Multiple significant cryptocurrency scams emerged within 12 hours in early September 2026, putting at least $100,000 in funds at risk and compromising high-profile social media accounts. A malicious governance proposal targeted the Olas (formerly Autonolas) protocol, endangering 40.196 ETH. A cross-vault accounting flaw on Reddio, an Ethereum layer-2 blockchain, led to an estimated loss of 9.25 ETH. Meanwhile, a cryptocurrency theft toolkit targeting Ledger and Trezor users was sold on the dark web, and the X accounts of Base co-founder Jesse Pollak and Neuralink executive Shivon Zilis were compromised to promote scams.
Eight months into 2026, scams continue to surge with no signs of slowing down. In the past 12 hours, four different kinds of scams shook the crypto industry.
A malicious governance proposal targeting Olas (formerly Autonolas) put approximately 40.196 Ethereum (ETH), worth $100,000, at risk. An attacker used the ENS name “autonolas-deployer.eth” and disguised the proposal as a routine treasury ownership migration. Executing it would transfer control from the legitimate Autonolas Timelock to an attacker-controlled contract, allowing the attacker to alter the treasury and withdraw its funds. The community has a three-day window to reject the proposal before it can be executed.
Additionally, an attack on Reddio, an Ethereum-compatible layer-2 blockchain, led to an estimated loss of 9.25 ETH due to a cross-vault accounting flaw that double-counted stETH as backing for both rsvETH and rsvstETH. If not fixed, an attacker could use a flash loan to deposit stETH, artificially inflate rsvETH’s share price, and redeem it for excess ETH while recovering the same stETH through rsvstETH.
Another illicit actor allegedly sold an “unleaked” cryptocurrency theft toolkit targeting Ledger and Trezor users. The toolkit succeeds primarily through social engineering and deceptive transaction-signing requests rather than a confirmed hardware vulnerability. It reportedly supports multiple cryptocurrencies and EVM chains, customizable recipient addresses, SMS-based interactions, and prebuilt scam templates.
Adding more fuel to the fire, Jesse Pollak, Base co-founder, warned that an attacker used a compromised third-party app connected to his social media account to post scam content. He has since deleted the posts and revoked all app connections. This coincided with the X account of Neuralink executive Shivon Zilis being compromised and used to promote the SLINK memecoin. Elon Musk’s emoji response made the post appear legitimate, triggering a wave of FOMO buying.
DeFiLlama data shows that between September 2025 and September 2026, total losses are worth $1.732 billion. In H1 2026 alone, crypto theft and fraud losses exceeded $1 billion. However, H1 2025 was even worse, seeing $2.3 billion lost. Despite the increase in scams, Genians claim that Kimsuky, a North Korean cyber-espionage group, is utilizing AI to improve its hacking activities.
