Overview

Wallet & address intelligence

Know your address
before it becomes a risk.

addr.red brings wallet and address intelligence, risk flags, and early intelligence into one workspace. Give analysts, investigators, and organizations the source-backed evidence to make informed decisions.

1,717Risk-flagged addresses
12,186Scored addresses
1,717High / Critical addresses
23Intelligence · 24h
31Enabled sources

Intelligence Feed

Latest 40
EventCategorySourcesTime
SEAL blocked URL · https://maticsea.space/app-924a52.js

Blocked URL: https://sites.google.com/view/routingnumbererrorrobinhoodpho/home

Open source
Investigation1 source
Beldex · [PT] Beldex / Wallet - BDX / Aug2026

This report presents the results of an independent source-code security assessment of the Beldex wallet browser extension and the bdx-web3js integration SDK. Audit type: PT Total findings: 13 Open critical/high findings: 0

Open source
Investigation1 source
Revolut hackers demand $3 million in Monero, threaten to sell customer data

The group gave Revolut 24 hours to pay and said it targeted customers with significant crypto holdings. Revolut said it has not not received any direct contact from the individuals.

Open source
News1 source
A stolen coin can be returned. A leaked identity cannot.

We keep building the honeypots, and we are about to hand the same architecture to billions of AI agents, writes Evin McMullen, CEO and co-founder of Billions.

Open source
News1 source
Startale

Startale’s ERC-7579 smart accounts on Ethereum were exploited. The attacker abused a transient-storage initialization flag in initializeAccount that persists for the entire transaction, allowing re-initialization with a malicious bootstrap in the same tx after factory deployment. This enabled draining ~330 pre-funded counterfactual accounts (no signatures or capital required) for a total of ~$2,876. The Soneium network itself was unaffected. Amount of loss: $ 2,876 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
Flamincome

Flamincome (legacy contracts of Flamingo Finance) was exploited due to unsafe asset accounting and valuation. The attacker flash-loaned ~$18M USDT, injected USDP/3CRV LP into the Strategy (treating a permissionlessly injectable Convex BaseRewardPool balance as its own assets and overvaluing it via Curve’s get_virtual_price() in a depegged pool), inflated the VaultYUSDT share price, and redeemed real Aave aUSDT liquidity for ~$345.9K profit. Amount of loss: $ 345,900 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
Bonfiretoken

The BonfireSwap router’s transfer lacked access control: it did not require msg.sender == from or check the caller’s allowance on from. An attacker set approved holders as from and themselves as to, drained TOKEN via existing victim→router allowances, then forwarded funds through a same-token pool swap. About 41 approved holders were hit; loss ~$50,000. Amount of loss: $ 50,000 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
A hacker turned 25 cents of bitcoin into 46 billion fake BTC tokens on a DeFi bridge

Two software bugs allowed the attacker to create more than 2,000 times Bitcoin’s maximum supply in unbacked syBTC. Symbiosis puts preliminary losses at 9.97 BTC.

Open source
News1 source
How a simple coding mistake let a hacker drain $7.8 million from a crypto wallet

Security firms traced the $7.8 million loss to a helper contract the wallet owner had authorized, not to Safe itself.

Open source
News1 source
DCENT Wallet

On September 16, 2026, DCENT (formerly D'CENT) issued an urgent security alert stating that abnormal asset transfers had been detected in its mobile App Wallet (software wallet) and that an emergency investigation was underway. Initial findings indicate the issue is limited to the App Wallet, with no confirmed impact on hardware wallets themselves. Users holding assets in the App Wallet, or using the same mnemonic for both the App Wallet and a hardware wallet, are strongly advised to immediately transfer funds to a secure hardware wallet or other trusted address, and to remain vigilant against scams. Amount of loss: $ 6,570,000 Attack method: Unknown

Open source
Hack1 source
Unknown Gnosis Safe Wallet

An unidentified user’s Gnosis Safe wallet on Ethereum was drained of about $7,730,000. The attacker exploited an authorization bypass in a Router multicall function, used the victim Safe module to DelegateCall attacker-crafted data, injected aEthrsETH into a malicious Uniswap V4 hooked pool, then swapped and redeemed it as rsETH. Kelp later placed a 24-hour pause on an address that received the stolen rsETH. Amount of loss: $ 7,730,000 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
White House crypto adviser says Trump gave up 'historic' ethics powers in compromise

President Donald Trump's digital assets adviser spoke at a Washington event the day after a new compromise language was released for the Clarity Act.

Open source
News1 source
Bipartisan group of state attorneys general oppose Clarity Act over federal preemption worry

The state AGs said they were concerned the crypto legislation might restrict their ability to bring securities and commodities cases tied to online scams.

Open source
News1 source
Community alert: Defimon detected a governance takeover attempt of Yam.finance Attacker self-delegated ~504K $YAM (~3.3% of supply, just ov…

Community alert: Defimon detected a governance takeover attempt of Yam.finance Attacker self-delegated ~504K $YAM (~3.3% of supply, just over the quorum) and submitted YamGovernorAlpha proposal #45 with an empty description ("0x"). The single action calls…

Open source
Investigation1 source
OKX · [PoR] OKX / Recurrent / July2026

Audit type: POR Total findings: 0 Open critical/high findings: 0

Open source
Investigation1 source
OKX · [PoR] OKX / Recurrent / Aug2026

Audit type: POR Total findings: 0 Open critical/high findings: 0

Open source
Investigation1 source
Long Bridge

Long’s custodial bridge released 46.7928 WETH (about $118,000) from its Robinhood Chain vault after a third-party RPC fed the keeper fabricated Arc withdrawal events. No on-chain contract or key was breached. The team halted the keeper, rebuilt verification, and refilled the vault the same day from platform revenue. Users did not lose funds. Amount of loss: $ 118,000 Attack method: Supply Chain Attack

Open source
Hack1 source
MEXC · [POR] MEXC / Solvency Proof / Sep2026

Audit type: POR Total findings: 0 Open critical/high findings: 0

Open source
Investigation1 source
Spiral

The attacker manipulated the Uniswap V4 pool spot price. SpiralHookV2.borrow() valued collateral using poolManager.getSlot0() without TWAP or price-change limits. The noSameBlockSwap guard (keyed by tx.origin) was bypassed via 6 different EOAs, allowing borrowing against inflated collateral in the same block as the pump, resulting in a loss of ~10.7 ETH. Amount of loss: $ 26,800 Attack method: Price Manipulation

Open source
Hack1 source
Bitcoin activity, passports exposed after Revolut falls for fake government request

Passports, selfies and home addresses were also handed over after the digital bank treated a fraudulent request as legitimate, but no customer funds were lost.

Open source
News1 source
Community alert: Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a…

Community alert: Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a fraudulent government request. Exposed data included: -Copy of passport and/or driver's licence, plus the verification selfie -Account statements, IBAN, withdrawal records, and full transaction history including Bitcoin -Full name, date of birth, occupation -Home address, email, phone number While the incident is likely limited in size it seems to have been targeted at high net worth users.  An email alerting users was sent out to multiple Revolut users yesterday.

Open source
Investigation1 source
Chainflip

Cross-chain protocol Chainflip was exploited on its TRON USDT integration. The attacker abused TRON memo handling by attaching a custom memo to a transaction already signed by validators, causing the system to treat the same deposit as a separate failed swap and issue a duplicate refund. The attack was repeated eight times over about 90 minutes, producing six unauthorized payouts totaling 736,442.17 USDT. A pending user swap of 115,654.41 USDT remains safely in the vault. The network is paused, a fix is ready, restart is expected as early as Monday, and affected users will be made whole. Amount of loss: $ 736,442.17 Attack method: Protocol logic vulnerability

Open source
Hack1 source
💌 Onchain message: This message is from Zentra Finance. It concerns the 9 September 2026 exploit of our ctUSD reserve on Citrea, transacti…

💌 Onchain message: This message is from Zentra Finance. It concerns the 9 September 2026 exploit of our ctUSD reserve on Citrea, transaction 0x9ac5df7e93988cd977e4b1b0564f559ec3096db2fe1abdd97e45c348e3074aa1. We have traced the proceeds to this address. …

Open source
Investigation1 source
Dominion

Dominion Market’s Solana silver token $SILV suffered a treasury multisig compromise. With 3-of-5 keys, the attacker emptied the treasury and pulled SILV from loans, dumping about 46,909 tokens (face value ~$3 million) into thin DEX pools and realizing about $238,000 as the peg broke. The team pulled liquidity, rotated hardware, froze tokens bought in the incident window, and planned USDC refunds plus a repeg. Amount of loss: $ 238,000 Attack method: Private Key Leakage

Open source
Hack1 source
Symbiosis

An attacker exploited a vulnerability in Symbiosis’ Bitcoin Bridge (BridgeV2) by abusing incorrect parsing of Bitcoin transaction data and negative fee settings, minting approximately 2622^{62}2^{62} unbacked syBTC (notional face value ~46.1 billion) across BSC, Ethereum and Rootstock within about four minutes, then sold ~4.39 WBTC on Ethereum’s Uniswap V4 for ~$336,000. The team immediately paused native BTC routes, isolated the affected component, evacuated ~15.2 BTC of portal funds to reserve addresses, and offered a 20% white-hat bounty. The post-mortem confirmed total losses for LPs and affected users at 9.97 BTC. Other routes (EVM, TRON, TON, etc.) remained unaffected. Amount of loss: $ 775,000 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
ORBToken

Attackers exploited ORBToken’s receive() function (which auto-granted max allowance) and ORBCore’s whitelist tax exemption. The addPoolAndSell function lacked a reentrancy guard, enabling repeated tax-free sells. Combined with burnLP destroying large amounts of ORB in the LP and a subsequent sync() to manipulate reserves, the attacker extracted about $32,610.72. Amount of loss: $ 32,610.72 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
OMNI404

Ethereum ERC-404 token OMNI404 (O404) derived NFT mint/burn counts from integer balanceOf/units diffs in _transfer(). Its transfer() treated values ≤50 as ERC-721 IDs but still moved a fixed 1e18 units. Using flash loans and Uniswap V3 exact-output swaps (transfer(recipient, 1/2/.../21)), the attacker received full-unit tokens while the pool booked wei-level amounts, draining about 2.4 WETH. Amount of loss: $ 5,923 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
Ether.fi Liquid

Users of ether.fi Liquid (liquidETH) lost ~15.45 ETH after an attacker exploited missing access control in AtomicQueue.solve() on the caller-supplied solver parameter. The attacker crafted a malicious AtomicRequest, forced already-approved victim addresses to act as solver, and drained funds via existing ERC-20 allowances with transferFrom. About 11 users were affected. Amount of loss: $ 38130 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
Threatened with arrest online? Recognizing a law enforcement impersonation scam

So-called digital arrest scams use false claims of authority to pressure victims virtually into making rapid digital payments, including cryptocurrency transactions, writes Moody's Rich Graham.

Open source
News1 source
U.S. Treasury sanctions another widespread cyber-scam hub, Xinbi Guarantee

Chinese-language platform Xinbi is accused of operating on crypto transactions as it offered services to other criminal networks.

Open source
News1 source
KYC data is an irresistible honeypot for hackers, and we must change how it is collected

Privacy-preserving identity verification systems could allow individuals to prove only what a service needs to know while keeping the underlying information under their control, writes Coin Center’s Laz Pieper.

Open source
News1 source
Singaporean 22-year old pleads guilty to being the ringleader in $245 million crypto fraud case

Malone Lam, a Miami resident charged with stealing 4,100 bitcoin, led a ring of fraudsters who stole crypto via online scams and home invasions.

Open source
News1 source
Zilliqa · [SCA] Zilliqa / Zilliqa Ownership Proof / Aug2026

Zilliqa 1.0 was a legacy L1 that combined PoW consensus with pBFT finality and EC-Schnorr transaction signing over secp256k1. It was shut down over a year ago in favor of Zilliqa 2.0, an EVM-compatible, PoS-based chain that continues to support legacy Zilliqa 1.0 accounts and transaction formats. Following a July 2026 incident which exposed the leaf keys of a section of users, affected holders now need a way to migrate their legacy accounts to new EVM-compatible accounts without exposing the underlying key material — the leaked leaf keys must not be sufficient to migrate funds. Audit type: SCA Total findings: 21 Open critical/high findings: 0

Open source
Investigation1 source
KuCoin · [POR] KuCoin / Solvency Proof / Sep2026

Audit type: POR Total findings: 0 Open critical/high findings: 0

Open source
Investigation1 source
Europeum · [PT] Europeum / API / Aug2026

Audit type: PT Total findings: 20 Open critical/high findings: 0

Open source
Investigation1 source
BeatXswap

BeatXswap’s LiquidityVestingConvert used the Uniswap/Pancake V3 slot0() spot price as its only oracle, with no TWAP or deviation checks. An attacker flash-loaned 6,000,000 BTX, dumped it to crash the pool price, then called deposit() twice (10,000 + 2,000 USDT) to mint LP at the manipulated quote and drain 2,984,557 BTX (~$77,512). Amount of loss: $ 77,512 Attack method: Price Manipulation

Open source
Hack1 source
Zentra Finance

On September 9, 2026, an attacker used a single transaction on Citrea mainnet and ~200,000 USDC.e of flash liquidity as temporary collateral to drain 140,000 ctUSD and 30 USDC.e from Zentra’s lending pool. The root cause was an accounting edge case in repayWithATokens: the debt path could complete while the matching aToken burn was reduced to zero. The operations multisig paused all markets about 17 minutes later; no second exploit occurred. Amount of loss: $ 140,030 Attack method: Smart Contract Vulnerability

Open source
Hack1 source
BeatSwap

BeatSwap (BeatXswap) on BSC was exploited after LiquidityVestingConvert used Uniswap V3 slot0() spot price as its sole oracle, with no TWAP or deviation checks. The attacker flash-loaned 6,000,000 BTX, dumped it to crash sqrtPriceX96, then called deposit() twice (10,000 + 2,000 USDT) to mint LP at the manipulated price and drain 2,984,557 BTX (~$77,512). Amount of loss: $ 77,512 Attack method: Price Manipulation

Open source
Hack1 source
Nomic nBTC Bridge

An attacker exploited a bug in Nomic’s custom forwarding mechanism to double-spend nBTC and send unbacked vouchers to Osmosis. Osmosis and IBC themselves were not compromised. 39.84 nBTC of the minted supply sat in Alloyed BTC (~36% of its backing). Osmosis froze Nomic and Alloyed BTC flows, upgraded with validators, and froze 22.65 BTC in the attacker’s address. Governance will be asked to seize those funds and cover the rest from the community pool. Amount of loss: $ 3,150,000 Attack method: Double-Spending Attack

Open source
Hack1 source
Amnext

The old BNB Chain DeFi protocol Amnext (AMC), a no-loss lottery/prize-pool product, was exploited. The attacker mass-minted Ticket AMC and drained about 154.02 WBNB from the protocol via PancakeSwap, causing a loss of approximately $ 116,100. Amount of loss: $ 116,100 Attack method: Smart Contract Vulnerability

Open source
Hack1 source