Hack
Anthropic Research Shows AI Agents Are Closing In on Real DeFi Attack Capability
Models tested by MATS and the Anthropic Fellows program generated turnkey exploit scripts and identified fresh vulnerabilities, suggesting automated exploitation is becoming technically and economically viable.

Solana Traders Hit by Months-Long Browser Malware That Skimmed Every Swap
Wallet interfaces typically summarize instructions as a single swap, and the bundled transaction executes atomically—meaning users unknowingly sign off on both.

North Korea’s AI-Powered Hackers Are Redefining Crypto Crime
Mysten Labs’ chief cryptographer warns that artificial intelligence, not quantum computing, poses the real near-term threat to blockchain security.

XRP Investor Says $3M in XRP Was Stolen; Cold Wallet Maker Says Seed Import Made Wallet Hot
Long-time XRP investor Brandon LaRoque says he discovered the loss on Oct. 15 in cold wallet maker Ellipal’s mobile app, but the theft occurred on Oct. 12.

'Great Hackers, Terrible Traders': How Exploiters Panic Sold and Lost $13M During Market Chaos
Six hacker wallets dumped ETH during the Oct. 10 market crash, then rebought at higher prices, amplifying losses.

WazirX Restructuring Cleared in Massive Relief for $230M Hack Victims
The sanction order followed an August re-vote that saw 95.7% of creditors by number and 94.6% by value support the plan.

$21M Crypto Theft on Hyperliquid Tied to Private Key Leak: PeckShield
According to PeckShield, the theft stemmed from a private key compromise, allowing an attacker to drain the victim’s funds in a single swift move.

This Invisible 'ModStealer' Is Targeting Your Browser-Based Crypto Wallets
The code includes pre-loaded instructions to target 56 browser wallet extensions and is designed to extract private keys, credentials, and certificates.

Ethereum, Solana Wallets Targeted in Massive 'npm' Attack But Just 5 Cents Taken
The credential stealer harvested username, password, and 2FA codes before sending them to a remote host. With full access, the attacker republished every "qix" package with a crypto-focused payload.

Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.
