Ostium Attributes $24M Exploit to Off-Chain Breach, Smart Contracts Unaffected
The decentralized trading protocol says trader collateral remains safe and will reveal a recovery plan for LPs.
We use cookies for anonymous analytics and ad measurement to improve the site. Cookie policy.
Original coverage across the crypto market, updated daily.
The decentralized trading protocol says trader collateral remains safe and will reveal a recovery plan for LPs.
OpenAI's AI agent exploited vulnerable code at two firms after escaping a secure test environment.

OpenAI internal benchmark incident shows autonomous exploit chains could threaten smart contract security with irreversible losses.

OpenAI's internal test highlights how autonomous AI exploits could threaten blockchain systems.

DeFi lending protocol Bonzo Lend lost over $9 million after an attacker exploited a vulnerability in a third-party Supra oracle contract on Hedera.
Hedera-based lending protocol Bonzo Lend lost $9 million after a manipulated price update was accepted by the Supra oracle verifier.
EMURGO steps down from Cardano's Pentad governance body citing the SecondFi exploit, sending ADA down 5%.

A crypto trader suffered a $2 million loss after a same-block backrun extraction exploit.
Attackers exploited weak seed phrases generated by the Ill Bloom bug, stealing $3.1 million from 431 wallets.
The DeFi protocol aims to recover and return funds drained from 374 wallets via a software flaw.

Ethereum layer-2 Taiko urges users to bridge funds out after exploit steals over $1.7 million.
An exploit on Secret Network's Axelar bridge drained $4.67 million via an infinite-mint bug that went undetected for seven days.

The bot, responsible for 70% of Ethereum sandwich attacks from Nov 2024 to Oct 2025, lost $7.5M in an exploit.

Security firm SlowMist analyzed an exploit of the deprecated Aztec Connect, warning of risks from immutable smart contracts.

An exploit of a defunct Aztec Connect contract leads to $2.1 million loss, but current Aztec protocols remain secure.
Attacker exploited a proof verification flaw in Aztec Connect, draining over $2.1 million from the defunct protocol.

Critics question whether Pump.fun's latest product encourages creativity or crosses into exploitation with risky user dares.
Syscoin paused its cross-chain bridge after an attacker exploited a validation issue to mint approximately 5 billion unauthorized SYS tokens.