exploitsTriple-A's $11.8M Hot Wallet Drain: Seven Chains, and 31 Hours Nobody Closed the TapTriple-A's treasury wallets were swept across seven chains starting July 24, 2026. The theft took hours. Deposits kept arriving and kept being swept for 31.Dmitry Serdyuk·Jul 30, 20263m
exploitsB2 Network $3.86M Staking Drain: The Upgrade Key Did All the WorkB2 Network lost 8.59M B2 tokens, about $3.86M, when someone used the staking contract's upgrade authority. That privilege had sat on the same wallet since 2025.Dmitry Serdyuk·Jul 27, 20263m
exploitsAFX Trade $24.15M Bridge Exploit: Compromised Validator Keys Signed a Valid DrainAFX Trade's bridge lost $24.15M in USDC on Arbitrum. No contract bug: five operator-held validator keys signed a real quorum, and the bridge did exactly as told.Dmitry Serdyuk·Jul 24, 20263m
exploitsThe Fake Recruiter Repo That Hid Its Malware in a Tailwind ConfigA fake Web3 recruiter sends a GitHub repo to try before the interview. The malware hides as a 4 MB Tailwind plugin, fires on the dev command, and hunts wallets, SSH keys, and seed phrases.Dmitry Serdyuk·Jul 23, 20264m
exploitsThe TRAE Extension Backdoor That Ran Its C2 on an Ethereum ContractA fake Solidity plugin, juannegro.solidity, backdoors Windows, macOS, and Linux dev machines and reads its C2 address from an Ethereum contract the attacker updates on-chain.Dmitry Serdyuk·Jul 22, 20263m
exploitsAllbridge Core $1.65M Exploit: A 2023 Flash Loan Fix That Missed SolanaAllbridge Core lost $1.65M on Solana to the same flash loan trick it said it fixed in 2023. The one-pool promise held on BNB Chain and not on Solana.Dmitry Serdyuk·Jul 21, 20263m
exploitsInjective npm SDK Backdoored to Steal Wallet Keys: Anatomy of a Near MissA compromised maintainer account backdoored 18 @injectivelabs npm packages on July 8, 2026, harvesting wallet seed phrases at key-derivation time. It failed by minutes. Here is how it nearly worked.Dmitry Serdyuk·Jul 14, 20263m
exploitsSummer.fi's $6M Lazy Summer Exploit: When a Donation Broke the Vault MathAn attacker donated an asset into a Summer.fi Lazy Summer vault, inflated its totalAssets() share price, and redeemed a flash loan for a $6M profit. No key was stolen. The accounting was the hole.Dmitry Serdyuk·Jul 8, 20264m
exploitsBonkDAO's $20M Governance Takeover: When Buying the Vote Beats Hacking the CodeAn attacker spent about $4M buying BONK, took a voting majority on BonkDAO's Realms governance, and passed one proposal that moved $20M out of the treasury. No contract was hacked. The rules were.Dmitry Serdyuk·Jul 7, 20264m
exploitsAztec Connect's $2.19M Exploit: A ZK-Rollup Settlement Bug in a Contract No One Could PatchA deprecated Aztec Connect contract was drained of $2.19M when its L1 settlement loop and its ZK proof disagreed on how many slots were real. Its keys were renounced, so no one could pause it.Dmitry Serdyuk·Jul 5, 20264m
exploitsHumanity Protocol's $36M Key Compromise: A Runbook for Wallets That Touch ContractsOne compromised laptop held seven keys and cleared two multisigs, draining $36M+ from Humanity Protocol. A runbook for segregating, monitoring, and revoking project wallets that touch contracts.Dmitry Serdyuk·Jun 10, 20263m
researchAudit the Release Pipeline Like a Smart ContractYour contracts are audited. Your release pipeline isn't. Mini Shai-Hulud proved npm provenance signs whatever a compromised workflow ships. Here's the checklist Web3 teams should run on their own pipeline.Dmitry Serdyuk·May 19, 20263m
researchCopy Fail: When a Linux Bug Becomes Protocol RiskCopy Fail is a Linux kernel privilege escalation, not a smart contract bug. For Web3 teams running validators, CI runners, deployer hosts, and signing infrastructure, that's exactly why it matters.Dmitry Serdyuk·May 5, 20263m
technicalSmart Contract Audit Checklist: What to Prepare Before Your EngagementThe preparation checklist that separates smooth audit engagements from costly delays. What your team needs to have ready before auditors touch your code.Dmitry Serdyuk·Mar 20, 20263m
researchClaude Code Security vs Codex Security: What Each AI Vulnerability Scanner Actually DeliversAnthropic and OpenAI both shipped AI-powered vulnerability scanners in early 2026. We break down what each tool actually does, where they fall short, and why neither one replaces a smart contract audit.Dmitry Serdyuk·Mar 18, 20264m