BlockThreat - Week 30, 2026
$59.7M stolen across 10 incidents. Two DPRK operations using familiar tactics. An early warning for the next $100M+ security event.
DeFi losses continue accelerating with almost $60M in losses across 10 incidents this week. The DeFi threat landscape is starting to feel a lot like movie reruns, with more and more exploits arriving as sequels to old hits. Verus Hack Part 2, Allbridge Hack Part 2, Wemix Part 2 and so on. The frustrating part is that many of these sequels recycle the same underlying bugs. We really never learn, do we?
If a BlockThreat subscription would meaningfully support your learning, research, protocol, or public goods work, you may be eligible for a community-sponsored account.
In this week’s edition, we focus on the return of two North Korean threat actors and the exact tactics they used to steal nearly $25M from two projects. We also discuss an emerging threat and mitigations for the next $100M+ ecosystem-wide security event that both teams and individuals should start implementing now.
Beyond that, there is an excellent curated selection of the latest bug-hunting techniques, offensive AI tooling, notable vulnerability writeups, active phishing and malware campaigns, and detailed coverage of all 10 incidents from this week.
