Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.
Coinsbuy exploited for $8 milllion
Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.
Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft
The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.
Wanchain bridge on Cardano exploited for more than $9 million
Allbridge exploited for $1.66 million
Across Protocol exploited for $3.35 million
Ostium loses at least $24 million to oracle exploit
The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.
Bonzo Lend exploited for $9 million in oracle attack
Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.
Summer Finance exploited for $6 million, shuts down
Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."
- "Lazy Summer USDC Vault Exploit Post-Mortem: What Happened and What Comes Next", Summer Finance
- "Sunsetting Summer.fi and the Labs Company", Summer Finance
Polymarket customers lose $2.97 million, company blames third-party vendor
Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.







![A circle overlaid with ][ symbols, followed by "Ostium" in orange capitals](https://primary-cdn.web3isgoinggreat.com/entryImages/logos/resized/ostium_300.webp)


