Skip to main content
Sign in

Avoid your next
big mistake

Crowdsourced due diligence for crypto

Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis

Browse investigationsSubmit evidenceHow it works

Featured Investigations

200·
sort:
avoid.net/fluid-instadapp52/100[CAUTIONARY]

Fluid, formerly known as Instadapp, is a DeFi lending, borrowing, and trading protocol founded in 2018 by brothers Samyak and Sowmay Jain. The protocol rebranded from Instadapp to Fluid in December 2024 following the launch of its DEX product. As of mid-2026, Fluid operates with approximately $720 million in TVL across multiple chains and has been subject to two notable security incidents: a March 2026 bad-debt event stemming from a third-party hack of the Resolv protocol (~$19.3 million absorbed), and a May 2026 off-chain key compromise of its Merkle rewards distribution infrastructure that drained approximately 125,000 FLUID and 51,900 GHO.

avoid.net/probit-global23/100[CRITICAL]

ProBit Global was a South Korea-founded centralized cryptocurrency exchange that operated from 2018 until it permanently terminated all services by April 1, 2026. The shutdown followed an inability or unwillingness to obtain MiCA licensing for EU/EEA users and a stated broader regulatory and restructuring rationale for global operations. The wind-down included a controversial abandoned-funds clause under which assets not withdrawn by April 1, 2026 were deemed permanently lost, as well as a monthly administrative fee of up to 10% of balances during the grace period, raising significant consumer-protection concerns.

avoid.net/inertia-protocol42/100[WARNING]

Inertia Protocol (INRT) is a modular liquid restaking token (LRT) and lending protocol built on the Initia blockchain, launched to mainnet in April 2025. The protocol suffered a confirmed exploit in May 2025 in which approximately $152,000 was drained from five lending markets via a known ERC4626 share-price inflation attack; the protocol states its Insurance Fund restored affected user balances. Team composition, smart contract audit history, and investor backing are not publicly disclosed.

avoid.net/uniblock64/100[CAUTIONARY]

Uniblock is a Canadian Web3 infrastructure company founded in 2022 that provides a unified, multi-chain API aggregation platform for blockchain developers, connecting over 300 blockchains and 55 data providers through a single interface with patented auto-routing technology. The company is venture-backed with C$7.5 million in total funding from institutional investors including SBI Ven Capital, AllianceDAO, NGC Ventures, Alchemy, and MoonPay. No regulatory actions, fraud allegations, or significant security incidents have been identified; risk factors are principally commercial and operational rather than conduct-related.

avoid.net/superfortune-ai-gua28/100[WARNING]

Superfortune AI is an AI-powered InfoFi platform on BNB Chain, incubated by Manta Labs, that combines Chinese metaphysical traditions with crypto market analytics. Its native token GUA launched on November 27, 2025. On May 27, 2026, approximately 14.98 million GUA tokens intended for an airdrop distribution were redirected to a lookalike attacker-controlled address, resulting in losses of approximately $15.18 million and a roughly 76% token price crash within 24 hours. The root cause remains disputed: the team attributed the incident to a compromised signer private key, while the absence of prior on-chain interaction between the attacker and project wallets has raised unresolved questions about the multisig workflow.

avoid.net/dxsale4/100[CRITICAL]

DxSale is a decentralized token launchpad and liquidity-locking platform launched in August 2020, originally on Ethereum and later expanded to BNB Chain and other EVM networks. On May 28, 2026, a hidden backdoor in legacy BNB Chain liquidity locker contracts was exploited to drain approximately $7.3 million from more than 1,400 LP positions locked as far back as 2021. On-chain analysis identified a 269-day pre-exploit ownership transfer chain passing through approximately 80 wallets, with indicators strongly suggesting insider involvement by a current or former team member.

avoid.net/geoffrey-woo32/100[WARNING]

Geoffrey Woo is an American entrepreneur and venture capitalist who co-founded Anti Fund with Jake Paul in 2021 and serves as chairman of Ketone-IQ. In February 2026, Woo launched an AI-themed memecoin called AntiHunter (ANTIHUNTER) on the Base blockchain and publicly claimed it carried '0% rug pull risk' because he was already wealthy. On-chain investigator ZachXBT challenged the claim, citing the Paul brothers' documented history of five failed crypto projects — all down 99%+ from peak — and identifying three alleged token sales by Woo's wallet that appeared to contradict his stated promise to pre-announce any insider transactions. As of June 2026, ANTIHUNTER trades approximately 99%+ below its February 2026 all-time high, consistent with ZachXBT's expectations.

avoid.net/beaverd-beaverd4/100[CRITICAL]

@beaverd is an anonymous X (Twitter) account that won X's $1 million Creators Prize in February 2026 for an investigative article on Deloitte. Days after the prize announcement, on-chain analytics firm Bubblemaps published a detailed investigation alleging that wallet clusters linked to @beaverd had engaged in serial pump-and-dump activity across dozens of Solana memecoins launched via Pump.fun, extracting an estimated $600,000 in profits. @beaverd did not dispute the wallet links, responding publicly with 'cry me a river, also these aren't even the top 5 greatest hits,' a statement widely interpreted as an implicit admission of the activity.

avoid.net/deepsnitch-ai12/100[CRITICAL]

DeepSnitch AI is an Ethereum-based utility token project marketed as an AI-powered crypto scam-detection platform, operated by SignalPlex Lab Ltd., a company incorporated in the British Virgin Islands with no publicly disclosed team members. The project raised an alleged $2.87M in a multi-stage presale (figures across sources range from $2.2M to $2.87M and cannot be independently verified from a primary financial source) before listing on Uniswap on March 31, 2026, after which the token price collapsed approximately 99% within days, accompanied by widespread reports of presale buyers unable to claim tokens, a honeypot flag from security scanner Blockaid, and extended team silence. The team subsequently attributed the Blockaid flag to contract anti-dump mechanics misread as a honeypot, launched a V1 platform on April 10, 2026, and the contract flag was reportedly cleared; however, trading volume subsequently went dormant and no Tier 1 or Tier 2 source has independently verified any key claim.

avoid.net/cls-global-fzc-zm-quant-investment3/100[CRITICAL]

CLS Global FZC LLC (UAE) and ZM Quant Investment Ltd (British Virgin Islands) were crypto market-making firms that provided market-manipulation-as-a-service to token issuers. Both were charged in October 2024 by the U.S. DOJ and SEC as part of Operation Token Mirrors, a coordinated FBI sting that used a fake token called NexFundAI to document wash trading solicitation in real time. CLS Global pleaded guilty in January 2025 and was sentenced in April 2025 to pay $428,059 and serve a three-year U.S. market ban; ZM Quant's criminal case (1:24-cr-10187, D. Mass.) remained pending as of mid-2025 with its two individual defendants, Baijun Ou and Ruiqi Liu, based outside the United States. The SEC voluntarily dismissed its parallel civil actions against both entities on March 31, 2026, consistent with the current administration's broader rollback of crypto enforcement actions initiated under the prior administration.

avoid.net/jump-trading42/100[WARNING]

Jump Trading is a Chicago-based proprietary trading firm founded in 1999, operating one of the largest high-frequency trading operations globally across futures, equities, fixed income, FX, and cryptocurrency markets. Its crypto division, Jump Crypto, became a major force in DeFi infrastructure between 2021 and 2023, co-developing Wormhole, Pyth Network, and the Firedancer Solana validator client. The firm has faced significant regulatory and legal exposure: its subsidiary Tai Mo Shan settled with the SEC in December 2024 for $123 million over TerraUSD manipulation, the Terraform bankruptcy administrator filed a $4 billion civil lawsuit in December 2025 naming Jump and individual executives, and a separate CFTC investigation was reported in 2024 with no public resolution as of mid-2026.

avoid.net/ravedao2/100[CRITICAL]

RaveDAO is a Web3 entertainment protocol that markets itself as a community bridging electronic dance music culture with blockchain-based ticketing, governance, and event access. Its native token, RAVE, launched on Binance Alpha in December 2025 and experienced a ~10,800% price surge in April 2026 before collapsing approximately 95% within 48 hours amid substantial on-chain evidence of insider supply control and an alleged coordinated 'bait and liquidate' short-squeeze scheme. Binance, Bitget, and Gate.io opened formal investigations; on-chain investigator ZachXBT publicly accused the project's affiliated insiders of engineering the rally and named RAVE as part of a broader pattern of Bitget-enabled market-maker fraud.

avoid.net/zoth-protocol8/100[CRITICAL]

Zoth Protocol is an Ethereum-based real-world asset (RWA) re-staking and tokenization platform founded in 2023 by Pritam Dutta and Koushik Bhargav. In March 2025 the protocol suffered two separate security incidents within three weeks: an initial $285,000 logic-flaw exploit on March 1 and a far more damaging $8.4 million deployer-key compromise on March 21 that enabled a malicious proxy contract upgrade. The protocol has since launched a user compensation program, engaged Crystal Blockchain BV for fund recovery, and announced a security overhaul backed by a $15 million strategic token commitment from Bolts Capital.

avoid.net/celsius-network0/100[CRITICAL]

Celsius Network was a centralized crypto lending platform founded in 2017 that attracted over 1.7 million users and $20 billion in assets under management by offering yields of up to 18% on deposited cryptocurrency. In June 2022 the platform froze all withdrawals, subsequently filed for Chapter 11 bankruptcy in July 2022, and exposed a $1.2 billion balance sheet deficit. Founder and CEO Alex Mashinsky was arrested in July 2023, pleaded guilty to commodities fraud and securities fraud in December 2024, and was sentenced to 12 years in federal prison in May 2025.

avoid.net/doj-pig-butchering-seizure-july-202692/100[VERIFIED]

On July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints seeking to recover more than $25 million in USDT linked to pig butchering investment fraud and romance scams traced to networks operating out of Southeast Asia. The action was carried out by the Scam Center Strike Force, a multi-agency unit launched in November 2025 that has cumulatively recovered over $800 million in cryptocurrency from Chinese transnational criminal organizations running scam compound operations in Cambodia, Myanmar, and Laos. No individual defendants were named in the July 2026 complaints; the government proceeded in rem, suing the digital assets directly.

avoid.net/liquid-marketplace6/100[CRITICAL]

Liquid Marketplace (also styled Liquid MarketPlace) was a Toronto-based platform that offered fractional ownership of physical and digital collectibles through blockchain-based ERC-20 tokens, co-founded by YouTuber Logan Paul and collectors Ryan Bahadori and Amin Nikdel. In June 2024 the Ontario Securities Commission filed enforcement proceedings before Canada's Capital Markets Tribunal, alleging a multi-layered fraud in which approximately $3 million of more than $10 million raised from investors was misappropriated by the company's three principal executives through undisclosed shell companies, personal expenses, and interest-free loans that were never repaid. As of mid-2026 the merits hearing remains active and no final adjudication has been issued.

avoid.net/midnight-night-token52/100[CAUTIONARY]

Midnight is a privacy-focused Layer 1 blockchain developed by Input Output Global (IOG), the engineering firm behind Cardano, and overseen by the Cayman-based Midnight Foundation. It uses zero-knowledge proofs and a dual-token model (NIGHT and DUST) to offer selective data disclosure for compliant private smart contracts. The NIGHT token launched in December 2025 with a 24 billion fixed supply; in July 2026, a third-party Wanchain bridge connecting Cardano to BNB Chain was exploited for approximately 515 million NIGHT tokens (~$10-13 million), crashing the token price 30-43% to an all-time low, though Midnight's core Layer 1 protocol was not compromised.

avoid.net/kelp-dao32/100[WARNING]

Kelp DAO is a liquid restaking protocol built on EigenLayer that issues rsETH, a non-rebasing liquid restaking token. Originally incubated by Stader Labs and later rebranded to KernelDAO, the protocol grew to over $1.6 billion in TVL before suffering the largest single DeFi exploit of 2026: a $292 million cross-chain bridge attack attributed to North Korea's Lazarus Group. The protocol completed an operational rsETH recovery approximately five weeks after the hack through the DeFi United initiative, but significant reputational, systemic, and structural questions remain.

avoid.net/zrx-0x-protocol62/100[CAUTIONARY]

0x Protocol (ticker: ZRX) is a decentralized exchange infrastructure protocol founded in 2016 by Will Warren and Amir Bandeali, enabling peer-to-peer token trading on Ethereum and multiple other chains. The project conducted a $24 million ICO in August 2017, has processed over $200 billion in cumulative trading volume, and operates the Matcha DEX aggregator. In September 2023, the U.S. CFTC settled charges against ZeroEx, Inc.—the corporate entity behind 0x—for $200,000 related to the unlicensed offering of leveraged token trading; and in January 2026 a third-party integration (SwapNet) used in Matcha Meta suffered a $13.4 million exploit, though 0x's core protocol contracts were not compromised.

avoid.net/b-squared-network28/100[WARNING]

B-Squared Network (B² Network) is a Bitcoin Layer-2 protocol using ZK-Rollup technology, headquartered in Singapore and founded in 2022, with backing from HashKey Capital, OKX Ventures, IDG Capital, and others. On July 22, 2026, the protocol suffered a $3.86 million exploit when an attacker gained unauthorized access to the staking contract's upgrade authority, draining 8.59 million B2 tokens that were subsequently laundered through cross-chain infrastructure. The team pledged full compensation to affected stakers and offered a 10% bounty for return of funds; no attacker has been identified.

avoid.net/triple-a-payments42/100[WARNING]

Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payment gateway founded by Eric Barbier and licensed by the Monetary Authority of Singapore (MAS) as a Major Payment Institution. On July 25, 2026, the company confirmed unauthorized access to its treasury hot wallets, with on-chain investigators estimating losses of approximately $11.8 million across six blockchains; the company stated that customer funds were unaffected and that it can meet all liabilities. The incident remained unresolved as of July 27, 2026, with no attacker identified and no funds recovered.

avoid.net/doj-25m-pig-butchering-seizure-july-20265/100[CRITICAL]

On July 21, 2026, the U.S. Attorney's Office for the District of Columbia, operating through the Scam Center Strike Force, filed five civil forfeiture complaints targeting more than $25 million in USDT linked to international pig-butchering fraud rings operating primarily from Southeast Asia. The complaints identify hundreds of U.S. and Canadian victims across romance scams, fake cryptocurrency investment platforms, and fraudulent asset-recovery services, with no individual defendants named. This action is part of a broader 2026 enforcement surge that includes a $61 million USDT seizure in North Carolina, Treasury sanctions against Cambodian Senator Kok An and his Crown Resorts compound network, and a Dubai-led international operation resulting in 276 arrests and $701 million frozen.

avoid.net/wolf-capital-crypto-trading-llc2/100[CRITICAL]

Wolf Capital Crypto Trading LLC was an Oklahoma-based cryptocurrency investment firm operated by Travis Ford that raised approximately $9.4 million from roughly 2,800 investors between October 2022 and December 2024 through a Ponzi scheme promising daily returns of 1–2% (approximately 547% annually). Ford pleaded guilty to conspiracy to commit wire fraud in January 2025 and was sentenced in November 2025 to 60 months in federal prison, ordered to forfeit over $1 million and pay over $170,000 in restitution. The Commodity Futures Trading Commission (CFTC) filed a parallel civil enforcement action in December 2025 seeking disgorgement, civil penalties, and permanent trading and registration bans.

avoid.net/vladhood-vlad-memecoin-scam2/100[CRITICAL]

On July 23, 2026, unknown attackers compromised the verified X account of Robinhood CEO Vlad Tenev and used it to promote a fraudulent memecoin called Vladhood ($VLAD), falsely presenting it as the official mascot of the Robinhood Chain network and claiming it would be listed in the Robinhood app. The token had been pre-deployed on the Pons launchpad 46 minutes before the post appeared, and attackers extracted approximately 650 ETH ($1.2–$1.3 million USD) through trading fee collection rather than a traditional rug pull. No attacker attribution or law enforcement action had been publicly reported as of late July 2026.

avoid.net/bonzo-lend22/100[CRITICAL]

Bonzo Lend is a decentralized lending and borrowing protocol on the Hedera network, adapted from the Aave v2 codebase and formerly the largest DeFi lending protocol on Hedera by total value locked. On July 11, 2026, the protocol suffered a $9.05 million loss when an attacker exploited a critical signature verification flaw in its third-party Supra oracle provider, inflating the SAUCE token price by approximately twelve orders of magnitude and borrowing assets far in excess of deposited collateral. Protocol operations remain paused pending a Halborn-audited recovery contract deployment backed by the Hedera Foundation.

avoid.net/bitmart-exchange18/100[CRITICAL]

BitMart is a centralized cryptocurrency exchange founded in 2017 by Sheldon Xia and incorporated in the Cayman Islands, which at its peak served users in over 180 countries and listed more than 1,700 cryptocurrencies. In December 2021, BitMart suffered one of the largest hot-wallet hacks in crypto history, losing approximately $196 million, which triggered a Federal Trade Commission investigation and raised unresolved questions about victim reimbursement. On July 26, 2026, BitMart announced it would wind down all trading operations by August 26, 2026 and fully close by January 31, 2027, citing vague 'operating conditions' while its CEO simultaneously disclosed he had been excluded from the shutdown decision — a combination of events that poses immediate fund-access risk for remaining users.

avoid.net/ashcrypto18/100[CRITICAL]

Ashcrypto (also known as AshWSB) is a crypto influencer with over 2.1 million followers on X who has been publicly accused by on-chain investigator ZachXBT of running pump-and-dump schemes on illiquid CEX-listed altcoins. The most documented case involves the ROYA token, where Ashcrypto allegedly publicly promoted the asset while simultaneously selling his position and telling premium channel subscribers he was holding and buying more. No regulatory enforcement action has been filed as of July 2026.

avoid.net/triple-a38/100[WARNING]

Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payments company founded in 2017 and licensed as a Major Payment Institution by the Monetary Authority of Singapore (MAS). On July 24-25, 2026, attackers drained approximately $9.7 million from the company's hot wallets across at least four blockchain networks, with stolen funds consolidated into a single Ethereum address. As of the date of this report, Triple-A had issued no public acknowledgment of the breach despite continuing to accept live deposits, raising concerns about transparency obligations under its MAS licence.

avoid.net/b2-network28/100[WARNING]

B² Network (BSquared Network) is a Bitcoin Layer-2 scaling protocol founded in November 2022, utilizing zero-knowledge proof verification and EVM-compatible rollup technology. On July 22–23, 2026, the project suffered a confirmed security exploit in which an attacker gained unauthorized access to the upgrade authority of its B2 token staking contract on BNB Chain, draining 8.59 million B2 tokens valued at approximately $3.86 million. The stolen funds were sold for BNB, bridged to Ethereum, and are being routed through NEAR Intents toward Zcash for laundering, according to blockchain investigator Specter. The incident was one of three coordinated exploits on the same day — alongside the Verus Ethereum Bridge ($7.54M) and AFX Trade ($24.15M) — in what Lookonchain labeled 'Hackers' Day,' with combined losses of $35.55 million.

avoid.net/normie-memecoin8/100[CRITICAL]

Normie (NORMIE) was a memecoin launched in March 2024 on Coinbase's Base layer-2 blockchain that reached a peak market cap of approximately $130 million on April 2, 2024. On May 26, 2024, an attacker exploited a premarket-user recognition flaw in the token's smart contract via a flash loan attack, minting billions of tokens beyond the 1 billion supply cap and draining liquidity pools, causing a 99% price collapse and approximately $41 million in market cap destruction. A blockchain scam-detection tool reported the vulnerability had been detected in March 2024 but was never patched by the development team.

avoid.net/taptools38/100[WARNING]

TapTools was Cardano's largest on-chain analytics platform, serving over one million users with token price tracking, DeFi monitoring, portfolio tools, and a data API used by hundreds of third-party Cardano projects since its 2022 launch. In June 2026, the platform announced it would wind down operations within two weeks after losing five senior executives — including both co-founders, its COO, its CTO, and a backend developer elevated to act as CTO — in the span of roughly one year. The shutdown, occurring alongside the closure of JPG Store (Cardano's largest NFT marketplace) and the cancellation of Cardano Summit 2026, contributed to a 10–30% ADA price decline and prompted Cardano founder Charles Hoskinson to warn of a broader 'wave of failures' across the ecosystem.

avoid.net/stream-finance4/100[CRITICAL]

Stream Finance was an Ethereum-based DeFi yield aggregator founded in February 2024 by Diogenes Casares and Solal Afota that collapsed in November 2025 after disclosing a $93 million loss attributed to an off-chain trader who allegedly misappropriated protocol assets to cover personal margin-call losses. The collapse caused its xUSD synthetic stablecoin to depeg from $1.00 to approximately $0.26 within 24 hours, triggering an estimated $285 million in cascading exposure across multiple interconnected DeFi protocols including Morpho, Euler, Elixir, Silo, and Gearbox. A federal civil lawsuit (Case No. 3:2025cv10524, N.D. Cal.) was filed on December 8, 2025, accusing operator Caleb McMeans and trader Ryan DeMattia of misappropriation; as of mid-2026 the protocol entered a formal wind-down under a newly incorporated holding company with no confirmed creditor recovery timeline.

avoid.net/dutch-crypto-investment-fraud-ring-20260/100[CRITICAL]

A large-scale international investment fraud network, dismantled by Dutch and Belgian police in July 2026, operated approximately 20 call centers staffed by over 700 people who posed as financial advisers and used fake cryptocurrency trading platforms to steal an estimated €100 million per month from victims worldwide. The alleged mastermind — Ehud Tenenbaum, a 46-year-old dual Israeli-Polish national known in cybercrime circles as 'The Analyzer' for his late-1990s hacking of U.S. government systems — was arrested in Poland in May 2026 and extradited to the Netherlands. Tens of thousands of victims across multiple countries are estimated, with Dutch victims alone reporting nearly €25 million in losses.

avoid.net/doj-pig-butchering-25m-forfeiture-20260/100[CRITICAL]

On July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints seeking more than $25 million in cryptocurrency linked to pig butchering, romance, and asset-recovery fraud schemes. The action, executed through the Scam Center Strike Force, represents the largest forfeiture action ever sought by the DOJ specifically targeting crypto confidence scams, and documents a major active threat surface involving Chinese transnational crime syndicates, fake investment platforms, and Tether-denominated laundering chains affecting thousands of victims across the United States and Canada.

avoid.net/summer-fi25/100[CRITICAL]

Summer.fi (formerly Oasis.app) was a DeFi frontend and yield protocol platform with roots in the original MakerDAO ecosystem, operating for approximately seven years before shutting down in 2026. On July 6, 2026, an attacker exploited a share-accounting vulnerability in its Lazy Summer Protocol vaults via a $65.4 million flash loan, stealing approximately $6.04 million in depositor funds; the root cause was traced to stale Silo token valuations inherited from the November 2025 Stream Finance collapse. Following the exploit, Summer.fi Labs announced the permanent shutdown of operations, with the application scheduled to remain accessible through August 31, 2026 pending DAO-governed recovery of affected vault funds estimated at approximately $4 million.

avoid.net/lien-finance22/100[CRITICAL]

Lien Finance is a governance-free Ethereum DeFi protocol launched in August 2020 that enables users to create options and stablecoins by tranching ETH deposits into two derivative bond tokens (SBT and LBT). On July 24, 2026, the protocol was exploited for approximately 542,144 USDC through manipulation of its permissionless bond registration system and a flawed OTC pricing function. This is the protocol's second significant security incident, following a September 2020 near-miss in which a whitehat coalition rescued approximately $10 million from a related BondMaker contract vulnerability.

avoid.net/afx-trade18/100[CRITICAL]

AFX Trade is a decentralized perpetual futures exchange (perp DEX) built on Arbitrum that uses a fully on-chain central limit order book (CLOB) and settles in USDC. On July 22–23, 2026, the protocol suffered a $24.15 million loss after attackers compromised the private validator signing keys controlling its third-party USDC custody bridge, fraudulently meeting the multi-signature threshold required to authorize a withdrawal. The incident represents one of three clustered bridge exploits on the same day, which collectively drained $35.55 million across the DeFi ecosystem.

avoid.net/janus-henderson-anemoy-aaa-clo-fund-jaaa72/100[CAUTIONARY]

The Janus Henderson Anemoy AAA CLO Fund (JAAA) is a tokenized real-world asset fund providing on-chain exposure to AAA-rated tranches of Collateralized Loan Obligations (CLOs), actively managed by Janus Henderson Investors U.S. LLC as sub-advisor and issued by Anemoy Capital SPC Limited, a British Virgin Islands regulated professional fund. Launched in June 2025 with a $1 billion seed allocation from the Sky/MakerDAO ecosystem via the Grove DeFi protocol, the tokenized fund had approximately $686 million in assets under management as of June 2026. The fund is restricted to non-US qualified institutional investors who pass KYC/AML onboarding via the Centrifuge platform, and carries inherent risks from CLO market credit spreads, smart contract infrastructure, cross-jurisdictional regulatory uncertainty, and stablecoin dependency.

avoid.net/invesco-short-duration-us-government-securities-fund-ustb78/100[VERIFIED]

USTB is a tokenized short-duration U.S. Treasury fund originally launched by Superstate in February 2024 and transitioned to Invesco Advisers, Inc. as investment manager in mid-2026. As of July 2026, the fund holds approximately $682 million in AUM, is deployed on Ethereum, Solana, and Plume, and is restricted to accredited investors and qualified purchasers. It operates as a private Section 3(c)(7) fund under a Regulation D Rule 506(c) exemption and has no record of regulatory enforcement actions, fraud allegations, or security incidents.

avoid.net/janus-henderson-anemoy-treasury-fund-jtrsy82/100[VERIFIED]

The Janus Henderson Anemoy Treasury Fund (JTRSY) is a tokenized British Virgin Islands professional fund that invests exclusively in short-term U.S. Treasury Bills with maturities under six months, issued on-chain via the Centrifuge protocol. The fund is regulated by the BVI Financial Services Commission, managed by Anemoy Asset Management with Janus Henderson Investors as sub-investment manager, and has received top-tier credit ratings including AA+f/S1+ from S&P Global Ratings as of March 2025. Access is restricted to non-U.S. professional investors and qualified crypto institutions, with subscriptions and redemptions settled in USDC.

avoid.net/united-stables-u48/100[WARNING]

United Stables is a USD-pegged stablecoin issued by United Stables Limited (registered in the British Virgin Islands), operating under the ticker symbol U. Launched in December 2025 on BNB Chain and Ethereum, it reached approximately $1 billion in circulating supply by mid-2026, ranking among the top-100 cryptocurrencies by market cap. The issuer explicitly states it holds no regulatory licenses under MiCA, Hong Kong stablecoin law, or the US GENIUS Act, and the public leadership profile is extremely limited, with the CEO identified only as 'Athena Y.'

avoid.net/bfusd52/100[CAUTIONARY]

BFUSD is a reward-bearing margin asset launched by Binance Futures in November 2024, designed exclusively for use as collateral in USDT-M Futures trading. It is not a blockchain token, cannot be withdrawn from Binance, and generates yield through delta-neutral funding-fee strategies and ETH staking. While Binance maintains a reserve fund and transparency dashboard, the product carries significant concentrated counterparty risk tied to Binance's centralized custody model and its operator's prior criminal guilty plea on AML charges in 2023.

avoid.net/blackrock-usd-institutional-digital-liquidity-fund82/100[VERIFIED]

BUIDL is a tokenized U.S. dollar money market fund managed by BlackRock and issued on public blockchains through tokenization platform and transfer agent Securitize. Launched on Ethereum in March 2024, it holds cash, U.S. Treasury bills, and repurchase agreements, is custodied by Bank of New York Mellon, and is offered as a private placement restricted to accredited/qualified institutional investors rather than as a retail SEC-registered security. It has grown into the largest tokenized U.S. Treasury fund by assets under management, but access, redemption, and transfer are gated by centralized whitelisting and freeze controls typical of permissioned real-world-asset (RWA) tokens.

avoid.net/global-dollar68/100[CAUTIONARY]

Global Dollar (USDG) is a fiat-backed stablecoin issued by Paxos Digital Singapore Pte. Ltd. and regulated by the Monetary Authority of Singapore, launched in November 2024 to anchor the Global Dollar Network (GDN), a consortium of exchanges and fintechs including Robinhood, Kraken, Galaxy Digital, Anchorage Digital, Bullish, Nuvei, and Visa. USDG differentiates itself from USDT and USDC by sharing reserve yield with network partners rather than retaining it at the issuer, and publishes monthly third-party reserve attestations. The stablecoin itself has no confirmed depeg incidents or direct regulatory enforcement action to date, but its issuer, Paxos, has a documented history of AML/KYC compliance failures tied to the BUSD stablecoin, and USDG's yield-distribution model sits in a regulatory gray area under the GENIUS Act's interest-payment prohibitions that lawmakers and banking groups are actively seeking to close.

avoid.net/lighter62/100[CAUTIONARY]

Lighter is a venture-backed, zero-fee perpetual futures decentralized exchange built as a custom zero-knowledge rollup on Ethereum, founded by former Citadel engineer Vladimir Novakovski. It has raised roughly $89 million from high-profile investors including Founders Fund, Ribbit Capital, Haun Ventures, Craft Ventures, Dragonfly and Robinhood Markets, reaching a $1.5 billion valuation, and briefly ranked among the top perpetuals DEXs by volume. The platform has drawn scrutiny over post-token-launch withdrawal delays, a front-end chart-manipulation controversy following a bot-driven price spike, heavy team/investor token allocation, and a sharp decline in trading volume and user activity after its December 2025 airdrop.

avoid.net/usds63/100[CAUTIONARY]

USDS is the primary stablecoin of Sky (formerly MakerDAO), launched in September 2024 as the successor to DAI within Sky's product line, with holders able to convert 1:1 between the two tokens. USDS is over-collateralized by a mix of crypto assets, USDC held via peg stability modules, and tokenized real-world assets including U.S. Treasuries, but it has drawn recurring criticism over a wallet-freezing capability, a custody arrangement for hundreds of millions of dollars in reserves that relied on a single externally-owned wallet, and rising governance complexity under Sky's 'Endgame' restructuring. No confirmed hack or sustained depeg of USDS itself has been documented as of this writing, though it inherits pass-through depeg risk from its USDC backing.

avoid.net/usdd28/100[WARNING]

USDD is a stablecoin issued by the TRON DAO Reserve, launched in May 2022 and marketed as an over-collateralized, algorithmically-assisted alternative to Terra's failed UST. USDD de-pegged from its $1.00 target within weeks of launch and again during the November 2022 FTX collapse, and has since faced sustained criticism over opaque, shifting reserve composition, a defunct governance structure, and the concentration of control and collateral around TRON founder Justin Sun and his exchange HTX. Independent stablecoin rating firm Bluechip assigned USDD the lowest grade ('F') among stablecoins it assessed, citing commingled reserves and an absence of functioning decentralized governance.

avoid.net/usd138/100[WARNING]

USD1 is a U.S. dollar-pegged stablecoin launched in March 2025 by World Liberty Financial (WLFI), a DeFi project with direct financial ties to the Trump family. Reserves are custodied by BitGo Trust Company and attested to monthly by Crowe LLP, but the coin has drawn scrutiny for delayed attestation reports, heavy offshore concentration, an unresolved conflict-of-interest controversy tied to a $2 billion MGX-Binance transaction, a June 2026 exchange delisting following an address freeze, and open questions about whether its issuance structure complies with the GENIUS Act. As of July 2026 it ranks among the largest stablecoins by market capitalization, though its governance is entangled with the political and business interests of a sitting U.S. president's family.

avoid.net/teleswap32/100[WARNING]

TeleSwap (formerly TeleportDAO) is a cross-chain bridge protocol that lets users move Bitcoin and Runes to EVM chains, TON, and Solana using light-client and "Locker"/"Teleporter" custodian architecture, funded by a $2.5M 2023 seed round and a 2024 public token sale. On July 15, 2026, on-chain investigator ZachXBT and the SlowMist Hacked incident database reported suspicious outflows of roughly $735,000 from TeleSwap's Bitcoin hot wallet followed by laundering through Tornado Cash; as of this writing TeleSwap has not issued a public confirmation, technical postmortem, or the underlying transaction details, which is itself a notable transparency concern. Overall reporting quality on the incident is thin — it traces back mainly to one investigator's claim and aggregator write-ups rather than a project statement, a named security-firm root-cause report, or Tier-1 news coverage, so key facts (attack vector, exact amount, affected users) remain unverified.

avoid.net/barnbridge12/100[CRITICAL]

BarnBridge was an Ethereum-based DeFi protocol, structured as a DAO, best known for its SMART Yield product, which tranched variable-rate yield from lending markets like Compound and Aave into fixed and variable risk classes. The protocol halted operations in mid-2023 after founders disclosed an SEC investigation, and BarnBridge DAO and its two founders settled with the SEC in December 2023 for $1.7 million over unregistered offer and sale of crypto asset securities and unregistered investment company violations. On July 15, 2026, despite being effectively defunct, BarnBridge's SMART Yield governance and legacy token approvals were exploited in a governance-takeover attack that drained approximately $776,000 in USDC from roughly 50 wallets; the attacker reportedly spent only about $600 to acquire enough BOND voting power to pass a malicious upgrade proposal through an inactive DAO. The scout flag characterizing this as a governance-attack incident is substantiated: the event is corroborated across multiple independent crypto-news outlets and an on-chain security firm, though as of this writing it lacks coverage from top-tier wire/legal press specific to the 2026 incident itself (the 2023 SEC action is Tier 1 sourced).

avoid.net/zilliqa61/100[CAUTIONARY]

Zilliqa is a Singapore-founded, sharded layer-1 blockchain launched in 2017 out of National University of Singapore research, with a track record of independent smart-contract audits and no history of SEC or DOJ enforcement action against the project itself. Its trust profile is weighed down by two distinct security incidents: a February 2025 exploit of Zilliqa's own X-Bridge token-manager contracts (protocol-level fault, roughly $42,000 realized loss) and a July 2026 theft of ZIL tokens from an exchange partner's cold wallet, which Zilliqa's own preliminary findings attribute to a technical flaw in legacy ZIL1 wallet transaction-signing rather than to the exchange's custody practices — a claim that as of this writing is corroborated by only one secondary source and remains unconfirmed by Zilliqa's promised full post-mortem.

avoid.net/knaken4/100[CRITICAL]

Knaken (Knaken Cryptohandel B.V.), a Rotterdam-based Dutch cryptocurrency exchange founded in 2017, was declared bankrupt by a Rotterdam court on July 16, 2026 after roughly €7 million in customer funds could not be accounted for. The platform, which had roughly 30,000 customers, went offline in early June 2026 after failing to obtain the license required under the EU's Markets in Crypto-Assets (MiCA) regulation, and is now the subject of a Dutch Public Prosecution Service (OM) criminal investigation into the missing funds.

avoid.net/benjamin-paul-wiener8/100[CRITICAL]

Benjamin Paul Wiener is a 43-year-old Sioux Falls, South Dakota resident and founder of the Benaiah group of investment entities who was indicted by a federal grand jury in June 2026 on 29 counts including wire fraud, bank fraud, money laundering, and aggravated identity theft, in connection with an alleged Ponzi-style scheme that solicited roughly $20-25 million from investors in cash and cryptocurrency. Wiener pleaded not guilty at his arraignment on July 10, 2026, and is scheduled for trial on September 15, 2026; the case is a pending criminal matter and Wiener is presumed innocent unless and until convicted. A separate, earlier-filed civil lawsuit and court-ordered asset freeze/receivership against Wiener's Benaiah entities alleges similar conduct and predates the criminal indictment.

avoid.net/summer-fi-lazy-summer-protocol22/100[CRITICAL]

Summer.fi, a DeFi yield-optimization platform formerly known as Oasis.app that spun out of the Maker Foundation in 2021, operated the DAO-governed Lazy Summer Protocol until a July 6, 2026 exploit drained roughly $6.04 million from two of its USDC vaults via a flash-loan-funded share-price manipulation of the Fleet Commander accounting contract. Summer.fi's own post-mortem attributes the loss to an operational oversight — an old, capped strategy that was never fully removed from vault net-asset-value calculations — rather than a smart-contract bug or compromised keys. The Summer.fi Labs company announced on July 15, 2026 that it would wind down and shut off its app by August 31, 2026, leaving user compensation and the fate of roughly $4 million in illiquid affected-vault holdings to a future Lazy Summer DAO governance vote.

avoid.net/trump-memecoin-presidential-conflict-of-interest-and-retail-losses8/100[CRITICAL]

The $TRUMP token is a Solana-based memecoin launched on January 17, 2025 — three days before President Donald Trump's inauguration — by two Trump-affiliated entities, CIC Digital LLC and Fight Fight Fight LLC, which collectively retained 80% of the 1-billion-token supply under a multi-year vesting schedule. Trump's June 2026 Office of Government Ethics financial disclosure reported $635 million in royalties from the token, funneled through a licensing agreement with an entity called 'Celebration Coins' for which no public digital footprint could be found. As the token collapsed more than 97% from its January 2025 peak of approximately $74, on-chain analysis by Chainalysis attributed losses of over $700 million to retail buyers across more than 764,000 wallets, while legal experts, Senate investigators, and ethics watchdogs raised alarms that the token's anonymous purchase mechanism created an untraceable channel for gifts and influence payments to a sitting president.

avoid.net/mica-eu-mass-non-compliance-83-unlicensed-platform-risk18/100[CRITICAL]

The European Union's Markets in Crypto-Assets Regulation (MiCA) transitional grace period expired on July 1, 2026. Of approximately 1,200+ crypto firms that previously operated under national VASP registrations, only roughly 210–244 obtained full Crypto Asset Service Provider (CASP) authorization — a conversion rate of approximately 17–20%, leaving an estimated 83% operating in breach of EU law. ESMA confirmed on April 17, 2026 that no extensions would be granted and that unlicensed firms must cease EU services immediately; affected major exchanges include Binance (withdrew Greek application June 24, 2026), MEXC, Bitget, CoinEx, and others serving millions of European users.

avoid.net/wojtek-kulisz-merry-sim-swap-crypto-theft-ring2/100[CRITICAL]

Wojtek Kulisz, known online as 'Merry', is a Polish national alleged by blockchain investigator ZachXBT to be among four individuals arrested in Poland on June 25, 2026, as part of a joint CBZC-FBI-HSI operation targeting an organized SIM swap crypto theft ring. The group is accused of breaching telecommunications infrastructure, hijacking victims' phone numbers, and draining cryptocurrency exchange accounts, with prosecutors estimating laundered funds in excess of tens of millions of Polish zlotys (approximately $5–$15 million USD). Polish authorities placed all four suspects in pretrial detention facing charges of participation in an organized criminal group, unauthorized computer system access, and money laundering, each carrying a maximum sentence of 25 years.

avoid.net/aztec-connect-deprecated-bridge-double-exploit-june-202620/100[CRITICAL]

In June 2026, two separate deprecated Aztec infrastructure contracts on Ethereum were exploited within one week, draining a combined total of approximately $4.25 million. The first exploit, on June 14, targeted the legacy Aztec Connect rollup contract via a proof verification mismatch; a follow-on second attack on June 15 drained residual funds. A third, separate exploit on June 17-18 hit the deprecated Aztec Private Rollup Bridge's escapeHatch function. Aztec Labs stated it had renounced all admin keys over the affected contracts in April 2024 and that the incidents had no connection to the current Aztec Network or AZTEC ERC-20 token.

avoid.net/nanobit-fake-crypto-platform-sec-pig-butchering-judgment0/100[CRITICAL]

NanoBit Limited was a fraudulent cryptocurrency trading platform operated from approximately September 2023 to June 2024 that defrauded at least 18 investors of nearly $1 million via a 'pig butchering' scheme conducted through WhatsApp groups. The U.S. Securities and Exchange Commission filed charges in September 2024 against four corporate entities and three individuals, and on June 16, 2026, the U.S. District Court for the Eastern District of New York entered a $5,518,902 default judgment — one of the SEC's first securities-fraud judgments against a fake-platform pig butchering operation — though recovery is considered essentially impossible as more than $2 million was wired to bank accounts in Hong Kong.

avoid.net/edel-finance28/100[WARNING]

Edel Finance is a decentralized lending protocol for tokenized equities, built as an Aave v3 fork on the Base/EVM network with an institutional Canton Network component, that launched mainnet on March 25, 2026. On July 1, 2026, the protocol suffered a flash-loan oracle manipulation exploit that drained approximately $403,000 from its xStock lending reserves, with stolen funds routed immediately to Tornado Cash. The protocol had also faced prior controversy in November 2025 over alleged insider acquisition of more than 30% of the EDEL token supply, contradicting stated tokenomics.

avoid.net/binance-mica-greece-application-withdrawal32/100[WARNING]

Binance, the world's largest cryptocurrency exchange by trading volume, withdrew its Markets in Crypto-Assets (MiCA) license application from Greece's Hellenic Capital Market Commission on June 24, 2026, days before the EU's July 1, 2026 compliance deadline, after reports indicated the regulator was preparing to reject the bid. The withdrawal triggered a suspension of services across all 27 EU member states effective July 1, 2026, affecting users in France, Italy, Poland, Spain, and other countries. Binance stated it intends to pursue MiCA authorization through another EU member state, with France cited as the most likely destination, though the exchange already faces an active judicial probe there over alleged money laundering and tax fraud.

avoid.net/rowan-energy-david-duckworth-five-year-green-crypto-fraud2/100[CRITICAL]

Rowan Energy was a UK-based company founded by David Duckworth that marketed a blockchain-powered green energy rewards platform, selling SmartMiner hardware devices and the RWN token under the premise of tokenized renewable energy certificates. In April 2025, a white-hat researcher discovered a hidden token minting function and a suppressed token supply nearly double the publicly stated figure; Duckworth denied the allegations for 69 days before the company quietly shut down its blockchain on June 24–25, 2025, causing a greater than 99.9% collapse in RWN token value and leaving investors with no refund or recourse.

avoid.net/clawd-token-fake-clawdbot-ai-scam2/100[CRITICAL]

The $CLAWD token is a fraudulent Solana memecoin launched in January 2026 by unidentified actors who exploited a roughly 10-second window during the ClawdBot-to-Moltbot brand rename to seize the project's X handle and GitHub organization. Presenting the token as an official launch by the viral open-source AI project, the scammers drove the market cap to approximately $16 million before founder Peter Steinberger publicly denied any involvement and the token collapsed by roughly 90%. No attacker has been publicly identified and investor losses are considered unrecoverable.

avoid.net/stakedao38/100[WARNING]

StakeDAO is a DeFi protocol launched in January 2021 that provides liquid locking, yield strategies, and governance aggregation built primarily around Curve Finance's ecosystem on Ethereum and Arbitrum. On May 27, 2026, the protocol suffered a significant exploit when an attacker compromised its deployer private key and used it to reconfigure a LayerZero v2 OFT bridge peer, enabling the minting of approximately 5.44 trillion vsdCRV tokens on Arbitrum and the extraction of roughly $91,000 in ETH. The incident did not involve a smart contract vulnerability but exposed a critical operational security failure: the deployer key was a single point of failure with no multisig protection, no timelock, and was allegedly operated as a hot key inside automated infrastructure.

avoid.net/secret-network-axelar-bridge-exploit-june-20268/100[CRITICAL]

On June 10, 2026, an attacker exploited a missing channel-origin validation in a customized CW20-ICS20 smart contract on Secret Network to mint approximately $4.67 million in unbacked Axelar-wrapped tokens (saTokens) and redeem them for real escrowed assets. The exploit went undetected for seven days due in part to Secret Network's privacy-by-default architecture, which encrypts account balances and masked the missing collateral until a failed cross-chain transfer on June 17 exposed the shortfall. Blockchain security firm Common Prefix traced the vulnerability to the contract's initial deployment in early 2023; a March 5, 2026 contract migration added new functionality but carried the unpatched validation flaw forward without a new security audit.

avoid.net/courier-based-pig-butchering-scam-network-fbi-warning-june-20260/100[CRITICAL]

In June 2026, the FBI's Internet Crime Complaint Center issued a formal public service announcement warning that cryptocurrency investment fraud operators — commonly operating 'pig butchering' schemes from forced-labor compounds in Southeast Asia — have adopted a physical courier variant to collect cash directly from victims when banks block electronic transfers. This hybrid approach uses in-person couriers authenticated via dollar bill serial numbers or pre-arranged passwords to collect cash from victims at their homes or public locations. Pig butchering scams caused Americans $11.37 billion in losses in 2025 alone, with the courier variant representing an escalation designed to circumvent traditional financial institution fraud controls.

avoid.net/loopring-dex-shutdown-june-202638/100[WARNING]

Loopring, Ethereum's first zero-knowledge rollup decentralized exchange, permanently ceased all trading and relayer operations on June 28, 2026, citing lack of meaningful user adoption, architectural obsolescence relative to modern zkEVM competitors, and a cascade of major exchange delistings of its LRC token. The shutdown is notable for disabling the protocol's hallmark trustless self-custody exit mechanism in favor of a team-controlled batch distribution, raising concerns among DeFi researchers about the integrity of the protocol's security guarantees at the moment they matter most.

avoid.net/shibarium-bridge32/100[WARNING]

The Shibarium Bridge is the Ethereum-to-Shibarium cross-chain bridge operated by the Shiba Inu ecosystem team, enabling transfer of SHIB, BONE, LEASH, and other tokens between Ethereum mainnet and the Shibarium Layer 2 network. The bridge suffered two major incidents: a chaotic launch in August 2023 that left approximately $1.7 million in ETH temporarily inaccessible, and a far more serious exploit in September 2025 in which attackers compromised 10 of 12 validator signing keys to drain approximately $3–4.1 million in assets. The bridge was partially restored in October 2025 following a security overhaul, but hack victims faced ongoing repayment delays and independent analysts raised persistent concerns about centralization and governance design.

avoid.net/huobi-htx14/100[CRITICAL]

HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.

avoid.net/thorchain-gg20-mpc-vault-exploit-may-202638/100[WARNING]

On May 15, 2026, THORChain suffered a targeted cryptographic exploit in which a malicious node operator reconstructed a full private key from a single Asgard vault by exploiting incremental key material leakage in the GG20 Threshold Signature Scheme, draining approximately $10.7 to $11 million across nine blockchain networks. The protocol executed an automated and community-coordinated emergency halt, published a formal exploit report on May 21, 2026, and resumed trading on June 23, 2026, after a 39-day shutdown and an 11-stage security overhaul. The incident is the third major security breach in THORChain's history and exposed systemic risks in GG20-based MPC implementations.

avoid.net/q2-2026-record-crypto-hack-wave0/100[CRITICAL]

The second quarter of 2026 became the most-hacked quarter on record by incident count, with 83 confirmed crypto security incidents totaling approximately $755.3 million in losses. Two attacks — KelpDAO ($292–293 million) and Drift Protocol ($280–285 million) — together accounted for roughly 75% of quarterly losses and were both attributed by blockchain intelligence firms to North Korea's Lazarus Group and its TraderTraitor subunit. The quarter marked a structural shift in dominant attack methodology away from smart contract code vulnerabilities toward infrastructure misconfiguration, private key compromise, and multi-month social engineering campaigns.

avoid.net/blessings-in-no-time-bint0/100[CRITICAL]

Blessings in No Time (BINT) was an illegal chain-referral pyramid scheme operated by LaShonda Moore (38) and Marlon Moore (39) of Frisco, Texas, from June 2020 to June 2021. The scheme defrauded more than 10,000 people nationwide out of more than $30 million by falsely promising 800% returns on $1,400 investments, and specifically targeted the African American community through weekly livestream broadcasts during the COVID-19 pandemic. In January 2026, a federal jury convicted the Moores on conspiracy, wire fraud, and money laundering charges; in June 2026, they were each sentenced to 40 years in federal prison and ordered to pay more than $4.3 million in restitution.

avoid.net/syscoin28/100[WARNING]

Syscoin (SYS) is a dual-chain blockchain protocol originally launched in 2014 that combines a Bitcoin-derived UTXO chain with an Ethereum-compatible smart contract layer called NEVM. In June 2026, a critical proof-parsing flaw in its cross-chain bridge allowed an attacker to mint approximately 5 billion unauthorized SYS tokens — more than five times the circulating supply — valued at roughly $8.5–10 million; all funds were ultimately recovered and burned. The project has accumulated a pattern of serious concerns spanning its history: a 2014 ICO fund theft, a 2018 GitHub supply-chain compromise, and extensive 2024 governance allegations including a Dutch criminal investigation into alleged fraud, embezzlement, and unauthorized token issuance by its own foundation directors.

avoid.net/dark2web0/100[CRITICAL]

Dark2Web was a darknet and clear-web cybercrime forum operated by the same individuals who ran the AudiA6 cryptocurrency laundering service. It served as the primary advertising hub and networking venue for ransomware affiliates, hackers, and other cybercriminals who used AudiA6 to launder proceeds. Both platforms were seized by an international law enforcement coalition on June 10-11, 2026, and their two alleged administrators were arrested in Georgia and face extradition to the United States.

avoid.net/bitget-exchange-shawn-liu42/100[WARNING]

Bitget is a Seychelles-headquartered centralized cryptocurrency exchange founded in 2018, ranking among the top 10 global exchanges by trading volume as of 2025. The platform is known for its copy trading product and native token BGB, but has drawn regulatory warnings from multiple jurisdictions including Australia (ASIC), Canada, Germany, France, Spain, and Austria for operating unlicensed derivatives products. In May 2026, on-chain investigator ZachXBT published allegations identifying founder Shawn Liu as the alleged behind-the-scenes operator and accusing Bitget of enabling token supply manipulation schemes involving at least four listed assets.

avoid.net/ravedao-rave-token4/100[CRITICAL]

RaveDAO is a Web3 project that organized electronic music events and launched the RAVE token on Binance Alpha in December 2025. In April 2026, RAVE surged approximately 10,800% in nine days to a peak market cap near $6.6 billion before collapsing 95% within 48 hours, erasing roughly $5.7 billion in value. On-chain investigator ZachXBT alleged coordinated insider manipulation based on extreme supply concentration and suspicious pre-surge token transfers, prompting formal investigations by Binance and Bitget; RaveDAO denied any involvement.

avoid.net/rain-protocol-rain-token12/100[CRITICAL]

Rain Protocol is a decentralized prediction markets protocol built on Arbitrum, with its native RAIN token reaching an approximately $8.8 billion fully diluted valuation (FDV) by mid-2026. On-chain investigator ZachXBT alleged in June 2026 that 99.97% of RAIN's total supply is controlled by 81 wallets and that deployer wallet funding trails link the Rain team to the Data Ownership Protocol (DOP) and TOMI networks, projects associated with Israeli entrepreneur Moshe Hogeg, who faces a recommended $290 million fraud indictment in Israel. Rain Protocol has not issued a public response to these allegations, and no regulatory action has been taken against Rain Protocol directly.

avoid.net/eleven-drainer0/100[CRITICAL]

Eleven Drainer is a Drainer-as-a-Service (DaaS) toolkit and phishing syndicate that emerged around August 2025, offering rented wallet-draining infrastructure to criminal operators who deploy it through phishing sites, DNS hijacks, and compromised front-ends. The kit is associated with confirmed theft of at least $4.2 million across a three-week window in November 2025, including a $700,000 loss from a DNS hijack of decentralized exchanges Aerodrome and Velodrome. As of June 2026, the kit remains active and was detected embedded in a compromised Gitcoin subdomain.

avoid.net/wojtek-kulisz-aka-merry-sim-swap-gang2/100[CRITICAL]

Wojtek Kulisz, known online as 'Merry', is a Polish national alleged to be a social engineering threat actor linked by blockchain investigator ZachXBT to a four-person SIM-swap criminal ring arrested by Polish and U.S. authorities on June 25, 2026. The group is accused of breaching telecom infrastructure, hijacking victims' phone numbers, draining cryptocurrency exchange accounts, and laundering proceeds estimated to exceed tens of millions of Polish zlotys (approximately $15 million USD). Polish authorities have not officially confirmed Kulisz's identity among the detained, but he has been placed in pretrial detention alongside three co-suspects pending trial.

avoid.net/huione-group-haowang-guarantee0/100[CRITICAL]

Huione Group is a Cambodia-based conglomerate that operated Huione Guarantee (also known as Haowang Guarantee), a Telegram-based peer-to-peer marketplace that blockchain analytics firm Elliptic has described as the largest illicit online marketplace ever recorded, processing over $31 billion in illicit transactions since 2021. The group's payments arm, Huione Pay, received an additional $103 billion in cryptocurrency payments over its lifetime. On June 23, 2026, the U.S. Department of Justice seized the cloud computing infrastructure used by Huione Group subsidiaries as part of Operation Riptide; the U.S. Treasury's FinCEN had previously designated Huione Group a primary money laundering concern in October 2025 under Section 311 of the USA PATRIOT Act and simultaneously proposed extending the ban to successor entity H-Pay Service PLC.

avoid.net/olpc-bnblabubu-token-pancakeswap-pool-exploit2/100[CRITICAL]

On June 20, 2026, an attacker drained approximately $1.1 million from the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) by exploiting a logic flaw in the OLPC token's _update function, which triggered a massive burn of pool reserves. Approximately 46 days prior to the attack, the OLPC token contract owner had maliciously altered the decimalsValue parameter to an abnormally large integer before renouncing ownership, a sequence that security researchers and analysts widely characterize as a premeditated rug pull disguised as an external exploit. Stolen funds — 633.4 ETH — were bridged to Ethereum and deposited into Tornado Cash.

avoid.net/taiko-ethereum-l2-bridge18/100[CRITICAL]

On June 22, 2026, Taiko — an Ethereum-equivalent layer-2 rollup — suffered a bridge exploit in which an attacker drained approximately $1.7 million from its L1 Bridge and ERC-20 vault by using an RSA-3072 Intel SGX signing key that had been committed in plaintext to the public taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and execute fraudulent withdrawal transactions on Ethereum with no corresponding deposits on Taiko's chain. Taiko halted block production network-wide, froze affected contracts, and urged all users to exit every bridge on the network within approximately eight minutes of the attack being detected by Blockaid's monitoring system.

avoid.net/aztec-deprecated-private-rollup-bridge-exploit-june-202620/100[CRITICAL]

In June 2026, two separate exploits drained a combined total of over $4 million from deprecated Aztec Network smart contracts — Aztec Connect on June 14 ($2.19M) and the Aztec Private Rollup Bridge on June 17 ($2.16M). Both contracts had been shut down years earlier but remained immutable and on-chain, custodying residual user assets with no administrative override capability.

avoid.net/q2-2026-defi-record-hack-wave0/100[CRITICAL]

Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses. The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026. The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.

avoid.net/memecore-m-token9/100[CRITICAL]

MemeCore is a Layer 1 blockchain project whose native M token collapsed 74-80% on June 25, 2026, erasing approximately $3 billion in market value with no confirmed exploit, hack, or public announcement. On-chain investigator ZachXBT and associated analysts had previously flagged alleged insider control exceeding 90% of the token supply, $7.9 million in suspicious Kraken withdrawals to 18 newly created wallets, and near-zero decentralized exchange liquidity, raising serious questions about the token's valuation legitimacy and the due diligence performed by listing exchanges including Binance, Bybit, Kraken, and Bitget.

avoid.net/ekubo-protocol42/100[WARNING]

Ekubo Protocol is a concentrated-liquidity DEX built primarily on Starknet, founded by ex-Uniswap lead engineer Moody Salem and backed by Uniswap Labs Ventures. On May 5, 2026, a missing payer-validation check in the IPayer.pay callback of its EVM swap router contracts allowed an attacker to drain approximately $1.4 million in WBTC from a single victim wallet across 85 rapid transactions, with the Starknet core deployment and liquidity providers remaining unaffected. The stolen funds were subsequently converted to ETH and routed through Tornado Cash.

avoid.net/olpc-token-pancakeswap-olpc-labubu-pool2/100[CRITICAL]

On June 20, 2026, the OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited for approximately $1.11 million. Security researchers and on-chain analysts determined the attack was premeditated: 46 days before the exploit, the OLPC token deployer had silently set the contract's decimalsValue parameter to an astronomically large value (7326680472586200649), then renounced ownership to obscure their intent. The attacker triggered a massive reserve-desynchronizing burn, drained the pool, converted proceeds to approximately 1,115,903 USDT, bridged to Ethereum, and deposited 633.4 ETH into Tornado Cash.

avoid.net/ice22/100[CRITICAL]

Ice Open Network (ION) is a Layer-1 blockchain founded by Alexandru Iulian Florea that launched a mobile tap-to-mine program in July 2023 and deployed its mainnet in January 2025. The project attracted a claimed community of 40 million users before suffering a severe token price collapse of approximately 93% in April 2026, a concurrent insider data breach, and mounting credibility questions over the founder's documented history operating a cybercrime-adjacent proxy botnet service and a prior 2018 ICO that allegedly left investors with near-total losses.

avoid.net/world-cup-pvp-token-wcup4/100[CRITICAL]

World Cup PvP Token (ticker: WCUP) is an ERC-20 token that launched on June 10, 2026, capitalizing on hype surrounding the 2026 FIFA World Cup. On-chain analytics firm Bubblemaps alleged that a coordinated group of over 30 wallets pre-purchased approximately 95% of the token's circulating supply within minutes of launch, driving the market cap to $50 million on the first day against only $536,000 in actual liquidity. Multiple crypto influencers on X promoted the token without disclosing alleged compensation, a pattern consistent with a coordinated pump-and-dump scheme.

avoid.net/humanity-protocol-h-token-hack18/100[CRITICAL]

On June 8-9, 2026, Humanity Protocol suffered a $36 million exploit when attackers compromised private keys stored on a malware-infected employee laptop, enabling them to drain approximately 141 million H tokens from an Ethereum bridge and mint an additional 300+ million tokens on BNB Smart Chain. The protocol's H token crashed 80-89% within hours of the attack becoming public. Blockchain security firm Quantstamp later attributed the attack tooling to DPRK-affiliated threat actors, and the team has since launched a token migration and recovery program with a $1 million USDT bounty for information.

avoid.net/taiko-ethereum-l2-bridge-exploit15/100[CRITICAL]

On June 22, 2026, an attacker drained approximately $1.7 million from the Taiko Ethereum layer-2 bridge and ERC-20 vault by exploiting a leaked Intel SGX RSA-3072 signing key that had been publicly committed to the taikoxyz/raiko GitHub repository. The attacker used the key to register as a legitimate prover, forge L2 state attestations, and submit withdrawal requests on Ethereum with no matching deposits on Taiko, causing the bridge contracts to release funds against fraudulent proofs. Taiko halted block production and froze bridge withdrawals within approximately eight minutes of the attack being detected by Blockaid's monitoring system.

avoid.net/yg42/100[WARNING]

Yield Guild Games (YGG) is a Philippines-based web3 gaming guild and decentralized autonomous organization that gained prominence during the 2021 Axie Infinity play-to-earn boom. The YGG token launched in July 2021, reached an all-time high of approximately $11.27 in November 2021, and subsequently lost over 99% of its value as the play-to-earn economy collapsed. The project has since pivoted toward multi-game community coordination and game publishing under the YGG Play brand, backed by major investors including a16z Crypto and DWF Labs.

avoid.net/saga-evm-blockchain32/100[WARNING]

Saga is a Layer-1 blockchain protocol designed to support application-specific chains (chainlets), with a focus on gaming and DeFi use cases. In January 2026, its SagaEVM chainlet suffered a critical exploit in which an inherited vulnerability in the Ethermint EVM codebase allowed an attacker to mint approximately $7 million in unbacked stablecoins, which were subsequently bridged to Ethereum and largely laundered through Tornado Cash. The broader Saga SSC mainnet, consensus layer, and validator set were not compromised, but the incident exposed material risks from deploying EVM compatibility layers built on unaudited inherited codebases.

avoid.net/blockfills-reliz-technology-group-holdings4/100[CRITICAL]

BlockFills, a Chicago-based institutional crypto trading and lending firm operating through parent entity Reliz Technology Group Holdings, Inc., filed Chapter 11 bankruptcy on March 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware, reporting $50–100M in assets against $100–500M in liabilities. A central allegation — confirmed by debtors' own counsel at the first-day hearing — is that client funds were never segregated but were commingled with company funds on a single balance sheet, producing an estimated $77M deficit that renders clients unsecured creditors. In June 2026, Brussels-based market maker Keyrock agreed to acquire substantially all BlockFills assets for $3.25M, a figure that represents a fraction of total liabilities and raises serious doubts about meaningful client recovery.

avoid.net/kelpdao-bridge-exploit-april-20262/100[CRITICAL]

On April 18, 2026, attackers drained 116,500 rsETH (approximately $292–294 million) from KelpDAO's LayerZero-powered cross-chain bridge, making it the largest DeFi exploit of 2026. The attack exploited a single-DVN (Decentralized Verifier Network) configuration by compromising RPC nodes and using a DDoS to force failover to poisoned infrastructure, tricking the bridge verifier into approving a phantom token release. The operation has been attributed with preliminary confidence to North Korea's Lazarus Group, specifically the TraderTraitor subunit, and triggered systemic contagion across at least 9 DeFi protocols and 20+ chains, including a major liquidity crisis on Aave.

avoid.net/namada-protocol-masp-ibc-transfer-logic-exploit-june-19-202622/100[CRITICAL]

On June 19, 2026, Namada Protocol's Multi-Asset Shielded Pool (MASP) was drained of approximately $600,000 in IBC-bridged assets including ATOM, USDC, OSMO, TIA, and NYM via an IBC Transfer Logic Exploit. The attack went undetected for a material period because a stale chain indexer continued displaying the drained balances as available, while live RPC queries showed zero; the discrepancy was first identified by independent security researchers at F12. Namada confirmed the exploit and issued an appeal to the responsible party to contact them, but as of the investigation date had not disclosed the specific vulnerability, recovery status, or a comprehensive postmortem.

avoid.net/secret-network-axelar-ibc-bridge-exploit-june-20268/100[CRITICAL]

On approximately June 10, 2026, an attacker exploited a missing channel-verification check in a Secret Network-side ICS-20 smart contract governing the Cosmos IBC connection between Secret Network and Axelar, minting unbacked wrapped tokens that were redeemed for approximately $4.67 million in real bridged assets. The exploit went undetected for seven days due to Secret Network's privacy-by-default design, and was only discovered on June 17 when a routine cross-chain transfer failed due to depleted escrow. Axelar's emergency committee severed all Secret and Secret-SNIP IBC connections on June 17; the stolen funds were subsequently laundered through Osmosis, bridged to Ethereum, and deposited across KuCoin, ChangeNow, and HitBTC.

avoid.net/mica-transitional-period-expiry-unlicensed-eu-crypto-platforms28/100[WARNING]

The EU Markets in Crypto-Assets Regulation (MiCA) transitional grace period for crypto asset service providers expires on July 1, 2026, with no extension available. As of May–June 2026, only approximately 183–204 firms hold full CASP authorization across the EU, leaving an estimated 75–83% of formerly registered providers unlicensed. EU users on unlicensed platforms face account restrictions, potential withdrawal freezes, loss of statutory asset protections, and possible abrupt service cutoffs beginning July 1, 2026.

avoid.net/satori-finance48/100[WARNING]

Satori Finance was a decentralized perpetual futures exchange that raised $10 million in May 2022 from Polychain Capital, Coinbase Ventures, and Jump Crypto, and processed a reported $134 billion in cumulative trading volume before announcing its shutdown on June 16, 2026. The platform cited prolonged unfavorable market conditions and insufficient revenue as the reason for closure, giving users a 30-day window to withdraw funds before a hard deadline of July 16, 2026 at 23:59 UTC. No hacks, exploits, or fraud allegations have been substantiated; the shutdown appears to be an orderly wind-down of a VC-backed DeFi project that failed commercially.

avoid.net/rhea-finance32/100[WARNING]

Rhea Finance is a chain-abstracted DeFi liquidity hub on the NEAR Protocol, formed in early 2025 through the merger of Ref Finance and Burrow Finance. On April 16, 2026, the protocol suffered a major exploit in which an attacker bypassed slippage protection in its margin trading module using intermediate asset reuse across a chain swap path, ultimately draining an estimated $18.4 million from the reserve pool — more than double the initial $7.6 million estimate. Approximately $9.2 million was subsequently returned or frozen, with the remainder still outstanding as of mid-2026; a compensation framework was announced but had not been finalized at the time of publication.

avoid.net/aztec-connect-deprecated-bridge-exploits-june-202610/100[CRITICAL]

In June 2026, two separate exploits drained a combined total of approximately $4.3–4.4 million from deprecated Aztec bridge contracts within three days. The first exploit, on June 14, targeted the abandoned Aztec Connect RollupProcessor contract (deprecated March 2023) by exploiting a settlement-boundary mismatch in zk-rollup proof verification; the second, on June 17–18, targeted a deprecated Private Rollup Bridge (closed 2022) via an unauthenticated escape hatch function. Both contracts were immutable with admin keys renounced, making intervention impossible. Aztec Labs and the Aztec Foundation confirmed the affected contracts have no connection to the current Aztec network or the AZTEC ERC-20 token.

avoid.net/audia6-crypto-laundering-service0/100[CRITICAL]

AudiA6 was a professional cryptocurrency mixing and laundering service that allegedly processed over EUR 336 million (approximately USD 389 million) in illicit funds on behalf of ransomware gangs, darknet markets, and other cybercriminals between 2022 and 2025. An international law enforcement coalition led by Europol and the U.S. Department of Justice dismantled the service on June 10, 2026, arresting its two alleged administrators in Batumi, Georgia. The service has since been formally charged in the Eastern District of Pennsylvania.

avoid.net/evita-pay-iurii-gugnin2/100[CRITICAL]

Evita Pay (operating as Evita Investments Inc. and Evita Pay Inc.) was a New York-based cryptocurrency payment company founded by Iurii Gugnin, a Russian national. On June 9, 2025, Gugnin was arrested and charged in a 22-count federal indictment in the Eastern District of New York, alleging he used Evita to funnel approximately $530 million through U.S. banks and cryptocurrency exchanges on behalf of clients at sanctioned Russian financial institutions between June 2023 and January 2025. Gugnin was ordered detained pending trial and faces potential sentences of up to 30 years per bank fraud count.

avoid.net/meta-1-coin0/100[CRITICAL]

Meta-1 Coin was a fraudulent digital asset marketed from 2018 to 2023 by Robert Dunlap through the Meta-1 Coin Trust, with false claims that the token was backed by $44 billion in gold and $1 billion in fine art. Dunlap used automated trading bots on a sham exchange called the Meta Exchange to inflate the coin's apparent price and volume, defrauding approximately 1,000 investors of more than $20 million. In April 2026, Dunlap was sentenced to 23 years in federal prison following a November 2025 conviction on mail fraud charges in the Northern District of Illinois.

avoid.net/robert-dunlap-meta-1-coin-trust0/100[CRITICAL]

Robert Dunlap, 55, of Houston, Texas, operated Meta-1 Coin Trust from 2018 to 2023, raising more than $20 million from nearly 1,000 investors by falsely claiming a digital asset called 'Meta-1 Coin' was backed by $44 billion in gold and $1 billion in artwork. Dunlap fabricated audit documents and manipulated trading prices using automated bots. He was convicted by a federal jury in November 2025 on two counts of mail fraud and sentenced on April 17, 2026, to 23 years in federal prison by U.S. District Judge LaShonda A. Hunt in the Northern District of Illinois.

avoid.net/volo-protocol47/100[WARNING]

Volo Protocol is a liquid staking and DeFi vaults platform built on the Sui blockchain, offering voloSUI (vSUI) as a liquid staking token and multi-asset yield vaults. In January 2024, it was acquired by NAVI Protocol, a leading Sui lending protocol. On April 22, 2026, Volo suffered a $3.5 million exploit targeting three isolated vaults holding WBTC, XAUm, and USDC; the team pledged to absorb all user losses and approximately $500,000 was frozen on-chain, while the root cause — attributed by security researchers to a compromised privileged operator key rather than a smart contract flaw — remained under investigation at time of writing.

avoid.net/rhea-finance-exploit-april-20269/100[CRITICAL]

On April 16, 2026, Rhea Finance — the leading DeFi hub on the NEAR blockchain, formed by the March 2025 merger of Ref Finance and Burrow Finance — was exploited for an estimated $18.4 million (initially reported as $7.6 million) via a two-phase attack combining fake token pool seeding with a slippage-protection bypass in its margin trading module. Approximately $9 million in assets was subsequently recovered or frozen, including $3.291 million USDT frozen by Tether, leaving an estimated $8–9 million outstanding as of late April 2026.

avoid.net/lazarus-group-graphalgo-fake-recruiter-npm-pypi-campaign0/100[CRITICAL]

The 'graphalgo' campaign is a North Korean state-sponsored software supply-chain operation attributed to the Lazarus Group, active since at least May 2025 and publicly disclosed in February 2026. Threat actors impersonate cryptocurrency-sector recruiters using fabricated companies — most notably 'Veltrix Capital' — to deliver coding-assessment repositories seeded with malicious npm and PyPI packages that install a remote-access trojan (RAT) targeting developer systems and cryptocurrency wallets. By April 2026 the campaign had respawned under new personas including 'Blockmerce' and 'Bridgers Finance', with operatives registering a real U.S. LLC to enhance credibility.

avoid.net/yelo-yelotree0/100[CRITICAL]

Yelo, known online as @yelotree, is a crypto key opinion leader (KOL) and former professional Fortnite esports player with approximately 180,000 Twitter followers who also operated a luxury car rental business in Miami. As of May 2026, Yelo faces federal criminal charges alleging he laundered funds stolen from cryptocurrency holders through that rental business, with a potential sentence of up to 30 years. Separately, Yelo participated in undisclosed paid promotion of the Sharpei memecoin on Solana in October 2024, which subsequently suffered a documented rug pull that erased 96% of its market value.

avoid.net/granary-finance-grain42/100[WARNING]

Granary Finance was a decentralized, non-custodial lending and borrowing protocol forked from Aave V2, built by Byte Masons and an anonymous developer known as Fantom Menace, launching on Fantom in March 2022 before expanding to eight chains. The protocol raised over $5 million USDC via a community liquidity generation event in March 2023 and introduced the GRAIN governance token, but its TVL collapsed from a peak of approximately $60 million to under $200,000. By early 2025, the team announced the full withdrawal and discontinuation of Granary Finance across all chains, with GRAIN and OATH token holders migrated to the successor platform Cod3x (CDX). No regulatory actions, rug-pull allegations, or direct hacks of Granary contracts were documented; key risks include near-total value decline, deeply pseudonymous founding team, and protocol end-of-life.

avoid.net/siren-token9/100[CRITICAL]

SIREN is a BNB Chain AI-themed meme token launched in early 2025 via the Four.meme fair-launch platform. Beginning in March 2026 the token underwent a series of extreme pump-and-dump cycles, crashing roughly 90% from its all-time high of approximately $3.83 within ten days. On-chain investigators ZachXBT and BubbleMaps identified a single wallet cluster holding nearly 50% of circulating supply, linked by ZachXBT to addresses associated with DWF Labs-affiliated tokens; ZachXBT later named SIREN as one of at least six tokens subject to a coordinated market-maker manipulation playbook allegedly enabled by Bitget, alongside RAVE, RIVER, LAB, MYX, and SKYAI.

avoid.net/hypurrfi-domain-hijack-april-202657/100[CAUTIONARY]

On April 3, 2026, the frontend domain hypurr.fi of HypurrFi — a DeFi lending protocol on Hyperliquid EVM — was hijacked via a social engineering attack targeting the domain registrar Openprovider. No user funds were confirmed drained and the protocol's smart contracts remained intact throughout; the team migrated frontend operations to hypurrfi.com and subsequently recovered control of the original domain. The incident is part of a documented six-week cluster of DeFi registrar-level frontend attacks in March–April 2026 targeting Neutrl, HypurrFi, and CoW Swap.

avoid.net/brandon-michael-tardibone4/100[CRITICAL]

Brandon Michael Tardibone, 28, of Miami, Florida, was federally indicted on May 11, 2026 in the Southern District of Florida (case 1:26-cr-20181) on charges of conspiracy to commit money laundering and harboring an alien unlawfully present in the United States. Prosecutors allege he provided housing and material support to Canadian co-defendant Trenton Richard David Johnston — who allegedly orchestrated a $13 million cryptocurrency fraud scheme via social-engineering impersonation attacks — while Johnston was unlawfully overstaying his visa, and that both defendants jointly laundered more than $1 million of stolen proceeds through luxury goods and South Florida nightlife. All charges are allegations; both defendants are presumed innocent unless and until proven guilty at trial.

avoid.net/the-dao-hack-20160/100[CRITICAL]

The DAO was a decentralized autonomous organization launched on Ethereum in April 2016 that raised approximately $150 million in ETH — the largest crowdfund in history at the time. On June 17, 2016, an unknown attacker exploited a reentrancy vulnerability in its smart contract code, draining approximately 3.6 million ETH (roughly $60–70 million at the time). The incident led to a contentious Ethereum hard fork on July 20, 2016, splitting the chain into Ethereum (ETH) and Ethereum Classic (ETC), and triggered the SEC's 2017 finding that DAO tokens were unregistered securities.

avoid.net/heco-bridge-htx1/100[CRITICAL]

On November 22, 2023, the HECO Chain cross-chain bridge and the HTX exchange (formerly Huobi), both linked to entrepreneur Justin Sun, were simultaneously exploited in what security researchers attributed to a private key compromise. The HECO bridge lost approximately $87 million in various tokens; additional HTX hot wallet losses brought confirmed totals to roughly $113 million. Blockchain analytics firm Elliptic subsequently attributed the attack to North Korea's Lazarus Group, which began laundering funds through Tornado Cash in March 2024.

avoid.net/gamma-strategies33/100[WARNING]

Gamma Strategies is a non-custodial, automated concentrated liquidity management protocol operating across multiple EVM chains, allowing users to deposit assets into managed vaults (Hypervisors) that actively rebalance Uniswap V3 and similar DEX positions. On January 4, 2024, the protocol suffered a price manipulation exploit across four vaults resulting in approximately $3.4–6.2 million in losses, caused by misconfigured price change thresholds in deposit proxy settings. The protocol paused deposits, engaged OpenZeppelin for a remediation audit, and committed to a long-term user compensation plan funded by protocol revenue, though full recovery of lost funds was not guaranteed at launch of that plan.

avoid.net/edgevana69/100[CAUTIONARY]

Edgevana is a Las Vegas-based bare-metal infrastructure and node-deployment platform founded in 2019, specializing in Solana validator onboarding, RPC node provisioning, and decentralized edge compute. The company operates a liquid staking product (edgeSOL) with approximately 839,000 SOL under management and has secured notable partnerships with the Solana Foundation, Avalanche, and StackPath. No regulatory actions, fraud allegations, or significant security incidents have been identified.

avoid.net/gateio57/100[CAUTIONARY]

Gate.io (rebranded to Gate.com in May 2025) is a major global cryptocurrency exchange founded in 2013 as Bter.com by Lin Han, currently incorporated in the Cayman Islands and serving over 52 million users across more than 4,600 assets. The exchange has faced significant scrutiny including an alleged undisclosed $230 million hack in 2018 attributed to North Korean state actors, a 2025 public notice from the Cayman Islands Monetary Authority (CIMA) confirming it has never been licensed in its ostensible home jurisdiction, and a pattern of user complaints regarding account freezes, withdrawal blocks, and a disputed $LA futures incident in 2025. The exchange publishes monthly proof-of-reserves reports audited by Hacken and holds licenses in several jurisdictions including Malta (MiCA), Dubai (VARA), Cyprus (CySEC), and Australia (AUSTRAC).

avoid.net/sigma-bot4/100[CRITICAL]

SIGMA is a multi-chain Telegram trading bot operating at sigma.win that supports Ethereum, BSC, Base, Solana, Avalanche, and other networks. On May 11, 2026, a crypto trader known as Unihax0r suffered a private key compromise draining over $200,000 across Ethereum, Base, and BSC, with both affected wallets traceable exclusively to SIGMA's wallet generation infrastructure. SIGMA has published no post-mortem, security advisory, or public statement in response to the incident as of late May 2026.

avoid.net/squid-game-token0/100[CRITICAL]

Squid Game Token (SQUID) was a fraudulent Binance Smart Chain token launched in late October 2021 that exploited the global popularity of Netflix's Squid Game series. The anonymous developers embedded a smart contract mechanism preventing any investor from selling their tokens while reserving that ability exclusively for themselves. On November 1, 2021, they drained approximately $3.38 million in liquidity within minutes, crashing the price from a peak of $2,861 to nearly zero, then deleted all project communications and disappeared.

avoid.net/map-protocol18/100[CRITICAL]

MAP Protocol is a cross-chain omnichain infrastructure project founded in 2019, issuing the MAPO token and operating the Butter Bridge for cross-chain asset transfers. On May 21, 2026, an attacker exploited an abi.encodePacked hash-collision vulnerability in Butter Bridge V3.1's retry-message path, minting approximately 1 quadrillion MAPO tokens — roughly 4.8 million times the legitimate circulating supply — causing a 96% token price collapse and extracting approximately $290,000 in combined ETH and liquidity. MAP Protocol subsequently paused all bridge operations and announced plans to patch, audit, and redeploy the bridge infrastructure.

avoid.net/frontier-front18/100[CRITICAL]

Frontier (FRONT) was a chain-agnostic DeFi aggregation and non-custodial wallet platform that launched via token generation event in September 2020 and rebranded to Self Chain (SLF) in 2024. The project's founder and CEO, Ravindra Kumar, was ousted in June 2025 following allegations of involvement in a $50 million OTC crypto fraud scheme. The rebranding itself drew significant community backlash due to a 4x token supply increase (90M to 360M) conducted at a 1:1 swap ratio, which on-chain analysts characterized as a 75% effective dilution of holder value. Binance subsequently delisted SLF in September 2025 following a monitoring tag placement and exchange concerns about code transparency and governance.

avoid.net/ill-bloom-vulnerability0/100[CRITICAL]

Ill Bloom is an actively exploited cryptographic vulnerability disclosed by blockchain security firm Coinspect in July 2026, stemming from insecure pseudorandom number generators (PRNGs) used during seed phrase generation in certain lesser-known mobile software wallets. Attackers have confirmed drained at least $5 million from over 2,100 identified vulnerable addresses across Bitcoin, Ethereum, Polygon, Tron, Solana, and Rootstock, with wallets remaining at risk as of the disclosure date. The vulnerability is not a scam or fraud entity but represents an ongoing, active-exploitation security threat requiring immediate action by potentially affected users.

avoid.net/circle-usyc78/100[VERIFIED]

USYC (US Yield Coin) is a tokenized money market fund representing shares in the Hashnote International Short Duration Yield Fund Ltd., a Cayman Islands-regulated fund investing primarily in short-duration U.S. Treasury securities and reverse repurchase agreements. Originally issued by Hashnote, USYC and its issuer were acquired by Circle Internet Group in January 2025; the token is now issued by Circle International Bermuda Limited, a Bermuda Monetary Authority-licensed entity, and has grown to become the largest tokenized U.S. Treasury product on-chain by assets under management. The product carries genuine institutional-grade structure and disclosure, but access is restricted to non-U.S. persons and KYC'd institutional entities, redemption ultimately depends on centralized allowlisting and issuer-controlled smart contracts, and the fund itself was not directly implicated in the January 2025 Usual/USD0++ depeg despite serving as collateral for that episode.

avoid.net/vlad4/100[CRITICAL]

"$VLAD" is not a single token but a ticker that has been used by at least three distinct, unrelated crypto projects on Robinhood's new "Robinhood Chain" blockchain during its permissionless memecoin boom in July 2026, plus unrelated pre-existing tokens with the same ticker on other chains (a Solana pump.fun token called Vladcoin and a low-volume Ethereum token called Vlad Finance). The most notable and highest-signal use of the ticker is "Vladhood ($VLAD)", a fraudulent token promoted via a confirmed unauthorized post from the compromised X account of Robinhood CEO Vlad Tenev, which falsely claimed official Robinhood affiliation. Separately, an opportunistic copycat memecoin called "The Green Bull (VLAD)" and unverified speculation about a "$VLAD" token tied to the (subsequently halted) Vlad.fun launchpad have also circulated. No project using the $VLAD ticker has any confirmed official affiliation with Robinhood Markets or Vlad Tenev, and the ticker has become a recurring vector for impersonation and copycat-token schemes.

avoid.net/ylds68/100[CAUTIONARY]

YLDS is a yield-bearing, SEC-registered debt security issued as a tokenized face-amount certificate by Figure Certificate Company (FCC), a wholly owned subsidiary of Figure Technology Solutions, Inc. (Nasdaq: FIGR). It is the first interest-bearing transferable stablecoin to be registered under the U.S. Investment Company Act of 1940, and as of mid-2026 has approximately $540 million in circulation across Provenance Blockchain, Solana, Stellar, and Sui. While the product carries legitimate regulatory backing, parent company Figure Technology Solutions faces outstanding short-seller allegations regarding blockchain misrepresentation, lending quality, and a significant 2026 data breach affecting nearly one million customers.

avoid.net/falcon-usd-usdf42/100[WARNING]

Falcon USD (USDf) is a synthetic overcollateralized dollar token issued by Falcon Finance, a protocol incubated and backed by DWF Labs, launched publicly on April 30, 2025. As of mid-2026, USDf holds a market capitalization of approximately $1.4 billion, ranking it among the top synthetic stablecoins. The protocol has attracted significant scrutiny due to its parent firm DWF Labs facing alleged market manipulation and wash trading charges, a notable depeg event in July 2025, opaque off-chain reserve management, and concerns raised by independent DeFi risk researchers over collateral quality and centralized control.

avoid.net/paypal-usd68/100[CAUTIONARY]

PayPal USD (PYUSD) is a US dollar-pegged stablecoin issued by Paxos Trust Company, a New York-chartered limited purpose trust company regulated by the NYDFS, and marketed by PayPal. Reserves are attested monthly by an independent accounting firm and are held in cash and short-term US Treasuries, with redemption rights subject to Paxos and PayPal compliance review. PYUSD carries the same centralization risks common to bank-issued stablecoins (issuer freeze and address-wipe functions) and its issuer, Paxos, has a prior NYDFS enforcement history tied to its Binance-branded BUSD stablecoin, though PYUSD itself has not been the subject of a depeg event, and a 2023 SEC subpoena into PYUSD was closed in February 2025 without enforcement action.

avoid.net/ledger-live58/100[CAUTIONARY]

Ledger Live is the official companion application published by Ledger SAS for managing Ledger hardware wallets. The genuine application itself has no documented vulnerabilities that have led to direct fund loss, but the "Ledger Live" name and branding have been repeatedly and successfully counterfeited on major app marketplaces (Apple App Store, Microsoft Store, Google Play, Chrome Web Store), resulting in tens of millions of dollars in alleged theft from users who mistook fake listings for the real app. Separately, a genuine Ledger-published software component in the same ecosystem (the Ledger Connect Kit library) was compromised in a December 2023 supply-chain attack that briefly redirected funds from users of dApps integrating with Ledger hardware wallets.

avoid.net/cavepay18/100[CRITICAL]

Cavepay (marketed at the domain cavepay.app and via a Telegram channel) presented itself as a multi-cryptocurrency wallet service. Independent, credible reporting on the project is essentially nonexistent: no Tier 1 or Tier 2 news coverage, regulatory action, or court records were found. The only substantive third-party assessment located is an automated scam-detection aggregator that flags the site for phishing and gives it the lowest possible trust rating, and the domain no longer resolves. Given the near-total absence of verifiable information, this page should be treated as low confidence — it documents red flags and an information vacuum rather than a confirmed fraud finding or a confirmed clean bill of health.

avoid.net/peter-stokes-scattered-spider3/100[CRITICAL]

Peter Stokes, 19, a dual U.S.-Estonian national, was arrested in Finland in April 2026 on an Interpol Red Notice and extradited to the United States on July 1, 2026 to face federal charges in the Northern District of Illinois for alleged membership in the Scattered Spider cybercrime collective. Prosecutors allege Stokes participated in a May 2025 social-engineering breach of an unnamed luxury jewelry retailer in which attackers reset an employee's two-factor authentication credentials via the company help desk, stole data, and demanded roughly $8 million in cryptocurrency. All allegations against Stokes are pending trial and unproven in court; Scattered Spider as a network has been linked by U.S. authorities to more than 100 corporate intrusions and over $100 million in crypto-denominated ransom and extortion payments.

avoid.net/wanchain32/100[WARNING]

Wanchain is a blockchain interoperability project founded in 2017 by Jack Lu that operates cross-chain bridges connecting networks such as Ethereum, BNB Chain, and Cardano. On July 21, 2026, Wanchain's Cardano-to-BNB Chain bridge was exploited for approximately $10 million (515.2 million NIGHT tokens) due to a signature-reuse flaw in its TreasuryCheck validator, one of the larger cross-chain bridge exploits of 2026. The incident caused a 30-40% intraday crash in the price of NIGHT (the token of the Cardano-affiliated Midnight blockchain) and prompted Wanchain to take its bridge offline while the Midnight Foundation publicly distanced its core network from the breach.

avoid.net/trenton-johnston-crypto-social-engineering-theft-ring2/100[CRITICAL]

Trenton Richard David Johnston, a 20-year-old Canadian national, pleaded guilty on June 10, 2026 in U.S. District Court (Southern District of Florida) to conspiracy to commit money laundering in connection with a social engineering scheme that caused losses exceeding $13 million in cryptocurrency. Johnston operated as part of a broader theft ring — connected to 'The Com' hacker network — alongside co-conspirators including Miami resident Brandon Michael Tardibone and an uncharged individual identified by blockchain investigator ZachXBT as Dritan Kapllani Jr., who is alleged to be linked to approximately $19 million in total social engineering thefts. The scheme involved impersonating support representatives from Google, Trezor, and other crypto companies to trick victims into surrendering access to their digital wallets.

avoid.net/polygon-zkevm38/100[WARNING]

Polygon zkEVM was a zero-knowledge rollup network launched in March 2023 by Polygon Labs, built upon the 2021 acquisition of Hermez Network for approximately $250 million in MATIC tokens. Despite early promise — including Vitalik Buterin processing the first transaction — the chain never achieved meaningful adoption, reportedly failed to implement the cost-reducing EIP-4844 blobs upgrade, and was shut down on July 1, 2026. Assets locked in DeFi smart contracts at the time of shutdown cannot be auto-migrated and may be permanently inaccessible.

avoid.net/zero-network-zerion-l238/100[WARNING]

Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.

avoid.net/jaredfromsubway-eth-mev-bot-counter-honeypot-exploit10/100[CRITICAL]

JaredFromSubway.eth is a pseudonymously operated Ethereum MEV (Maximal Extractable Value) sandwich-attack bot that rose to infamy in 2023 and became responsible for an estimated 70% of all sandwich attacks on the Ethereum network between November 2024 and October 2025. On June 20, 2026, an unknown attacker reversed the bot's predatory logic against it, deploying 66 fake token contracts and fake liquidity pools to manipulate the bot into granting persistent token spending approvals, then sweeping approximately $7.5 million in WETH, USDC, and USDT in a single coordinated drain transaction. The stolen funds were subsequently routed through Tornado Cash, and the bot's operator — who offered a 50% white-hat bounty — has alleged they will pursue legal and law-enforcement remedies.

avoid.net/humanity-protocol-staged-hack-allegation-zachxbt18/100[CRITICAL]

Humanity Protocol is a Hong Kong-based proof-of-personhood blockchain project that raised $50 million at a $1.1 billion valuation before suffering a $32-36 million private key compromise on June 8-9, 2026. On-chain investigator ZachXBT publicly alleged the incident appeared 'possibly staged' as a coordinated exit, citing pre-hack token manipulation and suspicious market-maker activity; ZachXBT subsequently updated his assessment to separate the private key compromise from the alleged price manipulation, concluding both events likely occurred but may have been independent. The project's H token fell as much as 90% from its all-time high, wiping over $1 billion in market capitalization, and the BNB Chain token contract remained under attacker control as of mid-June 2026.

avoid.net/leva-heal-limited-fake-ledger-live-app-apple-app-store2/100[CRITICAL]

Leva Heal Limited is a UK-registered company (Companies House number 12178110) whose Apple developer account was used to publish a fraudulent application impersonating Ledger Live on the macOS App Store between April 7 and April 13, 2026. The app harvested users' 24-word seed phrases, resulting in the theft of approximately $9.5 million in cryptocurrency from at least 50 victims. Apple removed the app and terminated the associated developer account on or around April 13-14, 2026, after community reports surfaced through on-chain investigator ZachXBT.

avoid.net/axiom-solana-dex32/100[WARNING]

Axiom is a Y Combinator-backed (Winter 2025 cohort) browser-based trading terminal for Solana, founded by Henry Zhang ('Mist') and Preston Ellis ('Cal'), that aggregates decentralized exchange liquidity and offers sub-400-millisecond execution for memecoin and perpetual futures trading. In February 2026, blockchain investigator ZachXBT published evidence that senior employees, primarily business development lead Broox Bauer, used internal admin dashboards to surveil private user wallet data and allegedly front-run profitable traders for more than ten months, netting an alleged $400,000 in illicit gains. Axiom acknowledged the misconduct, revoked tool access, and pledged an internal investigation, but as of late June 2026 no criminal charges have been filed, no formal user remediation program has been announced, and the platform continues to operate.

avoid.net/a7a5-stablecoin-old-vector0/100[CRITICAL]

A7A5 is a Russian ruble-backed stablecoin issued by Old Vector LLC, a Kyrgyzstan-registered company incorporated in December 2024, operating on the Ethereum and TRON blockchains. It was created by A7 LLC, a Moscow-based cross-border payment firm 51%-owned by sanctioned Moldovan oligarch Ilan Shor and 49%-owned by Promsvyazbank, a sanctioned Russian state-owned bank. By mid-2026, A7A5 had processed over $110 billion in cumulative on-chain transactions, making it the subject of sanctions designations by the United States, European Union, United Kingdom, Canada, Switzerland, Ukraine, and other jurisdictions for its role in enabling Russian sanctions evasion and providing a settlement layer for entities seeking to bypass Western financial restrictions.

avoid.net/abracadabra-money-mim-depeg-june-202612/100[CRITICAL]

Abracadabra Money's Magic Internet Money (MIM) stablecoin experienced a severe depeg event in June 2026, falling from its $1 target to approximately $0.43–$0.50, a collapse of over 50%. The crisis built over ten days beginning June 15, 2026, and was accompanied by $994 million in cross-market liquidations and a broader crypto market downturn. Emergency measures launched June 25 — including sharply raised Cauldron interest rates and suspended Curve bribes — represent the protocol's fourth major stability incident since 2024.

avoid.net/isis-nigeria-turkey-crypto-financing-entities-nine-to-nine-manhattan-bureau-generation-currency-spider-alkaram0/100[CRITICAL]

On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated five entities as nodes in an ISIS cryptocurrency financing network: three Nigerian bureaux de change (Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited), each owned and controlled by Mukhtar Adamu Muhammad, an alleged ISIS-West Africa financial facilitator based in Lagos; and two Turkey-based money service businesses (Spider Gayrimenkul Ve Genel Ticaret Limited Sirketi and Alkaram Danismanlik Gayrimenkul Ic Ve Dis Genel Ticaret Limited Sirketi), both owned and controlled by Mohamad Alhmidan, who was previously designated by OFAC in March 2016. These entities allegedly served as the cash-conversion and hawala infrastructure through which ISIS supporters across Europe, the Middle East, and Africa routed cryptocurrency to the Islamic State.

avoid.net/mukhtar-adamu-muhammad-isis-wa-nigeria-crypto-facilitator0/100[CRITICAL]

Mukhtar Adamu Muhammad, a 35-year-old Lagos-based bureau de change operator born August 2, 1990, was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, under Executive Order 13224 for allegedly facilitating financial transfers on behalf of ISIS in West Africa (ISIS-WA/ISWAP). He is alleged to have channeled ISIS funds through three Nigerian money service businesses he owns — Nine to Nine Exchange Bureau de Change Limited, Manhattan Bureau de Change Limited, and Generation Currency Bureau de Change Limited — operating across Lagos and Kano states. The designation is reported to be the first OFAC action specifically targeting ISIS crypto financing infrastructure in West Africa.

avoid.net/miloud-abderrahmane-isis-tron-facilitator-france0/100[CRITICAL]

Miloud Abderrahmane is a French national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026 under Executive Order 13224 for providing material support to ISIS, including routing TRON cryptocurrency to ISIS-affiliated individuals in Syria and elsewhere, and for allegedly providing explosive device manufacturing instructions to ISIS supporters. OFAC published two TRON wallet addresses directly tied to him on the Specially Designated Nationals (SDN) list, making this one of very few OFAC counterterrorism designations to include specific individual on-chain wallet identifiers rather than targeting an exchange or custodian.

avoid.net/hu-xiaowei-prince-group-second-in-command2/100[CRITICAL]

Hu Xiaowei, also known as Chen Xiao'er, Hu Shi, and Wu An Ming, is a 44-year-old Chinese-born individual alleged by U.S. Treasury and Taiwanese prosecutors to be the second-in-command of Cambodia's Prince Group Transnational Criminal Organization (TCO). He was arrested in Osaka, Japan on June 14, 2026 on charges of filing falsified residency records, and was designated by OFAC on June 23, 2026 as part of the largest U.S. government action ever taken against a Southeast Asian cybercriminal network. He allegedly controlled a network of British Virgin Islands shell companies used to launder proceeds from pig-butchering cryptocurrency fraud schemes that cost American victims at least $10 billion in 2024.

avoid.net/trenton-richard-johnston2/100[CRITICAL]

Trenton Richard David Johnston is a Canadian national who pleaded guilty on June 10, 2026 in U.S. District Court in Miami to conspiracy to commit wire fraud and conspiracy to commit money laundering in connection with a social-engineering cryptocurrency theft scheme that caused at least $13.04 million in victim losses. Johnston, who was 19 at the time of his March 2026 arrest and had overstayed a U.S. tourist visa, is identified as Co-Conspirator 2 in federal filings that name Dritan Kapllani Jr. as Co-Conspirator 1 in the same 185 BTC theft. He awaits sentencing and has agreed to deportation to Canada.

avoid.net/polymarket-june-2026-supply-chain-attack38/100[WARNING]

On June 25, 2026, Polymarket, a prominent prediction market platform, suffered a supply chain attack through a compromised third-party frontend vendor. Attackers injected malicious JavaScript that drained approximately $3.1 million in pUSD from at least 11 user wallets on Polygon, with stolen funds bridged to Ethereum and converted to roughly 1,893 ETH. The incident occurred against a backdrop of a concurrent CFTC marketing-fraud investigation and a prior private key compromise in May 2026.

avoid.net/ascendex-bitmax12/100[CRITICAL]

AscendEX (formerly BitMax), a mid-tier centralized cryptocurrency exchange founded in 2018, came under acute scrutiny on June 26, 2026, when on-chain investigator ZachXBT publicly flagged the platform after widespread user reports of withdrawals frozen in an 'initiating' state for weeks with no on-chain transaction hashes generated. On-chain analysis of the exchange's publicly known hot wallets via Arkham and TRM found minimal balances of major assets including ETH, USDT, USDC, and SOL, leading ZachXBT to state the exchange is 'likely facing liquidity issues.' As of the date of ZachXBT's disclosure, AscendEX had issued no public statement addressing the allegations, no proof of reserves, and no withdrawal restoration timeline.

avoid.net/dlmc-token-bnb-chain-flash-loan-exploit18/100[CRITICAL]

DLMC (Decentralized Legacy Management Corporation) is a BNB Chain DeFi token that suffered a flash loan price manipulation exploit on June 24, 2026, resulting in a net loss of approximately $222,560 in USDT from its treasury. The project markets itself as a fully decentralized, CertiK-verified ecosystem with renounced ownership, but a design flaw in its internal price calculation allowed an attacker to drain funds in a single transaction. No team has been publicly identified, no post-exploit response has been issued, and the protocol's referral and DAO reward structure resemble patterns common in high-risk DeFi schemes.

avoid.net/abdelhakim-boukich0/100[CRITICAL]

Abdelhakim Boukich is a former Dutch national operating from Syria who was designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, for materially supporting ISIS through cryptocurrency financing. Boukich established and controls Bitcoin Xchange, a Syria-based money service business that served as a core off-ramp for ISIS-linked fundraising campaigns, processing approximately $10 million in transaction volume across hundreds of transactions with ISIS-affiliated networks. He is listed on OFAC's Specially Designated Nationals (SDN) list under the SDGT tag and is known by the aliases Abu Sulayman Alholandi and Muhammad Babili.

avoid.net/bitcoin-xchange-syria-based-isis-linked0/100[CRITICAL]

Bitcoin Xchange is a Syria-based money services business established in late 2020 and controlled by Abdelhakim Boukich, a former Dutch national operating from Syria. On June 22, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) formally designated the entity under Executive Order 13224 for materially supporting ISIS by facilitating cryptocurrency-to-cash conversions on behalf of ISIS associates across multiple countries. On-chain analysis by TRM Labs attributed approximately USD 10 million in total transaction volume to addresses linked to Bitcoin Xchange, with hundreds of transactions connected to ISIS-linked fundraising campaigns.

avoid.net/h-pay-service-plc-huione-successor-entity2/100[CRITICAL]

H-Pay Service PLC is a Cambodia-based payment company incorporated in October 2024 that U.S. regulators allege is a successor entity to Huione Pay, itself a subsidiary of the Huione Group — a conglomerate FinCEN designated as a primary money laundering concern in October 2025 for laundering at least $4 billion in illicit proceeds linked to North Korean state-sponsored cyber heists and Southeast Asian pig-butchering scam networks. On June 23–24, 2026, FinCEN proposed amending its Huione Group final rule to explicitly encompass H-Pay Service PLC and any future successors, while the DOJ simultaneously seized backend cloud infrastructure used by Huione Group subsidiaries to process billions in fraud proceeds. H-Pay is alleged to have assumed Huione Pay's branches, customer base, branding, and operational footprint specifically to circumvent the existing U.S. financial restrictions imposed on Huione Group.

avoid.net/aman-kesar-india-crypto-scam-ring2/100[CRITICAL]

A New Delhi-based cryptocurrency fraud ring, identified through on-chain analysis by blockchain investigator ZachXBT in June 2026, is alleged to have stolen over $1 million from American victims since 2025, primarily targeting elderly individuals via social engineering. The ring was exposed when a suspected money mule, Aman Kesar (X: @Amankesar11), contacted ZachXBT seeking help unfreezing 5.73 BTC (~$475,000) held by Changelly under anti-money laundering review. On-chain tracing linked the frozen funds to a cluster of confirmed social engineering thefts; Kesar subsequently deleted his X account and all public posts following the exposure.

avoid.net/noman-saleem2/100[CRITICAL]

Noman Saleem, 39, of Queens and Levittown, New York, pleaded guilty to federal wire fraud charges on September 30, 2025, and was sentenced on June 23, 2026 to 15 months in federal prison for impersonating well-known cryptocurrency influencers on Telegram to defraud investors of at least $1,415,067. Operating between December 2020 and March 2021, Saleem created fake Telegram channels mimicking legitimate influencers, charged victims $500–$600 for access to VIP subchannels, and falsely promised returns from cryptocurrency staking that never occurred. The case was prosecuted by the U.S. Attorney's Office for the District of Maryland and investigated by the FBI Baltimore Field Office.

avoid.net/unicoin-inc4/100[CRITICAL]

Unicoin Inc. is a New York City-based digital asset company founded by CEO Alexander Konanykhin and co-founder Silvina Moschini, associated with the streaming television series Unicorn Hunters. The company sold 'rights certificates' purportedly conveying future claims to Unicoin tokens, marketing them as backed by billions of dollars in real estate and pre-IPO equity. On May 20, 2025, the SEC filed a civil complaint in the U.S. District Court for the Southern District of New York alleging that Unicoin and its top executives committed securities offering fraud by materially overstating asset values, fabricating sales figures, and falsely claiming SEC registration status, raising more than $100 million from over 5,000 investors between February 2022 and the time of the filing.

avoid.net/praetorian-group-international-pgi-ramil-palafox0/100[CRITICAL]

Praetorian Group International (PGI), also marketed as PGI Global, was a multi-level marketing cryptocurrency investment scheme operated by Ramil Ventura Palafox between December 2019 and October 2021. The scheme defrauded over 90,000 investors worldwide of more than $201 million by falsely promising daily returns of 0.5–3% from Bitcoin and foreign exchange trading that was not occurring at the claimed scale. On February 12, 2026, Palafox was sentenced to 20 years in federal prison by the U.S. District Court for the Eastern District of Virginia following his September 2025 guilty plea to wire fraud and concealment money laundering.

avoid.net/arthur-hayes-maelstrom-cio-exit-liquidity-allegations22/100[CRITICAL]

Arthur Hayes, co-founder of BitMEX and Chief Investment Officer of the Maelstrom family office fund, publicly designated HYPE, ZEC, NEAR, and WLD as high-conviction portfolio holdings in May and early June 2026, then liquidated all four positions within 13 days of the initial public recommendation. On June 6, 2026, blockchain investigator ZachXBT published on-chain evidence alleging that Hayes' public promotions generated retail buy-side depth that allowed him to exit without significant slippage, characterising his followers as 'exit liquidity.' Hayes denied intentional coordination, framing the exits as normal target-based trading driven by a macro thesis shift, and published a detailed essay titled 'Reality Test' on June 8, 2026. No formal regulatory action has been announced as of the investigation date.

avoid.net/andean-medjedovic-kyberswap-indexed-finance-fugitive-active-laundering-20262/100[CRITICAL]

Andean 'Andy' Medjedovic is a Canadian national charged by the U.S. Department of Justice in February 2025 with five federal counts related to the alleged theft of approximately $65 million across two DeFi exploits: the 2021 Indexed Finance hack ($16.5M) and the 2023 KyberSwap exploit ($48.8M). He has been a fugitive since December 2021, evaded extradition after a Serbian court rejected a Dutch arrest warrant in late 2024, and as of April 2026 wallets attributed to him by law enforcement had routed approximately $24.88 million through Tornado Cash, with an estimated $29 million in exploit proceeds remaining in identified wallets.

avoid.net/abracadabra-finance-mim-stablecoin22/100[CRITICAL]

Abracadabra Finance is a multi-chain DeFi lending protocol that allows users to mint its USD-pegged stablecoin Magic Internet Money (MIM) against interest-bearing collateral. The protocol has suffered four significant security exploits between January 2024 and October 2025, with cumulative losses exceeding $21 million, and its MIM stablecoin depegged twice in a single week in June 2026 — reaching as low as $0.80 — due to critically thin DEX exit liquidity. As of mid-June 2026, MIM was trading approximately 18% below its $1 peg, with the protocol relying on a 140 million SPELL token incentive program to attract liquidity providers.

avoid.net/mr-parveen-india-social-engineering-scam-ring2/100[CRITICAL]

A New Delhi-based social engineering fraud operation, allegedly directed by an individual known only as 'Mr. Parveen,' was publicly exposed by blockchain investigator ZachXBT on June 19, 2026. The ring is accused of stealing over $1 million from American victims — predominantly elderly individuals — since 2025, using impersonation and account-takeover tactics across U.S. cryptocurrency exchanges, Bitcoin ATMs, Cash App, and Robinhood. The operation was inadvertently uncovered when an alleged money mule, Aman Kesar (@Amankesar11), contacted ZachXBT seeking help recovering 5.73 BTC frozen at Changelly, exposing the wider theft cluster through on-chain analysis.

avoid.net/pump-fun-solana-memecoin-launchpad-ecosystem-fraud12/100[CRITICAL]

Pump.fun is a Solana-based memecoin launchpad operated by Baton Corporation Limited that launched in January 2024 and rapidly became the dominant token creation platform on Solana, generating over $1 billion in fees by April 2025. The platform is the subject of multiple federal class action lawsuits alleging it facilitated unregistered securities sales, insider front-running via MEV infrastructure, and systemic pump-and-dump fraud affecting retail traders. Third-party analysis of over 7 million tokens launched on the platform between January 2024 and March 2025 found that 98.6% exhibited fraudulent characteristics including pump-and-dump patterns and rug pulls.

avoid.net/mastra-ai-npm-supply-chain-attack-june-20260/100[CRITICAL]

On June 17, 2026, attackers hijacked a dormant npm contributor account ('ehindero') to inject a malicious dependency ('easy-day-js') into 140+ packages across the @mastra npm scope, affecting an estimated 1.1 million+ weekly downloads. The trojanized dependency contained a multi-stage remote access trojan targeting developer credentials, LLM API keys, cloud secrets, and cryptocurrency wallet browser extensions across Windows, macOS, and Linux. Mastra and npm responded within hours by revoking the compromised account, unpublishing malicious versions, and forward-rolling clean releases.

avoid.net/rodney-burton-bitcoin-rodney2/100[CRITICAL]

Rodney Burton, a 56-year-old Miami-based crypto promoter operating under the alias 'Bitcoin Rodney,' pleaded guilty on June 15, 2026, to conspiracy to operate an unlicensed money transmitting business in connection with the HyperFund Ponzi scheme, which federal prosecutors allege collected approximately $1.89 billion from investors worldwide between 2020 and 2022. Burton personally received at least $7.85 million in fraudulent proceeds and leveraged appearances by high-profile celebrities to recruit retail investors. He was arrested in January 2024 at Miami International Airport carrying a one-way ticket to the United Arab Emirates and has been held without bail pending sentencing on July 23, 2026.

avoid.net/hyperbridge-polkadot-ethereum-bridge38/100[WARNING]

Hyperbridge is a cross-chain interoperability bridge built by Polytope Labs, connecting Polkadot to Ethereum and EVM-compatible networks using zero-knowledge proof-based consensus verification. On April 13, 2026, an attacker exploited a Merkle Mountain Range (MMR) proof verification flaw in its Ethereum gateway contract, minting approximately 1 billion bridged DOT tokens and causing realized losses subsequently revised to $2.5 million across four EVM chains. The protocol was paused, underwent a full architectural rebuild rather than a patch, and relaunched in June 2026 with structural changes to governance, proof generation, and token architecture.

avoid.net/easy-day-js-mastra-npm-supply-chain-attack0/100[CRITICAL]

On June 16–17, 2026, attackers published a typosquatted npm package named easy-day-js mimicking the legitimate dayjs date library, then used a hijacked former-contributor npm account (ehindero) to inject it as a dependency across 141–144 packages in the @mastra organization within an 88-minute window. The malicious postinstall payload functioned as a cross-platform remote access trojan (RAT) and infostealer, exfiltrating cryptocurrency wallet credentials, browser history, and developer secrets before self-deleting, with affected packages carrying a combined weekly download count exceeding 1.1 million.

avoid.net/darwin-labs-private-limited4/100[CRITICAL]

Darwin Labs Private Limited is an India-registered technology venture studio co-founded by Sahil Baghla, Ayush Varshney, and Nikunj Jain. Indian authorities allege the company designed and built the entire technological infrastructure underpinning the GainBitcoin Ponzi scheme, one of India's largest cryptocurrency frauds, involving approximately 8,000 investors and estimated losses of Rs 6,606 crore (roughly $790 million). Two co-founders were arrested by Pune Police in April 2018, and a third — Ayush Varshney — was arrested by the Central Bureau of Investigation (CBI) in March 2026 after being intercepted at Mumbai airport while allegedly attempting to flee to Sri Lanka.

avoid.net/miasma-npm-supply-chain-attack5/100[CRITICAL]

Miasma is a multi-wave, self-propagating npm supply chain attack campaign active from June 1 through at least June 10, 2026, that compromised hundreds of widely-used npm packages and dozens of GitHub repositories across organizations including Red Hat, Vapi.ai, and Microsoft Azure. The malware, a variant of the Mini Shai-Hulud credential-stealing worm associated with threat actor TeamPCP (also tracked as UNC6780), exfiltrates cloud credentials, CI/CD secrets, SSH keys, and browser-stored data including crypto wallet files, then uses stolen tokens to republish backdoored package versions and spread to additional repositories. No confirmed cryptocurrency theft or quantified financial loss from crypto assets had been publicly documented as of the investigation date, though the malware's collectors enumerate local wallet storage and the attack's credential-theft scope poses downstream risk to any crypto developer environments that installed affected packages.

avoid.net/smoking22/100[CRITICAL]

Smoking Chicken Fish (SCF) is a Solana-based meme coin launched on Pump.fun in mid-August 2024 that rapidly reached a $130 million market cap within two weeks of launch and incorporated an unusual real-world dimension as a registered nonprofit planning to build a physical church in Marfa, Texas. The project imploded in September 2024 when its de facto leader, known as 'Pastor Kelby,' was ousted by the community following allegations that he accepted undisclosed payments from derivative token projects, solicited donations directly into his personal wallet, and had a history of alleged rug pulls. The token has since declined approximately 99.6% from its all-time high, trading at fractions of a cent as of mid-2026.

avoid.net/evan-tangeman2/100[CRITICAL]

Evan Tangeman, 22, of Newport Beach, California, pleaded guilty on December 8, 2025 to RICO conspiracy for his role as a money launderer in the 'Social Engineering Enterprise,' a multi-state criminal organization that stole over $263 million in cryptocurrency between October 2023 and May 2025. He admitted to laundering at least $3.5 million in stolen proceeds and was sentenced on April 24, 2026 to 70 months in federal prison plus three years supervised release by U.S. District Judge Colleen Kollar-Kotelly in Washington, D.C. Tangeman was the ninth defendant to plead guilty in what prosecutors described as one of the largest cryptocurrency theft conspiracies ever prosecuted.

avoid.net/vortex2/100[CRITICAL]

Vortex is a cryptocurrency market-making firm whose leadership was indicted by a federal grand jury in Oakland, California on August 28, 2025, on charges of wire fraud conspiracy and wire fraud in connection with an alleged coordinated wash-trading scheme. Three Russian nationals — Gleb Gora (CEO, age 24), Sergei Ryzhkov (CFO), and Michael Vogel (Business Development Manager) — are alleged to have artificially inflated cryptocurrency token prices using automated trading bots and planned to liquidate their holdings at peak prices, leaving retail investors with losses. The indictment was publicly announced on March 30, 2026, as part of the DOJ's Operation Token Mirrors, a multi-agency undercover enforcement action targeting market-manipulation-as-a-service operations.

avoid.net/tesseradao-tsr-token-unauthorized-mint-exploit3/100[CRITICAL]

On June 1, 2026, an attacker leveraged a compromised admin key on BNB Chain to mint 99 million TSR tokens outside TesseraDAO's normal supply controls, swapping them for approximately $2.5 million in USDT and collapsing the TSR token price by approximately 99%. The exploiter subsequently bridged the stolen proceeds to Ethereum and laundered approximately 1,285.5 ETH through Tornado Cash. As of the date of reporting, TesseraDAO issued no public statement, raising unresolved questions about whether the incident constituted an external key compromise or an insider-orchestrated exit.

avoid.net/humanity-protocol-june-2026-exploit8/100[CRITICAL]

On June 8-9, 2026, Humanity Protocol suffered a coordinated cross-chain exploit in which attackers compromised seven private keys stored on a single malware-infected employee laptop, draining approximately 447 million H tokens — valued at $32-36 million — across Ethereum and BNB Smart Chain. Blockchain investigator ZachXBT initially alleged the incident was 'possibly staged' based on pre-funded attacker wallets, suspicious market-making activity, and DEX-only token dumps, though he subsequently revised his assessment, concluding the private key compromise and the earlier suspicious market-making were independent events. The H token crashed between 87-89% within hours of the attack and remained deeply depressed ahead of a 266.5 million token unlock scheduled for June 25, 2026.

avoid.net/miasma-redhat-npm-supply-chain-attack2/100[CRITICAL]

Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.

avoid.net/phala-cloud-june-2026-api-breach52/100[CAUTIONARY]

On June 1, 2026, Phala Network disclosed and patched a vulnerability in the Phala Cloud API that permitted unauthorized modification of Confidential Virtual Machines (CVMs) using Offchain KMS key management. An attacker deployed a malicious pre-launch script beginning May 31, 2026, potentially exfiltrating decrypted environment variables including AWS credentials and ECR registry keys from affected CVMs. Phala patched the vulnerability within approximately 17 hours and notified affected users directly, though the incident exposed a structural gap between the platform's confidentiality marketing and the actual security boundary enforced by its Offchain KMS configuration.

avoid.net/atm-token-bnb-chain-exploit4/100[CRITICAL]

ATM Token is an obscure BEP-20 token deployed on BNB Smart Chain that suffered a confirmed exploit on June 4, 2026, resulting in approximately $243,500 in losses. The attack was made possible by a flawed custom transferFrom() function that automatically swapped 20% of each token transfer into BSC-USD, which an attacker abused repeatedly within a single transaction. The project has no verified security audit, no public whitepaper or website, and issued no statement following the incident.

avoid.net/token-of-power-top4/100[CRITICAL]

Token of Power (TOP) is an Ethereum-based ERC-20 governance token created in March 2021 as a financial art experiment built around fractionalized ownership of a MetaMask-themed NFT, with liquidity and governance managed through a Balancer V1 pool and an Aragon DAO. On June 9, 2026, the project suffered a catastrophic governance-takeover exploit in which an attacker acquired a majority of the token's 16,384-token supply, used the Aragon DAO's absence of timelock protections to create, vote on, and execute a malicious proposal in a single transaction, minted 10 billion new TOP tokens, and drained 944.2 WETH (approximately $1.58 million) from the Balancer V1 liquidity pool. Stolen funds were laundered through Tornado Cash and no official project response had been issued as of June 10, 2026.

avoid.net/letsbonk-fun32/100[WARNING]

LetsBonk.fun, later rebranded as Bonk.fun, is a Solana-based memecoin launchpad launched on April 25, 2025 by the BONK community in partnership with Raydium Protocol. The platform rose to capture over 78% of Solana launchpad market share at its mid-2025 peak before experiencing steep decline, and suffered a domain hijack and wallet-drainer attack in March 2026. The platform's permissionless token creation model, built-in multi-wallet bundler tooling, and community reports alleging the platform hosted 'KOL-backed bundled scams' present elevated risk for retail investors.

avoid.net/pt-digi-global-konsultan0/100[CRITICAL]

PT Digi Global Konsultan is an Indonesian company used as a front for an international pig-butchering cryptocurrency fraud syndicate dismantled by Central Java Police in May 2026. The operation ran from July 2025 to May 2026 out of Sukoharjo District, Central Java, defrauding at least 133 victims — predominantly US citizens — of approximately $2.33 million USD (Rp41.1 billion). Thirty-nine suspects were arrested, including foreign nationals from Nepal and Myanmar, and Indonesian authorities are collaborating with the FBI.

avoid.net/syscoin-bridge22/100[CRITICAL]

Syscoin Bridge is the cross-chain bridge infrastructure connecting Syscoin's UTXO chain and its Network Enhanced Virtual Machine (NEVM) EVM-compatible layer. In June 2026, an attacker exploited a proof-validation parsing flaw in the bridge relay, minting approximately 5 billion unauthorized SYS tokens valued at roughly $10 million and inflating the circulating supply by an estimated 568 percent. The bridge was paused immediately and the attacker subsequently returned the funds following private whitehat negotiations, though the incident raised serious questions about audit coverage of the relay component.

avoid.net/venus-protocol-the-token-flash-loan-exploit-march-20265/100[CRITICAL]

On March 15, 2026, Venus Protocol's BNB Chain Core Pool was exploited via a donation-attack supply-cap bypass targeting the THENA (THE) token market, resulting in approximately $3.7 to $5.07 million in extracted assets and $2.15 million in residual bad debt. The attacker conducted a nine-month preparation phase funded by 7,447 ETH received through Tornado Cash, and exploited a getCashPrior() vulnerability in Venus's Compound-forked vToken contracts that had been documented in a May 2023 Code4rena audit and previously exploited on Venus's zkSync deployment in February 2025, yet was not patched across all protocol deployments prior to this larger incident.

avoid.net/apyx-finance33/100[WARNING]

Apyx Finance is a DeFi protocol that issues apxUSD, a synthetic dollar stablecoin backed primarily by preferred equity shares of digital asset treasury companies, most notably Strategy's STRC preferred stock, rather than by fiat or crypto-native collateral. On June 4, 2026, apxUSD fell to approximately $0.93 during a Bitcoin drawdown that pushed STRC below its $100 par value, a roughly 7% deviation from peg. The protocol characterized this episode as expected behavior intrinsic to its equity-backed design, a framing that drew skepticism from market participants who noted structural risks including liquidity mismatches between 24/7 crypto markets and exchange-hours equity trading, leverage stacking in downstream DeFi venues, and the protocol's exclusion of US and EU persons from participation.

avoid.net/catfi-memecoin0/100[CRITICAL]

CATFI is a Solana-based memecoin launched in early 2025 via the Pump.fun launchpad. South Korean prosecutors charged five individuals, including a ringleader known online as 'Eth Father' (surname Park), with orchestrating a rug pull that inflated the token's price approximately 1,001-fold within 26 hours before draining liquidity and abandoning the project. This case represents South Korea's first criminal prosecution of a decentralized-exchange rug pull under the Virtual Asset User Protection Act.

avoid.net/bitrefill52/100[CAUTIONARY]

Bitrefill is a Stockholm-based cryptocurrency e-commerce platform founded in 2014 that allows users to purchase digital gift cards, eSIMs, and mobile top-ups using Bitcoin and other cryptocurrencies across more than 100 countries. On March 1, 2026, Bitrefill suffered a significant cyberattack attributed to the North Korea-linked Lazarus Group (Bluenoroff subunit), in which attackers compromised an employee laptop, escalated access via legacy credentials, drained hot wallets, and exposed approximately 18,500 customer purchase records. Bitrefill stated it would cover all financial losses from operational capital and characterized this as the platform's first major security incident in over a decade of operation.

avoid.net/unicoin3/100[CRITICAL]

Unicoin, Inc. is a New York City-based cryptocurrency company that launched the Unicoin token in February 2022, promoting it as an asset-backed, dividend-paying digital asset tied to the Unicorn Hunters investment television series. On May 20, 2025, the U.S. Securities and Exchange Commission filed a civil fraud complaint against the company and three senior executives in the Southern District of New York, alleging they defrauded more than 5,000 investors through false claims that the token was backed by billions of dollars of real estate and pre-IPO equity interests when those assets were worth a fraction of the stated values. The case remains pending as of mid-2026, with Unicoin having filed a motion to dismiss in August 2025.

avoid.net/catfi2/100[CRITICAL]

CATFI is a Solana-based meme coin launched in early 2025 via Pump.fun that was the subject of South Korea's first criminal indictment for a decentralized exchange rug pull. Five suspects, including alleged ringleader Park (alias 'Eth Father'), were indicted on May 27, 2026 by the Seoul Southern District Prosecutors' Office under the Virtual Asset User Protection Act after allegedly engineering a 1,001-fold price pump within 26 hours then draining all liquidity, leaving 256 investors with approximately 900 million won (~$650,000 USD) in losses. The case is legally significant as the first application of South Korea's unfair-trading statutes to on-chain DEX conduct without a centralized platform intermediary.

avoid.net/gnosis-pay42/100[WARNING]

Gnosis Pay is a self-custodial Visa debit card platform launched in 2023 that allows users to spend stablecoins such as EURe directly from Safe smart-contract wallets at over 80 million merchants globally. On June 1, 2026, an active exploit was discovered targeting a vulnerability in the Zodiac Delay Modifier v1.1.0 and Roles Modifier v2 modules used by Gnosis Pay, allowing attackers to bypass the platform's built-in three-minute transaction delay protection and drain funds from affected Safe wallets. Gnosis co-founder Martin Köppelmann committed to covering all user losses, and a phased service restoration with new card-linked Safe accounts was announced for affected users as of June 2, 2026.

avoid.net/pump-fun-solana-labs-rico-class-action17/100[CRITICAL]

Aguilar v. Baton Corporation Ltd. (Case No. 1:25-cv-00880, S.D.N.Y.) is an active federal class action alleging that Pump.fun, Solana Labs, the Solana Foundation, and named executives operated a coordinated racketeering enterprise — referred to as the 'Solana-Pump.Fun Racketeering Enterprise' — that rigged its memecoin launchpad to benefit insiders while marketing it as a fair platform to retail investors. Plaintiffs allege aggregate retail losses between $4 billion and $5.5 billion, while the platform collected an alleged $722 million in fees. As of early 2026, defendants have filed motions to dismiss the Second Amended Complaint; no ruling on those motions has been publicly reported as of June 2026.

avoid.net/fake-metamask-update-phishing-campaign-may-20260/100[CRITICAL]

A coordinated phishing campaign active in late May 2026 impersonated MetaMask by sending fake 'mandatory 2026 system upgrade' notifications via email and push alerts, directing victims to pixel-accurate clone sites that solicited a single Permit/token-approval signature draining wallets within seconds. On-chain investigator ZachXBT placed total losses at more than $9 million across 400+ addresses on Ethereum, Polygon, Arbitrum, and Base as of May 30, 2026. The campaign is part of a sustained multi-variant operation against MetaMask users that began at least as early as January 2026; MetaMask itself is an impersonation victim and is not at fault.

avoid.net/unicoin-alex-konanykhin-silvina-moschini4/100[CRITICAL]

Unicoin, Inc. (formerly TransparentBusiness, Inc.) is a New York-based crypto company that sold 'Unicoin Rights Certificates' — instruments purportedly convertible one-for-one into future Unicoin tokens backed by real-world assets — beginning in February 2022. On May 20, 2025, the U.S. Securities and Exchange Commission filed a civil fraud complaint in the Southern District of New York against the company and four executives, alleging that the firm raised up to $110 million from more than 5,000 investors while fabricating $3 billion in sales, overstating real estate asset values by billions of dollars, and falsely marketing the certificates as SEC-registered. As of June 2026 the case remains active; Unicoin has filed a motion to dismiss and no ruling has been reported.

avoid.net/jonathan-spalletta2/100[CRITICAL]

Jonathan Spalletta, 36, of Rockville, Maryland, was charged on March 30, 2026 by the U.S. Attorney's Office for the Southern District of New York with one count of computer fraud and one count of money laundering in connection with two hacks of the decentralized exchange Uranium Finance in April 2021 that allegedly yielded approximately $54.7 million in stolen cryptocurrency. He is alleged to have laundered proceeds through Tornado Cash and converted them into rare collectibles including Magic: The Gathering cards, first-edition Pokemon sets, and antiquities. He surrendered to authorities on March 30, 2026, entered a not-guilty plea, and is awaiting trial scheduled for September 2026 before U.S. District Judge Jed S. Rakoff.

avoid.net/treasure-dao34/100[WARNING]

Treasure DAO is an Arbitrum-based NFT gaming and metaverse ecosystem centered around the MAGIC token, founded in 2021 by John Patten and Karel Vuong. In March 2022, its NFT marketplace suffered a critical smart contract exploit in which attackers purchased approximately $1.4 million worth of NFTs at zero cost by passing a zero-quantity parameter to the buyItem() function, bypassing all payment validation. The project has since undergone significant restructuring, including the shutdown of its proprietary zkSync-based Treasure Chain in May 2025, mass layoffs, and a strategic pivot toward AI agent infrastructure.

avoid.net/roger-ver22/100[CRITICAL]

Roger Ver (born 1979, San Jose, California) is an entrepreneur and early Bitcoin investor nicknamed 'Bitcoin Jesus' for his prominent role evangelizing cryptocurrency beginning in 2011. He later became CEO and Executive Chairman of Bitcoin.com and a principal promoter of Bitcoin Cash (BCH) following the 2017 hard fork. In April 2024 he was arrested in Spain on a U.S. Department of Justice indictment charging mail fraud, tax evasion, and filing false tax returns related to approximately $48 million in allegedly concealed capital gains; in October 2025 he resolved the charges without prison time by entering a deferred prosecution agreement and paying $49.9 million.

avoid.net/ethena-usde55/100[CAUTIONARY]

Ethena is a synthetic-dollar protocol launched on Ethereum in 2023, issuing USDe — a delta-neutral synthetic dollar backed by crypto spot collateral and offsetting short perpetual futures positions rather than fiat bank deposits. The protocol also issues a governance token (ENA) and a yield-bearing staked variant (sUSDe) marketed as an 'Internet Bond.' While it achieved a peak supply exceeding $14 billion in 2025, it has faced regulatory enforcement in Germany under MiCAR, a localized depeg event on Binance in October 2025, ongoing counterparty and negative-funding-rate risk critiques, and comparisons — contested by the founding team — to the failed Terra/UST model.

avoid.net/trevor-vernon-argent-capital-management2/100[CRITICAL]

Trevor L. Vernon and his firm Argent Capital Management LLC (ACM), based in Franklin, North Carolina, face a civil enforcement complaint filed July 7, 2026 by the U.S. Commodity Futures Trading Commission (CFTC) in the Western District of North Carolina. The CFTC alleges Vernon fraudulently solicited over $14.8 million from at least 60 investors between March 2022 and February 2026 by falsely claiming his commodity pool generated extraordinary profits from equity index futures, options, and crypto asset trading, while investors' funds in fact suffered consistent and catastrophic losses. The complaint further alleges Ponzi-like payments to early investors using new investor capital, misappropriation of approximately $136,000 for private air travel, and false sworn testimony to the CFTC during its investigation.

avoid.net/spiko-amundi-overnight-swap-fund-eur78/100[VERIFIED]

The Spiko Amundi Overnight Swap Fund EUR (ticker: eurSAFO) is a tokenized UCITS money market fund launched in March 2026, co-developed by French fintech Spiko and Amundi, Europe's largest asset manager with approximately €2.4 trillion under management. The EUR share class is regulated by France's Autorité des Marchés Financiers (AMF) and operates as a sub-fund of SPIKO SICAV, using fully collateralized total return swaps with Tier 1 bank counterparties to deliver yields above overnight benchmarks. As of mid-2026, eurSAFO had approximately $830 million in total asset value across five blockchain networks, ranking among the largest tokenized RWA funds globally.

avoid.net/spiko-eu-t-bills-money-market-fund78/100[VERIFIED]

Spiko EU T-Bills Money Market Fund (ticker: EUTBL) is a tokenized money market fund structured as a UCITS sub-fund of the Spiko SICAV, investing exclusively in short-term Eurozone sovereign Treasury Bills. It is regulated by the French Autorité des marchés financiers (AMF), managed by Twenty First Capital, and custodied by CACEIS Bank (a Credit Agricole subsidiary). As of July 2026 it ranks approximately #64 by market capitalization on CoinGecko with over $1 billion in assets under management, making it one of the largest tokenized real-world asset (RWA) products in Europe. No fraud, hack, or regulatory enforcement actions have been identified against Spiko or the fund.

avoid.net/usx62/100[CAUTIONARY]

USX is a Solana-native synthetic stablecoin issued by Solstice Finance, a DeFi protocol incubated by Deus X Capital, a $1 billion institutional digital-asset investment firm. Launched on September 30, 2025 with $160 million in TVL, USX is backed 1:1 by a diversified reserve of USDC, USDT, tokenized Treasuries, and delta-neutral hedged positions, with reserves attested in real time via Chainlink and Accountable. In December 2025, USX briefly depegged to $0.10 on secondary Solana DEX markets due to a liquidity crunch; the issuer attributed the event to secondary-market illiquidity rather than collateral failure, and USX subsequently restabilized near $1.00.

avoid.net/audiera-beat32/100[WARNING]

Audiera is a BNB Chain-based Web3 gaming and music platform that markets itself as the blockchain evolution of the Audition rhythm game franchise, issuing the BEAT token at TGE in November 2025. The project has attracted significant speculative trading volume, reaching a market cap briefly exceeding $2 billion in June 2026 before collapsing approximately 88% within days, raising pump-and-dump concerns among analysts. Key risk factors include anonymous or undisclosed founding team, unverified IP licensing claims relating to the original Audition game IP owned by T3 Entertainment, concentrated token distribution, and derivative-driven price action disconnected from measurable user adoption.

avoid.net/pax-gold-paxg72/100[CAUTIONARY]

PAX Gold (PAXG) is a regulated, gold-backed ERC-20 token issued by Paxos Trust Company, launched in September 2019, where each token represents one fine troy ounce of physical gold stored in Brink's vaults in London. Paxos holds a national trust charter from the U.S. Office of the Comptroller of the Currency (OCC) as of December 2025, and publishes monthly third-party attestation reports via KPMG. The issuing entity, Paxos Trust Company, entered a $48.5 million settlement with the New York Department of Financial Services (NYDFS) in August 2025 over anti-money laundering failures tied to its prior BUSD stablecoin business, which does not directly implicate PAXG but reflects compliance weaknesses at the parent firm.

avoid.net/ondo-us-dollar-yield-usdy72/100[CAUTIONARY]

Ondo US Dollar Yield (USDY) is a tokenized yield-bearing note issued by Ondo USDY LLC, a Delaware bankruptcy-remote special purpose vehicle affiliated with Ondo Finance, and backed by short-duration U.S. Treasuries, iShares Short Treasury Bond ETF shares, and bank demand deposits. The token is offered exclusively to non-U.S. persons under a Regulation S exemption, accrues yield through a rising token price or daily rebasing, and had grown to approximately $740 million in supply across ten blockchains as of early 2026. A two-year SEC investigation into Ondo Finance was closed without charges in December 2025, though ongoing risks include centralized price-setting infrastructure, limited FDIC deposit coverage on a portion of reserves, and access and composability constraints imposed by the token's on-chain allowlist system.

200 entities tracked · record updated 2026-07
Page transparency log
Last updated fingerprint: CmrCks…Vo71