Skip to content

More top stories

Incident Tracker

All incidents →
Disclosed Incident Chain Reported impact Status
Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check
Signing interface compromise · Supply chain
Ethereum approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 Feb. 2025) Resolved
Radiant Capital Signing Compromise, October 2024: What Happened & What to Check
Key compromise · Signing interface compromise
Arbitrum, BNB Chain approx. US$50 million(Radiant Capital, 17 Okt. 2024) Contained
WazirX Multisig Compromise, July 2024: What Happened & What to Check
Key compromise · Signing interface compromise
Ethereum approx. US$234.9 million(WazirX, 18 Juli 2024) Contained
DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check
Key compromise
Bitcoin 4,502.9 BTC(DMM Bitcoin, 31 Mai 2024) Resolved
Munchables Insider Key Compromise, March 2024: What Happened & What to Check
Access control · Insider access
Blast approx. US$62 million (returned)(Munchables, 26 März 2024) Resolved
Kompromittierung der Orbit-Chain-Bridge, Dezember 2023: Was geschah und was zu prüfen ist
Bridge exploit · Key compromise
Ethereum, Orbit Chain approx. US$81.5 million(Orbit Chain, 1 Jan. 2024) Contained

Regulation watch

All jurisdictions →

New Zealand

New Zealand has consulted on whether its technology-neutral approach remains adequate, rather than moving to a MiCA-style dedicated regime.

As of

France

The substantive question in France is now the transition of nationally registered PSANs into MiCA authorisation, and the AMF publishes the register of who holds what.

As of

the Netherlands

The Dutch registration regime was notably strict in practice, and the transition to European authorisation has been the main development.

As of

Saudi Arabia

Official communication has consisted mainly of cautions that virtual currencies are not recognised and that firms offering them are not licensed domestically. Central bank work on distributed ledger technology has proceeded on a separate track from any retail crypto authorisation.

As of

More reporting

All incidents →

From the Newsroom

Who writes here, and what they are working on

Full masthead →

The weekly security digest

The week's incidents and rule changes, each with its primary source and the check worth running. Free, short, no price calls.

About the digest

Frequently asked

Full methodology →
What is Conisec?
Conisec is an independent publication covering crypto security incidents, exploits, and regulation. We track what broke, who it affected, and what the rules say — and we cite a primary document for every claim.
What is "The Ledger" on your stories?
The Ledger is a fixed four-line panel on every security, incident and regulatory story: what happened, who's exposed, how to verify it yourself, and what changes. The verification line is the point — we hand you the check rather than asking you to trust us.
Where do your incident details come from?
Primary sources only: official project post-mortems, exchange status pages, security-firm advisories, regulator notices, court filings and on-chain records. Secondary reporting may corroborate a fact but never stands alone for a loss figure, an attribution or a legal characterisation. If it cannot be sourced, it does not publish.
Is anything on Conisec financial, legal or security advice?
No. Everything we publish is for information only. We do not issue buy or sell calls, we do not give legal or tax advice, and we never tell a reader to move funds, revoke an approval or interact with a contract address. We link the official advisory and let the issuer's own instructions stand.
Are your writers real people, and do you use AI?
Every public byline on Conisec is a real, named person. We do not publish under "admin" and we do not invent staff, bios, photos or credentials. Our editorial guidelines state plainly whether and how AI assists our work; a human is accountable for every published claim.
How do I report a correction or a missing incident?
Use our contact page. Corrections are appended and dated on the article itself — never silently rewritten — and logged publicly on our corrections page.

Still unsure about something? Ask us — or read how we source and verify, our editorial guidelines and what we will never ask you for.