A security release fixes denial-of-service vulnerabilities in peer-to-peer and JSON-RPC handlers that become exploitable after Amsterdam activates on mainnet, correcting opcode caching and account handling.
A formal assurance framework for smart contracts uses multiple proof and testing tools together to catch mutations and regressions in deployed bytecode.
The Security Alliance Radar tracked incident trends and losses across threat categories over the past week.
A misconfigured deposit-token whitelist allowed redemptions that emptied a vault, draining liquidity and moving assets back to mainnet.
MetaMask's staking service withdrew validators from Lido following a security incident at its infrastructure provider, but users' wallets and funds remain unaffected.
More: Lido Research · The Defiant · Decrypt · The Defiant · Lido
Ethereum's consensus client Lighthouse released a medium-priority security patch affecting all mainnet validators, underscoring ongoing vigilance in client stability.
A Polygon zkEVM proving system patch addresses soundness vulnerabilities in BLAKE2, BLAKE3, and JumpDest logic that could affect proof validity.
Attackers are targeting victims via compromised email accounts and impersonating support staff to steal cryptocurrency and credentials before victims can secure their accounts.
The weekly security report tracks attack trends across Ethereum and ecosystem apps, providing early warning of shifting threat vectors and incident patterns insiders use to harden defenses.
The exchange recovering from its $388 million breach reveals the attacker is converting stolen ether to other assets, complicating recovery efforts.
More: CoinDesk · The Defiant · Decrypt · Unchained · Cointelegraph · CoinDesk · The Defiant
A fraudulent bridge impersonating an upbit-backed L2 project stole funds from users who mistakenly deposited, highlighting risks of naming confusion and unaudited bridges.
A bridge handling Ethereum deposits lost nearly all user funds in coordinated transfers, marking another significant loss in cross-chain infrastructure.
Kelp's developers claim LayerZero approved the single-verifier setup that enabled the April attack, then shifted blame to Kelp rather than accept responsibility.
Formal verification offers defenders an edge against AI-driven attacks on Ethereum infrastructure, starting with an analysis of the trusted code base in clients.
A flaw in Magic Eden's legacy token approvals let attackers drain NFT collections until security researchers intervened and recovered most assets.
Earlier on Security
September 2026 · 16 stories
August 2026 · 20 stories
July 2026 · 15 stories