BlockThreat - Week 7, 2026
Are audits and bug bounties just an outdated tax in the age of AI? DPRK hopes you think so. A look back at what actually improved in crypto security over the past five years and what comes next.
Another week of relatively low losses with only $657K stolen across 5 incidents. The majority of losses came from two very similar exploits on BSC chain where someone is clearly hunting deflationary sell bugs to manipulate oracles in vulnerable pools.
It’s during low impact weeks like this that crypto starts to feel almost… safe. Maybe your latest AI tooling just found all the bugs. Maybe audits are an outdated tax that only slows down “experimentation.” After all, why pay five figures to have someone tell you what you already suspect, especially when half the industry is openly complaining that audit prices are “insane” and holding launches hostage?

At the same time, we look at bug bounties for the most critical infrastructure in the ecosystem and realize the numbers already don’t match the stakes. Ethereum is pitching zero downtime for a massively complex system with an enormous blast radius, yet a critical is still priced like a mid-tier DeFi project hack:

And what’s the worst that could happen? If something goes wrong, we’ll just call SEAL 911 to magically freeze attacker funds and beat them up with a virtual block chain until everything is returned. And if that fails, no worries, we’ll just negotiate with attackers and pay them a “whitehat reward” at the current market rate of 30%. All good!
Last week I wrote about the warning signs that tend to show up before a run of major hacks. This is one of them: a few calm weeks get misread as progress. Teams assume risk is down because headline losses are down. So budgets tighten, audits get framed as “overpriced blockers,” bounties stay capped because “nothing’s happening”, a low likelihood report is labeled as “accepted risk” on some spreadsheet instead of a live failure mode waiting for the right attacker.
The irony is these quiet weeks aren’t free. We’re living off years of getting hacked, drained, and social engineered. That’s 1,615 hard earned lessons and roughly $14B in losses in the past five years alone that taught us to build better tooling, stronger standards, develop real scar tissue to really push down losses per incident from the wild west of early 2020s:

The key takeaway is simple: average losses per incident fell from roughly $13M to $14M five years ago to about $5M to $8M in recent years, even with mega hacks like Bybit ($1.5B). That didn’t happen by accident. It lines up with the period where the ecosystem actually scaled with more audit companies and solo researchers, bug bounty contests and programs, monitoring that catches real exploits, the rise of Security Alliance, and a community that learned the hard way and built infrastructure to match. It wasn’t luck. It was incentives and execution. We started paying for prevention and for early warning as if losses were inevitable, and that investment is what made weeks like this possible.
So don’t take quiet stretches as permission to relax. Quiet weeks are when the next mega hacks get planned. If users are trusting you with their life savings, security isn’t optional and it isn’t something you can negotiate after the fact. Pay for prevention and early warning now, or pay later in losses, chaos, and broken trust.
Let’s dive into the news!
News
- Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi.
- TheDAO Security Fund announced its first allocation to support SEAL and SEAL911 teams.
- Web3 Security M&As and IPOs.
- The Ultimate Guide to Web3 Security by Hypernative.
- BlockFills Halts Withdrawals as Market Stress Spreads.
Crime
- Binance fires top investigators who claim to have uncovered evidence of Iranian sanctions violations.
- Israeli insider “ricosuave666” (now “Rundeep”) on Polymarket actually turned out to be a real insider. An IDF reservist and a civilian were arrested.
- Defunct P2P Crypto Platform Paxful Sentenced to $4M Penalty for Money Laundering, Travel Act Violations.
- Israelis Arrested Over Alleged Insider Polymarket Trades on IDF Military Secrets.
- Cambodia arrests 800 in latest casino scam centre raid.
- Paxful crypto platform fined $4 million after prosecutors say it ‘profited from moving money for criminals’.
- Mansions and sports cars: former SafeMoon CEO sentenced to 8 years in prison for crypto scheme.
- Chinese crypto scammer sentenced in absentia to 20 years after fleeing US. The saga of Daren Li continues.
Crime - Wrench Attacks
- Binance France CEO Targeted in Failed Home Invasion Near Paris, Three Arrested.
- French Police Arrest Six After Magistrate Kidnapped in Crypto Ransom Case.
Policy
- Landmark ruling: Supreme Court rules police can force open bank safe deposit boxes in $700m crypto fraud probe.
- South Korean Financial Regulator to Probe Crypto Market Manipulation, Impose Penalties for IT Failures.
Phishing
- Hostage situation - When the President herself asks for your help by Mauro Eldritch (Bitso Quetzal Team). A wild counter-phish stories.
- Snail mail letters target Trezor and Ledger users in crypto-theft attacks.
- Compilation: ways you can lose your cryptos by souilos (Opsek).
Phishing - DPRK
- PSA: DPRK IT workers are applying to remote roles using real LinkedIn accounts of individuals they're impersonating by SEAL. These profiles often have verified workplace emails and identity badges, which DPRK operatives hope will make their fraudulent applications appear legitimate.
- UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering by Mandiant.
- Digital Parasites by Rekt covers the plague of North Korean IT workers.
- Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets by Seongsu Park.
Scams
- Legitimacy on Demand by Rekt.
Contests
- Capture the Funds Contest Continues! by Certora.
Media
- Over 2 hours of Solodit submissions read out to fall asleep to. Learn security through osmosis, enjoy. Created by the good folks at Cyfrin.
- HackerOne - The Future of Security in the Age of AI: How Coinbase leverages offensive security and real-world testing with Hari (Cantina), Shashank Agrawal, Anmol Malhotra, Rick Roane (Coinbase) and Kyle Metivier (HackerOne).
Vulnerabilities
- Security Advisory: Citrea ''citrea-evm'' Vulnerability. The bug in EIP-6780 implementation could allow attacker to infinite mint assets.
- Permission denied - The story of an EIP that sinned by Trust Security. A deep dive into a DoS issue in EIP-2612 reported to 30+ projects on Immunefi.
- zkLogin: when ZKP is not enough by Sofia Celi (Brave).
- AAVE V4 Security Assessment by Trail of Bits.
Vulnerabilities - Supply Chain
- Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware. Patch now!
- Fake 7-Zip downloads are turning home PCs into proxy nodes.
- CVE-2026-26007: Python Cryptography Flaw (CVSS 8.2) Leaks Private Keys.
Research
- OWASP Smart Contract Top 10 : 2026. New research highlights the most critical smart contract risks, helping Web3 developers and security teams stay ahead of evolving threats.
- The Onchain Risk Map by Opencover and Nexus Mutual. A taxonomy of blockchain risks designed to help risk professionals, industry stakeholders, and sophisticated users identify and manage risk throughout their onchain journey.
- Monero in 2025: Persistent Use and Emerging Network-Layer Insights by TRM.
- THE BREACH: 2025 SECURITY DECODED. BlockSec dissects the year that broke crypto covering ten top breaches of 2025 including Cetus, Bybit, Balancer, GMX, and others.
- The Anatomy of Exposure: How Blockchain Transactions Leak Information at Every Layer - Logos Press Engine by Logos.
- Secret Harbour: Encrypted Multisig Transactions for Safe. Decentralized transaction queue including end-to-end encryption, ensuring that transaction details stay secret until they end up onchain.
Research - AI
- The "Kritt" Evolution: How an AI Hater Found a $500k Edge by chobby.
- Trail of Bits Claude Code Config. Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits. Covers sandboxing, permissions, hooks, skills, MCP servers, and usage patterns we've found effective across security audits, development, and research.
- I used an AI auditor. It worked by Ross Wei.
- Leaky LLMs: Accident or Nature? by Péter Szilágyi (DarkBio).
- HornetMCP - Vector data base of 23,625 smart contract vulnerabilities.
- Smart Contract Vulnerabilities by kadenzipfel. A collection of smart contract vulnerabilities along with prevention methods.
Research - Bug Hunting
- 34 Auditing Tips to crush it in 2026 by Recon.
- Efficiency in Bug Hunting: Moving Beyond the Noise to Find Real Impact by shakquraa.
- Yearn saved my life by sam.rise. A heartwarming story of saving a fellow DeFi project by the good guys at Yearn.
- Moving Averages in DeFi: Security Vulnerabilities and Attack Prevention by Bloqarl (Zealynx).
- One of the biggest reasons why it's hard to experiment in crypto is security audits and their costs an interesting thread by Abbas Khan.
Research - SUI
- A Mental Model for EVM Developers Building on Sui by Eric Nordelo (OpenZeppelin).
Research - Web2
- Top 5 Web2 Vulnerabilities Threatening Your DeFi Organization by Paul (Cantina).
- Top 10 web hacking techniques of 2025 by PortSwigger.
- Accessing $6 million worth of private key by a Web2 issue on SocialFi by 0xaudron.
- The most common vulnerabilities in dApp frontends (and how to mitigate them) by Łukasz M (Monethic).
Whitepapers
- Giving AI Agents Access to Cryptocurrency and Smart Contracts Creates New Vectors of AI Harm.
- Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies.
Tools
- Vespera: A highly flexible AI Agent-driven EVM smart contract vulnerability detection framework.
- CEL (Continuous Execution Layer). CEL is a next-generation security infrastructure designed to transform blockchain security from periodic audits into a continuous, autonomous, and strategic execution layer.
- SCV Scan by kadenzipfel. A Claude Code skill that scans Solidity codebases for security vulnerabilities by referencing 36 unique vulnerability types sourced from smart-contract-vulnerabilities.
- SolidityGuard by Alt Research. Advanced Solidity/EVM smart contract security auditor using 104 vulnerability patterns, tool integrations with Slither, Mythril, Echidna, Aderyn, Foundry Medusa, Halmos, Certora, and others,.
- You can inspect a transaction in EVM Chronicle with a full stack trace, where SLOAD and SSTORE are translated to variables, and see full path variable changes.
Hacks
Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.
Unkn_4e9B6e Compromise
Date: February 9, 2026
Attack Vector: Reward Manipulation
Chain: Ethereum
https://x.com/TikkalaResearch/status/1945910398781415787
Unkn_db005b
Date: February 12, 2026
Attack Vector: Price Oracle Manipulation
Impact: $10,000
Chain: Ethereum
https://x.com/DefimonAlerts/status/2022554639116186046
Figure Technology Compromise
Date: February 13, 2026
Attack Vector: Social Engineering
Chain: Ethereum
https://techcrunch.com/2026/02/13/fintech-lending-giant-figure-confirms-data-breach/
OCA Pool Compromise
Date: February 13, 2026
Attack Vector: Price Oracle Manipulation
Impact: $422,000
Chain: BSC
https://x.com/Phalcon_xyz/status/2022518083685105834
SOF Pool Compromise
Date: February 14, 2026
Attack Vector: Price Oracle Manipulation
Impact: $225,000
Chain: BSC
https://x.com/Phalcon_xyz/status/2022617941569867926