XPR Network patched a smart contract vulnerability in proton.swaps that allowed negative withdrawals. Recovery efforts recovered approximately 1.856 billion XPR tokens (87% of stolen assets) and 100% of stablecoins, with 20 block producers coordinating the multisig recovery and broader infrastructure improvements underway.
Chainflip lost $736,442 in USDT through a TRON integration exploit on September 12, where an attacker manipulated transaction memos to trigger multiple payouts from a single deposit. The incident highlights risks in cross-chain infrastructure where validators and blockchains process transactions correctly, but settlement logic interprets them incorrectly, exposing vulnerabilities in how protocols handle chain-specific edge cases.
Symbiosis Finance experienced a security exploit on September 11, 2026, where an attacker exploited a Bitcoin bridge vulnerability to mint over $46 billion in unbacked syBTC tokens. However, only approximately $336,000 in real value was extracted before the bridge was halted, highlighting the critical difference between on-chain token supply and actual liquidity in crypto protocols.
A security researcher reported discovering and preventing a $500 million protocol exploit, receiving a $50,000 finder's fee while criticizing the disparity between bug bounty payments and criminal payouts for vulnerabilities.
Alephium's bridge exploit from June led to a security postmortem published on September 11, 2026. The bridge is now restored and operational, with the team focusing on mainnet launch and Powfi development while implementing enhanced security measures and temporarily suspending bug bounty rewards due to increased AI-assisted attacks.
Ehsan criticizes a blockchain protocol for poor security practices that led to a hack, arguing the developers lack accountability and victim mentality. Blockstream responds to the Liquid Network theft by refusing ransom demands, rejecting the framing as responsible disclosure, and pledging to pursue legal avenues while calling on the Bitcoin community to uphold white-hat principles.
A Web3 security learner describes a reentrancy attack vulnerability in the Olas protocol where developers violated the Checks-Effects-Interactions pattern. An attacker exploited the _safeMint callback to reenter the contract, reduce their bond requirement to 1 wei, and subsequently drain a massive bond amount from the protocol.
A Twitter thread discusses a reentrancy vulnerability in the Olas protocol where developers violated the Checks-Effects-Interactions pattern by calling _safeMint before finalizing bond accounting, allowing attackers to reenter the contract and drain funds by paying minimal wei. The post highlights the importance of updating internal state before external calls and using reentrancy guards.
A sophisticated exploit on Liquid, Blockstream's Bitcoin sidechain, resulted in nearly 4,000 BTC being withdrawn without corresponding backing through a vulnerability in confidential transaction validation. The attacker, claiming to be a whitehat, returned 3,400 BTC but retained approximately 598.5 BTC (~$48M) while demanding a 10% bug bounty, leaving the reserve deficit unresolved.
A security vulnerability in Nomic's IBC bridge allowed double-minting of nBTC tokens, resulting in 40.65 nBTC being created and subsequently drained across multiple blockchain networks. The attacker exploited a code flaw that minted coins twice for single deposits, then converted the stolen assets to ETH and USDC through Osmosis, Axelar, and other cross-chain bridges, ultimately netting approximately 600+ ETH equivalent.
A security researcher argues that exploiters who use blackmail to extract funds should not be called white hats, even if bug bounties are inadequate. The Liquid protocol exploiter obtained $47M through exploitation and blackmail rather than reporting the vulnerability through standard bug bounty channels, demonstrating how leverage from holding funds creates vastly different negotiating outcomes than legitimate security disclosures.
White-hat hackers returned 3,400 BTC (~$270 million) after exploiting a Blockstream Liquid Network vulnerability, with 598 BTC still outstanding. The incident highlights cryptocurrency infrastructure security risks despite improvements, as a single software flaw exposed hundreds of millions in funds without private key compromise.
A security researcher criticizes inadequate bug bounty compensation for discovering a critical vulnerability that could have caused 85% losses, arguing bounties should reflect severity and value protected rather than arbitrary amounts.