Permit22026-10-04 03:04:08Address loses $167,300 in LINK after signing Permit2 phishing approvalOdaily reported that a user lost $167,300 worth of LINK tokens after signing a phishing approval targeting Permit2 on Ethereum on Aug. 18, 2025. The brief identified the incident as a Permit2-related phishing authorization and said the loss took place on Ethereum. No additional details were provided about the address, the transaction path, or where the tokens were moved after the approval was signed. The report was published by Odaily as a market analysis newsflash.40
SlowMist2026-10-04 01:59:40SlowMist says Goldpesa exploit caused about $114,900 in lossesSlowMist said Goldpesa was exploited, with losses estimated at about $114,900. According to the security firm, the root cause was in GPXHooks' reBalance() logic. When it performed liquidity operations through a shared PositionManager, it failed to verify whether the GPX/USDC currency delta was zero, leaving the hook's burn credit unisolated from the caller's state. SlowMist said the attacker used an unlock action together with an unsettled MINT_POSITION operation to create a negative delta, then triggered rebalance so the hook generated positive credit. Because TAKE_PAIR could only withdraw the net amount, the hook actually received only about 33,900 USDC, while the difference was offset by what SlowMist described as phantom debt. The attacker then burned their own position, canceled out the debt, and withdrew about 115,000 USDC from PoolManager.40
CertiK2026-10-01 11:46:56CertiK says Q3 2026 saw 247 security incidents with roughly $1.26 billion in lossesCertiK’s security dashboard recorded 247 security incidents in the third quarter of 2026, according to a ChainCatcher news brief. That figure was up 12.8% from the previous quarter. Total losses for the quarter were about $1.26 billion. CertiK’s data also showed that the Q3 loss figure was 53.9% higher than the $819.4 million reported for the second quarter. The update provides a quarter-over-quarter snapshot of incident count and financial damage based on CertiK’s tracking data.60
North Korea2026-09-30 09:16:54Elliptic says North Korea-linked crypto thefts topped $1.2 billion this yearElliptic said it has tracked more than 50 security incidents tied to North Korea, with total funds stolen this year reaching about $1.2 billion. The firm also said some of the funds stolen from Bitget overlap with addresses linked to last year’s $1.5 billion Bybit exchange hack. Based on preliminary on-chain money laundering patterns, Elliptic said the Bitget incident appears to have been carried out by the hacking group TraderTraitor. The update ties together the latest Bitget theft with previously identified wallet activity connected to the Bybit case and adds to Elliptic’s running count of North Korea-related attacks monitored so far this year.190
Chainalysis2026-09-29 23:16:52Chainalysis says crypto crime is becoming more professionalized, with attackers adopting AI faster than defendersDuring Money20/20 Asia in Bangkok in April 2026, Chainalysis ASEAN and Hong Kong Regional Director Diederik Van Wersch told WuBlockchain that the crypto industry is entering a phase where several forces are converging at once: stablecoins are moving deeper into payments, more institutions are entering on-chain finance, regulators are shifting from rulemaking to enforcement, and AI is changing both attack and defense. In his view, that convergence matters more than any single trend on its own. Van Wersch said on-chain crime is becoming more organized and industrialized. Chainalysis cited figures from its 2026 Crypto Crime Report showing that crypto addresses linked to illicit activity received at least $154 billion in 2025, up 162% year over year, with value received by sanctioned entities rising 694%. He also argued that blockchain transparency does not automatically make the sector safer. Public data still needs attribution, cross-chain tracing, behavioral analysis, and real-world context before it can support risk decisions. The interview also covered stablecoin compliance, regional competition among Hong Kong, Singapore, and the UAE, growth across APAC markets such as India, Japan, Indonesia, and Vietnam, and the limits of manual investigations as criminals begin using AI more aggressively. Van Wersch said attackers are currently adopting AI faster because they face fewer regulatory and audit constraints, but he maintained that defenders still hold a structural advantage because blockchain transactions remain traceable and auditable over time.160
DYORSWAP2026-09-28 13:08:04DYORSWAP users sent 767.65 ETH to a fake GIWA bridge after spoofed chain passed checksDYORSWAP, a multi-chain decentralized exchange, said scammers tricked it into integrating a fake version of the upcoming GIWA blockchain over the weekend, leading users to send funds to a spoofed bridge contract. The incident resulted in roughly $2 million in losses, with DYORSWAP later saying 1,335 addresses bridged a total of 767.65 ETH and that almost all of it was drained. According to the exchange, the fake OP Stack chain used the same chain ID as the legitimate GIWA network, 9134, which made it appear valid during DYORSWAP’s initial verification. DYORSWAP also pointed to suspicious messages that may have spread false information inside its community. The bridge contract was deployed shortly after 6 PM UTC on Saturday and emptied a little more than 12 hours later, with proceeds later moved into Tornado Cash. GIWA’s official X account denied that its mainnet existed, but the denial came only minutes before the fake bridge was drained. DYORSWAP said users who bridged less than 5 ETH would receive a 40% refund, while larger cases would be reviewed individually. In a later update, it said it had already distributed more than 200 ETH in compensation and identified addresses it believes were involved in the scam, allegedly funded from Binance and Gate.220
GoPlus2026-09-28 09:54:04GoPlus flags another meme coin rug factory on Robinhood Chain with over $9 million in 30-day flowGoPlus Security said on Sept. 28 that it had identified a high-risk fraudulent meme coin factory on Robinhood Chain, with more than $9 million in transaction flow over the past 30 days and links to hundreds of scam meme tokens. The team pointed to a fund collection address, 0x8c3Bad30cc7563A2D0357F49509FFd063666bb00, which held about 56.0635 ETH, or roughly $148,000, as of Sept. 28, 2026. According to GoPlus, the address had around 1,385 transactions in total. Across its latest 400 transactions, inflows were about 1,728.02 ETH and outflows were about 1,861.12 ETH, bringing two-way turnover to roughly 3,589.14 ETH, or about $9.49 million. GoPlus said it found direct on-chain evidence across related high-risk meme tokens showing a pattern of token approval or selling, liquidation into ETH, and transfers into the same collection address. The firm added that the figures reflect gross amounts routed into the collection system for the same project batches, not net profit. It also compared the pattern with a separate case recently disclosed by on-chain researcher Wazz, while saying there is no evidence at this stage that the two cases involve the same group.520
DYORSWAP2026-09-28 00:12:15DYORSWAP says fake GIWA incident was a scam network, with about 766 ETH moved out and over 200 ETH repaidDYORSWAP said in an official statement that the so-called GIWA mainnet 9134 incident was not caused by a vulnerability in the DYOR contract. Instead, the team said the losses were tied to a fraudulent network impersonating GIWA Chain 9134. According to the statement, the network had a bridge and batcher resembling OP Stack infrastructure and was deployed at 02:10:59 on Sept. 27, 2026, UTC+8. Roughly 8.5 hours before deployment, the address received about 0.045 ETH from an address linked to ChangeHero. On-chain data cited by DYORSWAP shows that 1,335 addresses bridged in about 767.65 ETH in total, and around 766.25 ETH was ultimately transferred out through the cross-chain bridge. DYORSWAP also said it has already used its own funds to compensate affected users with more than 200 ETH. The team added that it is still tracing the bridge deployer, the source of funds, early test wallets, and the later movement of the transferred assets.270