🔴 Threat Brief — 2026-08-19
Maya Protocol lost $1.7M to a fake-subsidy exploit. MemeCore's bridge printed a billion tokens from thin air. Two different failures, same lesson: verify what's actually backed.
(HIGH) Maya Protocol drained for ~$1.7M
Attacker inflated ARB.LINK accounting with a false subsidy, then cycled add/remove liquidity to extract 48.87M CACAO and 98.82 LINK from shared pools. LPs in THORChain-style shared-liquidity venues are at risk. Pull positions until subsidy logic is audited.
(CRITICAL) MemeCore bridge mints 1B $M with no backing
MemeCore.com minted ~1 billion $M (half the circulating supply) to a fresh wallet with no lock/burn on the source chain. ZachXBT flagged insiders holding >90% of supply. Anyone holding $M should exit. Verify any bridge requires equivalent burns before minting.
(HIGH) Bybit: AI recovered $700M of $1.46B stolen by DPRK
First major CEX to put numbers on AI-assisted fund recovery. $760M still missing. Move funds off any CEX you don't actively trade on.
How Digibastion helps:
Personal OpSec threat modelling at digibastion.com covers wallet security, CEX custody risk, and how to evaluate which bridges and protocols are safe to interact with. DM for a personal threat model of your crypto setup.
Sources:
• Maya Protocol Exploit - https://t.me/defendoreng
• MemeCore Bridge Mint - https://t.me/defimonalerts
• Bybit AI Recovery - https://www.coindesk.com/tech/2026/08/19/a-year-after-losing-usd1-46-billion-bybit-says-ai-helped-it-save-usd700-million
Stay safe. Stay sovereign.
Maya Protocol lost $1.7M to a fake-subsidy exploit. MemeCore's bridge printed a billion tokens from thin air. Two different failures, same lesson: verify what's actually backed.
(HIGH) Maya Protocol drained for ~$1.7M
Attacker inflated ARB.LINK accounting with a false subsidy, then cycled add/remove liquidity to extract 48.87M CACAO and 98.82 LINK from shared pools. LPs in THORChain-style shared-liquidity venues are at risk. Pull positions until subsidy logic is audited.
(CRITICAL) MemeCore bridge mints 1B $M with no backing
MemeCore.com minted ~1 billion $M (half the circulating supply) to a fresh wallet with no lock/burn on the source chain. ZachXBT flagged insiders holding >90% of supply. Anyone holding $M should exit. Verify any bridge requires equivalent burns before minting.
(HIGH) Bybit: AI recovered $700M of $1.46B stolen by DPRK
First major CEX to put numbers on AI-assisted fund recovery. $760M still missing. Move funds off any CEX you don't actively trade on.
How Digibastion helps:
Personal OpSec threat modelling at digibastion.com covers wallet security, CEX custody risk, and how to evaluate which bridges and protocols are safe to interact with. DM for a personal threat model of your crypto setup.
Sources:
• Maya Protocol Exploit - https://t.me/defendoreng
• MemeCore Bridge Mint - https://t.me/defimonalerts
• Bybit AI Recovery - https://www.coindesk.com/tech/2026/08/19/a-year-after-losing-usd1-46-billion-bybit-says-ai-helped-it-save-usd700-million
Stay safe. Stay sovereign.
❤1
🔴 Threat Brief — 2026-08-21
Tornado Cash's expired domain got hijacked. One user lost 1,010 ETH from an old bookmark.
(HIGH) Tornado Cash Domain Hijack: 1,010 ETH Lost
Attackers re-registered tornado[.]cash after OFAC sanctions let it lapse. A user clicked an old bookmark to the fake frontend, which captured withdrawal notes while deposits hit real contracts. Drained in 12 hours. Delete old bookmarks. Use verified IPFS or ENS links only.
(HIGH) Coldcard $114M Theft: Firmware Shipped
Coldcard shipped new firmware after a $114M theft. Three weeks of review found more bugs. Updating won't fix a compromised wallet. Verify device integrity if exposed.
(HIGH) Allbridge CCTP Router Drained for $191K
Attacker forged a Circle message on Polygon 24 days early, declaring 1M USDC with no burn. Flash-loaned 808K USDC, redeemed the fake attestation for 999K USDC.
How Digibastion helps:
DNS hijacking prevention is core to our coverage. The Tornado Cash takeover is that exact attack class. Wallet security and phishing resources at digibastion.com cover real patterns like this.
Sources:
• Tornado Cash Domain Hijack - https://www.cryptotimes.io/2026/08/20/user-loses-1010-eth-in-phishing-attack-via-hijacked-tornado-cash-domain/
• Coldcard $114M firmware - https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs
• Allbridge $191K drain - https://t.me/defendor_eng
Stay safe. Stay sovereign.
Tornado Cash's expired domain got hijacked. One user lost 1,010 ETH from an old bookmark.
(HIGH) Tornado Cash Domain Hijack: 1,010 ETH Lost
Attackers re-registered tornado[.]cash after OFAC sanctions let it lapse. A user clicked an old bookmark to the fake frontend, which captured withdrawal notes while deposits hit real contracts. Drained in 12 hours. Delete old bookmarks. Use verified IPFS or ENS links only.
(HIGH) Coldcard $114M Theft: Firmware Shipped
Coldcard shipped new firmware after a $114M theft. Three weeks of review found more bugs. Updating won't fix a compromised wallet. Verify device integrity if exposed.
(HIGH) Allbridge CCTP Router Drained for $191K
Attacker forged a Circle message on Polygon 24 days early, declaring 1M USDC with no burn. Flash-loaned 808K USDC, redeemed the fake attestation for 999K USDC.
How Digibastion helps:
DNS hijacking prevention is core to our coverage. The Tornado Cash takeover is that exact attack class. Wallet security and phishing resources at digibastion.com cover real patterns like this.
Sources:
• Tornado Cash Domain Hijack - https://www.cryptotimes.io/2026/08/20/user-loses-1010-eth-in-phishing-attack-via-hijacked-tornado-cash-domain/
• Coldcard $114M firmware - https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs
• Allbridge $191K drain - https://t.me/defendor_eng
Stay safe. Stay sovereign.
🔴 Threat Brief — 2026-08-22
Attackers minted unbacked SAND on Base via LayerZero hijack. A supply chain attack poisoned a VS Code extension to steal Web3 dev keys.
(CRITICAL) Sandbox SAND OFT Exploit on Base
Attackers hijacked LayerZero delegate permissions via approveAndCall to mint ~14.9B unbacked SAND (face value ~$49B) across 400+ txs on Base. Real loss was ~80 ETH ($675K) from the Ethereum OFT adapter. Upbit and Bithumb suspended SAND. Check if your SAND is on Ethereum (backed) or Base (possibly unbacked). Avoid SAND on Base until remediation.
(HIGH) Malicious Solidity Pro VS Code Extension
A VS Code extension called "Solidity Pro" stole crypto wallets and dev credentials across versions 1.0.0-4.0.0. It targeted MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr wallets plus GitHub tokens, SSH keys, and Telegram bot tokens. Remove it, rotate all keys, rebuild if used.
How Digibastion helps:
Both attacks exploit trust in daily tools: bridges and dev extensions. Digibastion's threat modelling covers wallet security basics for retail users and opsec assessment for teams handling keys.
Sources:
• Sandbox SAND Exploit: $49B New Tokens - https://coingape.com/upbit-warns-bithumb-suspends-sand-after-500m-token-mint-exploit-on-base/
• Malicious Solidity Pro VS Code Extension - https://cybersecuritynews.com/malicious-solidity-pro-vs-code-extension/
• PeckShieldAlert SAND confirmation - https://x.com/PeckShieldAlert/status/2091016046555582891
Stay safe. Stay sovereign.
Attackers minted unbacked SAND on Base via LayerZero hijack. A supply chain attack poisoned a VS Code extension to steal Web3 dev keys.
(CRITICAL) Sandbox SAND OFT Exploit on Base
Attackers hijacked LayerZero delegate permissions via approveAndCall to mint ~14.9B unbacked SAND (face value ~$49B) across 400+ txs on Base. Real loss was ~80 ETH ($675K) from the Ethereum OFT adapter. Upbit and Bithumb suspended SAND. Check if your SAND is on Ethereum (backed) or Base (possibly unbacked). Avoid SAND on Base until remediation.
(HIGH) Malicious Solidity Pro VS Code Extension
A VS Code extension called "Solidity Pro" stole crypto wallets and dev credentials across versions 1.0.0-4.0.0. It targeted MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr wallets plus GitHub tokens, SSH keys, and Telegram bot tokens. Remove it, rotate all keys, rebuild if used.
How Digibastion helps:
Both attacks exploit trust in daily tools: bridges and dev extensions. Digibastion's threat modelling covers wallet security basics for retail users and opsec assessment for teams handling keys.
Sources:
• Sandbox SAND Exploit: $49B New Tokens - https://coingape.com/upbit-warns-bithumb-suspends-sand-after-500m-token-mint-exploit-on-base/
• Malicious Solidity Pro VS Code Extension - https://cybersecuritynews.com/malicious-solidity-pro-vs-code-extension/
• PeckShieldAlert SAND confirmation - https://x.com/PeckShieldAlert/status/2091016046555582891
Stay safe. Stay sovereign.
🔴 Threat Brief — 2026-08-23
Term Labs governance attack drained $8.5M today. Two more threats below.
(CRITICAL) Term Labs governance attack: $8.5M stolen
A governance attack on Term Labs drained 2,843 ETH plus $1.6M in DAI. Funds traceable onchain. Anyone holding governance tokens in a DAO with cheap vote acquisition is at risk. Review your timelocks and proposal thresholds.
(HIGH) Microsoft Entra ID CVE-2026-69836 patched
A CVSS 10.0 deserialization flaw in Microsoft Entra ID could allow remote code execution with no user interaction. Microsoft patched before disclosure, no evidence of exploitation. If your crypto ops use cloud identity services, verify patching.
(MEDIUM) Bitcoin Red Team scans for AI-discoverable flaws
A volunteer group of 20+ devs is scanning Bitcoin wallets and apps for bugs AI models can now find. Triggered by Coldcard hack and Kimi K3 release. The protocol is secure. The software around it may not be.
How Digibastion helps:
Our threat alerts surface incidents like these in real time. Our OpSec threat modelling service assesses your personal setup and identifies where you are exposed.
Sources:
• Term Labs hack alert - https://t.me/QuillMonitor
• Microsoft Entra ID CVE-2026-69836 - https://decrypt.co/376287/microsoft-perfect-10-exploit-hackers-run-code
• Bitcoin Red Team AI security - https://decrypt.co/376296/bitcoin-target-ai-red-team-group-fighting-back
Stay safe. Stay sovereign.
Term Labs governance attack drained $8.5M today. Two more threats below.
(CRITICAL) Term Labs governance attack: $8.5M stolen
A governance attack on Term Labs drained 2,843 ETH plus $1.6M in DAI. Funds traceable onchain. Anyone holding governance tokens in a DAO with cheap vote acquisition is at risk. Review your timelocks and proposal thresholds.
(HIGH) Microsoft Entra ID CVE-2026-69836 patched
A CVSS 10.0 deserialization flaw in Microsoft Entra ID could allow remote code execution with no user interaction. Microsoft patched before disclosure, no evidence of exploitation. If your crypto ops use cloud identity services, verify patching.
(MEDIUM) Bitcoin Red Team scans for AI-discoverable flaws
A volunteer group of 20+ devs is scanning Bitcoin wallets and apps for bugs AI models can now find. Triggered by Coldcard hack and Kimi K3 release. The protocol is secure. The software around it may not be.
How Digibastion helps:
Our threat alerts surface incidents like these in real time. Our OpSec threat modelling service assesses your personal setup and identifies where you are exposed.
Sources:
• Term Labs hack alert - https://t.me/QuillMonitor
• Microsoft Entra ID CVE-2026-69836 - https://decrypt.co/376287/microsoft-perfect-10-exploit-hackers-run-code
• Bitcoin Red Team AI security - https://decrypt.co/376296/bitcoin-target-ai-red-team-group-fighting-back
Stay safe. Stay sovereign.
