CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Cryptohack Roundup: Harmony, BTCPay Exploits

Data Breach Today Archived Aug 13, 2026 ✓ Full text saved

Also: CTFC-led $48M Fraud Case, NFT Founder Charged in $10M Scam This week, Harmony and BTCPay hacked, violent crypto thefts surged, the U.S. CFTC filed a $48 million fraud case, an NFT founder charged, North Koreans used artificial intelligence for crypto exploits, and the U.S. sanctioned two Iranian exchanges.

Full text archived locally
✦ AI Summary · Claude Sonnet


    Blockchain & Cryptocurrency , Cryptocurrency Fraud , Fraud Management & Cybercrime Cryptohack Roundup: Harmony, BTCPay Exploits Also: CTFC-led $48M Fraud Case, NFT Founder Charged in $10M Scam Rashmi Ramesh (rashmiramesh_) • August 13, 2026     Credit Eligible Get Permission Image: Shutterstock Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Harmony and BTCPay hacked, violent crypto thefts surged, the U.S. CFTC filed a $48 million fraud case, an NFT founder charged, North Koreans used artificial intelligence for crypto exploits, and the U.S. sanctioned two Iranian exchanges. See Also: OnDemand | NSM-8 Deadline July 2022:Keys for Quantum-Resistant Algorithms Implementation Harmony Confirms Exploit After Billions of Tokens Minted Harmony confirmed an exploit after an attacker created about 4 billion of its One tokens without authorization. An X user named Juiceberg first reported the attack, saying the hacker minted the tokens by exploiting empty transaction records. Most had reached exchanges, while about 115 million One tokens could still be sold directly on the network. Harmony said it was working with exchanges to stop and freeze the funds. The blockchain platform is also preparing a software fix and considering whether to reverse transactions. It has not yet disclosed what technical weakness allowed the attack. One fell 34% over 24 hours to around $0.0008, valuing the newly created tokens at roughly $3.2 million. Harmony suffered a major hack in 2022, when attackers stole nearly $100 million from its Horizon bridge. The FBI attributed the attack to North Korea (see: Horizon Offers $1M Bounty to Hackers Who Stole $100M). BTCPay Server Warns Of Active Security Attack BTCPay Server warned users that attackers are exploiting a critical security flaw that could put funds at risk. The project urged users to immediately update their servers to version 2.4.2. Users who cannot install the update should shut down their BTCPay Server until they can upgrade, the team said. BTCPay Server did not disclose how many users were affected or whether attackers stole any funds. BTCPay Server is free software that allows individuals and businesses to accept bitcoin payments without relying on a payment company. Users host the software themselves. Violent Crypto Thefts Surge In 2026 Violent criminals stole more than $30 million in cryptocurrency during the first half of 2026, putting the year on course for a record, Chainalysis said. These attacks include kidnappings, home invasions and hostage situations where victims are forced to transfer digital assets. France emerged as a major hotspot. Chainalysis recorded 30 publicly known cases in the country by mid-year, compared with 19 during all of 2025. French authorities have reported even more incidents and made about 200 arrests. Chainalysis linked the surge to leaks of personal information about cryptocurrency holders. Attackers are also increasingly targeting victims' relatives and acquaintances. Despite the rise in violence, criminals are succeeding less often, Chainalysis said. About a quarter of theft attempts resulted in payments through late June, down sharply from previous years. US CFTC Accuses Florida Man Of $48 Million Crypto Fraud The U.S. Commodity Futures Trading Commission filed a complaint against Florida businessman Christopher Delgado for misusing $48 million in customer funds, spending the money on a yacht, luxury goods, travel and pet grooming. The CFTC alleged that Delgado and his company Goliath Ventures operated a Ponzi scheme, where money from newer customers is used to pay earlier customers instead of generating genuine investment returns. More than 1,600 customers gave Goliath about $397 million, the agency said. Delgado allegedly told customers their money would earn returns through cryptocurrency trading services that allow users to exchange assets without a central company. Instead, customer funds were allegedly used for personal expenses and payments to other customers. The CFTC said corporate cards funded millions of dollars in travel, luxury purchases and family expenses. The U.S. Securities and Exchange Commission also initiated litigation. Delgado separately pleaded guilty in June to federal fraud and money laundering charges. NFT Founder Faces Federal Fraud Charges U.S. federal prosecutors charged non-fungible tokens startup founder Taj Tarsha with securities and wire fraud, alleging he diverted millions of dollars from investors to personal expenses. Each charge carries a maximum prison sentence of 20 years. Tarsha raised more than $10 million from nearly 70 investors through Few and Far Limited. He sold agreements that promised investors digital tokens in the future to support a planned online marketplace for NFTs, which are digital records used to show ownership of unique items. Prosecutors said Tarsha instead spent investor money on gambling, risky digital assets, a loan for a Miami condominium, interior design and his DJ activities. An audit uncovered the alleged misuse. Tarsha also allegedly misled investors about token sales and continued development. Prosecutors said he had dismissed nearly all employees while directing a remaining contractor to make the marketplace appear active. North Korean Hackers Use AI to Target Crypto Firms North Korean nation-state threat actor Kimsuky is using artificial intelligence tools to strengthen cyberattacks against cryptocurrency and financial companies, saidSouth Korean cybersecurity firm Genians. The researchers found evidence that Kimsuky operated three AI systems on its own computers. Running these systems locally allows hackers to analyze information and generate content without sending sensitive data to outside online services. Genians said Kimsuky is combining existing publicly available AI technology with malicious software, data analysis and tools that can automate parts of an attack. The group does not appear to be building its own AI models. Kimsuky is also using AI to create convincing phishing documents designed to trick people into revealing information or opening harmful files. Some materials copied the appearance of a Korean investment platform and focused on digital assets and financial services. North Korean hackers stole $2 billion in cryptocurrency last year. US Sanctions Two Iranian Crypto Exchanges The U.S. Department of the Treasury sanctioned crypto exchanges Shelbit and Aban Tether, expanding the Trump administration's "Economic Fury" campaign against Iranian financial networks. Treasury alleged that the exchanges helped move large amounts of cryptocurrency, evade U.S. sanctions and support Iran's Islamic Revolutionary Guard Corps and other U.S.-designated terrorist groups. It also sanctioned Shelbit operator Siavash Kayvanpour and several companies he controls. Wallets belonging to the Revolutionary Guard sent more than $1 million to Shelbit and received over $2 million from the exchange, according to the Treasury. Officials also accused Shelbit of serving more than 2,000 gambling websites involved in laundering tens of millions of dollars. The sanctions follow a Reuters investigation that found Shelbit processed at least $4 billion over two years through networks linked to Iranian gambling sites and other entities. Aban Tether allegedly handled millions of dollars involving previously sanctioned Iranian crypto platforms.
    💬 Team Notes
    Article Info
    Source
    Data Breach Today
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗