
Featured Post
USDT Freeze 2026: Who's Frozen, How to Check, Live Data
As of 2026-07-26, Tether has blacklisted 9,597 USDT addresses and frozen $5.69 billion via the USDT smart contract's freeze mechanic. This 2026 pillar guide covers how freezes work on-chain, why Tether freezes addresses (with 2026 case data from the $344M April Iran seizure to the $131M July Operation Economic Fury freeze, and roughly $1B cumulative Iran-linked seizures since the campaign began), how the multisig-delay window opens a documented escape channel (BlockSec's analysis of 8,310 executed freeze proposals recorded $215.5M moved out during the delay), what 'destroyed' USDT really means for victims (burn-and-reissue mechanism), whether frozen addresses can be unfrozen (3.6% do get removed), and how to build compliance around freeze risk.

How to Visualize Crypto Money Flows
How to visualize crypto money flows: build a money flow graph, why flows beat spreadsheets for investigations, and how labels turn graphs into evidence.

How to Detect a Rug Pull Before Investing
How to detect a rug pull before investing: check the deployer, not just the chart, the red flags that actually matter, and a four-step due diligence workflow.

What Crypto Investigation Tooling Really Costs: Four Billing Models Compared
The real cost of crypto investigation tooling: four billing dimensions, what each tool charges at each tier, and the hidden costs beyond the sticker price.

Bitget's $387.5M Off-Chain Breach: Beyond Keys and Contracts
On September 24, 2026, attackers exploited a vulnerability in a third-party security product, obtained internal credentials, and forged withdrawal commands. The resulting transfers moved approximately $387.5M from some of Bitget's operational wallets across Ethereum, other EVM networks, XRP Ledger, Zcash, and TRON; private keys and cold wallets remained intact. This deep dive summarizes the disclosed incident path and fund flow, examines rapid conversion into native assets and the ecosystem recovery response, proposes a systematic defense-in-depth framework for institutions, and explains how authorized blockchain penetration testing can validate cross-layer assumptions.

Bitget's $387M Hack: Laundering Path, Freezes and Attribution
An on-chain review of the $387.5 million Bitget hack: how the attacker swapped stolen stablecoins into native tokens within 41 minutes, moved funds toward Bitcoin through THORChain and CoinJoin, and where the roughly $840,000 frozen by Tether, Circle and NEAR Intents came from. We also look at the evidence behind the North Korea attribution and how the case compares with the 2025 Bybit hack.

~$11.3M Lost: Multicall Router, Nostra | BlockSec Weekly
This report, covering 2026/09/14 - 2026/09/20, examines two security incidents with approximately $11.3M in combined losses, on Ethereum and Starknet. In the larger one, a multicall router accepted its own address as a dispatch target, so the nested call reached the Gateway module of a Safe wallet carrying the router's own already-authorized identity instead of the external caller's, and roughly 2,900 `aEthrsETH` was routed out of that wallet into an attacker-created Uniswap v4 pool. On Starknet, Nostra's oracle integration required a minimum of only one aggregated source, so when only two of the three configured price sources reached the aggregation, a manipulated thin-pool quote averaged with a normal quote to value `NSTR` at roughly $49.52, supporting approximately $3.5M of borrowing against overvalued collateral.

AML Banking: A Compliance Checklist for Banks
AML banking checklist: onboarding KYC, transaction monitoring, suspicious activity reports, and a risk-based approach banks must operate at exam speed.

AML in Finance: How Traditional Institutions Fight Money Laundering
AML in finance spans customer due diligence, transaction monitoring, and suspicious reporting for banks, brokerages, and asset managers in every regime.

Blockchain Security Software: Attack Prevention, Compliance Monitoring, and the Overlap
Blockchain security software spans attack prevention and compliance monitoring: where the two overlap, what each covers, and how a combined stack works.

Blockchain Forensics Software: What Investigation Teams Should Expect
Blockchain forensics software for investigation teams: path reconstruction, entity attribution, evidence quality, and how the capability tiers differ.

OFAC Sanctions Monitoring for Crypto: What Changes After Designation
OFAC sanctions crypto news is an operational event: every designation updates the SDN list and can flip already-onboarded wallets from clean to risky overnight.

SAR Form: What a Suspicious Activity Report Contains
SAR form: what a suspicious activity report contains. See the key fields, jurisdictional format differences, and how a KYT tool exports the draft for review.