Skip to main content
AVOID.NET

Investigation Queue

Community-submitted investigation requests. 1 pending

Queued (1)

  • QueuedLiquid Network (Blockstream)pri 9On September 6-7, 2026, attackers drained roughly 4,000 BTC (~$320 million) from the federation reserve wallet backing Blockstream's Liquid Network, a Bitcoin sidechain used by several exchanges to move BTC and mint L-BTC. This is one of the largest crypto hacks of 2026 and highlights systemic risk in Bitcoin sidechain/custody infrastructure. No existing AVOID.NET page covers Liquid Network or Blockstream's federation model, despite adjacent entities (e.g. Coldcard/Coinkite firmware exploit) already being tracked. Key findings: - Attackers withdrew ~4,000 of 4,200 BTC (~$320M) from Liquid's multisig federation wallet on Sept 6, 2026, exploiting a bug in the Elements-based federation logic - Attackers self-identified as 'white hats' via an OP_RETURN message ('we are whitehats. contact us on chain') and negotiated with Blockstream via encrypted on-chain messaging - As of Sept 8, 2026, ~3,400 BTC (~$270M, 85%) was returned; ~598 BTC (~$47M) remains withheld pending patch deployment across all federation nodes - Security researchers and journalists dispute the 'white hat' framing, noting the retained ~$47M functions more like an extortion bounty than a disclosed-vulnerability reward - Network was paused and is being restarted only after every federation node installs the patch, raising questions about the long-term viability and trust model of the sidechain Sources: - Bitcoin Network Says $320 Million Stolen in Latest Crypto Hack: https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack - A $320 Million Hack Exposes the Cracks in Crypto's Plumbing: https://www.bloomberg.com/news/articles/2026-09-08/bitcoin-s-latest-hack-puts-key-crypto-vulnerability-in-spotlight - Liquid Network hack: Whitehats return 3,400 BTC: https://www.coindesk.com/markets/2026/09/08/white-hat-hackers-return-most-of-usd320m-bitcoin-taken-from-liquid-network - 'White hat' hackers take $47 million bounty after $320 million crypto theft: https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward - 2026's Biggest Hack To Date: Attackers Drained USD 319 Million in Bitcoin From Liquid Network, Then Returned 85% of Funds: https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds Scout priority: 9/10 | Urgency: high | Category: bridgeSep 10

Fulfilled (94)

  • FulfilledPhoenix tradepri 5Sep 10
  • FulfilledTaptaptappri 5Sep 10
  • FulfilledStonkSep 9
  • FulfilledSkrSep 9
  • FulfilledFomo tokenSep 9
  • FulfilledFake GTA 6 Leak Wallet-Drainer Campaignpri 5A phishing site discovered September 1, 2026 poses as a seller of a leaked GTA 6 copy (offered for $50 or 1 SOL) and runs wallet-drainer code specifically targeting Solana wallets (with a separate script for seven EVM chains). The site profiles wallet balances, leaves only fee-covering dust, and can silently change payout destinations server-side, and is actively able to drain victims connecting a wallet. This is a live, ongoing scam vector aimed at Solana users not yet in the AVOID.NET corpus. Key findings: - Discovered/reported by Malwarebytes on September 1, 2026; site mimics an official GTA 6 fan countdown using real Rockstar promotional assets - Solana-specific drainer component calculates victim balance and transfers out all but fee reserves; a separate multi-chain script targets Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base and Fantom - Drainer pulls operator ID/config from a remote server, allowing attackers to redirect stolen funds without changing the front-end site, and includes anti-detection measures against automated scanners - GTA 6's real launch is not until November 19, 2026, meaning any pre-release 'leaked copy' offer is fraudulent by definition Sources: - Fake GTA 6 leaked copy drains your crypto wallet: https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet - Dangerous Fake GTA 6 Leak Site Drains Crypto Wallets 2026: https://www.tronweekly.com/fake-gta-6-leak-site-drains-sol-eth-wallets/ Scout priority: 5/10 | Urgency: high | Category: otherSep 9
  • FulfilledKylie Jenner X account hack / $KYLIE Solana memecoin scampri 6On August 24-26, 2026, Kylie Jenner's verified X account (~39.5M followers) was compromised and used to promote a Pump.fun-launched Solana memecoin ($KYLIE), which spiked to a ~$1.2 million market cap before collapsing 68-90%. This is part of an escalating, repeatable campaign pattern of hijacking verified celebrity/brand X accounts to pump short-lived Solana tokens (also used against SpaceX/Starlink for SCATMAN in July 2026, netting ~$125K, and Robinhood CEO Vlad Tenev's account, already tracked on AVOID.NET as 'vladhood-vlad-memecoin-scam') — indicating an organized, recurring scheme rather than an isolated incident. Key findings: - Kylie Jenner's X account posted, then deleted, a Pump.fun link (handle 'cutekjenner') and a Solana contract address on August 24, 2026 - The $KYLIE token spiked to roughly $1.19-1.21 million market cap before crashing 68-90% within a short window - Same campaign pattern was used against SpaceX/Starlink's account in July 2026 (SCATMAN token, ~$125,000 extracted) and Robinhood CEO Vlad Tenev's account in late July 2026 (Vladhood, ~$1.2 million extracted) — the latter already tracked on AVOID.NET - X has not confirmed whether its anti-scam account-lock protections were active or failed during the Jenner incident Sources: - Kylie Jenner's X Account Reportedly Hacked to Push Meme Coin That Crashed 68%: https://finance.yahoo.com/markets/crypto/articles/kylie-jenners-x-account-reportedly-041314498.html - CoinDesk: Kylie Jenner's X account was reportedly hacked to promote a meme coin called $KYLIE: https://x.com/CoinDesk/status/2092351344401064312 - Kylie Jenner's X Account Was Hacked for Crypto: X Never Confirmed Its Anti-Scam Lock Deployed: https://www.techtimes.com/articles/325433/20260825/kylie-jenners-x-account-was-hacked-crypto-x-never-confirmed-its-anti-scam-lock-deployed.htm Scout priority: 6/10 | Urgency: medium | Category: otherSep 9
  • FulfilledAnsem / $ANSEM ("Black Bull") creator-coin controversypri 6Prominent Solana trader/influencer Ansem became the center of a creator-coin rug-pull controversy in late June 2026: an anonymous developer deployed an ANSEM-branded token, sent Ansem 650 million tokens for free (peak value $71M+), and Ansem then airdropped roughly $7 million of the token to followers to build a holder base — a pattern investigators say concentrates supply and risk in the hands of an influencer who did not create or officially endorse the token, and who publicly denied intending a rug pull after backlash. Key findings: - No single official $ANSEM token exists; multiple unaffiliated tokens using the name appeared simultaneously on Solana after Ansem's name began trending - An anonymous deployer spent ~$6,300 to launch a token and sent 650 million tokens directly to Ansem's wallet at no cost - Between June 27-29, 2026, Ansem airdropped ~$7 million worth of ANSEM tokens to Solana users; his wallet held over $71 million of the token at peak - Ansem publicly denied intent to conduct a '$2 million rug pull' amid community backlash over supply concentration - Case exemplifies the broader 2026 'creator coin' meta on Solana where influencers profit from fees/allocations on tokens bearing their name/likeness without creating them Sources: - What is $ANSEM? The Solana influencer memecoin: https://crypto.news/what-is-ansem-coin-solana-influencer-memecoin-explained/ - Ansem responds to creator token controversy, denies intent to exploit investors: https://www.bitget.com/news/detail/12560605483689 Scout priority: 6/10 | Urgency: medium | Category: individualSep 9
  • FulfilledAquifer (Solana AMM)pri 8Aquifer, a Solana-based automated market maker, lost roughly $2.5 million on August 31, 2026 to an exploit that drained wallets on both Solana and Ethereum. The team believes it stemmed from compromised wallet access rather than a smart-contract bug, offered the attacker a 20% white-hat bounty for returning 80% of funds by a September 3, 2026 deadline, and as of the latest reporting no return has been confirmed, leaving user/protocol funds unresolved and the root cause undisclosed. Key findings: - Attacker-controlled wallets on Solana and Ethereum drained ~$2.5 million from Aquifer on August 31, 2026, first flagged by blockchain monitor Defimon - Aquifer's Solana upgrade authority cryptographically signed an on-chain message offering the attacker a 20% bounty to return at least 80% of stolen funds by Sept 3, 2026, 14:00 UTC, explicitly excluding law enforcement cooperation from the offer - As of early September 2026 reporting, no public confirmation that any funds were returned; the exact compromise vector (wallet-key compromise vs. contract bug) remains unestablished - Incident occurred amid a spike in August 2026 exploits (reported ~50 hacks/~$159.5M in losses across DeFi that month) Sources: - Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty: https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/ - Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty (CoinDesk): https://coindesk.cc/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty-108352.html - Aquifer Exploit Drains $2.5M as August Hacks Hit 50 [2026]: https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/ Scout priority: 8/10 | Urgency: high | Category: protocolSep 9
  • FulfilledTeraswitch (Solana validator hosting concentration incident)pri 6A routing failure at data-center/network provider Teraswitch on August 12, 2026 knocked out its autonomous system AS20326, which alone represented 27.34% of all staked SOL, taking ~90 validators (28.83% of staked SOL, including Solana's second-largest validator Helius) offline simultaneously and pushing the network within roughly 4.5 percentage points of its one-third finality-halt threshold. This exposes a systemic infrastructure-concentration risk in Solana's validator set that AVOID.NET does not currently track as an entity/incident. Key findings: - Teraswitch's AS20326 hosted 118.9M SOL (27.34% of total network stake); 94% of that stake went offline simultaneously during the August 12, 2026 routing failure - About 90 validators across London, Amsterdam, Dublin, Frankfurt, Singapore and Tokyo went delinquent; North American validators were unaffected - Helius, Solana's second-largest validator, was offline for the full ~33-minute outage window; Marinade Finance noted its validators did not fail over before routing was restored - Network came within ~4.51 percentage points of the 33.34% delinquent-stake threshold at which Solana loses transaction finality Sources: - Smart contract blockchain Solana neared a freeze threshold Wednesday, Marinade Finance says: https://www.coindesk.com/tech/2026/08/12/smart-contract-blockchain-solana-nearly-froze-wednesday-marinade-finance-says - Solana Nears Transaction Finalization Halt Due to TeraSwitch Outage: https://forklog.com/en/solana-nears-transaction-finalization-halt-due-to-teraswitch-outage/ - Solana Hit 86% of Its Halt Threshold After a Teraswitch Routing Failure: https://solanafloor.com/news/solana-hit-86-of-its-halt-threshold Scout priority: 6/10 | Urgency: medium | Category: otherSep 9
  • FulfilledSOL Strategies Inc. (STKE)pri 7SOL Strategies, a publicly traded Solana digital-asset-treasury (DAT) company, disclosed acute liquidity stress: it has pledged 252,851 SOL (~C$26.4M) as collateral to Kamino Finance against ~C$13.9M of debt, with Kamino able to auto-liquidate if loan-to-value hits 75%. The company reported C$37.33M in current liabilities against only C$1.87M cash, and a subsequent filing disclosed a C$101.7M loss with asset write-downs. This is a Solana-ecosystem treasury vehicle under real financial stress that could force distressed SOL sales or a collateral liquidation event, and is not currently covered by AVOID.NET. Key findings: - 252,851 SOL (~C$26.4M) pledged to Kamino Finance against ~C$13.9M debt; more than half of SOL Strategies' treasury is encumbered by borrowing - Kamino can automatically liquidate the collateral if the loan-to-value ratio reaches 75% - As of the August 19, 2026 disclosure, the company held only C$1.87M cash plus ~C$22M of unencumbered crypto, against C$37.33M in current liabilities - A separate SEC/filing report shows SOL Strategies (STKE) posted a C$101.7M loss with asset write-downs and undertook new equity raises to shore up liquidity - Management's stated liquidity plan includes cost cuts, staking/validator/HoudiniSwap revenue, selective SOL sales, securities issuance, and further draws on its $500M ATW convertible note facility Sources: - This Solana treasury company may sell SOL as a DeFi loan ties up more than half its treasury: https://cryptoslate.com/this-solana-treasury-company-may-sell-sol-as-a-defi-loan-ties-up-more-than-half-its-treasury/ - SOL Strategies (STKE) hit by C$101.7M loss, asset write-downs and new equity raises: https://www.stocktitan.net/sec-filings/STKE/6-k-sol-strategies-inc-current-report-foreign-issuer-9f05f589052b.html Scout priority: 7/10 | Urgency: medium | Category: otherSep 9
  • FulfilledKaminopri 2Solana SPL token, mint KMNo3nJsBXfcpJTVhZcXLW7RmTwTt4GVFE7suUBo9sS, symbol KMNO. Surfaced by an AVOID.NET wallet scan (holder exposure ≈ $10.69). Include the mint address in the investigation's addresses field so future scans resolve it.Sep 4
  • Fulfilledcat in a dogs worldpri 2Solana SPL token, mint MEW1gQWJ3nEXg2qgERiKu7FAFj79PHvQVREQUzScPP5, symbol MEW. Surfaced by an AVOID.NET wallet scan (holder exposure ≈ $27.60). Include the mint address in the investigation's addresses field so future scans resolve it.Sep 4
  • FulfilledPudgy Penguinspri 2Solana SPL token, mint 2zMMhcVQEXDtdE6vsFS7S7D5oUodfJHE8vd1gnBouauv, symbol PENGU. Surfaced by an AVOID.NET wallet scan (holder exposure ≈ $29.13). Include the mint address in the investigation's addresses field so future scans resolve it.Sep 4
  • Fulfilleddogwifhatpri 2Solana SPL token, mint EKpQGSJtjMFqKZ9KQanSqYXRcF8fBopzLHYxdM65zcjm, symbol $WIF. Surfaced by an AVOID.NET wallet scan (holder exposure ≈ $31.40). Include the mint address in the investigation's addresses field so future scans resolve it.Sep 4
  • FulfilledGurhan Kiziloz (BlockDAG)pri 6Gurhan Kiziloz is the concealed founder of BlockDAG Network, a project claiming USD 442 million raised in presale. ZachXBT on-chain analysis found less than USD 100 million traceable. BDAG launched at USD 0.0005 — 100x below the marketed USD 0.05 price — and now trades at USD 0.000081, down 99.8%. A Brazilian court froze USD 213 million in USDT across 48 Kiziloz-linked wallets in May 2026 for alleged unpaid gambling taxes and unregistered crypto sales. His prior company Lanistar received a UK FCA consumer warning and was liquidated in 2025. AVOID.NET has a co-founder page (gurhan-kiziloz-blockdag-co-founder) but no clean standalone individual slug for Kiziloz himself. Key findings: - Concealed identity for two years while Antony Turner served as BlockDAG public-facing CEO - ZachXBT found less than USD 100M traceable on-chain despite claimed USD 200-442M raised - BDAG token down 99.8% from marketed USD 0.05 presale price; launched at USD 0.0005 - Brazilian court froze USD 213M USDT across 48 Kiziloz-linked wallets in May 2026 over gambling taxes and unregistered crypto sales - Prior company Lanistar received UK FCA consumer warning in 2020, then liquidated September 2025 Sources: - Inside BlockDAG $442m crypto maze of missing miners, unpaid employees, and breached contracts: https://www.dlnews.com/articles/defi/inside-crypto-project-blockdag-442-million-usd-maze/ - BlockDAG Under Fire as Investigator Alleges $300M Scam: https://cryptopotato.com/blockdag-under-fire-as-investigator-alleges-300m-scam/ - BlockDAG and Gurhan Kiziloz Under More Fire: ZachXBT Finds $25M Presale Commingled: https://finance.yahoo.com/markets/crypto/articles/blockdag-gurhan-kiziloz-under-more-101715359.html Scout priority: 6/10 | Urgency: medium | Category: individualSep 2
  • FulfilledRamil Ventura Palafoxpri 7Ramil Palafox, founder of Praetorian Group International (PGI), was sentenced to 20 years in federal prison in February 2026 for a USD 201 million Bitcoin Ponzi scheme that defrauded over 90,000 investors. On April 6, 2026, he cut off his GPS monitor and fled before surrendering to prison — briefly becoming an FBI Most Wanted fugitive before being recaptured in Los Angeles. AVOID.NET has a combined PGI entity page but no individual page for Palafox himself. Given his direct personal accountability for the fraud, the 20-year DOJ sentence, and the fugitive episode, a dedicated individual page is warranted for cross-reference. Key findings: - Sentenced February 12, 2026 to 20 years for wire fraud and money laundering (PGI USD 201M Ponzi scheme) - PGI defrauded 90,000+ investors globally with false promises of 0.5-3% daily Bitcoin trading returns - April 6, 2026: cut GPS monitor and fled before reporting to prison; FBI Most Wanted warrant issued - Arrested days later in Los Angeles, California; now in federal custody serving 20-year sentence - DOJ Eastern District of Virginia confirmed case; IRS Criminal Investigation and FBI participated Sources: - Ramil Ventura Palafox gets 20 years sentence over $200 million bitcoin Ponzi scheme: https://www.coindesk.com/policy/2026/02/13/pgi-global-ceo-gets-20-years-sentence-over-usd200-million-bitcoin-ponzi-scheme - Praetorian Group International CEO sentenced to 20 years in prison: https://www.irs.gov/compliance/criminal-investigation/praetorian-group-international-ceo-sentenced-to-20-years-in-prison-for-200m-bitcoin-ponzi-scheme - FBI Most Wanted: Ramil Ventura Palafox escape notification: https://x.com/FBIMostWanted/status/2044793297852362893 - PGI Global Ramil Ventura Palafox arrested in California: https://behindmlm.com/companies/pgi-global/pgi-globals-ramil-ventura-palafox-arrested-in-california/ Scout priority: 7/10 | Urgency: medium | Category: individualSep 2
  • FulfilledCodexFieldpri 7On July 10, 2026, on-chain researcher Specter flagged CodexField — a decentralized code-management platform on BNB Greenfield — for suspected rug-pull activity involving up to USD 85 million in user funds. Suspicious activity included bridging 17.3 million USDT from TRON to Ethereum then converting to DAI on Polygon, while simultaneously renaming the project X account to @CodexField_AI and taking down all deposit-collecting subdomains. The pattern matches confirmed rug pulls: treasury outflows, social media scrubbing, and developer silence. BNB Chain has not issued an official statement. The USD 85M figure lacks a complete on-chain trace but partial flows are confirmed. Key findings: - On-chain researcher Specter issued community security alert July 10, 2026 citing abnormal CodexField fund outflows - 17.3 million USDT traced bridging from TRON to Ethereum, converted to DAI on Polygon; USD 6.5M completed, USD 10.8M in transit at alert time - CodexField renamed X account to @CodexField_AI and removed all deposit-collecting subdomains within hours of investigation going public - Alleged total user funds at risk: USD 85 million (partial on-chain verification; full trace not published) - BNB Chain and CodexField have not confirmed or denied allegations as of last reporting; developers silent Sources: - On-Chain Investigator Flags BNB Chain CodexField as a Potential $85M Rug Pull: https://www.cryptotimes.io/2026/07/10/on-chain-investigator-flags-bnb-chains-codexfield-as-a-potential-85m-rug-pull/ - CodexField Hit With $85M Fraud Claims After BNB Backing: https://financefeeds.com/codexfield-hit-with-85m-fraud-claims-after-bnb-backing/ - Analyst flags CodexField over suspected $85M rug pull: https://www.cryptopolitan.com/analyst-flags-codexfield-85m-rug-pull/ Scout priority: 7/10 | Urgency: high | Category: protocolSep 2
  • FulfilledLayerZero — DVN Single-Verifier Configuration Riskpri 7LayerZero's cross-chain messaging infrastructure was the attack surface for the $292M KelpDAO bridge exploit in April 2026. While LayerZero itself was not directly hacked, the incident exposed a systemic design risk: protocols using a 1-of-1 DVN (Decentralized Verifier Network) configuration — where LayerZero Labs itself is the sole verifier — create a single point of failure for the entire bridge. LayerZero later admitted it 'made a mistake.' Multiple other protocols may still run 1-of-1 DVN setups, representing ongoing risk across all LayerZero-connected bridges. A separate Sandbox (SAND) LayerZero bridge was also exploited in August 2026. Key findings: - LayerZero Labs publicly admitted on May 9, 2026 it 'made a mistake' in the KelpDAO DVN configuration - DPRK Lazarus Group (TraderTraitor unit) compromised LayerZero Labs' own DVN RPC infrastructure to forge cross-chain messages draining $292M - Kelp DAO dropped LayerZero for Chainlink's CCIP following the incident - Dispute between LayerZero and Kelp DAO: Kelp claimed LayerZero approved the 1/1 setup; LayerZero denied recommending it - The Sandbox (SAND) LayerZero bridge was also exploited in August 2026, indicating a pattern across LayerZero integrations - Unknown number of other live integrations may still use the vulnerable 1/1 DVN configuration Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: medium | Category: protocolSep 2
  • FulfilledRadoslaw Piesiewiczpri 7Radoslaw Piesiewicz, president of the Polish Olympic Committee, was arrested August 27, 2026 for allegedly accepting bribes to sign a sponsorship contract with Zondacrypto. The case illustrates how the exchange used institutional legitimacy — Olympic branding — to attract retail investors while allegedly defrauding them. The arrest is concurrent with the bankruptcy declaration and represents an active criminal proceeding. Key findings: - Arrested August 27, 2026 for accepting bribes to grant Zondacrypto a sponsorship contract with the Polish Olympic Committee - Arrest is simultaneous with the Estonian court's bankruptcy declaration of Zondacrypto - The sponsorship legitimized the exchange in the eyes of Polish retail investors during the period it was allegedly being looted - Case is active; further charges may follow as the criminal investigation broadens Sources: - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: high | Category: individualSep 2
  • FulfilledPrzemyslaw Kralpri 8Przemyslaw Kral is the former CEO of Zondacrypto (formerly BitBay), Poland's largest crypto exchange, who fled to Israel in April 2026 as prosecutors opened a $97M criminal fraud investigation. He is charged with participation in fraud on a vast scale and holds dual Polish-Israeli citizenship — Israel does not extradite its own nationals, making criminal accountability highly uncertain. He claims 4,500 BTC are inaccessible because private keys are held by missing founder Suszek, but prosecutors dispute this. Up to 30,000 users are left holding the consequences. Key findings: - Charged with participation in fraud on a vast scale in connection with the Zondacrypto collapse affecting 30,000 users - Fled to Israel in April 2026; Israeli citizenship blocks extradition to Poland - Reportedly cooperating with prosecutors for a reduced sentence as of mid-2026 - Claims co-founder Suszek holds sole private keys to 4,500 BTC cold wallet; prosecutors dispute this account - Exchange lost approximately 99.7% of Bitcoin reserves under his tenure as CEO - Departure reportedly coordinated with the unexplained disappearance of $21M+ in assets across 511 transactions Sources: - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: high | Category: individualSep 2
  • FulfilledSuperior Browser Extension Campaign — Wallet Drainerpri 8Socket Security identified a coordinated cluster of 19 malicious Chrome and Edge extensions — tracked as the 'Superior' campaign — that have collectively reached approximately 80,000 crypto users and remain active as of late August 2026. The extensions use a supply-chain attack pattern (acquire or create legitimate extensions, then push malicious updates) to establish a C2 channel and inject wallet-draining payloads. An updated Edge extension with a new C2 domain was published August 14, 2026, confirming the campaign is ongoing. Key findings: - 19 Chrome and Edge extensions with shared code identified by Socket Security, reaching ~80,000 users; campaign tracked as 'Superior,' active since at least February 2024 - Attack method: acquire legitimate extensions or publish clean versions, then push malicious updates — 14 created by actor, 5 purchased from prior owners - Malware creates WebSocket C2 channel, strips CSP headers, and uses XSS injection to execute wallet-secret-stealing and crypto-draining payloads - New Edge extension with updated C2 domain published August 14, 2026 — campaign is live and adapting after initial disclosure - Targets any Ethereum/EVM wallet installed as a browser extension; credential theft is a secondary objective Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: otherSep 2
  • FulfilledZondacrypto — Bankruptcy Declaration and CEO Flight (August 2026)pri 9Poland's largest crypto exchange, formerly BitBay, was declared bankrupt by an Estonian court on August 27, 2026 after CEO Przemyslaw Kral fled to Israel and the platform's co-founder Sylwester Suszek went missing — believed dead — taking private keys to 4,500 BTC. Up to 30,000 users are unable to access roughly $82-97M in funds. Polish prosecutors opened a criminal fraud investigation; the Polish Olympic Committee president was arrested the same day for bribery tied to the exchange; and affiliated fintech Femion also filed for bankruptcy. First creditor meeting is September 17, 2026. Key findings: - Harju County Court (Tallinn) declared BB Trade Estonia OÜ bankrupt on August 27, 2026; trustee Margus Lentsius appointed - CEO Przemyslaw Kral fled to Israel in April 2026; Israeli citizenship effectively blocks extradition to Poland - Approximately 99.7% of Bitcoin reserves disappeared via 511 transactions between December 2025 and April 2026 - Estimated losses of ~350M PLN ($82-97M) affecting roughly 30,000 users - Polish Olympic Committee president Radoslaw Piesiewicz arrested August 27, 2026 for accepting bribes to sponsor Zondacrypto - Co-founder Sylwester Suszek missing since 2022; allegedly holds private keys to 4,500 BTC cold wallet - Affiliated Polish fintech Femion filed for bankruptcy in exchange collapse fallout - First creditor meeting: September 17, 2026; two-month window to lodge claims from court publication Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: high | Category: exchangeSep 2
  • FulfilledAudiA6 Crypto Laundering Networkpri 8AudiA6 was a professional dark-web cryptocurrency money laundering service that processed over $389 million for ransomware gangs and other cybercriminals, dismantled in June 2026 by a US-led international operation. Two operators were charged by the DOJ and arrested in Georgia. AudiA6 also operated the Dark2Web cybercrime forum. This is a materially different entity from the existing 'dark2web' slug — AudiA6 is the laundering service infrastructure itself and deserves its own investigation page. Key findings: - AudiA6 laundered over $389M (approximately EUR 336M) in cryptocurrency for ransomware gangs and cybercriminals, charging a 5% fee per transaction - Also operated the Dark2Web cybercrime forum, providing dual infrastructure for ransomware proceeds and cybercrime coordination - Operators Ruslan Igorevich Tkachuk (37) and Alexander Vladimirovich Ledenev (25) charged by DOJ (EDPA) and arrested in Batumi, Georgia, June 2026 - Takedown led by US Secret Service and IRS-CI with Europol, Eurojust, and 11 partner nations including Australia, Canada, UK, Germany, Japan - DOJ complaint filed in Eastern District of Pennsylvania; seizure banners placed on both clear web and dark web infrastructure Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: otherSep 1
  • FulfilledSuperior Browser Extension Campaign — Wallet Drainerpri 8Socket Security identified a coordinated cluster of 19 malicious Chrome and Edge extensions — tracked as the 'Superior' campaign — that have collectively reached approximately 80,000 crypto users and remain active as of late August 2026. The extensions use a supply-chain attack pattern (acquire or create legitimate extensions, then push malicious updates) to establish a C2 channel and inject wallet-draining payloads. An updated Edge extension with a new C2 domain was published August 14, 2026, confirming the campaign is ongoing. Key findings: - 19 Chrome and Edge extensions with shared code identified by Socket Security, reaching ~80,000 users; campaign tracked as 'Superior,' active since at least February 2024 - Attack method: acquire legitimate extensions or publish clean versions, then push malicious updates — 14 created by actor, 5 purchased from prior owners - Malware creates WebSocket C2 channel, strips CSP headers, and uses XSS injection to execute wallet-secret-stealing and crypto-draining payloads - New Edge extension with updated C2 domain published August 14, 2026 — campaign is live and adapting after initial disclosure - Targets any Ethereum/EVM wallet installed as a browser extension; credential theft is a secondary objective Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: otherSep 1
  • FulfilledOttersexSep 1
  • FulfilledAsymmetric ResearchSep 1
  • FulfilledCoinsbuy Exchange — August 2026 Hot Wallet Drainpri 7On August 9-10, 2026, Coinsbuy lost $7.9 million across coordinated Ethereum and TRON wallet drains. The attacker began with a 5 USDT test transaction then systematically emptied 8 TRON wallets of 6.04M USDC and 3 Ethereum wallets of 1.89M USDT plus 77 ETH within one hour. Cross-chain operations were linked via the Bridgers swapper. Stolen funds were laundered into Monero, with ChangeNOW helping freeze a six-figure portion. The corpus has Coinsbuy entity pages but no dedicated incident page for this specific August 2026 attack event. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledCoinW6pri 8CoinW6 is a fake crypto trading platform at the center of the SEC's first-ever pig butchering enforcement action filed in September 2024. Operators posed as wealthy professionals on LinkedIn and Instagram, built romantic relationships over WhatsApp, then directed victims to CoinW6's fraudulent interface showing fabricated returns. The SEC charged five entities and three individuals for stealing at least $2.2M from 11 investors (July 2022 to December 2023). The companion NanoBit case reached a $5.5M default judgment in June 2026. The corpus has a NanoBit page but no page for CoinW6, leaving a gap in coverage of this landmark SEC enforcement action. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledTectonic / Cronos — August 2026 TONIC Price Manipulation Exploitpri 10On August 30-31, 2026, an attacker manipulated the price of TONIC, Tectonic's thinly traded governance token (~$1.34M liquidity, ~$11K daily volume), by roughly 100x in 20 minutes on the Cronos chain. The inflated TONIC was deposited as collateral to borrow harder assets from Tectonic's lending pools, draining an estimated $75 million — more than half of all August 2026 crypto losses. Cronos validators halted block production network-wide and rolled back chain state to before the attack. Only ~$6M escaped to Ethereum before the halt. The existing tectonic corpus page (last updated 2026-08-30) covers the protocol entity but there is no dedicated incident page for this exploit, which triggered a full Layer-1 chain rollback. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 10/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledCoinhub Bitcoin ATM — Fraud Facilitation Networkpri 6Coinhub, one of the largest surviving US crypto ATM operators after Bitcoin Depot's collapse, has been repeatedly cited in ICIJ and Boston Globe investigations for its role in facilitating $388 million in 2025 ATM fraud losses, with elderly victims disproportionately targeted. The operator continues to expand retail placements despite mounting regulatory pressure and state-level fraud-liability legislation targeting its business model. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledLazarus Group Mach-O Man ClickFix macOS Campaignpri 7In April 2026, CertiK documented a new Lazarus Group attack vector — the Mach-O Man campaign — using ClickFix social engineering to lure macOS users via fake online meeting invitations that instruct them to paste malicious terminal commands, granting full credential and system access. This is functionally distinct from the existing lazarus-group-mach-o-man-macos-campaign-2026 slug (check whether that slug fully covers this) and is an active threat against crypto firms and DeFi teams. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledBitcoin Depot — Crypto ATM Fraud Facilitatorpri 7Bitcoin Depot's May 2026 Chapter 11 bankruptcy — shutting 9,700 kiosks overnight — occurred while the company was under federal scrutiny for its role in facilitating $389 million in FBI-tracked ATM fraud losses in 2025. State authorities had already revoked licenses and launched investigations. The abrupt shutdown left kiosk users unable to retrieve loaded funds and merits a dedicated investigation distinct from general ATM fraud trends. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledCronos Chain — Tectonic-Triggered Blockchain Rollbackpri 7After the $75 million Tectonic exploit on August 30, Cronos validators halted block production and executed a full chain rollback, erasing roughly 24 hours of transaction history. This raises critical questions about chain immutability, centralization of Cronos validator governance, and Crypto.com's role in coordinating the rollback decision. No existing AVOID.NET slug covers the Cronos chain itself or this governance action. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledOperation Economic Outcast — Iran Digital Asset Sanctionspri 7On August 24, 2026, the U.S. Treasury unveiled Operation Economic Outcast, the first sectoral sanctions designating Iran's entire digital asset sector as sanctionable, targeting nearly 60 entities and individuals across crypto, tech, gold, and shipping. This systemic regime — distinct from individual exchange designations already in the corpus — represents a new legal risk framework that any user interacting with Iran-adjacent protocols or wallets needs to understand. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledMaya Protocol — August 2026 Six-Bug Exploitpri 8On August 18, 2026, MAYAChain was exploited via a chain of six chained software bugs in a single 23-message transaction, allowing an attacker to withdraw 48.87 million synthetic CACAO tokens and drain $1.7 million in real cross-chain assets across Bitcoin and other pools. CACAO fell 89% and total pool value dropped $11 million. The existing maya-protocol and maya-protocol-mayachain slugs exist; this incident constitutes major new evidence for both pages and merits a dedicated incident record. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledBitcoin Depotpri 9Bitcoin Depot, formerly the largest crypto ATM operator in North America with 9,700 machines, filed for Chapter 11 bankruptcy on May 18, 2026, shutting down all ATMs overnight. The company had been linked by federal investigators to $389 million in FBI-tracked ATM fraud losses in 2025 and faced state license revocations before collapse. The abrupt shutdown left users unable to retrieve funds loaded into kiosk networks and represents a major consumer-harm event with no existing AVOID.NET coverage. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledMore Markets (Flow EVM Lending Protocol)pri 9On August 31, 2026, More Markets — a DeFi lending protocol built on the Flow EVM blockchain — was exploited for approximately $9.3 million (15.5 million WFLOW tokens) via an E-Mode liquid staking token overborrow attack. The protocol issued no public statement, provided no operational pause, and left users with zero guidance; after the exploit, total value locked collapsed to $3.64 million against $3.67 million in active loans, leaving essentially no buffer between assets and liabilities. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: undefined | Category: undefinedSep 1
  • FulfilledHeebooAug 30
  • FulfilledAllbridgepri 6On August 19, 2026, Allbridge's Base CCTP router was exploited via forged Circle attestation messages prepared a month earlier on Polygon, draining ~$191K through a missing sender-identity and mint-amount verification. SlowMist's post-mortem flagged systemic cross-chain verification failures that could enable substantially larger attacks on higher-liquidity deployments. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedAug 30
  • FulfilledTerm Financepri 8On August 23, 2026, an attacker bootstrapped from 2 ETH (Tornado Cash), acquired majority voting power in Term Finance's sparsely held DAO, and passed malicious governance proposals to drain $8.5M (2,843 ETH + 1.68M USDC) from depositor vaults. Term Labs permanently shut down all Meta Vault deposits in response, confirmed by PeckShield and CertiK. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 30
  • FulfilledCryptoSpain / Alvaro Romillo / Madeira Invest Clubpri 8Alvaro Romillo, a Spanish crypto influencer known as CryptoSpain, was detained without bail in 2026 on charges of orchestrating a $300M fraud through Madeira Invest Club, characterized by prosecutors as a complex Ponzi scheme. He leveraged his influencer platform to attract retail investors. Romillo faces up to 18 years in prison under Spanish law if a mass-offense classification is applied. One of the largest influencer-driven crypto frauds in European history. Key findings: Sources: - https://www.theblock.co/post/378108/spanish-crypto-influencer-cryptospain-detained-on-300-million-fraud-money-laundering-charges: https://www.theblock.co/post/378108/spanish-crypto-influencer-cryptospain-detained-on-300-million-fraud-money-laundering-charges Scout priority: 8/10 | Urgency: high | Category: cryptoAug 30
  • FulfilledNovaTech Ltd.pri 8NovaTech Ltd. raised over $650M in crypto from 200,000+ investors (2019-2023) via a fraudulent MLM/trading program run by Cynthia and Eddy Petion. Funds were not traded as promised but used to pay prior investors and personal expenses. The scheme disproportionately targeted the Haitian-American community. NovaTech collapsed May 2023; most investors could not recover funds. The SEC charged the Petions and six promoters with fraud. Despite the 2024 filing date, the scale ($650M, 200K victims) and absence from the corpus makes this a critical addition. Key findings: Sources: - https://www.sec.gov/newsroom/press-releases/2024-95: https://www.sec.gov/newsroom/press-releases/2024-95 - https://www.theblock.co/post/310780/sec-charges-novatech-with-allegedly-operating-a-pyramid-scheme-that-raised-650-million-in-crypto: https://www.theblock.co/post/310780/sec-charges-novatech-with-allegedly-operating-a-pyramid-scheme-that-raised-650-million-in-crypto - https://www.financemagnates.com/trending/novatechs-650-million-crypto-fraud/: https://www.financemagnates.com/trending/novatechs-650-million-crypto-fraud/ Scout priority: 8/10 | Urgency: high | Category: cryptoAug 30
  • FulfilledEdward Zimbardi / The Crypto Programpri 9Edward Zimbardi, 59, operated 'The Crypto Program,' defrauding 6,000+ investors out of $165M by promising guaranteed 25% monthly returns on fake advertising packages. He fled to Fiji to evade prosecution. A federal indictment filed July 8, 2026 charged him with 12 wire fraud counts, 12 money laundering counts, and 1 money laundering conspiracy count. Fijian authorities deported Zimbardi to U.S. custody on August 14, 2026. DOJ case is now active. Key findings: Sources: - https://www.theblock.co/news/regulation/2026-08-18-the-crypto-program-promoter-deported-from-fiji-over-alleged-165-million-ponzi-scheme-412083: https://www.theblock.co/news/regulation/2026-08-18-the-crypto-program-promoter-deported-from-fiji-over-alleged-165-million-ponzi-scheme-412083 - https://www.law360.com/articles/2514428/doj-charges-ga-man-over-165m-crypto-ponzi-scheme: https://www.law360.com/articles/2514428/doj-charges-ga-man-over-165m-crypto-ponzi-scheme - https://www.11alive.com/article/news/crime/georgia-man-edward-zimbardi-arrested-in-fiji-accused-of-running-165-million-crypto-ponzi-scheme/85-6d3048cb-01ea-4195-9d3b-d43422cfeae7: https://www.11alive.com/article/news/crime/georgia-man-edward-zimbardi-arrested-in-fiji-accused-of-running-165-million-crypto-ponzi-scheme/85-6d3048cb-01ea-4195-9d3b-d43422cfeae7 Scout priority: 9/10 | Urgency: critical | Category: cryptoAug 30
  • FulfilledHarmony ONE (August 2026 Layer-1 mint exploit)pri 9On August 12, 2026, an attacker exploited a quorum verification bug in Harmony's Layer-1 consensus — minting ~4 billion unauthorized ONE tokens (26% of supply). The code counted public keys in a signature mask rather than actual signers, allowing zero-signature messages to pass quorum. About 97% of minted tokens reached exchanges before any freeze. ONE fell 30-37% intraday to an all-time low. Emergency patch v2026.1.1 was deployed within ~65 minutes. This is a distinct new entity from harmony-protocol (2022 Horizon bridge hack). Key findings: Sources: - https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527: https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527 - https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens: https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens - https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm: https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm Scout priority: 9/10 | Urgency: critical | Category: cryptoAug 30
  • FulfilledThe Sandbox (SAND OFT exploit)pri 9On August 21-22, 2026, attackers hijacked LayerZero delegate permissions on The Sandbox's SAND omnichain fungible token (OFT) contract on Base via approveAndCall, minting 329 trillion unbacked SAND tokens across 703 events. Actual liquid losses were ~$675,000 in real SAND plus ~79 ETH converted. The Sandbox halted Base and BNB Smart Chain bridges and announced a pre-exploit snapshot to compensate liquidity providers. Exposes a critical access-control failure in OFT bridge infrastructure. Key findings: Sources: - https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/: https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/ - https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/: https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/ - https://cryptorank.io/news/feed/49fcb-the-sandbox-sand-exploit-49b-in-new-tokens-flood-base: https://cryptorank.io/news/feed/49fcb-the-sandbox-sand-exploit-49b-in-new-tokens-flood-base - https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/: https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/ Scout priority: 9/10 | Urgency: critical | Category: cryptoAug 30
  • FulfilledColdcard / Coinkitepri 10Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet — draining ~1,816 BTC (~$116M) from 5,200+ addresses across four waves. The root cause was a March 2021 build error that caused seed generation to fall back on weak software RNG instead of hardware entropy, collapsing key strength from 128 bits to as low as 40 bits, brute-forceable without physical access. Mk2, Mk3, and older Mk4/Mk5/Q devices on pre-patch firmware are affected. Third-largest crypto hack of 2026. Key findings: Sources: - https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack: https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack - https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/: https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/ - https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/: https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/ - https://cryptobriefing.com/coldcard-wallet-exploit-bitcoin-theft-112m/: https://cryptobriefing.com/coldcard-wallet-exploit-bitcoin-theft-112m/ Scout priority: 10/10 | Urgency: critical | Category: cryptoAug 30
  • FulfilledWeb3Portpri 8Web3Port is the Chinese market-making firm at the center of the Movement Labs MOVE token dump scandal. Documents reviewed by CoinDesk showed Web3Port received 66 million MOVE tokens (5% of total supply) via an opaque intermediary called Rentech, which appeared on both sides of the agreement simultaneously. Web3Port sold the tokens one day after listing, creating approximately 38 million dollars in downward price pressure. Binance banned Web3Port account for misconduct. The DOJ has opened a grand jury investigation into the affair. Movement Labs went bankrupt in July 2026 with MOVE down 99% from its all-time high. Web3Port has not been investigated by AVOID.NET despite being a named participant in one of the year most significant token manipulation cases. Key findings: - Received 66 million MOVE tokens via a dual-sided agreement with intermediary Rentech — a firm with no public digital footprint - Dumped tokens on the open market one day after MOVE exchange debut, generating approximately 38 million dollars in downward price pressure - Binance banned Web3Port market-making account and described its conduct as misconduct - A DOJ grand jury investigation into the MOVE token launch is ongoing; Rushi Manche won advancement of legal fees related to the probe - Movement Labs subsequently filed for Chapter 11 bankruptcy in July 2026, reporting assets under 500,000 dollars against over 1 million dollars in liabilities Sources: - Inside Movement Token-Dump Scandal: Secret Contracts, Shadow Advisers and Hidden Middlemen: https://www.coindesk.com/tech/2025/04/30/inside-movement-s-token-dump-scandal-secret-contracts-shadow-advisors-and-hidden-middlemen - Movement Labs files for Chapter 11 months after token scandal: https://www.coindesk.com/policy/2026/07/21/movement-labs-files-for-chapter-11-months-after-token-scandal-and-strategic-overhaul - Ousted founders 1.6 million claim tops Movement Labs bankruptcy filing: https://www.theblock.co/news/business/2026-07-21-ousted-founders-1-6-million-claim-tops-movement-labs-bankruptcy-filing-409151 Scout priority: 8/10 | Urgency: high | Category: individualAug 29
  • FulfilledSocket Security Malicious Browser Extension Campaign August 2026pri 9On August 28, 2026, cybersecurity firm Socket disclosed a campaign of 19 malicious Chrome and Edge browser extensions with embedded crypto wallet draining, seed-phrase harvesting, and exchange credential-stealing code. The extensions affected an estimated 80,000 users across multiple chains. Five of the 19 were legitimate extensions that had been acquired and weaponized by the threat actors. The campaign specifically targeted hardware wallet seed phrases and is active right now, representing an emerging browser supply-chain attack vector that AVOID.NET users urgently need to know about. Key findings: - 19 malicious Chrome and Edge extensions identified by Socket Security on August 28, 2026, collectively affecting approximately 80,000 users - Five extensions were previously legitimate and were acquired then weaponized — including Enable Right Click and Copy, RapidLens, QuickLens, Password Protect PDF, and an Edge extension - 14 additional extensions built from scratch under crypto-themed names including LedgerLook: Wallet Checker, DeFi Pulse Tracker, Blockfolio: Address Monitor, and Multi-Chain Explorer - Malicious modules include a multi-chain wallet drainer, a hardware-wallet seed-phrase harvester, and an exchange account credential harvester - Extensions strip Content-Security-Policy headers and inject JavaScript on targeted pages, connecting to attacker-controlled exfiltration servers Sources: - 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code: https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html - 19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge: https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344 Scout priority: 9/10 | Urgency: high | Category: otherAug 29
  • FulfilledAviciAug 29
  • FulfilledFogoAug 29
  • FulfilledCFTC Crypto ATM Scam Warningpri 6On August 27, 2026, the CFTC issued a formal consumer alert after crypto ATM scams drove $388 million in reported losses in 2025 — a 58% year-on-year increase. Over half of all losses affected people over 50, totaling $302 million from that demographic alone. The CFTC explicitly stated that no legitimate government agency or company will instruct anyone to use a crypto ATM. No existing AVOID.NET slug covers crypto ATM fraud as a systemic category, and the formal regulatory warning and documented scale of harm ($388M) justify a dedicated investigation page. Key findings: - CFTC issued formal consumer alert August 27, 2026: crypto ATM scams caused $388M in reported losses in 2025, up 58% year-over-year - People over 50 accounted for more than half of crypto ATM scam complaints, representing $302M in losses - CFTC: no government agency, legitimate financial institution, or reputable company will instruct use of crypto ATMs to move money - Complaint volumes nationwide rose 23% overall; kiosk-specific complaints growing faster than general crypto fraud reports - Standard attack pattern: scammer stays on phone while victim feeds cash into ATM and sends to attacker wallet via QR code Sources: - CFTC Issues Warning as Crypto ATM Scams Top $388M, Over Half of Losses Hit People Over 50: https://www.cryptotimes.io/2026/08/27/cftc-issues-warning-as-crypto-atm-scams-top-388m/ - CFTC warns crypto ATM scams drove $388M in losses: https://crypto.news/cftc-warns-crypto-atm-scams-drove-388m-in-losses/ - CFTC warns consumers about risks of using crypto ATMs: https://cryptobriefing.com/cftc-warns-crypto-atm-risks/ Scout priority: 6/10 | Urgency: medium | Category: otherAug 29
  • FulfilledTrezor (ShipMonk Data Breach)pri 8On August 10, 2026, Trezor disclosed that its shipping partner ShipMonk suffered a data breach exposing personal data of 13,689 hardware wallet customers — including names, email addresses, phone numbers, and home addresses. The breach occurred via an unpatched vulnerability in the third-party analytics platform Metabase used by ShipMonk, affecting orders placed between May 10 and August 8. With violent crypto home invasions rising sharply in 2026, the exposure of verified crypto hardware wallet owner home addresses creates direct physical safety risk. The entity slug trezor exists but no breach-specific investigation page exists, and the physical threat vector is unique enough to warrant a dedicated entry. Key findings: - 13,689 Trezor hardware wallet customers had personal data exposed via ShipMonk breach on August 10, 2026 - 11,742 customers suffered full exposure: name, email address, phone number, and home shipping address - 1,947 additional customers had partial exposure limited to name, city, and email - Breach vector traced to an unpatched vulnerability in Metabase analytics platform used by ShipMonk as a third-party tool - No wallet firmware, private keys, or on-chain assets compromised — risk is social engineering and physical targeting by known home address Sources: - Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers: https://cybersecuritynews.com/trezor-shipmonk-data-breach/ - Trezor discloses data breach affecting nearly 14,000 customers: https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/ - With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line: https://cryptoslate.com/with-violent-crypto-home-invasions-surging-a-data-breach-exposing-over-10000-trezor-owners-puts-physical-safety-on-the-line/ - Recent customer data exposed in shipping provider incident: https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident Scout priority: 8/10 | Urgency: high | Category: wallet_serviceAug 29
  • FulfilledBitMart Exchange — Restructuring Pivot and Vanishing Small Withdrawals (August 2026)pri 9BitMart reversed its announced shutdown on August 22, 2026, pivoting to a restructuring plan via White & Case while simultaneously throttling small-ticket withdrawals to near-zero in the 48 hours before the August 26 trading cutoff. Users report small withdrawals have vanished with no processing confirmation, deepening FTX-scenario concerns about the exchange real liquidity position. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 28
  • FulfilledEvmos Networkpri 7Evmos, a Cosmos-based EVM blockchain, passed a shutdown governance proposal with 99.8% approval and ceased all block production on approximately May 18, 2026. Website, block explorer, and all infrastructure went offline with TVL dropping to zero. Its discontinuation had a direct downstream security impact: the Evmos stack's unpatched authorization bug was the exact vulnerability exploited in BounceBit's $3 million L1 exploit in August 2026, demonstrating that orphaned Evmos-stack contracts remain exploitable by third parties. Key findings: - Governance Proposal #331 passed 99.8% in favor; chain halted at block 37,318,000 on approximately May 18, 2026 - Website, block explorer, all infrastructure offline; TVL dropped to zero - Evmos's unpatched authorization flaw became the attack vector for BounceBit's $3M L1 exploit in August 2026 - BounceBit team cited Evmos discontinuation as reason the bug could not be patched — environment unmaintainable - Security researchers warn orphaned Evmos-stack contracts carry persistent unpatched vulnerabilities Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: medium | Category: protocolAug 28
  • FulfilledMoonbeam Network (GLMR)pri 8Moonbeam, a Polkadot parachain with a peak TVL of $275 million, permanently shut down on July 31, 2026, with only 24.83% of GLMR holders completing migration before the deadline. Late holders were directed to an email helpdesk with no public recovery portal and no guarantee of fund recovery. The chain halted all user transactions after the migration window closed, creating ongoing consumer harm as the team reviews claims on a discretionary basis. Key findings: - Polkadot parachain permanently halted July 31, 2026; only 24.83% of GLMR migrated before cutoff - Users with stranded funds directed to helpdesk@moonbeam.foundation with no universal post-cutoff recovery mechanism - Assets in Moonwell (GLMR, xcDOT, USDC, FRAX, ETH) and Wormhole bridges became permanently inaccessible after cutoff - TVL collapsed from $275 million in early 2022 to $1.34 million at closure - Network halted all user transactions after migration window closed; late GLMR holders have no automated recovery path Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: high | Category: protocolAug 28
  • FulfilledCoinsbuy Exchange — August 2026 Hackpri 7 Key findings: Sources: Scout priority: 7/10 | Urgency: undefined | Category: undefinedAug 28
  • FulfilledMiCA Transition Impersonation Fraud Cluster (2026)pri 8 Key findings: Sources: Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 28
  • FulfilledMaya Protocol — Six-Bug Exploit (August 2026)pri 8 Key findings: Sources: Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 28
  • FulfilledSaitama Token / Manpreet Kohlipri 9 Key findings: Sources: Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 28
  • FulfilledBounceBit L1 Exploit and Chain Shutdown (August 2026)pri 8On August 19-20, 2026, an attacker exploited an authorization vulnerability in the Evmos-based BounceBit Layer 1 blockchain, transferring 286.5 million BB tokens (~$3 million) from nine mainnet accounts across 14 transactions without ever touching private keys. The flaw was in the Evmos stack's authorization check, which failed to verify that the source account had approved the movement. BounceBit permanently shut down its L1 chain rather than attempt a patch, migrating BB as a BEP-20 token on BNB Chain via a pre-exploit snapshot. The permanent chain retirement makes this a significant trust-disqualifying event for the Bitcoin restaking protocol that warrants a standalone incident page alongside the existing 'bouncebit' protocol entry. Key findings: Sources: Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledOperation Economic Outcast — Iran Digital Assets Sectoral Sanctions (August 2026)pri 8On August 24, 2026, OFAC issued the first-ever sectoral sanctions targeting Iran's entire digital assets sector under EO 13902, as part of Operation Economic Outcast. This is a structural legal change: any foreign person anywhere in the world who operates in or provides support to Iran's digital asset sector is now subject to secondary sanctions — not just named individuals. The action designated nearly 60 entities, individuals, and vessels. This is relevant to AVOID.NET users because global exchanges, OTC desks, and DeFi protocols that process Iranian-origin crypto flows now carry compounding sanctions risk. It warrants a dedicated investigation page distinct from the Shelbit and Aban Tether entries. Key findings: Sources: Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledTerm Finance — Governance Exploit (August 2026)pri 9On August 23, 2026, Ethereum DeFi lending protocol Term Finance lost $8.5 million to a governance capture attack. The attacker spent approximately $951 to acquire 0.4852 tmvETH, which alone secured 90.66% of all existing voting power in the affected pool. Using that majority stake, the attacker submitted and self-approved malicious governance proposals that directed the vaults to hand over 2,843 ETH and 1.68 million USDC. Initial funding was just 2 ETH sourced through Tornado Cash. No contract bug was involved — the exploit worked entirely within the designed governance mechanism. This warrants a dedicated incident page separate from the existing 'term-labs' protocol entry. Key findings: Sources: Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledIvan Obukhov / Foscom FZEpri 9Ivan Obukhov is a UAE-based Ukrainian national sanctioned by OFAC on August 24, 2026, as part of Operation Economic Outcast. Since 2023 he processed more than $100 million in cryptocurrency to facilitate oil sales on behalf of the IRGC's Qods Force, effectively operating a crypto-for-sanctioned-oil payment channel at scale. He owns UAE-based Foscom FZE (acquired 2022) and brokered Iranian shadow-fleet vessels. This is a distinct individual/entity from the already-documented Shelbit and Aban Tether entries. The $100M+ throughput and direct IRGC-QF nexus make this a high-priority addition. Blockchain firm TRM Labs traced more than $6.3 billion in blockchain flows through related exchange Shelbit between May 2024 and March 2026. Key findings: Sources: Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledKenneth Thom (K Money) Finfluencer Investment Fraudpri 6Kenneth Thom, operating as crypto/finance influencer 'K Money,' was sentenced on August 11, 2026 to two years in prison for investment adviser fraud. Thom was a previously suspended securities broker who rebranded as a social media finfluencer and continued soliciting investor funds without disclosing his regulatory history, defrauding investors out of hundreds of thousands of dollars. The case represents a distinct pattern — broker-turned-influencer fraud — not covered by any existing AVOID.NET page, and the sentence establishes confirmed federal culpability. Key findings: Sources: - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledMANTRA Chain Upstream Exploit (August 2026)pri 8On August 20-21, 2026, an attacker exploited a vulnerability in an upstream Cosmos EVM dependency used by MANTRA Chain, forcing a full blockchain halt that froze all transactions, deposits, withdrawals, bridge operations, and validator endpoints. MANTRA's OM token dropped 18.5% to a record low. The chain resumed August 22 after deploying v8.4.0, but MANTRA has not disclosed full financial damage, the specific component exploited, or how much was extracted. MANTRA already has a troubled history — its OM token collapsed 90%+ in April 2025. The exploit-specific incident does not have a dedicated AVOID.NET page and warrants investigation given ongoing opacity. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 27
  • FulfilledSummer Finance (Summer.fi)pri 6Summer Finance, an Ethereum-based DeFi yield optimization protocol, was exploited for $6.017 million DAI on July 6, 2026, via a flash loan price manipulation attack. The attacker used a $65.4 million flash loan to exploit a share-accounting vulnerability in the Fleet Commander contract's totalAssets() function, withdrawing $70.9 million against a $64.8 million deposit. Shortly after the exploit, Summer Finance announced it had no viable path forward and began winding down operations, with the SUMR token falling over 18%. Key findings: - July 6, 2026: $6.017M DAI drained via flash loan attack exploiting a share-accounting bug in Summer Finance's Fleet Commander contract - Attacker used $65.4M flash loan to manipulate the totalAssets() valuation logic, withdrawing $70.9M against a $64.8M deposit - Protocol had $22M TVL pre-exploit per DeFiLlama; team announced 'no viable path forward other than to wind down operations' post-exploit - SUMR governance token fell >18% on wind-down announcement - Blockaid first flagged the exploit; CertiK confirmed the flash loan attack vector Sources: - DeFi protocol Summer Finance exploited for $6 million; analysts point to flash loan attack: https://www.theblock.co/post/407198/summer-finance-exploited - DeFi protocol Summer.fi halts Lazy Summer vaults after $6 million exploit: https://www.coindesk.com/web3/2026/07/06/defi-protocol-summer-fi-halts-lazy-summer-vaults-after-usd6-million-exploit - Summer Finance exploited for $6 million, shuts down: https://www.web3isgoinggreat.com/single/summer-finance-exploit - Summer Finance Pauses Vaults After $65.4M Flash Loan Attack Triggers $6M Loss: https://news.bitcoin.com/summer-finance-pauses-vaults-after-65-4m-flash-loan-attack-triggers-6m-loss/ Scout priority: 6/10 | Urgency: medium | Category: protocolAug 27
  • FulfilledCrypto Beast (ALT Token Influencer)pri 6Crypto Beast, a pseudonymous influencer with 1.2 million Twitter followers, was exposed by ZachXBT in July 2026 for orchestrating an $11 million pump-and-dump on the ALT token. Over approximately one week, Crypto Beast repeatedly promoted ALT as a 'next-gen DeFi revolution' while secretly controlling 45 connected insider wallets holding a large pre-allocated token position. On July 14, 2025, these wallets simultaneously dumped, crashing ALT's market cap from $190 million to $3 million within minutes. ZachXBT traced all dump wallets to a single Celestia address linked to Crypto Beast's known wallet. The influencer returned with giveaways after a brief account deletion, consistent with reputation-rebuilding before a repeat scheme. Key findings: - 45 connected insider wallets sold >$11M of ALT tokens on July 14, crashing market cap from $190M to $3M within minutes - ZachXBT traced all dump wallets to a single Celestia address also linked to Crypto Beast's publicly known wallet - Crypto Beast received a large private token allocation months before promotion; promoted ALT publicly for ~1 week before coordinating the dump - Prior pattern: documented history of promoting tokens that collapsed, including ALPHA, RICH, YE, RUG, ACE, and JOHN - After temporary account deletion, Crypto Beast resumed posting with giveaways — consistent with reputation-rebuilding before a repeat scheme Sources: - ZachXBT exposes 'Crypto Beast' for $11 million ALT scam: https://www.cryptopolitan.com/zachxbt-exposes-crypto-kol-crypto-beast/ - Crypto Influencer 'Crypto Beast' Dumps ALT Token for $11M After Promoting to Followers, ZachXBT Exposes: https://cryptorank.io/news/feed/46f3e-zachxbt-exposes-crypto-beast-11m-alt-token-dump - ZachXBT Exposes Crypto Beast's $11M ALT Token Dump: https://cryptonews.com/news/zachxbt-exposes-crypto-beast-11m-alt-token-dump/ - $11M Exit Scam? ZachXBT Exposes Influencer Crypto Beast in Shocking $ALT Dump: https://crypto-economy.com/11m-exit-scam-zachxbt-exposes-influencer-crypto-beast-in-shocking-alt-dump/ Scout priority: 6/10 | Urgency: medium | Category: individualAug 27
  • FulfilledFake Crypto AML Checker Sitespri 6Malwarebytes and multiple security firms issued warnings in August 2026 about an active wallet-drainer campaign operating through fake AML wallet checking websites. These sites impersonate legitimate services — primarily AMLBot — using copied logos, layouts, and compliance-sounding language. Unlike legitimate AML checks that only need a public wallet address, these phishing sites prompt users to connect wallets and approve token permissions, granting attackers drainage access. The campaign exploits users' security awareness, turning the act of checking wallet safety into the attack vector itself. Key findings: - August 2026: attackers built fake AML checker websites impersonating AMLBot, tricking users into connecting wallets and approving token permissions - Unlike real AML checks (public address only), fake sites request wallet connection and transaction signatures — granting drainage access - Sites use fake progress bars, compliance verification messages, and fraudulent fee requests to appear legitimate - Malwarebytes, Decrypt, Security Boulevard, and Cryptopolitan all independently flagged the campaign in August 2026 - Recommended remediation: disconnect wallet, revoke unknown token permissions; if seed phrase was entered, treat wallet as fully compromised Sources: - Scammers are using fake crypto AML checkers to drain your wallet: https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet - Fake Crypto AML Checkers Are Trying to Drain Users' Wallets: https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets - Fake crypto AML checkers push users to approve wallet-draining transactions: https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/ Scout priority: 6/10 | Urgency: medium | Category: otherAug 27
  • FulfilledCyberLeek Solana Tokenpri 6CyberLeek is an anonymous Solana meme coin launched August 15, 2026 by a group simultaneously publishing alleged GTA 6 leak footage, with embedded QR codes in the leaked videos driving speculative traffic. The token surged over 1,400% in 24 hours. The creator holds 270 million tokens in a private wallet and retains unilateral control over liquidity, presenting a textbook rug-pull risk profile. The launch strategy — viral cultural event paired with anonymous insider token control — is consistent with documented Solana pump-and-dump patterns. Key findings: - Launched August 15, 2026 on Solana alongside publication of alleged GTA 6 leak footage; embedded QR codes in leaked videos drove speculative buying - Token surged >1,400% in 24 hours; creator holds ~270 million tokens in a private wallet with unilateral liquidity control - Creator identity entirely anonymous; no smart contract audit; liquidity lock status unconfirmed - Launch mechanism (viral cultural event + anonymous insider position) is consistent with documented Solana rug-pull playbook - Multiple crypto security researchers flagged as a credible rug-pull risk within 48 hours of launch Sources: - CyberLeek GTA6 Leak Coin Investigation: https://bitquery.io/investigations/cyberleek-gta6-leak-coin - What Is CyberLeek Crypto? GTA 6 Leak Token Price and Scam Risks: https://bitcoinfoundation.org/news/altcoins/what-is-cyberleek-crypto-gta-6-leak-token-price-and-scam-risks/ - CyberLeek: GTA 6 Leak Token and Bleap Finance Analysis: https://www.bleap.finance/en-us/blog/cyberleek-crypto-gta-6-token Scout priority: 6/10 | Urgency: medium | Category: tokenAug 27
  • FulfilledTaj Tarsha / Few and Farpri 7Taj Tarsha, founder of Few and Far — an NFT marketplace startup — was indicted by the U.S. Attorney's Office for the Southern District of New York on August 5, 2026, on one count of securities fraud and one count of wire fraud. Tarsha raised over $10 million from at least 67 investors in 2022 via Simple Agreements for Future Tokens covering 95 million FAR tokens, then allegedly misappropriated funds for online casino gambling, speculative crypto purchases, a Miami condo loan, and personal expenses including DJ-related costs. The FAR token launched in May 2024 and became effectively worthless shortly after, leaving investors with total losses. Key findings: - Indicted August 5, 2026 (SDNY): one count securities fraud + one count wire fraud, each carrying up to 20 years imprisonment - Raised >$10M from 67+ investors in 2022 via SAFTs for 95M FAR tokens; funds misappropriated rather than used to build the NFT marketplace - Funds spent on: online casino gambling, speculative crypto trades, ~$1M in concealed salary and bonuses, Miami condo loan, interior decorating, DJ costs - FAR token launched May 2024 but quickly became effectively worthless and stopped trading - Tarsha was arrested June 6, 2026; indictment formally issued August 5; case assigned to U.S. District Judge Lewis A. Kaplan Sources: - NFT Startup Founder Charged With Fraud: https://www.justice.gov/usao-sdny/pr/nft-startup-founder-charged-fraud - Few and Far founder Taj Tarsha charged with misusing funds from $10 million raise: https://www.coindesk.com/policy/2026/08/06/nft-startup-founder-charged-with-misusing-funds-from-usd10-million-fundraising - US Charges NFT Founder in Alleged $10M Investor Fraud: https://www.occrp.org/en/news/us-charges-nft-founder-in-10m-investor-fraud - DOJ indicts NFT startup founder over alleged $10M investor fraud: https://cryptobriefing.com/few-and-far-founder-charged-fraud-10m-investors/ Scout priority: 7/10 | Urgency: high | Category: individualAug 27
  • FulfilledThe Sandbox SAND Bridge Exploitpri 8On August 21 to 22, 2026, an attacker exploited The Sandbox's SAND omnichain fungible token contract on Base and BNB Smart Chain by hijacking LayerZero delegate permissions via an approveAndCall function. Over five hours the attacker minted 329 trillion unbacked SAND tokens across 703 transactions — a notional face value of approximately $49 billion. Actual extracted value was approximately $675,000 (around 80 ETH drained from the Ethereum OFT Adapter). The Sandbox halted bridging on both chains and says it will snapshot and compensate eligible LPs. Key findings: - Attacker hijacked LayerZero delegate permissions on SAND OFT contract, enabling unauthorized minting of 329 trillion tokens across 703 events over 5 hours on August 21 to 22 - Notional mint value: ~$49 billion; actual on-chain extraction: ~80 ETH (~$675,000) drained from the Ethereum OFT Adapter - The Sandbox halted Base and BNB Smart Chain bridges immediately upon discovery; Ethereum bridge remained operational - SAND price dropped sharply before recovering once the limited actual-drain figure was clarified - The Sandbox stated it will snapshot impacted LP positions and compensate eligible holders Sources: - The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND: https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/ - The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens: https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/ - Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage: https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/ - The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND: https://cryptobriefing.com/sandbox-security-breach-500m-sand-minted/ Scout priority: 8/10 | Urgency: high | Category: protocolAug 27
  • FulfilledDeFi Governance Attack Wave 2026pri 6 Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedAug 26
  • FulfilledMiCA Transition Impersonation Scam Wave 2026pri 6 Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedAug 26
  • FulfilledCyberLeek / CYBERLEEK Solana Tokenpri 6 Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 6/10 | Urgency: undefined | Category: undefinedAug 26
  • FulfilledMaya Protocol — Six-Bug Exploit and Chain Haltpri 8 Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 26
  • FulfilledHarmony Protocol — Unauthorized 4 Billion ONE Token Mintpri 9 Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 26
  • FulfilledOFAC Operation Economic Outcast — Iran Digital Assets Sectoral Sanctions August 2026pri 7On August 24-25, 2026, the U.S. Treasury launched Operation Economic Outcast, issuing the first-ever sectoral sanctions designating Iran's entire digital assets sector as sanctionable under Executive Order 13902. This is a significant escalation beyond individual exchange designations — any global crypto business with Iranian counterparty exposure now faces secondary sanctions risk without needing a direct terrorism link. Designations include IRGC-Qods Force-linked crypto wallets and a Ministry of Intelligence cyber espionage group. This is distinct from the August 7 Shelbit/Aban Tether designations already in the corpus and represents a systemic compliance risk marker for a wide swathe of DeFi and CeFi entities. Key findings: - August 24-25, 2026: OFAC issued first-ever sectoral sanctions making Iran's entire digital assets sector sanctionable under E.O. 13902 - Designations cover IRGC-Qods Force-linked crypto wallets and a Ministry of Intelligence cyber espionage unit - Creates secondary sanctions exposure for any global crypto business with Iran-nexus counterparties — no direct terrorism link required - Separate from the August 7 Shelbit + Aban Tether action already in corpus; this is a broader sectoral escalation - Chainalysis notes compliance teams must urgently audit all Iran-nexus counterparty exposure across DeFi and CeFi Sources: - US Makes Iran's Crypto Sector Sanctionable, Ties Broker to M in Crypto Oil Payments: https://www.cryptotimes.io/2026/08/25/us-treasury-names-digital-assets-a-sanctionable-sector-of-irans-economy/ - OFAC Targets Crypto-for-Oil Payments in Latest Iran Sanctions: https://www.chainalysis.com/blog/ofac-iran-oil-payments-august-2026/ - OFAC Expands Iran Sanctions to Crypto Sector Under New Campaign: https://blockchain.news/news/ofac-iran-crypto-sanctions-2026 Scout priority: 7/10 | Urgency: high | Category: otherAug 26
  • FulfilledMANTRA Chain — Network Halt and Upstream Exploit August 2026pri 9On August 20-21, 2026, MANTRA Chain — an EVM network built for real-world asset tokenization — froze all block production after an attacker exploited a vulnerability in an upstream dependency. South Korean exchanges Upbit and Bithumb suspended OM deposits and withdrawals, and Binance kept withdrawals suspended for over 15 hours after the chain resumed. The native token dropped 18% to a record low of /bin/zsh.004126, with market cap at roughly million down from a billion peak in 2024. This is MANTRA second major crisis in 2026 following the April 2025 OM crash of over 98%. The upstream vulnerability has not been publicly disclosed. The existing corpus entry mantra-om-token covers the April 2025 token collapse; the August 2026 network halt is a distinct new exploit event requiring a dedicated investigation. Key findings: - Chain halted late August 20, 2026 after attacker exploited a vulnerability in an upstream dependency — specific CVE not yet publicly disclosed - OM token fell 18% to a record low of /bin/zsh.004126; market cap collapsed from a B 2024 peak to approximately M - Upbit, Bithumb, and Binance suspended OM deposits and withdrawals; Binance freeze lasted 15+ hours post-restart - Chain resumed at 03:38 UTC August 22, 2026 but upstream vulnerability root cause remains unpatched publicly - Second major MANTRA crisis in four months following the April 2025 98%+ token collapse Sources: - MANTRA token plunges 18% to record low as blockchain halts after exploit: https://www.coindesk.com/tech/2026/08/21/mantra-token-plunges-18-to-record-low-as-blockchain-halts-after-exploit - MANTRA Freezes Blockchain After Cosmos EVM Incident as Token Hits New Low: https://cryptopotato.com/mantra-freezes-blockchain-after-cosmos-evm-incident-as-token-hits-new-low/ - Chain Halt: Network Runs, Withdrawal Stays Frozen: https://cryptoticker.io/en/mantra-chain-halt-withdrawal-frozen/ Scout priority: 9/10 | Urgency: high | Category: protocolAug 26
  • FulfilledThe Sandbox SAND — LayerZero Bridge Exploit August 2026pri 8On August 21-22, 2026, attackers exploited The Sandbox's SAND omnichain fungible token on Base by hijacking LayerZero delegate permissions via the approveAndCall function. Approximately 329 trillion unbacked SAND tokens were minted across 703 events over five hours. Actual extraction was approximately 14.75 million SAND drained from the Ethereum OFT Adapter, yielding roughly 80 ETH (~$675,000). The existing Sandbox entity (trust score 30, updated August 25) covers the project generically. This specific bridge exploit — the third major LayerZero bridge attack in five months — warrants a dedicated incident investigation, particularly because it accelerated the industry's $15 billion migration from LayerZero to Chainlink CCIP. Key findings: - Attackers minted 329.24 trillion unbacked SAND across 703 events over five hours on August 21-22, 2026 - Root cause: hijacked LayerZero delegate permissions combined with unguarded approveAndCall function on Base - Actual extraction: ~14.75M SAND from Ethereum OFT Adapter, yielding ~80 ETH (~$675,000) - Third major LayerZero bridge exploit in five months following Kelp DAO ($292M, April) and Stake DAO (May) - Sandbox disabled Base and BNB bridging; removed LayerZero peer settings via multisig; Ethereum and Polygon SAND unaffected - Incident contributed to accelerating a $15 billion industry migration from LayerZero to Chainlink CCIP Sources: - The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — crypto.news: https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/ - The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND — CryptoBriefing: https://cryptobriefing.com/sandbox-security-breach-500m-sand-minted/ - Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes: https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/ - Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out — EdgeX: https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain Scout priority: 8/10 | Urgency: high | Category: protocolAug 25
  • FulfilledHarmony ONE (Protocol Entity)pri 6AVOID.NET has entries for the Harmony Horizon Bridge hack and the August 2026 mint exploit event but no general entity page for Harmony ONE or the Harmony Protocol as a standing entity. The August 2026 exploit -- forging 3 trillion ONE, ATH price crash to /bin/zsh.0005735, chain rollback erasing 109,000+ transactions -- constitutes a systemic trust failure that warrants a comprehensive entity page anchoring cross-references from all related incident pages. Key findings: - Harmony has suffered at least two major security incidents: 2022 Horizon Bridge hack and August 2026 cross-shard mint exploit - August 2026 exploit revealed quorum verification bug allowing unsigned messages to pass consensus -- fundamental Layer-1 failure - ONE token hit all-time low of /bin/zsh.0005735 after August 2026 exploit, reflecting near-total market confidence collapse - Chain rollback demonstrated severe centralisation: small validator set unilaterally rewrote 141,000+ blocks of ledger history - No general Harmony ONE entity page exists in AVOID.NET despite multiple incident-level pages referencing the protocol Sources: - Harmony ONE Crashes 37% as Hacker Mints 4B Tokens: https://shattered.io/harmony-one-exploit-4-billion-tokens-2026/ - Harmony Protocol Hack: 4 Billion ONE Tokens Minted, Price Crashes 30%: https://coinpedia.org/news/harmony-protocol-hack-4-billion-one-tokens-minted-price-crashes-30/ - Harmony plans chain rollback as forged ONE spreads across network: https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/ - Harmony ONE Hits to All-Time Low After 4B Token Mint Exploit: https://dailycoin.com/harmony-one-hits-to-all-time-low-after-4b-token-mint-exploit Scout priority: 6/10 | Urgency: medium | Category: tokenAug 24
  • FulfilledBybit v. DPRK Lazarus Group -- .5B Hack Civil Lawsuit (August 2026)pri 7On August 7, 2026, Bybit filed a civil lawsuit against the DPRK, its Reconnaissance General Bureau, and the Lazarus Group over the .5 billion hack, and secured a preliminary asset freeze order. This is a novel legal action -- no prior crypto company civil suit against a nation-state for crypto theft has reached this stage. The lawsuit creates legally significant records distinct from existing Lazarus Group entity pages and warrants a dedicated case-file entry as a landmark legal precedent. Key findings: - Bybit filed civil suit August 7, 2026, naming DPRK, Reconnaissance General Bureau, and Lazarus Group as defendants - Preliminary asset freeze order secured alongside the lawsuit filing - Underlying incident is the .5 billion Bybit hack -- the largest single crypto exchange hack on record - Multiple analytics firms and US intelligence agencies attributed the hack to DPRK TraderTraitor/Lazarus Group - First time a major crypto exchange has filed civil suit plus secured asset freeze against a nation-state actor for a crypto theft Sources: - Bybit sues North Korea and Lazarus Group over .5 billion hack, secures asset freeze: https://www.coindesk.com/policy/2026/08/07/bybit-sues-north-korea-and-lazarus-group-over-usd1-5-billion-hack-secures-asset-freeze Scout priority: 7/10 | Urgency: medium | Category: otherAug 24
  • FulfilledBridgers Cross-Chain Swappri 7Bridgers is a cross-chain swap service identified by blockchain intelligence firm BlockWatchdog as the linking mechanism in the August 9, 2026 Coinsbuy hack, connecting TRON and Ethereum attack legs in a single M theft. No Bridgers entity exists in AVOID.NET. Bridgers Ethereum payout contract forwarded stolen funds directly into the attacker swap wallet. Whether complicit, negligent, or an unwitting relay requires investigation, but its confirmed role in a major Tier 1-sourced incident warrants a formal entry. Key findings: - BlockWatchdog confirmed Bridgers as the cross-chain link tying together TRON and Ethereum components of the August 9 Coinsbuy M hack - Bridgers Ethereum payout contract forwarded stolen funds directly into the attacker designated swap wallet - No Bridgers entity currently exists in AVOID.NET despite appearance as laundering relay in a confirmed, Tier 1-sourced incident - Used in conjunction with FixedFloat in same attack chain where ~79% of funds passed before Monero conversion - Cross-chain swap services present high money laundering risk when operating without robust transaction monitoring or KYC controls Sources: - Crypto hackers drained million from Coinsbuy using a clever cross-chain trick: https://www.coindesk.com/business/2026/08/10/crypto-exchange-coinsbuy-loses-usd8-million-in-coordinated-two-blockchain-attack - Coinsbuy Hack Drains M as July Losses Hit M [2026]: https://shattered.io/coinsbuy-exchange-hack-2026/ Scout priority: 7/10 | Urgency: medium | Category: bridgeAug 24
  • FulfilledFake Crypto AML Checker Infrastructurepri 8Malwarebytes documented on August 19, 2026 a coordinated wave of fraudulent websites impersonating legitimate AML compliance tools such as AMLBot. The sites display fabricated wallet risk scans to social-engineer users into connecting wallets and signing drainer transactions. The attack surface is novel: masquerading as a trust-and-safety tool, scammers target the security-conscious demographic AVOID.NET serves. Covered independently by Malwarebytes, Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk. Key findings: - Malwarebytes identified live campaign of fake AML screening sites impersonating AMLBot and generic compliance tools, reported August 19, 2026 - Sites display fake progress indicators and fabricated Clean/Low Risk results before requesting wallet connection and drainer signature - Some variants charge small upfront screening fees in crypto to simulate legitimacy before executing the drain - Attack preys specifically on security-aware users actively trying to verify their wallet risk status - Genuine AML checkers need only a public address -- any request for wallet connection or signed transaction is a definitive red flag - Campaign confirmed by independent coverage in Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk on the same date Sources: - Scammers are using fake crypto AML checkers to drain your wallet: https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet - Fake Crypto AML Checkers Are Trying to Drain Users Wallets: https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets - Scammers are using fake crypto AML checkers to drain your wallet: https://securityboulevard.com/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet/ - Fake crypto AML checkers push users to approve wallet-draining transactions: https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/ Scout priority: 8/10 | Urgency: high | Category: otherAug 24
  • FulfilledStep App (FITFI)pri 7Step App, a move-to-earn fitness blockchain application, permanently shut down all services on August 21, 2026 after four years of operation. The FITFI governance token collapsed 99.9% from its $0.73 ATH to $0.0001624 with a market cap of approximately $12,229 at shutdown, leaving retail holders with near-worthless positions. The platform had over 1 million downloads at peak, indicating broad retail exposure. The tokenomics model — paying users in emitted FITFI and KCAL to walk and run — was structurally unsustainable and foreseeable as such, raising questions about whether investors were adequately warned. Key findings: - All Step App services permanently terminated August 21, 2026; FITFI token down 99.9% from $0.73 ATH to $0.0001624 - Market cap collapsed to approximately $12,229 at shutdown — negligible recovery value for retail holders - KCAL reward token also collapsed from $1-$4 peak (2022-2023) to $0.01 - Platform had over 1 million downloads at peak, indicating broad retail investor exposure before collapse - Shutdown attributed to 'unsustainable tokenomics' — emission-based model structurally unable to outlast initial hype cycle - Cointelegraph, CryptoTimes, and CryptoBriefing all covered the closure with Tier 1/2 sourcing Sources: - Step App Shuts Down After 4 Years, FITFI Token Collapses to Near-Zero Market Cap: https://www.cryptotimes.io/2026/08/06/step-app-shuts-down-after-4-years-fitfi-token-collapses-to-near-zero-market-cap/ - Move-to-earn app Step App to shut down after four years: https://cryptobriefing.com/step-app-shuts-down-operations/ - Step App Shuts Down After Four Years as FITFI Extends Decline: https://cointelegraph.com/news/step-app-winds-down-four-years-move-to-earn - Emergency Exit Window Opens as Step App and NoOnes Cease Operations Today: https://nulltx.com/emergency-exit-window-opens-as-step-app-and-noones-cease-operations-today Scout priority: 7/10 | Urgency: medium | Category: tokenAug 24
  • FulfilledThe Sandbox — SAND Bridge Exploit (August 2026)pri 8On August 22, 2026, The Sandbox's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions combined with an approveAndCall mechanism, enabling unauthorized minting of up to 329 trillion face-value SAND tokens ($49 billion notional) across 400+ transactions over five hours. Actual realized losses were ~$675,000 in SAND plus ~79.74 ETH due to limited liquidity for the unbacked tokens. The Sandbox paused bridging on Base/BSC and contained the exploit before funds reached Ethereum. While the realized dollar loss is bounded, the attack vector — compromise of LayerZero delegate authorization — is a novel bridge security failure on a major mainstream gaming protocol with billions in token supply. The Sandbox does not appear to have a dedicated incident page in the corpus. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: undefined | Category: undefinedAug 24
  • FulfilledBounceBitpri 9BounceBit, a YZi Labs-backed Layer 1 BTC restaking chain, suffered an authorization exploit on August 19-20, 2026, in which an attacker moved 286.5 million BB tokens (~$3 million) across 14 transactions over four hours and 52 minutes. The bug resided in the Evmos vesting account module: a second authorization check ran against the wrong principal, allowing any caller to designate an arbitrary account as the funding source without holding a valid grant. No private keys were stolen and no user wallets were broken — the protocol logic itself was the attack surface. The exploit was severe enough to trigger a permanent chain shutdown; BB tokens will be reissued on BNB Chain via a pre-attack snapshot. The underlying Evmos framework was discontinued in May 2026, making a rebuild infeasible. This is a confirmed major incident that killed a live L1 chain and requires full investigation. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 9/10 | Urgency: undefined | Category: undefinedAug 24
  • FulfilledSolidity Pro VSCode Extension (Malicious)pri 7Two malicious Visual Studio Code extensions published as 'Solidity Pro' were confirmed in August 2026 to steal Web3 developer private keys, seed phrases, and cloud credentials via Telegram and Cloudflare Workers. Malware activated hours to days after install to evade automated scanners. Open VSX flagged both publishers (helper-beeps, web3devtoolsx) as malicious on August 6-7. Anyone who ran Solidity Pro 3.4.0 may have had production wallet keys exposed. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 7/10 | Urgency: high | Category: otherAug 23
  • FulfilledKey Coin Assets Ltdpri 8Key Coin Assets Ltd was wound up by the UK High Court on August 11, 2026 after the Insolvency Service confirmed no genuine cryptocurrency trading ever occurred. The firm promised 40-100% guaranteed returns, paid early investors with later investor funds, falsely claimed £42 million in assets at Companies House, and its director transferred investor deposits directly into a personal bank account on the same day they arrived. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: high | Category: otherAug 23
  • FulfilledCYBERLEEK Tokenpri 8CYBERLEEK is a Solana meme coin that staged fabricated GTA VI leak footage on August 18, 2026 with QR codes for the token burned into the video — three days after minting on August 15. Kotaku, GamesRadar, and Bitquery all confirmed the 'leak' was premeditated token advertising. Creators collect transaction fees continuously and raised an estimated $30,000 on day one alone; token reached a $22 million market cap with $112M daily trading volume at peak. Key findings: Sources: - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined - undefined: undefined Scout priority: 8/10 | Urgency: high | Category: tokenAug 23
  • FulfilledMaya Protocol (MAYAChain)pri 8Maya Protocol, a cross-chain DEX on MAYAChain, was exploited on August 18, 2026, through six chained software bugs in a single transaction. The attacker extracted ~20 BTC and ~$300K in other assets (direct loss ~$1.7M; pool-value impact ~$11M). CACAO crashed 89% to an all-time low. The network halted and has not resumed as of August 23. No funds returned. MAYAChain is a distinct protocol from THORChain and has no existing AVOID.NET investigation page. Key findings: - Six chained bugs exploited in a single 23-message MsgDeposit transaction on August 18, 2026 - ~20 BTC and ~$300K in other assets drained; total pool-value impact ~$11 million per CoinDesk - CACAO token crashed 89% intraday to an all-time low of ~$0.013 - MAYAChain halted all swaps and cross-chain operations; not restored as of August 23 - Attacker manipulated ARB.LINK accounting via a false slash subsidy then withdrew from the inflated pool; no funds returned Sources: - Six-Bug Exploit Halts Maya Protocol After $1.4 Million in Bitcoin Stolen: https://decrypt.co/375976/maya-protocol-halts-network-bitcoin-exploit - Maya Protocol exploit drains bitcoin and other assets as pool value drops by $11 million: https://www.coindesk.com/markets/2026/08/19/maya-protocol-exploit-drains-bitcoin-and-other-assets-as-pool-value-drops-usd11-million - Maya Protocol Becomes the 16th Crypto Hack Logged in August Alone: https://beincrypto.com/maya-protocol-exploit-halts-btc-swaps/ Scout priority: 8/10 | Urgency: high | Category: protocolAug 23
  • FulfilledTerm Labspri 9Term Labs, a fixed-rate DeFi lending protocol on Ethereum, suffered an $8.5 million governance exploit on August 23, 2026 — the same day as this scout run. An attacker funded with only 2 ETH from Tornado Cash bootstrapped sufficient voting power to seize supermajority control of four out of five USDC strategy vaults and 91% of the Ethereum Meta Vault, then voted to drain ~2,843 ETH and 1.6 million DAI. This is an active same-day incident. The governance attack vector means standard smart contract audits would not have flagged it, and the extremely low seed cost demonstrates systemic fragility in token-vote governance. Key findings: - $8.5 million drained in a governance manipulation attack on August 23, 2026 — the 18th logged hack of August alone - Attacker used only 2 ETH sourced from Tornado Cash to gain 100% voting control over four strategy vaults - ~2,843 ETH and ~1.6 million DAI drained to a single address starting 0xD5183 - Attack vector was governance manipulation, not a code exploit — standard audits would not have prevented it - DeFi governance attacks have extracted $25.1 million across five 2026 incidents; Term Labs is the largest single event in that cluster Sources: - Term Labs suffers $8.5M governance exploit as attacker seizes control of strategy vaults: https://cryptobriefing.com/term-labs-governance-exploit-vaults/ - Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit: https://beincrypto.com/term-labs-defi-exploit-vaults/ - Term Labs Loses $8.5M as Governance Exploit Drains Ethereum Vaults: https://cryptoadventure.com/term-labs-loses-8-5m-as-governance-exploit-drains-ethereum-vaults/ Scout priority: 9/10 | Urgency: critical | Category: protocolAug 23
  • FulfilledCrypto Whale — $25.6M Repeat Phishing Drain (August 2026)pri 6On August 12, 2026, an unidentified crypto whale lost $25.6 million in WBTC, cbBTC, LDO, USDS, and CRV through a phishing attack — marking the second major breach of the same wallet, which previously lost $24.2 million to the same phishing vector in 2023. Stolen assets were swapped to 20M DAI and 3,000 ETH and traced by PeckShield to four distinct addresses. This documents a systematic repeat-targeting pattern: the same methodology attacked the same wallet three years apart, suggesting either highly persistent adversarial intelligence on prior victims or automated scanning of historically exploited addresses. AVOID.NET should document this phishing infrastructure as a standalone threat entry. Key findings: - August 12, 2026: $25.6M drained from an unidentified whale wallet — WBTC, cbBTC, LDO, USDS, and CRV via phishing - Same wallet had lost $24.2M to the same phishing method in 2023 — documented repeat targeting of a prior victim - Stolen assets swapped to 20M DAI and 3,000 ETH; PeckShield traced funds to four distinct addresses - Part of a week (Aug 9-15) that saw over $37M in confirmed crypto theft across multiple incidents - Repeat targeting three years apart suggests persistent attacker intelligence on historically exploited wallets or addresses Sources: - Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M: https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/ - Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M: https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/ - Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack: https://beincrypto.com/crypto-whale-25-million-wallet-drain/ - A Crypto Whale Lost $25.6 Million To The Same Phishing Trick Twice: https://startupfortune.com/a-crypto-whale-lost-256-million-to-the-same-phishing-trick-twice/ Scout priority: 6/10 | Urgency: medium | Category: otherAug 23
  • FulfilledBoltz Bitcoin Bridgepri 9Boltz, a non-custodial open-source Bitcoin bridge enabling swaps between the Bitcoin mainchain, Lightning Network, and Liquid sidechain, shut down all swap operations indefinitely on August 3, 2026 after sustained AI-assisted exploitation attacks overwhelmed its small team. Multiple resourceful groups used automated AI tooling to probe Boltz's public codebase and generate novel exploit attempts faster than the team could ship patches. While Boltz's non-custodial design prevented direct user fund losses — losses fell on company operating funds — the service remains offline as of August 21 with no relaunch date. The original founders stepped away and transferred the project to a group described as 'Bitcoin veterans.' This is a novel threat pattern (AI-accelerated exploitation outpacing human patching) relevant to AVOID.NET users who may attempt to use Boltz or rely on wallets like Aqua and Bull Bitcoin that depended on it. Key findings: - August 3, 2026: Boltz halted all swaps indefinitely after AI-assisted hacking outpaced its patching capacity - Multiple resourceful groups used automated AI tooling to probe the public codebase and generate new exploit attempts faster than patches could ship - Boltz's non-custodial HTLC design prevented user fund losses; company operating funds were depleted by contained exploits - Approximately $262,000 TVL was held before the pause; wallets Aqua and Bull Bitcoin lost Lightning swap functionality - As of August 21, 2026, swaps remain offline with no announced relaunch date; original founders transferred the project to new operators - First documented case of a crypto service self-shutdown specifically due to AI-accelerated vulnerability discovery Sources: - This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast - Decrypt: https://decrypt.co/374933/bitcoin-bridge-shuts-down-ai-finding-bugs-too-fast - Boltz Bitcoin Bridge Shutdown: AI Hacks Force Exit [2026]: https://shattered.io/boltz-bitcoin-bridge-ai-hack-shutdown-2026/ - Boltz Bridge shuts down swap services indefinitely after AI-powered exploits overwhelm its team: https://cryptobriefing.com/boltz-bridge-shuts-down-ai-exploits/ - Boltz's shutdown shows the real danger of AI hacking is pushing crypto back into the hands of giant custodians: https://cryptoslate.com/boltzs-shutdown-shows-the-real-danger-of-ai-hacking-is-pushing-crypto-back-into-the-hands-of-giant-custodians/ - Bitcoin Bridge Boltz Suspends Services Amidst Rising AI Threats: https://protos.com/bitcoin-bridge-boltz-suspends-services-as-ai-hacks-outpace-patches/ Scout priority: 9/10 | Urgency: high | Category: bridgeAug 23

Failed / Rejected (5)

  • RejectedAquiferpri 7Solana-based proprietary automated market maker Aquifer was exploited for roughly $2.5 million on August 31, 2026 via a wallet/credential compromise. The team's on-chain 'whitehat' offer (80% return for a 20% bounty, deadline September 3, 2026 14:00 UTC) has passed with no public confirmation of fund recovery as of the most recent reporting, meaning the incident is unresolved and user/LP funds remain at risk. Not currently present in the AVOID.NET corpus. Key findings: - Attacker compromised linked Solana and Ethereum wallets tied to Aquifer, draining approximately $2.5 million on August 31, 2026 - Aquifer's Solana upgrade authority cryptographically signed an on-chain message offering the attacker 20% of funds as a bounty in exchange for returning 80% by September 3, 2026, 14:00 UTC - As of the latest reporting (September 4, 2026), no public source confirms the attacker returned any funds; the deadline passed without resolution - Incident occurred amid a record month for crypto hacks (50+ incidents in August 2026 per industry trackers) Sources: - Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty: https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/ - Aquifer Exploit Drains $2.5M as August Hacks Hit 50 [2026]: https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/ Scout priority: 7/10 | Urgency: high | Category: protocolDuplicate of request d66e06de-208a-42c7-b943-171607237e92 (aquifer-solana-amm) — same 31 Aug 2026 $2.5M Aquifer exploit, surfaced by a second scout sweep with richer sourcing. Kept the higher-priority entry.Sep 9
  • Rejectedsw-hk.comEmpty submission - no context provided, no claim to verify. Reversible: set status back to queued with context if this was real.Sep 4
  • RejectedContactTestingTest submission - context is literally 'Testing'. No entity, no claim, nothing to investigate. Reversible: set status back to queued if this was real.Sep 3
  • FailedContactJunk submission: 'Contact' is not a crypto entity (likely a web form field name)Sep 1
  • FailedContactjunk submission: entity_name='Contact' with no contextAug 28

Admin: Process Queue