<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>the daily grind — Security &amp; Hacks</title><description>Exploits, audits, bridge attacks, key compromises, and post-mortems. The state of crypto security and the auditors trying to keep up.</description><link>https://news.cryptogrind.com/</link><language>en-us</language><item><title>A Hacker &apos;Stole&apos; $76M in Bitcoin Today. The Actual Damage? $816K.</title><link>https://news.cryptogrind.com/blog/echo-protocol-76m-ebtc-monad-admin-key-exploit/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/echo-protocol-76m-ebtc-monad-admin-key-exploit/</guid><description>Echo Protocol on Monad was exploited via a compromised admin key — minting 1,000 fake eBTC worth $76.7M. The attacker could only cash out $816K before the team burned the rest. Here&apos;s what actually happened.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>defi</category><category>btcfi</category><category>monad</category><category>exploit</category></item><item><title>Hackers Hit THORChain on 4 Blockchains at Once — $10.8M Gone, Trading Halted, No One Knows How</title><link>https://news.cryptogrind.com/blog/thorchain-10m-exploit-four-chains-rune-halted/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/thorchain-10m-exploit-four-chains-rune-halted/</guid><description>THORChain was drained across Bitcoin, Ethereum, BNB Chain, and Base simultaneously on May 15. RUNE dropped 12%, all trading and signing was halted, and the team still hasn&apos;t explained the attack vector.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>defi</category><category>exploit</category><category>security</category><category>thorchain</category><category>hack</category><category>breaking-news</category></item><item><title>Blind Signing Has Drained Crypto of Billions. Ethereum Just Launched the Kill Switch.</title><link>https://news.cryptogrind.com/blog/ethereum-clear-signing-erc-7730-blind-signing-bybit/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/ethereum-clear-signing-erc-7730-blind-signing-bybit/</guid><description>The Ethereum Foundation, Ledger, MetaMask, Trezor, Fireblocks and WalletConnect just launched Clear Signing — an open standard that replaces the hex garbage users blindly approve with human-readable transaction descriptions. Bybit&apos;s $1.5B hack started with a blind signing. So did most of yours.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>ethereum</category><category>security</category><category>defi</category><category>breaking-news</category><category>wallets</category><category>erc-7730</category></item><item><title>For 18 Months, Any Miner Could Have Crashed Bitcoin&apos;s Network. 43% of Nodes Still Haven&apos;t Patched.</title><link>https://news.cryptogrind.com/blog/bitcoin-core-cve-2024-52911-43-percent-nodes-vulnerable/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/bitcoin-core-cve-2024-52911-43-percent-nodes-vulnerable/</guid><description>Bitcoin Core quietly patched its first-ever memory safety bug in late 2024, disguising the fix as a logging improvement. The vulnerability — now public — let miners remotely crash nodes running versions 0.14.0 through 28.x. Nearly half the network is still exposed.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>bitcoin</category><category>security</category><category>bitcoin-core</category><category>infrastructure</category><category>jobs</category></item><item><title>Someone Sent Grok a Morse Code Tweet — Then Walked Away With $175K in Crypto</title><link>https://news.cryptogrind.com/blog/grok-morse-code-200k-ai-agent-hack/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/grok-morse-code-200k-ai-agent-hack/</guid><description>A single obfuscated tweet tricked xAI&apos;s Grok into executing a $175K on-chain transfer — no private keys stolen, no smart contract exploit. Just a chatbot doing what it was told.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>ai-agents</category><category>defi</category><category>web3</category><category>hacks</category></item><item><title>500 Ethereum Wallets That Hadn&apos;t Moved in 8 Years Were Just Drained — And Nobody Knows How</title><link>https://news.cryptogrind.com/blog/dormant-ethereum-wallets-drained-coordinated-attack/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/dormant-ethereum-wallets-drained-coordinated-attack/</guid><description>A coordinated attacker swept over 500 long-dormant Ethereum addresses, stealing ~$800K and routing funds through ThorChain. The compromise vector is still unknown — and your old wallets may not be safe.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>ethereum</category><category>security</category><category>defi</category><category>hacks</category></item><item><title>Is North Korea Running an AI That Automatically Hacks DeFi? April&apos;s $625M Record Says the Theory Isn&apos;t Crazy</title><link>https://news.cryptogrind.com/blog/north-korea-ai-defi-hacker-april-625m-record/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/north-korea-ai-defi-hacker-april-625m-record/</guid><description>April 2026 was the worst month in crypto hack history: 30 attacks, $625M drained, North Korea behind 76% of it. Now a developer is claiming DPRK trained an AI to autonomously exploit DeFi — and the Wasabi Protocol&apos;s $5M multi-chain drain may be its latest hit.</description><pubDate>Fri, 01 May 2026 09:00:00 GMT</pubDate><category>breaking-news</category><category>hack</category><category>defi</category><category>north-korea</category><category>security</category><category>wasabi-protocol</category></item><item><title>Ethereum&apos;s Biggest Rivals Just Pooled $300M to Bail Out a North Korean Hack — and It Might Actually Work</title><link>https://news.cryptogrind.com/blog/defi-united-300m-aave-rseth-rescue-kelpdao/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/defi-united-300m-aave-rseth-rescue-kelpdao/</guid><description>DeFi United drops its technical rescue blueprint today, with Consensys, Aave, Compound, the Solana Foundation and 14 other protocols pledging $300M+ in ETH to re-collateralize rsETH after the $292M Lazarus-linked KelpDAO exploit. This is the most coordinated cross-protocol rescue in DeFi history.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>security</category><category>aave</category><category>ethereum</category><category>north-korea</category><category>lazarus</category></item><item><title>Litecoin Just Erased 3 Hours of Its Own Blockchain History — Then Lied About Why</title><link>https://news.cryptogrind.com/blog/litecoin-zero-day-mweb-13-block-reorg/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/litecoin-zero-day-mweb-13-block-reorg/</guid><description>A zero-day exploit in Litecoin&apos;s MimbleWimble privacy layer triggered a 13-block chain reorg, wiping three hours of transactions. Litecoin denied it was a zero-day. GitHub commits say otherwise.</description><pubDate>Sun, 26 Apr 2026 10:00:00 GMT</pubDate><category>breaking-news</category><category>litecoin</category><category>hack</category><category>exploit</category><category>security</category><category>mweb</category><category>defi</category></item><item><title>North Korea Just Sent Your CEO a Fake Zoom Invite — Then Drained Their Crypto Wallet</title><link>https://news.cryptogrind.com/blog/lazarus-mach-o-man-macos-crypto-executives/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/lazarus-mach-o-man-macos-crypto-executives/</guid><description>Lazarus Group&apos;s new &apos;Mach-O Man&apos; macOS malware is targeting crypto and fintech executives with convincing fake meeting invites, stealing keychain data and wallet credentials before erasing itself completely.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>north-korea</category><category>lazarus-group</category><category>hacks</category><category>macos</category><category>social-engineering</category></item><item><title>DeFi Lost More in 18 Days Than All of Q1 — And Congress Just Called an Emergency Hearing</title><link>https://news.cryptogrind.com/blog/april-defi-bloodbath-606m-18-days-congress-hearing/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/april-defi-bloodbath-606m-18-days-congress-hearing/</guid><description>April 2026 is already the worst month for crypto hacks since February 2025. $606 million gone in 18 days. 3.7x the entire first quarter. Today, Congress is holding hearings. Here&apos;s what broke.</description><pubDate>Tue, 21 Apr 2026 08:00:00 GMT</pubDate><category>defi</category><category>security</category><category>hacks</category><category>regulation</category><category>breaking-news</category><category>lazarus-group</category></item><item><title>An AI Tool No One Audited Just Cracked Open Crypto&apos;s Entire Frontend Layer</title><link>https://news.cryptogrind.com/blog/vercel-breach-crypto-frontend-context-ai/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/vercel-breach-crypto-frontend-context-ai/</guid><description>Hackers breached Vercel — the hosting backbone for thousands of DeFi apps — by exploiting a compromised third-party AI platform. API keys, tokens, and source code are on sale for $2M on BreachForums.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>defi</category><category>web3</category><category>infrastructure</category><category>hacks</category></item><item><title>Someone Forged a Single Message and Walked Away With $292 Million of Restaked ETH</title><link>https://news.cryptogrind.com/blog/kelp-dao-rseth-292m-layerzero-bridge-exploit/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/kelp-dao-rseth-292m-layerzero-bridge-exploit/</guid><description>Kelp DAO&apos;s rsETH bridge was drained in minutes after an attacker forged LayerZero cross-chain messages. Bad debt cascaded across Aave, Compound, and Euler. It&apos;s 2026&apos;s biggest DeFi hack — so far.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>hack</category><category>defi</category><category>layerzero</category><category>aave</category><category>restaking</category><category>security</category><category>jobs</category></item><item><title>The Secret Service Mapped 20,000 Crypto Scam Victims — And Your Wallet Might Be on the List</title><link>https://news.cryptogrind.com/blog/operation-atlantic-secret-service-crypto-approval-phishing/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/operation-atlantic-secret-service-crypto-approval-phishing/</guid><description>Operation Atlantic, a joint US-UK-Canada law enforcement strike, froze $12M and traced $45M in crypto approval phishing fraud across 30+ countries. Here&apos;s what that means for the industry.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>enforcement</category><category>security</category><category>regulation</category><category>defi</category></item><item><title>France Is Having a Crypto Kidnapping Every 2.5 Days — and the Government Is Finally Cracking Down</title><link>https://news.cryptogrind.com/blog/france-crypto-kidnapping-one-every-2-5-days/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/france-crypto-kidnapping-one-every-2-5-days/</guid><description>41 violent crypto kidnappings in 2026. France now has the worst crypto ransom attack rate in the world, and the interior ministry just admitted they&apos;ve lost control.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>regulation</category><category>crime</category><category>europe</category></item><item><title>The World&apos;s Most Sanctioned Crypto Exchange Just Got Hacked — and It&apos;s Blaming the CIA</title><link>https://news.cryptogrind.com/blog/grinex-hack-garantex-successor-western-spies/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/grinex-hack-garantex-successor-western-spies/</guid><description>Grinex — the sanctions-dodging successor to Russia&apos;s notorious Garantex — shut down after a $13M hack and blamed &apos;Western special services.&apos; The irony is too rich.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>hacks</category><category>russia</category><category>sanctions</category><category>enforcement</category><category>defi</category><category>exchange</category></item><item><title>Bitcoin Devs Just Cooked Up a Quantum Tripwire That Would Freeze Satoshi&apos;s $74B in BTC</title><link>https://news.cryptogrind.com/blog/bitcoin-quantum-tripwire-satoshi-coins-freeze/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/bitcoin-quantum-tripwire-satoshi-coins-freeze/</guid><description>A new &apos;canary address&apos; proposal would only freeze 6.5 million vulnerable BTC — including Satoshi&apos;s coins — if a quantum computer actually proves it can break Bitcoin first. Adam Back says there&apos;s a better way.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>bitcoin</category><category>quantum</category><category>security</category><category>bip-361</category><category>breaking-news</category><category>developers</category></item><item><title>North Korea Robbed Drift. Tether Wrote the Check — and Just Dethroned Circle on Solana.</title><link>https://news.cryptogrind.com/blog/drift-tether-148m-rescue-usdc-dethroned/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/drift-tether-148m-rescue-usdc-dethroned/</guid><description>Tether is bailing out Drift Protocol with $148M after North Korea&apos;s $285M heist — but the real play is quietly replacing Circle&apos;s USDC as Solana DeFi&apos;s settlement currency.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>solana</category><category>tether</category><category>usdt</category><category>usdc</category><category>circle</category><category>north-korea</category><category>hacks</category><category>stablecoins</category></item><item><title>A Fake Ledger App Ran on Apple&apos;s App Store for 2 Weeks and Drained $9.5 Million</title><link>https://news.cryptogrind.com/blog/fake-ledger-apple-app-store-9-million-theft/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/fake-ledger-apple-app-store-9-million-theft/</guid><description>A fraudulent Ledger Live app slipped through Apple&apos;s review process, stayed live for roughly two weeks, and drained $9.5 million from 50+ victims before ZachXBT blew the whistle.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>security</category><category>hack</category><category>apple</category><category>ledger</category><category>wallet</category><category>zachxbt</category></item><item><title>Hacker Minted 1 Billion Polkadot Tokens on Ethereum — and Only Got Away With $237K</title><link>https://news.cryptogrind.com/blog/hyperbridge-1-billion-dot-minted-237k-stolen/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/hyperbridge-1-billion-dot-minted-237k-stolen/</guid><description>A forged cross-chain proof let an attacker mint 1,000,000,000 fake DOT tokens on Ethereum in a single transaction. Thin liquidity saved Polkadot. Twelve days earlier, Hyperbridge had posted an April Fools&apos; joke about exactly this.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>hacks</category><category>polkadot</category><category>bridges</category><category>security</category></item><item><title>North Korea Spent Six Months Pretending to Be a Trading Firm to Steal $270M From Drift</title><link>https://news.cryptogrind.com/blog/drift-north-korea-six-month-infiltration/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/drift-north-korea-six-month-infiltration/</guid><description>Drift Protocol confirmed today that the April 1 exploit wasn&apos;t opportunistic — DPRK-linked hackers spent six months attending crypto conferences, building real relationships, and depositing real money before draining $270M.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>security</category><category>north-korea</category><category>dprk</category><category>solana</category><category>hacks</category><category>jobs</category></item><item><title>Circle Watched $232M in Stolen USDC Bridge Out for 6 Hours — and Did Nothing</title><link>https://news.cryptogrind.com/blog/circle-usdc-freeze-zachxbt-drift-hack/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/circle-usdc-freeze-zachxbt-drift-hack/</guid><description>ZachXBT just published a damning thread showing Circle had the power to freeze $232M in stolen Drift Protocol funds — during business hours, over 6 hours — and chose not to. It&apos;s part of a pattern spanning $420M across 15 cases since 2022.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>security</category><category>regulation</category><category>stablecoins</category><category>solana</category></item><item><title>Solana&apos;s Biggest Hack Since Wormhole: $270M Drained From Drift Protocol in Minutes</title><link>https://news.cryptogrind.com/blog/drift-protocol-solana-exploit-270m/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/drift-protocol-solana-exploit-270m/</guid><description>Drift Protocol, Solana&apos;s leading perpetuals DEX, was drained of up to $285M in a still-unconfirmed exploit on April 1 — and the attacker is still moving funds right now.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><category>breaking-news</category><category>defi</category><category>security</category><category>solana</category><category>exploit</category><category>hacks</category><category>jobs</category></item><item><title>Google Says Quantum Computers Could Crack Bitcoin in 9 Minutes. The Industry Needs Post-Quantum Engineers Yesterday.</title><link>https://news.cryptogrind.com/blog/google-quantum-bitcoin-crypto-jobs/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/google-quantum-bitcoin-crypto-jobs/</guid><description>Google says breaking Bitcoin may need 20x fewer qubits than thought. 6.9M BTC already exposed. The race to hire post-quantum crypto engineers starts now.</description><pubDate>Tue, 31 Mar 2026 15:00:00 GMT</pubDate><category>bitcoin</category><category>quantum-computing</category><category>google</category><category>security</category><category>cryptography</category><category>jobs</category><category>post-quantum</category><category>hiring</category></item><item><title>Anthropic Just Leaked Claude Code&apos;s Entire Source Code. Every Crypto Dev Using AI Should Be Paying Attention.</title><link>https://news.cryptogrind.com/blog/claude-code-source-leak-crypto-ai-security/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/claude-code-source-leak-crypto-ai-security/</guid><description>512K lines of TypeScript and 44 feature flags exposed via npm. If your crypto team uses AI coding tools, your threat model just changed.</description><pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate><category>security</category><category>ai</category><category>claude-code</category><category>npm</category><category>crypto</category><category>developer-tools</category><category>jobs</category><category>supply-chain</category></item><item><title>North Korea Just Backdoored npm&apos;s Most Popular HTTP Library. Crypto Was the Target.</title><link>https://news.cryptogrind.com/blog/axios-supply-chain-attack-crypto-security-jobs/</link><guid isPermaLink="true">https://news.cryptogrind.com/blog/axios-supply-chain-attack-crypto-security-jobs/</guid><description>The Axios supply chain attack dropped a crypto-wallet-stealing RAT on 100M weekly installs. What happened, why AI missed it, and the security roles crypto needs now.</description><pubDate>Tue, 31 Mar 2026 09:00:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>axios</category><category>crypto</category><category>north-korea</category><category>jobs</category><category>ai</category><category>vulnerabilities</category></item></channel></rss>