Three major hacks in just 4 days!
On May 15, #THORChain was exploited, with stolen funds exceeding $10M.
On May 18, the Verus-Ethereum Bridge (@VerusCoin) was hacked, with ~$11.5M stolen.
Today, @EchoProtocol_ was exploited, the hacker minted 1,000 $eBTC ($76.64M) and has already used it to steal 385 $ETH($821K).
Stay safe.
Important Announcement
Trading on THORChain is currently halted after a vault was compromised. Initial indications are user funds are safe and only protocol owned funds are affected.
The network automatically detected abnormal behavior and halted signing activity, which alerted the broader community and prevented further outbound transactions.
The investigation is still ongoing to determine the root cause. Contributors are actively working on the issue and we will report updates as we progress toward a solution.
What we currently know:
* One of the six Asgard vaults appears to have been compromised.
* Current estimates place the loss at approximately $10.7m USD
* The network automatically detected the abnormal behavior and halted signing activity, preventing further outbound activity.
* Nodes securing the vault were subject to their bonded RUNE being slashed as a result of the unauthorized outbound transactions.
* Churn activity has been paused while the investigation and remediation efforts are ongoing.
* Onboarding additional chains and operations requiring churns will be delayed until the network is stabilized.
* Initial indications show no individual user swaps were affected.
We are asking all node operators to immediately review their infrastructure, hosts, key management systems, and operational security for any signs of compromise or abnormal behavior, and to report anything suspicious in Discord.
Node operators participating in the affected vault are requested to securely provide Bifrost logs to the dev team for analysis using 'make relay' .
I was bullish all the way from 16k to 120k
Sold everything at 120k and shorted
Said 60k is next when BTC was at 120k
At 60k I said 79-85k is coming next
And this ladies, is the local top (80-85k)
The big crash towards 50k and lower soon
🚨 The Clarity Act is still in limbo.
Sen. Cynthia Lummis says the bill is “ready” for a hearing… but delays over stablecoin yield rules are still holding it back.
Months of “coming soon.”
Still no clarity.
Crypto lost $482M in Q1 2026 to hacks and exploits.
I just went through @hackenclub's Q1 Security & Compliance report, so you don't have to.
Here are the most important insights ↓
——————————
1️⃣ Audited VS unaudited protocols exploit amounts
Six audited protocols were exploited in Q1.
Average loss:
• $6.3M for audited projects
• $4.3M for unaudited
Audited projects hold more value, which makes them bigger targets.
Attackers also tend to target what falls outside the audit scope.
2️⃣ The biggest incident so far in 2026
In January, someone posing as IT support convinced an individual to hand over their hardware wallet recovery credentials.
The attacker walked away with $282M in BTC and LTC, immediately swapping into $XMR to make tracing nearly impossible.
Definitely the unluckiest individual in 2026.
3️⃣ Hackers are moving fast... or are they?
In 76% of cases, hackers move funds before the team is aware of the hit.
Average hack report time is ~1.5 days.
Makes you wonder whether some teams were genuinely unaware or if delaying the announcement was convenient for them.
4️⃣ Smart contract exploit trend
Total Q1 2026 losses were lower than Q1 2025, but only because there was no catastrophic exchange hack this quarter.
Smart contract exploit losses are actually up 213% YOY, reaching $86.2M across 28 incidents.
Not really an improvement if you look at it from this angle.
5️⃣ North Korean hackers keep draining the crypto space
They were responsible for $2.04B in theft in 2025, accounting for 52% of all annual losses.
None of it happened through smart contract exploits.
Every single incident used social engineering.
The fake VC call that took down @StepFinance_ is the same playbook they've been running, and it keeps working because of the human layer.
6️⃣ RWA protocols became the most vulnerable sector to audit findings
In Q1, RWA and TradFi protocols averaged 22.4 audit issues per review, more than any other sector.
Most of the risk isn't in the token logic itself.
It's in the compliance controls that are built correctly on paper but don't work how they're supposed to in practice.
7️⃣ Patching code introduces new vulnerabilities
1 in 3 attempts to fix a vulnerability accidentally introduced a new one in Q1 this year.
Projects need to treat code review after every patch as standard procedure if they don't want this to become a trend.
8️⃣ The @VenusProtocol extraction
The attacker spent nine months quietly accumulating 84% of the token's supply before triggering the exploit.
The whole thing was visible on-chain for the entire duration.
Nobody caught it.
9️⃣ AI-written code is prone to exploits
In February, @MoonwellDeFi lost $1.78M to what might be the first exploit of AI-authored code.
Using AI to code opens projects up to unforeseen vulnerabilities.
That's the defining security risk of 2026.
🔟 The most audited protocol in Q1 still got drained for $25M
Not even 18 audits stopped @ResolvLabs from getting drained.
The attacker compromised their AWS infrastructure to steal the key that authorized USR minting.
Two transactions later, 80 million unbacked USR tokens were minted from $200K in collateral, extracting $25M before the team paused operations.
——————————
With everything that's happening, it's clear that security in crypto is taken very lightly.
Teams should rethink their approach to this problem before focusing on anything else.
Otherwise, we could see a lot more victims featured in reports.
“The goal seems to be issuing the token, not making it valuable.”
That's the whole problem.
Projects treat tokens as a fundraising event, not as an asset that should capture value from what they're building.
Blockchain adoption is growing.
Stablecoins, DeFi, RWA tokenization, all real growth.
But if you're trying to express "long blockchain" through tokens, good luck finding more than 20 that actually tie project success to token value.
Exchanges don't help either.
They list everything, make money on volume, and let retail figure out which 99% of tokens are worthless.
Until tokens are designed to capture value from day one, the disconnect between blockchain growth and token prices isn't going anywhere.
google mapped the exact path to crack bitcoin's secp256k1 in 9 minutes. bitcoin blocks take 10 minutes. that 1-minute mempool window is a specific, publishable attack vector and BTC has zero coordinated upgrade plan. ethereum already has a 2029 quantum-resistant roadmap backed by coinbase, google, and stanford. 500,000 physical qubits are years away but the narrative repricing starts now. every protocol that stays silent on quantum readiness is going to bleed credibility. ETH answered. BTC hasn't.