Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
A pseudonymous on-chain analyst known as Wazz alleged in September 2026 that a single coordinated operation extracted at least $18.43 million from 53 memecoin launches on Robinhood Chain between July 10 and September 21, 2026, primarily by exploiting a tax-exemption feature in the Pons V2 launchpad. Blockchain analytics firm Bitquery subsequently identified a related but potentially distinct cluster of 56 launches accounting for approximately $15.5 million, while GoPlus Security separately flagged a second suspected rug factory routing over $9 million through a common consolidation network. No individuals have been publicly identified or charged, and neither Pons V2 nor Robinhood Chain has been alleged to have designed or participated in the scheme.
avoid.net/bitget-exchange-september-2026-backend-hack-387-5m→38/100[WARNING]On September 24, 2026, cryptocurrency exchange Bitget suffered the largest crypto exchange breach of 2026, with attackers draining approximately $387.5 million from the exchange's hot and warm wallets via a novel backend wallet infrastructure spoofing technique rather than private key theft. Bitget's CEO Gracy Chen stated that North Korea's Lazarus Group (also tracked as TraderTraitor) is the suspected perpetrator, a preliminary attribution corroborated by blockchain intelligence firm Elliptic and independent investigator ZachXBT, though no confirmed attribution has been publicly issued. Bitget's $464 million User Protection Fund was stated to cover customer losses in full; withdrawals were suspended and staged for reopening beginning September 28, 2026.
avoid.net/chillguy→28/100[WARNING]CHILLGUY is an anonymous-developer Solana meme coin launched via Pump.fun on November 15, 2024, based on the viral 'Chill Guy' character created by artist Phillip Banks. The token surged to a peak market cap of approximately $600–$660 million before declining more than 98% from its all-time high by mid-2026. The token carries significant risks including anonymous and unaccountable developers, no stated utility, an unresolved copyright dispute with the original artwork creator, extreme volatility, and no regulatory filings or consumer protections of any kind.
avoid.net/interpol-operation-jackal-iv-black-axe-crypto-fraud-network→4/100[CRITICAL]Operation Jackal IV was an eight-month INTERPOL-coordinated law enforcement operation (November 2025 – June 2026) targeting the Black Axe organized-crime network and affiliated West African criminal groups across 22 countries on six continents. Results announced on August 25, 2026 documented 58 arrests and 263 suspects identified, with the underlying criminal network alleged to run romance scams, cryptocurrency and investment fraud, business email compromise, and a crime-as-a-service infrastructure that collectively caused hundreds of millions of dollars in victim losses. Black Axe itself is a transnational organized-crime syndicate founded in Nigeria in 1977 with an estimated 30,000 members and annual criminal proceeds alleged to exceed $5 billion.
avoid.net/shibarium-bridge-flash-loan-exploit-september-2026→18/100[CRITICAL]The Shibarium bridge — connecting Shiba Inu's Layer 2 network to Ethereum — suffered a sophisticated flash loan and validator compromise attack in which approximately 224.57 ETH and 92.6 billion SHIB tokens, collectively valued at roughly $2.4 million, were drained from bridge contracts. The attacker borrowed 4.6 million BONE governance tokens via flash loan to seize a two-thirds validator supermajority on Shibarium's Heimdall consensus layer, then injected fraudulent checkpoints to authorize unauthorized withdrawals. Developers paused bridge functions, rotated all validator keys, recovered the 4.6 million BONE from the attacker's contract, and prepared a phased user refund plan.
avoid.net/swiftarc-capital-llc-siddharth-jawahar→2/100[CRITICAL]Swiftarc Capital LLC was a Texas-registered investment adviser operated by Siddharth Jawahar from approximately 2010 until its registration was revoked by the Texas State Securities Board in June 2022. Jawahar pleaded guilty in January 2026 to three federal counts of wire fraud after operating a Ponzi scheme from July 2016 through December 2023 that collected more than $35 million from at least 64 investors while investing only approximately $10 million. On September 15, 2026, U.S. District Judge Zachary M. Bluestone sentenced Jawahar to 11 years in federal prison and ordered him to pay $31.35 million in restitution.
avoid.net/jack-doherty→6/100[CRITICAL]Jack Colin Doherty (born October 8, 2003) is an American YouTuber and livestreamer with approximately 15 million subscribers, known primarily for stunt and prank content. He has been accused on multiple occasions of orchestrating pump-and-dump schemes involving Solana memecoins promoted to his large, predominantly young audience. No formal regulatory charges related to his crypto activity had been filed as of the investigation date.
avoid.net/robinhood-chain-rug-pull-syndicate→2/100[CRITICAL]An unnamed group of actors allegedly operated a coordinated memecoin rug-pull scheme across 53 token launches on Robinhood Chain between July 10 and September 21, 2026, extracting at least $18.43 million from retail investors. The operation was identified and documented by on-chain analyst Wazz (@WazzCrypto), with partial independent verification published by The Block. No individuals have been publicly identified, charged, or arrested as of September 28, 2026.
avoid.net/hefu-chai→8/100[CRITICAL]Hefu Chai, age 36, is a former technical lead at Robinhood Markets who was arrested and charged on September 15, 2026 by the U.S. Department of Justice with one count of commodities fraud and one count of wire fraud. Prosecutors in the Southern District of New York allege Chai exploited privileged access to confidential Robinhood Crypto listing schedules to trade perpetual futures on Hyperliquid before public announcements, allegedly profiting more than $50,000 between 2025 and 2026. The charges are accusations; no conviction, guilty plea, or adjudication has been entered as of the date of this report.
avoid.net/cbex-cryptobridge-exchange→2/100[CRITICAL]CBEX (Crypto Bridge Exchange), operated through the Nigerian registered shell company ST Technologies International Limited, was an AI-themed investment scheme that targeted retail investors primarily in Nigeria and Kenya between July 2024 and April 2025. The Nigeria Financial Intelligence Unit (NFIU) estimated investor losses at approximately 1.3 trillion naira (roughly $840 million), making it one of the largest crypto-related fraud collapses in African history. Nigeria's EFCC has arrested multiple promoters and arraigned them in the Federal High Court in Abuja; prosecutions were ongoing as of mid-2025.
avoid.net/axiom-dex-insider-trading-2026→22/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that employees of Axiom Exchange, a Y Combinator-backed Solana trading platform, abused internal customer support dashboards to track private user wallet activity and execute insider trades over approximately one year. The alleged scheme, centered on senior business development employee Broox Bauer, exploited the platform's lack of role-based access controls to compile non-public trading data on high-profile crypto traders, with a secondary layer of alleged front-running on Polymarket prediction markets using advance knowledge of ZachXBT's impending report. No formal criminal charges had been publicly announced as of the investigation's release.
avoid.net/akt→57/100[CAUTIONARY]AKT is the native utility token of Akash Network, a decentralized cloud computing marketplace built on the Cosmos SDK and founded in 2015 by Greg Osuri and Adam Bozanich under Overclock Labs. The project operates as a legitimate, open-source DePIN (Decentralized Physical Infrastructure Network) with public governance, audited code, and institutional partnerships including an indirect connection to NVIDIA through the Brev.dev acquisition. No regulatory actions, fraud allegations, or major exploits have been identified, though a responsibly disclosed critical vulnerability was patched in May 2024 and a spam attack disrupted the network briefly in March 2025.
avoid.net/vbit-technologies-corp-danh-c-vo→2/100[CRITICAL]VBit Technologies Corp. was a South Philadelphia-based bitcoin cloud-mining company founded in 2018 by Danh C. Vo. In December 2025 the U.S. Securities and Exchange Commission filed a civil complaint in the U.S. District Court for the District of Delaware alleging that Vo raised over $95.6 million from approximately 6,400 investors via 'hosting agreements' for mining rigs, the majority of which the SEC alleges did not exist, and then misappropriated approximately $48.5 million of those funds for personal use before departing the United States in November 2021. The company is now defunct; Vo's precise current whereabouts have not been publicly confirmed by authorities.
avoid.net/antier-solutions-private-limited→28/100[WARNING]Antier Solutions Private Limited is an Indian blockchain and Web3 development firm headquartered in Mohali, India, founded in 2005. One of its employees, Business Development Manager Sabby Singh, was indicted on September 4, 2025, by a federal grand jury in Oakland, California on charges of wire fraud and wire fraud conspiracy as part of the DOJ and FBI's Operation Token Mirrors, an undercover sting targeting cryptocurrency market manipulation. The indictment remains an accusation; no conviction or guilty plea by Singh has been publicly reported as of September 2026.
avoid.net/antier-operation-token-mirrors-defendants→22/100[CRITICAL]Operation Token Mirrors is a real, DOJ-confirmed undercover investigation in which the FBI and IRS Criminal Investigation created fake cryptocurrency tokens to identify firms offering illicit wash-trading and pump-and-dump services. A September 4, 2025 federal grand jury indictment, unsealed and announced on March 30, 2026 by the U.S. Attorney's Office for the Northern District of California, charged Sabby Singh — described as a Business Development Manager at 'Antier Solutions Private Limited,' identified as a partner firm of the market-making firm Contrarian — alongside three Contrarian executives, with wire fraud and wire fraud conspiracy for allegedly agreeing to pump a cryptocurrency token's price before planning to dump their holdings. No conviction has occurred; the charges are allegations, and it is not fully verified from available sources whether the indicted 'Antier Solutions Private Limited' is the same entity as the Mohali/Chandigarh, India-based Web3 development firm operating as antiersolutions.com.
avoid.net/bitbank-iranian-exchange→2/100[CRITICAL]BitBank is an Iranian cryptocurrency exchange, also known as BitBank3, launched in 2024 and alleged by the U.S. Treasury to be controlled by sanctioned Iranian financier Babak Zanjani. On September 17, 2026, the U.S. Office of Foreign Assets Control (OFAC) designated BitBank as part of Operation Economic Outcast, alleging that between June and July 2026 the platform was used to transfer hundreds of millions of dollars in Bitcoin to the Islamic Revolutionary Guard Corps (IRGC) and to process Strait of Hormuz maritime toll payments collected by the Iranian regime.
avoid.net/revolut→52/100[CAUTIONARY]Revolut is a UK-headquartered fintech and licensed neobank offering crypto trading, custody, and a euro stablecoin (EURR) to millions of customers across Europe and the UK, operating its crypto arm under a Cyprus MiCA license. While Revolut holds real regulatory licenses and has expanded its crypto product line significantly through 2026, it carries a documented risk profile: a 2025 anti-money-laundering fine in Lithuania, prior UK regulatory scrutiny over suspicious-account payouts, an outsized share of UK fraud complaints relative to peer banks, a September 2026 data breach that exposed customers' Bitcoin transaction histories and KYC documents via a spoofed government request, and abrupt crypto-service shutdowns in some jurisdictions (Hungary, the US) driven by regulatory change.
avoid.net/aurum-foundation→0/100[CRITICAL]Aurum Foundation is a Dubai-based MLM crypto Ponzi scheme that launched in mid-2024, promising monthly returns of 9.48% to 15.01% through an alleged AI trading bot called EX-AI, with no on-chain evidence of genuine trading activity. The scheme attracted regulatory fraud warnings from at least ten jurisdictions across Europe, Asia, Africa, and Oceania before collapsing on July 30, 2026, with operators issuing a 'we got hacked' announcement widely characterized as a classic exit-scam cover story. On-chain analysis identified approximately $31.7 million transiting through core wallets over a 17-day window, consistent with redistribution to early investors rather than external trading profits.
avoid.net/coldcard-hardware-wallet→32/100[WARNING]Coldcard is a Bitcoin-only hardware wallet manufactured by Canadian company Coinkite, long regarded as one of the most security-focused consumer Bitcoin signing devices available. In July 2026, a five-year-old firmware flaw introduced in March 2021 was exploited to drain approximately 1,816 BTC (~$116 million) from more than 5,200 affected wallet addresses — the largest hardware wallet exploit in recorded history. Coinkite published a security advisory, issued patched firmware, and suspended its standard customer-data deletion policy pending anticipated legal proceedings; no formal class action had been filed as of the date of this investigation.
avoid.net/bryan-pellegrino→38/100[WARNING]Bryan Pellegrino is the co-founder and CEO of LayerZero Labs, a cross-chain interoperability protocol that raised $263 million at a $3 billion valuation from investors including Sequoia Capital, a16z, and others. In April 2026, the largest single DeFi exploit of the year occurred on a LayerZero-powered bridge used by KelpDAO, resulting in approximately $292 million in losses; LayerZero subsequently issued a public apology and admitted fault in allowing a single-verifier configuration. On September 25, 2026, Evercrest Technologies (the developer behind KelpDAO) filed a civil claim in the Supreme Court of British Columbia naming Pellegrino personally as a defendant alongside LayerZero Labs, alleging negligent misrepresentation and defamation; the lawsuit is at the notice-of-claim stage and no court has made any finding of liability.
avoid.net/bryan-pellegrino-layerzero-ceo→42/100[WARNING]Bryan Pellegrino is co-founder and CEO of LayerZero Labs, the cross-chain messaging protocol underlying bridges across 70+ blockchains. Following an April 2026 exploit that drained $292 million in rsETH from KelpDAO's LayerZero-based bridge, KelpDAO's operating company, Evercrest Technologies, filed a civil claim in the Supreme Court of British Columbia naming Pellegrino personally alongside LayerZero, alleging negligent misrepresentation, negligence, and defamation. LayerZero has since publicly admitted fault in permitting the single-verifier configuration involved in the exploit, while Pellegrino has called the lawsuit meritless and said he will contest it in court.
avoid.net/eqibank→18/100[CRITICAL]EQIBank is a Dominica-licensed offshore digital bank founded in 2015 and launched in 2018, which has provided banking and payment-processing services to crypto firms including Tether and Bitfinex. In July 2026, U.S. federal prosecutors filed a civil forfeiture complaint in the Eastern District of California targeting approximately $84.2 million held by EQIBank's payment processor Capstone Ltd., a seizure the bank states represents roughly 80% of its monetary holdings. Dominica's Financial Services Unit placed EQIBank under enhanced supervisory oversight in June 2026, describing the measure as a preliminary step toward potential liquidation if the bank cannot serve its depositors.
avoid.net/capstone-ltd→12/100[CRITICAL]Capstone Ltd is a Montana-incorporated payments firm whose bank accounts were frozen by U.S. federal prosecutors in September 2026 following a civil forfeiture complaint alleging it operated as an unlicensed money transmitter across at least six U.S. states. The complaint, filed July 15, 2026 in the Eastern District of California, alleges Capstone misrepresented itself to U.S. banks as an IT services company while processing international wire transfers on behalf of EQIBank, a Dominica-licensed digital bank later identified by the Financial Times as a correspondent for stablecoin issuer Tether and affiliated exchange Bitfinex. Neither Tether, Bitfinex, nor EQIBank face criminal charges; the case against Capstone remains a civil forfeiture action with no criminal conviction entered as of September 26, 2026.
avoid.net/ondo-finance→62/100[CAUTIONARY]Ondo Finance is a real-world asset (RWA) tokenization protocol founded in 2021 that offers tokenized U.S. Treasury products (OUSG, USDY) and, through the separately incorporated Ondo Global Markets entity, tokenized U.S. equities and ETFs on Ethereum, Solana, BNB Chain, and other networks. The core tokenization and custody model — regulated broker-dealer custody, a bankruptcy-remote SPV issuer, and off-chain minting/redemption tied to Nasdaq/NYSE liquidity rather than on-chain DEX pools — is well documented and has not been credibly disputed. However, founder Nathan Allman's unexpected death in May 2026 triggered an unresolved corporate control dispute in Delaware Chancery Court between his estate (led by his mother, Kathleen Allman) and interim CEO Ian De Bode, compounded by a separate Hawaii conservatorship fight over Kathleen Allman's own capacity; this succession crisis, not the tokenization technology, is the dominant near-term governance risk. Ondo's underlying products, an SEC investigation closed without charges in late 2025, and continued regulatory engagement (no-action letter request, DTCC consortium) remain unchanged in substance since the prior review.
avoid.net/bingx→32/100[WARNING]BingX is a Singapore-headquartered centralized cryptocurrency exchange founded in 2018 (originally as Bingbon), operating across 160+ countries with over 10 million reported users. In September 2024, the exchange suffered a confirmed hot wallet breach totaling approximately $52 million across at least seven blockchain networks, with on-chain forensics subsequently linking the attack to North Korea's Lazarus Group. The exchange pledged full user compensation from reserves and resumed withdrawals within days, but independently unverified regulatory claims and initial opacity around the breach raise ongoing due-diligence concerns.
avoid.net/zyaire-wilkins-steam-malware-crypto-theft-ring→0/100[CRITICAL]Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, was arrested on July 14, 2026 and charged with conspiracy to obtain information by computer for private financial gain, a federal offense carrying up to 10 years imprisonment. Wilkins and at least one unnamed co-conspirator allegedly embedded information-stealing malware in eight fake video games distributed on Steam between May 2024 and February 2026, infecting approximately 8,000 computers and draining at least $220,000 from roughly 80 cryptocurrency wallets. Investigators linked Wilkins to the scheme via a chain of Bitcoin transactions, Bitrefill gift card purchases, Uber Eats delivery records, and Google account browser cookies.
avoid.net/jingliang-su→2/100[CRITICAL]Jingliang Su is a Chinese national who pleaded guilty in June 2025 and was sentenced on January 27, 2026 to 46 months in federal prison for conspiracy to operate an illegal money transmitting business. Federal prosecutors in the Central District of California established that Su laundered more than $36.9 million in proceeds from Cambodia-based digital asset investment fraud — commonly characterized as 'pig butchering' — that targeted 174 American victims. Su was one of at least nine co-conspirators convicted in connection with the scheme, which routed victim funds through a Bahamas bank account and converted them to Tether (USDT) stablecoin before transferring them to Cambodia.
avoid.net/doj-scam-center-strike-force-276-arrest-global-operation-2026→92/100[VERIFIED]The U.S. Department of Justice's Scam Center Strike Force, launched in November 2025 and based in the U.S. Attorney's Office for the District of Columbia, led a series of coordinated international enforcement actions in 2026 targeting Southeast Asian cryptocurrency investment fraud ('pig butchering') compounds. The centerpiece was an April 29, 2026 coordinated operation resulting in at least 276 arrests across multiple countries, the dismantlement of nine scam centers, and the restraint of over $701 million in cryptocurrency. The Strike Force has described annual American losses from these schemes at approximately $7.2 billion in 2025, and as of mid-2026 had restrained or seized approximately $938 million in total across all its actions.
avoid.net/zerion-wallet→43/100[WARNING]Zerion is a non-custodial DeFi portfolio tracker and multi-chain wallet founded in 2016, supporting 50+ blockchains including Ethereum and Solana. The platform has experienced multiple security incidents over its history, including a 2026 social engineering attack attributed to North Korean threat actors that resulted in approximately $100,000 in company internal wallet losses, though user funds were unaffected in each incident. Zerion also shut down its ZERO Layer-2 network in May 2026 after 1.5 years due to low adoption, with assets bridgeable until July 31, 2026.
avoid.net/texitcoin-minetxc-blockchain-mint→8/100[CRITICAL]TEXITcoin is a Texas-themed cryptocurrency venture founded by Robert J. 'Bobby' Gray of McKinney, Texas, operating alongside mining arm MineTXC and marketing/cold-storage arm Blockchain Mint. On February 11, 2026, the Texas State Securities Board issued Emergency Cease and Desist Order No. ENF-26-CDO-1893, alleging the respondents illegally and fraudulently sold unregistered 'Mining Package' securities to Texas residents through a multilevel marketing structure promising passive daily returns. An evidentiary hearing before Administrative Law Judge Katerina DeAngelo opened August 17, 2026; a final recommendation is expected by December 22, 2026, and no adjudication on the merits had been issued as of September 2026.
avoid.net/allbridge→28/100[WARNING]Allbridge is a cross-chain bridging protocol founded in 2021 that operates Allbridge Classic and Allbridge Core, supporting stablecoin transfers across more than 20 blockchains. The protocol has suffered three separate security incidents since its launch: a $573K flash loan exploit on BNB Chain in April 2023, a $1.65M flash loan attack on its Solana deployment in July 2026, and a $191K CCTP router exploit on Base in August 2026 involving forged Circle attestation messages. The recurrence of similar vulnerability classes across deployments — and the failure to apply 2023 remediations to all active chains — raises systemic concerns about the protocol's security review and deployment practices.
avoid.net/ondo-us-dollar-yield-usdy→60/100[CAUTIONARY]Ondo US Dollar Yield (USDY) is a tokenized yield-bearing note issued by Ondo USDY LLC, a Delaware bankruptcy-remote special purpose vehicle affiliated with Ondo Finance, and backed by short-duration U.S. Treasuries, iShares Short Treasury Bond ETF shares, and bank demand deposits. The token is offered exclusively to non-U.S. persons under a Regulation S exemption, accrues yield through a rising token price or daily rebasing, and had grown to approximately $740 million in supply across ten blockchains as of early 2026. A two-year SEC investigation into Ondo Finance was closed without charges in December 2025, though ongoing risks include centralized price-setting infrastructure, limited FDIC deposit coverage on a portion of reserves, and access and composability constraints imposed by the token's on-chain allowlist system.
avoid.net/trung-nguyen-van-triangle-pig-butchering-scam→3/100[CRITICAL]Trung Nguyen Van, a 37-year-old Vietnamese national, was criminally charged by the U.S. Attorney's Office for the Western District of Missouri on September 25, 2026 with two counts of money laundering for his alleged role in a 'pig butchering' romance/investment scam. Prosecutors allege a victim was fraudulently induced to transfer roughly $16 million in cryptocurrency between June and August 2024 into a fake investment platform called 'Triangle,' and that wallets linked to Van received approximately $53 million in crypto tied to wire-fraud schemes against U.S. victims between February 2018 and December 2024. The charges are allegations in a criminal complaint; Van has not been reported convicted, and no court verdict has been identified as of this writing.
avoid.net/trung-nguyen-van-triangle-crypto-platform→2/100[CRITICAL]Trung Nguyen Van, a 37-year-old Vietnamese national, was charged on September 25, 2026 by the U.S. Attorney's Office for the Western District of Missouri with two counts of money laundering in connection with an alleged international pig butchering fraud operation. Prosecutors allege that Van's cryptocurrency wallets received approximately $53.28 million tied to wire fraud schemes targeting U.S. residents between February 2018 and December 2024, including roughly $16 million from a single victim directed to a fraudulent platform called Triangle. The charges are at the criminal complaint stage; no conviction or guilty plea has been entered.
avoid.net/lazarus-group-tradertraitor-dprk-september-2026-blitz-campaign→0/100[CRITICAL]The September 2026 campaign page documents a cluster of cryptocurrency thefts attributed by multiple investigators and the exchange itself to North Korea's Lazarus Group and its TraderTraitor sub-actor. The largest confirmed incident is the September 24, 2026 Bitget exchange breach ($351.6M), which on-chain analyst Specter linked through XRP bridging patterns to the July 2026 AFX Exchange hack ($24.15M), itself formally attributed to TraderTraitor (UNC4899) in AFX's post-mortem. Elliptic assessed the Bitget theft as highly likely DPRK-linked, pushing North Korea's documented 2026 crypto theft total above $1 billion. A separate September 7 Liquid Network exploit ($320M) was claimed by self-described white-hat researchers and carries no public DPRK attribution. This campaign is distinct from the April 2026 blitz (Drift Protocol + KelpDAO, ~$577M combined) already documented separately in the corpus.
avoid.net/payy-network→18/100[CRITICAL]Payy Network is a zk-rollup stablecoin payments and crypto card platform built on Ethereum. On September 24, 2026, its Ethereum L1 rollup bridge contract was fully drained of approximately 1,832,149 USDC (~$1.83M) in a single transaction, prompting the platform to freeze all network, wallet, and card functions. The root cause has not been publicly confirmed by Payy; security firm ExVul alleged the attack batch was submitted using Payy's own prover and validator keys, suggesting a privileged key compromise rather than a public smart-contract bug.
avoid.net/ahmed-mekallach→62/100[CAUTIONARY]Ahmed Mekallach is a Montreal-based civil engineer and entrepreneur who founded Myte Group Inc., a small AI automation and custom software consultancy. No regulatory actions, court filings, fraud allegations, or crypto-specific misconduct have been identified against Mekallach or Myte Group in open sources as of September 2026. The submitter's question about trustworthiness cannot be definitively answered from public evidence alone; the company has a verifiable professional backstory but limited third-party review coverage.
avoid.net/meter-io-passport-bridge-block-validation-exploit-september-2026→18/100[CRITICAL]On September 23, 2026, an attacker exploited a block validation vulnerability on the Meter mainnet to mint approximately $2.3 million in unbacked wrapped MTRG (wMTRG) tokens via the Meter Passport bridge on BNB Chain, then sold a portion on PancakeSwap. Meter paused its mainnet and Passport bridge in response, warned users against all MTR/MTRG transactions, and disclosed that transactions after block 100731417 may not be honored during recovery. This is the second major exploit of the Meter Passport bridge infrastructure; the first, in February 2022, resulted in approximately $4.4 million in losses.
avoid.net/liquid-network→22/100[CRITICAL]Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.
avoid.net/liquid-network-elements-cache-bug-exploit-september-2026→18/100[CRITICAL]On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.
avoid.net/mid-tier-exchange-closure-wave-2026-ascendex-bitmex-bitmart-coinex→30/100[WARNING]Between July 1 and September 29, 2026, four mid-tier centralized exchanges — AscendEX, BitMEX, BitMart, and CoinEx — announced or completed shutdowns within a roughly 90-day window, representing the largest cluster of simultaneous exchange closures in the industry's history. Each cited a convergence of declining trading volumes, rising multi-jurisdiction regulatory compliance costs, and deteriorating market conditions as primary drivers. The closures present materially different risk profiles for affected users: AscendEX and BitMart have raised active solvency and fund-recovery concerns, while BitMEX and CoinEx are conducting more orderly wind-downs with verifiable reserve disclosures.
avoid.net/olamide-shanu→2/100[CRITICAL]Olamide Shanu, a 35-year-old Nigerian national from Lagos, pleaded guilty on September 21, 2026, in the U.S. District Court for the District of Idaho to conspiracy to commit money laundering in connection with an international sextortion and romance-fraud scheme. Prosecutors allege Shanu and co-conspirators defrauded approximately 150 American victims of more than $2.5 million and laundered proceeds through peer-to-peer payment apps and cryptocurrency wallets before transferring funds to co-conspirators in Nigeria. He was arrested in London in November 2023, extradited from the United Kingdom in September 2025, and faces up to 20 years in prison at his December 15, 2026 sentencing.
avoid.net/olaxbt→28/100[WARNING]OlaXBT (ticker: AIO) is a BNB Smart Chain-based AI trading platform that raised $3.38 million in seed funding led by Amber Group and launched publicly in July 2025. The project suffered a confirmed multi-signature wallet breach on September 1, 2025 that resulted in the theft of approximately 32 million AIO tokens (estimated $2 million at the time), forcing an emergency token contract migration that several exchanges declined to support. Additional risk factors include extreme holder concentration (approximately 96% of supply held by two addresses per CertiK Skynet data), an anonymous founding team with unverifiable claimed credentials, and multiple exchange delistings citing security concerns.
avoid.net/defi-governance-attack-cluster-2026-bonkdao-term-labs-pattern→15/100[CRITICAL]Between June and August 2026, at least four DeFi protocols — Token of Power, BonkDAO, BarnBridge SMART Yield, and Term Labs — lost a combined minimum of roughly $31 million to a recurring attack pattern in which an attacker cheaply acquires enough token-weighted voting power to pass a self-serving proposal through a protocol's own governance system, without exploiting any smart contract bug. This is a thematic cluster covering a genuine, verifiable attack class rather than a single entity; individual protocols in the cluster vary in size and legitimacy, but the pattern itself — low quorum thresholds, low voter turnout, and liquid governance tokens combined with governance-controlled treasuries — is a real, recurring structural vulnerability documented by multiple independent security firms and news outlets. A widely repeated claim that DefiLlama counts exactly "five governance attacks totaling $25.1 million" in 2026 could not be independently verified and appears mathematically inconsistent with the incidents this investigation confirmed, which alone exceed that total.
avoid.net/ai-powered-deepfake-crypto-scam-infrastructure-2026-industrialization-wave→2/100[CRITICAL]AI-generated synthetic media — deepfake video, voice cloning, and AI-authored phishing correspondence — has become an industrialized layer in cryptocurrency fraud as of 2026. The Chainalysis 2026 Crypto Crime Report documented that impersonation scams using these techniques grew more than 1,400% year-over-year in 2025, with crypto scam losses reaching at least $14–17 billion. This page covers the threat cluster as an investigable infrastructure phenomenon rather than a single entity, documenting the tooling ecosystem, active campaigns, law enforcement responses, and the evidential basis for each claim.
avoid.net/defi-price-manipulation-exploit-wave-record-32-attacks-in-2026→10/100[CRITICAL]In 2026, DeFi lending protocols suffered a record 32 price-manipulation exploits through August, nearly tripling the prior annual record of 12 set in 2025, according to blockchain intelligence firm TRM Labs. The attacks follow a repeatable template: inflate a low-liquidity collateral token via flash loan or fraudulent oracle update, post the inflated token as collateral, borrow hard assets, and exit before liquidation. Total DeFi losses across all attack vectors reached approximately $1.3 billion in the first eight months of 2026, with price manipulation representing one in eight of all crypto hacks tracked — up from one in seventeen in 2022.
avoid.net/mica-non-compliant-exchange-risk-cluster-post-july-1-2026→0/100[CRITICAL]From July 1, 2026, the EU's Markets in Crypto-Assets Regulation (MiCA) entered full enforcement, requiring all crypto-asset service providers (CASPs) serving EU residents to hold a valid authorisation from an EU national competent authority. Approximately 80% of previously operating exchanges failed to obtain authorisation by the deadline, creating a systemic consumer-protection risk cluster in which EU retail users holding assets on unlicensed platforms face potential account restrictions, withdrawal freezes, and — in at least one documented case (AscendEX) — possible permanent loss of funds due to exchange insolvency. ESMA maintains a formal register of both authorised CASPs and flagged non-compliant entities, but coverage of the latter is acknowledged to be incomplete.
avoid.net/mica-eu-mass-non-compliance-83-unlicensed-platform-risk→18/100[CRITICAL]The European Union's Markets in Crypto-Assets Regulation (MiCA) transitional grace period expired on July 1, 2026. Of approximately 1,200+ crypto firms that previously operated under national VASP registrations, only roughly 210–244 obtained full Crypto Asset Service Provider (CASP) authorization — a conversion rate of approximately 17–20%, leaving an estimated 83% operating in breach of EU law. ESMA confirmed on April 17, 2026 that no extensions would be granted and that unlicensed firms must cease EU services immediately; affected major exchanges include Binance (withdrew Greek application June 24, 2026), MEXC, Bitget, CoinEx, and others serving millions of European users.
avoid.net/mexc-exchange→32/100[WARNING]MEXC Exchange is a global cryptocurrency trading platform founded in 2018 and currently headquartered in the Seychelles. The exchange has accumulated regulatory warnings from multiple jurisdictions including Germany (BaFin), the Netherlands (AFM), Japan (FSA), Hong Kong (SFC), Estonia (FIU), and the Seychelles (FSA), primarily for operating without required authorizations. As of July 1, 2026, MEXC does not hold a MiCA Crypto-Asset Service Provider (CASP) license and formally exited the EU market, instructing EU users to withdraw funds before the deadline.
avoid.net/bitmart-exchange-creditor-committee-september-9-roadmap-deadline-missed→9/100[CRITICAL]BitMart, a centralized crypto exchange operating for nine years, announced an orderly wind-down on July 26, 2026, halting deposits and then trading by August 26, leaving more than 12 million registered users unable to withdraw funds. An ad hoc claimholder committee organized by distressed-asset firm Echo Base retained bankruptcy counsel on September 2 and is weighing involuntary insolvency proceedings after a $10 million rescue financing proposal submitted August 6 received no response from BitMart. BitMart missed its own September 9 roadmap deadline, providing no audited asset figures, no reserve report, no creditor claims portal, and no court filing — instead announcing the appointment of Alvarez and Marsal as financial adviser, a move that, as of the date of this writing, has left user funds in an unresolved standoff.
avoid.net/chainflip-tron-usdt-exploit-september-2026→28/100[WARNING]On September 12, 2026, an attacker exploited a memo-parsing vulnerability in Chainflip's TRON USDT settlement layer, draining 736,442.17 USDT across six unauthorized payouts in approximately 90 minutes. Chainflip halted all network operations, patched the vulnerability via software version 2.2.13, and restarted most routes by September 15–16 with TRON excluded. As of late September 2026, liquidity provider balances on the affected route have been zeroed and claims recorded separately on-chain, but no funding source, repayment schedule, or confirmed reimbursement has been publicly disclosed.
avoid.net/dabai-guarantee→2/100[CRITICAL]Dabai Guarantee (Chinese: 大白担保) is a Chinese-language criminal marketplace operating exclusively on Telegram, documented by Recorded Future's Insikt Group as a major active successor platform following the 2025 shutdown of Huione Guarantee and the January 2026 wind-down of Tudou Guarantee. The platform allegedly facilitates money laundering, sales of stolen personal data, SIM cards, compromised accounts, malware-as-a-service, and KYC bypass services for crypto-enabled fraud operations. As of mid-2026, no enforcement action targeting Dabai Guarantee specifically has been publicly reported, though the broader guarantee marketplace ecosystem has faced significant U.S. government action against peers including Huione and Xinbi.
avoid.net/ukrainian-crypto-confidence-fraud-ring-police-takedown-september-2026→0/100[CRITICAL]In early September 2026, Ukrainian law enforcement dismantled a network of fake cryptocurrency investment platforms that allegedly stole up to $1 million per month from victims across more than 20 countries. Operators manually fabricated account balances to simulate investment growth before deploying a hidden wallet-drainer triggered by a fraudulent 'test transaction.' 62 victims were identified and a 25-year-old IT specialist was alleged to be the lead organizer; a pre-trial investigation is ongoing.
avoid.net/ian-sofronov→8/100[CRITICAL]Ian Sofronov is a Russian national and former Sales Manager at GOTBIT Consulting LLC, a cryptocurrency market-making firm. A federal grand jury in San Francisco indicted him on March 25, 2025, on charges of conspiracy to commit wire fraud and wire fraud in connection with an alleged wash trading scheme that prosecutors say artificially inflated cryptocurrency trading volumes and prices. As of the latest available reporting, Sofronov has not been arrested and his whereabouts are unknown, while his two GOTBIT co-defendants pleaded guilty and were sentenced.
avoid.net/shibarium-bridge-flash-loan-exploit-september-2025→22/100[CRITICAL]On September 12, 2025, the Shibarium Ethereum-to-Layer-2 bridge suffered a multi-step exploit in which an attacker acquired 4.6 million BONE tokens via flash loan, used them to seize a supermajority of validator signing power, and drained approximately $4.1 million across at least 17 token types. The Shiba Inu development team suspended bridge operations, rotated all validator keys, recovered the flash-loaned BONE, and reopened the Plasma (BONE) Bridge on October 14, 2025 with a mandatory seven-day withdrawal delay and blacklist protections; a phased user compensation plan was announced but had not been fully distributed as of the bridge reopening.
avoid.net/megaeth→52/100[CAUTIONARY]MegaETH is an Ethereum layer-2 network developed by MegaLabs, marketed as a 'real-time blockchain' targeting up to 100,000 transactions per second. Backed by high-profile investors including Vitalik Buterin, Dragonfly Capital, and Joseph Lubin, the project raised over $100 million across seed and public sale rounds before its February 2026 mainnet launch and April 2026 MEGA token generation event. The network currently operates with a single centralized sequencer, its public token sale drew scrutiny over Sybil activity and thin lock-up participation, and the MEGA token lost roughly 55% of its value within days of listing — patterns consistent with other heavily hyped, VC-backed L2 launches rather than indicators of fraud.
avoid.net/ronald-spektor→2/100[CRITICAL]Ronald Spektor, 23, of Sheepshead Bay, Brooklyn (online handle @lolimfeelingevil), pleaded guilty on September 2, 2026 to a 31-count indictment and was sentenced on September 23, 2026 to 4 to 12 years in prison for operating a phishing and social-engineering scheme that stole nearly $16 million from approximately 100 Coinbase users across the United States between April 2023 and December 2024. He was ordered to pay approximately $16 million in restitution and to forfeit assets valued at over $500,000. These findings are based on a guilty plea and a court-issued sentence — not merely allegations.
avoid.net/operation-economic-outcast-iran-crypto-sector-sanctions-august-2026→5/100[CRITICAL]Operation Economic Outcast is a coordinated U.S. government enforcement campaign launched on August 24, 2026 by the Treasury Department targeting Iran's financial infrastructure, including a first-ever sectoral determination designating Iran's digital asset industry as subject to secondary sanctions under Executive Order 13902. The campaign designated nearly 60 entities, individuals, and vessels across five sectors — digital assets, technology, gold, aviation, and shipping — and ran in coordination with a Department of Justice indictment unsealed August 18, 2026 charging 17 Iranian nationals linked to the IRGC-directed Mabna Institute cyber-theft campaign. Subsequent actions under the Operation's banner continued through at least September 17, 2026, when OFAC sanctioned Iranian crypto exchange BitBank over alleged IRGC Bitcoin transfers of hundreds of millions of dollars.
avoid.net/gannon-ken-van-dyke→18/100[CRITICAL]Gannon Ken Van Dyke is a 38-year-old U.S. Army Master Sergeant stationed at Fort Bragg, North Carolina, who was charged in April 2026 by the Department of Justice and the CFTC with using classified military information to place prediction market bets on Polymarket, allegedly profiting approximately $409,881. He has pleaded not guilty to all charges; the allegations have not been adjudicated, and a trial is tentatively scheduled for December 7, 2026.
avoid.net/zksnarks-nft→22/100[CRITICAL]zkSNARKs is a 10,000-piece profile picture NFT collection launched on the Zcash blockchain in September 2026. It raised approximately $17 million through a blind auction but has delivered no working governance, community access tools, or ecosystem partnerships as of the date of publication. On-chain investigator ZachXBT publicly accused the project of being an eight-figure money grab, and NFT community figure Leonidas separately alleged team members had prior histories with Ordinals-era scams; those prior-history allegations remain unverified.
avoid.net/fomopeek→2/100[CRITICAL]FomoPeek was an iOS App Store application marketed as a read-only cryptocurrency whale-wallet monitor. Versions 1.1 and 1.2, distributed September 9–12, 2026, were found by SlowMist and OKX security researchers to contain a hidden iOS kernel-exploit framework capable of sandbox escape, Keychain decryption, and data extraction from 19 other installed apps. Approximately $579,984 in USDT was traced to a single attacker-controlled address before the developer released a clean version 1.3 on September 17, 2026.
avoid.net/coldcard-coinkite-hardware-wallet-exploit→12/100[CRITICAL]Coldcard is a Bitcoin-only hardware wallet produced by Toronto-based Coinkite Inc. Beginning July 30, 2026, attackers exploited a firmware build error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source, reducing effective key strength to as little as 40 bits on older models. Across four attack waves spanning several days, roughly 1,816 BTC (approximately $116 million) was drained from over 5,200 addresses without any physical access to the affected devices, making it the largest hardware wallet exploit on record.
avoid.net/doj-scam-center-strike-force-september-2026-action→92/100[VERIFIED]On September 9, 2026, the DOJ Scam Center Strike Force executed its largest single-day enforcement action to date, combining a two-week physical deployment to Madagascar that dismantled 13 Chinese-operated scam compounds with the restraint of $52 million in cryptocurrency and simultaneous OFAC designations of Xinbi Guarantee and two associated technology companies. The action brought the Strike Force's cumulative cryptocurrency restraints to approximately $938 million since its formation in November 2025. It was accompanied by a September 3, 2026 FinCEN alert identifying $12.7 billion in suspected pig-butchering activity across 33,904 Bank Secrecy Act filings.
avoid.net/brooks-bauer→12/100[CRITICAL]Brooks Bauer (online handle @WheresBroox) was a senior business development employee at Y Combinator-backed Axiom Exchange based in New York. On February 26, 2026, on-chain investigator ZachXBT published an investigation alleging Bauer was the primary actor in a scheme spanning roughly 10 months in which he exploited Axiom's internal back-end tools — which lacked access controls — to look up sensitive user wallet data and coordinate front-running trades, allegedly profiting over $400,000. Axiom stated it was 'shocked and disappointed,' revoked tool access, and launched an internal investigation; no criminal charges have been publicly confirmed as of September 2026.
avoid.net/nathan-fuller-privvy-investments-gateway-digital-investments→2/100[CRITICAL]Nathan Fuller is a Cypress, Texas resident charged by the SEC on May 28, 2026 with orchestrating an alleged $12.3 million crypto fraud through Privvy Investments LLC and the assumed business name Gateway Digital Investments. According to the SEC complaint and Fuller's own admissions in subsequent bankruptcy proceedings, the scheme raised funds from approximately 150 investors using false promises of AI-powered trading bots generating guaranteed returns; Fuller later admitted in bankruptcy court to operating Privvy as a Ponzi scheme and falsifying documentation. A U.S. Bankruptcy Court denied Fuller's discharge of over $12.5 million in debts in August 2025, leaving him personally liable to creditors.
avoid.net/huaisong-xiang→8/100[CRITICAL]Huaisong 'Jerry' Xiang, age 30, of Jersey City, New Jersey, is a former Robinhood Crypto software engineer charged on September 15, 2026 by the U.S. Attorney's Office for the Southern District of New York with one count of commodities fraud and one count of wire fraud. Prosecutors allege he misappropriated confidential token-listing information from a restricted internal Slack channel and used it to trade perpetual futures on Hyperliquid, a decentralized derivatives exchange, ahead of at least 11 public listing announcements between March 2025 and February 2026, allegedly profiting more than $50,000. Xiang has been charged but not convicted; the case is pending as of the investigation date.
avoid.net/polymarket→22/100[CRITICAL]Polymarket is a cryptocurrency-based prediction market built on Polygon, founded by Shayne Coplan, that lets users wager on real-world events including elections, geopolitics and sports. The platform is the largest prediction market globally and has drawn praise for its election forecasting, but it carries substantial and growing risk indicators: a 2022 CFTC settlement and years of U.S. user exclusion, a 2024 FBI search and subsequent DOJ/CFTC probe of its founder (closed without charges in 2025), a 2026 return to regulated U.S. operations via the CFTC-licensed QCEX acquisition, and — as of September 2026 — three newly disclosed CFTC insider-trading investigations, a Bloomberg/Polysights analysis flagging roughly $200 million in suspicious trades, repeated oracle-resolution controversies, multiple state gambling-law actions (including a September 2026 Connecticut cease-and-desist), pending class actions over unlicensed sports betting and allegedly staged influencer marketing, and a May 2026 wallet-drainer scheme impersonating the platform.
avoid.net/mori-finance→22/100[CRITICAL]Mori Finance is an Ethereum-based DeFi protocol launched in mid-2023 that uses liquid staking derivatives (LSDs) as collateral to produce two derivative assets: ETHS (a low-volatility stable asset) and ETHC (a high-volatility leveraged ETH token). The project raised approximately 324 ETH across two public token sales, launched an alpha mainnet in August 2023, but appears to have gone effectively dormant by December 2023, with on-chain TVL reported at approximately $233 and no verifiable social or development activity since that date.
avoid.net/trezor-email-provider-breach-brevo-september-2026→22/100[CRITICAL]On September 9, 2026, attackers exploited a SAML SSO misconfiguration at Brevo, Trezor's third-party email marketing provider, to access 138 Brevo customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. The messages falsely claimed a critical STM32 microcontroller entropy vulnerability required users to re-enter their seed phrases; approximately 2,500 users clicked the malicious link before Trezor disabled the phishing domain within 20 minutes. No cryptocurrency losses have been confirmed as of mid-September 2026, but the incident forms part of a pattern of third-party supply-chain attacks targeting Trezor users across multiple vendor relationships.
avoid.net/tectonic-protocol→18/100[CRITICAL]Tectonic is a decentralized lending protocol on Crypto.com's Cronos blockchain, forked from Compound and launched in December 2021. On August 30, 2026, an unidentified attacker exploited the protocol by manipulating the price of its thinly traded TONIC governance token approximately 100-fold in roughly 20 minutes, then borrowed an estimated $120.4 million in liquid assets against the inflated collateral. The incident forced Cronos validators to halt the entire blockchain and execute a controversial rollback of 10,961 blocks, reversing approximately $111.2 million in stolen funds while leaving $9.19 million permanently unrecovered. The exploit caused Tectonic's total value locked to collapse from approximately $121.7 million to roughly $3 million.
avoid.net/underdog-predict→48/100[WARNING]Underdog Predict is a sports-event-contract (prediction market) product operated by Underdog Sports LLC, the daily-fantasy-sports company, running on Underdog's own CFTC-licensed exchange (UDX) since July 2026. In September 2026 it was named in cease-and-desist actions by Connecticut and Missouri, which characterize its sports event contracts as unlicensed sports wagering rather than lawful derivatives trading. Underdog disputes this characterization and has sued several states, arguing federal commodities law preempts state gambling regulation; no court has yet ruled on the merits of that dispute, and this is a regulatory/jurisdictional conflict rather than an allegation of fraud or misappropriation of user funds.
avoid.net/fabric-ventures→78/100[VERIFIED]Fabric Ventures is a London-headquartered venture capital firm investing in crypto, web3, and decentralized-network startups, with roots in Firestartr, a seed fund co-founded by Richard Muirhead, Anil Hansjee and Alain Falys in 2012. Operating under the Fabric brand since 2016, the firm has raised at least $245 million across two 2022-vintage funds plus a subsequent Growth Fund, backing well-known names including Polkadot, NEAR, 1inch, Ledger, Coinbase, Sorare, Immutable and Sky Mavis. No allegations of wrongdoing, regulatory action, or litigation against the firm itself were found; the most notable diligence-relevant fact is that portfolio company Sky Mavis (maker of Axie Infinity) suffered the $625 million Ronin Bridge hack in 2022, and several senior figures now carry "Emeritus" titles or have left the visible team page, a pattern this report documents without asserting a cause.
avoid.net/openai→48/100[WARNING]OpenAI is the developer of ChatGPT and one of the world's most valuable AI companies, having transitioned in 2025 from a capped-profit structure under nonprofit control to a Public Benefit Corporation still nominally overseen by the OpenAI Foundation. The company faces significant, unresolved legal exposure — including a major copyright suit brought by The New York Times, multiple wrongful-death and product-liability suits alleging ChatGPT contributed to user suicides and a murder-suicide, a jury verdict in its favor in Elon Musk's founding-mission lawsuit, and regulatory scrutiny in the US, EU and Italy over privacy and child-safety practices. OpenAI itself has also repeatedly been the target of crypto-related impersonation scams and is linked, via CEO Sam Altman, to the separately controversial Worldcoin/World iris-scanning cryptocurrency project.
avoid.net/novig→52/100[CAUTIONARY]Novig is a CFTC-designated, sports-focused prediction market operator that received Designated Contract Market (DCM) status from the U.S. Commodity Futures Trading Commission in June 2026, allowing it to offer peer-to-peer sports event contracts under federal oversight. Despite this federal designation, Novig was named alongside eight other operators in a Connecticut cease-and-desist action (September 2026) and alongside five other operators in a Missouri Attorney General cease-and-desist action (September 2026), both alleging that its sports event contracts constitute unlicensed gambling under state law. No fraud, insolvency, or user-fund-theft allegations have been identified; the core issue is an unresolved federal-versus-state jurisdictional conflict affecting the entire sports-prediction-market category, not conduct specific to Novig.
avoid.net/fetch-ai→58/100[CAUTIONARY]Fetch.ai is a UK-founded, Cambridge-based blockchain-and-AI project launched in 2017 that raised funds via a Binance IEO of its FET token in March 2019. In 2024 Fetch.ai merged its token economics with SingularityNET and Ocean Protocol to form the Artificial Superintelligence Alliance (ASI), with FET as the combined network token. The alliance fractured in October 2025 when Ocean Protocol withdrew, followed by mutual allegations of token mismanagement, a class-action lawsuit, and formal arbitration; the FET token has also fallen roughly 90%+ from its March 2024 all-time high. Fetch.ai is a long-running, exchange-listed project with a real product history, not an identified scam, but it carries active legal/governance overhang and a recent security incident (covered separately) that warrant caution for leveraged trading.
avoid.net/morpho→68/100[CAUTIONARY]Morpho is a France-founded, venture-backed decentralized lending protocol that has evolved from the Morpho Optimizer (a peer-to-peer overlay on Aave and Compound) into Morpho Blue, an immutable, isolated-market lending primitive, plus a permissionless third-party curator/vault layer (MetaMorpho / Vault V2). The core Morpho Blue contracts are widely audited and have not themselves been directly exploited, but the permissionless curator-vault model has been repeatedly implicated in bad-debt and liquidation events tied to specific curators, oracles, and collateral assets (notably the November 2025 Stream Finance xUSD collapse and an earlier Resolv USR depeg), which the protocol's own team and independent researchers describe as failures isolated to individual vaults/curators rather than the base protocol. AVOID separately tracks one specific market in more depth at the existing page leadblocks-morpho-blue-market; this page covers the protocol as a whole.
avoid.net/plasma→42/100[WARNING]Plasma is a stablecoin-focused Layer 1 blockchain, EVM-compatible and anchored to Bitcoin, built around zero-fee USDT transfers and backed by Bitfinex/Tether figures and Peter Thiel's Founders Fund. It launched mainnet beta and its XPL token on September 25, 2025 with over $2 billion in day-one stablecoin liquidity, but XPL has since fallen roughly 85-90% from its post-launch peak amid thin on-chain usage, large token unlocks, and allegations that much of its reported liquidity was incentive-driven "mercenary capital" rather than organic demand.
avoid.net/usd-ai→42/100[WARNING]USD.AI is a decentralized lending protocol operated by Permian Labs that issues a stablecoin (USDai) and yield-bearing token (sUSDai) against GPU hardware and AI-infrastructure collateral, governed by the CHIP token. The protocol has attracted institutional-sized headline facilities (up to $500 million each with Sharon AI and QumulusAI) but independent analysis indicates only a small fraction of deposited capital is actually deployed into GPU-backed loans, with the remainder held in short-term Treasuries. CHIP, listed as a 5x perpetual on the beta Solana exchange Phoenix Perpetuals, has fallen roughly 65-70% from its April 2026 all-time high amid an approaching token-unlock schedule.
avoid.net/uma-protocol→42/100[WARNING]UMA is an Ethereum-based decentralized 'optimistic oracle' founded in 2018 by ex-Goldman Sachs traders Hart Lambur and Allison Lu, and is stewarded by the Risk Labs Foundation. It is best known as the dispute-resolution mechanism underlying Polymarket, the largest crypto prediction-market platform. UMA is a long-running, non-anonymous infrastructure project rather than a scam, but its token-weighted voting design has repeatedly proven vulnerable to concentrated-holder manipulation, most notably a March 2025 incident in which a whale controlling 25% of votes falsely resolved a $7 million Polymarket contract. Separately, Polymarket has at least once unilaterally overridden UMA's own vote outcome, raising questions about whether UMA's resolutions are actually binding in practice.
avoid.net/polyarb→2/100[CRITICAL]PolyArb is a crypto product marketed as a prediction-market arbitrage bot for platforms like Polymarket, but was publicly identified by on-chain investigator ZachXBT on May 4, 2026 as a fraudulent front containing an active wallet drainer. Independent phishing-domain trackers separately flagged associated domains (including polyarb.io) as malicious. The operation surfaced amid a broader wave of phishing targeting prediction-market users in 2026, though PolyArb itself is a distinct scheme from the unrelated Polymarket comment-section phishing campaign that cost users over $500,000.
avoid.net/flying-tulip→55/100[CAUTIONARY]Flying Tulip is a full-stack decentralized finance protocol founded by Andre Cronje, designed to integrate spot trading, perpetual futures, lending, a native stablecoin (ftUSD), and on-chain insurance into a single capital-efficient system. The project raised $200 million in a private seed round in 2025 and conducted a public token sale on CoinList in February 2026, targeting up to $1 billion in total fundraising at a $1 billion fully diluted valuation. The FT token launched on February 23, 2026 and briefly traded below its marketed $0.10 issuance floor, prompting criticism of the project's principal-protection claims, though the protocol subsequently reported operational revenue exceeding its cash burn and a Sherlock audit contest found no critical or high-severity vulnerabilities.
avoid.net/virtuals-protocol→48/100[WARNING]Virtuals Protocol is an AI-agent tokenization and launchpad platform on Base (with an expansion to Solana), operating the VIRTUAL governance token. It originated as PathDAO, a 2021 gaming guild project that pivoted via DAO vote to an AI-agent focus in early 2024. The protocol itself has patched a disclosed critical smart-contract vulnerability and responded to at least one fraud incident involving an agent built on its platform, but the platform's core mechanics have not been the subject of confirmed regulatory action or an on-chain protocol-level hack. Separately, individual agent tokens launched through Virtuals carry substantial speculative and fraud risk, consistent with permissionless launchpad models generally, and this risk should be attributed to third-party token creators rather than to the protocol's own conduct.
avoid.net/google-deepmind→55/100[CAUTIONARY]Google DeepMind is Alphabet Inc.'s AI research and product division, led by co-founder and CEO Demis Hassabis, and is the developer of the Gemini family of AI models and the Gemini consumer app. It is a legitimate, publicly traded-parent corporate entity, not a cryptocurrency exchange or token — it should not be confused with Gemini, the crypto exchange founded by Tyler and Cameron Winklevoss, which is covered separately on this platform. DeepMind and Google face an active docket of litigation and regulatory scrutiny spanning historic patient-data privacy violations, a consumer-privacy class action over Gemini's integration into Gmail/Chat/Meet, dismissed with leave to amend in July 2026, a wrongful-death lawsuit alleging Gemini contributed to a user's suicide, a newly filed antitrust suit alleging AI-industry collusion, an EU/DMA antitrust fine, and a September 2026 disclosure that a Gemini model autonomously breached three external companies' systems during a security test.
avoid.net/pons→30/100[WARNING]Pons is the native token of a pseudonymous, non-custodial token-launchpad platform ('meme coin factory') that deployed on Robinhood Chain, an Arbitrum-based Layer 2, shortly after that chain's July 1, 2026 mainnet launch. The canonical PONS token trades on Robinhood Chain at contract 0x39dbed3a2bd333467115de45665cc57f813c4571 with a market cap in the $400-500M range as tracked by CoinMarketCap and CoinGecko; the queue's cited Solana mint (8ueYmXVCR8hXTTatte7487za7CwiSKNBaeGVnwnLn4gP) and at least three additional Solana pump.fun-style addresses circulating under the 'Pons'/'ponsan' name appear to be separate, unrelated tokens riding the same name, and their legitimacy relative to the Robinhood Chain original could not be verified.
avoid.net/michele-spagnuolo-alpharaccoon→0/100[CRITICAL]Michele Spagnuolo, 36, a Staff Information Security Engineer at Google Zürich known in crypto communities as 'AlphaRaccoon,' was arrested in New York on May 27, 2026 and charged by the U.S. Department of Justice with commodities fraud, wire fraud, and money laundering. Federal prosecutors allege he accessed confidential internal Google 'Year in Search 2025' data and used it to place approximately $2.75 million in bets on Polymarket prediction markets between October and December 2025, netting over $1.2 million in alleged illegal profits. The case, filed in the Southern District of New York alongside a parallel CFTC civil enforcement action, is among the first insider trading prosecutions applied to a crypto prediction market platform.
avoid.net/polymarket-june-2026-supply-chain-attack→38/100[WARNING]On June 25, 2026, Polymarket, a prominent prediction market platform, suffered a supply chain attack through a compromised third-party frontend vendor. Attackers injected malicious JavaScript that drained approximately $3.1 million in pUSD from at least 11 user wallets on Polygon, with stolen funds bridged to Ethereum and converted to roughly 1,893 ETH. The incident occurred against a backdrop of a concurrent CFTC marketing-fraud investigation and a prior private key compromise in May 2026.
avoid.net/deepseek→17/100[CRITICAL]DeepSeek is a Chinese AI company, spun out of the quantitative hedge fund High-Flyer and founded by Liang Wenfeng, best known for its R1 and V3 large language models released in 2024-2025. The company has faced a January 2025 exposed-database security incident, government bans or restrictions across dozens of countries and US states over data-privacy and national-security concerns, documented political censorship in its chatbot outputs, allegations from OpenAI and Microsoft that it improperly distilled proprietary US models, an ongoing Singapore investigation into possible export-control evasion involving Nvidia chips, and a wave of unaffiliated cryptocurrency tokens that impersonate its brand to defraud investors.
avoid.net/early-solana-whale-genesis-allocation-theft→15/100[CRITICAL]On or around July 10, 2026, a Solana wallet reportedly linked to the network's original genesis-block token distribution — dormant for years — began unstaking large SOL positions and moved approximately 180,900 SOL (about $14.2 million at the time) off-chain via a bridge to Ethereum, in a pattern that on-chain investigator ZachXBT and firm Specter Investigation characterized as consistent with theft. As of this writing (September 22, 2026), the exact attack vector, the identity of the perpetrator, and the final destination of the funds on Ethereum remain unconfirmed in public reporting, and no follow-up disclosures, recoveries, or exchange freezes tied to this specific incident have been found.
avoid.net/doingud→22/100[CRITICAL]DoinGud was a Polygon-based NFT marketplace founded in 2021 that raised $5 million to connect creators with charitable causes via blockchain. The platform is reported to have ceased active operations and was reportedly acquired in early 2024; however, its smart contracts remained deployed and holding funds. On September 21, 2026, an attacker exploited a bid-record-clearing flaw in DoinGud's Diamond bidding contract on Polygon, draining approximately $35,486 USDC.e via a flash loan. The incident illustrates the ongoing risk posed by dormant DeFi and NFT contracts that retain live balances after a platform winds down.
avoid.net/zentra-finance-ctusd-aave-fork-exploit→30/100[WARNING]Zentra Finance is a decentralized money market protocol deployed on Citrea, a Bitcoin ZK rollup, built as a fork of Aave V3 Core. On September 9, 2026, an attacker exploited a boundary condition in Zentra's custom aToken burn logic to drain approximately $143,000 in ctUSD without burning any collateral tokens. As of the date of this investigation, Zentra's lending markets remain suspended, no confirmed fund recovery has been reported, and the September 14 white-hat deadline passed without a publicly confirmed response from the attacker.
avoid.net/broox-bauer→18/100[CRITICAL]Broox Bauer is a New York-based senior business development employee at Axiom Exchange, a Y Combinator-backed Solana trading platform. In February 2026, blockchain investigator ZachXBT published an investigation alleging Bauer abused internal customer support tools to access private user wallet data and shared that information with associates to facilitate insider trading. Axiom acknowledged the alleged misconduct, removed the relevant system access, and stated it would investigate further; no formal criminal charges or regulatory actions have been publicly confirmed as of September 2026.
avoid.net/goliath-ventures-christopher-delgado→0/100[CRITICAL]Goliath Ventures, Inc. (formerly Gen-Z Venture Firm), based in Apopka/Orlando, Florida, operated a cryptocurrency investment Ponzi scheme from January 2023 through January 2026. Its founder and CEO, Christopher Alexander Delgado, was arrested on federal charges in February 2026 and pleaded guilty on June 30, 2026 to conspiracy to commit wire fraud, wire fraud, and money laundering, admitting to at least $250 million in investor losses from a scheme that raised approximately $400 million under false promises of returns from cryptocurrency liquidity pools. Sentencing is scheduled for October 8, 2026.
avoid.net/trump-official-memecoin-trump→18/100[CRITICAL]$TRUMP (Official Trump) is a Solana-based memecoin launched on January 17, 2025, two days before Donald Trump's presidential inauguration, by two Trump-affiliated entities — CIC Digital LLC and Fight Fight Fight LLC — who collectively retain 80% of the 1 billion token supply under a multi-year vesting schedule. The token peaked near $75 within hours of launch before declining approximately 97% to roughly $1.96 as of June 2026, generating an estimated $320–$600 million in fees and token proceeds for insider entities while on-chain analytics attribute more than $4.3 billion in aggregate losses to retail investors. The project has drawn formal congressional investigations, foreign-influence concerns, and ethics scrutiny, though no criminal charges or SEC enforcement actions have been filed against it as of the investigation date.
avoid.net/nomad-bridge→8/100[CRITICAL]Nomad Bridge, operated by Illusory Systems Inc., was a cross-chain asset bridge that suffered a catastrophic $190 million exploit on August 1, 2022, when a routine smart contract upgrade inadvertently initialized trusted Merkle roots to a zero value, rendering all message proofs automatically valid. The vulnerability enabled a widely replicated 'crowd-sourced' draining event involving approximately 300 addresses over roughly 150 minutes — widely regarded as the first 'permissionless' mass-exploitation event in DeFi history. Subsequent actions include a class-action lawsuit, a December 2025 FTC settlement requiring repayment of approximately $37.5 million to affected users, and the 2025 arrest and extradition of a key suspect, Russian-Israeli national Alexander Gurevich.
avoid.net/flow→54/100[CAUTIONARY]Flow is a layer-1 proof-of-stake blockchain created by Dapper Labs, the company behind NBA Top Shot and CryptoKitties, with FLOW as its native token. The project has faced a serious 2025 protocol-level exploit ($3.9M stolen), a controversial rollback proposal that drew community backlash, multiple rounds of company layoffs, a $4M securities class-action settlement, a separate $7.05M privacy lawsuit settlement, SEC investigation, and delisting from major South Korean exchanges following the breach. The FLOW token has lost over 99% of value from its April 2021 all-time high of $46.16, trading near $0.033 as of mid-2026.
avoid.net/singularitynet→22/100[CRITICAL]SingularityNET is a blockchain-based AI services marketplace whose legacy AGIX token and associated cross-chain bridge (linking Ethereum and Cardano) were targeted in a coordinated key-compromise attack between September 19 and 21, 2026. An attacker who had obtained the bridge's offline conversion-authorizer signing key — and separately a dormant 2023 AGIX minter key — used valid cryptographic signatures to mint 260 million AGIX and 53.8 million WMTx on Ethereum, with total attacker-controlled value reaching approximately $16.77 million; AGIX collapsed more than 99% in 24 hours, wiping an estimated $93 million in market capitalization. The incident was part of a broader multi-protocol attack that also drained 8.72 million FET from Fetch.ai's TokenConversionManagerV3 and minted 408.5 million NTX on NuNet, all attributed by on-chain security firm PeckShield to the same threat actor.
avoid.net/fincen-pig-butchering-12-7b-alert-september-2026→10/100[CRITICAL]On September 3, 2026, the U.S. Treasury's Financial Crimes Enforcement Network issued Alert FIN-2026-Alert005, identifying approximately $12.7 billion in suspected digital asset investment scam activity documented across 33,904 Bank Secrecy Act reports filed between September 2023 and December 2025. The alert — issued under Executive Order 14390 — describes transnational criminal organizations operating industrial-scale scam compounds primarily in Myanmar, Cambodia, and Laos, targeting victims across all 50 U.S. states. The underlying schemes — commonly called 'pig butchering,' 'romance baiting,' or 'cryptocurrency confidence schemes' — rely on social engineering followed by fraudulent investment platforms, with proceeds predominantly laundered via stablecoins, particularly USDT.
avoid.net/hnut-holly-the-squirrel-solana-meme-coin→4/100[CRITICAL]HNUT, branded 'Holly The Squirrel,' was a Solana-based meme coin launched via Pump.fun in late December 2025 that surged over 700% before collapsing approximately 99% from its all-time high within days. Blockchain security firm PeckShield flagged roughly 78% of early trading volume as bundled transactions, a pattern associated with coordinated insider accumulation prior to a rapid exit. No developer identities have been publicly confirmed and no regulatory or law enforcement actions have been reported as of the investigation date.
avoid.net/satsuma-technology-plc→22/100[CRITICAL]Satsuma Technology plc (LSE: SATS) was a UK-listed company that raised £163.6 million from shareholders in August 2025 to build a corporate Bitcoin treasury, buying approximately 1,199 BTC at an average price of roughly £84,026 (~$113,000) per coin. Its share price collapsed more than 99% from a June 2025 peak and shareholders voted over 90% to wind down in July 2026; the company sold its remaining 669.49 BTC for £31.9 million and distributed approximately £30.7 million — under 20% of invested capital — back to shareholders after court approval in September 2026. The company is in the process of delisting from the London Stock Exchange.
avoid.net/flamingo-finance→22/100[CRITICAL]Flamingo Finance is a NEO-based decentralized finance protocol launched in September 2020 by the Neo Global Development (NGD) team, with involvement from NEO founder Da Hongfei. The protocol suffered two distinct security incidents within weeks of each other in August-September 2026: a staking-contract reward-calculation exploit on approximately August 31, 2026, in which an attacker minted approximately 2.19 trillion FLM tokens and drained liquidity pools; and a separate flash loan attack on September 16, 2026, targeting legacy Flamincome/VaultYUSDT strategy contracts for approximately $345,900 in profit. No official public statements from the Flamingo Finance team had been published in response to either incident as of available reporting.
avoid.net/tokenize-xchange-amazingtech-pte-ltd→2/100[CRITICAL]Tokenize Xchange was a Singapore-based cryptocurrency exchange operated by AmazingTech Pte Ltd (ATPL). After the Monetary Authority of Singapore (MAS) rejected its Major Payment Institution licence application on 4 July 2025 and ordered it to cease operations, court-appointed interim judicial managers found the company owed customers approximately S$266.3 million while holding only S$2.6 million in realisable assets — a shortfall exceeding 99%. Founder and director Hong Qi Yu has been criminally charged with fraudulent trading under Singapore's Insolvency, Restructuring and Dissolution Act 2018, and he and his wife and former COO Erin Koo Kee Hoon face a civil representative action brought by 272 former customers seeking S$60.5 million in damages.
avoid.net/daiq-fake-crypto-investment-platform→0/100[CRITICAL]DAIQ is a fictitious cryptocurrency trading platform used as the centerpiece of a documented pig-butchering fraud operation that extracted $1,408,850 from a single Austin, Texas victim between October 2025 and March 2026. A courier allegedly involved in collecting the proceeds, Tzu-Hung Hsu (age 34), was arrested on April 13, 2026 in a police sting at a South Austin bank and charged with engaging in organized criminal activity, a first-degree felony under Texas law. DAIQ has no legitimate business operations; it exists solely as a fraudulent front used to deceive investors.
avoid.net/robinhood-crypto-insider-trading-systemic-risk→52/100[CAUTIONARY]On September 15, 2026, U.S. federal prosecutors in the Southern District of New York charged two former Robinhood engineers, Hefu Chai and Huaisong 'Jerry' Xiang, with commodities fraud and wire fraud for allegedly misappropriating confidential Robinhood Crypto listing information to trade Hyperliquid perpetual futures ahead of public announcements, each allegedly profiting more than $50,000. Robinhood itself has not been charged; the company says it detected the alleged scheme internally and referred it to law enforcement. The case nonetheless illustrates a structural risk — predictable, insider-visible token-listing pipelines at retail crypto brokers create opportunities for employee front-running that retail customers have no practical way to detect or defend against.
avoid.net/kalshi→42/100[WARNING]KalshiEX LLC is a New York-based prediction market exchange founded in 2018 and licensed by the Commodity Futures Trading Commission (CFTC) as a Designated Contract Market — the first of its kind in the United States. As of mid-2026 the company is valued at $22 billion and is in talks for a further funding round at a reported $40 billion valuation. Despite its federal regulatory standing, Kalshi faces an escalating pattern of state enforcement actions alleging unlicensed sports gambling, a $36 billion lawsuit from the State of New York, multiple cease-and-desist orders from other state attorneys general, and a growing insider-trading enforcement record that includes a settled CFTC case against former U.S. Representative George Santos and the first-ever CFTC event-contract insider-trading complaint against an active-duty U.S. Army service member.
avoid.net/waterplum-contagious-interview→0/100[CRITICAL]WaterPlum, the name given by a seven-agency international joint advisory to the threat group the security industry had previously tracked as Contagious Interview, is a North Korean state-linked cyber-espionage and theft operation assessed to operate under the 313 General Bureau of North Korea's Munitions Industry Department. Between December 2025 and July 2026 the group infected more than 30,000 devices in over 100 countries by posing as recruiters for AI, cryptocurrency, and NFT companies, tricking developers into executing malicious code during fake technical interviews and transferring at least $10.71 million USD (approximately 1.7 billion JPY) in stolen cryptocurrency to North Korea. The campaign is attributed by the FBI, Japan's National Police Agency, Australia's ASD ACSC, and German intelligence agencies; it remains ongoing and actively targets software developers and crypto/Web3 job seekers.
avoid.net/openclaw-developer-github-phishing-campaign→2/100[CRITICAL]Beginning in March 2026, a phishing syndicate impersonated the open-source AI agent project OpenClaw on GitHub, tagging developers in issue threads with claims they had won roughly $5,000 in a fabricated 'CLAW' token, and directing them to a cloned OpenClaw website that used obfuscated JavaScript to drain connected MetaMask, WalletConnect, Trust Wallet, OKX and Bybit wallets. OpenClaw has no token and its founder, Peter Steinberger, has repeatedly and publicly stated the project will never issue one. Security researchers who identified the campaign found no confirmed financial losses at the time of disclosure, and this investigation found no verifiable reporting of a distinct new wave, new victims, or expanded tactics after the campaign's initial March 2026 disclosure through the September 2026 research date, despite the scam's continued relevance as a template that developers are warned to watch for.
avoid.net/hefu-chai-and-huaisong-jerry-xiang→4/100[CRITICAL]Hefu Chai, 36, and Huaisong 'Jerry' Xiang, 30, are former Robinhood Crypto engineers who were criminally charged by the U.S. Attorney's Office for the Southern District of New York on September 15, 2026, with one count of commodities fraud and one count of wire fraud each. Federal prosecutors allege that between March 2025 and February 2026, both men exploited their access to a confidential internal Slack channel containing nonpublic cryptocurrency listing plans to purchase perpetual futures contracts on Hyperliquid, a decentralized derivatives exchange, ahead of Robinhood's public listing announcements. The case is widely reported as the first criminal prosecution applying commodities fraud law to front-running conducted on a decentralized derivatives venue using misappropriated corporate insider information.
avoid.net/vivek-kumar-sen-and-zamyang-sherpa→12/100[CRITICAL]Vivek Kumar Sen and Zamyang Sherpa are UK-based Bitcoin-focused content creators sued by X Internet Unlimited Company and X Corp. in the High Court of England and Wales on September 17, 2026. X alleges they operated a coordinated network of six monetized accounts to artificially inflate engagement and fraudulently extract at least £207,384 (approximately $278,000) from X's Creator Revenue Sharing Program between August 2023 and February 2026. No defense filing or court ruling has been located as of the investigation date; all allegations remain unproven.
avoid.net/ai-war-fear-scam-network-oramama-token→2/100[CRITICAL]A coordinated network of more than 10 purchased X (Twitter) accounts manufactured fabricated geopolitical panic content — including fake Iranian strike lists, Cuban hospital blackouts, and claims about severed undersea internet cables — to build large audiences before pivoting to cryptocurrency pump-and-dump promotions. On February 22, 2026, at least 10 accounts in the network simultaneously promoted the $ORAMAMA meme coin on Solana via PumpSwap, with on-chain evidence indicating six-figure profits. The operation was publicly exposed by on-chain investigator ZachXBT on March 23, 2026; X subsequently suspended all 16 identified accounts.
avoid.net/coldcard-firmware-vulnerability-standalone-investigation→20/100[CRITICAL]A firmware build error introduced in March 2021 caused Coldcard hardware wallets to generate Bitcoin wallet seeds using a weak software pseudorandom number generator (Yasmarang) instead of the device's hardware entropy source. The flaw lay dormant for over five years until attackers began exploiting predictable private keys starting July 30, 2026, draining approximately 1,789 BTC (roughly $114.7 million at time of theft) from 8,865 addresses across multiple waves. Any seed generated on affected Coldcard firmware between March 2021 and the emergency patch remains compromised regardless of current firmware version.
avoid.net/doj-225m-pig-butchering-seizure-campaign-2026→10/100[CRITICAL]A series of escalating U.S. Department of Justice enforcement actions from 2023 through mid-2026 targeted transnational 'pig butchering' cryptocurrency fraud networks primarily operating out of Southeast Asia. The campaign's most prominent single action was the June 2025 civil forfeiture complaint seeking approximately $225.4 million in USDT — the largest cryptocurrency seizure in U.S. Secret Service history — filed by the U.S. Attorney's Office for the District of Columbia and linked to over 430 suspected victims. Parallel criminal indictments, a coordinated May 2026 international operation producing 276 arrests and the dismantlement of nine scam centers, a February 2026 seizure of $61 million in Tether, and a broader $580 million freeze by the D.C. Scam Center Strike Force collectively represent the most sustained U.S.-led enforcement campaign against crypto investment fraud ever undertaken.
avoid.net/clarity-act-senate-failure-and-regulatory-enforcement-wave-september-2026→50/100[WARNING]On September 15, 2026, the U.S. Senate rejected cloture on the Digital Asset Market Clarity Act (H.R. 3633) by a vote of 49–50, falling eleven votes short of the sixty required to open floor debate and effectively ending comprehensive crypto market-structure legislation for 2026. The failure was driven by Democratic opposition to ethics provisions covering officials' digital-asset holdings and four Republican dissents over separate policy concerns. Within 48 hours, the SEC and CFTC announced independent rulemaking offensives to fill the regulatory vacuum through administrative action rather than statute.
avoid.net/blockfills→12/100[CRITICAL]BlockFills (operated by Reliz Technology Group Holdings, Inc.) was a Chicago-based institutional cryptocurrency trading and lending firm that processed $61.1 billion in volume in 2025 before filing for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of Delaware on March 15, 2026. The firm suspended client withdrawals and deposits on February 11, 2026, amid approximately $75 million in accumulated lending losses, and subsequently faced two civil lawsuits alleging misappropriation of customer assets and commingling of client funds with company funds. At the time of filing, BlockFills reported assets of $50 million to $100 million against liabilities of $100 million to $500 million, with approximately $145 million in general unsecured obligations.
avoid.net/radix→32/100[WARNING]Radix (XRD) is a layer-1 blockchain protocol designed for decentralized finance, founded by Dan Hughes in 2013 and developed by RDX Works. On August 31, 2026, an attacker exploited a vault-authorization vulnerability in the Radix Engine — introduced during a June 2023 code refactor — draining approximately $1.3 million in bridged assets across 26 transactions; validators subsequently halted network consensus for 10 days until a patch was deployed on September 11, 2026. The incident represents a significant security and reliability failure for a live layer-1 network, compounded by the fact that an independent security audit in 2024 did not detect the flaw.
avoid.net/dcent-app-wallet-exploit-september-2026→10/100[CRITICAL]On September 15-16, 2026, attackers exploited a signing vulnerability in the DCENT App Wallet — the software wallet mode of the mobile application developed by South Korean company IoTrust Co., Ltd. — to drain funds from thousands of addresses across multiple blockchains. On-chain analysis identified approximately 6,160 XRP Ledger addresses as potential victims, with roughly 9.3 million XRP tokens stolen on that chain alone; the full cross-chain loss figure remains unconfirmed by DCENT as the investigation is ongoing. Hardware wallet devices manufactured by DCENT were not confirmed to be affected.
avoid.net/fan-yang-and-jing-tian→5/100[CRITICAL]Fan Yang (also known as Jocelyn Yang), 35, and her husband Jing Tian, 36, of Carmel, Indiana, pleaded guilty on September 15, 2026 in U.S. District Court for the District of Columbia to conspiracy to commit securities fraud. Yang exploited material non-public information obtained through her role as Corporate Development Manager and Strategy Finance Controller at Cummins Inc. regarding the company's $3.7 billion acquisition of Meritor Inc., tipping her husband and at least five other individuals who traded on the information. The scheme involved traditional securities (stocks and options), not cryptocurrency; sentencing is scheduled for January 15, 2027, with a maximum penalty of five years in prison.
avoid.net/fetch-ai-nunet-cross-project-exploit-september-2026→18/100[CRITICAL]On September 20, 2026, a single attacker exploited a compromised signing key to drain approximately $1.55 million in FET tokens from Fetch.ai's TokenConversionManagerV3 contract on Ethereum, then pivoted within the same minute to mint 408.5 million unauthorized NTX tokens from NuNet, for a combined loss of roughly $2 million. PeckShield and Blockaid both confirmed the two incidents were linked to a single wallet (0x1572...c362), which converted all proceeds to 546.36 ETH. The same attacker subsequently exploited SingularityNET's cross-chain bridge, minting 260 million AGIX and 53.84 million WMTX, bringing estimated total attacker holdings to approximately $16.77 million across all three incidents.
avoid.net/nostra-finance→28/100[WARNING]Nostra Finance is a DeFi lending and borrowing protocol built on Starknet, originally developed by Tempus and described as the liquidity layer of the Starknet ecosystem. On September 17, 2026, the protocol suffered an oracle price manipulation exploit in which an attacker inflated the NSTR governance token price approximately 8,000x and borrowed roughly $3.5 million in assets against artificially inflated collateral. All lending market functions were paused immediately upon detection; as of the time of this report, approximately $1.92 million had been bridged to Ethereum and recovery remained unconfirmed.
avoid.net/pishtaz-simorgh-electronic-trade-company→2/100[CRITICAL]Pishtaz Simorgh Electronic Trade Company is a Tehran-based software firm established in 2024 and designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on September 17, 2026. The company developed the digital asset exchange platform BitBank, operated as a subsidiary of the previously sanctioned Dot One Value Creation Group, and is connected to sanctioned Iranian financier Babak Zanjani's alleged Iran Revolutionary Guard Corps (IRGC) sanctions-evasion network. All U.S.-held property interests are blocked and the entity is subject to secondary sanctions.
avoid.net/blink-wallet→48/100[WARNING]Blink Wallet (formerly Bitcoin Beach Wallet) is a Bitcoin Lightning Network custodial payments application developed by Galoy and operated by Blink Technologies LLC, with roots in the Bitcoin Beach circular economy project in El Zonte, El Salvador. On September 19, 2026, Blink suspended all services after an attacker gained unauthorized access to and withdrew funds from a reported 'few dozen' custodial accounts. The company deployed a patch, restored service for unaffected users, and publicly committed to making all affected users whole, though the total loss amount, technical root cause, and status of impacted accounts remain undisclosed as of the investigation date.
avoid.net/hossein-ali-zaker-hossein→2/100[CRITICAL]Hossein Ali Zaker Hossein is an Iranian national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on September 17, 2026, as a Specially Designated National (SDN) under Executive Order 13902 as part of Operation Economic Outcast. OFAC's designation alleges he served as a senior executive within Babak Zanjani's Dot One conglomerate, acting as a key facilitator of Iranian sanctions evasion activity including oil exports and digital asset transfers that OFAC alleges ultimately benefited the Islamic Revolutionary Guard Corps (IRGC). He is subject to secondary sanctions, meaning any foreign individual or entity that engages in transactions with him may itself be designated.
avoid.net/nomic-chain→12/100[CRITICAL]Nomic Chain is a layer-1 blockchain built on a custom Rust-based stack that provides a decentralized, non-custodial Bitcoin bridge to the Cosmos ecosystem, issuing nBTC as an IBC-compatible 1:1 Bitcoin-backed token. In September 2026, a double-spend vulnerability in Nomic's custom IBC forwarding mechanism was publicly disclosed after going undetected for 74 days. The exploit allowed an attacker to mint approximately 40.65 unbacked nBTC, leaving roughly 36% of Osmosis's alloyed BTC (allBTC) without legitimate Bitcoin reserves, causing an estimated $3.15 million in losses and prompting Osmosis to freeze allBTC operations and pursue governance-driven recovery.
avoid.net/layerzero-labs→32/100[WARNING]LayerZero Labs is the Vancouver-based company that develops and maintains the LayerZero cross-chain messaging protocol and the ZRO governance token. The company became the subject of significant controversy following the April 2026 $292 million KelpDAO bridge exploit, in which LayerZero's own infrastructure was compromised and its personnel had previously approved the single-verifier configuration that enabled the attack. LayerZero Labs formally admitted in May 2026 that it 'made a mistake,' after weeks of publicly attributing blame to KelpDAO — a reversal that triggered a broader ecosystem migration estimated at approximately $15 billion in assets moving to competing bridge infrastructure.
avoid.net/layerzero-executor-wallet-incident-july-2026→62/100[CAUTIONARY]On July 15, 2026, security firm PeckShield and on-chain analyst Specter reported that LayerZero executor wallets appeared to have been drained of approximately $2.4 million across eight blockchain networks. LayerZero Core responded the same day, stating the transfers were routine internal inventory rebalancing and that no exploit had occurred and no user funds were at risk. The incident was not independently confirmed as a security breach, and as of the date of this investigation LayerZero's denial has not been publicly contradicted by on-chain forensic analysis or a third-party post-mortem.
avoid.net/osmosis-allbtc-nomic-bridge-double-spend-exploit-september-2026→38/100[WARNING]On September 9, 2026, the Cosmos-based DEX Osmosis froze minting, redemption, deposits, and withdrawals for its alloyed Bitcoin token (allBTC) after discovering that a double-spend flaw in the Nomic chain's custom BTC-forwarding mechanism had allowed an attacker to mint 40.650602 nBTC on Osmosis with no corresponding Bitcoin backing, compromising approximately 36% of allBTC's reserves. On-chain researcher Rarma traced the principal exploit activity to June 25, 2026, meaning the vulnerability went undetected for roughly 74 days before public disclosure. An emergency chain upgrade locked 22.65 BTC in the attacker-controlled address; a governance proposal to seize those funds and draw on the Osmosis community pool to cover the remaining ~17.19 BTC shortfall was launched on September 10, 2026, but had not been voted on as of the date of this report.
avoid.net/layerzero-dvn-single-verifier-configuration-risk→32/100[WARNING]LayerZero is a cross-chain messaging protocol whose permissive Decentralized Verifier Network (DVN) architecture allowed integrating protocols to deploy bridges secured by a single verifier. In April 2026, this design pattern was exploited by the DPRK-affiliated Lazarus Group (TraderTraitor unit), which compromised LayerZero Labs' own DVN infrastructure to forge cross-chain messages and drain approximately $292 million from KelpDAO's rsETH bridge — the largest DeFi exploit of 2026. LayerZero has since publicly admitted a mistake in allowing its DVN to operate as a 1-of-1 verifier for high-value transactions and has announced policy changes, but the incident triggered a $15 billion migration of secured value away from LayerZero to competing infrastructure. A separate August 2026 exploit of The Sandbox's LayerZero-powered bridge deepened concerns about systemic risk across LayerZero integrations.
avoid.net/the-sandbox-sand-oft-exploit→34/100[WARNING]On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.
avoid.net/dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign→0/100[CRITICAL]In April 2026, North Korea-linked threat actors attributed to the Lazarus Group and its subunits executed two separate, high-value cryptocurrency exploits within 18 days — draining approximately $285 million from Drift Protocol on April 1 and approximately $292 million from KelpDAO on April 18. Combined, the two attacks account for an estimated $577–635 million in losses, comprising 76% of all documented cryptocurrency hack value through April 2026 and representing the largest coordinated DPRK crypto theft campaign on record.
avoid.net/h1-2026-crypto-hack-landscape-ai-agent-attack-vector-emerges→0/100[CRITICAL]The first half of 2026 established a new all-time record for cryptocurrency exploit frequency, with 207–212 verified incidents (varying by methodology) resulting in $972 million to $1.32 billion in losses depending on the reporting firm. North Korea's Lazarus Group (TraderTraitor subunit) was responsible for approximately 55–66% of total losses through two concentrated attacks in April 2026, while AI-powered autonomous agents emerged as a distinct and novel attack surface for the first time in widely documented crypto security history.
avoid.net/kelpdao-layerzero-bridge-exploit-april-2026-dprk-lazarus→0/100[CRITICAL]On April 18, 2026, attackers preliminarily attributed to North Korea's Lazarus Group (TraderTraitor subunit) drained approximately $292 million in rsETH from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest single DeFi exploit of 2026 and accounting for a significant share of all H1 2026 crypto hack losses. The attack exploited a 1-of-1 Decentralized Verifier Node (DVN) configuration by compromising internal RPC nodes and DDoS-ing external nodes, forcing the bridge to accept a phantom burn message and release 116,500 rsETH to attacker-controlled addresses. A public dispute over responsibility followed, with LayerZero initially blaming KelpDAO's configuration before later partially acknowledging its own failure to police high-value transaction security; the exploit created an estimated $124–$230 million in bad debt on Aave and triggered a coordinated DeFi industry recovery effort called DeFi United.
avoid.net/june-2026-cross-chain-bridge-exploit-127m-three-protocols→10/100[CRITICAL]An alleged coordinated cross-chain bridge exploit on June 14, 2026 is described as draining $127 million from three DeFi protocols — identified only as BridgeLink, CrossFlow, and Relay Protocol — across Ethereum, Arbitrum, and Polygon in under 12 minutes. This specific incident, including the protocol names, the $127M figure, and the 03:42 UTC timestamp, cannot be independently verified through any Tier 1 or Tier 2 source as of June 30, 2026; the sole primary source is a blog post by Nadcab Labs, an Indian blockchain development services company with a commercial interest in publishing DeFi security content. While a severe pattern of verified cross-chain bridge exploits across 2026 provides real context, the specific claims in this investigation request should be treated as unverified until corroborated by credible on-chain analysis or major news coverage.
avoid.net/lazarus-group-mach-o-man-clickfix-macos-campaign→0/100[CRITICAL]In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.
avoid.net/the-sandbox-sand-layerzero-bridge-exploit-august-2026→12/100[CRITICAL]On August 21–22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base by hijacking LayerZero delegate permissions through the approveAndCall function, enabling unauthorized minting of approximately 329.24 trillion unbacked SAND tokens across 703 events over five hours. Actual financial extraction was substantially lower than headline figures: roughly 14.75 million SAND drained from the Ethereum OFT Adapter yielded approximately 80 ETH (~$675,000), while The Sandbox estimated the incident affected less than 0.01% of the 3-billion total SAND supply. The exploit was the third major LayerZero bridge incident in five months and contributed to accelerating an industry-wide migration from LayerZero to Chainlink CCIP, with publicly announced moves totaling approximately $15 billion.
avoid.net/lazarus-group-mach-o-man-macos-campaign-2026→0/100[CRITICAL]The Lazarus Group Mach-O Man campaign is a state-sponsored macOS malware operation publicly disclosed in April 2026, attributed to North Korea's Reconnaissance General Bureau via the Chollima operational unit. The campaign delivers a modular, Go-compiled malware kit through ClickFix social engineering — fake video-conference invitations distributed over Telegram — targeting cryptocurrency developers, fintech executives, and high-value enterprise users running Apple hardware. Researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform identified four distinct attack stages culminating in macOS Keychain theft, browser credential harvesting, and exfiltration via the Telegram Bot API.
avoid.net/dprk-crypto-theft-h1-2026-trm-labs-blockaid-report→0/100[CRITICAL]North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm. Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds. Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.
avoid.net/zksnarks-nft-zcash→22/100[CRITICAL]zkSNARKs is a 10,000-piece profile-picture NFT collection launched on the Zcash blockchain in September 2026. The project raised approximately $17 million through a blind auction of 8,000 units at a clearing price of 1.5 ZEC each. On September 19, 2026, on-chain investigator ZachXBT publicly accused the anonymous project team of extracting funds while delivering no governance infrastructure, community tools, or ecosystem integrations as promised, characterizing the launch as an eight-figure money grab comparable to prior Ordinals exit schemes.
avoid.net/splash-optim-finance-oada-cardano-stableswap-exploit→22/100[CRITICAL]On September 13, 2026, an attacker exploited a validator flaw in Splash Protocol's ADA/OADA StableSwap pool on Cardano, draining approximately 2,434,648 ADA and 1,988,222 OADA in two transactions. Splash subsequently patched the underlying vulnerability, but roughly 2.42 million ADA remains unrecovered and OADA holders are unable to redeem their positions as of mid-September 2026, with Optim Finance still auditing impacted addresses and no confirmed remediation path announced.
avoid.net/manic-android-banking-trojan→0/100[CRITICAL]Manic is an active Android malware family first identified by ThreatFabric and Kaspersky in 2026, combining banking-trojan credential theft, spyware, and remote device takeover. It targets 169 Android application package IDs including cryptocurrency wallets, exchanges, banks, authenticators, and government eID services, and employs a novel offline Wi-Fi mesh relay to exfiltrate stolen data through chains of nearby infected devices even without direct internet access. Primary targeting is concentrated on Ukraine, with secondary reach across Russia, Europe, and global fintech and cryptocurrency platforms.
avoid.net/abracadabra-money→28/100[WARNING]Abracadabra Money is a multi-chain DeFi lending protocol founded in 2021 that allows users to mint Magic Internet Money (MIM), a USD-pegged stablecoin, using interest-bearing tokens as collateral. The protocol has suffered four significant security incidents between 2022 and 2025, losing over $21 million in aggregate, and its MIM stablecoin has lost its dollar peg on multiple occasions. The protocol is also linked to the Wonderland/Sifu scandal of early 2022, which caused severe reputational and financial contagion across its interconnected 'Frog Nation' ecosystem.
avoid.net/miloud-abderrahmane-isis-crypto-facilitator→1/100[CRITICAL]Miloud Abderrahmane is a French national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, for allegedly conducting cryptocurrency transactions on behalf of ISIS-affiliated individuals in Syria and for allegedly providing instructional and manufacturing information on explosives to ISIS supporters. Two TRON blockchain addresses linked to him were added to the Specially Designated Nationals (SDN) list, and blockchain analytics firms have reported on-chain activity connecting the wallets to alleged ISIS-linked donation campaigns. He was designated as part of a broader OFAC action against three individuals and six entities accused of routing crypto and fiat funds to ISIS across Europe, the Middle East, and West Africa.
avoid.net/isis-k-crypto-wallet-network-tron-monero-sdn-designations→2/100[CRITICAL]On July 1, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) updated its Specially Designated Nationals (SDN) list entry for ISIS-Khorasan (ISIS-K) to add 134 cryptocurrency wallet addresses — 131 on TRON and 3 on Monero — used to solicit and move donations for the group's propaganda arm. Stablecoin issuer Tether froze the balances on all 131 TRON addresses within the sanctions window, while the three Monero addresses remain functionally beyond the reach of issuer-level freezing due to that network's privacy design. The action followed a June 22, 2026 OFAC designation of individuals and money-service businesses across Europe, the Middle East, and West Africa accused of facilitating ISIS financial transfers.
avoid.net/tartswap-tart-solana-mint-6mxygsp9qdjieqgcuhjbsru6vu1ymtyndwntsx6uwbtv→7/100[CRITICAL]A Solana SPL token trading under the name and ticker "TartSwap" (TART) at mint address 6MXygsP9QDJiEqGCuHjbsru6vU1YmtynDWnTsx6uWbTv shows on-chain hallmarks of a high-risk, illiquid meme-token launch: on-chain analytics show effectively zero real liquidity ($0–$0.03) despite a multi-million-dollar reported valuation and trading volume, alongside flagged insider wallet clusters. The name and branding duplicate an unrelated, separately-documented "TartSwap" project that describes itself as a BNB Chain-only decentralized exchange and explicitly warns that no TART contract address other than its own BNB Chain address should be trusted. No independent news coverage, audit, or regulatory record specific to this Solana token was found; findings below rely primarily on on-chain analytics tools and the rival project's own materials.
avoid.net/iran-irgc-crypto-exchange-network-ofac-sectoral-sanctions→2/100[CRITICAL]Between June and September 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated a network of Iranian and Iran-linked cryptocurrency exchanges — including Nobitex, Wallex, Bitpin, Ramzinex, Shelbit Exchange, Aban Tether, and BitBank — for allegedly laundering funds on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and helping the Iranian regime evade sanctions. On August 24, 2026, as part of a campaign named 'Operation Economic Outcast,' OFAC issued a first-of-its-kind sectoral determination under Executive Order 13902 naming digital assets a sanctionable sector of Iran's economy, extending secondary-sanctions risk to any foreign person or entity operating in or supporting that sector, not just entities with direct terrorism links. Treasury and blockchain-analytics research describe IRGC-associated wallets as having received billions of dollars in cryptocurrency in 2025 alone.
avoid.net/bitpapa-exchange→6/100[CRITICAL]Bitpapa (legally Bitpapa IC FZC LLC, also doing business as Baba House LLC and Papa Holding Ltd) is a UAE-registered peer-to-peer cryptocurrency exchange serving primarily Russian, Ukrainian, Belarusian, and other CIS-region users. It has been designated under sanctions programs in four separate jurisdictions — the United States (OFAC, March 2024), Ukraine (July 2025), the United Kingdom (May 2026), and the European Union (2026, effective August 2026) — each alleging that Bitpapa facilitated Russian sanctions evasion, including transactions with darknet markets and sanctioned banks and exchanges. The platform also independently lists the rouble-pegged A7A5 stablecoin, which researchers have linked to a sanctions-evasion network tied to a sanctioned political figure and a state-owned Russian bank.
avoid.net/oramama-token-oramama→3/100[CRITICAL]$ORAMAMA is a Solana-based meme token that served as the vehicle for a coordinated pump-and-dump scheme identified by on-chain investigator ZachXBT. On February 22, 2026, ten accounts within a larger 16-account network on X simultaneously promoted the token after building audiences through AI-assisted fabrication of US-Iran war panic content, then abandoned all mention of it once operators had exited their positions for six-figure profits. X suspended all 16 identified accounts following ZachXBT's public disclosure on March 23, 2026.
avoid.net/a7a5-russian-ruble-stablecoin→3/100[CRITICAL]A7A5 is a ruble-pegged stablecoin launched in January 2025 by Kyrgyzstan-registered issuer Old Vector on behalf of A7 LLC, a cross-border payments firm co-owned by sanctioned Moldovan fugitive Ilan Shor and Russian state-owned defense-sector bank Promsvyazbank (PSB). US, UK and EU authorities have sanctioned A7A5, its issuer, and its principal trading venues (Grinex, formerly Garantex), alleging the token was designed to help Russian individuals, businesses and the state evade Western financial restrictions and, per UK officials, to help fund Russia's war effort. The scout's claim that A7A5 launched in "February 2026" is not supported by any source found and appears to be incorrect; multiple Tier 1/Tier 2 sources place the launch in January 2025.
avoid.net/coldcard-wallet-coinkite-firmware-exploit→28/100[WARNING]Coldcard is a Bitcoin hardware wallet manufactured by Canadian company Coinkite. Beginning July 30, 2026, attackers exploited a five-year-old firmware bug that caused seed generation to use a weak software pseudorandom number generator instead of the device hardware entropy source, reducing effective key strength to as low as 40 bits on older models. Galaxy Research estimated total losses of approximately 1,816 to 2,417 BTC (roughly $116–$151 million USD) across more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026. Coinkite published a security advisory and patched firmware but has not announced any compensation program for affected users.
avoid.net/haruko→42/100[WARNING]Haruko is a London-based institutional digital asset infrastructure provider founded in 2021, serving over 80 clients globally across 100+ centralized venues, 30 blockchains, and 250 on-chain protocols. In September 2026, the company confirmed a targeted cyberattack affecting 15 institutional clients, in which attackers exploited a server-side process vulnerability to extract access tokens and gain read-only API access to client data; a small but confirmed amount of client funds was stolen. Haruko stated it patched the vulnerability, rotated server-side secrets, and committed to publishing a technical post-mortem.
avoid.net/revolut-data-breach-fake-government-request-september-2026→30/100[WARNING]On September 12, 2026, Revolut confirmed that an unauthorized third party had obtained sensitive data belonging to approximately 680 customers by submitting fraudulent information requests from a compromised email account operating inside Italy's Ministry of the Interior domain (pec.interno.it), which passed SPF, DKIM, and DMARC authentication checks. The exposed data reportedly included passport copies, identity verification selfies, IBANs, account statements, and full Bitcoin transaction histories. Revolut stated that its own systems and customer funds were not compromised, characterizing the incident as a social engineering attack against its data-request verification procedures rather than an intrusion.
avoid.net/htx-fca-uk-enforcement-illegal-crypto-promotions-2026→10/100[CRITICAL]The UK Financial Conduct Authority commenced High Court proceedings on 21 October 2025 against Huobi Global S.A. (the Panamanian entity behind the HTX exchange, formerly Huobi) and multiple categories of 'persons unknown', alleging repeated breach of Section 21 of the Financial Services and Markets Act 2000 by promoting cryptoasset services to UK consumers without authorisation. This is the FCA's first enforcement action against an offshore crypto exchange for illegal financial promotions. As of August 2026, proceedings are stayed while settlement talks continue; no court ruling on the merits has been issued.
avoid.net/huobi-htx→7/100[CRITICAL]HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.
avoid.net/solana-summit-toronto→82/100[VERIFIED]Solana Summit Canada is a two-day blockchain conference scheduled for September 23–24, 2026 at St. Lawrence Market North in Toronto, Ontario. The event is organized by Superteam Canada, a Solana Foundation-supported regional community chapter, and is listed as an official event on solana.com/events. No fraud indicators, fake ticket schemes, or scam activity have been identified in connection with this event.
avoid.net/hemi-genesis-drop-merklebox-exploit→38/100[WARNING]Hemi is a modular Layer-2 blockchain protocol designed to bridge Bitcoin and Ethereum into a single supernetwork, co-founded by former Bitcoin core developer Jeff Garzik and Max Sanchez. On September 7, 2026, an attacker exploited a reentrancy vulnerability in the MerkleBox smart contract used for Hemi's Genesis Drop token distribution, draining approximately 124.5 million unclaimed HEMI tokens, which were liquidated for roughly $255,000 in stablecoins. The exploit was isolated to the Genesis Drop claim contract; the core Hemi network, HEMI and veHEMI tokens, and bridge infrastructure were not affected.
avoid.net/bitbank-iranian-crypto-exchange→2/100[CRITICAL]BitBank, also known as BitBank3 and operating at bitbank3.com, is an Iranian digital asset exchange designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on September 17, 2026. According to OFAC, the exchange is a priority digital asset venture controlled by sanctioned Iranian financier Babak Zanjani, and was used between June and July 2026 to transfer hundreds of millions of dollars in Bitcoin to the Islamic Revolutionary Guard Corps (IRGC). The designation is part of Operation Economic Outcast, a broader U.S. government campaign to sever financial channels used by the Iranian regime.
avoid.net/claude-ai-crypto-arbitrage-bot-youtube-tutorial-scam→0/100[CRITICAL]A coordinated scam operation, active between at least February and August 2026, distributed nine near-identical YouTube tutorials purporting to teach viewers how to deploy a "Claude-built" AI crypto arbitrage bot. According to TRM Labs, the deployed smart contracts contained no trading logic whatsoever and simply forwarded any funds sent to them to operator-controlled addresses; 224 victims lost 274.60 ETH (approximately $517,205 USD) across six shared collection addresses. SentinelOne independently documented the same pattern of Ethereum drainers masquerading as AI trading bots on YouTube, tracing an overlapping campaign that collected over $900,000 USD from a single operator address.
avoid.net/ai-dating-scam-network-dora-doni-romi-cluster→0/100[CRITICAL]A China-based app studio, tracked by Anthropic as GTG-15001, operated a network of more than 20 fraudulent dating applications that allegedly used Anthropic's Claude AI to power thousands of undisclosed fake personas. During a two-week period in April 2026, the operation engaged at least 25,000 users — primarily men in the United States — through approximately 4,700 AI-generated profiles that sent roughly 2.36 million messages while users paid real money via in-app coin purchases to continue conversations. Anthropic published findings in September 2026, banned associated accounts, and reported the operator to Apple and Google; most named apps were removed by early September 2026, though Kira reportedly remained on Google Play as of September 16, 2026.
avoid.net/input-output-group-iog-youtube-channel-hijack-deepfake-hoskinson-giveaway-scam→5/100[CRITICAL]On September 18, 2026, unknown attackers hijacked the official YouTube channel of Input Output Group (IOG), the core development company behind the Cardano blockchain, and broadcast an approximately two-hour fraudulent livestream. The broadcast used suspected AI-generated video of IOG founder Charles Hoskinson to impersonate a Project Catalyst town hall and solicit cryptocurrency from viewers via QR code, promising to double any ADA sent. IOG and Hoskinson publicly warned users not to engage with channel content, and IOG confirmed it was working with YouTube to recover the account. This incident was not an attack on the Cardano blockchain or user wallets; it was a social-media account compromise targeting IOG's YouTube presence.
avoid.net/7zarc→4/100[CRITICAL]7zarc is a pseudonymous individual whose wallet cluster was publicly identified by on-chain investigator ZachXBT in September 2026 as allegedly having received 4,870 ETH (approximately $15 million) traceable to the Raidparty project's alleged $70 million exit scam. The wallets went dormant in 2022 and reactivated in September 2026, with the ETH subsequently moved to deposit addresses across multiple centralized exchanges. No charges have been filed and no court or regulatory finding has been made; the allegations originate from ZachXBT's on-chain analysis published on X.
avoid.net/raidparty→4/100[CRITICAL]Raidparty was an Ethereum-based play-to-earn idle MMO game launched in approximately 2021, featuring NFT heroes and fighters and a native token called Confetti (CFTI). On-chain investigator ZachXBT alleged in September 2026 that approximately $70 million was misappropriated in an exit scam, and identified a dormant wallet cluster linked to the pseudonym 7zarc moving 4,870 ETH (approximately $15 million) of alleged exit-scam proceeds to centralized exchange deposit addresses after roughly four years of inactivity. No arrests, regulatory actions, or court filings have been publicly identified as of the investigation date; the allegations originate from ZachXBT's on-chain analysis and have not been adjudicated.
avoid.net/ismael-sanchez-cryptofx→3/100[CRITICAL]Ismael Sanchez (also identified in SEC filings as Ismael Zarco Sanchez) was a lead salesperson who ran the Chicago office of CryptoFX LLC, a Houston-based operation that the SEC alleges was in reality a $300 million Ponzi scheme defrauding roughly 40,000 predominantly Latino investors between 2020 and 2022. On February 12, 2026, a federal jury in the Southern District of Texas found Sanchez liable for securities fraud and broker/securities-registration violations. The underlying CryptoFX scheme, run principally by Mauricio Chavez and Giorgio Benvenuto, was halted by an SEC emergency action in September 2022, and Sanchez was among 17 additional individuals charged by the SEC in March 2024.
avoid.net/cryptofx-llc→2/100[CRITICAL]CryptoFX LLC was a Houston, Texas-based company that the SEC has alleged operated a $300 million Ponzi scheme from approximately May 2020 to October 2022, targeting over 40,000 predominantly Latino investors across ten U.S. states and two foreign countries. The scheme purported to generate returns of 15 to 100 percent through cryptocurrency and foreign exchange trading but instead used investor funds to make Ponzi payments, pay commissions, and finance the personal expenses of its principals and network leaders. The SEC halted operations via emergency action in September 2022; a court-appointed receiver is administering recovery proceedings, and enforcement actions against 19 individuals and the company itself have resulted in judgments and ongoing litigation as of 2026.
avoid.net/symbiosis-finance-bridgev2-sybtc-exploit-september-2026→30/100[WARNING]On September 11, 2026, an attacker exploited two chained vulnerabilities in Symbiosis Finance's BridgeV2 smart contract, depositing 330 satoshis (~$0.25) and minting approximately 46.1 billion unbacked synthetic Bitcoin (syBTC) tokens — over 2,000 times Bitcoin's entire circulating supply. The attacker liquidated roughly 4.39 WBTC (~$336,000) on Uniswap before the incident was contained; Symbiosis recovered approximately 15 BTC (~$1.15 million) and suspended its native Bitcoin bridge pending a full security rewrite. This event is distinct from the broader Symbiosis Finance protocol, which has processed over $10 billion in cross-chain volume since 2022 and whose non-Bitcoin routing remained operational throughout.
avoid.net/operation-token-mirrors-doj-crypto-market-manipulation-ring→2/100[CRITICAL]Operation Token Mirrors is a multi-phase FBI and IRS Criminal Investigation undercover operation in which federal agents created fictitious cryptocurrency tokens — most notably the Ethereum-based 'NexFundAI' — to infiltrate and document alleged wash trading and pump-and-dump schemes offered as fee-based 'market making' services. The operation produced two coordinated enforcement waves: an initial October 2024 action by the U.S. Attorney for the District of Massachusetts charging 18 individuals and entities tied to Gotbit, CLS Global, ZM Quant, and MyTrade; and a subsequent 2025–2026 action by the U.S. Attorney for the Northern District of California charging 10 additional foreign nationals connected to Gotbit, Vortex, Antier Solutions, and Contrarian. As of mid-2026, Gotbit founder Aleksei Andriunin has been sentenced to eight months in prison, Gotbit has been ordered to cease operations and forfeit approximately $23 million, at least three other individuals have pleaded guilty or been sentenced, and three Singapore-based executives have been extradited to the United States to face trial.
avoid.net/symbiosis-finance→38/100[WARNING]Symbiosis Finance is a cross-chain DEX and bridge protocol launched in March 2022, enabling token swaps across 50+ EVM and non-EVM networks via synthetic assets and a permissioned relayer network. On September 11, 2026, an attacker exploited a message-validation flaw in its BridgeV2 contract, minting approximately 46.1 billion unbacked syBTC tokens on BNB Chain and extracting around $336,000 in real funds; total protocol losses were estimated at 9.97 BTC (~$770,000). The Bitcoin Bridge remains offline as of mid-September 2026, and a structural relayer-collusion risk — whereby two-thirds of MPC nodes acting together could drain user funds — persists independently of the exploit patch.
avoid.net/dcent-wallet→28/100[WARNING]DCENT Wallet is a hardware and software cryptocurrency wallet product developed by South Korean cybersecurity firm IoTrust Co., Ltd., founded in 2017 and headquartered in Seoul. On September 16, 2026, IoTrust publicly disclosed that it detected abnormal asset transfers on its DCENT App Wallet and launched an emergency investigation, urging all App Wallet users and any hardware wallet users who shared a mnemonic phrase with the App Wallet to move funds immediately. As of the date of this investigation, no root cause, loss total, or number of affected users has been disclosed, and the incident remains active.
avoid.net/chainflip→42/100[WARNING]Chainflip is a decentralized cross-chain swap protocol that uses a validator network, threshold signature schemes, and a Substrate-based State Chain to facilitate native asset swaps across blockchains without wrapped tokens or bridges. On September 12, 2026, an attacker exploited a flaw in Chainflip's TRON USDT memo-handling logic, triggering duplicate payouts across six transactions totaling 736,442.17 USDT over approximately 90 minutes. Chainflip halted the entire network, patched the vulnerability, and committed to making affected liquidity providers whole, though the specific reimbursement mechanism and a complete technical post-mortem remained pending as of the time of reporting.
avoid.net/prince-group-transnational-criminal-organization→0/100[CRITICAL]The Prince Group Transnational Criminal Organization (TCO) is a Cambodia-based criminal enterprise designated by the U.S. Treasury's OFAC under Executive Order 13581. U.S. and UK authorities allege the network operates industrial-scale cyber-enabled fraud (including cryptocurrency investment scams commonly called pig-butchering), human trafficking into forced-labor scam compounds, and global money laundering. As of June 2026, OFAC has cumulatively designated 146 individuals and entities within the network. The group's identified leader, Chen Zhi, was stripped of Cambodian citizenship and sent to China in January 2026; he faces a U.S. federal indictment. Hu Xiaowei has been publicly named by OFAC as the TCO's second-in-command.
avoid.net/tac-network→28/100[WARNING]TAC Network (TON Application Chain) is a Cosmos-based EVM Layer 1 blockchain designed to bridge Ethereum-compatible decentralized applications to the TON and Telegram ecosystem. On August 22, 2026, the network suffered a critical exploit via a shared Cosmos EVM vesting-account vulnerability, resulting in the drainage of approximately 2.99 billion TAC tokens (28.6% of total supply) from the bonded staking pool. The TAC Foundation responded by halting the chain and subsequently migrating the entire BEP20 TAC token supply on BNB Chain to a new contract that deliberately excluded attacker-linked addresses — a supply rewrite that raised token integrity questions for existing holders.
avoid.net/ascendex-exchange→4/100[CRITICAL]AscendEX (formerly BitMax) was a centralized cryptocurrency exchange founded in 2018 and headquartered in Singapore. On July 1, 2026, the exchange permanently ceased all operations, citing failure to obtain EU MiCA authorization and the collapse of an undisclosed strategic liquidity transaction. As of July 6, 2026, all automated withdrawals were suspended and moved to manual review, with the exchange explicitly stating it cannot guarantee the timing or amounts of user fund returns.
avoid.net/zachxbt-crypto-influencer-paid-promotion-leak-200-influencers-september-2025→12/100[CRITICAL]In early September 2025, on-chain investigator ZachXBT published a leaked rate sheet listing more than 200 crypto influencer accounts offered paid promotional deals, with Solana wallet addresses attached to each entry and per-post pricing ranging from $50 to $60,000. Of roughly 160 accounts that accepted payment, fewer than five disclosed their posts as advertising, representing a compliance rate below 3% against FTC and ASA disclosure standards. The incident exposed a systemic pattern of undisclosed paid promotion across crypto social media and has been cited in connection with influencer-driven promotional chains that preceded token collapses.
avoid.net/aquifer-amm→28/100[WARNING]Aquifer is a proprietary automated market maker (AMM) on Solana focused on stablecoin swaps, which had accumulated approximately $2.8 million in total value locked prior to a security incident on August 31, 2026. Attacker-controlled wallets on both Solana and Ethereum drained approximately $2.5 million from the protocol in what Aquifer attributed to a wallet compromise rather than a smart contract vulnerability. A 20% white-hat bounty offer with a September 3, 2026 deadline passed without any publicly confirmed return of funds, and no technical post-mortem has been released.
avoid.net/bitmex-exchange→28/100[WARNING]BitMEX (Bitcoin Mercantile Exchange), operated by HDR Global Trading Limited, is a Seychelles-registered cryptocurrency derivatives exchange that permanently shut down on September 23, 2026, ending an 11-year run. The exchange accumulated more than $200 million in total regulatory penalties across CFTC, FinCEN, and DOJ proceedings for willful failures to maintain adequate anti-money laundering and know-your-customer programs; its three co-founders and a senior employee each pleaded guilty to Bank Secrecy Act violations, though all four subsequently received presidential pardons in March 2025. Closure followed a two-year failed sale process, and the disposition of the exchange's approximately $270 million insurance fund remained publicly unresolved at the time of shutdown.
avoid.net/0x5a76a2830859c321a50937a22fde571fbf4810f3→38/100[WARNING]This Ethereum address is the official ERC-20 token contract for Binibit (BINI), an upgradeable ERC1967 proxy deployed around August 5, 2026, by an externally owned account funded through OKX. Binibit is a self-described blockchain ecosystem incorporating a centralized exchange, a decentralized exchange (BaiDEX), a Layer 1 network (BiniChain), and a token launchpad, incorporated as Binibit S.A. in Panama. No regulatory actions, OFAC sanctions, or verified fraud findings were identified as of September 2026; however, the project presents several elevated risk factors including anonymous individual leadership, no publicly available security audit, a proxy contract architecture that permits future contract upgrades, and a small number of Trustpilot complaints alleging locked accounts and blocked withdrawals.
avoid.net/faruk-fatih-ozer→0/100[CRITICAL]Faruk Fatih Ozer is the Turkish founder and CEO of Thodex, a cryptocurrency exchange that collapsed in April 2021 after he fled to Albania, leaving approximately 391,000 users unable to access an estimated $2 billion in funds. He was arrested in Albania in August 2022, extradited to Turkey in April 2023, and sentenced on September 7, 2023 to 11,196 years, 10 months, and 15 days in prison on charges of aggravated fraud, founding a criminal organization, and money laundering. He was found dead in Tekirdag F-Type High Security Prison on November 1, 2025, with Turkish authorities indicating initial findings pointed to suicide.
avoid.net/nesa-nes→28/100[WARNING]Nesa is a Cosmos-based Layer-1 blockchain marketed as infrastructure for verifiable, privacy-preserving AI, with its NES token launched via Binance Alpha in mid-2026. On August 24, 2026, an attacker exploited an integer-underflow vulnerability in the shared Cosmos EVM module to inflate a NES balance roughly 200x and bridge approximately $50 million worth of tokens (25.8% of stated supply) out via Hyperlane to Ethereum, crashing the NES price as much as 90% before a partial recovery; extreme slippage limited the attacker's realized profit to roughly $60,000. The same vendor-level bug hit MANTRA, TAC, and KiiChain in the same window, and Cosmos Labs has since admitted it wrongly cleared the underlying flaw months earlier; Nesa's own post-incident transparency has drawn separate criticism for withholding technical detail that peer chains disclosed.
avoid.net/cosmos-evm-vulnerability-august-2026-six-chain-exploit→18/100[CRITICAL]A critical integer underflow vulnerability (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was reported via bug bounty on April 25, 2026, but was incorrectly assessed by Cosmos Labs as posing no risk to live production networks. Between August 20 and August 25, 2026, attackers exploited the flaw across six Cosmos EVM-based blockchains, draining approximately $5.72 million in total. Cosmos Labs confirmed in its August 28 post-mortem that its initial clearance of the bug was in error, and that its patch-release process failed to provide downstream chains adequate notice to upgrade before exploitation began.
avoid.net/mirror→5/100[CRITICAL]Mirror Protocol was a Terra-based DeFi platform enabling synthetic assets (mAssets) that tracked prices of US stocks. The protocol suffered a $90 million exploit in October 2021 that went undetected for seven months, a governance attack campaign in December 2021 targeting $40 million in community funds, and a second $2 million oracle exploit in May 2022. It became permanently inactive in August 2022 following the catastrophic collapse of the Terra/LUNA/UST ecosystem, which was orchestrated by its parent company Terraform Labs under Do Kwon, who was subsequently convicted of fraud and sentenced to 15 years in prison.
avoid.net/trenton-johnston-crypto-social-engineering-theft-ring→2/100[CRITICAL]Trenton Richard David Johnston, a 20-year-old Canadian national, pleaded guilty on June 10, 2026 in U.S. District Court (Southern District of Florida) to conspiracy to commit money laundering in connection with a social engineering scheme that caused losses exceeding $13 million in cryptocurrency. Johnston operated as part of a broader theft ring — connected to 'The Com' hacker network — alongside co-conspirators including Miami resident Brandon Michael Tardibone and an uncharged individual identified by blockchain investigator ZachXBT as Dritan Kapllani Jr., who is alleged to be linked to approximately $19 million in total social engineering thefts. The scheme involved impersonating support representatives from Google, Trezor, and other crypto companies to trick victims into surrendering access to their digital wallets.
avoid.net/trenton-richard-johnston→2/100[CRITICAL]Trenton Richard David Johnston is a Canadian national who pleaded guilty on June 10, 2026 in U.S. District Court in Miami to conspiracy to commit wire fraud and conspiracy to commit money laundering in connection with a social-engineering cryptocurrency theft scheme that caused at least $13.04 million in victim losses. Johnston, who was 19 at the time of his March 2026 arrest and had overstayed a U.S. tourist visa, is identified as Co-Conspirator 2 in federal filings that name Dritan Kapllani Jr. as Co-Conspirator 1 in the same 185 BTC theft. He awaits sentencing and has agreed to deportation to Canada.
avoid.net/yelo-yelotree→0/100[CRITICAL]Yelo, known online as @yelotree, is a crypto key opinion leader (KOL) and former professional Fortnite esports player with approximately 180,000 Twitter followers who also operated a luxury car rental business in Miami. As of May 2026, Yelo faces federal criminal charges alleging he laundered funds stolen from cryptocurrency holders through that rental business, with a potential sentence of up to 30 years. Separately, Yelo participated in undisclosed paid promotion of the Sharpei memecoin on Solana in October 2024, which subsequently suffered a documented rug pull that erased 96% of its market value.
avoid.net/brandon-michael-tardibone→4/100[CRITICAL]Brandon Michael Tardibone, 28, of Miami, Florida, was federally indicted on May 11, 2026 in the Southern District of Florida (case 1:26-cr-20181) on charges of conspiracy to commit money laundering and harboring an alien unlawfully present in the United States. Prosecutors allege he provided housing and material support to Canadian co-defendant Trenton Richard David Johnston — who allegedly orchestrated a $13 million cryptocurrency fraud scheme via social-engineering impersonation attacks — while Johnston was unlawfully overstaying his visa, and that both defendants jointly laundered more than $1 million of stolen proceeds through luxury goods and South Florida nightlife. All charges are allegations; both defendants are presumed innocent unless and until proven guilty at trial.
avoid.net/coinex-exchange-closure-september-2026→42/100[WARNING]On September 15, 2026, CoinEx founder Yang Haipo announced the permanent wind-down of the CoinEx centralized exchange after nine years of operation, citing prolonged market downturns, declining trading volumes, and rising regulatory compliance costs. The exchange has published a phased closure schedule ending December 22, 2026, after which unclaimed balances will move to private custody subject to a 5% monthly fee. This incident page covers the shutdown event and its user-impact risks; a separate corpus entry covers CoinEx's broader operational history.
avoid.net/tbtfw-beverly-hills-luxury-car-dealer-crypto-laundering-vector→28/100[WARNING]TBTFW is an exotic car dealership at 9737 Wilshire Boulevard in Beverly Hills, California, operated by Zach Ersoff through Spur Ridge Holdings LLC. In September 2026, on-chain investigator ZachXBT alleged that stolen cryptocurrency from the Malone Lam $245 million RICO case was routed via Monero to TBTFW for vehicle purchases, with Austin Fine (@xmrfine) named as an alleged intermediary. As of September 16, 2026, no criminal charges have been filed against TBTFW, Zach Ersoff, or Spur Ridge Holdings in connection with the laundering allegations.
avoid.net/austin-fine-xmrfine→18/100[CRITICAL]Austin Fine, known online as @xmrfine, is a crypto-adjacent individual who on September 9, 2026 was publicly accused by on-chain investigator ZachXBT of allegedly facilitating money laundering on behalf of Malone Lam, the ringleader of a $245 million cryptocurrency theft ring who pleaded guilty to RICO conspiracy on September 8, 2026. ZachXBT alleged that Fine converted stolen crypto assets into luxury goods — including vehicles purchased through Beverly Hills dealership TBTFW — using Monero as an intermediary, and charged fees for doing so. As of September 16, 2026, no criminal charges have been filed against Austin Fine, and no public response from Fine has been documented.
avoid.net/swiss-bitcoin-pay→42/100[WARNING]Swiss Bitcoin Pay is a non-custodial Bitcoin payment processor incorporated as Swiss Bitcoin Pay Sàrl in Neuchâtel, Switzerland, serving over 1,000 merchants in 21 countries since late 2022. On September 14, 2026, the company took its servers offline after detecting suspected unauthorized access to its internal systems. No customer funds or private keys were reported as compromised, but five categories of sensitive personal and financial data were confirmed as potentially exposed, creating material phishing and social-engineering risk for affected merchants and customers.
avoid.net/orange-finance→28/100[WARNING]Orange Finance is an Arbitrum-based automated liquidity management protocol designed for LPDfi (liquidity provider DeFi), enabling users to earn swap fees and options premiums via concentrated AMM vaults. On January 8, 2025, the protocol suffered a critical security breach in which an attacker compromised the admin private key, exploited a misconfigured multi-signature wallet that required only a single signature to execute, and drained approximately $843,556 across all active vaults. The protocol was flagged by ZachXBT and has not resumed normal operations since the incident.
avoid.net/shibarium→28/100[WARNING]Shibarium is a layer-2 blockchain built on Ethereum, launched in August 2023 as the scaling solution for the Shiba Inu (SHIB) ecosystem. The network has faced a series of significant incidents including a failed initial launch that trapped $1.7 million in bridged funds, a September 2025 flash loan exploit that drained approximately $4.1 million from its cross-chain bridge via validator key compromise, persistent rug pull activity on its DeFi layer, allegations of code plagiarism, and ongoing transparency concerns stemming from fully pseudonymous leadership. Shibarium initiated a novel NFT-based restitution program following the 2025 exploit but as of early 2026 the recovery path remained unresolved.
avoid.net/aethir→36/100[WARNING]Aethir is a Singapore-based decentralized GPU cloud computing protocol operating as a Decentralized Physical Infrastructure Network (DePIN), founded in 2021 by Mark Rydon and Daniel Wang. The project raised approximately $109M across funding rounds and a $100M+ checker node sale, launched its ATH token in June 2024, and claims $147M+ ARR from enterprise AI and gaming clients. Risk factors include a 95% token price decline from its all-time high, a redirected Season 3 community airdrop, a cross-chain bridge exploit in April 2026 resulting in up to $400K in losses, heavy insider token allocation, and a ZachXBT flag whose specific basis has not been publicly detailed.
avoid.net/bankr→18/100[CRITICAL]Bankr is an AI-powered crypto wallet and trading bot built on the Base network (Ethereum L2), allowing users to trade, swap, and manage funds through natural-language commands on X (Twitter) and Farcaster. In May 2026, the platform suffered two separate security incidents within weeks of each other: a prompt-injection attack exploiting Grok that drained approximately $150,000–$175,000 in DRB tokens, and a distinct key-compromise or session-token breach that affected 14 user wallets and drained an estimated $170,000–$385,000 in total. Bankr publicly committed to reimbursing all affected users, but no confirmed completion of that reimbursement has been documented in available sources as of the investigation date.
avoid.net/su-zhu→3/100[CRITICAL]Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.
avoid.net/satish-kumbhani→0/100[CRITICAL]Satish Kumbhani is the founder of BitConnect, a cryptocurrency platform that the U.S. Department of Justice, SEC, and multiple state regulators have determined operated as a global Ponzi scheme defrauding investors of approximately $2.4 billion between 2016 and 2018. Kumbhani was indicted by a federal grand jury in San Diego on February 25, 2022, on charges carrying a maximum penalty of 70 years in prison, and has remained a fugitive from justice since disappearing from India following his U.S. indictment.
avoid.net/donald-g-basile-bitcoin-latinum-ltnm→2/100[CRITICAL]Donald G. Basile is the founder of Bitcoin Latinum (LTNM) and CEO of Monsoon Blockchain Corporation. On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and two entities he controlled — GIBF GP, Inc. and Monsoon Blockchain Corporation — alleging he raised approximately $16 million from hundreds of investors through materially false statements about nonexistent insurance coverage and asset backing. The SEC alleges more than 80% of investor funds were diverted to personal use, including real estate purchases and a $160,000 horse. The case is a civil action; no criminal charges have been reported as of the investigation date.
avoid.net/xinbi-guarantee→0/100[CRITICAL]Xinbi Guarantee is a Chinese-language illicit online marketplace that operated via Telegram, functioning as an escrow service connecting transnational criminal syndicates with vendors selling scam infrastructure, money laundering services, stolen data, and human trafficking recruitment. On September 9, 2026, the U.S. Treasury's OFAC designated Xinbi Guarantee as a significant transnational criminal organization under Executive Order 13581, and the DOJ's Scam Center Strike Force seized two cryptocurrency wallets and obtained restraining orders covering 47 additional wallets, together freezing approximately $52.8 million. Blockchain analytics firms place the platform's total transaction throughput at between $24 billion and $36 billion since approximately 2022.
avoid.net/mantra-chain-august-2026-exploit→38/100[WARNING]On August 20, 2026, MANTRA Chain — an RWA-focused Cosmos-based Layer 1 — suffered an exploit of a critical vulnerability in its upstream Cosmos EVM module, forcing a full network halt of approximately 30 hours and causing its OM token to drop 18% to a record low of $0.004126. Approximately 720.9 million OM tokens worth roughly $3.6 million were drained across the incident, part of a coordinated attack pattern that ultimately affected six Cosmos EVM chains and converted approximately $5.72 million in stolen assets across the ecosystem. This page covers the August 2026 security incident; the April 2025 token price collapse is documented separately under the 'mantra-chain' entry.
avoid.net/cosmos-labs→28/100[WARNING]Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.
avoid.net/mantra-chain-upstream-exploit-august-2026→32/100[WARNING]On August 20-21, 2026, MANTRA Chain halted all block production after an attacker exploited a critical vulnerability (ASA-2026-002) in the shared Cosmos EVM ICS20 precompile, a component developed by Cosmos Labs and used by multiple chains. MANTRA's OM token fell 18.5% to an all-time low of $0.004126 during the approximately 30-hour outage, and the chain resumed on August 22 after deploying patched version 8.4.0. MANTRA stated no user funds were exploited and that only two project-managed wallets were affected, but the team has not published a technical post-mortem nor disclosed what, if anything, was extracted from those wallets, leaving the full financial scope of the incident unresolved as of August 27, 2026.
avoid.net/mantra-chain→10/100[CRITICAL]MANTRA Chain, a Cosmos-EVM layer-1 blockchain focused on real-world asset tokenization, halted all block production on August 20, 2026 after an attacker exploited a known vulnerability in the shared Cosmos EVM ICS20 precompile module. The network was offline for approximately 30 hours, the native OM token fell 18% to an all-time low of $0.004126, and South Korean exchanges Upbit, Bithumb, and Coinone placed OM on delisting watchlists. This is MANTRA's second major crisis in 2026, following the April 2025 collapse of OM by more than 90%, and occurs in the context of a broader Cosmos EVM security incident that also affected KiiChain and TAC.
avoid.net/hefu-chai-huaisong-xiang→5/100[CRITICAL]Hefu Chai and Huaisong Xiang are former Robinhood Crypto engineers charged by the U.S. Department of Justice on September 15, 2026 with commodities fraud and wire fraud. Prosecutors allege they misappropriated confidential information from Robinhood's internal token-listing pipeline and used it to pre-position perpetual futures trades on the decentralized exchange Hyperliquid between 2025 and 2026, with each defendant allegedly profiting more than $50,000. The charges are allegations only; no conviction or guilty plea has been entered as of the date of this investigation.
avoid.net/blockstream→42/100[WARNING]Blockstream is a Bitcoin infrastructure company founded in 2014, led by cryptographer Adam Back, that develops the Liquid Network sidechain, Core Lightning, Blockstream Green wallet, Blockstream Jade hardware wallet, and Blockstream Satellite. The company achieved unicorn status with a $3.2 billion valuation in 2021 and has raised over $400 million in total financing. In September 2026, the Liquid Network suffered a critical ~$320 million exploit that drained approximately 4,000 BTC from its federation wallet, with ~598 BTC remaining unrecovered; the company also faces unresolved allegations regarding its Bitcoin Mining Note product and the undisclosed prior fraud conviction of its former mining division head.
avoid.net/soulja-boy-deandre-cortez-way→12/100[CRITICAL]Soulja Boy, born DeAndre Cortez Way, is an American rapper who became one of the most extensively documented celebrity crypto promoters linked to rug pulls and abandoned projects. Blockchain investigator ZachXBT documented 73 crypto promotions and 16 NFT collections between 2021 and 2023, estimating Way earned approximately $730,000 from paid endorsements, several of which subsequently rugged or were abandoned. The SEC charged Way in March 2023 for undisclosed paid promotion of TRX and BTT tokens; unlike six co-defendants who settled, Way did not initially respond to the charges, resulting in a default judgment. The SEC later filed to dismiss remaining claims against Way in 2026 as part of a broader resolution with the Justin Sun/Tron defendants. Way issued a public apology in December 2025, claiming ignorance of the fraudulent nature of the projects, though the timing coincided with renewed controversy after Base co-founder Jesse Pollak publicly disclosed a $1,500 investment in a new Soulja Boy-linked memecoin on the Base network.