EIP-7702 Wallet Delegation Faces Scrutiny After Phishing Research
Ethereum’s EIP-7702 wallet delegation feature is facing renewed scrutiny after security research presented at the USENIX Security Symposium linked a large share of analyzed authorization transactions to attacker-controlled contracts. The research found that 63% of EIP-7702 authorization transactions in the analyzed sample were connected to malicious contracts, with automated wallet-draining activity contributing to more than…
BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain
BTCPay Server has released version 2.4.2 to patch a critical vulnerability that allowed unauthenticated remote access to LND credential files, after attackers used the issue to drain merchant Lightning wallets. The project’s release notes describe a serious bug involving .macaroon files, which are used by LND to manage access permissions. In plain English, those files…
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affected seed generation on some older device versions. According to the validated incident notes, the issue relates to Coldcard Mk3 firmware versions 4.0.1 through 5.0.3, along with Mk4 and Mk5 devices before firmware 5.6.0, and Q…
Ostium Halts Trading After $18M Oracle Key Breach
Ostium Halts Trading After $18M Oracle Key Breach Arbitrum-based perpetuals exchange Ostium has suspended trading after an $18.4 million exploit tied to a compromised off-chain oracle key, highlighting again how vulnerable trading venues can be when price infrastructure fails. The attack did not appear to stem from a direct breach of Ostium’s smart contract code.…
Bitcoin BIP-361 Draft Puts Quantum Security Back On The Agenda
Reference: GitHub Bitcoin BIP-361 Draft Puts Quantum Security Back On The Agenda Bitcoin developers have introduced BIP-361, a draft proposal designed to prepare the network for a future migration away from legacy signature schemes that could become vulnerable in a post-quantum environment. The proposal, titled “Post Quantum Migration and Legacy Signature Sunset,” was authored by…
Trusted Volumes Hacker Returns 1,122 ETH, Keeps $2M Bounty
A hacker tied to the Trusted Volumes exploit has returned 1,122 ETH to the protocol, closing part of a security incident that began with a multi-million-dollar exploit earlier this year. The on-chain recovery is unusual because the attacker did not return everything. Instead, the wallet linked to the exploit sent back roughly $2 million worth…
Ethereum Research Thread Puts Sybil Resistance Back In Focus For Decentralized Networks
Ethereum Research Thread Puts Sybil Resistance Back In Focus For Decentralized Networks is a useful reminder that crypto coverage is not only about token prices. Sometimes the more important story is the infrastructure, regulation, security, or product layer sitting underneath the market noise. The immediate point is straightforward: an Ethereum Research post examines Sybil risks…
Cardano Activity Recovers After Yoroi Wallet Sync Fix
Cardano activity is showing signs of recovery after EMURGO addressed user concerns tied to Yoroi wallet syncing and connection lag. The issue was a client-side wallet problem, not a protocol exploit, and there has been no indication that user funds were lost or that the Cardano network itself was compromised. TL;DR EMURGO patched Yoroi wallet…
SecondFi Completes Refund Snapshot for Wallets Impacted by Recent Cardano Exploit
TL;DR SecondFi completed a final balance snapshot on June 26, 2026, after a Cardano wallet exploit. The snapshot covers 374 compromised wallets affected between June 21 and June 23. The snapshot is a refund-preparation step, not confirmation that users have already been paid. We have completed the final balance snapshot for affected wallets. — SecondFi…
Top Ethereum MEV Bot JaredfromSubway.eth Drained of Up to $15M in Counter-MEV Honeypot Exploit
TL;DR A prominent Ethereum MEV bot reportedly lost between $7.5 million and $15 million in a counter-MEV exploit. The attacker allegedly used fake token contracts to bait approvals and drain assets. The incident highlights approval hygiene risks for automated on-chain trading systems. Security Alert: The MEV bot JaredfromSubway.eth was exploited. — BlockSec (@BlockSecTeam) June 26,…