News category
Security & incidents
Hacks, vulnerabilities, fraud, asset loss and security-control disclosures.
Image: crypto.newsOstium Reports $23.75M USDC Exploit Originated from Off-Chain Breach, Not Smart Contract Flaw
According to crypto.news, Ostium has stated that its July exploit, which resulted in the loss of $23.75 million USDC, was caused by a breach in its off-chain infrastructure rather than a vulnerability in its smart contracts. The attacker manipulated price reporting mechanisms to drain funds from the protocol’s liquidity vault. This finding is not officially confirmed and is based solely on media reporting, with no verification from Ostium or any official source. The incident highlights risks associated with off-chain components in DeFi protocols.
Latest coverage
Security & incidents
Page 4 of 8
crypto.newsOstium Reports $23.75M USDC Exploit Originated from Off-Chain Breach, Not Smart Contract Flaw
According to crypto.news, Ostium has stated that its July exploit, which resulted in the loss of $23.75 million USDC, was caused by a breach in its off-chain infrastructure rather than a vulnerability in its smart contracts. The attacker manipulated price reporting mechanisms to drain funds from the protocol’s liquidity vault. This finding is not officially confirmed and is based solely on media reporting, with no verification from Ostium or any official source. The incident highlights risks associated with off-chain components in DeFi protocols.
theblock.co via LBankBitRiver Founder Reportedly Detained in Russia on Fraud Charges
According to media reports from Bits Media and The Block, Russian authorities have transferred BitRiver founder Igor Runets from house arrest to a pre-trial detention facility. The move follows allegations of fraud involving a crypto mining equipment deal with energy conglomerate En+, which reportedly resulted in damages of 1 billion rubles ($12.5 million). The case is not officially confirmed and is based solely on media reporting, with further investigation ongoing.
crypto.newsEthereum Foundation Appoints SEAL 911 Co-Founder Pascal Caversaccio to Board for One-Year Term
According to crypto.news, the Ethereum Foundation has appointed SEAL 911 co-founder Pascal Caversaccio to its board for an initial one-year voluntary term. This move, not officially confirmed by any first-party source, reflects the Foundation’s increased focus on privacy and security. The appointment expands the board to four members, including Vitalik Buterin, Aya Miyaguchi, and Patrick Storchenegger. Caversaccio’s background in incident response and privacy advocacy is expected to inform board-level oversight, but no new security programs or protocol changes have been announced. The Foundation’s mandate continues to prioritize privacy and censorship resistance, with management retaining execution authority.
crypto.newsBitRiver Founder Detained Amid $7.9M Mining Equipment Fraud Investigation
According to crypto.news, BitRiver founder Igor Runets has been moved from house arrest to pretrial detention as Moscow authorities investigate an alleged ₽1 billion mining equipment fraud. The case centers on accusations that Fox Group, controlled by Runets, failed to deliver prepaid mining equipment to Infrastructure of Siberia, part of the En+ group. Bankruptcy proceedings and asset freezes have followed, but these developments are not officially confirmed. All reported facts are based on media coverage and court records, and remain unverified by official sources.
crypto.newsLocked Liquidity: Why It Does Not Guarantee Token Safety
According to crypto.news, the widespread belief that locked liquidity makes a token safe is not officially confirmed and is increasingly misleading. While liquidity locks prevent the classic rug pull, modern launchpads have adapted by pairing locked pools with perpetual creator fees, turning the lock into a revenue engine for attackers. The lock does not address supply concentration, contract permissions, or future liquidity, and its presence is now standard rather than a meaningful safety signal. These findings are based on media reporting and have not been officially confirmed.
CoinDesk2026 Crypto Hacks: Governance, Keys, and Security Lessons – Not Officially Confirmed
CoinDesk has reported that in 2026, the majority of crypto thefts, totaling approximately $972 million, have occurred not due to contract bugs but through compromised keys, signers, and governance mechanisms. This pattern, as described by Immunefi's Mitchell Amador, highlights that security audits alone do not guarantee safety. The findings are not officially confirmed and are based solely on media reporting.