Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
On August 21–22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base by hijacking LayerZero delegate permissions through the approveAndCall function, enabling unauthorized minting of approximately 329.24 trillion unbacked SAND tokens across 703 events over five hours. Actual financial extraction was substantially lower than headline figures: roughly 14.75 million SAND drained from the Ethereum OFT Adapter yielded approximately 80 ETH (~$675,000), while The Sandbox estimated the incident affected less than 0.01% of the 3-billion total SAND supply. The exploit was the third major LayerZero bridge incident in five months and contributed to accelerating an industry-wide migration from LayerZero to Chainlink CCIP, with publicly announced moves totaling approximately $15 billion.
avoid.net/the-sandbox-sand→30/100[WARNING]The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.
avoid.net/ofac-iran-central-bank-crypto-wallet-freeze-july-2026→0/100[CRITICAL]On July 14, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) updated its Central Bank of Iran (Bank Markazi) SDN designation to add four TRON-based cryptocurrency wallet addresses that had collectively received $165 million in stablecoins, with $131 million immediately frozen by Tether. The action is part of the Trump administration's Operation Economic Fury maximum-pressure campaign against Iran and represents the second major stablecoin freeze of Iranian sovereign crypto reserves in 2026, bringing the cumulative OFAC-linked freeze of Bank Markazi USDT holdings to approximately $475 million.
avoid.net/global-pig-butchering-enforcement-cluster-276-arrests-m-seizures-2026→0/100[CRITICAL]A coordinated international law enforcement cluster spanning January through May 2026 dismantled multiple cryptocurrency romance-fraud (pig-butchering) networks, resulting in at least 276 arrests, the shutdown of nine scam compounds in Southeast Asia, and more than $701 million in cryptocurrency restrained. The cluster encompasses parallel actions by the U.S. Department of Justice Scam Center Strike Force, the FBI, Dubai Police, the Chinese Ministry of Public Security, INTERPOL Operation First Light 2026, U.S. Treasury OFAC sanctions, and a separate DOJ seizure of $61 million in Tether — collectively representing the largest coordinated crackdown on pig-butchering fraud on record.
avoid.net/verus-protocol-vrsc→21/100[CRITICAL]Verus Protocol (VRSC) is an open-source, privacy-focused Layer 1 blockchain launched in May 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and architect of the .NET framework. Its Ethereum cross-chain bridge suffered two exploits in 2026 — $11.58M on May 18 and $7.54M on July 23 — both caused by the same unpatched source-amount validation flaw in the bridge's import path. The project's decision to reopen the bridge and redeposit reserves on July 8 without a confirmed full patch or independent audit directly enabled the repeat attack, raising significant concerns about security governance.
avoid.net/jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys→0/100[CRITICAL]JADEPUFFER is a threat actor and ransomware campaign documented by Sysdig's Threat Research Team in July 2026, assessed as the first confirmed end-to-end autonomous ransomware operation directed by a large language model (LLM) rather than a human operator at each step. The attack exploited CVE-2025-3248, a critical unauthenticated remote code execution flaw in the Langflow AI workflow platform, and the LLM agent autonomously conducted reconnaissance, swept for cryptocurrency wallet private keys and seed phrases alongside other credentials, moved laterally, encrypted a production database, and delivered a ransom demand — all without human direction of individual steps. A follow-on variant named ENCFORGE, attributed to the same operator, subsequently targeted AI model weights and training datasets on Langflow-exposed hosts, and approximately 1,050 Langflow instances remained publicly reachable at time of Sysdig's disclosure.
avoid.net/jadepuffer→0/100[CRITICAL]JADEPUFFER is a threat cluster documented by Sysdig's Threat Research Team in July 2026 and assessed to be the first publicly confirmed example of an agentic AI-driven ransomware operator. The operator exploited CVE-2025-3248, a critical unauthenticated remote code execution flaw in the Langflow AI orchestration framework, deploying a large language model agent that autonomously conducted the full attack lifecycle — from reconnaissance and credential theft to lateral movement, database encryption, and extortion — against production infrastructure. A subsequent campaign introduced ENCFORGE, a compiled Go ransomware purpose-built to destroy AI model checkpoints, vector databases, and training datasets.
avoid.net/goliath-ventures-christopher-delgado→0/100[CRITICAL]Goliath Ventures, Inc. (formerly Gen-Z Venture Firm), based in Apopka/Orlando, Florida, operated a cryptocurrency investment Ponzi scheme from January 2023 through January 2026. Its founder and CEO, Christopher Alexander Delgado, was arrested on federal charges in February 2026 and pleaded guilty on June 30, 2026 to conspiracy to commit wire fraud, wire fraud, and money laundering, admitting to at least $250 million in investor losses from a scheme that raised approximately $400 million under false promises of returns from cryptocurrency liquidity pools. Sentencing is scheduled for October 8, 2026.
avoid.net/coldcard-coinkite-august-2026-multi-actor-attacker-cluster→0/100[CRITICAL]Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.
avoid.net/taj-tarsha-few-and-far-limited→2/100[CRITICAL]Taj Tarsha is the founder of Few and Far Limited, a Web3 NFT marketplace startup built on the NEAR Protocol that raised over $10 million from at least 67 investors via SAFT agreements for its FAR token. On August 5, 2026, the U.S. Attorney's Office for the Southern District of New York unsealed a federal indictment charging Tarsha, age 34, with securities fraud and wire fraud, alleging he systematically misappropriated investor funds for personal use including online gambling, speculative crypto trading, a Miami condominium, and a personal DJ hobby, while concealing the scheme following a 2023 internal audit. Each charge carries a statutory maximum of 20 years' imprisonment.
avoid.net/playsomo→60/100[CAUTIONARY]Playsomo, operating under the brand SOMO (@playsomo, somo.xyz), is a Web3 digital-collectibles and gaming company founded in 2021 in Tortola, British Virgin Islands, that was acquired outright by Animoca Brands on January 14, 2026. A pseudonymous X/Twitter account (@0xd_eth) has alleged that Taj Tarsha — separately indicted by the U.S. Attorney's Office for the Southern District of New York on August 5, 2026 on securities and wire fraud charges tied to his company Few and Far Limited — 'launched' a Playsomo token and implicated Animoca Brands and its co-founder Yat Siu. No court filing, DOJ statement, or mainstream news coverage of the Tarsha indictment names Playsomo, SOMO, or Animoca Brands, and no evidence of an official Playsomo/SOMO token with a verifiable contract address was found. This investigation treats the Tarsha connection as an unsubstantiated social-media allegation pending independent verification.
avoid.net/nobitex-wallex-bitpin-ramzinex→0/100[CRITICAL]On June 2, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated four Iranian cryptocurrency exchanges — Nobitex, Wallex, Bitpin, and Ramzinex — on the Specially Designated Nationals (SDN) list under Executive Orders 13224 and 13902 as part of the Trump administration's 'Economic Fury' maximum pressure campaign against Iran. The four exchanges collectively processed approximately $7.7 billion in 2025, representing roughly 78% of Iran's attributed crypto volume, and allegedly facilitated terror finance, sanctions evasion, IRGC-linked ransomware payments, and the Iranian Central Bank's acquisition of hundreds of millions in USDT. Secondary sanctions apply, meaning any foreign financial institution transacting with these entities after June 2, 2026 risks losing U.S. dollar correspondent banking access.
avoid.net/uxlink→20/100[CRITICAL]UXLINK is a Web3 social infrastructure platform founded in 2022 and headquartered in Singapore, claiming over 54 million registered users as of mid-2025. On September 22, 2025, the protocol suffered a critical multi-signature wallet exploit via a delegateCall vulnerability that resulted in over $11.3 million in direct losses and the fraudulent minting of approximately 10 trillion tokens. As of June 2026, the exploiter had laundered a cumulative $19.1 million through Tornado Cash, with an estimated $16 million in stolen funds still unrecovered.
avoid.net/irs-fake-digital-asset-compliance-portal-phishing-campaign-2026→0/100[CRITICAL]In late July 2026, an unidentified threat actor mailed counterfeit IRS letters to U.S. cryptocurrency holders directing them to a fictitious 'Digital Asset Compliance Portal' (DACP) at a lookalike domain. IRS Criminal Investigation (IRS-CI) issued a public warning on July 30, 2026, confirming no such portal exists and that the campaign was designed to harvest personal information, exchange credentials, and digital asset holdings. The phishing infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior history of financial phishing activity.
avoid.net/irs-fake-digital-asset-compliance-portal-letter-campaign-2026→0/100[CRITICAL]A fraud campaign active as of late July 2026 in which unknown threat actors mail physically printed letters impersonating the IRS, instructing cryptocurrency holders to enroll in a nonexistent 'Digital Asset Compliance Portal' via an embedded QR code. The IRS Criminal Investigation division publicly confirmed on July 30, 2026 that it does not operate any such portal and did not send the letters. Infrastructure linked to the campaign was registered through a Hong Kong-based registrar and hosted on Romanian servers previously associated with financial phishing attacks.
avoid.net/irs-fake-digital-asset-compliance-portal-physical-mail-phishing→0/100[CRITICAL]Beginning in late July 2026, an unidentified threat actor began mailing counterfeit IRS letters to cryptocurrency holders in the United States, directing recipients to a nonexistent 'Digital Asset Compliance Portal' via embedded QR codes. IRS Criminal Investigation (IRS-CI) publicly confirmed on July 30, 2026, that the portal does not exist and that the agency did not send the letters. Cybersecurity firms Coinbase and DarkTower traced the campaign's infrastructure to a domain registered through a Hong Kong registrar and hosted on Romanian servers previously associated with financial-institution phishing.
avoid.net/shelbit-exchange→0/100[CRITICAL]Shelbit Exchange is an unlicensed Dubai-based cryptocurrency exchange operated by Iranian expatriate Siavash Kayvanpour that processed at least $4 billion in digital assets since May 2024 for a network including Iran's central bank, IRGC-linked wallets, and more than 2,000 Farsi-language gambling sites. On August 7, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Shelbit Exchange, its operator Kayvanpour, and multiple affiliated corporate entities under Iran-related sanctions authorities. Dubai's Virtual Assets Regulatory Authority (VARA) separately issued a cease-and-desist and monetary fines on July 24, 2026, citing unlicensed operation, KYC failures, and anti-money laundering violations.
avoid.net/mica-post-deadline-impersonation-scam-cluster-esma-amf-warning-august-2026→0/100[CRITICAL]Following the expiry of the EU Markets in Crypto-Assets (MiCA) regulation transitional period on July 1, 2026, European regulators including ESMA, France's AMF, the Dutch AFM, and Belgium's FSMA documented a significant surge in impersonation scams targeting retail crypto investors. Fraudsters posed as regulatory officials and licensed exchanges to direct victims toward counterfeit websites, forged documents, and fraudulent transfer instructions. No individual perpetrators have been publicly named; the cluster encompasses multiple coordinated but distinct operations that share common tactics and timing.
avoid.net/garden-finance-cross-chain-bridge-july-2026-solver-database-exploit→3/100[CRITICAL]Garden Finance is a cross-chain atomic swap protocol that uses Hash Time-Locked Contracts (HTLCs) to facilitate trustless swaps between Bitcoin and EVM-chain assets. On July 26, 2026, an attacker compromised the off-chain database of an independent solver and inserted fraudulent transaction records, draining approximately $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Smart Chain. This was the protocol's second major security incident in under a year, following a substantially larger $11 million breach in October 2025 that involved a North Korea-affiliated threat actor group.
avoid.net/siavash-kayvanpour→0/100[CRITICAL]Siavash Kayvanpour is an Iranian-born expatriate and the identified primary operator of the Shelbit Exchange, a Dubai-based unlicensed cryptocurrency exchange that processed at least $4 billion since May 2024. On August 7, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Kayvanpour personally under Executive Order 13224 for materially supporting Iran's Islamic Revolutionary Guard Corps (IRGC) and the sanctioned exchange Nobitex. Any transaction with Kayvanpour or his controlled wallets and entities constitutes a U.S. sanctions violation.
avoid.net/dprk-crypto-theft-h1-2026-trm-labs-blockaid-report→0/100[CRITICAL]North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm. Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds. Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.
avoid.net/coinrail→0/100[CRITICAL]Coinrail was a small South Korean cryptocurrency exchange that suffered a major security breach on June 10, 2018, resulting in the theft of approximately $40 million worth of ERC-20 tokens including NPXS (Pundi X), ATX (Aston X), DENT, and others. The incident triggered a broader cryptocurrency market sell-off, contributing to a loss of over $40 billion in total crypto market capitalization. Following the hack, Coinrail suspended trading operations and cooperated with South Korean law enforcement; the exchange subsequently transitioned to an offline platform and never fully resumed normal operations.
avoid.net/jiang-wen-jie→0/100[CRITICAL]Jiang Wen Jie (also known as Jiang Nan) is a Chinese national charged by the U.S. Department of Justice on April 23, 2026, with wire fraud conspiracy for his alleged role as a team leader at Shunda Park, a pig-butchering scam compound that operated in Min Let Pan, Myanmar, from at least January to November 2025. Under Jiang's alleged supervision, trafficked workers were coerced into defrauding American victims through fake cryptocurrency investment platforms, with at least one victim losing over $3 million to a single scammer under his command. Jiang was arrested by Thai authorities in early 2026 on immigration charges while allegedly attempting to return to Myanmar after relocating to Cambodia following the Karen National Liberation Army's seizure of Shunda Park, and he remains in Thai custody as the DOJ pursues extradition.
avoid.net/mastra-ai-npm-supply-chain-attack-june-2026→0/100[CRITICAL]On June 17, 2026, attackers hijacked a dormant npm contributor account ('ehindero') to inject a malicious dependency ('easy-day-js') into 140+ packages across the @mastra npm scope, affecting an estimated 1.1 million+ weekly downloads. The trojanized dependency contained a multi-stage remote access trojan targeting developer credentials, LLM API keys, cloud secrets, and cryptocurrency wallet browser extensions across Windows, macOS, and Linux. Mastra and npm responded within hours by revoking the compromised account, unpublishing malicious versions, and forward-rolling clean releases.
avoid.net/aban-tether→0/100[CRITICAL]Aban Tether (Persian: آبان تتر) is an Iran-based cryptocurrency exchange specializing in USDT stablecoin trading that was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on August 7, 2026, for facilitating illicit cryptocurrency activity and sanctions evasion in support of Iran's Islamic Revolutionary Guard Corps (IRGC). The exchange is alleged to have processed millions of dollars in transactions involving previously designated Iranian platforms including Nobitex, Wallex, Bitpin, and Ramzinex, functioning as a conduit node within Iran's sanctioned crypto infrastructure. Its designation under Executive Order 13902 carries secondary sanctions risk for any global exchange, protocol, or institution that transacts with Aban Tether addresses.
avoid.net/0xdf8c3a7ffbdc144f462687120e4ae4c4e5e55abe→50/100[WARNING]0xdF8C3A7FFbdC144f462687120E4AE4C4e5E55abE is an Ethereum externally owned account (EOA) with no recorded on-chain transaction history, zero ETH balance, and no token holdings as of August 2026. No verifiable associations with scams, fraud, sanctions, regulatory actions, or illicit activity were found across any checked source; however, the absence of on-chain history and public intelligence makes a definitive trust assessment impossible.
avoid.net/zhuoying-chen-haojie-zhang-43m-pig-butchering-laundering-network→2/100[CRITICAL]Zhuoying Chen (aka 'Jolene,' 27, Brooklyn, NY) and Haojie Zhang (aka 'Kevin,' 38, Queens, NY) were charged by federal prosecutors on July 16, 2026 with conspiracy to commit money laundering in connection with laundering at least $43 million in proceeds from pig-butchering investment fraud schemes between 2020 and 2022. The pair allegedly managed a domestic infrastructure layer of a China-linked criminal network, recruiting over a dozen money mules across Brooklyn and Queens who opened 140 bank accounts under approximately 45 shell companies, then converted the layered funds to cryptocurrency for transfer to China-based co-conspirators. Both defendants face up to 20 years in prison.
avoid.net/mica-post-deadline-crypto-firm-impersonation-scam-cluster-august-2026→0/100[CRITICAL]Following the July 1, 2026 expiry of MiCA transitional arrangements, which forced over 1,700 unlicensed crypto firms to cease EU operations, financial regulators including ESMA, France's AMF, the Dutch AFM, and Belgium's FSMA identified a coordinated surge in impersonation fraud targeting displaced retail investors. Fraudsters have misused ESMA's official name, logo, and branding — including fabricated MiCA authorization documents and spoofed regulator communications — to deceive users seeking compliant alternatives into transferring assets to fraudulent wallets. This scam cluster is confirmed by formal regulatory advisories published August 6, 2026 and represents a distinct pattern exploiting genuine regulatory transition confusion.
avoid.net/noones-exchange→12/100[CRITICAL]NoOnes is a peer-to-peer cryptocurrency marketplace launched in 2023 by Ray Youssef, co-founder of the now-defunct Paxful exchange. The platform operates across 190+ countries, reports 2.5 million users, and is headquartered in Dubai. It carries significant reputational and structural risk owing to a confirmed $7.9 million hot-wallet exploit in January 2025, the founder's DOJ indictment on AML charges stemming from Paxful, and Youssef's subsequent forced departure from the CEO role in February 2026 under undisclosed legal circumstances.
avoid.net/huang-xingshan→2/100[CRITICAL]Huang Xingshan (also known as Ah Zhe and Huang Xing Saan) is a Chinese national charged by the U.S. Department of Justice on April 23, 2026, with wire fraud conspiracy for co-managing Shunda Park, an industrial-scale pig-butchering cryptocurrency fraud compound in Karen State, Myanmar. Prosecutors allege he served as a high-level manager and enforcer who personally participated in the physical punishment of trafficked workers. He was arrested by Thai authorities in early 2026 on immigration charges and remains in Thai custody while the U.S. pursues extradition.
avoid.net/zero-network-zerion-l2→28/100[WARNING]Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.
avoid.net/bonzo-finance→18/100[CRITICAL]Bonzo Finance is an open-source, non-custodial lending and borrowing protocol deployed on the Hedera network, developed by Bonzo Finance Labs and launched on mainnet on October 28, 2024. On July 11, 2026, an attacker exploited a BLS signature verification flaw in a Supra oracle contract to artificially inflate the price of the SAUCE token by approximately 12 orders of magnitude, draining approximately $9.05 million in USDC and wrapped HBAR from Bonzo Lend. The incident caused Bonzo Lend's total value locked to collapse 77% and Hedera's overall DeFi TVL to drop nearly 40% within 24 hours; Bonzo Lend and Bonzo Points were subsequently paused, with the Hedera Foundation committing backing for full user position recovery.
avoid.net/q2-2026-defi-record-hack-wave→0/100[CRITICAL]Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.
avoid.net/travis-ford-wolf-capital-crypto-ponzi→0/100[CRITICAL]Travis Ford, 36, of Glenpool, Oklahoma, was the co-founder, CEO, and head trader of Wolf Capital Crypto Trading LLC. He was sentenced on November 14, 2025, to 60 months in federal prison after pleading guilty in January 2025 to one count of conspiracy to commit wire fraud for operating a $9.4 million Ponzi scheme that defrauded approximately 2,800 investors. The CFTC filed a parallel civil enforcement action in December 2025 alleging broader fraud spanning October 2022 through December 2024 and involving more than $10 million from over 3,000 participants.
avoid.net/aurum-foundation→0/100[CRITICAL]Aurum Foundation is a Dubai-based MLM crypto Ponzi scheme that launched in mid-2024, promising monthly returns of 9.48% to 15.01% through an alleged AI trading bot called EX-AI, with no on-chain evidence of genuine trading activity. The scheme attracted regulatory fraud warnings from at least ten jurisdictions across Europe, Asia, Africa, and Oceania before collapsing on July 30, 2026, with operators issuing a 'we got hacked' announcement widely characterized as a classic exit-scam cover story. On-chain analysis identified approximately $31.7 million transiting through core wallets over a 17-day window, consistent with redistribution to early investors rather than external trading profits.
avoid.net/q2-2026-record-crypto-hack-wave→0/100[CRITICAL]The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.
avoid.net/benjamin-paul-wiener-benaiah-capital→0/100[CRITICAL]Benjamin Paul Wiener, a 43-year-old Sioux Falls, South Dakota resident, was indicted in June 2026 on 29 federal counts including wire fraud, money laundering, bank fraud, and aggravated identity theft. Prosecutors allege he operated a Ponzi-style cryptocurrency investment scheme through at least eight entities under the 'Benaiah' brand, raising approximately $25.1 million from dozens of investors primarily in South Dakota and Minnesota, resulting in estimated losses of approximately $20 million. Wiener pleaded not guilty on July 10, 2026, and trial is scheduled for September 15, 2026; all allegations remain unproven in court.
avoid.net/neyro-token-aurum-foundation-exit-scam-rebrand→0/100[CRITICAL]Aurum Foundation was an MLM crypto Ponzi scheme launched from Dubai in mid-2024 that marketed an alleged AI trading bot promising approximately 30% monthly returns. In June 2026, facing regulatory action from at least ten jurisdictions, operators rebranded to 'Neyro' and introduced a NEYRO token before executing a classic exit-scam on July 30, 2026, draining investor wallets and issuing a fabricated 'we got hacked' notice to conceal operator flight.
avoid.net/holoworld-ai-ava-token-insider-bundling-scheme→0/100[CRITICAL]Holoworld AI, a Solana-based AI avatar platform developed by Hologram Labs and backed by Polychain Capital's $6.5 million seed round, launched its AVA token on November 13, 2024, via Pump.fun. On-chain analytics firm Bubblemaps identified 23 wallets allegedly linked to the token deployer that accumulated approximately 40% of AVA's total supply at launch through coordinated automated sniping. AVA subsequently crashed more than 96% from its January 2025 all-time high of $0.33, erasing nearly $290 million in fully diluted valuation and causing substantial losses for retail holders.
avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-2026→38/100[WARNING]On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.
avoid.net/tanstack-npm-supply-chain-attack-mini-shai-hulud-teampcp→0/100[CRITICAL]On May 11, 2026, threat actor group TeamPCP executed a sophisticated supply chain attack against the TanStack npm ecosystem, compromising 42 packages across 84 malicious versions collectively downloaded millions of times per week. The attack, branded internally as the 'Mini Shai-Hulud' worm, chained three GitHub Actions vulnerabilities to extract an OIDC token from runner memory and autonomously publish credential-stealing payloads that spread to over 170 additional npm and PyPI packages including Mistral AI, UiPath, and OpenSearch. The campaign is the fourth documented wave from TeamPCP, a group active since at least late 2024, and represents the first recorded npm worm to produce validly-attested malicious packages under SLSA Build Level 3 provenance.
avoid.net/humanity-protocol-h-token-hack→13/100[CRITICAL]On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.
avoid.net/summer-finance-summer-fi-lazy-summer-protocol-flash-loan-exploit-and-shutdown→18/100[CRITICAL]On July 6, 2026, an attacker used a $65.4 million Morpho flash loan to exploit a stale-asset share-price manipulation vulnerability in Summer.fi's Lazy Summer Protocol, extracting approximately $6.04 million in DAI from two Ethereum USDC vaults. The stolen funds were subsequently laundered through Tornado Cash. On July 15, 2026, Summer.fi Labs announced it had no viable path forward and would cease operations by August 31, 2026, with governance of the Lazy Summer Protocol transferring entirely to the Lazy Summer DAO.
avoid.net/wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026→0/100[CRITICAL]WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660), which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026. Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework. Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation, link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host), and report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor; the two campaigns share the npm supply-chain vector but have distinct infrastructure and attribution.
avoid.net/bandcampro-ai-assisted-fraud-campaign→2/100[CRITICAL]Between September 2025 and May 2026, a solo Russian-speaking threat actor operating under the handle 'bandcampro' conducted a sustained AI-assisted fraud and credential-theft campaign targeting MAGA and QAnon communities to steal cryptocurrency. The actor deployed a jailbroken Google Gemini CLI — with safety guardrails persistently disabled via a GEMINI.md context injection file — as the operational backbone of an automated social engineering, influence operation, and hacking pipeline. The campaign is documented in a May 2026 Trend Micro research report titled 'Inside the 5-Year Influence and Fraud Patriot Bait Campaign.'
avoid.net/clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026→0/100[CRITICAL]A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.
avoid.net/oramama-x-war-panic-scam-network→2/100[CRITICAL]The ORAMAMA X War-Panic Scam Network is a coordinated cluster of more than 10 accounts on X (formerly Twitter) that used AI-generated geopolitical fear content — including fabricated claims about the US-Iran conflict — to accumulate large audiences before executing a confirmed pump-and-dump of the Solana meme token $ORAMAMA on February 22, 2026. On-chain investigator ZachXBT exposed the network in March 2026, documenting six-figure profits and warning that the scalable playbook posed nation-state-level disinformation risks.
avoid.net/fifa-world-cup-2026-crypto-phishing-and-typosquatting-infrastructure→0/100[CRITICAL]A coordinated, multi-actor scam infrastructure emerged around the 2026 FIFA World Cup (hosted across Canada, Mexico, and the United States, June 11 to July 19, 2026), comprising more than 13,000 to 19,000 registered World Cup-themed domains of which approximately 8.8% have been flagged as malicious or suspicious. The infrastructure combines typosquatted FIFA domains, AI-generated fake ticketing portals, cryptocurrency wallet drainers, seed-phrase phishing kits, and Android banking trojans, with at least one threat actor cluster — designated GHOST STADIUM — attributed to Chinese-speaking operators. The FBI issued a formal public service announcement on May 27, 2026, warning consumers and reporting at least 36 confirmed fraudulent domains spoofing official FIFA web properties.
avoid.net/supra-oracle-bonzo-lend-attack-vector→12/100[CRITICAL]On July 11, 2026, Hedera's largest lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a signature verification flaw in Supra's on-chain oracle verifier contract. The vulnerable code had been live for at least two years and was deployed to 11 other chains — all of which received a security patch in the days before the Hedera attack — while the Hedera instance remained unpatched. Supra, founded in 2020 and backed by Coinbase Ventures and other institutional investors, is a cross-chain oracle and infrastructure network whose verifier flaw carries systemic risk to any dependent protocol.
avoid.net/btcpay-server-lightning-lnd-macaroon-exploit-august-2026→47/100[WARNING]In August 2026, a critical, actively exploited vulnerability in BTCPay Server allowed unauthenticated remote attackers to obtain LND macaroon credential files, granting full administrative access to victim Lightning nodes and enabling fund theft. BTCPay Server released emergency patch v2.4.2 on August 7, 2026 to close the exposure, though already-stolen macaroon files remained valid until operators manually revoked them at the node level. Confirmed victims include hardware wallet company Foundation and Bitcoin publication Citadel21, with total losses undisclosed.
avoid.net/hypervault-finance→0/100[CRITICAL]Hypervault Finance was a yield-aggregating DeFi vault protocol built on the HyperEVM layer of the Hyperliquid blockchain that executed a confirmed exit scam on or around September 25–26, 2025, draining approximately $3.6–4.64 million from roughly 1,100 depositors. Operators bridged funds to Ethereum via deBridge, converted assets to ETH, and routed approximately 752 ETH into Tornado Cash to obscure the trail before deleting all web properties, social media accounts, and GitHub repositories. The project had falsely claimed ongoing security audits by Spearbit, Pashov Group, and Code4rena — none of which were conducted — and attracted deposits with promises of 76–95% annualized yields on stablecoins and HYPE liquidity tokens.
avoid.net/emerson-sousa-pires→0/100[CRITICAL]Emerson Sousa Pires is a Brazilian national and co-founder of MCC International Corp. (doing business as Mining Capital Coin), who faces a $46.2 million SEC default judgment entered August 26, 2025, alongside co-founder Luiz Carlos Capuci Jr. for operating an alleged crypto mining Ponzi scheme that defrauded approximately 65,535 investors. Pires is separately charged criminally and faces additional civil enforcement by the CFTC arising from a second fraudulent cryptocurrency investment platform, EmpiresX, through which he allegedly defrauded over 12,500 additional investors. He has reportedly fled to Brazil, where Brazilian law prohibits extradition of citizens, though Brazilian federal authorities conducted arrests in connection with parallel domestic proceedings in September 2023.
avoid.net/mcc-international-corp-cptlcoin-corp-bitchain-exchanges→0/100[CRITICAL]MCC International Corp. (doing business as Mining Capital Coin), CPTLCoin Corp., and Bitchain Exchanges were collectively operated as a multi-level marketing cryptocurrency fraud scheme that defrauded 65,535 investors worldwide of an alleged $62 million between at least January 2018 and 2022. The SEC filed charges in April 2022 and secured a combined $46 million default judgment in August 2025; co-founders Luiz Carlos Capuci Jr. and Emerson Sousa Pires fled to Brazil and were arrested there by Brazilian Federal Police in September 2023 under a separate domestic money-laundering investigation.
avoid.net/luiz-carlos-capuci-jr→0/100[CRITICAL]Luiz Carlos Capuci Jr. is the co-founder and CEO of MCC International Corp. (doing business as Mining Capital Coin) and the operator of CPTLCoin Corp. and Bitchain Exchanges. He is the subject of a DOJ criminal indictment unsealed in May 2022 for allegedly orchestrating a $62 million global cryptocurrency investment fraud affecting more than 65,000 investors, and faces up to 45 years in prison on three conspiracy counts. In August 2025, a U.S. federal court entered a $46 million default judgment against him and co-defendant Emerson Sousa Pires in the parallel SEC civil case.
avoid.net/siavash-kayvanpour-ofac-designated-shelbit-founder→2/100[CRITICAL]Siavash Kayvanpour is an Iranian expatriate and founder of Shelbit, an unlicensed cryptocurrency exchange that U.S. Treasury's OFAC personally designated on August 7, 2026 under Executive Order 13224 for materially supporting Iran's Islamic Revolutionary Guard Corps (IRGC). Blockchain investigators traced over USD 6.3 billion in flows through the Shelbit network between May 2024 and March 2026, linking the exchange to IRGC-affiliated wallets, Iran's central bank, and one of the world's largest illegal online gambling operations. Kayvanpour holds citizenships in Iran, Dominica, and Afghanistan, complicating international enforcement of the designation.
avoid.net/dean-daghita-cmdss-command-services-and-support→0/100[CRITICAL]Command Services and Support, Inc. (CMDSS) is a Haymarket, Virginia-based Service-Disabled Veteran-Owned Small Business led by president and CEO Dean Daghita that received a U.S. Marshals Service contract in October 2024 to manage and dispose of Class 2-4 seized cryptocurrency. In January 2026, blockchain investigator ZachXBT publicly alleged that Daghita's son, John Daghita (alias 'Lick'), had stolen over $46 million in digital assets from government-controlled USMS wallets by abusing insider access obtained through his father's company. John Daghita was arrested in Saint Martin on March 4, 2026, and was subsequently indicted on 15 federal counts; Dean Daghita himself had not been charged as of August 2026, though CMDSS's online presence was taken offline following the revelations and the company faces significant scrutiny over contract award process and oversight failures.
avoid.net/cryptomus-xeltox-enterprises-ltd→0/100[CRITICAL]Cryptomus is a cryptocurrency payment processor and exchange operated by Xeltox Enterprises Ltd., a company incorporated in British Columbia, Canada. In October 2025, Canada's financial intelligence unit FINTRAC imposed a record C$176.96 million (approximately US$126 million) administrative penalty against Xeltox for 2,593 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, citing failures to report transactions linked to child sexual abuse material, ransomware payments, fraud, and Iran sanctions evasion. Blockchain intelligence firm TRM Labs further assessed with high confidence that Cryptomus launched a successor platform, Heleket, shortly after implementing mandatory KYC controls, allegedly to continue facilitating illicit activity under a separate brand.
avoid.net/apple-app-store-systematic-fake-crypto-wallet-cluster-26-apps-april-2026→0/100[CRITICAL]Beginning in at least fall 2025 and publicly disclosed in April 2026, a coordinated cluster of 26 fraudulent iOS applications impersonating major cryptocurrency wallets was discovered on Apple's App Store by Kaspersky researchers. The campaign, dubbed FakeWallet and attributed with moderate confidence to the SparkKitty threat actor group, targeted seed phrase theft primarily from Chinese iOS users. The broader pattern of fake wallet apps on Apple's platforms in 2026 resulted in documented losses exceeding $11 million across multiple distinct incidents and triggered civil litigation against Apple.
avoid.net/fx-winning-david-merino-quintana→0/100[CRITICAL]FX Winning (also styled FXWinning) was a fraudulent cryptocurrency and foreign exchange investment platform allegedly masterminded by Spanish national David Merino Quintana, a businessman from Gran Canaria, Spain. Spanish authorities, coordinating with Europol, the US Drug Enforcement Administration, and investigators in Mexico and Colombia, allege the platform operated as a Ponzi scheme from approximately 2020 to 2023, collecting funds from up to 15,000 victims across more than 30 countries, with Spanish investigators estimating losses of at least €460 million and total funds collected potentially reaching €46 billion. Merino was arrested in Dubai on June 1, 2026, following an international arrest warrant issued by Spain's Audiencia Nacional, and extradition proceedings to Spain are pending.
avoid.net/blazar-token-john-a-desalvo→0/100[CRITICAL]Blazar Token was a fraudulent cryptocurrency created by former New Jersey State Corrections Lieutenant John A. DeSalvo, who marketed it to law enforcement personnel and first responders as a 'crypto pension' supplement beginning in November 2021. DeSalvo raised at least $623,888 from approximately 222 investors through materially false representations, then misappropriated the funds and executed a rug-pull in May 2022 by selling over 41 billion of his own tokens, collapsing the price. He pleaded guilty to federal securities fraud charges in March 2024, and the SEC reached a civil settlement in August 2026 ordering disgorgement of $681,105.
avoid.net/fake-sparrow-wallet-apple-app-store→0/100[CRITICAL]A fraudulent iOS application impersonating Sparrow Wallet — a legitimate Bitcoin wallet that has no official iOS release — passed Apple's App Store review process and operated on the platform between at least May and August 2025, draining a combined $1.84 million in Bitcoin from three victims by capturing their seed phrases. Three plaintiffs filed a federal lawsuit against Apple on July 24, 2026 in the Northern District of California, case 5:26-cv-07713, alleging negligence, fraudulent misrepresentation, and strict products liability; the actual perpetrators behind the fraudulent app remain unidentified.
avoid.net/titan→8/100[CRITICAL]TITAN (IRON Titanium Token) was the governance and collateral token of Iron Finance, a partially-collateralized algorithmic stablecoin protocol deployed on Polygon in May 2021. On June 16–17, 2021, the protocol suffered a catastrophic collapse — described by the Iron Finance team as 'the world's first large-scale crypto bank run' — during which TITAN's price fell from an all-time high of approximately $65 to effectively zero within hours, wiping out an estimated $2 billion in total value locked. The collapse was attributed by the Iron Finance team and independent analysts, including the U.S. Federal Reserve, to a fundamental design flaw in the protocol's stabilization mechanism rather than intentional fraud, though allegations of a rug pull circulated widely in the immediate aftermath.
avoid.net/irs-digital-asset-compliance-portal-phishing-campaign-2026→0/100[CRITICAL]Beginning in late July 2026, an organized criminal operation mailed counterfeit IRS letters to US cryptocurrency holders directing them via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest credentials and drain digital asset accounts. IRS Criminal Investigation confirmed the campaign on July 30, 2026, stating no such portal exists; infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior phishing history.
avoid.net/pump-fun-solana-labs-jito-labs-rico-mev-class-action-sdny-2026→20/100[CRITICAL]Aguilar v. Baton Corporation Ltd. (Case No. 1:25-cv-00880-CM) is a federal class action lawsuit filed in the U.S. District Court for the Southern District of New York against Pump.fun operator Baton Corporation Ltd., Solana Labs, the Solana Foundation, and their named executives, alleging a coordinated RICO racketeering enterprise centered on the Pump.fun memecoin launchpad. A second amended consolidated complaint was filed January 7, 2026, supported by over 5,000 alleged internal chat logs, and seeks between $4 billion and $5.5 billion in compensatory damages — potentially tripled under RICO. Jito Labs, initially named as a co-defendant for alleged MEV-enabling conduct, obtained a voluntary dismissal of claims against it in September 2025 without any settlement payment.
avoid.net/coldcard-coinkite-firmware-seed-entropy-exploit-multi-actor-august-2026→18/100[CRITICAL]A build-integration defect introduced in Coldcard firmware version 4.0.1 (March 2021) silently routed BIP-39 seed generation to a weak software pseudorandom number generator instead of the device's STM32 hardware random number generator, reducing effective entropy from the intended 128 bits to as low as 40 bits on Mk3 devices and approximately 72 bits on Mk4, Mk5, and Q models. Beginning July 30, 2026, at least 15 independent threat actors exploited the flaw to brute-force private keys offline and sweep affected wallets without physical device access. As of August 10, 2026, losses exceed 2,055 BTC (approximately $130 million USD) across more than 7,700 addresses, making this the largest hardware wallet exploit on record.
avoid.net/ashcrypto-roya-token-pump-and-dump→4/100[CRITICAL]Ashcrypto (X: @Ashcryptoreal) is a crypto influencer with over 2.1 million followers on X who was alleged by on-chain investigator ZachXBT in May 2026 to have executed a pump-and-dump scheme involving ROYA, the native token of Royale Finance. According to ZachXBT's published evidence, Ashcrypto publicly promoted ROYA while privately messaging premium-channel followers that his team was 'holding 100%' and buying more, while simultaneously selling. Ashcrypto did not respond to requests for comment and had not publicly addressed the allegations as of the time of reporting.
avoid.net/tiffany-milanovich→0/100[CRITICAL]Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.
avoid.net/fun-coffee-gcm-project→0/100[CRITICAL]Fun Coffee, also marketed as the GCM Project, was a purported Vietnam-based coffee technology investment scheme that operated a cryptocurrency deposit and multi-level-commission structure promising annual returns of 197% to 278%. The scheme entered the Hong Kong market in late 2025, was placed on the Hong Kong Securities and Futures Commission's suspicious investment product alert list on July 13, 2026, and collapsed on approximately July 20, 2026, when its mobile app, withdrawals, and customer support went offline simultaneously. A joint Hong Kong–Macau police operation in August 2026 resulted in eight arrests; a ninth arrest followed in Singapore. Confirmed police-reported losses stand at approximately HK$104 million (US$13.3 million) across more than 255 complaints as of early August 2026, while investors in a roughly 4,000-member chat group allege combined losses exceeding HK$1 billion (US$127 million).
avoid.net/eu-mica-post-deadline-regulator-impersonation-scam-cluster→0/100[CRITICAL]Following the expiration of the EU Markets in Crypto-Assets (MiCA) transitional period on July 1, 2026, a cluster of fraud operations emerged targeting crypto users displaced by the mass exit of more than 1,700 unlicensed exchanges from the European market. Fraudsters impersonate officials from ESMA, France's AMF, the Dutch AFM, and other national regulators, directing victims to transfer assets to criminal-controlled fake websites under the guise of regulatory compliance. Multiple EU financial watchdogs publicly warned of the scam wave in early August 2026, characterizing the transition window as unusually favorable for fraudsters.
avoid.net/coinsbuy→26/100[WARNING]Coinsbuy (coinsbuy.com) is a B2B cryptocurrency payments platform and exchange incorporated in Saint Vincent and the Grenadines, with reported operational presence in Panama. On August 9, 2026, wallets linked to the platform were drained of approximately $7.9–8.07 million across Ethereum and TRON networks in a coordinated cross-chain attack. The company stated that all affected client funds were covered from its own reserves, though the attack vector remained publicly unconfirmed as of mid-August 2026.
avoid.net/libra-diem→25/100[CRITICAL]Libra was a proposed global cryptocurrency announced by Facebook (now Meta) on June 18, 2019, initially designed as a multi-currency-backed stablecoin governed by an independent consortium called the Libra Association. The project faced immediate and sustained opposition from U.S. and international regulators, lost the majority of its founding payment-industry partners within months of announcement, underwent significant structural changes and a rebrand to Diem in December 2020, and ultimately shut down in January 2022 when the Diem Association sold its intellectual property and technology assets to Silvergate Capital Corporation for approximately $182 million. The acquired assets were subsequently written down to near zero when Silvergate itself collapsed in March 2023.
avoid.net/trump-memecoin-august-2026-sec-investigation-request→4/100[CRITICAL]The $TRUMP (Official Trump) memecoin launched on the Solana blockchain on January 17, 2025, two days before Donald Trump's presidential inauguration, and rapidly surged to a peak of approximately $75 before declining more than 98% to around $1.51 as of August 2026. Trump-affiliated entities — CIC Digital LLC and Fight Fight Fight LLC — retained 80% of the 1 billion token supply and have collectively earned an estimated $636 million in royalties, while approximately 988,905 retail investors accumulated losses exceeding $3.81 billion. On August 4, 2026, Senators Elizabeth Warren and Richard Blumenthal formally demanded that SEC Chairman Paul Atkins open an investigation into the token's alleged fraudulent enrichment schemes, though the SEC's own February 2025 guidance classifying memecoins as non-securities limits its enforcement authority.
avoid.net/blockfills-reliz-technology-group→12/100[CRITICAL]BlockFills, a Chicago-based institutional crypto trading and liquidity provider operating under parent entity Reliz Technology Group Holdings Inc., filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of Delaware on March 15, 2026, listing up to $500 million in liabilities against $50–100 million in assets. The filing followed the suspension of client deposits and withdrawals in February 2026, a lawsuit by creditor Dominion Capital alleging that client funds were commingled with company accounts, and a federal court order freezing approximately 70.6 BTC. A plan of reorganization was confirmed on July 13, 2026, with Keyrock completing the acquisition of BlockFills' trading and brokerage assets for $3.25 million.
avoid.net/cosmos-atom→42/100[WARNING]Cosmos is a Layer 1 blockchain protocol and interoperability hub founded by Jae Kwon and Ethan Buchman, with its mainnet launching in March 2019. The project pioneered the Inter-Blockchain Communication (IBC) protocol, enabling sovereign blockchains to transfer assets and data across networks. While the protocol has broad institutional adoption and a large ecosystem, it has faced material governance controversies, a serious security incident involving alleged North Korean developer contributions to its Liquid Staking Module, leadership fragmentation, and persistent concerns over the Interchain Foundation's financial transparency.
avoid.net/catfi-memecoin-catfi→2/100[CRITICAL]CATFI was a Solana-based memecoin launched via Pump.fun whose operators, led by a suspect identified only as Park (alias 'Eth Father'), orchestrated a coordinated pump-and-dump that caused approximately 900 million won (~$600,000) in investor losses across 256 victims in early 2025. South Korean authorities arrested five individuals in May 2026, resulting in South Korea's first criminal prosecution for a decentralized-exchange rug pull under the Virtual Asset User Protection Act, and the ringleader was sentenced to four years in prison by the Seoul Southern District Court on July 23, 2026.
avoid.net/cream-finance→0/100[CRITICAL]C.R.E.A.M. Finance is a decentralized lending protocol that launched on Ethereum in August 2020, originally forked from Compound Finance. The protocol suffered three major exploits across 2021, losing approximately $186 million in total user funds, and has been effectively dormant since early 2022 with minimal development activity and a TVL that collapsed from over $2 billion to under $3 million.
avoid.net/ravencoin-rvn→7/100[CRITICAL]In August 2026, Ravencoin's mainnet suffered a critical consensus vulnerability in its KAWPOW proof-of-work algorithm that allowed attackers to produce invalid blocks at a fraction of normal mining cost, beginning at block height 4,487,776 on August 7, 2026. Majority mining pools took unilateral control of the recovery process, issuing a patch without the core development team and threatening a deep three-day blockchain reorganization that would reverse all transactions since block 4,487,775. The incident — the network's third known consensus or supply failure — triggered an approximately 19-20% price crash, exchange-wide suspension of RVN transfers, and raised acute governance concerns about the project's effectively inactive development team.
avoid.net/stablr-multisig-exploit-and-eurr-usdr-depeg→28/100[WARNING]StablR is a Malta-licensed, MiCA-compliant stablecoin issuer backed by Tether that issues EURR (euro-pegged) and USDR (dollar-pegged) tokens on Ethereum and Solana. On May 24, 2026, an attacker compromised one signer in the platform's 1-of-3 minting multisig, replaced the remaining legitimate owners with malicious addresses, and minted approximately $13.5 million in unbacked tokens, realizing roughly $2.8 million (1,115 ETH) in net proceeds by dumping on decentralized exchanges. Both stablecoins lost significant peg value within hours; as of late July 2026, minting and redemption remain suspended and the reserve deficit had not been publicly resolved.
avoid.net/blockstream-jade-fake-firmware-phishing-campaign-august-2026→0/100[CRITICAL]A recurring phishing campaign has targeted owners of Blockstream Jade Bitcoin hardware wallets by sending fraudulent emails that impersonate Blockstream and claim to offer firmware updates. Blockstream first issued an official alert on September 12, 2025, confirming it never distributes firmware via email and that no Jade devices were confirmed compromised. The threat resurged in August 2026 in the wake of the high-profile Coldcard hardware wallet exploit, as opportunistic attackers broadened impersonation campaigns across the hardware wallet sector.
avoid.net/2026-violent-crypto-wrench-attack-wave-h1-chainalysis-report→0/100[CRITICAL]In H1 2026, physical coercion attacks ('wrench attacks') targeting cryptocurrency holders reached record levels, with Chainalysis documenting 46 incidents and over $30 million in confirmed losses, while CertiK's parallel Intel3D report verified 52 incidents and $124 million in total financial exposure. France emerged as the global epicenter, accounting for 33 of 52 verified incidents, largely attributed to a 2024 theft of tax records by a French government official and a separate breach of crypto tax platform Waltio affecting 50,000 users. The attack wave is on pace to surpass every prior full-year record and represents a structural shift in crypto crime toward physical coercion that bypasses on-chain security entirely.
avoid.net/harmony-protocol-one-token-unauthorized-mint-exploit-august-2026→0/100[CRITICAL]On August 12, 2026, Harmony Protocol confirmed an exploit in which approximately 4 billion ONE tokens were minted without authorization through a flaw in cross-shard receipt verification, representing roughly 26% of the token's prior circulating supply. An estimated 2.8 billion of the minted tokens (approximately 97% of the illicit supply) were transferred to centralized exchanges before Harmony could coordinate a freeze response; the token price fell between 30% and 40% to a record low of approximately $0.0005735. Harmony released emergency validator patch v2026.1.1 and paused its Horizon bridge while evaluating a potential blockchain rollback, but the root cause and confirmed token totals had not been officially disclosed as of the date of this report.
avoid.net/gotbit-vortex-antier-contrarian-doj-crypto-market-maker-manipulation-ring→0/100[CRITICAL]Four cryptocurrency market-making firms — Gotbit Consulting, Vortex, Antier Solutions, and Contrarian — were the subjects of coordinated DOJ criminal indictments filed between October 2024 and September 2025 and publicly announced on March 30, 2026. Ten foreign nationals were charged across three separate federal indictments in the Northern District of California and the District of Massachusetts for conducting wash trading and pump-and-dump schemes affecting over 60 cryptocurrency tokens, resulting in the seizure of more than $25 million in digital assets. Gotbit founder Aleksei Andriunin pleaded guilty and was sentenced to eight months in federal prison in June 2025, and Gotbit was ordered to forfeit approximately $23 million in cryptocurrency and cease operations.
avoid.net/hong-kong-insurance-agent-romance-scam-fake-crypto-app-3-3m-july-2026→0/100[CRITICAL]In late July 2026, Hong Kong police reported that a woman in her fifties working in insurance lost more than HK$26 million (approximately US$3.3 million) to a pig-butchering romance scheme involving a fraudulent cryptocurrency investment application that displayed fabricated returns exceeding 800%. The case was the largest among 25 romance-linked investment fraud cases recorded by Hong Kong police in the week of July 24–30, 2026, which collectively resulted in losses of nearly HK$70 million (approximately US$8.9 million). No specific perpetrators have been publicly named or charged as of the reporting date.
avoid.net/nicolo-nourafchan-robert-yadgarov-sec-doj-insider-trading-ring→0/100[CRITICAL]On May 6, 2026, the SEC and DOJ charged 30 individuals — with the SEC filing civil charges against 21 of them — in connection with an alleged decade-long insider trading scheme orchestrated by M&A attorney Nicolo Nourafchan and his partner Robert Yadgarov. Nourafchan allegedly misappropriated material nonpublic information from confidential client files at multiple elite BigLaw firms including Sidley Austin, Latham & Watkins, Cleary Gottlieb, and Goodwin Procter, then distributed tips through a tiered network of middlemen and traders in exchange for cash kickbacks. The alleged scheme spanned roughly 30 M&A transactions, generated tens of millions of dollars in illicit profits, and involved fugitives in Russia and Israel as well as international regulatory cooperation across five foreign jurisdictions.
avoid.net/263m-rico-social-engineering-crypto-theft-gang-dc-2024-2026-prosecutions→0/100[CRITICAL]The Social Engineering Enterprise (SEE) is a multi-state organized crime network that prosecutors allege stole over $263 million in cryptocurrency from multiple victims between October 2023 and May 2025, including over 4,100 Bitcoin from a single Washington, D.C. resident on August 18, 2024 — described by federal prosecutors as one of the largest single-victim cryptocurrency thefts in U.S. history. Formed through online gaming platform connections and prosecuted under the federal RICO statute in the U.S. District Court for the District of Columbia, the enterprise had 17 individuals charged as of late 2025, with 9 guilty pleas entered and at least two sentencings completed as of mid-2026.
avoid.net/mica-non-compliant-exchange-risk-cluster-post-july-1-2026→0/100[CRITICAL]From July 1, 2026, the EU's Markets in Crypto-Assets Regulation (MiCA) entered full enforcement, requiring all crypto-asset service providers (CASPs) serving EU residents to hold a valid authorisation from an EU national competent authority. Approximately 80% of previously operating exchanges failed to obtain authorisation by the deadline, creating a systemic consumer-protection risk cluster in which EU retail users holding assets on unlicensed platforms face potential account restrictions, withdrawal freezes, and — in at least one documented case (AscendEX) — possible permanent loss of funds due to exchange insolvency. ESMA maintains a formal register of both authorised CASPs and flagged non-compliant entities, but coverage of the latter is acknowledged to be incomplete.
avoid.net/july-2026-bridge-hack-wave-three-protocols-35-6m-one-day→0/100[CRITICAL]On July 22–23, 2026, three separate cross-chain bridge protocols — AFX Trade, B-Squared Network, and Verus — were exploited within approximately six hours of each other for a combined loss of roughly $35.6 million. The incidents contributed to a July 2026 monthly total of approximately $97 million in crypto security losses and are part of a record-setting H1 2026 in which total hack losses surpassed $1 billion across the industry. No single threat actor has been publicly attributed to all three attacks, though the clustering prompted security firm Blockaid to label the period 'Hackers Day.'
avoid.net/ascendex-bitmax→0/100[CRITICAL]AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.
avoid.net/movement-labs→0/100[CRITICAL]Movement Labs, the original development company behind the Movement blockchain and MOVE token, filed for Chapter 11 bankruptcy on July 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware. The filing followed a prolonged crisis triggered by a December 2024 market-making arrangement in which 66 million MOVE tokens — approximately 5% of total supply — were sold into the market one day after the token's exchange debut, creating roughly $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the token launch is ongoing as of mid-2026, and MOVE has lost over 94% of its peak value.
avoid.net/rushi-manche→0/100[CRITICAL]Rushikesh 'Rushi' Manche is the co-founder and former CEO of Movement Labs (MVMT Labs, Inc.), a blockchain infrastructure startup that raised at a $3 billion valuation and launched the MOVE token in December 2024. He was suspended on May 2, 2025 and terminated on May 7, 2025 following a third-party investigation by Groom Lake that, according to Movement Labs, linked him to a controversial market-making arrangement with intermediary Rentech and Chinese firm Web3Port that allegedly enabled a coordinated dump of approximately 66 million MOVE tokens within 24 hours of launch, causing an estimated $38 million in downward price pressure. A U.S. Department of Justice grand jury investigation into the MOVE token launch is confirmed; as of the date of this page no charges, indictment, or criminal finding against Manche has been publicly reported. MVMT Labs filed for Chapter 11 bankruptcy on July 15, 2026, listing Manche as its largest unsecured creditor with a $1.6 million claim while he simultaneously retains a 34.25% equity stake in the company.
avoid.net/novatech-ltd-cynthia-petion-650m-crypto-mlm-fraud→0/100[CRITICAL]NovaTech Ltd. (also marketed as NovaTech FX), incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion, is alleged by U.S. and Canadian regulators to have operated a fraudulent multi-level marketing and crypto investment scheme from June 2019 through May 2023 that raised more than $650 million from over 200,000 investors worldwide. The SEC filed a civil complaint on August 12, 2024, alleging the scheme functioned as a Ponzi, with new investor funds used to pay earlier participants rather than traded as claimed. Regulatory bodies in three jurisdictions — the U.S. SEC, Ontario's Capital Markets Tribunal, and the Maryland Securities Commissioner — have each taken enforcement action; as of the investigation date, the SEC civil litigation remains ongoing and no criminal convictions have been entered.
avoid.net/storj-labs→23/100[CRITICAL]Storj Labs, the company behind the decentralized cloud storage protocol and STORJ token, filed for voluntary Chapter 11 bankruptcy protection on July 26, 2026 in the U.S. Bankruptcy Court for the Northern District of West Virginia (case 5:26-bk-00512). The company attributes the filing to legacy financial obligations predating its current operating strategy, not to operational failure, and states that its decentralized storage network and customer services remain uninterrupted. STORJ token holders face significant uncertainty: the company has proposed an equity conversion mechanism, but terms remain undisclosed, court approval is required, and token holders rank behind all creditors under standard bankruptcy law.
avoid.net/ravencoin-consensus-vulnerability-exploit-august-2026→0/100[CRITICAL]On August 7, 2026, an attacker exploited a critical consensus vulnerability in the Ravencoin (RVN) network by manipulating the nHeight field in KAWPOW block headers to bypass proof-of-work verification. Invalid blocks were accepted by vulnerable nodes beginning at block height 4,487,776, prompting exchanges Upbit, Bitget, and Bitvavo to suspend RVN deposits and withdrawals and causing RVN to fall approximately 19% to around $0.00288. An emergency patch (v4.6.1.1-hf1) was released on August 10, 2026 by mining pool 2Miners rather than Ravencoin's core development team, marking at least the third significant consensus-level failure in the network's history.
avoid.net/shipmonk→16/100[CRITICAL]ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.
avoid.net/ascendex-insolvency-and-withdrawal-freeze-july-2026→0/100[CRITICAL]AscendEX (formerly BitMax), a Singapore-headquartered centralized crypto exchange founded in 2018, ceased all operations on July 1, 2026, citing a failure to obtain EU MiCA authorization and the collapse of a strategic liquidity transaction. On-chain data showed exchange reserves dropped by more than $240 million on June 20, 2026; by July 8 only approximately $13.45 million remained on-chain, over $12 million of which consisted of the exchange's own illiquid ASD and UNITE tokens. As of the investigation date, automated withdrawals have been frozen since July 6, 2026, replaced with a manual review process offering no guaranteed timeline or recovery amounts, and the exchange's own legal notice warned that formal insolvency proceedings could follow.
avoid.net/unidentified-crypto-whale-25-6m-repeated-phishing-drain→0/100[CRITICAL]On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.
avoid.net/bitradex→0/100[CRITICAL]BitradeX (operating primarily at bitradex.ai and previously bitradex.com) is an alleged MLM-structured cryptocurrency trading platform that markets AI-powered trading bots promising annualised returns of 109.5%–182.5%. Launched in early 2025 and promoted via French footballer Olivier Giroud as global brand ambassador from June 2025, the platform has received formal investor warnings from three regulators — Thailand's SEC (February 2026), Securities Commission Malaysia (March 2026), and the Alberta Securities Commission (April 2026) — each citing lack of registration or authorisation. BehindMLM and other analyst sources characterise the scheme as a Ponzi and pyramid hybrid with no retail product, Chinese-origin ownership obscured behind a UK-registered shell, and a pattern of withdrawal blocks consistent with schemes in terminal decline. As of August 2026, the platform reportedly ceased withdrawals and deployed an exit-scam narrative.
avoid.net/coreum-xrpl-bridge-exploit-august-2026→6/100[CRITICAL]On August 9, 2026, an attacker exploited a deposit-verification flaw in the cross-chain bridge connecting the XRP Ledger to the Coreum blockchain (operated by tx, formerly Coreum and Sologenic), draining 199,916.3 XRP — approximately $200,000 and 99.7% of the bridge's total reserve — across 94 multisig transactions over 97 minutes. The bridge was halted by tx as of August 11, 2026; bridged XRP on the tx chain is not fully backed as of the most recent reporting, and no compensation plan had been announced as of August 13, 2026.
avoid.net/ascendex→0/100[CRITICAL]AscendEX (formerly BitMax), a centralized cryptocurrency exchange founded in 2018, ceased all normal operations on July 1, 2026, after a capital restructuring deal with The Royal Investment Bank of Kelantan Inc. (RIBK) collapsed. The exchange froze automated withdrawals on July 6, 2026, disclosed it may be insolvent, and explicitly stated it could not guarantee full recovery of customer funds. The closure compounded a prior $77.7 million hot-wallet breach suffered in December 2021.
avoid.net/htx-fca-uk-enforcement-illegal-crypto-promotions-2026→10/100[CRITICAL]The UK Financial Conduct Authority commenced High Court proceedings on 21 October 2025 against Huobi Global S.A. (the Panamanian entity behind the HTX exchange, formerly Huobi) and multiple categories of 'persons unknown', alleging repeated breach of Section 21 of the Financial Services and Markets Act 2000 by promoting cryptoasset services to UK consumers without authorisation. This is the FCA's first enforcement action against an offshore crypto exchange for illegal financial promotions. As of August 2026, proceedings are stayed while settlement talks continue; no court ruling on the merits has been issued.
avoid.net/mev-bot-scam-youtube-ai-trading-bot-campaign-2026→0/100[CRITICAL]An ongoing campaign, active since at least mid-2022 and continuing through 2025, uses AI-generated YouTube videos to promote malicious Solidity smart contracts disguised as Maximal Extractable Value (MEV) arbitrage trading bots. According to SentinelOne Labs (SentinelLABS), one attacker wallet alone collected approximately 244.9 ETH (roughly $902,000 USD) from victims, with total documented losses across the broader campaign exceeding $1 million. Victims are deceived into deploying backdoored contracts via Remix IDE and depositing ETH, which is then routed directly to attacker-controlled wallets through obfuscated code.
avoid.net/vy-pham→0/100[CRITICAL]Vy Pham is a California-based cryptocurrency promoter charged in October 2024 by both the U.S. Department of Justice (DOJ) and the U.S. Securities and Exchange Commission (SEC) in connection with alleged market manipulation of two meme tokens: Saitama Inu and Robo Inu Finance. Pham agreed to plead guilty to conspiracy to commit market manipulation, conspiracy to commit wire fraud, and operating an unlicensed money transmitting business. The charges are part of a coordinated federal enforcement action, Operation Token Mirrors, which targeted 18 individuals and entities for widespread fraud in cryptocurrency markets.
avoid.net/rainberry-inc→13/100[CRITICAL]Rainberry Inc, formerly BitTorrent Inc and the developer of the BitTorrent protocol and BitTorrent Token (BTT), agreed in March 2026 to pay a $10 million civil penalty to settle SEC allegations that it facilitated wash trading to artificially inflate trading volume for the TRX cryptocurrency in 2018–2019. The settlement, filed as a proposed final judgment in U.S. District Court for the Southern District of New York, did not require any admission of wrongdoing. All remaining claims against Rainberry, Justin Sun (Tron founder and controlling owner), Tron Foundation, and BitTorrent Foundation were dismissed with prejudice.
avoid.net/debank-auction→0/100[CRITICAL]debank[.]auction is a malicious domain impersonating DeBank (debank.com), a legitimate decentralized finance portfolio tracker founded in 2018. Documented by Zscaler ThreatLabz in July 2026, the site combines typosquatting with indirect prompt injection (IPI) — embedding hidden instructions in its HTML to manipulate AI agents into misclassifying the fraudulent domain as the authoritative DeBank platform. The campaign represents an active, real-world exploitation of autonomous AI agents rather than solely targeting human users.
avoid.net/requests-secure-v2→0/100[CRITICAL]requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.
avoid.net/fbi-fake-token-tron-impersonation-wallet-freeze-extortion-scam-march-2026→0/100[CRITICAL]In March 2026, an unidentified threat actor deployed fraudulent TRC-20 tokens on the Tron network branded as FBI assets and airdropped them to at least 728 wallets, including high-net-worth addresses holding seven-figure USDT balances. The tokens carried messages falsely claiming recipient wallets were frozen for anti-money laundering violations and directed holders to an external phishing site demanding identity and credential submission. The FBI's New York Field Office issued an official warning on March 19, 2026, confirming it does not distribute tokens or request blockchain-based identity verification of any kind.
avoid.net/liquid-global→0/100[CRITICAL]Liquid Global (operating under its parent entity Quoine Pte. Ltd.) was a Japanese-headquartered cryptocurrency exchange founded in 2014 and rebranded from QUOINE to Liquid in 2018. In August 2021, the exchange suffered one of the largest exchange hacks of that year — approximately $97 million in Bitcoin, Ethereum, XRP, TRON, and other tokens stolen — with the attack subsequently attributed by Chainalysis to actors working on behalf of the DPRK, consistent with Lazarus Group tradecraft. FTX provided a $120 million emergency loan days after the breach, then acquired Liquid outright in April 2022; when FTX itself filed for Chapter 11 bankruptcy in November 2022, Liquid halted all withdrawals and customer funds were caught in the subsequent restructuring proceedings.
avoid.net/malone-lam-crypto-syndicate→0/100[CRITICAL]The Malone Lam Crypto Syndicate, also known as the Social Engineering Enterprise (SEE), is an alleged multi-state criminal organization that stole approximately $263 million in cryptocurrency between October 2023 and May 2025 through social engineering, residential home invasions, and hardware wallet theft. Led by Singaporean national Malone Lam (alias 'Anne Hathaway', 'Greavys'), the enterprise comprised at least 14 members recruited through online gaming platforms and operated specialized roles including database hackers, social engineering callers, money launderers, and physical burglars. The DOJ charged the organization under the RICO statute — one of the most aggressive crypto theft prosecutions ever filed — and as of June 2026, nine co-defendants have pleaded guilty and been sentenced to 70–78 months, while Lam and co-lead Jeandiel Serrano remain in pre-trial proceedings.
avoid.net/astroport→46/100[WARNING]Astroport is a decentralized exchange (DEX) and automated market maker (AMM) protocol originally launched on the Terra blockchain in December 2021 and subsequently rebuilt across multiple Cosmos ecosystem chains after Terra's collapse in May 2022. On July 30, 2024, the protocol suffered a significant security exploit on the Terra (Phoenix) chain resulting in approximately $6.4 million in losses due to a reentrancy vulnerability in IBC hooks that had been patched in April 2024 but accidentally reintroduced in a June 2024 upgrade. The protocol itself was the victim of this exploit; partial recovery was achieved by seizing attacker funds on Neutron and blacklisting addresses on Terra, though a portion of stolen assets reached Ethereum and remain unrecovered.
avoid.net/broox-bauer-axiom-insider-trading-ring→0/100[CRITICAL]Broox Bauer, a senior business development employee at Axiom Exchange, was publicly identified in February 2026 by on-chain investigator ZachXBT as the alleged orchestrator of an insider trading scheme running from early 2025. Bauer allegedly abused internal access to Axiom's customer support dashboard to extract private wallet data belonging to users and key opinion leaders, sharing that data with a small group to front-run trades. Axiom, a Y Combinator-backed Solana trading terminal that generated over $390 million in cumulative revenue, acknowledged the misconduct, terminated access to the relevant tools, and stated it would investigate and hold the responsible parties accountable.
avoid.net/axiom-trading→28/100[WARNING]Axiom Trading (axiom.trade) is a Y Combinator Winter 2025-backed Solana trading terminal that generated over $390 million in revenue since its January 2025 launch. In February 2026, blockchain investigator ZachXBT published a report alleging that senior business development employee Broox Bauer and associates systematically abused internal customer support tools to access private user wallet data and front-run customer trades for more than ten months, with alleged profits exceeding $400,000. Axiom removed access to the implicated tools and stated it was investigating, but no public disclosure of disciplinary or legal outcomes had been made as of June 2026.
avoid.net/axiom-dex→18/100[CRITICAL]Axiom is a Solana-based crypto trading platform founded in 2024 by Henry Zhang ('Mist') and Preston Ellis ('Cal'), which completed Y Combinator's Winter 2025 batch and generated over $390 million in cumulative revenue. In February 2026, blockchain investigator ZachXBT published a documented investigation revealing that a senior business development employee, Broox Bauer, along with colleagues, systematically abused internal dashboard tools with insufficient access controls to access private user wallet data and conduct insider trading for over 10 months beginning in early 2025. Axiom confirmed the breach, removed access to the implicated tools, and pledged an internal investigation, but no formal legal charges had been publicly filed as of the date of reporting.
avoid.net/heisenberg-guru-hsbg→0/100[CRITICAL]Heisenberg Guru (HSBG) is a Hong Kong-based cryptocurrency market maker alleged by on-chain investigator ZachXBT to have orchestrated coordinated supply-control manipulation schemes across at least six tokens — RIVER, RAVE, SIREN, MYX, SKYAI, and LAB — primarily through Bitget, with Binance and Gate.io as secondary venues. On May 19, 2026, ZachXBT posted a $10,000 personal bounty for insider evidence identifying the firm's operators, naming 'Sion' and 'Chao' as core team members. As of May 31, 2026, HSBG has not publicly responded to the allegations, no regulatory action has been confirmed, and the bounty remains open.
avoid.net/axiom-dex-insider-trading-broox-bauer→8/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that Broox Bauer, a senior business development employee at Axiom Exchange — a Solana-based trading platform backed by Y Combinator — exploited internal dashboard access controls to retrieve private user wallet data and coordinate front-running trades over approximately ten months. The alleged scheme involved compiling key opinion leader (KOL) wallet addresses into shared Google Sheets to position ahead of anticipated price moves, with alleged profits cited at over $400,000. Axiom stated it was shocked, revoked access, and pledged an internal investigation; no independent forensic audit or formal regulatory action had been publicly announced as of June 2026.
avoid.net/crypto-whale-repeat-phishing-drain-august-2026→2/100[CRITICAL]On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.
avoid.net/eclipse→22/100[CRITICAL]Eclipse is a Layer 2 blockchain on Ethereum that uses the Solana Virtual Machine (SVM) for execution, Celestia for data availability, and Ethereum for settlement. Developed by Eclipse Labs and launched on mainnet in November 2024, the project has experienced significant turbulence including the removal of its founder over sexual misconduct allegations, a heavily criticized token airdrop, a 95% TVL collapse, and a 65% workforce reduction in August 2025. As of early 2026, the project publicly admitted it had 'no users' and pivoted to building consumer applications in-house.
avoid.net/jewelbug-apt→0/100[CRITICAL]Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.
avoid.net/george-santos-cftc-prediction-market-manipulation→0/100[CRITICAL]Former U.S. Congressman George Anthony Devolder Santos was found by the Commodity Futures Trading Commission to have manipulated event contracts on the prediction market platform Kalshi by trading on his own attendance at the 2026 State of the Union address while making misleading public statements on social media to move contract prices in his favor. On July 31, 2026, Santos settled the action — without admitting or denying the findings — agreeing to disgorge $17,569.98 in profits, pay a $17,500 civil monetary penalty, and accept a three-year ban from all CFTC-registered entities. The case is described by multiple outlets as the first federal sanction imposed for political prediction market manipulation, though it follows separate earlier CFTC enforcement activity targeting insider trading in event contracts.
avoid.net/rossen-iossifov-rg-coins→0/100[CRITICAL]Rossen G. Iossifov, a 53-year-old Bulgarian national, owned and operated RG Coins, a cryptocurrency exchange in Sofia, Bulgaria that served as the primary off-ramp for the Alexandria (Romania) Online Auction Fraud Network, laundering nearly $5 million in crypto proceeds defrauded from approximately 900 American victims. Convicted in 2020 and sentenced in January 2021 to 121 months in federal prison, Iossifov was charged again in July 2026 with allegedly conspiring from his prison cell to steal and launder $290,000 in cryptocurrency that had already been ordered forfeited to the United States government following his prior conviction.
avoid.net/oraichain-evm-cross-chain-unauthorized-minting-exploit-august-2026→22/100[CRITICAL]On August 9, 2026, Oraichain — an AI-focused Layer 1 blockchain — suffered a supply-integrity exploit in which a vulnerability in its EVM cross-chain transfer path enabled the unauthorized minting of ORAI tokens. The team halted the entire network at 04:00 UTC, restricted all bridges and cross-chain routes, and coordinated with centralized exchanges including MEXC to freeze fund movements. As of mid-August 2026, the exploit path had been addressed, the network had been restored, and the team was preparing to burn the unauthorized minted balances to reconcile canonical ORAI supply.
avoid.net/node-gyp-npm-supply-chain-compromise-june-2026→0/100[CRITICAL]In June 2026, a self-propagating npm supply chain worm designated 'Miasma' exploited a novel install-time execution technique called 'Phantom Gyp' — abusing binding.gyp configuration files to trigger malicious code during npm install. The campaign spread across 57 packages and 286+ malicious versions, harvesting developer and CI/CD credentials from npm, GitHub, AWS, GCP, Azure, HashiCorp Vault, and Kubernetes, and then self-propagating by republishing poisoned releases using stolen publishing tokens. The attack poses a direct threat to crypto developers whose CI/CD pipelines manage private keys, wallet seed phrases, and signing infrastructure.
avoid.net/allbridge-core-second-flash-loan-exploit-july-2026→6/100[CRITICAL]On July 19–20, 2026, Allbridge Core, a cross-chain stablecoin bridge protocol, suffered a $1.65–1.66 million flash-loan exploit targeting its Solana USDC/USDT liquidity pools — the second structurally similar attack on the protocol since April 2023. An attacker borrowed $1.12 million USDC from Kamino Finance, manipulated the pool's internal stablecoin ratio through rapid swaps, extracted liquidity at distorted rates, then bridged the proceeds to Ethereum before the protocol was paused. The incident raised serious questions about the completeness of post-2023 remediation, specifically the failure to apply the protocol's own 'single-pool per blockchain' fix to its Solana deployment.
avoid.net/robinhood-chain-scam-ecosystem→2/100[CRITICAL]Robinhood Chain, an Arbitrum-based Ethereum Layer 2 launched by Robinhood Markets on July 1, 2026, experienced a rapid influx of fraudulent tokens within days of its permissionless mainnet going live, including honeypot contracts, vanishing-token scams, wallet-drainer schemes, and memecoin rug pulls. On July 23, 2026, the verified X account of Robinhood CEO Vlad Tenev was compromised and used to promote a fake memecoin called 'Vladhood' (VLAD), which generated approximately $22 million in trading volume before the post was removed. This page covers the scam ecosystem that emerged on Robinhood Chain and is distinct from Robinhood Markets, Inc. and its legitimate crypto brokerage operations.
avoid.net/misam-m-abidi→0/100[CRITICAL]Misam M. Abidi, 47, of Nolensville, Tennessee, is an independent candidate for Tennessee Governor who was indicted on June 12, 2026 by a federal grand jury in the Western District of Tennessee on 11 counts including wire fraud, money laundering, unlicensed money transmission, and aiding in false tax return preparation. Federal prosecutors allege Abidi operated Star Credit Holdings as a cryptocurrency Ponzi scheme between 2020 and 2024, diverting over $1.9 million of investor funds to himself and family members. Abidi and his associates also face a separate 2024 Tennessee state civil enforcement action involving an alleged $6.3 million fraud spanning 17 states, connected to the STAR Investment Club and the NUME cryptocurrency token issued through NumisMe LLC.
avoid.net/allo-protocol→57/100[CAUTIONARY]Allo Protocol is an open-source, EVM-compatible smart contract framework for on-chain capital allocation, developed by Gitcoin and launched on Ethereum mainnet in November 2023. It served as the underlying infrastructure for Gitcoin Grants Stack from 2023 through May 2025, when Gitcoin's software division (Grants Lab) was shut down due to financial constraints, placing Allo in maintenance mode. No fraud allegations, regulatory actions, or security exploits have been publicly documented against the protocol itself.
avoid.net/bits-of-gold→44/100[WARNING]Bits of Gold is Israel's largest regulated cryptocurrency broker, founded in 2013 and licensed by the Israeli Capital Market, Insurance and Savings Authority since 2022. On August 16-17, 2026, the company disclosed that a third-party analytics vendor breach exposed personal data on approximately 200,000 customers — including national ID numbers, bank account details, and public wallet addresses — stemming from CVE-2026-72898, an actively exploited zero-day in self-hosted Metabase software. Customer crypto funds and private keys were not compromised, and the company has engaged a cybersecurity incident-response firm while notifying Israeli regulators.
avoid.net/crypto-com-phishing-campaign-email-domain-abuse-august-2026→0/100[CRITICAL]An active phishing campaign confirmed on August 10, 2026 exploited Crypto.com's email-sending infrastructure — reportedly via abuse of the company's SendGrid marketing account and its associated branded click-tracking domain (url1137.crypto.com) — to deliver fraudulent messages that bypassed standard email-authentication filters. Crypto.com had issued an industry-wide phishing pre-warning on July 30–31, 2026; the campaign targeting its own users materialized within ten days. The attack is distinct from a breach of Crypto.com's core systems: the company has not confirmed that its primary databases or user accounts were compromised.
avoid.net/france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026→0/100[CRITICAL]In late June 2026, an unauthorized intrusion into France's General Directorate of Public Finances (DGFiP) exposed the personal and financial data of an estimated 678,437 taxpayers, including names, addresses, income figures, withholding rates, and tax identifiers. The breach was publicly claimed on August 12, 2026 by a threat actor using the pseudonym ZeroBytes, and confirmed by French authorities on August 14, 2026. The incident directly amplifies an established pattern of violent physical coercion — so-called wrench attacks — against crypto holders in France, which CertiK and Chainalysis both identified as the global epicenter of such attacks in H1 2026.
avoid.net/star-credit-holdings-misam-m-abidi→2/100[CRITICAL]Star Credit Holdings was a Tennessee-based cryptocurrency investment firm operated by Misam M. Abidi (age 47, of Nolensville, Tennessee) from approximately 2020 to 2024. On June 12, 2026, a federal grand jury in the Western District of Tennessee returned an 11-count indictment against Abidi, alleging he ran a classic Ponzi scheme that diverted over $1.9 million in investor funds to himself and family members. Abidi had previously faced state-level regulatory action in May 2024 over a broader alleged fraud involving Star Credit Holdings, a related cryptocurrency token (NUME/NumisMe), and co-defendants Ali Raza Galani and Anisha Abidi, with total alleged investor losses across 17 states exceeding $6.3 million.
avoid.net/vanta-stealer-python-infostealer-targeting-crypto-wallets→0/100[CRITICAL]Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.
avoid.net/bitmart-exchange-insolvency-claims-and-frozen-withdrawals-august-2026→0/100[CRITICAL]BitMart, a cryptocurrency exchange operating since 2017, announced an orderly wind-down on July 26, 2026, with all trading to cease by August 26, 2026, and full platform closure by January 31, 2027. Following the announcement, multiple users and at least one market-making firm reported being unable to withdraw assets, on-chain data recorded anomalously low withdrawal activity, and an open letter signed by users and employees gave founder Sheldon Xia until August 19 to disclose financial reserves and a repayment plan. Insolvency has been alleged but not independently confirmed; no regulatory body has filed charges or made a formal finding as of August 17, 2026.
avoid.net/doj-pig-butchering-civil-forfeiture-dc-district-july-2026→2/100[CRITICAL]On July 21, 2026, the U.S. Attorney's Office for the District of Columbia and the U.S. Secret Service Washington Field Office filed five civil forfeiture complaints in federal court seeking to recover more than $25 million in USDT traced to pig butchering fraud schemes operated from Southeast Asia. The filings, which proceed against the cryptocurrency assets themselves and name no individual defendants, targeted funds linked to romance scams, approval phishing, and fake investment platforms that defrauded more than 470 identified victims across the United States and Canada. The action is part of the broader DC Scam Center Strike Force, launched in November 2025, which had restrained or seized more than $832 million in cryptocurrency from Chinese transnational criminal organizations by June 2026.
avoid.net/christopher-delgado-goliath-ventures-inc→0/100[CRITICAL]Christopher Alexander Delgado (age 34, Apopka, Florida) was the President and CEO of Goliath Ventures Inc. (formerly Gen-Z Venture Firm), a Florida-based cryptocurrency investment firm that operated as a Ponzi scheme from at least January 2023 through January 2026. Delgado pleaded guilty on June 30, 2026, in the U.S. District Court for the Middle District of Florida to conspiracy to commit wire fraud, wire fraud, and money laundering in connection with a scheme that raised at least $397 million (per CFTC) to $425 million (per SEC) from over 1,300 to 1,611 investors. On August 11, 2026, both the CFTC and SEC filed separate civil enforcement actions against Delgado and Goliath Ventures; Goliath Ventures ceased operations in February 2026 and filed for bankruptcy in March 2026.
avoid.net/shuffle-shuffle-com→26/100[WARNING]Shuffle (shuffle.com) is a crypto casino and sportsbook launched in February 2023, operated by Natural Nine B.V. under a Curacao Gaming Control Board license, and founded by Noah Dummett alongside co-founders Darcy Spangler and Harley Fresh. In October 2025, Shuffle confirmed a major data breach through third-party CRM provider Fast Track that exposed personal data and KYC documents for the majority of its users. In August 2026, blockchain investigator ZachXBT alleged that stolen victim funds were wagered on Shuffle in real time while the alleged thief was on the phone with the victim; Shuffle confirmed it would lock the associated account after reviewing submitted evidence.
avoid.net/changenow→32/100[WARNING]ChangeNOW is a non-custodial, KYC-optional instant cryptocurrency swap service founded in 2017 and operated by CHN Group LLC, incorporated in Saint Vincent and the Grenadines. The platform supports swaps across more than 1,000 crypto assets without mandatory account registration, a design that has made it a recurrent node in post-exploit fund flows. In 2026 alone, stolen funds from two confirmed major hacks — the Gravity Bridge $5.4 million exploit (May 2026) and the Coinsbuy $7.9 million theft (August 2026) — were reportedly routed through ChangeNOW, though no regulatory enforcement action has been taken against the company as of August 2026.
avoid.net/trifleck→0/100[CRITICAL]Trifleck is a shell company with no verifiable business registration used as a front in an active LinkedIn-based malware campaign targeting crypto and Web3 developers, first publicly disclosed in May 2026. The campaign delivers a malicious 'pre-interview code review' ZIP file containing infostealers after recruiters posing as Trifleck employees contact developers with frontend job offers. The attack pattern, infrastructure, and malware families are consistent with tactics attributed by Microsoft, Mandiant, Palo Alto Unit 42, and the FBI to DPRK-aligned threat actors operating under the cluster known as Contagious Interview.
avoid.net/leap-wallet→52/100[CAUTIONARY]Leap Wallet was a non-custodial multi-chain crypto wallet founded in 2021 and backed by $3.2 million from Pantera Capital and CoinFund. Originally built for the Terra ecosystem, it pivoted to Cosmos after Terra's 2022 collapse and grew to support 100+ chains. On April 3, 2026, the team announced permanent cessation of all products effective May 28, 2026, without disclosing a specific reason, creating an eight-week compressed migration window that raised user security concerns.
avoid.net/triple-a-treasury-hack-july-2026→22/100[CRITICAL]Triple-A, a Singapore-based crypto payment platform holding a Major Payment Institution license from the Monetary Authority of Singapore (MAS), suffered an unauthorized access event beginning approximately July 24, 2026, in which approximately $11.8 million in company treasury assets was drained across seven blockchain networks over roughly 31 hours. The attacker consolidated stolen funds as approximately 5,287 ETH at a single Ethereum address. Triple-A stated that client funds were entirely segregated and unaffected, and that the company remained solvent and able to meet all liabilities.
avoid.net/zapper→47/100[WARNING]Zapper was a DeFi portfolio tracking and interaction platform founded in 2019 that reached 2 million monthly active users and raised approximately $16.5 million from investors including Mark Cuban and Framework Ventures. The platform announced it would permanently shut down all services on August 3, 2026, following a sustained decline in market demand and a damaging April 2025 domain hijacking incident in which attackers socially engineered Zapper's domain registrar to redirect users to a phishing page. The shutdown creates immediate user-protection concerns: lingering wallet permissions granted to Zapper's contracts should be revoked, and the closure creates conditions favorable for scammers to launch fake 'Zapper migration' or 'fund recovery' phishing campaigns targeting former users.
avoid.net/atomic-wallet-hack→0/100[CRITICAL]In June 2023, Atomic Wallet — an Estonian non-custodial cryptocurrency wallet with approximately five million users — suffered a major security breach in which attackers drained funds from an estimated 5,500 user wallets. Blockchain analytics firms Elliptic and on-chain investigators attributed the attack to North Korea's Lazarus Group with high confidence, and the FBI later confirmed this attribution. The total loss figure is disputed, with Elliptic placing it above $100 million and independent researcher Taylor Monahan estimating a minimum of $115 million; the underlying attack vector was never publicly confirmed by Atomic Wallet.
avoid.net/letsbonk-fun→20/100[CRITICAL]LetsBonk.fun, later rebranded as Bonk.fun, is a Solana-based memecoin launchpad launched on April 25, 2025 by the BONK community in partnership with Raydium Protocol. The platform rose to capture over 78% of Solana launchpad market share at its mid-2025 peak before experiencing steep decline, and suffered a domain hijack and wallet-drainer attack in March 2026. The platform's permissionless token creation model, built-in multi-wallet bundler tooling, and community reports alleging the platform hosted 'KOL-backed bundled scams' present elevated risk for retail investors.
avoid.net/austrian-albanian-crypto-investment-fraud-ring-europol-april-2026→2/100[CRITICAL]A criminal network operating out of Tirana, Albania, allegedly defrauded victims across Europe and worldwide of at least EUR 50 million through fake cryptocurrency investment platforms and follow-on fund-recovery scams. Austrian and Albanian authorities, supported by Europol and Eurojust, raided three call centers and nine residences on April 17, 2026, arresting ten suspects. No convictions have been recorded as of the investigation date; the arrests and seizures represent the law-enforcement action stage.
avoid.net/crypto-whale-repeat-phishing-25-6m-drain-august-2026→0/100[CRITICAL]On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in WBTC, cbBTC, aWBTC, DAI, ETH, LDO, USDS, and CRV to a phishing attack that induced the victim to authorize malicious token-approval transactions. The same wallet had previously lost $24.2 million in a nearly identical phishing scheme in September 2023, of which approximately 90% was returned; no funds from the 2026 attack had been recovered as of mid-August 2026. The combined gross exposure across both incidents is approximately $49.8 million, making this one of the most consequential repeat-targeting cases in Ethereum's history.
avoid.net/sturdy-v1→54/100[CAUTIONARY]Sturdy Finance V1 was a DeFi lending protocol that allowed users to earn yield on deposits while borrowers accessed interest-free loans backed by staked collateral. On June 12, 2023, an attacker exploited a read-only reentrancy vulnerability in the protocol's price oracle integration — a third-party flaw originating in Balancer — and drained approximately 442 ETH (roughly $800,000). Sturdy V1 paused markets immediately, reopened its stablecoin market within days, and later formally sunset V1 in favor of Sturdy V2, which launched in early 2024 with a redesigned, modular architecture and three additional audits.
avoid.net/manta-network→44/100[WARNING]Manta Network is a modular zero-knowledge blockchain platform consisting of Manta Pacific (an Ethereum L2) and Manta Atlantic (a Polkadot parachain being deprecated as of August 2026). The project launched its MANTA token in January 2024, an event marred by a large-scale DDoS attack on its RPC infrastructure and concurrent allegations — sourced from on-chain data and social media, not regulatory or court filings — that a Korean business development representative dumped 2 million ecosystem tokens at launch. No formal criminal charges or regulatory actions against Manta Network or its founders have been identified as of mid-2026.
avoid.net/dutch-crypto-investment-fraud-ring-2026→0/100[CRITICAL]A large-scale international investment fraud network, dismantled by Dutch and Belgian police in July 2026, operated approximately 20 call centers staffed by over 700 people who posed as financial advisers and used fake cryptocurrency trading platforms to steal an estimated €100 million per month from victims worldwide. The alleged mastermind — Ehud Tenenbaum, a 46-year-old dual Israeli-Polish national known in cybercrime circles as 'The Analyzer' for his late-1990s hacking of U.S. government systems — was arrested in Poland in May 2026 and extradited to the Netherlands. Tens of thousands of victims across multiple countries are estimated, with Dutch victims alone reporting nearly €25 million in losses.
avoid.net/fluid-instadapp→44/100[WARNING]Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.
avoid.net/bonk-fun→44/100[WARNING]BONK.fun (also marketed as LetsBONK.fun) is a no-code meme coin launchpad on the Solana blockchain, launched in April 2025 as a joint initiative between the BONK community and Raydium protocol. The platform rapidly captured majority market share from Pump.fun by mid-2025 before losing significant ground later that year, and suffered a domain-level security breach in March 2026 caused by a social engineering attack on its domain service provider — an incident attributed to the third-party infrastructure provider, not the platform's own code or contracts. The platform is operationally linked to Bonk, Inc. (Nasdaq: BNKK), a publicly traded company that holds a revenue sharing interest in the platform.
avoid.net/shawn-liu→14/100[CRITICAL]Shawn Liu (Chinese name: Liu Shuai) is the founder of Bitget, a major centralized cryptocurrency derivatives exchange, and the founder of Singaporean crypto venture fund Foresight Ventures. In May 2026, on-chain investigator ZachXBT publicly named Liu as the alleged true decision-maker behind Bitget, accusing him of enabling coordinated token supply-manipulation schemes while CEO Gracy Chen serves as the exchange's public face. Liu has not responded to any of the allegations, and no regulatory or legal findings have been made against him personally as of the date of this report.
avoid.net/bond-protocol→54/100[CAUTIONARY]Bond Protocol is a permissionless DeFi infrastructure platform launched in October 2022, originating from OlympusDAO's bonding mechanism, that enables protocols to create bond markets for treasury diversification and Protocol Owned Liquidity (POL). The protocol suffered a smart contract exploit in October 2022 in which approximately 30,437 OHM tokens (~$300,000) were drained from its Fixed-Expiry Teller contract; all funds were returned by the attacker within hours of the incident. The protocol raised a $2.5M seed round from credible venture investors and has since expanded to Ethereum, Arbitrum, and Optimism, though it shows signs of reduced activity as of 2025-2026.
avoid.net/dtrinity-dlend→40/100[WARNING]dTRINITY is a DeFi stablecoin lending protocol developed by Trinity Foundation Ltd., a Singapore-incorporated non-profit, with dLEND serving as its Aave v3-forked lending engine. The protocol launched on Fraxtal in December 2024 and subsequently deployed on Sonic, Katana, and Ethereum. It has suffered two separate security incidents since launch — a $56,000 authorization-check exploit in September 2025 and a $257,000 deposit inflation (liquidity index manipulation) attack in March 2026 — though the team committed to covering 100% of losses from internal funds in both cases and no user funds were reported uncompensated.
avoid.net/yg→39/100[WARNING]Yield Guild Games (YGG) is a Philippines-based web3 gaming guild and decentralized autonomous organization that gained prominence during the 2021 Axie Infinity play-to-earn boom. The YGG token launched in July 2021, reached an all-time high of approximately $11.27 in November 2021, and subsequently lost over 99% of its value as the play-to-earn economy collapsed. The project has since pivoted toward multi-game community coordination and game publishing under the YGG Play brand, backed by major investors including a16z Crypto and DWF Labs.
avoid.net/clober-liquidity-vault→52/100[CAUTIONARY]Clober Liquidity Vault is an automated market-making product built on top of CloberDEX, a fully on-chain central limit order book (CLOB) DEX deployed on Coinbase's Base network. On December 10, 2024, the Liquidity Vault suffered a reentrancy exploit that drained approximately 133.7 ETH (~$501,000) from the newly launched vault — one day after it received its first liquidity injection. The core CloberDEX protocol was unaffected, and the team offered a 20% white-hat bounty, which the attacker declined; funds were not recovered.
avoid.net/sweat-economy-sweat-protocol→45/100[WARNING]Sweat Economy is a move-to-earn cryptocurrency project built on the NEAR Protocol, originating from the Sweatcoin fitness app which reportedly has over 200 million registered users. The project raised $13 million in a 2022 private token sale and launched the SWEAT token in September 2022. On April 29, 2026, an external attacker exploited a vulnerability in the SWEAT token smart contract, draining approximately 13.71 billion tokens (roughly 65-67% of total supply) from foundation-controlled accounts; the team responded by pausing the contract, coordinating exchange freezes, and restoring all external user balances.
avoid.net/yield-guild-games-ygg→30/100[WARNING]Yield Guild Games (YGG) is a Philippines-originated Web3 gaming guild and DAO that rose to prominence in 2021 by facilitating play-to-earn scholarship programs, primarily around Axie Infinity, and raised $4.6 million led by Andreessen Horowitz. The organization has undergone significant restructuring since the collapse of the play-to-earn sector in 2022, and in July 2026 shut down its publishing arm YGG Play and laid off 35 employees as it pivoted toward supplying gaming behavioral data for AI training. No fraud allegations, hacks of the protocol, or regulatory enforcement actions have been identified; the primary concerns relate to sustained token value destruction, structural business-model risk, and heavy token-unlock inflation.
avoid.net/peopledao→52/100[CAUTIONARY]PeopleDAO is a community-governed metaDAO that emerged in December 2021 from the dissolution of ConstitutionDAO, adopting the $PEOPLE ERC-20 token as its governance mechanism. The organization aims to incubate subDAOs and projects advancing Web3 and social good. In March 2023, PeopleDAO suffered a social engineering incident in which an unknown third party exploited an accidentally shared editable payment spreadsheet to steal approximately 76.5 ETH (~$120,000) from the DAO treasury; no rug pull, founder fraud, or regulatory action has been documented.
avoid.net/darwin-labs-private-limited→0/100[CRITICAL]Darwin Labs Private Limited is an India-registered technology venture studio co-founded by Sahil Baghla, Ayush Varshney, and Nikunj Jain. Indian authorities allege the company designed and built the entire technological infrastructure underpinning the GainBitcoin Ponzi scheme, one of India's largest cryptocurrency frauds, involving approximately 8,000 investors and estimated losses of Rs 6,606 crore (roughly $790 million). Two co-founders were arrested by Pune Police in April 2018, and a third — Ayush Varshney — was arrested by the Central Bureau of Investigation (CBI) in March 2026 after being intercepted at Mumbai airport while allegedly attempting to flee to Sri Lanka.
avoid.net/eu-mica-regulator-impersonation-scam-wave→0/100[CRITICAL]Following the July 1, 2026 expiry of MiCA's transitional period, which forced an estimated 1,700 or more unlicensed crypto firms to wind down EU operations, a coordinated wave of impersonation fraud emerged in which criminals pose as European financial regulators — including ESMA and France's AMF — and as shuttered exchanges, in order to steal funds from displaced users. France's AMF and ESMA have each formally warned of the pattern, describing fraudsters who clone official communications, fabricate regulatory documents, and charge upfront 'administrative fees' to victims seeking to recover assets. This is a systemic, infrastructure-level fraud cluster rather than a single actor, with multiple national regulators across the EU reporting incidents.
avoid.net/bitget-voxel-futures-manipulation-april-2026→16/100[CRITICAL]On April 20, 2025, Bitget's VOXEL/USDT perpetual futures market experienced severe price and volume anomalies reportedly triggered by a malfunction in the exchange's proprietary market-making bot. Eight accounts allegedly exploited the bot's predictable trade pattern to extract profits exceeding $20 million from a roughly $100 million impact event before Bitget froze accounts and unilaterally reversed completed trades. The rollback drew widespread criticism, in part because Bitget CEO Gracy Chen had publicly condemned competitor Hyperliquid for conducting a structurally similar trade reversal just weeks earlier.
avoid.net/swan-treasury-sty-token→10/100[CRITICAL]Swan Treasury is a BNB Chain privacy-finance protocol offering anonymous identity, private transactions, dark pool liquidity, on-chain vaults, and a node network, with the STY token serving as its central ecosystem passkey. On July 30, 2026, the protocol suffered an estimated $625,000 loss after an attacker exploited a compromised off-chain signer private key that was hardcoded as the _signer address in the ZhaiquanBuy smart contract. As of August 20, 2026, Swan Treasury has not published a post-mortem or explained how the signer key was exposed, leaving users without clarity on the protocol's current security posture.
avoid.net/risex→29/100[WARNING]RISEx is a fully on-chain perpetual-futures exchange built on RISE Chain, backed by Galaxy Ventures and Vitalik Buterin. On August 3, 2026, an unauthorized withdrawal of 673,011.56 USDC was drained from the XLP vault's RWA strategy due to a smart-contract misconfiguration that had been present and exploitable since the vault's July 13, 2026 deployment — a 21-day undetected window. No completed third-party security audit existed for RISEx at the time of the exploit; the team patched the issue by 08:09 UTC the same day and compensated depositors from July protocol fees, but the stolen funds were not recovered.
avoid.net/ai-powered-crypto-phishing-infrastructure-2026→0/100[CRITICAL]A broad, industrialized criminal ecosystem has emerged in 2025–2026 in which threat actors use generative AI tools — including large language models, deepfake video engines, and voice-cloning services — to produce and operate crypto phishing infrastructure at unprecedented scale. Chainalysis documented $17 billion in crypto scam losses in 2025, with AI-enabled operations generating 4.5 times more revenue per campaign than traditional methods. Law enforcement agencies across the US, UK, and Canada have begun coordinated enforcement actions, but the pace of tool proliferation continues to outpace disruption.
avoid.net/lab-labusdt→0/100[CRITICAL]LAB is the native BEP-20 utility token of lab.pro, a self-described multi-chain AI trading terminal. Following a token generation event in October 2025, the token surged over 500% to a peak near $27 in spring 2026 before collapsing more than 99% from that high by August 2026. On-chain investigator ZachXBT published a detailed investigation in May 2026 alleging that insiders controlled over 95% of the token supply and orchestrated coordinated price manipulation across multiple centralized exchanges; those allegations have not been adjudicated by any court or regulator.
avoid.net/polkadot-dot→54/100[CAUTIONARY]Polkadot is a Layer 0 blockchain interoperability protocol founded by Gavin Wood (co-founder of Ethereum) and backed by the Web3 Foundation. It introduced a multi-chain architecture connecting independent blockchains via a central Relay Chain and launched its native token DOT in 2017. As of mid-2026, the project is classified as a digital commodity by U.S. regulators, has launched a spot ETF, and is executing a major technical upgrade (JAM), but faces credible concerns around treasury management, an ecosystem exodus of flagship parachains, a bridge exploit, and persistent adoption challenges relative to competitors.
avoid.net/lab→0/100[CRITICAL]LAB is the native token of LAB Terminal (formerly MemesLab), an AI-powered multi-chain trading platform that launched via Binance Alpha in October 2025. On-chain investigator ZachXBT published findings in May 2026 alleging that insiders controlled approximately 95% of the token's circulating supply and that the team orchestrated coordinated selling through a BVI-registered shell company and opaque OTC arrangements. By August 2026, the token had fallen approximately 98% from its all-time high of roughly $24, with a separate $18.3 million wallet dump in July 2026 attributed by ZachXBT to wallets directly funded by the LAB team.
avoid.net/harmony-one-protocol-entity→8/100[CRITICAL]Harmony (ONE) is a layer-1 sharded proof-of-stake blockchain founded in 2017 and launched on mainnet in June 2019. The protocol has suffered two major security incidents: the June 2022 Horizon Bridge hack attributed by the FBI to the DPRK-linked Lazarus Group, in which approximately $100 million was stolen, and an August 2026 cross-shard mint exploit in which an attacker forged between 4 billion and 3.01 trillion ONE tokens by exploiting a consensus-layer quorum verification flaw. The 2026 incident drove the ONE token to an all-time low of $0.0005735 and prompted an unilateral chain rollback erasing over 109,000 confirmed transactions, raising systemic concerns about the network's security architecture and degree of decentralisation.
avoid.net/bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026→14/100[CRITICAL]On August 7-8, 2026, cryptocurrency exchange Bybit announced that it had filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the Lazarus Group over the February 21, 2025 theft of approximately $1.5 billion in Ethereum-denominated assets -- the largest recorded cryptocurrency theft in history. Alongside the lawsuit, the court granted a preliminary injunction freezing identified stolen assets held by unnamed intermediary defendants. This is the first known instance of a major cryptocurrency exchange filing civil suit against a nation-state actor for a crypto theft and securing a judicial asset freeze order at this scale.
avoid.net/bridgers-cross-chain-swap→28/100[WARNING]Bridgers is a no-KYC, non-custodial cross-chain swap and liquidity aggregation service operated by SWFT Blockchain, a company founded in 2017 and headquartered in Silicon Valley. On August 9, 2026, blockchain intelligence firm BlockWatchdog identified Bridgers as the cross-chain linking mechanism in the $8.07 million Coinsbuy exchange hack, with Bridgers' Ethereum payout contract forwarding stolen funds directly into the attacker's designated swap wallet. Whether Bridgers was complicit, negligent, or an unwitting relay has not been determined; no regulatory action or legal finding has been made against the platform.
avoid.net/step-app-fitfi→14/100[CRITICAL]Step App was a move-to-earn fitness application built on Avalanche that rewarded users with KCAL and FITFI tokens for physical activity such as walking and running. The platform permanently shut down all services on August 21, 2026, after four years of operation. Its FITFI governance token collapsed approximately 99.9% from its all-time high of $0.73, leaving retail holders with positions valued in fractions of a cent and a total market cap at shutdown of roughly $12,229.
avoid.net/woofi→44/100[WARNING]WooFi is the decentralized exchange (DEX) component of WOO Network, a liquidity and trading ecosystem founded in 2019 and incubated by Kronos Research. The platform has suffered two significant security incidents — a March 2024 flash loan oracle exploit costing approximately $8.75 million, and a July 2025 phishing-driven breach of the affiliated centralized exchange WOO X costing $14 million — both of which are attributed to external attackers rather than insider misconduct. WOO X committed to full user reimbursement for the 2025 incident, and no regulatory actions or fraud allegations against WooFi's operators have been identified.
avoid.net/sheldon-xia-bitmart-founder→10/100[CRITICAL]Sheldon Xia is the founder of BitMart, a cryptocurrency exchange he established in 2017 that served over 13 million users across 180 countries before announcing a wind-down on July 26, 2026. Since that announcement, Xia has become the primary target of accountability demands from users and employees who allege frozen withdrawals and unpaid salaries, while Xia has publicly dismissed calls for a third-party audit and wallet disclosure as fabricated rumors. As of August 20, 2026, Xia has released no proof-of-reserves, no repayment plan, and no independent accounting of user funds, while on-chain data tracked by Arkham Intelligence shows a significant decline in wallet balances attributable to exchange-linked addresses.
avoid.net/ben-bitboy-armstrong→0/100[CRITICAL]Ben Armstrong, known online as 'BitBoy,' is a U.S.-based cryptocurrency content creator who built one of the largest crypto YouTube channels in the world, accumulating millions of subscribers. He was removed from the BitBoy Crypto brand in August 2023, and since then has faced a compounding series of legal proceedings including arrests, a federal defamation judgment of $2.8 million, regulatory scrutiny from the CFTC, and civil litigation tied to undisclosed paid promotions. As of mid-2026, Armstrong faces felony charges in Georgia related to alleged threats directed at a state court judge, with trial proceedings reported to be advancing.
avoid.net/hinkal-protocol→20/100[CRITICAL]Hinkal Protocol is a zero-knowledge proof-based privacy DeFi protocol founded by Georgi Koreli and Nika Koreli, operating on Ethereum and multiple other chains, that enables confidential on-chain transactions for institutional users. On July 3–4, 2026, an attacker exploited a business-logic flaw in its legacy note format to drain approximately $820,000 in USDC from its Ethereum deployment — representing nearly all of the protocol's total value locked. Hinkal subsequently committed to full 1:1 user reimbursement and paused all smart contracts pending a postmortem; no confirmed recovery of stolen funds had been reported as of August 20, 2026.
avoid.net/drift-protocol-dprk-exploit-april-2026→0/100[CRITICAL]On April 1, 2026, Drift Protocol — the largest decentralized perpetual futures exchange on Solana — suffered a loss of approximately $295 million in user assets after a six-month social engineering campaign attributed with medium-high confidence to UNC4736, a North Korean state-affiliated threat actor also tracked as AppleJeus or Citrine Sleet. Attackers posed as a quantitative trading firm, compromised Security Council members' devices, and exploited Solana's durable nonce mechanism to gain unauthorized administrative control before draining multiple vaults within roughly twelve minutes. Drift Protocol acknowledged the breach and published a token-based recovery framework backed by Tether ($127.5 million) and other partners, with a Q2 2026 protocol relaunch planned.
avoid.net/bitget-voxel-futures-manipulation-april-2025→14/100[CRITICAL]On April 20, 2025, eight accounts allegedly exploited a suspected flaw in Bitget's internal market-making bot during a 30-minute window, generating over $20 million in profits from anomalous price oscillations in the VOXEL/USDT perpetual futures market. Bitget unilaterally rolled back the affected trades within 24 hours and announced legal action against the eight accounts, while committing to compensate impacted users from recovered funds via airdrop. The incident drew particular scrutiny because Bitget's CEO had publicly criticized competitor Hyperliquid weeks earlier for conducting a similar trade reversal, creating a widely noted inconsistency.
avoid.net/edward-zimbardi-the-crypto-program→0/100[CRITICAL]Edward Anthony Zimbardi, 59, of Flowery Branch, Georgia, is the founder of The Crypto Program (also known as CryptoProgram.me), a crypto investment platform that federal prosecutors allege was a Ponzi scheme that collected more than $165 million from thousands of investors between June 2022 and August 2023. A federal grand jury indicted Zimbardi on July 8, 2026, on 12 counts of wire fraud, 12 counts of money laundering, and one count of money laundering conspiracy. Zimbardi was deported from Fiji on August 14, 2026, and arraigned in Los Angeles on August 17, 2026; the charges are accusations and no trial verdict has been entered.
avoid.net/b-network-bsquared-bitcoin-layer-2-staking-contract-exploit→22/100[CRITICAL]On July 22, 2026, B² Network — a Bitcoin Layer-2 ZK rollup protocol — suffered a security incident in which an attacker allegedly exploited unauthorized access to the B2 token staking contract's upgrade authority and drained approximately 8.59 million B2 tokens valued at roughly $3.86 million. The stolen tokens were converted to BNB, bridged to Ethereum, and reportedly laundered through NEAR Intents and HOT Protocol toward Zcash. The team suspended staking, committed to full user compensation, and reportedly offered the attacker legal immunity in exchange for a partial refund. As of August 2026, no funds have been publicly confirmed as recovered.
avoid.net/midnight-network-night-token→42/100[WARNING]Midnight Network is a privacy-focused blockchain launched as a partner chain to Cardano, developed by Shielded Technologies (an IOG spinout) and governed by the Midnight Foundation. The project uses zero-knowledge proofs and a 'rational privacy' model to offer selective disclosure rather than full anonymity, targeting enterprise and regulated use cases. The network launched its federated mainnet in March 2026 with institutional validators including Google Cloud and Vodafone, but its NIGHT token suffered severe post-launch volatility and was affected by a third-party bridge exploit in July 2026 that drained approximately 515 million tokens.
avoid.net/origin-protocol→28/100[WARNING]Origin Protocol is a San Francisco-based DeFi and NFT platform founded in 2017 by Josh Fraser and Matthew Liu, best known for its yield-bearing stablecoin Origin Dollar (OUSD) and Origin Ether (OETH). In November 2020, before completing any security audit, OUSD was exploited via a reentrancy flash-loan attack resulting in approximately $7.7 million in losses including over $1 million from the team's own treasury. The protocol subsequently completed multiple audits, compensated affected users, and relaunched; it has continued operating with expanded DeFi yield products through 2025, though the OGN token trades at a fraction of its 2021 all-time high.
avoid.net/coinkite-coldcard→13/100[CRITICAL]Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.
avoid.net/summer-finance-summer-fi→16/100[CRITICAL]Summer.fi (formerly Oasis.app) was a DeFi lending, borrowing, and yield-optimization platform on Ethereum, originally created within the Maker Foundation in 2016 and spun out as an independent company in June 2021. In June 2023 it rebranded from Oasis.app to Summer.fi to signal multi-protocol expansion. On July 6, 2026, its Lazy Summer Protocol was exploited for approximately $6.04 million through ERC-4626 share-price manipulation using stale-valued tokens left over from the November 2025 collapse of Stream Finance. Following the exploit, the company announced a full wind-down with the application ceasing operations on August 31, 2026, while the Lazy Summer DAO retains governance over remaining on-chain vault infrastructure.
avoid.net/donald-basile→4/100[CRITICAL]Donald G. Basile is a Silicon Valley technology executive and the founder and CEO of Bitcoin Latinum (LTNM) and its developer entity Monsoon Blockchain Corporation. In April 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and two entities he controls, alleging he raised approximately $16 million from hundreds of investors through materially false representations about insurance coverage, asset backing, and fund usage. All allegations in the SEC complaint remain untested in court; no ruling or adjudication has been entered as of the date of this report.
avoid.net/coldcard-coinkite→27/100[WARNING]Coinkite is a Toronto-based Canadian company founded in 2013 that manufactures Bitcoin-only hardware products, most notably the Coldcard hardware wallet. In July 2026, a firmware vulnerability introduced in March 2021 — which caused seed generation to rely on a weak software pseudorandom number generator instead of the device's hardware entropy source — was actively exploited, resulting in the theft of approximately 1,816 BTC (roughly $116 million) from over 5,200 wallet addresses. Coinkite acknowledged the flaw, released patched firmware, and faces class-action litigation threats; the perpetrators have not been publicly identified.
avoid.net/bitcoin-latinum→0/100[CRITICAL]Bitcoin Latinum (ticker: LTNM) is a cryptocurrency project launched in 2020 by Donald G. Basile through entities GIBF GP, Inc. and Monsoon Blockchain Corporation. The project marketed itself as the world's first insured, asset-backed digital currency and raised approximately $16 million from hundreds of investors via Simple Agreements for Future Tokens (SAFTs). In April 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and his companies, alleging that the asset-backing and insurance claims were fabricated, that investor funds were misappropriated for personal use, and that the token ultimately became worthless.
avoid.net/btcpay-server-lnd-macaroon-credential-exploit-august-2026→52/100[CAUTIONARY]BTCPay Server is a widely used open-source, self-hosted Bitcoin payment processor created in 2017. On August 7, 2026, the project disclosed and patched a critical pre-authentication vulnerability (present in all versions before 2.4.2) that allowed remote attackers to steal LND macaroon credential files and drain connected merchant Lightning nodes. The vulnerability was actively exploited before the public disclosure, with confirmed victims including hardware wallet maker Foundation and Bitcoin publication Citadel21; the attacker remained unidentified as of mid-August 2026.
avoid.net/indonesia-pig-butchering-syndicate-live-model-operation-2025-2026→0/100[CRITICAL]An international online fraud syndicate operating out of Sukoharjo and Surakarta in Central Java, Indonesia from approximately July 2025 to May 2026, allegedly defrauding at least 133 U.S. victims of approximately US$2.33 million through romance manipulation and fake cryptocurrency investment platforms, a scheme known as 'pig butchering.' Indonesian police arrested 39 suspects in May 2026 and have engaged the FBI given the predominance of American victims. Charges are pending; no convictions have been entered as of the date of this investigation.
avoid.net/doj-225m-pig-butchering-civil-forfeiture-u-s-v-approx-225-364-961-in-usdt→2/100[CRITICAL]On June 18, 2025, the U.S. Attorney's Office for the District of Columbia filed a civil forfeiture complaint (case 25-cv-1907) to seize approximately $225.3 million in USDT — at the time the largest-ever U.S. seizure of funds tied to cryptocurrency confidence scams. The funds were traced through a complex blockchain money-laundering network to a Philippines-based call center compound and approximately 144 accounts on the OKX exchange, with victims numbering more than 430 globally. The action sits within a broader 2025–2026 enforcement wave by the Scam Center Strike Force, which froze and seized over $580 million in cryptocurrency by February 2026 from Chinese transnational criminal organizations operating pig-butchering scam compounds in Burma, Cambodia, and Laos.
avoid.net/allbridge-core-cctp-base-chain-exploit-august-2026→8/100[CRITICAL]Allbridge Core, a cross-chain stablecoin bridge, suffered its third material security incident in 2026 on August 19 when an attacker exploited a missing balance verification in the protocol's newly deployed CCTP router on Base, draining 191,156 USDC. The attack, which involved crafting a forged Circle CCTP attestation message to book a phantom $1 million deposit before using a flash loan to cover the funding gap, represents a novel attack class with potential systemic implications for other protocols that accept CCTP attestations without verifying corresponding balance changes. This followed a $1.65 million flash loan exploit on Solana in July 2026 and an earlier BNB Chain exploit in April 2023.
avoid.net/patrick-yarmoch-fbi-agent-crypto-theft→0/100[CRITICAL]Patrick Steven Yarmoch (also spelled Yaroch in some filings), a former FBI supervisory special agent assigned to the Counterintelligence and Espionage Division, was arrested on July 31, 2026, and charged by criminal complaint in the U.S. District Court for the Eastern District of Virginia with interstate transportation of stolen property and receipt of stolen property. Prosecutors allege he accessed seed phrases stored in FBI intelligence systems during a national security investigation and transferred approximately $925,426 in cryptocurrency from wallets tied to a foreign adversary into accounts under his personal control. The case was at the criminal complaint stage as of August 2026; no conviction or guilty plea had been entered at that time.
avoid.net/irs-fake-digital-asset-compliance-portal-scam-2026→0/100[CRITICAL]Beginning in late July 2026, an organised threat actor began mailing physical letters to U.S. cryptocurrency holders that closely mimicked official IRS correspondence, directing recipients via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest wallet credentials, exchange logins, and identity data. The IRS issued a formal fraud alert on July 30, 2026, explicitly confirming it does not operate any such portal. Coinbase and cybersecurity firm DarkTower traced the campaign infrastructure to a recently registered domain hosted on Romanian servers previously linked to financial phishing networks, indicating a well-organised international fraud operation.
avoid.net/adam22-adam-john-grandmaison-cuck-meme-coin→0/100[CRITICAL]Adam22 (Adam John Grandmaison), host of the No Jumper hip-hop podcast with approximately 4.94 million YouTube subscribers, promoted a Solana meme coin ticker $CUCK on or around February 18, 2025. The token surged approximately 200% before liquidity was withdrawn and the price collapsed to near zero, a pattern described by investigator Coffeezilla and crypto media as a pump-and-dump. Adam22 publicly stated he was paid a large sum to promote the token and that he did not regret doing so; no criminal charges or regulatory enforcement actions had been filed against him as of August 2026.
avoid.net/crypto-whale-25-6m-repeat-phishing-drain-august-2026→0/100[CRITICAL]On August 12, 2026, an unidentified Ethereum whale wallet was drained of approximately $25.6 million in WBTC, cbBTC, LDO, USDS, and CRV through a phishing attack — the second major exploitation of the same address, which had previously lost $24.2 million to a phishing incident in September 2023. The stolen assets were swapped to approximately 20 million DAI and 3,000 ETH and traced by PeckShield to four distinct attacker-controlled addresses. This page documents the phishing infrastructure and repeat-targeting pattern rather than the victim; the victim is the unnamed whale wallet, not a threat actor.
avoid.net/maya-protocol-mayachain→12/100[CRITICAL]Maya Protocol is a permissionless, decentralized cross-chain liquidity network built on MAYAChain, a THORChain fork that launched mainnet in April 2023. On August 18, 2026, the protocol suffered its first documented loss-of-funds incident: an attacker chained six software vulnerabilities in a single 23-message transaction to extract approximately $1.36 million in hard assets (including 20.83 BTC) and trigger a broader pool-value impact estimated at $11 million, while CACAO crashed 89%. MAYAChain halted all operations on August 18, 2026, and has not resumed as of August 23, 2026; no funds have been returned.
avoid.net/boltz-bitcoin-bridge→34/100[WARNING]Boltz is a non-custodial, open-source Bitcoin bridge that enabled atomic swaps between the Bitcoin mainchain, Lightning Network, and Liquid sidechain. On August 3, 2026, Boltz suspended all swap operations indefinitely after sustained AI-assisted exploitation attacks reportedly outpaced the capacity of its small team to ship patches. No user funds were lost due to the platform's non-custodial HTLC design, but company operating funds were depleted by contained exploits, and the service remains offline as of August 21, 2026.
avoid.net/term-labs→17/100[CRITICAL]Term Labs is the company behind Term Finance, an Ethereum-based fixed-rate DeFi lending protocol that uses an on-chain double-auction mechanism to match borrowers and lenders. The protocol, backed by $8 million in venture funding from Electric Capital, Coinbase Ventures, and Maelstrom, suffered two significant loss events: a $1.6 million oracle misconfiguration in April 2025 (partially recovered) and a governance manipulation attack on August 23, 2026 that drained approximately $8.5 million from its strategy vaults. The 2026 attack represents an active, unresolved incident with no published post-mortem or reimbursement plan at time of writing.
avoid.net/michele-spagnuolo-alpharaccoon→0/100[CRITICAL]Michele Spagnuolo, 36, a Staff Information Security Engineer at Google Zürich known in crypto communities as 'AlphaRaccoon,' was arrested in New York on May 27, 2026 and charged by the U.S. Department of Justice with commodities fraud, wire fraud, and money laundering. Federal prosecutors allege he accessed confidential internal Google 'Year in Search 2025' data and used it to place approximately $2.75 million in bets on Polymarket prediction markets between October and December 2025, netting over $1.2 million in alleged illegal profits. The case, filed in the Southern District of New York alongside a parallel CFTC civil enforcement action, is among the first insider trading prosecutions applied to a crypto prediction market platform.
avoid.net/fake-crypto-aml-checker-infrastructure→0/100[CRITICAL]A coordinated network of fraudulent websites impersonating legitimate anti-money laundering (AML) compliance tools — most prominently AMLBot — was publicly documented by Malwarebytes on August 19, 2026. The sites simulate wallet-risk screening workflows to social-engineer users into connecting wallets and signing drainer transactions, in some cases also charging small upfront 'verification fees.' The campaign is notable for targeting security-conscious users who are actively trying to verify their own wallet safety, and for the systematic reuse of a shared malicious site template rebranded under multiple names and logos.
avoid.net/bouncebit→20/100[CRITICAL]BounceBit was a Bitcoin restaking Layer 1 blockchain backed by YZi Labs (formerly Binance Labs) and Blockchain Capital that launched mainnet in May 2024. On August 19-20, 2026, an attacker exploited an authorization flaw in the project's Evmos-based vesting account module to move 286.5 million BB tokens (~$3 million) across 14 transactions without holding valid grants. The protocol's reliance on the discontinued Evmos framework made a rebuild infeasible; BounceBit permanently shut down its chain and announced BB will be reissued as a BEP-20 token on BNB Chain using a pre-attack snapshot.
avoid.net/cyberleek-token→0/100[CRITICAL]CYBERLEEK ($CYBERLEEK) is a Solana-based meme coin launched on August 15, 2026, by an anonymous individual or group operating under the alias 'Cyberleek.' Three days after minting, on August 18, the same operators allegedly published what appeared to be GTA VI gameplay footage and the game's Leonida map, with QR codes linking directly to the token burned into the leaked material. Multiple gaming and crypto outlets, as well as on-chain analysis by Bitquery, concluded that the leak campaign was pre-constructed advertising for the token rather than independent whistleblowing. Take-Two Interactive filed DMCA subpoenas in the U.S. District Court for the Southern District of New York on August 20, 2026, compelling Microsoft and Discord to identify the individuals behind the 'Cyberleek' persona.
avoid.net/key-coin-assets-ltd→0/100[CRITICAL]Key Coin Assets Ltd (Companies House no. 11621809) was a UK-registered firm that presented itself as a cryptocurrency investment business, promising guaranteed returns of 40–100%. The UK High Court ordered it wound up on 11 August 2026 following an Insolvency Service investigation that found no evidence of genuine trading and determined that investor funds were transferred directly to the director's personal bank account. Nine investors who reported to Action Fraud lost more than £300,000 combined.