Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
CrossCurve, a cross-chain DeFi bridge formerly known as EYWA Protocol and backed by Curve Finance founder Michael Egorov, suffered an approximately $3 million exploit on February 1-2, 2026. An attacker exploited a missing access-control validation in the protocol's ReceiverAxelar smart contract to forge cross-chain messages and unlock tokens without corresponding deposits across Ethereum, Arbitrum, and at least seven other networks. As of available reporting, no funds have been confirmed recovered and the attacker has not publicly responded to the team's 72-hour bounty ultimatum.
avoid.net/india-otc-crypto-kol-scam-ravindra-k-mohammed-waseem-saurabh-diwan-vaibhav-gupta→4/100[CRITICAL]India's Enforcement Directorate (ED) registered a Prevention of Money Laundering Act (PMLA) case and conducted raids on July 18–19, 2026 in Bengaluru against a network of self-styled cryptocurrency Key Opinion Leaders (KOLs) accused of defrauding foreign investors through fraudulent over-the-counter (OTC) token allocation deals. The ED's Bengaluru Zonal Office estimates the total scam value at approximately USD 35 million (approximately ₹336–337 crore), substantially exceeding the USD 10 million reported in the originating FIR filed by a Dutch entity. Four individuals have been named: Mohammed Waseem, Saurabh Diwan, and Vaibhav Gupta as the primary KOL-facing operatives, and Bengaluru-based Ravindra K, identified by investigators as the alleged mastermind behind the OTC operation.
avoid.net/allbridge-core-solana-flash-loan-exploit-july-2026→22/100[CRITICAL]On July 19–20, 2026, Allbridge Core's Solana deployment suffered a flash loan exploit that drained approximately $1.65 million from stablecoin liquidity pools. An attacker borrowed $1.12 million USDC from Kamino, manipulated pool pricing ratios, and withdrew assets at artificially favorable rates before bridging proceeds to Ethereum. The incident was the second flash loan attack on Allbridge Core, following a nearly identical April 2023 exploit on BNB Chain for which the team had published an architectural fix that was never applied to the Solana deployment.
avoid.net/korvio-coin-kro→2/100[CRITICAL]Korvio Coin (KRO) is an alleged fraudulent cryptocurrency launched in 2018 in Himachal Pradesh, India, by alleged mastermind Subhash Sharma and associates, operating as a multi-level marketing (MLM) Ponzi scheme across platforms including Korvio, DGT, Hypenext, and A-Global. The scheme allegedly defrauded over 248,000 investors of an estimated ₹1,740 crore in gross investment (with net fraud estimated at ₹500 crore), with victims including over 1,000 serving police personnel. India's Enforcement Directorate (ED) has been investigating under the Prevention of Money Laundering Act (PMLA) since March 2024, with multiple arrests made through July 2026, while the alleged principal architect Subhash Sharma is believed to have fled to Dubai.
avoid.net/aquabot-aqua→2/100[CRITICAL]Aquabot was a Solana-based Telegram trading bot project that raised approximately 21,770 SOL (roughly $4.65 million USD) through a presale before alleged operators drained the presale wallet and routed funds through intermediary addresses to instant exchanges in early September 2025. The incident drew heightened scrutiny because several prominent Solana ecosystem entities, including Meteora, Helius, Dialect, SYMMIO, and QuillAudits, had publicly promoted or audited the project prior to the alleged rug pull. No law enforcement action or fund recovery has been publicly reported as of the time of this investigation.
avoid.net/verus-ethereum-bridge-second-exploit-july-2026→8/100[CRITICAL]On July 23, 2026, the Verus-Ethereum Bridge suffered a second major security exploit in 66 days, with an attacker draining approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. The attack exploited the same contract, entry path, and vulnerability class as a May 18, 2026 incident that had drained $11.58 million — raising critical concerns that the underlying flaw was never properly remediated before recovered funds were redeposited into the bridge on July 8, 2026. Combined losses from both exploits total approximately $19.1 million, with the July attacker subsequently laundering stolen assets through Tornado Cash.
avoid.net/wanchain-cardano-bridge-night-token-exploit-july-2026→18/100[CRITICAL]On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.
avoid.net/afx-trade-bridge-exploit-july-2026→12/100[CRITICAL]AFX Trade, a decentralized perpetuals exchange (perp DEX) built on Arbitrum and settling positions in USDC, suffered a $24.15 million exploit on July 22, 2026, when an attacker compromised the private keys of five hot-wallet validators operating the protocol's custom USDC custody bridge. The stolen USDC was bridged to Ethereum and converted to approximately 12,467 ETH, draining nearly the protocol's entire total value locked. AFX Trade suspended bridge operations, offered the attacker a 30% white-hat bounty for return of funds, and engaged security firms SlowMist and Zellic for the investigation; no post-mortem or user compensation plan had been published as of late July 2026.
avoid.net/doj-scam-center-strike-force-southeast-asia-romance-fraud-network→4/100[CRITICAL]A transnational organized crime network operating from fortified compounds in Cambodia, Myanmar, Laos, and adjoining Southeast Asian jurisdictions has defrauded tens of thousands of victims — primarily in the United States and Canada — through pig-butchering cryptocurrency investment scams and online romance fraud. The U.S. Department of Justice's Scam Center Strike Force, launched November 2025, has restrained more than $832 million in cryptocurrency and coordinated at least 276 arrests globally as of mid-2026. Five civil forfeiture complaints filed July 21, 2026 seek more than $25 million in additional crypto tied to over 670 suspected victim transactions.
avoid.net/rugproof-solana-launchpad→8/100[CRITICAL]Rugproof is an anonymous Solana-based token launchpad that markets itself as protecting investors from rug pulls through anti-dump mechanics, bonding curve mechanics, and SOL refund guarantees. On July 28–29, 2025, blockchain analytics firm Bubblemaps published on-chain findings alleging that the project's creator distributed SOL to 162 coordinated wallets that collectively acquired 50% of the RUGPROOF token supply at launch, a pattern Bubblemaps characterized as consistent with rug-pull bundling schemes. The project's team identity, tokenomics documentation, and smart contract audits remain undisclosed as of the date of reporting.
avoid.net/midnight-night-token→52/100[CAUTIONARY]Midnight is a privacy-focused Layer 1 blockchain developed by Input Output Global (IOG), the engineering firm behind Cardano, and overseen by the Cayman-based Midnight Foundation. It uses zero-knowledge proofs and a dual-token model (NIGHT and DUST) to offer selective data disclosure for compliant private smart contracts. The NIGHT token launched in December 2025 with a 24 billion fixed supply; in July 2026, a third-party Wanchain bridge connecting Cardano to BNB Chain was exploited for approximately 515 million NIGHT tokens (~$10-13 million), crashing the token price 30-43% to an all-time low, though Midnight's core Layer 1 protocol was not compromised.
avoid.net/b-squared-network→28/100[WARNING]B-Squared Network (B² Network) is a Bitcoin Layer-2 protocol using ZK-Rollup technology, headquartered in Singapore and founded in 2022, with backing from HashKey Capital, OKX Ventures, IDG Capital, and others. On July 22, 2026, the protocol suffered a $3.86 million exploit when an attacker gained unauthorized access to the staking contract's upgrade authority, draining 8.59 million B2 tokens that were subsequently laundered through cross-chain infrastructure. The team pledged full compensation to affected stakers and offered a 10% bounty for return of funds; no attacker has been identified.
avoid.net/b2-network→28/100[WARNING]B² Network (BSquared Network) is a Bitcoin Layer-2 scaling protocol founded in November 2022, utilizing zero-knowledge proof verification and EVM-compatible rollup technology. On July 22–23, 2026, the project suffered a confirmed security exploit in which an attacker gained unauthorized access to the upgrade authority of its B2 token staking contract on BNB Chain, draining 8.59 million B2 tokens valued at approximately $3.86 million. The stolen funds were sold for BNB, bridged to Ethereum, and are being routed through NEAR Intents toward Zcash for laundering, according to blockchain investigator Specter. The incident was one of three coordinated exploits on the same day — alongside the Verus Ethereum Bridge ($7.54M) and AFX Trade ($24.15M) — in what Lookonchain labeled 'Hackers' Day,' with combined losses of $35.55 million.
avoid.net/ripple-usd-rlusd→74/100[CAUTIONARY]Ripple USD (RLUSD) is a U.S. dollar-pegged stablecoin issued by Standard Custody & Trust Company, LLC, a wholly owned subsidiary of Ripple Labs, under a limited-purpose trust company charter granted by the New York Department of Financial Services (NYDFS). It launched on December 17, 2024, following formal regulatory approval, and had grown to approximately $1.5 billion in circulating supply as of July 2026. RLUSD carries standard centralization and counterparty risks inherent to issuer-controlled fiat-backed stablecoins, including administrative freeze and blacklist capabilities, but is backed by monthly Deloitte attestations, BNY Mellon custody of reserves, and a clear regulatory framework.
avoid.net/benjamin-paul-wiener→2/100[CRITICAL]Benjamin Paul Wiener is a 43-year-old Sioux Falls, South Dakota resident indicted in June 2026 by a federal grand jury on 29 counts including wire fraud, money laundering, bank fraud, and aggravated identity theft. Prosecutors allege he ran a Ponzi-style cryptocurrency investment scheme through eight companies, collecting approximately $25.1 million from dozens of victims across South Dakota and Minnesota while diverting an estimated $5.7 million for personal expenses. Wiener pleaded not guilty on July 10, 2026 and is scheduled for trial on September 15, 2026.
avoid.net/wojtek-kulisz-merry-sim-swap-crypto-theft-ring→2/100[CRITICAL]Wojtek Kulisz, known online as 'Merry', is a Polish national alleged by blockchain investigator ZachXBT to be among four individuals arrested in Poland on June 25, 2026, as part of a joint CBZC-FBI-HSI operation targeting an organized SIM swap crypto theft ring. The group is accused of breaching telecommunications infrastructure, hijacking victims' phone numbers, and draining cryptocurrency exchange accounts, with prosecutors estimating laundered funds in excess of tens of millions of Polish zlotys (approximately $5–$15 million USD). Polish authorities placed all four suspects in pretrial detention facing charges of participation in an organized criminal group, unauthorized computer system access, and money laundering, each carrying a maximum sentence of 25 years.
avoid.net/ascendex-bitmax→12/100[CRITICAL]AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.
avoid.net/ascendex→4/100[CRITICAL]AscendEX, a centralized cryptocurrency exchange founded in 2018 as BitMax and rebranded in 2021, ceased all operations on July 1, 2026, citing failure to obtain EU MiCA regulatory authorization and a failed liquidity transaction. On-chain investigator ZachXBT flagged depleted hot wallet reserves on June 26, 2026, revealing that approximately $240 million had departed known exchange wallets on June 20, leaving only an estimated $13.5 million in assets — largely illiquid native tokens — against an unknown volume of user withdrawal obligations. Automated withdrawals were suspended on July 6 with no guaranteed timeline or payout amounts, and ZachXBT subsequently urged affected users to file reports with law enforcement and regulators.
avoid.net/summer-fi→25/100[CRITICAL]Summer.fi (formerly Oasis.app) was a DeFi frontend and yield protocol platform with roots in the original MakerDAO ecosystem, operating for approximately seven years before shutting down in 2026. On July 6, 2026, an attacker exploited a share-accounting vulnerability in its Lazy Summer Protocol vaults via a $65.4 million flash loan, stealing approximately $6.04 million in depositor funds; the root cause was traced to stale Silo token valuations inherited from the November 2025 Stream Finance collapse. Following the exploit, Summer.fi Labs announced the permanent shutdown of operations, with the application scheduled to remain accessible through August 31, 2026 pending DAO-governed recovery of affected vault funds estimated at approximately $4 million.
avoid.net/zeus-network→37/100[WARNING]Zeus Network is a Solana-based protocol (token ticker ZEUS, mint ZEUS1aR7aX8DFFJf5QjWj2ftDDdNTroMNGo8YoQm3Gq) that markets itself as a permissionless Bitcoin-to-Solana bridge, minting a 1:1 Bitcoin-pegged asset called zBTC via its APOLLO application and Zeus Program Library (ZPL). The project raised roughly $8 million from named venture funds and angel investors, including Solana co-founder Anatoly Yakovenko, and its ZEUS token has fallen approximately 99.7% from its April 2024 all-time high, trading at fractions of a cent as of July 2026. A set of specific abandonment allegations attributed to a social-media watchdog account (deleted Discord, an unconfirmed Astarter "acquisition," an unreachable team, disabled comments) could not be independently corroborated from verifiable sources at the time of this review; on the contrary, available evidence points to an active, if commercially struggling, project rather than a confirmed rug pull or exit scam.
avoid.net/paypal-usd→68/100[CAUTIONARY]PayPal USD (PYUSD) is a US dollar-pegged stablecoin issued by Paxos Trust Company, a New York-chartered limited purpose trust company regulated by the NYDFS, and marketed by PayPal. Reserves are attested monthly by an independent accounting firm and are held in cash and short-term US Treasuries, with redemption rights subject to Paxos and PayPal compliance review. PYUSD carries the same centralization risks common to bank-issued stablecoins (issuer freeze and address-wipe functions) and its issuer, Paxos, has a prior NYDFS enforcement history tied to its Binance-branded BUSD stablecoin, though PYUSD itself has not been the subject of a depeg event, and a 2023 SEC subpoena into PYUSD was closed in February 2025 without enforcement action.
avoid.net/usds→63/100[CAUTIONARY]USDS is the primary stablecoin of Sky (formerly MakerDAO), launched in September 2024 as the successor to DAI within Sky's product line, with holders able to convert 1:1 between the two tokens. USDS is over-collateralized by a mix of crypto assets, USDC held via peg stability modules, and tokenized real-world assets including U.S. Treasuries, but it has drawn recurring criticism over a wallet-freezing capability, a custody arrangement for hundreds of millions of dollars in reserves that relied on a single externally-owned wallet, and rising governance complexity under Sky's 'Endgame' restructuring. No confirmed hack or sustained depeg of USDS itself has been documented as of this writing, though it inherits pass-through depeg risk from its USDC backing.
avoid.net/philippines-sec-multi-exchange-unlicensed-operations-enforcement→20/100[CRITICAL]In August 2025, the Philippine Securities and Exchange Commission (SEC) issued public advisories naming ten major global cryptocurrency exchanges — OKX, Bybit, KuCoin, Kraken, MEXC, Bitget, Phemex, CoinEx, BitMart, and Poloniex — as operating without mandatory Crypto Asset Service Provider (CASP) registration, and directed the National Telecommunications Commission (NTC) to instruct ISPs PLDT and Smart Communications to block access to these platforms. The action follows the July 5, 2025 effectivity of SEC Memorandum Circulars No. 4 and No. 5 (Series of 2025) which established the CASP regulatory framework. Filipino users of these platforms face inability to access funds through local ISPs, no legal recourse in Philippine courts, and exposure to fraud without regulatory protection.
avoid.net/taiko→38/100[WARNING]Taiko (ticker: TAIKO) is an Ethereum-equivalent, based contestable ZK-rollup Layer 2 developed by Taiko Labs, founded in 2022 by Daniel Wang, former founder of Loopring. The protocol launched on Ethereum mainnet on May 27, 2024 and raised $37 million in total funding. On June 22, 2026, an attacker exploited a critical operational security failure — an SGX RSA-3072 private signing key committed to a public GitHub repository — to forge valid L2 state attestations and drain approximately $1.7 million from the L1 Bridge and ERC20Vault contracts; Taiko halted block production, paused all bridge withdrawals, and pledged full treasury-backed reimbursement to affected users.
avoid.net/wojtek-kulisz-aka-merry-sim-swap-gang→2/100[CRITICAL]Wojtek Kulisz, known online as 'Merry', is a Polish national alleged to be a social engineering threat actor linked by blockchain investigator ZachXBT to a four-person SIM-swap criminal ring arrested by Polish and U.S. authorities on June 25, 2026. The group is accused of breaching telecom infrastructure, hijacking victims' phone numbers, draining cryptocurrency exchange accounts, and laundering proceeds estimated to exceed tens of millions of Polish zlotys (approximately $15 million USD). Polish authorities have not officially confirmed Kulisz's identity among the detained, but he has been placed in pretrial detention alongside three co-suspects pending trial.
avoid.net/trove-markets→8/100[CRITICAL]Trove Markets was a short-lived DeFi project that raised approximately $11.5 million through an ICO in January 2026 to build a perpetual futures exchange for collectibles (Pokemon cards, CS:GO skins) on Hyperliquid. Days before its token launch, the team pivoted to Solana without investor consent, retained $9.4 million of ICO funds, and the TROVE token crashed 97% within hours of its TGE. Multiple fraud allegations followed, including an alleged $10 million HYPE token dump from a project-linked wallet, undisclosed influencer payments, siphoning of $45,000 to a crypto casino, and on-chain evidence of wallet concentration; crypto investigator Eyeonchains alleges the real actor behind the project is Shanghai-based serial scammer Jin Qing Qing.
avoid.net/mining-automatic-zan-shaikh-bright-vision-distribution-llc→2/100[CRITICAL]Mining Automatic, operated by Zan Shaikh through Florida-based Bright Vision Distribution LLC, is the subject of SEC fraud charges filed July 20, 2026 alleging a $22 million Ponzi scheme that defrauded more than 380 investors between June 2023 and May 2025. The SEC alleges only approximately 13% of investor capital was spent on actual cryptocurrency mining operations, while the remainder was misappropriated for marketing, personal enrichment, and Ponzi-style recruitment payouts. As of the filing date, over $20 million in investor principal remains unrecovered.
avoid.net/aztec-deprecated-private-rollup-bridge-exploit-june-2026→20/100[CRITICAL]In June 2026, two separate exploits drained a combined total of over $4 million from deprecated Aztec Network smart contracts — Aztec Connect on June 14 ($2.19M) and the Aztec Private Rollup Bridge on June 17 ($2.16M). Both contracts had been shut down years earlier but remained immutable and on-chain, custodying residual user assets with no administrative override capability.
avoid.net/aztec-connect-deprecated-bridge-exploits-june-2026→10/100[CRITICAL]In June 2026, two separate exploits drained a combined total of approximately $4.3–4.4 million from deprecated Aztec bridge contracts within three days. The first exploit, on June 14, targeted the abandoned Aztec Connect RollupProcessor contract (deprecated March 2023) by exploiting a settlement-boundary mismatch in zk-rollup proof verification; the second, on June 17–18, targeted a deprecated Private Rollup Bridge (closed 2022) via an unauthenticated escape hatch function. Both contracts were immutable with admin keys renounced, making intervention impossible. Aztec Labs and the Aztec Foundation confirmed the affected contracts have no connection to the current Aztec network or the AZTEC ERC-20 token.
avoid.net/xue-sam-lee-hyperfund-co-founder→2/100[CRITICAL]Xue 'Sam' Lee, an Australian citizen residing in Dubai, is the alleged co-founder of HyperFund (also marketed as HyperVerse, HyperTech, HyperCapital, and HyperNation), a cryptocurrency investment scheme that U.S. authorities allege defrauded investors of approximately $1.89 billion between June 2020 and November 2022. In January 2024, the U.S. Department of Justice unsealed a criminal indictment and the SEC filed parallel civil charges against Lee for conspiracy to commit securities fraud and wire fraud. Lee was detained in Dubai in October 2024 following an Interpol Red Notice but, as of June 2026, has not been extradited to the United States and maintains his innocence.
avoid.net/hyperbridge-polkadot-ethereum-bridge→38/100[WARNING]Hyperbridge is a cross-chain interoperability bridge built by Polytope Labs, connecting Polkadot to Ethereum and EVM-compatible networks using zero-knowledge proof-based consensus verification. On April 13, 2026, an attacker exploited a Merkle Mountain Range (MMR) proof verification flaw in its Ethereum gateway contract, minting approximately 1 billion bridged DOT tokens and causing realized losses subsequently revised to $2.5 million across four EVM chains. The protocol was paused, underwent a full architectural rebuild rather than a patch, and relaunched in June 2026 with structural changes to governance, proof generation, and token architecture.
avoid.net/miasma-redhat-npm-supply-chain-attack→2/100[CRITICAL]Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.
avoid.net/edgex-edge-token→22/100[CRITICAL]edgeX is a decentralized perpetual futures exchange incubated by Amber Group and launched on mainnet in August 2024, with its native EDGE token generating at Token Generation Event on March 31, 2026. On June 2, 2026, the EDGE token crashed approximately 77% in under 60 seconds, erasing over $220 million in market value; edgeX attributed the event to an unidentified external party, while on-chain investigator ZachXBT alleged that a small group of insiders controlled the majority of the 1 billion token supply through a thin-float structure. A self-commissioned investigation found no team misconduct, a conclusion ZachXBT publicly derided as self-serving, and the project subsequently faced scrutiny for declining to disclose market-maker agreements or insider token allocations.
avoid.net/wolf-capital-crypto-trading-llc→2/100[CRITICAL]Wolf Capital Crypto Trading LLC was an Oklahoma-based cryptocurrency investment firm operated by Travis Ford that raised approximately $9.4 million from roughly 2,800 investors between October 2022 and December 2024 through a Ponzi scheme promising daily returns of 1–2% (approximately 547% annually). Ford pleaded guilty to conspiracy to commit wire fraud in January 2025 and was sentenced in November 2025 to 60 months in federal prison, ordered to forfeit over $1 million and pay over $170,000 in restitution. The Commodity Futures Trading Commission (CFTC) filed a parallel civil enforcement action in December 2025 seeking disgorgement, civil penalties, and permanent trading and registration bans.
avoid.net/cavepay→18/100[CRITICAL]Cavepay (marketed at the domain cavepay.app and via a Telegram channel) presented itself as a multi-cryptocurrency wallet service. Independent, credible reporting on the project is essentially nonexistent: no Tier 1 or Tier 2 news coverage, regulatory action, or court records were found. The only substantive third-party assessment located is an automated scam-detection aggregator that flags the site for phishing and gives it the lowest possible trust rating, and the domain no longer resolves. Given the near-total absence of verifiable information, this page should be treated as low confidence — it documents red flags and an information vacuum rather than a confirmed fraud finding or a confirmed clean bill of health.
avoid.net/zero-network-zerion-l2→38/100[WARNING]Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.
avoid.net/noman-saleem-telegram-influencer-impersonation-fraud→0/100[CRITICAL]Noman Saleem, 39, of Queens and Levittown, New York, was sentenced on June 23, 2026 to 15 months in federal prison after pleading guilty to wire fraud for impersonating well-known cryptocurrency influencers on Telegram and defrauding investors of at least $1,415,067 through a fabricated staking scheme. Saleem cloned influencer Telegram handles, charged $500–$600 for VIP channel access, promised guaranteed staking returns over 30–90 day terms, and never staked any funds, ultimately disappearing with victims' cryptocurrency. The case was prosecuted by the U.S. Attorney's Office for the District of Maryland and investigated by the FBI's Baltimore field office.
avoid.net/paxful-ray-youssef→4/100[CRITICAL]Paxful Holdings Inc., once one of the world's largest peer-to-peer Bitcoin trading platforms, pleaded guilty in December 2025 to three federal criminal counts including conspiracy to violate the Travel Act by facilitating illegal prostitution, operating an unlicensed money transmitting business, and violating Bank Secrecy Act AML requirements. Co-founder and former CEO Ray Youssef was separately indicted by the DOJ in February 2026 on related charges and was deported from Mexico to Los Angeles for arraignment. The company shut down operations in November 2025, having admitted to knowingly processing funds linked to fraud, sex trafficking, child sexual abuse material distribution, and transactions with North Korean and Iranian state-sponsored actors.
avoid.net/leva-heal-limited-fake-ledger-live-app-apple-app-store→2/100[CRITICAL]Leva Heal Limited is a UK-registered company (Companies House number 12178110) whose Apple developer account was used to publish a fraudulent application impersonating Ledger Live on the macOS App Store between April 7 and April 13, 2026. The app harvested users' 24-word seed phrases, resulting in the theft of approximately $9.5 million in cryptocurrency from at least 50 victims. Apple removed the app and terminated the associated developer account on or around April 13-14, 2026, after community reports surfaced through on-chain investigator ZachXBT.
avoid.net/alexander-vladimirovich-ledenev→2/100[CRITICAL]Alexander Vladimirovich Ledenev is a 25-year-old Russian national arrested in Batumi, Republic of Georgia on June 10, 2026, and charged by criminal complaint in the Eastern District of Pennsylvania with conspiracy to launder monetary instruments and sting money laundering. He is alleged to be a senior co-administrator of AudiA6, a cryptocurrency laundering service that processed approximately 10,333 Bitcoin (valued at roughly $389.7 million at transaction time) since its 2021 launch. Ledenev and co-defendant Ruslan Igorevich Tkachuk are currently in Georgian custody pending U.S. extradition proceedings; each faces a maximum sentence of 20 years in federal prison.
avoid.net/terence-kwok-humanity-protocol-staged-hack→14/100[CRITICAL]Terence Kwok is the founder of Humanity Protocol, a biometric decentralized identity project that raised $50 million from investors including Pantera Capital and Jump Crypto at a $1.1 billion valuation. On June 8–9, 2026, the project suffered a breach in which approximately $36 million was stolen via compromised private keys, causing the H token to crash 80–90%. On-chain investigator ZachXBT publicly characterized the incident as 'possibly staged,' citing pre-funded attacker wallets and a pattern consistent with a market-maker exit, though a subsequent investigation by security firm Quantstamp attributed the attack to DPRK-affiliated threat actors using a phishing campaign.
avoid.net/ice→22/100[CRITICAL]Ice Open Network (ION) is a Layer-1 blockchain founded by Alexandru Iulian Florea that launched a mobile tap-to-mine program in July 2023 and deployed its mainnet in January 2025. The project attracted a claimed community of 40 million users before suffering a severe token price collapse of approximately 93% in April 2026, a concurrent insider data breach, and mounting credibility questions over the founder's documented history operating a cybercrime-adjacent proxy botnet service and a prior 2018 ICO that allegedly left investors with near-total losses.
avoid.net/humanity-protocol-h-token-hack→18/100[CRITICAL]On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.
avoid.net/rhea-finance→32/100[WARNING]Rhea Finance is a chain-abstracted DeFi liquidity hub on the NEAR Protocol, formed in early 2025 through the merger of Ref Finance and Burrow Finance. On April 16, 2026, the protocol suffered a major exploit in which an attacker bypassed slippage protection in its margin trading module using intermediate asset reuse across a chain swap path, ultimately draining an estimated $18.4 million from the reserve pool — more than double the initial $7.6 million estimate. Approximately $9.2 million was subsequently returned or frozen, with the remainder still outstanding as of mid-2026; a compensation framework was announced but had not been finalized at the time of publication.
avoid.net/gateio→57/100[CAUTIONARY]Gate.io (rebranded to Gate.com in May 2025) is a major global cryptocurrency exchange founded in 2013 as Bter.com by Lin Han, currently incorporated in the Cayman Islands and serving over 52 million users across more than 4,600 assets. The exchange has faced significant scrutiny including an alleged undisclosed $230 million hack in 2018 attributed to North Korean state actors, a 2025 public notice from the Cayman Islands Monetary Authority (CIMA) confirming it has never been licensed in its ostensible home jurisdiction, and a pattern of user complaints regarding account freezes, withdrawal blocks, and a disputed $LA futures incident in 2025. The exchange publishes monthly proof-of-reserves reports audited by Hacken and holds licenses in several jurisdictions including Malta (MiCA), Dubai (VARA), Cyprus (CySEC), and Australia (AUSTRAC).
avoid.net/triple-a-payments→42/100[WARNING]Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payment gateway founded by Eric Barbier and licensed by the Monetary Authority of Singapore (MAS) as a Major Payment Institution. On July 25, 2026, the company confirmed unauthorized access to its treasury hot wallets, with on-chain investigators estimating losses of approximately $11.8 million across six blockchains; the company stated that customer funds were unaffected and that it can meet all liabilities. The incident remained unresolved as of July 27, 2026, with no attacker identified and no funds recovered.
avoid.net/ill-bloom-vulnerability→0/100[CRITICAL]Ill Bloom is an actively exploited cryptographic vulnerability disclosed by blockchain security firm Coinspect in July 2026, stemming from insecure pseudorandom number generators (PRNGs) used during seed phrase generation in certain lesser-known mobile software wallets. Attackers have confirmed drained at least $5 million from over 2,100 identified vulnerable addresses across Bitcoin, Ethereum, Polygon, Tron, Solana, and Rootstock, with wallets remaining at risk as of the disclosure date. The vulnerability is not a scam or fraud entity but represents an ongoing, active-exploitation security threat requiring immediate action by potentially affected users.
avoid.net/trevor-vernon-argent-capital-management→2/100[CRITICAL]Trevor L. Vernon and his firm Argent Capital Management LLC (ACM), based in Franklin, North Carolina, face a civil enforcement complaint filed July 7, 2026 by the U.S. Commodity Futures Trading Commission (CFTC) in the Western District of North Carolina. The CFTC alleges Vernon fraudulently solicited over $14.8 million from at least 60 investors between March 2022 and February 2026 by falsely claiming his commodity pool generated extraordinary profits from equity index futures, options, and crypto asset trading, while investors' funds in fact suffered consistent and catastrophic losses. The complaint further alleges Ponzi-like payments to early investors using new investor capital, misappropriation of approximately $136,000 for private air travel, and false sworn testimony to the CFTC during its investigation.
avoid.net/vlad→4/100[CRITICAL]"$VLAD" is not a single token but a ticker that has been used by at least three distinct, unrelated crypto projects on Robinhood's new "Robinhood Chain" blockchain during its permissionless memecoin boom in July 2026, plus unrelated pre-existing tokens with the same ticker on other chains (a Solana pump.fun token called Vladcoin and a low-volume Ethereum token called Vlad Finance). The most notable and highest-signal use of the ticker is "Vladhood ($VLAD)", a fraudulent token promoted via a confirmed unauthorized post from the compromised X account of Robinhood CEO Vlad Tenev, which falsely claimed official Robinhood affiliation. Separately, an opportunistic copycat memecoin called "The Green Bull (VLAD)" and unverified speculation about a "$VLAD" token tied to the (subsequently halted) Vlad.fun launchpad have also circulated. No project using the $VLAD ticker has any confirmed official affiliation with Robinhood Markets or Vlad Tenev, and the ticker has become a recurring vector for impersonation and copycat-token schemes.
avoid.net/knaken→4/100[CRITICAL]Knaken (Knaken Cryptohandel B.V.), a Rotterdam-based Dutch cryptocurrency exchange founded in 2017, was declared bankrupt by a Rotterdam court on July 16, 2026 after roughly €7 million in customer funds could not be accounted for. The platform, which had roughly 30,000 customers, went offline in early June 2026 after failing to obtain the license required under the EU's Markets in Crypto-Assets (MiCA) regulation, and is now the subject of a Dutch Public Prosecution Service (OM) criminal investigation into the missing funds.
avoid.net/andean-medjedovic-kyberswap-indexed-finance-attacker→0/100[CRITICAL]Andean Medjedovic is a 22-year-old Canadian national indicted by the U.S. Department of Justice (Eastern District of New York) on February 3, 2025, for allegedly stealing approximately $65 million from two decentralized finance protocols — Indexed Finance ($16.5 million in October 2021) and KyberSwap ($48.4 million in November 2023) — through flash-loan manipulation and deceptive smart contract trading. He has been a fugitive since December 2021, was arrested in Belgrade, Serbia in August 2024 but released after extradition was denied, and was believed to be at large in Bosnia as of January 2025. A Washington D.C. lobbying firm filed documents in February 2026 seeking a U.S. presidential pardon on his behalf.
avoid.net/abracadabra-money-mim-depeg-june-2026→12/100[CRITICAL]Abracadabra Money's Magic Internet Money (MIM) stablecoin experienced a severe depeg event in June 2026, falling from its $1 target to approximately $0.43–$0.50, a collapse of over 50%. The crisis built over ten days beginning June 15, 2026, and was accompanied by $994 million in cross-market liquidations and a broader crypto market downturn. Emergency measures launched June 25 — including sharply raised Cauldron interest rates and suspended Curve bribes — represent the protocol's fourth major stability incident since 2024.
avoid.net/andean-medjedovic→2/100[CRITICAL]Andean Medjedovic is a Canadian national and mathematics prodigy charged by U.S. federal prosecutors in February 2025 with allegedly stealing approximately $65 million from two decentralized finance protocols — Indexed Finance in October 2021 ($16.5 million) and KyberSwap in November 2023 ($48.4 million). He faces a five-count federal indictment in the Eastern District of New York covering wire fraud, unauthorized computer damage, attempted extortion, money laundering conspiracy, and money laundering. As of mid-2026, Medjedovic remains a fugitive, believed to be in Bosnia and Herzegovina, and has engaged Washington D.C. lobbyists in an attempt to secure a presidential pardon from the Trump administration.
avoid.net/huione-group-haowang-guarantee→0/100[CRITICAL]Huione Group is a Cambodia-based conglomerate that operated Huione Guarantee (also known as Haowang Guarantee), a Telegram-based peer-to-peer marketplace that blockchain analytics firm Elliptic has described as the largest illicit online marketplace ever recorded, processing over $31 billion in illicit transactions since 2021. The group's payments arm, Huione Pay, received an additional $103 billion in cryptocurrency payments over its lifetime. On June 23, 2026, the U.S. Department of Justice seized the cloud computing infrastructure used by Huione Group subsidiaries as part of Operation Riptide; the U.S. Treasury's FinCEN had previously designated Huione Group a primary money laundering concern in October 2025 under Section 311 of the USA PATRIOT Act and simultaneously proposed extending the ban to successor entity H-Pay Service PLC.
avoid.net/q2-2026-defi-record-hack-wave→0/100[CRITICAL]Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.
avoid.net/daniel-chartraw-crypto-pal→2/100[CRITICAL]Daniel Chartraw, 53, formerly of South Lake Tahoe and Lodi, California, was convicted by a federal jury on June 18, 2026 in the Eastern District of California for operating Crypto-Pal LLC, a fraudulent web-based cryptocurrency trading platform that falsely guaranteed high returns with no risk. Chartraw defrauded investors of nearly $1 million between March 2021 and February 2022, operating under aliases to conceal a prior federal fraud conviction for a separate multi-million-dollar precious metals scheme. He faces up to 20 years in prison per count at sentencing scheduled for September 28, 2026.
avoid.net/ekubo-protocol→42/100[WARNING]Ekubo Protocol is a concentrated-liquidity DEX built primarily on Starknet, founded by ex-Uniswap lead engineer Moody Salem and backed by Uniswap Labs Ventures. On May 5, 2026, a missing payer-validation check in the IPayer.pay callback of its EVM swap router contracts allowed an attacker to drain approximately $1.4 million in WBTC from a single victim wallet across 85 rapid transactions, with the Starknet core deployment and liquidity providers remaining unaffected. The stolen funds were subsequently converted to ETH and routed through Tornado Cash.
avoid.net/gotbit-vortex-antier-contrarian-market-manipulation-ring→2/100[CRITICAL]Gotbit, Vortex, Antier Solutions, and Contrarian are four cryptocurrency market-making firms whose executives and employees were charged by the U.S. Department of Justice as part of Operation Token Mirrors, an FBI-led undercover investigation into wash trading and pump-and-dump schemes. Between 2018 and 2025, the firms allegedly provided market manipulation as a service to dozens of crypto projects, generating artificial trading volume through algorithmic bots and coordinated self-dealing across hundreds of wallets. In total, more than $25 million in cryptocurrency was seized and 28 individuals and entities faced criminal or civil charges across two waves of enforcement in October 2024 and March 2026.
avoid.net/andean-medjedovic-kyberswap-indexed-finance-fugitive-active-laundering-2026→2/100[CRITICAL]Andean 'Andy' Medjedovic is a Canadian national charged by the U.S. Department of Justice in February 2025 with five federal counts related to the alleged theft of approximately $65 million across two DeFi exploits: the 2021 Indexed Finance hack ($16.5M) and the 2023 KyberSwap exploit ($48.8M). He has been a fugitive since December 2021, evaded extradition after a Serbian court rejected a Dutch arrest warrant in late 2024, and as of April 2026 wallets attributed to him by law enforcement had routed approximately $24.88 million through Tornado Cash, with an estimated $29 million in exploit proceeds remaining in identified wallets.
avoid.net/doj-ten-foreign-nationals-crypto-market-manipulation-ring→3/100[CRITICAL]Operation Token Mirrors was a multi-year FBI and IRS Criminal Investigation undercover operation culminating in the March 30, 2026 unsealing of three federal indictments charging ten foreign nationals employed across four cryptocurrency financial services firms — Gotbit, Vortex, Contrarian, and Antier Solutions — with wire fraud conspiracy and wire fraud for coordinated wash trading and pump-and-dump schemes designed to artificially inflate token prices and trading volumes. The case, filed in the Northern District of California, represents one of the most comprehensive enforcement actions against professional wash trading services in the history of crypto markets. More than $1 million in cryptocurrency has been seized, two defendants have pleaded guilty and been sentenced, and three were extradited from Singapore.
avoid.net/satori-finance→48/100[WARNING]Satori Finance was a decentralized perpetual futures exchange that raised $10 million in May 2022 from Polychain Capital, Coinbase Ventures, and Jump Crypto, and processed a reported $134 billion in cumulative trading volume before announcing its shutdown on June 16, 2026. The platform cited prolonged unfavorable market conditions and insufficient revenue as the reason for closure, giving users a 30-day window to withdraw funds before a hard deadline of July 16, 2026 at 23:59 UTC. No hacks, exploits, or fraud allegations have been substantiated; the shutdown appears to be an orderly wind-down of a VC-backed DeFi project that failed commercially.
avoid.net/ab-dao→18/100[CRITICAL]AB DAO (ticker: $AB) is a decentralized autonomous organization and blockchain ecosystem that emerged in early 2025 from the rebranding of the Newton Project (formerly $NEW), originally founded in 2018. The project attracted significant investigative scrutiny in April 2026 when a joint OCCRP and Guardian Australia investigation found that AB-affiliated entities promoted a Timor-Leste crypto resort project that involved multiple individuals subsequently sanctioned by the U.S. Treasury for alleged ties to the Prince Group, described by U.S. authorities as a multibillion-dollar online fraud syndicate. AB also announced a blockchain partnership with World Liberty Financial, a cryptocurrency project co-owned by Trump family members, in November 2025.
avoid.net/0x62d5a59e0d67c0381aad53b201b4a1b8dcd2c833→45/100[WARNING]0x62d5a59e0d67c0381aad53b201b4a1b8dcd2c833 is an Ethereum externally owned account (EOA) with minimal on-chain activity, consisting of exactly two zero-value incoming transfers from the same source address in May 2026. No name tags, entity labels, scam reports, or regulatory flags have been identified for this address across Etherscan, ChainAbuse, or open-web sources as of June 2026.
avoid.net/gnosis-pay→42/100[WARNING]Gnosis Pay is a self-custodial Visa debit card platform launched in 2023 that allows users to spend stablecoins such as EURe directly from Safe smart-contract wallets at over 80 million merchants globally. On June 1, 2026, an active exploit was discovered targeting a vulnerability in the Zodiac Delay Modifier v1.1.0 and Roles Modifier v2 modules used by Gnosis Pay, allowing attackers to bypass the platform's built-in three-minute transaction delay protection and drain funds from affected Safe wallets. Gnosis co-founder Martin Köppelmann committed to covering all user losses, and a phased service restoration with new card-linked Safe accounts was announced for affected users as of June 2, 2026.
avoid.net/jump-trading→42/100[WARNING]Jump Trading is a Chicago-based proprietary trading firm founded in 1999, operating one of the largest high-frequency trading operations globally across futures, equities, fixed income, FX, and cryptocurrency markets. Its crypto division, Jump Crypto, became a major force in DeFi infrastructure between 2021 and 2023, co-developing Wormhole, Pyth Network, and the Firedancer Solana validator client. The firm has faced significant regulatory and legal exposure: its subsidiary Tai Mo Shan settled with the SEC in December 2024 for $123 million over TerraUSD manipulation, the Terraform bankruptcy administrator filed a $4 billion civil lawsuit in December 2025 naming Jump and individual executives, and a separate CFTC investigation was reported in 2024 with no public resolution as of mid-2026.
avoid.net/quant-network→58/100[CAUTIONARY]Quant Network (QNT) is a UK-incorporated enterprise blockchain interoperability platform built on proprietary Overledger technology. Founded by Gilbert Verdian, the company has verified partnerships with major UK banks (Barclays, HSBC, Lloyds, NatWest) through the UK Regulated Liability Network, and completed Project Rosalind with the Bank of England and BIS. No SEC enforcement actions exist. Key concerns include closed-source code limiting auditability, centralized governance, a pay-to-play developer licensing model, and some partnership announcements with limited verifiable follow-through.
avoid.net/algorand→52/100[CAUTIONARY]Algorand is a Layer-1 blockchain founded in 2017 by Silvio Micali, a Turing Award-winning MIT cryptographer who co-invented zero-knowledge proofs and verifiable random functions. The protocol uses a Pure Proof-of-Stake consensus mechanism with genuine academic credibility, and has attracted institutional partnerships including FIFA and Visa-adjacent integrations. However, ALGO has been named as an alleged unregistered security in SEC complaints against both Bittrex and Binance, the Algorand Foundation conducted a highly criticized 2019 token auction that resulted in a mass refund event, the token trades approximately 96% below its 2021 all-time high, and the Foundation cut 25% of its workforce in 2025 while relocating from Singapore to the United States.
avoid.net/liquid-marketplace→6/100[CRITICAL]Liquid Marketplace (also styled Liquid MarketPlace) was a Toronto-based platform that offered fractional ownership of physical and digital collectibles through blockchain-based ERC-20 tokens, co-founded by YouTuber Logan Paul and collectors Ryan Bahadori and Amin Nikdel. In June 2024 the Ontario Securities Commission filed enforcement proceedings before Canada's Capital Markets Tribunal, alleging a multi-layered fraud in which approximately $3 million of more than $10 million raised from investors was misappropriated by the company's three principal executives through undisclosed shell companies, personal expenses, and interest-free loans that were never repaid. As of mid-2026 the merits hearing remains active and no final adjudication has been issued.
avoid.net/kelp-dao→32/100[WARNING]Kelp DAO is a liquid restaking protocol built on EigenLayer that issues rsETH, a non-rebasing liquid restaking token. Originally incubated by Stader Labs and later rebranded to KernelDAO, the protocol grew to over $1.6 billion in TVL before suffering the largest single DeFi exploit of 2026: a $292 million cross-chain bridge attack attributed to North Korea's Lazarus Group. The protocol completed an operational rsETH recovery approximately five weeks after the hack through the DeFi United initiative, but significant reputational, systemic, and structural questions remain.
avoid.net/zrx-0x-protocol→62/100[CAUTIONARY]0x Protocol (ticker: ZRX) is a decentralized exchange infrastructure protocol founded in 2016 by Will Warren and Amir Bandeali, enabling peer-to-peer token trading on Ethereum and multiple other chains. The project conducted a $24 million ICO in August 2017, has processed over $200 billion in cumulative trading volume, and operates the Matcha DEX aggregator. In September 2023, the U.S. CFTC settled charges against ZeroEx, Inc.—the corporate entity behind 0x—for $200,000 related to the unlicensed offering of leveraged token trading; and in January 2026 a third-party integration (SwapNet) used in Matcha Meta suffered a $13.4 million exploit, though 0x's core protocol contracts were not compromised.
avoid.net/bonzo-lend→22/100[CRITICAL]Bonzo Lend is a decentralized lending and borrowing protocol on the Hedera network, adapted from the Aave v2 codebase and formerly the largest DeFi lending protocol on Hedera by total value locked. On July 11, 2026, the protocol suffered a $9.05 million loss when an attacker exploited a critical signature verification flaw in its third-party Supra oracle provider, inflating the SAUCE token price by approximately twelve orders of magnitude and borrowing assets far in excess of deposited collateral. Protocol operations remain paused pending a Halborn-audited recovery contract deployment backed by the Hedera Foundation.
avoid.net/bitmart-exchange→18/100[CRITICAL]BitMart is a centralized cryptocurrency exchange founded in 2017 by Sheldon Xia and incorporated in the Cayman Islands, which at its peak served users in over 180 countries and listed more than 1,700 cryptocurrencies. In December 2021, BitMart suffered one of the largest hot-wallet hacks in crypto history, losing approximately $196 million, which triggered a Federal Trade Commission investigation and raised unresolved questions about victim reimbursement. On July 26, 2026, BitMart announced it would wind down all trading operations by August 26, 2026 and fully close by January 31, 2027, citing vague 'operating conditions' while its CEO simultaneously disclosed he had been excluded from the shutdown decision — a combination of events that poses immediate fund-access risk for remaining users.
avoid.net/janus-henderson-anemoy-aaa-clo-fund-jaaa→72/100[CAUTIONARY]The Janus Henderson Anemoy AAA CLO Fund (JAAA) is a tokenized real-world asset fund providing on-chain exposure to AAA-rated tranches of Collateralized Loan Obligations (CLOs), actively managed by Janus Henderson Investors U.S. LLC as sub-advisor and issued by Anemoy Capital SPC Limited, a British Virgin Islands regulated professional fund. Launched in June 2025 with a $1 billion seed allocation from the Sky/MakerDAO ecosystem via the Grove DeFi protocol, the tokenized fund had approximately $686 million in assets under management as of June 2026. The fund is restricted to non-US qualified institutional investors who pass KYC/AML onboarding via the Centrifuge platform, and carries inherent risks from CLO market credit spreads, smart contract infrastructure, cross-jurisdictional regulatory uncertainty, and stablecoin dependency.
avoid.net/usx→62/100[CAUTIONARY]USX is a Solana-native synthetic stablecoin issued by Solstice Finance, a DeFi protocol incubated by Deus X Capital, a $1 billion institutional digital-asset investment firm. Launched on September 30, 2025 with $160 million in TVL, USX is backed 1:1 by a diversified reserve of USDC, USDT, tokenized Treasuries, and delta-neutral hedged positions, with reserves attested in real time via Chainlink and Accountable. In December 2025, USX briefly depegged to $0.10 on secondary Solana DEX markets due to a liquidity crunch; the issuer attributed the event to secondary-market illiquidity rather than collateral failure, and USX subsequently restabilized near $1.00.
avoid.net/audiera-beat→32/100[WARNING]Audiera is a BNB Chain-based Web3 gaming and music platform that markets itself as the blockchain evolution of the Audition rhythm game franchise, issuing the BEAT token at TGE in November 2025. The project has attracted significant speculative trading volume, reaching a market cap briefly exceeding $2 billion in June 2026 before collapsing approximately 88% within days, raising pump-and-dump concerns among analysts. Key risk factors include anonymous or undisclosed founding team, unverified IP licensing claims relating to the original Audition game IP owned by T3 Entertainment, concentrated token distribution, and derivative-driven price action disconnected from measurable user adoption.
avoid.net/pax-gold-paxg→72/100[CAUTIONARY]PAX Gold (PAXG) is a regulated, gold-backed ERC-20 token issued by Paxos Trust Company, launched in September 2019, where each token represents one fine troy ounce of physical gold stored in Brink's vaults in London. Paxos holds a national trust charter from the U.S. Office of the Comptroller of the Currency (OCC) as of December 2025, and publishes monthly third-party attestation reports via KPMG. The issuing entity, Paxos Trust Company, entered a $48.5 million settlement with the New York Department of Financial Services (NYDFS) in August 2025 over anti-money laundering failures tied to its prior BUSD stablecoin business, which does not directly implicate PAXG but reflects compliance weaknesses at the parent firm.
avoid.net/falcon-usd-usdf→42/100[WARNING]Falcon USD (USDf) is a synthetic overcollateralized dollar token issued by Falcon Finance, a protocol incubated and backed by DWF Labs, launched publicly on April 30, 2025. As of mid-2026, USDf holds a market capitalization of approximately $1.4 billion, ranking it among the top synthetic stablecoins. The protocol has attracted significant scrutiny due to its parent firm DWF Labs facing alleged market manipulation and wash trading charges, a notable depeg event in July 2025, opaque off-chain reserve management, and concerns raised by independent DeFi risk researchers over collateral quality and centralized control.
avoid.net/aztec-connect-deprecated-bridge-double-exploit-june-2026→20/100[CRITICAL]In June 2026, two separate deprecated Aztec infrastructure contracts on Ethereum were exploited within one week, draining a combined total of approximately $4.25 million. The first exploit, on June 14, targeted the legacy Aztec Connect rollup contract via a proof verification mismatch; a follow-on second attack on June 15 drained residual funds. A third, separate exploit on June 17-18 hit the deprecated Aztec Private Rollup Bridge's escapeHatch function. Aztec Labs stated it had renounced all admin keys over the affected contracts in April 2024 and that the incidents had no connection to the current Aztec Network or AZTEC ERC-20 token.
avoid.net/loopring-dex-shutdown-june-2026→38/100[WARNING]Loopring, Ethereum's first zero-knowledge rollup decentralized exchange, permanently ceased all trading and relayer operations on June 28, 2026, citing lack of meaningful user adoption, architectural obsolescence relative to modern zkEVM competitors, and a cascade of major exchange delistings of its LRC token. The shutdown is notable for disabling the protocol's hallmark trustless self-custody exit mechanism in favor of a team-controlled batch distribution, raising concerns among DeFi researchers about the integrity of the protocol's security guarantees at the moment they matter most.
avoid.net/hu-xiaowei-prince-group-second-in-command→2/100[CRITICAL]Hu Xiaowei, also known as Chen Xiao'er, Hu Shi, and Wu An Ming, is a 44-year-old Chinese-born individual alleged by U.S. Treasury and Taiwanese prosecutors to be the second-in-command of Cambodia's Prince Group Transnational Criminal Organization (TCO). He was arrested in Osaka, Japan on June 14, 2026 on charges of filing falsified residency records, and was designated by OFAC on June 23, 2026 as part of the largest U.S. government action ever taken against a Southeast Asian cybercriminal network. He allegedly controlled a network of British Virgin Islands shell companies used to launder proceeds from pig-butchering cryptocurrency fraud schemes that cost American victims at least $10 billion in 2024.
avoid.net/blessings-in-no-time-bint→0/100[CRITICAL]Blessings in No Time (BINT) was an illegal chain-referral pyramid scheme operated by LaShonda Moore (38) and Marlon Moore (39) of Frisco, Texas, from June 2020 to June 2021. The scheme defrauded more than 10,000 people nationwide out of more than $30 million by falsely promising 800% returns on $1,400 investments, and specifically targeted the African American community through weekly livestream broadcasts during the COVID-19 pandemic. In January 2026, a federal jury convicted the Moores on conspiracy, wire fraud, and money laundering charges; in June 2026, they were each sentenced to 40 years in federal prison and ordered to pay more than $4.3 million in restitution.
avoid.net/rain-protocol-rain-token→12/100[CRITICAL]Rain Protocol is a decentralized prediction markets protocol built on Arbitrum, with its native RAIN token reaching an approximately $8.8 billion fully diluted valuation (FDV) by mid-2026. On-chain investigator ZachXBT alleged in June 2026 that 99.97% of RAIN's total supply is controlled by 81 wallets and that deployer wallet funding trails link the Rain team to the Data Ownership Protocol (DOP) and TOMI networks, projects associated with Israeli entrepreneur Moshe Hogeg, who faces a recommended $290 million fraud indictment in Israel. Rain Protocol has not issued a public response to these allegations, and no regulatory action has been taken against Rain Protocol directly.
avoid.net/blockfills-reliz-technology-group-holdings→4/100[CRITICAL]BlockFills, a Chicago-based institutional crypto trading and lending firm operating through parent entity Reliz Technology Group Holdings, Inc., filed Chapter 11 bankruptcy on March 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware, reporting $50–100M in assets against $100–500M in liabilities. A central allegation — confirmed by debtors' own counsel at the first-day hearing — is that client funds were never segregated but were commingled with company funds on a single balance sheet, producing an estimated $77M deficit that renders clients unsecured creditors. In June 2026, Brussels-based market maker Keyrock agreed to acquire substantially all BlockFills assets for $3.25M, a figure that represents a fraction of total liabilities and raises serious doubts about meaningful client recovery.
avoid.net/bitget-exchange→27/100[WARNING]Bitget is a centralized cryptocurrency derivatives and spot exchange founded in 2018, currently ranked among the top five global exchanges by trading volume with a reported user base exceeding 120 million. Between April and May 2026, blockchain investigator ZachXBT published a series of on-chain investigations alleging that Bitget systematically enabled coordinated pump-and-dump schemes across at least four tokens — RAVE, RIVER, SIREN, and LAB — by allowing insiders to pre-position large holdings before engineered price pumps that erased billions in retail value. A separate incident in April 2025 involving a malfunctioning market-making bot on VOXEL/USDT futures resulted in over $100 million in estimated losses, forced account rollbacks, and drew comparisons to earlier exchange failures.
avoid.net/cls-global-zm-quant→4/100[CRITICAL]CLS Global FZC LLC (UAE) and ZM Quant Investment Ltd (British Virgin Islands) are crypto market-making firms charged in October 2024 as part of DOJ Operation Token Mirrors, an FBI undercover sting that created a fake token called NexFundAI to expose market-manipulation-as-a-service. Both firms are alleged to have generated billions of dollars in artificial trading volume through algorithmic wash trading on behalf of token promoters. CLS Global pleaded guilty to criminal charges in January 2025 and was sentenced to pay $428,059 in April 2025; parallel DOJ criminal proceedings against ZM Quant (case 1:24-cr-10187) remain on record as of June 2026. The SEC voluntarily dismissed its civil enforcement actions against both entities on March 31, 2026, reflecting a policy shift under the current administration, though those dismissals do not constitute a finding of innocence and do not affect the DOJ criminal proceedings.
avoid.net/cls-global-fzc-zm-quant-investment→3/100[CRITICAL]CLS Global FZC LLC (UAE) and ZM Quant Investment Ltd (British Virgin Islands) were crypto market-making firms that provided market-manipulation-as-a-service to token issuers. Both were charged in October 2024 by the U.S. DOJ and SEC as part of Operation Token Mirrors, a coordinated FBI sting that used a fake token called NexFundAI to document wash trading solicitation in real time. CLS Global pleaded guilty in January 2025 and was sentenced in April 2025 to pay $428,059 and serve a three-year U.S. market ban; ZM Quant's criminal case (1:24-cr-10187, D. Mass.) remained pending as of mid-2025 with its two individual defendants, Baijun Ou and Ruiqi Liu, based outside the United States. The SEC voluntarily dismissed its parallel civil actions against both entities on March 31, 2026, consistent with the current administration's broader rollback of crypto enforcement actions initiated under the prior administration.
avoid.net/pond0x→18/100[CRITICAL]Pond0x is a decentralized exchange and token ecosystem launched in July 2023 by Jeremy Cahen, known online as Pauly0x. The project's initial token launch (PNDX) resulted in more than $2.2 million in investor losses due to a smart contract vulnerability that allowed any user to transfer tokens from another wallet without authorization; critics alleged this was intentional. The founder has an extensive record of legal and regulatory entanglements including a $9 million trademark judgment from Yuga Labs (later vacated on appeal and settled), court-documented allegations of evading asset seizure, and a February 2025 listing on San Juan, Puerto Rico's Top 10 Most Wanted list for alleged aggravated assault.
avoid.net/visor-finance→18/100[CRITICAL]Visor Finance was an Ethereum-based DeFi protocol offering active liquidity management for Uniswap v3 concentrated liquidity positions via smart-contract vaults called Hypervisors. The protocol suffered three separate security incidents in 2021 — an admin-key compromise in June ($500K), a price-manipulation attack in November (alleged $773K), and a critical reentrancy exploit in December that drained approximately $8.2M in VISR tokens from the vVISR staking contract. Following the December exploit, Visor merged with co-funded research arm Gamma Strategies in January 2022 and rebranded entirely, migrating token holders to the GAMMA token.
avoid.net/blockfills→12/100[CRITICAL]BlockFills (operated by Reliz Technology Group Holdings, Inc.) was a Chicago-based institutional cryptocurrency trading and lending firm that processed $61.1 billion in volume in 2025 before filing for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of Delaware on March 15, 2026. The firm suspended client withdrawals and deposits on February 11, 2026, amid approximately $75 million in accumulated lending losses, and subsequently faced two civil lawsuits alleging misappropriation of customer assets and commingling of client funds with company funds. At the time of filing, BlockFills reported assets of $50 million to $100 million against liabilities of $100 million to $500 million, with approximately $145 million in general unsecured obligations.
avoid.net/doj-pig-butchering-seizure-july-2026→92/100[VERIFIED]On July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints seeking to recover more than $25 million in USDT linked to pig butchering investment fraud and romance scams traced to networks operating out of Southeast Asia. The action was carried out by the Scam Center Strike Force, a multi-agency unit launched in November 2025 that has cumulatively recovered over $800 million in cryptocurrency from Chinese transnational criminal organizations running scam compound operations in Cambodia, Myanmar, and Laos. No individual defendants were named in the July 2026 complaints; the government proceeded in rem, suing the digital assets directly.
avoid.net/doj-25m-pig-butchering-seizure-july-2026→5/100[CRITICAL]On July 21, 2026, the U.S. Attorney's Office for the District of Columbia, operating through the Scam Center Strike Force, filed five civil forfeiture complaints targeting more than $25 million in USDT linked to international pig-butchering fraud rings operating primarily from Southeast Asia. The complaints identify hundreds of U.S. and Canadian victims across romance scams, fake cryptocurrency investment platforms, and fraudulent asset-recovery services, with no individual defendants named. This action is part of a broader 2026 enforcement surge that includes a $61 million USDT seizure in North Carolina, Treasury sanctions against Cambodian Senator Kok An and his Crown Resorts compound network, and a Dubai-led international operation resulting in 276 arrests and $701 million frozen.
avoid.net/vladhood-vlad-memecoin-scam→2/100[CRITICAL]On July 23, 2026, unknown attackers compromised the verified X account of Robinhood CEO Vlad Tenev and used it to promote a fraudulent memecoin called Vladhood ($VLAD), falsely presenting it as the official mascot of the Robinhood Chain network and claiming it would be listed in the Robinhood app. The token had been pre-deployed on the Pons launchpad 46 minutes before the post appeared, and attackers extracted approximately 650 ETH ($1.2–$1.3 million USD) through trading fee collection rather than a traditional rug pull. No attacker attribution or law enforcement action had been publicly reported as of late July 2026.
avoid.net/ashcrypto→18/100[CRITICAL]Ashcrypto (also known as AshWSB) is a crypto influencer with over 2.1 million followers on X who has been publicly accused by on-chain investigator ZachXBT of running pump-and-dump schemes on illiquid CEX-listed altcoins. The most documented case involves the ROYA token, where Ashcrypto allegedly publicly promoted the asset while simultaneously selling his position and telling premium channel subscribers he was holding and buying more. No regulatory enforcement action has been filed as of July 2026.
avoid.net/triple-a→38/100[WARNING]Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payments company founded in 2017 and licensed as a Major Payment Institution by the Monetary Authority of Singapore (MAS). On July 24-25, 2026, attackers drained approximately $9.7 million from the company's hot wallets across at least four blockchain networks, with stolen funds consolidated into a single Ethereum address. As of the date of this report, Triple-A had issued no public acknowledgment of the breach despite continuing to accept live deposits, raising concerns about transparency obligations under its MAS licence.
avoid.net/invesco-short-duration-us-government-securities-fund-ustb→78/100[VERIFIED]USTB is a tokenized short-duration U.S. Treasury fund originally launched by Superstate in February 2024 and transitioned to Invesco Advisers, Inc. as investment manager in mid-2026. As of July 2026, the fund holds approximately $682 million in AUM, is deployed on Ethereum, Solana, and Plume, and is restricted to accredited investors and qualified purchasers. It operates as a private Section 3(c)(7) fund under a Regulation D Rule 506(c) exemption and has no record of regulatory enforcement actions, fraud allegations, or security incidents.
avoid.net/janus-henderson-anemoy-treasury-fund-jtrsy→82/100[VERIFIED]The Janus Henderson Anemoy Treasury Fund (JTRSY) is a tokenized British Virgin Islands professional fund that invests exclusively in short-term U.S. Treasury Bills with maturities under six months, issued on-chain via the Centrifuge protocol. The fund is regulated by the BVI Financial Services Commission, managed by Anemoy Asset Management with Janus Henderson Investors as sub-investment manager, and has received top-tier credit ratings including AA+f/S1+ from S&P Global Ratings as of March 2025. Access is restricted to non-U.S. professional investors and qualified crypto institutions, with subscriptions and redemptions settled in USDC.
avoid.net/ylds→68/100[CAUTIONARY]YLDS is a yield-bearing, SEC-registered debt security issued as a tokenized face-amount certificate by Figure Certificate Company (FCC), a wholly owned subsidiary of Figure Technology Solutions, Inc. (Nasdaq: FIGR). It is the first interest-bearing transferable stablecoin to be registered under the U.S. Investment Company Act of 1940, and as of mid-2026 has approximately $540 million in circulation across Provenance Blockchain, Solana, Stellar, and Sui. While the product carries legitimate regulatory backing, parent company Figure Technology Solutions faces outstanding short-seller allegations regarding blockchain misrepresentation, lending quality, and a significant 2026 data breach affecting nearly one million customers.
avoid.net/united-stables-u→48/100[WARNING]United Stables is a USD-pegged stablecoin issued by United Stables Limited (registered in the British Virgin Islands), operating under the ticker symbol U. Launched in December 2025 on BNB Chain and Ethereum, it reached approximately $1 billion in circulating supply by mid-2026, ranking among the top-100 cryptocurrencies by market cap. The issuer explicitly states it holds no regulatory licenses under MiCA, Hong Kong stablecoin law, or the US GENIUS Act, and the public leadership profile is extremely limited, with the CEO identified only as 'Athena Y.'
avoid.net/binancelife→28/100[WARNING]BinanceLife (币安人生, ticker 币安人生/BINANCELIFE) is a Chinese-language meme token launched on the BNB Smart Chain via the Four.meme launchpad on October 4, 2025. It has no affiliation with the Binance exchange, Binance founder Changpeng Zhao (CZ), or CZ's memoir of the same Chinese title, despite its name and branding closely evoking Binance. The token operated for months with no official website, no verified team, and heavily concentrated token holdings, yet was nonetheless listed on Binance Alpha and later Binance's spot market, raising concerns about the risk of retail investors mistaking it for an official Binance-affiliated asset.
avoid.net/usdd→28/100[WARNING]USDD is a stablecoin issued by the TRON DAO Reserve, launched in May 2022 and marketed as an over-collateralized, algorithmically-assisted alternative to Terra's failed UST. USDD de-pegged from its $1.00 target within weeks of launch and again during the November 2022 FTX collapse, and has since faced sustained criticism over opaque, shifting reserve composition, a defunct governance structure, and the concentration of control and collateral around TRON founder Justin Sun and his exchange HTX. Independent stablecoin rating firm Bluechip assigned USDD the lowest grade ('F') among stablecoins it assessed, citing commingled reserves and an absence of functioning decentralized governance.
avoid.net/gmgn-ai→58/100[CAUTIONARY]GMGN.ai is a Singapore-based, primarily Chinese-run multi-chain memecoin trading terminal and Telegram trading bot, launched in mid-2023, focused on Solana, Ethereum, Base, and BNB Chain token discovery, smart-money wallet tracking, and copy trading. The platform states it is non-custodial and cannot move user wallet balances itself, but it carries a poor Trustpilot rating driven by complaints about copy-trading losses and unclear fees, and it has been the target of extensive phishing and impersonation campaigns — including fake mobile apps and cloned websites — that have drained victims' wallets. No confirmed breach of GMGN's own infrastructure or misappropriation of user funds by the company has been documented in available sources.
avoid.net/doj-global-pig-butchering-takedown-ko-thet-sanduo-giant-company→0/100[CRITICAL]In April and May 2026, the U.S. Department of Justice's Scam Center Strike Force, in coordination with the FBI, Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police, announced charges against six individuals operating three named cryptocurrency investment fraud organizations — Ko Thet Company, Sanduo Group, and Giant Company — as part of a coordinated global takedown that resulted in at least 276 arrests, dismantlement of nine scam centers, and restraint of over $701 million in cryptocurrency linked to money laundering. The operations are part of a broader law enforcement campaign against Southeast Asian pig-butchering fraud compounds that have been estimated to defraud Americans of billions of dollars annually, and are intertwined with human trafficking and forced labor.
avoid.net/binance-mica-greece-application-withdrawal→32/100[WARNING]Binance, the world's largest cryptocurrency exchange by trading volume, withdrew its Markets in Crypto-Assets (MiCA) license application from Greece's Hellenic Capital Market Commission on June 24, 2026, days before the EU's July 1, 2026 compliance deadline, after reports indicated the regulator was preparing to reject the bid. The withdrawal triggered a suspension of services across all 27 EU member states effective July 1, 2026, affecting users in France, Italy, Poland, Spain, and other countries. Binance stated it intends to pursue MiCA authorization through another EU member state, with France cited as the most likely destination, though the exchange already faces an active judicial probe there over alleged money laundering and tax fraud.
avoid.net/mexc-exchange→32/100[WARNING]MEXC Exchange is a global cryptocurrency trading platform founded in 2018 and currently headquartered in the Seychelles. The exchange has accumulated regulatory warnings from multiple jurisdictions including Germany (BaFin), the Netherlands (AFM), Japan (FSA), Hong Kong (SFC), Estonia (FIU), and the Seychelles (FSA), primarily for operating without required authorizations. As of July 1, 2026, MEXC does not hold a MiCA Crypto-Asset Service Provider (CASP) license and formally exited the EU market, instructing EU users to withdraw funds before the deadline.
avoid.net/rowan-energy-david-duckworth-five-year-green-crypto-fraud→2/100[CRITICAL]Rowan Energy was a UK-based company founded by David Duckworth that marketed a blockchain-powered green energy rewards platform, selling SmartMiner hardware devices and the RWN token under the premise of tokenized renewable energy certificates. In April 2025, a white-hat researcher discovered a hidden token minting function and a suppressed token supply nearly double the publicly stated figure; Duckworth denied the allegations for 69 days before the company quietly shut down its blockchain on June 24–25, 2025, causing a greater than 99.9% collapse in RWN token value and leaving investors with no refund or recourse.
avoid.net/shibarium-bridge→32/100[WARNING]The Shibarium Bridge is the Ethereum-to-Shibarium cross-chain bridge operated by the Shiba Inu ecosystem team, enabling transfer of SHIB, BONE, LEASH, and other tokens between Ethereum mainnet and the Shibarium Layer 2 network. The bridge suffered two major incidents: a chaotic launch in August 2023 that left approximately $1.7 million in ETH temporarily inaccessible, and a far more serious exploit in September 2025 in which attackers compromised 10 of 12 validator signing keys to drain approximately $3–4.1 million in assets. The bridge was partially restored in October 2025 following a security overhaul, but hack victims faced ongoing repayment delays and independent analysts raised persistent concerns about centralization and governance design.
avoid.net/huobi-htx→14/100[CRITICAL]HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.
avoid.net/taiko-l2-bridge-exploit-june-2026→22/100[CRITICAL]On June 21–22, 2026, Taiko — an Ethereum-equivalent Layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million (roughly 870 ETH and 1.99 million TAIKO tokens) by forging cross-chain withdrawal proofs using an SGX enclave signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The team halted block production, froze bridge and ERC20Vault contracts, and pledged full 1:1 recollateralization before reopening. The incident is part of a broader 2026 pattern of bridge exploits totaling over $340 million across 14+ incidents.
avoid.net/trenton-richard-johnston→2/100[CRITICAL]Trenton Richard David Johnston is a Canadian national who pleaded guilty on June 10, 2026 in U.S. District Court in Miami to conspiracy to commit wire fraud and conspiracy to commit money laundering in connection with a social-engineering cryptocurrency theft scheme that caused at least $13.04 million in victim losses. Johnston, who was 19 at the time of his March 2026 arrest and had overstayed a U.S. tourist visa, is identified as Co-Conspirator 2 in federal filings that name Dritan Kapllani Jr. as Co-Conspirator 1 in the same 185 BTC theft. He awaits sentencing and has agreed to deportation to Canada.
avoid.net/polymarket-june-2026-supply-chain-attack→38/100[WARNING]On June 25, 2026, Polymarket, a prominent prediction market platform, suffered a supply chain attack through a compromised third-party frontend vendor. Attackers injected malicious JavaScript that drained approximately $3.1 million in pUSD from at least 11 user wallets on Polygon, with stolen funds bridged to Ethereum and converted to roughly 1,893 ETH. The incident occurred against a backdrop of a concurrent CFTC marketing-fraud investigation and a prior private key compromise in May 2026.
avoid.net/lab-token-smartliquid-ai→4/100[CRITICAL]LAB is the native token of LABtrade, an AI-powered multi-chain trading terminal that launched its token generation event on October 14, 2025, with backers including Animoca Brands, Amber Group, and GSR. In May 2026, blockchain investigator ZachXBT published an investigation alleging that insiders control approximately 95% of the 1-billion-token supply, that 226 million LAB tokens were staged in Bitget addresses between March and April 2026 ahead of a coordinated 350%-plus price surge to a $6 billion fully diluted valuation, and that 100 million tokens worth roughly $480 million were subsequently withdrawn to 10 freshly created wallets in a 12-hour window. ZachXBT connected LAB founders Vova Sadkov and Mark X to a prior abandoned project (Eesee/$ESE), identified a BVI shell entity used in opaque loan contracts, placed a $10,000 bounty on Sadkov, and called on Binance, Bitget, and Gate.io to freeze insider profits or delist the token; no public rebuttal from the LAB team or Bitget had been issued as of the time of reporting.
avoid.net/fifa-world-cup-2026-crypto-scam-infrastructure→0/100[CRITICAL]A coordinated, multi-vector scam infrastructure emerged around the 2026 FIFA World Cup (June 11 – July 19, 2026), targeting fans through fake ticketing domains, insider-heavy memecoins, deepfake impersonation campaigns, fake live-streaming sites, and phishing-as-a-service kits. The FBI, TRM Labs, Malwarebytes, and FortiGuard Labs each issued independent warnings, with FortiGuard identifying over 13,000 FIFA-themed domains registered between January and May 2026, approximately 8.8% of which were classified as malicious or suspicious. Law enforcement flagged 30+ explicitly spoofed FIFA domains by name, while blockchain analytics firms documented a low-liquidity memecoin with alleged 95% insider supply concentration and cross-chain bridge laundering patterns.
avoid.net/olpc-bnblabubu-token-pancakeswap-pool-exploit→2/100[CRITICAL]On June 20, 2026, an attacker drained approximately $1.1 million from the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) by exploiting a logic flaw in the OLPC token's _update function, which triggered a massive burn of pool reserves. Approximately 46 days prior to the attack, the OLPC token contract owner had maliciously altered the decimalsValue parameter to an abnormally large integer before renouncing ownership, a sequence that security researchers and analysts widely characterize as a premeditated rug pull disguised as an external exploit. Stolen funds — 633.4 ETH — were bridged to Ethereum and deposited into Tornado Cash.
avoid.net/taiko-ethereum-l2-bridge→18/100[CRITICAL]On June 22, 2026, Taiko — an Ethereum-equivalent layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million from its L1 Bridge and ERC-20 vault by using an RSA-3072 Intel SGX signing key that had been committed in plaintext to the public taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and execute fraudulent withdrawal transactions on Ethereum with no corresponding deposits on Taiko's chain. Taiko halted block production network-wide, froze affected contracts, and urged all users to exit every bridge on the network within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/olpc-token-pancakeswap-olpc-labubu-pool→2/100[CRITICAL]On June 20, 2026, the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited for approximately $1.11 million. Security researchers and on-chain analysts determined the attack was premeditated: 46 days before the exploit, the OLPC token deployer had silently set the contract's decimalsValue parameter to an astronomically large value (7326680472586200649), then renounced ownership to obscure their intent. The attacker triggered a massive reserve-desynchronizing burn, drained the pool, converted proceeds to approximately 1,115,903 USDT, bridged to Ethereum, and deposited 633.4 ETH into Tornado Cash.
avoid.net/fifa-world-cup-2026-crypto-streaming-scam-network→0/100[CRITICAL]A coordinated network of fraudulent websites, malicious streaming applications, phishing campaigns, and deceptive cryptocurrency schemes targeting FIFA World Cup 2026 fans across at least six fraud typologies. The campaign encompasses more than 4,300 registered fraudulent domains, Android banking trojans embedded in fake streaming apps, a Chinese-speaking threat actor designated GHOST STADIUM operating 300+ pixel-perfect FIFA clones, and at least one fan-branded token (WCUP) alleged to be a pump-and-dump scheme. The FBI issued a public service announcement on May 27, 2026; estimated losses from ticket fraud alone range from $71 million to $474 million, with total campaign potential described by Group-IB as reaching into the billions.
avoid.net/world-cup-pvp-token-wcup→4/100[CRITICAL]World Cup PvP Token (ticker: WCUP) is an ERC-20 token that launched on June 10, 2026, capitalizing on hype surrounding the 2026 FIFA World Cup. On-chain analytics firm Bubblemaps alleged that a coordinated group of over 30 wallets pre-purchased approximately 95% of the token's circulating supply within minutes of launch, driving the market cap to $50 million on the first day against only $536,000 in actual liquidity. Multiple crypto influencers on X promoted the token without disclosing alleged compensation, a pattern consistent with a coordinated pump-and-dump scheme.
avoid.net/taiko-ethereum-l2-bridge-exploit→15/100[CRITICAL]On June 22, 2026, an attacker drained approximately $1.7 million from the Taiko Ethereum layer-2 bridge and ERC-20 vault by exploiting a leaked Intel SGX RSA-3072 signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and submit withdrawal requests on Ethereum with no matching deposits on Taiko, causing the bridge contracts to release funds against fraudulent proofs. Taiko halted block production and froze bridge withdrawals within approximately eight minutes of the attack being detected by Blockaid's monitoring system.
avoid.net/yg→42/100[WARNING]Yield Guild Games (YGG) is a Philippines-based web3 gaming guild and decentralized autonomous organization that gained prominence during the 2021 Axie Infinity play-to-earn boom. The YGG token launched in July 2021, reached an all-time high of approximately $11.27 in November 2021, and subsequently lost over 99% of its value as the play-to-earn economy collapsed. The project has since pivoted toward multi-game community coordination and game publishing under the YGG Play brand, backed by major investors including a16z Crypto and DWF Labs.
avoid.net/abracadabra-finance-mim-stablecoin→22/100[CRITICAL]Abracadabra Finance is a multi-chain DeFi lending protocol that allows users to mint its USD-pegged stablecoin Magic Internet Money (MIM) against interest-bearing collateral. The protocol has suffered four significant security exploits between January 2024 and October 2025, with cumulative losses exceeding $21 million, and its MIM stablecoin depegged twice in a single week in June 2026 — reaching as low as $0.80 — due to critically thin DEX exit liquidity. As of mid-June 2026, MIM was trading approximately 18% below its $1 peg, with the protocol relying on a 140 million SPELL token incentive program to attract liquidity providers.
avoid.net/rahul-ravinder-malhotra→50/100[WARNING]Extensive web research found no credible evidence connecting any individual named Rahul Ravinder Malhotra to cryptocurrency fraud, scams, hacks, regulatory enforcement, or sanctions. The only verifiable public match for this exact name is Rahul Ravinder K. Malhotra, a finance executive appointed as Chief Business Development Officer and Business Head for North America at Prabhudas Lilladher Private Limited in June 2024, with no reported crypto-risk associations. Due to very limited findable public information and significant name-collision risk — 'Rahul Malhotra' is a common Indian name with dozens of distinct LinkedIn profiles — a definitive risk assessment cannot be made.
avoid.net/pump-fun-solana-memecoin-launchpad-ecosystem-fraud→12/100[CRITICAL]Pump.fun is a Solana-based memecoin launchpad operated by Baton Corporation Limited that launched in January 2024 and rapidly became the dominant token creation platform on Solana, generating over $1 billion in fees by April 2025. The platform is the subject of multiple federal class action lawsuits alleging it facilitated unregistered securities sales, insider front-running via MEV infrastructure, and systemic pump-and-dump fraud affecting retail traders. Third-party analysis of over 7 million tokens launched on the platform between January 2024 and March 2025 found that 98.6% exhibited fraudulent characteristics including pump-and-dump patterns and rug pulls.
avoid.net/rodney-burton-bitcoin-rodney→2/100[CRITICAL]Rodney Burton, a 56-year-old Miami-based crypto promoter operating under the alias 'Bitcoin Rodney,' pleaded guilty on June 15, 2026, to conspiracy to operate an unlicensed money transmitting business in connection with the HyperFund Ponzi scheme, which federal prosecutors allege collected approximately $1.89 billion from investors worldwide between 2020 and 2022. Burton personally received at least $7.85 million in fraudulent proceeds and leveraged appearances by high-profile celebrities to recruit retail investors. He was arrested in January 2024 at Miami International Airport carrying a one-way ticket to the United Arab Emirates and has been held without bail pending sentencing on July 23, 2026.
avoid.net/zcash-orchard-counterfeit-vulnerability→38/100[WARNING]On June 5, 2026, Shielded Labs publicly disclosed a critical four-year-old soundness bug in Zcash's Orchard shielded pool that, if exploited, could have allowed unlimited undetectable counterfeit ZEC minting. The vulnerability was discovered on May 29, 2026 by security researcher Taylor Hornby using AI-assisted auditing tools, silently patched via emergency hard fork on June 2, and cannot be definitively ruled out as having been exploited due to Orchard's inherent privacy architecture. ZEC fell approximately 38–50% in the 48 hours following public disclosure.
avoid.net/miasma-npm-supply-chain-attack→5/100[CRITICAL]Miasma is a multi-wave, self-propagating npm supply chain attack campaign active from June 1 through at least June 10, 2026, that compromised hundreds of widely-used npm packages and dozens of GitHub repositories across organizations including Red Hat, Vapi.ai, and Microsoft Azure. The malware, a variant of the Mini Shai-Hulud credential-stealing worm associated with threat actor TeamPCP (also tracked as UNC6780), exfiltrates cloud credentials, CI/CD secrets, SSH keys, and browser-stored data including crypto wallet files, then uses stolen tokens to republish backdoored package versions and spread to additional repositories. No confirmed cryptocurrency theft or quantified financial loss from crypto assets had been publicly documented as of the investigation date, though the malware's collectors enumerate local wallet storage and the attack's credential-theft scope poses downstream risk to any crypto developer environments that installed affected packages.
avoid.net/volo-protocol→47/100[WARNING]Volo Protocol is a liquid staking and DeFi vaults platform built on the Sui blockchain, offering voloSUI (vSUI) as a liquid staking token and multi-asset yield vaults. In January 2024, it was acquired by NAVI Protocol, a leading Sui lending protocol. On April 22, 2026, Volo suffered a $3.5 million exploit targeting three isolated vaults holding WBTC, XAUm, and USDC; the team pledged to absorb all user losses and approximately $500,000 was frozen on-chain, while the root cause — attributed by security researchers to a compromised privileged operator key rather than a smart contract flaw — remained under investigation at time of writing.
avoid.net/pt-digi-global-konsultan→0/100[CRITICAL]PT Digi Global Konsultan is an Indonesian company used as a front for an international pig-butchering cryptocurrency fraud syndicate dismantled by Central Java Police in May 2026. The operation ran from July 2025 to May 2026 out of Sukoharjo District, Central Java, defrauding at least 133 victims — predominantly US citizens — of approximately $2.33 million USD (Rp41.1 billion). Thirty-nine suspects were arrested, including foreign nationals from Nepal and Myanmar, and Indonesian authorities are collaborating with the FBI.
avoid.net/bit-com→42/100[WARNING]Bit.com was a cryptocurrency derivatives and spot exchange launched in August 2020 by Matrixport, a Singapore-based digital asset firm founded by Bitmain co-founder Jihan Wu. On December 27, 2025, the exchange announced a phased wind-down under the label 'business restructuring,' with spot trading ceasing January 31, 2026, a backup withdrawal-only station active through March 31, 2026, and post-deadline asset recovery requiring individual customer-service requests. No regulatory action, security breach, or insolvency has been publicly reported as the cause; the shutdown appears consistent with a broader strategic consolidation by Matrixport, which rebranded as 'BIT' on March 20, 2026.
avoid.net/goliath-ventures→2/100[CRITICAL]Goliath Ventures (formerly Gen-Z Venture Firm) was a Florida-based cryptocurrency investment firm whose CEO, Christopher Alexander Delgado, 34, of Apopka, Florida, was arrested on February 24, 2026 on federal charges of wire fraud and money laundering. Federal prosecutors allege Delgado operated the company as a Ponzi scheme from January 2023 through January 2026, raising at least $328 million from more than 2,000 investors under false promises of 3-8% monthly returns through cryptocurrency liquidity pools, while only approximately $1.5 million was verifiably placed into liquidity pools. The firm filed for Chapter 11 bankruptcy in March 2026, and class action lawsuits have been filed against multiple third parties including JPMorgan Chase, Bank of America, Coinbase, law firm Alston & Bird, and Broad Financial for allegedly enabling the scheme.
avoid.net/treasure-dao→34/100[WARNING]Treasure DAO is an Arbitrum-based NFT gaming and metaverse ecosystem centered around the MAGIC token, founded in 2021 by John Patten and Karel Vuong. In March 2022, its NFT marketplace suffered a critical smart contract exploit in which attackers purchased approximately $1.4 million worth of NFTs at zero cost by passing a zero-quantity parameter to the buyItem() function, bypassing all payment validation. The project has since undergone significant restructuring, including the shutdown of its proprietary zkSync-based Treasure Chain in May 2025, mass layoffs, and a strategic pivot toward AI agent infrastructure.
avoid.net/ondo-finance→72/100[CAUTIONARY]Ondo Finance is a real-world asset (RWA) tokenization protocol founded in 2021 by former Goldman Sachs executives Nathan Allman and Justin Schmidt. The platform offers tokenized exposure to U.S. Treasury securities (OUSG, USDY) and, since September 2025, a broader set of tokenized equities via Ondo Global Markets. The protocol held over $1.8 billion in TVL as of late 2025 and received formal notice in November 2025 that a two-year SEC investigation had been closed without charges.
avoid.net/spiko-amundi-overnight-swap-fund-eur→78/100[VERIFIED]The Spiko Amundi Overnight Swap Fund EUR (ticker: eurSAFO) is a tokenized UCITS money market fund launched in March 2026, co-developed by French fintech Spiko and Amundi, Europe's largest asset manager with approximately €2.4 trillion under management. The EUR share class is regulated by France's Autorité des Marchés Financiers (AMF) and operates as a sub-fund of SPIKO SICAV, using fully collateralized total return swaps with Tier 1 bank counterparties to deliver yields above overnight benchmarks. As of mid-2026, eurSAFO had approximately $830 million in total asset value across five blockchain networks, ranking among the largest tokenized RWA funds globally.
avoid.net/usdgo→74/100[CAUTIONARY]USDGO is a USD-pegged enterprise stablecoin launched in February 2026, issued by Anchorage Digital Bank N.A. (the first federally chartered crypto bank in the United States) and branded and distributed by Hong Kong-listed OSL Group. As of July 2026 its circulating supply surpassed $1 billion, placing it among the top six regulated stablecoins globally. No fraud allegations, regulatory actions, or enforcement proceedings have been identified against the issuer or distributor in connection with USDGO.
avoid.net/spiko-eu-t-bills-money-market-fund→78/100[VERIFIED]Spiko EU T-Bills Money Market Fund (ticker: EUTBL) is a tokenized money market fund structured as a UCITS sub-fund of the Spiko SICAV, investing exclusively in short-term Eurozone sovereign Treasury Bills. It is regulated by the French Autorité des marchés financiers (AMF), managed by Twenty First Capital, and custodied by CACEIS Bank (a Credit Agricole subsidiary). As of July 2026 it ranks approximately #64 by market capitalization on CoinGecko with over $1 billion in assets under management, making it one of the largest tokenized real-world asset (RWA) products in Europe. No fraud, hack, or regulatory enforcement actions have been identified against Spiko or the fund.
avoid.net/adi→52/100[CAUTIONARY]ADI is the native utility token of ADI Chain, an Ethereum-compatible Layer 2 blockchain developed by Abu Dhabi-based ADI Foundation, a unit of Sirius International Holding — the digital arm of International Holding Company (IHC), a $240 billion UAE conglomerate chaired by Sheikh Tahnoon bin Zayed Al Nahyan, brother of the UAE president. Mainnet launched December 9, 2025, with the token listing simultaneously on Kraken, KuCoin, and Crypto.com; as of July 2026 it ranked approximately #69–#74 by market cap with a valuation near $840 million. The project carries meaningful institutional backing and regulatory legitimacy through a UAE Central Bank-approved dirham stablecoin and MoUs with BlackRock, Mastercard, and Franklin Templeton, but is offset by governance opacity in its parent conglomerate, an associated prediction-market subsidiary whose CEO has documented ties to the Qatargate corruption scandal, a principal executive who settled insider-trading charges with India's SEBI in 2025, and undisclosed investors in a July 2026 $50 million fundraise.
avoid.net/lighter→62/100[CAUTIONARY]Lighter is a venture-backed, zero-fee perpetual futures decentralized exchange built as a custom zero-knowledge rollup on Ethereum, founded by former Citadel engineer Vladimir Novakovski. It has raised roughly $89 million from high-profile investors including Founders Fund, Ribbit Capital, Haun Ventures, Craft Ventures, Dragonfly and Robinhood Markets, reaching a $1.5 billion valuation, and briefly ranked among the top perpetuals DEXs by volume. The platform has drawn scrutiny over post-token-launch withdrawal delays, a front-end chart-manipulation controversy following a bot-driven price spike, heavy team/investor token allocation, and a sharp decline in trading volume and user activity after its December 2025 airdrop.
avoid.net/usd1→38/100[WARNING]USD1 is a U.S. dollar-pegged stablecoin launched in March 2025 by World Liberty Financial (WLFI), a DeFi project with direct financial ties to the Trump family. Reserves are custodied by BitGo Trust Company and attested to monthly by Crowe LLP, but the coin has drawn scrutiny for delayed attestation reports, heavy offshore concentration, an unresolved conflict-of-interest controversy tied to a $2 billion MGX-Binance transaction, a June 2026 exchange delisting following an address freeze, and open questions about whether its issuance structure complies with the GENIUS Act. As of July 2026 it ranks among the largest stablecoins by market capitalization, though its governance is entangled with the political and business interests of a sitting U.S. president's family.
avoid.net/zilliqa→61/100[CAUTIONARY]Zilliqa is a Singapore-founded, sharded layer-1 blockchain launched in 2017 out of National University of Singapore research, with a track record of independent smart-contract audits and no history of SEC or DOJ enforcement action against the project itself. Its trust profile is weighed down by two distinct security incidents: a February 2025 exploit of Zilliqa's own X-Bridge token-manager contracts (protocol-level fault, roughly $42,000 realized loss) and a July 2026 theft of ZIL tokens from an exchange partner's cold wallet, which Zilliqa's own preliminary findings attribute to a technical flaw in legacy ZIL1 wallet transaction-signing rather than to the exchange's custody practices — a claim that as of this writing is corroborated by only one secondary source and remains unconfirmed by Zilliqa's promised full post-mortem.
avoid.net/nanobit-fake-crypto-platform-sec-pig-butchering-judgment→0/100[CRITICAL]NanoBit Limited was a fraudulent cryptocurrency trading platform operated from approximately September 2023 to June 2024 that defrauded at least 18 investors of nearly $1 million via a 'pig butchering' scheme conducted through WhatsApp groups. The U.S. Securities and Exchange Commission filed charges in September 2024 against four corporate entities and three individuals, and on June 16, 2026, the U.S. District Court for the Eastern District of New York entered a $5,518,902 default judgment — one of the SEC's first securities-fraud judgments against a fake-platform pig butchering operation — though recovery is considered essentially impossible as more than $2 million was wired to bank accounts in Hong Kong.
avoid.net/clawd-token-fake-clawdbot-ai-scam→2/100[CRITICAL]The $CLAWD token is a fraudulent Solana memecoin launched in January 2026 by unidentified actors who exploited a roughly 10-second window during the ClawdBot-to-Moltbot brand rename to seize the project's X handle and GitHub organization. Presenting the token as an official launch by the viral open-source AI project, the scammers drove the market cap to approximately $16 million before founder Peter Steinberger publicly denied any involvement and the token collapsed by roughly 90%. No attacker has been publicly identified and investor losses are considered unrecoverable.
avoid.net/courier-based-pig-butchering-scam-network-fbi-warning-june-2026→0/100[CRITICAL]In June 2026, the FBI's Internet Crime Complaint Center issued a formal public service announcement warning that cryptocurrency investment fraud operators — commonly operating 'pig butchering' schemes from forced-labor compounds in Southeast Asia — have adopted a physical courier variant to collect cash directly from victims when banks block electronic transfers. This hybrid approach uses in-person couriers authenticated via dollar bill serial numbers or pre-arranged passwords to collect cash from victims at their homes or public locations. Pig butchering scams caused Americans $11.37 billion in losses in 2025 alone, with the courier variant representing an escalation designed to circumvent traditional financial institution fraud controls.
avoid.net/isis-nigeria-turkey-crypto-financing-entities-nine-to-nine-manhattan-bureau-generation-currency-spider-alkaram→0/100[CRITICAL]On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated five entities as nodes in an ISIS cryptocurrency financing network: three Nigerian bureaux de change (Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited), each owned and controlled by Mukhtar Adamu Muhammad, an alleged ISIS-West Africa financial facilitator based in Lagos; and two Turkey-based money service businesses (Spider Gayrimenkul Ve Genel Ticaret Limited Sirketi and Alkaram Danismanlik Gayrimenkul Ic Ve Dis Genel Ticaret Limited Sirketi), both owned and controlled by Mohamad Alhmidan, who was previously designated by OFAC in March 2016. These entities allegedly served as the cash-conversion and hawala infrastructure through which ISIS supporters across Europe, the Middle East, and Africa routed cryptocurrency to the Islamic State.
avoid.net/mukhtar-adamu-muhammad-isis-wa-nigeria-crypto-facilitator→0/100[CRITICAL]Mukhtar Adamu Muhammad, a 35-year-old Lagos-based bureau de change operator born August 2, 1990, was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, under Executive Order 13224 for allegedly facilitating financial transfers on behalf of ISIS in West Africa (ISIS-WA/ISWAP). He is alleged to have channeled ISIS funds through three Nigerian money service businesses he owns — Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited — operating across Lagos and Kano states. The designation is reported to be the first OFAC action specifically targeting ISIS crypto financing infrastructure in West Africa.
avoid.net/miloud-abderrahmane-isis-tron-facilitator-france→0/100[CRITICAL]Miloud Abderrahmane is a French national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026 under Executive Order 13224 for providing material support to ISIS, including routing TRON cryptocurrency to ISIS-affiliated individuals in Syria and elsewhere, and for allegedly providing explosive device manufacturing instructions to ISIS supporters. OFAC published two TRON wallet addresses directly tied to him on the Specially Designated Nationals (SDN) list, making this one of very few OFAC counterterrorism designations to include specific individual on-chain wallet identifiers rather than targeting an exchange or custodian.
avoid.net/bitget-exchange-shawn-liu→42/100[WARNING]Bitget is a Seychelles-headquartered centralized cryptocurrency exchange founded in 2018, ranking among the top 10 global exchanges by trading volume as of 2025. The platform is known for its copy trading product and native token BGB, but has drawn regulatory warnings from multiple jurisdictions including Australia (ASIC), Canada, Germany, France, Spain, and Austria for operating unlicensed derivatives products. In May 2026, on-chain investigator ZachXBT published allegations identifying founder Shawn Liu as the alleged behind-the-scenes operator and accusing Bitget of enabling token supply manipulation schemes involving at least four listed assets.
avoid.net/abdelhakim-boukich→0/100[CRITICAL]Abdelhakim Boukich is a former Dutch national operating from Syria who was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, for materially supporting ISIS through cryptocurrency financing. Boukich established and controls Bitcoin Xchange, a Syria-based money service business that served as a core off-ramp for ISIS-linked fundraising campaigns, processing approximately $10 million in transaction volume across hundreds of transactions with ISIS-affiliated networks. He is listed on OFAC's Specially Designated Nationals (SDN) list under the SDGT tag and is known by the aliases Abu Sulayman Alholandi and Muhammad Babili.
avoid.net/bitcoin-xchange-syria-based-isis-linked→0/100[CRITICAL]Bitcoin Xchange is a Syria-based money services business established in late 2020 and controlled by Abdelhakim Boukich, a former Dutch national operating from Syria. On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) formally designated the entity under Executive Order 13224 for materially supporting ISIS by facilitating cryptocurrency-to-cash conversions on behalf of ISIS associates across multiple countries. On-chain analysis by TRM Labs attributed approximately USD 10 million in total transaction volume to addresses linked to Bitcoin Xchange, with hundreds of transactions connected to ISIS-linked fundraising campaigns.
avoid.net/fluid-instadapp→52/100[CAUTIONARY]Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.
avoid.net/probit-global→23/100[CRITICAL]ProBit Global was a South Korea-founded centralized cryptocurrency exchange that operated from 2018 until it permanently terminated all services by April 1, 2026. The shutdown followed an inability or unwillingness to obtain MiCA licensing for EU/EEA users and a stated broader regulatory and restructuring rationale for global operations. The wind-down included a controversial abandoned-funds clause under which assets not withdrawn by April 1, 2026 were deemed permanently lost, as well as a monthly administrative fee of up to 10% of balances during the grace period, raising significant consumer-protection concerns.
avoid.net/inertia-protocol→42/100[WARNING]Inertia Protocol (INRT) is a modular liquid restaking token (LRT) and lending protocol built on the Initia blockchain, launched to mainnet in April 2025. The protocol suffered a confirmed exploit in May 2025 in which approximately $152,000 was drained from five lending markets via a known ERC4626 share-price inflation attack; the protocol states its Insurance Fund restored affected user balances. Team composition, smart contract audit history, and investor backing are not publicly disclosed.
avoid.net/uniblock→64/100[CAUTIONARY]Uniblock is a Canadian Web3 infrastructure company founded in 2022 that provides a unified, multi-chain API aggregation platform for blockchain developers, connecting over 300 blockchains and 55 data providers through a single interface with patented auto-routing technology. The company is venture-backed with C$7.5 million in total funding from institutional investors including SBI Ven Capital, AllianceDAO, NGC Ventures, Alchemy, and MoonPay. No regulatory actions, fraud allegations, or significant security incidents have been identified; risk factors are principally commercial and operational rather than conduct-related.
avoid.net/superfortune-ai-gua→28/100[WARNING]Superfortune AI is an AI-powered InfoFi platform on BNB Chain, incubated by Manta Labs, that combines Chinese metaphysical traditions with crypto market analytics. Its native token GUA launched on November 27, 2025. On May 27, 2026, approximately 14.98 million GUA tokens intended for an airdrop distribution were redirected to a lookalike attacker-controlled address, resulting in losses of approximately $15.18 million and a roughly 76% token price crash within 24 hours. The root cause remains disputed: the team attributed the incident to a compromised signer private key, while the absence of prior on-chain interaction between the attacker and project wallets has raised unresolved questions about the multisig workflow.
avoid.net/dxsale→4/100[CRITICAL]DxSale is a decentralized token launchpad and liquidity-locking platform launched in August 2020, originally on Ethereum and later expanded to BNB Chain and other EVM networks. On May 28, 2026, a hidden backdoor in legacy BNB Chain liquidity locker contracts was exploited to drain approximately $7.3 million from more than 1,400 LP positions locked as far back as 2021. On-chain analysis identified a 269-day pre-exploit ownership transfer chain passing through approximately 80 wallets, with indicators strongly suggesting insider involvement by a current or former team member.
avoid.net/geoffrey-woo→32/100[WARNING]Geoffrey Woo is an American entrepreneur and venture capitalist who co-founded Anti Fund with Jake Paul in 2021 and serves as chairman of Ketone-IQ. In February 2026, Woo launched an AI-themed memecoin called AntiHunter (ANTIHUNTER) on the Base blockchain and publicly claimed it carried '0% rug pull risk' because he was already wealthy. On-chain investigator ZachXBT challenged the claim, citing the Paul brothers' documented history of five failed crypto projects — all down 99%+ from peak — and identifying three alleged token sales by Woo's wallet that appeared to contradict his stated promise to pre-announce any insider transactions. As of June 2026, ANTIHUNTER trades approximately 99%+ below its February 2026 all-time high, consistent with ZachXBT's expectations.
avoid.net/beaverd-beaverd→4/100[CRITICAL]@beaverd is an anonymous X (Twitter) account that won X's $1 million Creators Prize in February 2026 for an investigative article on Deloitte. Days after the prize announcement, on-chain analytics firm Bubblemaps published a detailed investigation alleging that wallet clusters linked to @beaverd had engaged in serial pump-and-dump activity across dozens of Solana memecoins launched via Pump.fun, extracting an estimated $600,000 in profits. @beaverd did not dispute the wallet links, responding publicly with 'cry me a river, also these aren't even the top 5 greatest hits,' a statement widely interpreted as an implicit admission of the activity.
avoid.net/deepsnitch-ai→12/100[CRITICAL]DeepSnitch AI is an Ethereum-based utility token project marketed as an AI-powered crypto scam-detection platform, operated by SignalPlex Lab Ltd., a company incorporated in the British Virgin Islands with no publicly disclosed team members. The project raised an alleged $2.87M in a multi-stage presale (figures across sources range from $2.2M to $2.87M and cannot be independently verified from a primary financial source) before listing on Uniswap on March 31, 2026, after which the token price collapsed approximately 99% within days, accompanied by widespread reports of presale buyers unable to claim tokens, a honeypot flag from security scanner Blockaid, and extended team silence. The team subsequently attributed the Blockaid flag to contract anti-dump mechanics misread as a honeypot, launched a V1 platform on April 10, 2026, and the contract flag was reportedly cleared; however, trading volume subsequently went dormant and no Tier 1 or Tier 2 source has independently verified any key claim.
avoid.net/ravedao→2/100[CRITICAL]RaveDAO is a Web3 entertainment protocol that markets itself as a community bridging electronic dance music culture with blockchain-based ticketing, governance, and event access. Its native token, RAVE, launched on Binance Alpha in December 2025 and experienced a ~10,800% price surge in April 2026 before collapsing approximately 95% within 48 hours amid substantial on-chain evidence of insider supply control and an alleged coordinated 'bait and liquidate' short-squeeze scheme. Binance, Bitget, and Gate.io opened formal investigations; on-chain investigator ZachXBT publicly accused the project's affiliated insiders of engineering the rally and named RAVE as part of a broader pattern of Bitget-enabled market-maker fraud.
avoid.net/zoth-protocol→8/100[CRITICAL]Zoth Protocol is an Ethereum-based real-world asset (RWA) re-staking and tokenization platform founded in 2023 by Pritam Dutta and Koushik Bhargav. In March 2025 the protocol suffered two separate security incidents within three weeks: an initial $285,000 logic-flaw exploit on March 1 and a far more damaging $8.4 million deployer-key compromise on March 21 that enabled a malicious proxy contract upgrade. The protocol has since launched a user compensation program, engaged Crystal Blockchain BV for fund recovery, and announced a security overhaul backed by a $15 million strategic token commitment from Bolts Capital.
avoid.net/celsius-network→0/100[CRITICAL]Celsius Network was a centralized crypto lending platform founded in 2017 that attracted over 1.7 million users and $20 billion in assets under management by offering yields of up to 18% on deposited cryptocurrency. In June 2022 the platform froze all withdrawals, subsequently filed for Chapter 11 bankruptcy in July 2022, and exposed a $1.2 billion balance sheet deficit. Founder and CEO Alex Mashinsky was arrested in July 2023, pleaded guilty to commodities fraud and securities fraud in December 2024, and was sentenced to 12 years in federal prison in May 2025.
avoid.net/normie-memecoin→8/100[CRITICAL]Normie (NORMIE) was a memecoin launched in March 2024 on Coinbase's Base layer-2 blockchain that reached a peak market cap of approximately $130 million on April 2, 2024. On May 26, 2024, an attacker exploited a premarket-user recognition flaw in the token's smart contract via a flash loan attack, minting billions of tokens beyond the 1 billion supply cap and draining liquidity pools, causing a 99% price collapse and approximately $41 million in market cap destruction. A blockchain scam-detection tool reported the vulnerability had been detected in March 2024 but was never patched by the development team.
avoid.net/taptools→38/100[WARNING]TapTools was Cardano's largest on-chain analytics platform, serving over one million users with token price tracking, DeFi monitoring, portfolio tools, and a data API used by hundreds of third-party Cardano projects since its 2022 launch. In June 2026, the platform announced it would wind down operations within two weeks after losing five senior executives — including both co-founders, its COO, its CTO, and a backend developer elevated to act as CTO — in the span of roughly one year. The shutdown, occurring alongside the closure of JPG Store (Cardano's largest NFT marketplace) and the cancellation of Cardano Summit 2026, contributed to a 10–30% ADA price decline and prompted Cardano founder Charles Hoskinson to warn of a broader 'wave of failures' across the ecosystem.
avoid.net/stream-finance→4/100[CRITICAL]Stream Finance was an Ethereum-based DeFi yield aggregator founded in February 2024 by Diogenes Casares and Solal Afota that collapsed in November 2025 after disclosing a $93 million loss attributed to an off-chain trader who allegedly misappropriated protocol assets to cover personal margin-call losses. The collapse caused its xUSD synthetic stablecoin to depeg from $1.00 to approximately $0.26 within 24 hours, triggering an estimated $285 million in cascading exposure across multiple interconnected DeFi protocols including Morpho, Euler, Elixir, Silo, and Gearbox. A federal civil lawsuit (Case No. 3:2025cv10524, N.D. Cal.) was filed on December 8, 2025, accusing operator Caleb McMeans and trader Ryan DeMattia of misappropriation; as of mid-2026 the protocol entered a formal wind-down under a newly incorporated holding company with no confirmed creditor recovery timeline.
avoid.net/dutch-crypto-investment-fraud-ring-2026→0/100[CRITICAL]A large-scale international investment fraud network, dismantled by Dutch and Belgian police in July 2026, operated approximately 20 call centers staffed by over 700 people who posed as financial advisers and used fake cryptocurrency trading platforms to steal an estimated €100 million per month from victims worldwide. The alleged mastermind — Ehud Tenenbaum, a 46-year-old dual Israeli-Polish national known in cybercrime circles as 'The Analyzer' for his late-1990s hacking of U.S. government systems — was arrested in Poland in May 2026 and extradited to the Netherlands. Tens of thousands of victims across multiple countries are estimated, with Dutch victims alone reporting nearly €25 million in losses.
avoid.net/doj-pig-butchering-25m-forfeiture-2026→0/100[CRITICAL]On July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints seeking more than $25 million in cryptocurrency linked to pig butchering, romance, and asset-recovery fraud schemes. The action, executed through the Scam Center Strike Force, represents the largest forfeiture action ever sought by the DOJ specifically targeting crypto confidence scams, and documents a major active threat surface involving Chinese transnational crime syndicates, fake investment platforms, and Tether-denominated laundering chains affecting thousands of victims across the United States and Canada.
avoid.net/lien-finance→22/100[CRITICAL]Lien Finance is a governance-free Ethereum DeFi protocol launched in August 2020 that enables users to create options and stablecoins by tranching ETH deposits into two derivative bond tokens (SBT and LBT). On July 24, 2026, the protocol was exploited for approximately 542,144 USDC through manipulation of its permissionless bond registration system and a flawed OTC pricing function. This is the protocol's second significant security incident, following a September 2020 near-miss in which a whitehat coalition rescued approximately $10 million from a related BondMaker contract vulnerability.
avoid.net/afx-trade→18/100[CRITICAL]AFX Trade is a decentralized perpetual futures exchange (perp DEX) built on Arbitrum that uses a fully on-chain central limit order book (CLOB) and settles in USDC. On July 22–23, 2026, the protocol suffered a $24.15 million loss after attackers compromised the private validator signing keys controlling its third-party USDC custody bridge, fraudulently meeting the multi-signature threshold required to authorize a withdrawal. The incident represents one of three clustered bridge exploits on the same day, which collectively drained $35.55 million across the DeFi ecosystem.
avoid.net/bfusd→52/100[CAUTIONARY]BFUSD is a reward-bearing margin asset launched by Binance Futures in November 2024, designed exclusively for use as collateral in USDT-M Futures trading. It is not a blockchain token, cannot be withdrawn from Binance, and generates yield through delta-neutral funding-fee strategies and ETH staking. While Binance maintains a reserve fund and transparency dashboard, the product carries significant concentrated counterparty risk tied to Binance's centralized custody model and its operator's prior criminal guilty plea on AML charges in 2023.
avoid.net/blackrock-usd-institutional-digital-liquidity-fund→82/100[VERIFIED]BUIDL is a tokenized U.S. dollar money market fund managed by BlackRock and issued on public blockchains through tokenization platform and transfer agent Securitize. Launched on Ethereum in March 2024, it holds cash, U.S. Treasury bills, and repurchase agreements, is custodied by Bank of New York Mellon, and is offered as a private placement restricted to accredited/qualified institutional investors rather than as a retail SEC-registered security. It has grown into the largest tokenized U.S. Treasury fund by assets under management, but access, redemption, and transfer are gated by centralized whitelisting and freeze controls typical of permissioned real-world-asset (RWA) tokens.
avoid.net/global-dollar→68/100[CAUTIONARY]Global Dollar (USDG) is a fiat-backed stablecoin issued by Paxos Digital Singapore Pte. Ltd. and regulated by the Monetary Authority of Singapore, launched in November 2024 to anchor the Global Dollar Network (GDN), a consortium of exchanges and fintechs including Robinhood, Kraken, Galaxy Digital, Anchorage Digital, Bullish, Nuvei, and Visa. USDG differentiates itself from USDT and USDC by sharing reserve yield with network partners rather than retaining it at the issuer, and publishes monthly third-party reserve attestations. The stablecoin itself has no confirmed depeg incidents or direct regulatory enforcement action to date, but its issuer, Paxos, has a documented history of AML/KYC compliance failures tied to the BUSD stablecoin, and USDG's yield-distribution model sits in a regulatory gray area under the GENIUS Act's interest-payment prohibitions that lawmakers and banking groups are actively seeking to close.
avoid.net/teleswap→32/100[WARNING]TeleSwap (formerly TeleportDAO) is a cross-chain bridge protocol that lets users move Bitcoin and Runes to EVM chains, TON, and Solana using light-client and "Locker"/"Teleporter" custodian architecture, funded by a $2.5M 2023 seed round and a 2024 public token sale. On July 15, 2026, on-chain investigator ZachXBT and the SlowMist Hacked incident database reported suspicious outflows of roughly $735,000 from TeleSwap's Bitcoin hot wallet followed by laundering through Tornado Cash; as of this writing TeleSwap has not issued a public confirmation, technical postmortem, or the underlying transaction details, which is itself a notable transparency concern. Overall reporting quality on the incident is thin — it traces back mainly to one investigator's claim and aggregator write-ups rather than a project statement, a named security-firm root-cause report, or Tier-1 news coverage, so key facts (attack vector, exact amount, affected users) remain unverified.
avoid.net/barnbridge→12/100[CRITICAL]BarnBridge was an Ethereum-based DeFi protocol, structured as a DAO, best known for its SMART Yield product, which tranched variable-rate yield from lending markets like Compound and Aave into fixed and variable risk classes. The protocol halted operations in mid-2023 after founders disclosed an SEC investigation, and BarnBridge DAO and its two founders settled with the SEC in December 2023 for $1.7 million over unregistered offer and sale of crypto asset securities and unregistered investment company violations. On July 15, 2026, despite being effectively defunct, BarnBridge's SMART Yield governance and legacy token approvals were exploited in a governance-takeover attack that drained approximately $776,000 in USDC from roughly 50 wallets; the attacker reportedly spent only about $600 to acquire enough BOND voting power to pass a malicious upgrade proposal through an inactive DAO. The scout flag characterizing this as a governance-attack incident is substantiated: the event is corroborated across multiple independent crypto-news outlets and an on-chain security firm, though as of this writing it lacks coverage from top-tier wire/legal press specific to the 2026 incident itself (the 2023 SEC action is Tier 1 sourced).
avoid.net/summer-fi-lazy-summer-protocol→22/100[CRITICAL]Summer.fi, a DeFi yield-optimization platform formerly known as Oasis.app that spun out of the Maker Foundation in 2021, operated the DAO-governed Lazy Summer Protocol until a July 6, 2026 exploit drained roughly $6.04 million from two of its USDC vaults via a flash-loan-funded share-price manipulation of the Fleet Commander accounting contract. Summer.fi's own post-mortem attributes the loss to an operational oversight — an old, capped strategy that was never fully removed from vault net-asset-value calculations — rather than a smart-contract bug or compromised keys. The Summer.fi Labs company announced on July 15, 2026 that it would wind down and shut off its app by August 31, 2026, leaving user compensation and the fate of roughly $4 million in illiquid affected-vault holdings to a future Lazy Summer DAO governance vote.
avoid.net/trump-memecoin-presidential-conflict-of-interest-and-retail-losses→8/100[CRITICAL]The $TRUMP token is a Solana-based memecoin launched on January 17, 2025 — three days before President Donald Trump's inauguration — by two Trump-affiliated entities, CIC Digital LLC and Fight Fight Fight LLC, which collectively retained 80% of the 1-billion-token supply under a multi-year vesting schedule. Trump's June 2026 Office of Government Ethics financial disclosure reported $635 million in royalties from the token, funneled through a licensing agreement with an entity called 'Celebration Coins' for which no public digital footprint could be found. As the token collapsed more than 97% from its January 2025 peak of approximately $74, on-chain analysis by Chainalysis attributed losses of over $700 million to retail buyers across more than 764,000 wallets, while legal experts, Senate investigators, and ethics watchdogs raised alarms that the token's anonymous purchase mechanism created an untraceable channel for gifts and influence payments to a sitting president.
avoid.net/mica-eu-mass-non-compliance-83-unlicensed-platform-risk→18/100[CRITICAL]The European Union's Markets in Crypto-Assets Regulation (MiCA) transitional grace period expired on July 1, 2026. Of approximately 1,200+ crypto firms that previously operated under national VASP registrations, only roughly 210–244 obtained full Crypto Asset Service Provider (CASP) authorization — a conversion rate of approximately 17–20%, leaving an estimated 83% operating in breach of EU law. ESMA confirmed on April 17, 2026 that no extensions would be granted and that unlicensed firms must cease EU services immediately; affected major exchanges include Binance (withdrew Greek application June 24, 2026), MEXC, Bitget, CoinEx, and others serving millions of European users.
avoid.net/edel-finance→28/100[WARNING]Edel Finance is a decentralized lending protocol for tokenized equities, built as an Aave v3 fork on the Base/EVM network with an institutional Canton Network component, that launched mainnet on March 25, 2026. On July 1, 2026, the protocol suffered a flash-loan oracle manipulation exploit that drained approximately $403,000 from its xStock lending reserves, with stolen funds routed immediately to Tornado Cash. The protocol had also faced prior controversy in November 2025 over alleged insider acquisition of more than 30% of the EDEL token supply, contradicting stated tokenomics.
avoid.net/stakedao→38/100[WARNING]StakeDAO is a DeFi protocol launched in January 2021 that provides liquid locking, yield strategies, and governance aggregation built primarily around Curve Finance's ecosystem on Ethereum and Arbitrum. On May 27, 2026, the protocol suffered a significant exploit when an attacker compromised its deployer private key and used it to reconfigure a LayerZero v2 OFT bridge peer, enabling the minting of approximately 5.44 trillion vsdCRV tokens on Arbitrum and the extraction of roughly $91,000 in ETH. The incident did not involve a smart contract vulnerability but exposed a critical operational security failure: the deployer key was a single point of failure with no multisig protection, no timelock, and was allegedly operated as a hot key inside automated infrastructure.
avoid.net/secret-network-axelar-bridge-exploit-june-2026→8/100[CRITICAL]On June 10, 2026, an attacker exploited a missing channel-origin validation in a customized CW20-ICS20 smart contract on Secret Network to mint approximately $4.67 million in unbacked Axelar-wrapped tokens (saTokens) and redeem them for real escrowed assets. The exploit went undetected for seven days due in part to Secret Network's privacy-by-default architecture, which encrypts account balances and masked the missing collateral until a failed cross-chain transfer on June 17 exposed the shortfall. Blockchain security firm Common Prefix traced the vulnerability to the contract's initial deployment in early 2023; a March 5, 2026 contract migration added new functionality but carried the unpatched validation flaw forward without a new security audit.
avoid.net/thorchain-gg20-mpc-vault-exploit-may-2026→38/100[WARNING]On May 15, 2026, THORChain suffered a targeted cryptographic exploit in which a malicious node operator reconstructed a full private key from a single Asgard vault by exploiting incremental key material leakage in the GG20 Threshold Signature Scheme, draining approximately $10.7 to $11 million across nine blockchain networks. The protocol executed an automated and community-coordinated emergency halt, published a formal exploit report on May 21, 2026, and resumed trading on June 23, 2026, after a 39-day shutdown and an 11-stage security overhaul. The incident is the third major security breach in THORChain's history and exposed systemic risks in GG20-based MPC implementations.
avoid.net/q2-2026-record-crypto-hack-wave→0/100[CRITICAL]The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.
avoid.net/syscoin→28/100[WARNING]Syscoin (SYS) is a dual-chain blockchain protocol originally launched in 2014 that combines a Bitcoin-derived UTXO chain with an Ethereum-compatible smart contract layer called NEVM. In June 2026, a critical proof-parsing flaw in its cross-chain bridge allowed an attacker to mint approximately 5 billion unauthorized SYS tokens — more than five times the circulating supply — valued at roughly $8.5–10 million; all funds were ultimately recovered and burned. The project has accumulated a pattern of serious concerns spanning its history: a 2014 ICO fund theft, a 2018 GitHub supply-chain compromise, and extensive 2024 governance allegations including a Dutch criminal investigation into alleged fraud, embezzlement, and unauthorized token issuance by its own foundation directors.
avoid.net/dark2web→0/100[CRITICAL]Dark2Web was a darknet and clear-web cybercrime forum operated by the same individuals who ran the AudiA6 cryptocurrency laundering service. It served as the primary advertising hub and networking venue for ransomware affiliates, hackers, and other cybercriminals who used AudiA6 to launder proceeds. Both platforms were seized by an international law enforcement coalition on June 10-11, 2026, and their two alleged administrators were arrested in Georgia and face extradition to the United States.
avoid.net/ravedao-rave-token→4/100[CRITICAL]RaveDAO is a Web3 project that organized electronic music events and launched the RAVE token on Binance Alpha in December 2025. In April 2026, RAVE surged approximately 10,800% in nine days to a peak market cap near $6.6 billion before collapsing 95% within 48 hours, erasing roughly $5.7 billion in value. On-chain investigator ZachXBT alleged coordinated insider manipulation based on extreme supply concentration and suspicious pre-surge token transfers, prompting formal investigations by Binance and Bitget; RaveDAO denied any involvement.
avoid.net/eleven-drainer→0/100[CRITICAL]Eleven Drainer is a Drainer-as-a-Service (DaaS) toolkit and phishing syndicate that emerged around August 2025, offering rented wallet-draining infrastructure to criminal operators who deploy it through phishing sites, DNS hijacks, and compromised front-ends. The kit is associated with confirmed theft of at least $4.2 million across a three-week window in November 2025, including a $700,000 loss from a DNS hijack of decentralized exchanges Aerodrome and Velodrome. As of June 2026, the kit remains active and was detected embedded in a compromised Gitcoin subdomain.
avoid.net/memecore-m-token→9/100[CRITICAL]MemeCore is a Layer 1 blockchain project whose native M token collapsed 74-80% on June 25, 2026, erasing approximately $3 billion in market value with no confirmed exploit, hack, or public announcement. On-chain investigator ZachXBT and associated analysts had previously flagged alleged insider control exceeding 90% of the token supply, $7.9 million in suspicious Kraken withdrawals to 18 newly created wallets, and near-zero decentralized exchange liquidity, raising serious questions about the token's valuation legitimacy and the due diligence performed by listing exchanges including Binance, Bybit, Kraken, and Bitget.
avoid.net/saga-evm-blockchain→32/100[WARNING]Saga is a Layer-1 blockchain protocol designed to support application-specific chains (chainlets), with a focus on gaming and DeFi use cases. In January 2026, its SagaEVM chainlet suffered a critical exploit in which an inherited vulnerability in the Ethermint EVM codebase allowed an attacker to mint approximately $7 million in unbacked stablecoins, which were subsequently bridged to Ethereum and largely laundered through Tornado Cash. The broader Saga SSC mainnet, consensus layer, and validator set were not compromised, but the incident exposed material risks from deploying EVM compatibility layers built on unaudited inherited codebases.
avoid.net/kelpdao-bridge-exploit-april-2026→2/100[CRITICAL]On April 18, 2026, attackers drained 116,500 rsETH (approximately $292–294 million) from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest DeFi exploit of 2026. The attack exploited a single-DVN (Decentralized Verifier Network) configuration by compromising RPC nodes and using a DDoS to force failover to poisoned infrastructure, tricking the bridge verifier into approving a phantom token release. The operation has been attributed with preliminary confidence to North Korea's Lazarus Group, specifically the TraderTraitor subunit, and triggered systemic contagion across at least 9 DeFi protocols and 20+ chains, including a major liquidity crisis on Aave.
avoid.net/namada-protocol-masp-ibc-transfer-logic-exploit-june-19-2026→22/100[CRITICAL]On June 19, 2026, Namada Protocol's Multi-Asset Shielded Pool (MASP) was drained of approximately $600,000 in IBC-bridged assets including ATOM, USDC, OSMO, TIA, and NYM via an IBC Transfer Logic Exploit. The attack went undetected for a material period because a stale chain indexer continued displaying the drained balances as available, while live RPC queries showed zero; the discrepancy was first identified by independent security researchers at F12. Namada confirmed the exploit and issued an appeal to the responsible party to contact them, but as of the investigation date had not disclosed the specific vulnerability, recovery status, or a comprehensive postmortem.
avoid.net/secret-network-axelar-ibc-bridge-exploit-june-2026→8/100[CRITICAL]On approximately June 10, 2026, an attacker exploited a missing channel-verification check in a Secret Network-side ICS-20 smart contract governing the Cosmos IBC connection between Secret Network and Axelar, minting unbacked wrapped tokens that were redeemed for approximately $4.67 million in real bridged assets. The exploit went undetected for seven days due to Secret Network's privacy-by-default design, and was only discovered on June 17 when a routine cross-chain transfer failed due to depleted escrow. Axelar's emergency committee severed all Secret and Secret-SNIP IBC connections on June 17; the stolen funds were subsequently laundered through Osmosis, bridged to Ethereum, and deposited across KuCoin, ChangeNow, and HitBTC.
avoid.net/mica-transitional-period-expiry-unlicensed-eu-crypto-platforms→28/100[WARNING]The EU Markets in Crypto-Assets Regulation (MiCA) transitional grace period for crypto asset service providers expires on July 1, 2026, with no extension available. As of May–June 2026, only approximately 183–204 firms hold full CASP authorization across the EU, leaving an estimated 75–83% of formerly registered providers unlicensed. EU users on unlicensed platforms face account restrictions, potential withdrawal freezes, loss of statutory asset protections, and possible abrupt service cutoffs beginning July 1, 2026.
avoid.net/audia6-crypto-laundering-service→0/100[CRITICAL]AudiA6 was a professional cryptocurrency mixing and laundering service that allegedly processed over EUR 336 million (approximately USD 389 million) in illicit funds on behalf of ransomware gangs, darknet markets, and other cybercriminals between 2022 and 2025. An international law enforcement coalition led by Europol and the U.S. Department of Justice dismantled the service on June 10, 2026, arresting its two alleged administrators in Batumi, Georgia. The service has since been formally charged in the Eastern District of Pennsylvania.
avoid.net/evita-pay-iurii-gugnin→2/100[CRITICAL]Evita Pay (operating as Evita Investments Inc. and Evita Pay Inc.) was a New York-based cryptocurrency payment company founded by Iurii Gugnin, a Russian national. On June 9, 2025, Gugnin was arrested and charged in a 22-count federal indictment in the Eastern District of New York, alleging he used Evita to funnel approximately $530 million through U.S. banks and cryptocurrency exchanges on behalf of clients at sanctioned Russian financial institutions between June 2023 and January 2025. Gugnin was ordered detained pending trial and faces potential sentences of up to 30 years per bank fraud count.
avoid.net/meta-1-coin→0/100[CRITICAL]Meta-1 Coin was a fraudulent digital asset marketed from 2018 to 2023 by Robert Dunlap through the Meta-1 Coin Trust, with false claims that the token was backed by $44 billion in gold and $1 billion in fine art. Dunlap used automated trading bots on a sham exchange called the Meta Exchange to inflate the coin's apparent price and volume, defrauding approximately 1,000 investors of more than $20 million. In April 2026, Dunlap was sentenced to 23 years in federal prison following a November 2025 conviction on mail fraud charges in the Northern District of Illinois.
avoid.net/robert-dunlap-meta-1-coin-trust→0/100[CRITICAL]Robert Dunlap, 55, of Houston, Texas, operated Meta-1 Coin Trust from 2018 to 2023, raising more than $20 million from nearly 1,000 investors by falsely claiming a digital asset called 'Meta-1 Coin' was backed by $44 billion in gold and $1 billion in artwork. Dunlap fabricated audit documents and manipulated trading prices using automated bots. He was convicted by a federal jury in November 2025 on two counts of mail fraud and sentenced on April 17, 2026, to 23 years in federal prison by U.S. District Judge LaShonda A. Hunt in the Northern District of Illinois.
avoid.net/rhea-finance-exploit-april-2026→9/100[CRITICAL]On April 16, 2026, Rhea Finance — the leading DeFi hub on the NEAR blockchain, formed by the March 2025 merger of Ref Finance and Burrow Finance — was exploited for an estimated $18.4 million (initially reported as $7.6 million) via a two-phase attack combining fake token pool seeding with a slippage-protection bypass in its margin trading module. Approximately $9 million in assets was subsequently recovered or frozen, including $3.291 million USDT frozen by Tether, leaving an estimated $8–9 million outstanding as of late April 2026.
avoid.net/lazarus-group-graphalgo-fake-recruiter-npm-pypi-campaign→0/100[CRITICAL]The 'graphalgo' campaign is a North Korean state-sponsored software supply-chain operation attributed to the Lazarus Group, active since at least May 2025 and publicly disclosed in February 2026. Threat actors impersonate cryptocurrency-sector recruiters using fabricated companies — most notably 'Veltrix Capital' — to deliver coding-assessment repositories seeded with malicious npm and PyPI packages that install a remote-access trojan (RAT) targeting developer systems and cryptocurrency wallets. By April 2026 the campaign had respawned under new personas including 'Blockmerce' and 'Bridgers Finance', with operatives registering a real U.S. LLC to enhance credibility.
avoid.net/yelo-yelotree→0/100[CRITICAL]Yelo, known online as @yelotree, is a crypto key opinion leader (KOL) and former professional Fortnite esports player with approximately 180,000 Twitter followers who also operated a luxury car rental business in Miami. As of May 2026, Yelo faces federal criminal charges alleging he laundered funds stolen from cryptocurrency holders through that rental business, with a potential sentence of up to 30 years. Separately, Yelo participated in undisclosed paid promotion of the Sharpei memecoin on Solana in October 2024, which subsequently suffered a documented rug pull that erased 96% of its market value.
avoid.net/granary-finance-grain→42/100[WARNING]Granary Finance was a decentralized, non-custodial lending and borrowing protocol forked from Aave V2, built by Byte Masons and an anonymous developer known as Fantom Menace, launching on Fantom in March 2022 before expanding to eight chains. The protocol raised over $5 million USDC via a community liquidity generation event in March 2023 and introduced the GRAIN governance token, but its TVL collapsed from a peak of approximately $60 million to under $200,000. By early 2025, the team announced the full withdrawal and discontinuation of Granary Finance across all chains, with GRAIN and OATH token holders migrated to the successor platform Cod3x (CDX). No regulatory actions, rug-pull allegations, or direct hacks of Granary contracts were documented; key risks include near-total value decline, deeply pseudonymous founding team, and protocol end-of-life.
avoid.net/siren-token→9/100[CRITICAL]SIREN is a BNB Chain AI-themed meme token launched in early 2025 via the Four.meme fair-launch platform. Beginning in March 2026 the token underwent a series of extreme pump-and-dump cycles, crashing roughly 90% from its all-time high of approximately $3.83 within ten days. On-chain investigators ZachXBT and BubbleMaps identified a single wallet cluster holding nearly 50% of circulating supply, linked by ZachXBT to addresses associated with DWF Labs-affiliated tokens; ZachXBT later named SIREN as one of at least six tokens subject to a coordinated market-maker manipulation playbook allegedly enabled by Bitget, alongside RAVE, RIVER, LAB, MYX, and SKYAI.
avoid.net/hypurrfi-domain-hijack-april-2026→57/100[CAUTIONARY]On April 3, 2026, the frontend domain hypurr.fi of HypurrFi — a DeFi lending protocol on Hyperliquid EVM — was hijacked via a social engineering attack targeting the domain registrar Openprovider. No user funds were confirmed drained and the protocol's smart contracts remained intact throughout; the team migrated frontend operations to hypurrfi.com and subsequently recovered control of the original domain. The incident is part of a documented six-week cluster of DeFi registrar-level frontend attacks in March–April 2026 targeting Neutrl, HypurrFi, and CoW Swap.
avoid.net/brandon-michael-tardibone→4/100[CRITICAL]Brandon Michael Tardibone, 28, of Miami, Florida, was federally indicted on May 11, 2026 in the Southern District of Florida (case 1:26-cr-20181) on charges of conspiracy to commit money laundering and harboring an alien unlawfully present in the United States. Prosecutors allege he provided housing and material support to Canadian co-defendant Trenton Richard David Johnston — who allegedly orchestrated a $13 million cryptocurrency fraud scheme via social-engineering impersonation attacks — while Johnston was unlawfully overstaying his visa, and that both defendants jointly laundered more than $1 million of stolen proceeds through luxury goods and South Florida nightlife. All charges are allegations; both defendants are presumed innocent unless and until proven guilty at trial.