
Abstract
During May-June 2026, crypto security incidents remained elevated across the industry. According to aggregated data from major blockchain monitoring agencies, 142 independent security incidents were confirmed during the period, resulting in approximately US$194 million in verifiable financial losses. DeFi security incidents accounted for 55% of total incidents, with related losses of approximately US$150 million, making DeFi the largest source of risk during the reporting period.
Overall, attack methods showed signs of diversification, scaling, and increasing intelligence. Attackers demonstrated improved ability to exploit both new and legacy vulnerabilities. Cross-chain bridges, private key management, and user endpoints became the three major weak points in the industry’s security risk landscape during the period.
Against this backdrop, MEXC continued to advance its verifiable asset protection framework centered on MEXC Trust. During May-June, MEXC Futures Insurance Fund reached a total balance of 750,854,749 USDT, representing growth of approximately 34.2% from the previous reporting period. Reserve ratios for major assets remained above 100%, with the BTC reserve ratio reaching 269.35%. During the same period, MEXC identified and restricted 9,518 accounts associated with organized risk activities, responded to 497 external investigation requests, and assisted in the recovery of 812 user misdirected deposits.
I. Overview
During May–June, the crypto industry recorded 142 security incidents, resulting in approximately US$194 million in clearly attributable financial losses. These incidents spanned multiple attack surfaces, including DeFi protocol smart-contract vulnerabilities, user-targeted phishing scams, private key and permission risks on centralized platforms, developer endpoint and supply-chain attacks, and physical “wrench attacks” and other threats.
By incident count, the distribution of May–June security incidents was as follows:

1.1 Financial Losses by Category

By financial losses, the distribution of May–June security incidents was as follows:
DeFi security incidents were also the largest risk source during the reporting period, with related losses of approximately US$150 million, significantly higher than those in other categories. This indicates that cross-chain bridges, smart contracts, and scenarios involving concentrated on-chain assets remained the primary targets for attackers.
Financial Losses by Security Category (May–June 2026)
Unit: US$10,000
| Category | Losses |
| Centralized Security | 1468 |
| DeFi Security | 150000 |
| Phishing & Scams | 1746 |
| Endpoint & Supply Chain Security | 1113 |
| Other Threats | 1110 |
II. Representative Cases
1. Centralized Security
- Humanity Protocol was attacked, resulting in total losses exceeding US$31 million and becoming the largest single-loss security incident during the bi-monthly period. The attack was reportedly caused by a foundation member being targeted by a North Korean hacking group through a social engineering phishing campaign, leading to private key compromise. Source: https://x.com/Humanityprot/status/2065480523057647652
- Polymarket experienced two consecutive security incidents during the period, resulting in total losses of approximately US$3.6 million. The first incident was caused by the leakage of a wallet private key used for internal operations and reward distribution, leading to losses of around US$600,000. The second incident stemmed from a compromise of a third-party service provider, where malicious code was injected into the frontend, resulting in approximately US$3 million in user asset losses. Sources: https://decrypt.co/372129/polymarket-refund-users-scammers-swipe-millions-website-exploit, https://x.com/ShantikiranC/status/2057754616230514957
- Gravity Bridge, a cross-chain bridge within the Cosmos ecosystem, was suspected to have been compromised due to leaked signing keys, resulting in approximately US$5.4 million in stolen assets. Source: https://x.com/SpecterAnalyst/status/2060613063816941820
2. DeFi Security
- TrustedVolumes was attacked due to a smart contract vulnerability, resulting in losses of approximately US$6.7 million. Source: https://x.com/trustedvolumes/status/2052235435292910005
- Syscoin Bridge was exploited due to a bridge validation vulnerability, resulting in losses of approximately US$10 million. Source: https://x.com/syscoin/status/2063749418365665413
- Verus-Ethereum Bridge was attacked due to a cross-chain message verification flaw, resulting in losses of approximately US$11.58 million. Source: https://x.com/blockaid_/status/2056176541785034803
3. Phishing & Scams
- Keith Gill’s verified X account (@TheRoaringKitty) was hacked and used to promote a Solana memecoin called $RKC (Red Kitten Crew). The hackers made a profit of over US$500,000. Source: https://ourcryptotalk.com/news/roaring-kitty-x-account-hacked-to-scam-rkc-token
- A Polymarket whale, AdrianCronauer, was reportedly targeted in a phishing attack, resulting in losses exceeding US$2 million. Source: https://www.theblockbeats.info/flash/348673
- Scammers used fake Uniswap advertisements on Google to conduct phishing campaigns, generating at least US$400,000 in illicit profits. Source: https://cointelegraph.com/news/scammers-make-400k-through-fake-uniswap-ads-on-google
4. Endpoint & Supply Chain Security
- The North Korean threat group Lazarus remains highly active, leveraging the “Contagious Interview” campaign to impersonate cryptocurrency and DeFi recruitment processes. Attackers lure blockchain developers into cloning malicious code repositories to steal credentials. Additional reports indicate that Lazarus has reportedly used social engineering phishing campaigns to deploy a new fileless Remote Access Trojan “RemotePE”, targeting banking and cryptocurrency organizations. Sources: https://opensourcemalware.com/blog/lazarus-group-uses-git-hooks-to-hide-malwarehttps://www.cryptopolitan.com/north-korea-lazarus-target-crypto-banks/
- The Rust supply chain malware “IronWorm” has been targeting developer environments and the Web3 ecosystem, posing risks to cryptocurrency development infrastructure. Source: https://x.com/SlowMist_Team/status/2062426026605441481
- Beware of phishing activities from fake TronLink Chrome extensions. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords. Source: https://x.com/SlowMist_Team/status/2053733043853238399
5. Other Threats
- “Wrench attacks“(physical coercion attacks targeting crypto holders) continued to increase. According to CertiK, 34 wrench attacks were recorded globally during the first four months of 2026, representing a 41% year-over-year increase and resulting in approximately US$101 million in losses. 82% of these attacks occurred in Europe. Source: https://www.theblock.co/post/400601/crypto-wrench-attacks-rise-victims-family-members-risk-certik
- Google Threat Intelligence confirmed that cybercriminals leveraged artificial intelligence models to discover and exploit a zero-day vulnerability. Source: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access
- AI-driven acceleration of quantum technology development may bring forward threats to cryptocurrency security. Experts warn that advances in AI could accelerate quantum computing progress, potentially impacting the long-term security of cryptographic systems used in digital assets. Source: https://www.coindesk.com/tech/2026/05/24/ai-is-speeding-up-the-quantum-threat-to-crypto-security-experts-warn
III. Industry Security Trend Summary for May–June
Overall, crypto security threats during May–June showed the following characteristics:
3.1 Private Keys and Internal Permissions Remain Weak Points
Multiple incidents demonstrated that private key management and internal access control remain critical weaknesses across the industry. A single endpoint compromise can lead to complete control of multisignature wallets, resulting in losses worth tens of millions of dollars. Given the significant financial impact and broad consequences of such incidents, technical safeguards alone are insufficient. Comprehensive internal monitoring and incident response capabilities remain essential.
3.2 Cross-Chain Bridges and Smart Contract Vulnerabilities Remain Core Attack Surfaces
Decentralized finance (DeFi) platforms continued to account for the largest share of security incidents during the reporting period. Cross-chain bridgesand smart contract vulnerabilities remained the primary attack vectors.
Attackers continued exploiting flaws in smart contract logic and cross-chain verification mechanisms to generate disproportionately high returns from relatively limited initial investment. Due to their concentration of assets and complex verification processes, cross-chain bridges remain among the industry’s highest-risk targets. Project teams should further strengthen pre-deployment security audits and adversarial testing.
3.3 Phishing Scams Are Evolving from Isolated Fraud to Organized Intrusions
Social engineering attacks continued to evolve. Attackers increasingly exploited compromised X accounts, search engine advertisements, and malicious code injected through third-party service providers to target users. These attacks have become increasingly organized and coordinated, posing persistent threats directly to users’ devices and interaction interfaces.
3.4 Developer Environments Are Becoming Attack Launchpads
North Korean state-sponsored hackers remained the biggest threat to the industry’s digital supply chains. Groups like Lazarus continued to sneak hidden, harmful code into the public open-source software ecosystem. They used popular developer software platforms like npm and PyPI to trick people into downloading malicious packages, letting hackers hijack systems from the inside.
Once a developer environment is compromised, supply chain contamination can rapidly spread across multiple projects, significantly amplifying the impact beyond a single application.
3.5 Physical Attacks and AI-Assisted Vulnerability Exploitation Are Rising
Although relatively fewer in number, these threats carry substantial potential impact. In particular, physical “wrench attacks” continue to rise, evolving from isolated incidents into regional and increasingly organized security threats.
At the same time, AI-assisted zero-day vulnerability development has begun to move from theoretical research into practical application. This suggests that attackers’ capabilities in vulnerability discovery, attack-chain construction, and automated exploitation may continue to improve.
IV. MEXC Trust: Verifiable Asset Protection and Risk Buffering
4.1 Futures Insurance Fund Surpasses 750 Million USDT
As of June 29, 2026, the total balance of MEXC’s Futures Insurance Fund reached 750,854,749 USDT, an increase of approximately 191 million USDT from the 559,465,757 USDT disclosed in the previous reporting period, representing growth of around 34.2%.
The Futures Insurance Fund is primarily designed to address potential position shortfalls under extreme market conditions, reduce the likelihood of Auto-Deleveraging (ADL) being triggered, and support orderly settlement in the futures market. Users can view related information through the Futures – Data – Insurance Fund section on the MEXC website, as well as the Proof of Trust page.
4.2 Major Assets Continue to Maintain Excess Reserves
In addition to risk buffering for the futures market, MEXC continues to provide users with on-chain verifiable asset coverage through its Proof of Reserves mechanism. As of the reporting date, the reserve ratios of MEXC’s major assets were as follows:
- BTC: Reserve ratio of 269.35%, with wallet assets of approximately 12,656.63 BTC and corresponding user assets of approximately 4,698.90 BTC;
- ETH: Reserve ratio of 118.14%, with wallet assets of approximately 77,527.30 ETH and corresponding user assets of approximately 65,624.74 ETH;
- USDT: Reserve ratio of 113.95%, with wallet assets of approximately 2.139 billion USDT and corresponding user assets of approximately 1.877 billion USDT;
- USDC: Reserve ratio of 125.41%, with wallet assets of approximately 95.41 million USDC and corresponding user assets of approximately 76.08 million USDC.
The related reserve data is publicly available via on-chain addresses and the Merkle Tree Proof of Reserves mechanism, allowing users to verify the asset coverage of their holdings.
4.3 Guardian Fund Maintains Dual-Reserve Structure
MEXC Guardian Fund continues to maintain a dual-reserve structure comprising USDT and BTC, with the corresponding holding addresses remaining publicly verifiable. Previously, MEXC disclosed that the Guardian Fund had added 1,000 BTC in reserves, forming a dual-reserve structure of USDT and BTC. The USDT reserve is primarily used to provide immediate liquidity support, while the BTC reserve serves as a long-term reserve asset designed to enhance the fund’s ability to preserve value across market cycles.
The Guardian Fund and the Futures Insurance Fund are complementary. The former is focused on platform-level user asset protection and long-term reserves, while the latter is designed to provide risk buffering for the futures market during periods of extreme volatility.
Guardian Fund wallet addresses:
- USDT: 0x469AfE803C54A36674C55231489Cf4b61da8c1bC
- BTC: 1MDVjZdX8QD212pT8Z8EMP7DuFQHKqN3mx
4.4 Risk Account Identification, External Investigation Support, and Recovery of Misdirected Deposits
During May–June, MEXC successfully identified and restricted 9,518 accounts associated with organized risk activities, involving 4,394 risk groups. These risk groups were mainly concentrated in the CIS region and Indonesia, involving 2,096 and 1,229 groups, respectively.
Regarding external investigation support and law enforcement cooperation, MEXC received 497 investigation requestsduring the reporting period, of which 53 involved judicial freeze assistance. The platform successfully intercepted 7 casesinvolving inflows of risky funds, totalling 303,277.37 USDT. All successfully intercepted cases involved judicial freeze assistance.
In addition, MEXC manually assisted with 812 user requests to return misdirected deposits, successfully returning assets totalling 343,515 USDT. These cases were reviewed manually and verified on-chain, with cross-chain tracking conducted where applicable.
V. Conclusion: From Industry Security Incidents to Verifiable Trust
The crypto security incidents recorded during May–June show that attackers are simultaneously exploiting protocol vulnerabilities, cross-chain verification flaws, weaknesses in private key management, supply-chain infiltration, and user interaction risks. For trading platforms, security is no longer a matter of isolated technical defense, but a systematic capability built on asset reserves, risk buffering, risk-control identification, external cooperation, and asset recovery mechanisms.
The core of MEXC Trust is to turn these capabilities into security infrastructure that is transparent, verifiable, and continuously operational. Through public Proof of Reserves, the Futures Insurance Fund, Guardian Fund, risk account identification, external investigation support, and misdirected deposit recovery mechanisms, MEXC will continue to enhance the transparency and verifiability of user asset protection.
