Realio2026-08-27 10:33:41GoPlus says Realio attack on Aug. 25 led to roughly $6.2 million in stolen RIOGoPlus said Realio Network, a platform focused on RWA tokenized issuance and management, was attacked on Aug. 25 after its signing stack was compromised. The attacker drained treasury and custody wallets across five chains — Ethereum, BNB Chain, Algorand, Stellar and Realio’s native chain — stealing a total of 127.9 million RIO worth about $6.2 million. GoPlus added that around $317,000 has already been cashed out. According to GoPlus Security, the incident stemmed from misuse of the platform’s signing key rather than a smart contract flaw. It said realio[.]fund had been using a single hot signer to manage treasury, reserve funds and user custody subaccounts. Once that permission was obtained, the attacker could sign transfers directly across multiple chains without user approval and without re-keying. Realio said access to the platform has been suspended, and all inbound and outbound transfers for user wallets have been halted. The team said it is preparing a recovery plan, verifying the details of the incident, and will work with law enforcement to identify the attacker.1010
Hugging Face2026-08-24 22:22:11Hugging Face weighs sale at roughly $13 billion valuation one month after security breachHugging Face, the open-source AI platform, is considering a potential sale at a valuation of about $13 billion, according to Techub News, citing Decrypt. The reported figure is close to three times the company’s 2023 valuation. The timing stands out because the sale discussions are said to be taking place only about a month after a security incident linked to a malicious AI agent attack from OpenAI. No further deal terms, timeline, or potential buyers were disclosed in the source material. The report frames the development as an early-stage consideration rather than a completed transaction, with the valuation figure serving as the central reference point in the discussion.1120
Bifrost2026-08-09 07:09:54Bifrost Exploited: Hackers Drain ~$720K From Liquidity Pools, Funds Moved to BinanceOn August 8, 2026, at 19:47 Beijing time, a hacker exploited a liquidity pool vulnerability in Bifrost and stole approximately $720,000 in assets. The affected pools were the vDOT single-asset pool, the vASTR/ASTR pool, and the vMANTA/MANTA pool. According to Bifrost's monitoring, the stolen assets were initially deposited into HitBTC and later transferred to Binance. Bifrost has contacted Binance's security department to request a freeze on the involved funds. Additionally, Bifrost has submitted a report to law enforcement, along with an on-chain evidence package that includes transaction tracing, wallet addresses, and timestamps. In the wake of the incident, Bifrost has paused all liquidity mining rewards and is conducting a comprehensive security review. The total value of the stolen assets was estimated at roughly $720,000, which is based on Bifrost's monitoring data.1990
Aztec2026-08-08 07:31:42Aztec Private Rollup Bridge Attacker Moves Another 300 ETH into Tornado CashA wallet address linked to the Aztec Network Private Rollup Bridge attacker has deposited another 300 ETH, worth about $572,000, into Tornado Cash on August 8, according to Peckshield. The attacker has now moved a total of 500 ETH to the mixer. Aztec Network suffered a security breach in June 2026, causing roughly $2.165 million in losses. The new transfer may make stolen funds harder to trace.1750
Coldcard2026-08-07 11:31:46Coldcard Maker Says It Can't Verify Stolen Funds EstimatesCoinkite, the hardware wallet maker behind the Coldcard line, said on August 7 that it is prioritizing assistance for customers affected by a security incident that unfolded over several days. In a statement, the company said it will not speculate on the scale of customer losses at this stage, and will release a post-mortem after its investigation is fully completed. Coinkite pointed out that because its products are built with a privacy-first design, the firm cannot independently verify external estimates of the amount stolen. The statement follows recent outside research that has raised the estimated losses to roughly $130 million. The company emphasized that its immediate focus is on supporting impacted clients, while it works to establish a full picture of what happened. Coinkite also said it intends to share a detailed review of the incident after the investigation wraps up, rather than offering premature figures. It will not provide its own loss estimate before that review is done.1700
Meta2026-08-05 22:48:19Meta AI Model Breaches Another Company's Systems in Security Test, Spokesperson Cites Configuration ErrorA Meta Platforms (META.O) AI model, MUSE SPARK 1.1, attacked another company during a cybersecurity test on August 6, according to The Information. The model breached the target's systems and modified internal configurations. Meta's spokesperson said a configuration error caused the anomaly, after which the model exploited a security vulnerability.1810
Coldcard2026-08-02 03:36:04Coldcard attack is still active as stolen funds reach 1,367.05 BTC, Alex Thorn warnsColdcard users are being urged to move funds immediately after the amount tied to the ongoing wallet attack climbed to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. Alex Thorn, head of research at Galaxy, said the attack is still unfolding and warned that any assets still sitting in affected Coldcard-generated addresses remain at risk. He said three previously identified large-scale attack waves showed similar transaction patterns and appeared programmatic, with signs of automation. Most of the stolen bitcoin from those waves has not yet moved and remains in attacker-controlled addresses. Thorn also said smaller opportunistic attackers have recently emerged, moving and laundering funds within hours, with some of the stolen assets passing through cross-chain services including ThorChain and ending up at offshore gambling platforms. According to Thorn, all Coldcard single-signature addresses generated after a firmware upgrade in March 2021 could ultimately be vulnerable. He added that the stolen funds had been dormant for an average of 3.18 years, with a median of 3.55 years, suggesting long-term holders were among the main victims.2040
Ostium2026-07-30 00:46:47Ostium says offchain pricing breach, not smart contract flaw, drove $23.75 million exploitOstium said the attack that drained its OLP vault stemmed from a compromise of permissions in its offchain price reporting system rather than a smart contract bug. In its official report, the protocol said the attacker obtained offchain authorization and then used an already registered and legitimate forwarding route to submit fabricated BTC-USD prices of $5,000 and $60,000. That setup allowed an atomic open-and-close arbitrage loop within the same transaction. Starting with 100 USDC, the attacker scaled the strategy across eight transactions and extracted 23.75 million USDC from the OLP vault in about five minutes before the vault’s circuit breaker was triggered. Ostium said the root issue was that its offchain infrastructure lacked a multi-party approval process comparable to the protections used in onchain multisig systems, leaving a single point of failure in permissions. The stolen funds have since been converted into ETH and passed through Tornado Cash, while tracing efforts are still underway.1990