90% intraday; the protocol announced a token migration and recovery airdrop the following week.
avoid.net/noman-saleem-telegram-influencer-impersonation-fraud→0/100[CRITICAL]Noman Saleem, 39, of Queens and Levittown, New York, was sentenced on June 23, 2026 to 15 months in federal prison after pleading guilty to wire fraud for impersonating well-known cryptocurrency influencers on Telegram and defrauding investors of at least $1,415,067 through a fabricated staking scheme. Saleem cloned influencer Telegram handles, charged $500–$600 for VIP channel access, promised guaranteed staking returns over 30–90 day terms, and never staked any funds, ultimately disappearing with victims' cryptocurrency. The case was prosecuted by the U.S. Attorney's Office for the District of Maryland and investigated by the FBI's Baltimore field office.
avoid.net/isis-nigeria-turkey-crypto-financing-entities-nine-to-nine-manhattan-bureau-generation-currency-spider-alkaram→0/100[CRITICAL]On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated five entities as nodes in an ISIS cryptocurrency financing network: three Nigerian bureaux de change (Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited), each owned and controlled by Mukhtar Adamu Muhammad, an alleged ISIS-West Africa financial facilitator based in Lagos; and two Turkey-based money service businesses (Spider Gayrimenkul Ve Genel Ticaret Limited Sirketi and Alkaram Danismanlik Gayrimenkul Ic Ve Dis Genel Ticaret Limited Sirketi), both owned and controlled by Mohamad Alhmidan, who was previously designated by OFAC in March 2016. These entities allegedly served as the cash-conversion and hawala infrastructure through which ISIS supporters across Europe, the Middle East, and Africa routed cryptocurrency to the Islamic State.
avoid.net/mukhtar-adamu-muhammad-isis-wa-nigeria-crypto-facilitator→0/100[CRITICAL]Mukhtar Adamu Muhammad, a 35-year-old Lagos-based bureau de change operator born August 2, 1990, was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, under Executive Order 13224 for allegedly facilitating financial transfers on behalf of ISIS in West Africa (ISIS-WA/ISWAP). He is alleged to have channeled ISIS funds through three Nigerian money service businesses he owns — Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited — operating across Lagos and Kano states. The designation is reported to be the first OFAC action specifically targeting ISIS crypto financing infrastructure in West Africa.
avoid.net/miloud-abderrahmane-isis-tron-facilitator-france→0/100[CRITICAL]Miloud Abderrahmane is a French national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026 under Executive Order 13224 for providing material support to ISIS, including routing TRON cryptocurrency to ISIS-affiliated individuals in Syria and elsewhere, and for allegedly providing explosive device manufacturing instructions to ISIS supporters. OFAC published two TRON wallet addresses directly tied to him on the Specially Designated Nationals (SDN) list, making this one of very few OFAC counterterrorism designations to include specific individual on-chain wallet identifiers rather than targeting an exchange or custodian.
avoid.net/hu-xiaowei-prince-group-second-in-command→2/100[CRITICAL]Hu Xiaowei, also known as Chen Xiao'er, Hu Shi, and Wu An Ming, is a 44-year-old Chinese-born individual alleged by U.S. Treasury and Taiwanese prosecutors to be the second-in-command of Cambodia's Prince Group Transnational Criminal Organization (TCO). He was arrested in Osaka, Japan on June 14, 2026 on charges of filing falsified residency records, and was designated by OFAC on June 23, 2026 as part of the largest U.S. government action ever taken against a Southeast Asian cybercriminal network. He allegedly controlled a network of British Virgin Islands shell companies used to launder proceeds from pig-butchering cryptocurrency fraud schemes that cost American victims at least $10 billion in 2024.
avoid.net/trenton-richard-johnston→2/100[CRITICAL]Trenton Richard David Johnston is a Canadian national who pleaded guilty on June 10, 2026 in U.S. District Court in Miami to conspiracy to commit wire fraud and conspiracy to commit money laundering in connection with a social-engineering cryptocurrency theft scheme that caused at least $13.04 million in victim losses. Johnston, who was 19 at the time of his March 2026 arrest and had overstayed a U.S. tourist visa, is identified as Co-Conspirator 2 in federal filings that name Dritan Kapllani Jr. as Co-Conspirator 1 in the same 185 BTC theft. He awaits sentencing and has agreed to deportation to Canada.
avoid.net/blessings-in-no-time-bint→0/100[CRITICAL]Blessings in No Time (BINT) was an illegal chain-referral pyramid scheme operated by LaShonda Moore (38) and Marlon Moore (39) of Frisco, Texas, from June 2020 to June 2021. The scheme defrauded more than 10,000 people nationwide out of more than $30 million by falsely promising 800% returns on $1,400 investments, and specifically targeted the African American community through weekly livestream broadcasts during the COVID-19 pandemic. In January 2026, a federal jury convicted the Moores on conspiracy, wire fraud, and money laundering charges; in June 2026, they were each sentenced to 40 years in federal prison and ordered to pay more than $4.3 million in restitution.
avoid.net/polymarket-june-2026-supply-chain-attack→38/100[WARNING]On June 25, 2026, Polymarket, a prominent prediction market platform, suffered a supply chain attack through a compromised third-party frontend vendor. Attackers injected malicious JavaScript that drained approximately $3.1 million in pUSD from at least 11 user wallets on Polygon, with stolen funds bridged to Ethereum and converted to roughly 1,893 ETH. The incident occurred against a backdrop of a concurrent CFTC marketing-fraud investigation and a prior private key compromise in May 2026.
avoid.net/ascendex-bitmax→12/100[CRITICAL]AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.
avoid.net/ethereum-foundation→58/100[CAUTIONARY]The Ethereum Foundation (Stiftung Ethereum) is a Swiss nonprofit organization founded in 2014 to support the development and growth of the Ethereum blockchain network, the world's second-largest by market capitalization. On June 23, 2026, the Foundation announced a sweeping restructuring that eliminated approximately 54 positions (roughly 20% of its workforce), cut its 2026 operating budget by 40%, closed its Privacy and Scaling Explorations (PSE) ZK research unit, and reorganized into five protocol-focused work clusters. The restructuring follows nine senior-level departures since January 2026, including both co-executive directors, and coincides with a credible warning from former core contributor Trent Van Epps that Ethereum's core development ecosystem could face a structural funding shortage within three to nine months.
avoid.net/catfi→2/100[CRITICAL]CATFI is a Solana-based meme coin launched in early 2025 via Pump.fun that was the subject of South Korea's first criminal indictment for a decentralized exchange rug pull. Five suspects, including alleged ringleader Park (alias 'Eth Father'), were indicted on May 27, 2026 by the Seoul Southern District Prosecutors' Office under the Virtual Asset User Protection Act after allegedly engineering a 1,001-fold price pump within 26 hours then draining all liquidity, leaving 256 investors with approximately 900 million won (~$650,000 USD) in losses. The case is legally significant as the first application of South Korea's unfair-trading statutes to on-chain DEX conduct without a centralized platform intermediary.
avoid.net/lab-token-smartliquid-ai→4/100[CRITICAL]LAB is the native token of LABtrade, an AI-powered multi-chain trading terminal that launched its token generation event on October 14, 2025, with backers including Animoca Brands, Amber Group, and GSR. In May 2026, blockchain investigator ZachXBT published an investigation alleging that insiders control approximately 95% of the 1-billion-token supply, that 226 million LAB tokens were staged in Bitget addresses between March and April 2026 ahead of a coordinated 350%-plus price surge to a $6 billion fully diluted valuation, and that 100 million tokens worth roughly $480 million were subsequently withdrawn to 10 freshly created wallets in a 12-hour window. ZachXBT connected LAB founders Vova Sadkov and Mark X to a prior abandoned project (Eesee/$ESE), identified a BVI shell entity used in opaque loan contracts, placed a $10,000 bounty on Sadkov, and called on Binance, Bitget, and Gate.io to freeze insider profits or delist the token; no public rebuttal from the LAB team or Bitget had been issued as of the time of reporting.
avoid.net/fifa-world-cup-2026-crypto-scam-infrastructure→0/100[CRITICAL]A coordinated, multi-vector scam infrastructure emerged around the 2026 FIFA World Cup (June 11 – July 19, 2026), targeting fans through fake ticketing domains, insider-heavy memecoins, deepfake impersonation campaigns, fake live-streaming sites, and phishing-as-a-service kits. The FBI, TRM Labs, Malwarebytes, and FortiGuard Labs each issued independent warnings, with FortiGuard identifying over 13,000 FIFA-themed domains registered between January and May 2026, approximately 8.8% of which were classified as malicious or suspicious. Law enforcement flagged 30+ explicitly spoofed FIFA domains by name, while blockchain analytics firms documented a low-liquidity memecoin with alleged 95% insider supply concentration and cross-chain bridge laundering patterns.
avoid.net/doj-225m-pig-butchering-forfeiture-june-2025→92/100[VERIFIED]On June 18, 2025, the U.S. Attorney's Office for the District of Columbia filed a civil forfeiture complaint — case no. 25-cv-1907 — seeking $225,364,961 in USDT held across seven cryptocurrency wallet groups, representing the largest seizure of funds tied to cryptocurrency confidence fraud in U.S. Secret Service history. The assets were traced through blockchain analysis to a transnational pig-butchering network linked to a Manila-based scam compound, ITECHNO Specialist Inc., with 144 exchange accounts on OKX and more than 430 identified victims worldwide. The action was coordinated by the FBI and U.S. Secret Service San Francisco Field Office, with Tether providing proactive investigative assistance including freezing and burning the targeted USDT tokens.
avoid.net/nobitex-june-2025-hack-predatory-sparrow→10/100[CRITICAL]On June 18, 2025, pro-Israel cyber group Gonjeshke Darande (Predatory Sparrow) breached Nobitex, Iran's largest cryptocurrency exchange, transferring over $90 million in user assets to computationally inaccessible vanity wallet addresses embedded with anti-IRGC political statements, effectively destroying the funds rather than stealing them. The attack was explicitly framed as a political operation targeting what the group characterized as a key instrument of Iranian sanctions evasion and terrorism financing, not a financially motivated theft. The incident was followed within 24 hours by the public release of Nobitex's full source code, exposing internal privacy-evasion modules, hardcoded banking credentials, and alleged bypass logic for politically sensitive accounts.
avoid.net/syscoin→28/100[WARNING]Syscoin (SYS) is a dual-chain blockchain protocol originally launched in 2014 that combines a Bitcoin-derived UTXO chain with an Ethereum-compatible smart contract layer called NEVM. In June 2026, a critical proof-parsing flaw in its cross-chain bridge allowed an attacker to mint approximately 5 billion unauthorized SYS tokens — more than five times the circulating supply — valued at roughly $8.5–10 million; all funds were ultimately recovered and burned. The project has accumulated a pattern of serious concerns spanning its history: a 2014 ICO fund theft, a 2018 GitHub supply-chain compromise, and extensive 2024 governance allegations including a Dutch criminal investigation into alleged fraud, embezzlement, and unauthorized token issuance by its own foundation directors.
avoid.net/taiko→38/100[WARNING]Taiko (ticker: TAIKO) is an Ethereum-equivalent, based contestable ZK-rollup Layer 2 developed by Taiko Labs, founded in 2022 by Daniel Wang, former founder of Loopring. The protocol launched on Ethereum mainnet on May 27, 2024 and raised $37 million in total funding. On June 22, 2026, an attacker exploited a critical operational security failure — an SGX RSA-3072 private signing key committed to a public GitHub repository — to forge valid L2 state attestations and drain approximately $1.7 million from the L1 Bridge and ERC20Vault contracts; Taiko halted block production, paused all bridge withdrawals, and pledged full treasury-backed reimbursement to affected users.
avoid.net/alexander-vladimirovich-ledenev→2/100[CRITICAL]Alexander Vladimirovich Ledenev is a 25-year-old Russian national arrested in Batumi, Republic of Georgia on June 10, 2026, and charged by criminal complaint in the Eastern District of Pennsylvania with conspiracy to launder monetary instruments and sting money laundering. He is alleged to be a senior co-administrator of AudiA6, a cryptocurrency laundering service that processed approximately 10,333 Bitcoin (valued at roughly $389.7 million at transaction time) since its 2021 launch. Ledenev and co-defendant Ruslan Igorevich Tkachuk are currently in Georgian custody pending U.S. extradition proceedings; each faces a maximum sentence of 20 years in federal prison.
avoid.net/ruslan-igorevich-tkachuk→2/100[CRITICAL]Ruslan Igorevich Tkachuk is a 37-year-old Ukrainian national charged by the U.S. Department of Justice in June 2026 as an alleged senior administrator of AudiA6, a cryptocurrency money laundering service that processed approximately $389 million in illicit transactions since 2021. Tkachuk was arrested in Batumi, Georgia on June 10, 2026, as part of a coordinated multinational law enforcement operation involving Europol, Eurojust, the U.S. Secret Service, IRS Criminal Investigation, and authorities from over a dozen countries. He is currently in Georgian custody awaiting extradition to the Eastern District of Pennsylvania, where he faces up to 20 years in federal prison if convicted.
avoid.net/dark2web→0/100[CRITICAL]Dark2Web was a darknet and clear-web cybercrime forum operated by the same individuals who ran the AudiA6 cryptocurrency laundering service. It served as the primary advertising hub and networking venue for ransomware affiliates, hackers, and other cybercriminals who used AudiA6 to launder proceeds. Both platforms were seized by an international law enforcement coalition on June 10-11, 2026, and their two alleged administrators were arrested in Georgia and face extradition to the United States.
avoid.net/hyperfund-rodney-bitcoin-rodney-burton→2/100[CRITICAL]HyperFund (also marketed as HyperVerse, HyperCapital, HyperTech, and HyperNation) was a global cryptocurrency investment scheme that allegedly raised approximately $1.89 billion from investors worldwide between June 2020 and November 2022 through fraudulent promises of daily passive returns backed by nonexistent crypto mining operations. The U.S. Department of Justice and SEC filed criminal and civil charges in January 2024 against co-founder Xue 'Sam' Lee and two key promoters, including Rodney 'Bitcoin Rodney' Burton, a Miami-based influencer who pleaded guilty on June 15, 2026 to conspiracy to operate an unlicensed money transmitting business and personally received over $7.8 million in proceeds.
avoid.net/andean-medjedovic→2/100[CRITICAL]Andean Medjedovic is a Canadian national and mathematics prodigy charged by U.S. federal prosecutors in February 2025 with allegedly stealing approximately $65 million from two decentralized finance protocols — Indexed Finance in October 2021 ($16.5 million) and KyberSwap in November 2023 ($48.4 million). He faces a five-count federal indictment in the Eastern District of New York covering wire fraud, unauthorized computer damage, attempted extortion, money laundering conspiracy, and money laundering. As of mid-2026, Medjedovic remains a fugitive, believed to be in Bosnia and Herzegovina, and has engaged Washington D.C. lobbyists in an attempt to secure a presidential pardon from the Trump administration.
avoid.net/bitget-exchange-shawn-liu→42/100[WARNING]Bitget is a Seychelles-headquartered centralized cryptocurrency exchange founded in 2018, ranking among the top 10 global exchanges by trading volume as of 2025. The platform is known for its copy trading product and native token BGB, but has drawn regulatory warnings from multiple jurisdictions including Australia (ASIC), Canada, Germany, France, Spain, and Austria for operating unlicensed derivatives products. In May 2026, on-chain investigator ZachXBT published allegations identifying founder Shawn Liu as the alleged behind-the-scenes operator and accusing Bitget of enabling token supply manipulation schemes involving at least four listed assets.
avoid.net/terence-kwok-humanity-protocol-staged-hack→14/100[CRITICAL]Terence Kwok is the founder of Humanity Protocol, a biometric decentralized identity project that raised $50 million from investors including Pantera Capital and Jump Crypto at a $1.1 billion valuation. On June 8–9, 2026, the project suffered a breach in which approximately $36 million was stolen via compromised private keys, causing the H token to crash 80–90%. On-chain investigator ZachXBT publicly characterized the incident as 'possibly staged,' citing pre-funded attacker wallets and a pattern consistent with a market-maker exit, though a subsequent investigation by security firm Quantstamp attributed the attack to DPRK-affiliated threat actors using a phishing campaign.
avoid.net/ravedao-rave-token→4/100[CRITICAL]RaveDAO is a Web3 project that organized electronic music events and launched the RAVE token on Binance Alpha in December 2025. In April 2026, RAVE surged approximately 10,800% in nine days to a peak market cap near $6.6 billion before collapsing 95% within 48 hours, erasing roughly $5.7 billion in value. On-chain investigator ZachXBT alleged coordinated insider manipulation based on extreme supply concentration and suspicious pre-surge token transfers, prompting formal investigations by Binance and Bitget; RaveDAO denied any involvement.
avoid.net/thai-southeast-asia-520m-cross-chain-crypto-scam-network→0/100[CRITICAL]A joint investigation by Elliptic's Asia-Pacific Intelligence team and the Royal Thai Police's High-Tech Crime Division (HTCD), published June 18–24, 2026, identified $520 million in incoming suspicious cryptocurrency transactions linked to a cross-chain criminal network operating across 32 blockchains and 400+ digital assets. The network encompasses pig-butchering romance investment fraud, credential theft, professional cross-chain money laundering, organized crime compounds in Cambodia and Myanmar, and at least one theft attributed to North Korean state-linked actors targeting Thai nationals. The investigation began with analysis of over 500 reported suspicious wallets associated with approximately $14 million in documented individual victim losses spanning January 2022 to October 2025.
avoid.net/rain-protocol-rain-token→12/100[CRITICAL]Rain Protocol is a decentralized prediction markets protocol built on Arbitrum, with its native RAIN token reaching an approximately $8.8 billion fully diluted valuation (FDV) by mid-2026. On-chain investigator ZachXBT alleged in June 2026 that 99.97% of RAIN's total supply is controlled by 81 wallets and that deployer wallet funding trails link the Rain team to the Data Ownership Protocol (DOP) and TOMI networks, projects associated with Israeli entrepreneur Moshe Hogeg, who faces a recommended $290 million fraud indictment in Israel. Rain Protocol has not issued a public response to these allegations, and no regulatory action has been taken against Rain Protocol directly.
avoid.net/dlmc-token-bnb-chain-flash-loan-exploit→18/100[CRITICAL]DLMC (Decentralized Legacy Management Corporation) is a BNB Chain DeFi token that suffered a flash loan price manipulation exploit on June 24, 2026, resulting in a net loss of approximately $222,560 in USDT from its treasury. The project markets itself as a fully decentralized, CertiK-verified ecosystem with renounced ownership, but a design flaw in its internal price calculation allowed an attacker to drain funds in a single transaction. No team has been publicly identified, no post-exploit response has been issued, and the protocol's referral and DAO reward structure resemble patterns common in high-risk DeFi schemes.
avoid.net/eleven-drainer→0/100[CRITICAL]Eleven Drainer is a Drainer-as-a-Service (DaaS) toolkit and phishing syndicate that emerged around August 2025, offering rented wallet-draining infrastructure to criminal operators who deploy it through phishing sites, DNS hijacks, and compromised front-ends. The kit is associated with confirmed theft of at least $4.2 million across a three-week window in November 2025, including a $700,000 loss from a DNS hijack of decentralized exchanges Aerodrome and Velodrome. As of June 2026, the kit remains active and was detected embedded in a compromised Gitcoin subdomain.
avoid.net/abdelhakim-boukich→0/100[CRITICAL]Abdelhakim Boukich is a former Dutch national operating from Syria who was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, for materially supporting ISIS through cryptocurrency financing. Boukich established and controls Bitcoin Xchange, a Syria-based money service business that served as a core off-ramp for ISIS-linked fundraising campaigns, processing approximately $10 million in transaction volume across hundreds of transactions with ISIS-affiliated networks. He is listed on OFAC's Specially Designated Nationals (SDN) list under the SDGT tag and is known by the aliases Abu Sulayman Alholandi and Muhammad Babili.
avoid.net/bitcoin-xchange-syria-based-isis-linked→0/100[CRITICAL]Bitcoin Xchange is a Syria-based money services business established in late 2020 and controlled by Abdelhakim Boukich, a former Dutch national operating from Syria. On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) formally designated the entity under Executive Order 13224 for materially supporting ISIS by facilitating cryptocurrency-to-cash conversions on behalf of ISIS associates across multiple countries. On-chain analysis by TRM Labs attributed approximately USD 10 million in total transaction volume to addresses linked to Bitcoin Xchange, with hundreds of transactions connected to ISIS-linked fundraising campaigns.
avoid.net/h-pay-service-plc-huione-successor-entity→2/100[CRITICAL]H-Pay Service PLC is a Cambodia-based payment company incorporated in October 2024 that U.S. regulators allege is a successor entity to Huione Pay, itself a subsidiary of the Huione Group — a conglomerate FinCEN designated as a primary money laundering concern in October 2025 for laundering at least $4 billion in illicit proceeds linked to North Korean state-sponsored cyber heists and Southeast Asian pig-butchering scam networks. On June 23–24, 2026, FinCEN proposed amending its Huione Group final rule to explicitly encompass H-Pay Service PLC and any future successors, while the DOJ simultaneously seized backend cloud infrastructure used by Huione Group subsidiaries to process billions in fraud proceeds. H-Pay is alleged to have assumed Huione Pay's branches, customer base, branding, and operational footprint specifically to circumvent the existing U.S. financial restrictions imposed on Huione Group.
avoid.net/doj-scam-center-disruption-week-june-2026→92/100[VERIFIED]Disruption Week was a coordinated public-private enforcement operation announced on June 3, 2026 by the U.S. Department of Justice's Scam Center Strike Force. The operation targeted Southeast Asian cryptocurrency investment fraud networks — commonly known as pig butchering scams — resulting in the disruption of more than 1.4 million social media accounts, the freezing of approximately $3.8 million in cryptocurrency, the removal of thousands of Starlink kits from scam compounds, and seven arrests in Thailand. This was the first major coordinated action of its kind, combining federal law enforcement with Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and multiple international law enforcement agencies.
avoid.net/goliath-ventures-christopher-alexander-delgado→2/100[CRITICAL]Goliath Ventures was an Orlando, Florida-based cryptocurrency investment firm whose CEO, Christopher Alexander Delgado, was arrested in February 2026 on federal wire fraud and money laundering charges after allegedly operating a $328 million Ponzi scheme affecting over 2,000 investors from January 2023 through January 2026. The scheme promised monthly returns of 3-8% through cryptocurrency liquidity pools, but federal prosecutors allege that only approximately $1.5 million of the $328 million raised was ever deployed into pools, with the remainder used to pay earlier investors and fund personal expenditures. Delgado signed a federal plea agreement on June 23, 2026; the company filed for Chapter 11 bankruptcy in March 2026; and a court-appointed receiver is overseeing remaining assets while separate civil class actions target JPMorgan Chase and Bank of America for allegedly enabling the scheme.
avoid.net/crypto-clipper-worm-microsoft-dcu-takedown-june-2026→0/100[CRITICAL]CryptoBandits is a self-propagating Windows malware campaign active since February 2026 that combines clipboard hijacking, seed-phrase theft, wallet-address substitution, and worm-like USB propagation with Tor-based command-and-control infrastructure. Microsoft Threat Intelligence disclosed the campaign on June 17, 2026, under the Defender detection name Trojan:Win32/CryptoBandits. Microsoft's Digital Crimes Unit, acting alongside Europol and law enforcement from multiple countries as part of Operation Endgame, disrupted the broader StealC and Amadey botnet infrastructure that delivered related infostealers on June 24, 2026, seizing 182 C2 IP addresses across 47 domains and freezing approximately EUR 41 million in criminal cryptocurrency assets.
avoid.net/wojtek-kulisz-aka-merry-sim-swap-gang→2/100[CRITICAL]Wojtek Kulisz, known online as 'Merry', is a Polish national alleged to be a social engineering threat actor linked by blockchain investigator ZachXBT to a four-person SIM-swap criminal ring arrested by Polish and U.S. authorities on June 25, 2026. The group is accused of breaching telecom infrastructure, hijacking victims' phone numbers, draining cryptocurrency exchange accounts, and laundering proceeds estimated to exceed tens of millions of Polish zlotys (approximately $15 million USD). Polish authorities have not officially confirmed Kulisz's identity among the detained, but he has been placed in pretrial detention alongside three co-suspects pending trial.
avoid.net/huione-group-haowang-guarantee→0/100[CRITICAL]Huione Group is a Cambodia-based conglomerate that operated Huione Guarantee (also known as Haowang Guarantee), a Telegram-based peer-to-peer marketplace that blockchain analytics firm Elliptic has described as the largest illicit online marketplace ever recorded, processing over $31 billion in illicit transactions since 2021. The group's payments arm, Huione Pay, received an additional $103 billion in cryptocurrency payments over its lifetime. On June 23, 2026, the U.S. Department of Justice seized the cloud computing infrastructure used by Huione Group subsidiaries as part of Operation Riptide; the U.S. Treasury's FinCEN had previously designated Huione Group a primary money laundering concern in October 2025 under Section 311 of the USA PATRIOT Act and simultaneously proposed extending the ban to successor entity H-Pay Service PLC.
avoid.net/secondfi-cardano-wallet→28/100[WARNING]SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026. Between June 21 and 23, 2026, attackers exploited a deterministic nonce-derivation flaw in the platform's wallet generation software, draining approximately 16 million ADA (~$2.4 million) from 374 user wallets. Up to 129 million ADA across 3,072 wallets was placed at risk, with blockchain security firm SlowMist estimating total exposure could exceed $20 million; EMURGO has committed to full user reimbursement through an independently secured restoration fund, though no timeline or audit has been published.
avoid.net/noman-saleem→2/100[CRITICAL]Noman Saleem, 39, of Queens and Levittown, New York, pleaded guilty to federal wire fraud charges on September 30, 2025, and was sentenced on June 23, 2026 to 15 months in federal prison for impersonating well-known cryptocurrency influencers on Telegram to defraud investors of at least $1,415,067. Operating between December 2020 and March 2021, Saleem created fake Telegram channels mimicking legitimate influencers, charged victims $500–$600 for access to VIP subchannels, and falsely promised returns from cryptocurrency staking that never occurred. The case was prosecuted by the U.S. Attorney's Office for the District of Maryland and investigated by the FBI Baltimore Field Office.
avoid.net/myswap-cl-protocol-starknet→22/100[CRITICAL]mySwap launched in 2022 as the first automated market maker on Starknet and later introduced a Concentrated Liquidity (CL) product that reached a peak TVL of approximately $9.7 million in April 2024 before declining sharply to near-zero. On June 19, 2026, an attacker deployed a malicious token named EVIL to abuse the protocol's CL pool accounting and shared vault logic, draining approximately $305,000 in residual LP assets from over 100,000 positions. The stolen funds were bridged cross-chain and routed through Railgun; no recovery or formal post-mortem has been confirmed.
avoid.net/olpc-bnblabubu-token-pancakeswap-pool-exploit→2/100[CRITICAL]On June 20, 2026, an attacker drained approximately $1.1 million from the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) by exploiting a logic flaw in the OLPC token's _update function, which triggered a massive burn of pool reserves. Approximately 46 days prior to the attack, the OLPC token contract owner had maliciously altered the decimalsValue parameter to an abnormally large integer before renouncing ownership, a sequence that security researchers and analysts widely characterize as a premeditated rug pull disguised as an external exploit. Stolen funds — 633.4 ETH — were bridged to Ethereum and deposited into Tornado Cash.
avoid.net/humanity-protocol→18/100[CRITICAL]Humanity Protocol is a zero-knowledge Layer-2 blockchain project using palm-scan biometrics for decentralized identity verification, often described as a rival to Worldcoin. On June 8, 2026, an attacker compromised a director's laptop via a phishing email impersonating South Korean exchange Bithumb, stole private keys controlling bridge and proxy-admin contracts, drained approximately 141 million H tokens from Ethereum, and minted an additional 100-300 million H tokens on BNB Smart Chain, causing total losses estimated at $36 million and an 80-89% collapse in the H token price. Blockchain security firm Quantstamp attributed the attack to DPRK-linked threat actors based on malware signatures and Hancom certificate patterns; on-chain investigator ZachXBT initially alleged the incident may have been staged to benefit an active market maker, but later stated he could not confirm insider involvement.
avoid.net/taiko-ethereum-l2-bridge→18/100[CRITICAL]On June 22, 2026, Taiko — an Ethereum-equivalent layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million from its L1 Bridge and ERC-20 vault by using an RSA-3072 Intel SGX signing key that had been committed in plaintext to the public taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and execute fraudulent withdrawal transactions on Ethereum with no corresponding deposits on Taiko's chain. Taiko halted block production network-wide, froze affected contracts, and urged all users to exit every bridge on the network within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/aztec-deprecated-private-rollup-bridge-exploit-june-2026→20/100[CRITICAL]In June 2026, two separate exploits drained a combined total of over $4 million from deprecated Aztec Network smart contracts — Aztec Connect on June 14 ($2.19M) and the Aztec Private Rollup Bridge on June 17 ($2.16M). Both contracts had been shut down years earlier but remained immutable and on-chain, custodying residual user assets with no administrative override capability.
avoid.net/q2-2026-defi-record-hack-wave→0/100[CRITICAL]Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.
avoid.net/leo-platform-npm-supply-chain-attack-june-2026→3/100[CRITICAL]On June 24, 2026, 20 npm packages belonging to the Leo Platform (LeoPlatform/LeoInsights) ecosystem were simultaneously compromised via a single hijacked maintainer account, delivering a credential-stealing worm structurally identical to the earlier Miasma campaign. The attack is attributed to tooling derived from the TeamPCP Shai-Hulud worm framework, which was open-sourced on May 12, 2026, enabling copycat or original-actor operations against new ecosystems. Approximately 13,600 weekly downloads were exposed to a payload capable of stealing CI/CD secrets, cloud credentials, cryptocurrency wallet files, and AI coding-tool configurations.
avoid.net/aman-kesar-india-crypto-scam-ring→2/100[CRITICAL]A New Delhi-based cryptocurrency fraud ring, identified through on-chain analysis by blockchain investigator ZachXBT in June 2026, is alleged to have stolen over $1 million from American victims since 2025, primarily targeting elderly individuals via social engineering. The ring was exposed when a suspected money mule, Aman Kesar (X: @Amankesar11), contacted ZachXBT seeking help unfreezing 5.73 BTC (~$475,000) held by Changelly under anti-money laundering review. On-chain tracing linked the frozen funds to a cluster of confirmed social engineering thefts; Kesar subsequently deleted his X account and all public posts following the exposure.
avoid.net/daniel-chartraw-crypto-pal→2/100[CRITICAL]Daniel Chartraw, 53, formerly of South Lake Tahoe and Lodi, California, was convicted by a federal jury on June 18, 2026 in the Eastern District of California for operating Crypto-Pal LLC, a fraudulent web-based cryptocurrency trading platform that falsely guaranteed high returns with no risk. Chartraw defrauded investors of nearly $1 million between March 2021 and February 2022, operating under aliases to conceal a prior federal fraud conviction for a separate multi-million-dollar precious metals scheme. He faces up to 20 years in prison per count at sentencing scheduled for September 28, 2026.
avoid.net/uxlink→32/100[WARNING]UXLINK is a Web3 social infrastructure platform founded in 2022 and headquartered in Singapore, claiming over 54 million registered users as of mid-2025. On September 22, 2025, the protocol suffered a critical multi-signature wallet exploit via a delegateCall vulnerability that resulted in over $11.3 million in direct losses and the fraudulent minting of approximately 10 trillion tokens. As of June 2026, the exploiter had laundered a cumulative $19.1 million through Tornado Cash, with an estimated $16 million in stolen funds still unrecovered.
avoid.net/memecore-m-token→9/100[CRITICAL]MemeCore is a Layer 1 blockchain project whose native M token collapsed 74-80% on June 25, 2026, erasing approximately $3 billion in market value with no confirmed exploit, hack, or public announcement. On-chain investigator ZachXBT and associated analysts had previously flagged alleged insider control exceeding 90% of the token supply, $7.9 million in suspicious Kraken withdrawals to 18 newly created wallets, and near-zero decentralized exchange liquidity, raising serious questions about the token's valuation legitimacy and the due diligence performed by listing exchanges including Binance, Bybit, Kraken, and Bitget.
avoid.net/ekubo-protocol→42/100[WARNING]Ekubo Protocol is a concentrated-liquidity DEX built primarily on Starknet, founded by ex-Uniswap lead engineer Moody Salem and backed by Uniswap Labs Ventures. On May 5, 2026, a missing payer-validation check in the IPayer.pay callback of its EVM swap router contracts allowed an attacker to drain approximately $1.4 million in WBTC from a single victim wallet across 85 rapid transactions, with the Starknet core deployment and liquidity providers remaining unaffected. The stolen funds were subsequently converted to ETH and routed through Tornado Cash.
avoid.net/myswap-starknet-cl-protocol→12/100[CRITICAL]mySwap is the first automated market maker deployed on Starknet, operating a concentrated liquidity (CL) protocol that reached a peak TVL of approximately $9.7 million in April 2024 before declining sharply to near-zero by early 2025. On June 19, 2026, an attacker exploited a shared-vault accounting vulnerability in the dormant CL protocol by deploying a fake token named EVIL, draining approximately $305,000 in residual LP assets. The stolen funds were bridged cross-chain and routed through Railgun; no recovery has been confirmed and the attacker remains unidentified.
avoid.net/olpc-token-pancakeswap-olpc-labubu-pool→2/100[CRITICAL]On June 20, 2026, the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited for approximately $1.11 million. Security researchers and on-chain analysts determined the attack was premeditated: 46 days before the exploit, the OLPC token deployer had silently set the contract's decimalsValue parameter to an astronomically large value (7326680472586200649), then renounced ownership to obscure their intent. The attacker triggered a massive reserve-desynchronizing burn, drained the pool, converted proceeds to approximately 1,115,903 USDT, bridged to Ethereum, and deposited 633.4 ETH into Tornado Cash.
avoid.net/ice→22/100[CRITICAL]Ice Open Network (ION) is a Layer-1 blockchain founded by Alexandru Iulian Florea that launched a mobile tap-to-mine program in July 2023 and deployed its mainnet in January 2025. The project attracted a claimed community of 40 million users before suffering a severe token price collapse of approximately 93% in April 2026, a concurrent insider data breach, and mounting credibility questions over the founder's documented history operating a cybercrime-adjacent proxy botnet service and a prior 2018 ICO that allegedly left investors with near-total losses.
avoid.net/teampcp-mini-shai-hulud-npm-supply-chain-worm→0/100[CRITICAL]TeamPCP is a threat actor group responsible for the 'Mini Shai-Hulud' self-propagating npm supply chain worm, first deployed on May 11, 2026. The campaign compromised over 600 npm packages across major ecosystems including TanStack, Mistral AI, UiPath, Red Hat, and Mastra AI, reaching two OpenAI employee devices and exfiltrating approximately 3,800 GitHub internal repositories. The malware specifically targets 166 cryptocurrency-related browser extensions and local wallet files, creating direct financial risk for crypto developers and end users.
avoid.net/misam-m-abidi→2/100[CRITICAL]Misam M. Abidi, 47, of Nolensville, Tennessee, is an independent candidate for Tennessee Governor who was indicted on June 12, 2026 by a federal grand jury in the Western District of Tennessee on 11 counts including wire fraud, money laundering, unlicensed money transmission, and aiding in false tax return preparation. Federal prosecutors allege Abidi operated Star Credit Holdings as a cryptocurrency Ponzi scheme between 2020 and 2024, diverting over $1.9 million of investor funds to himself and family members. Abidi and his associates also face a separate 2024 Tennessee state civil enforcement action involving an alleged $6.3 million fraud spanning 17 states, connected to the STAR Investment Club and the NUME cryptocurrency token issued through NumisMe LLC.
avoid.net/lab-token-vova-sadkov→4/100[CRITICAL]LAB is an AI-powered multi-chain trading terminal whose native token briefly reached a $6 billion fully diluted valuation in early June 2026 before collapsing more than 77% within hours. On-chain investigator ZachXBT alleges that insiders controlled approximately 95% of the token supply and coordinated with an unknown market maker across Bitget, Bybit, Binance, and OKX to engineer the price surge. Founder Vova Sadkov (UAE-based) and co-founder Mark X previously operated the abandoned Eesee (ESE) gamified NFT marketplace, which similarly left investors with significant losses after alleged vesting term changes at its token generation event.
avoid.net/miasma-npm-supply-chain-attack-red-hat→0/100[CRITICAL]On June 1, 2026, a supply chain attack designated 'Miasma' compromised at least 32 npm package releases under the @redhat-cloud-services namespace, collectively receiving approximately 80,000–116,991 weekly downloads. A single Red Hat employee's GitHub account was exploited after credentials appeared in infostealer logs as early as April 13, 2026 — a gap of roughly seven weeks before weaponization. The payload, derived from the TeamPCP 'Mini Shai-Hulud' malware family, is a self-propagating worm that harvests developer and cloud credentials, injects persistent GitHub Actions workflows, and targets 166 cryptocurrency browser extensions.
avoid.net/bitget-exchange→27/100[WARNING]Bitget is a centralized cryptocurrency derivatives and spot exchange founded in 2018, currently ranked among the top five global exchanges by trading volume with a reported user base exceeding 120 million. Between April and May 2026, blockchain investigator ZachXBT published a series of on-chain investigations alleging that Bitget systematically enabled coordinated pump-and-dump schemes across at least four tokens — RAVE, RIVER, SIREN, and LAB — by allowing insiders to pre-position large holdings before engineered price pumps that erased billions in retail value. A separate incident in April 2025 involving a malfunctioning market-making bot on VOXEL/USDT futures resulted in over $100 million in estimated losses, forced account rollbacks, and drew comparisons to earlier exchange failures.
avoid.net/drift-protocol→18/100[CRITICAL]Drift Protocol is a decentralized perpetual futures exchange on the Solana blockchain, launched in August 2021 and historically the largest open-source perps DEX on that network. On April 1, 2026, the protocol was drained of approximately $285–295 million in user assets in a coordinated attack attributed with medium-high confidence to UNC4736, a North Korean state-sponsored group also tracked as AppleJeus and Citrine Sleet, following a six-month social engineering campaign. As of May 2026, a recovery plan backed by Tether has been outlined but only a small fraction of the target funding has been secured, and the protocol remains offline pending a security-hardened relaunch.
avoid.net/fifa-world-cup-2026-crypto-streaming-scam-network→0/100[CRITICAL]A coordinated network of fraudulent websites, malicious streaming applications, phishing campaigns, and deceptive cryptocurrency schemes targeting FIFA World Cup 2026 fans across at least six fraud typologies. The campaign encompasses more than 4,300 registered fraudulent domains, Android banking trojans embedded in fake streaming apps, a Chinese-speaking threat actor designated GHOST STADIUM operating 300+ pixel-perfect FIFA clones, and at least one fan-branded token (WCUP) alleged to be a pump-and-dump scheme. The FBI issued a public service announcement on May 27, 2026; estimated losses from ticket fraud alone range from $71 million to $474 million, with total campaign potential described by Group-IB as reaching into the billions.
avoid.net/step-finance-hack-shutdown-2026→12/100[CRITICAL]Step Finance, a Solana-based DeFi portfolio tracking dashboard founded in 2021, suffered a treasury breach on January 31, 2026, when attackers compromised executive team devices and drained approximately 261,854 SOL (valued at $27–40 million depending on reporting method). Unable to secure financing or an acquisition, Step Finance and its affiliated platforms SolanaFloor and Remora Markets announced permanent closure on February 24, 2026, making this one of the most consequential operational security failures in the Solana ecosystem to date.
avoid.net/unicoin-inc→4/100[CRITICAL]Unicoin Inc. is a New York City-based digital asset company founded by CEO Alexander Konanykhin and co-founder Silvina Moschini, associated with the streaming television series Unicorn Hunters. The company sold 'rights certificates' purportedly conveying future claims to Unicoin tokens, marketing them as backed by billions of dollars in real estate and pre-IPO equity. On May 20, 2025, the SEC filed a civil complaint in the U.S. District Court for the Southern District of New York alleging that Unicoin and its top executives committed securities offering fraud by materially overstating asset values, fabricating sales figures, and falsely claiming SEC registration status, raising more than $100 million from over 5,000 investors between February 2022 and the time of the filing.
avoid.net/gotbit-vortex-antier-contrarian-market-manipulation-ring→2/100[CRITICAL]Gotbit, Vortex, Antier Solutions, and Contrarian are four cryptocurrency market-making firms whose executives and employees were charged by the U.S. Department of Justice as part of Operation Token Mirrors, an FBI-led undercover investigation into wash trading and pump-and-dump schemes. Between 2018 and 2025, the firms allegedly provided market manipulation as a service to dozens of crypto projects, generating artificial trading volume through algorithmic bots and coordinated self-dealing across hundreds of wallets. In total, more than $25 million in cryptocurrency was seized and 28 individuals and entities faced criminal or civil charges across two waves of enforcement in October 2024 and March 2026.
avoid.net/axiom-dex-insider-trading-2026→22/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that employees of Axiom Exchange, a Y Combinator-backed Solana trading platform, abused internal customer support dashboards to track private user wallet activity and execute insider trades over approximately one year. The alleged scheme, centered on senior business development employee Broox Bauer, exploited the platform's lack of role-based access controls to compile non-public trading data on high-profile crypto traders, with a secondary layer of alleged front-running on Polymarket prediction markets using advance knowledge of ZachXBT's impending report. No formal criminal charges had been publicly announced as of the investigation's release.
avoid.net/world-cup-pvp-token-wcup→4/100[CRITICAL]World Cup PvP Token (ticker: WCUP) is an ERC-20 token that launched on June 10, 2026, capitalizing on hype surrounding the 2026 FIFA World Cup. On-chain analytics firm Bubblemaps alleged that a coordinated group of over 30 wallets pre-purchased approximately 95% of the token's circulating supply within minutes of launch, driving the market cap to $50 million on the first day against only $536,000 in actual liquidity. Multiple crypto influencers on X promoted the token without disclosing alleged compensation, a pattern consistent with a coordinated pump-and-dump scheme.
avoid.net/humanity-protocol-h-token-hack→18/100[CRITICAL]On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.
avoid.net/taiko-ethereum-l2-bridge-exploit→15/100[CRITICAL]On June 22, 2026, an attacker drained approximately $1.7 million from the Taiko Ethereum layer-2 bridge and ERC-20 vault by exploiting a leaked Intel SGX RSA-3072 signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and submit withdrawal requests on Ethereum with no matching deposits on Taiko, causing the bridge contracts to release funds against fraudulent proofs. Taiko halted block production and froze bridge withdrawals within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/yg→42/100[WARNING]Yield Guild Games (YGG) is a Philippines-based web3 gaming guild and decentralized autonomous organization that gained prominence during the 2021 Axie Infinity play-to-earn boom. The YGG token launched in July 2021, reached an all-time high of approximately $11.27 in November 2021, and subsequently lost over 99% of its value as the play-to-earn economy collapsed. The project has since pivoted toward multi-game community coordination and game publishing under the YGG Play brand, backed by major investors including a16z Crypto and DWF Labs.
avoid.net/saga-evm-blockchain→32/100[WARNING]Saga is a Layer-1 blockchain protocol designed to support application-specific chains (chainlets), with a focus on gaming and DeFi use cases. In January 2026, its SagaEVM chainlet suffered a critical exploit in which an inherited vulnerability in the Ethermint EVM codebase allowed an attacker to mint approximately $7 million in unbacked stablecoins, which were subsequently bridged to Ethereum and largely laundered through Tornado Cash. The broader Saga SSC mainnet, consensus layer, and validator set were not compromised, but the incident exposed material risks from deploying EVM compatibility layers built on unaudited inherited codebases.
avoid.net/praetorian-group-international-pgi-ramil-palafox→0/100[CRITICAL]Praetorian Group International (PGI), also marketed as PGI Global, was a multi-level marketing cryptocurrency investment scheme operated by Ramil Ventura Palafox between December 2019 and October 2021. The scheme defrauded over 90,000 investors worldwide of more than $201 million by falsely promising daily returns of 0.5–3% from Bitcoin and foreign exchange trading that was not occurring at the claimed scale. On February 12, 2026, Palafox was sentenced to 20 years in federal prison by the U.S. District Court for the Eastern District of Virginia following his September 2025 guilty plea to wire fraud and concealment money laundering.
avoid.net/meteora-dex→18/100[CRITICAL]Meteora is a Solana-based decentralized exchange and liquidity protocol, originally founded as Mercurial Finance in 2021 and relaunched under the Meteora brand in February 2023 by Benjamin Chow and the Jupiter DEX team. In April 2025, two federal class action lawsuits were filed in the U.S. District Court for the Southern District of New York alleging that Meteora co-founder Benjamin Chow and co-defendant Kelsier Ventures engineered a series of pump-and-dump schemes, including the December 2024 M3M3 token launch that allegedly caused over $69 million in retail investor losses. An expanded complaint filed in mid-2025 further alleges that the same defendants used celebrity associations with Melania Trump and Argentine President Javier Milei to lend false legitimacy to additional meme coin schemes totaling at least $57 million in extracted funds.
avoid.net/arthur-hayes-maelstrom-cio-exit-liquidity-allegations→22/100[CRITICAL]Arthur Hayes, co-founder of BitMEX and Chief Investment Officer of the Maelstrom family office fund, publicly designated HYPE, ZEC, NEAR, and WLD as high-conviction portfolio holdings in May and early June 2026, then liquidated all four positions within 13 days of the initial public recommendation. On June 6, 2026, blockchain investigator ZachXBT published on-chain evidence alleging that Hayes' public promotions generated retail buy-side depth that allowed him to exit without significant slippage, characterising his followers as 'exit liquidity.' Hayes denied intentional coordination, framing the exits as normal target-based trading driven by a macro thesis shift, and published a detailed essay titled 'Reality Test' on June 8, 2026. No formal regulatory action has been announced as of the investigation date.
avoid.net/star-credit-holdings→2/100[CRITICAL]Star Credit Holdings is a cryptocurrency investment firm operated by Misam M. Abidi of Nolensville, Tennessee, that allegedly functioned as a Ponzi scheme from 2020 to 2024. On June 12, 2026, a federal grand jury in the Western District of Tennessee returned an 11-count indictment against Abidi for wire fraud, unlicensed money transmission, false tax return preparation, and money laundering, with allegations that he diverted over $1.9 million in investor funds to himself and family members. State regulators had previously taken action in May 2024, obtaining a temporary injunction freezing assets tied to Abidi, his wife Anisha Abidi, co-defendant Ali Raza Galani, and related entities including NumisMe LLC and Satori Credit Solutions LLC, with total alleged investor losses across 17 states exceeding $6.3 million.
avoid.net/rust-crypto-clipper-malware-fake-github-stars-campaign→0/100[CRITICAL]An active malware campaign discovered by Check Point Research in June 2026 distributes a Rust-based cryptocurrency clipboard hijacker for Windows and macOS disguised as crypto trading tools and gambling predictors. The operation manufactured false legitimacy through coordinated fake GitHub star networks, AI-narrated YouTube tutorials, inflated VirusTotal ratings, and a SourceForge page showing over 44,000 downloads, achieving more than 5,000 confirmed genuine GitHub downloads. The clipper silently replaces copied wallet addresses with attacker-controlled addresses drawn from an embedded list of over 15,500 addresses, primarily Bitcoin.
avoid.net/dsjex-bg-wealth-sharing-ponzi→0/100[CRITICAL]DSJEX (DSJ Exchange PTY Ltd) and BG Wealth Sharing Ltd operated as a coordinated Ponzi scheme from approximately January 2025 through early May 2026, defrauding an estimated $150 million from investors worldwide by promising 1.3–2.6% daily returns through fabricated AI trading signals. The operation laundered over $92 million cross-chain in a single week before a coordinated response by ZachXBT, Tether, Binance, OKX, and U.S. law enforcement froze $41.5 million. The scheme is linked to a broader TXEX/Shunda compound network that used trafficked forced labor in Myanmar and Cambodia, and thirteen regulators across five continents had issued fraud warnings before the collapse.
avoid.net/goliath-ventures→2/100[CRITICAL]Goliath Ventures (formerly Gen-Z Venture Firm) was a Florida-based cryptocurrency investment firm whose CEO, Christopher Alexander Delgado, 34, of Apopka, Florida, was arrested on February 24, 2026 on federal charges of wire fraud and money laundering. Federal prosecutors allege Delgado operated the company as a Ponzi scheme from January 2023 through January 2026, raising at least $328 million from more than 2,000 investors under false promises of 3-8% monthly returns through cryptocurrency liquidity pools, while only approximately $1.5 million was verifiably placed into liquidity pools. The firm filed for Chapter 11 bankruptcy in March 2026, and class action lawsuits have been filed against multiple third parties including JPMorgan Chase, Bank of America, Coinbase, law firm Alston & Bird, and Broad Financial for allegedly enabling the scheme.
avoid.net/zcash-orchard-counterfeiting-vulnerability→35/100[WARNING]A critical soundness bug in Zcash's Orchard shielded pool zero-knowledge proof circuit was publicly disclosed on June 5, 2026, after existing undetected for approximately four years since Orchard's May 2022 activation. The flaw, discovered by security researcher Taylor Hornby using the Anthropic Claude Opus 4.8 AI model, could have allowed a malicious actor to forge transactions and mint unlimited counterfeit ZEC within the shielded pool with no on-chain signature. An emergency soft fork (June 2) and subsequent NU6.2 hard fork (June 3) patched the circuit before public disclosure, but Zcash's inherent privacy properties make it cryptographically impossible to determine whether the vulnerability was exploited during its four-year exposure window, causing ZEC to fall approximately 38-50% on disclosure.
avoid.net/nobitex-wallex-bitpin-ramzinex→2/100[CRITICAL]On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated four Iranian cryptocurrency exchanges — Nobitex, Wallex, Bitpin, and Ramzinex — on the Specially Designated Nationals (SDN) list under Executive Orders 13224 and 13902 as part of the Trump administration's 'Economic Fury' maximum pressure campaign against Iran. The four exchanges collectively processed approximately $7.7 billion in 2025, representing roughly 78% of Iran's attributed crypto volume, and allegedly facilitated terror finance, sanctions evasion, IRGC-linked ransomware payments, and the Iranian Central Bank's acquisition of hundreds of millions in USDT. Secondary sanctions apply, meaning any foreign financial institution transacting with these entities after June 2, 2026 risks losing U.S. dollar correspondent banking access.
avoid.net/kelpdao-bridge-exploit-april-2026→2/100[CRITICAL]On April 18, 2026, attackers drained 116,500 rsETH (approximately $292–294 million) from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest DeFi exploit of 2026. The attack exploited a single-DVN (Decentralized Verifier Network) configuration by compromising RPC nodes and using a DDoS to force failover to poisoned infrastructure, tricking the bridge verifier into approving a phantom token release. The operation has been attributed with preliminary confidence to North Korea's Lazarus Group, specifically the TraderTraitor subunit, and triggered systemic contagion across at least 9 DeFi protocols and 20+ chains, including a major liquidity crisis on Aave.
avoid.net/andean-medjedovic-kyberswap-indexed-finance-fugitive-active-laundering-2026→2/100[CRITICAL]Andean 'Andy' Medjedovic is a Canadian national charged by the U.S. Department of Justice in February 2025 with five federal counts related to the alleged theft of approximately $65 million across two DeFi exploits: the 2021 Indexed Finance hack ($16.5M) and the 2023 KyberSwap exploit ($48.8M). He has been a fugitive since December 2021, evaded extradition after a Serbian court rejected a Dutch arrest warrant in late 2024, and as of April 2026 wallets attributed to him by law enforcement had routed approximately $24.88 million through Tornado Cash, with an estimated $29 million in exploit proceeds remaining in identified wallets.
avoid.net/namada-protocol-masp-ibc-transfer-logic-exploit-june-19-2026→22/100[CRITICAL]On June 19, 2026, Namada Protocol's Multi-Asset Shielded Pool (MASP) was drained of approximately $600,000 in IBC-bridged assets including ATOM, USDC, OSMO, TIA, and NYM via an IBC Transfer Logic Exploit. The attack went undetected for a material period because a stale chain indexer continued displaying the drained balances as available, while live RPC queries showed zero; the discrepancy was first identified by independent security researchers at F12. Namada confirmed the exploit and issued an appeal to the responsible party to contact them, but as of the investigation date had not disclosed the specific vulnerability, recovery status, or a comprehensive postmortem.
avoid.net/apyx-finance-apxusd→32/100[WARNING]Apyx Finance is a DeFi stablecoin protocol launched on Ethereum mainnet in February 2026 that introduced apxUSD, a synthetic dollar it describes as the first 'Dividend-Backed Stablecoin' (DBS), backed primarily by preferred equity shares from Bitcoin treasury companies, chiefly Strategy's STRC. On June 4, 2026, apxUSD depegged to as low as $0.9094 during a Bitcoin selloff, and the protocol characterized the 7-10% deviation as expected behavior rather than a model failure, offering no remediation plan. With a circulating supply of approximately $415M-$476M and liquidity heavily concentrated in Pendle and Curve, the protocol presents novel correlated equity-crypto drawdown risk to any DeFi system using apxUSD as stable collateral.
avoid.net/abracadabra-finance-mim-stablecoin→22/100[CRITICAL]Abracadabra Finance is a multi-chain DeFi lending protocol that allows users to mint its USD-pegged stablecoin Magic Internet Money (MIM) against interest-bearing collateral. The protocol has suffered four significant security exploits between January 2024 and October 2025, with cumulative losses exceeding $21 million, and its MIM stablecoin depegged twice in a single week in June 2026 — reaching as low as $0.80 — due to critically thin DEX exit liquidity. As of mid-June 2026, MIM was trading approximately 18% below its $1 peg, with the protocol relying on a 140 million SPELL token incentive program to attract liquidity providers.
avoid.net/bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m→10/100[CRITICAL]BridgeLink, CrossFlow, and Relay Protocol are three DeFi bridge protocols alleged to have been drained of a combined $127 million in a coordinated cross-chain exploit beginning at 03:42 UTC on June 14, 2026. The incident is described as exploiting a signature replay vulnerability combined with premature finality acceptance across Ethereum, Arbitrum, and Polygon. As of June 16, 2026, no Tier 1 or Tier 2 sources — including CoinDesk, The Block, Reuters, or Bloomberg — have published corroborating coverage, and no on-chain transaction hashes or official protocol statements have been publicly produced; the investigation page reflects low source confidence accordingly.
avoid.net/npm-debug-chalk-supply-chain-attack-september-2025→0/100[CRITICAL]On September 8, 2025, attackers compromised the npm account of open-source maintainer Josh Junon (alias 'qix') through a phishing campaign using the spoofed domain npmjs.help, then published malicious versions of 18 foundational JavaScript packages — including chalk (~300M weekly downloads) and debug (~357M) — that collectively exceeded 2 billion weekly downloads. The injected payload functioned as a browser-side wallet-draining cryptostealer, silently intercepting and rewriting cryptocurrency transaction destinations before signing. The malicious versions were available for approximately 7 hours before full removal; a second wave on September 9 targeted DuckDB npm accounts through the same phishing infrastructure.
avoid.net/mr-parveen-india-social-engineering-scam-ring→2/100[CRITICAL]A New Delhi-based social engineering fraud operation, allegedly directed by an individual known only as 'Mr. Parveen,' was publicly exposed by blockchain investigator ZachXBT on June 19, 2026. The ring is accused of stealing over $1 million from American victims — predominantly elderly individuals — since 2025, using impersonation and account-takeover tactics across U.S. cryptocurrency exchanges, Bitcoin ATMs, Cash App, and Robinhood. The operation was inadvertently uncovered when an alleged money mule, Aman Kesar (@Amankesar11), contacted ZachXBT seeking help recovering 5.73 BTC frozen at Changelly, exposing the wider theft cluster through on-chain analysis.
avoid.net/secret-network-axelar-ibc-bridge-exploit-june-2026→8/100[CRITICAL]On approximately June 10, 2026, an attacker exploited a missing channel-verification check in a Secret Network-side ICS-20 smart contract governing the Cosmos IBC connection between Secret Network and Axelar, minting unbacked wrapped tokens that were redeemed for approximately $4.67 million in real bridged assets. The exploit went undetected for seven days due to Secret Network's privacy-by-default design, and was only discovered on June 17 when a routine cross-chain transfer failed due to depleted escrow. Axelar's emergency committee severed all Secret and Secret-SNIP IBC connections on June 17; the stolen funds were subsequently laundered through Osmosis, bridged to Ethereum, and deposited across KuCoin, ChangeNow, and HitBTC.
avoid.net/mica-transitional-period-expiry-unlicensed-eu-crypto-platforms→28/100[WARNING]The EU Markets in Crypto-Assets Regulation (MiCA) transitional grace period for crypto asset service providers expires on July 1, 2026, with no extension available. As of May–June 2026, only approximately 183–204 firms hold full CASP authorization across the EU, leaving an estimated 75–83% of formerly registered providers unlicensed. EU users on unlicensed platforms face account restrictions, potential withdrawal freezes, loss of statutory asset protections, and possible abrupt service cutoffs beginning July 1, 2026.
avoid.net/doj-ten-foreign-nationals-crypto-market-manipulation-ring→3/100[CRITICAL]Operation Token Mirrors was a multi-year FBI and IRS Criminal Investigation undercover operation culminating in the March 30, 2026 unsealing of three federal indictments charging ten foreign nationals employed across four cryptocurrency financial services firms — Gotbit, Vortex, Contrarian, and Antier Solutions — with wire fraud conspiracy and wire fraud for coordinated wash trading and pump-and-dump schemes designed to artificially inflate token prices and trading volumes. The case, filed in the Northern District of California, represents one of the most comprehensive enforcement actions against professional wash trading services in the history of crypto markets. More than $1 million in cryptocurrency has been seized, two defendants have pleaded guilty and been sentenced, and three were extradited from Singapore.
avoid.net/axios-npm-supply-chain-attack-march-2026→4/100[CRITICAL]On March 31, 2026, two backdoored releases of the Axios JavaScript HTTP client library (versions 1.14.1 and 0.30.4) were published to the npm registry via a compromised maintainer account, injecting a malicious dependency that delivered the WAVESHAPER.V2 cross-platform remote access trojan to macOS, Windows, and Linux systems. The malicious packages were live for approximately three hours before removal; the attack has been attributed to UNC1069 (also tracked as Sapphire Sleet), a North Korean state-sponsored threat actor. CISA issued a formal advisory on April 20, 2026.
avoid.net/sapphire-sleet-unc1069→2/100[CRITICAL]Sapphire Sleet (Microsoft designation) / UNC1069 (Google Mandiant designation) is a North Korean state-sponsored advanced persistent threat group assessed to operate under the Reconnaissance General Bureau, active since at least 2018. The group is financially motivated and primarily targets cryptocurrency exchanges, DeFi platforms, venture capital funds, wallet providers, and software developers. On March 31, 2026, the group executed a supply chain compromise of the axios npm package — which receives over 100 million weekly downloads — deploying the WAVESHAPER.V2 cross-platform remote access trojan to approximately 600,000 installations during a three-hour exposure window.
avoid.net/rahul-ravinder-malhotra→50/100[WARNING]Extensive web research found no credible evidence connecting any individual named Rahul Ravinder Malhotra to cryptocurrency fraud, scams, hacks, regulatory enforcement, or sanctions. The only verifiable public match for this exact name is Rahul Ravinder K. Malhotra, a finance executive appointed as Chief Business Development Officer and Business Head for North America at Prabhudas Lilladher Private Limited in June 2024, with no reported crypto-risk associations. Due to very limited findable public information and significant name-collision risk — 'Rahul Malhotra' is a common Indian name with dozens of distinct LinkedIn profiles — a definitive risk assessment cannot be made.
avoid.net/pump-fun-solana-memecoin-launchpad-ecosystem-fraud→12/100[CRITICAL]Pump.fun is a Solana-based memecoin launchpad operated by Baton Corporation Limited that launched in January 2024 and rapidly became the dominant token creation platform on Solana, generating over $1 billion in fees by April 2025. The platform is the subject of multiple federal class action lawsuits alleging it facilitated unregistered securities sales, insider front-running via MEV infrastructure, and systemic pump-and-dump fraud affecting retail traders. Third-party analysis of over 7 million tokens launched on the platform between January 2024 and March 2025 found that 98.6% exhibited fraudulent characteristics including pump-and-dump patterns and rug pulls.
avoid.net/ab-dao→18/100[CRITICAL]AB DAO (ticker: $AB) is a decentralized autonomous organization and blockchain ecosystem that emerged in early 2025 from the rebranding of the Newton Project (formerly $NEW), originally founded in 2018. The project attracted significant investigative scrutiny in April 2026 when a joint OCCRP and Guardian Australia investigation found that AB-affiliated entities promoted a Timor-Leste crypto resort project that involved multiple individuals subsequently sanctioned by the U.S. Treasury for alleged ties to the Prince Group, described by U.S. authorities as a multibillion-dollar online fraud syndicate. AB also announced a blockchain partnership with World Liberty Financial, a cryptocurrency project co-owned by Trump family members, in November 2025.
avoid.net/june-2026-cross-chain-bridge-exploit-127m→0/100[CRITICAL]Research into an alleged $127 million cross-chain bridge exploit in June 2026 found no Tier 1 or Tier 2 corroboration for that specific figure. The only verifiable large bridge exploit in June 2026 was the Syscoin bridge incident (June 7, 2026), in which an attacker minted approximately 5 billion unauthorized SYS tokens valued at roughly $9-10 million via an SPV proof validation flaw; all stolen tokens were subsequently returned and burned. A separate, much larger bridge exploit — the KelpDAO/LayerZero incident attributed to North Korea's Lazarus Group — occurred in April 2026 and involved approximately $292 million, and may be the source of the inflated $127M figure circulating in lower-credibility outlets.
avoid.net/trove-markets→8/100[CRITICAL]Trove Markets was a short-lived DeFi project that raised approximately $11.5 million through an ICO in January 2026 to build a perpetual futures exchange for collectibles (Pokemon cards, CS:GO skins) on Hyperliquid. Days before its token launch, the team pivoted to Solana without investor consent, retained $9.4 million of ICO funds, and the TROVE token crashed 97% within hours of its TGE. Multiple fraud allegations followed, including an alleged $10 million HYPE token dump from a project-linked wallet, undisclosed influencer payments, siphoning of $45,000 to a crypto casino, and on-chain evidence of wallet concentration; crypto investigator Eyeonchains alleges the real actor behind the project is Shanghai-based serial scammer Jin Qing Qing.
avoid.net/mastra-ai-npm-supply-chain-attack-june-2026→0/100[CRITICAL]On June 17, 2026, attackers hijacked a dormant npm contributor account ('ehindero') to inject a malicious dependency ('easy-day-js') into 140+ packages across the @mastra npm scope, affecting an estimated 1.1 million+ weekly downloads. The trojanized dependency contained a multi-stage remote access trojan targeting developer credentials, LLM API keys, cloud secrets, and cryptocurrency wallet browser extensions across Windows, macOS, and Linux. Mastra and npm responded within hours by revoking the compromised account, unpublishing malicious versions, and forward-rolling clean releases.
avoid.net/node-gyp-npm-supply-chain-compromise-june-2026→0/100[CRITICAL]In June 2026, a self-propagating npm supply chain worm designated 'Miasma' exploited a novel install-time execution technique called 'Phantom Gyp' — abusing binding.gyp configuration files to trigger malicious code during npm install. The campaign spread across 57 packages and 286+ malicious versions, harvesting developer and CI/CD credentials from npm, GitHub, AWS, GCP, Azure, HashiCorp Vault, and Kubernetes, and then self-propagating by republishing poisoned releases using stolen publishing tokens. The attack poses a direct threat to crypto developers whose CI/CD pipelines manage private keys, wallet seed phrases, and signing infrastructure.
avoid.net/rhea-finance→32/100[WARNING]Rhea Finance is a chain-abstracted DeFi liquidity hub on the NEAR Protocol, formed in early 2025 through the merger of Ref Finance and Burrow Finance. On April 16, 2026, the protocol suffered a major exploit in which an attacker bypassed slippage protection in its margin trading module using intermediate asset reuse across a chain swap path, ultimately draining an estimated $18.4 million from the reserve pool — more than double the initial $7.6 million estimate. Approximately $9.2 million was subsequently returned or frozen, with the remainder still outstanding as of mid-2026; a compensation framework was announced but had not been finalized at the time of publication.
avoid.net/aztec-connect-deprecated-bridge-exploits-june-2026→10/100[CRITICAL]In June 2026, two separate exploits drained a combined total of approximately $4.3–4.4 million from deprecated Aztec bridge contracts within three days. The first exploit, on June 14, targeted the abandoned Aztec Connect RollupProcessor contract (deprecated March 2023) by exploiting a settlement-boundary mismatch in zk-rollup proof verification; the second, on June 17–18, targeted a deprecated Private Rollup Bridge (closed 2022) via an unauthenticated escape hatch function. Both contracts were immutable with admin keys renounced, making intervention impossible. Aztec Labs and the Aztec Foundation confirmed the affected contracts have no connection to the current Aztec network or the AZTEC ERC-20 token.
avoid.net/syscoin-bridge-exploit-june-2026→38/100[WARNING]On June 7, 2026, an attacker exploited a proof-validation parsing flaw in Syscoin's cross-chain bridge to mint approximately 5 billion unauthorized SYS tokens, representing roughly 568% of the pre-attack circulating supply and valued at approximately $9–10 million at the time. The Syscoin team paused the bridge, coordinated with exchanges to freeze tainted addresses, and subsequently recovered and permanently burned all 5 billion tokens after the attacker returned them following on-chain contact. A technical postmortem was published on June 15, 2026, and the bridge remained suspended pending final validation of the patch.
avoid.net/phantom-gyp-npm-supply-chain-attack-june-2026→0/100[CRITICAL]On June 3, 2026, attackers deployed a self-replicating worm across 57 npm packages in 286 malicious versions within under two hours, using a novel technique dubbed 'Phantom Gyp' that abused binding.gyp build configuration files to execute malicious code during npm install while bypassing all mainstream lifecycle-script security scanners. The campaign — classified as the latest wave of the Miasma/Shai-Hulud worm family — targeted CI/CD credential stores across AWS, GCP, Azure, GitHub, Kubernetes, and developer password managers, and included novel persistence mechanisms that injected backdoors into AI coding assistant configurations. The highest-profile victim was @vapi-ai/server-sdk (408,000+ monthly downloads), though Vapi confirmed the four compromised versions received zero downloads before removal.
avoid.net/xue-sam-lee-hyperfund-co-founder→2/100[CRITICAL]Xue 'Sam' Lee, an Australian citizen residing in Dubai, is the alleged co-founder of HyperFund (also marketed as HyperVerse, HyperTech, HyperCapital, and HyperNation), a cryptocurrency investment scheme that U.S. authorities allege defrauded investors of approximately $1.89 billion between June 2020 and November 2022. In January 2024, the U.S. Department of Justice unsealed a criminal indictment and the SEC filed parallel civil charges against Lee for conspiracy to commit securities fraud and wire fraud. Lee was detained in Dubai in October 2024 following an Interpol Red Notice but, as of June 2026, has not been extradited to the United States and maintains his innocence.
avoid.net/rodney-burton-bitcoin-rodney→2/100[CRITICAL]Rodney Burton, a 56-year-old Miami-based crypto promoter operating under the alias 'Bitcoin Rodney,' pleaded guilty on June 15, 2026, to conspiracy to operate an unlicensed money transmitting business in connection with the HyperFund Ponzi scheme, which federal prosecutors allege collected approximately $1.89 billion from investors worldwide between 2020 and 2022. Burton personally received at least $7.85 million in fraudulent proceeds and leveraged appearances by high-profile celebrities to recruit retail investors. He was arrested in January 2024 at Miami International Airport carrying a one-way ticket to the United Arab Emirates and has been held without bail pending sentencing on July 23, 2026.
avoid.net/trapdoor-supply-chain-attack→2/100[CRITICAL]TrapDoor is a coordinated cross-ecosystem software supply chain attack first observed on May 22, 2026, distributing credential-stealing malware across npm, PyPI, and Crates.io via 34+ malicious packages spanning 384+ versions. The campaign targets crypto, DeFi, Solana, Sui, Aptos, and AI developers by harvesting wallet keystores, SSH keys, cloud credentials, and browser session data, and is notable for a novel technique that poisons AI coding assistant configuration files to silently exfiltrate secrets. Security firm Socket and blockchain security firm SlowMist both described TrapDoor as one of the most significant supply chain attacks of 2026.
avoid.net/ironworm-npm-supply-chain-attack→0/100[CRITICAL]IronWorm is a Rust-based self-propagating malware campaign that compromised 36–37 npm packages in early June 2026 by exploiting a hijacked npm account ('asteroiddao') linked to the Arweave/WeaveDB ecosystem. The implant deploys an eBPF kernel rootkit, communicates over Tor, and includes a dedicated module targeting Exodus desktop wallet seed phrases and passwords. It self-replicates by abusing npm's Trusted Publishing flow and stolen GitHub Actions credentials to push backdated trojanized commits across at least nine GitHub organizations, making it one of the most technically sophisticated crypto-targeting supply chain attacks publicly documented to date.
avoid.net/audia6-crypto-laundering-service→0/100[CRITICAL]AudiA6 was a professional cryptocurrency mixing and laundering service that allegedly processed over EUR 336 million (approximately USD 389 million) in illicit funds on behalf of ransomware gangs, darknet markets, and other cybercriminals between 2022 and 2025. An international law enforcement coalition led by Europol and the U.S. Department of Justice dismantled the service on June 10, 2026, arresting its two alleged administrators in Batumi, Georgia. The service has since been formally charged in the Eastern District of Pennsylvania.