Category · 5 stories
Security
Most losses are not exotic. We report exploits and exchange failures with the post-mortem detail that makes them useful — the attack path, the amount, the recovery — and pair them with practical guidance on keys, approvals and hardware wallets so the lesson survives the news cycle.
Bitget loses $351.6m — and the fund it says covers it is one we could not verify
The largest exchange theft of 2026 came through spoofed transfers, not stolen keys. Bitget says a $464m protection fund absorbs it. We reviewed that fund before the hack: genuinely scoped to theft, and impossible to check.

Exchange publishes proof-of-reserves with a zero-knowledge attestation
An exchange has published a proof-of-reserves backed by a zero-knowledge attestation, proving it holds the assets it claims without exposing customer data. But reserves are only half of solvency. The liabilities side is where the real questions live.

Cross-chain bridge resumes operations after a security audit
A cross-chain bridge is back online after pausing for a security audit. The restart is a good moment to understand why bridges concentrate so much risk, how their trust models actually work, and what an audit can and cannot promise.

Self-custody without footguns: a practical security checklist
Most crypto losses are process failures, not exotic hacks. A mechanism-first checklist for hardware wallets, seed backups, hot/cold separation, and the signing mistakes that actually drain wallets.

How to set up your first hardware wallet, step by step
A calm, thorough walkthrough of setting up your first hardware wallet, from buying direct to testing recovery before you fund it, plus the beginner mistakes that quietly drain wallets.