Harmony hit by massive $3B+ ONE exploit
A flaw in Harmony’s cross-shard verification allowed attackers to mint around 3T $ONE tokens without authorization.
The tokens were quickly moved to exchanges, sending ONE down up to 50%. Harmony paused the bridge, deployed a patch, and is working on a possible rollback.
A flaw in Harmony’s cross-shard verification allowed attackers to mint around 3T $ONE tokens without authorization.
The tokens were quickly moved to exchanges, sending ONE down up to 50%. Harmony paused the bridge, deployed a patch, and is working on a possible rollback.
2
Names, addreses, phone numbers and emails of customers have been exposed.
@although
Please open Telegram to view this post
VIEW IN TELEGRAM
Attackers drained 99.7% of the XRP-Coreum bridge’s reserves in less than two hours.
The exploit targeted the cross-chain bridge that moves tokens between the XRP Ledger and Coreum. Once the attack began, the reserves were rapidly emptied, leaving almost nothing behind for users and liquidity providers.
The incident highlights why bridges remain one of crypto’s most dangerous weak points: a single exploit can empty an entire pool before developers can react.
@although
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Perks
Hosted By: @Dexters
To Participate:
• Join @larplounge
• Join @onchains
• Tap Participate
Participants: 24
Winners: 1
Giveaway Ends In: 6d 20h 30m
Please open Telegram to view this post
VIEW IN TELEGRAM
11
A longtime Bitcoin holder reportedly lost around $750,000 in BTC less than 12 hours after moving it to a major Australian exchange.
Hackers had allegedly controlled his Google account for months, including access to his email and cloud-backed Google Authenticator data.
They waited.
The moment he deposited BTC onto the exchange, they accessed the account and withdrew everything.
The victim reportedly woke up at 3 a.m. to a notification saying the withdrawal had been approved.
Big takeaway: disable cloud backup for Google Authenticator if you don’t want your Google account becoming another single point of failure.
For stronger protection, use hardware security keys like YubiKey — ideally two, so you have a backup.
Please open Telegram to view this post
VIEW IN TELEGRAM
1
An attacker impersonating support contacted the victim, gained access to their wallet, and stole over $1.2M in cryptocurrency.
@although / @larplounge
Please open Telegram to view this post
VIEW IN TELEGRAM
1
Yesterday: ~$500k swapped to ETH and pushed through Tornado Cash.
Three weeks ago: another $2M, same exact route.
All of it came from social engineering..
no hack, no exploit, just spoofed calls that look like they’re from Coinbase, fake emails with real-looking case IDs, cloned login pages. The victim moves the money themselves, believing they’re securing their account…
Tens of millions are still parked in these wallets, untouched.
This is the same threat actor who once left an onchain message trolling @zachxbt
Wallets:
0x5Da2ea20839C9C5AE0d909f2379Ecc2C74489D8a 0x3ECe139997CDa3c78a54e54f213592718767f296Please open Telegram to view this post
VIEW IN TELEGRAM
2
wow she really bought, and she is the best trader in the world def not down 95% from then