BlockThreat - Week 6, 2026

Bear markets don’t slow hackers down. They make them deadlier. The data reveals why 2026 is shaping up to be brutal and highlights the latest emerging threats.

BlockThreat - Week 6, 2026

Only $725K were lost this week across nine incidents. The majority of losses were attributed to a mishap at Bithumb which managed to gift its users $142M before clawing back all but about $400K. Coinbase disclosed another PII exposure tied to a subcontractor, an incident that finally pushed it to move customer support in-house after the previous breach cost the company $400M.

This week marks the four year anniversary of the Wormhole bridge hack in February 2022, when attackers stole $325M by effectively printing money. Wormhole wasn’t just a bridge failure. It was one in the series of $100M+ hacks that signaled the end of the bull market and the beginning of the 2022 downturn.

Bear markets have a habit of revealing truths we prefer to ignore. As we slide into another one in 2026, the question isn’t whether history will repeat, but how closely. Which attack vectors thrive when liquidity disappears? Which threat actors become more active when exits shrink and attention fades? And which defenses quietly fail once incentives flip?

In this week’s edition, we dig into those patterns. As a bonus, I’ll lay out projections for how the blockchain security industry is likely to evolve over the coming months and years and highlight the critical lessons and focus areas users, defenders, and auditors need to internalize if we want to make it through the next downturn relatively unscathed.

You’ll also find coverage of an exciting new AI security competition from EF, recent wrench attacks and arrests, practical techniques for bypassing common anti-phishing transaction simulators, and deep dives into the latest attack patterns and bug-hunting techniques.

Several clear patterns emerge from five years of incident data when viewed alongside BTC price movements, total losses in USD, and incident counts. In the chart below, the left axis tracks BTC price, while the right axis shows monthly losses in millions:

Here are some critical insights about what happened in the past bear and how things will likely play out in the future.

  • Mega hacks drive total losses. Months with $500M+ in losses are almost always caused by one or two catastrophic compromises, not a rise in background hacking activity of smaller DeFi projects.
  • Transition years are the most dangerous. In 2022, the average loss per incident was ~$13M, compared to ~$5–6M during the depths of the bear market and ~$8.7M during the 2025 bull market. These spikes align with market stress such as leverage unwinds, rushed upgrades, governance actions, migrations, and emergency fixes.
  • Incident counts never slow down. Even deep into bear markets, we consistently see ~40 incidents per month. What changes is severity. The catastrophic failures of 2022 gave way to many smaller, more contained incidents as the bear market progressed.

The pattern is consistent: a handful of massive hacks early in the bear market, followed by many smaller incidents later, and ultimately a return to truly large $1B+ compromises as the next bull market ramps up.

Which brings us to 2026. Expect it to be brutal:

  • Expect a wave of $100M+ DeFi and exchange hacks throughout 2026 with a slowdown around 2027-2028.
  • DeFi teams must double down on operational security, especially during periods of volatility when contract upgrades, governance actions, and large fund movements are rushed. Internal and external audits should be hyper focused on the Top 10 Attack Vectors which attackers exploit over and over, not theoretical edge cases.
  • AI-driven shortcuts come at a cost. Rushed development, blind trust in generated code, exposing secrets to AI models, and underfunded audits all combine to make catastrophic, multi-million-dollar exploits inevitable.
  • Exchanges will face highly targeted, sophisticated phishing campaigns. History suggests multiple $100M+ exchange compromises are likely, with DPRK-linked actors evolving faster than most defenses. Teams that are not actively tracking DPRK tradecraft and continuously updating controls will be the ones getting breached.
  • Rug pulls will decline, but phishing won’t. Lower user activity reduces opportunistic exploits, but social engineering remains relentless.

Bear markets don’t mean fewer hacks. They mean more dangerous ones. The bull to bear transition is when accumulated technical debt, rushed decisions, and weak operational practices finally snap.

It’s time to strap in, tighten controls, and survive the next year. This week’s newsletter breaks down real incidents, post-mortems, and lessons to help you prepare for what’s coming.

Let’s dive into the news!

Events

  • The Trial of Bastet by Ethereum Foundation. Kaggle Competition for LLM Identificatio of Smart Contract Vulnerabilities.

News

Crime

Crime - Wrench Attacks

Crime - DPRK

Phishing

Scams

  • Frankenclaw by Rekt. Covers the mess behind Clawdbot attempted renaming when the pump and dump scammers stepped in.

Malware

Media

Vulnerabilities

Research - Solana

Research - SUI

Research - EVM

Research - Bug Hunting

Research - Crypto and AI

Research - Infrastructure

Research - Whitepapers

Tools

Hacks

Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.

Coinbase Leak 2

Date: February 3, 2026
Attack Vector: Malicious Insider
Impact: PII Stolen
Chain: Ethereum

References:

NUSD Token Compromise

Date: February 4, 2026
Attack Vector: Function Parameter Validation
Impact: $71,600
Chain: Ethereum

References:

The DAO Recovery

Date: February 4, 2026
Attack Vector: N/A
Impact: PII Stolen
Chain: Ethereum

Interesting to watch how it was recovered by whitehats using a smart wallet account.

References:

SOFI Token Compromise

Date: February 5, 2026
Attack Vector: Reward Manipulation
Impact: $30,000
Chain: BSC

References:

Unkn_acddac Compromise

Date: February 6, 2026
Attack Vector: Arbitrary External Calls
Impact: $142,000
Chain: Ethereum

References:

Bithumb Misconfiguration

Date: February 6, 2026
Attack Vector: Misconfiguration
Impact: $402,000
Chain: Ethereum

Managed to reclaim 99.7% of the $142M printed by freezing all exchange operations.

References:

Unkn_Safe_635fa9 Compromise

Date: February 7, 2026
Attack Vector: Insufficient Function Access Control
Impact: $70,000
Chain: Ethereum

A custom module in the Safe Wallet has a receiveFlashLoan without verification of the flashloan initiator.

References:

Rescue Transaction:

CPIMP Mass Exploitation

Date: February 7, 2026
Attack Vector: Uninitialized Contract
Impact: $7,400
Chain: Base

References:

Date: February 8, 2026
Attack Vector: Stolen Private Keys
Impact: $2,100
Chain: Ethereum

References: