Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.
Coinsbuy exploited for $8 milllion
Step App "move-to-earn" project shuts down
Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.
Proof of Attendance Protocol (POAP) shuts down
The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.
Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."
Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
Two arrested after Flare Network staking site scammed users out of 3.4 million XRP (~$8.5 million)
Two men were arrested on fraud charges, and Korean police are seeking a third. They reportedly advertised the scam project via YouTube and online articles.
- "12.3 Billion Won Crypto Scam Group Arrested", The Chosun
Triple-A hacked for $11.8 million
Triple-A did not say how much was taken or how the wallets were compromised, and said the impact was limited to "specific operational accounts" and able to be covered by treasury reserves. Blockchain analyst Specter estimated the loss at $11.8 million, stolen across the bitcoin and Tron networks.
Poolin bitcoin mining pool operator files for bankruptcy
The largest liability by far is the $163.7 million owed to roughly 11,700 people who had money in Poolin Wallet when the company froze withdrawals in September 2022, citing "some liquidity issues" during that year's crash. Instead of returning their bitcoin, Poolin handed them IOU tokens, which it never redeemed.
Poolin was founded in Beijing in 2017 and in better days accounted for almost a fifth of the bitcoin network's hashrate.
- Chapter 11 voluntary petition filed by Poolin Technology
- "Poolin, Once One of Bitcoin's Biggest Mining Pools, Files for Bankruptcy", Decrypt [archive]
42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft
The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.
Wanchain bridge on Cardano exploited for more than $9 million
Allbridge exploited for $1.66 million
Across Protocol exploited for $3.35 million
MVMT Labs files for bankruptcy
Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.
The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.
- Chapter 11 Voluntary Petition filed by MVMT Labs
- "Movement Labs files for Chapter 11 bankruptcy months after token scandal", CoinDesk
Ostium loses at least $24 million to oracle exploit
The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.
Bonzo Lend exploited for $9 million in oracle attack
Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.
Summer Finance exploited for $6 million, shuts down
Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."
- "Lazy Summer USDC Vault Exploit Post-Mortem: What Happened and What Comes Next", Summer Finance
- "Sunsetting Summer.fi and the Labs Company", Summer Finance
Dutch Knaken crypto platform collapses with $8 million in customer funds missing
Dutch prosecutors asked courts to declare the platform bankrupt and install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers, who are missing around €7 million (~$8 million). The request was approved. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.
Polymarket customers lose $2.97 million, company blames third-party vendor
Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.
Users of the SecondFi Cardano wallet lose $2.4 million in series of hacks
After the attacks commenced, SecondFi "rescued" another 129 million ADA (~$19.4 million) by moving the assets to a third party entity. They announced that an external accounting firm would verify the funds and process user claims.
About a month after the hack, SecondFi announced it would shut down operations.
Taiko bridge exploited
Highly active MEV bot known as jaredfromsubway.eth drained for $7.7 million
On June 20, an attacker used a series of contracts to cause the bot to grant token approvals that were later used to drain 4,427 ETH ($7.7 million). Some of the funds were then laundered through Tornado Cash.
Main Street USD (msUSD) loses its dollar peg
On June 20, the verification provider Accountable announced that they had "terminated its service agreement with MainStreet, effective immediately. MainStreet was unable to meet our verification standards." The sudden loss of confidence in the token caused the price to plummet as holders rushed to withdraw funds.
Main Street issued a statement, claiming that "Mainstreet remains fully backed" and that "this is an infrastructure and reporting issue, not a solvency issue." However, they noted that "while our portfolio remains fully backed, converting positions into immediate liquidity depends on prevailing market depth and market-maker appetite."
Aztec Connect hacked for a second time in less than a week
The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.
Pudgy Penguins shuts down Pudgy Party NFT game after losing millions in less than ten months
Although Pudgy Penguins CEO Lucas Netz boasted on Twitter in December about "1M+ downloads today. 10M+ downloads soon." he later admitted interest in the game had quickly died off. In a community call to announce the game's shutdown, Netz acknowledged that within months of the launch, there were only 200–300 active players. The project had lost the company millions of dollars, he confessed.
Deprecated project Aztec Connect exploited for $2.1 million
The theft is only the latest in a string of attacks targeting vulnerable legacy smart contracts, many of which cannot be deleted, paused, or changed due to blockchains' immutable nature. Raydium and DxSale are two other platforms that have recently suffered losses due to old, insecure code.
Secret bridge exploited for $4.67 million a week before anyone notices
The exploit, which occurred on June 10, went unnoticed until June 17, when a transaction failed with a message suggesting that more tokens had been bridged out of the Secret network than had been bridged in.
Secret has warned, "If you hold Axelar-bridged saXXX tokens on Secret, please be aware their backing was affected and your funds may be lost."
Raydium users lose $1.34 million after legacy smart contract exploited
Raydium has said it will compensate users who lost funds in the exploit.
Humanity Protocol loses $36 million to employee laptop compromise
With the keys, the attacker stole more than 6 million of Humanity's H token, then used other keys to upgrade a bridge and drain 141 million more tokens. With the bridge access, they also minted 300 million new H tokens. The attacker then quickly swapped the ill-gotten tokens for ETH, causing the H price to plummet by 80–90%.
Humanity Protocol markets itself as a competitor to Sam Altman's World (formerly Worldcoin), a decentralized identity project that aims to use iris scans to prove that users are unique humans. Humanity raised $20 million in 2025 from Pantera Capital and Jump Crypto.
Thief steals remaining 7,200 unsold The Kiss NFTs in digital museum heist
Only about a quarter of them ever sold, leaving about 7,200 of them on the digital shelves. That is, until they were stolen (or, as the museum put it, "transferred from the wallet without authorization"). If valued at their sale price the stolen NFTs would be worth €13.32 million (US$15.3 million), though it's hard to argue the thief could've ever sold them for that amount given the museum had failed to do so for several years.
The stolen NFTs were soon made even less appealing to prospective buyers when the museum un-linked the image files from the digital assets, and OpenSea blocked them from trading.
- Hacker stahl dem Belvedere 7200 NFT-Zertifikate von Klimts "Kuss", Der Standard (in German) [archive]
Gravity Bridge drained of $5.4 million
DxSale exploited for $7.3 million
SquidRouterModule, unrelated to Squid Router, exploited for $3.2 million
The name led to some confusion due to the similarly named Squid Router, which is not related. It's not clear if the users who installed the module were aware that the two projects were separate.
Polymarket loses $700,000 to private key compromise
RetoSwap users lose $2.7 million to Haveno vulnerability
Because Monero is a privacycoin, a type of cryptocurrency that obscures transaction details including sender and receiver wallets, it is not feasible to trace the stolen assets.
Largest North American bitcoin ATM operator, Bitcoin Depot, files for bankruptcy
The company's bankruptcy filing reports between $10 million and $50 million in both assets and liabilities. In a recent financial disclosure, the company had reported a 49% year-over-year reduction in revenue and a net loss of $9.5 million for the year. The company had also suffered a $3.67 million hack in April.
Bitcoin Depot has blamed a challenging state-level regulatory environment for its bankruptcy, pointing to a series of regulatory restrictions and outright bans on crypto ATMs, which are a major conduit for crypto scams. An FBI report on Internet crime in 2024 showed 11,000 reports of fraud involving crypto ATMs – a 99% increase from the prior year. Almost $250 million was reported lost due to such scams, with a majority of it coming from victims over 60 years old. Several states have responded by introducing laws imposing strict compliance requirements or transaction limits on ATM operators, and Indiana and Tennessee have both recently banned the kiosks entirely. Additionally, the company is defending against lawsuits from both Massachusetts and Iowa, which argue that the company uses a misleading pricing structure, knowingly enables crypto scames, and maintains a predatory refund policy.
- "Bitcoin Depot Initiates Voluntary Chapter 11 Process to Facilitate an Orderly Wind-Down and Sale of the Company’s Assets", Bitcoin Depot press release [archive]
- Issue 92, Citation Needed [archive]
- Issue 105, Citation Needed [archive]
- Chapter 11 Voluntary Petition
Verus bridge hacked for $11.6 million
Verus halted the entire Verus network after the exploit was detected in hopes of limiting further damage.
The exploiter later accepted a bounty offer by Verus, returning 4,052 ETH (~$8.5 million) while keeping the remaining ~25% as a "bounty".












![A circle overlaid with ][ symbols, followed by "Ostium" in orange capitals](https://primary-cdn.web3isgoinggreat.com/entryImages/logos/resized/ostium_300.webp)

















