2026-09-25
Tier 1
Cash FX Group S.A.; The Conversion Pros, Inc.; Huascar Jose Lopez Castillo; Ronald Pope; Justin Halladay
The CFTC announced a federal complaint alleging Cash FX Group and related defendants operated a multilevel marketing Ponzi scheme that solicited more than USD 950 million, used false claims about expert traders, proprietary algorithms, and AI, misappropriated nearly all participant funds, and caused at least USD 406 million in participant losses.
United States / Florida federal court
U.S. Commodity Futures Trading Commission / U.S. District Court for the Middle District of Florida
Fraud / crypto-linked forex investment scheme / MLM
high confidence
CFTC civil enforcement complaintPonzi scheme allegationcrypto-linked payment railsforex commodity pool fraudfalse AI and algorithmic trading claimsparticipant fund misappropriationtrading and registration ban requestrestitution and disgorgement exposure
Cash FX is included as Tier 1 because the CFTC published an official enforcement complaint with named defendants, alleged USD 950 million solicitation, at least USD 406 million participant losses, and requested restitution, disgorgement, civil penalties, trading and registration bans, and permanent injunctive relief.
Listing post-mortem use: Use when reviewing tokens, venues, or payment processors connected to yield-marketing networks: test whether fundraising claims depend on unverifiable AI/algorithmic trading, pooled customer funds, referral incentives, false account statements, or crypto rails masking commodity-pool activity.
Source
2026-09-25
Tier 2
Evercrest Technologies / KelpDAO v. LayerZero Labs, LayerZero Canada, and Bryan Pellegrino
Fresh reporting says Evercrest Technologies, the company behind KelpDAO, sued LayerZero-related defendants in British Columbia over the April 2026 rsETH bridge exploit that drained about 116,500 rsETH, alleging negligent misrepresentation, negligence, and defamation tied to a single-verifier configuration and LayerZero-operated infrastructure.
Canada / British Columbia civil court
British Columbia civil court / private plaintiff claim
Cross-chain bridge / restaking / interoperability infrastructure
medium confidence
civil litigationbridge exploit liabilitysingle-verifier configuration riskDVN and RPC infrastructure dependencyrestaking asset lossvendor security assurance riskcustomer migration pressureinteroperability provider reputational risk
KelpDAO/LayerZero is included as Tier 2 because multiple reputable reports describe a named civil claim over a major bridge exploit with clear adverse consequences, but the claims have not yet been adjudicated and no official court docket was verified during this run.
Listing post-mortem use: Use when reviewing tokens or protocols dependent on bridge-issued/restaked assets: test whether cross-chain supply integrity relies on a single verifier, provider-operated RPC paths, nonstandard DVN thresholds, written vendor security assurances, or migration plans after exploit events.
Source
2026-09-24
Tier 1
Bitget exchange hot and warm wallet layers
Bitget confirmed unauthorized transfers from parts of its hot and warm wallet layers, later revised the affected amount from approximately USD 351.6 million to approximately USD 387.5 million, identified attacker-controlled addresses across EVM, XRP, Zcash and TRON, and launched tracing, freezing, and bounty recovery workflows while withdrawals remained under staged restoration.
Global / centralized exchange
Bitget / relevant authorities and on-chain security firms notified
Centralized exchange / custody / hot wallet security
high confidence
exchange hot wallet breachwithdrawal suspensioncustody control failureuser protection fund reliancelaw enforcement notificationon-chain fund tracingvenue operational riskattacker address disclosurecross-chain laundering riskfund freeze coordinationrecovery bounty programthird-party incident investigation
Bitget remains Tier 1 because the exchange itself confirmed a large hot-wallet security incident with direct adverse consequences: approximately USD 387.5 million transferred to attacker-controlled addresses, withdrawals paused or staged, attacker addresses disclosed, and tracing, freezing, bounty, law-enforcement, Mandiant, and SlowMist workflows engaged.
Listing post-mortem use: Use when reviewing assets dependent on Bitget liquidity, exchange custody assurances, hot-wallet transaction controls, cross-chain withdrawal routes, or venues that cite protection funds, bounty programs, and industry freezing coordination as mitigation for operational-security losses.
Source
2026-09-24
Tier 1
Payy Network Ethereum bridge and stablecoin payment app
Payy said its Ethereum bridge contract was exploited and drained, and paused Payy Network deposits, withdrawals, transfers, and card transactions while investigating; media traced a roughly 1.83 million USDC outflow from a Payy rollup contract.
Global / Ethereum / stablecoin payments
Payy protocol statement / Ethereum on-chain record
Stablecoin payments / Ethereum bridge / crypto card infrastructure
medium-high confidence
bridge exploitnetwork pausecard transaction freezeUSDC outflowcustomer balance uncertaintypayment continuity riskincident response pending
Payy is included as Tier 1 because the project-linked payment network was paused after a bridge exploit, producing direct adverse consequences for deposits, withdrawals, transfers, and card transactions.
Listing post-mortem use: Use when reviewing payment-token, bridge, or crypto-card listings: check bridge custody design, customer-balance segregation, card dependency on on-chain liquidity, pause controls, and restoration communications.
Source
2026-09-23
Tier 3
Darksword iOS exploit chain
SlowMist warned that attackers may have adapted the Darksword iOS exploit chain to compromise newer iOS devices through malicious Safari links and reach private keys or wallet records stored locally on self-custody devices.
Global / mobile wallet endpoint security
SlowMist warning; Google Threat Intelligence historical Darksword research referenced
Mobile wallet security / endpoint compromise / browser exploit delivery
medium confidence
mobile endpoint compromiseSafari malicious link deliveryprivate key exposurewallet data exfiltrationiOS exploit chaincommercial surveillance tooling spilloverself-custody user loss riskofficial confirmation pending
Darksword is included as Tier 3 because it is an early-warning security signal with a clear self-custody risk vector, but the specific claimed iOS 26.5 exposure and loss amounts were not officially confirmed during this run.
Listing post-mortem use: Use in wallet-drain post-mortems where users deny seed entry or malicious app installation: check mobile OS version, unsolicited links, Safari browsing history, endpoint telemetry, wallet storage model and whether losses cluster around mobile-heavy communities.
Source
2026-09-23
Tier 1
OKX listed-asset basket: DORA, ICX, STORJ, ZEUS and ELF
OKX announced delisting of DORA, ICX, STORJ, ZEUS and ELF spot trading pairs, suspended deposits from September 23, and scheduled withdrawals to stop on December 23, 2026.
Global / OKX spot markets
OKX
Centralized exchange spot markets / long-tail token listing maintenance
high confidence
exchange delistingdeposit suspensionwithdrawal deadlinelisting criteria failurespot liquidity contractiontrading bot closureorder cancellationuntradable asset migration
OKX is included as a Tier 1 negative-intel row because the official exchange notice creates direct adverse market-access consequences for five named assets, including spot-pair delistings, deposit suspension from September 23, automatic order and bot closures, temporary transfer restrictions during consolidation, and a December 23 withdrawal suspension deadline.
Listing post-mortem use: Use when reviewing assets with repeated exchange-review friction: check multi-venue support history, quote-pair concentration, deposit and withdrawal deadlines, trading-bot exposure, order-cancellation mechanics, and whether prior monitoring tags foreshadowed later delisting.
Source
2026-09-23
Tier 1
Ronald Spektor Coinbase user phishing scheme
The Brooklyn District Attorney announced Ronald Spektor was sentenced to four to 12 years in prison after pleading guilty to a 31-count indictment tied to a Coinbase impersonation scheme that stole nearly USD 16 million from about 100 users and laundered funds through swaps, mixing services, and gambling entities.
United States / New York
Brooklyn District Attorney Virtual Currency Unit / Brooklyn Supreme Court
Scam infrastructure / exchange-user social engineering / laundering
high confidence
criminal sentencingexchange impersonation scamsocial engineeringmoney launderingmixing servicescrypto gambling cash-outvictim restitution
The Spektor case is included as Tier 1 because an official prosecutor announced a completed criminal sentencing, forfeiture, and restitution order for a crypto phishing and laundering scheme with named exchange-user exposure.
Listing post-mortem use: Use when reviewing exchange-user exposure and token distribution channels: test whether user-acquisition, support, and wallet-migration flows can be impersonated, and whether downstream venues detect scam proceeds routed through swaps or gambling services.
Source
2026-09-22
Tier 1
Sophon
Upbit designated Sophon (SOPH) as a trading-caution asset and blocked SOPH deposits across KRW, BTC and USDT markets, citing disclosure shortcomings, token-circulation plan changes and procedural concerns; Bithumb reportedly placed SOPH under similar scrutiny.
South Korea / Global exchange listings
Upbit trading-support review; Bithumb investment-caution review reported
Exchange-listed token / Layer-2 consumer chain / listing disclosure controls
high confidence
exchange trading cautiondeposit suspensionpossible delisting reviewtoken circulation disclosure riskproject procedure transparencySouth Korea exchange listing frictionuser harm warningmulti-exchange review
Sophon is included as Tier 1 because an official Upbit notice created a direct adverse exchange consequence: SOPH was placed under trading caution, deposits were blocked, and a defined review window now carries possible trading-support termination risk.
Listing post-mortem use: Use when reviewing token listings with recent circulation-plan changes, migration history or Korean exchange exposure: verify supply disclosures, governance procedures, investor notice timing, deposit network changes, monitoring tags and contingency plans for caution designations.
Source
2026-09-22
Tier 2
Binance Holdings Ltd.
Bloomberg and Reuters reported that U.S. federal prosecutors are investigating whether Binance knowingly allowed trading that violated Iran sanctions, with scrutiny focused on compliance controls after Binance’s 2023 U.S. settlement and a separate USD 61M Iran-linked crypto forfeiture complaint.
United States / Iran sanctions
U.S. Department of Justice / SDNY and Criminal Division reported by Bloomberg and Reuters; related SDNY civil forfeiture record
Centralized exchange / sanctions compliance / AML transaction monitoring
medium-high confidence
Iran sanctions exposureDOJ investigation reportcentralized exchange compliance monitorAML transaction monitoringKYC sanctions geofencingUSDT TRON illicit-finance contextpost-settlement control testinglaw-enforcement cooperation risk
Binance is included as Tier 2 because fresh reputable reporting identifies a named exchange, U.S. authorities, Iran sanctions vector and control-focus risk, while the signal remains below Tier 1 because no new official charge, consent order or exchange restriction against Binance was public during this run.
Listing post-mortem use: Use when reviewing listings dependent on Binance liquidity, Binance Pay or Binance custody rails: test Iran and sanctioned-jurisdiction exposure, USDT/TRON flow monitoring, post-settlement control assurances, law-enforcement request history and whether market access assumptions depend on Binance avoiding new U.S. sanctions action.
Source
2026-09-21
Tier 1
WaterPlum / Contagious Interview DPRK cyber actor group
A joint law-enforcement advisory reported that North Korea-linked WaterPlum actors infected at least 30,000 devices in more than 100 countries, exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets and transferred about USD 10.71 million in crypto assets to DPRK-controlled accounts.
Global / DPRK sanctions and cybercrime
FBI IC3, Japan National Police Agency, Australian Signals Directorate / ACSC, German domestic security authority joint advisory
Crypto cybercrime / developer recruitment malware / wallet and private-key theft
high confidence
DPRK cybercrimefake recruitment malwaredeveloper workstation compromisewallet credential theftprivate key exfiltrationmalicious npm packagesAI face-swap interview deceptionemployer network pivot risksanctions exposure
WaterPlum is included as Tier 1 because official multi-jurisdiction law-enforcement sources describe a confirmed crypto-theft campaign with quantified wallet impact, named malware families, DPRK attribution and direct asset-transfer consequences.
Listing post-mortem use: Use when reviewing projects with remote developer teams, outsourced code contributors, hot-wallet access, npm/package dependencies or weak applicant screening: verify endpoint isolation, code-test sandboxing, wallet key custody, identity checks and DPRK sanctions-screening controls.
Source
2026-09-21
Tier 2
FomoPeek iOS app
Binance warned iPhone and iPad users after security researchers linked FomoPeek versions 1.1 and 1.2 to malicious code capable of exploiting iOS, escaping the sandbox and exposing private keys, seed phrases, credentials and files stored by other apps.
Global / mobile app distribution
Binance Wallet warning; SlowMist and OKX security analysis reported
Mobile wallet security / App Store malware / self-custody infrastructure
medium-high confidence
mobile malwareprivate key exposureseed phrase theftiOS sandbox escapeApp Store distribution riskremote command infrastructureself-custody wallet drain reportsdevice-level compromise
FomoPeek is included as Tier 2 because the signal is credible and structured, with named app versions, affected device class, clear wallet-credential risk vector and exchange/security-firm warnings, but no regulator action or final official app-store incident report was located during the run.
Listing post-mortem use: Use when reviewing wallet-drain incidents or mobile-heavy retail tokens: check whether affected users installed third-party portfolio apps, whether seed rotation guidance was issued, and whether customer support can distinguish protocol loss from endpoint compromise.
Source
2026-09-21
Tier 1
MultiversX
Upbit designated MultiversX EGLD trading pairs as caution markets after a confirmed VM-level atomicity exploit attempt produced invalid state changes, stopped network progression and triggered exchange deposit and withdrawal suspensions.
South Korea / Global exchange infrastructure
Upbit trading-support review; Bithumb, Kraken and Coinbase transfer restrictions; MultiversX recovery coordination
Layer-1 blockchain / exchange listings / validator and bridge infrastructure
high confidence
mainnet exploit attemptinvalid state changesnetwork haltexchange trading cautiondeposit withdrawal suspensionlisting support reviewvalidator coordination riskcross-chain bridge transfer warning
MultiversX is included as Tier 1 because an official Upbit notice designated EGLD as a trading-caution asset while transfers were suspended, and corroborating reports tie the action to a confirmed mainnet exploit attempt and network recovery process.
Listing post-mortem use: Use when reviewing L1 listings or exchange support decisions: check whether the network has VM-level atomicity protections, emergency halt procedures, exchange communication playbooks, validator coordination evidence, bridge advisories and prior trading-caution history.
Source
2026-09-20
Tier 2
Fetch.ai TokenConversionManagerV3 and NuNet NTX mint path
Security-monitoring and media reports said the same attacker drained roughly USD 1.56 million in FET from Fetch.ai TokenConversionManagerV3 using a valid conversion-authorizer signature and also caused roughly USD 452,000 of NuNet NTX mint exposure before swapping proceeds into ETH.
Global / DeFi / AI-token infrastructure
Blockaid / SlowMist / PeckShield monitoring; Fetch.ai investigation reported
AI-token infrastructure / DeFi token converter / authorization controls
medium-high confidence
protocol exploitauthorization-signature misusetoken converter drainunauthorized mint exposureAI-token infrastructure riskliquidity conversion to ETHtoken price crashpostmortem pending
Fetch.ai/NuNet is included as Tier 2 because fresh security-monitoring and media reports identify named projects, assets, loss estimates, attacker behavior and a concrete authorization-control risk vector, while final official post-mortem details remain pending.
Listing post-mortem use: Use when reviewing AI-token listings, migrations or converter contracts: verify signer controls, conversion limits, mint authority, reserve custody, emergency pause design, monitoring coverage and whether exploit proceeds were rapidly converted into liquid assets.
Source
2026-09-19
Tier 2
Lemon Brazil
Multiple industry reports said Argentine crypto app Lemon will cease local Brazil operations, stop Lemon Card processing on September 30 and automatically close Brazilian accounts on October 16 after deciding Brazil’s VASP license capital requirements were disproportionate to its local scale.
Brazil
Banco Central do Brasil virtual-asset service provider framework
Retail crypto app / VASP licensing / fiat on-off ramp / crypto card
medium confidence
market exitlicense capital requirementretail account closurecrypto card shutdownBRL deposit blockfiat on-ramp losssubscale VASP pressure
Lemon Brazil is included as Tier 2 because named reports identify a direct adverse consequence, dated account and card shutdowns, jurisdiction and licensing-capital risk vector, though the run did not locate a primary Lemon notice.
Listing post-mortem use: Use when reviewing LATAM retail-distribution claims: verify whether a token depends on small Brazil-facing wallets, card products, BRL rails or VASP applicants that may exit under capital and licensing pressure.
Source
2026-09-18
Tier 2
Binance Europe MiCA authorization bid
CoinDesk, citing a Wall Street Journal report, said ECB President Christine Lagarde personally intervened to delay or block Binance’s Greek MiCA license bid over compliance and dollar-stablecoin concerns; Binance withdrew the Greek application in June but says it still intends to seek MiCA authorization.
European Union / Greece
Hellenic Capital Market Commission / European Central Bank / ESMA policy context
Centralized exchange / EU MiCA licensing / stablecoin policy
medium-high confidence
license application frictionMiCA authorization riskstablecoin policy concernregulatory discretionexchange market-access uncertaintypast compliance issue overhangpassporting risk
Binance EU MiCA friction is included as Tier 2 because the report identifies a named exchange, jurisdiction, authorization pathway and direct market-access risk, but there is no final public enforcement order or formal license rejection in the source record.
Listing post-mortem use: Use when reviewing assets dependent on Binance EU liquidity or stablecoin rails: test whether venue access depends on unresolved MiCA licensing, dollar-stablecoin policy tolerance and national regulator passporting assumptions.
Source
2026-09-18
Tier 1
BitBank / Pishtaz Simorgh Electronic Trade Company / Babak Zanjani network
OFAC designated Iranian digital asset exchange BitBank, its software developer Pishtaz Simorgh and associated Zanjani-network individuals, alleging BitBank helped transfer hundreds of millions of dollars worth of Bitcoin to the IRGC and enabled Iranian sanctions-evasion infrastructure.
United States / Iran sanctions
U.S. Department of the Treasury / OFAC
Crypto exchange / sanctions evasion / illicit finance infrastructure
high confidence
OFAC sanctionsSDN blocking consequenceIran sanctions evasionIRGC financing allegationdigital asset exchange infrastructuresecondary sanctions exposureBTC flow tracingsoftware developer designation
BitBank is included as Tier 1 because Treasury/OFAC confirmed a designation with direct blocking consequences and detailed allegations of digital asset infrastructure supporting Iranian sanctions evasion and IRGC-linked Bitcoin transfers.
Listing post-mortem use: Use when reviewing tokens or venues with Middle East liquidity, Iranian user flow, OTC bridge exposure or unexplained BTC treasury flows: check OFAC screening coverage, counterparty ownership, software-vendor exposure and secondary-sanctions controls.
Source
2026-09-17
Tier 2
Nostra Finance Starknet money market
Nostra Finance paused lending, borrowing, withdrawals and liquidations after a manipulated NSTR oracle price reportedly allowed one account to borrow approximately USD 3.5 million in liquid assets against inflated collateral.
Global / DeFi / Starknet
Nostra Finance official X statement / PeckShield and CertiK monitoring
DeFi lending / Starknet money market / oracle risk
medium-high confidence
oracle manipulationprotocol pauselending market bad debtthin collateral marketStarknet DeFiwithdrawal suspensionfund tracingphishing follow-on risk
The Nostra/NSTR incident is included as Tier 2 because the protocol disclosed a money-market pause and media/security firms corroborated a specific oracle-manipulation loss estimate, but the final post-mortem and recovery outcome remain pending.
Listing post-mortem use: Use when reviewing Starknet or DeFi lending assets: check collateral concentration, oracle source and fallback design, market-cap-to-borrow-limit ratios, pause authority, bad-debt socialization and phishing-response communications.
Source
2026-09-17
Tier 1
Suspected illegal peer-to-peer crypto trading businesses in London
The FCA, HMRC and Metropolitan Police targeted three London premises suspected of illegal peer-to-peer crypto trading and issued cease-and-desist letters requiring traders to stop suspected illegal crypto businesses.
United Kingdom
Financial Conduct Authority / HMRC / Metropolitan Police Service
P2P crypto trading / AML registration / illicit finance
high confidence
cease-and-desistunregistered crypto businesspeer-to-peer tradingAML/KYT red flagmoney laundering routepremises disruptioncriminal investigation support
The FCA action is included as Tier 1 because it is an official regulator-led operation with direct cease-and-desist consequences against suspected illegal crypto trading premises and a clear AML risk vector.
Listing post-mortem use: Use when reviewing UK retail flow, OTC/P2P liquidity claims, market-maker sourcing, fiat on/off-ramp quality and AML controls behind tokens with heavy London or UK P2P distribution.
Source
2026-09-17
Tier 3
U.S. crypto asset transaction and market rulemaking
Reginfo.gov shows OIRA received CFTC RIN 3038-AF80, Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets, on September 17, 2026 at prerule stage, creating a formal rulemaking path after congressional market-structure legislation stalled.
United States
Commodity Futures Trading Commission / Office of Information and Regulatory Affairs
Crypto market structure / CFTC rulemaking / exchange compliance
high confidence
jurisdiction risk shiftmarket-structure rulemakingCFTC oversight expansionspot market compliance uncertaintyOIRA reviewfuture exchange obligationslegislative fallback risk
The CFTC/OIRA record is included as Tier 3 because it is an official early-stage jurisdiction-risk movement rather than an enforcement action, but it creates a structured monitoring row for U.S. market-structure compliance risk.
Listing post-mortem use: Use in listing post-mortems to test whether U.S. liquidity projections assumed no federal spot-market rulemaking, and whether market makers or exchanges can absorb CFTC market-structure compliance duties.
Source
2026-09-16
Tier 2
Flamingo Finance old Flamincome contracts
Security-monitoring and media reports said an attacker used roughly USD 18 million in USDT flash loans to manipulate old Flamincome contract share pricing and extract about USD 345,900 in profit from Flamingo Finance-related contracts.
Global / DeFi
Blockaid monitoring / public security reporting
DeFi yield vault / legacy contracts / flash-loan exploit
medium confidence
protocol exploitflash-loan manipulationlegacy contract exposureshare-price inflationyield-vault accounting riskUSDT losssecurity-monitoring alert
The Flamingo/Flamincome signal is included as Tier 2 because multiple fresh sources cite a named exploit pattern, assets and loss estimate, but this run did not locate an official protocol incident page.
Listing post-mortem use: Use when reviewing DeFi assets with migrated or legacy yield contracts: verify whether old vaults remain callable, whether share-price math can be flash-loan manipulated, and whether monitoring covers dormant integrations.
Source
2026-09-16
Tier 3
UK-facing crypto firms under the future cryptoasset regime
The FCA published guidance on the UK future cryptoasset regime and confirmed that authorisation applications open on 30 September 2026, with the regime taking effect on 25 October 2027 across stablecoin issuance, trading platforms, dealing, custody and staking arrangements.
United Kingdom
Financial Conduct Authority
Cryptoasset regulation / CASP authorisation / stablecoins / custody / staking
high confidence
authorisation gatewayjurisdiction risk shiftstablecoin perimetertrading platform authorisationcustody authorisationstaking perimeterregulatory preparation deadline
The FCA guidance is included as Tier 3 because it is not an enforcement action, but it is an official jurisdiction-risk shift that makes UK authorisation readiness a concrete longitudinal listing and market-access variable.
Listing post-mortem use: Use in post-mortems to test whether listed tokens depended on UK-facing venues, stablecoin issuance, custody, staking or dealing services that may require FCA authorisation after the gateway opens.
Source
2026-09-15
Tier 2
Balancer protocol
Reputable crypto media reported a Balancer proposal to wind down the protocol and return more than USD 9 million in treasury assets to BAL holders after revenue failed to recover following the roughly USD 128 million Balancer v2 exploit.
Global / DeFi governance
Balancer governance contributors
DeFi AMM / DAO governance / protocol treasury
medium-high confidence
protocol wind-downpost-exploit revenue collapseDAO treasury distributionliquidity migrationbug bounty terminationwithdrawal-only pool transitiongovernance vote risk
Balancer is included as Tier 2 because multiple fresh reputable reports describe a specific wind-down proposal with dated vote mechanics and direct implications for BAL holders, LPs and integrated DeFi venues, but the vote is not yet final.
Listing post-mortem use: Use when reviewing DeFi listings to ask whether post-exploit revenue, treasury runway, active contributors, bug bounty coverage and withdrawal-only transition plans can support ongoing market quality.
Source
2026-09-15
Tier 1
CoinEx
CoinEx announced an orderly cessation of operations, citing market downturn, contracted trading volume and liquidity, rising regulatory requirements, compliance costs and operational uncertainty, with services winding down from September 15 and withdrawals ending December 22, 2026.
HK / Global
CoinEx
Centralized exchange / exchange token / exchange chain
high confidence
exchange shutdownmarket-access lossliquidity contractionregulatory cost pressurewithdrawal deadlinefutures reduce-only modespot trading cessationexchange-chain shutdown
CoinEx is included because the exchange itself confirmed a full operational wind-down with dated service closures, user withdrawal deadlines and exchange-ecosystem shutdowns, creating direct market-access and liquidity consequences.
Listing post-mortem use: Use when reviewing assets primarily reliant on CoinEx liquidity, CET-linked incentives, CoinEx Smart Chain exposure, exchange-native DEX liquidity, or venues where shrinking volume plus regulatory-cost pressure can convert into forced wind-down risk.
Source
2026-09-15
Tier 1
Iranian military black-market oil-sale cryptocurrency proceeds
The U.S. Attorney for SDNY filed a civil forfeiture complaint against approximately USD 61 million in cryptocurrency alleged to be proceeds of sanctioned Iranian crude oil and petroleum sales intended to support the Iranian government and IRGC.
US / Iran sanctions
U.S. Department of Justice / SDNY / FBI
Sanctions evasion / illicit finance / crypto asset forfeiture
high confidence
sanctions evasioncivil forfeitureIran exposureIRGC financingillicit oil proceedsasset seizureAML/KYT tracing
The DOJ forfeiture complaint is included because it is an official judicial action targeting a specific crypto asset pool with direct adverse consequence and sanctions-linked illicit-finance allegations.
Listing post-mortem use: Use as sanctions-flow context when reviewing tokens or venues with high Iran-linked routing, OTC settlement exposure, energy-trade payment narratives, or weak wallet-cluster screening.
Source
2026-09-15
Tier 1
Former Robinhood Crypto engineers / Hyperliquid perpetual markets
Federal prosecutors charged two former Robinhood employees with fraud over allegedly misappropriating confidential Robinhood Crypto token-listing information and trading related Hyperliquid perpetuals ahead of public listing announcements.
US
U.S. Department of Justice / SDNY
Centralized exchange listings / derivatives / market integrity
high confidence
listing front-runningconfidential information misusemarket integrityemployee misconductperpetual futures abuseexchange listing controlsinsider trading analogue
The case is included because an official DOJ criminal action alleges misuse of crypto listing information with direct market-integrity implications for token listings and perpetual derivatives surveillance.
Listing post-mortem use: Use for listing post-mortems to compare pre-announcement derivatives positioning, employee access logs, information barriers, market-maker communications and abnormal open-interest changes before listings.
Source
2026-09-13
Tier 1
Chainflip TRON USDT integration
Chainflip disclosed that an attacker abused TRON transaction memo handling to trigger duplicate payouts from the same deposit, taking 736,442.17 USDT across six unauthorized payouts and leaving the network paused while a fix and restart plan were finalized.
Global / cross-chain DeFi
Chainflip protocol team
Cross-chain swaps / protocol vaults / stablecoin routing
high confidence
protocol exploitTRON memo parsing flawduplicate payout logicnetwork pausevault lossuser reimbursement exposurestablecoin route containment
Chainflip is included as Tier 1 because the project confirmed a protocol exploit with direct vault loss, network pause, promised reimbursement and a still-pending technical restart/report, creating a concrete adverse consequence for cross-chain stablecoin routing.
Listing post-mortem use: Use when reviewing cross-chain swap or bridge listings: test chain-specific memo parsing, idempotency of deposit processing, refund logic, validator signature replay assumptions, emergency pause coverage and public reimbursement mechanics.
Source
2026-09-12
Tier 2
Celsius Network bankruptcy estate / BitMEX entities
Celsius Network's bankruptcy estate sued five BitMEX entities seeking return of 6,360 BTC, valued around USD 495 million, over alleged fraud, market manipulation and wrongful liquidations during the March 2020 Covid crash.
United States / SDNY Bankruptcy Court
U.S. Bankruptcy Court for the Southern District of New York / Celsius litigation administrator
Bankruptcy litigation / crypto derivatives exchange / liquidation risk
medium-high confidence
bankruptcy estate litigationforced liquidation disputemarket manipulation allegationexchange wind-down timingBTC collateral claiminsurance fund conflict allegationderivatives venue continuity
The Celsius-BitMEX suit is included as Tier 2 because a court pleading and reputable reporting identify named entities, a specific 6,360 BTC claim and exchange-liquidation risk, but the allegations are not adjudicated.
Listing post-mortem use: Use when reviewing assets whose liquidity or liquidation cascades depended on BitMEX derivatives: examine liquidation-engine design, insurance fund incentives, venue wind-down timing, and estate recovery claims.
Source
2026-09-11
Tier 1
Symbiosis BridgeV2 and syBTC
Symbiosis disclosed an active incident after signed BridgeV2 transactions were reportedly used to mint massive unbacked syBTC supply across BNB Chain and Ethereum, with illicit syBTC sold for about 4.39 WBTC and non-BTC routes stated as unaffected.
Global / cross-chain DeFi
Symbiosis protocol team / on-chain security monitors
Cross-chain bridge / synthetic BTC / DeFi liquidity
high confidence
bridge exploitunbacked synthetic asset mintwrapped BTC peg riskDEX liquidity contaminationcross-chain message validationincident response opacity
Symbiosis is included as a Tier 1 protocol-action row because the event combines an acknowledged bridge incident, synthetic BTC supply integrity failure, DEX sale of illicitly minted assets and direct adverse consequence for wrapped BTC market trust.
Listing post-mortem use: Use when reviewing wrapped BTC, bridge tokens and DEX pools: test mint authority, bridge transaction signing, emergency pause coverage, token reserve proof, and secondary-market containment after unauthorized minting.
Source
2026-09-10
Tier 1
Osmosis allBTC and Nomic nBTC bridge
Osmosis froze Nomic and allBTC inflows and outflows and paused allBTC minting/redemption after a Nomic forwarding flaw reportedly enabled false-voucher minting, leaving roughly 36% of allBTC backing impaired and 22.65 BTC frozen.
Global / Cosmos ecosystem
Osmosis protocol governance / moderator subDAO
Cross-chain bridge / synthetic BTC / DEX liquidity
high confidence
bridge exploitsynthetic asset undercollateralizationfund freezegovernance recapitalization riskredemption pauseCosmos IBC adjacent risk
Osmosis and Nomic are included as a Tier 1 protocol-action row because the event combines an exploit, partially impaired synthetic BTC backing, frozen funds and direct mint/redemption restrictions.
Listing post-mortem use: Use when reviewing tokens or pools with wrapped-BTC liquidity: test reserve composition, bridge validation, pause authority, redemption availability and governance recapitalization assumptions.
Source
2026-09-10
Tier 1
Pax Dollar on Binance
Binance announced phased removal of USDP services, ending spot trading on September 24 and deposits on September 25, with withdrawals only available until November 24.
Global
Binance
Stablecoin / centralized exchange market access
high confidence
exchange delistingstablecoin market accesswithdrawal deadlineforced service wind-downpossible balance conversionliquidity loss
Binance USDP is included because the exchange set a confirmed service wind-down and spot delisting schedule with direct user consequences, even though the issuer says USDP remains redeemable.
Listing post-mortem use: Use when reviewing stablecoins or payment tokens whose exchange liquidity depends on a single major venue; separate issuer solvency from exchange service-removal and withdrawal-deadline risk.
Source
2026-09-10
Tier 2
TransparentBusiness Inc. / Unicoin v. Universal Navigation Inc. / Uniswap Labs
Unicoin sued Uniswap Labs seeking declarations of non-infringement and cancellation of Uniswap-linked UNI trademark registration after demand letters alleging trademark infringement, dilution, cybersquatting and unfair competition.
United States / New York
U.S. District Court for the Southern District of New York
DeFi / token brand and market access litigation
medium-high confidence
trademark litigationtoken ticker confusiondomain disputebrand enforcementpre-launch legal overhangDEX reputational risk
The Unicoin-Uniswap dispute is included as Tier 2 because it is a credible court-linked legal-risk signal, but it is not a final judgment, enforcement action or exchange delisting.
Listing post-mortem use: Use when reviewing token launches with ticker/name similarity to established assets; check trademark disputes, domain control, exchange naming conventions and post-listing confusion.
Source
2026-09-10
Tier 3
Tokenized equities, DeFi-linked tokenization products, Polymarket and Kalshi
ESMA's second 2026 risk monitor identified tokenized equities, DeFi exploit channels and prediction markets as areas requiring continued monitoring, warning that pseudonymous trading can hinder detection of insider dealing, wash trades and coordinated manipulation.
European Union
European Securities and Markets Authority (ESMA)
Tokenized securities / prediction markets / DeFi market infrastructure
high confidence
jurisdiction risk shiftmarket integrityinsider trading surveillancewash tradingtokenized equity legal ownership gaporacle and settlement dispute risk
ESMA is included as Tier 3 because it is a regulator-published early-warning signal, not a project-specific enforcement action, but it materially sharpens longitudinal risk around tokenized securities and prediction markets.
Listing post-mortem use: Use as a sector watchlist input for tokenized equities, event contracts and DeFi collateral assets; check legal ownership transfer, surveillance controls, geofencing, oracle governance and manipulation monitoring.
Source
2026-09-10
Tier 3
Non-decentralized finance trading protocols under revised CLARITY Act draft
A revised CLARITY Act draft reportedly adds a category for non-decentralized finance trading protocols with control or material-change authority, requiring covered protocols to register with the CFTC if the bill advances.
United States
U.S. Senate / CFTC and Treasury implementation contemplated
DeFi trading protocols / market structure legislation
medium-high confidence
policy risk shiftDeFi control-person testCFTC registration exposuregovernance centralization riskinterface and upgrade authority scrutinymarket structure uncertainty
The CLARITY Act revision is included as Tier 3 because it is a policy-risk movement, not an enacted obligation, but it creates a clear watchlist vector for controlled DeFi trading protocols.
Listing post-mortem use: Use when reviewing DeFi tokens: map who can alter protocol functions, operate interfaces, control fees or pause markets, and treat governance centralization as a forward regulatory-risk factor.
Source
2026-09-10
Tier 2
Kalshi planned single-stock and ETF perpetual futures
Citadel Securities warned the SEC and CFTC that equity-linked perpetual futures could create a parallel shadow market and surveillance gaps if products linked to publicly traded companies sit outside securities-market oversight; Kalshi reportedly plans roughly 60 stock and ETF perps but has no announced approval.
United States
SEC / CFTC joint product-definition process; Citadel Securities comment letter
Prediction markets / regulated derivatives / equity-linked perpetuals
medium-high confidence
regulatory classification disputemarket surveillance gapinsider trading risktrading halt coordinationsingle-stock derivatives perimeterCME litigation over perps
Kalshi equity perps are included as Tier 2 because named products and entities face a documented regulatory objection and live litigation-adjacent risk, but no final prohibition or enforcement order has been issued.
Listing post-mortem use: Use when assessing prediction-market or perp platforms: separate approved crypto products from planned equity products, verify regulator jurisdiction, halt coordination, surveillance sharing and margin/liquidation design.
Source
2026-09-09
Tier 1
WEEX, BloFin, Rezorex, Bitunix, DigiFinex, Toobit, XT.com, LATOKEN, WOO X, Pionex, ChangeNow, SimpleSwap, FixedFloat, WhiteBIT and Guardarian
FIU-IND reportedly issued PMLA non-compliance notices to 15 offshore crypto platforms serving Indian users without registration and sought app and URL takedown action.
India
Financial Intelligence Unit-India
Offshore VASP / exchange / swap service AML
medium-high confidence
AML registration failureoffshore VASP access restrictionapp takedownURL blockingIndia market-access riskPMLA compliance
The India FIU notice group is included because it names specific offshore VASPs, states an AML/PMLA risk vector, and carries direct market-access consequences through app and URL takedown requests.
Listing post-mortem use: Use when reviewing listings that rely on offshore venue liquidity or Indian retail flow; check whether named venues provided real accessible liquidity after regulatory blocking pressure.
Source
2026-09-08
Tier 1
Hemi / HEMI Genesis Drop claim contract
Hemi confirmed a Genesis Drop MerkleBox reentrancy exploit draining roughly 124.5 million unclaimed HEMI, while Upbit canceled HEMI trading minutes before launch and Bithumb reportedly placed HEMI under an investment warning after abnormal Genesis Drop withdrawals.
KR / Global
Hemi protocol team; Upbit; Bithumb
Bitcoin-secured L2 / token distribution / centralized exchange listings
high confidence
smart-contract exploitreentrancytoken-distribution claim contractpre-listing security failureexchange listing cancellationinvestment warningcross-chain exfiltrationDEX liquidity impact
Hemi becomes a structured negative-intelligence row because the project itself confirmed a 124.5M HEMI Genesis Drop exploit and Korean exchange venues reacted with direct market-access consequences, including Upbit cancellation and reported Bithumb warning status.
Listing post-mortem use: Use as a Tier 1 precedent for exchange listing post-mortems where the token did not fail after listing but was canceled at the gate because a pre-launch contract exploit altered supply, liquidity, disclosure, and investor-protection assumptions.
Source
2026-09-08
Tier 1
Malone Lam / international crypto theft and laundering network
The DOJ announced that Singaporean national Malone Lam pleaded guilty in Washington, D.C. to participating in a RICO conspiracy tied to more than USD 245 million in cryptocurrency theft and laundering.
US
U.S. Department of Justice / U.S. Attorney for the District of Columbia / FBI / IRS Criminal Investigation
Crypto cybercrime / social engineering / laundering infrastructure
high confidence
criminal prosecutionguilty pleaRICO conspiracysocial engineeringaccount takeoverphysical home intrusion riskcrypto launderinghigh-net-worth holder targeting
Malone Lam is included as a Tier 1 negative-intel row because DOJ records a guilty plea in a USD 245M cryptocurrency racketeering and laundering case, giving the database a confirmed prosecution signal for large-scale social-engineering theft infrastructure.
Listing post-mortem use: Use as Tier 1 law-enforcement context when reviewing tokens, venues, or counterparties with unusual wallet-drain patterns, mixer flows, pass-through wallets, OTC cash-out rails, or high-value account-takeover exposure.
Source
2026-09-07
Tier 1
amazon-forex.com; novatradecore.com; vall-fin.com; daoroyal.com; seamanfx.com; newfuturevip.com; trademarketcup.com; fxtrade.app; capitaldealhub.com/AI_app_es; digiteamagency.com/second-income/
CySEC reportedly warned that nine online trading and crypto platforms were not authorised to provide investment services or crypto-asset services under Cyprus law and MiCA Article 59.
CY / EU
Cyprus Securities and Exchange Commission
Unauthorised online trading and crypto-asset service platforms
medium-high confidence
unauthorised CASPinvestor warningMiCA compliance gapfake trading platformEU passporting riskconsumer harm
The CySEC warning is a direct adverse regulator signal for named unauthorised online trading and crypto-service domains in the EU market.
Listing post-mortem use: Use as a regulator-warning comparable for due diligence on EU-facing projects using broker-like websites, mobile apps, or crypto-service language without visible CASP authorisation.
Source
2026-09-07
Tier 1
Cozy Finance v2 protection markets on Optimism
Cozy Finance acknowledged an exploit affecting v2 protection markets on Optimism, with funds drained from the Cozy v2 Main Set and Rabbithole Set while the protocol investigated with security partners.
Global / Optimism
Cozy Finance protocol team
DeFi insurance / protection markets / Optimism
high confidence
protocol exploitDeFi insurance market drainOptimism deployment riskbridge-out fund movementrecurring protocol security failureunverified contract riskcoverage-market liquidity loss
Cozy Finance becomes a structured negative-intelligence entry because the protocol itself confirmed an Optimism v2 protection-market exploit with drained funds, creating direct user-loss and recurring-security risk signals.
Listing post-mortem use: Use as a Tier 1 comparable for listed DeFi insurance, coverage, oracle-dependent, or Optimism-native protocols when reviewing repeated exploit history, TVL concentration, and incident disclosure speed.
Source
2026-09-07
Tier 1
BONK trading pairs on Upbit
Upbit ended BONK trading support for BONK/KRW and BONK/USDT at 15:00 KST on September 7, citing unresolved security incident and disclosure concerns after a prior cautionary designation.
KR
Upbit
Meme token / Solana ecosystem / centralized exchange listing
high confidence
exchange delistingsecurity incident disclosureKorea market-access lossopen-order cancellationwithdrawal-only periodmeme-token governance transparency
Upbit’s official BONK delisting is a direct adverse exchange action with immediate trading loss in Korea and clear security/disclosure risk vectors.
Listing post-mortem use: Use in listing reviews to test whether cautionary asset designations, security incident remediation, and exchange-by-exchange disclosure standards were tracked before market-access assumptions were made.
Source
2026-09-07
Tier 1
Fake crypto investment platform network operated from Kyiv region
Ukrainian authorities dismantled a fake investment-platform network that allegedly used hidden crypto drainers to steal wallet assets from victims in more than 20 countries, with SBU citing monthly illegal turnover up to USD 1M.
UA / EU victims
National Police of Ukraine; Security Service of Ukraine; Office of the Prosecutor General
Scam infrastructure / wallet drainer / fake exchange and investment platforms
high confidence
wallet drainerfake investment platformorganized cybercrimecross-border victimsidentity data theftserver infrastructure seizureTelegram victim acquisition
The Ukraine takedown adds a structured law-enforcement record for wallet-drainer investment scams spanning more than 20 victim jurisdictions.
Listing post-mortem use: Use as scam-infrastructure context when reviewing tokens, wallets, or exchanges that appeared in fake-platform funnels, wallet-drainer approvals, or Telegram investment campaigns.
Source
2026-09-06
Tier 1
Liquid Network federation wallet
Liquid Network reportedly halted new transaction activity after actors claiming to be white-hat hackers withdrew roughly 4,000 BTC, about USD 320M, from the federation wallet backing the Bitcoin sidechain.
Global / Bitcoin sidechain
Liquid Network / Blockstream federation members
Bitcoin sidechain / exchange settlement / cross-chain bridge infrastructure
high confidence
bridge exploitfederation wallet compromisenetwork haltexchange settlement disruptionwrapped-BTC backing riskincident-response dependencycross-chain custody concentration
A reported 4,000 BTC federation-wallet withdrawal and network halt make Liquid Network a high-severity negative-intelligence record for bridge custody, wrapped-asset backing, and exchange settlement risk.
Listing post-mortem use: Use as a Tier 1 comparable when reviewing bridge, wrapped-asset, Bitcoin L2, and exchange-settlement projects where listing diligence relied on federation custody or peg security assumptions.
Source
2026-09-05
Tier 2
Router Protocol
Router Protocol reportedly announced that it will cease operations by September 30, 2026, burn 303.3M treasury ROUTE, shut Router Nitro and the app, and coordinate with centralized exchanges to remove ROUTE trading pairs.
Global
Router Protocol team
Cross-chain bridge / interoperability infrastructure
medium-high confidence
protocol shutdownbridge service winddownplanned exchange delistingtoken utility collapsefailed commercializationwithdrawal deadlinecross-chain infrastructure viability
Router Protocol’s reported wind-down is a high-confidence adverse signal for bridge-sector viability and ROUTE listing support, but remains Tier 2 because direct official-source capture was incomplete.
Listing post-mortem use: Use in listing post-mortems to test whether bridge usage, revenue sustainability, treasury concentration, and delisting coordination risk were monitored before ROUTE market support continued.
Source
2026-09-04
Tier 2
Binance Monitoring Tag for AVA, GNS, SCR and TOWNS; Binance Alpha removals for MTP, BDXN, TALE, BOS, MAIGA, TIMI, SAROS, U, SERAPH, RVV, AIAV, PENGUIN, ODOS and SN3
Binance added AVA, GNS, SCR and TOWNS to its Monitoring Tag list, placing them under closer review and higher-risk user warnings, while Binance Alpha separately removed fourteen early-stage tokens from its recommended list after review because they did not meet Alpha standards; withdrawals and selling remained available for Alpha assets.
Global / Binance venues
Binance exchange listing review and Binance Alpha review process
Centralized exchange listings / early-stage token discovery / market-access friction
medium-high confidence
exchange monitoring tagdelisting watchlistlisting standards reviewAlpha recommendation removalearly-stage token liquidity riskrisk-warning quiz requirementmarket-access frictionthin-liquidity sell pressurepost-listing standards failure
Included as Tier 2 because the signal is a named exchange review action with clear market-access friction across 18 assets, but confidence is medium-high rather than high because direct Binance announcement text was not fetched successfully and Alpha removal is less severe than spot delisting.
Listing post-mortem use: Use in exchange listing post-mortems to test whether monitoring tags or Alpha removals preceded liquidity decay, market-maker withdrawal, retail risk warnings, venue migration or later full delisting events.
Source
2026-09-04
Tier 2
Notional Finance escrow contract
PeckShield cited Specter findings that a Notional Finance escrow contract may have been exploited for about USD 1.7M in DAI and USDC, with the suspected attacker swapping funds into 689.2 ETH and depositing them into Tornado Cash; Notional had not publicly confirmed the incident when checked.
Global / Ethereum DeFi
PeckShieldAlert and Specter blockchain investigation reporting; Notional Finance official confirmation not found during collection
DeFi lending / escrow contracts / fixed-rate credit markets
medium-high confidence
suspected DeFi exploitescrow contract lossstablecoin drainTornado Cash laundering pathunconfirmed technical causeprotocol disclosure gapfixed-rate lending infrastructure risk
Included as Tier 2 because the signal is named, financially material and corroborated by security-investigator reporting, but it remains a suspected exploit without direct Notional confirmation or final root-cause disclosure.
Listing post-mortem use: Use when reviewing DeFi lending token or protocol listings that depend on escrow contracts, wrapped fixed-rate instruments, or stablecoin credit markets; check whether auxiliary contracts were included in security diligence and real-time monitoring.
Source
2026-09-03
Tier 2
CME Group challenge to CFTC treatment of Kalshi and Coinbase crypto perpetual products
The CFTC moved to dismiss CME Group's federal lawsuit challenging the agency's treatment of Kalshi crypto perpetual contracts and related Coinbase relief, arguing CME lacks standing while CME maintains the products should be treated as swaps rather than conventional futures.
United States
U.S. Commodity Futures Trading Commission; U.S. District Court for the District of Columbia
Regulated crypto derivatives / prediction-market exchange infrastructure / perpetual futures
high confidence
derivatives classification disputeCFTC litigationregulated crypto perpetual market-access riskstanding challengeswap versus futures perimeterKalshi product expansion during lawsuitCoinbase derivatives relief scrutiny
Included as Tier 2 because the event is a current, court-linked regulatory litigation signal with named entities and a clear market-access risk vector, but it is not a final judicial ruling or enforcement action.
Listing post-mortem use: Use when reviewing tokens whose U.S. liquidity or institutional access depends on regulated perpetual products; test whether derivatives classification litigation, leverage limits, margin design and exchange listing sequence affected post-listing market quality.
Source
2026-09-03
Tier 2
GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol and Hyperliquid named in Connecticut offshore DeFi warning
Connecticut Attorney General William Tong issued a consumer alert warning that unregulated offshore DeFi exchanges, including GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol and Hyperliquid, operate outside U.S. safeguards; the alert cited at least one Connecticut consumer unable to recover USD 200,000 deposited into an unregulated DeFi exchange after deceptive solicitation.
US / Connecticut
Connecticut Attorney General William Tong; Connecticut Department of Banking Commissioner Jorge Perez
DeFi perpetuals / offshore exchange access / consumer protection / AML and sanctions risk
high confidence
official consumer warningoffshore DeFi exchange riskperpetuals market accesspredatory leveragelimited recovery rightsKYC gapAML and sanctions exposureVPN bypass of U.S. restrictionssynthetic stock exposurecentralized control in claimed DeFi venues
Included as Tier 2 because the signal is an official state consumer alert with named platforms, jurisdiction, risk vectors and a concrete consumer-loss example, but it is not a final enforcement action and does not accuse the named venues of handling the loss.
Listing post-mortem use: Use when reviewing token listings tied to offshore perps venues, DeFi exchange governance tokens or synthetic asset platforms: test U.S. user access controls, KYC posture, leverage design, withdrawal discretion and prior FCA/MAS/state warning history.
Source
2026-09-02
Tier 2
YAM Finance
Defimon reported that an attacker self-delegated about 504,000 YAM, roughly 3.3% of supply and just above quorum, then submitted YamGovernorAlpha proposal #45 with an empty description to make an attacker-controlled address pending admin of the YAM Timelock, putting roughly USD 337,000 in protocol and DAO assets at risk unless holders vote it down.
Global / Ethereum DeFi governance
Defimon Alerts / Decurity on-chain monitoring; YAM governance contracts
DeFi governance / DAO treasury / legacy protocol administration
medium-high confidence
governance takeover attemptlow-turnout DAO quorum risktimelock admin transfertreasury control riskself-delegated voting powerlegacy protocol governanceproposal payload opacityon-chain monitoring alert
Included as Tier 2 because the signal is named, current, technically specific and financially material, but it remained an attempted governance takeover rather than a completed loss or official protocol shutdown at the time of review.
Listing post-mortem use: Use when reviewing governance-token listings to test whether quorum concentration, idle delegates, admin transfer functions and proposal review windows were assessed before exchange support or market-maker activity.
Source
2026-09-02
Tier 2
Tether / disputed 42.4M USDT freeze involving Thai plaintiffs
Two Thai businessmen sued Tether in the Southern District of New York, alleging Tether blacklisted ten Ethereum addresses holding about 42.4M USDT after an informal HSI request and before a warrant or court order; the complaint challenges whether a private stablecoin issuer can freeze, burn, and reissue secondary-market tokens before final judicial authorization.
US / New York federal court; related North Carolina seizure warrant
U.S. District Court for the Southern District of New York; Homeland Security Investigations; U.S. Attorney EDNC; Tether blacklist controls
Stablecoins / issuer blacklisting / law-enforcement asset recovery / fraud proceeds tracing
high confidence
stablecoin blacklist powerpre-warrant asset freeze disputelaw-enforcement request dependencyburn-and-reissue seizure mechanicspig-butchering fraud proceeds tracingsecondary-market holder rightsissuer reserve-income disgorgement claimcourt-supervised forfeiture uncertainty
Included as Tier 2 because it is a named, current, court-linked stablecoin adverse signal with a large frozen amount and clear legal-process risk vector, but it is not yet an adjudicated enforcement outcome or final issuer liability finding.
Listing post-mortem use: Use when reviewing listings or integrations that rely on freeze-capable stablecoins: test whether the venue disclosed blacklist dependencies, burn/reissue risk, law-enforcement escalation procedures, and customer remediation paths for disputed freezes.
Source
2026-09-01
Tier 2
Hyperliquid and HyperUnit routing used by Lazarus-linked wallets
Cointelegraph reported that wallets linked to the OFAC-sanctioned Lazarus Group moved USD 30M in digital assets through Hyperliquid and HyperUnit, sending BTC in, converting into ETH or SOL, bridging funds to Tron, Solana and Ethereum, and ultimately routing deposits to KuCoin, Kraken, LBank and unlabeled Tron-network services.
Global / United States sanctions exposure
Arkham analyst reporting; OFAC-sanctioned Lazarus Group attribution cited by Cointelegraph
DEX / perpetuals / bridge routing / AML and sanctions monitoring
medium-high confidence
OFAC-sanctioned actor exposureLazarus Group wallet flowDEX AML gapcross-chain bridge routingperpetuals venue reputational riskCEX off-ramp exposureNorth Korea-linked launderingregulated market access friction
Included as Tier 2 because the event is a credible named AML/sanctions signal with a clear risk vector and material flow size, but it is not yet a confirmed enforcement action against the venue.
Listing post-mortem use: Use in exchange listing and market-access post-mortems to evaluate whether HYPE or Hyperliquid-linked assets faced adverse diligence after sanctioned actor flow, bridge routing and CEX off-ramp visibility became public.
Source
2026-09-01
Tier 3
Crypto protocols affected by August 2026 hack cluster
PeckShieldAlert monthly data reported 50 major crypto hacks in August 2026, up 67% from 30 in July, with total losses of about USD 136.3M despite a 49.5% month-on-month fall in aggregate stolen value from July.
Global
PeckShieldAlert monthly security monitoring
Crypto security / DeFi exploits / protocol incident trend monitoring
medium-high confidence
hack frequency surgeDeFi exploit clusteringmonthly loss concentrationincident frequency versus severity divergenceprotocol-security monitoringlisting due-diligence riskcross-sector exploit comparables
The PeckShield August 2026 hack report is included as Tier 3 because it is a sector-level early-warning signal useful for longitudinal monitoring, while individual project records remain separate and require direct adverse structure.
Listing post-mortem use: Use as macro context in listing post-mortems to test whether an asset launched, listed, or expanded liquidity during a period of rising exploit frequency and whether security diligence tightened accordingly.
Source
2026-09-01
Tier 1
Hamas / Al Qassam Brigades crypto fundraising infrastructure
The U.S. Department of Justice announced court-authorized seizures that allowed the FBI to seize more than USD 560,000 in cryptocurrency donations destined for Hamas and disrupt domains, servers, fundraising channels and recruitment infrastructure used by Hamas and the Al Qassam Brigades.
United States / Global terrorist-financing networks
U.S. Department of Justice; FBI; U.S. District Court-authorized seizure process
Illicit finance / sanctions / terrorist financing / crypto fundraising infrastructure
high confidence
terrorist financingcourt-authorized crypto seizuresanctions exposurefundraising infrastructure disruptiondomain and server seizureillicit donation flowswallet attribution risklaw-enforcement asset recovery
Included as Tier 1 because DOJ confirmed a court-authorized cryptocurrency seizure and infrastructure disruption with a direct adverse consequence against named terrorist-financing infrastructure.
Listing post-mortem use: Use in listing and counterparty post-mortems to test whether an asset, issuer, market maker or venue had exposure to terrorism-financing wallets, donation infrastructure, or sanctioned-entity typologies before liquidity support was approved.
Source
2026-08-31
Tier 2
Legacy Balancer V1 BPool liquidity pool and forked BPool codebases
SlowMist-attributed reporting said an attacker drained roughly USD 234K from a Balancer V1-style pool by compressing WBTC reserves to dust and exploiting down-rounding in joinswapPoolAmountOut/calcSingleInGivenPoolOut so the pool minted 4,408.8 BPT for a one-satoshi input.
Global / Ethereum DeFi
SlowMist threat intelligence; Balancer legacy protocol context
DeFi AMM / legacy liquidity pools / forked protocol infrastructure
medium-high confidence
legacy DeFi exploitfixed-point rounding bugWBTC decimal mismatchsingle-sided join abuseflash loan reserve compressionimmutable contract riskunmaintained code exposureforked AMM blast radius
The Balancer V1 pool incident is included as Tier 2 because it is a credible, technically specific exploit with clear loss and address detail, but the adverse action is based on security-firm/media reporting rather than a fresh official Balancer response.
Listing post-mortem use: Use when reviewing listings that cite old DeFi liquidity depth: test whether liquidity was stranded in immutable legacy pools, forked BPool math, wrapped-asset decimals, or unmaintained contracts that could evaporate after exploit disclosure.
Source
2026-08-31
Tier 2
Float Protocol Hypervisor contracts
SlowMist reported that Float Protocol lost about USD 28K, or 10.71 ETH, after an attacker used flash-loan-funded swaps to manipulate a Uniswap V3 spot price and cause Hypervisor contracts to calculate inflated LP share values.
Global / Ethereum DeFi
SlowMist threat intelligence; Float Protocol context
DeFi liquidity management / Uniswap V3 strategy vaults / oracle design
medium-high confidence
flash loan attackUniswap V3 spot price manipulationslot0 reliancemissing TWAP validationmissing slippage protectionLP share mispricingstrategy vault accounting risksecurity-firm first disclosure
Float Protocol is included as Tier 2 because the signal is named, technically specific and security-firm attributed, but the run did not locate a direct protocol action or official postmortem that would support Tier 1 classification.
Listing post-mortem use: Use when reviewing tokens or protocols that depend on automated Uniswap V3 liquidity vaults: test whether LP-share pricing, TWAP design, flash-loan resistance and strategy-contract ownership were reviewed before liquidity support or listing.
Source
2026-08-31
Tier 2
More Markets lending protocol on Flow EVM
Blockaid reported an exploit on More Markets on Flow EVM in which an attacker used an Ankr bonded liquid-staking token and E-Mode to drain about 15.5M WFLOW from the mFlowWFLOW lending reserve, with an initial detected impact of roughly USD 9.3M.
Global / Flow EVM
Blockaid security monitoring; More Markets / More Labs context
DeFi lending / Flow EVM / liquid staking collateral
medium-high confidence
DeFi lending exploitreserve drainliquid staking collateral riskE-Mode leverage riskFlow EVM ecosystem exposurepost-exploit fund movementthird-party security alert before protocol postmortem
More Markets is included as Tier 2 rather than Tier 1 because the adverse signal is well-structured and security-firm attributed, but the run did not locate a direct More Markets official incident acknowledgement or protocol action.
Listing post-mortem use: Use in Flow ecosystem and DeFi lending post-mortems to test whether unsupported LST collateral, E-Mode configuration or prior Flow incident history should have triggered stricter exchange and market-maker diligence.
Source
2026-08-31
Tier 3
Upbit, Bithumb, Coinone, Korbit and Gopax altcoin listing practices
Seoul Economic Daily reported lawmaker-obtained data showing South Koreas five won-based exchanges listed 1,236 altcoins since 2022 and terminated trading support for 430, including 38 delisted less than one year after listing, increasing scrutiny of listing screening and investor-loss transfer.
South Korea
National Assembly National Policy Committee data request; Rep. Park Sung-hoon; Korean financial regulators referenced for follow-up
Centralized exchange listings / Korean won markets / retail investor protection
medium-high confidence
exchange delisting wavelisting-screening weaknessretail investor loss transferfee-war volume incentiveKorean won market access riskrapid post-listing support terminationregulatory investor-protection pressure
Korean won-market exchange delisting statistics are included as Tier 3 because they provide a structured jurisdiction-level early warning for listing-quality risk, even without a fresh enforcement order against a named exchange.
Listing post-mortem use: Use as a jurisdiction analogue when evaluating whether a Korean listing failed because initial exchange screening, fee-driven volume campaigns or weak investor-protection controls inflated early demand before rapid delisting.
Source
2026-08-30
Tier 1
Cronos Network and Tectonic lending protocol
Cronos validators halted block production on August 30 after Tectonic disclosed a security breach affecting the lending protocol; security reporting estimated roughly USD 75M in affected assets after a thin-liquidity TONIC collateral pump-and-borrow attack, while Tectonic warned users not to interact with the protocol until safe.
Global / Cronos ecosystem
Cronos Network validators; Tectonic Finance; Crypto.com security team
Layer 1 / DeFi lending / exchange-affiliated chain ecosystem
high confidence
chain haltDeFi lending exploitthin collateral manipulationTONIC price pumpbad debt riskvalidator interventionnetwork finality governance riskexchange-affiliated ecosystem contagion
Cronos/Tectonic is included as Tier 1 because a named lending protocol security breach produced a confirmed chain halt and direct user-interaction warning, with current security reporting estimating roughly USD 75M in affected assets.
Listing post-mortem use: Use when reviewing CRO, TONIC or Cronos ecosystem listings: test whether DeFi TVL dependency, thin collateral support, validator halt authority or unresolved bad debt preceded liquidity deterioration or exchange support changes.
Source
2026-08-29
Tier 1
Ajna v2 lending protocol on Ethereum
Ajna v2 suffered roughly USD 775K in losses across seven Ethereum pools after an apparent liquidation accounting exploit; the team publicly acknowledged unusual movements on August 29, asked users to withdraw quote tokens, repay loans and stop interacting with the protocol, while security coverage said the issue exploited internal liquidation primitives rather than an external oracle.
Global / Ethereum DeFi
Ajna team; Defimon and independent security researchers
DeFi lending / oracleless credit markets / immutable protocol security
medium-high confidence
DeFi lending exploitliquidation math vulnerabilityoracleless design riskimmutable protocol no-pause riskuser exit warningmissed early-warning alertpaired-collateral pool exposureTornado Cash-funded attacker preparation
Ajna v2 is included as Tier 1 because the team issued a direct user-exit warning after unusual movements and current security reporting identifies actual pool losses, making this a confirmed protocol-level adverse action.
Listing post-mortem use: Use when reviewing DeFi lending token or protocol listings that pitch immutability, no-governance, or oracleless design as a safety feature; test whether the same constraints limited incident response after exploit discovery.
Source
2026-08-29
Tier 1
Cosmos EVM module / MANTRA / TAC / KiiChain and other exposed chains
Fresh reporting on Cosmos Labs postmortem material said an accounting flaw in the Cosmos EVM module was exploited across six networks for roughly USD 5.72M, including MANTRA, TAC and KiiChain; Cosmos Labs contacted 40 networks, 13 potentially exposed chains patched, halted or mitigated, and accounts tied to centralized-exchange activity were reportedly frozen pending investigation.
Global / Cosmos ecosystem
Cosmos Labs; affected Cosmos EVM chains; centralized exchanges and relevant authorities for frozen attacker accounts
Layer 1 / shared EVM module / cross-chain infrastructure / ecosystem security
medium-high confidence
shared module vulnerabilitymulti-chain exploitemergency chain haltsilent patch disclosure failurecentralized exchange account freezesecurity triage failureecosystem blast-radius riskbridge and DEX exit routing
The Cosmos EVM event is included as Tier 1 because it combines a confirmed multi-chain exploit, emergency mitigation, reported frozen exchange accounts and a direct adverse consequence for multiple named networks.
Listing post-mortem use: Use when reviewing listings for Cosmos EVM assets, appchains, and shared-framework tokens: test whether liquidity relied on chains exposed to the vulnerable module, whether the exchange froze attacker accounts, and whether halted-chain history preceded listing deterioration.
Source
2026-08-29
Tier 1
Badger DAO and Storj on Coinbase
Coinbase said it will suspend trading for Badger DAO (BADGER) and Storj (STORJ) on September 28, 2026 at around 2 PM ET after its latest listed-asset review, moved the order books to limit-only mode, and said the suspension applies to Coinbase.com, Coinbase Exchange and Coinbase Prime while withdrawals remain available.
United States / Global Coinbase venues
Coinbase Markets / Coinbase Exchange listing standards review
Centralized exchange listings / DeFi DAO token / decentralized storage token
high confidence
exchange delistinglisting standards failureUS venue liquidity lossinstitutional access reductionlimit-only order book transitionpost-Chapter-11 listing riskasset review escalation
Coinbase BADGER/STORJ is included as Tier 1 because it is a confirmed exchange trading suspension with a direct adverse consequence for two named assets, even though it is not a regulator enforcement action.
Listing post-mortem use: Use in listing post-mortems to test whether Coinbase delisting preceded broader liquidity decay, market-maker withdrawal, treasury stress, US-access loss, or similar asset-review removals on other venues.
Source
2026-08-28
Tier 3
Dollar-backed stablecoin issuers and payment-scale stablecoin rails
BIS General Manager Pablo Hernandez de Cos said stablecoins do not provide a credible foundation for large-scale payments, highlighted weak singleness of money, interoperability and AML controls, warned of digital dollarization risks in emerging markets, and argued tokenized bank deposits are a stronger path for day-to-day payments.
Global / United States / emerging markets
Bank for International Settlements; Pablo Hernandez de Cos; Federal Reserve Jackson Hole Economic Policy Symposium context
Stablecoin payments / tokenized deposits / bank funding / monetary sovereignty
medium-high confidence
central-bank policy headwindpayment-scale credibility riskinteroperability weaknessAML controls challengedigital dollarization riskbank deposit displacementemerging-market monetary sovereignty pressuretokenized deposit competition
The BIS stablecoin warning is included as Tier 3 because it is a high-level sector risk movement, not a final adverse action against a named issuer, but it adds jurisdiction-radar value for stablecoin payment listings and emerging-market policy exposure.
Listing post-mortem use: Use when reviewing stablecoin-linked listings, payment-token partnerships, exchange stablecoin integrations, emerging-market distribution claims and whether a token narrative depends on adoption paths that central banks are explicitly resisting.
Source
2026-08-28
Tier 3
Nigerian digital asset exchanges, custodians, offering platforms and VASPs
Condia reported that Nigeria SEC draft digital-asset rules would require NGN 2 billion minimum capital for digital asset exchanges and custodians, NGN 500 million for platform operators and offering platforms, and NGN 200 million for VASPs, with at least one industry participant warning that the thresholds could shrink the Nigerian crypto market by half or more.
Nigeria
Nigeria Securities and Exchange Commission
Centralized exchange / custody / VASP licensing / emerging-market fiat rails
medium confidence
capital-threshold shocklicensing barrierexchange consolidation riskcustody authorization riskNGN market-access pressuresmall-operator exit riskemerging-market compliance coststablecoin and fiat-rail substitution risk
Nigeria SEC draft capital thresholds are included as Tier 3 because the signal is sector-level, single-source and not yet a final enforcement action, but it is structured enough to support jurisdiction radar and future listing-risk reviews for NGN-facing exchanges and VASPs.
Listing post-mortem use: Use when reviewing Nigerian listing access, NGN liquidity assumptions, local exchange survivability, fiat on/off-ramp resilience, custody partner selection and whether token distribution relied on platforms that may fail capital-threshold authorization tests.
Source
2026-08-27
Tier 1
Moonwell MAMO Core Market on Base
Moonwell said it was investigating an issue affecting the MAMO Core Market on Base and set borrow caps for all Base Core Markets to 1 wei, effectively blocking new borrowing; multiple security firms reported an approximately USD 8.7M to USD 9M exploit after MAMO price manipulation let the attacker borrow real assets against inflated collateral.
Global / Base ecosystem / United States market infrastructure exposure
Moonwell protocol emergency risk controls; CertiK, PeckShield and Blockaid security-firm analysis
DeFi lending / oracle risk / Base ecosystem / collateral-listing risk
medium-high confidence
oracle price manipulationilliquid collateral listing riskDeFi lending bad debtprotocol emergency borrowing freezeBase ecosystem exposurecbBTC liquidity drainUSDC and ETH asset draincross-chain fund consolidationgovernance asset collateral-risk reviewrepeat Moonwell oracle incident historylisting post-mortem collateral due diligence
Moonwell/MAMO is included as Tier 1 because the exploit produced a direct protocol action: Moonwell set Base Core Market borrow caps to 1 wei, effectively halting new borrowing, after security firms reported roughly USD 8.7M to USD 9M drained through MAMO collateral price manipulation. Confidence is medium-high until Moonwell publishes a final post-mortem and loss figure.
Listing post-mortem use: Use when reviewing whether a listed asset had adequate liquidity depth, oracle design, collateral caps, borrow caps, TWAP/circuit-breaker protections, prior incident history, and governance diligence before being admitted as lending collateral or exchange-supported collateral.
Source
2026-08-27
Tier 2
ZondaCrypto / Polish Olympic Committee sponsorship network / Radoslaw Piesiewicz
Polish prosecutors said the ZondaCrypto investigation had materially advanced and included possible crimes tied to financing political, media and sports-linked entities; fresh reporting said Polish Olympic Committee president Radoslaw Piesiewicz was detained on August 27 in the probe, including allegations around a EUR 40,000 watch and assistance with regulatory or sponsorship-related hurdles.
Poland / European Union
Polish National Prosecutor's Office; Polish police; Polish Justice Minister and Prosecutor General Waldemar Zurek
Centralized exchange / sponsorship governance / political exposure / market conduct / AML and fraud investigation
medium-high confidence
criminal investigationsuspected briberyfraud investigationmoney laundering allegationspolitically exposed person risksports sponsorship compliance riskcrypto exchange collapsecustomer fund-access failureregulatory capture concernmarket-access lobbying riskEU reputational risk
ZondaCrypto/PKOl is included as Tier 2 because the signal names a crypto exchange, jurisdiction, implicated public figure and clear bribery/fraud/AML vectors, with an official prosecutor statement plus fresh detention reporting. It is not Tier 1 for the database because final charges, liability findings and court outcomes were not yet public during this run.
Listing post-mortem use: Use when reviewing listings, sponsorships or exchange partnerships where a venue relied on political relationships, sports sponsorship, regulatory lobbying, PEP connections, or promotional crypto payouts rather than transparent customer-asset controls and licensing resilience.
Source
2026-08-26
Tier 2
Kraken customer accounts receiving unsolicited HTX-linked dust transfers
Fresh reporting said nearly 12,000 unsolicited small crypto transfers reached Kraken-linked addresses between August 17 and August 24, 2026, with the sending wallet attributed by Arkham Intelligence to HTX-associated addresses; Kraken temporarily restricted affected customer accounts during compliance review, later restored account access while segregating disputed funds, and described the pattern as an apparent attempt to spread UK- and EU-sanctioned funds to other platforms while HTX denied initiating the transfers.
Global / European Union / United Kingdom / United States
Kraken compliance controls; EU and UK sanctions context for HTX / Huobi Global; Arkham Intelligence wallet attribution disputed by HTX
Centralized exchange compliance / sanctions screening / KYT / customer account access
medium-high confidence
compliance poisoningsanctions-linked dust transferKYT false-positive and taint propagationcustomer account freezesegregated disputed fundsEU crypto sanctions implementationUK Russia-sanctions designation contextwallet-label attribution disputeexchange-to-exchange contamination riskunsolicited deposit operational riskautomated screening overload
Kraken/HTX dust-transfer compliance poisoning is included as Tier 2 because it names exchanges, jurisdictions and risk vectors, and produced a direct adverse customer-access consequence through temporary Kraken account restrictions. It is not Tier 1 because no final regulator, court or exchange enforcement action against HTX or Kraken was verified, attribution remains disputed, and the primary accessible evidence is reputable media citing Bloomberg, Kraken spokesperson context, Arkham labels and HTX denial rather than a direct official Kraken incident notice.
Listing post-mortem use: Use when reviewing exchange listings or market-maker arrangements where deposit addresses, omnibus wallets, sanctioned-entity exposure, low-value dust transfers, and KYT escalation rules can create account freezes or liquidity disruption even without direct issuer wrongdoing.
Source
2026-08-24
Tier 1
Iran-linked digital assets sector and Mabna Institute crypto addresses
Treasury launched Operation Economic Outcast on August 24, 2026, issued a sectoral sanctions determination covering Iran's digital assets sector, and OFAC sanctioned nearly 60 Iran-linked targets; TRM reported that OFAC listed 30 Bitcoin, Ethereum and TRON addresses tied to Mabna Institute defendants with about USD 16.8M in historical inflows.
United States / Iran / Global
U.S. Department of the Treasury / OFAC; DOJ Mabna Institute indictment context; TRM Labs on-chain analysis
Sanctions / illicit finance / exchange AML / cybercrime proceeds / jurisdiction risk
high confidence
OFAC sanctionssectoral sanctions determinationsecondary sanctions exposureIran digital asset sector risklisted crypto addressesMabna Institute cybercrime proceedsexchange screening obligationshistorical exposure reviewTRON and Ethereum illicit-flow riskcentralized exchange cashout riskjurisdiction risk shift
Operation Economic Outcast is Tier 1 because Treasury and OFAC took a confirmed sanctions action with direct adverse consequences for digital asset businesses: the Iranian digital assets sector was named in a sanctions determination, nearly 60 Iran-linked targets were designated, and listed Mabna Institute crypto addresses created immediate wallet-screening and secondary-sanctions risk.
Listing post-mortem use: Use to test whether a listed asset, market maker, bridge, OTC desk or exchange venue had Iranian digital-assets-sector exposure, OFAC-listed address proximity, or deficient sanctions controls before listing or liquidity support.
Source
2026-08-24
Tier 1
Profit Connect / Brent C. Kovar
Fresh local and crypto-media reporting citing the Nevada U.S. Attorney's Office said a federal jury convicted Brent C. Kovar on 15 counts tied to Profit Connect, a USD 24M crypto Ponzi scheme that promised 15%-30% annual returns, claimed AI cryptocurrency mining and false FDIC insurance, and defrauded at least 400 investors.
United States / Nevada
U.S. Attorney's Office for the District of Nevada; federal jury; FBI; IRS Criminal Investigation; FDIC Office of Inspector General
Crypto investment fraud / mining claims / AI-branded crypto scheme / criminal prosecution
medium-high confidence
criminal convictionwire fraudmail fraudmoney launderingcrypto Ponzi schemefake AI mining claimsfalse FDIC insurance claimsguaranteed yield marketinginvestor fund misusesentencing pendingretail investor harm
Profit Connect is included as Tier 1 because the reported federal jury conviction is a confirmed judicial adverse action with direct consequences for the operator and a named crypto investment product. Confidence is medium-high pending direct retrieval of the DOJ release, while multiple fresh reports identify the verdict, charges, amount, victims and sentencing date.
Listing post-mortem use: Use when reviewing listed or promoted assets whose narratives depend on opaque mining income, AI infrastructure claims, guaranteed yield, reserve assertions, insurance claims or affiliate-style investor recruitment.
Source
2026-08-23
Tier 1
Term Finance / Term Labs Meta Vaults
Term Labs confirmed a governance exploit impacting Term Vaults, then said all Term Meta Vaults were shut down, DAO governance roles were revoked, further deposits were permanently disabled and withdrawals remained open; fresh reporting citing CertiK estimated roughly $8.5M in losses tied to malicious vault-governance control.
Global / Ethereum DeFi
Term Labs / Term Finance protocol operators; CertiK monitoring context
DeFi lending / fixed-rate lending / vault governance / Yearn V3 strategy vaults
high confidence
governance exploitvault governance takeovermalicious proposal executionMeta Vault permanent deposit shutdownDAO role revocationwithdrawal-only wind-downtimelock and LP veto bypass allegationsTornado Cash-funded governance-token acquisition allegationDeFi fixed-rate lending riskYearn V3 strategy-vault dependency riskuser approval revocation warningpost-exploit impersonation scam risk
Term Finance is included as Tier 1 because the official project response created direct adverse consequences: irreversible Meta Vault shutdown, permanent deposit disablement, DAO role revocation and withdrawal-only remediation after a confirmed governance exploit. Confidence is high for the action and status because Term Labs posted the exploit and shutdown updates directly; the dollar-loss estimate remains contextual because it comes from media citing CertiK rather than final project accounting.
Listing post-mortem use: Use when reviewing DeFi lending or vault-related listings where token governance power, timelock design, LP veto mechanics, admin-role revocation, product wind-down and user approval hygiene affect market integrity or holder risk after listing.
Source
2026-08-22
Tier 1
The Sandbox SAND cross-chain bridge on Base and BNB Smart Chain
The Sandbox said it fully contained a vulnerability in the SAND cross-chain bridge on Base and BNB Smart Chain after an attacker minted unbacked SAND; the project disabled bridging to and from both networks, warned users not to trade SAND on Base or BSC because liquidity was compromised, and said Korean exchanges Upbit and Bithumb halted SAND deposits and withdrawals while reviewing the incident.
Global / Base / BNB Chain / South Korea
The Sandbox protocol operators; Upbit and Bithumb exchange risk controls
Gaming / metaverse token / cross-chain bridge / exchange deposit-withdrawal access
high confidence
cross-chain bridge exploitunbacked token mintbridge disablementisolated network liquidityexchange deposit and withdrawal suspensionLP compensation planLayerZero/OFT configuration riskwrapped-asset backing riskgaming-token listing durability riskSouth Korean exchange caution responsepermanent bridge-contract retirement1:1 holder compensationcentralized-exchange balance concentrationmajor exchange deposit-withdrawal suspensionattacker address flaggingreplacement bridge contract migration risk
The Sandbox SAND bridge incident remains Tier 1 because it produced direct adverse protocol and exchange consequences: unbacked SAND minting on Base and BNB Smart Chain, disabled bridging, compromised network liquidity warnings, deposit-withdrawal freezes, and now permanent retirement of affected bridge contracts plus a 1:1 compensation process for legitimate bridged-SAND holders.
Listing post-mortem use: Use when reviewing listings that relied on multi-chain availability, LayerZero/OFT bridge assumptions, DEX liquidity on Base or BNB Chain, South Korean exchange transfer availability, centralized-exchange holder concentration, compensation mechanics, and whether venue risk teams had procedures for unbacked wrapped-token mints and permanent bridge retirement.
Source
2026-08-21
Tier 1
BounceBit Chain
BounceBit said an issue affecting BounceBit Chain made BB transactions temporarily unavailable and paused exchange deposits and withdrawals; follow-up reporting citing BounceBit said an authorization flaw let an attacker move 286,543,148 BB from nine accounts, after which BounceBit decided to permanently shut down BounceBit Chain and reissue BB on BNB Chain from a pre-attack snapshot.
Global / BNB Chain
BounceBit protocol operators
Layer 1 / CeDeFi / chain authorization / exchange deposit-withdrawal access
medium-high confidence
protocol exploitchain authorization flawunauthorized token transferschain shutdowntoken reissuesnapshot rollback mechanicsexchange deposit and withdrawal pauseaccount-balance restoration riskEvmos stack maintenance risklisting durability risk
BounceBit is included as Tier 1 because the incident produced direct adverse consequences: unauthorized movement of 286.5M BB was reported, BB transfers and exchange deposits/withdrawals were paused, and the project moved toward shutting down its own chain and reissuing the token on BNB Chain. Confidence is medium-high because the official pause post was directly fetchable but the full shutdown/reissue details came through crypto media citing a later official X update.
Listing post-mortem use: Use when reviewing listings that rely on appchain durability, token migration assumptions, exchange deposit-withdrawal continuity, snapshot/reissue governance, and whether a project can preserve market integrity after a chain-level authorization exploit.
Source
2026-08-21
Tier 1
MANTRA Chain
MANTRA Chain halted the network after identifying an incident, freezing endpoints and transactions and temporarily affecting deposits and withdrawals; the official status page later said mainnet resumed block production on August 22 after a v8.4.0 restart that remediated a Cosmos-EVM module vulnerability, with user balances not altered.
Global
MANTRA Chain / protocol operators
Layer 1 / RWA chain / protocol operations / exchange deposit-withdrawal access
high confidence
protocol incidentchain halttransaction freezedeposit and withdrawal suspensionexchange transfer disruptionroot-cause uncertaintyRWA chain operational risknative-token price shockvalidator and endpoint liveness risklisting durability riskCosmos-EVM module vulnerabilityrestart remediationpost-halt monitoring
MANTRA Chain remains a Tier 1 row because the protocol action created a direct adverse consequence: transactions, endpoints and deposits/withdrawals were frozen during an incident. The row was updated on August 22 after the official status page confirmed restart under v8.4.0, remediation of a Cosmos-EVM module vulnerability, resumed block production and no balance alteration.
Listing post-mortem use: Use when reviewing listings that depend on chain liveness, deposit-withdrawal continuity, validator/operator emergency powers, RWA-chain reliability claims, and whether exchanges had credible halt/freeze handling before listing OM or MANTRA Chain assets.
Source
2026-08-20
Tier 2
Coinbase perpetual futures delisting basket
Multiple crypto market-data and news aggregators reported that Coinbase will delist nine perpetual futures contracts effective September 3, 2026 at 13:00 UTC, affecting Espresso, DoubleZero, RedStone, AEVO, Aethir, Kaspa, SKY, POPCAT and BRETT-linked contracts; open positions reportedly need to be closed before the deadline to avoid exchange settlement or liquidation mechanics.
Global / Coinbase International derivatives venue
Coinbase derivatives venue / exchange market operations
Exchange derivatives / perpetual futures / altcoin market access
medium confidence
exchange derivatives delistingperpetual futures market-access lossforced closeout or settlement riskaltcoin liquidity contractionderivatives venue migration riskmarket-maker inventory unwind risklisting durability risksecondary-source verification gap
The Coinbase derivatives basket is included as Tier 2 because it has named assets, a reported exchange venue, a clear deadline and a concrete derivatives-market consequence, but the run did not verify the primary Coinbase notice directly.
Listing post-mortem use: Use when reviewing tokens whose post-listing thesis relied on perpetual futures depth, exchange-backed leverage, market-maker inventory support, or broad venue availability rather than durable spot demand.
Source
2026-08-19
Tier 1
Maya Protocol / MAYAChain
Cointelegraph reported that Maya Protocol halted MAYAChain after an attacker chained software flaws to obtain an estimated $1.7M in crypto, including about 20 BTC and other assets; preliminary analysis said a 23-message transaction drained 48.87M CACAO and total pool value impact reached about $10.9M while CACAO fell nearly 89%.
Global
Maya Protocol / MAYAChain validators and development team
DeFi / cross-chain DEX / THORChain-derived protocol security
medium-high confidence
protocol exploitnetwork haltcross-chain DEX accounting bugliquidity pool mispricingoutbound transaction overwritetheft-protection compensation bugCACAO token collapsepool value lossbug bounty recovery uncertaintyTHORChain-fork code risk
Maya Protocol is included as Tier 1 because the exploit triggered a direct protocol action, a network halt, reported asset losses and a severe native-token price impact. Confidence is medium-high because the accessible source is reputable media citing cofounder statements and preliminary analysis rather than a final official post-mortem.
Listing post-mortem use: Use when reviewing listings or liquidity support for cross-chain DEX tokens, especially where protocol halts, pool-accounting bugs, bug-bounty recovery assumptions, or native-token collateral/liquidity design can magnify user losses.
Source
2026-08-19
Tier 1
Caroline Ellison / Gary Wang / Alameda Research / FTX
The CFTC announced that the U.S. District Court for the Southern District of New York entered supplemental consent orders against former Alameda CEO Caroline Ellison and Alameda/FTX co-founder Gary Wang, imposing five-year trading bans on both, a 10-year registration ban on Ellison, and an eight-year registration ban on Wang while resolving the CFTC enforcement actions.
United States
U.S. Commodity Futures Trading Commission / U.S. District Court for the Southern District of New York
Centralized exchange / affiliated market maker / digital commodity fraud enforcement
high confidence
CFTC enforcement resolutionfederal court supplemental consent orderstrading banregistration banFTX-Alameda fraud liabilityexchange-affiliate conflict risksenior executive misconductcustomer-asset and market-integrity failurelisting and market-maker due diligence precedent
The Ellison/Wang row is Tier 1 because it is an official CFTC enforcement resolution with federal court supplemental consent orders and direct adverse consequences: trading bans, registration bans and continuing cooperation obligations. It strengthens the database lineage for FTX-linked team and market-structure risk dossiers.
Listing post-mortem use: Use as a core comparator for exchange-token, centralized-exchange and market-maker listings where affiliate control, opaque customer-asset flows, insider access or senior-executive fraud liability later become post-listing failure points.
Source
2026-08-18
Tier 1
Kraken 56-token delisting and forced-liquidation cycles
Fresh coverage of Kraken support notices reported that Kraken is removing 56 cryptocurrencies across May, June and July 2026 delisting cycles, with the first withdrawal deadline on August 27, 2026 at 14:00 UTC and automatic exchange-run liquidation of remaining balances after the cutoff.
Global / European Union
Kraken
Centralized exchanges / listed-token support / post-delisting liquidation
medium-high confidence
multi-token delistingwithdrawal deadlineforced liquidationthin order book settlement riskminimal-or-zero proceeds riskpost-delisting custody accessMiCA-era exchange support contractionproject wind-down transfer failureresidual balance losslisting quality review failure
Kraken is included as Tier 1 because the reported official-notice pattern creates direct adverse consequences: trading/deposit halts, dated withdrawal cutoffs, and automatic liquidation of remaining user balances that may return minimal or zero proceeds. Confidence is capped at medium-high because the accessible detailed source is secondary analysis, though it cites Kraken support notices and provides notice-cycle dates and token lists.
Listing post-mortem use: Use when reviewing token delistings, exchange quality-screen failures, user harm from delayed withdrawal action, thin-liquidity forced liquidation, and whether asset teams maintained working withdrawal infrastructure after venue support ended.
Source
2026-08-18
Tier 1
Polymarket
The Korea Times reported that South Korea ordered domestic internet service providers to block access to Polymarket after the media and communications regulator concluded the overseas prediction market facilitates gambling or provides a gambling venue under the Criminal Act and similar sports-betting activity under the National Sports Promotion Act.
South Korea
Korea Media and Communications Standards Commission telecommunications review subcommittee
Prediction markets / crypto gambling perimeter / internet access controls
high confidence
ISP-level access blockillegal gambling classificationprediction-market regulatory perimetersports-betting law exposuredomestic user targeting evidencedecentralization defense rejectedcrypto settlement system scrutinycross-jurisdiction access restrictionslisting and banking reputational risk
Polymarket is included as Tier 1 because a named South Korean authority ordered direct access blocking with a clear adverse market-access consequence. The case is also useful as a jurisdiction analogue because the regulator explicitly rejected decentralization, P2P settlement and removal of Korean-language services as reasons to avoid domestic law.
Listing post-mortem use: Use when assessing prediction-market tokens, exchange listings, payment rails, market-maker exposure, app-store/search access, and jurisdiction filters where gambling-law classification can trigger sudden access blocks.
Source
2026-08-17
Tier 1
Bitfinex withdrawal cutoff for 13 delisted assets
Bitfinex users reportedly have until 10:00 UTC on August 31, 2026 to withdraw 13 recently delisted cryptocurrencies; after the cutoff standard withdrawals will be disabled and any recovery attempt becomes discretionary, fee-bearing, time-limited and not guaranteed.
Global
Bitfinex
Centralized exchanges / delisted token custody / withdrawal access
medium-high confidence
delisted token withdrawal cutoffpost-delisting custody accessmanual recovery uncertaintysmall-balance fee pressureexchange discretion over asset recoverylegacy wallet support contractioninterface/API ticker mismatch riskJPY balance forced conversion context
Bitfinex is included as Tier 1 because the reported exchange process creates direct adverse consequences for holders of 13 delisted assets: standard withdrawals end on a dated cutoff and later recovery is discretionary, fee-bearing and not guaranteed. Confidence is capped at medium-high because the official Bitfinex notice URL was reachable but not text-extractable during this run.
Listing post-mortem use: Use when reviewing delisted-token holder harm, exchange support wind-downs, small-balance recovery friction, market-access loss after delisting, and whether issuer communications gave users enough warning before withdrawal support ended.
Source
2026-08-17
Tier 1
Edward Zimbardi / The Crypto Program
The U.S. Attorney for the Northern District of Georgia announced that Edward Zimbardi, alleged operator of The Crypto Program, returned to the United States after deportation from Fiji to face 12 wire-fraud counts, 12 money-laundering counts and one money-laundering conspiracy count over a reported $165M cryptocurrency Ponzi scheme.
US / Fiji
U.S. Department of Justice; FBI Atlanta; Fijian authorities; U.S. Department of State
Crypto investment schemes / Ponzi fraud / victim restitution
high confidence
crypto Ponzi prosecutionwire fraud chargesmoney laundering chargesvictim restitution uncertaintycross-border suspect flightFiji deportation coordinationguaranteed-return investment schemewallet-controlled fundraising opacity
Edward Zimbardi / The Crypto Program is included as Tier 1 because the DOJ announced a federal criminal case with named defendant, named scheme, cross-border deportation, wire-fraud and money-laundering counts, and a reported $165M investor-loss scale. The indictment remains an allegation, but the prosecution and return-to-court event are confirmed adverse judicial signals.
Listing post-mortem use: Use when reviewing tokens, promoters, wallets, treasury flows or user acquisition channels tied to guaranteed monthly return narratives, advertising-package investments, referral-driven fundraising, or entities later named in US criminal crypto-fraud proceedings.
Source
2026-08-15
Tier 1
Binance transaction restrictions for HTX, EXMO, Rapira, Aifory Pro, ABCeX, WhiteBird, NoOnecrypto, Tradex, Monease, BitPapa and Exnode
Cointelegraph and CoinGape, citing Binance announcement af2be67dc03c4673b4f56c42db948253, reported that Binance will stop processing transactions involving HTX and ten other crypto platforms from August 23; attempted transactions may be held for compliance review and related wallets may be restricted during checks.
Global / European Union / United Kingdom / United States
Binance compliance restrictions; EU Russia sanctions package; UK OFSI; US OFAC sanctions context
Centralized exchanges / sanctions compliance / exchange counterparty controls
medium-high confidence
sanctioned-entity exposuretransaction processing haltwallet restriction during compliance reviewHTX and EXMO sanctions spillovercounterparty VASP riskEU and UK sanctions implementationKYT false-negative risk for changing exchange walletsliquidity and arbitrage routing frictionexchange-to-exchange transfer contamination
Binance is included as Tier 1 because reputable media extracted and linked the Binance announcement, named the affected VASPs, described the August 23 effective restriction and stated direct adverse consequences for transactions and wallets. Confidence is capped at medium-high because the Binance page itself was not extractable in this run.
Listing post-mortem use: Use when tracing why deposits, withdrawals, market-maker flows, treasury movements or arbitrage routes involving named VASPs were held, rejected or flagged by Binance after sanctions-related controls tightened.
Source
2026-08-15
Tier 1
Bitget sanctioned-entity transaction controls covering HTX, EXMO, Rapira, Aifory Pro, ABCeX, WhiteBird, Aban Tether, Shelbit and related platforms
Bitget published an official notice applying additional controls to direct or indirect transactions involving named entities, with effective waves on August 7, August 13 and August 23; attempted transactions may face enhanced compliance review, rejection, account restrictions during review, or account termination for Terms of Use breaches.
Global / European Union / United Kingdom / United States
Bitget sanctions-compliance controls; EU Russia sanctions package; UK OFSI; US OFAC context
Centralized exchanges / sanctions compliance / VASP counterparty risk
high confidence
sanctioned-entity exposureexchange transaction rejectionaccount restriction during compliance reviewcounterparty VASP riskHTX and EXMO sanctions spilloverEU Russia sanctions package implementationOFAC Iran sanctions implementationliquidity routing frictionKYT intermediary-provider screening
Bitget is included as Tier 1 because the official exchange notice names affected entities, states effective dates, and creates direct adverse consequences: enhanced review, transaction rejection, account restrictions and possible termination for connected accounts.
Listing post-mortem use: Use when reviewing listings, market-maker routing, treasury transfers, issuer liquidity programs or user-flow incidents that touched named sanctioned or restricted VASPs and later encountered CEX holds, rejected deposits/withdrawals, account restrictions or sanctions-screening escalations.
Source
2026-08-14
Tier 2
Polymarket
CoinDesk, citing the Financial Times, reported that JPMorgan Chase stopped providing banking services to Polymarket in October 2025 over regulatory concerns, requiring the prediction-market platform to secure another banking partner while it was reentering the U.S. market.
United States
JPMorgan Chase banking-risk controls; CFTC historical settlement context
Prediction markets / fiat banking access / crypto-adjacent market infrastructure
medium-high confidence
banking access lossregulatory concern by banking partnerprediction-market legal riskfiat on/off-ramp fragilityUS market reentry riskcounterparty risk reviewdebanking disclosure lagplatform continuity diligence
Polymarket is included as Tier 2 because the report identifies a named platform, a named major bank, a clear banking-access adverse consequence and a regulatory-risk vector, but it is a reported historical relationship change rather than a final enforcement action.
Listing post-mortem use: Use when reviewing prediction-market integrations, token launches tied to event-contract liquidity, or platforms whose operating model depends on fragile banking partners despite public growth narratives.
Source
2026-08-13
Tier 2
Trezor / ShipMonk fulfillment infrastructure
Trezor disclosed that ShipMonk, one of its shipping providers, experienced unauthorized access exposing customer order data for approximately 13,689 customers, including 11,742 customers with full name, email, phone number and shipping address exposure and 1,947 customers with partial exposure.
Global / United States / United Kingdom / Sweden / Colombia / Brazil / Italy / Portugal
Trezor; ShipMonk third-party fulfillment provider
Hardware wallets / custody infrastructure / customer data security
high confidence
third-party data breachcustomer shipping-address exposurephone-number exposurephishing and impersonation riskphysical coercion riskhardware-wallet customer privacy riskfulfillment-provider security risklong-tail scam targeting
Trezor is included as Tier 2 because the company confirmed a named third-party breach with clear customer-security consequences, but the incident did not compromise Trezor wallet systems or produce a confirmed protocol, exchange or regulator action.
Listing post-mortem use: Use as customer-data-security context when reviewing custody, wallet, hardware, KYC-heavy or physical-delivery crypto projects where leaked identity and address data can create downstream scam and personal-safety risk.
Source
2026-08-13
Tier 3
Crypto issuers relying on a tailored offering regime for investment contracts involving crypto assets
The SEC cancelled its August 14, 2026 open meeting that had been scheduled to consider proposing new rules to create a tailored offering regime for certain investment contracts involving crypto assets.
United States
U.S. Securities and Exchange Commission
Token issuance / securities compliance / U.S. crypto market structure
high confidence
rulemaking delaytoken offering uncertaintysecurities compliance ambiguitystartup fundraising frictionUS market-structure delayCLARITY Act fallback riskinnovation-exemption delay riskjurisdictional uncertainty
The SEC cancellation is included as Tier 3 because it is an official sector-level delay signal with listing and fundraising implications, but it does not impose a direct sanction or name a violating project.
Listing post-mortem use: Use as jurisdiction-radar context when a listing thesis assumes imminent U.S. token-offering clarity, innovation exemptions or reduced SEC registration friction.
Source
2026-08-12
Tier 1
Yepbit / Yepbit Exchange
ASIC warned consumers against Yepbit and Yepbit Exchange after receiving multiple investor reports of blocked withdrawals, said Yepbit falsely claimed ASIC had frozen customer funds during regulatory checks, took down several linked websites, and found the platform lacked both an Australian Financial Services Licence and AUSTRAC virtual-asset-service registration.
Australia
Australian Securities and Investments Commission (ASIC); AUSTRAC registration framework referenced
Crypto exchange / online trading platform / retail investment scam infrastructure
medium-high confidence
blocked withdrawalsregulator impersonation or false regulator-freeze claimwebsite takedownunlicensed financial servicesmissing AUSTRAC VASP registrationretail investor scam riskrefund deflection tacticsAustralia crypto licensing risk
Yepbit is included as Tier 1 because ASIC reportedly took direct website-disruption and investor-warning action tied to withdrawal complaints, false regulator-freeze explanations and missing Australian authorisations.
Listing post-mortem use: Use as a due-diligence comparable for exchanges or brokers with Australian user access, unclear licensing, blocked withdrawals, regulator impersonation claims, or domain/network churn after warnings.
Source
2026-08-12
Tier 1
Harmony Protocol
Harmony confirmed it was working with exchanges to stop and freeze funds after reports of an unauthorized mint of roughly 4 billion ONE; the team said it was preparing a patch and evaluating rollback options, while public reporting said ONE fell sharply after the incident.
Global
Harmony Protocol team; exchanges asked to freeze funds
Layer 1 protocol / bridge and token supply security
high confidence
unauthorized token mintprotocol exploit responseexchange freeze requestrollback option under reviewtoken supply integrity failuremarket price shockbridge and validator security diligencecentralized intervention risk
Harmony is included as Tier 1 because the project publicly confirmed a direct adverse protocol response: exchange freeze coordination, patch work and rollback review following an alleged 4B ONE unauthorized mint.
Listing post-mortem use: Use as a direct comparable for listings or integrations exposed to emergency token-supply changes, exchange freeze requests, rollback governance, bridge history or sudden circulating-supply uncertainty.
Source
2026-08-12
Tier 2
tx / XRPL bridge
Fresh reporting said the tx/XRPL bridge was drained of about 198,715.88 XRP after bridge software treated fake deposits as real, enabling the attacker to withdraw real XRP reserves; reports said the bridge remained halted and the operator had filed a report with the FBI.
Global
tx bridge operator; FBI report referenced in media
Cross-chain bridge / XRPL interoperability
medium-high confidence
bridge accounting flawfake deposit recognitionreserve drainbridge haltcross-chain asset backing riskFBI report referencedTHORChain routing and Tornado Cash laundering reportedvalidator signing control weakness
The tx/XRPL bridge is included as Tier 2 because the exploit is named, quantified and operationally adverse, but direct primary-source documentation was not retrieved during this run.
Listing post-mortem use: Use as a bridge due-diligence comparable for projects relying on wrapped XRP, cross-chain reserve attestations, validator-controlled withdrawals or non-native asset listings.
Source
2026-08-12
Tier 3
Designated contract markets offering prediction-market/event-contract incentive programs
The CFTC Division of Market Oversight issued an advisory warning that an increasing number of incentive-program filings by DCMs, particularly event-contract products, contain procedural or substantive deficiencies that can impair staff review of notice, terms and core-principle compliance.
United States
CFTC Division of Market Oversight
Prediction markets / market-maker incentives / event-contract compliance
high confidence
deficient rule filingsincentive-program compliance riskmarket-maker rebate scrutinywash-trading riskpre-arranged trading riskevent-contract surveillance gapDCM core-principle compliancesector-level early warning
The CFTC advisory is included as Tier 3 because it is a useful sector-wide early warning for prediction-market market-integrity risk, but it does not name a final enforcement target or impose a direct sanction.
Listing post-mortem use: Use as early-warning context when a listed project relies on prediction-market liquidity, market-maker rebates, incentive farming, event-contract integrations or unexplained volume spikes around rewards programs.
Source
2026-08-12
Tier 1
Goliath Ventures Inc. / Christopher Delgado
The CFTC filed a federal complaint alleging Goliath Ventures and CEO Christopher Delgado ran an approximately $397M Ponzi scheme that fraudulently solicited public funds for crypto asset trading, including bitcoin and ether, while misappropriating all customer funds; the CFTC also noted Delgado pleaded guilty in a parallel criminal case and the SEC filed a related civil action on August 11, 2026.
United States
CFTC; SEC; U.S. Attorney's Office for the Middle District of Florida; U.S. District Court for the Middle District of Florida
Crypto asset trading / investment scheme / digital commodity fraud
high confidence
crypto Ponzi schemecustomer fund misappropriationfalse account statementsguaranteed-return claimsparallel criminal caseSEC civil actionCFTC restitution and penalty claimstrading and registration ban risk
Goliath Ventures is included as Tier 1 because the CFTC confirmed a filed federal complaint over an alleged crypto-asset Ponzi scheme with direct adverse legal consequences and parallel SEC/criminal proceedings.
Listing post-mortem use: Use as a fraud-control comparable when reviewing projects or listing applicants with managed-trading claims, guaranteed returns, off-chain account statements, opaque custody, founder criminal exposure or commingled investor funds.
Source
2026-08-11
Tier 2
Moonbeam; ICON; Moonriver; SuperRare; Sophon
Binance added GLMR, ICX, MOVR, RARE and SOPH to its Monitoring Tag list after periodic reviews, putting the assets under closer scrutiny and warning they can be delisted if they no longer meet listing criteria; reporting noted notable 24h price declines for MOVR, GLMR, RARE and ICX after the announcement.
Global
Binance listing review process
Exchange-listed tokens / Layer 1 and application tokens / NFT and infrastructure assets
medium-high confidence
possible delisting riskexchange monitoring tagliquidity risklisting-standard reviewproject migration and shutdown contexttoken volatilityholder disclosure riskcentralized venue access risk
The five-token Binance monitoring action is included as Tier 2 because it is a named, exchange-driven negative signal with clear listing-friction and liquidity-risk implications, but it is not yet a final delisting.
Listing post-mortem use: Use as direct exchange-listing-friction context when reviewing assets with prior monitoring tags, migration deadlines, chain wind-downs, low liquidity or unexplained post-review selloffs before listing or relisting decisions.
Source
2026-08-11
Tier 2
Polymarket short-duration crypto markets
Fresh reporting summarized research finding 821 accounts that made about $8.2M from likely manipulation of Polymarket five-minute BTC settlement windows by moving Binance spot prices in the final seconds before single-snapshot settlement; Polymarket replaced instant snapshots with TWAP settlement on August 7, 2026.
Global / United States
Stanford University and Singapore Management University researchers; Polymarket; Chainlink Data Streams referenced in reporting
Prediction markets / crypto derivatives / oracle settlement design
medium-high confidence
market manipulationsingle-snapshot settlement riskoracle design weaknessretail loss concentrationcross-venue price impactprediction-market surveillance gapTWAP remediationinstitutional diligence risk
Polymarket is included as Tier 2 because the signal is named, recent, quantified and structurally useful, but it is based on research and media reporting rather than a final regulator or court action.
Listing post-mortem use: Use as market-structure context when evaluating assets or venues exposed to thin settlement windows, manipulable reference prices, oracle design shortcuts or unexplained retail-loss clusters before a listing or venue integration.
Source
2026-08-11
Tier 1
Key Coin Assets Ltd
The UK Insolvency Service said Key Coin Assets Ltd was wound up by the High Court on August 11, 2026 after investigators found no evidence of genuine crypto trading, more than GBP 300,000 in investor losses, funds routed to the director's personal account, fake testimonials and avoidance of normal payment references.
United Kingdom
UK Insolvency Service; High Court in London; Financial Conduct Authority warning context; Official Receiver
Crypto investment scheme / consumer fraud / unauthorized firm / insolvency
high confidence
court winding-up orderPonzi-style crypto schemeunauthorized firmconsumer investor lossno genuine crypto trading evidencedirector personal-account fund flowfake testimonialsFCA registration warningno ombudsman or compensation protectioninsolvency liquidation
Key Coin Assets is Tier 1 because a UK court winding-up order and official Insolvency Service release confirm direct adverse consequences: liquidation, investor losses above GBP 300,000, no evidence of genuine trading and appointment of the Official Receiver.
Listing post-mortem use: Use as a UK analogue for rejecting issuer, market-maker or treasury counterparties with guaranteed-return marketing, opaque banking trails, unauthorized investment activity or fake user testimonials.
Source
2026-08-11
Tier 2
KalshiEX LLC
The CFTC exercised emergency authority after KalshiEX notified it of a market emergency triggered by New York Attorney General litigation seeking a temporary restraining order against Kalshi offering event contracts nationwide and more than $36B in damages; the CFTC ordered Kalshi to continue operating under CEA core principles.
United States / New York
CFTC; New York Attorney General; KalshiEX LLC
Prediction markets / event-contract derivatives / crypto-adjacent market structure
high confidence
state-federal jurisdiction conflictmarket emergency noticetemporary restraining order risklarge damages claimevent-contract legal classificationprediction-market continuity riskstate gaming-law challengeregulatory fragmentation
Kalshi is included as Tier 2 because the CFTC confirmed a market-emergency order tied to a named lawsuit seeking severe operational and damages consequences, even though the platform is crypto-adjacent rather than a token issuer.
Listing post-mortem use: Use as jurisdiction-radar context when reviewing prediction-market integrations, tokenized event-contract exposure, platform access controls or crypto projects whose liquidity depends on US event-contract legal stability.
Source
2026-08-10
Tier 1
BTCPay Server / LND deployments
BTCPay Server confirmed attackers exploited a critical vulnerability in versions prior to 2.4.2 that could allow unauthenticated remote access to LND .macaroon credential files, enabling control of LND nodes and movement of funds; the project said users were affected and funds were stolen, and version 2.4.2 temporarily removes public LND API access on Docker deployments.
Global
BTCPay Server project
Bitcoin payment infrastructure / Lightning node operations
high confidence
critical security vulnerabilityLND credential exposurestolen fundsremote unauthenticated attackerLightning node takeovermerchant payment infrastructuretemporary wallet connectivity restrictionemergency upgrade requirement
BTCPay Server is included as Tier 1 because the project officially confirmed exploitation, affected users, stolen funds, emergency upgrade requirements and a direct temporary restriction on public LND API access.
Listing post-mortem use: Use as infrastructure-risk context when reviewing projects or merchants that rely on self-hosted Lightning payment stacks, exposed LND APIs, hot-wallet flows or delayed security-patch operations.
Source
2026-08-10
Tier 2
Gannon Ken Van Dyke / Polymarket event contracts
A federal judge reportedly stayed the CFTC civil case against active-duty U.S. Army Special Forces master sergeant Gannon Ken Van Dyke while the related DOJ criminal case proceeds; authorities allege he used confidential government information to earn about $409,881 from 13 Venezuela-related Polymarket trades.
United States
U.S. District Court; CFTC; U.S. Department of Justice
Prediction markets / event-contract compliance / classified-information trading risk
medium-high confidence
prediction-market insider tradingclassified information misuse allegationCFTC civil enforcement stayedDOJ criminal prosecutionevent-contract legal classification disputeVPN access controlscrypto proceeds movementsurveillance and wallet-referral pressure
The Van Dyke matter is included as Tier 2 because the fresh court stay is a credible judicial development in a named prediction-market insider-trading case, but it does not resolve liability or impose a final platform-level sanction.
Listing post-mortem use: Use as prediction-market regulatory context when a project, asset or venue depends on event-contract liquidity, politically sensitive markets, offshore access controls or unresolved CFTC/DOJ classification theories.
Source
2026-08-09
Tier 1
Cryptolink Pty Ltd
AUSTRAC suspended Cryptolink's VASP registration for three months from Sunday 9 August 2026 and said the company is no longer allowed to operate its 96 cryptocurrency ATMs after reporting failures and unanswered information requests.
Australia
AUSTRAC
Crypto ATM / VASP / cash-to-crypto rails
high confidence
AML/CTF reporting failurethreshold transaction reportscrypto ATM shutdownVASP registration suspensioncash-to-crypto high-risk transactionsenforceable undertaking breach follow-upregulatory monitoring
Cryptolink is included as Tier 1 because AUSTRAC officially suspended its VASP registration and ordered its 96 crypto ATMs offline after threshold transaction reporting failures and non-response to a regulator information request.
Listing post-mortem use: Use as a cash-rail and venue-access warning when reviewing assets, issuers or market makers dependent on crypto ATM distribution, high-cash retail flow or Australian VASP partners with AML reporting weaknesses.
Source
2026-08-09
Tier 2
Coinsbuy
Multiple crypto media reports and security-monitoring references said wallets linked to Coinsbuy were drained of more than $7.9M across Ethereum and TRON around 13:00 UTC on August 9, with stolen funds routed through swap/exchange venues and partly converted into Monero; reports said ChangeNOW helped freeze a six-figure amount and Coinsbuy temporarily paused deposits and withdrawals.
Global
PeckShield monitoring; Specter on-chain analysis; Coinsbuy statements reported by media
Crypto payment processor / wallet security / cross-chain laundering
medium confidence
wallet draincross-chain theftMonero launderingexchange and swap routingtemporary deposits and withdrawals pausepartner-assisted fund freezepayment-processor custody riskon-chain forensic monitoring
Coinsbuy is included as Tier 2 because the incident is named, recent and structurally useful for wallet-security and laundering-path monitoring, but primary company or law-enforcement documentation was not directly available in this run.
Listing post-mortem use: Use as comparable context for projects whose liquidity, treasury operations, merchant-payment rails or market makers depend on small payment processors, instant-swap venues, TRON/ETH hot wallets or weak post-incident disclosure.
Source
2026-08-08
Tier 1
Bybit Technology Limited v. Democratic People's Republic of Korea, DPRK Reconnaissance General Bureau, Lazarus Group and John Doe defendants
Bybit announced a U.S. civil RICO lawsuit against DPRK-linked Lazarus actors and said it secured a preliminary injunction freezing identified stolen assets tied to the February 2025 Bybit hack, with about $30.5M frozen across more than 28 exchanges and custodians and about $48.4M recovered.
United States / DPRK / Global
U.S. District Court for the District of Columbia; Bybit; FBI cooperation cited by Bybit
Centralized exchange security / state-sponsored cybercrime / asset recovery
high confidence
state-sponsored cybercrimecourt-ordered asset freezeexchange cold-wallet hackLazarus laundering networkcross-exchange custody freezecivil RICO recovery litigationblockchain forensicsETH theft proceeds
Bybit is included as Tier 1 because the company announced a U.S. federal civil action against DPRK/Lazarus-linked defendants and a preliminary injunction freezing traceable stolen assets, corroborated by a CourtListener docket for Bybit Technology Limited v. Democratic People's Republic of Korea.
Listing post-mortem use: Use as a precedent for listing and venue-risk reviews where a token, exchange, custodian, bridge or OTC route is exposed to hacked-asset flows, Lazarus attribution, court-preservation orders or post-hack recovery claims.
Source
2026-08-07
Tier 1
Binance spot pairs QNT/BTC, RPL/USDC, SIGN/BNB and SKL/USDC
Binance scheduled removal of QNT/BTC, RPL/USDC, SIGN/BNB and SKL/USDC spot trading pairs on August 7, 2026 after a periodic liquidity and volume review.
Global
Binance
Exchange spot markets / liquidity review
high confidence
exchange delistingspot liquiditymarket-access frictiontrading-pair concentration
Binance pair-level delisting is a structured adverse market-access signal because it removes specific quote routes after liquidity and volume review without fully delisting the underlying assets.
Listing post-mortem use: Use as a liquidity-friction marker when reviewing tokens with shrinking quote-pair breadth, weak volume, or dependence on a small number of exchange routes.
Source
2026-08-07
Tier 1
Aban Tether
OFAC designated Iran-based digital asset exchange Aban Tether, stating it processed millions of dollars of transactions involving previously designated Iranian exchanges including Nobitex, Wallex, Bitpin and Ramzinex, and designated it for operating in the Iranian financial sector.
Iran / United States / Global
U.S. Treasury OFAC; IRS-CI
Iranian digital asset exchange / sanctions evasion / exchange counterparty risk
high confidence
OFAC SDN designationIran sanctions exposuredesignated exchange counterparty flowfinancial-sector sanctionsblocked-property reportingsecondary sanctions riskstablecoin transaction monitoring
Aban Tether is included as Tier 1 because OFAC officially designated the Iran-based exchange for operating in Iran financial-sector activity and for transactions involving already designated Iranian crypto exchanges.
Listing post-mortem use: Use as sanctions-network context when a listed asset, market maker, liquidity venue, or issuer treasury has exposure to Iranian exchange flows, stablecoin settlement routes, or counterparties later connected to OFAC-designated VASPs.
Source
2026-08-06
Tier 3
EU crypto users migrating from unauthorised CASPs
European regulators reportedly observed fraudsters impersonating regulators and licensed crypto firms to steal assets from customers moving funds after the MiCA licensing transition deadline.
EU
ESMA; AMF; European national competent authorities
MiCA transition / consumer protection / scam infrastructure
medium confidence
impersonation scamMiCA transitionunauthorised CASP wind-downasset migrationconsumer protection
The MiCA transition created an early-warning scam surface: fraudsters can exploit legitimate provider exits and regulator registers to redirect customers to fake asset-transfer channels.
Listing post-mortem use: Use as jurisdiction-risk context when a token depends on EU retail distribution through smaller CASPs or faces customer-migration confusion after MiCA authorisation failures.
Source
2026-08-06
Tier 1
Coinbase LSETH-ETH, MINA-EUR, GRT-GBP, MASK-GBP, CHZ-USDT and CRO-USDT trading pairs
Coinbase Markets was reported to have moved five pairs to limit-only mode and to cease trading for LSETH-ETH, MINA-EUR, GRT-GBP, MASK-GBP, CHZ-USDT and CRO-USDT on August 6, 2026 to improve market health and concentrate liquidity.
Global / United States
Coinbase Markets
Centralized exchange spot market access / trading-pair liquidity
medium confidence
trading-pair delistingmarket-order restrictionliquidity concentrationfiat/stablecoin quote-pair lossexchange market-health reviewsecondary-market access friction
Coinbase pair removals are included as Tier 1 because trading on named pairs was reported to cease on a specific date with limit-only restrictions already applied, creating a direct adverse market-access consequence despite continued support for the assets.
Listing post-mortem use: Use as a pair-level market-access precedent when a token remains listed but loses specific fiat, stablecoin, or ETH quote routes after exchange market-health review.
Source
2026-08-05
Tier 1
Step App
Step App announced all services will wind down by August 21, 2026 and told users to unstake locked tokens and manage exchange positions; FITFI exchange access was already shrinking through KuCoin and Bithumb delisting deadlines.
Global
Step App; KuCoin; Bithumb
Move-to-earn / consumer crypto application
high confidence
project shutdownexchange delistingwithdrawal deadlineconsumer app wind-downtoken utility collapse
Step App became a confirmed adverse record after the project itself announced a full service shutdown and instructed users to unstake tokens and manage exchange positions before the deadline.
Listing post-mortem use: Use as a post-listing failure case for consumer reward tokens where active-user retention, app continuity, and exchange withdrawal deadlines define exit risk.
Source
2026-08-05
Tier 2
RedotPay / Binance Pay and Binance-affiliated entities
Binance-affiliated entities sued RedotPay and its founders, alleging RedotPay diverted roughly 470,000 Binance users and allowed Binance Pay funds to be used without segregation for prohibited RedotPay card top-ups, claiming about $472.8M in losses; RedotPay rejected the allegations.
Hong Kong / Singapore / Global
Hong Kong court filing reported by Bloomberg; Singapore hearing list context
Crypto payments / stablecoin cards / exchange payment rails
medium-high confidence
commercial lawsuitfunds segregation disputestablecoin card railspartner-channel diversionuser-base misappropriation allegationIPO readiness riskcross-border litigation
RedotPay is included as Tier 2 because the signal is a credible, named, cross-border lawsuit with clear funds-segregation and partner-channel risk vectors, but the allegations are contested and no final judicial consequence has been verified.
Listing post-mortem use: Use as a counterparty-risk analogue when reviewing crypto payment-card listings or investments that relied on exchange partnerships, partner user acquisition, or commingled stablecoin payment flows.
Source
2026-08-05
Tier 1
Shelbit Exchange / SHPS Shelbit / Shelbit General Trading LLC / Siavash Kayvanpour network
OFAC designated Shelbit-linked entities and operator Siavash Kayvanpour on August 7, 2026, alleging the network helped Iran-linked actors and IRGC-connected flows move digital assets through Shelbit Exchange; Treasury also cited VARA enforcement actions against Shelbit General Trading in January 2025 and July 2026 while the business remained active.
UAE / Iran / Global
U.S. Treasury OFAC; IRS-CI; Dubai VARA
Unlicensed exchange / sanctions evasion / offshore gambling crypto rails
high confidence
OFAC SDN designationIran sanctions exposureIRGC-linked digital asset flowsunlicensed exchange operationsAML/CFT control failureoffshore gambling proceedsblocked-property reportingdownstream exchange flow contaminationVARA enforcement history
Shelbit is upgraded to Tier 1 because OFAC officially designated Shelbit-linked entities and the Kayvanpour network, cited IRGC-linked digital-asset flows and VARA enforcement history, and created direct blocked-property and sanctions-compliance consequences.
Listing post-mortem use: Use as a Tier 1 AML/KYT precedent when reviewing listings or liquidity support that touched opaque offshore venues, gambling-affiliated flow sources, UAE-facing VASP entities, Iran-linked counterparties, or wallets later connected to OFAC-designated exchange networks.
Source
2026-08-05
Tier 1
Few and Far Limited / Taj Tarsha
The U.S. Department of Justice announced that Few and Far Limited founder Taj Tarsha was charged with fraud, creating a confirmed criminal-prosecution signal for an NFT startup and its founder-risk profile.
United States
U.S. Department of Justice / SDNY / FBI
NFT marketplace / startup fundraising / founder conduct
high confidence
founder fraud chargecriminal prosecutionNFT fundraising riskinvestor deceptiongovernance failurelaw-enforcement action
Few and Far is included as Tier 1 because the DOJ publicly announced a criminal fraud charge against its founder, giving the database a confirmed judicial adverse signal tied to NFT startup governance and founder due diligence.
Listing post-mortem use: Use as a founder-risk analogue when a listed NFT, marketplace, or early-stage token project later faces fraud allegations tied to fundraising, user traction, treasury use, or executive representations.
Source
2026-08-03
Tier 2
MOKE token and MokeLPManager
Crypto Times reported a suspected MOKE exploit on BNB Chain with an estimated $907,700 loss, involving PancakeSwap V2 liquidity pools, WBNB flows, LP token burns and the MokeLPManager contract; root cause remains unconfirmed.
BNB Chain / Global
TenArmor on-chain security alert / public blockchain data
DeFi / BNB Chain liquidity pools / meme-token infrastructure
medium confidence
suspected exploitliquidity-pool manipulationBNB Chain smart-contract riskPancakeSwap V2 LP exposureunclear root causethin-token incident response gap
MOKE is included as Tier 2 because it is a named token with a concrete chain, suspected exploit vector, estimated loss, implicated LP-manager contract and identifiable source trail, but there is no public project post-mortem or final technical attribution yet.
Listing post-mortem use: Use as a post-listing risk marker for tokens whose liquidity rests on lightly documented LP-manager contracts, thin PancakeSwap pools, or delayed incident disclosure after suspicious on-chain movement.
Source
2026-08-03
Tier 1
Across Protocol, Hashflow, PIVX, Vulcan Forged PYR, Vanar and Viction
Binance will delist ACX, HFT, PIVX, PYR, VANRY and VIC from spot trading on 2026-08-17, with futures, margin, loan, earn, pay, pool, convert and withdrawal deadlines staged through August and October.
Global
Binance
Centralized exchange listings / spot and derivatives market access
medium-high confidence
exchange delistingspot market access lossforced futures settlementmargin and loan closurewithdrawal deadline riskmonitoring tag escalationtoken migration support gap
Binance is included as a Tier 1 negative-intel row because the reported announcement creates direct adverse market-access consequences for six named tokens: futures settlement on August 7, service removals across multiple products, spot delisting on August 17, and withdrawal deadlines through October 17. The row is marked medium-high confidence because the accessible primary Binance page was not fully extractable during this run, while crypto.news cites the Binance announcement and provides a detailed timetable.
Listing post-mortem use: Use when reviewing tokens that moved from monitoring tags, project wind-down or migration uncertainty into full exchange removal, especially where derivatives settlement and withdrawal deadlines amplified post-listing liquidity loss.
Source
2026-08-03
Tier 1
Hashdex Bitcoin ETF (NYSE Arca: DEFI)
Hashdex announced it will close and liquidate the Hashdex Bitcoin ETF, stop accepting creation orders after August 17, 2026, delist shares from NYSE Arca after the last trading day, and pay a cash liquidating distribution around August 28 after selling remaining bitcoin holdings.
United States
Hashdex Asset Management Ltd. / NYSE Arca fund listing context
Crypto ETF / regulated fund products / listed Bitcoin exposure
high confidence
ETF liquidationfund delistingweak assets under managementtrading-liquidity pressureforced bitcoin liquidationcash distribution timing riskproduct-line rationalization
Hashdex Bitcoin ETF is included as Tier 1 because the sponsor itself confirmed a dated fund closure, creation-order stop, NYSE Arca delisting, remaining bitcoin liquidation and cash distribution timetable, creating direct adverse market-access consequences for the listed crypto fund product.
Listing post-mortem use: Use as a post-listing benchmark for ETF/ETP products whose listing thesis depended on sustained AUM, secondary-market liquidity, low operating-cost drag, and differentiated product positioning against larger issuers.
Source
2026-08-01
Tier 3
Unauthorised EU-facing crypto-asset service providers
ESMA highlighted expectations that unauthorised crypto-asset service providers must wind down activities in an orderly way and protect investors after the MiCA transitional period ended on 1 July 2026.
European Union
European Securities and Markets Authority (ESMA)
Crypto regulation / CASP licensing / EU market access
high confidence
unauthorised CASP market-access riskorderly wind-down obligationEU investor protection riskMiCA transition enforcement pressureexchange and wallet service continuity risklisting venue jurisdiction risk
ESMA is included as a Tier 3 watchlist row because its official public statement turns the post-MiCA transition gap into an explicit wind-down and investor-protection expectation for unauthorised CASPs. No single project is named, but the signal is useful for longitudinal EU market-access monitoring and listing post-mortems.
Listing post-mortem use: Use as jurisdiction radar when reviewing listings whose liquidity, user acquisition, custody access, or compliance narrative depended on European retail availability through unauthorised or unclear-status CASPs.
Source
2026-08-01
Tier 2
CoinEx
Crypto.news reported that WSJ/TRM-linked analysis traced more than $3.84 billion in Iran-linked flows through CoinEx since 2019, including activity connected to Central Bank of Iran wallets and North Korea-related Bybit-hack proceeds, while CoinEx denied knowingly facilitating sanctioned activity and said it strengthened sanctions controls.
United States / Iran / Hong Kong
US sanctions authorities and blockchain-forensics reporting cited by crypto.news
Centralized exchanges / sanctions compliance / AML transaction monitoring
medium-high confidence
Iran sanctions exposureoffshore exchange AML controlshigh-risk flow concentrationNorth Korea hack proceeds linkagereactive compliance remediationstablecoin freeze and seizure risk
CoinEx is included as a Tier 2 negative-intel row because the current crypto.news synthesis, citing WSJ/TRM-linked analysis, names the exchange, describes a $3.84B Iran-linked flow pattern, identifies sanctions and hack-proceeds vectors, and records CoinEx denial/remediation claims. It is not Tier 1 because no final enforcement action against CoinEx was verified in this run.
Listing post-mortem use: Use when reviewing listings or liquidity programs that relied on CoinEx access, offshore CEX market depth, lax-KYC routing, or counterparties later exposed to Iran/North Korea sanctions-flow allegations.
Source
2026-08-01
Tier 1
Virtual currency kiosk operators in Minnesota
Minnesota's new law bans virtual currency kiosks from operating in the state beginning August 1, 2026, requires public-facing kiosks to be removed by December 31, 2026, and requires affected kiosk-only operators to pay out customer money or virtual currency unless customers retain another access path.
US / Minnesota
Minnesota Legislature / Minnesota House of Representatives
Crypto ATMs / retail fiat on-ramps / scam infrastructure controls
high confidence
statewide crypto ATM banretail on-ramp shutdownpublic kiosk removal obligationcustomer payout obligationscam and elder-fraud controlsstate-level product restrictionphysical cash-to-crypto access loss
Minnesota is included as Tier 1 because an official legislative summary confirms a statewide virtual-currency kiosk ban effective August 1, 2026, with direct adverse consequences for operators: operation shutdown, public kiosk removal, and customer payout obligations. The row is sector-level rather than tied to a single token, but it is structured for retail on-ramp and scam-infrastructure monitoring.
Listing post-mortem use: Use when reviewing assets, wallet funnels, or retail-liquidity programs that depended on cash-to-crypto kiosk access, high-risk consumer acquisition, or physical on-ramp density in US state markets.
Source
2026-07-30
Tier 2
Coinkite COLDCARD hardware wallet firmware
Coinkite warned that COLDCARD seeds generated on Mk3 firmware 4.0.1 and later may be at risk, and that Mk4, Mk5, and Q seeds generated before fixed firmware releases had about 72 bits of entropy rather than the expected 128 bits.
Global
Coinkite official security advisory
Bitcoin self-custody / hardware wallets / key-management security
high confidence
weak seed entropyhardware wallet firmware flawuser fund migration riskBitcoin self-custody compromise risksupply-chain security due diligencecustody-infrastructure vendor risk
Coinkite is included because its official advisory confirms a seed-generation entropy flaw affecting COLDCARD Mk3 and some Mk4/Mk5/Q firmware states, with direct user-fund migration implications. Media reports and chain researchers associated the issue with large BTC drains, but the database row keeps the confirmed adverse signal anchored to the official advisory.
Listing post-mortem use: Use when reviewing wallet, custody, Bitcoin treasury, or security-tool listings where diligence relied on hardware-wallet reputation without firmware-version, entropy-generation, or user-migration risk checks.
Source
2026-07-29
Tier 2
Crypto DAO Pro token contract
Crypto Times reported that Blockaid flagged an access-control exploit in Crypto DAO's Pro token contract that transferred approximately $8.2M in USDT through a publicly callable vault function.
Global / BNB Chain
Blockaid / on-chain security monitors
BNB Chain DeFi / DAO token / vault contract security
medium confidence
access-control bugvault-drain exploitBNB Chain contract riskunaudited-contract riskstablecoin losson-chain incident response
Crypto DAO is included as Tier 2 because the exploit has a named protocol, chain, loss estimate, affected asset, and clear risk vector, but current verification is based on media citing security monitors rather than a project post-mortem.
Listing post-mortem use: Use when reviewing newly listed DAO or BNB Chain tokens where contract ownership, privileged vault functions, and audit status were underweighted before market access expanded.
Source
2026-07-29
Tier 2
LULA token on BNB Chain
Security monitors reportedly flagged a LULA reserve-manipulation attack using the recycle() function and a large flash loan, draining about $578.1K from a PancakeSwap V2 liquidity pool.
Global / BNB Chain
TenArmor / BlockSec Phalcon / CertiK security monitors
BNB Chain token / PancakeSwap liquidity / memecoin-style contract risk
medium confidence
reserve manipulationflash-loan exploitprivileged token functionPancakeSwap liquidity drainBNB Chain contract risklong-tail-token market integrity
LULA is included as Tier 2 because the incident has a named token, chain, estimated loss, exploit mechanism, and security-firm attribution, but no project-authored post-mortem was verified during this run.
Listing post-mortem use: Use when assessing long-tail token listings that had opaque tokenomics, privileged recycling functions, or PancakeSwap-dependent liquidity before broader venue access.
Source
2026-07-29
Tier 2
Lazy Summer Protocol vaults
A Lazy Summer governance RFC proposed removing every remaining Ark from all vaults across networks, leaving each vault as a buffer-only ERC-4626 withdrawal shell after a July 6 exploit and before the Summer.fi UI sunset scheduled for 31 August 2026.
Global
Lazy Summer DAO governance forum
DeFi yield vaults / DAO governance / multi-chain risk management
high confidence
post-exploit vault neutralizationwithdrawal-only product statestrategy offboardingDAO governance execution riskUI sunset riskmulti-chain vault exposure
Lazy Summer is included because its official governance forum records a concrete post-exploit plan to neutralize vaults into withdrawal-only shells across several networks.
Listing post-mortem use: Use for post-mortems on DeFi vault or yield-token listings where the product state changed from yield generation to withdrawal-only redemption after exploit remediation.
Source
2026-07-28
Tier 2
Altura Vault
Altura said a bank temporarily restricted the account holding funds intended for a fiat-to-USDT OTC conversion, delaying the final Vault redemption phase after the protocol had already begun an orderly wind-down.
GB / Global
Unidentified banking institution / Altura official statement
DeFi yield / RWA liquidation / stablecoin vault wind-down
high confidence
banking access lossredemption delayRWA liquidation dependencyOTC conversion dependencystablecoin vault wind-downcommunity-channel pause
Altura is included because an official project statement confirms a bank-account restriction that directly delayed user redemptions during a DeFi/RWA vault wind-down.
Listing post-mortem use: Use when reviewing RWA or stablecoin-vault listings whose liquidity promise relied on banked fiat rails, OTC conversion partners, or management-controlled off-chain liquidation steps.
Source
2026-07-27
Tier 3
Crypto platforms and issuers subject to U.S. state enforcement
New York Attorney General Letitia James urged Congress to strengthen crypto oversight, warning that the CLARITY Act could weaken state enforcement while NY crypto scam complaints tripled over three years and nearly $500M was reported to the office over five years.
US / New York
New York Attorney General
Crypto policy / consumer protection / state enforcement
high confidence
state enforcement riskconsumer scam complaintsfederal preemption concerncrypto legislation uncertaintyplatform oversight debatepolicy hearing signaljurisdictional risk shift
The NY AG warning is included as Tier 3 watchlist intelligence because it is official, current, and useful for jurisdiction-radar and longitudinal state-enforcement monitoring, but it is not a named enforcement action against a specific crypto project.
Listing post-mortem use: Use as jurisdictional context when reviewing U.S.-facing listings, consumer-token campaigns, or platform launches that relied on assumptions about federal preemption of state crypto enforcement.
Source
2026-07-26
Tier 1
BitMart exchange
BitMart announced an orderly cessation of operations, stopped new registrations, deposits, and orders on July 26 UTC, and secondary on-chain monitors reported withdrawal delays and reduced liquid wallet balances as users were instructed to remove assets before the platform shuts down.
Global / AU licensing context
BitMart / Nansen / Lookonchain / on-chain monitors
Centralized exchange / custody / market access / venue continuity
medium-high confidence
exchange wind-downwithdrawal delay riskdeposit and order haltwallet liquidity stresscustomer exit rushvenue-continuity riskrecent licensing-growth reversal
BitMart is included as Tier 1 because the exchange cessation is a confirmed direct adverse consequence affecting registrations, deposits, orders, trading timetable, and eventual platform closure. Withdrawal-stress details remain secondary and are treated as risk amplification, not as a proven insolvency finding.
Listing post-mortem use: Use when reviewing tokens whose exchange access, market-maker inventory, or retail liquidity depended on BitMart spot or futures markets, especially if withdrawal delays or wallet-liquidity stress affected post-listing exits.
Source
2026-07-26
Tier 1
AERGOUSDT perpetual contract on KuCoin Futures
KuCoin Futures announced scheduled delisting of the AERGOUSDT perpetual contract on July 28, 2026 UTC, with new-position restrictions before delisting.
Global
KuCoin Futures
Centralized exchange derivatives / token migration listing risk
medium-high confidence
exchange delistingperpetual futures liquidity contractionforced position managementmarket-access frictiontoken migration riskderivatives support contraction
KuCoin Futures surfaced an official announcement in search results stating that it will delist the AERGOUSDT perpetual contract at 07:00 UTC on July 28, 2026. The live page returned a regional access restriction during collection, so the row is classified with medium-high confidence from an official exchange search snippet and preserved as a confirmed exchange action for derivatives-listing risk tracking.
Listing post-mortem use: Use as a comparable when reviewing tokens whose post-listing support deteriorates around token swaps, ticker migrations, low-liquidity futures, or exchange product cleanups before spot delisting decisions.
Source
2026-07-26
Tier 1
WEMIX$ stablecoin system and WEMIX3.0 bridge infrastructure
WEMIX disclosed unauthorized WEMIX$ minting after contract control was compromised, with reports of about 5.22M WEMIX$ minted and 724,198 USDC.e moved while bridges, liquidity pools, PNIX DEX modules, NFT functions, and game-linked features were temporarily suspended.
Global / WEMIX3.0
WEMIX Foundation / ecosystem incident response
Layer-1 ecosystem / stablecoin module / bridges / game-chain infrastructure
high confidence
admin privilege compromiseunauthorized stablecoin mintingbridge suspensionliquidity-pool suspensioncross-chain laundering pathexchange freeze requestsgame-chain service restrictions
WEMIX is included as Tier 1 because the signal includes a project security update and direct adverse consequences: unauthorized minting, cross-chain movement of proceeds, suspension of bridges and pools, and restrictions across DEX, NFT, and game-linked infrastructure. The loss figure is smaller than many bridge exploits, but the control-plane blast radius is high.
Listing post-mortem use: Use when assessing assets whose liquidity and user activity depend on ecosystem stablecoins, bridge routing, game integrations, and admin-controlled service modules that can be frozen after contract compromise.
Source
2026-07-26
Tier 1
Storj Labs
Storj Labs announced voluntary Chapter 11 financial restructuring to resolve legacy liabilities while services continue, with media reporting the proceeding as case 5:26-bk-00512 and STORJ token selling pressure after the filing.
US
U.S. Bankruptcy Court for the Northern District of West Virginia / Storj Labs
Decentralized storage / public token / corporate restructuring
high confidence
Chapter 11 restructuringlegacy liabilitiestoken price drawdownservice-continuity riskcorporate solvency pressurecustomer/vendor uncertaintytoken-equity separation risk
Storj Labs is included as Tier 1 because a voluntary Chapter 11 filing is a confirmed judicial restructuring with direct adverse corporate and market consequences. The company states services are expected to continue, so the row should be used as solvency and governance risk rather than evidence of protocol shutdown.
Listing post-mortem use: Use when reviewing tokens where listed-asset performance depends on a corporate sponsor whose balance sheet, liabilities, or restructuring process can affect market confidence despite protocol continuity claims.
Source
2026-07-25
Tier 2
Triple-A hot wallet infrastructure
Security researchers reported that Triple-A-linked hot wallets were drained of roughly $9.3M-$9.7M across multiple chains, with stolen assets swapped, bridged, and consolidated into ETH on Ethereum.
SG / Global
PeckShield / Specter on-chain investigators
Crypto payments / merchant settlement / hot-wallet custody
high confidence
hot-wallet compromisemulti-chain asset drainpayments infrastructure riskmerchant settlement riskcross-chain laundering pathno official incident report foundpreliminary on-chain estimates
Crypto Times, CoinPedia, PeckShield-linked alerts, and Specter reporting indicate that Triple-A-linked hot wallets were drained across TRON, Ethereum, TON, Solana and other networks, then bridged and consolidated into an Ethereum wallet holding about 5,227 ETH. No Triple-A official incident report was found during the run, so this is classified as Tier 2 high-confidence security-firm-attributed negative intelligence.
Listing post-mortem use: Use when analyzing projects, exchanges, or merchant-payment tokens whose adoption story depends on payment gateway integrations, stablecoin settlement rails, or custodial hot-wallet operators with limited public controls.
Source
2026-07-24
Tier 2
Binance monitoring-tag review for Across Protocol, Lisk, and Stacks
Binance reportedly added ACX, LSK, and STX to its Monitoring Tag list, placing the assets under closer periodic review for volatility, liquidity, development activity, security, communication, tokenomics, and operational risk, with possible delisting if listing criteria are no longer met.
Global
Binance
Centralized exchange listing quality / token market structure
medium-high confidence
listing frictionmonitoring tagpotential delisting riskliquidity reviewdevelopment activity reviewtokenomics reviewmarket pressure
Binance ACX/LSK/STX monitoring is included as Tier 2 because it is a named exchange listing-friction signal with direct review consequences but no immediate trading suspension. Confidence is medium-high because the official Binance support notice was not directly retrieved during the run, though crypto.news reported specific criteria and effective date.
Listing post-mortem use: Use as a direct listing post-mortem input for tokens where Binance monitoring tags preceded liquidity drawdown, market-maker repricing, exchange concentration risk, or delisting decisions.
Source
2026-07-24
Tier 3
Crypto holders, custody operators, and wallet providers exposed to physical coercion
CertiK reported 52 verified crypto wrench-attack incidents in H1 2026, up 33.3% year over year, with recorded losses and ransom demands around $124.1M and Europe, especially France, concentrated in the visible dataset.
Global / Europe / FR
CertiK Intel3D
Physical security / custody / wallet controls
high confidence
physical coercionwrench attackhome invasionkidnappingransom demandprivate-key compromise under duressidentity-data leakagecustody-design risk
CertiK Intel3D reported that verified H1 2026 crypto wrench attacks rose to 52 incidents from 39 a year earlier, while recorded financial exposure increased to roughly $124.1M from about $10.5M. Because the signal is sector-level and not a project-specific enforcement or exploit, it is included as Tier 3 watchlist intelligence for custody and signer-risk monitoring.
Listing post-mortem use: Use as sector context when evaluating treasury-signing arrangements, founder-controlled wallets, wallet-provider controls, exchange data-leak exposure, and projects whose token treasury can be moved by a small number of identifiable people.
Source
2026-07-24
Tier 2
Lien Finance
SlowMist reported that Lien Finance lost roughly 542,144.63 USDC after attackers exploited bond-token exchange validation and pricing logic to mint unsupported assets and drain USDC liquidity.
Global / Ethereum
SlowMist / Defimon Alerts
Ethereum DeFi / structured bond tokens / OTC liquidity pools
high confidence
DeFi exploitbond-token validation flawunsupported synthetic asset mintingOTC pool pricing failurepermissionless bond registrationUSDC liquidity drainno official post-mortem found
Lien Finance is included as Tier 2 high-confidence negative intelligence because SlowMist identified a concrete 542,144.63 USDC loss tied to exchangeEquivalentBonds validation weaknesses, while Defimon Alerts described related OTC-pool pricing and permissionless bond-registration issues. It is not Tier 1 only because no direct Lien Finance official post-mortem or protocol action was verified during this run.
Listing post-mortem use: Use when reviewing listings or integrations for structured DeFi protocols that create synthetic bond-like assets and depend on internal pricing functions rather than deep external-market pricing.
Source
2026-07-24
Tier 1
Zilliqa native Ledger app and Upbit ZIL markets
Upbit placed ZIL under cautionary status for KRW and BTC markets while deposits and withdrawals remained suspended after Zilliqa disclosed a Ledger app nonce-generation flaw that can expose private keys after roughly five native transactions.
KR / Global
Upbit / Zilliqa
Layer-1 / hardware-wallet signing / centralized exchange market access
high confidence
exchange cautionary assetdeposit and withdrawal suspensionLedger app signing flawprivate-key recovery risknative transaction haltmarket-access reviewrecovery-plan uncertainty
Zilliqa/Upbit is included as a new Tier 1 row because it adds a distinct exchange-market consequence to the July 20 ZIL theft/transfer-halt row: Upbit placed ZIL under cautionary status across KRW and BTC markets while deposits and withdrawals remained suspended after Zilliqa disclosed the Ledger app signing flaw and native transaction halt.
Listing post-mortem use: Use when reviewing tokens whose exchange liquidity survived spot trading but settlement reliability, custody safety, and market-maker inventory movement were impaired by deposit-withdrawal suspensions and cautionary designations.
Source
2026-07-24
Tier 1
Bitkub Online Co. Ltd. / Bitkub Exchange
Thailand SEC filed a criminal complaint alleging Bitkub concealed or falsely reported a 2021 cyberattack that caused roughly THB 1.7B / $47M-$51M in losses, escalating a historical exchange hack into active regulatory and criminal process.
TH
Thailand Securities and Exchange Commission / Economic Crime Suppression Division
Centralized exchange / cybersecurity disclosure / VASP supervision
medium-high confidence
criminal complaintregulatory disclosure failureexchange cybersecurity incidentfalse reporting allegationcustomer asset lossmanagement accountabilityThailand VASP supervision
Multiple July 27 news wires reported that Thailand SEC filed a criminal complaint against Bitkub Online over alleged concealment or false reporting tied to a 2021 hack of roughly THB 1.7B / $47M-$51M. The official SEC domain was blocked during collection, so confidence is capped at medium-high, but the named regulator, exchange, alleged loss, jurisdiction, and criminal-referral consequence are sufficient for Tier 1 regulatory negative intelligence.
Listing post-mortem use: Use when reviewing Thai or APAC exchange listings where liquidity quality depended on a venue later accused of underreporting cyber losses or misrepresenting operational resilience.
Source
2026-07-24
Tier 2
Apple App Store / fake Sparrow Wallet applications
Three users filed a federal lawsuit alleging fake Sparrow Wallet apps distributed through Apple App Store captured seed phrases and caused about $1.835M in Bitcoin losses before Apple removed impersonating apps and terminated linked developer accounts.
US
U.S. District Court for the Northern District of California
Wallet distribution / scam infrastructure / app marketplace controls
high confidence
fake wallet appseed phrase theftapp marketplace vetting riskconsumer lawsuitBitcoin lossbrand impersonationdistribution-channel scam infrastructure
The Apple/Sparrow case is included as Tier 2 scam-infrastructure litigation because it has a named court, named platform, named impersonated wallet, alleged BTC loss amount, and a clear seed-phrase theft vector. Claims remain untested, but the distribution-control signal is useful for wallet and consumer-risk dossiers.
Listing post-mortem use: Use when analyzing projects whose retail adoption depends on wallet-app distribution, brand-protected download paths, or third-party marketplaces where impersonation can drain user assets after listing hype.
Source
2026-07-24
Tier 2
BitMEX / HDR Global Trading Limited
A proposed class action filed in SDNY alleges BitMEX and affiliates retained customer bitcoin collateral through unfair liquidations and insider trading, seeking return of 622.66 BTC as the exchange prepares to cease operations on September 23, 2026.
US / Global
U.S. District Court for the Southern District of New York / BitMEX
Centralized derivatives exchange / perpetual swaps / customer collateral
high confidence
class-action litigationcustomer collateral disputeforced liquidation allegationsinsider trading allegationsexchange shutdownwithdrawal deadline risklegacy derivatives venue risk
CourtListener shows a July 23, 2026 class-action complaint in BKX Services Inc. and David Namdar v. HDR Global Trading Limited et al. seeking recovery of bitcoin and alleging theft, fraud, and BitMEX exchange manipulation. CoinDesk and Benzinga reported that the plaintiffs claim 622.66 BTC in losses and that the case coincides with BitMEX preparing to cease operations on September 23, 2026, making this a Tier 2 legal and venue-continuity negative-intel row rather than a final judicial finding.
Listing post-mortem use: Use when reviewing assets whose liquidity quality, price discovery, or post-listing market structure depended on BitMEX derivatives markets, especially where forced liquidations, insurance-fund mechanics, or venue wind-down risk affected investor outcomes.
Source
2026-07-24
Tier 2
Binance / Changpeng Zhao / FTX Recovery Trust
Bloomberg Law reported that an FTX trust received permission to pursue Binance and Changpeng Zhao over alleged $1.76B fraudulent-transfer claims tied to a 2021 share repurchase, while some damages claims were dismissed.
US / Global
U.S. Bankruptcy Court / FTX Recovery Trust
Centralized exchange / bankruptcy litigation / exchange founder counterparty risk
medium-high confidence
bankruptcy litigationfraudulent transfer claimexchange founder litigationlegacy exchange transaction riskestate recovery actionreputational riskclaims not adjudicated
The FTX/Binance row is Tier 2 because it is a credible court-process signal with named parties, amount, legal theory, and partial claim survival, but it is not a final judgment or enforcement order. It is useful for exchange-risk dossiers and legacy listing post-mortems.
Listing post-mortem use: Use when analyzing tokens or venues whose market quality was shaped by inter-exchange deals, founder-controlled settlements, or bankruptcy-estate clawback risk after counterparty collapse.
Source
2026-07-23
Tier 1
AFX Trade bridge infrastructure
AFX Trade was drained of roughly 24.15M USDC after an attacker compromised validator signing keys for a bridge operated by the protocol; Offchain Labs said Arbitrum native bridge infrastructure was not exploited.
Global / Arbitrum
AFX Trade / Blockaid / Offchain Labs
Perpetual DEX / cross-chain bridge / Arbitrum protocol infrastructure
high confidence
bridge exploitvalidator signing key compromisehot-key quorum failureUSDC treasury drainthird-party Arbitrum protocol riskTVL depletionoff-chain operational security
AFX Trade is included as Tier 1 because security firm Blockaid and CoinDesk reported a confirmed 24.15M USDC drain from AFX-operated bridge infrastructure, with Offchain Labs clarifying that Arbitrum native bridge infrastructure was not breached. The direct adverse consequence was a near-total protocol TVL drain and attacker conversion of stolen USDC into roughly 12,467 ETH.
Listing post-mortem use: Use when reviewing listings whose liquidity, CEX market-making, or collateral settlement relied on third-party bridge reserves controlled by validator hot keys or small multisig/quorum structures.
Source
2026-07-23
Tier 1
BitMEX exchange
BitMEX announced a dated exchange closure in July and, on September 23, 2026 at 04:00 UTC, ended exchange trading and deposits while keeping web withdrawals available and scheduling API withdrawals to be disabled on September 28.
Global / Seychelles corporate context
BitMEX / HDR Global Trading Limited
Centralized exchange / derivatives / custody / venue continuity
high confidence
exchange closurevenue-continuity riskderivatives market-access lossforced position managementwithdrawal deadline riskexchange consolidationBMEX utility impairmenttrading halteddeposit haltAPI withdrawal cutoffpost-closure withdrawal-only mode
BitMEX remains Tier 1 because the earlier official closure has now taken effect: exchange operations ended on September 23, 2026, trading and deposits stopped, and remaining user exposure shifted to withdrawal execution and cutoff management.
Listing post-mortem use: Use as a realized exchange-winddown comparator for tokens or strategies reliant on legacy offshore derivatives venues: check staged delistings, position closeout windows, deposit cutoffs, web/API withdrawal rules, residual litigation, and user communication cadence.
Source
2026-07-23
Tier 1
B² Network token staking contract
B² Network said an attacker gained unauthorized access to the upgrade authority of its token staking contract; on-chain trackers reported roughly 3.86M in B2-related value drained, sold, bridged, and moved through cross-chain routes.
Global / BNB Chain / Bitcoin scaling ecosystem
B² Network / PeckShield / Lookonchain
Bitcoin scaling network / staking contract / BNB Chain token liquidity
medium-high confidence
upgrade authority compromisestaking contract exploitadmin key riskB2 token drainBNB Chain liquidity sell pressurecross-chain laundering pathcompensation obligation
B² Network is included as Tier 1 because CoinDesk reported that B² itself said an attacker gained unauthorized access to the staking contract upgrade authority, after which Lookonchain traced roughly 3.86M in B2-related value sold and moved cross-chain. The row is high enough confidence for public tracking, though capped at medium-high pending a full project post-mortem.
Listing post-mortem use: Use for post-listing reviews of tokens where staking contracts, proxy upgrade keys, or admin-controlled distribution contracts create market-impacting exploit paths independent of core network security.
Source
2026-07-23
Tier 2
Solido Money
Solido Money reported that two exploit waves generated 293.7M SUPRA in net proceeds by abusing an oracle misassignment and insufficient risk limits, with about 84% of proceeds traced to centralized exchange infrastructure and exchange assistance requested.
Global / Supra ecosystem
Solido Money forensic report / centralized exchange infrastructure
DeFi lending / oracle pricing / exchange laundering response
medium-high confidence
oracle misassignmentDeFi exploitinsufficient risk limitssynthetic asset mintingcentralized exchange tracingrecovery dependencyforensic report
Solido Money is included as Tier 2 because the July 28 forensic coverage adds a structured exploit-and-recovery record with named protocol, asset, mechanism, proceeds, exchange-tracing path, and recovery dependency. It is not Tier 1 here because the run did not verify a direct protocol halt or official primary report URL.
Listing post-mortem use: Use when reviewing DeFi listings where oracle assignment, collateral haircuts, risk limits, and exchange-side recovery cooperation determine whether an exploit becomes a market-wide token-liquidity event.
Source
2026-07-23
Tier 1
Verus Ethereum Bridge
Blockaid detected a second Verus Ethereum Bridge exploit that drained roughly 7.54M in assets through the same bridge contract, entry path, and apparent bug class involved in the May 2026 breach.
Global / Ethereum / Verus
Blockaid / Verus ecosystem security monitoring
Cross-chain bridge / Bitcoin and Ethereum-linked asset reserves
high confidence
repeat bridge exploitunbacked Ethereum-side payoutsimport path validation failuresame bug class recurrencebridge reserve drainremediation failurecross-chain asset custody risk
Verus Ethereum Bridge is included as Tier 1 because Blockaid reported a fresh 7.54M reserve drain on July 23, with crypto.news noting the attack used the same bridge contract, entry path, and apparent bug class as the May 2026 Verus exploit already in the database. This is a high-value repeat adverse consequence rather than a mere follow-up.
Listing post-mortem use: Use as a repeat-failure comparable where a project suffered a prior exploit, recovered or redeposited assets, then experienced a second drain before a durable technical fix was proven.
Source
2026-07-22
Tier 2
42DAO / Balance Protocol
Security firms reported that 42DAO-linked Balance Coin suffered an oracle-manipulation exploit that drained roughly $912K-$915K and caused BLC to lose more than 99% of its dollar peg.
Global / BNB Chain
PeckShield / SlowMist / TenArmor
Algorithmic stablecoin / DeFi lending and liquidation infrastructure
high confidence
oracle manipulationstablecoin depegunauthorized liquidationMaker-style fork without safeguardsBNB Chain liquidity drainmissing price deviation checksno public recovery plan
42DAO/BLC is included as a Tier 2 high-confidence negative-intel row because PeckShield and SlowMist reported a roughly $912K-$915K exploit tied to BTCB oracle manipulation, while BLC depegged by more than 99%. The event has direct market consequence and named security-firm attribution, but no 42DAO official post-mortem or recovery plan was found during this run.
Listing post-mortem use: Use when reviewing listings of algorithmic stablecoins, Maker-style forks, or collateralized debt protocols whose token value depends on oracle update controls, liquidation delays, and DEX liquidity depth.
Source
2026-07-22
Tier 1
35 BitMEX derivatives contracts scheduled for early settlement
BitMEX announced early settlement and delisting of 35 derivatives contracts at 12:00 UTC on 30 July 2026 due to insufficient trading interest and the decision to close the exchange.
Global
BitMEX
Centralized exchange derivatives / perpetual futures / product rationalization
high confidence
exchange delistingearly settlementperpetual futures liquidity contractionmarket-access frictionderivatives support contractionexchange closure spillover
The 35-contract BitMEX delisting is a separate row-level signal because it identifies affected assets, a scheduled early-settlement mechanism, and a direct market-access consequence before the full exchange closure date.
Listing post-mortem use: Use as a comparable when reviewing tokens with post-listing derivatives support that disappeared because trading interest was too low or the venue itself entered wind-down.
Source
2026-07-22
Tier 3
South-East Asia scam and criminal financial infrastructure
UNODC said South-East Asia criminal groups have consolidated into an interconnected tech-driven criminal economy, with scam losses across East Asia, South-East Asia, Australia, and New Zealand estimated at USD 88.3B-114.1B in 2025 and law enforcement needing specialized crypto tracing, seizure, and recovery capacity.
South-East Asia / East Asia / Australia / New Zealand
UNODC
AML / scam infrastructure / crypto proceeds tracing
high confidence
scam infrastructurecrypto proceeds tracingmoney launderingforced criminalitycross-border settlement railsancillary service providersregional governance risk
UNODC is included as a Tier 3 sector-risk row because its July 22 report provides an official regional early-warning signal: scam losses across East Asia, South-East Asia, Australia, and New Zealand reached an estimated USD 88.3B-114.1B in 2025, and the agency explicitly highlighted the need to identify, seize, and recover funds in the new crypto context.
Listing post-mortem use: Use as jurisdiction radar when reviewing post-listing liquidity patterns, suspicious inflows, market-maker routes, OTC distribution, and stablecoin payment rails connected to Southeast Asia scam or cyber-fraud typologies.
Source
2026-07-21
Tier 1
Wanchain Cardano-BNB Chain bridge / Midnight
Wanchain said its Cardano-BNB Chain bridge was unavailable after an incident involving NIGHT withdrawals from the Cardano bridge contract; BlockSec Phalcon reported roughly 515M NIGHT drained from the bridge treasury, with an initial root-cause theory around non-injective signed-message encoding in the TreasuryCheck validator.
Global
Wanchain / BlockSec Phalcon / Midnight Foundation
Cross-chain bridge / Cardano ecosystem / token custody
high confidence
bridge exploittoken treasury drainsignature reusevalidator message-encoding flawCardano-BNB bridgeDEX sell pressurethird-party bridge dependency
Wanchain/Midnight is a Tier 1 negative-intel row because the bridge operator confirmed an incident and made the Wanchain Bridge unavailable while independent security analysis reported a roughly 515M NIGHT treasury drain. Crypto.news and Crypto Times both cited BlockSec's technical finding that raw-concatenated variable-length fields may have enabled signature reuse, while Midnight framed the issue as isolated to third-party bridge infrastructure rather than the core network.
Listing post-mortem use: Use as a comparable for listings where token float, CEX liquidity, or market-maker routing depends on wrapped assets backed by bridge treasury contracts and off-chain or threshold-signature validation.
Source
2026-07-20
Tier 1
Polymarket
French gambling-regulator coverage reported that ANJ ordered internet service providers to block Polymarket access from French territory, alleging illegal gambling-law exposure and warning that advertising unauthorized betting or gambling sites is a criminal offense.
FR
Autorite Nationale des Jeux
Prediction markets / crypto gambling interface
medium confidence
jurisdiction access blockgambling lawprediction marketsgeo-restriction failureadvertising restrictionmarket manipulation concern
Polymarket is included as a Tier 1 adverse access signal because reported French ANJ action imposes a direct market-access block and advertising-risk consequence in a major EU jurisdiction.
Listing post-mortem use: Use as a comparable for tokens or platforms whose growth depends on prediction-market volumes in jurisdictions that may classify activity as unauthorized gambling rather than financial-market infrastructure.
Source
2026-07-20
Tier 1
Zilliqa / unnamed exchange partner
Zilliqa disclosed that ZIL was stolen from a cold wallet involving one exchange partner, opened an active investigation, and asked exchanges to temporarily pause ZIL deposits and withdrawals while it verified the root cause and scope.
Global
Zilliqa
Layer-1 / exchange custody / token transfer controls
high confidence
cold-wallet theftexchange partner custodydeposit and withdrawal suspensionlegacy wallet signing issueliquidity interruptionincident disclosure gap
Zilliqa is a Tier 1 negative-intel row because the project itself confirmed stolen ZIL from an exchange-partner cold wallet and took a direct adverse action by asking exchanges to pause deposits and withdrawals. A later project update, reported by Crypto Times, said the early investigation had found no evidence that exchange wallet management caused the incident and pointed instead to a technical issue affecting transaction signing in a specific set of legacy ZIL1 wallets.
Listing post-mortem use: Use when reviewing listings where exchange custody, legacy wallet compatibility, or project-led emergency transfer halts later affected token liquidity, settlement reliability, and market-maker inventory movement.
Source
2026-07-19
Tier 1
Allbridge Core Solana stablecoin bridge
Allbridge Core disclosed a security incident, paused the protocol as a precaution, told affected-pool LPs to withdraw, and asked arbitrageurs who benefited from the pool imbalance to return funds for LP compensation; contemporaneous on-chain reporting estimated roughly $1.65M lost through Solana flash-loan price manipulation.
Global
Allbridge Core
Cross-chain bridge / stablecoin liquidity
high confidence
bridge exploitflash-loan price manipulationprotocol haltLP lossSolana DeFistablecoin pool imbalance
Allbridge Core is a Tier 1 negative-intel row because the protocol itself confirmed a security incident, paused operations, advised LP withdrawals, and opened an LP-compensation return path after a pool imbalance tied to an estimated $1.65M exploit.
Listing post-mortem use: Use as a comparable for bridge tokens or Solana DeFi assets where market makers rely on native-liquidity bridge routes and where repeat exploit vectors undermine post-listing liquidity assumptions.
Source
2026-07-19
Tier 2
Dunamu / Upbit
Multiple reports said South Korea's Financial Supervisory Service sent Dunamu an inspection opinion letter around July 18-19, formally starting a sanctions process tied to the November 2025 Upbit Solana hot-wallet breach that drained about KRW 44.5B, including customer assets.
KR
Financial Supervisory Service
Centralized exchange / VASP cybersecurity
medium confidence
cybersecurity controlshot-wallet custodyVASP supervisionsanctions processcustomer asset protectionKorea exchange regulation
Dunamu/Upbit is included as Tier 2 because the reported FSS inspection opinion letter names the exchange operator, jurisdiction, prior hack vector, loss scale, and regulatory process, but no final sanction level is public yet.
Listing post-mortem use: Use as Korea jurisdiction context when evaluating exchange concentration, custody-control failures, and post-hack regulatory overhang for assets dependent on Upbit liquidity.
Source
2026-07-17
Tier 1
Across Protocol Solana bridge deployment and Risk Labs relayer
Across Protocol disclosed an attack on its Solana deployment, disabled Solana deposits as a containment measure, said user funds and in-flight bridge transfers were safe, and identified the potentially affected exposure as Risk Labs relayer capital while investigation and post-mortem remained pending.
Global / Solana / Ethereum
Across Protocol / Risk Labs / SEAL 911
Cross-chain bridge / intent-based settlement / Solana integration
medium-high confidence
bridge attackSolana integration riskrelayer capital exposuretemporary deposit disablementintent-based settlement riskcross-chain attacker address tracingpending post-mortem
Crypto Times reported that Across Protocol disclosed an attack on its Solana deployment at about 05:30 UTC on July 17, 2026. The team said user funds were safe, all bridge transactions completed, and the only potentially lost funds belonged to the Risk Labs-operated relayer, while Solana deposits were disabled and SEAL 911 tracing began across one Solana and two EVM attacker addresses. The row is Tier 1 because the protocol confirmed a security attack and direct operational restriction, even though the immediate financial exposure appears confined to relayer capital rather than user balances.
Listing post-mortem use: Use when reviewing cross-chain listings, bridge integrations, or intent-based transfer products where a perfect historic security record masked new-chain integration risk, relayer capital exposure, or temporary deposit restrictions.
Source
2026-07-17
Tier 1
DeFiTuna lending pools
DeFiTuna disclosed that an attacker exploited its Solana lending pools and drained about $580,000, leaving a matching deficit in the protocol's USDC lending pool while recovery and root-cause investigation remained open.
Global / Solana
DeFiTuna / Solana DeFi security monitoring
Solana DeFi / lending pools / leveraged liquidity
medium-high confidence
lending pool exploitUSDC pool deficitSolana DeFi exposureleveraged liquidity protocol riskuser-fund recovery uncertaintypatched attack vector pending post-mortem
Crypto Briefing reported that DeFiTuna, a Solana-based AMM and lending protocol supporting leveraged positions, disclosed a July 16 exploit that drained about $580,000 from its lending pools and left the USDC pool with a matching deficit. The team reportedly identified and mitigated the attack vector, but recovery mechanics and user compensation remained unresolved at publication. The row is Tier 1 because it describes a confirmed protocol exploit with direct adverse consequence for a named asset pool.
Listing post-mortem use: Use for post-mortems where a Solana DeFi or yield product showed unresolved pool deficits, opaque recovery commitments, or leveraged-liquidity mechanics that made user balances dependent on protocol accounting controls.
Source
2026-07-17
Tier 3
Virtual asset service providers and stablecoin issuers
FATF's 2026 virtual-assets targeted update, as reported by AML Intelligence, warned that organised crime groups are exploiting regulatory implementation gaps, offshore VASPs, DeFi exposure, and stablecoins, including proprietary stablecoins designed to resist freezing and seizure.
Global / FATF network
Financial Action Task Force
AML/KYT / stablecoins / offshore VASPs / DeFi
medium-high confidence
AML implementation gapTravel Rule enforcement lagoffshore VASP supervision riskstablecoin seizure resistancesanctions evasionscam-compound money launderingDPRK cyber theft exposureAI-enabled fraud typologies
AML Intelligence reported that FATF's seventh targeted update on virtual assets and VASPs found progress in legal adoption of Travel Rule frameworks but persistent gaps in practical supervision and enforcement. The report highlighted organised-crime-linked scam centers, DPRK-related cyber theft, sanctions evasion, offshore VASPs, DeFi exposure, and growing illicit use of stablecoins, including proprietary stablecoins designed to resist freezing and seizure. The row is Tier 3 because it is a sector-level early warning and jurisdiction-radar signal rather than a named enforcement action.
Listing post-mortem use: Use as background for listings or integrations where issuer reserves, stablecoin rails, offshore VASP partnerships, or DeFi access points later became relevant to sanctions, fraud-flow, Travel Rule, or asset-freeze failures.
Source
2026-07-17
Tier 2
Cycurion, Inc. (Cycurion Crypto subsidiary)
Cycurion announced that Nasdaq issued a delisting determination after CYCU traded below the $1.00 minimum bid requirement for 31 consecutive business days and was ineligible for the ordinary compliance period because of a prior reverse split; the company planned to appeal before the July 17 deadline.
United States
Nasdaq Hearings Panel / Nasdaq Listing Qualifications
Public crypto treasury companies / cybersecurity issuer / exchange listing compliance
high confidence
Nasdaq minimum bid deficiencydelisting determinationreverse-split compliance limitationcrypto treasury issuer market-structure riskpublic-market listing frictionappeal outcome uncertainty
Cycurion disclosed that Nasdaq issued a delisting determination dated July 10, 2026 because CYCU failed the $1.00 minimum bid rule for 31 consecutive business days from May 26 through July 9 and was not eligible for the usual 180-day compliance period after a 1-for-30 reverse split in October 2025. The company said it would request a Nasdaq Hearings Panel review by July 17, staying suspension while the appeal is pending. The row is Tier 2 because the adverse consequence is confirmed, but the crypto link is treasury-adjacent rather than a direct token, protocol, or VASP action.
Listing post-mortem use: Use when reviewing listings or treasury-pivot narratives where public issuer compliance stress, reverse splits, minimum-bid failures, or crypto treasury announcements masked deteriorating equity market quality.
Source
2026-07-16
Tier 1
Cascade Liquidity Strategy vault
Cascade reportedly suffered a CLS vault exploit that drained about 1.34M USDC from locked user pre-allocation funds and bridged proceeds across Arbitrum, Solana, and Ethereum.
Global / Arbitrum
Cascade / PeckShield
DeFi perpetuals / prelaunch liquidity vault / RWA trading infrastructure
medium-high confidence
vault exploitlocked user fundsprelaunch liquidity strategycross-chain laundering pathUSDC-to-DAI conversionArbitrum-to-Solana bridge movementRWA perps launch risk
Crypto Times reported that Cascade, a Polychain- and Variant-backed perpetuals platform, acknowledged an exploit affecting its Cascade Liquidity Strategy vault. PeckShield said about 1.34M USDC was drained from user funds, moved from Arbitrum to Solana, then bridged to Ethereum via Relay Protocol after conversion into DAI. The row is Tier 1 because it describes a concrete protocol exploit with direct user-fund loss and traceable laundering path, with confidence capped at medium-high because the primary protocol post was not directly retrievable during this run.
Listing post-mortem use: Use when reviewing RWA/perpetual listings that relied on invite-only pre-allocation campaigns, locked liquidity strategies, or cross-chain fund routing before full public launch.
Source
2026-07-16
Tier 1
Knaken Cryptohandel B.V. and Stichting Knaken Payments
Rotterdam District Court declared Knaken Cryptohandel B.V. and its client-payments foundation bankrupt after prosecutors said about EUR 7 million in customer assets was missing, customers were locked out of the trading platform, and Knaken lacked enough assets to fully repay customers.
Netherlands / European Union
Rotterdam District Court / Dutch Public Prosecution Service / FIOD / AFM signal context
Centralized exchange / crypto custody / MiCA authorization and insolvency
high confidence
exchange bankruptcycustomer fund shortfallblocked account accesscriminal investigationcustody segregation uncertaintyFIOD seizure contextMiCA authorization gaptrustee-controlled wind-down
Rotterdam District Court published that Knaken Cryptohandel B.V. was declared bankrupt on the Public Prosecution Service request. Prosecutors said a criminal investigation had begun because about EUR 7 million in customer balances was missing; the court found customers had been blocked from accessing the trading platform, were not sufficiently informed, and could not determine their legal position. The court held that Knaken lacked enough assets to fully pay customers, appointed C.F.W.A. Hamm as trustee, and moved the wind-down outside Knaken control. The row is Tier 1 because it is an official judicial insolvency action with direct customer-access and custody consequences.
Listing post-mortem use: Use for CEX and custody post-mortems where customer balances appeared as platform ledger entries but became dependent on bankruptcy trustees, custody-foundation records, wallet reconciliation, and MiCA-style safeguarding controls after access was blocked.
Source
2026-07-15
Tier 3
NOXA.fun memecoin launchpad on Robinhood Chain
KuCoin and BingX news items reported that NOXA.fun kept new token launches disabled after copycat tokens, bot-driven bulk launches, infrastructure limits, and token-spam pressure overwhelmed the launchpad; the replacement ENS interface focuses on browsing historical launches and creator-fee claims rather than new issuance.
Global / Robinhood Chain
NOXA.fun / Robinhood Chain ecosystem
Memecoin launchpads / token issuance infrastructure
medium confidence
token-spam pressurebot-driven launchescopycat-token proliferationlaunchpad product restrictioninfrastructure downtimememecoin market-quality risk
On July 15, 2026, KuCoin coverage of Robinhood Chain memecoin activity reported that NOXA.fun had suspended new token issuance after copycat tokens and bot-driven bulk launches became severe. A BingX-captured NOXA interface update separately said the ENS-accessible interface was live for historical token browsing and creator-fee claims while new launches remained disabled due to infrastructure limits and token spam. This is Tier 3 because it is a sector-watch signal rather than a regulator, exchange delisting, or confirmed exploit.
Listing post-mortem use: Useful for post-mortems where a newly listed memecoin shows suspicious early concentration, copycat branding, launchpad-origin spam, or venue-quality deterioration tied to a permissive launch infrastructure.
Source
2026-07-15
Tier 1
Ostium OLP vault on Arbitrum
Ostium paused all trading after an oracle signer-key compromise reportedly enabled future-dated price reports and drained approximately $11.86M-$18M USDC from the OLP liquidity vault.
Global / Arbitrum
Ostium / Blockaid / Arbitrum security researchers
DeFi perpetuals / RWA onchain trading / oracle infrastructure
high confidence
oracle signer key compromiseDeFi perpetuals vault draintrading haltRWA perps liquidity disruptionfuture-dated price reportsArbitrum protocol exposurefrozen trader positions
Blockaid reported that an attacker used a compromised Ostium oracle signer key and a registered PriceUpKeep forwarder to submit future-dated authorized price reports, producing artificial trading profits and draining the OLP vault on Arbitrum. Ostium publicly said it was aware of an OLP vault issue, paused all trading, and later said trader funds and open positions were preserved but frozen while the team investigated with security experts. Loss estimates vary between roughly $11.86M and $18M USDC, making this a Tier 1 protocol action with direct adverse consequence.
Listing post-mortem use: Use for post-mortems on RWA/perpetual venues where institutional backing, audits, or market-maker partnerships masked oracle-signer and vault-settlement concentration risk.
Source
2026-07-14
Tier 3
Pre-MiCA crypto-asset service providers operating in Europe
Multiple reports said only around 17-20% of more than 1,200 pre-MiCA crypto firms secured CASP authorisation before the July 1, 2026 transition cutoff, leaving a large tail of firms potentially unable to continue compliant EU service.
EU
EU MiCA / national competent authorities
Crypto-asset service providers / exchange and wallet access
medium confidence
licensing gapMiCA transitionmarket-access attritionCASP authorizationEU retail accessoffshore-app leakage
Finance Magnates and other industry sources reported a large post-MiCA transition gap, with roughly 80% of previously registered European crypto firms failing to secure CASP authorisation before the July 1, 2026 cutoff. This is classified as Tier 3 because it is a jurisdiction-level early-warning signal rather than a named enforcement action, but it is valuable for longitudinal monitoring of EU exchange access, venue consolidation, and listing-risk post-mortems.
Listing post-mortem use: Useful for weekly listing reviews where a token claims EU liquidity or distribution but the venue stack may be non-compliant, migrating customers, or losing access after MiCA transition deadlines.
Source
2026-07-14
Tier 1
BitMEX illiquid spot pairs scheduled for delisting
BitMEX announced it will delist nine spot pairs at 12:00 UTC on July 16, 2026, citing insufficient trading interest; all trading will cease and open orders will be canceled at settlement.
Global
BitMEX
Centralized exchange spot markets / listing liquidity
high confidence
exchange delistinginsufficient trading interestspot liquidity deteriorationopen-order cancellationmarket-access losslisting maintenance failure
BitMEX published an official July 2026 delisting notice saying UNI_USDT, APE_USDT, ATOM_USDT, AXS_USDT, BONK_USDT, LINK_USDT, POL_USDT, S_USDT, and TRX_USDT spot pairs will be delisted on July 16, 2026 because of insufficient trading interest. This is a Tier 1 exchange action because it has a direct adverse market-access consequence, a defined settlement time, and automatic open-order cancellation.
Listing post-mortem use: Use to test whether listing reviews distinguish token-level quality from pair-level venue liquidity, and whether low-interest pairs are monitored before exchange delisting forces order cancellation.
Source
2026-07-14
Tier 1
Lumi Finance / Sodium smart accounts on Arbitrum
Lumi Finance reportedly lost roughly $270,000 after a Sodium ERC-4337 smart-account validation flaw let an attacker-controlled paymaster obtain token allowances and batch-drain affected user accounts on Arbitrum.
Global
Blockaid / SlowMist / Lumi Finance ecosystem
Account abstraction / DeFi stablecoin and game-economy infrastructure
medium-high confidence
smart-account validation side effectsERC-4337 account abstractionunauthorized token approvalsuser wallet drainmalicious paymasterArbitrum DeFi exposurepermission revocation urgency
Crypto Times reported that Blockaid and SlowMist traced a roughly $270,000 Lumi Finance drain on Arbitrum to Sodium smart accounts performing token approvals as a side effect of ERC-4337 UserOperation validation. The attacker allegedly used a malicious paymaster/spender path, swept newly approved assets including LUA, LUAUSD and stablecoins, swapped proceeds to ETH, and transferred them to an attacker wallet. The event is Tier 1 because it is a concrete protocol-adjacent exploit with direct user-asset loss, though confidence remains medium-high until Lumi publishes its own full incident report.
Listing post-mortem use: Use for post-mortems on DeFi/game-economy tokens where protocol TVL looks small but user-side smart accounts hold larger at-risk balances, and where ERC-4337 validation assumptions were not part of listing due diligence.
Source
2026-07-14
Tier 1
Kalshi Michigan sports event contracts
Media reports said a Michigan state court temporarily barred Kalshi from offering sports event contracts to Michigan residents, while the CFTC stayed Kalshi's emergency-rule application to unwind or cancel affected Michigan trades, creating a direct conflict over venue access and settlement obligations.
United States / Michigan
CFTC; Ingham County Circuit Court; Michigan state authorities
Prediction markets / event-contract exchanges
high confidence
state-federal regulatory conflictsports event-contract restrictiontrade-cancellation disputevenue-access risksettlement obligation uncertaintyprediction-market compliance
On July 14, 2026, multiple outlets reported that a Michigan court order restricted Kalshi sports event contracts for Michigan residents and that the CFTC moved to stop Kalshi from canceling or unwinding affected trades under an emergency-rule filing. The row is Tier 1 because it reflects named judicial/regulatory action with direct adverse access and settlement consequences, even though the source used for this run is reputable media rather than the underlying court docket.
Listing post-mortem use: Useful when reviewing prediction-market tokens, event-contract venue integrations, or market-maker exposure to products where state access controls can force cancellation, refund, or settlement conflict.
Source
2026-07-13
Tier 2
SCATMAN token promoted through compromised SpaceXAI and Starlink X accounts
Multiple crypto media reports, citing Lookonchain on-chain tracing, said compromised SpaceXAI and Starlink X accounts were used to promote SCATMAN before attacker-linked wallets dumped roughly $125,000-$135,000 worth of ETH proceeds.
Global
N/A
Meme coin / social-account scam infrastructure
medium confidence
account compromiserug pullsocial engineeringmeme coinon-chain scamRobinhood Chain
SCATMAN is included as a Tier 2 negative-intel record because it links named compromised accounts, a named token, attacker wallet monetization, and a repeatable social-account rug-pull pattern, despite the absence of an official SpaceX or Starlink statement during this run.
Listing post-mortem use: Useful for post-mortems where a token experienced an early viral spike after high-profile social amplification and then collapsed after insider or attacker wallets exited.
Source
2026-07-13
Tier 2
High-volume USDT trading through Thai platforms
The Bank of Thailand and Thai SEC reportedly initiated deep audits into high-volume USDT trades structured to conceal ownership or bypass onshore remittance channels, with suspicious findings referred to the SEC for disciplinary or statutory action.
TH
Bank of Thailand; Securities and Exchange Commission Thailand
Stablecoin trading / fiat on-off ramps
medium-high confidence
AMLstablecoin flowshidden ownershipremittance bypassforeign seller activityplatform surveillance
Thailand high-volume USDT audit is included as a Tier 2 negative-intel record because it names authorities, asset, conduct vector, jurisdiction, and a concrete regulatory escalation path, while remaining short of a final enforcement order.
Listing post-mortem use: Useful for listing reviews where Thai liquidity appears strong but depends on opaque USDT seller flows, remittance arbitrage, or accounts later escalated to SEC/AMLO review.
Source
2026-07-11
Tier 1
Bonzo Lend on Hedera
Bonzo Finance Labs said Bonzo Lend was paused after an attacker used a manipulated SAUCE price accepted by a third-party Supra oracle verifier to borrow approximately $9.05 million of assets far beyond posted collateral.
Global
Bonzo Finance Labs / Bonzo Finance Foundation / Hedera / Supra
DeFi lending / oracle infrastructure / Hedera ecosystem
high confidence
oracle verification exploitDeFi lending pool pausethird-party oracle dependencymanipulated collateral valuationborrowed-asset extractionTVL impairmentliquidity-provider withdrawal uncertaintyHedera ecosystem contagion monitoringwhite-hat recovery dependency
Bonzo Finance Labs, in coordination with the Bonzo Finance Foundation, published a July 11, 2026 incident report saying Bonzo Lend on Hedera was paused after a third-party oracle-provider exploit. The report says an attacker submitted a manipulated SAUCE price at about 00:51 UTC, the Supra oracle verifier accepted a zero-signature-style proof it should have rejected, and the attacker then borrowed assets far beyond the few dollars of SAUCE collateral posted. Bonzo states the headline malicious extraction was approximately $9.05 million, while a separate roughly $1.0 million white-hat borrowing item is being treated as recovery context.
Listing post-mortem use: Use to test whether Bonzo, Hedera ecosystem tokens, or comparable DeFi lending listings reviewed oracle-provider verifier design, zero-signature and subgroup checks, third-party feed concentration, pause authority, recovery communications, liquidity-provider withdrawal paths, and TVL sensitivity to upstream infrastructure failures.
Source
2026-07-11
Tier 2
Ill Bloom vulnerable wallet-generation cohort
Coinspect's Ill Bloom disclosure says weak recovery-phrase generation created actively exploited wallet addresses; confirmed on-chain evidence dates to May 27, 2026 and affected users are instructed to migrate funds to newly generated wallets.
Global
Coinspect / Ill Bloom disclosure
Self-custody wallet security / seed phrase generation
high confidence
weak randomnessinsecure recovery phrase generationactive wallet drainmulti-chain address exposureunknown affected wallet softwarestaged disclosureseed phrase compromiseself-custody tooling riskwallet-vendor notification dependency
Coinspect's Ill Bloom site discloses an actively exploited wallet-generation vulnerability tied to weak recovery phrases. The site says the first confirmed on-chain evidence it identified dates to May 27, 2026, affected users should treat matching recovery phrases as compromised, and safe remediation requires creating a new wallet with a new phrase before migrating funds. The disclosure does not publicly name every vulnerable wallet app because public addresses do not prove which software generated them.
Listing post-mortem use: Use as sector context when reviewing projects with heavy self-custody distribution, wallet-partner integrations, airdrops to externally generated addresses, and post-incident claims that user drains were unrelated to protocol contracts.
Source
2026-07-11
Tier 1
Humanity (H) trading support on Coinone
Coinone reportedly announced that it will delist Humanity (H) on August 10, 2026 after the project failed to resolve watchlist issues tied to a June 9 issuer-managed wallet security incident that caused user losses.
South Korea
Coinone
Centralized exchange spot listing / identity protocol token
medium confidence
exchange delistingsecurity incident follow-throughissuer-managed wallet compromiseunresolved watchlist designationuser-loss incidentSouth Korea listing-review pressurewithdrawal-deadline monitoringpost-exploit venue support contraction
CryptoNews.net reported that South Korean exchange Coinone will delist Humanity (H) on August 10, 2026, citing an official Coinone notice. The reported basis is an unresolved June 9 security incident in an issuer-managed wallet that caused user losses and led to watchlist review. The official notice was not directly retrievable during this run, so the row is source-traced as medium-confidence secondary reporting.
Listing post-mortem use: Use to test whether Humanity listing reviews monitored issuer-managed wallet security, Korean exchange watchlist notices, incident-remediation evidence, user-loss exposure, withdrawal deadlines, and whether one venue's delisting accelerated broader exchange support contraction.
Source
2026-07-10
Tier 1
ACH, CKB, BIO, and XTZ margin services on KuCoin
KuCoin announced it will delist margin trading services for ACH, CKB, BIO, and XTZ, closing margin trading, lending, borrowing, affected transfer functions and loan repayment services on staged UTC deadlines from July 13 to July 16, 2026.
Global
KuCoin
Centralized exchange margin / lending / borrowing support
high confidence
margin service delistinglending and borrowing closureforced position closureopen-order cancellationloan repayment suspensionmargin grid bot shutdownsharp-price-fluctuation early-action risklisting support monitoring
KuCoin is removing margin services for ACH, CKB, BIO, and XTZ. The notice instructs users to cancel orders, close positions, repay loans, and move tokens out of margin accounts; it also warns that open orders may be canceled, positions liquidated, margin grid bots shut down automatically, and early delisting may occur under sharp price fluctuation.
Listing post-mortem use: Use to test whether listing reviews over-weighted spot availability while missing margin-borrow liquidity fragility, bot-dependent flow, debt-ratio stress, and exchange service-removal deadlines for ACH, CKB, BIO, or XTZ.
Source
2026-07-08
Tier 1
Cross The Ages (CTA) on KuCoin
KuCoin placed Cross The Ages under Special Treatment delisting, scheduled trading-bot removal and spot delisting on July 9, kept deposits closed, and set a withdrawal-service closure deadline of August 10, 2026.
Global
KuCoin
Centralized exchange spot listing / game-token market access
high confidence
special treatment delistingspot market delistingtrading-bot shutdowndeposit closurewithdrawal deadlineproject-related withdrawal failure riskgame-token listing support contractionuser loss warning
KuCoin published a July 8, 2026 Special Treatment notice saying Cross The Ages (CTA) will be delisted. Trading bots for CTA are removed at 08:00 UTC on July 9, the project is delisted at 10:00 UTC on July 9, deposits remain closed, and withdrawals close on August 10. The notice also warns that KuCoin may close withdrawals if project-related issues prevent transfers and will not cover user losses.
Listing post-mortem use: Use to test whether CTA listing reviews captured KuCoin Special Treatment triggers, exchange bot dependency, closed-deposit status, withdrawal-deadline communication, on-chain transfer reliability and user-loss disclaimers before the delisting window.
Source
2026-07-08
Tier 3
Rivalz Network (RIZ) deposit service on KuCoin
KuCoin temporarily suspended Rivalz Network (RIZ) deposit service for essential maintenance and said it would not notify users through a further restoration announcement.
Global
KuCoin
Centralized exchange wallet infrastructure / AI-network token deposit support
high confidence
deposit suspensionwallet maintenancerestoration notice unavailableAI-network token transfer-route frictionmarket-maker inventory mobility risklisting support monitoring
KuCoin published a July 8, 2026 notice saying it had suspended the deposit service for Rivalz Network (RIZ) due to essential maintenance. The notice does not cite an exploit, delisting, or trading halt, but the deposit route is unavailable and KuCoin says users will not receive a further restoration announcement, making this a Tier 3 operational watchlist row.
Listing post-mortem use: Use to test whether RIZ or comparable AI-network token listing reviews had redundant deposit routes, wallet-maintenance monitoring, market-maker inventory plans, and restoration verification when a venue says no further notice will be issued.
Source
2026-07-07
Tier 3
BONK deposit and withdrawal services on KuCoin
KuCoin temporarily suspended BONK deposit and withdrawal services for essential maintenance and said it would not publish a further restoration announcement.
Global
KuCoin
Centralized exchange wallet infrastructure / meme-token transfer support
high confidence
deposit suspensionwithdrawal suspensionwallet maintenancerestoration notice unavailablememe-token transfer-route frictionmarket-maker inventory mobility risklisting support monitoring
KuCoin published a July 7, 2026 official notice saying it had suspended BONK deposit and withdrawal services due to essential maintenance. The notice did not cite a trading halt, exploit, or delisting, but it directly restricts user transfer access and says users will not receive a further restoration announcement, making it a Tier 3 operational negative-intel watchlist row.
Listing post-mortem use: Use to test whether BONK or comparable meme-token listing reviews had redundant exchange transfer routes, wallet-maintenance monitoring, market-maker inventory mobility plans, and restoration checks when the venue says no further announcement will be issued.
Source
2026-07-06
Tier 1
Binance margin and loan products for TST and IOTX
Binance announced margin and loan delisting for TST and IOTX, including borrowing suspension, automatic loan closure, position settlement, order cancellation, and possible liquidation or forced sale of remaining margin balances.
Global
Binance
Centralized exchange margin and crypto loan support
high confidence
margin delistingcrypto loan closureborrowing suspensionautomatic settlementpending order cancellationportfolio margin liquidationcollateral forced salemarket-access frictionlisting support monitoring
Binance published a July 6, 2026 notice saying Margin and Loan will delist TST and IOTX on July 10 at 10:00 UTC. Borrowing is suspended from July 7; affected loan positions are closed, margin pairs removed, isolated orders canceled, cross-margin liabilities repaid through collateral handling, and remaining portfolio-margin balances can be liquidated into USDT.
Listing post-mortem use: Use to test whether TST/IOTX listing reviews separated spot access from margin, loan, collateral and portfolio-margin support, and whether post-listing monitoring captured borrow suspension, forced settlement, and collateral forced-sale risk before product removal.
Source
2026-07-05
Tier 3
ESUSDT futures on MEXC
MEXC updated ESUSDT futures funding-rate limits from 3% to 5% and warned that funding rates may be further adjusted in extreme market conditions.
Global
MEXC
Centralized exchange derivatives / funding-rate risk controls
medium confidence
funding-rate limit changederivatives carry-cost volatilityextreme market condition warningperpetual futures risk controlmarket-maker funding exposureleveraged position monitoringlisting support monitoring
MEXC's July 5, 2026 official announcement index showed an ESUSDT futures funding-rate limit update effective at 18:55 UTC, moving the upper and lower limits from 3% to 5%. Because this is not a delisting or enforcement action, it is treated as a Tier 3 derivatives watchlist signal for funding-volatility and market-maker stress.
Listing post-mortem use: Use to test whether ES listing and market-maker reviews tracked funding-rate cap changes, carry-cost stress, extreme-market warnings, and dependency on a single high-volatility perpetual venue.
Source
2026-07-05
Tier 3
Gate TR WEN and CAT token rebranding
Gate TR temporarily suspended deposits, withdrawals, and trading services for WEN and CAT from 2026-07-05 03:00 UTC during a token-name rebranding process, with post-change review before relisting under the new names.
Turkey
Gate TR
Centralized exchange spot / token identity and rebrand operations
high confidence
temporary trading suspensiondeposit suspensionwithdrawal suspensiontoken rebrand operationasset identity changepost-change listing reviewregional venue access frictionlisting support monitoring
Gate TR published a July 3 notice that WEN and CAT would be renamed to WENSOL and SIMONSCAT, and that deposits, withdrawals, WEN/USDT trading and CAT/TRY trading would be temporarily suspended from July 5, 2026 at 03:00 UTC. Because the notice says the tokens will be reviewed again before listing under new names, this is a Tier 3 operational listing-support watchlist signal.
Listing post-mortem use: Use to test whether WEN/CAT or comparable meme-token listings had clear rebrand handling, ticker continuity controls, user communication, temporary trading-pause planning, and regional exchange relisting verification.
Source
2026-07-04
Tier 3
HYPER withdrawals on Bitget via Binance Smart Chain
Bitget suspended HYPER withdrawals on Binance Smart Chain from 2026-07-04 09:19 UTC+8 due to wallet maintenance, with reopening date to be announced separately.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific withdrawal support
high confidence
withdrawal suspensionnetwork-specific support interruptionwallet maintenancereopening time uncertainBinance Smart Chain transfer-route frictionmarket-maker exit-route frictionlisting support monitoring
Bitget published a July 4, 2026 notice suspending HYPER withdrawals on Binance Smart Chain because of wallet maintenance. The exchange did not provide a reopening time, making this a Tier 3 operational watchlist signal rather than a confirmed exploit, enforcement action, or delisting.
Listing post-mortem use: Use to check whether HYPER listing and market-making plans had redundant transfer routes, withdrawal-restoration monitoring, and contingency plans for network-specific exchange wallet maintenance.
Source
2026-07-04
Tier 2
THE, GWEI and VANRY futures on MEXC
MEXC reduced maximum leverage for THE futures from 125x to 50x for futures trading and 75x to 50x for copy trade, and reduced GWEI and VANRY futures leverage from 50x to 20x, with restrictions on increasing positions and warnings that some orders or copy trades above the new limit will not execute.
Global
MEXC
Centralized exchange derivatives / leverage and copy-trading risk controls
high confidence
maximum leverage reductionderivatives product restrictioncopy-trading leverage restrictionposition increase blocked above new limittrigger order execution riskmarket-maker leverage constraintvolatility risk control signallisting support monitoring
MEXC published official July 4, 2026 notices reducing maximum leverage for THE, GWEI and VANRY futures. THE moved from 125x to 50x for futures and 75x to 50x for copy trade, while GWEI and VANRY moved from 50x to 20x. The notices warn users to adjust positions and orders, making this a high-confidence Tier 2 derivatives risk-control signal.
Listing post-mortem use: Use to test whether THE, GWEI or VANRY listing and market-making reviews model leverage cap cuts, copy-trading dependence, order invalidation risk, and market-maker inventory constraints separately from outright delisting.
Source
2026-07-03
Tier 1
Bitget spot markets for A47, HPP, NODE, FRAX, OG, DUSK, LUMIA and NFP
Bitget announced an eight-pair July 10 spot delisting after periodic review, with deposits already suspended, pending-order cancellation, unified-account removal, bot/copy-trading removal, OG margin liquidation workflow, and OG/DUSK Simple Earn delisting.
Global
Bitget
Centralized exchange spot, bots, copy trading, margin and Earn support
high confidence
centralized exchange delistingdeposit suspensionopen-order cancellationunified-account removalspot bot removalcopy-trading removalmargin liquidationEarn product delistingwithdrawal deadlinelisting support monitoring
Bitget published a July 3, 2026 official notice scheduling delisting of A47/USDT, HPP/USDT, NODE/USDT, FRAX/USDT, OG/USDT, DUSK/USDT, LUMIA/USDT and NFP/USDT on July 10. The notice says deposits are already suspended, withdrawals remain open until October 10, spot orders will be canceled, affected pairs will be removed from unified account trading, bots, copy trading, Convert, and selected Earn/margin products, with OG margin positions subject to automatic closeout and liability liquidation.
Listing post-mortem use: Use to test whether listing reviews captured weak trading volume/liquidity, team responsiveness, community activity, smart-contract stability, product breadth dependence, bot/copy-trading exposure, margin liabilities, and user-withdrawal deadlines before Bitget removed support.
Source
2026-07-02
Tier 1
ME3 listing on MEXC
MEXC said it would cancel the ME3 listing after discussions with the project team, closed ME3 deposits, warned users not to deposit to avoid asset losses, and expected to support ME3 withdrawals for 30 days.
Global
MEXC
Centralized exchange spot listing / launch-campaign execution
medium confidence
listing cancellationdeposit closureasset-loss warningwithdrawal windowproject-team coordination issueexchange rejection signallaunch campaign disruptionlisting support monitoring
MEXC said it would cancel the ME3 listing following discussions with the project team. The notice says ME3 deposits have been closed, warns users not to deposit to avoid asset losses, and expects to support ME3 withdrawals for 30 days, making it a confirmed Tier 1 listing-cancellation signal with medium confidence on event-date attribution.
Listing post-mortem use: Use to evaluate whether ME3 or comparable pre-listing reviews captured project-team execution risk, exchange cancellation triggers, deposit cutoffs, user asset-loss warnings, withdrawal windows, and campaign-reward liabilities.
Source
2026-07-02
Tier 1
NFPUSDT Perpetual Futures on MEXC
MEXC delisted the NFPUSDT perpetual futures pair on 2026-07-02 at 08:00 UTC, with fair-price position closure, open-order cancellation, and Demo/Futures Grid removal where applicable.
Global
MEXC
Centralized exchange derivatives / single-asset perpetual futures support
high confidence
perpetual futures delistingforced position closureopen-order cancellationfutures grid shutdownderivatives liquidity contractionsingle-asset venue support reductionmarket-maker strategy interruptionlisting support monitoring
MEXC listed a July 2, 2026 delisting for the NFPUSDT perpetual futures pair at 08:00 UTC. The action closes positions at fair price, cancels open orders, and removes affected Demo/Futures Grid support where applicable, making it a confirmed Tier 1 exchange-action signal.
Listing post-mortem use: Use to test whether NFP listings relied on MEXC perpetual liquidity, futures grid flow, or derivatives market-maker routes that were disrupted by forced closure.
Source
2026-07-01
Tier 1
AscendEX centralized exchange operations
AscendEX reportedly ceased all business operations effective July 1, stopped account opening, deposits, trading, staking and lending, and moved withdrawals into manual review from July 6 with no guarantee on timing or amount.
Global / EU
AscendEX / MiCA authorization context
Centralized exchange operations / custody and withdrawal access
medium confidence
centralized exchange shutdownwithdrawal manual reviewwithdrawal-delay riskcustody-access impairmentMiCA authorization gapliquidity-reserve concernuser asset recovery riskfounder silencelisting venue counterparty risk
KuCoin News republished BitPush reporting that AscendEX ceased operations effective July 1, 2026, citing market conditions, MiCA authorization issues and broader regulatory, financial and operational factors. The report quotes the exchange statement that withdrawals may be delayed or may not be processed during manual review, and says on-chain monitoring showed limited liquid assets, making this a Tier 1 centralized-exchange custody and withdrawal-access negative-intel row.
Listing post-mortem use: Use as a venue-risk post-mortem benchmark for listings that relied on AscendEX liquidity, custody or market-maker routes; test whether exchange due diligence monitored authorization status, reserve depth, withdrawal queues, hot-wallet liquidity, incident history and founder/team responsiveness.
Source
2026-07-01
Tier 3
IN deposits on Bitget via Ethereum
Bitget suspended IN deposits on the Ethereum network from 2026-07-01 11:52 UTC+8 due to wallet maintenance, with the reopening date to be announced separately.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific deposit support
high confidence
deposit suspensionnetwork-specific support interruptionwallet maintenancereopening time uncertainEthereum transfer-route frictionmarket-maker funding-route frictionlisting support monitoring
Bitget published a July 1, 2026 notice suspending IN deposits over Ethereum from 11:52 UTC+8 because of wallet maintenance. The reopening date was left for a later announcement, making it a Tier 3 venue-access watchlist signal.
Listing post-mortem use: Use to test whether IN listing reviews captured network-specific deposit reliability, exchange restoration monitoring, Ethereum route redundancy, and market-maker funding contingency plans.
Source
2026-07-01
Tier 2
Bitget rToken withdrawals
Bitget temporarily suspended rToken withdrawals from 17:00 July 1, 2026 UTC+8 while trading remained available, citing dividend, stock-split, reverse-split, and corporate-action processing consistency.
Global
Bitget
Centralized exchange RWA / tokenized equity withdrawal infrastructure
high confidence
withdrawal suspensiontokenized equity settlement frictioncorporate-action processing riskRWA custody and circulation gapresumption time uncertainon-chain integration pendinglisting support monitoring
Bitget published a July 1, 2026 notice temporarily suspending rToken withdrawals from 17:00 UTC+8 while leaving rToken trading open. The exchange linked the pause to corporate-action processing and pending on-chain/wallet integration work, making it a high-confidence Tier 2 RWA withdrawal-friction signal rather than a final enforcement action.
Listing post-mortem use: Use to evaluate whether tokenized-equity listings model dividends, stock splits, reverse splits, wallet integration readiness, withdrawal continuity, and user-exit limitations separately from trading availability.
Source
2026-07-01
Tier 3
KuCoin Story (IP) rename to Data Network (DATA) and Streamr DATA ticker migration
KuCoin support for Story (IP) renaming to Data Network (DATA) requires Streamr DATA to be renamed DATAOLD and temporarily pauses Streamr DATA withdrawals from 10:00 on July 1, 2026 until the ticker update is complete.
Global
KuCoin
Centralized exchange token migration / ticker rename operations
high confidence
ticker collisionwithdrawal pausetoken rename support frictionasset identity confusionmigration operations riskuser-exit timing risklisting support monitoring
KuCoin announced support for renaming Story (IP) to Data Network (DATA) and said the existing Streamr DATA ticker would move to DATAOLD before July 2, 2026. Streamr DATA withdrawals are paused from 10:00 on July 1 until the ticker update completes, making this a Tier 3 token-migration operations signal.
Listing post-mortem use: Use to evaluate whether token migration reviews captured ticker collisions, legacy asset withdrawal pauses, user confusion, exchange implementation timing, and market-data continuity.
Source
2026-07-01
Tier 1
STRAX, NOCK, RNBW and NAT USDT-M Perpetual Futures on MEXC
MEXC delisted STRAX, NOCK, RNBW and NAT USDT-M perpetual futures on 2026-07-01 at 07:00 UTC, with fair-price position closure, open-order cancellation, and Demo/Futures Grid removal where applicable.
Global
MEXC
Centralized exchange derivatives / multi-asset perpetual futures support
high confidence
perpetual futures delistingforced position closureopen-order cancellationfutures grid shutdownderivatives liquidity contractionmulti-asset venue support reductionmarket-maker strategy interruptionlisting support monitoring
MEXC listed a July 1, 2026 delisting for STRAX, NOCK, RNBW and NAT USDT-M perpetual futures at 07:00 UTC. The action closes positions at fair price, cancels open orders, and removes affected Demo/Futures Grid support where applicable, making it a confirmed Tier 1 exchange-action signal.
Listing post-mortem use: Use to test whether STRAX, NOCK, RNBW, or NAT listings relied on MEXC perpetual liquidity, grid strategies, or market-maker inventory channels that were impaired by forced settlement.
Source
2026-06-30
Tier 3
USDT withdrawals on Bitget via Morph Network
Bitget suspended USDT withdrawals over the Morph network from 2026-06-30 12:30 UTC+8 due to wallet maintenance, then published a same-day reopening notice at 2026-06-30 07:05 UTC.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific stablecoin withdrawal support
high confidence
withdrawal suspensionnetwork-specific support interruptionwallet maintenancesame-day restorationMorph transfer-route frictionstablecoin settlement frictionlisting support monitoring
Bitget published a June 30, 2026 notice suspending USDT withdrawals over Morph Network from 12:30 UTC+8 for wallet maintenance, followed by a same-day reopening notice. The short interruption is a Tier 3 operational watchlist signal rather than a protocol-level adverse event.
Listing post-mortem use: Use to test whether Morph-connected listings and stablecoin settlement plans included redundant withdrawal routes, incident-duration tracking, and same-day restoration validation.
Source
2026-06-30
Tier 1
ALEO, PITCH, POND and GITLAWB USDT-M Perpetual Futures on MEXC
MEXC delisted ALEO, PITCH, POND and GITLAWB USDT-M perpetual futures on 2026-06-30 at 07:00 UTC, with fair-price position closure, open-order cancellation, and Demo/Futures Grid removal where applicable.
Global
MEXC
Centralized exchange derivatives / multi-asset perpetual futures support
high confidence
perpetual futures delistingforced position closureopen-order cancellationfutures grid shutdownderivatives liquidity contractionmulti-asset venue support reductionmarket-maker strategy interruptionlisting support monitoring
MEXC listed a June 30, 2026 delisting for ALEO, PITCH, POND and GITLAWB USDT-M perpetual futures at 07:00 UTC. The action closes positions at fair price, cancels open orders, and removes affected Demo/Futures Grid support where applicable, making it a confirmed Tier 1 exchange-action signal.
Listing post-mortem use: Use to test whether ALEO, PITCH, POND or GITLAWB listings depended on MEXC perpetual liquidity, grid strategies, or market-maker inventory routes that were impaired by forced settlement.
Source
2026-06-30
Tier 1
NAKA/USDC spot trading pair on MEXC
MEXC announced that, based on recent assessments, it would delist the NAKA/USDC spot trading pair on 2026-06-30 at 10:00 UTC and automatically cancel all open orders for the affected pair.
Global
MEXC
Centralized exchange spot market / pair-level liquidity support
high confidence
spot pair delistingopen-order cancellationquote-currency route removalUSDC liquidity contractionpair-level venue support reductionmarket-depth fragmentationlisting support monitoring
MEXC listed NAKA/USDC for spot-pair delisting on June 30, 2026 at 10:00 UTC after recent assessments, with open orders automatically canceled. This is a confirmed Tier 1 exchange-action signal for pair-level liquidity contraction.
Listing post-mortem use: Use to evaluate whether NAKA listings had adequate quote-currency diversity, USDC market depth, open-order cancellation handling, and fallback liquidity routes after pair-level delisting.
Source
2026-06-29
Tier 3
STAYNEX deposit service on KuCoin
KuCoin temporarily closed the deposit service for STAYNEX (STAY) due to essential maintenance and stated it would not issue a further restoration announcement.
Global
KuCoin
Centralized exchange wallet infrastructure / deposit support
high confidence
deposit suspensionwallet maintenancerestoration disclosure limitedvenue access frictionmarket-maker funding-route frictionlisting support monitoring
KuCoin published a June 29, 2026 notice temporarily closing STAYNEX (STAY) deposits due to essential maintenance. The exchange said further restoration developments would not be announced separately, making this a Tier 3 venue-access watchlist signal.
Listing post-mortem use: Use to test whether STAY exchange-support reviews captured deposit-route continuity, restoration-notice gaps, market-maker funding constraints, and fallback venue coverage.
Source
2026-06-28
Tier 3
ACT withdrawals on Bitget via Solana
Bitget suspended ACT withdrawals over the Solana network from 2026-06-28 10:27 UTC+8 due to wallet maintenance, with reopening date to be announced separately.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific withdrawal support
high confidence
withdrawal suspensionnetwork-specific support interruptionwallet maintenancereopening time uncertainSolana transfer-route frictionAI-agent token venue-access frictionlisting support monitoring
Bitget published a June 28, 2026 notice suspending ACT withdrawals over Solana from 10:27 UTC+8 because of wallet maintenance. The notice gives no fixed reopening time. Combined with ACT appearing in Binance Monitoring Tag coverage earlier in June, this is a Tier 3 listing-support watchlist signal.
Listing post-mortem use: Use to test whether ACT listing reviews captured monitoring-tag escalation, network-specific withdrawal reliability, AI-agent token volatility, market-maker settlement routes, and venue-restoration monitoring.
Source
2026-06-28
Tier 1
IPUSDT and IPUSDC Perpetual Futures on MEXC
MEXC delisted IPUSDT and IPUSDC perpetual futures on 2026-06-28 at 08:00 UTC, closing positions at fair price, canceling open orders, and removing affected Demo and Futures Grid trading support where applicable.
Global
MEXC
Centralized exchange derivatives / token migration derivatives support
high confidence
perpetual futures delistingforced position closureopen-order cancellationfutures grid shutdownderivatives liquidity contractiontoken migration support frictionmarket-maker strategy interruptionmulti-venue IP derivatives contraction
MEXC listed a June 28, 2026 delisting for IPUSDT and IPUSDC perpetual futures at 08:00 UTC, with fair-price position closure, open-order cancellation, and Demo/Futures Grid removal where applicable. KuCoin, Flipster, and XT also showed IP perpetual-delisting notices around the same date, making this a confirmed Tier 1 exchange-action signal for IP derivatives support contraction.
Listing post-mortem use: Use to test whether IP listings captured token migration timing, derivatives venue concentration, forced settlement exposure, grid-bot risk, market-maker contingency plans, and multi-venue derivatives support contraction.
Source
2026-06-27
Tier 3
EZSWAP withdrawals on Bitget via Manta Network
Bitget suspended EZSWAP withdrawals over the Manta Network from 2026-06-28 01:50 UTC+8 due to wallet maintenance, with reopening date to be announced separately.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific withdrawal support
high confidence
withdrawal suspensionnetwork-specific support interruptionwallet maintenancereopening time uncertainManta Network transfer-route frictionmarket-maker settlement frictionlisting support monitoring
Bitget published a June 27, 2026 notice suspending EZSWAP withdrawals over Manta Network from June 28, 2026 at 01:50 UTC+8 because of wallet maintenance. The reopening date was left to a later announcement, making it a structured venue-access watchlist signal.
Listing post-mortem use: Use to test whether EZSWAP or Manta-connected listings had redundant withdrawal routes, exchange-specific restoration monitoring, and market-maker settlement contingency plans.
Source
2026-06-27
Tier 3
Beldex deposit and withdrawal services on KuCoin
KuCoin announced that Beldex deposit and withdrawal services were temporarily closed due to essential maintenance, without a restoration notice commitment.
Global
KuCoin
Centralized exchange wallet infrastructure / privacy-coin access
high confidence
deposit suspensionwithdrawal suspensionessential maintenancerestoration notice uncertaintyprivacy-coin venue-access frictionexchange wallet infrastructure riskmarket-maker settlement friction
KuCoin published a June 27, 2026 notice saying it had temporarily closed Beldex deposit and withdrawal services due to essential maintenance and would not issue a further announcement when services are restored. This is an exchange-access watchlist signal rather than a final delisting or enforcement action.
Listing post-mortem use: Use to test whether BDX or comparable privacy-asset reviews tracked venue-specific wallet maintenance, restoration disclosure, withdrawal continuity, and market-maker transfer alternatives.
Source
2026-06-22
Tier 1
WOJAKUSDT Perpetual Futures on MEXC
MEXC announced the WOJAKUSDT Perpetual Futures pair would be delisted on 2026-06-22 at 07:00 UTC, with positions closed at fair price, open orders canceled, and futures grid trading removed for the affected pair.
Global
MEXC
Centralized exchange derivatives / memecoin perpetual futures
high confidence
perpetual futures delistingforced position closureopen-order cancellationfutures grid shutdownderivatives liquidity contractionmemecoin venue-access frictionmarket-maker strategy interruption
MEXC's delisting notice states that WOJAKUSDT perpetual futures would be removed on June 22, 2026 at 07:00 UTC, with open positions closed at fair price, open orders canceled, and Demo/Futures Grid Trading also delisted where applicable. This is a confirmed Tier 1 exchange action because it directly closes derivatives access and user positions.
Listing post-mortem use: Use to test whether WOJAK or comparable memecoin listings had concentration in one derivatives venue, grid-bot exposure, market-maker contingency plans, and adequate user notice before forced perpetual closure.
Source
2026-06-22
Tier 1
Taiko L1 Bridge and ERC20Vault
Taiko confirmed a compromise of its chain-state verification mechanism, warned that all bridges deployed on Taiko could no longer rely on prior security assumptions, advised users to withdraw bridge funds, and later confirmed the L1 Bridge and ERC20Vault were paused with withdrawals fully stopped.
Global
Taiko
Layer 2 / bridge infrastructure / cross-chain asset custody
high confidence
bridge exploitchain-state verification compromisewithdrawals stoppedbridge pausecross-chain proof validationcentralized-exchange deposit suspension requestsecurity council responseL2 finality and settlement risk
Taiko published a June 22, 2026 security notice confirming a compromise of its chain-state verification mechanism and warning that bridge security assumptions could no longer be relied upon. A follow-up official update said the exploit was contained, the L1 Bridge and ERC20Vault were paused, and withdrawals through them were fully stopped, making this a confirmed Tier 1 protocol action with direct asset-access consequences.
Listing post-mortem use: Use to test whether TAIKO listings and bridge-dependent assets captured chain-state verification risk, emergency pause authority, exchange deposit-suspension playbooks, withdrawal continuity, and incident disclosure speed.
Source
2026-06-21
Tier 3
ACE withdrawals on Bitget via Binance Smart Chain
Bitget suspended ACE withdrawals over the Binance Smart Chain network from 2026-06-21 08:17 UTC+8 due to wallet maintenance, with reopening date to be announced separately.
Global
Bitget
Centralized exchange wallet infrastructure / network-specific withdrawal support
high confidence
withdrawal suspensionnetwork-specific support interruptionwallet maintenancereopening time uncertainexchange transfer-route frictionmarket-maker settlement frictionlisting support monitoring
Bitget published a June 21, 2026 official support notice suspending ACE withdrawals over Binance Smart Chain from 08:17 UTC+8 because of wallet maintenance. The exchange did not provide a fixed reopening time, making the item a structured Tier 3 venue-access watchlist signal rather than a confirmed enforcement or delisting event.
Listing post-mortem use: Use to test whether ACE or comparable listings had redundant withdrawal routes, clear market-maker settlement procedures, restoration-time disclosure, and monitoring for repeated exchange wallet-maintenance interruptions.
Source
2026-06-19
Tier 1
Binance QKC deposit/withdrawal support via BNB Smart Chain
Binance announced it will cease support for QuarkChain (QKC) deposits and withdrawals via BNB Smart Chain from 2026-06-26 08:00 UTC; deposits sent through that network after the cutoff will not be credited and may lead to asset loss.
Global
Binance
Centralized exchange wallet infrastructure / token network support
high confidence
deposit route removalwithdrawal route removalnetwork support cessationasset loss warningBNB Smart Chain support contractionexchange wallet infrastructure riskuser transfer-route confusionlisting support friction
Binance published a June 19, 2026 official notice saying it will stop supporting QKC deposits and withdrawals via BNB Smart Chain from June 26, 2026. The notice warns that deposits sent through the affected route after the cutoff will not be credited and may cause asset loss, while other Binance-supported networks remain available.
Listing post-mortem use: Use to test whether QKC or comparable listings tracked network-specific deposit and withdrawal support, cutoff notices, asset-loss warnings, transfer-route redundancy, and market-maker wallet-route dependencies.
Source
2026-06-19
Tier 1
KuCoin XION to VERONA rename across trading bots, deposits, withdrawals, spot pairs, and WebSocket services
KuCoin support for the XION-to-VERONA rename includes XION/USDT trading-bot delisting, XION deposit and withdrawal closure, XION/USDT and XION/USDC spot trading suspension, and a stated PRO and Classic WebSocket disruption window during the migration.
Global
KuCoin
Centralized exchange token migration / spot trading / deposit-withdrawal support
high confidence
token rename migrationtrading-bot shutdowndeposit closurewithdrawal closurespot trading suspensionpending order cancellation guidancewebsocket disruption riskticker-selection risk after migrationexchange product support contraction
KuCoin published a June 19, 2026 notice supporting the rename of Xion (XION) to Verona (VERONA) at a 1:1 ratio. The exchange said XION/USDT trading bots would be delisted at 10:00 UTC on June 20, XION deposits and withdrawals would close at 08:00 UTC on June 21, XION/USDT and XION/USDC spot trading would be suspended at 10:00 UTC on June 21, and PRO and Classic WebSocket services may experience temporary disconnections, data loss, or delays from 08:00 to 10:00 UTC on June 22.
Listing post-mortem use: Use to test whether XION/VERONA listing reviews captured rename timing, trading-bot shutdowns, spot suspension, deposit/withdrawal closure, pending-order cancellation guidance, WebSocket/data-feed risk, and post-migration ticker-selection errors.
Source
2026-06-18
Tier 3
ACT, BLUR, PIVX and QKC on Binance Monitoring Tag list
Binance extended its Monitoring Tag to ACT, BLUR, PIVX and QKC, stating tagged tokens exhibit higher volatility and risks, require recurring user risk acknowledgement, and are at risk of no longer meeting listing criteria.
Global
Binance
Centralized exchange listing risk / monitored tokens
high confidence
monitoring tagdelisting watchlisthigher volatilitylisting criteria riskliquidity reviewteam responsiveness reviewnetwork safety reviewuser risk-quiz friction
Binance published a June 18, 2026 notice extending the Monitoring Tag to ACT, BLUR, PIVX and QKC. The exchange said tagged tokens carry higher volatility and risk, may fail future listing criteria, and require users to pass a recurring quiz and accept terms before trading on Binance Spot or Margin.
Listing post-mortem use: Use to compare whether prior listing reviews anticipated monitoring-tag escalation factors: liquidity, development activity, network stability, public communication, responsiveness to exchange diligence, and unethical or negligent conduct indicators.
Source
2026-06-18
Tier 1
Celsius Network and Alexander Mashinsky
CFTC announced a federal consent order resolving its enforcement action against Celsius founder Alexander Mashinsky, imposing permanent anti-fraud injunctions plus permanent trading and registration bans.
US
Commodity Futures Trading Commission; U.S. District Court for the Southern District of New York
CeFi lending / digital asset yield products
high confidence
regulatory enforcementfraud injunctiontrading banregistration banCeFi yield misrepresentationcustomer asset safety claimsbankruptcy-linked customer harmfounder conduct risk
The CFTC said the Southern District of New York entered a consent order resolving its 2023 action against Celsius founder Alexander Mashinsky. The order permanently enjoins him from anti-fraud violations and imposes permanent trading and registration bans; the release also recaps allegations that Celsius misrepresented the safety, profitability, and regulatory compliance of a digital asset lending platform that received about USD 20 billion in customer funds before bankruptcy.
Listing post-mortem use: Use as a benchmark for reviewing token listings or yield products tied to founder representations, customer asset custody, promised rewards, reserve transparency, and bankruptcy contagion after platform failure.
Source
2026-06-17
Tier 1
Binance BTTC and TRX deposit/withdrawal support via BNB Smart Chain
Binance announced it will cease support for BitTorrent (BTTC) and TRON (TRX) deposits and withdrawals via BNB Smart Chain from 2026-06-24 08:00 UTC; deposits sent through those routes after the cutoff will not be credited and may lead to asset loss.
Global
Binance
Centralized exchange wallet infrastructure / token network support
high confidence
deposit route removalwithdrawal route removalnetwork support cessationasset loss warningBNB Smart Chain support contractionexchange wallet infrastructure riskuser transfer-route confusionlisting support friction
Binance published a June 17, 2026 official notice saying it will stop supporting BTTC and TRX deposits and withdrawals via BNB Smart Chain from June 24, 2026, and warned that deposits sent over those routes after the cutoff will not be credited and may cause asset loss.
Listing post-mortem use: Use to test whether listing and post-listing reviews tracked network-specific deposit and withdrawal support, cutoff timing, user asset-loss warnings, cross-chain route redundancy, and market-maker transfer-path dependencies.
Source
2026-06-14
Tier 1
KuCoin Earn flexible savings products for MNDE and DATA
KuCoin Earn scheduled MNDE and DATA flexible savings delisting for June 14, 2026, with user principal and earnings automatically transferred to Funding Accounts after delisting or fixed-term lock expiry.
Global
KuCoin Earn
Centralized exchange earn products / yield product restrictions
high confidence
earn product delistingyield product restrictionautomatic redemption transferexchange product support losslong-tail asset support degradationuser reinvestment disruption
KuCoin Earn confirmed MNDE and DATA flexible savings delisting effective June 14, making this a confirmed exchange product-access restriction with direct user-account consequences.
Listing post-mortem use: Use to evaluate whether post-listing reviews tracked shrinking exchange product surfaces, automatic user asset transfers, earn demand dependence, and clustering of yield-product delistings.
Source
2026-06-14
Tier 3
SIREN deposit service on KuCoin
KuCoin temporarily closed the deposit service for SIREN due to essential maintenance and said users would not receive a further restoration announcement.
Global
KuCoin
Centralized exchange operations / AI-agent token deposit infrastructure
high confidence
deposit suspensiontoken inflow restrictionexchange operational maintenanceunclear restoration noticelisting support frictionAI-agent token venue risk
KuCoin confirmed a same-day SIREN deposit suspension for essential maintenance, creating a low-severity but structured negative signal for exchange access and listing-support continuity.
Listing post-mortem use: Use to test whether SIREN listing reviews tracked deposit-path outages, maintenance explanations without restoration notices, recent price/volume stress, and exchange operational dependency.
Source
2026-06-14
Tier 1
KuCoin TON to GRAM rename across trading bots, deposits, withdrawals, and spot pairs
KuCoin support for the TON-to-GRAM rename includes trading-bot delistings, TON deposit and withdrawal closure, TON/USDT and TON/USDC spot trading suspension, and a 1:1 conversion workflow with follow-up announcements pending.
Global
KuCoin
Centralized exchange token migration / spot trading / deposit-withdrawal support
high confidence
token rename migrationdeposit closurewithdrawal closurespot trading suspensiontrading-bot shutdownpending order cancellationmigration completion dependencyexchange product support contraction
KuCoin confirmed the effective June 14 TON-to-GRAM spot and deposit-withdrawal suspension steps, adding a distinct exchange-access row to the existing TON/GRAM support-contraction cluster.
Listing post-mortem use: Use to test whether TON/GRAM reviews captured cross-venue migration timing, bot shutdowns, spot suspension, deposit/withdrawal closure, order-cancellation guidance, and ticker-selection risks after conversion.
Source
2026-06-14
Tier 3
USDD ERC20 and Switchboard Protocol deposit services on KuCoin
KuCoin temporarily closed deposit services for USDD on Ethereum ERC20 and Switchboard Protocol due to essential maintenance, with no further restoration announcement planned.
Global
KuCoin
Centralized exchange operations / stablecoin and oracle-network deposit infrastructure
high confidence
deposit suspensionstablecoin inflow restrictionoracle token deposit frictionEthereum ERC20 support interruptionunclear restoration noticeexchange wallet maintenance
KuCoin reported a same-day maintenance-driven deposit suspension affecting USDD on Ethereum ERC20 and Switchboard Protocol, making it a structured exchange-access friction signal.
Listing post-mortem use: Use in post-mortems to check whether stablecoin/oracle listings maintained redundant deposit routes and whether venue notices disclosed restoration timing clearly enough for users and market makers.
Source
2026-06-13
Tier 3
STGUSDT perpetual contract on KuCoin Futures
KuCoin Futures changed STGUSDT perpetual funding intervals from every eight hours to every one hour, increasing funding cadence during a period of futures-risk warning and potential volatility.
Global
KuCoin Futures
Centralized exchange derivatives / perpetual contracts
high confidence
funding interval compressionperpetual market stressderivatives volatility riskliquidation cadence riskmarket-maker monitoringexchange risk-parameter change
KuCoin Futures compressed STGUSDT funding intervals from eight hours to one hour, creating an early-warning derivatives risk signal rather than a final delisting or enforcement action.
Listing post-mortem use: Use to test whether listing and market-making reviews tracked funding interval changes, derivatives exposure, forced-liquidation sensitivity, and venue-specific risk-parameter shifts.
Source
2026-06-12
Tier 1
Humanity Protocol $H token on Ethereum and BNB Smart Chain
Humanity Protocol published Quantstamp findings that stolen director keys enabled unauthorized $H movement and minting across Ethereum and BNB Smart Chain; the attack crashed open-market $H price by about 89%, left attacker addresses holding more than USD 21 million in ETH proceeds, and will lead the project to abandon the compromised BSC deployment.
Global / KR / BNB Chain / Ethereum
Humanity Protocol / Quantstamp incident response
Identity protocol / token bridge security / BNB Chain deployment risk
high confidence
admin key compromisetargeted phishing impersonating exchange counterpartyremote-access malwarebridge control compromiseunauthorized token mintingDEX sell pressure89 percent token price crashoperational wallet drainBSC deployment abandonmentDPRK-linked intrusion indicatorsexchange-partner recovery dependency
Humanity Protocol published a June 12, 2026 incident summary prepared by Quantstamp for the June 8 $H compromise. The report says an attacker phished a director with a Bithumb-themed email, installed remote-access malware, stole keys, moved about 141.18 million $H on Ethereum, minted about 100 million unauthorized $H on BNB Smart Chain, sold tokens on Uniswap and PancakeSwap over roughly eight hours, crashed the open-market $H price by about 89%, and left known attacker addresses with more than USD 21 million in ETH proceeds while BSC proceeds were still being tallied.
Listing post-mortem use: Use in listing post-mortems to test whether diligence covered director-device security, exchange-counterparty phishing controls, multisig signer segregation, bridge/proxy upgrade permissions, chain-specific abandonment plans, approval-revocation guidance, and exchange coordination after unauthorized minting.
Source
2026-06-11
Tier 1
OKX TON to GRAM migration across margin, futures, spot, earn, and loan products
OKX announced a TON-to-GRAM migration that immediately ceased TON borrowing and schedules margin, perpetual futures, expiry perps, spot pairs, Convert, Copy trading, Trading bots, Simple Earn, and Flexible Loan support changes, with pending orders canceled and some loan positions subject to forced repayment or collateral discount changes.
Global
OKX
Centralized exchange token migration / margin / derivatives / spot support
high confidence
exchange token migrationborrowing feature cessationmargin trading suspensionperpetual futures delistingspot trading pair delistingpending order cancellationforced loan repayment riskcollateral discount resetearn product automatic redemptionmigration completion dependency
OKX published a June 11, 2026 notice supporting TON migration to GRAM at 1:1. The notice says TON borrowing ceased at 10:30 UTC on June 11, margin trading will be suspended on June 15, TON perps and X-Perps will be delisted on June 16, spot pairs will be delisted on June 16, related services will be suspended, Simple Earn orders will be redeemed, and Flexible Loan users may face forced repayment or a collateral discount reset to zero if they do not adjust before delisting.
Listing post-mortem use: Use in listing and migration post-mortems to test whether exchange support plans cover margin debt, collateral haircuts, derivatives settlement, bot shutdowns, earn redemption, order cancellation, and delays between old-token delisting and new-token relisting.
Source
2026-06-10
Tier 3
USDC-Aptos network withdrawal service on Bitget
Bitget suspended USDC-Aptos network withdrawals for wallet maintenance, with reopening date to be announced separately.
Global
Bitget
Centralized exchange operations / stablecoin network withdrawal infrastructure
high confidence
withdrawal suspensionstablecoin exit-path disruptionnetwork-specific wallet maintenanceunclear restoration timingexchange operational friction
Bitget announced on June 10 that it would suspend the withdrawal function for USDC on the Aptos network starting at 12:50 UTC+8 due to wallet maintenance. The reopening date was not specified and would be announced separately.
Listing post-mortem use: Use as a comparable for post-listing stablecoin network support, exit-route availability, and exchange wallet-maintenance responsiveness.
Source
2026-06-10
Tier 1
Raydium legacy AMM V3 liquidity pools
Raydium acknowledged an exploit involving unauthorized removal of liquidity from deprecated legacy AMM V3 pools, with about $1.34 million in RAY, SOL, and USDC affected and treasury reimbursement promised.
Global
Raydium / protocol security investigators
DeFi security / Solana DEX liquidity infrastructure
high confidence
protocol exploitdeprecated contract exposureLP mint validation flawunauthorized liquidity removaltreasury reimbursementTornado Cash laundering tracelegacy infrastructure riskSolana DEX liquidity risk
Raydium-linked statements reported by crypto.news, Decrypt, and Protos describe a June 10 exploit against deprecated legacy AMM V3 pools. The attacker used an LP mint validation flaw to remove roughly $1.34 million in RAY, SOL, and USDC; Raydium said active users and current pools were unaffected and that treasury funds would reimburse impacted legacy-pool exposure.
Listing post-mortem use: Use in DEX and Solana ecosystem post-mortems to test whether listing diligence covered deprecated programs, inaccessible UI pools, LP mint validation logic, treasury reimbursement capacity, and mixer-linked recovery/escalation workflows.
Source
2026-06-09
Tier 3
Legend of Arcadia deposit service on KuCoin
KuCoin temporarily closed the deposit service for Legend of Arcadia (ARCA) due to essential maintenance and said restoration would not receive a further announcement.
Global
KuCoin
Centralized exchange operations / game token deposit infrastructure
high confidence
deposit suspensionexchange operational maintenancetoken inflow restrictionunclear restoration noticelisting support friction
KuCoin published a June 9 notice saying it had suspended the deposit service for Legend of Arcadia (ARCA) due to essential maintenance. The notice apologized for inconvenience and said users would not receive a further announcement when the service was restored.
Listing post-mortem use: Use as a low-severity comparable for token listings with recurring wallet maintenance, deposit-path outages, or ambiguous restoration communications.
Source
2026-06-09
Tier 1
TON product support on KuCoin margin, convert, trading bot, and UTA collateral
KuCoin announced a coordinated TON support contraction: spot margin services delisting, convert delisting, trading-bot pair delisting, and removal from Unified Trading Account collateral options.
Global
KuCoin
Centralized exchange margin / convert / collateral support
high confidence
margin-service delistingcollateral eligibility removalconvert-service delistingtrading-bot shutdownliquidation riskexchange product support contraction
KuCoin said TON margin services would be delisted at 06:00 UTC on June 10, with margin trading, lending, borrowing, transfer functions, and repayment functions affected and possible forced liquidation for high debt-ratio accounts. Separate same-day notices also removed TON from Convert, TONUSDT trading bots, and UTA collateral eligibility.
Listing post-mortem use: Use as a comparable for cases where a large-cap asset remains listed but loses enough exchange product surfaces to impair leverage, collateral, RFQ conversion, and automated strategy access.
Source
2026-06-08
Tier 3
NEAR network deposit and withdrawal services on Bitget
Bitget announced NEAR network deposits and withdrawals will be suspended from June 10, 2026 due to wallet maintenance, with no reopening date announced.
Global
Bitget
Centralized exchange operations / token deposit and withdrawal infrastructure
high confidence
deposit suspensionwithdrawal suspensionwallet maintenanceunclear reopening datenetwork transfer frictionexchange operational continuityscheduled user-access impairment
Bitget published a June 8, 2026 notice scheduling suspension of NEAR network deposit and withdrawal services from 07:00 UTC+8 on June 10 because of wallet maintenance. The reopening date was not provided, making this a Tier 3 watchlist signal for operational transfer support rather than a confirmed delisting or enforcement action.
Listing post-mortem use: Use when checking whether deposit/withdrawal maintenance windows created avoidable user exit friction, whether restoration timing was disclosed, and whether transfer-support interruptions correlated with liquidity changes on the venue.
Source
2026-06-08
Tier 1
KuCoin DUSDT, MBOXUSDT, and HIGHUSDT perpetual contracts
KuCoin Futures announced it will delist DUSDT, MBOXUSDT, and HIGHUSDT perpetual contracts on June 11, 2026, suspend new positions shortly before delisting, cancel open orders, and settle remaining positions using the final 30-minute average index price.
Global
KuCoin Futures
Centralized exchange derivatives / perpetual contracts
high confidence
perpetual contract delistingforced position settlementopen-order cancellationnew-position suspensionderivatives liquidity lossindex-price manipulation contingencytrading bot support losspre-delisting volatility risk
KuCoin Futures published a June 8, 2026 notice scheduling DUSDT, MBOXUSDT, and HIGHUSDT perpetual-contract delisting for 07:00 UTC on June 11. New positions will be suspended from 06:50 UTC, open orders will be canceled, and remaining positions will be settled using a 30-minute average index-price mechanism, creating a confirmed Tier 1 adverse exchange action.
Listing post-mortem use: Use to test whether derivatives venue support, automated strategy dependency, index-quality risk, leverage exposure, and user wind-down windows were reviewed before maintaining these assets in listing or market-making coverage.
Source
2026-06-08
Tier 1
KuCoin Earn flexible savings products for YB and ZIL
KuCoin Earn announced YB and ZIL will be delisted from flexible savings, with user principal and earnings automatically transferred to Funding Accounts after delisting or lock expiry.
Global
KuCoin Earn
Centralized exchange earn products / yield product restrictions
high confidence
earn product delistingyield product restrictionautomatic redemption transferexchange product support losslong-tail asset support degradationpost-margin-delisting clustering
KuCoin Earn published a June 8, 2026 notice saying YB and ZIL would be removed from KuCoin Earn flexible savings. User principal and earnings are to be moved to Funding Accounts after delisting or lock expiry. Because YB and ZIL were also part of a recent KuCoin margin-service delisting cluster, this is a confirmed Tier 1 exchange product-restriction signal.
Listing post-mortem use: Use to evaluate whether exchange product breadth was shrinking before broader market-access deterioration: compare Earn removal with prior margin delisting, lending/borrowing shutdown, bot restrictions, liquidity depth, and user redemption treatment.
Source
2026-06-06
Tier 1
HTX WLFI and USD1 markets after World Liberty Financial address freeze
HTX said World Liberty Financial unilaterally froze specific HTX on-chain addresses after sanctions-compliance reviews, prompting HTX to suspend WLFI/USDT, USD1/USDT, BTC/USD1, and ETH/USD1 trading and convert user USD1 holdings to USDT.
Global / US / UK
HTX; World Liberty Financial
Centralized exchanges / stablecoin issuer controls / sanctions compliance
high confidence
issuer-controlled address freezestablecoin blacklist authorityexchange trading suspensionforced user balance conversionsanctions-compliance disputecustody and user asset-rights conflictlisting support instabilitypotential legal remedies
HTX published a June 6, 2026 statement saying the WLFI project team had frozen specific HTX on-chain addresses after sanctions-compliance reviews. HTX suspended WLFI and USD1-related trading pairs from 13:00 UTC on June 5 and said user USD1 balances would be converted to USDT, making this a confirmed Tier 1 negative-intel signal for stablecoin issuer controls and exchange listing support.
Listing post-mortem use: Use to test whether issuer freeze authority, sanctions-screening governance, exchange wallet concentration, pair suspension handling, and forced conversion rules were reviewed before listing or maintaining WLFI/USD1 markets.
Source
2026-06-06
Tier 3
XO Protocol deposit service on KuCoin
KuCoin temporarily closed deposit service for XO Protocol (XOXO) due to essential maintenance and said it would not issue a further restoration announcement.
Global
KuCoin
Centralized exchange operations / token deposit infrastructure
high confidence
deposit suspensionexchange maintenancetoken transfer frictionunclear restoration timingvenue-dependence riskpublic-restoration-notice gap
KuCoin published a June 6, 2026 notice stating that it had suspended deposits for XO Protocol (XOXO) due to essential maintenance. The exchange said it would not notify users in a further announcement when services were restored, making the signal useful for ongoing listing-support monitoring.
Listing post-mortem use: Use when reviewing whether deposit-service interruptions, no-follow-up restoration notices, and exchange-wallet maintenance preceded later liquidity deterioration or delisting.
Source
2026-06-05
Tier 1
Bitget spot and margin markets for HIPPO, C98, SYS, POWR, AMP, TOWN, U2U, INJ/USDC, AR/USDC, ARB/USDC, and XRP/BTC
Bitget announced a scheduled June 12, 2026 delisting of eleven spot pairs, with deposits already suspended for seven tokens and margin liquidation risk for INJ/USDC, AR/USDC, and ARB/USDC.
Global
Bitget
Centralized exchange listings / spot and margin-market asset review
high confidence
scheduled exchange delistingdeposit suspensionspot liquidity lossopen order cancellationtrading bot removalcopy trading removalspot margin closureforced liquidation riskcollateral and debt unwind
Bitget published a June 5, 2026 official notice scheduling removal of eleven spot pairs on June 12: HIPPO/USDT, C98/USDT, SYS/USDT, POWR/USDT, AMP/USDT, TOWN/USDT, U2U/USDT, INJ/USDC, AR/USDC, ARB/USDC, and XRP/BTC. Deposits for seven tokens are already suspended, spot bots and selected copy-trading pairs will be removed, and spot margin services for INJ/USDC, AR/USDC, and ARB/USDC will close with automatic liquidation handling if users do not repay and close positions.
Listing post-mortem use: Use in post-mortems to test whether periodic-review criteria, low quote-pair volume, deposit restrictions, bot/copy-trading reliance, and margin debt exposure preceded broader venue support loss.
Source
2026-06-05
Tier 1
Bitget spot markets for SWARMS, VFY, BDXN, ESPORTS, POL/USDC, and DOGE/BTC
Bitget delisted six spot trading pairs on June 5, 2026 after periodic review, with deposit suspensions, order cancellation, unified-account removal, bot removal, and copy-trading removal for affected pairs.
Global
Bitget
Centralized exchange listings / spot-market asset review
high confidence
centralized exchange delistingdeposit suspensionspot liquidity lossopen order cancellationtrading bot removalcopy trading removalunified account transfer restrictionwithdrawal deadline
Bitget announced that SWARMS/USDT, VFY/USDT, BDXN/USDT, ESPORTS/USDT, POL/USDC, and DOGE/BTC would be delisted at 10:00 UTC on June 5, 2026. The notice includes suspended deposits for SWARMS, VFY, BDXN, and ESPORTS, automatic cancellation of pending orders, removal from unified account spot trading, bot removal, copy-trading removal for SWARMS/USDT, and a September 5 withdrawal deadline for several affected tokens.
Listing post-mortem use: Use to evaluate whether weak volume, liquidity quality, project responsiveness, bot dependence, and copy-trading exposure were visible before Bitget removed market support.
Source
2026-06-05
Tier 1
KuCoin margin services for YB, ZIL, YFI, and NEO
KuCoin announced it will delist isolated margin services for YB and ZIL and cross margin services for YFI and NEO, closing margin trading, lending, borrowing, transfers, and repayment functions for the affected tokens on scheduled dates from June 8 to June 11, 2026.
Global
KuCoin margin risk and exchange operations
Centralized exchange margin markets / product restriction
high confidence
centralized exchange margin delistingproduct restrictionmargin trading closurelending and borrowing closureforced order cancellationliquidation processtrading bot shutdownAPI index subscription changesharp-price-move early delisting risk
KuCoin published a June 5, 2026 official notice stating that isolated margin trading services for YB and ZIL and cross margin services for YFI and NEO will be delisted on scheduled dates from June 8 to June 11. The notice says margin trading, lending, borrowing, transfers, and loan repayment for the affected tokens will be closed or suspended; if users do not close positions and repay loans, KuCoin will cancel orders, initiate liquidation handling, transfer remaining assets, and may convert remaining delisted assets into USDT where debt-ratio conditions require it. This is a Tier 1 confirmed exchange product-restriction signal with direct adverse consequences for leveraged users.
Listing post-mortem use: Use in listing and post-mortem reviews to test whether margin-service delisting was an early signal before broader liquidity deterioration: check open-order cancellation, leverage availability, lending/borrowing closure, bot deactivation, API subscription changes, and debt-ratio liquidation handling.
Source
2026-06-05
Tier 1
LBank COSUSDT perpetual contract
LBank Futures announced automatic settlement and delisting of the COSUSDT perpetual contract at 12:00 UTC on June 6, 2026.
Global
LBank
Centralized exchange derivatives / perpetual contracts
high confidence
perpetual contract delistingautomatic settlementderivatives liquidity lossforced position closureopen-position deadline
LBank said its futures venue would automatically settle the COSUSDT perpetual contract and delist it at 12:00 UTC on June 6, 2026 after settlement completion. Users were advised to close open positions before the delisting time to avoid automatic settlement.
Listing post-mortem use: Use when reviewing whether derivatives support loss, forced settlement, and short user notice preceded broader market-access degradation or listing-quality concerns for COS.
Source
2026-06-05
Tier 3
EFAON ERC-20 withdrawal service on LBank
LBank said it suspended withdrawals of EFAON-erc20 at 22:23 UTC on June 5, 2026.
Global
LBank
Centralized exchange operations / token withdrawal infrastructure
high confidence
withdrawal suspensionexchange operational frictiontoken exit-path disruptionunclear restoration timingERC-20 transfer risk
LBank published a June 6 notice stating that EFAON-erc20 withdrawals had been suspended at 22:23 UTC on June 5, 2026. The notice did not provide a restoration time, making it a Tier 3 exchange-operation watchlist signal.
Listing post-mortem use: Use to check whether withdrawal suspensions preceded user complaints, liquidity deterioration, or later delisting for long-tail exchange-supported assets.
Source
2026-06-05
Tier 3
SYN-ARBITRUM, ONE, and SYN-BEP20 withdrawal services on LBank
LBank suspended withdrawals for SYN-ARBITRUM, ONE, and SYN-BEP20 at 09:00 UTC on June 5, 2026.
Global
LBank
Centralized exchange operations / token withdrawal infrastructure
high confidence
withdrawal suspensioncross-chain withdrawal frictionexchange operational maintenancetoken exit-path disruptionunclear restoration timing
LBank said withdrawals of SYN-ARBITRUM, ONE, and SYN-BEP20 were suspended at 09:00 UTC on June 5, 2026. The notice did not provide a restoration time, making it an operational negative-intel record rather than a confirmed delisting.
Listing post-mortem use: Use when testing if cross-chain withdrawal outages were early warning signs before liquidity loss, user complaints, or exchange support changes.
Source
2026-06-04
Tier 2
KuCoin BRL PIX withdrawal and refund services
KuCoin escalated its Brazil PIX rail warning into an official maintenance notice: from 16:00 BRT on June 4, 2026, BRL PIX deposits and withdrawals and crypto purchases using BRL balances may fail until further notice.
Brazil
KuCoin upstream payment providers / Brazil PIX fiat rail
Fiat on/off-ramp infrastructure / exchange payment rails
high confidence
fiat off-ramp disruptionpayment provider instabilitywithdrawal failurerefund delayBrazil PIX dependencybank account retry requirementscheduled PIX maintenancecrypto purchase failureuntil-further-notice fiat rail outage
KuCoin issued a June 4, 2026 official notice stating that, because of a system upgrade by payment service providers, PIX-related services entered maintenance from 16:00 BRT with duration until further notice. During the maintenance period, PIX deposits and withdrawals in BRL and crypto purchases using BRL balances may fail. This updates the June 2 PIX instability row and remains a high-confidence Tier 2 fiat-rail negative signal rather than a final enforcement or asset delisting.
Listing post-mortem use: Use when assessing whether a listed asset or venue has reliable fiat exit paths in Brazil: review payment-provider concentration, maintenance windows, failed withdrawal and purchase handling, refund timing, and user-notification quality during fiat-rail disruptions.
Source
2026-06-04
Tier 3
Hooli deposit service on KuCoin
KuCoin temporarily closed the deposit service for Hooli (HOOLI) due to essential maintenance and said it would not issue a further restoration announcement.
Global
KuCoin exchange operations
Centralized exchange operations / token deposit infrastructure
high confidence
deposit suspensionexchange operational maintenancetoken transfer frictionunclear restoration timingvenue-dependence risk
KuCoin posted an official notice on June 4, 2026 saying it had suspended the deposit service for Hooli (HOOLI) because of essential maintenance. The notice says users will not receive a further restoration announcement. This is a Tier 3 early-warning record for exchange operational friction and listing-support monitoring.
Listing post-mortem use: Use when assessing whether a token showed operational warning signs before market-access loss: compare deposit suspension timing, exchange-wallet restoration pattern, and liquidity retention after deposits reopen.
Source
2026-06-04
Tier 3
LAB deposit service on KuCoin
KuCoin temporarily closed the deposit service for LAB due to essential maintenance and said it would not issue a further restoration announcement.
Global
KuCoin exchange operations
Centralized exchange operations / token deposit infrastructure
high confidence
deposit suspensionexchange operational maintenancetoken transfer frictionunclear restoration timingvenue-dependence risk
KuCoin posted an official notice on June 4, 2026 saying it had suspended the deposit service for LAB because of essential maintenance. The notice says KuCoin will not publish a further restoration announcement. This is a high-confidence Tier 3 watchlist signal because the direct adverse consequence is deposit unavailability, not a confirmed exploit, enforcement action, or delisting.
Listing post-mortem use: Use when reviewing long-tail token support quality: check deposit uptime, whether exchange-wallet maintenance preceded liquidity deterioration, and whether users had enough public notice to manage transfer risk.
Source
2026-06-03
Tier 1
Alephium Bridge
Alephium published an official on-chain report for the May 30 bridge exploit, detailing forged Wormhole-message use, a 64-second drain across Ethereum and BSC, 13.76 million unbacked wALPH minted, Tornado Cash laundering, and a June 2 governance recovery that burned 96.4% of the fake wALPH supply.
Global
Alephium Bridge team and bridge guardians
DeFi security / cross-chain bridges / wrapped assets
high confidence
cross-chain bridge exploitforged bridge messagewrapped-asset unbacked mintbridge node fallback validation failureTornado Cash launderinggovernance recovery actionsecondary-market unrecovered supply
Alephium's June 3 official on-chain report describes the May 30, 2026 Alephium Bridge exploit. The attacker used a fake-event contract to feed false data into the bridge path, drained assets from Ethereum and BSC in about 64 seconds, minted 13,757,076.37 unbacked wALPH, routed proceeds through swaps, deBridge, and Tornado Cash, and left 500,000 wALPH outside the immediate recovery window. On June 2, bridge guardians executed an authorized governance recovery that burned 13,257,077.37 unbacked wALPH. This is a Tier 1 protocol action because the official report documents a confirmed exploit and direct recovery consequence.
Listing post-mortem use: Use for post-mortems on bridge-dependent listings: test whether forged-message and fallback-validation assumptions were reviewed, whether wrapped supply can be invalidated by governance, whether unrecovered wrapped assets reached secondary pools, and whether mixer-routing triggers exchange-freeze workflows.
Source
2026-06-03
Tier 3
RealityMetaverse deposit service on KuCoin
KuCoin temporarily closed the deposit service for RealityMetaverse (RMV) due to essential maintenance and said it would not issue a further restoration announcement.
Global
KuCoin exchange operations
Centralized exchange operations / token deposit infrastructure
high confidence
deposit suspensionexchange operational maintenancetoken transfer frictionunclear restoration timingvenue-dependence risk
KuCoin posted an official notice on June 3, 2026 saying it had suspended the deposit service for RealityMetaverse (RMV) because of essential maintenance. The notice states that users will not receive a further announcement when services are restored, making this a Tier 3 operational early-warning signal rather than a confirmed delisting, enforcement, or exploit event.
Listing post-mortem use: Use when reviewing whether an asset had pre-delisting operational stress: check deposit availability, wallet maintenance frequency, exchange communication quality, and whether suspended deposits affected liquidity or user exit paths.
Source
2026-06-03
Tier 1
Zcash Orchard shielded pool and Zebra node implementation
Zcash Foundation disclosed a critical Orchard Action circuit soundness bug, temporarily disabled Orchard actions by emergency soft fork, and activated NU6.2 to re-enable Orchard with a corrected circuit.
Global
Zcash Foundation / ZODL / Zcash protocol operators
Privacy coins / zero-knowledge protocol security
high confidence
critical protocol vulnerabilityemergency soft forkhard fork remediationtemporary shielded-pool disablementdouble-spend riskzero-knowledge circuit soundnessexchange and infrastructure coordinationprivacy-coin supply-verification risk
The Zcash Foundation said a critical Orchard zero-knowledge circuit soundness vulnerability was found on May 29, 2026. Zebra 4.5.3 temporarily disabled Orchard actions at mainnet height 3,363,426, and Zebra 5.0.0 activated NU6.2 at height 3,364,600 on June 3 to re-enable Orchard with a corrected circuit. The Foundation said there was no known exploitation and no evidence of unauthorized value creation, but the episode is a confirmed adverse protocol-security and exchange-coordination signal.
Listing post-mortem use: Use for post-mortems on privacy coins and ZK-heavy assets: check whether circuit-soundness assumptions, emergency fork readiness, exchange/wallet coordination, and supply-verification limitations were reviewed before listing or continued support.
Source
2026-06-03
Tier 1
Nobitex, Wallex, Bitpin, Ramzinex, and named Nobitex leaders
OFAC designated Nobitex, Wallex, Bitpin, Ramzinex, and multiple Nobitex leaders, alleging Iranian-regime support, sanctions evasion, IRGC-linked transactions, and ransomware-linked wallet activity, with blocked-property and transaction-prohibition consequences.
United States / Iran
U.S. Department of the Treasury Office of Foreign Assets Control (OFAC)
Centralized exchanges / sanctions compliance / illicit finance
high confidence
OFAC sanctions designationblocked propertysanctions evasionIRGC-linked transaction exposureransomware wallet exposurestablecoin sanctions risksecondary sanctions and strict-liability compliance risk
On June 3, 2026, Treasury/OFAC designated Nobitex, Wallex, Bitpin, Ramzinex, and named Nobitex leaders. Treasury says Nobitex processed more than half of Iranian digital-asset inflows in 2025 and facilitated transactions linked to the IRGC, sanctions evasion, and ransomware-related wallets; Wallex, Bitpin, and Ramzinex were also described as Iranian digital-asset exchanges operating in Iran's financial sector. The sanctions implications include blocked property, reporting duties, transaction prohibitions, and civil or criminal penalty exposure, making this a confirmed Tier 1 sanctions signal.
Listing post-mortem use: Use in listing and counterparty post-mortems to test whether sanctions-screening caught exchange-specific Iranian exposure, whether stablecoin flows involved sanctioned platforms, and whether wallet-risk escalation happened before liquidity or market-making relationships were approved.
Source
2026-06-02
Tier 1
OKX listed-asset basket: MAJOR and Jambo
OKX scheduled delisting of MAJOR and J spot pairs after stating the affected pairs did not fulfill listing criteria; MAJOR/USD was scheduled for June 2, with related Buy/Sell and Convert services suspended from May 30 and deposits suspended from May 26.
Global
OKX Token Delisting / Hiding Guideline and asset-review process
Centralized exchange listings / spot-market asset review
high confidence
centralized exchange delistinglisting criteria failureservice suspensiondeposit suspensiontrading bot closureuntradable asset migration
OKX published a May 26 official notice that MAJOR and J would be delisted after regular monitoring found several trading pairs did not fulfill listing criteria. The MAJOR/USD pair was scheduled for removal on June 2, 2026, with MAJOR/USDT and J/USDT on June 5; related Buy/Sell and Convert services were suspended from May 30, deposits from May 26, and withdrawals from August 26. The June 2 effective action makes this a Tier 1 exchange delisting signal.
Listing post-mortem use: Use for post-mortems on assets that lose top-tier venue support: review asset-quality indicators, deposit cutoff timing, bot and convert-service suspension, residual withdrawal windows, and whether local pair availability masked broader listing stress.
Source
2026-06-02
Tier 1
Phemex MCDX spot market
Phemex delisted the MCDX/USDT spot trading pair at 10:00 UTC on June 2, 2026, automatically removed pending orders, and ended MCDX deposits and withdrawals at the same timestamp.
Global
Phemex exchange asset-review / market operation notice
Centralized exchange listings / long-tail spot assets
high confidence
centralized exchange delistingspot market liquidity lossopen order cancellationdeposit suspensionwithdrawal suspensioncustomer support-dependent asset recovery
Phemex announced on June 1 that MCDX/USDT would be delisted from its spot market at 10:00 UTC on June 2, 2026. The notice also states that pending orders would be automatically removed and MCDX deposits and withdrawals would no longer be available after the same time, making this a confirmed Tier 1 exchange action with direct adverse consequence.
Listing post-mortem use: Use when reviewing whether a token had overconcentration on a small number of venues, whether withdrawal deadlines were monitored, and whether customer-support recovery became the only post-delisting asset path.
Source
2026-06-01
Tier 3
DeFi exploit and cross-chain bridge sector
CertiK's May 2026 loss data reported about $68.3 million lost to hacks, exploits, scams, and security breaches, with bridges causing about $28.6 million in losses and late-month Gravity Bridge and Alephium Bridge incidents tied to private-key access.
Global
CertiK; DeFiLlama; crypto.news reporting
DeFi security / cross-chain bridges / private key management
medium-high confidence
cross-chain bridge exploit concentrationprivate key compromiseprotocol code vulnerabilityAI-assisted malware riskdeveloper supply-chain targetingmonthly exploit-loss deterioration
A June 1, 2026 crypto.news report attributed May 2026 crypto security losses to CertiK data: about $68.3 million lost across exploits, scams, and breaches, with Verus Protocol and THORChain as the largest May incidents and cross-chain bridges representing about $28.6 million. The report also flagged late-May Alephium Bridge and Gravity Bridge private-key incidents and rising AI-assisted malware activity, so this is classified as a Tier 3 sector-risk movement rather than a new final enforcement or single-protocol action.
Listing post-mortem use: Use as a weekly and monthly comparator when a listed asset depends on bridge liquidity, wrapped collateral, multisig authority, AI-assisted developer tooling, or operational keys that may sit outside normal smart-contract audit scope.
Source
2026-06-01
Tier 1
Giottus listed-asset basket: Dent, FUNToken, Gari Network, Hooked Protocol, Measurable Data Token, TrueFi, and Wanchain
Giottus discontinued trading for seven listed tokens and scheduled remaining user balances above Rs 1 to be automatically converted to INR at 15:00 IST on June 1, 2026.
India
Giottus exchange asset-review process
Centralized exchange listings / long-tail spot assets
high confidence
centralized exchange delistingforced fiat conversionopen order cancellationlong-tail asset liquidity lossIndia exchange listing standardscustody exit deadline
Giottus announced that Dent, FUNToken, Gari Network, Hooked Protocol, Measurable Data Token, TrueFi, and Wanchain would be delisted on June 1, 2026. The official notice says trading would be discontinued, open orders cancelled, and remaining user balances above Rs 1 automatically converted into INR at 15:00 IST, making this a confirmed Tier 1 exchange action with direct adverse consequence.
Listing post-mortem use: Use when reviewing why a long-tail token lost exchange support: check whether asset-review triggers, local compliance alignment, volume quality, custody deadlines, and automatic conversion terms were visible before listing or continued support.
Source
2026-05-30
Tier 3
Bitcoin ATM and crypto kiosk operators
Same-day sector analysis consolidated a widening adverse pattern for Bitcoin ATM operators: regulatory bans and limits, consumer-fraud litigation, license suspensions, restitution settlements, and Bitcoin Depot's Chapter 11 wind-down after taking its kiosk network offline.
United States / Canada
State regulators and attorneys general; DFPI; bankruptcy court; consumer-protection authorities
Crypto kiosks / retail fiat on-ramps
medium-high confidence
crypto ATM scam infrastructureconsumer fraud exposureAML and KYC compliance failurestate-level product restrictionbankruptcy and network shutdowncash-to-crypto access contraction
CryptoSlate's May 30, 2026 analysis described a sector-level deterioration for Bitcoin ATMs, citing Bitcoin Depot's May 18 Chapter 11 filing and network shutdown, Canada's proposed ATM ban debate, California kiosk limits and DFPI enforcement, Iowa lawsuits against Bitcoin Depot and CoinFlip, Maine's Bitcoin Depot restitution settlement, and Connecticut license-suspension pressure. The row is classified as Tier 3 because the May 30 item is a fresh sector-risk synthesis rather than a new final enforcement order, but the underlying adverse actions are official and structured enough for longitudinal monitoring.
Listing post-mortem use: Use in listing and partner post-mortems to test whether retail on-ramp exposure was screened for scam complaint concentration, cash transaction limits, fee practices, AML/KYC gaps, state-license suspensions, and dependency on kiosk liquidity or distribution.
Source
2026-05-22
Tier 1
Polymarket operational wallet / UMA CTF Adapter-related infrastructure
Polymarket confirmed a six-year-old private key tied to internal top-up configuration was compromised, with roughly $573,200 transferred and $164,000 frozen after coordination with investigators and exchanges.
Global / United States
Polymarket engineering; ZachXBT; BitcoinVN; ChangeNOW
Prediction markets / protocol operations security
medium-high confidence
private key compromiseoperational wallet drainpartial fund freezekey-management failureincident response and KMS migration
On May 22, 2026, Polymarket engineering attributed suspicious outflows to a compromised legacy private key rather than a Polymarket or UMA smart-contract exploit. Public reporting said about $573,200 was transferred and $164,000 was frozen with help from ZachXBT, BitcoinVN, and ChangeNOW; Polymarket said user funds and contracts were unaffected and that it rotated the key and moved private keys to KMS-based management.
Listing post-mortem use: Use in listing post-mortems to test whether project due diligence covered old private keys, operational-wallet permissions, KMS migration, admin-key revocation, and incident-response coordination with exchanges or on-chain investigators.
Source
2026-05-22
Tier 2
Polymarket and Kalshi
The House Oversight Committee opened an investigation into whether Polymarket and Kalshi users can trade prediction contracts using non-public information and requested documents on identity checks, geo-restrictions, and anomalous-trading surveillance.
United States
U.S. House Committee on Oversight and Government Reform
Prediction markets / exchange infrastructure
high confidence
market integrity investigationinsider trading controlsKYC and geo-restriction scrutinyprediction-market surveillanceoffshore access controls
On May 22, 2026, the House Oversight Committee requested documents and information from Polymarket and Kalshi after reports of suspiciously timed prediction-market bets. The probe focuses on identity verification, foreign and domestic account controls, geographic restrictions, and anomalous-trading monitoring rather than a final enforcement outcome, so it is classified as a high-confidence Tier 2 adverse signal.
Listing post-mortem use: Use as a comparable when reviewing prediction-market tokens, oracle/resolution infrastructure, market-making support, or listings tied to event-contract platforms that could be exposed to insider-information trading claims.
Source
2026-05-20
Tier 3
MiCA-regulated crypto-asset issuers and service providers
The European Commission opened a MiCA review consultation to assess whether the EU crypto-asset framework remains fit for purpose and whether amendments or complementary regulation may be warranted.
EU
European Commission DG FISMA
Crypto regulation / CASP licensing / stablecoins
high confidence
jurisdiction risk shiftMiCA rule reviewCASP compliance burdenstablecoin regulationfuture legislative amendment
The European Commission launched a public and targeted consultation on May 20, 2026 to review the functioning of MiCA after initial implementation and market-policy developments. The targeted consultation is intended for crypto-asset service providers, crypto-asset issuers, public authorities, central banks, and finance ministries, and the Commission states that the mandated report may be accompanied by a legislative proposal if warranted.
Listing post-mortem use: Use as jurisdiction-radar context when reviewing EU market access, CASP sponsor readiness, stablecoin support, token issuer disclosure obligations, and listings whose business model depends on a stable MiCA perimeter.
Source
2026-05-20
Tier 2
Jane Street Group / Terraform Labs estate
Newly unsealed filings in Terraform estate litigation allege Jane Street used a private Telegram backchannel with Terraform insiders before selling about $192M of UST ahead of the Terra collapse.
US
US federal court / Terraform bankruptcy estate litigation
Stablecoins / market makers / trading firms
medium confidence
market integrity litigationstablecoin depeginsider information allegationmarket-maker red flagbankruptcy estate recovery
CoinDesk reported on May 20, 2026 that newly unsealed Manhattan federal court filings in Terraform estate litigation describe a private Telegram backchannel allegedly connecting a former Terraform intern working at Jane Street with Terraform insiders. The amended complaint alleges Jane Street sold roughly 193 million UST tokens, including an $85M Curve sale shortly after Terraform removed liquidity, then built short positions; Jane Street disputes the claims and says it will defend itself.
Listing post-mortem use: Use when reconstructing Terra/UST/LUNA listing failures, stablecoin depeg post-mortems, and token listings where affiliated market makers or insiders may have informational advantages during liquidity stress.
Source
2026-05-19
Tier 1
Echo Protocol Monad eBTC deployment
Echo Protocol suspended cross-chain transactions after unauthorized eBTC minting on Monad led to estimated realized losses of about $816,000 and a much larger unbacked eBTC supply event.
Global
Echo Protocol / Curvance / Monad ecosystem statements
Bitcoin DeFi / cross-chain bridge
high confidence
admin key compromiseunauthorized mintbridge suspensionlending collateral contagionmixer outflow
Crypto.news reported that an attacker minted roughly 1,000 unauthorized eBTC on Echo Protocol's Monad deployment, used part of the position as Curvance collateral, borrowed real Bitcoin-backed assets, bridged value to Ethereum, and routed ETH through Tornado Cash. Echo suspended cross-chain transactions while investigating, and ecosystem statements said Monad itself and Curvance core contracts were not breached.
Listing post-mortem use: Use as a direct comparable for listings or integrations of wrapped Bitcoin assets, bridge-issued collateral, and projects relying on single-admin mint paths or shallow new-chain lending markets.
Source
2026-05-19
Tier 2
Hormuz Safe Bitcoin-backed shipping insurance
Iran-linked Hormuz Safe reportedly offers Bitcoin-settled insurance for ships transiting the Strait of Hormuz, creating sanctions, maritime-finance, and payment-rail exposure for counterparties.
IR
Iran Ministry of Economy and Financial Affairs / Fars News reporting
Sanctions exposure / crypto insurance rails
high confidence
sanctions evasion riskBitcoin settlementshipping insurancestate-linked payment railmaritime access restriction
Claims Journal republished Bloomberg reporting that Iran started a Bitcoin-backed insurance service for Iranian shipping companies transiting the Strait of Hormuz, citing Fars and documents from Iran's Ministry of Economy and Financial Affairs. The report links the service to sanctions pressure, maritime passage controls, and Bitcoin settlement, making it a structured Tier 2 negative-intel signal rather than a completed enforcement action.
Listing post-mortem use: Use as jurisdictional context when reviewing projects, payment processors, insurers, or trading venues with exposure to Iranian maritime commerce, BTC settlement rails, or sanctioned-entity flow clusters.
Source
2026-05-19
Tier 2
Crypto national trust charter applicants and approvals
Senator Elizabeth Warren pressed the OCC over at least nine crypto national trust charters, alleging the approvals let crypto firms act like banks while evading full bank safeguards.
US
US Senate Banking Committee minority / Office of the Comptroller of the Currency
Crypto custody / banking access
high confidence
banking access scrutinycharter approval challengeconsumer protection riskstablecoin activityseparation of banking and commerce
The Senate Banking Committee minority published Senator Warren's May 19 letter to OCC Comptroller Jonathan Gould questioning at least nine national trust charters for crypto companies. The letter argues that the approvals may let crypto firms conduct custody, payment, lending, and stablecoin-like activities without full bank safeguards, and requests applications, legal analyses, and related communications by June 1, 2026.
Listing post-mortem use: Use as banking-access and regulatory-arbitrage context when reviewing listings or post-mortems for exchange tokens, stablecoin issuers, custody providers, and crypto firms whose market structure depends on national trust bank approvals.
Source
2026-05-18
Tier 2
Garden Finance
Garden Finance reportedly lost approximately $11M after a compromised solver drained funds; the protocol offered a 10% bounty and said user funds were not affected.
Global
Garden Finance / security media reporting
Cross-chain bridge / solver infrastructure
medium confidence
solver compromisebridge infrastructureoperational securitykey managementbounty negotiation
Cryptonews.net reported that Garden Finance lost about $11M through a compromised solver and offered a 10% bounty for fund return. The report says the protocol stated user funds were not affected, but the incident remains adverse because it points to solver/key-management exposure inside bridge operations.
Listing post-mortem use: Use when reviewing tokens or protocols dependent on solver networks, bridge market makers, off-chain relayers, or concentrated execution infrastructure.
Source
2026-05-18
Tier 2
Verus-Ethereum Bridge
Security researchers reported that the Verus-Ethereum Bridge was drained of more than $11.5M through a forged cross-chain transfer exploit.
Global
Blockaid / PeckShield / GoPlus / ExVul security researchers
Cross-chain bridge / DeFi
high confidence
bridge exploitcross-chain message validationreserve drainTornado Cash funding traceliquidity loss
Crypto.news reported that Blockaid, PeckShield, GoPlus, and ExVul linked a Verus-Ethereum Bridge drain to a forged cross-chain transfer message and missing validation checks. Reported drained assets included 103.6 tBTC, 1,625 ETH, and about 147,000 USDC, later swapped into roughly 5,402 ETH.
Listing post-mortem use: Use as a comparable for bridge-dependent token listings, cross-chain reserve validation failures, and listings where external security researchers identify an exploit before formal project disclosure.
Source
2026-05-17
Tier 1
CRYPGPT spot market
BloFin's delisting schedule closed CRYPGPT withdrawals at 09:00 UTC on May 17, 2026 after earlier spot trading and deposit termination.
Global
BloFin
Exchange spot markets / AI tokens
high confidence
exchange delistingwithdrawal closuremarket-access lossAI-token liquiditycustody deadline
BloFin previously announced removal of the CRYPGPT/USDT spot pair and set May 17, 2026 at 09:00 UTC as the final withdrawal deadline. The deadline creates a confirmed adverse market-access and custody-risk signal for CRYPGPT holders on that venue.
Listing post-mortem use: Use when reviewing AI-token listings that depend on thin centralized-exchange liquidity, short delisting remediation windows, or exchange-hosted custody exits.
Source
2026-05-17
Tier 1
CoinEx delisted asset basket
CoinEx's delisting schedule terminated withdrawals for twelve previously delisted assets at 08:00 UTC on May 17, 2026.
Global
CoinEx
Exchange spot markets / long-tail tokens
high confidence
exchange delistingwithdrawal closurelong-tail liquidityasset support terminationlisting maintenance failure
CoinEx's official delisting notice set May 17, 2026 at 08:00 UTC as the withdrawal termination time for RIFSOL, PNP, LLM, VIA, AIMONICA, BADGER, GRAIL, TSUKA, HXD, UNA, 0X0, and MOCHI after trading ended earlier. The action is a confirmed adverse exchange-support signal for the affected assets.
Listing post-mortem use: Use as a basket comparable for post-listing maintenance failures, long-tail spot-market cleanup, and cases where final withdrawal deadlines matter as much as the initial trading halt.
Source
2026-05-15
Tier 1
XTIUSDT and XBRUSDT perpetual contracts
BitMart announced delisting and automatic closure of XTIUSDT and XBRUSDT perpetual contracts, with no new positions allowed after the delisting time.
Global
BitMart
Exchange derivatives / tokenized commodities
high confidence
exchange delistingforced settlementderivatives liquiditycontract migrationmarket-access friction
BitMart said it would delist XTIUSDT and XBRUSDT perpetual contracts on May 15, 2026 at 10:30 UTC. The exchange stated that contracts would be automatically closed, open positions settled at market price at delisting, and users would no longer be able to open positions after the cutoff.
Listing post-mortem use: Use as a comparable for post-listing derivative support failures, forced settlement, and liquidity degradation when evaluating tokenized commodity assets or exchange-maintained perpetual contracts.
Source
2026-05-15
Tier 2
Crypto scam compounds
Draft cyber-scam legislation proposes capital punishment for violent scam-compound offenses.
MM
Myanmar Government
Scam infrastructure
medium confidence
AMLhuman traffickingscam infrastructurecross-border enforcement
Myanmar's draft cyber-scam bill is not a completed enforcement action, but it is a negative intelligence signal for crypto-facilitated scam infrastructure and regional AML pressure.
Listing post-mortem use: Raises risk weight for projects, wallets, payment rails, or exchanges with exposure to Southeast Asia scam-compound flows.
Source
2026-05-15
Tier 1
THORChain
THORChain halted trading after an Asgard vault compromise caused an estimated $10.7M protocol-owned fund loss.
Global
THORChain protocol / security researchers
Cross-chain liquidity / DeFi
high confidence
cross-chain exploitprotocol haltvault compromiseliquidity disruptionnode security
THORChain paused trading after security researchers flagged a multi-chain exploit and the protocol confirmed one of six Asgard vaults was compromised. Reported losses were approximately $10.7M in protocol-owned funds, while initial statements said individual user swaps were not affected.
Listing post-mortem use: Use as a direct adverse comparable when reviewing listings or non-listings of RUNE, bridge tokens, cross-chain liquidity assets, and projects dependent on threshold-signature vault operations.
Source
2026-05-14
Tier 2
DeFi and offshore VASPs
AUSTRAC flags DeFi and offshore VASPs as money-laundering blind spots.
AU
AUSTRAC
Exchange / DeFi / AML
high confidence
AMLoffshore VASPDeFitraceability
The AUSTRAC risk snapshot expands the negative intelligence surface beyond completed enforcement into AML blind spots likely to shape future supervision.
Listing post-mortem use: Use as jurisdiction-risk context when a token or venue has heavy offshore VASP routing, DeFi liquidity, or weak attribution controls.
Source
2026-05-13
Tier 1
Banco Topazio
Central bank action reportedly suspends OTC virtual asset activity over AML control failures.
BR
Banco Central do Brasil
OTC virtual asset activity
medium confidence
AMLOTCcustomer due diligencebanking rails
Banco Topazio is a structured negative intelligence entry because it links AML failures, virtual asset OTC activity, and bank-supervised settlement infrastructure.
Listing post-mortem use: Increases risk weight for OTC-heavy liquidity routes and bank-linked settlement partners with weak CDD controls.
Source