https://www.web3isgoinggreat.com/?id=trust-wallet-hack HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagram ThreadsRSSLeaderboardGlossaryContributeNewsletterStoreSkip to timeline Illustration: A sad-looking Bored Ape Yacht Club NFT monkey looks at a world engulfed in flames. Web3 is Going Just Great ...and is definitely not an enormous grift that's pouring lighter fluid on our already smoldering planet. Created by Molly White. Subscribe to her newsletter for weekly recaps. * Twitter * Mastodon * Bluesky * Instagram * Threads Start from the top [robber] December 25, 2025 * Binance's Trust Wallet extension hacked; users lose $7 million A blue and green gradient shield symbol followed by "Trust Wallet" in blue(attribution) The Trust Wallet Chrome extension was compromised in an apparent supply chain attack. People who used the non-custodial wallet extension after it updated to version 2.68 lost funds after malicious code was introduced to exfiltrate wallet seed phrases so that the attackers could then drain the wallets. Victims have lost a combined $7 million due to the compromise. Binance founder Changpeng Zhao -- who supposedly has no managerial role at Binance after he and the company were criminally charged in the US -- announced that Binance would reimburse users who lost funds. * Tweet thread by TrustWallet [archive] * Tweet thread by SlowMist [archive] * Tweet by Changpeng Zhao [archive] Theme tags: Hack or scam [robber] December 19, 2025 * Crypto trader loses $50 million to address poisoning attack A crypto trader lost almost $50 million in the Tether stablecoin after falling victim to an address poisoning attack. Because blockchain wallet addresses are long, random alphanumeric strings, traders often use the first and/or last several characters to quickly recognize wallets, and copy and paste regularly used wallet addresses from their transaction history. This has given rise to a type of scam known as "address poisoning", where scammers generate wallet addresses that share similar beginning and end characters, and use them to send transactions to wealthy victims. If they're lucky, as they were in this case, the victim will accidentally copy the similar looking scammer's wallet address when making a transfer of significant size. After the theft, the victim sent an on-chain message to the scammer, offering a $1 million "bounty" for the return of the remaining funds. They threatened, "We have officially filed a criminal case. With the assistance of law enforcement, cybersecurity agencies, and multiple blockchain protocols, we have already gathered substantial and actionable intelligence regarding your activities." However, there's been no activity from the wallet since the message, and the thief had long since begun laundering the funds via Tornado Cash. * Thief wallet, Etherscan [archive] * On-chain message, Etherscan Theme tags: Hack or scam Tech tags: stablecoins [robber] December 16, 2025 * Yearn Finance suffers fourth exploit only weeks after third A blue circle with a white symbol of a Y with a U-shaped semicircle below it(attribution) Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH (~$300,000). The affected contract is a legacy contract that was part of the Yearn v1 project (once known as iearn). The attacker used a flash loan to manipulate the price of tokens in the vault, allowing them to withdraw the iearn assets, which they then swapped for ETH. This is Yearn's fourth hack, following the $6.6 million theft in November, an $11 million exploit in 2023, and an $11 million exploit in 2021. Yearn also lost around $1.4 million in 2023 in connection to the Euler Finance attack. * Tweet by PeckShield [archive] * Tweet by Weilin (William) Li [archive] * Exploit transaction, Etherscan [archive] Theme tags: Hack or scam Blockchain tags: Blockchain: Ethereum Tech tags: DeFi [robber] December 12, 2025 * Ribbon Finance suffers $2.7 million exploit, plans to use "dormant" users' funds to repay active users A red circle with a white angled hook shape(attribution) Ribbon Finance, which has partially rebranded to Aevo, has lost $2.7 million after attackers exploited a vulnerability in the smart contract for legacy Ribbon vaults that enabled them to manipulate oracle prices and withdraw a large amount of ETH and USDC. Ribbon has announced it will cover $400,000 of the lost funds with its own assets. However, Ribbon is also offering users a lower-than-expected haircut on their assets by assuming that some of the largest affected accounts will not withdraw their assets, having been dormant for several years. While this plan may benefit active users, it seems like it could get very messy if those dormant users do wish to withdraw their assets and discover they've been used to pay others. * Tweet by Aevo (fka Ribbon Finance) [archive] * Tweet by Aevo (fka Ribbon Finance) [archive] * Tweet by Anton Cheng [archive] Theme tags: Hack or scam Blockchain tags: Blockchain: Ethereum Tech tags: DeFi [shades] December 8, 2025 * Binance employee suspended after launching a token and promoting it with company accounts Binance logo, a yellow diamond next to the word Binance in yellow caps(attribution) Binance has announced that the company has suspended an employee who used the platform's official Twitter accounts to promote a memecoin they had launched. The token, called "year of the yellow fruit", pumped in price after official Binance accounts coaxed followers to "harvest abundantly". Binance publicly acknowledged that an employee had been suspended for misconduct over the incident. "These actions constitute abuse of their position for personal gain and violate our policies and code of professional conduct," Binance tweeted from its BinanceFutures account. After this announcement, the memecoin token price spiked even further. Earlier this year, Binance fired another employee after discovering they had used inside information to profit from a token sale event. * "Binance post confirming insider trading sends 'year of the yellow fruit' meme token even higher", The Block * Tweet by Binance Futures [archive] Theme tags: Shady business Blockchain tags: Blockchain: BNB Chain December 4, 2025 * Prysm consensus client bug causes Ethereum validators to lose over $1 million A blue prism shape with a notch cut out of it, followed by "Prysm by Offchain Labs"(attribution) Ethereum validators running the Prysm consensus client lost around 382 ETH ($1.18 million) after a bug resulted in delays that caused validators to miss blocks and attestations. Though the bug had been introduced around a month prior, it did not affect validators until Ethereum completed its "Fusaka" network update on December 3. Around 19% of Ethereum validators use the Prysm consensus client, which is developed by Offchain Labs. * "Fusaka Mainnet Prysm Incident", Prysm * Client Distribution, Clientdiversity.org Theme tags: Bug Blockchain tags: Blockchain: Ethereum [robber] November 30, 2025 Yearn Finance hacked for the third time A blue circle with a white symbol of a Y with a U-shaped semicircle below it(attribution) Yearn Finance, a defi yield protocol, has suffered another hack. The exploiter took advantage of bugs in the project's smart contract to drain assets from several of its pools by minting a huge number of yETH tokens and then withdrawing the corresponding asset in the pools. $2.4 million of the stolen assets, which were denominated in pxETH, a liquid staking token issued by Redacted Cartel, were recovered after the issuer burned the stolen tokens and reissued them to the team's wallet -- essentially, removing the tokens from the hacker's wallet. However, the hacker routed the remaining funds through the Tornado Cash cryptocurrency mixer, which makes recovery substantially more challenging. This is the third time Yearn Finance has been hacked, following an $11 million exploit in 2023 and another $11 million exploit in 2021. Yearn also suffered around $1.4 million in losses in 2023 in connection to the Euler Finance attack. * "yETH Pool Exploit: Technical Incident Report and Math Reconstruction", Banteg * "Yearn hacker loses $2.4M of $9M loot as tokens burned from wallet", Protos * "Yearn Finance details $9 million yETH exploit, confirms partial recovery and outlines remediation plan", The Block Theme tags: Hack or scam Blockchain tags: Blockchain: Ethereum Tech tags: DeFi [robber] November 27, 2025 Upbit hacked for $30 million "UPbit" in blue tones, with the space between the U and P resembling an upward pointing arrow(attribution) The Korean cryptocurrency exchange Upbit suffered a loss of around $30 million in various Solana-based assets due to a hack. Some entities have suggested that Lazarus, a North Korean state-sponsored cybercrime group, was behind the hack. Upbit reimbursed users who had lost funds from company reserves. The exchange was able to freeze around $1.77 million of the stolen assets. This theft occurred exactly six years after Upbit suffered a theft of 342,000 ETH (priced at around $50 million at the time). * "Upbit Reveals 5.9B-Won Corporate Loss in Latest Hack, Fully Reimburses Users", CoinDesk * "South Korean police launch formal probe into $30 million Upbit hack amid 'delay' allegations", DL News * "South Korea suspects North Korea behind hack of crypto exchange Upbit, Yonhap reports", Reuters Theme tags: Hack or scam Blockchain tags: Blockchain: Solana [robber] November 22, 2025 * Aerodrome and Velodrome suffer website takeovers, again An interlocking shape formed out of a rainbow strip, followed by the text "velodrome" in black sans serif(attribution) Attackers redirected users intending to visit the websites for the decentralized exchanges Aerodrome and Velodrome to their own fraudulent versions using DNS hijacking, after taking control of the websites' domains. The platforms urged users not to visit the websites as they worked to regain control. This is the second time such an attack has happened to these same platforms, with another DNS hijacking incident occurring almost exactly two years ago. In that instance, users lost around $100,000 when submitting transactions via the scam websites. * "Top DEXs Aerodrome, Velodrome hit with front-end compromise, urge users to avoid main domains", The Block [archive] Theme tags: Hack or scam Blockchain tags: Blockchain: Ethereum Tech tags: DeFi November 21, 2025 * Cardano founder calls the FBI on a user who says his AI mistake caused a chainsplit A blue hexagon shape formed out of circles, with smaller circles radiating out from it, followed by "Cardano" in blue caps (attribution) On November 21, the Cardano blockchain suffered a major chainsplit after someone created a transaction that exploited an old bug in Cardano node software, causing the chain to split. The person who submitted the transaction fessed up on Twitter, writing, "It started off as a 'let's see if I can reproduce the bad transaction' personal challenge and then I was dumb enough to rely on AI's instructions on how to block all traffic in/out of my Linux server without properly testing it on testnet first, and then watched in horror as the last block time on explorers froze." Charles Hoskinson, the founder of Cardano, responded with a tweet boasting about how quickly the chain recovered from the catastrophic split, then accused the person of acting maliciously. "It was absolutely personal", Hoskinson wrote, adding that the person's public version of events was merely him "trying to walk it back because he knows the FBI is already involved". Hoskinson added, "There was a premeditated attack from a disgruntled [single pool operator] who spent months in the Fake Fred discord actively looking at ways to harm the brand and reputation of IOG. He targeted my personal pool and it resulted in disruption of the entire cardano network." Hoskinson's decision to involve the FBI horrified some onlookers, including one other engineer at the company who publicly quit after the incident. They wrote, "I've fucked up pen testing in a major way once. I've seen my colleagues do the same. I didn't realize there was a risk of getting raided by the authorities because of that + saying mean things on the Internet." * Tweet thread by Homer J [archive] * Tweet by Charles Hoskinson [archive] * Tweet by Charles Hoskinson [archive] Theme tags: Bug, Law, Yikes Blockchain tags: Blockchain: Cardano No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.