EXPLOIT news
Attacker Prints 5.23M WEMIX$ From Thin Air, Forces a Full Network Halt
At 09:17 UTC on July 26, an attacker with admin rights over the WEMIX$ stablecoin contract minted 5,225,525 tokens (about $5.22M) and laundered roughly $724,198 in USDC.e across Ethereum and BNB Chain, prompting WEMIX to freeze bridges, DEX and marketplace trading.
B² Network Skipped The Whitehat Bounty Script And Offered The $3.86M Attacker Outright Legal Immunity For A Partial Refund
B² Network lost 8.59M B2 (~$3.86M) after an attacker compromised the upgrade authority on its staking contract. Funds moved B2 to BNB to ETH, then through NEAR Intents into Zcash. B² responded with a legal immunity offer, not a standard whitehat bounty.
Verus Redeposited $11.56M Into The Bridge That Just Got Drained. Two Weeks Later An Attacker Emptied It Again For $7.54M
Verus refunded its bridge on July 8 after the May exploit. Fourteen days later a different attacker drained $7.54M through the same forged import path bug class. Blockaid flagged the entry vector as identical. Post-incident review missed the class.
42DAO's Own Oracle Signed Off On A BTCB Print That Let An Attacker Mint 4.5 Million BLC From Nothing
An attacker poked 42DAO's Median Oracle on July 22, 2026, got a bad BTCB print accepted, and used it to mint 4.5M BLC from a null address on BNB Chain. The drain via PancakeSwap V2 hit $915K and the stablecoin collapsed 99% to $0.001209 in two hours.
Allbridge's Own 2023 Fix Would Have Blocked This Attack, But Solana's Pool Was Misconfigured
Allbridge paused Core after an attacker drained roughly $1.65M from Solana stablecoin pools using a Kamino flash loan. A post-2023 safeguard should have stopped the exact attack, but the Solana pool held both USDC and USDT.
Follow every move that matters to your bag.
Track your portfolio, LP positions and impermanent loss live. Join Koinlytics and see what moves the market before it shows on Twitter.
Join Koinlytics
Koinlytics