The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Business & Venture

Crypto Lost $65.9M in June, Not to Zero-Day Bugs but to Preventable Mistakes

Compromised credentials, excessive privileges and bridge validation failures accounted for most crypto losses last month, according to blockchain security firm Hacken.

Crypto Lost $65.9M in June, Not to Zero-Day Bugs but to Preventable Mistakes

Crypto projects lost $65.9 million across 20 security incidents in June, with the month’s biggest breaches stemming from compromised credentials, excessive administrative privileges and bridge validation flaws rather than previously unknown software vulnerabilities, according to Hacken, a blockchain cybersecurity and smart contract auditing company.

Key Takeaways
  • Crypto projects lost $65.9 million across 20 security incidents in June, according to Hacken.
  • Nearly half of the losses came from compromised access controls rather than flaws in blockchain code.
  • Researchers say the industry's recurring failures point to operational security problems that remain unresolved.
Listen to this article
READY

Hacken’s June Pulse report said only $2.5 million was recovered from two incidents. The firm’s researchers estimated that the three largest attacks accounted for more than 85% of all losses during the month. “The industry isn’t facing a shortage of warnings — it’s facing a shortage of fixes,” Hacken wrote.

Humanity Protocol Recorded the Largest Loss

The biggest incident involved Humanity Protocol, a decentralized identity project building proof-of-humanity infrastructure for blockchain applications. Malware on a foundation team member’s device exposed private keys controlling wallets on multiple blockchains, Hacken said. The attacker drained funds from more than 17 wallets and also gained proxy administrator privileges, allowing roughly 100 million unbacked H tokens to be minted.

The token fell between 80% and 90% within hours after the additional supply entered the market, according to the report.

Hacken said the incident resulted from shared operational access rather than a flaw in the protocol’s smart contracts. The firm recommended separating custody keys from upgrade authority and protecting administrative functions with dedicated hardware wallets, air-gapped systems and timelocks.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

Approval Abuse Cost MEV Bot Operator $15M

The second-largest incident targeted JaredFromSubway, an operator known for Ethereum-based maximal extractable value (MEV) trading bots. Attackers deployed 66 counterfeit token wrappers and liquidity pools that manipulated the bot’s automated approval process before draining Wrapped Ether (WETH), USD Coin (USDC) and Tether (USDT) worth about $15 million, Hacken said.

The operator later offered a $1 million bounty for information leading to the recovery of the funds, but no reward was claimed, according to the report. Hacken said automated approval systems should restrict permissions to verified contracts, limit approval scopes and revoke approvals once transactions are completed.

Bridge Validation Flaw Led to Syscoin Exploit

The third-largest breach affected the Syscoin Bridge, part of Syscoin, a blockchain network focused on interoperability. According to Hacken, a validation flaw allowed attackers to create roughly 5 billion SYS tokens on the bridge’s UTXO chain without locking equivalent assets on the corresponding blockchain.

Syscoin paused the bridge before the full amount could be withdrawn, limiting realized losses to about $10 million, the report said. Hacken said the flaw resembled the Verus-Ethereum bridge exploit disclosed in May because both incidents validated each side of a transfer independently without verifying that the transferred amounts matched.

The three incidents together represented more than 85% of June’s reported crypto losses. It Underscores how compromised credentials, administrative controls and transaction validation remained central attack vectors during the month, according to Hacken.

“In May the offensive-defensive AI gap inverted. In June it widened. Attackers are using AI to manufacture malware at scale. Defenders are still running one-time audits. That mismatch is now showing up in the loss data, Hacken noted.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is a bridge validation failure?

A bridge validation failure occurs when a cross-chain protocol allows token minting without verifying that equivalent assets are locked. The Syscoin Bridge exploit resulted in the unauthorized creation of five billion SYS tokens due to this logic flaw. This vulnerability illustrates the systemic risk of independent chain validation in multi-chain environments.
02

Why does the Humanity Protocol breach matter for the DeFi industry?

This breach proves that centralized operational failures can destroy the value of decentralized identity projects in hours. The H token plummeted 90 percent after an attacker used compromised credentials to mint 100 million unbacked assets. It forces a total re-evaluation of how teams manage proxy administrator privileges and private keys.
03

How will Hacken identify emerging crypto security threats?

Hacken utilizes its monthly Pulse report to monitor real-time attack vectors like approval abuse and credential harvesting. The June assessment identified that 85 percent of total market losses originated from just three preventable incidents. Analysts are currently auditing the offensive-defensive AI gap to improve automated threat detection for global clients.
04

What are the risks of automated approval systems in MEV trading?

Automated systems often grant excessive permissions that attackers can manipulate via counterfeit token wrappers and liquidity pools. The JaredFromSubway bot lost $15 million in Wrapped Ether after failing to restrict approval scopes to verified contracts. Critics argue that failing to revoke approvals after transactions creates a permanent backdoor for sophisticated drainers.
05

How will the shift toward AI-generated malware affect protocol defense?

Attackers are using generative tools to manufacture malicious code at a scale that outpaces traditional manual auditing. Hacken reports that the mismatch between high-velocity exploits and static audits resulted in nearly $66 million in June losses. Protocols must adopt real-time behavioral monitoring to survive the industrialization of AI-driven cybercrime.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.