Crypto lost $210.3M to hacks in July 2026 across 30 major incidents — a 177% increase from June's $75.9M.
The COLDCARD incident alone accounted for ~$70M, making it the third-largest crypto theft of 2026 so far.
Top losses:
• COLDCARD — ~$110M
• AFX (Arbitrum) — ~$24M
• Ostium — ~$24M
• BONK — ~$21.2M
• Wanchain Cardano–BNB Bridge — ~$13M
@awarefy
The COLDCARD incident alone accounted for ~$70M, making it the third-largest crypto theft of 2026 so far.
Top losses:
• COLDCARD — ~$110M
• AFX (Arbitrum) — ~$24M
• Ostium — ~$24M
• BONK — ~$21.2M
• Wanchain Cardano–BNB Bridge — ~$13M
@awarefy
❤2
BNB Chain blames former employee for unauthorized meme token
BNB Chain says a wallet linked to a recently launched meme token was originally created by a former employee for a tutorial and was never intended for official use.
According to the company, the ex-employee retained access to the wallet’s seed phrase after leaving and later used it to generate a new private key and launch the token independently.
@awarefy
BNB Chain says a wallet linked to a recently launched meme token was originally created by a former employee for a tutorial and was never intended for official use.
According to the company, the ex-employee retained access to the wallet’s seed phrase after leaving and later used it to generate a new private key and launch the token independently.
@awarefy
❤3
How attackers compromised Coldcard wallets
Researchers say a flaw in Coldcard firmware caused affected wallets to generate recovery seed phrases from predictable system data—such as processor identifiers and internal timers—instead of using secure hardware randomness.
Rather than attacking the devices directly, hackers recreated the vulnerable seed generation process offline, generated millions of possible seed phrases, matched them against funded Bitcoin addresses on the blockchain, and recovered the corresponding private keys to steal the funds.
The vulnerability reportedly remained unnoticed for five years before being patched.
@awarefy
Researchers say a flaw in Coldcard firmware caused affected wallets to generate recovery seed phrases from predictable system data—such as processor identifiers and internal timers—instead of using secure hardware randomness.
Rather than attacking the devices directly, hackers recreated the vulnerable seed generation process offline, generated millions of possible seed phrases, matched them against funded Bitcoin addresses on the blockchain, and recovered the corresponding private keys to steal the funds.
The vulnerability reportedly remained unnoticed for five years before being patched.
@awarefy
❤2
Adform supply chain attack swapped crypto wallet addresses
Attackers compromised Adform's trackpoint-async.js script, turning it into malware that replaced Bitcoin, Ethereum, and Tron wallet addresses on websites using the company's advertising code.
Anyone who copied a crypto address from an affected site on July 27 may have unknowingly pasted an attacker's address instead. The malicious script also modified addresses typed directly into forms.
Adform removed the malicious code, notified customers, and advises users to clear their browser cache and verify wallet addresses before sending funds.
@awarefy
Attackers compromised Adform's trackpoint-async.js script, turning it into malware that replaced Bitcoin, Ethereum, and Tron wallet addresses on websites using the company's advertising code.
Anyone who copied a crypto address from an affected site on July 27 may have unknowingly pasted an attacker's address instead. The malicious script also modified addresses typed directly into forms.
Adform removed the malicious code, notified customers, and advises users to clear their browser cache and verify wallet addresses before sending funds.
@awarefy
❤2
⚠️BREAKING: Two French crypto millionaires held hostage and tortured in a 52-hour kidnapping nightmare.
The victims were allegedly beaten, burned, and forced to hand over $30,000 in crypto as captors demanded $150,000. The ordeal ended only after a high-speed police chase, with six people convicted in connection with the attack, per Daily Mail.
CertiK has recorded 50+ wrench attacks targeting crypto holders in H1 2026, with France emerging as a major hotspot for violent crypto-related kidnappings and extortion.
@awarefy
The victims were allegedly beaten, burned, and forced to hand over $30,000 in crypto as captors demanded $150,000. The ordeal ended only after a high-speed police chase, with six people convicted in connection with the attack, per Daily Mail.
CertiK has recorded 50+ wrench attacks targeting crypto holders in H1 2026, with France emerging as a major hotspot for violent crypto-related kidnappings and extortion.
@awarefy
❤3
⚠️ UPDATE: Apple Explains the Real Reason for Telegram’s Removal from the App Store
According to Bloomberg, Apple has explained why Telegram was removed from the App Store:
We briefly removed Telegram from the App Store after our review found content that violates our strict guidelines prohibiting child sexual abuse material (CSAM). The app was subsequently restored after the developer promptly removed the content and banned the user who posted it,' Apple tells Bloomberg.
Telegram has also responded on X saying:
“I'm sure this stance will be applied equally to all other apps in the store, in the future right? @Aрple"
@awarefy
According to Bloomberg, Apple has explained why Telegram was removed from the App Store:
We briefly removed Telegram from the App Store after our review found content that violates our strict guidelines prohibiting child sexual abuse material (CSAM). The app was subsequently restored after the developer promptly removed the content and banned the user who posted it,' Apple tells Bloomberg.
Telegram has also responded on X saying:
“I'm sure this stance will be applied equally to all other apps in the store, in the future right? @Aрple"
@awarefy
❤2
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️Gram Wallet Is Now Rolling Out
Pavel Durov has announced that Telegram's Gram Wallet is now live for a select group of users, with a gradual rollout to over 1 billion users planned over the next couple of weeks.
@awarefy
Pavel Durov has announced that Telegram's Gram Wallet is now live for a select group of users, with a gradual rollout to over 1 billion users planned over the next couple of weeks.
@awarefy
🥰2❤1
⚠️Two Thai businessmen are suing Tether for freezing $42.4M of their USDT
Nutthawat Rukthammachalern and Natthawat Kasamvilas say Tether blacklisted their wallets in October 2025 - 42,417,785 USDT, after nothing more than an informal request from a Homeland Security agent 💀
No warrant. No court order. No notice to them. A seizure warrant only showed up four months later, and they argue it still doesn’t let Tether freeze, burn or reissue anything.
Their core claim:
Tether isn’t their custodian, they bought these tokens on the open market. And while their money sits frozen, Tether keeps collecting the Treasury yield on the reserves backing it 💵
They want the wallets unblocked, the interest handed back, and damages if the tokens get burned.
@awarefy
Nutthawat Rukthammachalern and Natthawat Kasamvilas say Tether blacklisted their wallets in October 2025 - 42,417,785 USDT, after nothing more than an informal request from a Homeland Security agent 💀
No warrant. No court order. No notice to them. A seizure warrant only showed up four months later, and they argue it still doesn’t let Tether freeze, burn or reissue anything.
Their core claim:
Tether isn’t their custodian, they bought these tokens on the open market. And while their money sits frozen, Tether keeps collecting the Treasury yield on the reserves backing it 💵
They want the wallets unblocked, the interest handed back, and damages if the tokens get burned.
@awarefy
🥰2
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️JUST IN: North Korea’s Lazarus Group reportedly laundered over $30 MILLION through Hyperliquid.
The hackers swapped the funds into Ethereum and Solana, then spread them across multiple chains and exchanges to hide the trail.
The wallets were previously linked to tens of millions in stolen crypto.
@awarefy
The hackers swapped the funds into Ethereum and Solana, then spread them across multiple chains and exchanges to hide the trail.
The wallets were previously linked to tens of millions in stolen crypto.
@awarefy
🥰2
Awarefy
⚠️Two Thai businessmen are suing Tether for freezing $42.4M of their USDT Nutthawat Rukthammachalern and Natthawat Kasamvilas say Tether blacklisted their wallets in October 2025 - 42,417,785 USDT, after nothing more than an informal request from a Homeland…
⚠️UPDATE - It appears that the $42.4M Tether freeze in this suit stems from a North Carolina pig-butchering case.
HSI Raleigh opened it from a victim tip: romance/investment fraud, fake trading platform, then layering through wallets so the stolen USDT would look clean.
On 10/31/25, Tether blacklisted the Thai plaintiffs’ Ethereum addresses after an informal HSI request… no warrant, no notice.
One of those wallets, 0xf3bF…A3eB, was holding ~$26.1M and had already been mapped as a consolidation address in an “accumulate, layer, integrate” flow.
The court paper arrived later. On 2/19/26, EDNC issued warrant 5:26-MJ-1267-JG telling Tether to burn the frozen USDT and remint it to a government wallet.
Five days after that, EDNC/HSI announced a $61M USDT seizure “traced to addresses allegedly associated with laundering proceeds stolen from pig-butchering victims.” Tether was publicly thanked for the transfer.
@awarefy
HSI Raleigh opened it from a victim tip: romance/investment fraud, fake trading platform, then layering through wallets so the stolen USDT would look clean.
On 10/31/25, Tether blacklisted the Thai plaintiffs’ Ethereum addresses after an informal HSI request… no warrant, no notice.
One of those wallets, 0xf3bF…A3eB, was holding ~$26.1M and had already been mapped as a consolidation address in an “accumulate, layer, integrate” flow.
The court paper arrived later. On 2/19/26, EDNC issued warrant 5:26-MJ-1267-JG telling Tether to burn the frozen USDT and remint it to a government wallet.
Five days after that, EDNC/HSI announced a $61M USDT seizure “traced to addresses allegedly associated with laundering proceeds stolen from pig-butchering victims.” Tether was publicly thanked for the transfer.
@awarefy
🥰2
⚠️Threat Actor $pider Milan Exposed for carrying out Home Invasions with rapper Lil Zay Osama
Sources say $pider Milan (@Goth on IG) partnered with rapper Lil Zay Osama (In OTF) to do invasions for cryptocurrency. He is also allegedly responsible for the shooting at Tiffany's house (formerly @fraud).
@awarefy
Sources say $pider Milan (@Goth on IG) partnered with rapper Lil Zay Osama (In OTF) to do invasions for cryptocurrency. He is also allegedly responsible for the shooting at Tiffany's house (formerly @fraud).
@awarefy
🥰2
⚠️August Crypto Losses Hit $215M
CertiK reports that crypto hacks and exploits caused $215M in losses this August. The biggest threat was collateral price manipulation, responsible for $131.6M, while the Tectonic exploit alone cost $120.4M.
Around $110.7M has already been returned or frozen.
@awarefy
CertiK reports that crypto hacks and exploits caused $215M in losses this August. The biggest threat was collateral price manipulation, responsible for $131.6M, while the Tectonic exploit alone cost $120.4M.
Around $110.7M has already been returned or frozen.
@awarefy
🥰2
⚠️Major Solana Apps Disrupted by Helius Outage
Users on Phantom, Axiom, Pump[.]fun and other platforms are reporting they can’t send or withdraw funds, with many seeing “Solana's Blockchain Network is Degraded” errors.
It appears the problems are coming from Helius, a major Solana RPC provider used by many wallets and apps. Helius is currently experiencing a major outage affecting its RPC, WebSocket and related services, causing these errors across multiple platforms.
The estimated time for a full resolution is currently unknown.
@awarefy
Users on Phantom, Axiom, Pump[.]fun and other platforms are reporting they can’t send or withdraw funds, with many seeing “Solana's Blockchain Network is Degraded” errors.
It appears the problems are coming from Helius, a major Solana RPC provider used by many wallets and apps. Helius is currently experiencing a major outage affecting its RPC, WebSocket and related services, causing these errors across multiple platforms.
The estimated time for a full resolution is currently unknown.
@awarefy
🥰1