Extropy reports major crypto hacks in January 2026. Truebit loses $26M, Ledger data breach exposes users, and phishing attacks surge. The first two weeks of 2026Extropy reports major crypto hacks in January 2026. Truebit loses $26M, Ledger data breach exposes users, and phishing attacks surge. The first two weeks of 2026

Web3 Chaos Hits Hard: Millions Drained in Just Two Weeks of 2026 – Report

2026/01/13 23:06
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Extropy reports major crypto hacks in January 2026. Truebit loses $26M, Ledger data breach exposes users, and phishing attacks surge.

The first two weeks of 2026 brought a wave of security incidents across Web3 platforms. 

Extropy published its Security Bytes report documenting these events. The findings portray a troubling picture of the current threat landscape.

According to the report, attackers continued their operations through the holiday season. The damage ranged from multimillion-dollar exploits to sophisticated phishing campaigns.

Truebit Protocol Loses $26 Million to Legacy Code Flaw

The year’s first major incident hit Truebit Protocol on January 8. An attacker drained roughly $26 million in what Extropy calls a “zombie code” exploit.

The vulnerability stemmed from an integer overflow in legacy smart contracts. These older contracts lacked modern Solidity’s native overflow protections. The attacker minted millions of TRU tokens at virtually no cost.

Once created, the tokens flooded back into the protocol. All available liquidity vanished within hours. The TRU token price collapsed by nearly 100% in just 24 hours.

Extropy notes that the attacker moved 8,535 ETH through Tornado Cash immediately. Security firms later linked the wallet to a previous Sparkle Protocol exploit. This suggests a repeat offender specifically targeting abandoned contracts.

The report warns that legacy contracts remain a critical vulnerability. Projects must either monitor or deprecate old code actively.

TMXTribe Watches $1.4M Drain Over 36 Hours

Between January 5 and January 7, TMXTribe suffered a slower but equally devastating attack. The GMX fork on Arbitrum lost $1.4 million over 36 continuous hours.

Extropy describes the exploit as mechanically simple. A loop minted LP tokens, swapped them for stablecoins, then unstaked repeatedly. The unverified contracts prevented public analysis of the exact flaw.

What troubled researchers most was the team’s response. According to the report, developers remained active on-chain throughout the attack. They deployed new contracts and executed upgrades during the drain.

However, they never triggered an emergency pause function. The team sent an on-chain bounty message to the attacker instead. The thief ignored it, bridged funds to Ethereum, and laundered them through Tornado Cash.

Extropy questions whether this represents negligence or something worse. The report emphasizes that unverified contracts serve as red flags for users.

Ledger Customers Face Physical Security Risks

On January 5, Ledger confirmed a data breach affecting its customer base. The breach originated from payment processor Global-e, not Ledger’s hardware.

Customer names, shipping addresses, and contact information were compromised. Extropy warns this creates what security experts call “wrench attack” scenarios. Attackers now possess a list of crypto hardware wallet owners and their locations.

The report notes a bitter irony. Ledger previously faced criticism for charging for security features. Now their payment processor has exposed users to physical danger at no cost.

Extropy advises users to expect sophisticated phishing attempts. The stolen data allows attackers to establish false trust through personalized communications.

Related Reading: A Round Up of Security Incidents Surrounding Ledger Hardware Wallets

MetaMask Phishing Campaign Drains $107,000

Security researcher ZachXBT flagged a sophisticated phishing operation targeting MetaMask users. The campaign has drained over $107,000 from hundreds of wallets.

Victims received professional emails claiming a mandatory 2026 upgrade. The messages used legitimate marketing templates and featured a modified MetaMask logo. Extropy describes the “party hat” fox design as disarmingly festive.

The scam avoided asking for seed phrases. Instead, it prompted users to sign contract approvals. This permitted attackers to move unlimited tokens from victim wallets.

By keeping individual thefts under $2,000, the operation avoided major alerts. Extropy emphasizes that signatures can be as dangerous as leaked keys.

The post Web3 Chaos Hits Hard: Millions Drained in Just Two Weeks of 2026 – Report appeared first on Live Bitcoin News.

Market Opportunity
Major Logo
Major Price(MAJOR)
$0.06121
$0.06121$0.06121
+0.45%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Zcash is Predicted to Reach $215.89 By Mar 12, 2026

Zcash is Predicted to Reach $215.89 By Mar 12, 2026

The post Zcash is Predicted to Reach $215.89 By Mar 12, 2026 appeared on BitcoinEthereumNews.com. Disclaimer: This is not investment advice. The information provided
Share
BitcoinEthereumNews2026/03/08 08:09
Why Is Crypto Down in 2026? Binance Leverage Hits Exhaustion Lows as Pepeto Lines Up a Moonshot

Why Is Crypto Down in 2026? Binance Leverage Hits Exhaustion Lows as Pepeto Lines Up a Moonshot

Here is something the fear headlines are not telling you. The Binance estimated leverage ratio dropped to 0.146 in early March 2026, its lowest reading since April
Share
Techbullion2026/03/08 08:18
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27