BlockThreat - Week 7, 2026

Are audits and bug bounties just an outdated tax in the age of AI? DPRK hopes you think so. A look back at what actually improved in crypto security over the past five years and what comes next.

BlockThreat - Week 7, 2026

Another week of relatively low losses with only $657K stolen across 5 incidents. The majority of losses came from two very similar exploits on BSC chain where someone is clearly hunting deflationary sell bugs to manipulate oracles in vulnerable pools.

It’s during low impact weeks like this that crypto starts to feel almost… safe. Maybe your latest AI tooling just found all the bugs. Maybe audits are an outdated tax that only slows down “experimentation.” After all, why pay five figures to have someone tell you what you already suspect, especially when half the industry is openly complaining that audit prices are “insane” and holding launches hostage?

At the same time, we look at bug bounties for the most critical infrastructure in the ecosystem and realize the numbers already don’t match the stakes. Ethereum is pitching zero downtime for a massively complex system with an enormous blast radius, yet a critical is still priced like a mid-tier DeFi project hack:

And what’s the worst that could happen? If something goes wrong, we’ll just call SEAL 911 to magically freeze attacker funds and beat them up with a virtual block chain until everything is returned. And if that fails, no worries, we’ll just negotiate with attackers and pay them a “whitehat reward” at the current market rate of 30%. All good!

Last week I wrote about the warning signs that tend to show up before a run of major hacks. This is one of them: a few calm weeks get misread as progress. Teams assume risk is down because headline losses are down. So budgets tighten, audits get framed as “overpriced blockers,” bounties stay capped because “nothing’s happening”, a low likelihood report is labeled as “accepted risk” on some spreadsheet instead of a live failure mode waiting for the right attacker.

The irony is these quiet weeks aren’t free. We’re living off years of getting hacked, drained, and social engineered. That’s 1,615 hard earned lessons and roughly $14B in losses in the past five years alone that taught us to build better tooling, stronger standards, develop real scar tissue to really push down losses per incident from the wild west of early 2020s:

The key takeaway is simple: average losses per incident fell from roughly $13M to $14M five years ago to about $5M to $8M in recent years, even with mega hacks like Bybit ($1.5B). That didn’t happen by accident. It lines up with the period where the ecosystem actually scaled with more audit companies and solo researchers, bug bounty contests and programs, monitoring that catches real exploits, the rise of Security Alliance, and a community that learned the hard way and built infrastructure to match. It wasn’t luck. It was incentives and execution. We started paying for prevention and for early warning as if losses were inevitable, and that investment is what made weeks like this possible.

So don’t take quiet stretches as permission to relax. Quiet weeks are when the next mega hacks get planned. If users are trusting you with their life savings, security isn’t optional and it isn’t something you can negotiate after the fact. Pay for prevention and early warning now, or pay later in losses, chaos, and broken trust.

Let’s dive into the news!

News

Crime

Crime - Wrench Attacks

Policy

Phishing

Phishing - DPRK

Scams

Contests

Media

Vulnerabilities

Vulnerabilities - Supply Chain

Research

Research - AI

Research - Bug Hunting

Research - SUI

Research - Web2

Whitepapers

Tools

  • Vespera: A highly flexible AI Agent-driven EVM smart contract vulnerability detection framework.
  • CEL (Continuous Execution Layer). CEL is a next-generation security infrastructure designed to transform blockchain security from periodic audits into a continuous, autonomous, and strategic execution layer.
  • SCV Scan by kadenzipfel. A Claude Code skill that scans Solidity codebases for security vulnerabilities by referencing 36 unique vulnerability types sourced from smart-contract-vulnerabilities.
  • SolidityGuard by Alt Research. Advanced Solidity/EVM smart contract security auditor using 104 vulnerability patterns, tool integrations with Slither, Mythril, Echidna, Aderyn, Foundry Medusa, Halmos, Certora, and others,.
  • You can inspect a transaction in EVM Chronicle with a full stack trace, where SLOAD and SSTORE are translated to variables, and see full path variable changes.

Hacks

Detailed indicators of compromise including exploit transactions, attacker address, exploit PoCs are available upon request.

Unkn_4e9B6e Compromise

Date: February 9, 2026
Attack Vector: Reward Manipulation
Chain: Ethereum

https://x.com/TikkalaResearch/status/1945910398781415787

Unkn_db005b

Date: February 12, 2026
Attack Vector: Price Oracle Manipulation
Impact: $10,000
Chain: Ethereum

https://x.com/DefimonAlerts/status/2022554639116186046

Figure Technology Compromise

Date: February 13, 2026
Attack Vector: Social Engineering
Chain: Ethereum

https://techcrunch.com/2026/02/13/fintech-lending-giant-figure-confirms-data-breach/

OCA Pool Compromise

Date: February 13, 2026
Attack Vector: Price Oracle Manipulation
Impact: $422,000
Chain: BSC

https://x.com/Phalcon_xyz/status/2022518083685105834

SOF Pool Compromise

Date: February 14, 2026
Attack Vector: Price Oracle Manipulation
Impact: $225,000
Chain: BSC

https://x.com/Phalcon_xyz/status/2022617941569867926