Security News & Insights

Stay updated with the latest developments in blockchain security and smart contract auditing
December 5, 2025

Critical Vulnerability Found in Major DeFi Protocol Leads to $50M Exploit

A reentrancy vulnerability in a popular decentralized finance protocol allowed attackers to drain over $50 million in various tokens. The protocol has temporarily suspended operations while the team works with security experts to patch the flaw and recover funds.

November 28, 2025

New Research Reveals 30% of Solidity Smart Contracts Contain Known Vulnerabilities

Academic researchers have analyzed over 10,000 smart contracts and found that approximately 30% contain known security vulnerabilities that could be exploited. The study emphasizes the need for improved automated analysis tools and mandatory security audits.

November 20, 2025

Cross-Chain Bridge Security Concerns Mount After Three Major Incidents

Security researchers have identified common vulnerabilities in cross-chain bridge implementations that have led to multiple incidents this month. Experts recommend enhanced verification mechanisms and multi-signature requirements for cross-chain transactions.

November 15, 2025

Ethereum Foundation Announces New Smart Contract Audit Incentive Program

The Ethereum Foundation has launched a program to subsidize security audits for critical infrastructure contracts. The initiative aims to improve the overall security of the Ethereum ecosystem by making professional audits more accessible to smaller development teams.

November 10, 2025

AI-Powered Smart Contract Analysis Tools Show Promising Results in Bug Detection

New research demonstrates that AI-enhanced tools can detect certain types of smart contract vulnerabilities with higher accuracy than traditional methods. However, experts warn that human oversight remains essential for comprehensive security assessments.

October 16, 2025

Bittensor Hack Highlights NFT-Based Money Laundering Risks

The Bittensor hack revealed how anime NFTs are exploited for money laundering, prompting urgent regulatory scrutiny and security measures for NFT platforms. The incident acted as a stark reminder for the crypto community, revealing the pressing need for improved security measures and stricter regulatory scrutiny in the NFT space.

October 10, 2025

AI Smart Contract Audit Tools Struggle to Find Real Bugs

Despite advancements in AI, smart contract audit tools are struggling to identify real bugs. The tools often miss critical vulnerabilities, highlighting the need for human oversight in the auditing process.

October 7, 2025

North Korea's Crypto Hackers Have Stolen Over $2B in 2025

Elliptic analysis reveals that North Korea-linked hackers have already stolen over $2 billion in cryptoassets in 2025, the largest annual total on record, with three months still to go.

October 3, 2025

Crypto Hack Losses Down 37% in Q3 as Tactics Shift to Wallets

Crypto hack losses dropped 37% in Q3 to $509 million, but September saw a record surge in million-dollar incidents, led by exchange and DeFi exploits. Despite this, industry efforts to harden codebases may be paying off.

October 1, 2025

CertiK Reports Surge in Crypto Hacks, $173M Lost in August

CertiK reported that crypto hacks shot up by over 13% from July to August 2025, with thieves walking away with around $173 million. Phishing scams alone made up $101 million of that total. The month's worst hits included a massive $91 million phishing attack and a $53 million hack of BTC Turk.

September 29, 2025

LISA Technical Report: An Agentic Framework for Smart Contract Auditing

The LISA framework combines rule-based and logic-based methods to address a broad spectrum of vulnerabilities in smart contracts, significantly outperforming both LLM-based approaches and traditional static analysis tools.

September 17, 2025

India Mandates Cybersecurity Audits for Crypto Exchanges

Amid increasing instances of cyber thefts, the Indian government has mandated cybersecurity audits for all cryptocurrency exchanges and custodians. Platforms are required to have a security auditor registered with the Indian Computer Emergency Response Team (CERT-In), the nodal agency that deals with cybersecurity incidents.

September 11, 2025

Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits

Sui-based yield trading protocol Nemo lost $2.59 million in a Sept. 7 exploit caused by unaudited code deployed without multisignature controls. Despite an auditor flagging the issue months prior, the team failed to address it in time, leading to the breach.

September 10, 2025

NPM Supply Chain Attack Puts Crypto Users at Risk

On September 8th, cybersecurity researchers uncovered one of the most serious supply chain attacks in recent history. Hackers successfully compromised NPM (Node Package Manager), the world’s largest library of open-source software components, relied on by developers to build everything from websites to cryptocurrency wallets.

August 28, 2025

The Hacken 2025 Half-Year Web3 Security Report Is Out

Hacken's report reveals that $3.1 billion was lost across Web3 in H1 2025, already surpassing all of 2024. Access control exploits accounted for $1.83 billion of the losses.

August 22, 2025

2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Sector

Kroll's H1 2025 Threat Landscape Report dives into the complexities of crypto-based cyber threats, highlighting the rise in malware leveraging the blockchain and the impact of changing regulations.

August 19, 2025

Web3 Security Report Q1 2025: $2B Lost in 90 Days

The first quarter of 2025 marked one of the most alarming periods in Web3 security history — with over $2 billion lost in just three months. A 96% increase compared to Q1 2024, driven by operational failures and access control exploits.

August 18, 2025

XRP Ledger Ranks Last in Blockchain Security Review

XRP Ledger ranked last in Kaiko's blockchain security review. An April supply-chain hack raised concerns over developer tooling. A small validator set and low decentralisation hurt XRPL's rating.

July 17, 2025

2025 Crypto Crime Mid-Year Update

Over $2.17 billion has been stolen in crypto so far in 2025, led by the $1.5 billion ByBit hack. Personal wallet compromises now represent a growing share of total ecosystem theft, with attackers increasingly targeting individual users.

July 15, 2025

2025 H1 Report: Crypto Exploits and Security Breaches

In total, $2.3 billion was lost in H1 2025, exceeding the total loss for 2024. Access control attacks were responsible for over $1.6 billion in lost value, followed by social engineering attacks.

May 21, 2025

Adaptive Plan-Execute Framework for Smart Contract Security Auditing

A new framework, SmartAuditFlow, enhances smart contract security analysis through dynamic audit planning and structured execution, outperforming traditional auditing methods.

February 21, 2025

Bybit Hit by Record $1.5B Hack Attributed to Lazarus Group

In February 2025, cryptocurrency exchange Bybit suffered a massive hack, resulting in the theft of $1.5 billion worth of Ether tokens. Cybersecurity researchers and blockchain analysts linked the attack to the Lazarus Group, a hacking group believed to be backed by North Korea. Bybit stated that it was able to recover most of the stolen Ethereum and remained solvent throughout the incident. The company announced new security upgrades and offered a bounty to help track down the hackers and recover the remaining funds.

February 12, 2025

OWASP SC Top 10 (2025) Breakdown: The Most Critical Smart Contract Risks

The OWASP SC Top 10 for 2025 highlights the most critical smart contract risks, with access control vulnerabilities topping the list. These flaws allow attackers to gain unauthorized control over smart contracts.

Stay Informed About Security

Get expert insights on smart contract security and stay ahead of emerging threats