Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
On March 15, 2022, Agave (an Aave fork on Gnosis Chain) and Hundred Finance (a Compound fork deployed on Gnosis Chain) were simultaneously exploited via a reentrancy attack that abused post-transfer callback hooks in Gnosis Chain's non-standard ERC-677 bridged tokens, resulting in combined losses of approximately $11.7 million. Hundred Finance suffered a second major exploit in April 2023 on Optimism ($7.4 million), after which the protocol voted to shut down permanently in August 2023. Agave continued operating in diminished capacity before its DAO formally wound down in early 2024.
avoid.net/helium-mobile→58/100[CAUTIONARY]Helium Mobile is a Mobile Virtual Network Operator (MVNO) launched by Nova Labs, Inc. in 2023, marketed as the world's first crypto-powered consumer cellular service. It provides coverage primarily via T-Mobile's wholesale 5G network, supplemented by a community-built Wi-Fi hotspot layer, and issues MOBILE token rewards to subscribers and hotspot operators. Parent company Nova Labs settled a $200,000 SEC fraud charge in April 2025 over misrepresentations made to investors about enterprise partnerships, while the MOBILE token has been deprecated in favor of HNT under community governance proposal HIP 138.
avoid.net/helium→58/100[CAUTIONARY]Helium is a decentralized physical infrastructure network (DePIN) founded in 2013 by Amir Haleem, Shawn Fanning, and Sean Carey, operated by Nova Labs, Inc. The network incentivizes individuals to deploy wireless hotspots for IoT (LoRaWAN) and mobile coverage using its HNT token, which migrated to the Solana blockchain in April 2023. The project has a documented history of misrepresenting partner relationships to investors, resulting in a $200,000 SEC civil settlement in April 2025, but has demonstrated meaningful real-world usage growth through verified carrier data-offload partnerships with AT&T, T-Mobile, and Telefonica.
avoid.net/goosefx→42/100[WARNING]GooseFX was a Solana-based decentralized finance platform founded in 2021 that offered an AMM DEX (GAMMA), single-sided liquidity pools, perpetual futures trading, and an NFT aggregator under the GOFX utility token. The project raised $4.5 million in seed funding from reputable investors including Animoca Brands and CoinShares, received at least one published security audit from Halborn, and accumulated over $700 million in cumulative trading volume during 2024 before announcing a voluntary wind-down in August 2025. No regulatory actions, theft-related exploits, or rug-pull signals have been identified; the protocol sunsetting appears to reflect commercial failure rather than fraud.
avoid.net/firedancer→63/100[CAUTIONARY]Firedancer is an independent, high-performance Solana validator client developed by Jump Crypto (Jump Trading Group), written from scratch in C primarily by a team led by Chief Science Officer Dr. Kevin Bowers and founding engineer Ritchie Patel. Released under the Apache 2.0 open-source license, it aims to increase Solana's throughput toward one million transactions per second while improving network resilience through client diversity. As of May 2026, the client is live on Solana mainnet with roughly 20% of validators running it, though full rollout remains cautious pending completion of comprehensive third-party security audits. The project carries a notable backer-risk signal: Jump Crypto's parent subsidiary Tai Mo Shan settled SEC charges for $123 million in December 2024 over TerraUSD manipulation, and a separate CFTC investigation was reported in 2024 with no publicly disclosed outcome as of this writing.
avoid.net/dual-finance→62/100[CAUTIONARY]Dual Finance is a Solana-based structured-products protocol offering Dual Investment Pools (DIPs) and Staking Options, products designed to provide yield to token holders and sustainable liquidity incentives to DAOs. Founded in 2022 by named individuals with verifiable TradFi and FAANG backgrounds, the protocol reached a peak TVL of approximately $35 million in 2023 but has since contracted sharply to under $500K as of mid-2025. No exploits, regulatory actions, or fraud allegations have been identified in public records; the primary concerns are low current TVL, limited publicly-verifiable audit documentation, and significant DUAL token price depreciation since its 2023 ATH.
avoid.net/decaf→52/100[CAUTIONARY]Decaf (decaf.so) is a non-custodial stablecoin wallet and payments platform built on Solana and Stellar, founded in 2022 and headquartered in Miami, FL, targeting emerging-market users who need low-cost cross-border payments and fiat cash-out. The company has raised a seed round from recognizable crypto-native and fintech investors including Visa, and has established formal partnerships with Circle, MoneyGram, and the Stellar Development Foundation. No regulatory actions, hacks, or fraud allegations have been identified as of the investigation date.
avoid.net/aurory→26/100[WARNING]Aurory is a Solana-based free-to-play, play-to-earn role-playing game featuring NFT creatures called Nefties, launched in 2021 by a team with backgrounds at major game studios. The project suffered a significant December 2023 exploit of its SyncSpace marketplace bridge, resulting in approximately $830,000 in stolen AURY tokens. As of mid-2026, the AURY token trades near all-time lows, down over 99% from its 2021 peak, reflecting sustained tokenomics pressure, limited adoption, and investor uncertainty following the security incident.
avoid.net/anza→69/100[CAUTIONARY]Anza (Anza Technology, Inc.) is a Delaware-incorporated software development firm founded in January 2024 by approximately 45 former Solana Labs engineers and executives, including Solana co-founder Stephen Akridge. The company serves as the primary maintainer of the Agave validator client — a fork of the original Solana Labs codebase and the majority client on the Solana network — and has proposed Alpenglow, a wholesale redesign of Solana's consensus mechanism approved by governance in September 2025. Anza has no token of its own; risk considerations center on its outsized influence over Solana's core protocol, the regulatory context of its formation, and a personal civil lawsuit involving co-founder Stephen Akridge.
avoid.net/turtledex→2/100[CRITICAL]TurtleDex was a purported decentralized cloud storage protocol launched on Binance Smart Chain (BSC) in March 2021. The project raised approximately 9,000 BNB (roughly $2.5 million) in a presale on March 15, 2021, then executed an exit scam on or around March 19, 2021, draining liquidity pools on PancakeSwap and ApeSwap, converting the proceeds to ETH, and disappearing entirely. The team's identities were disclosed only under pseudonyms in a pre-launch AMA, and no funds were recovered.
avoid.net/logan-paul-cryptozoo→6/100[CRITICAL]CryptoZoo was a blockchain-based NFT game co-founded by YouTuber Logan Paul that launched in September 2021 promising players would earn money by breeding virtual animals using the $ZOO token; the game's core gameplay mechanics were never delivered, leading to investor losses, a prominent investigative YouTube series by Coffeezilla, class-action litigation, and an eventual partial refund program. A class-action lawsuit was dismissed with prejudice in October 2025 on the grounds that Paul's promotional statements constituted non-actionable 'puffery', while Paul's own defamation lawsuit against Coffeezilla was proceeding toward a May 2026 jury trial as of the most recent available public records.
avoid.net/hashocean→2/100[CRITICAL]HashOcean (hashocean.com) was a cloud-mining platform that operated from approximately 2014 to 2016, claiming to run data centers in San Francisco, New York, Nuremberg, and Singapore and offering free hashrate to new signups. The site disappeared on or after June 25, 2016, affecting an alleged 700,000 users worldwide. Independent analysis and community assessments characterized it as a Ponzi scheme; no verified law enforcement action or identified operators have been publicly confirmed.
avoid.net/gracetoken→20/100[CRITICAL]GraceToken is an ambiguous name shared by at least two unrelated cryptocurrency projects. The first (ticker: GRCE, Ethereum) was a 2017 charity-fundraising ICO that officially announced its shutdown in January 2018, citing resource exhaustion and inability to gain traction; its team identities were never publicly disclosed. The second (ticker: GRC, BNB Smart Chain) is a separate 2022 community-oriented meme token that reached an all-time high of approximately $0.87 in April 2022 before collapsing to near-zero, with no remaining liquidity or active trading; no Tier 1 or Tier 2 source has confirmed a deliberate rug pull for either project.
avoid.net/finiko→2/100[CRITICAL]Finiko was a Russia-based cryptocurrency Ponzi scheme that operated from late 2019 until its collapse in July 2021. Founded by Kirill Doronin and several associates in Kazan, Russia, the scheme accepted Bitcoin and Tether from investors while promising monthly returns of up to 30 percent, and issued a proprietary FNK token. According to Chainalysis, Finiko received over $1.5 billion worth of Bitcoin across more than 800,000 deposits during its 19-month operation, netting an estimated $1.1 billion from victims; Russian authorities officially recorded over 7,700 victims and losses exceeding 5 billion rubles. Doronin was arrested in July 2021, several co-founders were subsequently apprehended through Interpol cooperation with the UAE, and the scheme was identified by U.S. Treasury's FinCEN as one of the top counterparties of sanctioned exchange Bitzlato.
avoid.net/faze-clan→2/100[CRITICAL]Save the Kids ($KIDS) was a BEP-20 token launched on June 5, 2021, on Binance Smart Chain and traded on PancakeSwap, marketed as a charity token that would donate 1% of transaction fees to children's causes. The token collapsed approximately 70% within hours of launch following coordinated selling by pre-sale insiders, including FaZe Clan members who had promoted it to their predominantly teenage audiences. YouTuber-investigator Stephen 'Coffeezilla' Findeisen subsequently established through on-chain analysis and Discord evidence that the token's anti-whale protection had been secretly modified before launch to enable rapid insider dumps, and that FaZe Clan member Frazier 'Kay' Khattri and YouTube personality Sam Pepper were among the primary architects of the scheme.
avoid.net/defi100→12/100[CRITICAL]DeFi100 (ticker: D100) was a synthetic index fund and elastic-supply rebase token launched on Binance Smart Chain in February 2021 by an anonymous developer group operating under the name Wrapp3d. On May 22, 2021, the project's website displayed a profane message claiming to have scammed investors, which the team attributed to a website hack rather than an intentional exit; the widely cited $32 million loss figure originated from an unverified Twitter claim and is contradicted by the project's own market-cap data, which placed its peak capitalization below $2 million. The project is effectively abandoned, and its token has lost more than 99% of its all-time-high value.
avoid.net/fq1tyso61ah1tzodyjfswmzsd3gtoybbrnozxubz21p8→3/100[CRITICAL]The Solana address FQ1tyso61AH1tzodyJfSwmzsD3GToybbRNoZxUBz21p8 is the token mint for Dasha (ticker: VVAIFU), the native token of vvaifu.fun — a no-code AI agent launchpad on Solana launched via Pump.fun on October 19, 2024. The token reached an all-time high of approximately $0.21 in November 2024, driven by speculative hype around the AI agent narrative, but has since collapsed approximately 99.9% to under $0.0003 as of mid-2026. The team behind vvaifu.fun operates pseudonymously, no formal audits have been disclosed, and CoinMarketCap lists a CertiK security score of 3.5 out of 10.
avoid.net/gateio→57/100[CAUTIONARY]Gate.io (rebranded to Gate.com in May 2025) is a major global cryptocurrency exchange founded in 2013 as Bter.com by Lin Han, currently incorporated in the Cayman Islands and serving over 52 million users across more than 4,600 assets. The exchange has faced significant scrutiny including an alleged undisclosed $230 million hack in 2018 attributed to North Korean state actors, a 2025 public notice from the Cayman Islands Monetary Authority (CIMA) confirming it has never been licensed in its ostensible home jurisdiction, and a pattern of user complaints regarding account freezes, withdrawal blocks, and a disputed $LA futures incident in 2025. The exchange publishes monthly proof-of-reserves reports audited by Hacken and holds licenses in several jurisdictions including Malta (MiCA), Dubai (VARA), Cyprus (CySEC), and Australia (AUSTRAC).
avoid.net/frax-finance→52/100[CAUTIONARY]Frax Finance is a decentralized stablecoin protocol launched in December 2020, originally pioneering a fractional-algorithmic design for its FRAX stablecoin. Following the collapse of algorithmic stablecoins in 2022, the protocol voted in 2023 to move to full collateralization, and has since expanded into a broader DeFi ecosystem including liquid staking (frxETH), a lending market (Fraxlend), a Layer 2 blockchain (Fraxtal), and a fully-backed institutional stablecoin (frxUSD) collateralized by BlackRock's BUIDL fund. The protocol faces documented concerns about historical centralization via a core-team-controlled multisig, an unresolved bug bounty attribution dispute, and prior security incidents including a DNS domain hijacking and an X account compromise.
avoid.net/cow-swap-cow-protocol→50/100[WARNING]CoW Protocol (trading interface: CoW Swap) is a decentralized exchange aggregator and MEV-protection protocol spun out of GnosisDAO in 2022. On April 14, 2026, the protocol's cow.fi domain was hijacked via a social engineering attack that exploited registrar Gandi SAS and the Finnish .fi registry authority Traficom using forged identity documents, redirecting users to a phishing interface for approximately 90 minutes and causing confirmed losses of approximately $1.2 million. The protocol's smart contracts were not compromised; CoW DAO subsequently passed CIP-86 in May 2026 to offer discretionary grants reimbursing verified victims up to 100% of their losses.
avoid.net/kucoin-hack→32/100[WARNING]On September 25, 2020, the KuCoin cryptocurrency exchange suffered a major security breach in which hackers obtained the private keys to the exchange's hot wallets and stole approximately $281 million in Bitcoin, Ethereum, ERC-20 tokens, and other assets — the largest exchange hack of 2020. KuCoin subsequently recovered approximately 84% of stolen funds through on-chain tracking, project-team token swaps, and law enforcement cooperation, with the remaining 16% covered by the exchange's insurance fund. The hack was attributed to North Korea's Lazarus Group by blockchain analytics firm Chainalysis; separately, in March 2024 the U.S. Department of Justice criminally charged KuCoin and two of its founders for operating an unlicensed money transmitting business and Bank Secrecy Act violations, resulting in a $297.4 million guilty plea settlement in January 2025.
avoid.net/exactly-protocol→42/100[WARNING]Exactly Protocol is a decentralized, non-custodial fixed and variable interest rate lending protocol deployed on the Optimism Layer 2 network. On August 18, 2023, the protocol suffered a critical exploit in its DebtManager periphery contract that drained approximately $7.3 million from 117 user accounts through an access control bypass and reentrancy attack. Despite multiple prior audits of its core contracts, the vulnerable periphery contract was outside the audit scope at the time of the attack; the stolen funds were bridged to Ethereum and have not been publicly confirmed as recovered.
avoid.net/openzeppelin-ai-exploit-threat-vector→15/100[CRITICAL]On May 26, 2026, Manuel Aráoz, co-founder of smart contract security firm OpenZeppelin, issued a public warning on X declaring that he considers 'all of DeFi unsafe,' citing the emergence of AI coding agents that are 'superhuman' at discovering and weaponizing smart contract vulnerabilities. The warning coincided with more than $1.1 billion lost to DeFi hacks in the prior 12 months and was substantiated by Anthropic research published in late 2025 demonstrating that frontier AI models can autonomously exploit known smart contract vulnerabilities at scale. This entry tracks the AI-assisted DeFi exploit surface as a forward-looking threat category, documenting the evidence base, industry response, and structural security asymmetry that Aráoz and corroborating researchers describe.
avoid.net/delio-south-korea-crypto-lender-fraud→3/100[CRITICAL]Delio was South Korea's first VASP-licensed cryptocurrency deposit and lending platform, founded in 2018 by CEO Jeong Sang-ho. In June 2023, the platform abruptly froze approximately $169–180 million in customer withdrawals affecting roughly 2,800 investors, citing market volatility linked to the concurrent collapse of sister-platform Haru Invest and cascading losses from the November 2022 FTX bankruptcy. A Seoul court declared Delio bankrupt on November 22, 2024, and prosecutors at Seoul Southern District Court demanded a 20-year prison sentence for Jeong Sang-ho in April–May 2026, with a first-instance verdict scheduled for July 16, 2026.
avoid.net/blockdag-network→4/100[CRITICAL]BlockDAG Network (BDAG) is a cryptocurrency project that ran a presale from December 2023 through February 2026, claiming to raise over $442 million, though its CEO stated publicly the actual figure was approximately $200 million. On-chain investigator ZachXBT and a DL News investigation have alleged that the project's true co-founder, Gurhan Kiziloz, operated behind the scenes while using a paid frontman as public CEO, transferred presale funds through Middle Eastern OTC brokers, and commingled at least $25 million in presale proceeds from BlockDAG and a sister project (ZKP) to pay influencers promoting Kiziloz's casino venture. Following its February 2026 token launch, BDAG fell approximately 99.98% from its all-time high within two months.
avoid.net/injective-protocol→55/100[CAUTIONARY]Injective Protocol is a Layer 1 blockchain built on the Cosmos SDK, designed for decentralized finance applications including derivatives, perpetuals, and spot trading via a fully on-chain order book. Founded in 2018 by Eric Chen and Albert Chon and backed by Binance Labs, Pantera Capital, and Mark Cuban, it launched its canonical mainnet in November 2021 and has grown to a top-tier DeFi chain. No regulatory enforcement actions have been identified against Injective; however, concerns exist around a 2025-2026 bug bounty dispute involving an alleged $500 million critical vulnerability, validator stake concentration, and third-party scams impersonating the protocol.
avoid.net/leo-token→35/100[WARNING]UNUS SED LEO (LEO) is the utility token of the iFinex ecosystem (Bitfinex exchange, Tether). Created in May 2019 as a $1B token sale to recapitalize after an $850M loss when payment processor Crypto Capital Corp had funds seized by multiple governments. The NYAG alleged iFinex covered the $850M shortfall using Tether reserves. Bitfinex and Tether settled with the NYAG in February 2021 for $18.5M, admitting no wrongdoing. The LEO smart contract was alleged by Cointelligence to contain deliberate flaws enabling fraud. iFinex commits 27% of monthly revenue to LEO buybacks/burns. Following the 2016 Bitfinex hack recovery (94,643 BTC), 80% of recovered funds must be used for LEO buybacks per the whitepaper. LEO surged past $10, entering top 10 by market cap (~$9.3B).
avoid.net/near-protocol→64/100[CAUTIONARY]NEAR Protocol is a layer-1 proof-of-stake blockchain founded in 2017 by Illia Polosukhin and Alexander Skidanov, featuring a sharded architecture (Nightshade) and human-readable account names, with mainnet launching in April 2020. The project has raised over $540 million from notable investors including Andreessen Horowitz and Tiger Global, and has maintained an active development roadmap pivoting toward AI agent infrastructure. No direct fraud or regulatory enforcement actions have been identified against the protocol itself, though ecosystem-level exploits, centralization concerns, and investor overlap with collapsed entities such as FTX Ventures and Three Arrows Capital have been noted.
avoid.net/uniswap→58/100[CAUTIONARY]Uniswap is a decentralized exchange (DEX) protocol built on Ethereum, founded in November 2018 by Hayden Adams and operated commercially by Uniswap Labs. It is the largest DEX by trading volume globally, using an automated market maker (AMM) model. The protocol has faced significant regulatory scrutiny — including an SEC Wells notice in April 2024 (closed without action in February 2025), a CFTC settlement resulting in a $175,000 penalty in September 2024, and a multi-year scam-token class action dismissed with prejudice in March 2026 — while remaining operationally active and technologically mature through its v4 release.
avoid.net/memecore→22/100[CRITICAL]MemeCore (M) is a self-described Layer 1 blockchain and meme-economy platform launched in 2024, with its native token listing on multiple major centralized exchanges in July 2025 at a market capitalization that reached approximately $4.2-6 billion by early 2026. On-chain investigator ZachXBT publicly challenged the project in April 2026, alleging that insiders hold over 90% of the token supply against a reported circulating float, and flagged $7.9 million in suspicious post-listing outflows from Kraken to 18 newly created wallet addresses. MemeCore has not provided a verifiable on-chain rebuttal to these allegations as of May 2026, and CertiK's audit data independently confirms that approximately 87.4% of the top two holders' combined ratio represents significant supply concentration.
avoid.net/thodex→0/100[CRITICAL]Thodex was a Turkish cryptocurrency exchange founded in 2017 (originally as Koineks) by Faruk Fatih Özer that collapsed in April 2021 when the platform abruptly halted trading and its founder fled to Albania, leaving approximately 391,000 users unable to access funds estimated at $2 billion to $2.6 billion. Özer was arrested in Albania in August 2022, extradited to Turkey in April 2023, convicted in September 2023 and sentenced to 11,196 years in prison alongside his two siblings, and died in a Turkish high-security prison on November 1, 2025, in circumstances that prompted a formal investigation.
avoid.net/nirvana-v1→5/100[CRITICAL]Nirvana V1 was a Solana-based algorithmic stablecoin and yield protocol that operated twin tokens: ANA (an algorithmic metastable wealth token) and NIRV (a decentralized stablecoin). On July 28, 2022, the protocol was catastrophically exploited via a flash loan attack that drained approximately $3.5 million — representing nearly all protocol reserves — causing both tokens to collapse and forcing a permanent shutdown. The attacker, Shakeeb Ahmed, was later identified, arrested, and convicted in the first-ever U.S. criminal prosecution for hacking a smart contract, and was sentenced to three years in prison in April 2024.
avoid.net/amun→38/100[WARNING]Amun refers to two related but distinct entities: Amun AG, a Swiss ETP issuer that rebranded to 21Shares in 2020 and lists regulated crypto exchange-traded products on the SIX Swiss Exchange; and Amun Ltd / Amun DeFi Tokens, a separate DeFi arm that issued leveraged tokens and on-chain index products on Ethereum and Polygon. The DeFi arm experienced a critical smart contract exploit on December 26, 2022 resulting in approximately $300,000 in losses, followed by the termination of multiple product lines. On-chain investigator ZachXBT has been cited in connection with flagging Amun, though a specific, verifiable public post could not be independently confirmed at the time of this investigation.
avoid.net/dydx-v3→30/100[WARNING]dYdX V3 was a decentralized perpetual futures exchange built on Ethereum using StarkWare's StarkEx Layer-2 technology, operated by dYdX Trading Inc. The platform suffered a $9 million insurance fund drain in November 2023 due to an alleged coordinated market manipulation attack targeting YFI and SUSHI markets, a DNS hijacking attack in July 2024, and a software supply chain compromise in September 2022. The V3 product was formally sunset on October 28, 2024, with trading migrated to the dYdX Chain (V4) on Cosmos.
avoid.net/riskonblast→2/100[CRITICAL]RiskOnBlast was a GambleFi (gambling and exchange) platform launched on the Blast Layer-2 network in February 2024. Its anonymous team executed an exit scam (rug pull) on February 24, 2024, draining approximately 420 ETH (~$1.3 million) from over 750 investor wallets immediately after the IDO cap was reached. The project is linked by on-chain evidence to a serial fraud group responsible for more than $20 million in losses across multiple DeFi protocols.
avoid.net/seneca→22/100[CRITICAL]Seneca is a decentralized stablecoin lending protocol that allowed users to mint senUSD against collateral. On February 28, 2024, attackers exploited a critical arbitrary external-call vulnerability in its Chamber contract, draining approximately $6.4 million from user wallets across Ethereum and Arbitrum. Approximately 80% of stolen funds were recovered after an on-chain bounty offer; however, the vulnerability had been publicly identified months before the exploit and the team proceeded to launch without patching it.
avoid.net/vladhood-vlad-memecoin-scam→2/100[CRITICAL]On July 23, 2026, unknown attackers compromised the verified X account of Robinhood CEO Vlad Tenev and used it to promote a fraudulent memecoin called Vladhood ($VLAD), falsely presenting it as the official mascot of the Robinhood Chain network and claiming it would be listed in the Robinhood app. The token had been pre-deployed on the Pons launchpad 46 minutes before the post appeared, and attackers extracted approximately 650 ETH ($1.2–$1.3 million USD) through trading fee collection rather than a traditional rug pull. No attacker attribution or law enforcement action had been publicly reported as of late July 2026.
avoid.net/bonzo-lend→22/100[CRITICAL]Bonzo Lend is a decentralized lending and borrowing protocol on the Hedera network, adapted from the Aave v2 codebase and formerly the largest DeFi lending protocol on Hedera by total value locked. On July 11, 2026, the protocol suffered a $9.05 million loss when an attacker exploited a critical signature verification flaw in its third-party Supra oracle provider, inflating the SAUCE token price by approximately twelve orders of magnitude and borrowing assets far in excess of deposited collateral. Protocol operations remain paused pending a Halborn-audited recovery contract deployment backed by the Hedera Foundation.
avoid.net/bitmart-exchange→18/100[CRITICAL]BitMart is a centralized cryptocurrency exchange founded in 2017 by Sheldon Xia and incorporated in the Cayman Islands, which at its peak served users in over 180 countries and listed more than 1,700 cryptocurrencies. In December 2021, BitMart suffered one of the largest hot-wallet hacks in crypto history, losing approximately $196 million, which triggered a Federal Trade Commission investigation and raised unresolved questions about victim reimbursement. On July 26, 2026, BitMart announced it would wind down all trading operations by August 26, 2026 and fully close by January 31, 2027, citing vague 'operating conditions' while its CEO simultaneously disclosed he had been excluded from the shutdown decision — a combination of events that poses immediate fund-access risk for remaining users.
avoid.net/pig-butchering-scam-network-operation-atlantic-2026-global-crackdown→0/100[CRITICAL]Pig butchering (sha zhu pan) scam networks are transnational organized crime enterprises, predominantly Chinese-run, operating out of fortified compounds in Southeast Asia — primarily Myanmar, Cambodia, and Laos — that combine romance fraud, fake cryptocurrency investment platforms, and human trafficking of coerced workers. The first four months of 2026 produced more enforcement action against these networks than the entire preceding decade, culminating in a coordinated takedown on April 29, 2026 that resulted in at least 276 arrests and the shutdown of nine scam centers. Key concurrent actions included Operation Atlantic (March 16, 2026), a $61 million Tether seizure (March 12, 2026), a $701 million cryptocurrency restraint tied to the Shunda compound in Burma, and Treasury sanctions against a Cambodian senator and 27 associated entities.
avoid.net/chen-zhi-prince-group→2/100[CRITICAL]Chen Zhi (also known as Vincent), the Chinese-born founder and chairman of Cambodia-based Prince Holding Group, was indicted by the U.S. Department of Justice in October 2025 on wire fraud conspiracy and money laundering conspiracy charges for allegedly directing forced-labor scam compounds engaged in large-scale 'pig butchering' cryptocurrency investment fraud. Concurrent civil forfeiture of approximately 127,271 Bitcoin — valued at roughly $15 billion and described as the largest forfeiture action in DOJ history — was filed against assets linked to Chen. He was arrested in Cambodia in January 2026 and extradited to China, where he faces separate accusations.
avoid.net/easy-day-js-mastra-npm-supply-chain-attack→0/100[CRITICAL]On June 16–17, 2026, attackers published a typosquatted npm package named easy-day-js mimicking the legitimate dayjs date library, then used a hijacked former-contributor npm account (ehindero) to inject it as a dependency across 141–144 packages in the @mastra organization within an 88-minute window. The malicious postinstall payload functioned as a cross-platform remote access trojan (RAT) and infostealer, exfiltrating cryptocurrency wallet credentials, browser history, and developer secrets before self-deleting, with affected packages carrying a combined weekly download count exceeding 1.1 million.
avoid.net/darwin-labs-private-limited→4/100[CRITICAL]Darwin Labs Private Limited is an India-registered technology venture studio co-founded by Sahil Baghla, Ayush Varshney, and Nikunj Jain. Indian authorities allege the company designed and built the entire technological infrastructure underpinning the GainBitcoin Ponzi scheme, one of India's largest cryptocurrency frauds, involving approximately 8,000 investors and estimated losses of Rs 6,606 crore (roughly $790 million). Two co-founders were arrested by Pune Police in April 2018, and a third — Ayush Varshney — was arrested by the Central Bureau of Investigation (CBI) in March 2026 after being intercepted at Mumbai airport while allegedly attempting to flee to Sri Lanka.
avoid.net/sanduo-group-giant-company→0/100[CRITICAL]Sanduo Group and Giant Company are alleged front organizations used to operate cryptocurrency 'pig butchering' investment fraud schemes targeting victims in the United States and dozens of other countries. Four individuals — three Indonesian nationals and one Burmese national — were federally charged in the Southern District of California in March and April 2026 for wire fraud conspiracy and money laundering conspiracy in connection with these entities, following a coordinated international takedown led by the FBI, Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police that resulted in 276 arrests and the dismantling of nine scam centers. The broader pig butchering ecosystem from which these groups operated is documented by law enforcement and researchers to rely heavily on human trafficking and forced labor.
avoid.net/kelsier-labs→4/100[CRITICAL]Kelsier Labs LLC, operating as Kelsier Ventures, is a Delaware-incorporated Web3 investment and marketing firm founded in 2020 and led by CEO Hayden Mark Davis and family members Gideon Davis (COO) and Charles Thomas Davis (father). The firm is the subject of multiple active legal proceedings alleging that it orchestrated coordinated pump-and-dump schemes across several high-profile Solana-based memecoins — including $M3M3, $LIBRA, and $MELANIA — resulting in alleged investor losses estimated at over $286 million. Argentine authorities have frozen assets tied to Davis and requested an Interpol Red Notice for his arrest in connection with the $LIBRA scandal.
avoid.net/miasma-npm-supply-chain-attack→5/100[CRITICAL]Miasma is a multi-wave, self-propagating npm supply chain attack campaign active from June 1 through at least June 10, 2026, that compromised hundreds of widely-used npm packages and dozens of GitHub repositories across organizations including Red Hat, Vapi.ai, and Microsoft Azure. The malware, a variant of the Mini Shai-Hulud credential-stealing worm associated with threat actor TeamPCP (also tracked as UNC6780), exfiltrates cloud credentials, CI/CD secrets, SSH keys, and browser-stored data including crypto wallet files, then uses stolen tokens to republish backdoored package versions and spread to additional repositories. No confirmed cryptocurrency theft or quantified financial loss from crypto assets had been publicly documented as of the investigation date, though the malware's collectors enumerate local wallet storage and the attack's credential-theft scope poses downstream risk to any crypto developer environments that installed affected packages.
avoid.net/lab-token-ai-terminal-vova-sadkov→4/100[CRITICAL]LAB is the native token of the AI Terminal, a multi-chain trading platform founded by Vova Sadkov (Vladimir Sadkov) and a co-founder identified as Mark X. In May 2026, on-chain investigator ZachXBT published findings alleging that insiders controlled more than 95% of the circulating LAB token supply, that 226 million tokens were concentrated in Bitget deposit addresses before a 350%-plus price pump, and that the project simultaneously operated four distinct mechanisms to extract value from retail participants. The token subsequently crashed as much as 77% from its peak, wiping approximately $6.8 billion in market value.
avoid.net/zinc→32/100[WARNING]The name 'Zinc' encompasses at least three distinct crypto entities: (1) Zinc Protocol, a 2018 Tel Aviv-based ERC20 advertising token that appears to have gone dormant with a ~98.8% price decline from its all-time high; (2) Zinc, a Solana-based gamified mining protocol that emerged from a pivot of the failed ZKLSOL privacy mixer project funded through MetaDAO, which became one of Solana's top revenue generators but is embroiled in a documented governance dispute over investor buyout terms; and (3) Zinc, a Zcash inscription protocol operating at zinc.is. The most active and notable entity as of mid-2026 is the Solana-based Zinc/ZKFG project, which raises concerns about anonymous founding team, absence of formal legal documentation governing its pivot from the original ZKLSOL mandate, and an unresolved governance conflict with MetaDAO investors.
avoid.net/kat-katana-network→52/100[CAUTIONARY]Katana Network is a DeFi-native Ethereum Layer-2 rollup incubated by Polygon Labs and GSR, launched on Polygon's AggLayer in mid-2025. Its native governance and incentive token, KAT, had its Token Generation Event (TGE) in March 2026 and is distinct from the older Katana DEX built by Sky Mavis on the Ronin sidechain for Axie Infinity. The project carries acknowledged centralization risks at its current Stage 0 classification by L2Beat, significant post-TGE token price depreciation, and elevated smart-contract and bridge risk stemming from its multi-protocol integration architecture.
avoid.net/allo-protocol→68/100[CAUTIONARY]Allo Protocol is an open-source, EVM-compatible smart contract framework for on-chain capital allocation, developed by Gitcoin and launched on Ethereum mainnet in November 2023. It served as the underlying infrastructure for Gitcoin Grants Stack from 2023 through May 2025, when Gitcoin's software division (Grants Lab) was shut down due to financial constraints, placing Allo in maintenance mode. No fraud allegations, regulatory actions, or security exploits have been publicly documented against the protocol itself.
avoid.net/0x62d5a59e0d67c0381aad53b201b4a1b8dcd2c833→45/100[WARNING]0x62d5a59e0d67c0381aad53b201b4a1b8dcd2c833 is an Ethereum externally owned account (EOA) with minimal on-chain activity, consisting of exactly two zero-value incoming transfers from the same source address in May 2026. No name tags, entity labels, scam reports, or regulatory flags have been identified for this address across Etherscan, ChainAbuse, or open-web sources as of June 2026.
avoid.net/antier-solutions→62/100[CAUTIONARY]Antier Solutions Pvt. Ltd. is an India-based blockchain and Web3 development firm headquartered in Mohali, Punjab, founded in 2005 and led by CEO Vikram R. Singh. The company provides custom blockchain development, crypto exchange development, DeFi platforms, and enterprise blockchain services to global clients. In May 2026 it received its first institutional funding of $3 million led by GVFL; it carries generally positive ratings on B2B review platforms, though a small number of Trustpilot reviews allege fraudulent conduct, a claim not corroborated by regulatory filings or major news sources.
avoid.net/meta-1-coin→0/100[CRITICAL]Meta-1 Coin was a fraudulent digital asset marketed from 2018 to 2023 by Robert Dunlap through the Meta-1 Coin Trust, with false claims that the token was backed by $44 billion in gold and $1 billion in fine art. Dunlap used automated trading bots on a sham exchange called the Meta Exchange to inflate the coin's apparent price and volume, defrauding approximately 1,000 investors of more than $20 million. In April 2026, Dunlap was sentenced to 23 years in federal prison following a November 2025 conviction on mail fraud charges in the Northern District of Illinois.
avoid.net/amir-hossein-rad→2/100[CRITICAL]Amir Hossein Rad is the chairman, co-founder, and former CEO of Nobitex, Iran's largest cryptocurrency exchange. On June 2, 2026, OFAC personally designated Rad under Executive Orders 13224 and 13902 for his leadership role at an exchange the U.S. Treasury accused of enabling sanctions evasion, supporting the Islamic Revolutionary Guard Corps (IRGC), and facilitating terrorist financing. He was among four individuals designated alongside the exchange itself as part of the Trump administration's 'Economic Fury' campaign targeting Iran's financial infrastructure.
avoid.net/tanstack-npm-supply-chain-attack-mini-shai-hulud-teampcp→0/100[CRITICAL]On May 11, 2026, threat actor group TeamPCP executed a sophisticated supply chain attack against the TanStack npm ecosystem, compromising 42 packages across 84 malicious versions collectively downloaded millions of times per week. The attack, branded internally as the 'Mini Shai-Hulud' worm, chained three GitHub Actions vulnerabilities to extract an OIDC token from runner memory and autonomously publish credential-stealing payloads that spread to over 170 additional npm and PyPI packages including Mistral AI, UiPath, and OpenSearch. The campaign is the fourth documented wave from TeamPCP, a group active since at least late 2024, and represents the first recorded npm worm to produce validly-attested malicious packages under SLSA Build Level 3 provenance.
avoid.net/openclaw-github-phishing-campaign→0/100[CRITICAL]An active phishing campaign, first disclosed by OX Security in March 2026 and continuing into June 2026, abuses the OpenClaw brand and GitHub's issue notification system to target software developers with fake $5,000 CLAW token giveaways. Victims are directed via Google LinkShare redirect URLs to token-claw[.]xyz, a near-identical clone of openclaw.ai, where a malicious wallet-connect prompt triggers a JavaScript drainer (eleven.js) capable of siphoning funds from MetaMask, Trust Wallet, OKX Wallet, Bybit Wallet, and WalletConnect-compatible wallets. OpenClaw founder Peter Steinberger has publicly stated the project has no token and never will.
avoid.net/vortex→2/100[CRITICAL]Vortex is a cryptocurrency market-making firm whose leadership was indicted by a federal grand jury in Oakland, California on August 28, 2025, on charges of wire fraud conspiracy and wire fraud in connection with an alleged coordinated wash-trading scheme. Three Russian nationals — Gleb Gora (CEO, age 24), Sergei Ryzhkov (CFO), and Michael Vogel (Business Development Manager) — are alleged to have artificially inflated cryptocurrency token prices using automated trading bots and planned to liquidate their holdings at peak prices, leaving retail investors with losses. The indictment was publicly announced on March 30, 2026, as part of the DOJ's Operation Token Mirrors, a multi-agency undercover enforcement action targeting market-manipulation-as-a-service operations.
avoid.net/malone-lam-crypto-syndicate→0/100[CRITICAL]The Malone Lam Crypto Syndicate, also known as the Social Engineering Enterprise (SEE), is an alleged multi-state criminal organization that stole approximately $263 million in cryptocurrency between October 2023 and May 2025 through social engineering, residential home invasions, and hardware wallet theft. Led by Singaporean national Malone Lam (alias 'Anne Hathaway', 'Greavys'), the enterprise comprised at least 14 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars. The DOJ charged the organization under the RICO statute — one of the most aggressive crypto theft prosecutions ever filed — and as of June 2026, nine co-defendants have pleaded guilty and been sentenced to 70–78 months, while Lam and co-lead Jeandiel Serrano remain in pre-trial proceedings.
avoid.net/gamer-crew-263m-social-engineering-ring-new-defendants→0/100[CRITICAL]The 'Social Engineering Enterprise' (SE Enterprise) is a DOJ-designated RICO criminal organization that stole over $263 million in cryptocurrency — primarily 4,100 BTC from a single Washington, D.C. victim in August 2024 — through a combination of database breaches, impersonation calls, and residential burglaries targeting hardware wallets. The enterprise grew from friendships formed on online gaming platforms and operated from October 2023 through at least May 2025, with at least 17 defendants charged across multiple superseding indictments, nine of whom have pleaded guilty as of early 2026. A second superseding indictment unsealed in June 2026 added three new defendants — Nicholas Dellecave, Mustafa Ibrahim, and Danish Zulfiqar — expanding the prosecution and marking ongoing international coordination with Dubai law enforcement.
avoid.net/misam-abidi-star-credit-holdings→2/100[CRITICAL]Misam M. Abidi, 47, of Nolensville, Tennessee, faces an 11-count federal indictment unsealed June 13, 2026, for allegedly operating a cryptocurrency investment Ponzi scheme through Star Credit Holdings between 2020 and 2024. Prosecutors allege he diverted over $1.9 million of investor funds to himself and family members, and the broader enterprise involving co-defendants Ali Raza Galani and Anisha Abidi allegedly caused losses exceeding $6.3 million across 17 states. Related state regulatory actions by the Tennessee Department of Commerce and Insurance and the Tennessee Attorney General resulted in a temporary injunction and asset freeze in May 2024.
avoid.net/tesseradao-tsr-token-unauthorized-mint-exploit→3/100[CRITICAL]On June 1, 2026, an attacker leveraged a compromised admin key on BNB Chain to mint 99 million TSR tokens outside TesseraDAO's normal supply controls, swapping them for approximately $2.5 million in USDT and collapsing the TSR token price by approximately 99%. The exploiter subsequently bridged the stolen proceeds to Ethereum and laundered approximately 1,285.5 ETH through Tornado Cash. As of the date of reporting, TesseraDAO issued no public statement, raising unresolved questions about whether the incident constituted an external key compromise or an insider-orchestrated exit.
avoid.net/humanity-protocol-june-2026-exploit→8/100[CRITICAL]On June 8-9, 2026, Humanity Protocol suffered a coordinated cross-chain exploit in which attackers compromised seven private keys stored on a single malware-infected employee laptop, draining approximately 447 million H tokens — valued at $32-36 million — across Ethereum and BNB Smart Chain. Blockchain investigator ZachXBT initially alleged the incident was 'possibly staged' based on pre-funded attacker wallets, suspicious market-making activity, and DEX-only token dumps, though he subsequently revised his assessment, concluding the private key compromise and the earlier suspicious market-making were independent events. The H token crashed between 87-89% within hours of the attack and remained deeply depressed ahead of a 266.5 million token unlock scheduled for June 25, 2026.
avoid.net/doj-scam-center-strike-force-southeast-asia-pig-butchering-network→3/100[CRITICAL]The Southeast Asia pig-butchering network is a constellation of transnational organized crime syndicates — primarily Chinese-language criminal organizations — operating forced-labor scam compounds across Cambodia, Myanmar (Burma), and Laos that have stolen an estimated $10 billion or more annually from American victims through cryptocurrency investment fraud. In November 2025, the U.S. Department of Justice established the Scam Center Strike Force, a multi-agency interagency task force headquartered in the District of Columbia, to coordinate criminal prosecution, civil asset forfeiture, Treasury sanctions, and private-sector disruption against these networks. By mid-2026, the Strike Force had restrained approximately $725.9 million in cryptocurrency, coordinated at least 276 arrests across an international operation in April–May 2026, and partnered with nine private technology companies during a dedicated 'Disruption Week' that disabled more than 1.4 million fraudulent accounts globally.
avoid.net/miasma-redhat-npm-supply-chain-attack→2/100[CRITICAL]Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.
avoid.net/predatory-sparrow-gonjeshke-darande→30/100[WARNING]Predatory Sparrow, known in Persian as Gonjeshke Darande, is a hacking group active since at least July 2021 that has claimed responsibility for a series of destructive cyberattacks against Iranian critical infrastructure, financial institutions, and cryptocurrency exchanges. The group is widely believed by security researchers, Israeli media, and anonymous U.S. defense officials to have links to the Israeli government, though Israel has never formally acknowledged any connection. Their operations are politically motivated, targeting entities alleged to support Iran's Islamic Revolutionary Guard Corps (IRGC) and facilitate sanctions evasion, and have extended directly into the cryptocurrency space with the June 2025 destruction of approximately $90 million in digital assets stolen from Iran's largest crypto exchange, Nobitex.
avoid.net/world-cup-2026-crypto-scam-network→0/100[CRITICAL]The 2026 FIFA World Cup has attracted a coordinated wave of crypto-linked fraud operating across multiple typologies, including typosquatting domain networks, fake ticket portals demanding cryptocurrency payment, fixed-match betting schemes, pump-and-dump fan meme coins, and Android banking malware bundled in fake streaming apps. Law enforcement agencies including the FBI Cyber Division and the Los Angeles County Sheriff's Department have issued public warnings, while blockchain analytics firm TRM Labs and cybersecurity vendors Malwarebytes, CybelAngel, and The Hacker News have documented active infrastructure running since at least August 2025, months before the first match.
avoid.net/indonesia-pig-butchering-operation-central-java-2026→0/100[CRITICAL]An international online fraud syndicate operating under the cover of PT Digi Global Konsultan in Sukoharjo District, Central Java, conducted a pig-butchering romance-and-crypto-investment scam from July 2025 to May 2026, defrauding at least 133 US citizens of approximately $2.32 million. Central Java Police arrested 39 suspects of Indonesian, Nepalese, and Myanmar nationality on May 20, 2026, in coordination with the US Federal Bureau of Investigation. Separately, US federal charges were filed in the Southern District of California in April 2026 against Indonesian nationals linked to related pig-butchering organizations.
avoid.net/mrbeast-superverse-crypto-deals→28/100[WARNING]Jimmy Donaldson, known as MrBeast and the most-subscribed individual creator on YouTube, has been the subject of on-chain investigations alleging that wallets attributed to him generated approximately $23 million in profits through participation in crypto token presales followed by coordinated liquidations, including an alleged $11.4 million from the SuperVerse (SUPER) token in 2021. No formal regulatory charges had been filed against Donaldson as of mid-2026, though Senator Elizabeth Warren and Representative Warren Davidson opened a congressional inquiry in March 2026 targeting Beast Industries over crypto plans directed at minors. Donaldson has denied wrongdoing, attributing relevant financial activity to third-party managers, and no independent court or regulatory body has verified the on-chain attribution.
avoid.net/phala-cloud-june-2026-api-breach→52/100[CAUTIONARY]On June 1, 2026, Phala Network disclosed and patched a vulnerability in the Phala Cloud API that permitted unauthorized modification of Confidential Virtual Machines (CVMs) using Offchain KMS key management. An attacker deployed a malicious pre-launch script beginning May 31, 2026, potentially exfiltrating decrypted environment variables including AWS credentials and ECR registry keys from affected CVMs. Phala patched the vulnerability within approximately 17 hours and notified affected users directly, though the incident exposed a structural gap between the platform's confidentiality marketing and the actual security boundary enforced by its Offchain KMS configuration.
avoid.net/axiom-dex→28/100[WARNING]Axiom is a Solana-based crypto trading platform founded in 2024 by Henry Zhang ('Mist') and Preston Ellis ('Cal'), which completed Y Combinator's Winter 2025 batch and generated over $390 million in cumulative revenue. In February 2026, blockchain investigator ZachXBT published a documented investigation revealing that a senior business development employee, Broox Bauer, along with colleagues, systematically abused internal dashboard tools with insufficient access controls to access private user wallet data and conduct insider trading for over 10 months beginning in early 2025. Axiom confirmed the breach, removed access to the implicated tools, and pledged an internal investigation, but no formal legal charges had been publicly filed as of the date of reporting.
avoid.net/southeast-asian-pig-butchering-scam-compounds-276-arrest-operation→0/100[CRITICAL]A coordinated international law enforcement operation conducted in April–May 2026 by the FBI, Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police resulted in at least 276 arrests and the dismantlement of at least nine cryptocurrency investment fraud centers operating in Southeast Asia and the UAE. The operation targeted three named scam organizations — Ko Thet Company, Sanduo Group, and Giant Company — charged in the Southern District of California, alongside a parallel Scam Center Strike Force action on April 23, 2026, that seized 503 fraudulent domains, charged two Chinese nationals for managing Myanmar's Shunda Park compound, sanctioned Cambodian Senator Kok An and 28 associates, and restrained $701.96 million in cryptocurrency. A $10 million State Department reward was simultaneously announced for information on the Tai Chang scam centers in Burma's Karen State.
avoid.net/sinaloa-cartel-ofac-ethereum-address-designations→0/100[CRITICAL]The U.S. Treasury's Office of Foreign Assets Control (OFAC) has designated multiple Ethereum wallet addresses linked to the Sinaloa Cartel's fentanyl trafficking and cryptocurrency money laundering operations. The most recent action, on May 20, 2026, added six Ethereum addresses and 11 individuals to the Specially Designated Nationals (SDN) list, marking the eighth Sinaloa Cartel designation linked to cryptocurrency since September 2023. All designated addresses are subject to strict-liability blocking obligations for U.S. persons and entities.
avoid.net/doj-225m-crypto-confidence-scam-seizure-june-2026→5/100[CRITICAL]On June 18, 2025, the U.S. Attorney's Office for the District of Columbia filed a civil forfeiture complaint seeking $225,364,961 in USDT linked to a sophisticated cryptocurrency investment fraud and money laundering network, marking the largest cryptocurrency seizure in U.S. Secret Service history. The funds were traced via blockchain analysis to pig-butchering scam operations allegedly run from compounds in the Philippines and Vietnam, affecting over 430 suspected victims globally. The action is part of a broader 2025-2026 federal crackdown that includes the D.C. Scam Center Strike Force, Operation Level Up, and a coordinated international sweep resulting in 276 arrests and $701 million in restrained assets.
avoid.net/iran-war-panic-crypto-scam-network-oramama-x-account-manipulation→2/100[CRITICAL]In March 2026, on-chain investigator ZachXBT exposed a coordinated network of at least 11 X accounts that manufactured fake geopolitical panic — primarily around the Iran war and Cuban humanitarian crises — to funnel followers into pump-and-dump cryptocurrency schemes. The network used purchased aged accounts, AI-generated fake personas, and mass cross-reposting to artificially inflate reach, culminating in the coordinated promotion of the $ORAMAMA token on Solana's PumpSwap on February 22, 2026, generating alleged six-figure on-chain profits. X suspended all 16 identified accounts by the evening of March 23, 2026.
avoid.net/fluid-instadapp→52/100[CAUTIONARY]Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.
avoid.net/sweat-economy-sweat-protocol→42/100[WARNING]Sweat Economy is a move-to-earn protocol on NEAR Protocol that rewards users with SWEAT tokens for physical activity, built on top of the Sweatcoin app which has over 120 million registered users. On April 29, 2026, the SWEAT token contract on NEAR was exploited via a Rust smart contract vulnerability, allowing an attacker to drain approximately 13.71 billion SWEAT tokens — roughly 65% of total supply — valued at approximately $3.5 million, within 30 seconds. The Sweat Foundation coordinated with MEXC exchange and Rhea Finance to freeze attacker funds and ultimately restored all external user balances, with a patched contract subsequently deployed.
avoid.net/operation-atlantic-approval-phishing-network→92/100[VERIFIED]Operation Atlantic was a week-long multinational law enforcement operation conducted in late March and early April 2026, co-hosted by the U.S. Secret Service, the UK National Crime Agency, the Ontario Provincial Police, and the Ontario Securities Commission. The operation targeted cryptocurrency approval phishing fraud networks spanning more than 30 countries, resulting in $12 million in stolen funds frozen, over 20,000 compromised wallet addresses identified, 120 scam domains disrupted, and $45 million in total fraud identified. No criminal arrests or indictments were publicly announced as part of this operation; its primary mandate was disruption, victim outreach, and asset freezing.
avoid.net/robert-dunlap-meta-1-coin-trust→0/100[CRITICAL]Robert Dunlap, 55, of Houston, Texas, operated Meta-1 Coin Trust from 2018 to 2023, raising more than $20 million from nearly 1,000 investors by falsely claiming a digital asset called 'Meta-1 Coin' was backed by $44 billion in gold and $1 billion in artwork. Dunlap fabricated audit documents and manipulated trading prices using automated bots. He was convicted by a federal jury in November 2025 on two counts of mail fraud and sentenced on April 17, 2026, to 23 years in federal prison by U.S. District Judge LaShonda A. Hunt in the Northern District of Illinois.
avoid.net/ambient-finance→58/100[CAUTIONARY]Ambient Finance (formerly CrocSwap, operated by Crocodile Labs) is a decentralized exchange protocol running its entire DEX inside a single smart contract, deployed on Ethereum and several Layer 2 networks. The project raised $6.5 million in a seed round in July 2023 from credible institutional investors including BlockTower Capital, Jane Street, and Circle Ventures. It has experienced two notable security incidents: a DNS hijacking attack in October 2024 that compromised its frontend, and an on-chain smart contract exploit in June 2026 that resulted in approximately $110,600 in losses.
avoid.net/basis-markets→2/100[CRITICAL]Basis Markets was a UK-based project that raised approximately $28 million from retail investors in late 2021 through NFT membership sales and a BASIS token offering, marketing itself as a decentralized algorithmic hedge fund offering delta-neutral arbitrage returns. The UK Serious Fraud Office (SFO) opened a formal investigation and, on 20 November 2025, arrested two men on suspicion of fraud and money laundering in what the SFO described as its first major cryptocurrency case. The project shut down in June 2022 citing proposed US regulatory changes, and on-chain analysis by independent researchers alleged that investor funds were routed directly to founders' personal wallets rather than a project treasury.
avoid.net/privvy-investments-nathan-fuller→2/100[CRITICAL]Privvy Investments LLC was a Texas-based cryptocurrency investment company operated by Nathan Fuller of Cypress, Texas, that the SEC alleges raised approximately $12.3 million from roughly 150 investors between October 2022 and mid-2024 using false claims about proprietary AI-powered trading bots. Fuller admitted in September 2025 Texas bankruptcy proceedings that the scheme was a Ponzi operation, and the SEC filed a civil complaint against him on May 28, 2026, in the U.S. District Court for the Southern District of Texas, alleging misappropriation of at least $6.2 million for personal use and $5.5 million in Ponzi-style payouts to earlier investors.
avoid.net/broox-bauer-axiom-insider-trading-ring→6/100[CRITICAL]Broox Bauer, a senior business development employee at Axiom Exchange, was publicly identified in February 2026 by on-chain investigator ZachXBT as the alleged orchestrator of an insider trading scheme running from early 2025. Bauer allegedly abused internal access to Axiom's customer support dashboard to extract private wallet data belonging to users and key opinion leaders, sharing that data with a small group to front-run trades. Axiom, a Y Combinator-backed Solana trading terminal that generated over $390 million in cumulative revenue, acknowledged the misconduct, terminated access to the relevant tools, and stated it would investigate and hold the responsible parties accountable.
avoid.net/volo-protocol→47/100[WARNING]Volo Protocol is a liquid staking and DeFi vaults platform built on the Sui blockchain, offering voloSUI (vSUI) as a liquid staking token and multi-asset yield vaults. In January 2024, it was acquired by NAVI Protocol, a leading Sui lending protocol. On April 22, 2026, Volo suffered a $3.5 million exploit targeting three isolated vaults holding WBTC, XAUm, and USDC; the team pledged to absorb all user losses and approximately $500,000 was frozen on-chain, while the root cause — attributed by security researchers to a compromised privileged operator key rather than a smart contract flaw — remained under investigation at time of writing.
avoid.net/token-of-power-top→4/100[CRITICAL]Token of Power (TOP) is an Ethereum-based ERC-20 governance token created in March 2021 as a financial art experiment built around fractionalized ownership of a MetaMask-themed NFT, with liquidity and governance managed through a Balancer V1 pool and an Aragon DAO. On June 9, 2026, the project suffered a catastrophic governance-takeover exploit in which an attacker acquired a majority of the token's 16,384-token supply, used the Aragon DAO's absence of timelock protections to create, vote on, and execute a malicious proposal in a single transaction, minted 10 billion new TOP tokens, and drained 944.2 WETH (approximately $1.58 million) from the Balancer V1 liquidity pool. Stolen funds were laundered through Tornado Cash and no official project response had been issued as of June 10, 2026.
avoid.net/letsbonk-fun→32/100[WARNING]LetsBonk.fun, later rebranded as Bonk.fun, is a Solana-based memecoin launchpad launched on April 25, 2025 by the BONK community in partnership with Raydium Protocol. The platform rose to capture over 78% of Solana launchpad market share at its mid-2025 peak before experiencing steep decline, and suffered a domain hijack and wallet-drainer attack in March 2026. The platform's permissionless token creation model, built-in multi-wallet bundler tooling, and community reports alleging the platform hosted 'KOL-backed bundled scams' present elevated risk for retail investors.
avoid.net/meteora-benjamin-chow→12/100[CRITICAL]Meteora is a Solana-based decentralized exchange and liquidity protocol that originated from Mercurial Finance in early 2023. Its co-founder Benjamin Chow resigned in February 2025 amid allegations of insider manipulation across at least 15 token launches, including M3M3, LIBRA, MELANIA, ENRON, and TRUST. Two separate federal class-action lawsuits filed in the Southern District of New York allege that Chow, Meteora, and co-defendants Kelsier Labs LLC collectively orchestrated pump-and-dump schemes causing at least $69 million in investor losses.
avoid.net/lab-token-vova-sadkov→4/100[CRITICAL]LAB is an AI-powered multi-chain trading terminal whose native token briefly reached a $6 billion fully diluted valuation in early June 2026 before collapsing more than 77% within hours. On-chain investigator ZachXBT alleges that insiders controlled approximately 95% of the token supply and coordinated with an unknown market maker across Bitget, Bybit, Binance, and OKX to engineer the price surge. Founder Vova Sadkov (UAE-based) and co-founder Mark X previously operated the abandoned Eesee (ESE) gamified NFT marketplace, which similarly left investors with significant losses after alleged vesting term changes at its token generation event.
avoid.net/apemars-aprz→4/100[CRITICAL]ApeMars (APRZ) was an ERC-20 meme token that raised $532,969.34 from 1,884 presale investors across 23 stages before listing on Uniswap on June 6, 2026. On June 7, 2026, the APRZ/WETH price collapsed 99.95% — from $0.00580 to $0.00000032 — in minutes across only 11 trades as ETH was removed from the Uniswap liquidity pool, consistent with a coordinated liquidity drain. The project's official X account was suspended simultaneously, no team statement has been issued as of the investigation date, and approximately $532K in raised presale funds remain unaccounted for.
avoid.net/syscoin-bridge→22/100[CRITICAL]Syscoin Bridge is the cross-chain bridge infrastructure connecting Syscoin's UTXO chain and its Network Enhanced Virtual Machine (NEVM) EVM-compatible layer. In June 2026, an attacker exploited a proof-validation parsing flaw in the bridge relay, minting approximately 5 billion unauthorized SYS tokens valued at roughly $10 million and inflating the circulating supply by an estimated 568 percent. The bridge was paused immediately and the attacker subsequently returned the funds following private whitehat negotiations, though the incident raised serious questions about audit coverage of the relay component.
avoid.net/verus-protocol-ethereum-bridge→20/100[CRITICAL]The Verus-Ethereum Bridge is a cross-chain infrastructure component enabling asset transfers between the Verus (VRSC) network and Ethereum. On May 18, 2026, the bridge was exploited for approximately $11.58 million through a business-logic validation flaw that allowed an attacker to withdraw far more value on the Ethereum side than was deposited on the Verus side. Following negotiations, the attacker returned approximately 75% of the stolen funds (4,052 ETH) in exchange for a 1,350 ETH bounty and an agreement to halt investigations.
avoid.net/bitget-exchange→27/100[WARNING]Bitget is a centralized cryptocurrency derivatives and spot exchange founded in 2018, currently ranked among the top five global exchanges by trading volume with a reported user base exceeding 120 million. Between April and May 2026, blockchain investigator ZachXBT published a series of on-chain investigations alleging that Bitget systematically enabled coordinated pump-and-dump schemes across at least four tokens — RAVE, RIVER, SIREN, and LAB — by allowing insiders to pre-position large holdings before engineered price pumps that erased billions in retail value. A separate incident in April 2025 involving a malfunctioning market-making bot on VOXEL/USDT futures resulted in over $100 million in estimated losses, forced account rollbacks, and drew comparisons to earlier exchange failures.
avoid.net/step-finance-treasury-theft-january-2026→10/100[CRITICAL]On January 31, 2026, Step Finance, a Solana-based portfolio tracking and DeFi analytics platform, suffered a treasury theft in which an attacker drained approximately 261,854 SOL (valued at roughly $27.3 million at the time) after compromising executive team devices and seizing staking authority over protocol wallets. The incident led to a 93% collapse in the STEP governance token price and ultimately forced the permanent shutdown of Step Finance and its affiliated projects SolanaFloor and Remora Markets by February 24, 2026.
avoid.net/zcash-orchard-counterfeiting-vulnerability→35/100[WARNING]A critical soundness bug in Zcash's Orchard shielded pool zero-knowledge proof circuit was publicly disclosed on June 5, 2026, after existing undetected for approximately four years since Orchard's May 2022 activation. The flaw, discovered by security researcher Taylor Hornby using the Anthropic Claude Opus 4.8 AI model, could have allowed a malicious actor to forge transactions and mint unlimited counterfeit ZEC within the shielded pool with no on-chain signature. An emergency soft fork (June 2) and subsequent NU6.2 hard fork (June 3) patched the circuit before public disclosure, but Zcash's inherent privacy properties make it cryptographically impossible to determine whether the vulnerability was exploited during its four-year exposure window, causing ZEC to fall approximately 38-50% on disclosure.
avoid.net/audia6→0/100[CRITICAL]AudiA6 was a professional cryptocurrency mixing and laundering service that operated from 2021 until its dismantlement on June 10, 2026, in a coordinated international law enforcement operation. The service processed approximately 10,333 Bitcoin — valued at roughly $389 million at the time of transactions — for ransomware groups, darknet market operators, and other cybercriminals, charging commissions of 3–10%. Two alleged operators, Ruslan Igorevich Tkachuk (Ukrainian, 37) and Alexander Vladimirovich Ledenev (Russian, 25), were arrested in Batumi, Georgia, and face U.S. federal charges in the Eastern District of Pennsylvania carrying up to 20 years in prison each.
avoid.net/lab-token→4/100[CRITICAL]LAB is a multi-chain AI trading terminal token that launched its TGE in October 2025 and surged over 350% to a $6 billion fully diluted valuation in early May 2026 before crashing more than 65%. On-chain investigator ZachXBT published findings alleging that insiders control approximately 95% of the token supply, that 100 million LAB tokens worth roughly $480 million were withdrawn from Bitget to 10 freshly created wallets within a 12-hour window, and that the team orchestrated a coordinated retail extraction scheme involving OTC discount deals, unilateral vesting extensions, unpaid marketing obligations, and coercive KOL agreements. No public denial or response has been issued by the project's founders.
avoid.net/rain-protocol→14/100[CRITICAL]Rain Protocol (RAIN) is a decentralized prediction market infrastructure protocol built on Arbitrum that reached approximately $8.8–9 billion in fully diluted valuation by early June 2026, positioning it briefly among the top 15 cryptocurrencies globally. On June 5, 2026, on-chain investigator ZachXBT published findings alleging that addresses linked to the RAIN team share transaction trails with wallets connected to the failed Data Ownership Protocol (DOP) and TOMI projects, both previously linked to Israeli entrepreneur Moshe Hogeg, who faces criminal fraud charges in Israel. ZachXBT characterized the token as a likely insider-controlled pump with 99.97% of circulating supply held by 81 wallets and offered a $100,000 bounty for documentation of centralized exchange market manipulation; Rain Protocol had not issued a public response as of the date of these reports.
avoid.net/humanity-protocol→18/100[CRITICAL]Humanity Protocol is a zero-knowledge Layer-2 blockchain project using palm-scan biometrics for decentralized identity verification, often described as a rival to Worldcoin. On June 8, 2026, an attacker compromised a director's laptop via a phishing email impersonating South Korean exchange Bithumb, stole private keys controlling bridge and proxy-admin contracts, drained approximately 141 million H tokens from Ethereum, and minted an additional 100-300 million H tokens on BNB Smart Chain, causing total losses estimated at $36 million and an 80-89% collapse in the H token price. Blockchain security firm Quantstamp attributed the attack to DPRK-linked threat actors based on malware signatures and Hancom certificate patterns; on-chain investigator ZachXBT initially alleged the incident may have been staged to benefit an active market maker, but later stated he could not confirm insider involvement.
avoid.net/piggybank-protocol→32/100[WARNING]PiggyBank Protocol is a Solana-based DeFi yield platform offering delta-neutral funding-rate arbitrage vaults across USDC, JitoSOL, and tokenized stock (xStocks) assets. On or around June 6, 2026 the protocol disclosed that a mid-cap basis trade involving locked LAB tokens had failed, producing NAV declines of approximately 15%, 12%, and 9% across its three active vaults. On-chain investigator ZachXBT publicly alleged that the protocol had exposed depositor funds to a token he characterized as a scam with over 95% insider-controlled supply, raising serious risk-management and disclosure concerns that remain unresolved as of the investigation date.
avoid.net/flooring-protocol→13/100[CRITICAL]Flooring Protocol (fp.io) is an Ethereum-based NFT fractionalization platform that converts non-fungible tokens into fungible micro-tokens (μTokens and fpTokens) pegged to collection floor prices. The protocol launched in October 2023, was exploited twice — once in December 2023 (~$1.6M stolen) and again in June 2026 (~$570K in NFTs rescued by a Yuga Labs white-hat team — and entered formal sunset mode in September 2025 after liquidity and organizational failures. At the time of the June 2026 incident, the protocol was effectively defunct with a TVL of approximately $9.51.
avoid.net/iggy-azalea-mother-memecoin→0/100[CRITICAL]MOTHER (ticker: MOTHER) is a Solana-based memecoin launched on May 28, 2024 by Australian rapper Iggy Azalea (legal name Amethyst Amelia Kelly). The token peaked at a market capitalization of approximately $136–200 million in mid-June 2024 before declining roughly 99.5% to approximately $1.3 million by May 2026. On May 5, 2026, plaintiff Kenneth Kolbrak filed a federal class action against Azalea in the U.S. District Court for the Southern District of New York, alleging she misled consumers about the token's real-world utility through promises regarding an online casino (MOTHERLAND), a telecommunications integration (Unreal Mobile), and a luxury marketplace (DreamVault) that allegedly were not delivered as represented; all claims in that suit are allegations and remain unadjudicated.
avoid.net/zcash-orchard-pool-counterfeiting-bug→62/100[CAUTIONARY]In May 2026, independent security researcher Taylor Hornby discovered a critical soundness vulnerability in the Zcash Orchard shielded pool's zero-knowledge proof circuit that had existed since the pool's launch in May 2022. The flaw — an under-constrained elliptic-curve multiplication gadget in the halo2_gadgets crate — could theoretically have allowed unlimited undetectable counterfeit ZEC creation within the Orchard pool, though it could not inflate total ZEC supply due to the turnstile mechanism. The Zcash Open Development Lab coordinated an emergency two-phase response within 50 hours: a soft fork on June 2 disabling Orchard transactions, followed by the NU6.2 hard fork on June 3 deploying the corrected circuit. No exploitation has been confirmed, though the privacy properties of the Orchard pool make definitive confirmation impossible. ZEC fell approximately 38% on public disclosure on June 5, 2026.
avoid.net/hyperfund-hyperverse→2/100[CRITICAL]HyperFund (also marketed as HyperVerse, HyperCapital, HyperNation, and HyperTech) was a cryptocurrency investment scheme that raised approximately $1.89 billion from global investors between June 2020 and November 2022 by promising daily passive returns of 0.5–1% backed by purported large-scale crypto mining operations. The U.S. Department of Justice and the Securities and Exchange Commission both filed charges in January 2024, alleging the scheme had no legitimate mining revenues and operated as a pyramid and Ponzi structure in which new investor deposits funded earlier investors' withdrawals. Co-founder Xue 'Sam' Lee remains at large following a temporary detention in Dubai; co-promoter Rodney 'Bitcoin Rodney' Burton is held without bail with trial scheduled for September 14, 2026; and co-promoter Brenda 'Bitcoin Beautee' Chunga has pleaded guilty and awaits sentencing.
avoid.net/evm-cross-chain-wallet-drain-campaign-june-2026→0/100[CRITICAL]Beginning approximately January 2, 2026, blockchain investigator ZachXBT flagged an active, automated campaign draining hundreds of wallets across at least a dozen EVM-compatible chains, with over $107,000 stolen in mostly sub-$2,000 increments consolidated into a single aggregation address (0xAc2e5153170278e24667a580baEa056ad8Bf9bFB). The root cause was not confirmed at the time of ZachXBT's initial disclosure; suspected vectors included token-approval abuse, malicious signature exploits, a fake-MetaMask phishing email campaign, and possible spillover from the Trust Wallet browser-extension supply-chain compromise of December 2025. This entry serves as a consumer-protection warning and on-chain address flag.
avoid.net/gnosis-pay-zodiac-delay-module-exploit→57/100[CAUTIONARY]On June 1, 2026, Gnosis Pay's Zodiac Delay Module — a third-party smart contract add-on designed to impose mandatory waiting periods on outgoing Safe transactions — was exploited via a signature-verification flaw in the Delay Modifier v1.1.0 and Roles Modifier v2. Blockchain security firm CertiK estimated losses at approximately $265,000 affecting 41 Gnosis Safes, with stolen funds partially bridged to Hyperliquid and converted to Monero. Gnosis co-founder Martin Köppelmann publicly pledged full reimbursement for all affected users, card services were restored for over 99% of users by June 7, and Safe core contracts were confirmed unaffected.
avoid.net/syscoin-bridge-exploit-june-2026→38/100[WARNING]On June 7, 2026, an attacker exploited a proof-validation parsing flaw in Syscoin's cross-chain bridge to mint approximately 5 billion unauthorized SYS tokens, representing roughly 568% of the pre-attack circulating supply and valued at approximately $9–10 million at the time. The Syscoin team paused the bridge, coordinated with exchanges to freeze tainted addresses, and subsequently recovered and permanently burned all 5 billion tokens after the attacker returned them following on-chain contact. A technical postmortem was published on June 15, 2026, and the bridge remained suspended pending final validation of the patch.
avoid.net/mass-ethereum-address-poisoning-wave-dec-2025-jan-2026→0/100[CRITICAL]A large-scale industrialized campaign of Ethereum address-poisoning attacks surged sharply following the December 3, 2025 Fusaka protocol upgrade, which reduced per-transaction gas fees by approximately 67% and made high-volume dust-transfer campaigns economically viable at unprecedented scale. Two high-profile victims suffered a combined loss of approximately $62.2 million between December 2025 and January 2026, with a single victim losing $49,999,950 in USDT on December 19, 2025. An independent academic study published by Carnegie Mellon University researchers (Tsuchiya et al., presented at USENIX Security 2025) quantified the broader campaign at 270 million on-chain poisoning attempts targeting 17 million wallets across Ethereum and BNB Smart Chain from July 2022 to June 2024, with confirmed losses of at least $83.8 million over that earlier study period.
avoid.net/crosscurve-formerly-eywa-bridge-exploit-feb-2026→12/100[CRITICAL]On February 1, 2026, CrossCurve — a cross-chain DEX and bridge protocol operating under the EYWA brand — suffered a critical exploit of its ReceiverAxelar bridge contract via a missing Axelar Gateway validation check. Approximately $1.4 million in liquid assets were confirmed stolen, while the total PortalV2 contract balance drained was approximately $3 million (including largely illiquid EYWA tokens). No funds were recovered as of the investigation date.
avoid.net/faris-ali-uk-crypto-home-invasion-ring→0/100[CRITICAL]Three Sheffield teenagers carried out an armed home-invasion robbery on June 18, 2024 at a flat in Hoxton, east London, stealing approximately £3.1 million (reported as $4.3M USD in some outlets) in cryptocurrency from a victim they had located using a misappropriated law-enforcement database. Blockchain investigator ZachXBT publicly identified the ringleader online as 'Faris Ali' in October 2024; Sheffield Crown Court proceedings name the ringleader as Faris Hassan. All three perpetrators pleaded guilty and were sentenced to a combined 16 years in youth detention at Sheffield Crown Court on November 7, 2025, with the stolen cryptocurrency recovered within 72 hours and returned to the victim.
avoid.net/fifa-world-cup-2026-crypto-scam-tokens→2/100[CRITICAL]A cluster of fraudulent crypto schemes exploiting the 2026 FIFA World Cup brand, comprising fake ticketing portals demanding cryptocurrency payment, fixed-match betting operations, and opportunistic memecoins with concentrated insider ownership. The FBI issued a formal public service announcement on May 27, 2026 listing 39 spoofed FIFA domains, and blockchain intelligence firm TRM Labs identified at least three active fraud operations linked to four cryptocurrency wallet addresses as of June 11, 2026. Victims are predominantly sports fans with limited prior crypto exposure who are unlikely to recognize on-chain red flags.
avoid.net/iranian-crypto-exchanges-ofac-designation-nobitex-wallex-bitpin-ramzinex-june-2026→0/100[CRITICAL]On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) added four Iranian cryptocurrency exchanges — Nobitex, Wallex, Bitpin, and Ramzinex — to the Specially Designated Nationals (SDN) list under counterterrorism and Iran financial-sector authorities, representing the Treasury Department's largest single enforcement action to date against Iran's digital asset economy. The four exchanges collectively handled approximately 78 percent of Iran's attributed 2025 crypto volume, totaling roughly $7.78 billion, and were alleged to have facilitated sanctions evasion, terrorist financing for the IRGC, and support for other U.S.-designated entities including Hamas. The action forms the third layer of a five-month OFAC enforcement campaign that began in January 2026 and has frozen nearly $500 million in regime-linked cryptocurrency.
avoid.net/truebit-oracle-exploit-january-2026→0/100[CRITICAL]On January 8, 2026, the Truebit Protocol smart contract on Ethereum was exploited via an integer overflow vulnerability in a legacy, unaudited Purchase contract (deployed circa 2021, compiled with Solidity v0.5.3), allowing an attacker to mint TRU tokens at near-zero cost and drain 8,535 ETH (approximately $26.2–26.6 million) from the bonding-curve reserve. The stolen funds were fully laundered through Tornado Cash by January 11, 2026, and no meaningful recovery has been reported. The incident caused TRU token to collapse approximately 99.9% within 24 hours, and the same primary attacker address was linked by PeckShield to a prior Sparkle Protocol exploit approximately 12 days earlier.
avoid.net/rhea-finance-exploit-april-2026→9/100[CRITICAL]On April 16, 2026, Rhea Finance — the leading DeFi hub on the NEAR blockchain, formed by the March 2025 merger of Ref Finance and Burrow Finance — was exploited for an estimated $18.4 million (initially reported as $7.6 million) via a two-phase attack combining fake token pool seeding with a slippage-protection bypass in its margin trading module. Approximately $9 million in assets was subsequently recovered or frozen, including $3.291 million USDT frozen by Tether, leaving an estimated $8–9 million outstanding as of late April 2026.
avoid.net/tudou-guarantee-telegram-marketplace→0/100[CRITICAL]Tudou Guarantee was a Chinese-language, Telegram-based illicit marketplace that processed over $12 billion in USDT transactions, making it the third-largest such marketplace in recorded history. Operated as an escrow and guarantee service for vendors selling stolen data, money laundering services, scam infrastructure, and AI deepfake tools to pig-butchering and other fraud operators, it emerged as the primary successor to Huione Guarantee following that platform's May 2025 shutdown. Tudou ceased public Telegram transactions in January 2026 following the arrest and extradition of Prince Group chairman Chen Zhi to China.
avoid.net/lazarus-group-graphalgo-fake-recruiter-npm-pypi-campaign→0/100[CRITICAL]The 'graphalgo' campaign is a North Korean state-sponsored software supply-chain operation attributed to the Lazarus Group, active since at least May 2025 and publicly disclosed in February 2026. Threat actors impersonate cryptocurrency-sector recruiters using fabricated companies — most notably 'Veltrix Capital' — to deliver coding-assessment repositories seeded with malicious npm and PyPI packages that install a remote-access trojan (RAT) targeting developer systems and cryptocurrency wallets. By April 2026 the campaign had respawned under new personas including 'Blockmerce' and 'Bridgers Finance', with operatives registering a real U.S. LLC to enhance credibility.
avoid.net/zedcex-zedxion-babak-morteza-zanjani-irgc-linked-exchanges→0/100[CRITICAL]Zedcex Exchange Ltd. and Zedxion Exchange Ltd. are two UK-registered cryptocurrency exchanges designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on January 30, 2026, in the first-ever U.S. sanctions action specifically targeting digital asset exchanges linked to Iran's Islamic Revolutionary Guard Corps (IRGC). On-chain analysis by TRM Labs identified approximately $1 billion in IRGC-associated flows through the two platforms between 2023 and 2025, routed almost exclusively in USDT on the TRON blockchain. Both entities are connected to Babak Morteza Zanjani, a previously OFAC-sanctioned Iranian financier convicted of embezzling billions from Iran's National Oil Company whose death sentence was commuted in 2024.
avoid.net/resolv-usr-stablecoin-minting-exploit-march-2026→2/100[CRITICAL]On March 22, 2026, an attacker compromised Resolv Labs' AWS Key Management Service (KMS) infrastructure to steal the SERVICE_ROLE private key controlling the USR minting contract. Using this key, the attacker deposited approximately $100,000-$200,000 in USDC across two transactions and minted approximately 80 million unbacked USR tokens at a 400-500x over-mint ratio, ultimately extracting roughly $23-$25 million in ETH. The exploit crashed USR's dollar peg by approximately 70-80% within 17 minutes, created functional insolvency for the Resolv protocol ($95M assets vs $173M liabilities), and spread cascading losses across at least 15 Morpho vaults and Fluid/Instadapp lending markets. The Resolv Foundation subsequently launched a tiered compensation plan in late May 2026 and reported completing over $77 million in phase-one redemptions by late May 2026.
avoid.net/yieldblox-stellar-oracle-manipulation-exploit-feb-2026→0/100[CRITICAL]On February 22, 2026, the YieldBlox DAO-managed lending pool on Stellar's Blend V2 protocol was drained of approximately $10.97 million via a thin-liquidity oracle manipulation attack targeting the USTRY/USDC pair on the Stellar DEX. An attacker inflated the Reflector VWAP oracle price of USTRY from approximately $1.05 to $107 with a single low-volume trade costing roughly $5, then used overvalued USTRY collateral to borrow the pool's entire XLM and USDC reserves. Stellar Tier-1 validators froze approximately 48 million XLM (~$7.5 million) before the funds could be fully bridged out; the protocol developer Script3 committed to full depositor compensation and the attacker rejected a 10% white-hat bounty offer.
avoid.net/fake-uniswap-v4-airdrop-phishing-network-2026→0/100[CRITICAL]A persistent, multi-vector phishing network impersonating Uniswap across fake airdrops, cloned interfaces, and fraudulent Google Search advertisements has operated across multiple campaigns since at least 2022. The most recent and documented wave, active from late 2025 through May 2026, uses drainer-as-a-service tooling — primarily the AngelFerno kit — to trick victims into signing malicious wallet-approval transactions via Google Ads placed above legitimate Uniswap search results. Verified aggregate losses across the discrete 2025–2026 Google Ads campaign episodes reach approximately $1.63 million; broader industry-wide wallet drainer losses in 2024 reached $494 million across all protocols according to Scam Sniffer, but that figure is not attributable to Uniswap impersonation alone.
avoid.net/vanilla-drainer-daas→0/100[CRITICAL]Vanilla Drainer is a Drainer-as-a-Service (DaaS) criminal platform first documented in October 2024 that provides phishing kits and malicious smart contract infrastructure to affiliate fraudsters in exchange for a 15-20% commission on stolen proceeds. Blockchain investigator Darkbit attributed at least $5.27 million in cryptocurrency thefts to the service within a three-week window in mid-2025, and the Security Alliance (SEAL) identified Vanilla Drainer as one of the two primary drainer families deployed via Google Ads malvertising campaigns that stole more than $1.27 million between March 13-30, 2026. No operators have been publicly identified and no law enforcement actions against the service have been confirmed as of mid-2026.
avoid.net/chen-zhi-prince-holding-group→0/100[CRITICAL]Chen Zhi (also known as 'Vincent'), age 37, is the founder and chairman of Prince Holding Group, a Cambodia-based multinational conglomerate indicted in October 2025 by a federal grand jury in the Eastern District of New York (EDNY) for operating forced-labor cryptocurrency fraud compounds across Cambodia. The U.S. Department of Justice filed a civil forfeiture action for approximately 127,271 BTC (valued at approximately $15 billion), the largest forfeiture action in DOJ history. Chen Zhi was arrested on January 6, 2026 in Cambodia and extradited to China; his Cambodian citizenship was revoked prior to extradition.
avoid.net/mach-o-man-lazarus-chollima-macos-malware→0/100[CRITICAL]Mach-O Man is a four-stage macOS malware kit attributed to North Korea's Lazarus Group (Chollima division), publicly disclosed in April 2026 by researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform. The campaign uses ClickFix social engineering — delivering fake meeting invitations via Telegram — to trick cryptocurrency and fintech executives into executing a terminal command that deploys a modular toolkit capable of stealing macOS Keychain secrets, browser credentials, session cookies, and crypto wallet extension data. Security researchers have linked the same threat actor cluster to over $575 million stolen from Drift Protocol and KelpDAO in April 2026 alone, and Lazarus Group's cumulative cryptocurrency theft since 2017 is estimated to exceed $7.3 billion.
avoid.net/apyx-finance→33/100[WARNING]Apyx Finance is a DeFi protocol that issues apxUSD, a synthetic dollar stablecoin backed primarily by preferred equity shares of digital asset treasury companies, most notably Strategy's STRC preferred stock, rather than by fiat or crypto-native collateral. On June 4, 2026, apxUSD fell to approximately $0.93 during a Bitcoin drawdown that pushed STRC below its $100 par value, a roughly 7% deviation from peg. The protocol characterized this episode as expected behavior intrinsic to its equity-backed design, a framing that drew skepticism from market participants who noted structural risks including liquidity mismatches between 24/7 crypto markets and exchange-hours equity trading, leverage stacking in downstream DeFi venues, and the protocol's exclusion of US and EU persons from participation.
avoid.net/kok-an-crown-resorts-anco-brothers→2/100[CRITICAL]Kok An (born Phu Kok An, 1954) is a Sino-Cambodian senator, businessman, and one of Cambodia's wealthiest individuals, whose flagship companies Crown Resorts and Anco Brothers were designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on April 23, 2026, along with 28 other individuals and entities, for allegedly operating and protecting a network of scam compounds that coerce human-trafficking victims into perpetrating 'pig butchering' crypto-investment fraud against American citizens. The designations, made under executive orders targeting significant malicious cyber-enabled activities, freeze all U.S.-linked assets and prohibit Americans from transacting with any designated party. Parallel law enforcement actions by Thailand, including a July 2025 Thai Criminal Court arrest warrant and raids seizing assets worth over 1.17 billion baht, and a November 2025 Thai revocation of Kok An's and his three children's fraudulently obtained Thai nationality, reflect a sustained international enforcement campaign against his network.
avoid.net/bit-com→42/100[WARNING]Bit.com was a cryptocurrency derivatives and spot exchange launched in August 2020 by Matrixport, a Singapore-based digital asset firm founded by Bitmain co-founder Jihan Wu. On December 27, 2025, the exchange announced a phased wind-down under the label 'business restructuring,' with spot trading ceasing January 31, 2026, a backup withdrawal-only station active through March 31, 2026, and post-deadline asset recovery requiring individual customer-service requests. No regulatory action, security breach, or insolvency has been publicly reported as the cause; the shutdown appears consistent with a broader strategic consolidation by Matrixport, which rebranded as 'BIT' on March 20, 2026.
avoid.net/probit-global→23/100[CRITICAL]ProBit Global was a South Korea-founded centralized cryptocurrency exchange that operated from 2018 until it permanently terminated all services by April 1, 2026. The shutdown followed an inability or unwillingness to obtain MiCA licensing for EU/EEA users and a stated broader regulatory and restructuring rationale for global operations. The wind-down included a controversial abandoned-funds clause under which assets not withdrawn by April 1, 2026 were deemed permanently lost, as well as a monthly administrative fee of up to 10% of balances during the grace period, raising significant consumer-protection concerns.
avoid.net/zondacrypto→0/100[CRITICAL]Zondacrypto, formerly known as BitBay and Zonda, was once described as Poland's largest cryptocurrency exchange, serving over 1.3 million users across Central and Eastern Europe. Beginning in December 2025, the platform experienced a severe withdrawal freeze that escalated into a full collapse by April 2026, with Polish prosecutors estimating losses of at least 350 million zloty (approximately $96 million USD) affecting an estimated 30,000 or more users. The crisis has prompted criminal investigations in Poland, a partial operating license suspension by Estonian regulators, the resignation of the company's entire supervisory board, and the reported flight of CEO Przemyslaw Kral to Israel, where his dual citizenship complicates extradition.
avoid.net/mantra-om-token→18/100[CRITICAL]MANTRA is a Cosmos SDK-based Layer 1 blockchain focused on real-world asset (RWA) tokenization, co-founded by John Patrick Mullin. Its native OM token collapsed approximately 90% in roughly one hour on April 13, 2025, falling from around $6.30 to under $0.50 and wiping out an estimated $5–6 billion in market capitalization. The causes remain disputed: the project team attributed the crash to reckless forced liquidations by centralized exchanges, while on-chain analysts, OKX, and critics alleged coordinated insider selling, supply manipulation, and artificially inflated liquidity metrics.
avoid.net/yelo-yelotree→0/100[CRITICAL]Yelo, known online as @yelotree, is a crypto key opinion leader (KOL) and former professional Fortnite esports player with approximately 180,000 Twitter followers who also operated a luxury car rental business in Miami. As of May 2026, Yelo faces federal criminal charges alleging he laundered funds stolen from cryptocurrency holders through that rental business, with a potential sentence of up to 30 years. Separately, Yelo participated in undisclosed paid promotion of the Sharpei memecoin on Solana in October 2024, which subsequently suffered a documented rug pull that erased 96% of its market value.
avoid.net/goliath-ventures→2/100[CRITICAL]Goliath Ventures (formerly Gen-Z Venture Firm) was a Florida-based cryptocurrency investment firm whose CEO, Christopher Alexander Delgado, 34, of Apopka, Florida, was arrested on February 24, 2026 on federal charges of wire fraud and money laundering. Federal prosecutors allege Delgado operated the company as a Ponzi scheme from January 2023 through January 2026, raising at least $328 million from more than 2,000 investors under false promises of 3-8% monthly returns through cryptocurrency liquidity pools, while only approximately $1.5 million was verifiably placed into liquidity pools. The firm filed for Chapter 11 bankruptcy in March 2026, and class action lawsuits have been filed against multiple third parties including JPMorgan Chase, Bank of America, Coinbase, law firm Alston & Bird, and Broad Financial for allegedly enabling the scheme.
avoid.net/granary-finance-grain→42/100[WARNING]Granary Finance was a decentralized, non-custodial lending and borrowing protocol forked from Aave V2, built by Byte Masons and an anonymous developer known as Fantom Menace, launching on Fantom in March 2022 before expanding to eight chains. The protocol raised over $5 million USDC via a community liquidity generation event in March 2023 and introduced the GRAIN governance token, but its TVL collapsed from a peak of approximately $60 million to under $200,000. By early 2025, the team announced the full withdrawal and discontinuation of Granary Finance across all chains, with GRAIN and OATH token holders migrated to the successor platform Cod3x (CDX). No regulatory actions, rug-pull allegations, or direct hacks of Granary contracts were documented; key risks include near-total value decline, deeply pseudonymous founding team, and protocol end-of-life.
avoid.net/catfi-memecoin→0/100[CRITICAL]CATFI is a Solana-based memecoin launched in early 2025 via the Pump.fun launchpad. South Korean prosecutors charged five individuals, including a ringleader known online as 'Eth Father' (surname Park), with orchestrating a rug pull that inflated the token's price approximately 1,001-fold within 26 hours before draining liquidity and abandoning the project. This case represents South Korea's first criminal prosecution of a decentralized-exchange rug pull under the Virtual Asset User Protection Act.
avoid.net/uniblock→64/100[CAUTIONARY]Uniblock is a Canadian Web3 infrastructure company founded in 2022 that provides a unified, multi-chain API aggregation platform for blockchain developers, connecting over 300 blockchains and 55 data providers through a single interface with patented auto-routing technology. The company is venture-backed with C$7.5 million in total funding from institutional investors including SBI Ven Capital, AllianceDAO, NGC Ventures, Alchemy, and MoonPay. No regulatory actions, fraud allegations, or significant security incidents have been identified; risk factors are principally commercial and operational rather than conduct-related.
avoid.net/rathnakishore-giri→0/100[CRITICAL]Rathnakishore Giri, also known as 'Ravi' Giri, is a 31-year-old Ohio investment manager convicted of wire fraud for orchestrating a Bitcoin-derivatives Ponzi scheme that raised over $10 million from at least 150 investors between 2019 and 2022. Operating through two entities — NBD Eidetic Capital, LLC and SR Private Equity, LLC — he falsely promised guaranteed, risk-free returns while using new investor funds to repay earlier ones and diverting proceeds to fund a lavish personal lifestyle. On May 18, 2026, he was sentenced to nine years in federal prison after an aggravating factor emerged: following his October 2024 guilty plea, and while on pretrial release, he continued soliciting new cryptocurrency investors, causing additional harm and prompting an amended plea agreement.
avoid.net/ramzinex→2/100[CRITICAL]Ramzinex (legal name: Mubadala Ramzinex; also registered as Ramzineh Electronic Commerce Innovation Company) is an Iranian cryptocurrency exchange founded in 2018 and headquartered in Tehran. On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Ramzinex under Executive Order 13902, citing facilitation of transactions linked to the Islamic Revolutionary Guard Corps (IRGC), a government-backed Iranian financial institution, and sanctions evasion. The designation was part of the Trump administration's broader 'Economic Fury' campaign, which simultaneously sanctioned three other major Iranian exchanges: Nobitex, Wallex, and Bitpin.
avoid.net/bitpin→0/100[CRITICAL]Bitpin (legal name: Nooyan Bitpin, also known as Sana Ayman Mubadala) is an Iranian cryptocurrency exchange founded in 2020 and headquartered in the Anzali Free Zone, Gilan, Iran. On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Bitpin on the Specially Designated Nationals (SDN) list under Executive Orders 13224 and 13902, citing IRGC-linked transactions, sanctions evasion, and investors with alleged ties to circumventing U.S. restrictions. Bitpin accounted for approximately 10% of Iranian digital asset inflows in 2025 and processed an estimated USD 821 million in volume that year, making it Iran's third-largest exchange by that metric among the four simultaneously designated platforms.
avoid.net/dxsale→4/100[CRITICAL]DxSale is a decentralized token launchpad and liquidity-locking platform launched in August 2020, originally on Ethereum and later expanded to BNB Chain and other EVM networks. On May 28, 2026, a hidden backdoor in legacy BNB Chain liquidity locker contracts was exploited to drain approximately $7.3 million from more than 1,400 LP positions locked as far back as 2021. On-chain analysis identified a 269-day pre-exploit ownership transfer chain passing through approximately 80 wallets, with indicators strongly suggesting insider involvement by a current or former team member.
avoid.net/shunda-scam-compound→0/100[CRITICAL]Shunda Park was a large-scale cryptocurrency investment fraud compound operated in Min Let Pan, Myanmar (Burma), active from at least January 2025 until its seizure by the Karen National Liberation Army (KNU/KNLA) in November 2025. The compound ran pig-butchering scams targeting victims across 30 or more countries, using trafficked workers held under threat of violence. In April 2026, the U.S. Department of Justice charged two Chinese nationals — Huang Xingshan and Jiang Wen Jie — with wire fraud conspiracy for managing the compound, as part of a coordinated international enforcement action that resulted in 276 arrests, the dismantling of nine scam centers, and the restraint of over $701 million in cryptocurrency.
avoid.net/edgex-edge-token→22/100[CRITICAL]edgeX is a decentralized perpetual futures exchange incubated by Amber Group and launched on mainnet in August 2024, with its native EDGE token generating at Token Generation Event on March 31, 2026. On June 2, 2026, the EDGE token crashed approximately 77% in under 60 seconds, erasing over $220 million in market value; edgeX attributed the event to an unidentified external party, while on-chain investigator ZachXBT alleged that a small group of insiders controlled the majority of the 1 billion token supply through a thin-float structure. A self-commissioned investigation found no team misconduct, a conclusion ZachXBT publicly derided as self-serving, and the project subsequently faced scrutiny for declining to disclose market-maker agreements or insider token allocations.
avoid.net/bitrefill→52/100[CAUTIONARY]Bitrefill is a Stockholm-based cryptocurrency e-commerce platform founded in 2014 that allows users to purchase digital gift cards, eSIMs, and mobile top-ups using Bitcoin and other cryptocurrencies across more than 100 countries. On March 1, 2026, Bitrefill suffered a significant cyberattack attributed to the North Korea-linked Lazarus Group (Bluenoroff subunit), in which attackers compromised an employee laptop, escalated access via legacy credentials, drained hot wallets, and exposed approximately 18,500 customer purchase records. Bitrefill stated it would cover all financial losses from operational capital and characterized this as the platform's first major security incident in over a decade of operation.
avoid.net/alephium→34/100[WARNING]Alephium is a Swiss-founded Proof-of-Work Layer-1 blockchain launched November 8, 2021, featuring sharded smart contracts and the Proof-of-Less-Work consensus mechanism. On May 29-30, 2026, its TokenBridge was exploited for approximately $815,000 in approximately seven minutes via an off-chain backend vulnerability that allowed forged guardian messages to authorize unauthorized transfers and the minting of 13.76 million unbacked wrapped ALPH tokens. The team took the bridge offline, burned the unauthorized tokens, and committed to full user compensation.
avoid.net/unicoin→3/100[CRITICAL]Unicoin, Inc. is a New York City-based cryptocurrency company that launched the Unicoin token in February 2022, promoting it as an asset-backed, dividend-paying digital asset tied to the Unicorn Hunters investment television series. On May 20, 2025, the U.S. Securities and Exchange Commission filed a civil fraud complaint against the company and three senior executives in the Southern District of New York, alleging they defrauded more than 5,000 investors through false claims that the token was backed by billions of dollars of real estate and pre-IPO equity interests when those assets were worth a fraction of the stated values. The case remains pending as of mid-2026, with Unicoin having filed a motion to dismiss in August 2025.
avoid.net/thorchain→52/100[CAUTIONARY]THORChain is a decentralized cross-chain liquidity protocol built on the Cosmos SDK that enables native asset swaps across major blockchains without wrapped tokens. The protocol has suffered at least six significant security incidents since 2021, including a May 15, 2026 exploit in which a malicious validator node exploited a GG20 threshold signature scheme vulnerability to drain approximately $10.7–10.8 million across nine chains. THORChain has also faced documented use by the North Korean Lazarus Group as a primary money laundering channel, a $200 million insolvency crisis in early 2025 requiring a debt-to-equity restructuring, and ongoing questions about its permissionless design and unwillingness to block illicit flows.
avoid.net/marlon-ferro-gothferrari→2/100[CRITICAL]Marlon Ferro, 20, of Santa Ana, California, known online as 'GothFerrari,' was sentenced on May 6, 2026 to 78 months in federal prison for his role as a physical burglar in a multi-state cryptocurrency theft enterprise that stole over $263 million between October 2023 and March 2025. Ferro pleaded guilty on October 17, 2025 to one count of conspiracy to participate in a racketeer influenced and corrupt organization (RICO) and was ordered to pay $2.5 million in restitution and serve three years of supervised release.
avoid.net/catfi→2/100[CRITICAL]CATFI is a Solana-based meme coin launched in early 2025 via Pump.fun that was the subject of South Korea's first criminal indictment for a decentralized exchange rug pull. Five suspects, including alleged ringleader Park (alias 'Eth Father'), were indicted on May 27, 2026 by the Seoul Southern District Prosecutors' Office under the Virtual Asset User Protection Act after allegedly engineering a 1,001-fold price pump within 26 hours then draining all liquidity, leaving 256 investors with approximately 900 million won (~$650,000 USD) in losses. The case is legally significant as the first application of South Korea's unfair-trading statutes to on-chain DEX conduct without a centralized platform intermediary.
avoid.net/axiom-trading→38/100[WARNING]Axiom Trading (axiom.trade) is a Y Combinator Winter 2025-backed Solana trading terminal that generated over $390 million in revenue since its January 2025 launch. In February 2026, blockchain investigator ZachXBT published a report alleging that senior business development employee Broox Bauer and associates systematically abused internal customer support tools to access private user wallet data and front-run customer trades for more than ten months, with alleged profits exceeding $400,000. Axiom removed access to the implicated tools and stated it was investigating, but no public disclosure of disciplinary or legal outcomes had been made as of June 2026.
avoid.net/layerzero→52/100[CAUTIONARY]LayerZero is an omnichain messaging protocol developed by LayerZero Labs that enables cross-chain communication across 90+ blockchains. On April 18, 2026, a $292 million exploit of the KelpDAO rsETH bridge — the largest DeFi hack of 2026 — exposed a critical single-point-of-failure in the protocol's Decentralized Verifier Network (DVN) configuration, attributed by LayerZero to North Korea's TraderTraitor (Lazarus Group). LayerZero initially blamed KelpDAO for the configuration before reversing course in May 2026 and admitting fault, triggering a mass client exodus exceeding $1 billion in migrated assets.
avoid.net/alephium-bridge→18/100[CRITICAL]The Alephium TokenBridge is a Wormhole-fork cross-chain bridge linking the Alephium blockchain to Ethereum and BNB Chain. On May 30, 2026, the bridge was exploited for approximately $815,000 in locked assets, and 13.76 million unbacked wrapped ALPH tokens were minted on Ethereum; the attack completed in roughly seven minutes. Alephium has taken the bridge offline, pledged user compensation, and executed a partial governance burn of fraudulently minted tokens, but the underlying root cause — described by the team as an off-chain backend vulnerability — remains disputed against earlier reports of direct guardian key compromise.
avoid.net/tesseradao→0/100[CRITICAL]TesseraDAO is a BNB Chain project whose governance token TSR was the subject of a severe exploit on June 1, 2026, in which an attacker minted 99 million unauthorized TSR tokens and dumped them for approximately $2.5 million USDT, causing a 99% price collapse within hours. Stolen proceeds were bridged to Ethereum and laundered via Tornado Cash, with 1,285.5 ETH confirmed passed through the mixer. Security analysts noted that minting privileges were controlled exclusively by deployer-related addresses, raising questions about whether the incident constituted an external hack or an insider compromise.
avoid.net/edgex-exchange→28/100[WARNING]edgeX Exchange is a StarkEx-powered perpetual futures DEX incubated by Amber Group, which launched its EDGE token on March 31, 2026. On June 1, 2026, the EDGE token collapsed approximately 70–77% within hours, erasing over $220 million in market capitalization and triggering roughly $2.81 million in liquidations. The team attributed the crash to deliberate external market manipulation, while on-chain investigator ZachXBT publicly alleged insider supply control and demanded disclosure of market-maker agreements — allegations that remain publicly unanswered as of June 3, 2026.
avoid.net/gnosis-pay→42/100[WARNING]Gnosis Pay is a self-custodial Visa debit card platform launched in 2023 that allows users to spend stablecoins such as EURe directly from Safe smart-contract wallets at over 80 million merchants globally. On June 1, 2026, an active exploit was discovered targeting a vulnerability in the Zodiac Delay Modifier v1.1.0 and Roles Modifier v2 modules used by Gnosis Pay, allowing attackers to bypass the platform's built-in three-minute transaction delay protection and drain funds from affected Safe wallets. Gnosis co-founder Martin Köppelmann committed to covering all user losses, and a phased service restoration with new card-linked Safe accounts was announced for affected users as of June 2, 2026.
avoid.net/geoffrey-woo→32/100[WARNING]Geoffrey Woo is an American entrepreneur and venture capitalist who co-founded Anti Fund with Jake Paul in 2021 and serves as chairman of Ketone-IQ. In February 2026, Woo launched an AI-themed memecoin called AntiHunter (ANTIHUNTER) on the Base blockchain and publicly claimed it carried '0% rug pull risk' because he was already wealthy. On-chain investigator ZachXBT challenged the claim, citing the Paul brothers' documented history of five failed crypto projects — all down 99%+ from peak — and identifying three alleged token sales by Woo's wallet that appeared to contradict his stated promise to pre-announce any insider transactions. As of June 2026, ANTIHUNTER trades approximately 99%+ below its February 2026 all-time high, consistent with ZachXBT's expectations.
avoid.net/undisclosed-kol-paid-promotion-network-2025→12/100[CRITICAL]On September 1, 2025, blockchain investigator ZachXBT published a leaked spreadsheet documenting over 200 crypto influencers (key opinion leaders, or KOLs) approached to promote a token campaign, with more than 160 confirmed to have accepted payments ranging from $50 to $60,000 per post via the Solana network. Of those 160+, fewer than five disclosed the promotional posts as paid advertisements — a compliance rate under 3% — in apparent violation of U.S. Federal Trade Commission Endorsement Guides and, where promoted assets qualify as securities, Section 17(b) of the Securities Act of 1933. The sponsoring project was later identified as AI memecoin platform Memenetic, which publicly acknowledged the payments.
avoid.net/google-coin-fake-gemini-ai-chatbot-presale-scam→2/100[CRITICAL]In February 2026, Malwarebytes researcher Stefan Dasic documented a live fraudulent cryptocurrency presale site promoting a non-existent token called 'Google Coin.' The operation deployed a custom AI chatbot impersonating Google's Gemini assistant — using its sparkle icon, green 'Online' indicator, and name — to deliver scripted investment pitches, fabricated institutional endorsements from OpenAI, Binance, Coinbase, Squarespace, and SpaceX, and personalized return projections (e.g. $395 presale investment projected to become $2,755 at listing). Victims were directed to send irreversible cryptocurrency payments to six wallets spanning Bitcoin, Ethereum, Solana, TRON, and XRP Ledger. Google has never issued a cryptocurrency; the token, the chatbot persona, and all associated endorsements were entirely fabricated.
avoid.net/elizaos-ai16z-eliza-labs→28/100[WARNING]ElizaOS (formerly ai16z) is an open-source AI agent framework developed by Eliza Labs and launched on Solana in October 2024. The project reached a $2.6 billion token market cap in January 2025 before collapsing more than 99% amid allegations of unauthorized brand misappropriation from Andreessen Horowitz, disputed claims about the autonomy of its marketed AI agent, and a disputed token migration in late 2025 that critics alleged diluted retail holders. As of April 2026 a federal class action lawsuit (SDNY case 1:26-cv-3238) is pending against Eliza Labs, founder Shaw Walters, co-defendant Sebastian Quinn-Watson, and AI16Z DAO.
avoid.net/cls-global-zm-quant→4/100[CRITICAL]CLS Global FZC LLC (UAE) and ZM Quant Investment Ltd (British Virgin Islands) are crypto market-making firms charged in October 2024 as part of DOJ Operation Token Mirrors, an FBI undercover sting that created a fake token called NexFundAI to expose market-manipulation-as-a-service. Both firms are alleged to have generated billions of dollars in artificial trading volume through algorithmic wash trading on behalf of token promoters. CLS Global pleaded guilty to criminal charges in January 2025 and was sentenced to pay $428,059 in April 2025; parallel DOJ criminal proceedings against ZM Quant (case 1:24-cr-10187) remain on record as of June 2026. The SEC voluntarily dismissed its civil enforcement actions against both entities on March 31, 2026, reflecting a policy shift under the current administration, though those dismissals do not constitute a finding of innocence and do not affect the DOJ criminal proceedings.
avoid.net/dprk-it-worker-network-overseas-scheme→0/100[CRITICAL]The DPRK IT Worker Network is a state-directed, multi-year operation run by the North Korean government that places thousands of fraudulently credentialed software developers inside U.S. and global technology and crypto companies using stolen identities, fake personas, and U.S.-based facilitators. Workers generate hundreds of millions of dollars annually in illicit wages funneled back to Pyongyang to fund weapons of mass destruction and ballistic missile programs, and have escalated to data theft and extortion. The operation has drawn DOJ indictments of dozens of individuals across multiple enforcement waves (2024–2026), OFAC sanctions designating front companies and facilitators in China, Vietnam, Laos, Russia, and Spain, and FBI warnings to private industry.
avoid.net/citrine-sleet-applejeus→0/100[CRITICAL]Citrine Sleet (also tracked as AppleJeus, Gleaming Pisces, UNC4736, and Labyrinth Chollima) is a North Korean state-sponsored threat cluster attributed to Bureau 121 of the Reconnaissance General Bureau (RGB), active since at least 2018. The group specializes in financially motivated cyberattacks against cryptocurrency exchanges, DeFi protocols, and developer toolchains, deploying trojanized trading applications, supply chain compromises, and zero-day exploits to steal digital assets. Chainalysis estimates DPRK-linked actors have stolen at least $6.75 billion in cryptocurrency since 2016, with Citrine Sleet/UNC4736 operations accounting for multiple hundred-million-dollar individual incidents including the April 2026 Drift Protocol exploit ($285 million) and the October 2024 Radiant Capital breach ($50 million).
avoid.net/tradertraitor-unc4899→0/100[CRITICAL]TraderTraitor (also tracked as UNC4899, Jade Sleet, Slow Pisces, and PUKCHONG) is a North Korean state-sponsored cyber threat cluster operating under the Reconnaissance General Bureau (RGB), formally designated by the FBI, CISA, and U.S. Treasury as responsible for stealing billions of dollars in cryptocurrency from blockchain companies, exchanges, and developers since at least 2020. The cluster is most prominently attributed to the February 2025 Bybit heist — the largest cryptocurrency theft in history at approximately $1.5 billion — as well as the May 2024 DMM Bitcoin theft ($308 million), the July 2023 JumpCloud supply chain attack, and the April 2022 Ronin Network compromise ($620 million). Chainalysis estimates North Korean actors, dominated by TraderTraitor operations, stole $2.02 billion in 2025 alone, pushing their all-time attributed total to approximately $6.75 billion since 2017.
avoid.net/korea-mangyongdae-computer-technology-company→2/100[CRITICAL]Korea Mangyongdae Computer Technology Company (KMCTC) is a North Korean state-linked IT firm sanctioned by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on November 4, 2025, for operating overseas IT worker delegations in China and using Chinese nationals as banking proxies to launder proceeds from fraudulent employment and cybercrime schemes. The company is operated under the MAEI 607 Management Office, which connects it to the DPRK's military-industrial apparatus, and its IT workers are alleged to have generated hundreds of millions of dollars annually for the North Korean regime's weapons programs. KMCTC and its president, U Yong Su, are designated on the U.S. SDN list under Executive Order 13810.
avoid.net/cheil-credit-bank→0/100[CRITICAL]Cheil Credit Bank, also known as First Credit Bank and formerly as Kyongyong Credit Bank, is a North Korean state-controlled financial institution headquartered in Pyongyang with representative offices in Beijing, Shenyang, and Shanghai. First designated by OFAC in September 2017 under Executive Order 13810 for operating in North Korea's financial services sector, the bank was dramatically re-expanded on November 4, 2025, when OFAC added 53 cryptocurrency addresses to its Specially Designated Nationals listing, linking it to over $12.7 million in USDT-TRC20 flows between June 2023 and May 2025 — funds attributed primarily to DPRK overseas IT workers and cybercrime proceeds destined for the regime's weapons programs.
avoid.net/amnokgang-technology-development-company→0/100[CRITICAL]Amnokgang Technology Development Company is a North Korean state-controlled IT firm established in 1982 and headquartered in Pyongyang. The U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned it on March 12, 2026, for managing overseas DPRK IT worker delegations that allegedly generated nearly $800 million in illicit revenue in 2024 to fund North Korea's weapons of mass destruction programs. Seven cryptocurrency addresses across Ethereum and Tron networks were designated, with TRM Labs reporting over $12 million in tracked on-chain transactions through those addresses.
avoid.net/safe-wallet→68/100[CAUTIONARY]Safe{Wallet}, operated by the Safe Ecosystem Foundation, is the dominant smart-contract multisig platform on Ethereum and EVM-compatible chains, securing approximately $35 billion in assets across 61 million accounts as of Q1 2026. In February 2025, a developer machine compromise by North Korea's Lazarus Group (TraderTraitor) allowed attackers to inject malicious JavaScript into the app.safe.global frontend, enabling the theft of approximately $1.5 billion in ETH from Bybit — the largest cryptocurrency heist in history. The Safe smart contracts themselves were not compromised; the attack was entirely at the infrastructure and frontend layer. Safe has since rebuilt its infrastructure and launched Safenet, a decentralized transaction-security network, as a structural response.
avoid.net/krish-kumar-future-fractal-investments→2/100[CRITICAL]Krish Kumar is a Tulsa, Oklahoma college student who, between approximately January 2024 and February 2025, raised approximately $7.8 million across two self-managed crypto-focused investment funds — Future Fractal Investments LLC and Arcane Resonance Fund LLC. On March 26, 2026, the SEC filed settled civil charges (LR-26507, Case No. 4:26-cv-00184, N.D. Okla.) alleging Kumar misappropriated nearly $7 million: transferring more than $5.6 million of Future Fractal assets to personal accounts to buy 33,009 options on a Bitcoin mining company, losing approximately 98% in four trading days, then fabricating a cover-up including a photoshopped brokerage screenshot, before raising $1.8 million through a second fund and using $300,000 of that capital to pay off a prior investor in a Ponzi-like manner. Kumar consented to a bifurcated judgment with permanent injunctions; monetary remedies including disgorgement, civil penalties, and a five-year conduct bar remain pending as of June 2026.
avoid.net/manu-singh-contrarian→3/100[CRITICAL]Manu Singh, an Indian national age 34, was the Chief Executive Officer of Contrarian, a cryptocurrency market-making firm registered in the British Virgin Islands. On September 4, 2025, a federal grand jury in Oakland (N.D. Cal.) indicted Singh and three co-defendants as part of DOJ/FBI Operation Token Mirrors for alleged wire fraud conspiracy and wire fraud related to coordinated pump-and-dump wash trading schemes. Singh was arrested in Singapore on October 2, 2025 at U.S. request, extradited to the United States, and made his initial court appearance in Oakland on March 30, 2026; he remained in federal custody as of that date. All charges are allegations; Singh has not been convicted and is presumed innocent.
avoid.net/overhere-clinton-so→18/100[CRITICAL]OverHere Limited is a Hong Kong-registered Web3 launchpad founded and controlled by Clinton So. The company served as the primary launch platform for the $HAWK memecoin on December 4, 2024, a token associated with viral internet personality Haliey Welch. Within hours of launch the token surged to an alleged peak market cap of approximately $491 million before collapsing more than 90%, and on December 19, 2024 OverHere Limited and Clinton So were named defendants in a federal securities class action (EDNY Case No. 1:24-cv-08650) alongside co-defendants Alex Larson Schultz and the Tuah the Moon Foundation. The litigation was actively proceeding as of early 2026, with lead plaintiff Alexander Escobar appointed April 23, 2025 and co-lead counsel Wolf Popper LLP and Burwick Law designated by Judge Cheryl L. Pollak; an amended complaint filed in November 2025 expanded the defendant pool and added coordinated fraud allegations.
avoid.net/melania-memecoin→12/100[CRITICAL]$MELANIA is a Solana-based memecoin launched on January 19, 2025 by MKT World LLC, a Florida company linked to First Lady Melania Trump, one day before her husband's presidential inauguration. The token reached a peak market capitalization of approximately $1.6–1.73 billion before losing roughly 99% of its all-time high value; as of June 2026 it trades near $0.09. A class action lawsuit filed in the Southern District of New York (Hurlock v. Kelsier Ventures, amended October 2025) alleges that Kelsier Ventures CEO Hayden Davis and Meteora co-founder Benjamin Chow orchestrated a pre-engineered pump-and-dump scheme across at least 15 tokens, using Melania Trump's name as 'window dressing' without her alleged knowledge of the insider mechanics.
avoid.net/beaverd-beaverd→4/100[CRITICAL]@beaverd is an anonymous X (Twitter) account that won X's $1 million Creators Prize in February 2026 for an investigative article on Deloitte. Days after the prize announcement, on-chain analytics firm Bubblemaps published a detailed investigation alleging that wallet clusters linked to @beaverd had engaged in serial pump-and-dump activity across dozens of Solana memecoins launched via Pump.fun, extracting an estimated $600,000 in profits. @beaverd did not dispute the wallet links, responding publicly with 'cry me a river, also these aren't even the top 5 greatest hits,' a statement widely interpreted as an implicit admission of the activity.
avoid.net/sahil-arora→3/100[CRITICAL]Sahil Arora (also known online as 'Sahil Crypto', formerly @Habibi_Comm on X) is an Indian-born, Dubai-based entrepreneur documented across multiple Tier 2 sources as a serial celebrity memecoin operator who allegedly orchestrated pump-and-dump schemes involving Caitlyn Jenner, Jason Derulo, Iggy Azalea, Rich the Kid, Floyd Mayweather, Davido, and others between 2021 and 2025. He allegedly paid celebrities fees ranging from $15,000 to $200,000+ per promotional post while secretly controlling 25–40% of each token's supply, then dumping his holdings immediately after the celebrity promotion caused a price spike. Arora was permanently banned from X in June 2024 and admitted in public interviews to profiting from rug pulls; in July 2025 Dubai authorities reportedly detained him and seized assets exceeding $20 million, though Arora publicly denied arrest via video.
avoid.net/geoffrey-woo-antihunter-antihunter-memecoin→22/100[CRITICAL]Geoffrey Woo, Stanford-educated co-founder of the Anti Fund venture capital firm alongside Jake Paul, launched the AntiHunter (ANTIHUNTER) AI-themed memecoin on the Base blockchain in February 2026, publicly claiming '0% rug pull risk' because he is 'already rich.' Blockchain investigator ZachXBT subsequently identified three token swaps attributed to insider wallets that appear to violate Woo's stated commitment to pre-announce all insider sales, raising credible concerns about transparency. The token reached an all-time high market cap of approximately $12.6 million on February 13, 2026, before declining roughly 99% to a market cap of approximately $85,000 as of early June 2026.
avoid.net/undisclosed-kol-promo-network-zachxbt-expos-september-2025→5/100[CRITICAL]On September 1, 2025, blockchain investigator ZachXBT published a leaked price sheet documenting over 200 crypto influencers (key opinion leaders) who were approached to promote an AI memecoin platform called Memenetic on Solana, with on-chain payment verification showing more than 160 accepted compensation ranging from $50 to $60,000 per post. Fewer than five of the roughly 160 confirmed paid recipients disclosed the arrangements as advertisements, a compliance rate below 3% and in direct violation of FTC Endorsement Guides. The evidence — consisting of Solana wallet addresses and publicly verifiable transaction hashes — indicates the promotions were organized through a tiered commercial infrastructure, with an additional allegation from the Memenetic project team that two intermediaries, @MsCryptomom1 and @imanihamida, allegedly defrauded them of $232,000 in USDC while managing the influencer campaign.
avoid.net/deepsnitch-ai→12/100[CRITICAL]DeepSnitch AI is an Ethereum-based utility token project marketed as an AI-powered crypto scam-detection platform, operated by SignalPlex Lab Ltd., a company incorporated in the British Virgin Islands with no publicly disclosed team members. The project raised an alleged $2.87M in a multi-stage presale (figures across sources range from $2.2M to $2.87M and cannot be independently verified from a primary financial source) before listing on Uniswap on March 31, 2026, after which the token price collapsed approximately 99% within days, accompanied by widespread reports of presale buyers unable to claim tokens, a honeypot flag from security scanner Blockaid, and extended team silence. The team subsequently attributed the Blockaid flag to contract anti-dump mechanics misread as a honeypot, launched a V1 platform on April 10, 2026, and the contract flag was reportedly cleared; however, trading volume subsequently went dormant and no Tier 1 or Tier 2 source has independently verified any key claim.
avoid.net/google-coin-fake-gemini-ai-chatbot-presale-operation→0/100[CRITICAL]A fraudulent cryptocurrency presale operation, discovered by Malwarebytes on February 18, 2026, that deployed a custom AI chatbot impersonating Google's Gemini assistant to sell a non-existent token called 'Google Coin.' The site mimicked Google's visual identity, displayed fabricated endorsements from OpenAI, Binance, Coinbase, Squarespace, and SpaceX, and promised investors 7x returns through irreversible cryptocurrency payments. Google (Alphabet Inc.) has never issued a cryptocurrency; this operation was entirely fabricated and constitutes an AI-automated impersonation fraud with no legitimate entity behind it.
avoid.net/bitclout-deso-nader-al-naji→32/100[WARNING]BitClout was a blockchain-based social media platform launched in March 2021 by Nader Al-Naji, operating under the pseudonym 'Diamondhands', which later rebranded to the DeSo (Decentralized Social) blockchain. In July 2024, the SEC and DOJ charged Al-Naji with raising approximately $257 million through alleged unregistered securities sales and fraud, while allegedly concealing his identity and misusing at least $7 million of investor funds for personal expenses including a Beverly Hills mansion and cash gifts to family members. Both the DOJ criminal case (dismissed without prejudice, February 2025) and the SEC civil case (dismissed with prejudice, March 2026) were dropped with no penalties, fines, or admissions of guilt, though the documented fundraise scale and the SEC and DOJ allegations remain part of the public record.
avoid.net/krish-kumar-future-fractal-investments-arcane-resonance-fund→2/100[CRITICAL]Krish Kumar, a 19-year-old college freshman from Tulsa, Oklahoma, is the subject of settled civil charges filed by the SEC on March 26, 2026, for allegedly misappropriating nearly $7 million from two crypto-focused investment funds he solely managed: Future Fractal Investments LLC and Arcane Resonance Fund LLC. Between January 2024 and February 2025, Kumar raised approximately $7.8 million from roughly two dozen investors, then transferred the vast majority of those assets to personal accounts, lost approximately 98% by purchasing speculative options in a Bitcoin mining company over four trading days, and allegedly fabricated performance records including a photoshopped brokerage screenshot. Kumar later launched a second fund targeting parents of college friends, in a structure the SEC characterizes as resembling a Ponzi scheme.
avoid.net/alex-larson-schultz-overhere-limited-hawk-memecoin→4/100[CRITICAL]Alex Larson Schultz (known online as 'Doc Hollywood'), OverHere Limited CEO Clinton So, and the Cayman Islands-registered Tuah The Moon Foundation are the principal architects behind the $HAWK memecoin launched December 4, 2024, on Solana, which used the viral celebrity of Hailey Welch ('Hawk Tuah Girl') to attract retail investors before collapsing more than 93% within hours of launch. A federal class action (Case 1:24-cv-08650, EDNY) filed December 19, 2024, alleges unregistered securities violations and a coordinated pump-and-dump scheme; the lawsuit has since been amended to add Welch, her manager, and Meteora DEX as additional defendants. The SEC and FBI investigated Welch and closed their inquiries without charges in early 2025; the civil litigation against Schultz, So, and OverHere remains active.
avoid.net/jump-trading→42/100[WARNING]Jump Trading is a Chicago-based proprietary trading firm founded in 1999, operating one of the largest high-frequency trading operations globally across futures, equities, fixed income, FX, and cryptocurrency markets. Its crypto division, Jump Crypto, became a major force in DeFi infrastructure between 2021 and 2023, co-developing Wormhole, Pyth Network, and the Firedancer Solana validator client. The firm has faced significant regulatory and legal exposure: its subsidiary Tai Mo Shan settled with the SEC in December 2024 for $123 million over TerraUSD manipulation, the Terraform bankruptcy administrator filed a $4 billion civil lawsuit in December 2025 naming Jump and individual executives, and a separate CFTC investigation was reported in 2024 with no public resolution as of mid-2026.
avoid.net/river-token→18/100[CRITICAL]RIVER is the native governance token of River Protocol, a chain-abstraction stablecoin project that launched via Binance Wallet's inaugural BuildKey IDO in September 2025, raising $100 million in two hours. The token surged to an all-time high of approximately $87.79 on January 26, 2026, before collapsing more than 94% to roughly $5 as of early June 2026. On-chain investigator ZachXBT publicly named RIVER as the anchor case in his May 2026 investigation into Hong Kong-based market maker Heisenberg Guru (HSBG), alleging coordinated supply-control manipulation across centralized exchanges, and offering a $10,000 personal bounty for insider evidence targeting HSBG operators identified by the handles 'Sion' and 'Chao'.
avoid.net/siren-token→9/100[CRITICAL]SIREN is a BNB Chain AI-themed meme token launched in early 2025 via the Four.meme fair-launch platform. Beginning in March 2026 the token underwent a series of extreme pump-and-dump cycles, crashing roughly 90% from its all-time high of approximately $3.83 within ten days. On-chain investigators ZachXBT and BubbleMaps identified a single wallet cluster holding nearly 50% of circulating supply, linked by ZachXBT to addresses associated with DWF Labs-affiliated tokens; ZachXBT later named SIREN as one of at least six tokens subject to a coordinated market-maker manipulation playbook allegedly enabled by Bitget, alongside RAVE, RIVER, LAB, MYX, and SKYAI.
avoid.net/trump-official-memecoin-trump→18/100[CRITICAL]$TRUMP (Official Trump) is a Solana-based memecoin launched on January 17, 2025, two days before Donald Trump's presidential inauguration, by two Trump-affiliated entities — CIC Digital LLC and Fight Fight Fight LLC — who collectively retain 80% of the 1 billion token supply under a multi-year vesting schedule. The token peaked near $75 within hours of launch before declining approximately 97% to roughly $1.96 as of June 2026, generating an estimated $320–$600 million in fees and token proceeds for insider entities while on-chain analytics attribute more than $4.3 billion in aggregate losses to retail investors. The project has drawn formal congressional investigations, foreign-influence concerns, and ethics scrutiny, though no criminal charges or SEC enforcement actions have been filed against it as of the investigation date.
avoid.net/pump-fun-solana-labs-rico-class-action→17/100[CRITICAL]Aguilar v. Baton Corporation Ltd. (Case No. 1:25-cv-00880, S.D.N.Y.) is an active federal class action alleging that Pump.fun, Solana Labs, the Solana Foundation, and named executives operated a coordinated racketeering enterprise — referred to as the 'Solana-Pump.Fun Racketeering Enterprise' — that rigged its memecoin launchpad to benefit insiders while marketing it as a fair platform to retail investors. Plaintiffs allege aggregate retail losses between $4 billion and $5.5 billion, while the platform collected an alleged $722 million in fees. As of early 2026, defendants have filed motions to dismiss the Second Amended Complaint; no ruling on those motions has been publicly reported as of June 2026.
avoid.net/morocoin-berge-blockchain-cirkor-ai-wealth-investment-club-network→0/100[CRITICAL]Morocoin Tech Corp., Berge Blockchain Technology Co. Ltd., Cirkor Inc., AI Wealth Inc., Lane Wealth Inc., AI Investment Education Foundation Ltd., and Zenith Asset Tech Foundation are seven entities charged by the SEC on December 22, 2025 (Case No. 1:25-cv-04102, D. Colo.) with defrauding at least $14 million from U.S. retail investors in a coordinated pig-butchering and AI-themed investment confidence scheme operating from January 2024 through January 2025. The scheme used WhatsApp-based fake investment clubs, deepfake social media advertisements, fabricated AI-generated trading signals, and counterfeit trading platforms that conducted no actual trading, followed by advance fee demands to further extract funds from victims attempting withdrawals.
avoid.net/crypto-beast→4/100[CRITICAL]Crypto Beast is the online handle of Chris Woytko (@cryptobeastreal), a crypto influencer with approximately 800,000 X followers who has been publicly exposed by on-chain investigator ZachXBT for allegedly orchestrating a pump-and-dump scheme on the $ALT (Altcoin Fun) token in July 2025. According to ZachXBT's on-chain analysis, 45 linked wallets coordinated an $11 million dump on July 14, 2025, collapsing the token from a $190 million market cap to approximately $3 million within hours. ZachXBT also documented an alleged pattern of similar bundled rug-pull operations across at least six prior tokens ($ALPHA, $RICH, $YE, $RUG, $ACE, $JOHN). No confirmed legal or regulatory action had been filed as of the time of research.
avoid.net/ravedao→2/100[CRITICAL]RaveDAO is a Web3 entertainment protocol that markets itself as a community bridging electronic dance music culture with blockchain-based ticketing, governance, and event access. Its native token, RAVE, launched on Binance Alpha in December 2025 and experienced a ~10,800% price surge in April 2026 before collapsing approximately 95% within 48 hours amid substantial on-chain evidence of insider supply control and an alleged coordinated 'bait and liquidate' short-squeeze scheme. Binance, Bitget, and Gate.io opened formal investigations; on-chain investigator ZachXBT publicly accused the project's affiliated insiders of engineering the rally and named RAVE as part of a broader pattern of Bitget-enabled market-maker fraud.
avoid.net/xaman-wallet-impersonation-xrp-airdrop-phishing-2026→2/100[CRITICAL]Beginning at least as early as March 2026 and escalating sharply through May 2026, a sustained and coordinated phishing campaign has impersonated Xaman Wallet — the dominant self-custody wallet for the XRP Ledger, developed by XRPL Labs — across fake social media accounts, counterfeit domains, fraudulent browser extensions, and fake desktop wallet applications. Xaman founder Wietse Wind confirmed on May 23, 2026 that more than 20 fake X/Twitter accounts and more than 10 fraudulent domains are created daily as part of this campaign. The legitimate Xaman product and XRPL Labs are the impersonated party and bear no responsibility for the fraudulent activity.
avoid.net/solana-blinks-durable-nonce-drainer-kits-2026→0/100[CRITICAL]A family of increasingly sophisticated wallet-drainer toolkits targeting the Solana ecosystem that weaponize legitimate Solana protocol features — Blinks (blockchain action links), durable nonces, and the system 'assign' instruction — to bypass the transaction-simulation safety layer that most Solana wallets rely on as their primary defense. Documented in detail by security researchers from February 2024 onward and materially escalated in late 2025 and early 2026, these kits are distributed as scam-as-a-service products supporting 90+ wallet types; losses attributable to Solana phishing reached approximately $90 million in H1 2025 alone, before the simulation-bypass generation was widely deployed. A state-level durable-nonce attack on Drift Protocol (April 2026) demonstrated that the same primitive can scale to $285 million in a single operation.
avoid.net/neutrl-dns-hijack-march-2026→62/100[CAUTIONARY]On March 19, 2026, DeFi protocol Neutrl experienced a suspected DNS hijack of its frontend domain, in which attackers allegedly social-engineered the protocol's DNS provider to redirect user traffic to a malicious interface targeting Permit2 wallet approvals. Neutrl paused its smart contracts as a precaution, migrated to new infrastructure by March 21, and confirmed all user funds remained safe via the protocol's custodial isolation framework. This incident is considered the earliest confirmed event in a six-week cluster of DeFi frontend hijacks in early 2026 that also struck HypurrFi (April 3) and CoW Swap (April 14).
avoid.net/hypurrfi-domain-hijack-april-2026→57/100[CAUTIONARY]On April 3, 2026, the frontend domain hypurr.fi of HypurrFi — a DeFi lending protocol on Hyperliquid EVM — was hijacked via a social engineering attack targeting the domain registrar Openprovider. No user funds were confirmed drained and the protocol's smart contracts remained intact throughout; the team migrated frontend operations to hypurrfi.com and subsequently recovered control of the original domain. The incident is part of a documented six-week cluster of DeFi registrar-level frontend attacks in March–April 2026 targeting Neutrl, HypurrFi, and CoW Swap.
avoid.net/donald-basile-bitcoin-latinum-ltnm-monsoon-blockchain-corporation→2/100[CRITICAL]Donald G. Basile, founder of Bitcoin Latinum (LTNM) and CEO of Monsoon Blockchain Corporation, was charged by the SEC on April 17, 2026 with defrauding hundreds of U.S. investors of approximately $16 million through a SAFT offering that relied on fabricated insurance claims, a phantom asset-backed trust, and misrepresentations about how investor funds would be used. The token launched on overseas exchanges in October 2021 and subsequently collapsed by more than 90%, and the SEC alleges Basile diverted investor proceeds to personal real estate, credit card expenses, and a $160,000 horse while no underlying fund was ever created.
avoid.net/fake-chainbase-airdrop-phishing-campaign→2/100[CRITICAL]An ongoing phishing campaign, active since at least July 2025, impersonates Chainbase — a legitimate Singapore-based Web3 data infrastructure company — to lure cryptocurrency holders into either granting unlimited wallet spend approvals or surrendering seed phrases via fake 'wallet update' forms. The campaign exploits the timing of Chainbase's real $C token airdrop (launched July 14, 2025 on airdrop.chainbase.com) and operates through dozens of rotating domains anchored by chainbz[.]vip, using stolen branding, malicious ads, and social media spam. Chainbase has not authorized any third-party claim sites; all legitimate claims occurred exclusively at airdrop.chainbase.com.
avoid.net/fake-metamask-update-phishing-campaign-may-2026→0/100[CRITICAL]A coordinated phishing campaign active in late May 2026 impersonated MetaMask by sending fake 'mandatory 2026 system upgrade' notifications via email and push alerts, directing victims to pixel-accurate clone sites that solicited a single Permit/token-approval signature draining wallets within seconds. On-chain investigator ZachXBT placed total losses at more than $9 million across 400+ addresses on Ethereum, Polygon, Arbitrum, and Base as of May 30, 2026. The campaign is part of a sustained multi-variant operation against MetaMask users that began at least as early as January 2026; MetaMask itself is an impersonation victim and is not at fault.
avoid.net/trust-wallet-chrome-extension-hack-december-2025→28/100[WARNING]On December 24, 2025, a malicious version (v2.68) of the Trust Wallet Chrome extension was published to the Chrome Web Store using a stolen Chrome Web Store API key obtained via the Shai-Hulud 2.0 npm supply chain worm in November 2025. The backdoored extension silently exfiltrated decrypted seed phrases from 2,520 to 2,596 wallet addresses (figure varies by source and verification cutoff) to an attacker-controlled server, resulting in approximately $7–8.5 million in cryptocurrency losses over roughly 48 hours. Trust Wallet (a Binance subsidiary) voluntarily committed to reimbursing all verified victims and released an emergency clean patch (v2.69) on December 26, 2025.
avoid.net/unicoin-alex-konanykhin-silvina-moschini→4/100[CRITICAL]Unicoin, Inc. (formerly TransparentBusiness, Inc.) is a New York-based crypto company that sold 'Unicoin Rights Certificates' — instruments purportedly convertible one-for-one into future Unicoin tokens backed by real-world assets — beginning in February 2022. On May 20, 2025, the U.S. Securities and Exchange Commission filed a civil fraud complaint in the Southern District of New York against the company and four executives, alleging that the firm raised up to $110 million from more than 5,000 investors while fabricating $3 billion in sales, overstating real estate asset values by billions of dollars, and falsely marketing the certificates as SEC-registered. As of June 2026 the case remains active; Unicoin has filed a motion to dismiss and no ruling has been reported.
avoid.net/shai-hulud-teampcp-supply-chain-attack→0/100[CRITICAL]Shai-Hulud is a self-replicating supply chain worm attributed to the financially motivated threat group TeamPCP (also tracked as DeadCatx3, PCPcat, ShellForce, CipherForce, and UNC6780 by Google's Threat Intelligence Group). Active since September 2025, the campaign has compromised hundreds of npm and PyPI packages by harvesting CI/CD credentials through malicious preinstall lifecycle hooks, directly enabling the Trust Wallet Chrome extension hack of December 2025 in which approximately $8.5 million was stolen from 2,520 wallets. As of June 2026, the campaign remains active through copycat variants following TeamPCP's public open-sourcing of the worm's source code on May 12–13, 2026.
avoid.net/lucifer-drainer→0/100[CRITICAL]Lucifer Drainer is a criminal drainer-as-a-service (DaaS) platform that industrializes cryptocurrency wallet theft through a structured affiliate model. Active since at least early 2025, it operates by providing affiliates with phishing kits, automated site-cloning tools, and commission-split infrastructure (operators retain 20% per successful drain) while affiliates supply phishing traffic. Despite Telegram bot bans in August 2025 and documentation domain suspension in November 2025, the operation migrated to IPFS and remained active as of May 2026, making it one of the most operationally resilient drainer platforms in the current threat landscape.
avoid.net/paxful→4/100[CRITICAL]Paxful was a U.S.-based peer-to-peer Bitcoin marketplace founded in 2015 by Ray Youssef and Artur Schaback. After operating for a decade and processing approximately $5 billion in trades across 14 million users, the platform ceased operations by November 1, 2025, citing the lasting impact of historic compliance failures and unsustainable remediation costs. In December 2025, Paxful Holdings pleaded guilty to three federal criminal charges — including conspiring to violate the Travel Act, operating an unlicensed money transmitting business, and BSA anti-money laundering violations — and was sentenced in February 2026 to a $4 million criminal penalty; FinCEN separately assessed a $3.5 million civil penalty for the same underlying conduct.
avoid.net/gravity-bridge→22/100[CRITICAL]Gravity Bridge is a purpose-built, decentralized blockchain bridge developed by Althea Network that enables bidirectional transfer of ERC-20 tokens between Ethereum and the Cosmos IBC ecosystem. It launched mainnet in December 2021 after three independent security audits and became the most widely adopted bridge in the Cosmos ecosystem. On May 30, 2026, the bridge suffered a critical security incident in which approximately $5.4 million was drained via an alleged validator signing-key compromise, prompting a full bridge halt that remained in effect as of June 2, 2026.
avoid.net/brandon-michael-tardibone→4/100[CRITICAL]Brandon Michael Tardibone, 28, of Miami, Florida, was federally indicted on May 11, 2026 in the Southern District of Florida (case 1:26-cr-20181) on charges of conspiracy to commit money laundering and harboring an alien unlawfully present in the United States. Prosecutors allege he provided housing and material support to Canadian co-defendant Trenton Richard David Johnston — who allegedly orchestrated a $13 million cryptocurrency fraud scheme via social-engineering impersonation attacks — while Johnston was unlawfully overstaying his visa, and that both defendants jointly laundered more than $1 million of stolen proceeds through luxury goods and South Florida nightlife. All charges are allegations; both defendants are presumed innocent unless and until proven guilty at trial.
avoid.net/layerzero-protocol→55/100[CAUTIONARY]LayerZero is a major omnichain interoperability protocol operated by LayerZero Labs, deployed across 130+ blockchains and processing over 200 million cross-chain messages as of early 2026. The protocol gained institutional backing from Citadel Securities, ARK Invest, Tether, and Sequoia Capital, and is the infrastructure behind USDT0, which processed over $70 billion in cross-chain USDT transfers. In April 2026, LayerZero's off-chain DVN infrastructure was compromised via a social engineering attack attributed to North Korea's Lazarus Group (TraderTraitor), enabling the $292 million KelpDAO rsETH bridge exploit — the largest DeFi hack of 2026 — and triggering a multi-billion-dollar client exodus to competing bridge providers.
avoid.net/zoth-protocol→8/100[CRITICAL]Zoth Protocol is an Ethereum-based real-world asset (RWA) re-staking and tokenization platform founded in 2023 by Pritam Dutta and Koushik Bhargav. In March 2025 the protocol suffered two separate security incidents within three weeks: an initial $285,000 logic-flaw exploit on March 1 and a far more damaging $8.4 million deployer-key compromise on March 21 that enabled a malicious proxy contract upgrade. The protocol has since launched a user compensation program, engaged Crystal Blockchain BV for fund recovery, and announced a security overhaul backed by a $15 million strategic token commitment from Bolts Capital.
avoid.net/voltage-finance→15/100[CRITICAL]Voltage Finance (formerly FuseFi) is a decentralized finance protocol operating on the Fuse Network, offering token swapping, lending, liquidity farming, and cross-chain bridging via an automated market maker. The protocol has been the subject of two confirmed security exploits: a March 2022 reentrancy attack that drained approximately $4.67 million from its lending pools via a third-party partner (Ola Finance), and a March 2025 insider-related exploit of its Simple Staking pools resulting in approximately $322,000 in losses. No funds were recovered in either incident as of the time of this investigation.