OPN Intel
AS-OF
BTC$77,682MAYER1.12×200W1.20×PI-CYCLE41%DRAWDOWN-38%PUELL0.94×W-RSI56BMSB1.11×
AS OF 2026-08-30

OPN Intel · Intel / Beat

Threats intelligence

34 articles

Instruments on this beat
Drawdown from ATH-38%as-of readings · Stress instruments — how deep the current damage runs.
ThreatsTrust Inversion5 min read
Hinkal Lost $820,000 After Its Privacy Proof Verification Failed to Verify Anything
An attacker drained roughly $820,000, nearly the protocol's entire total value locked, from Hinkal, a zero-knowledge privacy protocol, on July 3, 2026, by submitting a deposit that skipped the required cryptographic proof and then withdrawing funds the contract should have refused. Blockchain security firm CertiK confirmed the technique targeted Hinkal's core proof-verification step, and the stolen funds moved through Tornado Cash and a Thorchain bridge to Bitcoin within hours. It's the latest entry in OPNorange's Trust Inversion series: a mechanism built to provide privacy and security became the exact vector that broke both.
July 4, 2026
ThreatsTrust Inversion5 min read
$1.7 Million Drained Through a Single Forged Proof on Taiko
On June 22, 2026, an attacker forged source-signal proofs on Taiko's Ethereum L2 bridge and drained $1.7 million from an ERC-20 vault for withdrawals with no matching deposits on the source chain. Taiko halted block production and urged users to withdraw from every bridge on the network because chain state verification failure is not bounded to a single contract: when the proof mechanism fails, every bridge relying on it fails simultaneously. This is the Trust Inversion pattern at the cryptographic layer: the mechanism that was supposed to make bridges trustless became the attack surface. Native Bitcoin in self-custody has no proof verification layer, no source-signal mechanism, and no bridge to forge.
June 22, 2026
ThreatsTrust Inversion5 min read
FTX Repays Bitcoin Creditors at $16,871 Petition-Date Price
June 16, 2026 is the record date for the fifth FTX creditor distribution, with payments to commence July 31. To claim, former FTX customers must have completed KYC with BitGo, Kraken, or Payoneer by today's cutoff. The payout formula is fixed at petition-date prices from November 11, 2022, when Bitcoin closed at $16,871. Bitcoin trades above $66,000 today. A creditor who held 1 BTC on FTX will receive approximately $16,871 in USD. The same 1 BTC held in private-key self-custody through the same 3.5 years is worth approximately $66,000 and required no claim, no tax disclosure to a third party, and no onboarding with a distribution provider. The FTX bankruptcy is the largest single retail test of custodial risk ever conducted. The record date is the financial checkpoint where the gap between the custodial outcome and the self-custody outcome becomes precise and permanent.
June 16, 2026
ThreatsTrust Inversion5 min read
AudiA6 Takedown Hits $389M Wash for 20 Ransomware Groups
On June 10, 2026, an international coalition led by the US Secret Service, IRS Criminal Investigation, and Polish Police dismantled AudiA6, a cryptocurrency laundering service that processed more than €336 million for 20 ransomware groups between 2022 and 2025, including funds stolen through the fake Ledger Live app attack OPNorange covered in April. AudiA6 operated by cycling stolen crypto through more than 6,000 KYC-verified money mule accounts at legitimate exchanges and returning clean funds within approximately one hour for a 3-to-10 percent commission. The takedown is a genuine law enforcement success but a diagnostic one: the €692,000 frozen at arrest is under 0.2 percent of the $389 million already processed, and none of it goes back to individual victims.
June 13, 2026
Threats5 min read
AI Finds DeFi Exploits for $1.22 in Compute
Manuel Aráoz, co-founder of OpenZeppelin, warned May 27 that he now considers all of DeFi unsafe. AI coding agents have become superhuman at finding smart contract vulnerabilities, and the economics are one-sided: the average cost for an AI agent to exhaustively scan a contract is $1.22, while the potential exploit revenue those agents can generate has been doubling every 1.3 months. In the past 12 months, more than $1.1 billion has been drained from DeFi protocols, and DeFi total value locked (TVL) has declined $20 billion in 2026 alone. Aráoz's core asymmetry: defenders must find and fix every bug in every contract they deploy, and they must do it faster than AI agents that never sleep, while attackers need just one. The OPNorange thesis: the self-custody stack has no smart contract attack surface for AI to exploit. Private keys to native BTC cannot be drained by any auditing agent because there is no contract code to audit.
May 27, 2026
ThreatsTrust Inversion5 min read
Sui Validators Reversed a $223M DEX Exploit by Vote
On May 22, an attacker exploited an integer overflow bug in an open-source math library used by Cetus Protocol, the dominant concentrated-liquidity DEX on the Sui blockchain, and drained approximately $223 million from liquidity pools. Sui validators coordinated within hours to freeze roughly $162 million still held in attacker-controlled Sui addresses, and a governance vote concluded in under 48 hours with 90.9% of staked validators in favor of recovery. The seizure worked against this thief, and the code path that achieved it does not disappear when the voting ends.
May 22, 2026
Threats3 min read
ThorChain Loses $10M on the Rail Lazarus Uses
On May 15, blockchain investigator ZachXBT and security firm PeckShield flagged what appears to be a multi-chain exploit against ThorChain spanning Bitcoin, Ethereum, BNB Chain, and Base, with losses estimated at approximately $10 million. The protocol activated its Mimir governance module to halt trading and signing operations. RUNE, the protocol's native token, dropped 12%. The attack vector has not been confirmed and no post-mortem has been published. ThorChain is the documented cash-out route for North Korea's Lazarus Group across 2026's two largest DeFi exploits: approximately $175 million of the unfrozen Kelp DAO proceeds moved through ThorChain after the April 18 breach, and Drift Protocol's April 1 proceeds moved through similar permissionless routes. The protocol's no-KYC, no-freeze design is why sovereignty-seekers use it for cross-chain Bitcoin swaps. It is also why the exploit proceeds cannot be frozen while the investigation proceeds.
May 15, 2026
Threats6 min read
Aave's $71M Emergency Motion Invokes Common-Law Theft Doctrine
On Monday, May 4, Aave LLC filed a 29-page emergency motion in the Southern District of New York seeking to vacate the Gerstein Harrow restraining notice that has frozen $71 million in ETH on Arbitrum since May 1. The filing, prepared by Morrison Cohen LLP and submitted before Judge Margaret M. Garnett, makes a direct property-law argument: a thief does not gain lawful ownership of stolen property by taking it, and recovered stolen funds belong to the victims, not to the thief or to creditors with claims against the thief. Aave demands either immediate vacatur, an expedited hearing with temporary vacatur, or a $300 million cash bond from plaintiffs if the freeze remains. CEO Stani Kulechov: 'A thief does not own what he steals.' The case will determine whether on-chain attribution to a sanctioned entity can override ordinary ownership rules to convert recovered stolen assets into seizable judgment-debtor property. The answer will shape the contours of property law in the age of programmable money.
May 5, 2026
Threats5 min read
Tether's $344M OFAC Freeze Makes Sanctions a Stablecoin Feature
On Monday, May 4, Tether confirmed it has supported US government freezes totaling more than $344 million USDT across two Tron addresses, in coordination with OFAC and the Treasury Department. Public reporting describes the addresses as Iran-linked sanctions evasion infrastructure: approximately $213 million at one address and $131 million at the other. The freeze framework is operationally distinct from anything that applies to Bitcoin or other self-custody assets. Stablecoin issuers possess unilateral freeze authority because their tokens are issued claims rather than native protocol assets, and the issuer can blacklist any address by upgrading the contract. Tether has now blocked over $2.5 billion cumulative since 2017, with 2026 alone accounting for more than $1 billion of that total. The mechanism enables sanctions enforcement against Iran, Russia, and DPRK addresses today. The same mechanism can be turned, by political decision, against any address an issuer is compelled to freeze tomorrow. The OPNorange thesis: Tether is not outside the system. It is a programmable extension of it.
May 4, 2026
Threats4 min read
Binance Adds a Withdrawal Lock as Wrench Attacks Climb 75%
On May 3, CoinDesk reported that Binance is launching a withdrawal-lock feature designed to protect users from being forced into withdrawing their funds during physical-coercion attacks. The lock is an internal policy mechanism, not a cryptographic constraint: Binance employees can override it under sufficient operational pressure. The friction itself is the deterrent. The story is significant not because the feature solves the problem but because the world's largest crypto exchange now considers the wrench-attack threat structural enough to engineer counter-coercion features into the product. The 2025 wrench-attack data backs the assumption: documented attacks rose 75% year-over-year, financial losses reached $40.9 million, kidnappings remained the primary vector but physical assaults surged 250%. The OPNorange angle is direct: an exchange-level withdrawal lock is structurally weaker than self-custody with a duress passphrase, and the gap between the two is the operational sovereignty argument compressed into a single product feature.
May 3, 2026
Threats5 min read
$629M Drained in April, the Worst Crypto-Theft Month Since 2024
On Wednesday, April 30, DefiLlama published the final April tally: $629.69 million stolen across 12+ documented incidents, the worst single month for crypto theft since the $1.4 billion Bybit breach in February 2025 and the most incidents in a single month in industry history. CertiK's parallel tracker puts the figure at $650.9 million, calling it the worst month since March 2022. DeFi protocols accounted for $614.17 million of total losses. Two attacks alone, Drift Protocol on April 1 and Kelp DAO on April 18, account for approximately 95% of the month's losses, both attributed to North Korea's Lazarus Group. The pattern is not a wave of many small attacks. It is a few surgical operations against high-value targets. April closes with the structural shift the security community has been warning about for years finally measurable: the primary attack vector is no longer smart contract code. It is trust-chain compromise and cross-chain verification failure.
Apr 30, 2026
ThreatsTrust Inversion6 min read
Drift Hack Began With Months of In-Person DPRK Social Engineering
On Wednesday, April 29, TRM Labs and Chainalysis published detailed analyses of the April 1 Drift Protocol breach: North Korean state-backed operators began the campaign in fall 2025 with in-person meetings between proxies and Drift employees, building professional credibility for months before exploiting it. Access came through Solana durable nonces, a feature that lets transactions be signed in advance and broadcast later, converting routine pre-signed approvals from Security Council members into delayed exploits. Once admin control was transferred, attackers whitelisted a fake CVT token as collateral, deposited the fake collateral, and drained real assets from vaults in approximately 12 minutes. The same intelligence research now puts North Korea-linked actors at 76% of all 2026 crypto theft and approximately $6 billion cumulative since 2017. The attribution share has risen from under 10% in 2020-2021 to 64% in 2025 to 76% in early 2026.
Apr 29, 2026
ThreatsTrust Inversion5 min read
UNC1069 Is Deepfaking CEOs on Zoom to Drain Crypto Wallets
On April 15, 2026, crypto wallet provider Zerion disclosed that approximately $100,000 was stolen from its hot wallets through an AI-enabled social engineering attack that compromised employee sessions, credentials, and private keys. The methodology matched a detailed Mandiant report published February 9, 2026 documenting North Korean threat group UNC1069 using deepfake video of real crypto CEOs inside fake Zoom calls to deliver the ClickFix payload. The Security Alliance has blocked 164 UNC1069-linked domains between February and April. This is the industrialization of AI-enabled social engineering at the nation-state level, and the attack surface is the human layer, not the smart contract layer.
Apr 24, 2026
Threats5 min read
$292M rsETH Exploit Is 2026's Largest DeFi Hit
On Saturday, April 18 at 17:35 UTC, an attacker drained 116,500 rsETH from Kelp DAO's LayerZero-powered bridge by tricking the cross-chain messaging layer into releasing reserves. The stolen tokens represent about 18% of rsETH's circulating supply and are worth roughly $292 million at current prices. LayerZero has linked the exploit to a subgroup of North Korea's Lazarus Group. The cascading fallout included an $8 billion withdrawal wave from Aave, a 20% drop in the AAVE token, and emergency freezes across SparkLend, Fluid, Lido's earnETH product, and Ethena's LayerZero OFT bridges. Arbitrum's Security Council has frozen $71 million in ETH tied to the attacker's address. This is now the largest DeFi exploit of the year, overtaking Drift by a few million dollars.
Apr 21, 2026
ThreatsTrust Inversion4 min read
Fake Ledger App Drained $9.5M From Apple's App Store
A counterfeit version of Ledger Live operated on Apple's Mac App Store from April 7 to April 13, 2026, draining approximately $9.5 million from more than 50 victims before Apple removed it. The attack worked by prompting users to enter their 24-word seed phrase during a fake wallet setup flow. Once entered, attackers immediately reconstructed the wallet on a separate device and drained every account on the seed. Three victims lost over $1 million each. Musician Garrett Dutton, known as G. Love, lost 5.92 BTC — his retirement savings accumulated over a decade — while setting up a new MacBook. The hardware wallet never failed. The seed phrase rule did.
Apr 16, 2026
Threats4 min read
An Insider Already Reached Kraken Before the Extortion Demand
On April 13, Kraken disclosed that a criminal group is attempting to extort the company by threatening to release videos of internal systems containing client data. The extortion follows two separate insider incidents in which support staff accessed customer account data without authorization, affecting roughly 2,000 accounts. Kraken's CSO said the company will not pay and will not negotiate. Law enforcement is involved. The same week, Kraken confirmed a confidential IPO filing and Deutsche Börse invested $200 million at a $13.3 billion valuation. Galaxy Digital separately disclosed an unrelated insider security incident. No funds were at risk. The access already happened.
Apr 15, 2026
ThreatsTrust Inversion5 min read
Your AI Agent's Plumbing Can Steal Your Crypto
Researchers from UC Santa Barbara, UC San Diego, blockchain security firm Fuzzland, and World Liberty Financial published a paper documenting a class of attacks on LLM routers — the services that sit between users and AI models like Claude, ChatGPT, and Gemini. Of 428 routers analyzed, 9 were found injecting malicious code or stealing credentials. The paper defines two attack classes: payload injection, where the router rewrites tool-call traffic, and secret exfiltration, where it harvests credentials from plaintext. One router drained ETH from a researcher-controlled test wallet. Secondary reporting links the research to a $500,000 real-world wallet drain, though the primary paper documents the test wallet theft. Two routers deployed adaptive evasion targeting autonomous sessions specifically. The attack surface is not the AI model. It is the infrastructure between you and the model.
Apr 13, 2026
Threats4 min read
FBI's Own Token Showed Most Crypto Volume Is Manufactured
Federal grand juries unsealed indictments on March 30 charging 10 executives and employees at four crypto market-making firms — Gotbit, Vortex, Antier, and Contrarian — with wire fraud and conspiracy for running wash trading operations that manufactured fake volume and inflated token prices. The operation behind the charges, called Token Mirrors, involved FBI and IRS agents creating their own cryptocurrency tokens, approaching the firms as clients, and documenting exactly what wash trading as a service looks like when you buy it.
Apr 3, 2026
Threats5 min read
Fake $500 Token, Stolen Key, $285M Drained From Drift
On April 1, Drift Protocol — Solana's largest perpetual futures exchange — lost $285 million in 12 minutes. The attacker didn't find a bug in the smart contracts. Two audits had passed the code in the past four years. What they found instead was a single admin key with god-mode access to the entire protocol, and three weeks of preparation time to build a fake token the oracle would believe was worth $1. The Circle USDC freeze angle is the second story inside this one.
Apr 2, 2026
Threats3 min read
One Phone Call Drove 59% of Q1's $480M Crypto Losses
On March 27, CertiK published its Q1 running total: 103 security incidents, 36 phishing scams, approximately $480 million in losses since January 1. The number sounds like escalation. The breakdown tells a different story. A single social engineering attack accounts for $284 million, or 59% of the entire quarter. Strip it and Q1 is tracking below the baseline pace of recent years.
Mar 27, 2026
Threats4 min read
Lazarus Hacked Bitrefill Through One Compromised Laptop
On March 1, North Korea's Lazarus Group breached Bitrefill, the crypto gift card platform, through a single compromised employee laptop. Hot wallets were drained, 18,500 purchase records were accessed, and attackers moved through legacy credentials into production infrastructure before the company could contain it. The playbook is identical to Bybit.
Mar 18, 2026
Threats5 min read
How Chinese Criminal Networks Turned Pig Butchering Into a Global Industry
Chinese-speaking crime syndicates have spent a decade building something that looks less like a fraud operation and more like a franchise. A January 2026 Infoblox report documents the full supply chain: trafficked labor in Southeast Asian compounds, PII databases for sale at $0.10 per account, AI-assisted victim management tools, and turnkey scam platforms starting at $50. The industrialization is complete. What looks like a romance is a production line.
Mar 17, 2026
Threats4 min read
Fake Trezor Rep Steals $282 Million in a Phone Call
On January 10, 2026, a single investor lost 1,459 BTC and 2.05 million LTC, over $282 million, after being convinced to hand over their seed phrase to someone posing as Trezor support. The hardware wallet worked perfectly. The human didn't.
Mar 16, 2026
Threats5 min read
How AI Turned Crypto Scams Into a $17 Billion Industry
Crypto scams stole an estimated $17 billion in 2025, according to Chainalysis. Impersonation fraud grew 1,400% year-over-year. AI-enabled operations were 4.5 times more profitable than traditional ones. The threat model has fundamentally shifted — from hacking systems to hacking people.
Mar 13, 2026
Threats4 min read
OnlyFake Shut Down. The KYC Bypass Market Didn't.
The operator of an AI-powered fake ID factory just pled guilty — 10,000+ counterfeit documents designed to bypass crypto exchange KYC. He faces 15 years. But the real question isn't about one Ukrainian with a website. It's about why KYC verification is this easy to defeat.
Feb 27, 2026
Threats5 min read
Social Engineering Drove 84% of January's $370 Million Theft
84% of January 2026's crypto losses came from social engineering, not protocol exploits. The industry spent billions securing the wrong layer.
Feb 24, 2026
Threats6 min read
Bybit Lost $1.5 Billion in a Single Hack
One year ago today, North Korea’s Lazarus Group executed the largest crypto heist in history. Here’s what actually happened — and what it means for your custody decisions.
Feb 21, 2026
Threats5 min read
The Coinbase Insider Breach Made KYC Your Biggest Vulnerability
Two separate insider breaches. 70,000 users exposed. Government IDs, home addresses, and wallet balances — leaked by bribed contractors.
Feb 19, 2026
Threats5 min read
Your Phone Number Is the Weakest Security Credential You Own
Your phone suddenly shows 'No Service.' Within minutes, your email is compromised, your exchange accounts are drained, and your 2FA is worthless. SIM swap attacks are surging — and your phone number is the skeleton key.
Feb 19, 2026
Threats5 min read
Deepfake Scams Now Account for 40% of High-Value Crypto Fraud
AI-generated deepfakes now account for ~40% of high-value crypto fraud. Seeing and hearing are no longer believing.
Feb 17, 2026
Threats5 min read
One Wrong Paste, $50 Million Lost to Address Poisoning
A crypto user withdrew $50 million and sent it to an attacker's address that looked nearly identical to their own. Address poisoning is the simplest, cheapest, and most effective attack in crypto — and it works because of how you copy and paste.
Feb 15, 2026
Threats5 min read
The Psychology That Makes Smart People Fall for Crypto Fraud
Education and intelligence don't protect you. Cialdini's six principles of influence explain why pig butchering scams work on PhDs, engineers, and executives. The defense is a mental model, not more information.
Feb 9, 2026
Threats5 min read
Americans Lost $333 Million to Bitcoin ATM Scams in 2025
FBI data shows Americans lost $333 million to Bitcoin ATM scams in 2025. The median victim is 71 years old. No legitimate organization will ever ask you to pay at a crypto kiosk.
Feb 6, 2026
Threats5 min read
AI Voice Cloning Made Virtual Kidnapping a Scalable Scam
Scammers clone your daughter's voice from three seconds of social media audio, call you in a panic, and demand Bitcoin. These attacks are happening thousands of times a day.
Feb 3, 2026