Hack News
Crypto news, in-depth analysis and latest market developments tagged Hack. The COINOTAG editorial desk keeps the latest 100 articles up to date.
20
5
July 21, 2026 at 02:56 PM UTC
A Hack in the cryptocurrency ecosystem refers to any unauthorized intrusion, exploit, or breach that compromises the security of a blockchain protocol, smart contract, centralized exchange, custodial wallet, or decentralized application, resulting in the theft, manipulation, or destruction of digital assets and the personally identifiable data of users. As the digital asset industry scales toward multi-trillion-dollar valuations, the frequency and sophistication of every Hack continues to escalate, with attackers leveraging cross-chain bridge weaknesses, oracle manipulation, reentrancy bugs, private-key compromise, governance takeovers, and increasingly AI-assisted social engineering to drain liquidity from protocols once considered battle-tested. The implications of a major Hack extend far beyond immediate financial loss: a single high-profile incident can trigger regulatory scrutiny, erode trust in DeFi primitives, slow institutional adoption of a spot Bitcoin or Ethereum ETF, and reshape the security expectations placed on validators, custodians, and Layer 2 sequencers. Within the broader ecosystem, the entanglement of AI & Crypto threat models, DeFi protocol design, and exchange custody architecture means that no participant—whether a retail holder relying on a cold wallet, a DAO treasury manager, or a centralized exchange operator—is fully insulated from the cascading effects of a meaningful breach. COINOTAG tracks every notable Hack with forensic clarity, documenting the on-chain trail, the affected counterparties, the disclosed root cause, and the remediation pathway, so readers can distinguish isolated implementation flaws from systemic vulnerabilities and adjust their personal risk posture accordingly. This dedicated section consolidates verified reporting, post-mortem analyses, white-hat disclosures, and stolen-fund recovery updates so that the lessons of each Hack translate into measurable improvements across the wallets, bridges, and contracts that custody the next cycle of capital.
Latest Articles
20 articlesCardano Bridge Exploit Drains 515 Million NIGHT Tokens
Cardano News A security breach on a Cardano cross-chain bridge drained roughly 515 million Midnight (NIGHT) tokens, sending the privacy network's token to an all-time low near $
Ethereum-Based Summer.fi Shuts Down After $6.04M USDC Vault Exploit
Crypto News Summer.fi, the Ethereum-based decentralized finance platform, will wind down operations after a $6.04 million exploit drained two of its USDC vaults, the company confirmed. The team said the July 6 attack on its Lazy Summer Protocol destroyed the capital needed to rebuild, le
Hedera Oracle Exploit Drains $9M From Bonzo Lend, Including 34.5M Wrapped HBAR
HBAR News Hedera-based lending protocol Bonzo Lend lost roughly $9 million after an attacker manipulated the price of the SAUCE token used as collateral, draining the pool for far more than was ever deposited. The incident, disclosed in a preliminary report over the weekend, struck a dec
Ethereum Foundation AI Agents Uncover Validator-Crashing Bug CVE-2026-34219
Ethereum News Ethereum's core developers turned coordinated AI agents loose on the network's own client software and surfaced a genuine, remotely triggerable vulnerability capable of knocking validator nodes offline. The flaw lived inside gossipsub, the peer-to-peer messaging layer that
Hedera HBAR Exploit Tally Climbs to $5.25 Million in Bridged Funds
HBAR News Hedera (HBAR), the enterprise-focused distributed ledger, was hit by an exploit that has driven tracked losses past $5 million, according to on-chain data first surfaced over the weekend. The incident came to light on Saturday when blockchain trackers flagged suspicious outflow
Cardano’s EMURGO Steps Down From Pentad Governance After $2.4M Hack
Cardano News Cardano (ADA) came under renewed pressure after EMURGO, one of the network’s three founding entities, formally stepped down from the Pentad — the cooperative body that steers Cardano’s strategic governance. The token slipped
BONK Treasury Loses $20M to Malicious Governance Vote
BONK News South Korea's three largest digital-asset exchanges — Upbit, Bithumb and Coinone — placed BONK, the Solana-based meme coin, under a formal trading-caution designation on July 7. The exchanges' official announcements state the flag took effect at 4:00 p.m. local time and runs th
BONK DAO Loses $20 Million in Malicious Governance Attack
BONK News BONK (BONK), the largest meme token on Solana, suffered an estimated $20 million treasury drain after attackers pushed through a malicious on-chain governance proposal, the project confirmed. The stolen tokens have begun moving toward centralized exchanges, raising fears of imm
Summer.fi Loses $6 Million in Active DeFi Exploit, SUMR Token Slides
Crypto News A live exploit drained roughly $6 million from Summer.fi, the front-end for the onchain Lazy Summer vault protocol, in the second recorded DeFi breach of July. Security monitoring surfaced the incident on Monday morning, with on-chain data pinning early losses near $6 million
Cardano SecondFi Breach: 129M ADA Worth $18.5M Moved by White Hat
Cardano News Cardano (ADA) is at the center of an $18.5 million wallet breach after a self-described white hat hacker moved 129 million ADA out of vulnerable SecondFi wallets. The disclosure, made on June 25 by Cardano founder Charles Hos
Bitcoin Near $61K Amid Extreme Fear as ADA Yoroi Exploit, Solana DEX Mania Grip Markets
Crypto News Activity on Solana-based decentralized exchanges turned frenetic over the past 24 hours, with speculative trading pairs delivering extreme moves. The most-watched altcoin pairs included FITNESS/SOL, which led trending scr
Bitcoin Near $66K as Aztec Hack Drains $2.19M, Dunamu-Naver Merger Faces Probe
Crypto News Bitcoin clawed back toward the $66,000 mark, yet the recovery is showing little conviction. On-chain data points to fading strength: trading volumes are thinning and network activity remains subdued, while momentum gauges and on-balance volume still sit near <a href="https://
Nvidia Raises $25B for AI Push as Aztec Loses $2.19M to Settlement Exploit
Crypto News Chipmaker Nvidia returned to the debt market on Monday with a $25 billion investment-grade bond sale, its first since 2021 and one of the largest corporate offerings of the year. Investor demand was extraordinary: order books swelled past $85 billion, more than three times th
Humanity Token Hack Halts Deposits, Anthropic Blocks Fable 5, Bitcoin Holds Near $65K
Crypto News Crypto community channels lit up over Humanity (H), an altcoin where a security breach forced several exchanges to suspend deposits and withdrawals while traders braced for a June 25 token unlock. With Korean-exchange bal
SpaceX Stock Lists on Solana, ETF Assets Top $1B as Raydium Suffers $1.34M Exploit
Solana News SpaceX shares are poised to begin trading on Solana the same day the company is expected to list on Nasdaq, an aggressive push to bring newly listed U.S. equities on-chain from day one. A tokenized version called SPCX, issued by regulated brokerage Backpack alongside tokeniza
Morpho Raises $175M, Zoomex Logs $5.25B Volume, $1.58M TOP Governance Hack
Crypto News Derivatives venue Zoomex closed May with execution metrics that underscored how technical reliability draws volume even when Bitcoin chops sideways. The platform reported 24-hour futures turnover above $5.25 billion again
SEC Veteran Joins Backpack Board, GSR Wins FINRA Nod as $36M Humanity Exploit Rattles Market
Crypto News Crypto exchange Backpack US has appointed former U.S. Securities and Exchange Commission Acting Chairman Michael S. Piwowar to its board of directors, a signal of the firm's deepening U.S. ambitions. Piwowar, an Obama-era appointee who served as a commissioner from 2013 to 20
Bitcoin Stalls Near $62.6K as Strategy Adds 1,550 BTC, Humanity Hack Drains $32M
Bitcoin News The recent Bitcoin rebound off Friday's sub-$60,000 plunge looks more like a relief rally than a genuine turn, analysts caution. Traders argue the asset must reclaim the $79,000-$80,000 zone before the move qualifies as
Robinhood Completes $180M WonderFi Deal as Radiant Capital Winds Down After $50M Hack
Crypto News Robinhood Markets has officially closed its $180 million acquisition of Toronto-based digital asset firm WonderFi, marking the U.S. retail brokerage's formal entry into Canada's regulated crypto market. The deal, first announced in May 2025, brings WonderFi's two flagship pla
Gravity Bridge Hit by $5.4M Exploit as Bitcoin ETFs Bleed $2.97B Amid Peak Sentiment
Crypto News Gravity Bridge, a cross-chain protocol moving assets between Ethereum and the Cosmos ecosystem, was drained of roughly $5.4 million in a fresh exploit that has forced validators to suspend operations. On-chain analysts spotted suspicious outflows late Saturday, with early for
Frequently Asked Questions
What is a crypto hack and how does it differ from a scam?
A crypto hack is a technical compromise in which an attacker exploits a vulnerability in code, infrastructure, or key management to seize digital assets without the owner's consent. Typical vectors include smart-contract bugs (reentrancy, integer overflow, faulty access control), cross-chain bridge exploits, oracle manipulation, private-key leaks, and infrastructure breaches at centralized exchanges. A hack is fundamentally different from a scam: scams rely on social manipulation to convince victims to send funds voluntarily (rug pulls, phishing, fake giveaways), whereas a hack bypasses or breaks the security controls protecting funds the user never agreed to transfer. The distinction matters legally, because most jurisdictions treat unauthorized computer access and theft of digital property as separate criminal categories, and operationally, because the remediation path—on-chain tracing, exchange freezes, bounty negotiation with the attacker, or protocol-level fork—depends on which category the incident falls under.
How do hackers steal cryptocurrency from exchanges and DeFi protocols?
Attackers use a layered toolkit that varies by target. Against centralized exchanges, the most common entry points are compromised employee credentials, malicious insiders, vulnerable hot-wallet infrastructure, and supply-chain attacks against third-party software dependencies. Against DeFi protocols, attackers typically audit the publicly verifiable smart-contract source code for logic flaws such as flash-loan-assisted price manipulation, broken access control on admin functions, missing slippage checks, or unsafe delegatecall patterns. Cross-chain bridges remain the highest-value targets because they aggregate large reserves while relying on off-chain validator sets whose signing keys can be compromised. Once funds are extracted, attackers usually route the proceeds through mixing services, privacy chains, or decentralized exchanges to obscure the trail before attempting to off-ramp through smaller centralized venues with weaker KYC enforcement.
Can stolen cryptocurrency be recovered after a hack?
Recovery is possible but far from guaranteed and depends on how quickly the trail is identified and which venues the funds pass through. Public blockchains are transparent, so on-chain forensics firms can usually map the laundering path within hours, and if the attacker sends funds to a compliant centralized exchange, that exchange can freeze the deposit at the request of the victim, law enforcement, or the affected protocol. Many DeFi teams offer white-hat bounties—typically 5 to 20 percent of the stolen amount—in exchange for the return of the remainder, and a meaningful share of high-profile hacks ultimately resolve through such negotiations. Recovery becomes substantially harder when funds reach privacy mixers, cross-chain bridges to less transparent ledgers, or peer-to-peer over-the-counter markets. Statistically, only a minority of stolen crypto is fully recovered, which is why proactive security hygiene matters far more than post-incident pursuit.
Are crypto exchanges insured against hacks, and what happens to user funds?
Insurance coverage varies dramatically by jurisdiction and operator. Some large regulated exchanges maintain commercial crime insurance policies that cover a portion of hot-wallet losses, and several have built internal reserve funds—such as Binance's SAFU or Coinbase's customer protection pool—funded by trading fees and earmarked for breach reimbursement. However, these arrangements are voluntary, not equivalent to bank deposit insurance, and typically exclude losses caused by user-side compromise such as phishing or weak passwords. In a major hack, the exchange's response usually follows one of three paths: full reimbursement from reserves, socialized losses distributed across all users (the "haircut" model), or bankruptcy proceedings in which creditors recover cents on the dollar over multiple years. Users holding assets on an exchange should review the venue's published proof-of-reserves, audited financials, and explicit insurance terms rather than assume any default safety net applies.
How can I protect my cryptocurrency from being hacked?
Effective self-custody security rests on five practical layers. First, store the majority of long-term holdings in a hardware wallet or cold wallet that never connects to internet-facing software, and verify recipient addresses on the device screen rather than on the host computer. Second, separate operational wallets used for daily DeFi activity from savings wallets, so a compromised browser session cannot drain the entire balance. Third, audit every smart-contract token approval you have ever granted using a revocation tool, because dormant unlimited approvals to deprecated protocols are one of the largest sources of preventable losses. Fourth, treat your seed phrase as the single most valuable asset you own: never type it into any website, never photograph it, and store backups in physically separated, tamper-evident locations. Fifth, slow down: most successful retail hacks rely on urgency-driven phishing emails, fake support direct messages, or malicious browser extensions, and a 30-second pause to verify the source through an independent channel defeats the majority of attacks.

