4,000 BTC (~$320 million) stolen from Liquid Network by claimed whitehats, 90% returned

An unauthorized withdrawal of 3,998.5 BTC (~$320 million) from the Liquid Network, a bitcoin sidechain, prompted a network halt. By disabling nodes that bridge between Liquid and the bitcoin mainchain, attackers are limited in their ability to cash out via bridge. Blockstream, the developers of Liquid Network, also said they had contacted exchanges to ask them to pause LBTC deposits and withdrawals, cutting off another avenue.

The unauthorized transaction included a message reading "we are whitehats. contact us on chain", suggesting the possibility that the withdrawal was in fact well-intentioned security researchers aiming to "rescue" funds after discovering they were vulnerable and then return them to a secure wallet. After some back and forth, the attacker returned 3,400 BTC (~$272 million) keeping 600 BTC (~$48 million), likely as a "bounty".

More Markets exploited for $9.3 million

Defi lending project More Markets lost $9.3 million after an attacker was able to trick the lending protocol logic and empty the project's reserve. The attack was noticed by blockchain security researchers at Blockaid; More Labs later announced they were investigating. Oddly, while acknowledging that funds had been stolen, they wrote, "Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused." They claimed that only 5% of the assets were bridged out of the Flow blockchain, though did not explain how they planned to prevent the attacker from moving more tokens or collapsing the token price entirely.

Crypto.com-affiliated Cronos blockchain halted after Tectonic theft

The ostensibly decentralized Cronos blockchain was halted after a price manipulation attack allowed an attacker to borrow around $120 million against nearly worthless collateral from the Tectonic lending platform. The attacker pumped the price of the thinly traded TONIC token, the native token of Tectonic, then borrowed against it. The attacker cashed out approximately $9.19 million by bridging it to Ethereum before the Cronos chain was halted, limiting their profits. The blockchain was offline for almost 24 hours, during which time it was rolled back to a block prior to the hack — essentially undoing all the transactions that occurred after that block.

Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain — though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.

Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks

A vulnerability in a smart contract belonging to Rain, a crypto payments infrastructure provider, resulted in $1.1 million in losses to various firms. Customers of the Avici cryptocurrency neobank, which offers a Visa credit card through which customers can spend crypto, suffered roughly $500,000 in losses. Customers of another neobank, Tria, lost more than $430,000.

The losses are somewhat unusual because the neobanks describe themselves as self-custodial, which normally means that customers have total control over their crypto assets rather than storing them on a third-party platform. Normally, self-custody is more resilient to exploits like this, given that assets remain in user wallets. However, because these neobanks require customers to load funds they want to be able to spend into a third-party contract, they were vulnerable to the theft.

Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.