KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure

Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."

KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.

$1.76 million stolen from MAYAChain in attack exploiting six bugs

The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.

Ravencoin rolls back blockchain after exploit

Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.

Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.

$26.9 million erroneously liquidated on Aave after Chaos Labs oracle bug

Users of the Aave defi lending protocol who had borrowed from the wstETH/stETH pool suffered erroneous liquidations when a price oracle from Chaos Labs reported an inaccurately low price ratio between the two assets. The oracle bug caused some loans to report that they were below the required "health factor" (the ratio between the assets loaned and the amount of collateral provided by the borrower), triggering forcible liquidations across the platform amounting to $26.9 million.

Chaos Labs, presumably embarrassed to have lived up to its name, promised to reimburse users whose positions were improperly liquidated.

Moonwell lending protocol suffers $1.78 million loss after second oracle misconfiguration in four months

After an oracle misconfiguration, the Moonwell defi lending protocol accumulated $1.78 million in bad debt. When the protocol showed that cbETH was priced at just over a dollar, rather than its actual market price of around $2,200, bots and humans alike rushed to take advantage of the mispricing. The error cascaded into liquidations across the platform.

This is the second time Moonwell has suffered a loss thanks to an oracle misconfiguration. In November 2025, the platform was left with almost $3.7 million in bad debt after a different asset was mispriced.

Although the vulnerable pull requests were at least partially developed by an AI tool, the security auditor who initially attributed the vulnerability to Claude Opus 4.6 later softened his criticism, noting that even senior developers could have made the same mistake. He did, however, criticize the project for a lack of sufficiently rigorous testing that should have caught the issue.

Prysm consensus client bug causes Ethereum validators to lose over $1 million

Ethereum validators running the Prysm consensus client lost around 382 ETH ($1.18 million) after a bug resulted in delays that caused validators to miss blocks and attestations. Though the bug had been introduced around a month prior, it did not affect validators until Ethereum completed its "Fusaka" network update on December 3. Around 19% of Ethereum validators use the Prysm consensus client, which is developed by Offchain Labs.

Cardano founder calls the FBI on a user who says his AI mistake caused a chainsplit

On November 21, the Cardano blockchain suffered a major chainsplit after someone created a transaction that exploited an old bug in Cardano node software, causing the chain to split. The person who submitted the transaction fessed up on Twitter, writing, "It started off as a 'let's see if I can reproduce the bad transaction' personal challenge and then I was dumb enough to rely on AI's instructions on how to block all traffic in/out of my Linux server without properly testing it on testnet first, and then watched in horror as the last block time on explorers froze."

Charles Hoskinson, the founder of Cardano, responded with a tweet boasting about how quickly the chain recovered from the catastrophic split, then accused the person of acting maliciously. "It was absolutely personal", Hoskinson wrote, adding that the person's public version of events was merely him "trying to walk it back because he knows the FBI is already involved". Hoskinson added, "There was a premeditated attack from a disgruntled [single pool operator] who spent months in the Fake Fred discord actively looking at ways to harm the brand and reputation of IOG. He targeted my personal pool and it resulted in disruption of the entire cardano network."

Hoskinson's decision to involve the FBI horrified some onlookers, including one other engineer at the company who publicly quit after the incident. They wrote, "I've fucked up pen testing in a major way once. I've seen my colleagues do the same. I didn't realize there was a risk of getting raided by the authorities because of that + saying mean things on the Internet."

Paxos accidentally mints more than twice the global GDP in PayPal stablecoins

Paxos, the issuer of PayPal's PYUSD stablecoin, accidentally minted 300 trillion of the supposedly dollar-pegged token. For context, this is approximately 2.5x the global GDP, and around 125x the total number of US dollars actually in circulation.

Paxos later announced that the mint was an "internal technical error", and that they had burned the excess tokens.

While PayPal promises its customers that "Reserves are held 100% in US dollar deposits, US treasuries and cash equivalents – meaning that customer funds are available for 1:1 redemption with Paxos," there clearly isn't much in the way of safeguards to ensure that is always the case. As with most stablecoin issuers, Paxos merely issues self-reported and unreviewed portfolio reports, and monthly third-party attestations (not audits) of reserves.

Kinto token crashes; community claims rug pull, Kinto claims hack

The price of Kinto's $K token suddenly crashed 90%, sparking accusations of a rug pull. A tranche of investor tokens had just been unlocked recently, leading some to speculate that investors dumped their tokens on retail buyers.

However, Kinto blamed the token crash on the exploit that was recently disclosed by VennBuild, claiming on Twitter that "we got hacked by a state actor". Venn seemed to corroborate Kinto's explanation that the crash was related to the exploit, tweeting that although they had tried to warn all vulnerable projects before publicly disclosing the bug, "Sadly the Kinto token was not found despite being vulnerable, and exploited without time to mitigate."

Kinto has announced a plan to try to fundraise to cover a $1.4 million loss in liquidity, then create a new $K token based on a snapshot of previous token holdings.

Security researchers disclose exploit that put over $10 million across multiple protocols at risk

On July 9, security researchers at VennBuild and other firms disclosed a "critical backdoor" affecting thousands of smart contracts, which one of the researchers said left "over $10,000,000 at risk for months". The researchers suggested that the backdoor was likely created by Lazarus, a North Korean state-sponsored hacking group.

According to the researchers, they found thousands of contracts affected by the exploit, and worked with multiple protocols to upgrade contracts or withdraw vulnerable funds. The researchers theorized that the attackers were "likely a sophisticated group waiting for a bigger target, not small wins."

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.