$SOL Distribution Concentration Analysis Current vs Six Months Ago.
And analysis of the top #1 $SOL holdings of ALTs that you will position yourself Q4.
$SOL distribution has become slightly more concentrated over the past six months, .
They happen because bridges, upgrade permissions, and privileged systems become the weakest link.
In Web3, attackers don't look for the strongest code.
They look for the weakest assumption.
Three DeFi hacks. One lesson.
AFX Trade.
Verus.
B² Network.
Different protocols.
Different attack vectors.
Same reality.
Most DeFi failures don't happen because blockchains are broken.
⚠️HACKS GALORE: Three exploits drain $35.5 Million within hours in a brutal day for DeFi.
- AFX Trade- $24.15M hack
The AFX-operated USDC custody bridge on Arbitrum was exploited, forcing the team to suspend bridge operations.
- Verus - $7.55M hack
The Verus Ethereum Bridge was exploited after an attacker abused the bridge's import mechanism to trigger unbacked payouts, marking the second exploit using the same failure mode since May.
- B² Network $3.86M hack
Attackers gained unauthorized access to the $B2 staking contract's upgrade authority, prompting the team to suspend staking while security reviews are completed. The issue has since been contained, with no further impact expected.
$35.5M lost in hours.
Three separate exploits.
Three different protocols.
Yet they all reinforce the same principle:
Security is only as strong as the most privileged component in your system.
Whether it's a bridge, an upgrade key, or a custody mechanism...
⚠️HACKS GALORE: Three exploits drain $35.5 Million within hours in a brutal day for DeFi.
- AFX Trade- $24.15M hack
The AFX-operated USDC custody bridge on Arbitrum was exploited, forcing the team to suspend bridge operations.
- Verus - $7.55M hack
The Verus Ethereum Bridge was exploited after an attacker abused the bridge's import mechanism to trigger unbacked payouts, marking the second exploit using the same failure mode since May.
- B² Network $3.86M hack
Attackers gained unauthorized access to the $B2 staking contract's upgrade authority, prompting the team to suspend staking while security reviews are completed. The issue has since been contained, with no further impact expected.
Every exchange shutdown creates a new attack surface.
Not because the exchange is unsafe.
But because scammers know users are rushing to withdraw funds.
Major events don't just move markets.
They create opportunities for attackers.
Dear BitMEX Users,
Today, we share with a very heavy heart that BitMEX exchange will shut down its operations, effective 23 September 2026 at 04:00:00 UTC.
The owner and operator of BitMEX, HDR Global Trading Limited, has made the difficult decision to close operations following a strategic review of the business.
It may not look the same today, but we are proud of our 11+ year legacy and the role we played in shaping the crypto industry. We invented the 100x leverage perpetual swap, which for most of you, was the first step to your crypto trading journey. It is now the most traded financial product in the crypto industry, adopted by thousands of users and exchanges. And we remain proud of our robust security infrastructure, which has allowed us to maintain a flawless track record of 0 customer funds lost to hacks in our entire operating history.
We want to reassure you that your assets remain fully safe and under your control during this transition period. This announcement is just to give enough time to ensure a smooth withdrawal process for everyone.
From today we strongly encourage all users to close their positions and withdraw their funds as soon as convenient. For more details on the full process, please read our blog: https://t.co/OOHeh6xHm8
BitMEX was once home to some of the greatest traders today. Our team has dedicated tremendous effort and passion into building the platform into what it is, and we are glad to have reached some of you during your time with us. To everyone who has traded, supported, and grown alongside us - thank you for your trust over the last 11 years.
The BitMEX Team
It's a reminder that even industry giants can become irrelevant when innovation slows and competition moves faster.
The real lesson isn't:
"BitMEX is closing."
The real lesson is:
In crypto, survival isn't guaranteed by history.
The exploit is over.
The recovery phase has begun.
That's when scammers usually become most active.
Expect fake recovery portals, fake support accounts and fake airdrops.
Verify everything.✅
⚠️ Recovery Update: Bounty Offer Made to Attacker
To keep our community informed on our recovery efforts, we want to provide more context regarding the second attack that occurred during the recent security incident.
Context on the 2nd Attack: Shortly after the initial breach, a second, entirely unrelated party exploited the same vulnerability. This independent actor capitalized on the exploit to drain an additional ~4 million ADA (along with various Cardano Native Tokens) from compromised user wallets.
Our Outreach & Bounty Offer: Approximately two weeks ago, we contacted this secondary attacker directly via an onchain message sent to the wallet holding the stolen funds. We offered a standard white-hat resolution:
🔹 Return 90% of the funds (3,618,421 ADA + CNTs) to our recovery address
🔹 Retain 10% (402,047 ADA) as a bounty
🔹 Deadline: 10 July 2026, 23:59 UTC
The onchain message can be verified here: https://t.co/jXyhX8FzhW
The deadline has passed and we have yet to receive a response.
As stated in our message, this offer does not waive any rights, remedies, claims, or options, including the ability to continue the investigation, coordinate with third parties, or pursue legal and law enforcement channels where appropriate.
We will share further updates through our official channels.
@secondfiapp Transparency throughout the recovery process matters just as much as transparency during the incident. Wishing the team success in recovering users' funds.
Take time and read it will help you and the users.
This was not a phishing attack.
This was not a smart contract exploit.
It was a failure in one of the most sensitive components of any wallet:
Key generation and transaction signing.
An update regarding the recent security incident involving SecondFi
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide users with a transparent update based on the information currently available.
An independent investigation
EMURGO engaged Groom Lake, an independent forensic investigation / blockchain intelligence provider to assist with tracing and evidentiary analysis and they reviewed the incident using primary technical evidence, including code, code history, and public blockchain data.
What the investigation indicates to date:
1. Attack from an external actor: linked to high-volume addresses employing advanced tradecraft: @0xGroomLake indicates that the primary operation behind the unauthorised transfers was sophisticated, external, and well-funded, with indicators consistent with activity by a professional, state-aligned threat actor. Certain indicators are being assessed for potential overlap with known DPRK-linked threat activity of Lazarus Group.
2. Two separate attackers: Groom Lake also identified activity by a second party that appears, based on current evidence, to be separate from the primary operation and to have affected a different set of wallets during the same window. No overlap in affected wallets has been identified to date.
The root cause: A cryptographic flaw
The root cause was a highly subtle flaw in how the wallet software generated per-transaction signatures. In simplified terms, a value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. This could enable affected private key material to be derived from information visible on the public blockchain.
This cryptographic flaw was also visible in a copy of the relevant code that had been published without authorisation to a public GitHub repository. We are continuing to assess the circumstances surrounding the publication and are cooperating with the relevant authorities.
Fix and winding down of SecondFi
The flaw has been patched, and new wallets created with the corrected software are not known to be affected by this issue. However, given the gravity of this event and as previously announced, we have made the difficult decision to wind down SecondFi and Yoroi wallet.
Asset recovery and safe migration
Our current priority is supporting affected users, assisting recovery efforts, and enabling users to move assets securely.
1. Recovery tool: A secure recovery tool using zero-knowledge (ZK) proofs is being developed. The portal is designed to allow users to initiate the process directly while limiting the information required to do so. The tool is currently in testing, and we are engaging a specialist third-party auditor to review it before its anticipated release in August 2026.
2. Safe migration: In the meantime, we are preparing wallet export functionality designed to allow users to migrate their assets to a wallet of their choice. We anticipate releasing this by early August 2026.
Please follow our official channels for further updates.
Important Security Reminder
SecondFi will NEVER request private keys, recovery phrases, or wallet credentials, and we will never DM you first. Do not trust any checker, link, or account outside our official channels:
▪️ X accounts: @secondfiapp and @secondfi_jp
▪️ Support portal: https://t.co/bKfl8SK9D2
MERIX Conclusion
This incident is a reminder that the security of a blockchain ecosystem depends not only on the blockchain itself, but also on the software built around it.
A secure blockchain does not guarantee a secure wallet.