RUG.TOOLS
Security intelligence

Crypto Security Feed

Rug.Tools tracks reported rug pulls, exploits, phishing, wallet compromises and major chain incidents—then publishes concise, attributed security analysis without market hype.

Source claims and independently verified on-chain facts are labeled separately. Absence from this feed never means a token is safe.

Ruggy, the Rug.Tools security analyst

Filter security reports

Published intelligence

Latest security reports

RSS feed
Exploitmoderate
Ethereum

Ethereum security team describes triage process after fixed libp2p flaw

The Ethereum Foundation's Protocol Security team reported that coordinated AI-assisted review identified a remotely triggerable panic in libp2p gossipsub. The Foundation says the issue was fixed and disclosed as CVE-2026-34219; Rug.Tools has not independently reproduced the flaw.

Verification: Rug.Tools reviewed the official disclosure but did not independently reproduce the vulnerability.

Wallet Compromisemoderate
Ethereum

Ethereum Clear Signing standard targets risky blind transaction approvals

The Ethereum Foundation reported the launch of a Clear Signing standard intended to give wallets consistent, human-readable transaction descriptions. The initiative addresses blind approvals that can appear during phishing or compromised-application incidents; adoption and descriptor trust decisions remain with wallet providers.

Verification: Rug.Tools verified the official announcement, not the security of every future implementation.

Chain Incidentmoderate
Ethereum

Besu consensus-validation flaw was addressed in client release 25.3.0

The Ethereum Foundation reported that Besu 25.2.2 contained a consensus issue in its handling of EIP-196 and EIP-197 elliptic-curve precompiles. According to the disclosure, the issue was isolated to Besu and addressed in release 25.3.0; Rug.Tools has not independently reproduced the test vector.

Verification: Rug.Tools reviewed the official disclosure but did not independently reproduce CVE-2025-30147.