Solana’s 9,000-Wallet Drain: Who Logged the Seed Phrases?
Slope’s telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
Slope’s telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto’s most chaotic heist.
A 2-of-5 multisig guarding nine figures. Lazarus took the two keys it needed, and the bridge-custody era changed for good.
No stolen keys, no exploit — just a death spiral in the mechanism itself. Why UST’s fall is mandatory reading for DeFi threat modelling.
No key stolen, no bug exploited — an attacker borrowed a voting majority on Aave, passed his own proposal, and drained the vaults in one block.
North Korea’s Lazarus Group drained Axie Infinity’s Ronin bridge of $625M with five forged signatures and a leftover permission nobody revoked.
Seventeen users, one fake migration flow, and $1.7M in Apes gone — the phishing heist that made signature UX a security discipline.
Attackers defeated the second factor, not the vault, draining $34M from 483 accounts before a platform-wide withdrawal halt stopped them.
A forged keeper-list substitution drained $611M across three chains. Then the attacker gave it all back. The bridge bug class that defined Web3’s worst year.
As FTX fell, hundreds of millions moved from its wallets — later attributed mostly to insiders per trial testimony. Custody without governance is the vulnerability.
An attacker forged a bridge proof to mint 2M BNB (~$570M), then validators halted the chain mid-launder. Only ~$100M escaped before the freeze.
Post-quantum cryptography is no longer a research-only topic. With NIST's first PQC standards finalized and organizations facing long-term risks such as harvest-now, decrypt-later, cyber teams need to understand how PQC affects PKI, TLS, code signing, firmware trust, crypto agility, and migration planning. This guide explains what PQC is, where QKD fits, how hybrid deployments work, and what defenders should prioritize first.