Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.
Ravencoin rolls back blockchain after exploit
Harmony token plunges 40% after unauthorized mint
Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback — that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.
This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North Korean hacking groups.
Coinsbuy exploited for $8 milllion
Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.
Step App "move-to-earn" project shuts down
Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.
Proof of Attendance Protocol (POAP) shuts down
The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.
Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."
Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".






