KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.
KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure
$1.76 million stolen from MAYAChain in attack exploiting six bugs
Ravencoin rolls back blockchain after exploit
Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.
$26.9 million erroneously liquidated on Aave after Chaos Labs oracle bug
Chaos Labs, presumably embarrassed to have lived up to its name, promised to reimburse users whose positions were improperly liquidated.
Moonwell lending protocol suffers $1.78 million loss after second oracle misconfiguration in four months
This is the second time Moonwell has suffered a loss thanks to an oracle misconfiguration. In November 2025, the platform was left with almost $3.7 million in bad debt after a different asset was mispriced.
Although the vulnerable pull requests were at least partially developed by an AI tool, the security auditor who initially attributed the vulnerability to Claude Opus 4.6 later softened his criticism, noting that even senior developers could have made the same mistake. He did, however, criticize the project for a lack of sufficiently rigorous testing that should have caught the issue.
Prysm consensus client bug causes Ethereum validators to lose over $1 million
- "Fusaka Mainnet Prysm Incident", Prysm
- Client Distribution, Clientdiversity.org
Cardano founder calls the FBI on a user who says his AI mistake caused a chainsplit
Charles Hoskinson, the founder of Cardano, responded with a tweet boasting about how quickly the chain recovered from the catastrophic split, then accused the person of acting maliciously. "It was absolutely personal", Hoskinson wrote, adding that the person's public version of events was merely him "trying to walk it back because he knows the FBI is already involved". Hoskinson added, "There was a premeditated attack from a disgruntled [single pool operator] who spent months in the Fake Fred discord actively looking at ways to harm the brand and reputation of IOG. He targeted my personal pool and it resulted in disruption of the entire cardano network."
Hoskinson's decision to involve the FBI horrified some onlookers, including one other engineer at the company who publicly quit after the incident. They wrote, "I've fucked up pen testing in a major way once. I've seen my colleagues do the same. I didn't realize there was a risk of getting raided by the authorities because of that + saying mean things on the Internet."
Paxos accidentally mints more than twice the global GDP in PayPal stablecoins
Paxos later announced that the mint was an "internal technical error", and that they had burned the excess tokens.
While PayPal promises its customers that "Reserves are held 100% in US dollar deposits, US treasuries and cash equivalents – meaning that customer funds are available for 1:1 redemption with Paxos," there clearly isn't much in the way of safeguards to ensure that is always the case. As with most stablecoin issuers, Paxos merely issues self-reported and unreviewed portfolio reports, and monthly third-party attestations (not audits) of reserves.
Kinto token crashes; community claims rug pull, Kinto claims hack
However, Kinto blamed the token crash on the exploit that was recently disclosed by VennBuild, claiming on Twitter that "we got hacked by a state actor". Venn seemed to corroborate Kinto's explanation that the crash was related to the exploit, tweeting that although they had tried to warn all vulnerable projects before publicly disclosing the bug, "Sadly the Kinto token was not found despite being vulnerable, and exploited without time to mitigate."
Kinto has announced a plan to try to fundraise to cover a $1.4 million loss in liquidity, then create a new $K token based on a snapshot of previous token holdings.
Security researchers disclose exploit that put over $10 million across multiple protocols at risk
According to the researchers, they found thousands of contracts affected by the exploit, and worked with multiple protocols to upgrade contracts or withdraw vulnerable funds. The researchers theorized that the attackers were "likely a sophisticated group waiting for a bigger target, not small wins."









