MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
Consensys found no compromised assets or data, no malicious code deployment and no user impact, but contractor access controls face scrutiny.
Follow crypto hack news, exploits, bridge attacks, protocol breaches, and security lessons from major incidents across Web3.
Cardano’s governance model depends on ordinary ADA holders participating, and the SecondFi exploit shows how much that model depends on secure wallet UX.
The malicious proposal shows how token-weighted votes can become a treasury access path when DAO review controls are too thin.
Blockaid estimated about $6 million drained as Summer.fi paused Lazy Summer vaults and investigated the cause.
Edel’s exploit was small, but it hit the next frontier for tokenized equities: credit markets, where 1:1 backing is not enough if wrappers, vaults and exchange rates can be gamed.
DeFiLlama data shows $780.3 million in Q2 known losses as bridges, keys and protocol logic turn security into a live cost of participation.
The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks.