BlockThreat - Week 6, 2026
Bear markets don’t slow hackers down. They make them deadlier. The data reveals why 2026 is shaping up to be brutal and highlights the latest emerging threats.
Only $725K were lost this week across nine incidents. The majority of losses were attributed to a mishap at Bithumb which managed to gift its users $142M before clawing back all but about $400K. Coinbase disclosed another PII exposure tied to a subcontractor, an incident that finally pushed it to move customer support in-house after the previous breach cost the company $400M.
This week marks the four year anniversary of the Wormhole bridge hack in February 2022, when attackers stole $325M by effectively printing money. Wormhole wasn’t just a bridge failure. It was one in the series of $100M+ hacks that signaled the end of the bull market and the beginning of the 2022 downturn.
Bear markets have a habit of revealing truths we prefer to ignore. As we slide into another one in 2026, the question isn’t whether history will repeat, but how closely. Which attack vectors thrive when liquidity disappears? Which threat actors become more active when exits shrink and attention fades? And which defenses quietly fail once incentives flip?
In this week’s edition, we dig into those patterns. As a bonus, I’ll lay out projections for how the blockchain security industry is likely to evolve over the coming months and years and highlight the critical lessons and focus areas users, defenders, and auditors need to internalize if we want to make it through the next downturn relatively unscathed.
You’ll also find coverage of an exciting new AI security competition from EF, recent wrench attacks and arrests, practical techniques for bypassing common anti-phishing transaction simulators, and deep dives into the latest attack patterns and bug-hunting techniques.
Several clear patterns emerge from five years of incident data when viewed alongside BTC price movements, total losses in USD, and incident counts. In the chart below, the left axis tracks BTC price, while the right axis shows monthly losses in millions:

Here are some critical insights about what happened in the past bear and how things will likely play out in the future.
- Mega hacks drive total losses. Months with $500M+ in losses are almost always caused by one or two catastrophic compromises, not a rise in background hacking activity of smaller DeFi projects.
- Transition years are the most dangerous. In 2022, the average loss per incident was ~$13M, compared to ~$5–6M during the depths of the bear market and ~$8.7M during the 2025 bull market. These spikes align with market stress such as leverage unwinds, rushed upgrades, governance actions, migrations, and emergency fixes.
- Incident counts never slow down. Even deep into bear markets, we consistently see ~40 incidents per month. What changes is severity. The catastrophic failures of 2022 gave way to many smaller, more contained incidents as the bear market progressed.
The pattern is consistent: a handful of massive hacks early in the bear market, followed by many smaller incidents later, and ultimately a return to truly large $1B+ compromises as the next bull market ramps up.
Which brings us to 2026. Expect it to be brutal:
- Expect a wave of $100M+ DeFi and exchange hacks throughout 2026 with a slowdown around 2027-2028.
- DeFi teams must double down on operational security, especially during periods of volatility when contract upgrades, governance actions, and large fund movements are rushed. Internal and external audits should be hyper focused on the Top 10 Attack Vectors which attackers exploit over and over, not theoretical edge cases.
- AI-driven shortcuts come at a cost. Rushed development, blind trust in generated code, exposing secrets to AI models, and underfunded audits all combine to make catastrophic, multi-million-dollar exploits inevitable.
- Exchanges will face highly targeted, sophisticated phishing campaigns. History suggests multiple $100M+ exchange compromises are likely, with DPRK-linked actors evolving faster than most defenses. Teams that are not actively tracking DPRK tradecraft and continuously updating controls will be the ones getting breached.
- Rug pulls will decline, but phishing won’t. Lower user activity reduces opportunistic exploits, but social engineering remains relentless.
Bear markets don’t mean fewer hacks. They mean more dangerous ones. The bull to bear transition is when accumulated technical debt, rushed decisions, and weak operational practices finally snap.
It’s time to strap in, tighten controls, and survive the next year. This week’s newsletter breaks down real incidents, post-mortems, and lessons to help you prepare for what’s coming.
Let’s dive into the news!
Events
- The Trial of Bastet by Ethereum Foundation. Kaggle Competition for LLM Identificatio of Smart Contract Vulnerabilities.
News
- Notepad++ Hijacked by State-Sponsored Hackers. In-depth backdoor analysis here.
- Newsletter platform Substack notifies users of data breach. Not the reason I moved from Substack, but now I'm glad I did.
- Bithumb accidentally gave away 2,000 BTC and crashed its market. Luckily as a centralized exchange, it was able to recover 99.7% of accidentally sent funds.
- Coinbase confirms insider breach linked to leaked support tool screenshots. It looks like the second second identical breach type finally pushed Coinbase to open its customer service hub in Charlotte with 150 employees.
- GoPlus January Web3 Security Data Report including losses from phishing attacks, rug pulls, and other scams.
- Trillion Dollar Security Dashboard by Ethereum Foundation. An overview of Ethereum's security posture, risks, mitigations, and progress across UX, smart contracts, infra, consensus, monitoring, and governance.
Crime
- Argentine Crypto Fugitive With $56 Million in Bitcoin Arrested in Venezuela.
- Xinbi Marketplace Remains Active with USD 17.9 Billion in Total Volume Despite Enforcement Actions by TRM.
- Incognito Market Owner "Pharaoh" Sentenced to 30 Years for Running $105M Dark Web Drug Empire.
Crime - Wrench Attacks
- Targeted Scottsdale home invasion linked to alleged $66M cryptocurrency plot. Home intrusion while dressed as a FedEx delivery.
- UK Teens Jailed After $4.3M Wrench Attack Robbery Caught on Police Video.
- Wrench Attacks Report by CertiK.
Crime - DPRK
- Hunting Lazarus Part IV: Real Blood on the Wire by Red Asgard.
- Hunting Lazarus Part III: The Infrastructure That Was Too Perfect by Red Asgard.
- BlueNoroff's latest campaigns: GhostCall and GhostHire by Kaspersky.
- North Korea’s “Prospect Call” Trap: Lazarus Turns Teams Meetings into macOS Credential Theft by Kyle Henson, Oren Biderman (Daylight).
Phishing
- Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft by Mandiant.
- Large-scale address poisoning + social engineering campaign targeting multisig users by Safe Labs. Attackers are creating lookalike Safe addresses to phish users.
- T₀ vs T₁: The Simulation Problem by Elliot Friedman. Phishing attacks that can defeat transaction simulations.
- Analysis of Token Vesting Phishing Poisoning by SlowMist.
- North Korea’s “Prospect Call” Trap: Lazarus Turns Teams Meetings into macOS Credential Theft | Daylight MDR Team.
Scams
- Frankenclaw by Rekt. Covers the mess behind Clawdbot attempted renaming when the pump and dump scammers stepped in.
Malware
- From magic to malware: How OpenClaw's agent skills become an attack surface by Jason Meller (1Password).
- Analysis of ClawHub Malicious Skills Poisoning by SlowMist.
Media
- The Fifth Estate - He was a math prodigy. Now authorities say he’s behind $65M in crypto thefts. Another documentary about Andean Medjedovic who according to the documentary was last seen in Bosnia.
- Cypher Talk - Ep01 - Security and Privacy in 2026.
- The Dangerous Evolution of AI Hacking by Cybernews.
Vulnerabilities
- Improving UserOperation Execution Safety in EntryPoint v0.9. An issue in ERC-4337 that can cause smart wallet transactions to revert. More from Trust who discovered this issue and shared more on scope.
- libgcrypt 1.8 contains a carry overflow bug in the STRIBOG hash function by Guido Vranken.
Research - Solana
- Solana Smart Contract Audit Guide 2026: Firedancer, Token-2022 & Security Checklist by Zealynx.
- Cyfrin Solana Course — Dutch Auction by Zuhaib Mohammed.
Research - SUI
- A Mental Model for EVM Developers Building on Sui - Part One by OpenZeppelin.
Research - EVM
- Smart Contracts Hacking - Attacks Library by JohnnyTime. Explore our comprehensive collection of smart contract vulnerabilities, attack vectors, and security exploits. Master the techniques used by hackers and auditors alike.
- From Bug to Rekt — 4 New Real DeFi Exploits Reproduced on Ethereum by Coinspect.
- Formal Verification with Certora by Certora. Formally verify smart contracts using the Certora Verification Language and Certora Prover.
- How memory works under the hood in the EVM and how this knowledge led me to recently discover a critical vulnerability by kaden.
- How DeFi Hacks Have Changed & What This Means for Protocols by Seth Hallem (Certora).
- Stop Auditing Base Like Ethereum: A DeFi Security Guide by QuillAudits.
- I found *15,733* unique system paths exposed in verified contracts by apoorv. An interesting forensics technique.
- EIP-1153: The foundation of the Till-pattern by Aniket Tyagi.
Research - Bug Hunting
- A White Mage’s Guide to Web3 Bug Hunting.
- Bug bounty, feedback, strategy and alchemy by Rachid Allam (zhero).
- Solidity Smart Contract Audit 2026: Pricing, AI & Readiness Manifesto by Zealynx.
Research - Crypto and AI
- Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries.
- The Lobster’s Armor: The Definitive Hacker’s Guide to Building Safely on OpenClaw by Cantina.
- Hacking Moltbook: The AI Social Network Any Human Can Control by Gal Nagli (Wiz).
Research - Infrastructure
- Wallet Security Ranking: Third Edition by Coinspect.
- AI Agents Are Execution Engines, Not Chatbots. Treat Them Accordingly by Raiders.
- AI's Transformative Impact on Web3 Security: Predictions from Late 2026 Onwards by Dacian.
Research - Whitepapers
- TxRay: Agentic Postmortem of Live Blockchain Attacks. More on its inner workers here. Looks it's getting good results already.
- LogicScan: An LLM-driven Framework for Detecting Business Logic Vulnerabilities in Smart Contracts.
- Evaluating the Vulnerability Landscape of LLM-Generated Smart Contracts.
- No More Hidden Pitfalls? Exposing Smart Contract Bad Practices with LLM-Powered Hybrid Analysis.
- Enhancing Smart Contract Vulnerability Detection in DApps Leveraging Fine-Tuned LLM.
- AtomGraph: Tackling Atomicity Violation in Smart Contracts using Multimodal GCNs.
- Malicious Code Detection in Smart Contracts via Opcode Vectorization.
- MoveScanner: Analysis of Security Risks of Move Smart Contracts.
- SmartBugBert: BERT-Enhanced Vulnerability Detection for Smart Contract Bytecode.
Tools
- VulnLLM-R-7B: Specialized Reasoning LLM for Vulnerability Detection by Hugging Models. The first specialized reasoning Large Language Model designed specifically for software vulnerability detection. Unlike traditional static analysis tools (like CodeQL) or small LLMs that rely on simple pattern matching, VulnLLM-R is trained to reason step-by-step about data flow, control flow, and security context. It mimics the thought process of a human security auditor to identify complex logic vulnerabilities with high accuracy.
- Vespera: A highly flexible AI Agent-driven EVM smart contract vulnerability detection framework by VectorBits.
- A peek under the hood of Recon Magic.
- Wen withdraw. Know when to withdraw from privacy pools
- TxSense by dcablorh. SUI transaction decoder.
- USDT Freeze Tracker by BlockSec.
- Announcing @KleidiWallet, a self-custody wallet where every transaction has a configurable time delay by Ξlliot (@Elliot0x).
Hacks
Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.
Coinbase Leak 2
Date: February 3, 2026
Attack Vector: Malicious Insider
Impact: PII Stolen
Chain: Ethereum
References:
- https://www.bleepingcomputer.com/news/security/coinbase-confirms-insider-breach-linked-to-leaked-support-tool-screenshots/
- https://www.charlotteobserver.com/news/business/article314605024.html
NUSD Token Compromise
Date: February 4, 2026
Attack Vector: Function Parameter Validation
Impact: $71,600
Chain: Ethereum
References:
- https://x.com/TenArmorAlert/status/2019245306693521912
- https://x.com/nn0b0dyyy/status/2019310749106278558
The DAO Recovery
Date: February 4, 2026
Attack Vector: N/A
Impact: PII Stolen
Chain: Ethereum
Interesting to watch how it was recovered by whitehats using a smart wallet account.
References:
- https://x.com/Giveth/status/2018972970132078652
- https://x.com/pcaversaccio/status/2019015398016889082
- https://protos.com/the-dao-hacked-again-but-this-time-its-the-good-guys/
SOFI Token Compromise
Date: February 5, 2026
Attack Vector: Reward Manipulation
Impact: $30,000
Chain: BSC
References:
- https://x.com/TenArmorAlert/status/2019242237503111519
- https://x.com/nn0b0dyyy/status/2019404236593983974
Unkn_acddac Compromise
Date: February 6, 2026
Attack Vector: Arbitrary External Calls
Impact: $142,000
Chain: Ethereum
References:
- https://x.com/phalcon_xyz/status/2020344525911388381?s=46
- https://x.com/Phalcon_xyz/status/2020424091216584926
Bithumb Misconfiguration
Date: February 6, 2026
Attack Vector: Misconfiguration
Impact: $402,000
Chain: Ethereum
Managed to reclaim 99.7% of the $142M printed by freezing all exchange operations.
References:
- https://protos.com/bithumb-accidentally-gave-away-2000-btc-and-crashed-its-market/
- https://www.reuters.com/world/asia-pacific/crypto-firm-accidentally-sends-44-billion-bitcoins-users-2026-02-07/
- https://x.com/gothburz/status/2020286999630872778
- https://x.com/iphelix/status/2020649604816208322
Unkn_Safe_635fa9 Compromise
Date: February 7, 2026
Attack Vector: Insufficient Function Access Control
Impact: $70,000
Chain: Ethereum
A custom module in the Safe Wallet has a receiveFlashLoan without verification of the flashloan initiator.
References:
- https://etherscan.io/tx/0x69fb51cacd2d2ac99874f0af1117596b15d88d0f10ee9f8c5c8e233f887aaff0
- https://x.com/phalcon_xyz/status/2020344525911388381
Rescue Transaction:
CPIMP Mass Exploitation
Date: February 7, 2026
Attack Vector: Uninitialized Contract
Impact: $7,400
Chain: Base
References:
- https://x.com/defimonalerts/status/2020512358410363245
- https://x.com/DefimonAlerts/status/2020392996664144299
- https://x.com/DefimonAlerts/status/2020049238093086909
- https://x.com/DefimonAlerts/status/2019460192434262295Owockibot Compromise
Date: February 8, 2026
Attack Vector: Stolen Private Keys
Impact: $2,100
Chain: Ethereum
References: