Crypto security news
Security notes are the incident book: exploits, pauses, and the post-mortems that show who was in the blast radius. The desk names the contract, the funds, and what is still unknown.
Hacks, oracle failures, and bridge drains land here — not as a scoreboard, as a record of what broke and who is exposed.
Newest first. Every security note on DefiEdge is listed below.
- Ontology Restarts Mainnet After Malicious Activity Pause, Orders Sync Nodes to v3.1.5
The protocol resumed block production on Sept. 2 but left the attack path undisclosed and required immediate node upgrades for compatibility.
- Polygon Labs Patched Consensus DoS Flaws Through Private Hard Forks
Austin and Kyoto upgrades addressed block-processing and validator workload vulnerabilities with no mainnet exploitation reported.
- TAC Network Stays Halted After Exploit Drains 28.6 Percent of Bonded Staking Pool
Protocol proposes treasury-funded replacement for sold tokens while 1.66 billion attacker-held TAC on BNB Chain remains unresolved.
- ICON Foundation Traces Replay Exploit to Float64 Serial Check in Migration Contract
Two withdrawal messages were reused 1,490 times on Aug. 27, releasing foundation assets with a net confirmed loss of 150.2 ETH and 31,204 USDC.
- Injective Network Halted Four Hours After Binary Options Exploit
Attacker created 299 markets via a deprecated but registered oracle and extracted roughly $4.9 million through a no-price refund mechanism.
- Cronos Network Halts After Tectonic Price Manipulation on Illiquid TONIC
Attacker borrowed against inflated collateral in a Mango Markets-style exploit; loss estimated at $75 million.
- Switchboard Suspends Oracle Services on Aptos, Sui, Iota and Movement After Move Network Reports
The oracle provider stated that its Move-based implementation may have been compromised and directed users to alternative solutions while the matter is reviewed.
- Polygon PoS Discloses Client Flaws Fixed by Austin and Kyoto Forks
Denial-of-service and validator exhaustion issues in Bor and Heimdall were addressed before any mainnet impact.
- Fogo Pauses Mainnet After Detecting Unauthorized Activity
The protocol halted operations to block further asset movement and will upgrade the network to restrict linked addresses.
- Fogo L1 Halts Mainnet After Attacker Receives 400 Million FOGO Tokens
The unauthorized issuance equals 10 percent of circulating supply and roughly 4 percent of genesis supply, valued at about $3 million.
- Cosmos Labs Says It Wrongly Cleared Bug Behind $5.7 Million Exploit
The firm acknowledged clearing a vulnerability that led to losses across six chains, with MANTRA Chain reporting $3.6 million taken.
- MANTRA Chain Releases Exploit Post-Mortem Without Recovery Commitment
Protocol publishes formal recap of August 20-21 drain but offers no funding plan.
- Ledger ships Ethereum app 1.22.3 to close two signing flaws left open after 1.22.2
LSB-024 and LSB-025 fixed on Aug 25; no evidence of exploitation reported