Inside the 12-Hour Crypto Crime Wave: Four Shocking Scams That Could Wipe Out Your Investment—Are You Ready?
By now, eight months into 2026, you’d think the crypto scam wave might be ebbing—but nope, it’s crashing harder than ever. Just a week into September, the crypto market’s murkiness darkens again, courtesy of a fresh spike in scams. Sounds like déjà vu? Well, hold onto your hats because in just the last 12 hours, four distinct types of scams have rattled the industry to its core. Here’s a question to chew on: how does a rogue governance proposal put over 40 ETH—roughly $100,000—at risk, while a social engineering toolkit silently targets your treasured Ledger or Trezor wallets? And how come even big-name pioneers aren’t safe from digital wolves in sheep’s clothing? The crypto underbelly is evolving—its tricks more daring, losses more staggering—and if you think this isn’t your fight, think again. This isn’t just about coins lost—it’s about trust, security, and the future of decentralized finance. Ready to dive deep? LEARN MORE
Eight months into 2026, scams continue to surge with no signs of slowing down. Just one week into September, the market is once again clouded by rising scams.
Notably, in the past 12 hours, there were four different kinds of scams that shook the crypto industry.
How is 40.196 ETH at risk?
Starting with a malicious governance proposal targeting Olas (formerly Autonolas) has put around 40.196 Ethereum [ETH] worth of $100,000 at risk.

This happened after an attacker used the ENS name “autonolas-deployer.eth” and disguised the proposal as a routine treasury ownership migration.
In reality, executing it would transfer control from the legitimate Autonolas Timelock to an attacker-controlled contract. This in turn would allow the attacker to alter the treasury and withdraw its funds. Hence, to avoid this, the community has a three-day window to reject the proposal before it can be executed.
More such incidents
Additionally, there was an attack on Reddio (an Ethereum-compatible Layer 2 blockchain), which led to an estimated loss of 9.25 ETH. This happened because of a cross-vault accounting flaw that double-counted stETH as backing for both rsvETH and rsvstETH.
Needless to say, if this is not fixed in time, an attacker could misuse this with a flash loan. All the attacker needs to do is to deposit stETH to artificially inflate rsvETH’s share price and then redeem it for excess ETH. This in turn would allow them to recover the same stETH through rsvstETH.
While these two attacks were gaining attention, another illicit actor allegedly sold an “unleaked” cryptocurrency theft toolkit targeting Ledger and Trezor users. Interestingly, this was successful primarily through social engineering and deceptive transaction-signing requests rather than a confirmed hardware vulnerability.
This looks serious, as the toolkit reportedly supports multiple cryptocurrencies and EVM chains, customizable recipient addresses, SMS-based interactions, and prebuilt scam templates.

Here, the above image clearly shows a Trezor Model T-style request for a 5 ETH transaction, designed to trick users into approving a malicious transfer. The seller also claims “one-click” functionality and says similar tools have sold for five-figure prices.
Big names are getting attacked as well
Adding more fuel to the fire, Jesse Pollak, Base co-founder, warned that an attacker used a compromised third-party app connected to his social media account to post scam content. Though he has now deleted the posts and revoked all app connections, cutting off the attacker’s access, concerns remain.
This further coincided with an X account of Neuralink executive Shivon Zilis being compromised and used to promote the SLINK memecoin. However, things got serious when Elon Musk’s emoji response made the post appear legitimate and triggered a wave of FOMO buying.
2025 vs. 2026
DeFiLlama data suggest that between September 2025 and September 2026, total losses are worth $1.732 billion.

That said, in H1 2026 alone, crypto theft and fraud losses exceeded $1 billion, as previously reported by AMBCrypto. Yet, despite these huge losses, H1 2025 was even worse, as it saw $2.3 billion lost to funds.
However, despite the increase in scams, Genians claim that Kimsuky, a North Korean cyber-espionage group, is utilizing AI to improve its hacking activities.
Final Summary
- A malicious governance proposal has put 40.196 ETH associated with Autonolas at risk.
- Base co-founder warned that an attacker used his social-media account to post scam content.




Post Comment