Other Incidents 722 incidents

Cybersecurity incidents not classified under a specific category

Other

Drift Protocol $285M DPRK Social Engineering Exploit

2026-04-01 [vendor] Drift Protocol (Solana DeFi perpetual futures DEX)
Vector: Six-month DPRK social engineering operation (UNC4736/TraderTraitor) targeted Drift Security Council members; attackers built relationships with team members and used Solana's 'durable nonces' feature to trick council members into pre-signing malicious transactions that transferred admin control

On April 1, 2026, UNC4736 (North Korean state-sponsored TraderTraitor group) executed a 12-minute, 31-transaction drain of $285 million from Drift Protocol, the largest Solana DeFi …

Other

Attack proposal

2026-03-24 [vendor] Moonwell governance attack
Vector: Governance attack / malicious on-chain proposal

The Moonwell lending protocol faced a governance attack on its deprecated Moonriver instance that could have drained $1 million from the project. Because Moonwell's MFAM governance …

Other

Resolv Protocol DeFi Exploit — $24 Million Minted via Smart Contract Vulnerability

2026-03-22 [vendor] Resolv Protocol (Ethereum DeFi stablecoin protocol)
Vector: Attacker exploited a vulnerability in Resolv Protocol's smart contracts on Ethereum, allowing unauthorized minting of tokens worth approximately $24 million; the specific technical exploit involved manipulating the protocol's collateralization or price oracle mechanisms

In March 2026, an attacker exploited a vulnerability in Resolv Protocol — an Ethereum-based decentralised finance (DeFi) stablecoin protocol — to mint approximately $24 million in …

Other

Bitcoin Depot Crypto ATM Breach - $3.66M BTC Stolen

2026-03-20
Vector: Attackers obtained credentials linked to Bitcoin Depot's digital asset settlement accounts, enabling unauthorized transfer of Bitcoin from company-controlled corporate wallets

On March 20, 2026, attackers used compromised credentials to access Bitcoin Depot's digital asset settlement accounts and transfer 50.903 BTC (valued at approximately $3.665 …

Other

Chapter 11 Voluntary Petition

2026-03-15 [vendor] BlockFills goes bankrupt
Vector: Protocol collapse / insolvency

Approximately a month after halting deposits and withdrawals, citing liquidity issues and "recent market and financial conditions", the American crypto lender BlockFills has filed …

Other

Tweet by Stani Kulechov

2026-03-12 [vendor] Aave swap loss [loss] $50M

A trader using the Aave interface attempted to swap $50 million USDT for AAVE. However, due to the enormous size of the order, the purchase had dramatic impact on the aave price. …

Other

Stryker Handala Iran-Linked MDM Wiper Attack

2026-03-11 [vendor] Microsoft Intune (mobile device management)
Vector: Handala (Void Manticore, MOIS-affiliated Iran) compromised a Microsoft Intune admin account at Stryker, then used the MDM platform to issue remote wipe commands against the entire enrolled device fleet across 79 countries

On March 11, 2026, the Iran-linked hacktivist group Handala (a persona of Void Manticore, affiliated with Iran's Ministry of Intelligence and Security) wiped between 80,000 and …

Other

Bithumb Cryptocurrency Exchange Hack — South Korea, Recovery Plan 2026

2026-03-01 [vendor] Bithumb cryptocurrency exchange (South Korea)
Vector: Bithumb suffered an unauthorised access incident affecting its cryptocurrency exchange platform; specific technical attack vector not publicly disclosed at time of reporting; the exchange was working on a recovery plan to compensate affected users and restore operations

In early 2026, Bithumb — South Korea's largest cryptocurrency exchange with approximately $1 billion in daily trading volume and over 8 million registered users — suffered a …

Other

FBI Seizes Handala Iranian Leak Domains After Stryker Hack

2026-03-01 [vendor] Handala leak site infrastructure (Iranian IRGC-linked)
Vector: US federal law enforcement (FBI/DOJ) executed court-ordered domain seizures targeting four web domains used by Handala, an Iran-linked hacktivist group, for publishing stolen data and coordinating cyberattack claims

In March 2026, US federal law enforcement seized four web domains associated with Handala's Iranian online leak infrastructure, days after Handala published materials it claimed to …

Other [SC]

FBI DCS-3000 Surveillance Network Breach - China-Linked 'Major Incident'

2026-02-17 [vendor] FBI Digital Collection System Network DCS-3000 (Red Hook) - pen register and tap-and-trace surveillance infrastructure
Vector: Threat actors leveraged a commercial Internet Service Provider's vendor infrastructure to access FBI systems; FBI systems in the Virgin Islands were compromised

On February 17, 2026, the FBI began investigating abnormal activity in an unclassified system — DCS-3000 (known as Red Hook), part of its Digital Collection System Network (DCSNet) …

Other

Tweet thread by zachxbt

2026-01-23 [vendor] Lick theft
Vector: On-chain theft (attributed by zachxbt)

Two crypto thieves decided to settle an argument over who was wealthier by screensharing as they transferred crypto between wallets to prove ownership. In doing so, one of them — …

Other

GRU APT28 SOHO Router DNS Hijacking Campaign — Cloud Activity Espionage

2026-01-01 [vendor] SOHO routers (multiple vendors including TP-Link, ASUS, Netgear, D-Link) used by target organisations [malware] MooBot (Mirai variant), custom DNS hijacking tools
Vector: GRU-linked APT28 (Fancy Bear) threat actors compromised SOHO (Small Office/Home Office) routers by exploiting default credentials, unpatched firmware vulnerabilities, or known CVEs in popular router models; once compromised, attackers modified the routers' DNS resolver settings to redirect DNS queries through attacker-controlled infrastructure, enabling passive interception of cloud service authentication traffic for high-value targets

In early 2026, security researchers and government agencies disclosed a new cyberespionage campaign by hackers tied to Russia's GRU military intelligence agency (Fancy Bear / APT28 …

Other

Tweet by DappRadar

2025-11-17 [vendor] DappRadar
Vector: Protocol collapse / insolvency

Amid a month of falling crypto prices, the crypto tracking platform DappRadar has announced it will be shutting down after seven years of operation. "Running a platform of this …

Other

US Congressional Budget Office China-Suspected Cyberattack

2025-11-01 [vendor] Cisco ASA (firewall)
Vector: Suspected exploitation of an outdated Cisco ASA firewall (last patched 2024) — vulnerable to newly discovered bugs actively exploited by suspected Chinese state-sponsored hackers; suspected PRC/China state-backed actor

In early November 2025, the US Congressional Budget Office (CBO) detected and confirmed a cyberattack by a suspected foreign actor. US officials briefed CNN that Chinese …

Other

Tweet by Chaofan Shou

2025-08-27 [vendor] BetterBank [loss] $1M

The PulseChain-based defi project BetterBank was exploited by an attacker who took advantage of a vulnerability that allowed them to mint arbitrary tokens, some of which they then …

Other

SK Telecom BPFDoor Malware Breach - 27 Million SIM Records

2025-04-18 [malware] BPFDoor; Tiny Shell
Vector: Multiple strains of malware (including 27 variants of BPFDoor backdoor, Tiny Shell, and other tools) installed on SK Telecom's internal servers; went undetected for approximately 3 years (2022–2025)

SK Telecom (South Korea's largest mobile carrier, ~27 million subscribers) officially confirmed a breach on April 19, 2025, after detecting malware on April 18 targeting its Home …

Other

Tweet by BinanceWallet

2025-03-24 [vendor] Binance insider trading

Binance announced on Twitter that they had fired an employee after discovering that they had engaged in insider trading. The employee took a large position in a token that he knew …

Other

Opexus Federal Contractor Insider Breach

2025-02-18
Vector: Insider threat: two employees (twin brothers) with prior hacking convictions retained privileged access; exfiltrated files via USB drive and deleted government databases during and after termination meeting

Opexus, a Thoma Bravo-owned software company providing records management services to nearly every US federal agency, was compromised by twin brothers Muneeb and Suhaib Akhter who …

Other

Tweet thread

2025-01-23 [vendor] Thorchain
Vector: Protocol collapse / insolvency

The ThorChain project is in crisis amid news that the project is insolvent. In order to prevent what would effectively be a bank run and likely death spiral, the project has paused …

Other

Order

2025-01-17 [vendor] Genesis
Vector: Regulatory / legal action

The Digital Currency Group has agreed to settle with the SEC for $38 million over charges that its Genesis subsidiary misled investors. When the hedge fund Three Arrows Capital …

Other

"MakersPlace Announces Market Exit"

2025-01-16 [vendor] MakersPlace NFT marketplace
Vector: Protocol collapse / insolvency

Citing "ongoing market challenges and funding difficulties", the MakersPlace NFT platform announced it will be shutting down after six years of operations. The company had raised …

Other

Tweet by David Hoffman

2025-01-11 [vendor] Bankless hosts slammed for dumping tokens

The hosts of the Bankless crypto podcast have landed in hot water after selling off some of the substantial quantities of $AICC tokens they were allocated as investors in the …

Other

Machine-Speed Cyberattacks — AI-Automated Attack Chains Outpace Human Defence

2025-01-01 [vendor] Enterprise networks globally across all sectors
Vector: AI and automation enable attackers to execute complete attack chains — from initial access through lateral movement, privilege escalation, data exfiltration, and ransomware deployment — faster than human security operations teams can detect and respond; AI-driven tools exploit vulnerabilities and pivot across networks without requiring human attacker intervention at each step

By 2025-2026, documented case studies from Darktrace, CrowdStrike, Palo Alto Networks Unit 42, and Microsoft MSTIC demonstrate that the most advanced attackers are executing …

Other

Tweet by RTFKT

2024-12-02 [vendor] Nike to

Nike will be shutting down its RTFKT "virtual collectibles" project at the end of January 2025, according to an announcement made in early December. Nike had acquired RTFKT in 2021 …

Other

Midnight Blizzard Large-Scale RDP Spear-Phishing Campaign

2024-10-22
Vector: Russian SVR-linked Midnight Blizzard (APT29/NOBELIUM) sent signed malicious RDP configuration files via spear-phishing email; RDP files connected targets' machines to attacker-controlled servers, mapping local resources for data theft and malware staging

From 22 October 2024, Midnight Blizzard targeted thousands of users across 100+ organizations in government, academia, defense, and NGOs in UK, Europe, Australia, and Japan. Emails …

Other

BleepingComputer

2024-10-03 [vendor] American Water Works customer IT systems
Vector: CWE-284: Improper Access Control

American Water Works, the largest regulated water and wastewater utility in the United States (serving 14+ million people across 14 states), detected unauthorized activity in its …

Other

Tweet thread by Samperson

2024-09-15 [vendor] Flappy Bird creator disavows crypto spin-off

A blockchain-based version of the 2014 hit game Flappy Bird has emerged, taking advantage of the recent "tap-to-earn" crypto craze. The @flappy_bird Twitter account posted "I AM …

Other

Eve Frontier FAQ

2024-09-13 [vendor] Eve Online announcement

CCP, the developer of the Eve Online space MMORPG, has angered their fanbase with a new announcement that their upcoming game will be built on the blockchain and incorporate …

Credential theft

Transport for London (TfL) Scattered Spider Attack

2024-08-31
Vector: Social engineering / MFA bypass by Scattered Spider members; attacker gained internal access via compromised employee credentials

Scattered Spider attacked Transport for London on 31 August 2024, ultimately exposing data of approximately 10 million customers — one of the largest breaches in British history. …

Other

Tweet by Devin Finzer

2024-08-28 [vendor] OpenSea Wells notice
Vector: Regulatory / legal action

OpenSea has announced that they received a Wells notice from the U.S. Securities and Exchange Commission, warning them of a likely lawsuit from the agency. According to CEO Devin …

Other [SC]

CrowdStrike Falcon Sensor Update — Global Windows BSOD Outage (8.5 Million Devices)

2024-07-19 [vendor] CrowdStrike Falcon sensor (Windows) — Channel File 291
Vector: A faulty content configuration update (Channel File 291) for the CrowdStrike Falcon sensor on Windows hosts caused a logic error in the sensor's Content Interpreter, triggering an out-of-bounds memory read that led to an exception handling failure and Windows BSOD (Blue Screen of Death)

On 19 July 2024, CrowdStrike released a faulty content configuration update (Channel File 291) to Windows systems running the CrowdStrike Falcon endpoint detection and response …

Other

<i>Logan Paul v. Stephen Findeisen</i>

2024-06-27 [vendor] Logan Paul lawsuit against Coffeezilla
Vector: Regulatory / legal action

A year and a half after threatening to sue YouTuber Coffeezilla for his series of videos exposing influencer Logan Paul's (alleged) role in (allegedly) scamming his large following …

Other

Web3 Is Going Great

2024-04-30 [vendor] Changpeng Zhao
Vector: Regulatory / legal action

Former Binance CEO Changpeng "CZ" Zhao has been sentenced to four months in prison after pleading guilty to money laundering-related charges. The charges were filed in November, …

Other

Tweet by Roger Stone

2024-04-17 [vendor] Roger Stone endorses $TRUMP memecoin

Amid tweets alleging corruption among jurors in his 2019 criminal case, far-right activist and Trumpworld figure Roger Stone has posted several tweets endorsing "MAGA Memecoin", …

Other

"Fighting for DeFi"

2024-04-10 [vendor] Uniswap Wells notice
Vector: Regulatory / legal action

The US Securities and Exchange Commission issued a warning to the Uniswap decentralized exchange in the form of a Wells notice. Wells notices are used to inform the recipient of an …

Other

Minute Entry

2024-03-28 [vendor] Sam Bankman-Fried
Vector: Regulatory / legal action

Sixteen months after the collapse of his FTX cryptocurrency exchange, Sam Bankman-Fried has been sentenced to 25 years in prison. He has also been ordered to pay an $11 billion …

Other

Volexity / Palo Alto Networks PSIRT / CISA / Tenable

2024-03-26 [vendor] Palo Alto Networks PAN-OS GlobalProtect [malware] UPSTYLE Python backdoor [cve] CVE-2024-3400
Vector: CWE-77: Command Injection via arbitrary file creation in GlobalProtect feature

CVSS 10.0. Threat actor UTA0218 exploited zero-day in PAN-OS GlobalProtect feature allowing unauthenticated OS command execution as root. Affected PAN-OS 10.2, 11.0, 11.1 with …

Other

Tweet thread by Charles Wang

2024-03-15 [vendor] Tether user's accidental burn

Someone accidentally threw away $1.36 million when they accidentally sent Tethers to the Tether contract address — making them permanently inaccessible in a process known as …

Other

Tweet by zachxbt

2024-02-26 [vendor] BitForex withdrawals [loss] $57M
Vector: On-chain theft (attributed by zachxbt)

The Hong Kong-based BitForex cryptocurrency exchange has shut down access to its platform after a suspicious outflow of around $57 million on several blockchains. Users who have …

Other

"The disappointing tea.xyz"

2024-02-26 [vendor] tea.xyz spam

This crypto skeptic I've heard of once said "Show me the incentive and I will show you the outcome."A project called tea.xyz promised people they could "get rewards for [their] …

Other

Tweet by Cyvers Alerts

2024-02-20 [vendor] AAX money movement [loss] $56M

The Hong Kong-based AAX cryptocurrency exchange suspended withdrawals in November 2022, only days after the FTX collapse and related chaos in the cryptocurrency world. They claimed …

Other

Tweet thread by zachxbt

2024-02-20 [vendor] Influencer "Crypto Rover" accused of pump-and-dump and other shady behavior
Vector: On-chain theft (attributed by zachxbt)

A popular cryptocurrency influencer known as "Crypto Rover" has been accused by blockchain sleuth zachxbt of shady behavior, including accepting promotional payments from crypto …

Other

"KSI Accidentally Exposes His Crypto Scams"

2024-02-15 [vendor] YouTuber KSI accused of pump-and-dump [loss] $850,000
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuths Coffeezilla and zachxbt teamed up on an investigation into YouTuber and crypto promoter KSI, accusing him of pumping up interest into the XCAD project and then …

Other

IBM Security Intelligence

2024-01-18 [vendor] Unitronics PLC / Muleshoe, TX water tower SCADA
Vector: CWE-1188: Insecure Default Initialization of Resource (default credentials on internet-exposed industrial control systems)

In January 2024, Russian hackers affiliated with Sandworm (a GRU/Russian military intelligence cyber unit) infiltrated water treatment systems in Muleshoe, Texas, causing a water …

Other

<i>USA v. Rodney Burton</i>

2024-01-09 [vendor] Bitcoin Rodney arrest
Vector: Regulatory / legal action

A crypto influencer known as "Bitcoin Rodney" was arrested by US authorities for his involvement in the HyperVerse crypto scam, which fleeced victims out of over $1 billion. In …

Other [SC]

Healthcare Vendor Supply Chain Systemic Risk — Cascading Breaches Across US Hospital Systems

2024-01-01 [vendor] Healthcare technology vendor ecosystem — EHR vendors, billing processors, lab networks, pharmacy benefit managers
Vector: Healthcare vendor supply chain attacks exploit the concentration of sensitive patient data and operational dependencies in third-party EHR vendors, billing processors, managed care platforms, and file transfer systems; a single vendor breach cascades to hundreds of hospital and health plan clients simultaneously

By 2025-2026, healthcare vendor supply chain attacks had become the dominant breach vector in US healthcare, with HHS OIG and OCR reporting that third-party vendor incidents …

Other

Global Ransomware Law Enforcement Disruption Operations 2025-2026 — Europol, FBI, NCA

2024-01-01 [vendor] LockBit, BlackCat/ALPHV, Hive, Cl0p, Scattered Spider — ransomware operations disrupted 2024-2026 [malware] LockBit, ALPHV/BlackCat, Hive, Cl0p, REvil, Scattered Spider
Vector: Law enforcement disruption of ransomware infrastructure using proactive techniques: infiltrating group chats and affiliate portals months before public action (Operation Cronos / LockBit), seizing cryptocurrency from ransomware wallets, arresting affiliates and key operators globally, and publishing decryption keys for victims

By 2025-2026, international law enforcement agencies had significantly shifted their approach to ransomware disruption — moving from reactive arrests after the fact to proactive …

Other

Chapter 7 Voluntary Petition

2023-12-14 [vendor] SafeMoon files for bankruptcy
Vector: Regulatory / legal action

The company behind the SafeMoon cryptocurrency scam has filed for Chapter 7 bankruptcy. Screenshots circulated on Twitter of a letter to employees citing "a number of operational …

Other

Tweet thread by BitStable

2023-11-29 [vendor] BitStable sale failure

BitStable launched their BSSB token in a public sale only to watch as all tokens sold out in one block. Four entities acquired the majority of the BSSB tokens, an outcome that the …

Other

Iranian IRGC CyberAv3ngers Water Utility ICS Attacks — US and Israel Infrastructure

2023-11-22 [vendor] Unitronics Vision Series PLCs (programmable logic controllers) at US water and wastewater facilities [cve] CVE-2023-6448
Vector: CyberAv3ngers (affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command, IRGC-CEC) exploited internet-exposed Unitronics Vision Series PLCs at water and wastewater facilities; the PLCs had default factory passwords and were directly internet-accessible without authentication

Beginning 22 November 2023, CyberAv3ngers — a threat group affiliated with Iran's IRGC Cyber-Electronic Command — conducted attacks against Unitronics Vision Series PLCs at water …

Other

<i>SEC v. Kraken</i>

2023-11-20 [vendor] Kraken sued by U.S. SEC
Vector: Regulatory / legal action

Kraken is the latest cryptocurrency exchange to face a lawsuit from the U.S. Securities and Exchange Commission. According to the SEC, Kraken violated securities laws by listing …

Other

"Superdao is closing down"

2023-10-19 [vendor] Superdao to
Vector: Protocol collapse / insolvency

Superdao, a project aiming to assist communities in forming DAOs, has announced it will be closing its doors. It was blunt in its announcement: "it became clear that the crypto …

Other

<i>Schiermeyer v. Thurston</i>

2023-08-31 [vendor] Gala Games lawsuits
Vector: Regulatory / legal action

The two co-founders of blockchain gaming company Gala Games are suing each other. One lawsuit, filed by Gala Games CEO Eric Schiermeyer, alleges that Gala's director Wright …

Other

Tweet by belgio

2023-08-30 [vendor] Starknet upgrade leaves $550,000 inaccessible

"The wallets that did not upgrade in time will lose their assets," a StarkWare customer support representative said on Discord to an individual inquiring why they could no longer …

Other

Retool MFA Bypass via Google Authenticator Cloud Sync Phishing

2023-08-27 [vendor] Google Authenticator (cloud sync feature); Okta
Vector: Attacker used spear phishing SMS (smishing) to social engineer a Retool employee into providing credentials and a Google Authenticator TOTP code, then used the synced OTP tokens from Google Account cloud sync (newly enabled feature) to bypass MFA and access Retool's Okta admin, then Google Workspace and internal systems

On August 27, 2023, a Retool employee received a convincing smishing (SMS phishing) message claiming to be from Retool IT support regarding a benefits enrollment issue requiring …

Other

<i>Glow Token v. Crypto.com</i>

2023-08-18 [vendor] Crypto founder [loss] $273,000

Bryan Lawrence, the leader of a crypto project called Glow Token, recently shared that he'd fallen victim to scammers impersonating employees of the Crypto.com exchange. Lawrence …

Other

"SEC Charges Hex Founder Richard Heart with Misappropriating Millions of Dollars of Investor Funds from Unregistered Crypto Asset Securities Offerings that Raised more than $1 Billion"

2023-07-31 [vendor] SEC goes after Richard Heart and his projects Hex, PulseChain, and PulseX
Vector: Regulatory / legal action

The SEC filed charges against Richard Heart, the operator of Hex, PulseChain, and PulseX. Despite Heart's best attempts at evading securities laws — including by asking people to …

Other

Tweet by Spreekaway

2023-07-21 [vendor] Party Parrot treasury distribution

You almost have to hand it to the Party Parrot team, they really figured out how to take advantage of ostensibly "decentralized" governance to line their own pockets. After raising …

Other

Tweet thread by Multichain

2023-07-14 [vendor] Multichain finally confirms their CEO was arrested in China
Vector: Regulatory / legal action

After a months-long saga involving "stuck" transactions, Multichain announcing they couldn't get in contact with their CEO, rumors that the whole team was arrested, and several …

Other

<i>United States v. Mashinksy</i>

2023-07-13 [vendor] Celsius lawsuits, CEO arrest
Vector: Ponzi / pyramid scheme

A multi-agency hammer came down on the bankrupt cryptocurrency lender and alleged Ponzi scheme that was Celsius. The co-founder and former CEO of the company, Alex Mashinsky, was …

Other

<i>CFTC v. Todd</i>

2023-07-12 [vendor] Digitex
Vector: Regulatory / legal action

Adam Todd, the CEO of the Digitex Futures exchange, has been ordered to pay $3.9 million in disgorgement and $11.7 million in penalties. The Commodity Futures Trading Commission …

Other

Tweet thread by m4gicpotato

2023-07-10 [vendor] Arkham Intelligence referral program exposes user emails

In a somewhat amusing complement to Arkham Intelligence's "on-chain intelligence exchange" announcement, a new product which seeks to allow people to buy and sell private …

Other

Order to cease and desist

2023-06-22 [vendor] Prime Trust
Vector: Regulatory / legal action

The Nevada Financial Institutions Division issued a cease and desist to the Prime Trust crypto custodian. Earlier in the month, the apparently embattled Prime Trust signed a …

Other

Tweet thread by zachxbt

2023-06-16 [vendor] Machi Big Brother sues zachxbt
Vector: On-chain theft (attributed by zachxbt)

Crypto personality and creator of C.R.E.A.M. Finance Jeffrey Huang, aka "Machi Big Brother", has filed a defamation lawsuit against crypto sleuth zachxbt. Huang alleges that …

Other

Tweets by Wyre

2023-06-16 [vendor] Wyre finally
Vector: Protocol collapse / insolvency

The crypto payments platform Wyre finally announced they would be winding down "due to market conditions". This came after a January announcement from the CEO, where it was not …

Other

Abra cease and desist

2023-06-15 [vendor] Abra insolvency
Vector: Regulatory / legal action

In an emergency cease-and-desist issued on June 15, the Texas State Securities Board alleged that the Abra crypto lending firm was "insolvent or nearly insolvent" as of interviews …

Other

"출금 중지 조치 안내"

2023-06-14 [vendor] Delio suspends withdrawals
Vector: Withdrawal halt / insolvency

South Korean cryptocurrency lending platform Delio announced to its customers on June 14 that they would be suspending withdrawals. In a letter to customers, they wrote that the …

Other

Bankruptcy petition

2023-06-13 [vendor] Banq bankruptcy
Vector: Protocol collapse / insolvency

Banq, a subsidiary of the Prime Trust crypto custodian, has filed for bankruptcy. Banq is a "crypto-friendly" payment processor based in Nevada, though according to the bankruptcy …

Other

Order on Motion for Default Judgment

2023-06-09 [vendor] CFTC awarded summary judgment in case against Ooki DAO
Vector: Regulatory / legal action

Ooki DAO was sued in September of last year for allowing illegal trading of digital assets, engaging in activities only allowed by registered futures commission merchants, and not …

Other

CISA

2023-06-01 [vendor] Consumer and SOHO routers, IP cameras, DVRs (multiple vendors) [malware] Flax Typhoon botnet (Raptor Train)
Vector: CWE-1188: Insecure Default Initialization of Resource (compromised SOHO routers and IoT devices with default/weak credentials)

In September 2024, the FBI and CISA announced the disruption of a botnet operated by Flax Typhoon, a Chinese state-sponsored threat actor (also tracked as RedJuliett/Ethereal …

Other

Tweet thread by Wu Blockchain

2023-05-31 [vendor] Binance reportedly begins layoffs

Crypto giant Binance has reportedly begun layoffs, according to independent crypto reporter Colin Wu, who cited several anonymous sources. The layoffs will amount to around 20% of …

Other

"Notice on Exit from Canadian Market"

2023-05-30 [vendor] Bybit exits Canada
Vector: Regulatory / legal action

The cryptocurrency exchange Bybit announced that they would be exiting Canada. The company cited "recent regulatory development" in the country for their decision to stop offering …

Other

"Unbanked will be winding down"

2023-05-26 [vendor] Unbanked to
Vector: Protocol collapse / insolvency

The US-based crypto payments and custody platform Unbanked announced in a blog post that they will be shutting down services. The company was founded in 2018, and claimed they …

Other

Tweet by Binance

2023-05-12 [vendor] Binance exits Canada
Vector: Regulatory / legal action

Binance announced they would be exiting Canada, "proactively withdrawing" ahead of stablecoin regulation and crypto investment limits. As is becoming a trend in the industry, …

Other

"Suspension of activities"

2023-04-27 [vendor] Bit4You suspends activities
Vector: Protocol collapse / insolvency

The only Belgian crypto platform, the Bit4You crypto lender, announced they would be suspending activities after the CoinLoan crypto exchange was ordered to suspend activities …

Other

Notice of restraint on disposition

2023-04-25 [vendor] CoinLoan suspends withdrawals [loss] $10M
Vector: Withdrawal halt / insolvency

The Estonian crypto exchange CoinLoan announced they were immediately suspending all operations, including withdrawals. The action came after CoinLoan was declared insolvent by an …

Other

"Important Message For Bittrex U.S. Customers"

2023-03-31 [vendor] Bittrex crypto exchange to close US operations
Vector: Regulatory / legal action

Bittrex, one of the oldest and largest cryptocurrency exchanges serving US customers, announced that it would be shuttering its US platform. "It's just not economically viable for …

Other

Tweet thread by Stephane Kasriel

2023-03-13 [vendor] Meta ends support for NFTs

In a Twitter thread, Meta (formerly Facebook) Head of Commerce and Fintech Stephane Kasriel announced that they would be "down digital collectibles (NFTs) for now to focus on other …

Other

Tweet by Coinbase

2023-03-10 [vendor] Coinbase

The collapse of the Silicon Valley Bank on March 10 led to concerns over the stability of the stablecoin USDC, after it was revealed that a portion (later specified at $3.3 …

Other

"Silvergate has collapsed"

2023-03-08 [vendor] Silvergate bank
Vector: Protocol collapse / insolvency

California-based Silvergate bank had pivoted almost entirely to serving crypto clients, a move that proved fatal to them in the wake of the FTX collapse and ensuing contagion. On …

Other

Indictment

2023-02-23 [vendor] Sam Bankman-Fried indicted on four new charges in criminal case
Vector: Regulatory / legal action

Sam Bankman-Fried, the founder and former CEO of the now-bankrupt FTX exchange, was already facing eight criminal charges for offenses including wire fraud, securities fraud, money …

Other

<i>SEC v. Payward Ventures (dba Kraken)</i>

2023-02-09 [vendor] Kraken ends staking, pays $30 million in settlement with U.S. SEC
Vector: Regulatory / legal action

U.S. cryptocurrency exchange Kraken has reportedly agreed to close up shop on its crypto staking operation and pay a $30 million fine to the U.S. Securities and Exchange …

Other

Infosecurity Magazine

2023-02-01 [vendor] FortiGate 300D firewall / Littleton Electric Light and Water Departments OT network
Vector: CWE-1188: Insecure Default Initialization of Resource (unpatched FortiGate 300D firewall — CVE patched December 2022, not applied until after breach)

Volt Typhoon (VOLTZITE per Dragos), a Chinese state-sponsored APT group, maintained persistent unauthorized access to the operational technology (OT) network of Littleton Electric …

Other

Tweet by CoffeeZilla

2023-01-04 [vendor] Logan Paul threatens to sue CoffeeZilla

Influencer-turned-(alleged)-crypto-grifter Logan Paul has threatened to sue scam researcher CoffeeZilla, who has exposed Paul's "CryptoZoo" blockchain game project as his latest …

Other

Tweet by DNP3

2023-01-03 [vendor] DNP3 gambled with investor funds

DNP3 is a streamer known for giving away large sums of money to other streamers. He is also a crypto founder behind projects including CluCoin, the Xenia play-to-earn game, the …

Other

Tweet by Cameron Winklevoss

2023-01-02 [vendor] Tyler and Cameron Winklevoss, Gemini founders

On November 16, Genesis halted withdrawals from its lending service shortly after the FTX collapse. Gemini, who partners with Genesis lending to power their Earn program, halted …

Other

Salt Typhoon AT&T / Verizon / Lumen Telecom Espionage (Confirmed)

2023-01-01 [vendor] Cisco IOS routers; CALEA lawful intercept systems [malware] Demodex (kernel-mode rootkit)
Vector: Chinese MSS-linked Salt Typhoon APT exploited vulnerabilities in telecom network infrastructure including Cisco routers; leveraged CALEA wiretap backdoor access and a Windows kernel-mode rootkit (Demodex) for persistence

Salt Typhoon (China MSS) breached at least 9 US telecom carriers including AT&T, Verizon, T-Mobile, Lumen, Spectrum, Consolidated Communications, and Windstream. Active for 1-2 …

Other

Wikipedia / SecurityWeek / Congress.gov CRS

2023-01-01 [vendor] AT&T / Verizon / T-Mobile / Lumen / Spectrum / Consolidated Communications / Windstream telecom infrastructure
Vector: CWE-287: Improper Authentication (exploitation of network edge devices and telecom infrastructure to access CALEA lawful intercept systems)

Chinese MSS-affiliated APT Salt Typhoon (FamousSparrow) breached at least 9 US telecoms including AT&T, Verizon, T-Mobile starting ~late 2022/early 2023. Accessed CALEA lawful …

Other

Unsellable NFTs website

2022-12-29 [vendor] Tax loss harvesting tool launched

If you bought an NFT for $1,000 and it's now worthless, you still have to find someone willing to buy it before you can claim it as a loss on your taxes. A project called …

Other

Announcement

2022-12-21 [vendor] Caroline Ellison and Gary Wang
Vector: Regulatory / legal action

Two of Sam Bankman-Fried's inner circle, Caroline Ellison and Gary Wang, have pled guilty to federal criminal charges and are cooperating in the case against Sam Bankman-Fried. …

Other

Tweet by Sasha Ivanov

2022-12-20 [vendor] Waves

Apparently adopting Do Kwon's belief that the solution to a crashing algorithmic stablecoin project is creating another project, Waves founder Sasha Ivanov has announced, "I will …

Other

Tweet by TBD

2022-11-29 [vendor] TBD

TBD is a subsidiary of Block (formerly Square), a tech company co-founded by billionaire social media mogul and Twitter founder Jack Dorsey. In July, they unveiled the concept of …

Other

BlockFi Inc. bankruptcy filing

2022-11-28 [vendor] BlockFi bankruptcy [loss] $1.3B
Vector: Protocol collapse / insolvency

Crypto lending firm BlockFi has filed for Chapter 11 bankruptcy in the wake of the FTX collapse. The company was in dire straits in the spring after Terra and Three Arrows Capital …

Other

Tweet by Wu Blockchain

2022-11-24 [vendor] CoinList
Vector: Withdrawal halt / insolvency

Beginning in mid-November, users of the CoinList exchange and ICO platform reported that they couldn't withdraw assets from the platform. On November 24, CoinList tweeted, "There …

Other

Tweets by Coinhouse

2022-11-17 [vendor] Coinhouse
Vector: Withdrawal halt / insolvency

The French crypto broker Coinhouse announced that they would be suspending withdrawals from their crypto "savings account" product. Coinhouse partners with Genesis to offer the …

Other

Tweet by Coffeezilla

2022-11-15 [vendor] Salt
Vector: Withdrawal halt / insolvency

The crypto lending firm SALT announced that they would be halting withdrawals due to exposure to FTX. "I am sorry to report that the collapse of FTX has impacted our business," …

Other

Tweet by CZ

2022-11-14 [vendor] Binance announces industry recovery fund

CZ of Binance announced on Twitter that Binance would be forming an "industry recovery fund", which he says is intended for projects that are "otherwise strong, but in a liquidity …

Other

Tweet thread by Travis Kling

2022-11-14 [vendor] Ikigai Asset Management reveals FTX exposure

The founder and chief investment officer of the Californian crypto hedge fund Ikigai Asset Management wrote on Twitter, "Last week Ikigai was caught up in the FTX collapse. We had …

Other

Tweet by Wu Blockchain

2022-11-13 [vendor] Huobi reveals FTX exposure

Huobi announced to shareholders that they had $18.1 million in crypto assets on the FTX exchange, where they can't be withdrawn. They reported that approximately $13.2 million of …

Other

Tweet by cryptogle

2022-11-12 [vendor] Tokensoft intentionally publishes user data

Tokensoft is a project that aims to help web3 projects launch fairly, without the launches being gamed. The group evidently thought they had come across 5,000 or so users who had …

Other

Tweet by FTX

2022-11-11 [vendor] FTX [loss] $1.7B
Vector: Protocol collapse / insolvency

Aaaand there it goes.FTX announced that it had filed for Chapter 11 bankruptcy in the United States. Sam Bankman-Fried resigned as CEO.SBF had spoken about trying to raise …

Other

Tweet by BlockFi

2022-11-10 [vendor] BlockFi
Vector: Withdrawal halt / insolvency

BlockFi had a tough time this past June, floundering after substantial losses in the crypto downturn. They were bailed out by FTX, who extended them a $250 million loan, then …

Other

Media release

2022-11-10 [vendor] Securities Commission of the Bahamas freezes FTX assets
Vector: Protocol collapse / insolvency

The Securities Commission of the Bahamas (where FTX is headquartered) announced they had frozen the assets of FTX and "related parties" — presumably Alameda. They also disclosed …

Other

Tweet by Binance

2022-11-09 [vendor] Binance rescinds FTX bailout
Vector: Protocol collapse / insolvency

It's over as quickly as it started, and it started pretty dang quickly. Binance walked away from the non-binding letter of intent that Binance signed to acquire FTX, which doesn't …

Other

Tweet thread by Sam Bankman-Fried

2022-11-08 [vendor] Binance offers FTX bailout

Surprising just about everyone, FTX's Sam Bankman-Fried and Binance's Changpeng "CZ" Zhao announced suddenly that Binance had signed a "non-binding [letter of intent], intending to …

Other

Telegram message from Pavel Durov

2022-11-05 [vendor] Telegram repossesses usernames

In August, the popular messaging app Telegram started repossessing some desirable usernames that were already being used. Shortly afterwards, Telegram founder Pavel Durov explained …

Other

Tweet thread by Freeway

2022-10-23 [vendor] Freeway [loss] $160M
Vector: Withdrawal halt / insolvency

Freeway, a financial scheme where users buy "Superchargers", which are crypto "simulations" that promise to pay out rewards of up to 43% annually, seems to have taken the off-ramp. …

Other

In re: Voyager Digital Holdings, et al

2022-10-17 [vendor] Texas Securities investigators looking into FTX
Vector: Regulatory / legal action

Joseph Jason Rotunda, Director of the Enforcement Division of the Texas State Securities Board, submitted a filing to the ongoing Voyager bankruptcy case. FTX is the highest bidder …

Other

Tweets by Zcash Media

2022-10-05 [vendor] Zcash spam attack

Zcash is a privacycoin which, unlike popular blockchains like Bitcoin and Ethereum, allows users to obscure who they are sending money to and how much. Since June or July, the …

Other

FTX

2022-09-19 [vendor] UK FCA warns against FTX

The United Kingdom's Financial Conduct Authority issued a warning that FTX is not authorized by them, but is targeting consumers in the UK. "Almost all firms and individuals …

Other

Tweet thread by Brian Armstrong

2022-09-14 [vendor] Coinbase rolls out politics feature

When the "politics" were widespread civil unrest in the summer of 2020 triggered by the police murder of George Floyd, and pressure on the company to release a statement in support …

Other

Tweet by Stephanie Martin

2022-09-08 [vendor] Celsius Monopoly

After what USA Strong Head of Sales & Partnerships described as "months and months" of work, apparently the company had decided they had sunk too much effort into the …

Other

"Proposal To Upgrade To UAV V3"

2022-08-30 [vendor] Compound Finance cETH bug
Vector: Software bug / unintentional loss

Compound Finance released an update to change the price feed used by the Compound v2 protocol. Despite being audited by three firms, no one caught a bug that caused all …

Other

Tweet thread by zachxbt

2022-08-18 [vendor] Bribe Protocol [loss] $6M
Vector: On-chain theft (attributed by zachxbt)

The Bribe Protocol promised a DAO infrastructure tool where "token holders get paid to govern", and raised $5.5 million in funding in January to work on their extensive roadmap. …

Other

Etherscan address of "hacker"

2022-08-12 [vendor] Martin Shkreli [loss] $459,261
Vector: Exit scam / rug pull

I've almost got to give it to him. When I wrote up Druglike, Martin "Pharma Bro" Shkreli's new "web3" project for drug discovery, and asked him some questions in the project …

Other

Announcement

2022-08-11

Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …

Other

Announcement

2022-08-11 [vendor] Untamed Isles squanders Kickstarter funds on crypto

Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …

Other

Tweet thread by OpenSea

2022-08-10 [vendor] OpenSea requires police report to freeze NFTs

The dominant NFT platform, OpenSea, has changed its policy around NFTs that are reported as stolen. OpenSea now requires those who have reported an NFT as stolen to produce a …

Other

Specially Designated Nationals List Update

2022-08-08 [vendor] OFAC sanctions Tornado Cash
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The U.S. Office of Foreign Assets Control (OFAC) added Tornado Cash to its SDN list: a list of "Specially Designated Nationals And Blocked Persons" with whom U.S. individuals and …

Other

Tweet by zachxbt

2022-08-03 [vendor] News outlets publish wrong recovery address after Nomad
Vector: On-chain theft (attributed by zachxbt)

After the August 1 Nomad bridge exploit, Nomad created an address where people who took money out of the bridge could return it.However, that was not the address that CoinGape …

Other

Nomad Bridge Exploit ($190M Drained, 'Chaotic' Free-for-All)

2022-08-01 [vendor] Nomad cross-chain bridge
Vector: A routine smart contract upgrade introduced a misconfiguration in Nomad's Replica contract — setting the 'trusted root' to 0x00, causing the contract to accept any message as valid; once the initial exploit was noticed on-chain, hundreds of copycat exploiters joined to drain the remaining funds

On August 1, 2022, the Nomad cross-chain bridge was drained of approximately $190 million in a chaotic 'free-for-all' exploit. A recent routine upgrade had inadvertently set the …

Other

"CoinFLEX Update: July 29, 2022"

2022-07-29 [vendor] CoinFLEX layoffs
Vector: Protocol collapse / insolvency

CoinFLEX, a yield farming platform that stopped withdrawals in late June, announced they had made major staff cuts to reduce their cost base by 50–60%. "The intention is to remain …

Other

Tweet thread by Dan Olson

2022-07-27 [vendor] SpiceDAO wraps up

"DAO delusion was at its peak when the community went into this journey together", wrote SpiceDAO founder Soban "Soby" Saqib. SpiceDAO (named for the Dune drug) won an auction to …

Other

Tweet thread by Johnny Lyu

2022-07-26 [vendor] Yes, they have a

Those in the crypto ecosystem have long claimed to embrace the principles of censorship resistance and freedom of speech, but apparently some of them draw the line at speech that's …

Other

Celsius court docket

2022-07-22 [vendor] Celsius customers send letters to bankruptcy judge
Vector: Protocol collapse / insolvency

Celsius customers have begun to send letters to the judge presiding over Celsius Network's bankruptcy case in the Southern District of New York. More than fifty letters have been …

Other

"Minecraft and NFTs"

2022-07-20

Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …

Other

"Minecraft and NFTs"

2022-07-20 [vendor] Minecraft disallows NFTs

Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …

Other

Tweet by Betty Boop

2022-07-14 [vendor] Betty Boop NFT announcement
Vector: Ponzi / pyramid scheme

The studio behind Betty Boop decided there was no better time to launch a Betty Boop NFT collection than during a period of record low interest in NFTs (or, more likely, they …

Other

Rogers Communications Network Outage / Breach — 12 Million Canadians Disrupted

2022-07-08 [vendor] Rogers Communications network infrastructure
Vector: A network maintenance update to Rogers' IP routing policy distributed during a network upgrade caused a cascade failure across Rogers' core network; the failure was a configuration error rather than a cyberattack; the outage took down mobile, internet, and cable services for approximately 12 million Canadian customers

On 8 July 2022, Rogers Communications — Canada's largest telecommunications company serving approximately 12 million wireless customers — suffered a massive network outage that …

Other

Tweet thread by 0x_b1

2022-07-07 [vendor] Former Celsius asset manager accuses them of Ponzi scheme
Vector: Ponzi / pyramid scheme

Jason Stone, founder of the KeyFi company who formerly managed assets for Celsius, filed a complaint against Celsius Network in a New York court, alleging the company was operating …

Other

"Temporary change in withdrawal limits"

2022-07-04 [vendor] CoinLoin limits withdrawals
Vector: Withdrawal halt / insolvency

Claiming that they had no exposure to the various high profile collapses in the crypto industry lately, CoinLoan announced that they nevertheless would be reducing account …

Other

"Corporate statement"

2022-07-04 [vendor] Vauld
Vector: Withdrawal halt / insolvency

Vauld, a major cryptocurrency lender backed by the likes of Coinbase and Peter Thiel, announced they have suspended withdrawals, trading, and deposits due to the crypto market …

Other

Tweet by KenneyNL

2022-06-29 [vendor] w3itch.io steals website code and games

A somewhat blundering group of developers decided to create "w3itch.io", an online marketplace for game creators. The marketplace said it was intended to be friendly to games …

Other

"The Way Forward"

2022-06-24 [vendor] Bitpanda layoffs

The Austrian cryptocurrency exchange Bitpanda joined the recent litany of crypto companies laying off employees. In an announcement to staff, later shared publicly, the company …

Other

"Update on withdrawals"

2022-06-23 [vendor] CoinFLEX
Vector: Withdrawal halt / insolvency

Yield farming platform CoinFLEX is the latest crypto platform to stop allowing customers to withdraw their money. Customers had raised concerns about withdrawals not processing, …

Other

RFIA bill

2022-06-23 [vendor] Lummis and Gillibrand solicit feedback on bill via Github
Vector: Regulatory / legal action

After announcing their crypto-friendly proposed legislation earlier in June, Senators Lummis and Gillibrand have uploaded it to Github to solicit feedback, as was apparently widely …

Other

Tweet thread by Wu Blockchain

2022-06-20 [vendor] Bybit plans layoffs

Bybit, a Dubai-based cryptocurrency exchange, is reportedly joining the group of crypto companies laying off employees amidst plummeting cryptocurrency markets. Journalist Colin Wu …

Other

"Announcement of Withdrawl on Hoo"

2022-06-19 [vendor] Hoo
Vector: Withdrawal halt / insolvency

The Hong Kong-based cryptocurrency exchange Hoo announced that they would be pausing withdrawals, after so many customers tried to withdraw their crypto that they began to run out …

Other

Twitter thread by Danny 8BC

2022-06-15 [vendor] 8 Blocks Capital calls to freeze Three Arrows Capital funds

8 Blocks Capital is a Hong Kong-based trading firm. In a Twitter thread, Danny Yuan explained that 8BC had been using 3AC's trading accounts to reduce their trading fees. He wrote, …

Other

Twitter thread by Tim Connors

2022-06-14 [vendor] Merit DAO votes to renege on deal

Members of the Merit DAO, a DAO operating in the play-to-earn space, voted on proposals renege on a deal signed with an early investor to the DAO, Yield Guild Games (YGG). The …

Other

"A Memo to the Celsius Community"

2022-06-12 [vendor] Celsius
Vector: Withdrawal halt / insolvency

The Celsius platform announced that they would be pausing all withdrawals, swaps, and transfers due to "extreme market conditions".There has been a lot of concern lately about …

Other

"Tiger Incident Analysis"

2022-06-02 [vendor] Forest Tiger Pro [loss] $5M
Vector: Exit scam / rug pull

The TIGER project was supposed to be a DAO aiming to "support global technical teams" and protect wild animals and the environment. The project was broad-ranging, and had NFT, …

Other

Press release

2022-06-01 [vendor] OpenSea insider trader arrested
Vector: Regulatory / legal action

Nate Chastain was asked to resign from his position as Head of Product at OpenSea in September 2021 following allegations of NFT insider trading. Online sleuths had discovered that …

Other

HUMBL lawsuit

2022-05-20 [vendor] HUMBL class action
Vector: Regulatory / legal action

A litigation firm filed a class action lawsuit against HUMBL, a financial services company that touts its web3 and defi products. The lawsuit alleges that HUMBL and its executives …

Other

Coinbase 05/10/2022 Form 10-Q

2022-05-10 [vendor] Coinbase adds bankruptcy language to quarterly report

Coinbase added new language to its latest 10-Q, a quarterly report submitted by public companies to the SEC. In the section outlining risks to the business, Coinbase wrote: …

Other

Web3 Is Going Great

2022-05-04 [vendor] ape holders can use multiple slurp juices on a single ape

a lotta yall still dont get itape holders can use multiple slurp juices on a single apeso if you have 1 astro ape and 3 slurp juices you can create 3 new apesTonight's slurp juice …

Other

"NFT Sales Are Flatlining"

2022-05-03 [vendor] NFT sales down 92%

The Wall Street Journal reported that "the NFT market is collapsing", citing data from NonFungible that showed daily average sales of NFTs had dropped 92% from their September …

Other

Lifshitz Law Firm, P.C. Announces Investigations of Cassava Sciences, Inc. (NASDAQCM: SAVA), Coinbase Global, Inc. (NASDAQGS: COIN), HyreCar, Inc. (NASDAQCM: HYRE), and Longeveron Inc. (NASDAQCM: LGVN)

2022-04-13 [vendor] Coinbase class action lawsuit filed
Vector: Regulatory / legal action

A group of shareholders have filed a class-action lawsuit against Coinbase, alleging that the registration and prospectus statements provided for the company's IPO were false and …

Other

Tweet by Cobie

2022-04-12 [vendor] Coinbase insider trading

On April 11, Coinbase announced 50 new cryptocurrencies they were considering listing on their exchange. These announcements tend to increase the price of the tokens under …

Other

Tweet by Pierce Brown

2022-04-12 [vendor] Solar Society promotional art

"Don't make your dystopian books our reality, Pierce," a fan replied to sci-fi author Pierce Brown's announcement of an NFT project. Brown, the author of the bestselling Red Rising …

Other

Industroyer2 Ukraine Power Grid Attack — Sandworm (Detected and Blocked)

2022-04-08 [vendor] IEC 60870-5-104 SCADA; Ukrainian high-voltage substations [malware] Industroyer2; CaddyWiper; ORCSHRED; SOLOSHRED; AWFULSHRED
Vector: Sandworm (GRU Unit 74455) pre-positioned in Ukrainian energy sector network with undisclosed initial access vector (likely spearphishing or supply chain); deployed Industroyer2 IEC 60870-5-104 payload targeting high-voltage substations; simultaneously deployed five wiper variants (CaddyWiper, ORCSHRED, SOLOSHRED, AWFULSHRED) targeting Windows, Linux, and Solaris systems

On April 8, 2022 — during Russia's full-scale military invasion of Ukraine — Sandworm (GRU Unit 74455) attempted to deploy an upgraded version of Industroyer malware (dubbed …

Other

Web3 Is Going Great

2022-04-04 [vendor] Robert Malone speaking to trucker convoy

Robert W. Malone, a COVID-19 conspiracy theorist, gave a speech to a group of anti-vax truckers in which he announced plans to dox over 4,000 "[World Economic Forum] trainees" by …

Other

Tweet thread by Anton Nell

2022-03-06 [vendor] Andre Cronje and Anton Nell leave crypto

Andre Cronje and Anton Nell, the prolific developers of around 25 defi projects including yearn.fi and the new Solidly exchange, suddenly announced on Twitter that they would be …

Other

"WAGMI" video

2022-02-28 [vendor] Randi Zuckerberg music video

Apparently hoping to create the "rallying cry for the women of web3", Randi Zuckerberg released her second crypto-themed song "WAGMI", a parody of Twisted Sister's "We're Not Gonna …

Other

Tweet by Gavin Wood

2022-02-27 [vendor] Gavin Wood tries to use Ukraine invasion as marketing opportunity

On February 26, the Ukrainian government tweeted Bitcoin and Ethereum addresses, allowing cryptocurrency donations directly to the government to support their resistance to the …

Other

Tweet by ESETresearch

2022-02-26 [vendor] Scammers try to profit off Ukraine invasion

Cryptocurrency scammers have turned to the crisis in Ukraine to provide fodder for their scams. Some have taken the tactic of pretending to be a person trying to escape the country …

Other

Cyberattacks in Modern Armed Conflicts — Russia-Ukraine, Israel-Hamas, Taiwan Strait 2022-2026

2022-02-24 [vendor] Ukrainian government, financial, energy, and media infrastructure; Israeli government and critical infrastructure; civilian internet services globally [malware] HermeticWiper, WhisperGate, CaddyWiper, IsaacWiper, Sandworm AcidRain, Industroyer2, SolarWinds SUNBURST [cve] CVE-2022-24521
Vector: Coordination of destructive wiper malware, DDoS campaigns, information operations, and OT/ICS attacks by state-sponsored threat actors and hacktivist auxiliaries alongside conventional military operations; use of pre-positioned access (established months or years before conflict activation) against critical infrastructure

The 2022-2026 period fundamentally documented the integration of cyberattacks into modern armed conflicts as a standard component of military operations. Key documented cyber …

Other

Tweet thread by Brian Armstrong

2022-02-21 [vendor] Coinbase takes credit for ad

Coinbase CEO Brian Armstrong embarked on a 12-tweet-long thread congratulating Coinbase employees for coming up with the bouncing QR code Super Bowl ad. He wrote, "I guess if there …

Other

Tweet thread by zachxbt

2022-02-20 [vendor] Composable Finance exec unmasked as Omar Zaki
Vector: On-chain theft (attributed by zachxbt)

Composable Finance is a company that makes infrastructure tools for defi. Until recently, their head of product has been known only as 0xbrainjar, and has operated pseudonymously. …

Other

Tweet by Gary Vaynerchuk

2022-02-16 [vendor] Gary Vee calls out shadiness

Gary Vaynerchuk, an entrepreneur and now crypto/NFT personality, took to Twitter to express his frustration with some projects that airdrop their NFTs to big-name collectors and …

Other

"Taxman makes first ever seizure of NFTs"

2022-02-13 [vendor] British authorities seize NFTs in tax investigation
Vector: Regulatory / legal action

British tax authorities seized three NFTs in what they said was an attempt to dodge £1.4 million ($1.9M) in taxes. Officials stated that the seizure was a "warning to anyone who …

Other

Tweet by coloradotravis

2022-02-13 [vendor] Coinbase outage

People were apparently tempted by Coinbase's Super Bowl ad — which was just a QR code bouncing around the screen like the DVD screensaver — so much so that it took the Coinbase …

Other

"Exposing A Game Developer"

2022-02-11 [vendor] TitanReach alleged fund misappropriation [loss] $150,000

The "Runescape-like" MMO game known as TitanReach has had a bumpy history so far, first failing to reach its Kickstarter goal in a crowdfunding project launched in 2020, but …

Other

Tweet thread by duckrabbitblog

2022-02-08 [vendor] British Journal of Photography replaces Twitter account

The British Journal of Photography is a magazine and institution within the fine art and documentary photography world dating to 1854. In June 2021, they asked for investments, but …

Other

Tweet thread by NFTtheft

2022-02-07 [vendor] NFT Music Stream unauthorized marketplace

Following close on the heels of the disaster of an idea that was HitPiece, a new project called "NFT Music Stream" cropped up. Like HitPiece, the project appeared to be scraping …

Other

Tweet by SuperRare

2022-02-07 [vendor] SuperRare community manager controversy

The same week as bigoted tweets from an ENS director Brantly Millegan surfaced, so too did racist tweets by Ashni Christenson, then-community manager for the NFT platform …

Other

Tweet by boxbrown

2022-02-04 [vendor] Gumroad NFT controversy

Brian Box Brown, an artist who had previously worked for the digital self-publishing platform Gumroad, tweeted that he was ramping up his original art sales because "my former …

Other

Wormhole Bridge Exploit ($320M Stolen)

2022-02-02 [vendor] Wormhole cross-chain bridge (Solana/Ethereum)
Vector: Attacker exploited a signature verification vulnerability in Wormhole's Solana smart contract — a failure to properly validate 'guardian' program accounts allowed the attacker to spoof a valid signature and fraudulently mint 120,000 wETH (wrapped Ethereum) on Solana without depositing collateral

On February 2, 2022, the Wormhole cross-chain bridge — which facilitates token transfers between Solana, Ethereum, and other blockchains — suffered a smart contract exploit …

Other

Reddit thread on r/defi

2022-01-27 [vendor] Wonderland developer exposed as Michael Patryn
Vector: On-chain theft (attributed by zachxbt)

Sifu, the pseudonymous chief developer of the Wonderland protocol, was revealed to be Michael Patryn, previously known as Omar Dahani. Patryn was a co-founder of the Canadian …

Other

Tweet by PeckShieldAlert

2022-01-26 [vendor] Let's Go Brandon coin crashes

The "Let's Go Brandon" $LGB coin tied to NASCAR driver Brandon Brown, and created as an apparent way to support "the American dream" and stick it to Joe Biden (somehow), suddenly …

Other

Tweet by NFTtheft

2022-01-20 [vendor] McDonalds steals artwork

Shortly after rolling out their hexagonal NFT profile pictures, @twitter posted "gm, looking for an nft pfp". The next day, McDonald's German language communications account, …

Other

Instagram statement by MetaBirkins

2022-01-17 [vendor] MetaBirkins lawsuit
Vector: Regulatory / legal action

Mason Rothschild, the creator of "MetaBirkins" NFTs, was the target of a trademark lawsuit by Birkin bag-maker Hermès. The lawsuit came after he ignored a cease and desist from the …

Other

Tweet by Bojjisama_AoA

2022-01-15 [vendor] InvertedCulture and MadHashers

Shortly after it was discovered that the images used for the NFT project "InvertedCulture" were nothing more than unauthorized flipped copies from a different NFT project, DNA …

Other

Original tweet by @Mozilla

2022-01-06 [vendor] Original Mozilla tweet

Someone on the Mozilla Foundation's social team inexplicably thought that tweeting "Dabble in @dogecoin? HODLing some #Bitcoin & #Ethereum? We're using @BitPay to …

Other

Tweet thread by carsonturner

2022-01-01 [vendor] Carson Turner NFT loss [loss] $38,000
Vector: Software bug / unintentional loss

Carson Turner accused ACYCapital of "exploiting @BoredApeYC through a glitch in @rarible" after they bought his Bored Ape NFT that he had listed for sale (and which he has …

Other

Tweet by usdcoinprinter

2022-01-01 [vendor] Tether prints $1 billion

Shortly after midnight on January 1, Tether added another $1 billion to its total supply. Although Tether claims that all of its supply is fully backed by actual currency, many …

Other

Tweet thread by LiamRSharp

2021-12-17 [vendor] Artist may need to close online gallery

Comics artist Liam Sharp wrote on Twitter that he would likely need to close his DeviantArt gallery, which he has maintained for fourteen years, because his artwork keeps being …

Other

BitMart Exchange Hack — $196M Hot Wallet Theft

2021-12-04 [vendor] BitMart (cryptocurrency exchange, Cayman Islands)
Vector: Theft of private keys for two of BitMart's hot wallets — one on Ethereum and one on Binance Smart Chain; the exact method of key compromise was not publicly disclosed by BitMart

On December 4, 2021, security firm PeckShield identified large unauthorized outflows from BitMart's hot wallets totaling approximately $196 million — approximately $100 million …

Other

CISA / Apache Software Foundation / CrowdStrike

2021-12-01 [vendor] Apache Log4j 2 [malware] Conti (ransomware), various cryptominers, Orcus RAT [cve] CVE-2021-44228 +2
Vector: CWE-917: Improper Neutralization of Special Elements in Expression Language (JNDI injection in log4j)

Critical CVSS 10.0 RCE vulnerability in Apache Log4j 2 logging library. Publicly disclosed Dec 9 2021; patch released same day (2.15.0). Nation-state actors from China, Iran, North …

Other [SC]

BadgerDAO Frontend Exploit ($120M Stolen via Injected Approvals)

2021-11-10 [vendor] BadgerDAO (Bitcoin yield DeFi protocol); Cloudflare CDN
Vector: Attackers compromised the Cloudflare API key for BadgerDAO's frontend, injecting malicious JavaScript that prompted users to approve unlimited ERC-20 token transfers to attacker-controlled addresses when interacting with the BadgerDAO web application

BadgerDAO, a DeFi protocol allowing users to earn yield on Bitcoin via Ethereum-based vaults, suffered a frontend supply chain attack beginning approximately November 10, 2021, …

Other

Cream Finance DeFi Flash Loan Attack — $130M (Third Exploit)

2021-10-27 [vendor] Cream Finance (DeFi lending protocol, Ethereum)
Vector: Flash loan attack exploiting a price oracle manipulation vulnerability in Cream Finance's lending protocol; attackers used flash loans from multiple DeFi protocols to manipulate the price oracle for the yUSD token (a Yearn Finance vault token), inflating its reported collateral value and enabling the attacker to borrow far more than the actual collateral value across multiple transactions

On October 27, 2021, Cream Finance suffered its third exploit of the year (previous hacks in February 2021 for $37.5M and August 2021 for $18.8M). This third attack was the …

Other

Microsoft Exchange ProxyShell Zero-Days RCE — CVE-2021-34473, CVE-2021-34523, CVE-2021-31207

2021-08-13 [vendor] Microsoft Exchange Server (on-premises) [malware] LockFile ransomware, Babuk ransomware, web shells (various) [cve] CVE-2021-34473 +2
Vector: Multiple threat actors exploited three chained vulnerabilities in Microsoft Exchange Server (ProxyShell) after their technical details were demonstrated at Black Hat and DEF CON 2021; the chain allows unauthenticated remote code execution on Exchange servers by combining server-side request forgery, privilege escalation, and arbitrary file write

ProxyShell is a chain of three Microsoft Exchange Server vulnerabilities — CVE-2021-34473 (SSRF/ACL bypass), CVE-2021-34523 (privilege escalation), and CVE-2021-31207 (arbitrary …

Other

Poly Network DeFi Cross-Chain Exploit ($611M Stolen, Fully Returned)

2021-08-10 [vendor] Poly Network (cross-chain DeFi bridge)
Vector: Cryptographic vulnerability in Poly Network's cross-chain smart contract: attacker exploited the _executeCrossChainTx function's keeper role privilege escalation across Ethereum, Binance Smart Chain, and Polygon to override ownership of the protocol's fund management contract

On August 10, 2021, an attacker exploited a critical vulnerability in Poly Network's cross-chain interoperability protocol to steal approximately $611 million across three …

Other

Web3 Is Going Great

2021-08-04 [vendor] Uulala SEC settlement
Vector: Regulatory / legal action

The company Uulala, which aimed to provide underbanked individuals with opportunities to build credit, settled with the SEC over charges that they ran an unregistered ICO that …

Other

Tweet by Cory Doctorow

2021-07-20 [vendor] Norton Antivirus mines crypto

Norton, the makers of the popular Norton Antivirus software, started installing "Norton Crypto" on customers' machines when they install the popular Norton 360 antivirus and …

Other

CISA Advisory AA24-038A / Microsoft Security Blog

2021-06-01 [vendor] Cisco routers / Fortinet VPN / various SOHO network devices [cve] CVE-2021-40539 +1
Vector: CWE-77: Command Injection / exploitation of internet-facing SOHO routers and VPN devices to establish footholds

Chinese state-sponsored group Volt Typhoon (Bronze Silhouette) active since mid-2021, targeting US critical infrastructure sectors: communications, energy, transportation, …

Other

Uranium Finance DeFi BSC Exploit — $50 Million Stolen via Liquidity Migration Attack

2021-04-28 [vendor] Uranium Finance (Binance Smart Chain DeFi protocol) v2 liquidity migration contracts
Vector: Uranium Finance's v2 smart contracts contained a critical arithmetic error in the liquidity migration function; the attacker exploited the bug during the protocol's migration from v1 to v2, using flash loans to manipulate reserve balances and drain funds from liquidity pools; the exploit required only a small initial capital to trigger and was executed in a single transaction

On 28 April 2021, an attacker exploited a critical vulnerability in Uranium Finance — a decentralised exchange (DEX) and automated market maker (AMM) protocol built on Binance …

Other

Oldsmar Florida Water Treatment Plant — TeamViewer HMI Remote Access Attack

2021-02-05 [vendor] TeamViewer remote access software; water treatment SCADA/HMI
Vector: TeamViewer remote desktop software left installed and accessible on a water treatment plant HMI (Human Machine Interface) workstation; shared/weak credentials with no multi-factor authentication; attacker gained remote control of the operator's screen and mouse while the operator watched

On February 5, 2021, an unknown attacker gained remote access via TeamViewer to the HMI (Human Machine Interface) workstation of the City of Oldsmar, Florida's water treatment …

Other

Microsoft Security Blog / CISA AA21-062A / CSO Online

2021-01-03 [vendor] Microsoft Exchange Server (on-premises) [malware] China Chopper webshell / HAFNIUM custom tooling [cve] CVE-2021-26855 +3
Vector: CWE-918: Server-Side Request Forgery (SSRF auth bypass chained with post-auth arbitrary file write for webshell installation)

Chinese state-sponsored group HAFNIUM exploited four zero-days in on-premises Microsoft Exchange starting Jan 3 2021. CVE-2021-26855 (SSRF auth bypass) chained with CVE-2021-27065 …

Other

Harvest Finance Flash Loan Attack ($34M)

2020-10-26 [vendor] Harvest Finance (DeFi yield aggregator)
Vector: Attacker used a large flash loan to manipulate the USDC/USDT price in Curve Finance's Y pool, which Harvest Finance relied on for pricing; by temporarily moving the oracle price, the attacker could deposit and withdraw stablecoins at artificially favorable exchange rates, extracting value in repeated cycles

On October 26, 2020, Harvest Finance — a DeFi yield aggregator managing over $1 billion in assets — suffered a flash loan economic attack resulting in approximately $34 million in …

Other

KuCoin Exchange Hack — $281M Stolen, Attributed to Lazarus Group (DPRK)

2020-09-25 [vendor] KuCoin (Seychelles-based global cryptocurrency exchange)
Vector: Theft of private keys for KuCoin's hot wallets; the precise method of initial access was not disclosed, but the private keys for hot wallets holding Bitcoin, Ethereum, ERC-20 tokens, and other cryptocurrencies were compromised, enabling mass unauthorized withdrawals

On September 25, 2020, KuCoin detected large unauthorized outflows from its hot wallets across multiple blockchains including Bitcoin, Ethereum, Litecoin, XRP, Stellar, TRON, and …

Other

GEDmatch DNA Genealogy Database Breach — 1.45 Million Profiles Opted Into Law Enforcement

2020-07-19 [vendor] GEDmatch DNA genealogy database
Vector: An attacker compromised GEDmatch's database and changed the privacy settings of all 1.45 million user profiles from 'opt-out' to 'opt-in' for law enforcement searches; separately, a distributed denial-of-service (DDoS) attack was used to distract from the breach; the full details of the intrusion vector were not disclosed

On 19-20 July 2020, GEDmatch — a popular free genealogy DNA comparison service with approximately 1.45 million registered users — suffered a cyberattack that changed the privacy …

Other

Binance Bitcoin Exchange Hack — 7,000 BTC (~$40M)

2019-05-07 [vendor] Binance (world's largest cryptocurrency exchange by trading volume)
Vector: Coordinated attack combining phishing, viruses, and other techniques to steal API keys, two-factor authentication codes, and potentially other user information; attackers accumulated API keys and 2FA codes from a large number of Binance users over an extended period, then executed the withdrawal in a single large transaction that bypassed Binance's automated risk management systems by exploiting the user-level API permissions

On May 7, 2019, Binance CEO Changpeng Zhao (CZ) announced that hackers had stolen 7,000 BTC (worth approximately $40 million) from the exchange's hot wallet in a single large …

Other

Cosmos Bank India ATM Cashout ($13.5M, Proxy Switch, 28 Countries)

2018-08-11 [vendor] Bank ATM payment switch server
Vector: Attackers pre-positioned malware on Cosmos Bank's ATM payment switch infrastructure (the server that approves/declines ATM transactions); the malware created a fraudulent proxy switch that intercepted card authorization requests and returned approvals for compromised cloned cards, bypassing the legitimate Visa/RuPay networks

On August 11 and 13, 2018, Cosmos Co-operative Bank Ltd. of Pune, India — one of India's oldest cooperative banks — suffered a sophisticated two-weekend ATM cashout operation …

Other

Banco de Chile SWIFT Heist + Wiper Distraction ($10M, Lazarus)

2018-05-24 [vendor] SWIFT financial messaging; bank endpoint workstations [malware] KillMBR wiper (custom variant); SWIFT transaction injector
Vector: Lazarus Group-affiliated attackers gained access to Banco de Chile's internal network; deployed a custom MBR (Master Boot Record) wiping malware across ~9,000 workstations and 500 servers as a distraction; while IT teams responded to the destructive attack, attackers simultaneously submitted fraudulent SWIFT transfer instructions

On May 24, 2018, Banco de Chile — Chile's largest bank — suffered a sophisticated coordinated attack combining a destructive cyber operation with financial fraud. Attackers …

Other

NiceHash Cryptocurrency Mining Marketplace Hack — ~4,736 BTC (~$64M)

2017-12-06 [vendor] NiceHash (Slovenian cryptocurrency mining marketplace)
Vector: Social engineering of a NiceHash employee; attackers obtained the employee's credentials (likely via spearphishing), used them to access NiceHash internal systems, and ultimately gained access to the payment system's Bitcoin wallet private keys, draining the entire contents of the company's payment wallet in a single transaction

On December 6, 2017, NiceHash — a platform where users sell their computing power for cryptocurrency mining — halted operations after discovering that its internal payment system …

Other

TRITON/TRISIS Malware: First Attack Targeting Industrial Safety Systems (Saudi Aramco Petrochemical)

2017-06-01 [vendor] Schneider Electric Triconex Safety Instrumented System (SIS) [malware] TRITON (TRISIS, HatMan)
Vector: Russian state-sponsored actors (attributed to the Central Scientific Research Institute of Chemistry and Mechanics / CNIIHM, Moscow) gained IT network access via spear-phishing, pivoted to the OT network, then developed a zero-day exploit targeting Schneider Electric Triconex Safety Instrumented System (SIS) controllers

TRITON (also known as TRISIS and HatMan) is the world's first known malware specifically designed to attack industrial Safety Instrumented Systems (SIS) — the last line of …

Other

French Presidential Campaign (En Marche! / Macron) Hack — APT28, #MacronLeaks

2017-01-01 [vendor] En Marche! presidential campaign (Emmanuel Macron, France)
Vector: APT28 (GRU / Fancy Bear) spearphishing targeting En Marche! campaign staff with credential-harvesting domains mimicking the campaign's email infrastructure; phishing domains registered beginning in March 2017

In the final hours before France's legally mandated media blackout ahead of the May 7, 2017 presidential election runoff, approximately 9GB of documents and emails allegedly stolen …

Other

Industroyer/CrashOverride: Ukraine Power Grid Attack (Kyiv Blackout, Sandworm)

2016-12-17 [vendor] IEC 60870-5-101/104 SCADA; Siemens SIPROTEC relays (CVE-2015-5374) [malware] Industroyer (CrashOverride); KillDisk
Vector: Sandworm (GRU Unit 74455) deployed Industroyer malware that natively spoke industrial communication protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) to directly communicate with and manipulate power grid SCADA/ICS equipment without requiring attackers to understand specific OT configurations

On December 17, 2016, exactly one year after the first Ukraine power grid attack (BlackEnergy 2015), Russian military intelligence (GRU Sandworm team) deployed Industroyer against …

Other

Shadow Brokers NSA Exploit Leak (EternalBlue → WannaCry/NotPetya)

2016-08-13 [vendor] NSA Tailored Access Operations (TAO) toolset [malware] EternalBlue; EternalRomance; FUZZBUNCH; DoublePulsar; DanderSpritz [cve] CVE-2017-0144 +1
Vector: A group calling themselves 'The Shadow Brokers' claimed to have stolen cyberweapons from the NSA's Tailored Access Operations (TAO) unit; released NSA exploit tools in staged leaks from August 2016 through April 2017; method of original exfiltration from NSA never officially confirmed

Between August 2016 and April 2017, a group known as 'The Shadow Brokers' released staged leaks of what they claimed were NSA cyberweapon repositories stolen from the NSA's elite …

Other [SC]

Bitfinex Bitcoin Exchange Hack — 119,756 BTC (~$72M)

2016-08-02 [vendor] Bitfinex (Hong Kong-based cryptocurrency exchange, iFinex Inc.); BitGo (multi-signature wallet co-signer)
Vector: Attackers compromised BitGo's multi-signature co-signing service integrated with Bitfinex's wallet infrastructure; the exact initial access vector was never fully disclosed, but the attack involved manipulating Bitfinex's API to authorize fraudulent withdrawal transactions that BitGo's servers co-signed without detecting the anomaly

On August 2, 2016, Bitfinex — at the time the world's largest USD-denominated Bitcoin exchange — announced that 119,756 BTC had been stolen from customer accounts, worth …

Other

DNC / Podesta Email Hack — APT28/GRU, Russian Election Interference 2016

2016-03-19 [vendor] Democratic National Committee (DNC) IT infrastructure; Hillary Clinton Campaign Chair John Podesta's Gmail [malware] X-Agent (Sofacy) keylogger/credential harvester; X-Tunnel network tunneling tool; Mimikatz credential dumper
Vector: APT28 (GRU Unit 26165 / Fancy Bear) spearphishing via Google OAuth credential-harvesting pages; John Podesta clicked a link in a fake Google security alert email on March 19, 2016; DNC compromise involved separate APT28 intrusion beginning in approximately March 2016 alongside APT29 (Cozy Bear) intrusion from mid-2015

In 2016, two separate Russian GRU units conducted coordinated cyber intrusions against the Democratic Party and Clinton presidential campaign. APT29 (GRU Unit 29155 / Cozy Bear) …

Other

Bangladesh Bank SWIFT Heist ($81M Stolen via SWIFT Messaging, Lazarus Group)

2016-02-04 [vendor] SWIFT Alliance Access messaging software [malware] EVTDIAG; MSOUTC; MSOUTC (SWIFT-specific malware suite)
Vector: Lazarus Group (DPRK) spearphishing targeted Bangladesh Bank employees; malware installed on bank's internal network gained access to the SWIFT Alliance Access software and credentials; attackers monitored bank operations for months before submitting fraudulent SWIFT transfer instructions

On the night of February 4–5, 2016, Lazarus Group (North Korean state-sponsored hackers) submitted 35 fraudulent SWIFT transfer instructions from Bangladesh Bank's account at the …

Other

Bangladesh Bank SWIFT Heist — $81 Million Stolen via Fraudulent SWIFT Messages

2016-02-04 [vendor] Bangladesh Bank SWIFT terminal / SWIFT Alliance Access software [malware] EVTDIAG, MSOUTC, MSOUTC (Lazarus custom malware)
Vector: North Korean Lazarus Group gained access to Bangladesh Bank's SWIFT messaging terminals by compromising workstations at the bank using malware introduced via a malicious PDF; the attackers installed malware that modified SWIFT software to forge outgoing payment messages and delete evidence of the fraudulent transfers

In February 2016, North Korea's Lazarus Group executed the most audacious central bank heist in history by compromising Bangladesh Bank's SWIFT messaging system and fraudulently …

Other

FASTCash ATM Cashout Operations — DPRK Lazarus BeagleBoyz ($100M+, 30+ Banks)

2016-01-01 [vendor] IBM AIX payment switch servers; bank ATM networks [malware] FASTCash implant (AIX trojan)
Vector: Spearphishing targeting bank employees for initial access; lateral movement to payment switch application servers running IBM AIX; deployment of custom AIX malware that intercepted ATM transaction approval requests and returned fraudulent approvals for compromised cards even with zero balances; pre-positioned mule networks executed simultaneous global ATM withdrawals

FASTCash was a multi-year North Korean state-sponsored campaign (2016–ongoing) targeting bank payment switch servers — the AIX-based systems that approve or decline ATM …

Other

BlackEnergy/KillDisk: First Cyberattack Causing a Power Outage (Ukraine, Sandworm)

2015-12-23 [vendor] Microsoft Office (macro); ICS SCADA systems [malware] BlackEnergy3; KillDisk
Vector: Sandworm (GRU) sent spear-phishing emails with malicious Microsoft Word documents containing BlackEnergy3 macros to Ukrainian energy company employees; gaining access to IT networks before pivoting to SCADA systems; operators were locked out via KillDisk wiping workstations while attackers opened breakers via VPN

On December 23, 2015, coordinated cyberattacks against three Ukrainian electricity distribution companies — Prykarpattyaoblenergo, Chernivtsioblenergo, and Kyivoblenergo — caused …

Other

Bundestag (German Parliament) APT28 Hack — 16GB Data, Full Network Rebuild

2015-04-01
Vector: APT28 (Fancy Bear / GRU Unit 26165) spearphishing emails delivering trojanized links to Bundestag employees; malware installation enabled keylogging and credential harvesting; attackers then moved laterally across the 20,000-node parliamentary IT network for several weeks

Between approximately April and May 2015, Russian military intelligence (GRU) APT28 (Fancy Bear) conducted a sophisticated intrusion into the German Federal Parliament (Bundestag) …

Other

U.S. CENTCOM Twitter and YouTube Account Hijack by ISIS Sympathizers

2015-01-12 [vendor] Twitter, YouTube (Google)
Vector: Social media account compromise — attackers claiming affiliation with ISIS obtained credentials for the official U.S. Central Command (CENTCOM) Twitter and YouTube accounts, likely via phishing or credential reuse, and posted propaganda

On January 12, 2015, individuals calling themselves 'CyberCaliphate' and claiming affiliation with the Islamic State (ISIS) hijacked the official Twitter and YouTube accounts of …

Other

TV5Monde Broadcast Disruption — APT28 False-Flag Operation (CyberCaliphate)

2015-01-01 [vendor] TV broadcast encoding hardware; social media accounts
Vector: APT28 (Sandworm / GRU) spearphishing targeting TV5Monde employees beginning approximately January 2015; credential theft and lateral movement over approximately 3 months; pre-positioned access to broadcast encoding infrastructure; coordinated simultaneous attack on broadcast systems and social media accounts

On April 9, 2015, TV5Monde — France's international television network broadcasting to 200 million people in 160 countries — had all 11 of its TV channels knocked off the air …

Other

Sony Pictures Hack: Lazarus Group Wiper + Data Exfiltration

2014-11-24 [malware] Destover (wiper/backdoor)
Vector: North Korea's Lazarus Group (Bureau 121) used spear-phishing to gain initial access to Sony Pictures' network, conducted months of reconnaissance, then deployed 'Destover' destructive malware (wiper) while simultaneously exfiltrating terabytes of data

On November 24, 2014, attackers identifying themselves as 'Guardians of Peace' (GOP) deployed the Destover destructive wiper malware across Sony Pictures' corporate network, wiping …

Other

Heartbleed OpenSSL Vulnerability — Mass Exploitation of CVE-2014-0160

2014-04-07 [vendor] OpenSSL 1.0.1 through 1.0.1f (used by approximately 17% of all HTTPS web servers) [cve] CVE-2014-0160
Vector: Critical buffer over-read vulnerability in OpenSSL's TLS heartbeat extension (RFC 6520) allowed remote unauthenticated attackers to read up to 64KB of memory per request from vulnerable servers, potentially exposing private keys, session tokens, and plaintext credentials

CVE-2014-0160 (Heartbleed) was a critical vulnerability in OpenSSL's TLS/DTLS heartbeat extension, introduced in OpenSSL 1.0.1 (released March 2012) and present in all versions …

Other [SC]

US Senate Commerce Committee / BreachSense / Huntress

2013-11-15 [vendor] Target Corporation POS systems [malware] BlackPOS / Kaptoxa
Vector: CWE-1104: Use of Unmaintained Third-Party Components (phishing of HVAC vendor Fazio Mechanical for network credentials, then lateral movement to POS environment)

Attackers phished Fazio Mechanical (HVAC vendor) to steal Target network credentials in Nov 2013. Moved laterally from vendor-accessible HVAC network segment to POS environment due …

Other

Mt. Gox Bitcoin Exchange Collapse — 850,000 BTC Lost (Hack + Insolvency)

2011-09-01 [vendor] Mt. Gox (bitcoin exchange, Tokyo, operated by Tibanne Ltd., CEO Mark Karpelès)
Vector: Multiple attack vectors over multiple years: (1) 2011 auditor laptop compromise allowed private key theft and price manipulation; (2) ongoing transaction malleability exploitation allowed attackers to claim non-received Bitcoin withdrawals were unprocessed and have them re-sent; (3) internal control failures and alleged insider theft; Mt. Gox repeatedly processed duplicate withdrawal requests due to mishandling of Bitcoin transaction IDs

Mt. Gox was once the world's largest Bitcoin exchange, handling over 70% of global BTC transactions at its peak. On February 7, 2014, Mt. Gox suspended all Bitcoin withdrawals …

Other

RSA SecurID Seed Value Theft (40M Tokens Compromised)

2011-03-01 [vendor] RSA SecurID (two-factor authentication tokens); Adobe Flash [cve] CVE-2011-0609
Vector: Spear-phishing email with an Excel spreadsheet exploiting an Adobe Flash zero-day (CVE-2011-0609) was opened by an RSA employee; the embedded malware installed a backdoor enabling attackers to extract the SecurID token seed database

In March 2011, RSA Security (division of EMC) suffered a breach when a spear-phishing email titled '2011 Recruitment Plan' was opened by an employee. The Excel attachment exploited …

Other

Operation Aurora — Chinese APT Nation-State Espionage (Google, Adobe, 30+ Companies)

2009-06-01 [vendor] Microsoft Internet Explorer 6/7/8 [malware] Hydraq (Aurora backdoor) [cve] CVE-2010-0249
Vector: Spear-phishing emails delivering a zero-day exploit for Internet Explorer (CVE-2010-0249, a use-after-free vulnerability in IE 6/7/8); watering hole attacks; lateral movement and data exfiltration once initial foothold established

Operation Aurora was a sophisticated, coordinated nation-state cyber espionage campaign originating in China and targeting at least 30 major corporations, with Google being the …

Other

Stuxnet / Operation Olympic Games — First Cyberweapon, Iran Natanz Centrifuges

2009-06-01 [vendor] Siemens Step7 SCADA; Siemens S7-300/S7-400 PLCs; Microsoft Windows [malware] Stuxnet [cve] CVE-2010-2568 +2
Vector: USB drive air-gap bypass for initial delivery into the isolated Natanz network; exploited four Windows zero-day vulnerabilities (CVE-2010-2568, CVE-2010-2772, CVE-2010-2729, CVE-2010-2568 LNK file); targeted Siemens Step7 SCADA software and Siemens S7-315/S7-417 PLCs; manipulated centrifuge rotor speeds while forging normal readings to SCADA operators

Stuxnet is the first publicly known cyberweapon designed to cause physical destruction of industrial equipment. Jointly developed by the United States (NSA, CIA — under 'Operation …

Other

Samy Worm — First Self-Replicating XSS Worm (MySpace, 1M Infected in 20 Hours)

2005-10-04 [vendor] MySpace social network [malware] Samy worm (JavaScript XSS worm)
Vector: Reflected/stored cross-site scripting (XSS) vulnerability in MySpace user profiles exploited by a self-replicating JavaScript payload; the worm ran in any visitor's browser when they viewed an infected profile, automatically added the author as a friend, replicated itself to the visitor's own profile, and spread exponentially

On October 4, 2005, security researcher Samy Kamkar launched the Samy worm — the first self-replicating cross-site scripting (XSS) worm in history. The worm exploited an XSS …

Other

Samy Worm — MySpace XSS Self-Propagating Worm (1 Million Infected in 20 Hours)

2005-10-04 [vendor] MySpace social network [malware] Samy worm (JS/Samy)
Vector: Stored cross-site scripting (XSS) — the worm exploited a flaw in MySpace's profile page rendering that allowed JavaScript injection despite MySpace's attempted input sanitization; the author used CSS style attributes to smuggle JavaScript that MySpace's filters failed to strip

On October 4, 2005, Samy Kamkar released a self-propagating JavaScript worm on MySpace, the then-dominant social network. The worm exploited a stored XSS vulnerability in MySpace …

Other

Zotob Worm — Windows 2000 MS05-039 Exploit (CNN, NYT, DHS Disrupted)

2005-08-13 [vendor] Microsoft Windows 2000 Plug and Play service [malware] Zotob (IRCBot variant) [cve] CVE-2005-1983
Vector: Exploitation of MS05-039 (CVE-2005-1983), a critical buffer overflow vulnerability in the Windows Plug and Play service affecting Windows 2000 systems; the worm propagated automatically via TCP port 445 without requiring user interaction, exploiting unpatched systems within 4 days of the security patch release

The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 security patch for a critical Plug and Play buffer overflow vulnerability in …

Other

Zotob Worm — Windows 2000 Plug and Play Exploit (CNN, NYT, DHS Disrupted)

2005-08-13 [vendor] Microsoft Windows 2000 [malware] Zotob (W32/Zotob, also Tpbot, Esbot, Rbot variants) [cve] CVE-2005-1983
Vector: Remote code execution exploit (MS05-039) against the Windows Plug and Play service on unpatched Windows 2000 systems; the worm appeared within days of Microsoft's August 9, 2005 Patch Tuesday release, exploiting the vulnerability before most organizations could patch

The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 patch for a critical Plug and Play buffer overflow vulnerability in Windows 2000. …

Other

MyDoom Email Worm (Fastest-Spreading Ever, $38B Damages)

2004-01-26 [vendor] Microsoft Windows [malware] MyDoom (W32/Mydoom, Novarg, Mimail.R)
Vector: Email attachment with social engineering lures (fake mail delivery failure notices, rejected email messages); also spread via Kazaa P2P shared folders; installed a backdoor on TCP port 3127 for spam relay and DDoS

MyDoom, discovered on January 26, 2004, remains the fastest-spreading email worm in recorded history — a record unbroken as of 2026. Within the first 36 hours, MyDoom was …

Other

SQL Slammer Worm (75K Hosts in 10 Minutes, Global Internet Disruption)

2003-01-25 [vendor] Microsoft SQL Server 2000; Microsoft MSDE 2000 [malware] SQL Slammer (W32/SQLSlam, Sapphire) [cve] CVE-2002-0649
Vector: Single-packet UDP buffer overflow (376 bytes total) against Microsoft SQL Server 2000 and MSDE 2000 (MS02-039); patch available 6 months prior; worm fit entirely in one UDP packet and required no TCP handshake, enabling maximum propagation speed

SQL Slammer, also known as Sapphire, is the fastest-spreading computer worm in recorded history. Launched at 05:30 UTC on January 25, 2003, the 376-byte worm doubled the number of …

Other

Nimda Multi-Vector Worm (Five Propagation Methods, Most Widespread in 22 Minutes)

2001-09-18 [vendor] Microsoft IIS; Microsoft Outlook; Microsoft Internet Explorer [malware] Nimda (W32/Nimda, 'admin' reversed) [cve] CVE-2001-0333 +1
Vector: Five simultaneous propagation vectors: (1) email attachment exploit; (2) infected IIS web servers serving malicious JavaScript to visitors; (3) open network shares; (4) IIS 4.0/5.0 directory traversal (Unicode/double decode vulnerabilities); (5) backdoors installed by Code Red II

Nimda (released exactly one week after the September 11 attacks) became the most widespread internet virus in history within 22 minutes of release, surpassing Code Red. Its five …

Other

Code Red IIS Buffer Overflow Worm (359K Hosts, $2.6B Damages)

2001-07-13 [vendor] Microsoft IIS (Internet Information Services) [malware] Code Red (W32/CodeRed) [cve] CVE-2001-0500
Vector: Buffer overflow vulnerability in Microsoft IIS 4.0/5.0 Index Server (MS01-033 / CVE-2001-0500); patch available one month prior; worm propagated by scanning random IP addresses and exploiting unpatched IIS servers with no user interaction

Code Red exploited a buffer overflow in the IDQ.DLL component of Microsoft IIS web server software (documented in MS01-033). The worm required no user interaction — it scanned …

Other

ILOVEYOU / Love Bug VBScript Worm (45M Computers, $10–15B Damages)

2000-05-04 [vendor] Microsoft Windows Script Host; Microsoft Outlook [malware] ILOVEYOU (VBS/LoveLetter)
Vector: Email with subject 'ILOVEYOU' and attachment 'LOVE-LETTER-FOR-YOU.TXT.vbs'; VBScript executed automatically via Windows Script Host, overwrote files, propagated via Outlook to entire address book, and downloaded a password-stealing Trojan

On May 4-5, 2000, the ILOVEYOU worm began spreading from the Philippines, where computer science student Onel de Guzman had released it via a stolen internet access account. The …

Other

Melissa Virus Email Macro Worm ($80M Damages)

1999-03-26 [vendor] Microsoft Word (macro); Microsoft Outlook [malware] Melissa (W97M/Melissa)
Vector: Word document macro virus emailed as attachment with 'Important Message From [sender]' subject; the VBA macro auto-forwarded itself to the first 50 addresses in the victim's Outlook address book and defaced documents with Simpsons references

On March 26, 1999, David Lee Smith of Aberdeen, New Jersey posted the Melissa macro virus to the alt.sex Usenet newsgroup using a stolen AOL account. The virus was embedded in a …