📊 Trend tracker
22 new today · 8 developing
7-day: 150 incidents, $1.00B stolen
30-day: 150 incidents, $1.00B stolen
7-day vectors: smart-contract bug (30), social engineering (12), phishing / wallet drainer (11)
Repeat targets (30d): certik (5), bitcoin (5), thetanuts (5), sanctions (4), uxlink (4)
Last 24 hours
[ADVISORY · NEW] @SlowMist_Team: 🔥Glad to support @HTX_DAO’s HTX Genesis Hackathon as a security partner! (@SlowMist_Team)
[ENFORCEMENT · NEW] Thailand Expands Crypto Mining Probe Into $300M Chinese Laundering Network (Decrypt)
[ADVISORY · NEW] A shared Quantum computer for Web3 is here, but it doesn’t run on AWS (crypto.news)
[OTHER · NEW] Franklin Templeton closes 250 Digital acquisition deal and sets up new Franklin Crypto division (CoinDesk)
[SCAM · NEW] Yi He warns of alleged impersonation scam as CoinUp denies Zhu Pan ties (crypto.news)
[ENFORCEMENT · NEW] Hut 8 agrees to $2.35 million settlement in investor suit tied to US Bitcoin merger — ~$2.4M (The Block)
[ENFORCEMENT · NEW] Treasury Sanctions Three Individuals and Six Entities for Routing Crypto to ISIS (The Defiant)
[ENFORCEMENT · NEW] OFAC Sanctions ISIS Operators for Financing Terror Group with Crypto (Chainalysis)
[EXPLOIT · NEW] @GoPlusSecurity: 🧵1/4 — ~$1.7M (@GoPlusSecurity)
[OTHER · NEW] a16z-Backed Goldfinch Finance Winds Down After Originating $100M in Loans (The Defiant)
[ENFORCEMENT · NEW] Solana treasury firm Solmate’s largest stakeholder sues board for self-dealing, fiduciary breaches (The Block)
[ADVISORY · NEW] Re7 Labs Opens $223K USDC Compensation Pool for USR Exploit Victims (The Defiant)
[ENFORCEMENT · NEW] Dormant Wallet Tied to HashFlare Fraud Moves 10,600 ETH Worth $18.5M (The Defiant)
[OTHER · NEW] @CertiK: Excited to see our CTO @kang_li join #MYBW2026 as a Star Speaker. (CertiK)
[OTHER · NEW] @tayvano_: guys 😭 https://t.co/LGBXxmyoFF https://t.co/Z6O7asZ6OP (@tayvano_)
[OTHER · NEW] @tayvano_: Oh shit Brazil’s govt also got pwn’d by Mythos. https://t.co/V0rSWLvkqt (@tayvano_)
[ADVISORY · NEW] @HalbornSecurity: What separates a high-caliber security audit from a surface-level one? 🤔 (@HalbornSecurity)
also: @HalbornSecurity[SCAM · NEW] @tayvano_: when i screamed at yall to stop getting malware’d this is NOT what i meant https://t.co/33m829Yf98 (@tayvano_)
[OTHER · NEW] @tayvano_: Politicians and security nerds will never speak the same language lmao. https://t.co/cwlZtNuJW4 (@tayvano_)
Earlier · 24–72h
[EXPLOIT · DEVELOPING · day 3] @Phalcon_xyz: .@taikoxyz was reportedly attacked, with losses exceeding $1.7M. Our initial investigation suggests the likely root cau… — ~$1.7M (@Phalcon_xyz)
also: @MistTrack_io · @PeckShieldAlert[EXPLOIT · DEVELOPING · day 4] Q2 2026 emerges as most-hacked quarter on record with 83 incidents — ~$755.0M (Cointelegraph (Security))
[EXPLOIT · NEW] @GoPlusSecurity: 🧵1/3 — ~$1.1M (@GoPlusSecurity)
[EXPLOIT · DEVELOPING · day 3] @GoPlusSecurity: 🧵1/5 — ~$15.0M (@GoPlusSecurity)
[ADVISORY · DEVELOPING · day 3] @tayvano_: Subhead: Skids still inside, still trying to find the twitter logins so they can drop a wallet drainer https://t.co/GxT… (@tayvano_)
[ADVISORY · DEVELOPING · day 2] @CertiK: “It’s getting harder to trust digital identities.” (CertiK)
[OTHER · DEVELOPING · day 3] @spreekaway: possibly funded by rival US Based Prediction Market Platform but also, yeah doesn’t look great for polymarket lol https… (@spreekaway)
[ADVISORY · DEVELOPING · day 3] @tayvano_: lmaoooooooooo (@tayvano_)
[ADVISORY · DEVELOPING · day 5] @MistTrack_io: ✨MistTrack Quarterly Update: Risk Decay Model, Connection Path Analysis, and Developer Plan (@MistTrack_io)
🧠 Deep reads
Secret Network’s Axelar Bridge Drained $4.67M via Infinite-Mint Flaw (The Defiant)
Synthetix Governance Votes to Retire sUSD, Pay Holders in Vested SNX (The Defiant)
💡 Security thought-spark
China’s $300M Thai crypto mining laundering probe underscores how mining operations can serve as high-volume fiat off-ramps; audit your miners’ payout addresses and KYC/AML flows for unusual aggregation patterns linking to sanctioned entities.
Full data: https://gmsecurity.net/briefing.json. Feedback or a source to add? hello@gmsecurity.net. George Donnelly offers Web3 development & security consulting.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.