News linked to this event type.
According to Cointelegraph, Hacken, a blockchain security firm, released its Q1 2026 report revealing that Web3 projects suffered $464.5 million in losses due to hacking and scams during the quarter. Phishing and social engineering attacks accounted for $306 million—making them the primary source of losses. A hardware wallet scam in January alone caused $282 million in losses, representing 81% of the quarter’s total losses. Smart contract vulnerabilities led to $86.2 million in losses, while failures in access control—including compromised private keys and cloud services—resulted in $71.9 million in losses. The report notes that the largest security incidents predominantly occurred in off-chain operations and infrastructure layers—areas typically beyond the scope of traditional audits. Europe’s regulatory frameworks, MiCA and DORA, are increasingly imposing stricter requirements on security monitoring and incident response, and global regulators are also raising standards for real-time monitoring and emergency response.
According to CoinDesk, cryptocurrency exchange Kraken was extorted by a criminal group that threatened to publicly release videos of its internal systems. Kraken stated that it had previously identified and addressed two incidents involving unauthorized access by internal personnel, affecting limited customer data from approximately 2,000 accounts—0.02% of its total user base—but emphasized that its systems were never breached and customer funds remained secure at all times. Nick Percoco, Kraken’s Chief Security Officer, explicitly affirmed the company would not capitulate to criminals. Kraken has notified affected users, enhanced security controls, and is cooperating with law enforcement authorities to advance the investigation; it believes existing evidence is sufficient to identify and apprehend those responsible. Separately, Galaxy Digital recently experienced a similar cybersecurity incident, though it likewise resulted in no loss of customer funds or data.
According to CoinDesk, researchers from the University of California, Santa Barbara; the University of California, San Diego; blockchain security firm Fuzzland; and World Liberty Financial jointly published a paper warning that “LLM routers”—intermediary services positioned between users and AI models—have become a major threat to cryptocurrency asset security. The researchers discovered that 26 LLM routers are secretly injecting malicious tool calls and stealing user credentials, with one incident resulting in the complete draining of a customer’s cryptocurrency wallet worth $500,000. Additionally, by “poisoning” the router ecosystem, the researchers were able to gain control of approximately 400 downstream hosts within hours. Since sensitive data—including private keys and API credentials—is frequently transmitted in plaintext through these routers, users unknowingly expose their assets to risk. The researchers note that as McKinsey forecasts AI agents will mediate $3–5 trillion in global consumer commerce by 2030—and Binance founder Changpeng Zhao predicts AI agents’ payment volume will be one million times greater than that of humans—the current infrastructure’s security lags far behind the pace of industry development. The “weakest link” risk could thus trigger systemic, cascading crises.
According to The Block, Circle CEO Jeremy Allaire responded at a press conference in Seoul, South Korea, to criticism over Circle’s decision not to freeze the stolen USDC involved in the Drift incident. He stated that Circle fulfills its legal obligations and freezes wallets only upon instruction from law enforcement agencies or courts; unilaterally freezing assets would constitute a “major ethical dilemma.” He also revealed that Circle is engaging with U.S. legislative bodies regarding the Clarity Act, seeking to establish a “safe harbor” mechanism for stablecoin issuers in extreme circumstances—but emphasized that any such authority must be explicitly granted through legislation, not exercised unilaterally by the company.
Polkadot’s official response to the security vulnerability discovered in Hyperbridge’s Ethereum gateway contract: Hyperbridge services have been temporarily suspended to investigate the issue. This vulnerability affects only DOT tokens bridged to Ethereum via Hyperbridge and does not impact DOT tokens within the Polkadot ecosystem or DOT transferred via other cross-chain bridges. The Polkadot mainnet, parachains, and native DOT remain secure and unaffected.
According to BlockSec Phalcon, the HandlerV1 contract managed by Hyperbridge on the Ethereum network was found to contain a Merkle Mountain Range (MMR) proof replay vulnerability, resulting in approximately $242,000 in losses. The vulnerability stems from the lack of binding between proofs and requests, enabling attackers to replay historical valid proofs alongside newly forged requests to perform malicious actions—such as altering administrator privileges. In the specific incident, the attacker changed the Polkadot (DOT) token administrator and then exploited those privileges to mint additional DOT tokens for profit. Observed attack transactions include: changing the DOT token administrator and minting new tokens (losses of ~$237,400), changing the ARGN token administrator and minting new tokens (losses of ~$3,800), and host withdrawal operations. The vulnerability was discovered by PhalconSecurity and analyzed via PhalconExplorer. Previously, the Hyperbridge gateway contract was attacked, leading to the unauthorized minting and subsequent dumping of 1 billion DOT tokens on Ethereum.
According to PeckShieldAlert monitoring, approximately 1 billion Polkadot (DOT) tokens have been minted and dumped on the Ethereum network. Details of the incident are still under further verification. According to CertiK monitoring, the Hyperbridge gateway contract was attacked; the attacker forged messages to tamper with the admin privileges of the Polkadot token contract on Ethereum, and profited approximately $237,000 by minting and selling 1 billion tokens.
According to The Block, U.S. musician Garrett Dutton (stage name G. Love) lost 5.9 BTC—worth approximately $420,000—after downloading and using a counterfeit Ledger wallet app from the App Store and entering his recovery phrase. On-chain analyst ZachXBT discovered that the attacker laundered the stolen Bitcoin via the KuCoin platform. This incident once again exposes the security risks posed by fake wallet apps, reminding users to exercise heightened caution when downloading and using cryptocurrency-related applications, and to avoid entering sensitive information through unofficial channels.
According to Cointelegraph, researchers from the University of California recently revealed security risks in certain third-party AI large language model (LLM) routers that could lead to the theft of cryptocurrency assets. The study found that LLM routers—acting as API intermediaries—can read plaintext information; some routers were discovered injecting malicious code and stealing credentials. The research team tested 28 paid and 400 free routers, identifying nine routers that actively injected malicious code, two that deployed trigger-avoidance mechanisms, and 17 that accessed Amazon Web Services (AWS) credentials. One router even transferred ETH using the researchers’ Ethereum private key. The study notes that malicious behavior by routers is difficult to detect, and the “YOLO mode” present in some AI agent frameworks—which automatically executes commands—further increases security risks. Researchers recommend that developers avoid transmitting private keys or mnemonic phrases through AI agents and urge AI companies to implement cryptographic signing of responses to enhance security.
Currently, quantum threats to Bitcoin remain theoretical, but companies such as Google and Cloudflare have already begun preparations and set a target of completing post-quantum migration by 2029.
Officials from the Bank of England, the Financial Conduct Authority, and the Treasury are consulting with the National Cyber Security Centre to examine potential vulnerabilities in critical IT systems revealed by Anthropic’s latest model.
According to CoinDesk, as North Korea’s infiltration methods targeting the cryptocurrency industry grow increasingly sophisticated, security experts point out that North Korea’s cryptocurrency theft activities differ fundamentally from those of other state-sponsored hacking groups—both in motive and methodology—making it one of the most dangerous threats facing the cryptocurrency ecosystem.
OpenAI announced that during a recent industry-wide security incident, a potential security issue was identified in Axios, a third-party development library used by OpenAI. After investigation, there is no evidence that user data was accessed, systems were compromised, or software was tampered with. As a precautionary measure, OpenAI has initiated security hardening efforts, focusing on strengthening the authentication mechanism for its macOS application to prevent malicious actors from distributing counterfeit official applications. OpenAI also urges all macOS users to update to the latest version of the application as soon as possible—either via in-app updates or through official channels—to mitigate potential risks.
Sam Altman, CEO of OpenAI, responded to a Molotov cocktail attack on his residence by stating he had “underestimated the real-world impact of public narratives and emotions amid AI anxiety” and, unusually, shared family photos publicly. Altman said he understands society’s fear and unease regarding AI’s rapid advancement, noting that humanity is currently undergoing “one of the most intense technological transformations in history.” The associated risks have expanded beyond model alignment issues to systemic, societal-level challenges. AI power must not be concentrated in the hands of a few institutions; instead, broader distribution should be achieved through technological democratization and institutional constraints. The race toward AGI has evolved into a “struggle for power,” where the allure of power—akin to the “One Ring”—may drive extreme behavior. The solution lies in expanding technological accessibility and preventing any single entity from monopolizing critical capabilities. Additionally, Altman acknowledged missteps in corporate governance and conflict resolution—including decisions made during his clash with the board—and apologized for past conduct. He reaffirmed that he had previously rejected Elon Musk’s attempt to control OpenAI, a choice that safeguarded the company’s independent development path. Earlier reports indicated that Sam Altman, co-founder of OpenAI, was targeted in a Molotov cocktail attack at his home.
Circle Chief Strategy Officer Dante Disparte responded to the major security breach affecting Drift Protocol on April 1, which resulted in over $270 million in stolen funds. He stated that open financial systems must be built upon foundations of legal accountability, shared security, and rules that evolve in real time with emerging threats. Circle freezes USDC funds only when legally required—a measure reflecting its compliance obligations and safeguarding users’ assets and privacy rights. He emphasized that openness and accountability must be balanced, and all participants across the ecosystem—including protocols, wallets, infrastructure providers, exchanges, and stablecoin issuers—must jointly shoulder responsibility for security and accountability. Circle is collaborating with U.S. and international policymakers to advance stablecoin legislation, including the GENIUS Act, to establish a more modern legal framework enabling lawful, rapid intervention against illicit activities while protecting property rights and privacy—ensuring the continued resilience and robust growth of open financial systems.
Decentralized GPU cloud computing infrastructure platform Aethir confirmed that its Ethereum-related bridge contract was attacked. The team promptly disconnected the affected contract and, in collaboration with major exchanges, blacklisted the hacker’s wallet, limiting losses to under $90,000. Earlier, blockchain security firm PeckShield estimated losses at $400,000. The attacker exploited Aethir’s cross-chain smart contract, AethirOFTAdapter, to transfer stolen funds from BNB Chain to Tron. Aethir stated that its Ethereum mainnet ATH token supply remains unaffected. It plans to release a detailed compensation plan and incident analysis next week and will collaborate with exchanges including Binance, Upbit, and Bithumb to freeze funds. Web3 security platform ZeroShadow is assisting with the investigation. In 2025, Aethir achieved $127.8 million in revenue and deployed over 440,000 GPU containers globally.
According to The Block, Avihu Levy, a researcher at StarkWare, published a paper proposing the Quantum Safe Bitcoin (QSB) scheme, claiming it enables quantum-resistant transactions under Bitcoin’s existing script rules—without requiring a soft fork. This scheme replaces elliptic-curve cryptography with the RIPEMD-160 hash function via a “hash-to-signature” puzzle, thereby enhancing resilience against quantum attacks. The paper notes that QSB’s current per-transaction cost ranges from $75 to $150—significantly higher than today’s average transaction fee—and involves complex user experience; thus, it is recommended only as a “last resort.” The scheme remains constrained by script opcodes and size limits, and does not yet support all use cases—such as the Lightning Network. Compared to BIP-360—which requires protocol-level changes—QSB needs no modifications to the Bitcoin protocol, but remains experimental.
According to Reuters, Kraken has become the first cryptocurrency exchange approved for a Federal Reserve master account. However, the account is restricted: it only permits Kraken’s banking operations to access the Fedwire payment system and hold limited balances—earning no interest and ineligible for emergency lending. This move has raised concerns in the U.S. financial system regarding risk and transparency, including a call from Maxine Waters, Chair of the House Financial Services Committee, for greater disclosure of account details. Regulatory experts warn that lightly regulated crypto firms gaining direct access to the Federal Reserve’s payment system could pose operational and financial stability risks. The Federal Reserve stated that these restrictions are intended to mitigate liquidity shocks and credit risk; however, banks caution that they may impair banking system liquidity and exacerbate money laundering and operational vulnerabilities. Kraken says its bank reserves are fully backed and that it complies with bank-level anti-money laundering (AML) and customer identification requirements.
He Yi also firmly responded to external attacks targeting her personally at the end of the article, stating: “You’re clearly well-versed in attacking a professional woman—just stigmatize her by claiming, ‘She only got where she is today thanks to men,’ deliberately fabricate salacious rumors, and reduce me to a ‘trophy.’” She emphasized: “My identity isn’t granted by anyone—I forged it myself. I came, I saw, I conquered—true for my career, and equally true for my relationships.”
According to Cointelegraph, the joint U.S., U.K., and Canadian law enforcement operation “Operation Atlantic” concluded in March this year, led by the U.K.’s National Crime Agency (NCA). The operation froze over $12 million in assets suspected to be proceeds of fraud, identified more than 20,000 victims, and involved total fraud losses exceeding $45 million. The operation focused on authorized phishing attacks—a scam technique that tricks users into signing malicious authorizations, thereby granting attackers permission to transfer tokens from their wallets. Binance participated in the operation, providing account screening and fraud intelligence support; however, no funds were frozen from its platform.