Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
Polkadot is a Layer 0 blockchain interoperability protocol founded by Gavin Wood (co-founder of Ethereum) and backed by the Web3 Foundation. It introduced a multi-chain architecture connecting independent blockchains via a central Relay Chain and launched its native token DOT in 2017. As of mid-2026, the project is classified as a digital commodity by U.S. regulators, has launched a spot ETF, and is executing a major technical upgrade (JAM), but faces credible concerns around treasury management, an ecosystem exodus of flagship parachains, a bridge exploit, and persistent adoption challenges relative to competitors.
avoid.net/lab-labusdt→8/100[CRITICAL]LAB is the native BEP-20 utility token of lab.pro, a self-described multi-chain AI trading terminal. Following a token generation event in October 2025, the token surged over 500% to a peak near $27 in spring 2026 before collapsing more than 99% from that high by August 2026. On-chain investigator ZachXBT published a detailed investigation in May 2026 alleging that insiders controlled over 95% of the token supply and orchestrated coordinated price manipulation across multiple centralized exchanges; those allegations have not been adjudicated by any court or regulator.
avoid.net/lab→8/100[CRITICAL]LAB is the native token of LAB Terminal (formerly MemesLab), an AI-powered multi-chain trading platform that launched via Binance Alpha in October 2025. On-chain investigator ZachXBT published findings in May 2026 alleging that insiders controlled approximately 95% of the token's circulating supply and that the team orchestrated coordinated selling through a BVI-registered shell company and opaque OTC arrangements. By August 2026, the token had fallen approximately 98% from its all-time high of roughly $24, with a separate $18.3 million wallet dump in July 2026 attributed by ZachXBT to wallets directly funded by the LAB team.
avoid.net/ben-bitboy-armstrong→8/100[CRITICAL]Ben Armstrong, known online as 'BitBoy,' is a U.S.-based cryptocurrency content creator who built one of the largest crypto YouTube channels in the world, accumulating millions of subscribers. He was removed from the BitBoy Crypto brand in August 2023, and since then has faced a compounding series of legal proceedings including arrests, a federal defamation judgment of $2.8 million, regulatory scrutiny from the CFTC, and civil litigation tied to undisclosed paid promotions. As of mid-2026, Armstrong faces felony charges in Georgia related to alleged threats directed at a state court judge, with trial proceedings reported to be advancing.
avoid.net/sheldon-xia-bitmart-founder→18/100[CRITICAL]Sheldon Xia is the founder of BitMart, a cryptocurrency exchange he established in 2017 that served over 13 million users across 180 countries before announcing a wind-down on July 26, 2026. Since that announcement, Xia has become the primary target of accountability demands from users and employees who allege frozen withdrawals and unpaid salaries, while Xia has publicly dismissed calls for a third-party audit and wallet disclosure as fabricated rumors. As of August 20, 2026, Xia has released no proof-of-reserves, no repayment plan, and no independent accounting of user funds, while on-chain data tracked by Arkham Intelligence shows a significant decline in wallet balances attributable to exchange-linked addresses.
avoid.net/bitget-voxel-futures-manipulation-april-2026→28/100[WARNING]On April 20, 2025, Bitget's VOXEL/USDT perpetual futures market experienced severe price and volume anomalies reportedly triggered by a malfunction in the exchange's proprietary market-making bot. Eight accounts allegedly exploited the bot's predictable trade pattern to extract profits exceeding $20 million from a roughly $100 million impact event before Bitget froze accounts and unilaterally reversed completed trades. The rollback drew widespread criticism, in part because Bitget CEO Gracy Chen had publicly condemned competitor Hyperliquid for conducting a structurally similar trade reversal just weeks earlier.
avoid.net/maya-protocol-mayachain→28/100[WARNING]Maya Protocol (MAYAChain) is a Cosmos SDK-based decentralized cross-chain liquidity protocol and a friendly fork of THORChain, launched on mainnet in April 2023. Its native token CACAO serves as the settlement and gas asset across its liquidity pools. On August 18–19, 2026, the protocol suffered its first documented loss-of-funds incident when an attacker exploited six chained software bugs to fabricate approximately 49.45 million CACAO tokens and withdraw roughly $1.7 million in real assets including 20 BTC, causing an automated network halt and an approximately 89% collapse in CACAO's price.
avoid.net/swan-treasury-sty-token→18/100[CRITICAL]Swan Treasury is a BNB Chain privacy-finance protocol offering anonymous identity, private transactions, dark pool liquidity, on-chain vaults, and a node network, with the STY token serving as its central ecosystem passkey. On July 30, 2026, the protocol suffered an estimated $625,000 loss after an attacker exploited a compromised off-chain signer private key that was hardcoded as the _signer address in the ZhaiquanBuy smart contract. As of August 20, 2026, Swan Treasury has not published a post-mortem or explained how the signer key was exposed, leaving users without clarity on the protocol's current security posture.
avoid.net/eu-mica-regulator-impersonation-scam-wave→0/100[CRITICAL]Following the July 1, 2026 expiry of MiCA's transitional period, which forced an estimated 1,700 or more unlicensed crypto firms to wind down EU operations, a coordinated wave of impersonation fraud emerged in which criminals pose as European financial regulators — including ESMA and France's AMF — and as shuttered exchanges, in order to steal funds from displaced users. France's AMF and ESMA have each formally warned of the pattern, describing fraudsters who clone official communications, fabricate regulatory documents, and charge upfront 'administrative fees' to victims seeking to recover assets. This is a systemic, infrastructure-level fraud cluster rather than a single actor, with multiple national regulators across the EU reporting incidents.
avoid.net/yield-guild-games-ygg→42/100[WARNING]Yield Guild Games (YGG) is a Philippines-originated Web3 gaming guild and DAO that rose to prominence in 2021 by facilitating play-to-earn scholarship programs, primarily around Axie Infinity, and raised $4.6 million led by Andreessen Horowitz. The organization has undergone significant restructuring since the collapse of the play-to-earn sector in 2022, and in July 2026 shut down its publishing arm YGG Play and laid off 35 employees as it pivoted toward supplying gaming behavioral data for AI training. No fraud allegations, hacks of the protocol, or regulatory enforcement actions have been identified; the primary concerns relate to sustained token value destruction, structural business-model risk, and heavy token-unlock inflation.
avoid.net/bitget-voxel-futures-manipulation-april-2025→28/100[WARNING]On April 20, 2025, eight accounts allegedly exploited a suspected flaw in Bitget's internal market-making bot during a 30-minute window, generating over $20 million in profits from anomalous price oscillations in the VOXEL/USDT perpetual futures market. Bitget unilaterally rolled back the affected trades within 24 hours and announced legal action against the eight accounts, while committing to compensate impacted users from recovered funds via airdrop. The incident drew particular scrutiny because Bitget's CEO had publicly criticized competitor Hyperliquid weeks earlier for conducting a similar trade reversal, creating a widely noted inconsistency.
avoid.net/crossmint→70/100[CAUTIONARY]Crossmint is a New York-based web3 infrastructure company founded in 2022 by Alfonso Gómez-Jordana Mañas and Rodrigo Fernández Touza. It provides APIs and no-code tools for embedded wallets, NFT minting, stablecoin orchestration, and AI-agent payments, reporting over 40,000 enterprise and developer customers. The company raised $23.6 million in March 2025 led by Ribbit Capital, holds SOC 2 Type II certification, a VASP license, and received MiCA authorization in Spain in December 2025.
avoid.net/olympusdao→28/100[WARNING]OlympusDAO is a decentralized reserve currency protocol launched in March 2021 on Ethereum, issuing the OHM token backed by a treasury of on-chain assets. It attracted billions in TVL during 2021 through ultra-high staking APYs exceeding 7,000% and a viral '(3,3)' game-theory meme, before OHM collapsed more than 99% from its all-time high. The protocol remains operational but is a shadow of its peak, having transitioned toward sustainable lending products while continuing to face unresolved legal claims and a documented smart contract exploit.
avoid.net/alpha-finance-lab→48/100[WARNING]Alpha Finance Lab (also known as Alpha Venture DAO, later rebranded to Stella) is a DeFi protocol builder founded in 2020 and best known for Alpha Homora, the first leveraged yield farming protocol on Ethereum. In February 2021, a vulnerability in Alpha Homora V2's own smart contract code was exploited by a third party, resulting in approximately $37.5 million drained from Cream Finance's Iron Bank through an uncollateralized protocol-to-protocol lending arrangement. Alpha bore primary responsibility for the exploited vulnerability; subsequent disputes over the resulting bad debt led to Iron Bank freezing approximately $41 million in Alpha Homora user deposits on Ethereum in March 2023, a dispute that as of mid-2023 remained unresolved with Iron Bank, with Alpha establishing a goodwill compensation fund for affected depositors.
avoid.net/bit-com→62/100[CAUTIONARY]Bit.com was a cryptocurrency derivatives exchange operated by Matrixport, a Singapore-headquartered digital asset financial services firm founded by Bitmain co-founder Jihan Wu. The exchange launched in August 2020 and achieved a top-two global ranking in Bitcoin options volume before conducting an orderly, phased shutdown completed March 31, 2026, citing business restructuring. No fraud allegations, regulatory enforcement actions, or user fund losses have been identified against the exchange itself; the parent company Matrixport rebranded as BIT in March 2026 and continues operating under multiple licensed jurisdictions.
avoid.net/sweat-economy-sweat-protocol→55/100[CAUTIONARY]Sweat Economy is a move-to-earn cryptocurrency project built on the NEAR Protocol, originating from the Sweatcoin fitness app which reportedly has over 200 million registered users. The project raised $13 million in a 2022 private token sale and launched the SWEAT token in September 2022. On April 29, 2026, an external attacker exploited a vulnerability in the SWEAT token smart contract, draining approximately 13.71 billion tokens (roughly 65-67% of total supply) from foundation-controlled accounts; the team responded by pausing the contract, coordinating exchange freezes, and restoring all external user balances.
avoid.net/peopledao→52/100[CAUTIONARY]PeopleDAO is a community-governed metaDAO that emerged in December 2021 from the dissolution of ConstitutionDAO, adopting the $PEOPLE ERC-20 token as its governance mechanism. The organization aims to incubate subDAOs and projects advancing Web3 and social good. In March 2023, PeopleDAO suffered a social engineering incident in which an unknown third party exploited an accidentally shared editable payment spreadsheet to steal approximately 76.5 ETH (~$120,000) from the DAO treasury; no rug pull, founder fraud, or regulatory action has been documented.
avoid.net/zetachain→62/100[CAUTIONARY]ZetaChain is a Layer-1 blockchain founded in 2021 that enables omnichain smart contracts and native cross-chain interoperability across Bitcoin, Ethereum, and other networks without bridges. The protocol launched its mainnet beta in January 2024, raised $27 million in a Series A in August 2023, and achieved EU MiCAR compliance and DFSA recognition. In April 2026, it suffered a $333,868 exploit of its GatewayEVM smart contract targeting internal team wallets; no user funds were lost, though the team acknowledged it had previously overlooked a bug bounty report flagging the same vulnerability.
avoid.net/astroport→46/100[WARNING]Astroport is a decentralized exchange (DEX) and automated market maker (AMM) protocol originally launched on the Terra blockchain in December 2021 and subsequently rebuilt across multiple Cosmos ecosystem chains after Terra's collapse in May 2022. On July 30, 2024, the protocol suffered a significant security exploit on the Terra (Phoenix) chain resulting in approximately $6.4 million in losses due to a reentrancy vulnerability in IBC hooks that had been patched in April 2024 but accidentally reintroduced in a June 2024 upgrade. The protocol itself was the victim of this exploit; partial recovery was achieved by seizing attacker funds on Neutron and blacklisting addresses on Terra, though a portion of stolen assets reached Ethereum and remain unrecovered.
avoid.net/exactly-protocol→58/100[CAUTIONARY]Exactly Protocol is a decentralized, non-custodial fixed- and variable-rate lending protocol deployed on Optimism and Ethereum, developed by Exa Labs. On August 18, 2023, the protocol suffered a smart contract exploit in its DebtManager periphery contract that resulted in the loss of approximately $7.3 million (4,324 ETH) belonging to 117 user accounts; the protocol itself was a victim of the attack, not the perpetrator. The team responded with a governance-approved compensation plan, law-enforcement engagement, and a substantially expanded post-incident audit program, and the protocol has continued operating with an evolving consumer app product.
avoid.net/wazirx-india→42/100[WARNING]WazirX is an Indian cryptocurrency exchange founded in 2018 by Nischal Shetty, Sameer Mhatre, and Siddharth Menon and operated by Zanmai Labs Pvt Ltd (India) and its Singapore parent Zettai Pte Ltd. The exchange suffered a catastrophic $234.9 million hack on July 18, 2024 attributed by a joint US-Japan-South Korea government statement to North Korea's Lazarus Group, causing a 16-month operational shutdown; the Singapore High Court approved a restructuring scheme in October 2025 under which users began receiving approximately 85% of pre-hack balances, with remaining claims represented by non-tradable Recovery Tokens as of mid-2026. Separately, India's Enforcement Directorate has pursued the exchange under FEMA and money-laundering provisions since 2021, and a disputed ownership relationship with Binance remained unresolved at the time of the hack.
avoid.net/ekubo-protocol→62/100[CAUTIONARY]Ekubo Protocol is a concentrated-liquidity AMM DEX launched on Starknet in mid-2023 and subsequently expanded to Ethereum and Arbitrum. Founded by Moody Salem, a former Uniswap Labs engineer, the protocol is governed by an on-chain DAO and has commanded roughly 60% of Starknet DEX TVL. In May 2026 the protocol's EVM V2 swap router contracts suffered an access-control exploit that drained approximately $1.4 million in WBTC from user wallets; the Starknet core deployment was unaffected, and the team funded an on-chain recovery fund for victims.
avoid.net/unibot→48/100[WARNING]Unibot is a Telegram-based cryptocurrency trading bot launched in May 2023 that enables users to trade on Uniswap and other decentralized exchanges directly within Telegram. On October 31, 2023, Unibot suffered a smart contract router exploit in which approximately $560,000–$640,000 in user tokens were stolen by an external attacker; the team subsequently reimbursed affected users. The platform operates with an anonymous founding team and involves inherent custodial risks because the bot manages user wallet interactions.
avoid.net/clober-liquidity-vault→52/100[CAUTIONARY]Clober Liquidity Vault is an automated market-making product built on top of CloberDEX, a fully on-chain central limit order book (CLOB) DEX deployed on Coinbase's Base network. On December 10, 2024, the Liquidity Vault suffered a reentrancy exploit that drained approximately 133.7 ETH (~$501,000) from the newly launched vault — one day after it received its first liquidity injection. The core CloberDEX protocol was unaffected, and the team offered a 20% white-hat bounty, which the attacker declined; funds were not recovered.
avoid.net/dexodus-finance→48/100[WARNING]Dexodus Finance is a perpetual decentralized exchange (DEX) built on the Base network, founded in 2023 and based in Barcelona, Spain. The protocol offers oracle-based perpetual trading with copy trading, gasless trading, and gamified features. On May 26, 2025, the protocol suffered a smart contract exploit resulting in approximately $291,000–$300,000 in losses from its liquidity pool due to a stale Chainlink oracle signature replay vulnerability; the team reported full fund recovery within 24 hours and subsequently launched a revised V2 protocol audited by Halborn.
avoid.net/dtrinity-dlend→52/100[CAUTIONARY]dTRINITY is a DeFi stablecoin lending protocol developed by Trinity Foundation Ltd., a Singapore-incorporated non-profit, with dLEND serving as its Aave v3-forked lending engine. The protocol launched on Fraxtal in December 2024 and subsequently deployed on Sonic, Katana, and Ethereum. It has suffered two separate security incidents since launch — a $56,000 authorization-check exploit in September 2025 and a $257,000 deposit inflation (liquidity index manipulation) attack in March 2026 — though the team committed to covering 100% of losses from internal funds in both cases and no user funds were reported uncompensated.
avoid.net/yg→54/100[CAUTIONARY]Yield Guild Games (YGG) is a Philippines-based web3 gaming guild and decentralized autonomous organization that gained prominence during the 2021 Axie Infinity play-to-earn boom. The YGG token launched in July 2021, reached an all-time high of approximately $11.27 in November 2021, and subsequently lost over 99% of its value as the play-to-earn economy collapsed. The project has since pivoted toward multi-game community coordination and game publishing under the YGG Play brand, backed by major investors including a16z Crypto and DWF Labs.
avoid.net/shawn-liu→28/100[WARNING]Shawn Liu (Chinese name: Liu Shuai) is the founder of Bitget, a major centralized cryptocurrency derivatives exchange, and the founder of Singaporean crypto venture fund Foresight Ventures. In May 2026, on-chain investigator ZachXBT publicly named Liu as the alleged true decision-maker behind Bitget, accusing him of enabling coordinated token supply-manipulation schemes while CEO Gracy Chen serves as the exchange's public face. Liu has not responded to any of the allegations, and no regulatory or legal findings have been made against him personally as of the date of this report.
avoid.net/triple-a-payments→62/100[CAUTIONARY]Triple-A (Triple-A Technologies Pte Ltd) is a Singapore-headquartered crypto payment gateway founded in 2017 by Eric Barbier, licensed by the Monetary Authority of Singapore as a Major Payment Institution and holding additional regulatory authorizations in the EU, US, and Canada. In July 2026, the company's own treasury hot wallets were drained of approximately $11.8 million across six blockchain networks in a security breach; Triple-A stated that customer funds were held separately in trust and were not affected. The incident raises operational security questions, but represents a suffered attack on company treasury rather than fraud perpetrated by the company.
avoid.net/woofi→52/100[CAUTIONARY]WooFi is the decentralized exchange (DEX) component of WOO Network, a liquidity and trading ecosystem founded in 2019 and incubated by Kronos Research. The platform has suffered two significant security incidents — a March 2024 flash loan oracle exploit costing approximately $8.75 million, and a July 2025 phishing-driven breach of the affiliated centralized exchange WOO X costing $14 million — both of which are attributed to external attackers rather than insider misconduct. WOO X committed to full user reimbursement for the 2025 incident, and no regulatory actions or fraud allegations against WooFi's operators have been identified.
avoid.net/bonk-fun→52/100[CAUTIONARY]BONK.fun (also marketed as LetsBONK.fun) is a no-code meme coin launchpad on the Solana blockchain, launched in April 2025 as a joint initiative between the BONK community and Raydium protocol. The platform rapidly captured majority market share from Pump.fun by mid-2025 before losing significant ground later that year, and suffered a domain-level security breach in March 2026 caused by a social engineering attack on its domain service provider — an incident attributed to the third-party infrastructure provider, not the platform's own code or contracts. The platform is operationally linked to Bonk, Inc. (Nasdaq: BNKK), a publicly traded company that holds a revenue sharing interest in the platform.
avoid.net/bond-protocol→62/100[CAUTIONARY]Bond Protocol is a permissionless DeFi infrastructure platform launched in October 2022, originating from OlympusDAO's bonding mechanism, that enables protocols to create bond markets for treasury diversification and Protocol Owned Liquidity (POL). The protocol suffered a smart contract exploit in October 2022 in which approximately 30,437 OHM tokens (~$300,000) were drained from its Fixed-Expiry Teller contract; all funds were returned by the attacker within hours of the incident. The protocol raised a $2.5M seed round from credible venture investors and has since expanded to Ethereum, Arbitrum, and Optimism, though it shows signs of reduced activity as of 2025-2026.
avoid.net/manta-network→52/100[CAUTIONARY]Manta Network is a modular zero-knowledge blockchain platform consisting of Manta Pacific (an Ethereum L2) and Manta Atlantic (a Polkadot parachain being deprecated as of August 2026). The project launched its MANTA token in January 2024, an event marred by a large-scale DDoS attack on its RPC infrastructure and concurrent allegations — sourced from on-chain data and social media, not regulatory or court filings — that a Korean business development representative dumped 2 million ecosystem tokens at launch. No formal criminal charges or regulatory actions against Manta Network or its founders have been identified as of mid-2026.
avoid.net/dutch-crypto-investment-fraud-ring-2026→0/100[CRITICAL]A large-scale international investment fraud network, dismantled by Dutch and Belgian police in July 2026, operated approximately 20 call centers staffed by over 700 people who posed as financial advisers and used fake cryptocurrency trading platforms to steal an estimated €100 million per month from victims worldwide. The alleged mastermind — Ehud Tenenbaum, a 46-year-old dual Israeli-Polish national known in cybercrime circles as 'The Analyzer' for his late-1990s hacking of U.S. government systems — was arrested in Poland in May 2026 and extradited to the Netherlands. Tens of thousands of victims across multiple countries are estimated, with Dutch victims alone reporting nearly €25 million in losses.
avoid.net/fluid-instadapp→52/100[CAUTIONARY]Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.
avoid.net/sturdy-v1→62/100[CAUTIONARY]Sturdy Finance V1 was a DeFi lending protocol that allowed users to earn yield on deposits while borrowers accessed interest-free loans backed by staked collateral. On June 12, 2023, an attacker exploited a read-only reentrancy vulnerability in the protocol's price oracle integration — a third-party flaw originating in Balancer — and drained approximately 442 ETH (roughly $800,000). Sturdy V1 paused markets immediately, reopened its stablecoin market within days, and later formally sunset V1 in favor of Sturdy V2, which launched in early 2024 with a redesigned, modular architecture and three additional audits.
avoid.net/magpie-protocol→62/100[CAUTIONARY]Magpie Protocol is a cross-chain DEX aggregator and liquidity aggregation platform founded in Dubai in 2022, backed by Jump Crypto and others in a $3 million seed round. In April 2024 the protocol suffered a smart contract exploit in which approximately $129,000 was drained from 221 user wallets due to an unchecked calldata vulnerability; the team fully reimbursed all affected users within two weeks. The project subsequently rebranded to Fly in Q1 2025 and launched the FLY governance token on the Sonic blockchain in June 2025, reporting over $6.3 billion in cumulative trading volume and 260,000 unique on-chain users as of that date.
avoid.net/thetanuts-finance→62/100[CAUTIONARY]Thetanuts Finance is a multi-chain DeFi options protocol launched in August 2021, offering structured products (options vaults) across Ethereum, BNB Chain, Arbitrum, Polygon, and other networks. The protocol has raised $35 million across two funding rounds and has undergone seven smart-contract audits, but suffered a $2.1 million exploit in June 2026 targeting a deprecated legacy vault, with approximately $2 million subsequently recovered through whitehat efforts. TVL has declined substantially from a 2022 peak of roughly $50 million to under $1 million as of mid-2026.
avoid.net/thalaswap→62/100[CAUTIONARY]ThalaSwap is the decentralized exchange component of Thala Labs, an Aptos-based DeFi protocol offering an AMM, the Move Dollar (MOD) overcollateralized stablecoin, liquid staking, and a launchpad. On November 15, 2024, an input-validation bug introduced in a two-line patch to the v1 farming contract allowed an attacker to drain $25.5 million in liquidity pool tokens; funds were fully recovered within hours after SEAL 911 identified the exploiter via on-chain evidence and the attacker returned assets in exchange for a $300,000 bounty.
avoid.net/austrian-albanian-crypto-investment-fraud-ring-europol-april-2026→2/100[CRITICAL]A criminal network operating out of Tirana, Albania, allegedly defrauded victims across Europe and worldwide of at least EUR 50 million through fake cryptocurrency investment platforms and follow-on fund-recovery scams. Austrian and Albanian authorities, supported by Europol and Eurojust, raided three call centers and nine residences on April 17, 2026, arresting ten suspects. No convictions have been recorded as of the investigation date; the arrests and seizures represent the law-enforcement action stage.
avoid.net/b-network-bsquared-bitcoin-layer-2-staking-contract-exploit→30/100[WARNING]On July 22, 2026, B² Network — a Bitcoin Layer-2 ZK rollup protocol — suffered a security incident in which an attacker allegedly exploited unauthorized access to the B2 token staking contract's upgrade authority and drained approximately 8.59 million B2 tokens valued at roughly $3.86 million. The stolen tokens were converted to BNB, bridged to Ethereum, and reportedly laundered through NEAR Intents and HOT Protocol toward Zcash. The team suspended staking, committed to full user compensation, and reportedly offered the attacker legal immunity in exchange for a partial refund. As of August 2026, no funds have been publicly confirmed as recovered.
avoid.net/crypto-whale-repeat-phishing-25-6m-drain-august-2026→0/100[CRITICAL]On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in WBTC, cbBTC, aWBTC, DAI, ETH, LDO, USDS, and CRV to a phishing attack that induced the victim to authorize malicious token-approval transactions. The same wallet had previously lost $24.2 million in a nearly identical phishing scheme in September 2023, of which approximately 90% was returned; no funds from the 2026 attack had been recovered as of mid-August 2026. The combined gross exposure across both incidents is approximately $49.8 million, making this one of the most consequential repeat-targeting cases in Ethereum's history.
avoid.net/robinhood-chain-scam-ecosystem→12/100[CRITICAL]Robinhood Chain, an Arbitrum-based Ethereum Layer 2 launched by Robinhood Markets on July 1, 2026, experienced a rapid influx of fraudulent tokens within days of its permissionless mainnet going live, including honeypot contracts, vanishing-token scams, wallet-drainer schemes, and memecoin rug pulls. On July 23, 2026, the verified X account of Robinhood CEO Vlad Tenev was compromised and used to promote a fake memecoin called 'Vladhood' (VLAD), which generated approximately $22 million in trading volume before the post was removed. This page covers the scam ecosystem that emerged on Robinhood Chain and is distinct from Robinhood Markets, Inc. and its legitimate crypto brokerage operations.
avoid.net/bits-of-gold→52/100[CAUTIONARY]Bits of Gold is Israel's largest regulated cryptocurrency broker, founded in 2013 and licensed by the Israeli Capital Market, Insurance and Savings Authority since 2022. On August 16-17, 2026, the company disclosed that a third-party analytics vendor breach exposed personal data on approximately 200,000 customers — including national ID numbers, bank account details, and public wallet addresses — stemming from CVE-2026-72898, an actively exploited zero-day in self-hosted Metabase software. Customer crypto funds and private keys were not compromised, and the company has engaged a cybersecurity incident-response firm while notifying Israeli regulators.
avoid.net/zapper→52/100[CAUTIONARY]Zapper was a DeFi portfolio tracking and interaction platform founded in 2019 that reached 2 million monthly active users and raised approximately $16.5 million from investors including Mark Cuban and Framework Ventures. The platform announced it would permanently shut down all services on August 3, 2026, following a sustained decline in market demand and a damaging April 2025 domain hijacking incident in which attackers socially engineered Zapper's domain registrar to redirect users to a phishing page. The shutdown creates immediate user-protection concerns: lingering wallet permissions granted to Zapper's contracts should be revoked, and the closure creates conditions favorable for scammers to launch fake 'Zapper migration' or 'fund recovery' phishing campaigns targeting former users.
avoid.net/triple-a-treasury-hack-july-2026→28/100[WARNING]Triple-A, a Singapore-based crypto payment platform holding a Major Payment Institution license from the Monetary Authority of Singapore (MAS), suffered an unauthorized access event beginning approximately July 24, 2026, in which approximately $11.8 million in company treasury assets was drained across seven blockchain networks over roughly 31 hours. The attacker consolidated stolen funds as approximately 5,287 ETH at a single Ethereum address. Triple-A stated that client funds were entirely segregated and unaffected, and that the company remained solvent and able to meet all liabilities.
avoid.net/letsbonk-fun→32/100[WARNING]LetsBonk.fun, later rebranded as Bonk.fun, is a Solana-based memecoin launchpad launched on April 25, 2025 by the BONK community in partnership with Raydium Protocol. The platform rose to capture over 78% of Solana launchpad market share at its mid-2025 peak before experiencing steep decline, and suffered a domain hijack and wallet-drainer attack in March 2026. The platform's permissionless token creation model, built-in multi-wallet bundler tooling, and community reports alleging the platform hosted 'KOL-backed bundled scams' present elevated risk for retail investors.
avoid.net/solana-blinks-durable-nonce-drainer-kits-2026→0/100[CRITICAL]A family of increasingly sophisticated wallet-drainer toolkits targeting the Solana ecosystem that weaponize legitimate Solana protocol features — Blinks (blockchain action links), durable nonces, and the system 'assign' instruction — to bypass the transaction-simulation safety layer that most Solana wallets rely on as their primary defense. Documented in detail by security researchers from February 2024 onward and materially escalated in late 2025 and early 2026, these kits are distributed as scam-as-a-service products supporting 90+ wallet types; losses attributable to Solana phishing reached approximately $90 million in H1 2025 alone, before the simulation-bypass generation was widely deployed. A state-level durable-nonce attack on Drift Protocol (April 2026) demonstrated that the same primitive can scale to $285 million in a single operation.
avoid.net/orca→80/100[VERIFIED]Orca is a concentrated-liquidity automated market maker (AMM) and decentralized exchange built on the Solana blockchain, launched in February 2021 by co-founders Grace "Ori" Kwan and Yutaro Mori. Its core product, Whirlpools, is an open-source CLMM protocol with six independent security audits, a verifiable on-chain build, and no confirmed exploits since inception. The protocol operates via a DAO governed by the ORCA token and has expanded to Eclipse mainnet; the primary documented risk factors are residual upgrade-authority centralization, the legacy Three Arrows Capital investor relationship (now defunct), and a 2023 decision to geo-block U.S. users from the web interface without a public regulatory explanation.
avoid.net/blockfi→38/100[WARNING]BlockFi was a cryptocurrency lending platform founded in 2017 by Zac Prince and Flori Marquez, once valued at $3 billion. The company faced a $100 million SEC and state regulator settlement in February 2022 for offering unregistered securities, then collapsed in November 2022 following the implosion of FTX, which had extended BlockFi a $400 million credit facility. After filing Chapter 11 bankruptcy, BlockFi achieved a notable outcome: all creditors received 100% recovery of allowed claims, funded largely by a $874.5 million settlement with FTX/Alameda Research.
avoid.net/three-arrows-capital→2/100[CRITICAL]Three Arrows Capital (3AC) was a Singapore-based cryptocurrency hedge fund founded in 2012 by Su Zhu and Kyle Davies that, at its peak in early 2022, managed an estimated $10 billion in assets. Severe losses from the Terra/LUNA ecosystem collapse in May 2022 triggered cascading margin calls and a liquidity crisis that led to court-ordered liquidation in the British Virgin Islands on June 27, 2022, leaving more than $3.5 billion in creditor claims. The founders subsequently faced arrest warrants, prison sentences for non-cooperation with liquidators, a nine-year regulatory ban by Singapore's Monetary Authority, and fines from Dubai's virtual asset regulator over a failed post-collapse exchange venture.
avoid.net/dodo-amm→62/100[CAUTIONARY]DODO is a decentralized exchange (DEX) and on-chain liquidity protocol launched in August 2020, built around a proprietary Proactive Market Maker (PMM) algorithm that sources external oracle prices to concentrate liquidity and reduce slippage. On March 8, 2021, attackers exploited a reinitialization vulnerability in the V2 Crowdpool smart contracts, draining approximately $3.8 million from four pools; roughly $3.1 million was subsequently returned by white-hat and front-running bots, with an estimated $700,000 remaining unrecovered from the original attacker. No regulatory actions by the SEC, CFTC, or other agencies have been reported against the project or its founders as of August 2026.
avoid.net/lcx→62/100[CAUTIONARY]LCX (Liechtenstein Cryptoassets Exchange) is a regulated crypto exchange and tokenization platform headquartered in Vaduz, Liechtenstein, holding eight registrations under the Liechtenstein Financial Market Authority (FMA) pursuant to the Token and Trusted Technology Service Provider Act (TVTG). In January 2022 the exchange suffered a hot wallet compromise in which approximately $7.94 million in crypto assets were stolen, with stolen funds rapidly laundered through Tornado Cash; LCX subsequently used its own funds to compensate affected users and cooperated with international law enforcement to freeze an alleged 60% of stolen assets. The exchange is flagged by ZachXBT and carries a below-average trust score primarily due to the 2022 hack, ongoing user complaints about withdrawal delays and account freezes, and the broader security posture concerns that led to the compromise.
avoid.net/dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign→0/100[CRITICAL]In April 2026, North Korea-linked threat actors attributed to the Lazarus Group and its subunits executed two separate, high-value cryptocurrency exploits within 18 days — draining approximately $285 million from Drift Protocol on April 1 and approximately $292 million from KelpDAO on April 18. Combined, the two attacks account for an estimated $577–635 million in losses, comprising 76% of all documented cryptocurrency hack value through April 2026 and representing the largest coordinated DPRK crypto theft campaign on record.
avoid.net/lcx-exchange→52/100[CAUTIONARY]LCX Exchange (Liechtenstein Cryptoassets Exchange) is a regulated crypto trading platform incorporated in Liechtenstein and registered with the country's Financial Market Authority (FMA). On January 8, 2022, the exchange suffered a hot wallet compromise resulting in the theft of approximately $6.8–7.94 million in various cryptocurrencies; LCX subsequently covered all user losses from company funds and cooperated with multi-jurisdictional law enforcement, ultimately freezing approximately 60% of stolen assets. As of 2024–2025, LCX remains operational, holds multiple licenses under the Liechtenstein Blockchain Act (TVTG), and has filed a pre-application for a pan-European MiCA license.
avoid.net/atomic-wallet-hack→10/100[CRITICAL]In June 2023, Atomic Wallet — an Estonian non-custodial cryptocurrency wallet with approximately five million users — suffered a major security breach in which attackers drained funds from an estimated 5,500 user wallets. Blockchain analytics firms Elliptic and on-chain investigators attributed the attack to North Korea's Lazarus Group with high confidence, and the FBI later confirmed this attribution. The total loss figure is disputed, with Elliptic placing it above $100 million and independent researcher Taylor Monahan estimating a minimum of $115 million; the underlying attack vector was never publicly confirmed by Atomic Wallet.
avoid.net/playdapp→22/100[CRITICAL]PlayDapp is a South Korean blockchain gaming platform and NFT marketplace founded in 2017 and operating on Ethereum and Polygon. In February 2024, an attacker who had obtained PlayDapp's contract deployer private key via a phishing email added themselves as an authorized minter and minted 1.79 billion PLA tokens across two events, representing a nominal loss of approximately $290 million. The platform subsequently suspended the PLA smart contract and executed a 1:1 migration to a new token (PDA) to remediate the illegitimate token supply.
avoid.net/trifleck→2/100[CRITICAL]Trifleck is a shell company with no verifiable business registration used as a front in an active LinkedIn-based malware campaign targeting crypto and Web3 developers, first publicly disclosed in May 2026. The campaign delivers a malicious 'pre-interview code review' ZIP file containing infostealers after recruiters posing as Trifleck employees contact developers with frontend job offers. The attack pattern, infrastructure, and malware families are consistent with tactics attributed by Microsoft, Mandiant, Palo Alto Unit 42, and the FBI to DPRK-aligned threat actors operating under the cluster known as Contagious Interview.
avoid.net/leap-wallet→62/100[CAUTIONARY]Leap Wallet was a non-custodial multi-chain crypto wallet founded in 2021 and backed by $3.2 million from Pantera Capital and CoinFund. Originally built for the Terra ecosystem, it pivoted to Cosmos after Terra's 2022 collapse and grew to support 100+ chains. On April 3, 2026, the team announced permanent cessation of all products effective May 28, 2026, without disclosing a specific reason, creating an eight-week compressed migration window that raised user security concerns.
avoid.net/edward-zimbardi-the-crypto-program→2/100[CRITICAL]Edward Zimbardi, 59, of Flowery Branch, Georgia, is accused of operating 'The Crypto Program,' an alleged cryptocurrency Ponzi scheme that prosecutors allege collected more than $165 million from at least 6,000 investors worldwide between June 2022 and August 2023 by promising guaranteed 25% monthly returns on fake advertising packages. Zimbardi was indicted on 25 federal counts on July 8, 2026, by a grand jury in the Northern District of Georgia, deported from Fiji on August 14, 2026, and appeared before a federal magistrate in Los Angeles on August 17, 2026. All charges are allegations; no conviction has been entered.
avoid.net/changenow→42/100[WARNING]ChangeNOW is a non-custodial, KYC-optional instant cryptocurrency swap service founded in 2017 and operated by CHN Group LLC, incorporated in Saint Vincent and the Grenadines. The platform supports swaps across more than 1,000 crypto assets without mandatory account registration, a design that has made it a recurrent node in post-exploit fund flows. In 2026 alone, stolen funds from two confirmed major hacks — the Gravity Bridge $5.4 million exploit (May 2026) and the Coinsbuy $7.9 million theft (August 2026) — were reportedly routed through ChangeNOW, though no regulatory enforcement action has been taken against the company as of August 2026.
avoid.net/bitmart-exchange-insolvency-claims-and-frozen-withdrawals-august-2026→12/100[CRITICAL]BitMart, a cryptocurrency exchange operating since 2017, announced an orderly wind-down on July 26, 2026, with all trading to cease by August 26, 2026, and full platform closure by January 31, 2027. Following the announcement, multiple users and at least one market-making firm reported being unable to withdraw assets, on-chain data recorded anomalously low withdrawal activity, and an open letter signed by users and employees gave founder Sheldon Xia until August 19 to disclose financial reserves and a repayment plan. Insolvency has been alleged but not independently confirmed; no regulatory body has filed charges or made a formal finding as of August 17, 2026.
avoid.net/shuffle-shuffle-com→38/100[WARNING]Shuffle (shuffle.com) is a crypto casino and sportsbook launched in February 2023, operated by Natural Nine B.V. under a Curacao Gaming Control Board license, and founded by Noah Dummett alongside co-founders Darcy Spangler and Harley Fresh. In October 2025, Shuffle confirmed a major data breach through third-party CRM provider Fast Track that exposed personal data and KYC documents for the majority of its users. In August 2026, blockchain investigator ZachXBT alleged that stolen victim funds were wagered on Shuffle in real time while the alleged thief was on the phone with the victim; Shuffle confirmed it would lock the associated account after reviewing submitted evidence.
avoid.net/doj-pig-butchering-civil-forfeiture-dc-district-july-2026→10/100[CRITICAL]On July 21, 2026, the U.S. Attorney's Office for the District of Columbia and the U.S. Secret Service Washington Field Office filed five civil forfeiture complaints in federal court seeking to recover more than $25 million in USDT traced to pig butchering fraud schemes operated from Southeast Asia. The filings, which proceed against the cryptocurrency assets themselves and name no individual defendants, targeted funds linked to romance scams, approval phishing, and fake investment platforms that defrauded more than 470 identified victims across the United States and Canada. The action is part of the broader DC Scam Center Strike Force, launched in November 2025, which had restrained or seized more than $832 million in cryptocurrency from Chinese transnational criminal organizations by June 2026.
avoid.net/christopher-delgado-goliath-ventures-inc→2/100[CRITICAL]Christopher Alexander Delgado (age 34, Apopka, Florida) was the President and CEO of Goliath Ventures Inc. (formerly Gen-Z Venture Firm), a Florida-based cryptocurrency investment firm that operated as a Ponzi scheme from at least January 2023 through January 2026. Delgado pleaded guilty on June 30, 2026, in the U.S. District Court for the Middle District of Florida to conspiracy to commit wire fraud, wire fraud, and money laundering in connection with a scheme that raised at least $397 million (per CFTC) to $425 million (per SEC) from over 1,300 to 1,611 investors. On August 11, 2026, both the CFTC and SEC filed separate civil enforcement actions against Delgado and Goliath Ventures; Goliath Ventures ceased operations in February 2026 and filed for bankruptcy in March 2026.
avoid.net/indonesia-pig-butchering-syndicate-live-model-operation-2025-2026→2/100[CRITICAL]An international online fraud syndicate operating out of Sukoharjo and Surakarta in Central Java, Indonesia from approximately July 2025 to May 2026, allegedly defrauding at least 133 U.S. victims of approximately US$2.33 million through romance manipulation and fake cryptocurrency investment platforms, a scheme known as 'pig butchering.' Indonesian police arrested 39 suspects in May 2026 and have engaged the FBI given the predominance of American victims. Charges are pending; no convictions have been entered as of the date of this investigation.
avoid.net/crypto-com-phishing-campaign-email-domain-abuse-august-2026→3/100[CRITICAL]An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.
avoid.net/france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026→8/100[CRITICAL]In late June 2026, an unauthorized intrusion into France's General Directorate of Public Finances (DGFiP) exposed the personal and financial data of an estimated 678,437 taxpayers, including names, addresses, income figures, withholding rates, and tax identifiers. The breach was publicly claimed on August 12, 2026 by a threat actor using the pseudonym ZeroBytes, and confirmed by French authorities on August 14, 2026. The incident directly amplifies an established pattern of violent physical coercion — so-called wrench attacks — against crypto holders in France, which CertiK and Chainalysis both identified as the global epicenter of such attacks in H1 2026.
avoid.net/vanta-stealer-python-infostealer-targeting-crypto-wallets→2/100[CRITICAL]Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.
avoid.net/star-credit-holdings-misam-m-abidi→2/100[CRITICAL]Star Credit Holdings was a Tennessee-based cryptocurrency investment firm operated by Misam M. Abidi (age 47, of Nolensville, Tennessee) from approximately 2020 to 2024. On June 12, 2026, a federal grand jury in the Western District of Tennessee returned an 11-count indictment against Abidi, alleging he ran a classic Ponzi scheme that diverted over $1.9 million in investor funds to himself and family members. Abidi had previously faced state-level regulatory action in May 2024 over a broader alleged fraud involving Star Credit Holdings, a related cryptocurrency token (NUME/NumisMe), and co-defendants Ali Raza Galani and Anisha Abidi, with total alleged investor losses across 17 states exceeding $6.3 million.
avoid.net/misam-m-abidi→2/100[CRITICAL]Misam M. Abidi, 47, of Nolensville, Tennessee, is an independent candidate for Tennessee Governor who was indicted on June 12, 2026 by a federal grand jury in the Western District of Tennessee on 11 counts including wire fraud, money laundering, unlicensed money transmission, and aiding in false tax return preparation. Federal prosecutors allege Abidi operated Star Credit Holdings as a cryptocurrency Ponzi scheme between 2020 and 2024, diverting over $1.9 million of investor funds to himself and family members. Abidi and his associates also face a separate 2024 Tennessee state civil enforcement action involving an alleged $6.3 million fraud spanning 17 states, connected to the STAR Investment Club and the NUME cryptocurrency token issued through NumisMe LLC.
avoid.net/allo-protocol→68/100[CAUTIONARY]Allo Protocol is an open-source, EVM-compatible smart contract framework for on-chain capital allocation, developed by Gitcoin and launched on Ethereum mainnet in November 2023. It served as the underlying infrastructure for Gitcoin Grants Stack from 2023 through May 2025, when Gitcoin's software division (Grants Lab) was shut down due to financial constraints, placing Allo in maintenance mode. No fraud allegations, regulatory actions, or security exploits have been publicly documented against the protocol itself.
avoid.net/ramzinex→2/100[CRITICAL]Ramzinex (formally Ramzineh Electronic Commerce Innovation Company) is a Tehran-based cryptocurrency exchange founded in 2018 that served over one million Iranian users across more than 200 trading pairs. On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control designated Ramzinex on its Specially Designated Nationals list under Executive Order 13902 and Iran-related sanctions authorities, alleging the exchange processed transactions linked to the Islamic Revolutionary Guard Corps and a government-backed Iranian financial institution. The designation carries secondary sanctions exposure, meaning non-U.S. financial institutions that conduct significant transactions with Ramzinex after June 2, 2026, risk correspondent account restrictions and further OFAC action.
avoid.net/allbridge-core-second-flash-loan-exploit-july-2026→20/100[CRITICAL]On July 19–20, 2026, Allbridge Core, a cross-chain stablecoin bridge protocol, suffered a $1.65–1.66 million flash-loan exploit targeting its Solana USDC/USDT liquidity pools — the second structurally similar attack on the protocol since April 2023. An attacker borrowed $1.12 million USDC from Kamino Finance, manipulated the pool's internal stablecoin ratio through rapid swaps, extracted liquidity at distorted rates, then bridged the proceeds to Ethereum before the protocol was paused. The incident raised serious questions about the completeness of post-2023 remediation, specifically the failure to apply the protocol's own 'single-pool per blockchain' fix to its Solana deployment.
avoid.net/node-gyp-npm-supply-chain-compromise-june-2026→0/100[CRITICAL]In June 2026, a self-propagating npm supply chain worm designated 'Miasma' exploited a novel install-time execution technique called 'Phantom Gyp' — abusing binding.gyp configuration files to trigger malicious code during npm install. The campaign spread across 57 packages and 286+ malicious versions, harvesting developer and CI/CD credentials from npm, GitHub, AWS, GCP, Azure, HashiCorp Vault, and Kubernetes, and then self-propagating by republishing poisoned releases using stolen publishing tokens. The attack poses a direct threat to crypto developers whose CI/CD pipelines manage private keys, wallet seed phrases, and signing infrastructure.
avoid.net/phantom-gyp-npm-supply-chain-attack-june-2026→0/100[CRITICAL]On June 3, 2026, attackers deployed a self-replicating worm across 57 npm packages in 286 malicious versions within under two hours, using a novel technique dubbed 'Phantom Gyp' that abused binding.gyp build configuration files to execute malicious code during npm install while bypassing all mainstream lifecycle-script security scanners. The campaign — classified as the latest wave of the Miasma/Shai-Hulud worm family — targeted CI/CD credential stores across AWS, GCP, Azure, GitHub, Kubernetes, and developer password managers, and included novel persistence mechanisms that injected backdoors into AI coding assistant configurations. The highest-profile victim was @vapi-ai/server-sdk (408,000+ monthly downloads), though Vapi confirmed the four compromised versions received zero downloads before removal.
avoid.net/summer-finance-summer-fi→28/100[WARNING]Summer Finance, operating as Summer.fi, was a DeFi yield-optimization protocol that spun out of the Maker Foundation in 2021 and rebranded from Oasis.app in June 2023. On July 6, 2026, its Lazy Summer Protocol was exploited for approximately $6.04 million through a share-price manipulation attack that leveraged stale-valued tokens left over from the November 2025 collapse of Stream Finance. Following the exploit, the company announced it would cease operations, with the Summer.fi application shutting down on August 31, 2026, and governance of remaining vault infrastructure transitioning to the Lazy Summer DAO.
avoid.net/coinkite-coldcard→18/100[CRITICAL]Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.
avoid.net/oraichain-evm-cross-chain-unauthorized-minting-exploit-august-2026→28/100[WARNING]On August 9, 2026, Oraichain — an AI-focused Layer 1 blockchain — suffered a supply-integrity exploit in which a vulnerability in its EVM cross-chain transfer path enabled the unauthorized minting of ORAI tokens. The team halted the entire network at 04:00 UTC, restricted all bridges and cross-chain routes, and coordinated with centralized exchanges including MEXC to freeze fund movements. As of mid-August 2026, the exploit path had been addressed, the network had been restored, and the team was preparing to burn the unauthorized minted balances to reconcile canonical ORAI supply.
avoid.net/crypto-whale-repeat-phishing-drain-august-2026→10/100[CRITICAL]On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.
avoid.net/jewelbug-apt→2/100[CRITICAL]Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.
avoid.net/wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026→2/100[CRITICAL]WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660), which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026. Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework. Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation, link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host), and report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor; the two campaigns share the npm supply-chain vector but have distinct infrastructure and attribution.
avoid.net/ravedao→2/100[CRITICAL]RaveDAO is a Web3 entertainment protocol that markets itself as a community bridging electronic dance music culture with blockchain-based ticketing, governance, and event access. Its native token, RAVE, launched on Binance Alpha in December 2025 and experienced a ~10,800% price surge in April 2026 before collapsing approximately 95% within 48 hours amid substantial on-chain evidence of insider supply control and an alleged coordinated 'bait and liquidate' short-squeeze scheme. Binance, Bitget, and Gate.io opened formal investigations; on-chain investigator ZachXBT publicly accused the project's affiliated insiders of engineering the rally and named RAVE as part of a broader pattern of Bitget-enabled market-maker fraud.
avoid.net/heisenberg-guru-hsbg→4/100[CRITICAL]Heisenberg Guru (HSBG) is a Hong Kong-based cryptocurrency market maker alleged by on-chain investigator ZachXBT to have orchestrated coordinated supply-control manipulation schemes across at least six tokens — RIVER, RAVE, SIREN, MYX, SKYAI, and LAB — primarily through Bitget, with Binance and Gate.io as secondary venues. On May 19, 2026, ZachXBT posted a $10,000 personal bounty for insider evidence identifying the firm's operators, naming 'Sion' and 'Chao' as core team members. As of May 31, 2026, HSBG has not publicly responded to the allegations, no regulatory action has been confirmed, and the bounty remains open.
avoid.net/rossen-iossifov-rg-coins→2/100[CRITICAL]Rossen G. Iossifov, a 53-year-old Bulgarian national, owned and operated RG Coins, a cryptocurrency exchange in Sofia, Bulgaria that served as the primary off-ramp for the Alexandria (Romania) Online Auction Fraud Network, laundering nearly $5 million in crypto proceeds defrauded from approximately 900 American victims. Convicted in 2020 and sentenced in January 2021 to 121 months in federal prison, Iossifov was charged again in July 2026 with allegedly conspiring from his prison cell to steal and launder $290,000 in cryptocurrency that had already been ordered forfeited to the United States government following his prior conviction.
avoid.net/probit-global→23/100[CRITICAL]ProBit Global was a South Korea-founded centralized cryptocurrency exchange that operated from 2018 until it permanently terminated all services by April 1, 2026. The shutdown followed an inability or unwillingness to obtain MiCA licensing for EU/EEA users and a stated broader regulatory and restructuring rationale for global operations. The wind-down included a controversial abandoned-funds clause under which assets not withdrawn by April 1, 2026 were deemed permanently lost, as well as a monthly administrative fee of up to 10% of balances during the grace period, raising significant consumer-protection concerns.
avoid.net/alephium→34/100[WARNING]Alephium is a Swiss-founded Proof-of-Work Layer-1 blockchain launched November 8, 2021, featuring sharded smart contracts and the Proof-of-Less-Work consensus mechanism. On May 29-30, 2026, its TokenBridge was exploited for approximately $815,000 in approximately seven minutes via an off-chain backend vulnerability that allowed forged guardian messages to authorize unauthorized transfers and the minting of 13.76 million unbacked wrapped ALPH tokens. The team took the bridge offline, burned the unauthorized tokens, and committed to full user compensation.
avoid.net/helium→58/100[CAUTIONARY]Helium is a decentralized physical infrastructure network (DePIN) founded in 2013 by Amir Haleem, Shawn Fanning, and Sean Carey, operated by Nova Labs, Inc. The network incentivizes individuals to deploy wireless hotspots for IoT (LoRaWAN) and mobile coverage using its HNT token, which migrated to the Solana blockchain in April 2023. The project has a documented history of misrepresenting partner relationships to investors, resulting in a $200,000 SEC civil settlement in April 2025, but has demonstrated meaningful real-world usage growth through verified carrier data-offload partnerships with AT&T, T-Mobile, and Telefonica.
avoid.net/eclipse→32/100[WARNING]Eclipse is a Layer 2 blockchain on Ethereum that uses the Solana Virtual Machine (SVM) for execution, Celestia for data availability, and Ethereum for settlement. Developed by Eclipse Labs and launched on mainnet in November 2024, the project has experienced significant turbulence including the removal of its founder over sexual misconduct allegations, a heavily criticized token airdrop, a 95% TVL collapse, and a 65% workforce reduction in August 2025. As of early 2026, the project publicly admitted it had 'no users' and pivoted to building consumer applications in-house.
avoid.net/george-santos-cftc-prediction-market-manipulation→8/100[CRITICAL]Former U.S. Congressman George Anthony Devolder Santos was found by the Commodity Futures Trading Commission to have manipulated event contracts on the prediction market platform Kalshi by trading on his own attendance at the 2026 State of the Union address while making misleading public statements on social media to move contract prices in his favor. On July 31, 2026, Santos settled the action — without admitting or denying the findings — agreeing to disgorge $17,569.98 in profits, pay a $17,500 civil monetary penalty, and accept a three-year ban from all CFTC-registered entities. The case is described by multiple outlets as the first federal sanction imposed for political prediction market manipulation, though it follows separate earlier CFTC enforcement activity targeting insider trading in event contracts.
avoid.net/axiom-dex-insider-trading-broox-bauer→14/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that Broox Bauer, a senior business development employee at Axiom Exchange — a Solana-based trading platform backed by Y Combinator — exploited internal dashboard access controls to retrieve private user wallet data and coordinate front-running trades over approximately ten months. The alleged scheme involved compiling key opinion leader (KOL) wallet addresses into shared Google Sheets to position ahead of anticipated price moves, with alleged profits cited at over $400,000. Axiom stated it was shocked, revoked access, and pledged an internal investigation; no independent forensic audit or formal regulatory action had been publicly announced as of June 2026.
avoid.net/axiom-dex→28/100[WARNING]Axiom is a Solana-based crypto trading platform founded in 2024 by Henry Zhang ('Mist') and Preston Ellis ('Cal'), which completed Y Combinator's Winter 2025 batch and generated over $390 million in cumulative revenue. In February 2026, blockchain investigator ZachXBT published a documented investigation revealing that a senior business development employee, Broox Bauer, along with colleagues, systematically abused internal dashboard tools with insufficient access controls to access private user wallet data and conduct insider trading for over 10 months beginning in early 2025. Axiom confirmed the breach, removed access to the implicated tools, and pledged an internal investigation, but no formal legal charges had been publicly filed as of the date of reporting.
avoid.net/broox-bauer-axiom-insider-trading-ring→6/100[CRITICAL]Broox Bauer, a senior business development employee at Axiom Exchange, was publicly identified in February 2026 by on-chain investigator ZachXBT as the alleged orchestrator of an insider trading scheme running from early 2025. Bauer allegedly abused internal access to Axiom's customer support dashboard to extract private wallet data belonging to users and key opinion leaders, sharing that data with a small group to front-run trades. Axiom, a Y Combinator-backed Solana trading terminal that generated over $390 million in cumulative revenue, acknowledged the misconduct, terminated access to the relevant tools, and stated it would investigate and hold the responsible parties accountable.
avoid.net/axiom-trading→38/100[WARNING]Axiom Trading (axiom.trade) is a Y Combinator Winter 2025-backed Solana trading terminal that generated over $390 million in revenue since its January 2025 launch. In February 2026, blockchain investigator ZachXBT published a report alleging that senior business development employee Broox Bauer and associates systematically abused internal customer support tools to access private user wallet data and front-run customer trades for more than ten months, with alleged profits exceeding $400,000. Axiom removed access to the implicated tools and stated it was investigating, but no public disclosure of disciplinary or legal outcomes had been made as of June 2026.
avoid.net/gemini→58/100[CAUTIONARY]Gemini is a New York-based cryptocurrency exchange and custodian bank founded in 2015 by Cameron and Tyler Winklevoss, regulated under a NYDFS Limited Purpose Trust Charter. The exchange gained significant notoriety following the collapse of its Gemini Earn lending program in late 2022, which left approximately 340,000 users with roughly $900 million in frozen assets; subsequent SEC and NYDFS enforcement actions were resolved by early 2024 and 2026 respectively with full customer restitution. Gemini went public on the Nasdaq in September 2025 under the ticker GEMI, but its stock has since declined more than 80% amid deepening losses, executive departures, mass layoffs, and a contested post-IPO strategic pivot to prediction markets.
avoid.net/bitmex→56/100[CAUTIONARY]BitMEX (Bitcoin Mercantile Exchange) is a cryptocurrency derivatives exchange founded in 2014 by Arthur Hayes, Ben Delo, and Samuel Reed that pioneered the perpetual swap contract and at its peak was one of the largest crypto derivatives platforms in the world. In October 2020, the CFTC and DOJ charged the exchange and its co-founders with operating an unregistered trading platform and willfully failing to implement anti-money laundering and know-your-customer programs in violation of the Bank Secrecy Act. All three co-founders subsequently pleaded guilty, the exchange paid a $100 million civil settlement, and in March 2025 the founders and the corporate entity received presidential pardons from Donald Trump.
avoid.net/liquid-global→10/100[CRITICAL]Liquid Global (operating under its parent entity Quoine Pte. Ltd.) was a Japanese-headquartered cryptocurrency exchange founded in 2014 and rebranded from QUOINE to Liquid in 2018. In August 2021, the exchange suffered one of the largest exchange hacks of that year — approximately $97 million in Bitcoin, Ethereum, XRP, TRON, and other tokens stolen — with the attack subsequently attributed by Chainalysis to actors working on behalf of the DPRK, consistent with Lazarus Group tradecraft. FTX provided a $120 million emergency loan days after the breach, then acquired Liquid outright in April 2022; when FTX itself filed for Chapter 11 bankruptcy in November 2022, Liquid halted all withdrawals and customer funds were caught in the subsequent restructuring proceedings.
avoid.net/blockchain-capital→68/100[CAUTIONARY]BCAP is the world's first tokenized venture capital fund interest, issued in April 2017 as a Regulation D security token. It represents a non-voting economic interest in Blockchain Capital's Fund III. The firm manages $2B+ AUM with portfolio companies including Coinbase, Kraken, and Circle. Key risks include a $6.3M SIM-swap attack on co-founder Bart Stephens, Brock Pierce founding controversy, Epstein/Coinbase periphery connections, and effectively zero secondary market liquidity despite the token wrapper. No SEC enforcement actions exist.
avoid.net/fbi-fake-token-tron-impersonation-wallet-freeze-extortion-scam-march-2026→2/100[CRITICAL]In March 2026, an unidentified threat actor deployed fraudulent TRC-20 tokens on the Tron network branded as FBI assets and airdropped them to at least 728 wallets, including high-net-worth addresses holding seven-figure USDT balances. The tokens carried messages falsely claiming recipient wallets were frozen for anti-money laundering violations and directed holders to an external phishing site demanding identity and credential submission. The FBI's New York Field Office issued an official warning on March 19, 2026, confirming it does not distribute tokens or request blockchain-based identity verification of any kind.
avoid.net/clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026→0/100[CRITICAL]A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.
avoid.net/ai-powered-crypto-phishing-infrastructure-2026→2/100[CRITICAL]A broad, industrialized criminal ecosystem has emerged in 2025–2026 in which threat actors use generative AI tools — including large language models, deepfake video engines, and voice-cloning services — to produce and operate crypto phishing infrastructure at unprecedented scale. Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods. Law enforcement agencies across the US, UK, and Canada have begun coordinated enforcement actions, but the pace of tool proliferation continues to outpace disruption.
avoid.net/malone-lam-crypto-syndicate→0/100[CRITICAL]The Malone Lam Crypto Syndicate, also known as the Social Engineering Enterprise (SEE), is an alleged multi-state criminal organization that stole approximately $263 million in cryptocurrency between October 2023 and May 2025 through social engineering, residential home invasions, and hardware wallet theft. Led by Singaporean national Malone Lam (alias 'Anne Hathaway', 'Greavys'), the enterprise comprised at least 14 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars. The DOJ charged the organization under the RICO statute — one of the most aggressive crypto theft prosecutions ever filed — and as of June 2026, nine co-defendants have pleaded guilty and been sentenced to 70–78 months, while Lam and co-lead Jeandiel Serrano remain in pre-trial proceedings.
avoid.net/requests-secure-v2→0/100[CRITICAL]requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.
avoid.net/debank-auction→2/100[CRITICAL]debank[.]auction is a malicious domain impersonating DeBank (debank.com), a legitimate decentralized finance portfolio tracker founded in 2018. Documented by Zscaler ThreatLabz in July 2026, the site combines typosquatting with indirect prompt injection (IPI) — embedding hidden instructions in its HTML to manipulate AI agents into misclassifying the fraudulent domain as the authoritative DeBank platform. The campaign represents an active, real-world exploitation of autonomous AI agents rather than solely targeting human users.
avoid.net/vy-pham→4/100[CRITICAL]Vy Pham is a California-based cryptocurrency promoter charged in October 2024 by both the U.S. Department of Justice (DOJ) and the U.S. Securities and Exchange Commission (SEC) in connection with alleged market manipulation of two meme tokens: Saitama Inu and Robo Inu Finance. Pham agreed to plead guilty to conspiracy to commit market manipulation, conspiracy to commit wire fraud, and operating an unlicensed money transmitting business. The charges are part of a coordinated federal enforcement action, Operation Token Mirrors, which targeted 18 individuals and entities for widespread fraud in cryptocurrency markets.
avoid.net/rainberry-inc→25/100[CRITICAL]Rainberry Inc, formerly BitTorrent Inc and the developer of the BitTorrent protocol and BitTorrent Token (BTT), agreed in March 2026 to pay a $10 million civil penalty to settle SEC allegations that it facilitated wash trading to artificially inflate trading volume for the TRX cryptocurrency in 2018–2019. The settlement, filed as a proposed final judgment in U.S. District Court for the Southern District of New York, did not require any admission of wrongdoing. All remaining claims against Rainberry, Justin Sun (Tron founder and controlling owner), Tron Foundation, and BitTorrent Foundation were dismissed with prejudice.
avoid.net/mev-bot-scam-youtube-ai-trading-bot-campaign-2026→2/100[CRITICAL]An ongoing campaign, active since at least mid-2022 and continuing through 2025, uses AI-generated YouTube videos to promote malicious Solidity smart contracts disguised as Maximal Extractable Value (MEV) arbitrage trading bots. According to SentinelOne Labs (SentinelLABS), one attacker wallet alone collected approximately 244.9 ETH (roughly $902,000 USD) from victims, with total documented losses across the broader campaign exceeding $1 million. Victims are deceived into deploying backdoored contracts via Remix IDE and depositing ETH, which is then routed directly to attacker-controlled wallets through obfuscated code.
avoid.net/ravencoin-consensus-vulnerability-exploit-august-2026→10/100[CRITICAL]On August 7, 2026, an attacker exploited a critical consensus vulnerability in the Ravencoin (RVN) network by manipulating the nHeight field in KAWPOW block headers to bypass proof-of-work verification. Invalid blocks were accepted by vulnerable nodes beginning at block height 4,487,776, prompting exchanges Upbit, Bitget, and Bitvavo to suspend RVN deposits and withdrawals and causing RVN to fall approximately 19% to around $0.00288. An emergency patch (v4.6.1.1-hf1) was released on August 10, 2026 by mining pool 2Miners rather than Ravencoin's core development team, marking at least the third significant consensus-level failure in the network's history.
avoid.net/htx-fca-uk-enforcement-illegal-crypto-promotions-2026→18/100[CRITICAL]The UK Financial Conduct Authority commenced High Court proceedings on 21 October 2025 against Huobi Global S.A. (the Panamanian entity behind the HTX exchange, formerly Huobi) and multiple categories of 'persons unknown', alleging repeated breach of Section 21 of the Financial Services and Markets Act 2000 by promoting cryptoasset services to UK consumers without authorisation. This is the FCA's first enforcement action against an offshore crypto exchange for illegal financial promotions. As of August 2026, proceedings are stayed while settlement talks continue; no court ruling on the merits has been issued.
avoid.net/bitradex→4/100[CRITICAL]BitradeX (operating primarily at bitradex.ai and previously bitradex.com) is an alleged MLM-structured cryptocurrency trading platform that markets AI-powered trading bots promising annualised returns of 109.5%–182.5%. Launched in early 2025 and promoted via French footballer Olivier Giroud as global brand ambassador from June 2025, the platform has received formal investor warnings from three regulators — Thailand's SEC (February 2026), Securities Commission Malaysia (March 2026), and the Alberta Securities Commission (April 2026) — each citing lack of registration or authorisation. BehindMLM and other analyst sources characterise the scheme as a Ponzi and pyramid hybrid with no retail product, Chinese-origin ownership obscured behind a UK-registered shell, and a pattern of withdrawal blocks consistent with schemes in terminal decline. As of August 2026, the platform reportedly ceased withdrawals and deployed an exit-scam narrative.
avoid.net/coreum-xrpl-bridge-exploit-august-2026→12/100[CRITICAL]On August 9, 2026, an attacker exploited a deposit-verification flaw in the cross-chain bridge connecting the XRP Ledger to the Coreum blockchain (operated by tx, formerly Coreum and Sologenic), draining 199,916.3 XRP — approximately $200,000 and 99.7% of the bridge's total reserve — across 94 multisig transactions over 97 minutes. The bridge was halted by tx as of August 11, 2026; bridged XRP on the tx chain is not fully backed as of the most recent reporting, and no compensation plan had been announced as of August 13, 2026.
avoid.net/unidentified-crypto-whale-25-6m-repeated-phishing-drain→0/100[CRITICAL]On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.
avoid.net/shipmonk→28/100[WARNING]ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.
avoid.net/ascendex→5/100[CRITICAL]AscendEX (formerly BitMax), a centralized cryptocurrency exchange founded in 2018, ceased all normal operations on July 1, 2026, after a capital restructuring deal with The Royal Investment Bank of Kelantan Inc. (RIBK) collapsed. The exchange froze automated withdrawals on July 6, 2026, disclosed it may be insolvent, and explicitly stated it could not guarantee full recovery of customer funds. The closure compounded a prior $77.7 million hot-wallet breach suffered in December 2021.
avoid.net/mica-non-compliant-exchange-risk-cluster-post-july-1-2026→8/100[CRITICAL]From July 1, 2026, the EU's Markets in Crypto-Assets Regulation (MiCA) entered full enforcement, requiring all crypto-asset service providers (CASPs) serving EU residents to hold a valid authorisation from an EU national competent authority. Approximately 80% of previously operating exchanges failed to obtain authorisation by the deadline, creating a systemic consumer-protection risk cluster in which EU retail users holding assets on unlicensed platforms face potential account restrictions, withdrawal freezes, and — in at least one documented case (AscendEX) — possible permanent loss of funds due to exchange insolvency. ESMA maintains a formal register of both authorised CASPs and flagged non-compliant entities, but coverage of the latter is acknowledged to be incomplete.
avoid.net/ascendex-insolvency-and-withdrawal-freeze-july-2026→2/100[CRITICAL]AscendEX (formerly BitMax), a Singapore-headquartered centralized crypto exchange founded in 2018, ceased all operations on July 1, 2026, citing a failure to obtain EU MiCA authorization and the collapse of a strategic liquidity transaction. On-chain data showed exchange reserves dropped by more than $240 million on June 20, 2026; by July 8 only approximately $13.45 million remained on-chain, over $12 million of which consisted of the exchange's own illiquid ASD and UNITE tokens. As of the investigation date, automated withdrawals have been frozen since July 6, 2026, replaced with a manual review process offering no guaranteed timeline or recovery amounts, and the exchange's own legal notice warned that formal insolvency proceedings could follow.
avoid.net/ascendex-bitmax→12/100[CRITICAL]AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.
avoid.net/chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-2026→0/100[CRITICAL]ChainDrop is a self-propagating npm supply chain worm discovered on August 4, 2026, representing the latest wave of the Mini Shai-Hulud malware family attributed to the threat group TeamPCP. By compromising the GitHub account of open-source maintainer Jared Wray (jaredwray), attackers injected a two-stage credential-harvesting payload into the widely used keyv and cacheable package ecosystems, which then self-propagated to over 440 additional npm packages representing approximately 2 billion combined monthly downloads. A distinguishing technical characteristic is the worm's use of an Ethereum smart contract for dynamic command-and-control infrastructure, a technique known as EtherHiding, which explicitly targets crypto and Web3 developer tooling alongside cloud and CI/CD credentials.
avoid.net/tanstack-npm-supply-chain-attack-mini-shai-hulud-teampcp→0/100[CRITICAL]On May 11, 2026, threat actor group TeamPCP executed a sophisticated supply chain attack against the TanStack npm ecosystem, compromising 42 packages across 84 malicious versions collectively downloaded millions of times per week. The attack, branded internally as the 'Mini Shai-Hulud' worm, chained three GitHub Actions vulnerabilities to extract an OIDC token from runner memory and autonomously publish credential-stealing payloads that spread to over 170 additional npm and PyPI packages including Mistral AI, UiPath, and OpenSearch. The campaign is the fourth documented wave from TeamPCP, a group active since at least late 2024, and represents the first recorded npm worm to produce validly-attested malicious packages under SLSA Build Level 3 provenance.
avoid.net/miasma-redhat-npm-supply-chain-attack→2/100[CRITICAL]Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.
avoid.net/shai-hulud-teampcp-supply-chain-attack→0/100[CRITICAL]Shai-Hulud is a self-replicating supply chain worm attributed to the financially motivated threat group TeamPCP (also tracked as DeadCatx3, PCPcat, ShellForce, CipherForce, and UNC6780 by Google's Threat Intelligence Group). Active since September 2025, the campaign has compromised hundreds of npm and PyPI packages by harvesting CI/CD credentials through malicious preinstall lifecycle hooks, directly enabling the Trust Wallet Chrome extension hack of December 2025 in which approximately $8.5 million was stolen from 2,520 wallets. As of June 2026, the campaign remains active through copycat variants following TeamPCP's public open-sourcing of the worm's source code on May 12–13, 2026.
avoid.net/rushi-manche→12/100[CRITICAL]Rushikesh 'Rushi' Manche is the co-founder and former CEO of Movement Labs (MVMT Labs, Inc.), a blockchain infrastructure startup that raised at a $3 billion valuation and launched the MOVE token in December 2024. He was suspended on May 2, 2025 and terminated on May 7, 2025 following a third-party investigation by Groom Lake that, according to Movement Labs, linked him to a controversial market-making arrangement with intermediary Rentech and Chinese firm Web3Port that allegedly enabled a coordinated dump of approximately 66 million MOVE tokens within 24 hours of launch, causing an estimated $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the MOVE token launch is confirmed; as of the date of this page no charges, indictment, or criminal finding against Manche has been publicly reported. MVMT Labs filed for Chapter 11 bankruptcy on July 15, 2026, listing Manche as its largest unsecured creditor with a $1.6 million claim while he simultaneously retains a 34.25% equity stake in the company.
avoid.net/movement-labs→8/100[CRITICAL]Movement Labs, the original development company behind the Movement blockchain and MOVE token, filed for Chapter 11 bankruptcy on July 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware. The filing followed a prolonged crisis triggered by a December 2024 market-making arrangement in which 66 million MOVE tokens — approximately 5% of total supply — were sold into the market one day after the token's exchange debut, creating roughly $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the token launch is ongoing as of mid-2026, and MOVE has lost over 94% of its peak value.
avoid.net/storj-labs→28/100[WARNING]Storj Labs, the company behind the decentralized cloud storage protocol and STORJ token, filed for voluntary Chapter 11 bankruptcy protection on July 26, 2026 in the U.S. Bankruptcy Court for the Northern District of West Virginia (case 5:26-bk-00512). The company attributes the filing to legacy financial obligations predating its current operating strategy, not to operational failure, and states that its decentralized storage network and customer services remain uninterrupted. STORJ token holders face significant uncertainty: the company has proposed an equity conversion mechanism, but terms remain undisclosed, court approval is required, and token holders rank behind all creditors under standard bankruptcy law.
avoid.net/novatech-ltd-cynthia-petion-650m-crypto-mlm-fraud→2/100[CRITICAL]NovaTech Ltd. (also marketed as NovaTech FX), incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion, is alleged by U.S. and Canadian regulators to have operated a fraudulent multi-level marketing and crypto investment scheme from June 2019 through May 2023 that raised more than $650 million from over 200,000 investors worldwide. The SEC filed a civil complaint on August 12, 2024, alleging the scheme functioned as a Ponzi, with new investor funds used to pay earlier participants rather than traded as claimed. Regulatory bodies in three jurisdictions — the U.S. SEC, Ontario's Capital Markets Tribunal, and the Maryland Securities Commissioner — have each taken enforcement action; as of the investigation date, the SEC civil litigation remains ongoing and no criminal convictions have been entered.
avoid.net/263m-rico-social-engineering-crypto-theft-gang-dc-2024-2026-prosecutions→0/100[CRITICAL]The Social Engineering Enterprise (SEE) is a multi-state organized crime network that prosecutors allege stole over $263 million in cryptocurrency from multiple victims between October 2023 and May 2025, including over 4,100 Bitcoin from a single Washington, D.C. resident on August 18, 2024 — described by federal prosecutors as one of the largest single-victim cryptocurrency thefts in U.S. history. Formed through online gaming platform connections and prosecuted under the federal RICO statute in the U.S. District Court for the District of Columbia, the enterprise had 17 individuals charged as of late 2025, with 9 guilty pleas entered and at least two sentencings completed as of mid-2026.
avoid.net/hong-kong-insurance-agent-romance-scam-fake-crypto-app-3-3m-july-2026→0/100[CRITICAL]In late July 2026, Hong Kong police reported that a woman in her fifties working in insurance lost more than HK$26 million (approximately US$3.3 million) to a pig-butchering romance scheme involving a fraudulent cryptocurrency investment application that displayed fabricated returns exceeding 800%. The case was the largest among 25 romance-linked investment fraud cases recorded by Hong Kong police in the week of July 24–30, 2026, which collectively resulted in losses of nearly HK$70 million (approximately US$8.9 million). No specific perpetrators have been publicly named or charged as of the reporting date.
avoid.net/lido-finance→70/100[CAUTIONARY]Lido Finance is the largest Ethereum liquid-staking protocol, launched in December 2020, enabling users to stake ETH and receive the liquid derivative token stETH without meeting the standard 32 ETH validator minimum. Governed by the Lido DAO via the LDO token, the protocol held approximately 24% of all staked ETH and roughly $19 billion in TVL as of early 2026. Lido carries no fraud or exit-scam history, but poses well-documented systemic centralization risk to Ethereum consensus, governance-concentration concerns among LDO token holders, and faces an active US federal securities lawsuit alleging that LDO is an unregistered security.
avoid.net/kamino-finance→74/100[CAUTIONARY]Kamino Finance is a Solana-based DeFi protocol that combines automated concentrated-liquidity vaults, a lending and borrowing market (K-Lend), and leveraged yield strategies. Launched in August 2022 as a spin-off from Hubble Protocol, it has grown to become the largest DeFi protocol by total value locked on Solana, with multi-billion-dollar deposits as of 2026. The protocol has maintained a zero-bad-debt record since launch, completed more than ten independent security audits, and operates a $1.5 million bug bounty program, though centralization risks around upgrade authority keys and token distribution remain publicly documented concerns.
avoid.net/nicolo-nourafchan-robert-yadgarov-sec-doj-insider-trading-ring→2/100[CRITICAL]On May 6, 2026, the SEC and DOJ charged 30 individuals — with the SEC filing civil charges against 21 of them — in connection with an alleged decade-long insider trading scheme orchestrated by M&A attorney Nicolo Nourafchan and his partner Robert Yadgarov. Nourafchan allegedly misappropriated material nonpublic information from confidential client files at multiple elite BigLaw firms including Sidley Austin, Latham & Watkins, Cleary Gottlieb, and Goodwin Procter, then distributed tips through a tiered network of middlemen and traders in exchange for cash kickbacks. The alleged scheme spanned roughly 30 M&A transactions, generated tens of millions of dollars in illicit profits, and involved fugitives in Russia and Israel as well as international regulatory cooperation across five foreign jurisdictions.
avoid.net/bandcampro-ai-assisted-fraud-campaign→2/100[CRITICAL]Between September 2025 and May 2026, a solo Russian-speaking threat actor operating under the handle 'bandcampro' conducted a sustained AI-assisted fraud and credential-theft campaign targeting MAGA and QAnon communities to steal cryptocurrency. The actor deployed a jailbroken Google Gemini CLI — with safety guardrails persistently disabled via a GEMINI.md context injection file — as the operational backbone of an automated social engineering, influence operation, and hacking pipeline. The campaign is documented in a May 2026 Trend Micro research report titled 'Inside the 5-Year Influence and Fraud Patriot Bait Campaign.'
avoid.net/injective-protocol→55/100[CAUTIONARY]Injective Protocol is a Layer 1 blockchain built on the Cosmos SDK, designed for decentralized finance applications including derivatives, perpetuals, and spot trading via a fully on-chain order book. Founded in 2018 by Eric Chen and Albert Chon and backed by Binance Labs, Pantera Capital, and Mark Cuban, it launched its canonical mainnet in November 2021 and has grown to a top-tier DeFi chain. No regulatory enforcement actions have been identified against Injective; however, concerns exist around a 2025-2026 bug bounty dispute involving an alleged $500 million critical vulnerability, validator stake concentration, and third-party scams impersonating the protocol.
avoid.net/chainlink→67/100[CAUTIONARY]Chainlink is a decentralized blockchain oracle network founded in 2017 by Sergey Nazarov and Steve Ellis, with Cornell University professor Ari Juels co-authoring the whitepaper. The protocol provides smart contracts with tamper-resistant access to off-chain data and computation, holding an estimated 69–70% share of the oracle market and enabling over $26 trillion in cumulative transaction value as of 2025. No regulatory actions have been filed against Chainlink or its parent entity, Chainlink Labs; the primary documented concerns center on token-supply centralization and a 2020 campaign by an anonymous entity publishing unverified fraud allegations that were subsequently discredited.
avoid.net/ethereum→64/100[CAUTIONARY]Ethereum (ETH) is the second-largest cryptocurrency by market capitalization (~$278 billion as of May 2026) and the leading smart-contract platform, hosting the majority of decentralized finance (DeFi) and NFT activity. The protocol has a documented history of governance controversy stemming from the 2016 DAO hack hard fork, ongoing centralization concerns around liquid staking and MEV infrastructure, and persistent smart-contract and phishing-based fraud targeting end users, though Ethereum itself has not been the subject of any regulatory enforcement action and its spot ETFs have received SEC approval.
avoid.net/nexo→34/100[WARNING]Nexo is a crypto lending and yield platform founded in 2018 by Antoni Trenchev and Kosta Kantchev, incorporated in the Cayman Islands, that grew to over $11 billion in assets under management. The company paid a $45 million settlement to the SEC and a multistate coalition of regulators in January 2023 over the unregistered offer and sale of its Earn Interest Product, and exited the US market in late 2022. A Bulgarian criminal investigation launched simultaneously was closed in December 2023 for lack of evidence, after which Nexo filed a $3 billion ICSID arbitration claim against Bulgaria; Nexo formally reentered the US market in February 2026 in partnership with Bakkt.
avoid.net/voyager-digital→0/100[CRITICAL]Voyager Digital was a US-based cryptocurrency brokerage and lending platform founded in 2018 that grew to 3.5 million users and $5.9 billion in assets before filing for Chapter 11 bankruptcy on July 5, 2022, following a $650 million loan default by Three Arrows Capital. The company's collapse resulted in customers losing access to funds, multiple federal regulatory actions against the firm and its CEO Stephen Ehrlich, and the failure of two successive acquisition deals by FTX and Binance.US. After a court-approved liquidation plan in May 2023, creditors received partial distributions estimated at approximately 70% of claims across multiple tranches through 2024.
avoid.net/duelbits→32/100[WARNING]DuelBits is a Curacao-licensed crypto casino and sportsbook operated by Liquid Entertainment N.V., launched in 2020. The platform suffered a confirmed $4.6 million private key compromise on February 13, 2024, affecting wallets on both the Ethereum and BNB Chain networks. DuelBits has also been flagged in broader contexts related to unlicensed gambling promotion, Twitch's 2022 ban on unlicensed gambling streams, and mixed user reports of withdrawal delays and account-closure disputes.
avoid.net/july-2026-bridge-hack-wave-three-protocols-35-6m-one-day→0/100[CRITICAL]On July 22–23, 2026, three separate cross-chain bridge protocols — AFX Trade, B-Squared Network, and Verus — were exploited within approximately six hours of each other for a combined loss of roughly $35.6 million. The incidents contributed to a July 2026 monthly total of approximately $97 million in crypto security losses and are part of a record-setting H1 2026 in which total hack losses surpassed $1 billion across the industry. No single threat actor has been publicly attributed to all three attacks, though the clustering prompted security firm Blockaid to label the period 'Hackers Day.'
avoid.net/levana-perps→32/100[WARNING]Levana Perps is a decentralized perpetual-swap protocol originally deployed on Osmosis (Cosmos ecosystem) and later expanded to Sei and Injective. In December 2023, the protocol suffered a confirmed oracle-manipulation exploit spanning 13 days that drained approximately $1.14 million (roughly 10% of liquidity provider funds). The protocol subsequently underwent a strategic rebrand and token migration into the Rujira (RUJI) ecosystem in 2025, effectively sunsetting the standalone LVN token.
avoid.net/2026-violent-crypto-wrench-attack-wave-h1-chainalysis-report→0/100[CRITICAL]In H1 2026, physical coercion attacks ('wrench attacks') targeting cryptocurrency holders reached record levels, with Chainalysis documenting 46 incidents and over $30 million in confirmed losses, while CertiK's parallel Intel3D report verified 52 incidents and $124 million in total financial exposure. France emerged as the global epicenter, accounting for 33 of 52 verified incidents, largely attributed to a 2024 theft of tax records by a French government official and a separate breach of crypto tax platform Waltio affecting 50,000 users. The attack wave is on pace to surpass every prior full-year record and represents a structural shift in crypto crime toward physical coercion that bypasses on-chain security entirely.
avoid.net/gotbit-vortex-antier-contrarian-doj-crypto-market-maker-manipulation-ring→2/100[CRITICAL]Four cryptocurrency market-making firms — Gotbit Consulting, Vortex, Antier Solutions, and Contrarian — were the subjects of coordinated DOJ criminal indictments filed between October 2024 and September 2025 and publicly announced on March 30, 2026. Ten foreign nationals were charged across three separate federal indictments in the Northern District of California and the District of Massachusetts for conducting wash trading and pump-and-dump schemes affecting over 60 cryptocurrency tokens, resulting in the seizure of more than $25 million in digital assets. Gotbit founder Aleksei Andriunin pleaded guilty and was sentenced to eight months in federal prison in June 2025, and Gotbit was ordered to forfeit approximately $23 million in cryptocurrency and cease operations.
avoid.net/ravencoin-rvn→22/100[CRITICAL]In August 2026, Ravencoin's mainnet suffered a critical consensus vulnerability in its KAWPOW proof-of-work algorithm that allowed attackers to produce invalid blocks at a fraction of normal mining cost, beginning at block height 4,487,776 on August 7, 2026. Majority mining pools took unilateral control of the recovery process, issuing a patch without the core development team and threatening a deep three-day blockchain reorganization that would reverse all transactions since block 4,487,775. The incident — the network's third known consensus or supply failure — triggered an approximately 19-20% price crash, exchange-wide suspension of RVN transfers, and raised acute governance concerns about the project's effectively inactive development team.
avoid.net/harmony-protocol-one-token-unauthorized-mint-exploit-august-2026→8/100[CRITICAL]On August 12, 2026, Harmony Protocol confirmed an exploit in which approximately 4 billion ONE tokens were minted without authorization through a flaw in cross-shard receipt verification, representing roughly 26% of the token's prior circulating supply. An estimated 2.8 billion of the minted tokens (approximately 97% of the illicit supply) were transferred to centralized exchanges before Harmony could coordinate a freeze response; the token price fell between 30% and 40% to a record low of approximately $0.0005735. Harmony released emergency validator patch v2026.1.1 and paused its Horizon bridge while evaluating a potential blockchain rollback, but the root cause and confirmed token totals had not been officially disclosed as of the date of this report.
avoid.net/catfi-memecoin-catfi→2/100[CRITICAL]CATFI was a Solana-based memecoin launched via Pump.fun whose operators, led by a suspect identified only as Park (alias 'Eth Father'), orchestrated a coordinated pump-and-dump that caused approximately 900 million won (~$600,000) in investor losses across 256 victims in early 2025. South Korean authorities arrested five individuals in May 2026, resulting in South Korea's first criminal prosecution for a decentralized-exchange rug pull under the Virtual Asset User Protection Act, and the ringleader was sentenced to four years in prison by the Seoul Southern District Court on July 23, 2026.
avoid.net/cream-finance→12/100[CRITICAL]C.R.E.A.M. Finance is a decentralized lending protocol that launched on Ethereum in August 2020, originally forked from Compound Finance. The protocol suffered three major exploits across 2021, losing approximately $186 million in total user funds, and has been effectively dormant since early 2022 with minimal development activity and a TVL that collapsed from over $2 billion to under $3 million.
avoid.net/cream-lending→10/100[CRITICAL]C.R.E.A.M. Finance (Crypto Rules Everything Around Me) is a decentralized lending and borrowing protocol launched in August 2020, forked from Compound Finance. The protocol suffered three major exploits in 2021 totaling approximately $185 million in losses, making it one of the most frequently and severely hacked DeFi protocols in history. On-chain investigator ZachXBT flagged the protocol and its founders, and the CREAM token has collapsed more than 99% from its all-time high.
avoid.net/stablr-multisig-exploit-and-eurr-usdr-depeg→28/100[WARNING]StablR is a Malta-licensed, MiCA-compliant stablecoin issuer backed by Tether that issues EURR (euro-pegged) and USDR (dollar-pegged) tokens on Ethereum and Solana. On May 24, 2026, an attacker compromised one signer in the platform's 1-of-3 minting multisig, replaced the remaining legitimate owners with malicious addresses, and minted approximately $13.5 million in unbacked tokens, realizing roughly $2.8 million (1,115 ETH) in net proceeds by dumping on decentralized exchanges. Both stablecoins lost significant peg value within hours; as of late July 2026, minting and redemption remain suspended and the reserve deficit had not been publicly resolved.
avoid.net/cosmos-atom→54/100[CAUTIONARY]Cosmos is a Layer 1 blockchain protocol and interoperability hub founded by Jae Kwon and Ethan Buchman, with its mainnet launching in March 2019. The project pioneered the Inter-Blockchain Communication (IBC) protocol, enabling sovereign blockchains to transfer assets and data across networks. While the protocol has broad institutional adoption and a large ecosystem, it has faced material governance controversies, a serious security incident involving alleged North Korean developer contributions to its Liquid Staking Module, leadership fragmentation, and persistent concerns over the Interchain Foundation's financial transparency.
avoid.net/blockstream-jade-fake-firmware-phishing-campaign-august-2026→5/100[CRITICAL]A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.
avoid.net/coinsbuy→38/100[WARNING]Coinsbuy (coinsbuy.com) is a B2B cryptocurrency payments platform and exchange incorporated in Saint Vincent and the Grenadines, with reported operational presence in Panama. On August 9, 2026, wallets linked to the platform were drained of approximately $7.9–8.07 million across Ethereum and TRON networks in a coordinated cross-chain attack. The company stated that all affected client funds were covered from its own reserves, though the attack vector remained publicly unconfirmed as of mid-August 2026.
avoid.net/blockfills-reliz-technology-group→12/100[CRITICAL]BlockFills, a Chicago-based institutional crypto trading and liquidity provider operating under parent entity Reliz Technology Group Holdings Inc., filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of Delaware on March 15, 2026, listing up to $500 million in liabilities against $50–100 million in assets. The filing followed the suspension of client deposits and withdrawals in February 2026, a lawsuit by creditor Dominion Capital alleging that client funds were commingled with company accounts, and a federal court order freezing approximately 70.6 BTC. A plan of reorganization was confirmed on July 13, 2026, with Keyrock completing the acquisition of BlockFills' trading and brokerage assets for $3.25 million.
avoid.net/titan→8/100[CRITICAL]TITAN (IRON Titanium Token) was the governance and collateral token of Iron Finance, a partially-collateralized algorithmic stablecoin protocol deployed on Polygon in May 2021. On June 16–17, 2021, the protocol suffered a catastrophic collapse — described by the Iron Finance team as 'the world's first large-scale crypto bank run' — during which TITAN's price fell from an all-time high of approximately $65 to effectively zero within hours, wiping out an estimated $2 billion in total value locked. The collapse was attributed by the Iron Finance team and independent analysts, including the U.S. Federal Reserve, to a fundamental design flaw in the protocol's stabilization mechanism rather than intentional fraud, though allegations of a rug pull circulated widely in the immediate aftermath.
avoid.net/trump-memecoin-august-2026-sec-investigation-request→14/100[CRITICAL]The $TRUMP (Official Trump) memecoin launched on the Solana blockchain on January 17, 2025, two days before Donald Trump's presidential inauguration, and rapidly surged to a peak of approximately $75 before declining more than 98% to around $1.51 as of August 2026. Trump-affiliated entities — CIC Digital LLC and Fight Fight Fight LLC — retained 80% of the 1 billion token supply and have collectively earned an estimated $636 million in royalties, while approximately 988,905 retail investors accumulated losses exceeding $3.81 billion. On August 4, 2026, Senators Elizabeth Warren and Richard Blumenthal formally demanded that SEC Chairman Paul Atkins open an investigation into the token's alleged fraudulent enrichment schemes, though the SEC's own February 2025 guidance classifying memecoins as non-securities limits its enforcement authority.
avoid.net/oramama-x-war-panic-scam-network→2/100[CRITICAL]The ORAMAMA X War-Panic Scam Network is a coordinated cluster of more than 10 accounts on X (formerly Twitter) that used AI-generated geopolitical fear content — including fabricated claims about the US-Iran conflict — to accumulate large audiences before executing a confirmed pump-and-dump of the Solana meme token $ORAMAMA on February 22, 2026. On-chain investigator ZachXBT exposed the network in March 2026, documenting six-figure profits and warning that the scalable playbook posed nation-state-level disinformation risks.
avoid.net/libra-diem→30/100[WARNING]Libra was a proposed global cryptocurrency announced by Facebook (now Meta) on June 18, 2019, initially designed as a multi-currency-backed stablecoin governed by an independent consortium called the Libra Association. The project faced immediate and sustained opposition from U.S. and international regulators, lost the majority of its founding payment-industry partners within months of announcement, underwent significant structural changes and a rebrand to Diem in December 2020, and ultimately shut down in January 2022 when the Diem Association sold its intellectual property and technology assets to Silvergate Capital Corporation for approximately $182 million. The acquired assets were subsequently written down to near zero when Silvergate itself collapsed in March 2023.
avoid.net/fun-coffee-gcm-project→2/100[CRITICAL]Fun Coffee, also marketed as the GCM Project, was a purported Vietnam-based coffee technology investment scheme that operated a cryptocurrency deposit and multi-level-commission structure promising annual returns of 197% to 278%. The scheme entered the Hong Kong market in late 2025, was placed on the Hong Kong Securities and Futures Commission's suspicious investment product alert list on July 13, 2026, and collapsed on approximately July 20, 2026, when its mobile app, withdrawals, and customer support went offline simultaneously. A joint Hong Kong–Macau police operation in August 2026 resulted in eight arrests; a ninth arrest followed in Singapore. Confirmed police-reported losses stand at approximately HK$104 million (US$13.3 million) across more than 255 complaints as of early August 2026, while investors in a roughly 4,000-member chat group allege combined losses exceeding HK$1 billion (US$127 million).
avoid.net/bitrefill→52/100[CAUTIONARY]Bitrefill is a Stockholm-headquartered crypto e-commerce platform founded in 2014 that allows users to purchase gift cards, eSIMs, and phone top-ups with Bitcoin and other cryptocurrencies. On March 1, 2026, the company suffered a confirmed cyberattack in which attackers compromised an employee laptop, escalated access to production infrastructure and hot wallets, drained an undisclosed amount of cryptocurrency, and exfiltrated approximately 18,500 purchase records. Bitrefill publicly attributed the attack to North Korea's Lazarus Group (Bluenoroff subgroup) based on malware signatures, on-chain tracing, and reuse of IP and email addresses consistent with prior DPRK-linked operations.
avoid.net/eu-mica-post-deadline-regulator-impersonation-scam-cluster→0/100[CRITICAL]Following the expiration of the EU Markets in Crypto-Assets (MiCA) transitional period on July 1, 2026, a cluster of fraud operations emerged targeting crypto users displaced by the mass exit of more than 1,700 unlicensed exchanges from the European market. Fraudsters impersonate officials from ESMA, France's AMF, the Dutch AFM, and other national regulators, directing victims to transfer assets to criminal-controlled fake websites under the guise of regulatory compliance. Multiple EU financial watchdogs publicly warned of the scam wave in early August 2026, characterizing the transition window as unusually favorable for fraudsters.
avoid.net/coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-2026→18/100[CRITICAL]A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.
avoid.net/pump-fun-solana-labs-jito-labs-rico-mev-class-action-sdny-2026→28/100[WARNING]Aguilar v. Baton Corporation Ltd. (Case No. 1:25-cv-00880-CM) is a federal class action lawsuit filed in the U.S. District Court for the Southern District of New York against Pump.fun operator Baton Corporation Ltd., Solana Labs, the Solana Foundation, and their named executives, alleging a coordinated RICO racketeering enterprise centered on the Pump.fun memecoin launchpad. A second amended consolidated complaint was filed January 7, 2026, supported by over 5,000 alleged internal chat logs, and seeks between $4 billion and $5.5 billion in compensatory damages — potentially tripled under RICO. Jito Labs, initially named as a co-defendant for alleged MEV-enabling conduct, obtained a voluntary dismissal of claims against it in September 2025 without any settlement payment.
avoid.net/ashcrypto-roya-token-pump-and-dump→18/100[CRITICAL]Ashcrypto (X: @Ashcryptoreal) is a crypto influencer with over 2.1 million followers on X who was alleged by on-chain investigator ZachXBT in May 2026 to have executed a pump-and-dump scheme involving ROYA, the native token of Royale Finance. According to ZachXBT's published evidence, Ashcrypto publicly promoted ROYA while privately messaging premium-channel followers that his team was 'holding 100%' and buying more, while simultaneously selling. Ashcrypto did not respond to requests for comment and had not publicly addressed the allegations as of the time of reporting.
avoid.net/tiffany-milanovich→2/100[CRITICAL]Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.
avoid.net/irs-digital-asset-compliance-portal-phishing-campaign-2026→0/100[CRITICAL]Beginning in late July 2026, an organized criminal operation mailed counterfeit IRS letters to US cryptocurrency holders directing them via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest credentials and drain digital asset accounts. IRS Criminal Investigation confirmed the campaign on July 30, 2026, stating no such portal exists; infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior phishing history.
avoid.net/apple-app-store-systematic-fake-crypto-wallet-cluster-26-apps-april-2026→2/100[CRITICAL]Beginning in at least fall 2025 and publicly disclosed in April 2026, a coordinated cluster of 26 fraudulent iOS applications impersonating major cryptocurrency wallets was discovered on Apple's App Store by Kaspersky researchers. The campaign, dubbed FakeWallet and attributed with moderate confidence to the SparkKitty threat actor group, targeted seed phrase theft primarily from Chinese iOS users. The broader pattern of fake wallet apps on Apple's platforms in 2026 resulted in documented losses exceeding $11 million across multiple distinct incidents and triggered civil litigation against Apple.
avoid.net/fx-winning-david-merino-quintana→1/100[CRITICAL]FX Winning (also styled FXWinning) was a fraudulent cryptocurrency and foreign exchange investment platform allegedly masterminded by Spanish national David Merino Quintana, a businessman from Gran Canaria, Spain. Spanish authorities, coordinating with Europol, the US Drug Enforcement Administration, and investigators in Mexico and Colombia, allege the platform operated as a Ponzi scheme from approximately 2020 to 2023, collecting funds from up to 15,000 victims across more than 30 countries, with Spanish investigators estimating losses of at least €460 million and total funds collected potentially reaching €46 billion. Merino was arrested in Dubai on June 1, 2026, following an international arrest warrant issued by Spain's Audiencia Nacional, and extradition proceedings to Spain are pending.
avoid.net/fake-sparrow-wallet-apple-app-store→0/100[CRITICAL]A fraudulent iOS application impersonating Sparrow Wallet — a legitimate Bitcoin wallet that has no official iOS release — passed Apple's App Store review process and operated on the platform between at least May and August 2025, draining a combined $1.84 million in Bitcoin from three victims by capturing their seed phrases. Three plaintiffs filed a federal lawsuit against Apple on July 24, 2026 in the Northern District of California, case 5:26-cv-07713, alleging negligence, fraudulent misrepresentation, and strict products liability; the actual perpetrators behind the fraudulent app remain unidentified.
avoid.net/cryptomus-xeltox-enterprises-ltd→2/100[CRITICAL]Cryptomus is a cryptocurrency payment processor and exchange operated by Xeltox Enterprises Ltd., a company incorporated in British Columbia, Canada. In October 2025, Canada's financial intelligence unit FINTRAC imposed a record C$176.96 million (approximately US$126 million) administrative penalty against Xeltox for 2,593 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, citing failures to report transactions linked to child sexual abuse material, ransomware payments, fraud, and Iran sanctions evasion. Blockchain intelligence firm TRM Labs further assessed with high confidence that Cryptomus launched a successor platform, Heleket, shortly after implementing mandatory KYC controls, allegedly to continue facilitating illicit activity under a separate brand.
avoid.net/blazar-token-john-a-desalvo→2/100[CRITICAL]Blazar Token was a fraudulent cryptocurrency created by former New Jersey State Corrections Lieutenant John A. DeSalvo, who marketed it to law enforcement personnel and first responders as a 'crypto pension' supplement beginning in November 2021. DeSalvo raised at least $623,888 from approximately 222 investors through materially false representations, then misappropriated the funds and executed a rug-pull in May 2022 by selling over 41 billion of his own tokens, collapsing the price. He pleaded guilty to federal securities fraud charges in March 2024, and the SEC reached a civil settlement in August 2026 ordering disgorgement of $681,105.
avoid.net/btcpay-server-lightning-lnd-macaroon-exploit-august-2026→62/100[CAUTIONARY]In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.
avoid.net/fifa-world-cup-2026-crypto-phishing-and-typosquatting-infrastructure→2/100[CRITICAL]A coordinated, multi-actor scam infrastructure emerged around the 2026 FIFA World Cup (hosted across Canada, Mexico, and the United States, June 11 to July 19, 2026), comprising more than 13,000 to 19,000 registered World Cup-themed domains of which approximately 8.8% have been flagged as malicious or suspicious. The infrastructure combines typosquatted FIFA domains, AI-generated fake ticketing portals, cryptocurrency wallet drainers, seed-phrase phishing kits, and Android banking trojans, with at least one threat actor cluster — designated GHOST STADIUM — attributed to Chinese-speaking operators. The FBI issued a formal public service announcement on May 27, 2026, warning consumers and reporting at least 36 confirmed fraudulent domains spoofing official FIFA web properties.
avoid.net/secondfi-cardano-wallet→13/100[CRITICAL]SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026. Between June 21 and 23, 2026, attackers exploited a deterministic nonce-derivation flaw in the platform's wallet generation software, draining approximately 16 million ADA (~$2.4 million) from 374 user wallets. Up to 129 million ADA across 3,072 wallets was placed at risk, with blockchain security firm SlowMist estimating total exposure could exceed $20 million; EMURGO has committed to full user reimbursement through an independently secured restoration fund, though no timeline or audit has been published.
avoid.net/taiko-ethereum-l2-bridge→10/100[CRITICAL]On June 22, 2026, Taiko — an Ethereum-equivalent layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million from its L1 Bridge and ERC-20 vault by using an RSA-3072 Intel SGX signing key that had been committed in plaintext to the public taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and execute fraudulent withdrawal transactions on Ethereum with no corresponding deposits on Taiko's chain. Taiko halted block production network-wide, froze affected contracts, and urged all users to exit every bridge on the network within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/dean-daghita-cmdss-command-services-and-support→4/100[CRITICAL]Command Services and Support, Inc. (CMDSS) is a Haymarket, Virginia-based Service-Disabled Veteran-Owned Small Business led by president and CEO Dean Daghita that received a U.S. Marshals Service contract in October 2024 to manage and dispose of Class 2-4 seized cryptocurrency. In January 2026, blockchain investigator ZachXBT publicly alleged that Daghita's son, John Daghita (alias 'Lick'), had stolen over $46 million in digital assets from government-controlled USMS wallets by abusing insider access obtained through his father's company. John Daghita was arrested in Saint Martin on March 4, 2026, and was subsequently indicted on 15 federal counts; Dean Daghita himself had not been charged as of August 2026, though CMDSS's online presence was taken offline following the revelations and the company faces significant scrutiny over contract award process and oversight failures.
avoid.net/emerson-sousa-pires→2/100[CRITICAL]Emerson Sousa Pires is a Brazilian national and co-founder of MCC International Corp. (doing business as Mining Capital Coin), who faces a $46.2 million SEC default judgment entered August 26, 2025, alongside co-founder Luiz Carlos Capuci Jr. for operating an alleged crypto mining Ponzi scheme that defrauded approximately 65,535 investors. Pires is separately charged criminally and faces additional civil enforcement by the CFTC arising from a second fraudulent cryptocurrency investment platform, EmpiresX, through which he allegedly defrauded over 12,500 additional investors. He has reportedly fled to Brazil, where Brazilian law prohibits extradition of citizens, though Brazilian federal authorities conducted arrests in connection with parallel domestic proceedings in September 2023.
avoid.net/luiz-carlos-capuci-jr→2/100[CRITICAL]Luiz Carlos Capuci Jr. is the co-founder and CEO of MCC International Corp. (doing business as Mining Capital Coin) and the operator of CPTLCoin Corp. and Bitchain Exchanges. He is the subject of a DOJ criminal indictment unsealed in May 2022 for allegedly orchestrating a $62 million global cryptocurrency investment fraud affecting more than 65,000 investors, and faces up to 45 years in prison on three conspiracy counts. In August 2025, a U.S. federal court entered a $46 million default judgment against him and co-defendant Emerson Sousa Pires in the parallel SEC civil case.
avoid.net/wanchain-cardano-bridge-night-token-exploit-july-2026→8/100[CRITICAL]On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.
avoid.net/taiko-ethereum-l2-bridge-exploit→7/100[CRITICAL]On June 22, 2026, an attacker drained approximately $1.7 million from the Taiko Ethereum layer-2 bridge and ERC-20 vault by exploiting a leaked Intel SGX RSA-3072 signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and submit withdrawal requests on Ethereum with no matching deposits on Taiko, causing the bridge contracts to release funds against fraudulent proofs. Taiko halted block production and froze bridge withdrawals within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/huobi-htx→7/100[CRITICAL]HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.
avoid.net/pump-fun-solana-memecoin-launchpad-ecosystem-fraud→4/100[CRITICAL]Pump.fun is a Solana-based memecoin launchpad operated by Baton Corporation Limited that launched in January 2024 and rapidly became the dominant token creation platform on Solana, generating over $1 billion in fees by April 2025. The platform is the subject of multiple federal class action lawsuits alleging it facilitated unregistered securities sales, insider front-running via MEV infrastructure, and systemic pump-and-dump fraud affecting retail traders. Third-party analysis of over 7 million tokens launched on the platform between January 2024 and March 2025 found that 98.6% exhibited fraudulent characteristics including pump-and-dump patterns and rug pulls.
avoid.net/rugproof-solana-launchpad→0/100[CRITICAL]Rugproof is an anonymous Solana-based token launchpad that markets itself as protecting investors from rug pulls through anti-dump mechanics, bonding curve mechanics, and SOL refund guarantees. On July 28–29, 2025, blockchain analytics firm Bubblemaps published on-chain findings alleging that the project's creator distributed SOL to 162 coordinated wallets that collectively acquired 50% of the RUGPROOF token supply at launch, a pattern Bubblemaps characterized as consistent with rug-pull bundling schemes. The project's team identity, tokenomics documentation, and smart contract audits remain undisclosed as of the date of reporting.
avoid.net/verus-ethereum-bridge-second-exploit-july-2026→0/100[CRITICAL]On July 23, 2026, the Verus-Ethereum Bridge suffered a second major security exploit in 66 days, with an attacker draining approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. The attack exploited the same contract, entry path, and vulnerability class as a May 18, 2026 incident that had drained $11.58 million — raising critical concerns that the underlying flaw was never properly remediated before recovered funds were redeposited into the bridge on July 8, 2026. Combined losses from both exploits total approximately $19.1 million, with the July attacker subsequently laundering stolen assets through Tornado Cash.
avoid.net/91m-bitcoin-social-engineering-theft-hardware-wallet-impersonation-august-2026→0/100[CRITICAL]On August 19, 2025, a single victim lost 783 BTC (approximately $91 million at the time) after attackers impersonated customer support representatives for both a hardware wallet manufacturer and a cryptocurrency exchange. The stolen funds were routed through Wasabi Wallet's CoinJoin mixing service to obstruct traceability. Blockchain investigator ZachXBT publicly disclosed the theft on August 21, 2025, noting it occurred exactly one year after the $243 million Genesis creditor social engineering theft of August 19, 2024. This incident and its successor threats constitute a documented category-level attack pattern targeting high-net-worth Bitcoin holders through trusted-service impersonation, particularly dangerous in the August 2026 environment following the Coldcard firmware exploit and associated phishing surge.
avoid.net/clickfix-bnb-chain-etherhiding-malware-campaign→0/100[CRITICAL]An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.
avoid.net/mcc-international-corp-cptlcoin-corp-bitchain-exchanges→2/100[CRITICAL]MCC International Corp. (doing business as Mining Capital Coin), CPTLCoin Corp., and Bitchain Exchanges were collectively operated as a multi-level marketing cryptocurrency fraud scheme that defrauded 65,535 investors worldwide of an alleged $62 million between at least January 2018 and 2022. The SEC filed charges in April 2022 and secured a combined $46 million default judgment in August 2025; co-founders Luiz Carlos Capuci Jr. and Emerson Sousa Pires fled to Brazil and were arrested there by Brazilian Federal Police in September 2023 under a separate domestic money-laundering investigation.
avoid.net/siavash-kayvanpour-ofac-designated-shelbit-founder→2/100[CRITICAL]Siavash Kayvanpour is an Iranian expatriate and founder of Shelbit, an unlicensed cryptocurrency exchange that U.S. Treasury's OFAC personally designated on August 7, 2026 under Executive Order 13224 for materially supporting Iran's Islamic Revolutionary Guard Corps (IRGC). Blockchain investigators traced over USD 6.3 billion in flows through the Shelbit network between May 2024 and March 2026, linking the exchange to IRGC-affiliated wallets, Iran's central bank, and one of the world's largest illegal online gambling operations. Kayvanpour holds citizenships in Iran, Dominica, and Afghanistan, complicating international enforcement of the designation.
avoid.net/supra-oracle-bonzo-lend-attack-vector→22/100[CRITICAL]On July 11, 2026, Hedera's largest lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a signature verification flaw in Supra's on-chain oracle verifier contract. The vulnerable code had been live for at least two years and was deployed to 11 other chains — all of which received a security patch in the days before the Hedera attack — while the Hedera instance remained unpatched. Supra, founded in 2020 and backed by Coinbase Ventures and other institutional investors, is a cross-chain oracle and infrastructure network whose verifier flaw carries systemic risk to any dependent protocol.
avoid.net/summer-finance-summer-fi-lazy-summer-protocol-flash-loan-exploit-and-shutdown→18/100[CRITICAL]On July 6, 2026, an attacker used a $65.4 million Morpho flash loan to exploit a stale-asset share-price manipulation vulnerability in Summer.fi's Lazy Summer Protocol, extracting approximately $6.04 million in DAI from two Ethereum USDC vaults. The stolen funds were subsequently laundered through Tornado Cash. On July 15, 2026, Summer.fi Labs announced it had no viable path forward and would cease operations by August 31, 2026, with governance of the Lazy Summer Protocol transferring entirely to the Lazy Summer DAO.
avoid.net/hypervault-finance→0/100[CRITICAL]Hypervault Finance was a yield-aggregating DeFi vault protocol built on the HyperEVM layer of the Hyperliquid blockchain that executed a confirmed exit scam on or around September 25–26, 2025, draining approximately $3.6–4.64 million from roughly 1,100 depositors. Operators bridged funds to Ethereum via deBridge, converted assets to ETH, and routed approximately 752 ETH into Tornado Cash to obscure the trail before deleting all web properties, social media accounts, and GitHub repositories. The project had falsely claimed ongoing security audits by Spearbit, Pashov Group, and Code4rena — none of which were conducted — and attracted deposits with promises of 76–95% annualized yields on stablecoins and HYPE liquidity tokens.
avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-2026→38/100[WARNING]On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.
avoid.net/lazarus-group-mach-o-man-macos-campaign-2026→0/100[CRITICAL]The Lazarus Group Mach-O Man campaign is a state-sponsored macOS malware operation publicly disclosed in April 2026, attributed to North Korea's Reconnaissance General Bureau via the Chollima operational unit. The campaign delivers a modular, Go-compiled malware kit through ClickFix social engineering — fake video-conference invitations distributed over Telegram — targeting cryptocurrency developers, fintech executives, and high-value enterprise users running Apple hardware. Researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform identified four distinct attack stages culminating in macOS Keychain theft, browser credential harvesting, and exfiltration via the Telegram Bot API.
avoid.net/ai-agent-prompt-injection-crypto-attack-class-2026→0/100[CRITICAL]Prompt injection attacks against autonomous AI crypto trading agents constitute a documented and accelerating threat class in 2026, responsible for over $45 million in aggregate losses across multiple confirmed incidents. Attackers embed hidden instructions in airdropped NFT metadata, web page content, and encoded social media posts to cause AI agents with wallet signing authority to execute unauthorized fund transfers — no smart contract vulnerability required. Security firm Blockaid, OWASP, and researchers at Zscaler have each independently confirmed prompt injection as a live, reproducible attack vector against production AI agent deployments.
avoid.net/dprk-crypto-theft-h1-2026-trm-labs-blockaid-report→0/100[CRITICAL]North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm. Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds. Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.
avoid.net/q2-2026-record-crypto-hack-wave→0/100[CRITICAL]The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.
avoid.net/q2-2026-defi-record-hack-wave→0/100[CRITICAL]Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.
avoid.net/humanity-protocol-h-token-hack→18/100[CRITICAL]On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.
ZachXBT Intelligence · Backfilled
5Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor, also tracked as APT38, TraderTraitor, BlueNorOff, Hidden Cobra, and ZINC, operating under the Reconnaissance General Bureau (RGB) of the Korean People's Army. Active since approximately 2009, the group has stolen an estimated $6.75 billion in cryptocurrency through targeted attacks on exchanges, bridges, and blockchain companies, using stolen funds to finance North Korea's weapons programs and circumvent international sanctions. The U.S. Department of Justice has indicted three named members, and OFAC placed the group on the Specially Designated Nationals (SDN) list in April 2022.
avoid.net/trezor→57/100[CAUTIONARY]Trezor is a legitimate Prague-based hardware wallet manufacturer (SatoshiLabs) and one of the oldest in the industry, but it has accumulated a significant threat ecosystem around its brand. A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps. Trezor hardware devices have also been subject to disclosed physical attack vectors, including an alleged unpatchable flaw in the STM32 microcontroller used in the Trezor T model.
avoid.net/coinspaid→62/100[CAUTIONARY]CoinsPaid (operating legal entity Dream Finance OÜ, headquartered in Tallinn, Estonia) is a business-to-business crypto payment processing platform founded in 2014 by Max Krupyshev and Pavel Kashuba. The company suffered two confirmed external cyberattacks — a $37.3 million theft in July 2023 and a $7.5 million breach in January 2024 — both attributed to third-party attackers with the first definitively linked to North Korea's Lazarus Group by blockchain analysts and the FBI; client funds were reported unaffected in both incidents. The company is currently navigating significant regulatory uncertainty under the EU's MiCA framework after losing its legacy Estonian FIU licence and suspending operations through its Lithuanian entity, while its CASP application in Estonia remains pending as of mid-2026.
avoid.net/ninamo→71/100[CAUTIONARY]Ninamo is a purported crypto entity whose name was submitted for investigation on AVOID.NET. Exhaustive searches across regulatory databases, blockchain explorers, crypto news outlets, scam trackers, social media platforms, domain registries, and the Wayback Machine returned no verifiable information about any crypto project, exchange, token, or DeFi protocol operating under the name Ninamo. No wallet addresses, enforcement actions, community reports, or archived web presence could be located.
avoid.net/hypurr-nfts→74/100[CAUTIONARY]Hypurr NFTs are a 4,600-piece cat-themed NFT collection airdropped by the Hyper Foundation on September 28, 2025, to early Hyperliquid users who participated in the November 2024 Genesis Event. On the day of launch, blockchain investigator ZachXBT flagged the theft of eight Hypurr NFTs from compromised HyperEVM wallets, yielding approximately $400,000 in profit for the attacker. The collection itself is a legitimate product of the Hyper Foundation, but the incident exposed wallet security vulnerabilities in the HyperEVM ecosystem and coincided with a broader pattern of exploits across Hyperliquid-based protocols in late September 2025.