BlockThreat - Week 9, 2026

Another week of chain killer vulnerabilities, actively exploited ZK mistakes, supply chain compromises, phishing campaigns, and the strange case of rug pullers getting hacked.

BlockThreat - Week 9, 2026

More than $8 million in crypto was stolen this week across 9 incidents. The majority of losses came from South Korea, where the National Tax Service lost $4.8 million after accidentally leaking a seized wallet seed phrase in a press release. It was a completely preventable incident and one that may sound familiar: the Gangnam Police Station in Seoul recently lost $1.4 million in BTC as well. There is clearly a serious gap in how government institutions securely custody crypto assets.

However, it is the other incidents that deserve closer attention as indicators of what is coming next, from actively exploited patterns in ZK contracts to ongoing supply chain and phishing campaigns. We also cover the latest batch of critical blockchain layer vulnerabilities, best practices for securely setting up and operating AI agents, and plenty of onchain investigations and arrests.