
NEAR Intents is back online after a $3.8 million exploit that targeted an interaction flaw between Omni's deposit and withdrawal infrastructure and NEAR Intents smart contracts, affecting USDT on BSC. Co-founder Illia Polosukhin said the team patched the vulnerability within an hour of detection and pledged full compensation to affected users. The core NEAR protocol, NEAR token, and other applications were unaffected, though some impacted chains remain restricted. A full post-mortem is planned.
19 hours ago

An internal FBI memo instructs employees to assume that the hacking group ShinyHunters has stolen their personal data. The group claims it breached FBIjobs.gov through an Oracle PeopleSoft zero-day vulnerability, exfiltrating 2 to 3 TB of data covering nearly all FBI agents and job applicants, and even some spouses' information. Brett Leatherman, head of the FBI's cyber division, responded in a video on September 29, mentioning arrests in the Netherlands and issuing a warning to the hackers. The article focuses on the data breach; cryptocurrency only appears in the price ticker module and is unrelated to the main text.
2026-09-30

This article examines the reality of crypto wallet control through three incidents: HTX-related dust transfers that can cheaply cripple exchange hot wallets and force withdrawal suspensions; Bitget's roughly $388 million loss after a third-party security product flaw allowed forged internal signing instructions, triggering unauthorized transfers from hot and warm wallets; and a U.S. Senate report scrutinizing Iran-linked USDT flows, showing Tether can freeze assets at specific addresses. The article argues that wallet control does not belong solely to private key holders but is distributed among senders, custodians, issuers, and regulators, and that on-chain visibility also has its limits.
2026-09-30

A MEXC user reported losing roughly $340,000 after their account was compromised, with the attacker allegedly retaining API access even after account recovery. Between 04:12 and 04:25 on September 27, 322,110 USDT and 9,133,999 ONE were withdrawn — just 27 minutes after a 24-hour security lock was lifted. MEXC says it has reached an agreement with the user and calls the matter "fully resolved," but has not disclosed settlement terms or confirmed any compensation. The incident began with an unauthorized security reset request on September 25, after which the exchange froze the account and restored the original email.
2026-09-28

Zano has restarted its chain at block 3,833,000, erasing roughly a month of network history after a Gateway Address vulnerability allowed unauthorized ZANO and fUSD tokens into circulation. The rollback predates hard fork 6, which activated the Gateway Address feature in August. Miners, stakers, node operators, and exchanges must install updated software and follow the restored chain. MEXC has suspended ZANO and fUSD deposits and withdrawals. Zano says it will compensate affected users using funds from developers, the team, and large holders, without minting new tokens. ZANO's price fell over 12% within 24 hours.
2026-09-28

Japanese police have arrested two suspects accused of helping a fake-police scam ring steal about ¥81 million in cryptocurrency from a woman in her 40s. The group, believed to be based in Cambodia, allegedly posed as Japanese officers and pressured the victim into transferring funds by claiming her bank card was tied to a money-laundering probe. Confirmed losses in related cases total roughly ¥240 million, while fake-police scams in Japan have cost ¥617.1 billion this year through July. Authorities believe a Chinese national directed the operation from an overseas scam center. The specific cryptocurrency and wallet addresses were not disclosed.
2026-09-27

Google revealed that its AI security agent, PageBreak, has discovered more than 500 cross-site scripting (XSS) vulnerabilities across its own web applications, including some sensitive domains, though the company did not disclose which apps were affected or how severe the flaws were. Launched as a pilot in November 2025 and promoted to a full project in January 2026, PageBreak relies on models like Gemini 3.1 Pro and 3.5 Flash to scan for bugs, then uses an independent verifier to inject JavaScript payloads and confirm whether each flaw is actually exploitable, keeping false positives near zero. Google also plans to integrate PageBreak more tightly with CodeMender, which can automatically generate fix code.
2026-09-25

Google has unveiled PageBreak, an internal AI agent built by its product security team to automatically find and verify real vulnerabilities in its own web apps. Unlike typical AI scanners, it only reports a flaw after confirming it through actual exploitation, keeping false positives near zero. It has already uncovered over 500 XSS bugs and is set to work alongside CodeMender, an automated patching agent. The article also touches on the flood of low-quality AI-generated vulnerability reports and the growing buzz around AI in security.
2026-09-25

A couple in the West Midlands, UK, were forced to transfer a large amount of cryptocurrency to attackers' wallets after three men broke into their home, with a fourth directing the operation remotely via video call. Police believe it was a premeditated, targeted robbery, and Crimestoppers is offering up to £10,000 for information. CertiK data shows home invasions became the dominant form of physical attacks on crypto holders in the first half of 2026, with 52 incidents recorded and about $124.1 million involved.
2026-09-24

The FBI hosted its ninth Virtual Assets Technical Exchange in San Antonio, bringing together hundreds of investigators, foreign law enforcement partners, and crypto security experts to address rising digital asset fraud, hacking, and state-sponsored cyber threats. FBI data shows crypto-related complaints caused over $11 billion in losses in 2025, while Chainalysis estimates sanctioned entities received $104 billion in crypto that year, up 694% year-over-year. TRM Labs reports North Korea-linked crypto theft reached $643 million in the first half of 2026. Topics included terrorist financing, scams, human trafficking, and violent attacks targeting crypto holders.
2026-09-24