Crypto Security Report July 2026

Featuring MetaMask's 10th anniversary security milestones, global law enforcement operations dismantling crypto crime infrastructure across 97 countries, threat reports from SlowMist and TRM Labs, and more.

9 minutes
Crypto Security Report July 2026

Each month, MetaMask Security Director Luker reports on the latest crypto attacks, emerging risks, scam preventions, and hacker takedowns. This installment kicks off with the good news first.

In July 2026, MetaMask celebrated its 10th birthday, and recapped scam prevention efforts from the last year. Over 6.5 million malicious site visits were blocked by MetaMask in 2025 alone, preventing nearly 150,000 malicious transactions, and helping users avoid over $500 million in losses. Global law enforcement also hit back against hackers. INTERPOL's Operation First Light spanned 97 countries with 5,800 arrests and $293 million intercepted. Europol's Operation Endgame froze $47 million in criminal crypto. And, Poland's SIM-swapping bust drew FBI and ZachXBT assistance.

Elsewhere, SlowMist and TRM Labs shared H1 2026 crypto hack reports, tallying $956M–$972M in losses across 200+ incidents, with TRM attributing 66% to North Korea. Coinspect's Ill Bloom disclosure revealed thousands of wallets at risk from weak seed generation, and fake GTA 6 early access sites and malware-laced Steam games showed scammers using games themselves to reach crypto holders. Dive into the details below, but first...

Isabella Abbott (AKA "The First Lady of Limu") was the first Native Hawaiian woman to earn a PhD in science. She went on to become a leading expert on Pacific marine algae, having discovered over 200 species. She spent much of her career at Stanford, where in 1972 she became the university's first woman and first person of color promoted directly to full professor of biology.

MetaMask turns 10 with 6.5 million malicious site visits blocked and $500 million in losses prevented in 2025

MetaMask turned 10 years old on July 14 2026, and we look forward to providing the most secure experience possible for many more to come! As highlighted in our announcement:

"In 2025 alone, MetaMask's protections blocked more than 6.5 million malicious website visits and prevented nearly 150,000 malicious transactions, helping users avoid over $500 million in losses. As blockchain technology has evolved from early experimentation toward mainstream financial services, MetaMask has continuously strengthened the protections embedded in the platform. Today, built-in security alerts, frontrun protection, real-time threat monitoring and regular independent security audits help protect users at every stage of their onchain journey, and that security is why millions of users have trusted MetaMask to navigate the decentralized economy for the past ten years. That commitment becomes even more important as the platform expands beyond the wallet into a broader consumer financial platform."

Operation Endgame freezes $47M in criminal crypto and dismantles SocGholish, Amadey, and StealC malware pipelines

Europol's latest phase of Operation Endgame froze about $47 million in criminal crypto by dismantling the malware pipelines behind the thefts. SocGholish, Amadey, and StealC each worked to trick victims through fake browser updates before quietly lifting passwords and wallet data. StealC in particular has a control panel that includes “a plugin that tried to decrypt the seed phrases of victims' MetaMask wallets, researchers at Proofpoint found.” Police took down 326 servers and 142 domains, and recovered 27 million stolen credentials.

Poland SIM-swapping bust nets four suspects with FBI and ZachXBT assistance

Poland's SIM-swapping bust revealed four suspects accused of hijacking phone numbers and email accounts to take over crypto exchange logins were arrested through a joint effort between Polish police, the FBI, and Homeland Security Investigations, with independent blockchain investigator ZachXBT helping identify one suspect from raid photos.

INTERPOL Operation First Light 2026 spans 97 countries with 5,800 arrests and $293M intercepted

INTERPOL's Operation First Light 2026 is the biggest of these efforts, spanning 97 countries, nearly 5,800 arrests, and $293 million in intercepted assets tied to social engineering scams. Highlights include a fake police station dismantled in Eswatini, a $122.5 million crypto laundering trail traced in Thailand, a $6.6 million business email compromise transfer blocked in real time between Singapore and Oman, and a public awareness campaign in Macao that stopped a victim from sending $372,000.

All these stories tell a tale of authorities going after the shared infrastructure and networks criminals depend on, not just chasing stolen funds after the fact.

The Red Guild explores sustainable funding after Giveth Ethereum Security Quantum round

The Red Guild has been a collective of active contributors to the web3 security space for over three years, operating as a non-profit organization, doing public goods alongside entities like SEAL and ZachXBT. The guild came in second of all the qualifying participants of Giveth's Ethereum Security Quantum Funding round, and is using the funds to pay back those contributors who worked to make the ecosystem safer without any guarantee that they would be compensated.

However, even with the funding from this round, it is not enough to sustain the organization as a public good. As one of The Red Guild’s founders, matta, put it: "We will continue exploring different ways to fund ourselves, but this time outside public-good contributions, at least temporarily, until we can find our holy grail. It might be The Phishing Dojo, which, by the way, is about to release its first open real beta, or it might be [another] new exploration." 

Some of the past activities from the group include leading the ETH Rangers program, security awareness campaigns, Damn Vulnerable DeFi, leading the Security Frameworks by SEAL, and, of course, The Phishing Dojo threat simulation program.  We here at MetaMask appreciate everything The Red Guild has done for Ethereum security and wish you the best in finding a more sustainable path!

Crypto security H1 2026 threat reports: SlowMist and TRM Labs count $956M–$972M in losses across 182–207 incidents

Two separate reports on H1 2026 from SlowMist and TRM Labs, respectively, tell a similar top line story but disagree on the details. SlowMist counted 182 security incidents totaling roughly $956 million in losses. TRM counted 207 incidents totaling about $972 million. Both agree the pattern is the same: more attacks than ever, but total dollars stolen fell by more than half compared to H1 2025. The gap in incident counts likely comes down to methodology and what each firm classifies as a reportable hack, but the broader trend lines up.

Where the two reports really diverge is on causation. SlowMist frames the Kelp DAO exploit on LayerZero, a $292 million loss from a compromised DVN configuration, as a supply chain attack and the single largest incident of the half. TRM agrees on the dollar figure but categorizes it differently. It folds Kelp DAO into a broader "infrastructure and operational compromise" bucket. That bucket also includes a second North Korea linked attack on Drift Protocol, worth about $285 million. SlowMist's report doesn't mention that hack at all. Together, TRM attributes $643 million to North Korea, or 66% of all H1 losses. SlowMist doesn't put a number on state actor attribution like this, even though it flags Lazarus Group as active.

Following these trends, Forbes released an article highlighting the fact that attacks becoming more sophisticated and surgical explain the shift in quality over quantity. The general trend is a departure from smart contract vulnerability exploits to operational security and distributed key management weaknesses.

Coinspect Ill Bloom vulnerability puts thousands of wallets at risk from weak seed generation

Coinspect published research on a weak seed generation issue affecting crypto wallets, building on the pattern first seen in the Milk Sad research. The root problem traces back to an insecure source of randomness used during wallet creation, which shrinks the pool of possible recovery phrases down to something an attacker could actually brute force. Unfortunately, this isn't a bug you can patch away after the fact. If a recovery phrase was generated with weak randomness, that phrase stays weak forever, even if the wallet app gets updated or the user moves the same seed into a completely different wallet. Coinspect's investigation is still ongoing, but they've already created a public checker and guidance for both users and wallet developers. Compromises should be treated as seed level risks and the only real fix is generating and migrating funds to a brand new wallet with secure randomness.

Coinspect's own coverage of the issue and additional reporting from The Hacker News point to the risk sitting mainly with older or lesser known mobile wallets and browser extensions, not mainstream wallets, such as MetaMask. Speaking of, Coinspect also separately named MetaMask the most secure wallet across all platforms in its 2025 wallet security ranking. Pair MetaMask with a secure hardware wallet for anything holding meaningful value, avoid accumulating high value on a single address, and always keep an eye out for official communications on app security.

Fake GTA 6 early access sites and malware-laced Steam games target crypto holders

Two recent cases show scammers increasingly using video games themselves, not just phishing links, to reach crypto holders. With Grand Theft Auto 6 still absent from PC and Android ahead of its November 19 2026 console launch, fake "VIP Early Access" sites have surfaced using real game branding to charge fans roughly $250 in crypto for downloads that don't exist, sometimes delivering info-stealing malware or ransomware instead.

Separately, federal prosecutors charged 21-year-old Florida student Zyaire Wilkins for allegedly publishing multiple fully playable, malware-laced games directly on Steam over two years, including titles like BlockBlasters, Dashverse, and PirateFi. The FBI says around 8,000 people were infected and roughly $220,000 was drained from about 80 crypto wallets, with the group allegedly using bots to target users with large crypto holdings. Investigators eventually traced the scheme through stolen Bitcoin funneled into gift cards, leading agents directly to the culprit.

Stay safe out there, all you keyboard cowboys!


MetaMask’s August 2026 Crypto Security Report included details of 6.5 million malicious site visits blocked by MetaMask in 2025 alone, preventing nearly 150,000 malicious transactions, and helping users avoid over $500 million in losses. Elsewhere, INTERPOL's Operation First Light 2026 spanning 97 countries with 5,800 arrests and $293 million intercepted. Additionally, SlowMist and TRM Labs documented $956M–$972M in H1 2026 crypto losses. And, Coinspect's Ill Bloom weak seed generation vulnerability putting thousands of wallets at risk. Browse previous editions of the MetaMask Crypto Security Report for more threats, trends, and tips for staying safe across the ecosystem.

  • Luker
    Luker

      Jen Luker, known by most as just Luker, is the Director of Product Security at Consensys, where she leads the frontline defenders who protect millions of users from vulnerabilities, emerging threats, and malicious actors across decentralized tech. An active participant in the Ethereum ecosystem since 2017, she has held key roles including Editor at ETHNews and Project Manager at MyCrypto. Luker is a regular speaker at industry conferences, the author of MetaMask's monthly Crypto Security Report, and an official ETH Security Badge holder as designated by The DAO. She's also a passionate advocate for continuous education and security awareness as essential pillars for the future of Ethereum and blockchain technology.

      Read all articles