Poolin bitcoin mining pool operator files for bankruptcy

Poolin Technology, once among the largest bitcoin mining pools in the world, has filed for bankruptcy, listing more than $100 million in debts against less than $10 million in assets.

The largest liability by far is the $163.7 million owed to roughly 11,700 people who had money in Poolin Wallet when the company froze withdrawals in September 2022, citing "some liquidity issues" during that year's crash. Instead of returning their bitcoin, Poolin handed them IOU tokens, which it never redeemed.

Poolin was founded in Beijing in 2017 and in better days accounted for almost a fifth of the bitcoin network's hashrate.

42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft

Balance Coin, a small algorithmic stablecoin built on BNB Chain, lost its dollar peg and crashed to fractions of a cent after an attacker successfully exploited a flaw in its pricing logic. The attacker was able to trick the system into accepting an incorrectly low bitcoin price, which they then used to drain multiple vaults used by the project's lending protocol.

The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.

Wanchain bridge on Cardano exploited for more than $9 million

An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.

Allbridge exploited for $1.66 million

The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.

Across Protocol exploited for $3.35 million

The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.

MVMT Labs files for bankruptcy

MVMT Labs, the company behind the Movement blockchain, has filed for bankruptcy, reporting assets of between $100,001 and $500,000 against liabilities of between $1 million and $10 million. The largest unsecured claim, at more than $1.6 million, belongs to co-founder Rushi Manche — whom the company fired in May 2025 after an investigation into the MOVE token launch.

Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.

The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.

Ostium loses at least $24 million to oracle exploit

Decentralized perpetual futures exchange Ostium was drained of at least $24 million after an attacker manipulated its oracle system — a system that pulls in off-chain price data. After the attacker apparently gained access to the private key used to sign oracle messages, they were able to submit future-dated oracle reports that tricked the system into thinking trades were profitable.

The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.

Bonzo Lend exploited for $9 million in oracle attack

The Hedera-based decentralized lending platform Bozno Lend was exploited for just over $9 million after an attacker took advantage of a flaw in the project's oracle system. The attacker was able to deposit tokens worth only a few dollars, then manipulate the project's oracle to reflect a dramatically higher price. They then borrowed $6.63 million in USDC and 34.5 million wrapped HBAR (~$2.4 million).

Bonzo has announced they will reimburse users affected by the exploit, with support from the Hedera Foundation.

Summer Finance exploited for $6 million, shuts down

Summer Finance, a defi platform that provides "institutional defi vault infrastructure", was exploited for $6 million in an apparent flash loan attack. The attacker used a flash loan to deposit $64.8 million and then withdraw $70.9 million, taking advantage of a price manipulation bug that allowed them to withdraw more than they deposited.

Shortly after the exploit, Summer Finance announced it had "no viable path forward other than to wind down operations". They added, "a meaningful portion of the team's own capital was held in the affected vaults, removing the runway we needed to rebuild."

Dutch Knaken crypto platform collapses with $8 million in customer funds missing

The Dutch cryptocurrency platform Knaken (not to be confused with the American Kraken platform) abruptly went offline in early June, leaving roughly 30,000 customers unable to access their funds. The company was unable to secure a license under the EU's MiCA regulations, which it said forced them to shut down. Though they claimed to be winding down the company in an orderly fashion, they reportedly stopped paying customer withdrawals, and asked customers to stop filing claims.

Dutch prosecutors asked courts to declare the platform bankrupt and install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers, who are missing around €7 million (~$8 million). The request was approved. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.