Hack News
Crypto news, in-depth analysis and latest market developments tagged Hack. The COINOTAG editorial desk keeps the latest 100 articles up to date.
20
5
August 14, 2026 at 09:21 AM UTC
A Hack in the cryptocurrency ecosystem refers to any unauthorized intrusion, exploit, or breach that compromises the security of a blockchain protocol, smart contract, centralized exchange, custodial wallet, or decentralized application, resulting in the theft, manipulation, or destruction of digital assets and the personally identifiable data of users. As the digital asset industry scales toward multi-trillion-dollar valuations, the frequency and sophistication of every Hack continues to escalate, with attackers leveraging cross-chain bridge weaknesses, oracle manipulation, reentrancy bugs, private-key compromise, governance takeovers, and increasingly AI-assisted social engineering to drain liquidity from protocols once considered battle-tested. The implications of a major Hack extend far beyond immediate financial loss: a single high-profile incident can trigger regulatory scrutiny, erode trust in DeFi primitives, slow institutional adoption of a spot Bitcoin or Ethereum ETF, and reshape the security expectations placed on validators, custodians, and Layer 2 sequencers. Within the broader ecosystem, the entanglement of AI & Crypto threat models, DeFi protocol design, and exchange custody architecture means that no participant—whether a retail holder relying on a cold wallet, a DAO treasury manager, or a centralized exchange operator—is fully insulated from the cascading effects of a meaningful breach. COINOTAG tracks every notable Hack with forensic clarity, documenting the on-chain trail, the affected counterparties, the disclosed root cause, and the remediation pathway, so readers can distinguish isolated implementation flaws from systemic vulnerabilities and adjust their personal risk posture accordingly. This dedicated section consolidates verified reporting, post-mortem analyses, white-hat disclosures, and stolen-fund recovery updates so that the lessons of each Hack translate into measurable improvements across the wallets, bridges, and contracts that custody the next cycle of capital.
For developments across every coin and topic, browse the crypto news archive, or follow the breaking news feed for real-time updates.
Latest Articles
20 articlesBitcoin Wallet Maker Trezor Confirms 13,689 Customers Exposed in Breach
Trezor says a ShipMonk breach exposed 13,689 customers, but no private keys or funds were affected. Phishing risk is the main concern.
TRON (TRX) Wallet Drain at Coinsbuy Hits $7.9M
Wallets linked to Coinsbuy and TRON (TRX) lost $7.9M, with funds routed through exchanges toward Monero as investigators trace addresses.
Bitcoin (BTC) Wallet Maker Declines to Confirm $130M Loss Estimate
Coinkite declines to estimate losses after a Coldcard security breach, while external research puts the potential impact near $130 million.
Bybit Sues North Korea Over $1.5 Billion Ethereum Hack
Bybit filed a U.S. civil suit against North Korea and Lazarus over the $1.5 billion Ethereum theft and secured a freeze on traceable assets.
Bitcoin (BTC) Coldcard Hack Losses Confirmed at $111 Million
Confirmed Coldcard hack losses reach $111 million in Bitcoin, likely above $130 million, as 30.185 BTC moves for the first time.
Bitcoin at Center of $1.2 Billion Crypto Hack Wave Spanning 276 Exploits
REKT data shows 276 crypto hacks totaling $1.2B in 2026. Coldcard exploit drains 1,719 BTC, BTCPay patches critical flaw, Binance sues RedotPay for $472.8M.
Bitcoin Trading Venue Bybit Wins Expedited Discovery in $1.5B Crypto Hack Case
Crypto News A U.S. federal court has granted Bybit, a major venue for Bitcoin (BTC) and broader altcoin trading, expedited discovery in its civil action to trace assets stolen in a $1.5 billion hack tied to North Korea. The order, reflected in court records unsealed this week, gives the
Bitcoin (BTC) BTCPay Server Issues Emergency 2.4.2 Fix After Active Exploit
Bitcoin News Bitcoin (BTC) payment infrastructure came under fresh scrutiny on Friday after BTCPay Server disclosed that a severe software flaw is already being exploited by unidentified attackers. The project, an open-source and sel
Bitcoin (BTC) Long-Term Holder Supply Falls 210,000 BTC After Coldcard Breach
Bitcoin News Bitcoin (BTC) has recorded an unusual supply shift after roughly 210,000 BTC exited long-term holder wallets during the past week, according to on-chain data reviewed by COINOTAG. The decline reduces long-term holder supply from almost 15 million BTC to about 14.7 million BT
Bitcoin Security Alert After Hackers Breach 1,640 Firms
North Korean-linked hackers used fake job interviews to breach 1,640 companies in 57 countries, targeting crypto wallet keys and cloud access.
Bitcoin Targeted in North Korean Hack Campaign Across 1,640 Firms
Crypto News Bitcoin (BTC) wallets and private keys were the central objective in a North Korean hacking campaign that reached 1,640 companies across 57 countries, according to internal evidence presented by security researcher Vangelis Stikas at the Black Hat conference. The keys targete
Ethereum Wallet Threat Exposed in North Korean Hack Data With 1,640 Victims
Researcher's 22-month infiltration of North Korean servers exposed 1,640 organizations and put Ethereum wallet custody at risk.
Bitcoin (BTC) Users in Korea Avoid 1,596 BTC Coldcard Exploit
South Korea’s Bitcoin users avoided the 1,596 BTC Coldcard exploit by using manual entropy, while on-chain data confirms faulty RNG.
Bitcoin Mempool Spikes to 89,031 After Coldcard Hack
Bitcoin News Bitcoin (BTC) network activity surged after the July 30 Coldcard wallet theft began, prompting users to reorganize holdings, with unconfirmed transactions in the memory pool reaching 89,031 on Tuesday, the highest count
Bitcoin (BTC) Coldcard Bug Drains More Than 1,300 BTC
A Coldcard entropy flaw drained over 1,300 BTC, Bitcoin trades near $63,500, and Bitdeer signs a $4.7 billion Norway AI data-center deal.
Bitcoin Bridge Boltz Suspends Swaps With $262K TVL After AI Attacks
Bitcoin News Bitcoin (BTC) swap provider Boltz has suspended its non-custodial bridge service indefinitely, saying automated attacks powered by artificial intelligence are now finding vulnerabilities faster than its engineers can close th
Bitcoin (BTC) Coldcard Exploit Losses Top $100 Million
Bitcoin News Bitcoin (BTC) holders using Coldcard hardware wallets have lost more than $100 million after a firmware flaw made private-key generation predictable. The episode is a stress test for <a href='https://en.coinotag.com/tag/
Bitcoin (BTC) Active Addresses Hit 980,000 After Coldcard Hack
Bitcoin News Bitcoin (BTC) recorded its most active on-chain day since Dec. 10, 2024, after daily active addresses climbed from about 645,000 on July 30 to roughly 980,000 on July 31. The surge was not driven by fresh demand. It followed a security incident involving Coldcard hardware wa
Bitcoin (BTC) Whales Accumulate 19,610 BTC After Coldcard Exploit
Bitcoin News Bitcoin (BTC) whales used a security-driven selloff as an accumulation window, adding 19,610 BTC since July 29 while smaller holders retreated, according to on-chain data. Wallets holding between 10 and 10,000 BTC lifted
Bitcoin’s Boltz Halts Atomic Swaps With $180,860 Locked
Bitcoin News Boltz, a non-custodial swap protocol built around Bitcoin (BTC), halted all atomic swap operations on Monday after concluding that AI-assisted attackers are disco
Frequently Asked Questions
What is a crypto hack and how does it differ from a scam?
A crypto hack is a technical compromise in which an attacker exploits a vulnerability in code, infrastructure, or key management to seize digital assets without the owner's consent. Typical vectors include smart-contract bugs (reentrancy, integer overflow, faulty access control), cross-chain bridge exploits, oracle manipulation, private-key leaks, and infrastructure breaches at centralized exchanges. A hack is fundamentally different from a scam: scams rely on social manipulation to convince victims to send funds voluntarily (rug pulls, phishing, fake giveaways), whereas a hack bypasses or breaks the security controls protecting funds the user never agreed to transfer. The distinction matters legally, because most jurisdictions treat unauthorized computer access and theft of digital property as separate criminal categories, and operationally, because the remediation path—on-chain tracing, exchange freezes, bounty negotiation with the attacker, or protocol-level fork—depends on which category the incident falls under.
How do hackers steal cryptocurrency from exchanges and DeFi protocols?
Attackers use a layered toolkit that varies by target. Against centralized exchanges, the most common entry points are compromised employee credentials, malicious insiders, vulnerable hot-wallet infrastructure, and supply-chain attacks against third-party software dependencies. Against DeFi protocols, attackers typically audit the publicly verifiable smart-contract source code for logic flaws such as flash-loan-assisted price manipulation, broken access control on admin functions, missing slippage checks, or unsafe delegatecall patterns. Cross-chain bridges remain the highest-value targets because they aggregate large reserves while relying on off-chain validator sets whose signing keys can be compromised. Once funds are extracted, attackers usually route the proceeds through mixing services, privacy chains, or decentralized exchanges to obscure the trail before attempting to off-ramp through smaller centralized venues with weaker KYC enforcement.
Can stolen cryptocurrency be recovered after a hack?
Recovery is possible but far from guaranteed and depends on how quickly the trail is identified and which venues the funds pass through. Public blockchains are transparent, so on-chain forensics firms can usually map the laundering path within hours, and if the attacker sends funds to a compliant centralized exchange, that exchange can freeze the deposit at the request of the victim, law enforcement, or the affected protocol. Many DeFi teams offer white-hat bounties—typically 5 to 20 percent of the stolen amount—in exchange for the return of the remainder, and a meaningful share of high-profile hacks ultimately resolve through such negotiations. Recovery becomes substantially harder when funds reach privacy mixers, cross-chain bridges to less transparent ledgers, or peer-to-peer over-the-counter markets. Statistically, only a minority of stolen crypto is fully recovered, which is why proactive security hygiene matters far more than post-incident pursuit.
Are crypto exchanges insured against hacks, and what happens to user funds?
Insurance coverage varies dramatically by jurisdiction and operator. Some large regulated exchanges maintain commercial crime insurance policies that cover a portion of hot-wallet losses, and several have built internal reserve funds—such as Binance's SAFU or Coinbase's customer protection pool—funded by trading fees and earmarked for breach reimbursement. However, these arrangements are voluntary, not equivalent to bank deposit insurance, and typically exclude losses caused by user-side compromise such as phishing or weak passwords. In a major hack, the exchange's response usually follows one of three paths: full reimbursement from reserves, socialized losses distributed across all users (the "haircut" model), or bankruptcy proceedings in which creditors recover cents on the dollar over multiple years. Users holding assets on an exchange should review the venue's published proof-of-reserves, audited financials, and explicit insurance terms rather than assume any default safety net applies.
How can I protect my cryptocurrency from being hacked?
Effective self-custody security rests on five practical layers. First, store the majority of long-term holdings in a hardware wallet or cold wallet that never connects to internet-facing software, and verify recipient addresses on the device screen rather than on the host computer. Second, separate operational wallets used for daily DeFi activity from savings wallets, so a compromised browser session cannot drain the entire balance. Third, audit every smart-contract token approval you have ever granted using a revocation tool, because dormant unlimited approvals to deprecated protocols are one of the largest sources of preventable losses. Fourth, treat your seed phrase as the single most valuable asset you own: never type it into any website, never photograph it, and store backups in physically separated, tamper-evident locations. Fifth, slow down: most successful retail hacks rely on urgency-driven phishing emails, fake support direct messages, or malicious browser extensions, and a 30-second pause to verify the source through an independent channel defeats the majority of attacks.

